LogRhythm Reference Architecture
Gen5 Reference Architecture
The tables in this section describe LogRhythm appliance platforms and performance specifications for each. You can use this information to determine what kind of systems you will use for installing LogRhythm.
New installations of the Data Indexer are only supported on the Linux platform. The Data Indexer is only supported on Windows in an XM configuration.
SAN storage is supported only in LogRhythm's software only solution and not in LogRhythm appliances. With respect to appliances, SAN storage is supported only for inactive archives.
In the tables that follow, Allocation Unit Size is abbreviated as AUS. Where not otherwise specified, default AUS is expected.
Appliance Reference Architecture
Reference Platform | Performance (MPS) | Hardware | Operating System | Disk/Vol 1 Config | Disk/Vol 2 Config |
---|---|---|---|---|---|
LR-DC3500 Series | Sustained Collection Rate: 10,000 Burst Collection Rate: 25,000 |
| Windows 2019 or 2022 Standard Edition | Physical Disk:
Virtual Disk:
Logical Volume:
| not applicable |
LR-DC3501 Series | Sustained Collection Rate: 10,000 Burst Collection Rate: 25,000 |
| Windows 2019 or 2022 Standard Edition | Physical Disk:
Virtual Disk:
Logical Volume:
| Physical Disk:
Virtual Disk:
Logical Volume:
|
Reference Platform | Performance (MPS) | Hardware | Operating System | Disk/Vol 1 Config | Disk/Vol 2 Config |
---|---|---|---|---|---|
LR-WC3500 Series | Web Console:
|
| Windows 2019 or 2022 Standard Edition | Physical Disk:
Virtual Disk:
Logical Volume:
| Physical Disk:
Virtual Disk:
Logical Volume:
|
LR-WC3501 Series | Web Console:
|
| Windows 2019 or 2022 Standard Edition | Physical Disk:
Virtual Disk:
Logical Volume:
| Physical Disk:
Virtual Disk:
Logical Volume:
|
Reference Platform | Performance (MPS) | Hardware | Operating System | Disk/Vol 1 Config | Disk/Vol 2 Config | Disk/Vol 3 Config |
---|---|---|---|---|---|---|
LR-XM4500 Series | Data Processor:
AI Engine:
Data Indexer:
Platform Manager:
Web Console:
|
| Windows 2019 or 2022 Standard Edition | Physical Disk:
Virtual Disk:
Logical Volume:
| Physical Disk:
Virtual Disk:
Logical Volume:
| Physical Disk:
Virtual Disk:
Logical Volume:
|
LR-XM6500 Series | Data Processor:
AI Engine:
Data Indexer:
Platform Manager:
Web Console:
|
| Windows 2019 or 2022 Standard Edition | Physical Disk:
Virtual Disk:
Logical Volume:
| Physical Disk:
Virtual Disk:
Logical Volume:
| Physical Disk:
Virtual Disk:
Logical Volume:
|
LR-XM8500 Series | Data Processor:
AI Engine:
Data Indexer:
Platform Manager:
Web Console:
|
| Windows 2019 or 2022 Standard Edition | Physical Disk:
Virtual Disk:
Logical Volume:
| Physical Disk:
Virtual Disk:
Logical Volume:
| Physical Disk:
Virtual Disk:
Logical Volume:
|
Reference Platform | Performance (MPS) | Hardware | Operating System | Disk/Vol 1 Config | Disk/Vol 2 Config | Disk/Vol 3 Config | Disk/Vol 4 Config |
---|---|---|---|---|---|---|---|
LR-PM5500 Series | Platform Manager:
AI Engine:
Web Console:
|
| Windows 2019 or 2022 Standard Edition | Physical Disk:
Virtual Disk:
Logical Volume:
| Physical Disk:
Virtual Disk:
Logical Volume:
| Physical Disk:
Virtual Disk:
Logical Volume:
| not applicable |
LR-PM7500 Series | Platform Manager:
AI Engine:
Web Console:
|
| Windows 2019 or 2022 Standard Edition | Physical Disk:
Virtual Disk:
Logical Volume:
| Physical Disk:
Virtual Disk:
Logical Volume:
| Physical Disk:
Virtual Disk:
Logical Volume:
| Physical Disk:
Virtual Disk:
Logical Volume:
|
Reference Platform | Performance (MPS) | Hardware | Operating System | Disk/Vol 1 Config | Disk/Vol 2 Config | Disk/Vol 3 Config |
---|---|---|---|---|---|---|
LR-DP5500 Series | Data Processor:
|
| Windows 2019 or 2022 Standard Edition | Physical Disk:
Virtual Disk:
Logical Volume:
| Physical Disk:
Virtual Disk:
Logical Volume:
| Physical Disk:
Virtual Disk:
Logical Volume:
|
LR-DP7500 Series | Data Processor:
|
