Deployment Architecture

Sizing new installation, calculate storage from events

reswob4
Builder

Hi,
we are preparing to deploy splunk and I have a question about sizing. All the documentation I've found so far talk about size of the storage per day in GB and the tools that I have found calculate that storage against existing splunk installs or demo installs. All I have currently is the calculation of events per day our (smallish) network will generate. Is there a way (or an article or link or previous discussion) to translate events per day into storage per day?

The events are mostly from windows servers and firewall logs.

Thanks.

Tags (1)
0 Karma
1 Solution

martin_mueller
SplunkTrust
SplunkTrust

Take the number of events per day and multiply with the average event length to get the anticipated volume per day. Then you can apply the regular rule of thumb that you'll need maybe 50% of the daily volume for daily storage. How much depends on the type of data.

This may sound overly obvious, but since an event could be 20 bytes or 20000 bytes there's no reasonably conversion from events per day to volume per day. Once you have volume per day you can estimate storage per day at least roughly. The best way would still be to do a trial installation on the trial or free license.

View solution in original post

martin_mueller
SplunkTrust
SplunkTrust

Take the number of events per day and multiply with the average event length to get the anticipated volume per day. Then you can apply the regular rule of thumb that you'll need maybe 50% of the daily volume for daily storage. How much depends on the type of data.

This may sound overly obvious, but since an event could be 20 bytes or 20000 bytes there's no reasonably conversion from events per day to volume per day. Once you have volume per day you can estimate storage per day at least roughly. The best way would still be to do a trial installation on the trial or free license.

reswob4
Builder

Thanks. That helps.

0 Karma
Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...