# System requirements for Elastic Security "All-in-One" pilot deployment

**URL:** <https://discuss.elastic.co/t/system-requirements-for-elastic-security-all-in-one-pilot-deployment/385731>\
**Category:** SIEM\
**Created:** [April 1, 2026, 2:01pm UTC](https://discuss.elastic.co/t/system-requirements-for-elastic-security-all-in-one-pilot-deployment/385731 "2026-04-01T14:01:02Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![PatreKerier](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/patrekerier/32/141214_2.png) [@PatreKerier](https://discuss.elastic.co/u/PatreKerier)\
**Post date:** [April 1, 2026, 2:01pm UTC](https://discuss.elastic.co/t/system-requirements-for-elastic-security-all-in-one-pilot-deployment/385731/1 "2026-04-01T14:01:02Z")

</div>

**Hello everyone,**

My company is planning a pilot project to test **Elastic Security** (including Elasticsearch, Kibana, Logstash, and Fleet). We are also looking into integrating it with various third-party services.

For this testing phase, we intend to deploy the entire stack on a single machine ( **All-in-One setup** ). Could you please provide recommendations regarding the system requirements? Specifically, I would appreciate guidance on:

- **CPU:** Recommended number of cores (vCPU).

- **RAM:** Minimum and recommended memory allocation for a stable environment.

- **Storage:** Recommended disk space and type (SSD/NVMe).

Thank you in advance for your help!

---

<div class="post-metadata">

**Author:** ![arav](https://avatars.discourse-cdn.com/v4/letter/a/b9e5f3/32.png) [@arav](https://discuss.elastic.co/u/arav)\
**Post date:** [April 3, 2026, 5:07am UTC](https://discuss.elastic.co/t/system-requirements-for-elastic-security-all-in-one-pilot-deployment/385731/2 "2026-04-03T05:07:03Z")

</div>

Let’s say, for 10 log sources with different integrations, 20 vCPU, 32gb RAM, 750gb NVMe SSD is the recommended baseline. You can go bigger if you can/want. Me and my team did it with almost this same requirements, but with each machine of their own in the stack.

---

<div class="post-metadata">

**Author:** ![PatreKerier](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/patrekerier/32/141214_2.png) [@PatreKerier](https://discuss.elastic.co/u/PatreKerier)\
**Post date:** [April 3, 2026, 5:46am UTC](https://discuss.elastic.co/t/system-requirements-for-elastic-security-all-in-one-pilot-deployment/385731/3 "2026-04-03T05:46:03Z")

</div>

Can you tell me if it will be possible to implement the placement of SIEM in our infrastructure based on SAS disks?

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [April 3, 2026, 8:30am UTC](https://discuss.elastic.co/t/system-requirements-for-elastic-security-all-in-one-pilot-deployment/385731/4 "2026-04-03T08:30:42Z")

</div>

I would strongly recommend that you use SSD disks as both indexing and querying in Elasticsearch can be very I/O intensive, especially at higher data volumes. NVMe SSD is ideal but SAS SSDs might also work. If you are considering using HDD I would strongly recommend against that.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 1, 2026, 8:31am UTC](https://discuss.elastic.co/t/system-requirements-for-elastic-security-all-in-one-pilot-deployment/385731/5 "2026-05-01T08:31:08Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