| Windows 2019 or 2022 Standard Edition | Physical Disk:
Virtual Disk:
Logical Volume:
| Physical Disk:
Virtual Disk:
Logical Volume:
| Physical Disk:
Virtual Disk:
Logical Volume:
|
Reference Platform | Performance (MPS) | Hardware | Operating System | Disk/Vol 1 Config | Disk/Vol 2 Config |
---|---|---|---|---|---|
LR-DX3500 Series | Data Indexer:
|
| Rocky 9.0+ Red Hat Enterprise Linux 9.0+ CentOS 7.4+ Red Hat Enterprise Linux 7.4+ | Physical Disk:
Virtual Disk:
Logical Volume:
Volume Size: / 200 GB | Physical Disk:
Virtual Disk:
Logical Volume:
Volume Size: /usr/local/logrhythm 8800 GB |
LR-DX5500 Series | Data Indexer:
|
| Rocky 9.0+ Red Hat Enterprise Linux 9.0+ CentOS 7.4+ Red Hat Enterprise Linux 7.4+ | Physical Disk:
Virtual Disk:
Logical Volume:
Volume Size: / 200 GB | Physical Disk:
Virtual Disk:
Logical Volume:
Volume Size: /usr/local/logrhythm 16000 GB |
LR-DX7500 Series | Data Indexer:
|
| Rocky 9.0+ Red Hat Enterprise Linux 9.0+ CentOS 7.4+ Red Hat Enterprise Linux 7.4+ | Physical Disk:
Virtual Disk:
Logical Volume:
Logical Volume:
Volume Size: / 200 GB | Physical Disk:
Virtual Disk:
Logical Volume:
Volume Size: /usr/local/logrhythm 39 TB |
LR-DXW5120 | Data Indexer:
|
| Rocky 9.0+ Red Hat Enterprise Linux 9.0+ CentOS 7.4+ Red Hat Enterprise Linux 7.4+ | Physical Disk:
Virtual Disk:
Logical Volume:
Volume Size: / 200 GB | Physical Disk:
Virtual Disk:
Logical Volume:
Volume Size: /usr/local/logrhythm 108TB |
Reference Platform | Performance (MPS) | Hardware | Operating System | Disk/Vol 1 Config | Disk/Vol 2 Config |
---|---|---|---|---|---|
LR-AIE7500 Series | AI Engine:
|
| Windows 2019 or 2022 Standard Edition | Physical Disk:
Virtual Disk:
Logical Volume:
| Physical Disk:
Virtual Disk:
Logical Volume:
|
Reference Platform | Performance (MPS) | Hardware | Operating System | Disk/Vol 1 Config | Disk/Vol 2 Config |
---|---|---|---|---|---|
LR-NM3500 | 1 Gb Network Monitor |
| CentOS 7.6 or Red Hat Enterprise Linux 7 | Physical Disk:
Virtual Disk:
Logical Volume:
| Physical Disk:
Virtual Disk:
Logical Volume:
|
LR-NM5500 | 5 Gb Network Monitor |
| CentOS 7.6 or Red Hat Enterprise Linux 7 | Physical Disk:
Virtual Disk:
Logical Volume:
| Physical Disk:
Virtual Disk:
Logical Volume:
|
Reference Platform | Performance (MPS) | Hardware | Operating System | Disk/Vol 1 Config | Disk/Vol 2 Config |
---|---|---|---|---|---|
SANM5026 (direct attached storage for NM) | 12 Gbps SAS | PERC H840 RAID Controller with 8 GB Cache | not applicable | Physical Disk:
Virtual Disk:
Logical Volume:
| not applicable |
SAAR5120 (direct attached storage for archives) | 12 Gbps SAS | PERC H840 RAID Controller with 8 GB Cache | not applicable | Physical Disk:
Virtual Disk:
Logical Volume:
| not applicable |
SAPM5020 (direct attached storage for PM) | 12 Gbps SAS | PERC H840 RAID Controller with 8 GB Cache | not applicable | Physical Disk:
Virtual Disk:
Logical Volume:
| Physical Disk:
Virtual Disk:
Logical Volume:
|
The virtual platforms described in the table below are for labs/sandbox use only. They are not intended for production use.
Reference Platform | Performance (MPS) | Hardware | Operating System | Disk/Vol 1 Config | Disk/Vol 2 Config |
---|---|---|---|---|---|
LR-XMVS For labs/sandbox use only | Data Processor:
Data Indexer:
Platform Manager:
|
| Windows 2019 or 2022 Standard Edition | Disk:
Logical Volume:
| Disk:
Logical Volume:
|
LR-PMVS1 For labs/sandbox use only | Platform Manager:
|
| Windows 2019 or 2022 Standard Edition | Disk:
Logical Volume:
| Disk:
Logical Volume:
|
LR-DPVS1 For labs/sandbox use only | Data Processor:
|
| Windows 2019 or 2022 Standard Edition | Disk:
Logical Volume:
| not applicable |
LR-DXVS1 For labs/sandbox use only | Data Indexer:
|
| CentOS 7.6 or Red Hat Enterprise Linux 7 | Disk:
Logical Volume:
| Disk:
Logical Volume:
|
AWS Platform Reference Architecture
AWS EC2 instances should be considered minimums. In some environments, higher performance instances may be required.
