In reading this post on building a small NetWitness deployment for testing and experimention
I couldn't see any reference to how many virtual machines, what services to install on those VMs and what the specs of those VMs should be. (perhaps it's there, I just can't find it.)
The system I'm using has about 1TB of disk space and 64GB of RAM.
For the Node Zero (Admin Server) you should plan like 40GB Ram, ESA about 8 - 12 and then for a Packet Hybrid or Endpoint Log Hybrid you could allocate 8 GB RAM each.
View solution in original post
Thanks, that seems to have worked pretty well.