If you are just getting started with Humio, we recommend running Humio as a Docker container since Docker contains the external dependencies needed, Kafka and Zookeeper. If you plan on running Humio on bare metal, please refer to our Bare Metal Installation Guide.
For information on how to choose hardware, and how to size your Humio installation, see Humio instance sizing.
Hardware requirements depend on - how much data you will be ingesting, and - how many concurrent searches you will be running
Scaling Your Environment
Humio was made to scale, and scales very well within the nodes in a cluster. Running a cluster of three or more Humio nodes provides higher capacity in terms of both ingest and search performance, and also allows high availability by replicating data to more than one node.
If you want to run a clustered node please review Cluster Setup.
Here are a few guidelines to help you determine what hardware you’ll need.
Example Setup Your machine has 64GB of RAM, 8 hyper-threads (4 cores) and 1TB of storage. Your machine can hold 460GB of ingest data compressed in RAM and process 8GB/s. In this case, it means 10 seconds worth of query time will run through 80GB of data. So this machine fits an 80GB/day ingest, with +5 days’ data available for fast querying. You can store 7.2TB of data before your disk is 80% full, corresponding to 90 days at 80GB/day ingest rate.
This example assumes that all data has the same retention settings. But you can configure Humio to automatically delete some events before others, allowing some data to be kept for several years while other data gets deleted after one week, for example.
For more details, refer to our Instance Sizing Reference.
Please refer to the configuration reference page.