Reference Platform | Performance (MPS) | Instance Type | Operating System | Disk/Vol Config 1 | Disk/Vol Config 2 |
---|---|---|---|---|---|
LR-DC3400 | Sustained Collection Rate: 2,000-5,000 Burst Collection Rate: 10,000 Max Remote Windows Log Sources: 500 | AWS: m6a.xlarge vCPU: 4 Memory: 16GB | Windows 2019 or 2022 Standard Edition | Disk Type: gp3 - 250 GB Volume Size: C Drive: 250 GB Description: Operating System | Disk Type: gp3 - 100 GB Volume Size: D Drive: 100 GB Description: State |
Reference Platform | Performance (MPS) | Instance Type | Operating System | Disk/Vol Config 1 | Disk/Vol Config 2 | Disk/Vol Config 3 | Disk/Vol Config 4 |
---|---|---|---|---|---|---|---|
LR-XM4500 Series | Data Processor:
AI Engine:
Data Indexer:
Platform Manager:
Web Console:
| AWS: r6i.4xlarge vCPU: 16 Memory: 128GB | Windows 2019 or 2022 Standard Edition | Disk Type: gp3 - 250 GB Volume Size: C Drive: 250 GB Description: Operating System | Disk Type: gp3 - 800 GB Volume Size: D Drive: 500 GB S Drive: 100 GB L Drive: 150 GB T Drive: 50 GB Description: SQL DB / SQL Logs / State / Temp | Disk Type: gp3 - 1500 GB Volume Size: E Drive: 1500 GB Description: Elasticsearch Data | not applicable |
LR-XM6500 Series | Data Processor:
AI Engine:
Data Indexer:
Platform Manager:
Web Console:
| AWS: m6a.12xlarge vCPU: 48 Memory: 192GB | Windows 2019 or 2022 Standard Edition | Disk Type: gp3 - 250 GB Volume Size: C Drive: 250 GB Description: Operating System | Disk Type: gp3 - 3000 GB Volume Size: D Drive: 2700 GB S Drive: 250 GB T Drive: 50 GB Description: SQL DB / State / Temp | Disk Type: gp3 - 9000 GB Volume Size: E Drive: 9000 GB Description: Elasticsearch Data | Disk Type: gp3 - 200 to 800 GB Volume Size: L Drive: 800 GB (if DR is used) or L Drive: 200 GB (if DR not used) Description: SQL Logs |
LR-XM8500 Series | Data Processor:
AI Engine:
Data Indexer:
Platform Manager:
Web Console:
| AWS: m6a.16xlarge vCPU: 64 Memory: 256GB | Windows 2019 or 2022 Standard Edition | Disk Type: gp3 - 250 GB Volume Size: C Drive: 250 GB Description: Operating System | Disk Type: gp3 - 5000 GB Volume Size: D Drive: 4500 GB S Drive: 450 GB T Drive: 50 GB Description: SQL DB / State / Temp | Disk Type: gp3 - 16000 GB Volume Size: E Drive: 16000 GB Description: Elasticsearch Data | Disk Type: gp3 - 200 to 800 GB Volume Size: L Drive: 800 GB (if DR is used) or L Drive: 200 GB (if DR not used) Description: SQL Logs |
Reference Platform | Performance (MPS) | Instance Type | Operating System | Disk/Vol Config 1 | Disk/Vol Config 2 | Disk/Vol Config 3 |
---|---|---|---|---|---|---|
LR-PMC-Small | Platform Manager only:
Deployments under 5000mps DR/HA not supported | AWS: r6i.xlarge vCPU: 4 Memory: 32GB | Windows 2019 or 2022 Standard Edition | Disk Type: gp3 - 250 GB Volume Size: C Drive: 250 GB Description: Operating System | Disk Type: gp3 - 500 GB Volume Size: D Drive: 350 GB L Drive: 50 GB S Drive: 50 GB T Drive 50 GB Description: SQL DB / SQL Logs / State / Temp | not applicable |
LR-PMC-Large | Platform Manager only:
Deployments between 5,000 to 10,000mps DR/HA not supported | AWS: m5a.2xlarge vCPU: 8 Memory: 32GB | Windows 2019 or 2022 Standard Edition | Disk Type: gp3 - 250 GB Volume Size: C Drive: 250 GB Description: Operating System | Disk Type: gp3 - 1000 GB Volume Size: D Drive: 750 GB L Drive: 100 GB S Drive: 100 GB T Drive 50 GB Description: SQL DB / SQL Logs / State / Temp | not applicable |
LR-PM5500 Series | Platform Manager:
AI Engine:
Web Console:
| AWS: r6i.4xlarge vCPU: 16 Memory: 128GB | Windows 2019 or 2022 Standard Edition | Disk Type: gp3 - 250 GB Volume Size: C Drive: 250 GB Description: Operating System | Disk Type: gp3 - 1900 GB Volume Size: D Drive: 1600 GB S Drive: 250 GB T Drive 50 GB Description: SQL DB / State / Temp | Disk Type: gp3 - 200 to 800 GB Volume Size: L Drive: 800 GB (if DR is used) or L Drive: 200 GB (if DR not used) Description: SQL Logs |
LR-PM7500 Series | Platform Manager:
AI Engine:
Web Console:
| AWS: m6a.8xlarge vCPU: 32 Memory: 128GB | Windows 2019 or 2022 Standard Edition | Disk Type: gp3 - 250 GB Volume Size: C Drive: 250 GB Description: Operating System | Disk Type: gp2 Volume Size: D Drive: 5000 GB S Drive: 500 GB T Drive 50 GB Description: SQL DB / State / Temp | Disk Type: gp3 - 200 to 800 GB Volume Size: L Drive: 800 GB (if DR is used) or L Drive: 200 GB (if DR not used) Description: SQL Logs |
Reference Platform | Performance (MPS) | Instance Type | Operating System | Disk/Vol Config 1 | Disk/Vol Config 2 | Disk/Vol Config 3 |
---|---|---|---|---|---|---|
LR-DPAWC3500 | Data Processor:
AI Engine:
Web Console:
| AWS: r6i.xlarge vCPU: 4 Memory: 32GB | Windows 2019 or 2022 Standard Edition | Disk Type: gp3 - 250 GB Volume Size: C Drive: 250 GB Description: Operating System | Disk Type: gp3 - 150 GB Volume Size: S Drive: 150 GB Description: State | Disk Type: sc1 - adjustable Volume Size: E Drive: 500 GB Description: Inactive Archives (adjustable) |
