Doing budget forecasting, planning to implement Graylog next year, and trying to estimate our hardware costs to do so. Our organization is very small, we anticipate only 5-10gb of log ingestion per day. The docs suggest that at that scale we ought to have 2 (physical!?) servers, one for Graylog with 8 cores and 16GB of RAM, and one for Data Node with 8 cores and 24GB of RAM. Is there any reason I shouldn’t just build one big hypervisor with enough cores and ram for both and spin up a VM for each of those?
Given that it’s hard to even find a server cpu with less than 12 cores, it kind of seems like the docs are written with the assumption I’ll be virtualizing, but I don’t know if there’s some other concern I’m missing. Thanks for your guidance!
Before you post: Your responses to these questions will help the community help you. Please complete this template if you’re asking a support question.
Don’t forget to select tags to help index your topic!
1. Describe your incident:
n/a
2. Describe your environment:
- TBD
3. What steps have you already taken to try and solve the problem?
Reading the manual
4. How can the community help?
Please sanity-check my understanding of this topic and explain if I’ve misunderstood something.