---
icon: material/calculator-variant-outline
title: "Node Counting"
---

CPU/memory per node, and how to count nodes across Retriever-only, MCP-only, analytics hosts, Lambda, and partial-rollout setups.

??? tenx-nodecounting "What are the CPU and memory requirements per node"

    **You control both.** The 10x Engine runs on the JVM (HotSpot or GraalVM), so resource allocation is explicit:

    - **Memory:** Set by the container memory limit. The heap is sized as a share of that limit and will not exceed it. 512 MB is a reasonable default for most workloads.
    - **CPU:** Set via [`threadPoolSize`](https://doc.log10x.com/run/transform/parallelize/#paralleleventthreadpoolsize){target="_blank"}, a fixed thread count (e.g., `2`) or a fraction of available cores (e.g., `0.25` = 25%). One or two dedicated threads handle most production volumes.

    A single node with 512 MB heap and 2 threads handles **100+ GB/day** of log throughput. [Backpressure](https://doc.log10x.com/run/input/stream/#backpressure){target="_blank"} throttles input gracefully if the pipeline approaches its resource limit, so the host stays stable under load.

    Both values map directly to standard Kubernetes resource specs in your DaemonSet manifest.

??? tenx-nodecounting "What if I only use Retriever (no Edge)"

    Count the **collectors shipping logs to S3**. Those are your billing units. See [Retriever](https://log10x.com/retriever){target="_blank"} for details.

??? tenx-nodecounting "What if I only use the MCP SIEM-polling tool (no DaemonSet)"

    The [MCP server](https://github.com/log-10x/log10x-mcp){target="_blank"}'s SIEM-sample tool offers on-demand log analyzer polling without a DaemonSet. Each concurrent 10x Engine instance launched by the tool counts as one node.

??? tenx-nodecounting "Do analytics servers (Splunk, Elasticsearch, Datadog) count as nodes"

    **No.** Only hosts running a 10x collector count. Your analytics infrastructure, including Splunk indexers, Elasticsearch data nodes, and Datadog Agent hosts, are not billing units.

    **Example:** 200 EKS worker nodes running Filebeat DaemonSets + 30 Elasticsearch data nodes + 3 Splunk indexers = **200 nodes**. Only the worker nodes running log collection count.

??? tenx-nodecounting "Do Lambda functions count as nodes"

    **No.** Lambda invocations are not billing units. The DaemonSet Reporter and the Receiver sidecar both assume a long-lived host with a forwarder and don't apply to ephemeral functions.

    For serverless workloads, use the [MCP server](https://github.com/log-10x/log10x-mcp){target="_blank"}'s SIEM-sample tool (agentless log analyzer polling) and [Retriever](https://doc.log10x.com/apps/retriever/) (offload to your S3 bucket + on-demand fetch). Pricing is based on concurrent 10x Engine instances and Retriever pods in your cluster, not the number of Lambda functions.

??? tenx-nodecounting "Do Fargate, Cloud Run, or serverless containers count"

    **Serverless containers count; serverless functions do not.** Fargate (ECS and EKS), Cloud Run, and Azure Container Apps convert at **10 average concurrent tasks = 1 node**, declared from your cloud console. GKE Autopilot worker nodes count like any Kubernetes node. AWS Lambda and other FaaS stay free, as above.

    **Example:** 300 average concurrent Fargate tasks = **30 nodes**.

??? tenx-nodecounting "What if I deploy only to a subset of nodes"

    Count only the nodes running the 10x DaemonSet. If you use `nodeSelector` or `nodeAffinity` to deploy on 50 of your 200 worker nodes, your count is **50**.

??? tenx-nodecounting "What if I use both the Reporter/Receiver and Retriever"

    Count your **Reporter/Receiver collectors only**. Retriever pods don't add to node count.

    If you run the Reporter (DaemonSet) or Receiver (sidecar) on 200 nodes and also use Retriever, you pay for **200 nodes**. Retriever and the MCP server are included at no extra charge.