LR-DPAWC5500 | Data Processor:
AI Engine:
Web Console:
| AWS: r6i.2xlarge vCPU: 8 Memory: 64GB | Windows 2019 or 2022 Standard Edition | Disk Type: gp3 - 250 GB Volume Size: C Drive: 250 GB Description: Operating System | Disk Type: gp3 - 250 GB Volume Size: S Drive: 250 GB Description: State | Disk Type: sc1 - adjustable Volume Size: E Drive: 1000 GB Description: Inactive Archives (adjustable) |
LR-DPAWC7500 | Data Processor:
AI Engine:
Web Console:
| AWS: m6i.4xlarge vCPU: 16 Memory: 64GB | Windows 2019 or 2022 Standard Edition | Disk Type: gp3 - 250 GB Volume Size: C Drive: 250 GB Description: Operating System | Disk Type: gp3 - 500 GB Volume Size: S Drive: 500 GB Description: State | Disk Type: sc1 - adjustable Volume Size: E Drive: 2000 GB Description: Inactive Archives (adjustable) |
Reference Platform | Performance (MPS) | Instance Type | Operating System | Disk/Vol Config 1 | Disk/Vol Config 2 | Disk/Vol Config 3 |
---|---|---|---|---|---|---|
LR-DP5500 Series | Data Processor:
| AWS: c6i.8xlarge vCPU: 32 Memory: 64GB | Windows 2019 or 2022 Standard Edition | Disk Type: gp3 - 250 GB Volume Size: C Drive: 250 GB Description: Operating System | Disk Type: gp3 - 500 GB Volume Size: S Drive: 500 GB Description: Active Archives and LR State | Disk Type: sc1 - adjustable Volume Size: E Drive: 2000 GB Description: Inactive Archives (adjustable) |
LR-DP7500 Series | Data Processor:
| AWS: c6i.12xlarge vCPU: 48 Memory: 96GB | Windows 2019 or 2022 Standard Edition | Disk Type: gp3 - 250 GB Volume Size: C Drive: 250 GB Description: Operating System | Disk Type: gp3 - 1200 GB Volume Size: S Drive: 1200 GB Description: Active Archives and LR State | Disk Type: sc1 - adjustable Volume Size: E Drive: 8000 GB Description: Inactive Archives (adjustable) |
Reference Platform | Performance (MPS) | Instance Type | Operating System | Disk/Vol Config 1 | Disk/Vol Config 2 |
---|---|---|---|---|---|
LR-AIE7500 Series | AI Engine:
| AWS: c6i.12xlarge vCPU: 48 Memory: 96GB | Windows 2019 or 2022 Standard Edition | Disk Type: gp3 - 250 GB Volume Size: C Drive: 250 GB Description: Operating System | Disk Type: gp3 - 500 GB Volume Size: D Drive: 500 GB Description: AIE State/Data |
Reference Platform | Performance (MPS) | Instance Type | Operating System | Disk/Vol Config 1 | Disk/Vol Config 2 | Disk/Vol Config 3 | Disk/Vol Config 4 |
---|---|---|---|---|---|---|---|
LR-DX1500 Series | Data Indexer:
| AWS: r5.2xlarge vCPU: 4 Memory: 64GB | AWS Marketplace Image: Rocky Linux 9 (Official) - x86_64 by Rocky Linux | Disk Type: gp3 - 250 GB Volume Size: / 250 GB Description: Operating System | Disk Type: gp3 - 4400 GB Throughput - default IOPS - default Volume Size: /usr/local/logrhythm 4400 GB Description: Elasticsearch Data | not applicable | not applicable |
LR-DX3500 Series | Data Indexer:
| AWS: m6i.4xlarge vCPU: 16 Memory: 64GB | AWS Marketplace Image: Rocky Linux 9 (Official) - x86_64 by Rocky Linux | Disk Type: gp3 - 250 GB Volume Size: / 250 GB Description: Operating System | Disk Type: gp3 - 8800 GB Throughput - default IOPS - default Volume Size: /usr/local/logrhythm 8800 GB Description: Elasticsearch Data | not applicable | not applicable |
LR-DX5500 Series | Data Indexer:
| AWS: m6i.8xlarge vCPU: 32 Memory: 128GB | AWS Marketplace Image: Rocky Linux 9 (Official) - x86_64 by Rocky Linux | Disk Type: gp3 - 250 GB Volume Size: / 250 GB Description: Operating System | Disk Type: gp3 - 16000 GB Throughput - 300MB/s IOPS - 5000 Volume Size: /usr/local/logrhythm 16000 GB Description: Elasticsearch Data | not applicable | not applicable |
LR-DX7500 Series | Data Indexer:
| AWS: m6i.16xlarge vCPU: 64 Memory: 256GB | AWS Marketplace Image: Rocky Linux 9 (Official) - x86_64 by Rocky Linux | Disk Type: gp3 - 250 GB Volume Size: / 250 GB Description: Operating System | Disk Type: gp3 - 16000 GB Throughput - 300MB/s IOPS - 5000 Volume Size: LVM - /usr/local/logrhythm 16000 GB Description: Elasticsearch Data | Disk Type: gp3 - 16000 GB Throughput - 300MB/s IOPS - 5000 Volume Size: LVM - /usr/local/logrhythm 16000 GB Description: Elasticsearch Data | not applicable |
LR-DXW5120 Series | Data Indexer:
| AWS: r5a.4xlarge vCPU: 16 Memory: 128GB | AWS Marketplace Image: Rocky Linux 9 (Official) - x86_64 by Rocky Linux | Disk Type: gp3 - 250 GB Volume Size: / 250 GB Description: Operating System | Disk Type: st1 - 16000 GB Volume Size: LVM - /usr/local/logrhythm 16000 GB Description: Elasticsearch Data | Disk Type: st1 - 16000 GB Volume Size: LVM - /usr/local/logrhythm 16000 GB Description: Elasticsearch Data | Additional disks based on TTL required |
Google Cloud Platform Reference Architecture
Google Cloud instance sizes should be considered minimums. In some environments, higher performance instances may be required.
