SIEM Kitchen

Chef 1: Input Calculator

Define your environment's log sources and asset counts to calculate total daily raw and indexed data volumes.

Log SourceBase Avg/Asset (MB)Asset CountDaily RawDaily IndexedRequired License
Total Assets: 0
Total Raw Logs: 0.00 GB
Total Index Size: 0.00 GB
Required Splunk License: 0.00 GB
Chef 2: Splunk Architecture & Planner

Plan your Splunk distributed topology. Calculations dynamically factor in premium applications, storage tiers, and high-availability clustering.

Premium Apps

Index Settings

Data Lifecycle Retention

(~1.0 mo)
(~2.0 mo)
(~9.2 mo)

Indexer Storage Blueprint (Per Server)

OS & App (SSD RAID 1): 50 GB
Hot/Warm (SSD/NVMe RAID 10): 0 GB
Cold (HDD RAID 5/6): 0 GB
Frozen (Object/NFS/S3): 0 GB
Total Usable Local Disk Needed: 0 TB / Indexer

Detailed Server Roles & Compute

Server RoleCountMin (vCPU/RAM)Rec (vCPU/RAM)Heavy (vCPU/RAM)
Chef 3: RAID Calculator

Determine usable hardware capacity, fault tolerance, and IOPS speed gains for your underlying Splunk disk arrays.

Usable Capacity: -
Unavailable Capacity: -
Capacity Utilization: -
Read Speed Gain (Max): -
Write Speed Gain (Max): -
Fault Tolerance (Disks): -
TierRAIDDisk SizeCountUsableUtilizationSpeed (R/W)FTAction
No RAID configurations added yet.
Chef 4: Splunk Commander

Generate OS-level baseline configurations (ulimits, THP, Firewalls) to prepare Linux nodes prior to Splunk installation.

Chef 5: Splunk Sampler

Generate an `indexes.conf` baseline mapping your storage partitions to Splunk index lifecycle definitions dynamically using Chef 2 calculations.

Chef X: What's Next? 🚀
In the future, suggested settings for Cisco switches and routers, Windows and Linux, Sysmon, etc. will be added.
💡 Version 3.2.0 | What do you want? Send a message!

References

Splunk Validated Architectures (SVA) Guidelines | Splunk Capacity Planning Manual | Splunk Enterprise Storage Requirements | Enterprise Security (ES) Sizing | ITSI Sizing Guidelines | indexes.conf Configuration Reference | Storage Fault Tolerance Matrices | RAID Sizing & Performance Standards | Linux System Requirements (THP, limits, systemd)

Copyright 2026 - nextnoble.info - Powered by dear Gemini