Hello all. I'm trying to stand up osquery on-prem. How many servers would I need for about 30,000 endpoints? I understand that I can use Scale Sets in Azure but am trying to set up a test environment with a budget of $0. Any advice would be appreciated.
Thanks for your quick response. Can you estimate the number of servers I may need? I will check out that link.
03/20/2020, 7:10 PM
4-6 perhaps? Depends on so many factors.
03/24/2020, 12:07 AM
@zwass What are some of those factors?
03/24/2020, 12:11 AM
Intervals set for logging, config retrieval, and distributed query checkins will play a large role. Also how many distributed queries you actually run, how many labels you create, the volume of logs being pushed from scheduled queries.