Reference Platform | Performance (MPS) | Instance Type | Operating System | Disk/Vol Config 1 | Disk/Vol Config 2 |
---|---|---|---|---|---|
LR-DC3400 | Sustained Collection Rate: 2,000-5,000 Burst Collection Rate: 10,000 Max Remote Windows Log Sources: 500 | n2-standard-4 vCPU: 4 Memory: 16GB | Windows 2019 or 2022 Standard Edition | Disk Type: pd-standard - 250 GB Volume Size: C Drive: 200 GB Description: Operating System | Disk Type: pd-standard - 100 GB Volume Size: D Drive: 100 GB Description: LR State |
Reference Platform | Performance (MPS) | Instance Type | Operating System | Disk/Vol Config 1 | Disk/Vol Config 2 | Disk/Vol Config 3 | Disk/Vol Config 4 |
---|---|---|---|---|---|---|---|
LR-XM4500 Series | Data Processor:
AI Engine:
Data Indexer:
Platform Manager:
Web Console:
| n2-highmem-16 vCPU: 16 Memory: 128GB | Windows 2019 or 2022 Standard Edition | Disk Type: pd-standard - 250GB Volume Size: C Drive: 250 GB Description: Operating System | Disk Type: pd-balanced - 800 GB Volume Size: D Drive: 500 GB L Drive: 100 GB S Drive: 150 GB T Drive: 50 GB Description: SQL Databases/ES Data/SQL Logs/LR State/SQL Temp | Disk Type: pd-balanced - 1500 GB Volume Size: E Drive: 1500 GB Description: Elasticsearch Data | not applicable |
LR-XM6500 Series | Data Processor:
AI Engine:
Data Indexer:
Platform Manager:
Web Console:
| n2-custom vCPU: 40 Memory: 196GB | Windows 2019 or 2022 Standard Edition | Disk Type: pd-standard - 250GB Volume Size: C Drive: 250 GB Description: Operating System | Disk Type: pd-balanced - 3000 GB Volume Size: D Drive: 2750 GB S Drive: 250 GB T Drive: 50 GB Description: SQL Databases/State/SQL Temp | Disk Type: pd-balanced - 9000 GB Volume Size: E Drive: 9000 GB Description: ElasticSearch Data | Disk Type: pd-ballanced - 200 to 800 GB Volume Size: L Drive: 800 GB (if DR is used) or L Drive: 200 GB (if DR not used) Description: SQL Logs |
LR-XM8500 Series | Data Processor:
AI Engine:
Data Indexer:
Platform Manager:
Web Console:
| n2-custom vCPU: 48 Memory: 256GB | Windows 2019 or 2022 Standard Edition | Disk Type: pd-standard - 250GB Volume Size: C Drive: 250 GB Description: Operating System | Disk Type: pd-balanced - 5000 GB Volume Size: D Drive: 4500 GB S Drive: 450 GB T Drive: 50 GB Description: SQL Databases/SQL Logs/SQL Temp | Disk Type: pd-balanced - 16000 GB Volume Size: E Drive: 16000 GB Description: ElasticSearch Data | Disk Type: pd-ballanced - 200 to 800 GB Volume Size: L Drive: 800 GB (if DR is used) or L Drive: 200 GB (if DR not used) Description: SQL Logs |
Reference Platform | Performance (MPS) | Instance Type | Operating System | Disk/Vol Config 1 | Disk/Vol Config 2 | Disk/Vol Config 3 |
---|---|---|---|---|---|---|
LR-PMC-Small | Platform Manager only:
Deployments under 5000mps DR/HA not supported | n2-highmem-4 vCPU: 4 Memory: 32GB | Windows 2019 or 2022 Standard Edition | Disk Type: pd-standard - 250GB Volume Size: C Drive: 250 GB Description: Operating System | Disk Type: pd-balanced - 500 GB Volume Size: D Drive: 350 GB L Drive: 50 GB S Drive: 50 GB T Drive 50 GB Description: SQL DB / SQL Logs / State / Temp | not applicable |
LR-PMC-Large | Platform Manager only:
Deployments between 5,000 to 10,000mps DR/HA not supported | n2-standard-8 vCPU: 8 Memory: 32GB | Windows 2019 or 2022 Standard Edition | Disk Type: pd-standard - 250GB Volume Size: C Drive: 250 GB Description: Operating System | Disk Type: pd-balanced - 1000 GB Volume Size: D Drive: 750 GB L Drive: 100 GB S Drive: 100 GB T Drive 50 GB Description: SQL DB / SQL Logs / State / Temp | not applicable |
LR-PM5500 Series | Platform Manager:
AI Engine:
Web Console:
| n2-custom vCPU: 20 Memory: 128GB | Windows 2019 or 2022 Standard Edition | Disk Type: pd-standard - 250GB Volume Size: C Drive: 250 GB Description: Operating System | Disk Type: pd-balanced - 2000 GB Volume Size: D Drive: 1600 GB S Drive: 300 GB T Drive: 100 GB Description: SQL DB / State / Temp | Disk Type: pd-balanced - 200 to 800 GB Volume Size: L Drive: 800 GB (if DR is used) or L Drive: 400 GB (if DR not used) Description: SQL Logs |
LR-PM7500 Series | Platform Manager:
AI Engine:
Web Console:
| n2-custom vCPU: 48 Memory: 196GB | Windows 2019 or 2022 Standard Edition | Disk Type: pd-standard - 250GB Volume Size: C Drive: 250 GB Description: Operating System | Disk Type: pd-balanced - 8200 GB Volume Size: D Drive: 7500 GB S Drive: 500 GB T Drive: 200 GB Description: SQL DB / State / Temp | Disk Type: pd-balanced - 200 to 800 GB Volume Size: L Drive: 2000 GB (if DR is used) or L Drive: 500 GB (if DR not used) Description: SQL Logs |
Reference Platform | Performance (MPS) | Instance Type | Operating System | Disk/Vol Config 1 | Disk/Vol Config 2 | Disk/Vol Config 3 |
---|---|---|---|---|---|---|
LR-DPAWC3500 | Data Processor:
AI Engine:
Web Console:
