Skip to main content

Server Requirements (On-prem)


UXM Deployment and Scaling Overview

UXM is built to deliver reliable performance and scalability — supporting 10,000+ desktop agents and handling millions of web page requests daily.
To ensure optimal performance, we recommend deploying a Splunk Heavy Forwarder integrated with UXM, which includes NGINX and the RabbitMQ queue. This setup forwards data to Splunk Indexers through the HTTP Event Collector (HEC), ensuring efficient, real-time data ingestion.


1. Standalone Deployment

Best for:
Organizations with up to 20,000 endpoints and up to 4 concurrent data analysis users.

If your organization already uses Splunk, we recommend adding a Heavy Forwarder configured with NGINX and RabbitMQ. This helps manage data flow smoothly and prevents overloading your Search Head.

ComponentNumber of ServersCPUMemoryDiskSoftware
Data Receiving, Analysis, and Storage18 vCPU32 GB RAM300 GB SSDNGINX, RabbitMQ, Splunk Search Head, Splunk Indexer

Typical Splunk license usage: < 10 GB per day.


2. Small Distributed Deployment

Best for:
Environments with around 20,000 endpoints and more than 4 concurrent users performing data analysis.

This model separates the data collection and data analysis/storage functions, enabling better scalability and performance as your environment grows.

ComponentNumber of ServersCPUMemoryDiskSoftware
Data Collector1 per 20,000 endpoints8 vCPU12 GB RAM100 GB SSDSplunk Heavy Forwarder, NGINX, RabbitMQ
Data Analysis and Storage116 vCPU64 GB RAM100 GB SSD + 500 GB for 1-year retentionSplunk Search Head, Splunk Indexer

Typical Splunk license usage: 10–70 GB per day.


3. Large Distributed Deployment

Best for:
Large organizations managing up to 70,000 laptops/desktops/thin clients, 6,000 Citrix servers, and approximately 60,000 Citrix users.

This architecture ensures high reliability and performance by distributing data collection, analysis, and storage across multiple dedicated servers.

ComponentNumber of ServersCPUMemoryDiskSoftware
Data Collector4 (1 per 20,000 endpoints)16 vCPU16 GB RAM300 GB SSDSplunk Heavy Forwarder, NGINX, RabbitMQ
Data Analysis148 vCPU62 GB RAM300 GB SSDSplunk Search Head
Data Storage148 vCPU62 GB RAM300 GB SSD + 10 TB for 1-year retentionSplunk Indexer

Typical Splunk license usage: ~75 GB per day.