I have received many requests for Log Insight configuration maximums. While most of the relevant information is available in the official documentation, there is no central place to reference… until now!
UPDATE: Configuration maximums have been added to the Log Insight documentation starting with 3.0. This information may be out of date — please use the official documentation!
Virtual Appliance
- CPU = 16
- Memory = 32 GB
- IOPS = 1,500
- Storage = 2 TB (+ OS drive)
- Domain name servers = 2
NOTES: The above information applies on a per-node basis (cluster information below). Also, be aware that additional resources can improve performance especially CPU.
Log Insight
- Directly connected devices = 750 (assumes large configuration and on a per-node basis) – use a syslog aggregator to support more devices
- Events per second = 7,500 (assumes large configuration and on a per-node basis) – higher is possible for low query environments
- Workers = 5 (6-node cluster) – more are possible (hard limit at 16)
- Syslog message length = 10 KB for text field, 100 KB per HTTP POST request
- Ingestion API HTTP POST request = 16 KB for text field, 100 KB per HTTP POST request
- vCenter Operations Manager integrations = 1 – for alerts it is a many (LI) : 1 (vC Ops), for launch in context it is 1 (LI) : 1 (vC Ops)
Log Insight Agent
More Information
Looking for other sizing information?
Option |
||||||
---|---|---|---|---|---|---|
UPDATE: Configuration maximums have been added to the Log Insight documentation starting with 3.0. This information may be out of date — please use the official documentation!
© 2014 – 2021, Steve Flanders. All rights reserved.
Is the directly connected devices and events per second per worker?
Yes! I have updated the post, thanks.