| n2-highmem-4 vCPU: 4 Memory: 32GB | Windows 2019 or 2022 Standard Edition | Disk Type: pd-standard - 250GB Volume Size: C Drive: 250 GB Description: Operating System | Disk Type: pd-balanced - 150 GB Volume Size: S Drive: 150 GB Description: State | Disk Type: pd-standard - adjustable Volume Size: E Drive: 500 GB Description: Inactive Archives (adjustable) |
LR-DPAWC5500 | Data Processor:
AI Engine:
Web Console:
| n2-highmem-8 vCPU: 8 Memory: 64GB | Windows 2019 or 2022 Standard Edition | Disk Type: pd-standard - 250GB Volume Size: C Drive: 250 GB Description: Operating System | Disk Type: pd-balanced - 250 GB Volume Size: S Drive: 250 GB Description: State | Disk Type: pd-standard - adjustable Volume Size: E Drive: 1000 GB Description: Inactive Archives (adjustable) |
LR-DPAWC7500 | Data Processor:
AI Engine:
Web Console:
| n2-standard-16 vCPU: 16 Memory: 64GB | Windows 2019 or 2022 Standard Edition | Disk Type: pd-standard - 250GB Volume Size: C Drive: 250 GB Description: Operating System | Disk Type: pd-balanced - 500 GB Volume Size: S Drive: 500 GB Description: State | Disk Type: pd-standard - adjustable Volume Size: E Drive: 2000 GB Description: Inactive Archives (adjustable) |
Reference Platform | Performance (MPS) | Instance Type | Operating System | Disk/Vol Config 1 | Disk/Vol Config 2 | Disk/Vol Config 3 |
---|---|---|---|---|---|---|
LR-DP5500 Series | Data Processor:
| n2-custom vCPU: 24 Memory: 64GB | Windows 2019 or 2022 Standard Edition | Disk Type: pd-standard - 250GB Volume Size: C Drive: 250 GB Description: Operating System | Disk Type: pd-balanced - 500 GB Volume Size: S Drive: 500 GB Description: Active Archives/LR State | Disk Type: pd-standard - adjustable Volume Size: E Drive: 2000 GB Description: Inactive Archives (adjustable) |
LR-DP7500 Series | Data Processor:
| n2-custom vCPU: 48 Memory: 128GB | Windows 2019 or 2022 Standard Edition | Disk Type: pd-standard - 250GB Volume Size: C Drive: 250 GB Description: Operating System | Disk Type: pd-balanced - 1000 GB Volume Size: S Drive: 1000 GB Description: Active Archives/LR State | Disk Type: pd-standard - adjustable Volume Size: E Drive: 8000 GB Description: Inactive Archives (adjustable) |
Reference Platform | Performance (MPS) | Instance Type | Operating System | Disk/Vol Config 1 | Disk/Vol Config 2 |
---|---|---|---|---|---|
LR-AIE7500 Series | AI Engine: Max MPS: 75,000 Max Number of Rules: 2,000 | n2-custom vCPU: 48 Memory: 128GB | Windows 2019 or 2022 Standard Edition | Disk Type: pd-standard - 250GB Volume Size: C Drive: 250 GB Description: Operating System | Disk Type: pd-balanced - 500 GB Volume Size: S Drive: 500 GB Description: AIE State/Data |
GCP only allows for a max volume of 64TB per instance. You will need to add multiple instances to meet the DXW5120 hardware appliance.
Reference Platform | Performance (MPS) | Instance Type | Operating System | Disk/Vol Config 1 | Disk/Vol Config 2 | Disk/Vol Config 3 |
---|---|---|---|---|---|---|
LR-DX1500 Series | Data Indexer:
| n2-highmem-8 vCPU: 8 Memory: 64GB | Image Family: rocky-linux-9-optimized-gcp | Disk Type: pd-standard - 250 GB Volume Size: / 250 GB Description: Operating System | Disk Type: pd-balanced - 4400 GB Volume Size: /usr/local/logrhythm 4400 GB Description: Elasticsearch Data | not applicable |
LR-DX3500 Series | Data Indexer:
| n2-standard-16 vCPU: 16 Memory: 64GB | Image Family: rocky-linux-9-optimized-gcp | Disk Type: pd-standard - 250 GB Volume Size: / 250 GB Description: Operating System | Disk Type: pd-balanced - 8800 GB Volume Size: /usr/local/logrhythm 8800 GB Description: Elasticsearch Data | not applicable |
LR-DX5500 Series | Data Indexer:
| n2-standard-32 vCPU: 32 Memory:128GB | Image Family: rocky-linux-9-optimized-gcp | Disk Type: pd-standard - 250 GB Volume Size: / 250 GB Description: Operating System | Disk Type: pd-balanced - 16000 GB Volume Size: /usr/local/logrhythm 16000 GB Description: Elasticsearch Data | not applicable |
LR-DX7500 Series | Data Indexer:
| n2-standard-64 vCPU: 64 Memory: 256GB | Image Family: rocky-linux-9-optimized-gcp | Disk Type: pd-standard - 250 GB Volume Size: / 250 GB Description: Operating System | Disk Type: pd-balanced - 32000 GB Volume Size: /usr/local/logrhythm 32000 GB Description: Elasticsearch Data | not applicable |
LR-DXW5120 | Data Indexer:
| n2-highmem-16 vCPU: 16 Memory: 128GB | Image Family: rocky-linux-9-optimized-gcp | Disk Type: pd-standard - 250 GB Volume Size: / 250 GB Description: Operating System | *Disk Type: pd-standard - 64000 GB Volume Size: /usr/local/logrhythm 64000 GB Description: Elasticsearch Data | Additional disks based on TTL required |
Azure Platform Reference Architecture
Microsoft Azure instance sizes should be considered minimums. In some environments, higher performance instances may be required.
For all platforms, use only read host cache on data disks, such as SQL data or Elasticsearch data.
