I was asked to make a PoC to show the capability the Elastic as a SIEM so the PoC will take logs from (Fortigate Firewall, Two WIndows PCs, one Windows server for file sharing) So I will setup Elasticsearch as one node only and kibana in another instance and Fleet to manage the agents, So how can I estimate the requirements of hardware for each Instance according to its role espicially the instance will be the elasticsearch node.
First, Thanks for the reply.
Secondly, I want to ask if the Sizing calculators that estimate that the fortigate firewall for example is accurate or I can depend on its results.
another thing that what is the CPU/ram Ratio I can use.
and Thank you again.
If it allowed to you to provide me with the test results without without any sensitive data to your organization and if you can't. if possible you can tell me high level info like you provided in your first reply.
Thanks in advance.