Reference Platform | Performance (MPS) | Instance Type | Operating System | Disk/Vol Config 1 | Disk/Vol Config 2 |
---|---|---|---|---|---|
LR-DC3400 | Sustained Collection Rate: 2,000-5,000 Burst Collection Rate: 10,000 Max Remote Windows Log Sources: 500 | D4 v5 vCPU: 4 Memory: 16GB | Windows 2019 or 2022 Standard Edition | Disk Type: S15 - 256 GB Volume Size: C Drive: 256 GB Description: Operating System | Disk Type: S10 - 128 GB Volume Size: D Drive: 128 GB Description: State |
Reference Platform | Performance (MPS) | Instance Type | Operating System | Disk/Vol Config 1 | Disk/Vol Config 2 | Disk/Vol Config 3 | Disk/Vol Config 4 |
---|---|---|---|---|---|---|---|
LR-XM4500 Series | Data Processor:
AI Engine:
Data Indexer:
Platform Manager:
Web Console:
| E16 v5 vCPU: 16 Memory: 128GB | Windows 2019 or 2022 Standard Edition | Disk Type: S15 - 256 GB Volume Size: C Drive: 256 GB Description: Operating System | Disk Type: E30 - 1024 GB Volume Size: D Drive: 775 GB L Drive: 100 GB S Drive: 100 GB T Drive: 50 GB Description: SQL Data/SQL Logs/LR State/SQL Temp | Disk Type: E40 - 2048 GB Volume Size: E Drive: 2048 GB Description: Elasticsearch Data | not applicable |
LR-XM6500 Series | Data Processor:
AI Engine:
Data Indexer:
Platform Manager:
Web Console:
| D48 v5 vCPU: 48 Memory: 192GB | Windows 2019 or 2022 Standard Edition | Disk Type: S15 - 256GB Volume Size: C Drive: 256 GB Description: Operating System | Disk Type: E40 - 2048 GB Volume Size: D Drive: 1748 GB S Drive: 250 GB T Drive: 50 GB Description: SQL Data/SQL Logs/LR State/SQL Temp | Disk Type: E60 - 8192 GB Volume Size: E Drive: 8192 GB Description: Elasticsearch Data | Disk Type: P15 or P20 - 256 or 512 GB Volume Size: L Drive: 256 GB (if DR is used) or L Drive: 512 GB (if DR not used) Description: SQL Logs |
LR-XM8500 Series | Data Processor:
AI Engine:
Data Indexer:
Platform Manager:
Web Console:
| D64 v5 vCPU: 64 Memory: 256GB | Windows 2019 or 2022 Standard Edition | Disk Type: S15 - 256GB Volume Size: C Drive: 256 GB Description: Operating System | Disk Type: E50 - 4096 GB Volume Size: D Drive: 3645 GB L Drive: 150 GB S Drive: 250 GB T Drive: 50 GB Description: SQL Data/SQL Logs/LR State/SQL Temp | Disk Type: E70 - 16384 Volume Size: E Drive: 16384 GB Description: Elasticsearch Data | Disk Type: P15 or P20 - 256 or 512 GB Volume Size: L Drive: 512 GB (if DR is used) or L Drive: 256 GB (if DR not used) Description: SQL Logs |
Reference Platform | Performance (MPS) | Instance Type | Operating System | Disk/Vol Config 1 | Disk/Vol Config 2 | Disk/Vol Config 3 |
---|---|---|---|---|---|---|
LR-PMC-Small | Platform Manager only:
Deployments under 5000mps DR/HA not supported | E4 v5 vCPU: 4 Memory: 32GB | Windows 2019 or 2022 Standard Edition | Disk Type: S15 - 256GB Volume Size: C Drive: 256 GB Description: Operating System | Disk Type: P20 - 512 GB Volume Size: D Drive: 350 GB L Drive: 50 GB S Drive: 50 GB T Drive: 50 GB Description: SQL Data / SQL Logs / LR State / SQL Temp | not applicable |
LR-PMC-Large | Platform Manager only:
Deployments between 5,000 to 10,000mps DR/HA not supported | D8 v5 vCPU: 8 Memory: 32GB | Windows 2019 or 2022 Standard Edition | Disk Type: S15 - 256GB Volume Size: C Drive: 256 GB Description: Operating System | Disk Type: P30 - 1024 GB Volume Size: D Drive: 750 GB L Drive: 100 GB S Drive: 100 GB T Drive: 50 GB Description: SQL Data / SQL Logs / LR State / SQL Temp | not applicable |
LR-PM5500 Series | Platform Manager:
AI Engine:
Web Console:
| E16 v5 vCPU: 16 Memory: 128GB | Windows 2019 or 2022 Standard Edition | Disk Type: S15 - 256GB Volume Size: C Drive: 256 GB Description: Operating System | Disk Type: P40 - 2048 GB Volume Size: D Drive: 1848 GB S Drive: 100 GB T Drive: 100 GB Description: SQL Data / LR State / SQL Temp | Disk Type: P15 or P20 - 256 or 512 GB Volume Size: L Drive: 512 GB (if DR is used) or L Drive: 256 GB (if DR not used) Description: SQL Logs |
LR-PM7500 Series | Platform Manager:
AI Engine:
Web Console:
| D32 v5 vCPU: 32 Memory: 128GB | Windows 2019 or 2022 Standard Edition | Disk Type: S15 - 256GB Volume Size: C Drive: 256 GB Description: Operating System | Disk Type: P50 - 4096 GB Volume Size: D Drive: 3896 GB S Drive: 100 GB T Drive: 100 GB Description: SQL Data / LR State / SQL Temp | Disk Type: P20 or P30 - 512 or 1048 GB Volume Size: L Drive: 1048 GB (if DR is used) or L Drive: 512 GB (if DR not used) Description: SQL Logs |
Reference Platform | Performance (MPS) | Instance Type | Operating System | Disk/Vol Config 1 | Disk/Vol Config 2 | Disk/Vol Config 3 |
---|---|---|---|---|---|---|
LR-DPAWC3500 | Data Processor:
AI Engine:
Web Console:
| E4 v5 vCPU: 4 Memory: 32GB | Windows 2019 or 2022 Standard Edition | Disk Type: S15 - 256GB Volume Size: C Drive: 256 GB Description: Operating System | Disk Type: P10 - 128 GB Volume Size: S Drive: 128 GB Description: State | Disk Type & Volume Size1 Description: Inactive Archives |
LR-DPAWC5500 | Data Processor:
AI Engine:
Web Console:
| E8 v5 vCPU: 4 Memory: 64GB | Windows 2019 or 2022 Standard Edition | Disk Type: S15 - 256GB Volume Size: C Drive: 256 GB Description: Operating System | Disk Type: P15 - 256 GB Volume Size: S Drive: 256 GB Description: State | Disk Type & Volume Size1 Description: Inactive Archives |
LR-DPAWC7500 | Data Processor:
AI Engine:
Web Console:
| D16 v5 vCPU: 16 Memory: 64GB | Windows 2019 or 2022 Standard Edition | Disk Type: S15 - 256GB Volume Size: C Drive: 256 GB Description: Operating System | Disk Type: P20 - 512 GB Volume Size: S Drive: 512 GB Description: State | Disk Type & Volume Size1 Description: Inactive Archives |
Reference Platform | Performance (MPS) | Instance Type | Operating System | Disk/Vol Config 1 | Disk/Vol Config 2 | Disk/Vol Config 3 |
---|---|---|---|---|---|---|
LR-DP5500 Series | Max Processing Rate: 15,000 | F32s v2 vCPU: 32 Memory: 64GB | Windows 2019 or 2022 Standard Edition | Disk Type: S15 - 256GB Volume Size: C Drive: 256 GB Description: Operating System | Disk Type: P20 - 512 GB Volume Size: S Drive: 512 GB Description: State | Disk Type & Volume Size1 Description: Inactive Archives |
LR-DP7500 Series | Max Processing Rate: 40,000 | F64s v2 vCPU: 64 Memory: 128GB | Windows 2019 or 2022 Standard Edition | Disk Type: S15 - 256GB Volume Size: C Drive: 256 GB Description: Operating System | Disk Type: P30 - 1024 Volume Size: S Drive: 1024 GB Description: State | Disk Type & Volume Size1 Description: Inactive Archives |
Reference Platform | Performance (MPS) | Instance Type | Operating System | Disk/Vol Config 1 | Disk/Vol Config 2 |
---|---|---|---|---|---|
LR-AIE7500 Series | Max MPS: 75,000 Max Number of Rules: 2,000 | F64s v2 vCPU: 64 Memory: 128GB | Windows 2019 or 2022 Standard Edition | Disk Type: S15 - 256GB Volume Size: C Drive: 256 GB Description: Operating System | Disk Type: P20 - 512 GB Volume Size: S Drive: 512 GB Description: State |
The DX warm storage values do not match to appliances and can be adjusted based on customer need, with a limit of 120TB total on DXW5120.
Reference Platform | Performance (MPS) | Instance Type | Operating System | Disk/Vol Config 1 | Disk/Vol Config 2 | Disk/Vol Config 3 | Disk/Vol Config 4 | Disk/Vol Config 5 |
---|---|---|---|---|---|---|---|---|
LR-DX1500 Series | Data Indexer:
| E8 v5 vCPU: 8 Memory: 64GB | The Rocky Enterprise Software Foundation Inc: Rocky Linux 9 | Disk Type : S15 - 256GB Volume Size: / 256 GB Description: Operating System | Disk Type: E50 - 4096GB Volume Size: /usr/local/logrhythm 4096 GB Description: Elasticsearch Data | not applicable | not applicable | not applicable |
LR-DX3500 Series | Data Indexer:
| D16 v5 vCPU: 16 Memory: 64GB | The Rocky Enterprise Software Foundation Inc: Rocky Linux 9 | Disk Type : S15 - 256GB Volume Size: / 256 GB Description: Operating System | Disk Type: E60 - 8192GB Volume Size: /usr/local/logrhythm 8192 GB Description: Elasticsearch Data | not applicable | not applicable | not applicable |
LR-DX5500 Series | Data Indexer:
| D32 v5 vCPU: 32 Memory: 128GB | The Rocky Enterprise Software Foundation Inc: Rocky Linux 9 | Disk Type : S15 Volume Size: / 256 GB Description: Operating System | Disk Type: E70 - 16384GB Volume Size: /usr/local/logrhythm 16,384 GB Description: Elasticsearch Data | not applicable | not applicable | not applicable |
LR-DX7500 Series | Data Indexer:
| D64 v5 vCPU: 64 Memory: 256GB
| The Rocky Enterprise Software Foundation Inc: Rocky Linux 9 | Disk Type : S15 Volume Size: / 256 GB Description: Operating System | Disk Type: E70 - 16384GB Volume Size: /usr/local/logrhythm Description: Elasticsearch Data | Disk Type: E70 - 16384GB Volume Size: /usr/local/logrhythm Description: Elasticsearch Data | not applicable | not applicable |
LR-DXW5120 Series | Data Indexer:
| E16 v5 vCPU: 16 Memory: 128GB | The Rocky Enterprise Software Foundation Inc: Rocky Linux 9 | Disk Type : S15 Volume Size: / 256 GB Description: Operating System | Disk Type: S80 - 32,767GB Volume Size: /usr/local/logrhythm Description: Elasticsearch Data | Disk Type: S80 - 32,767GB Volume Size: /usr/local/logrhythm Description: Elasticsearch Data | Disk Type: S80 - 32,767GB Volume Size: /usr/local/logrhythm Description: Elasticsearch Data | Additional disks based on TTL required |