Deployment Architecture

Sizing new installation, calculate storage from events

reswob4
Builder

Hi,
we are preparing to deploy splunk and I have a question about sizing. All the documentation I've found so far talk about size of the storage per day in GB and the tools that I have found calculate that storage against existing splunk installs or demo installs. All I have currently is the calculation of events per day our (smallish) network will generate. Is there a way (or an article or link or previous discussion) to translate events per day into storage per day?

The events are mostly from windows servers and firewall logs.

Thanks.

Tags (1)
0 Karma
1 Solution

martin_mueller
SplunkTrust
SplunkTrust

Take the number of events per day and multiply with the average event length to get the anticipated volume per day. Then you can apply the regular rule of thumb that you'll need maybe 50% of the daily volume for daily storage. How much depends on the type of data.

This may sound overly obvious, but since an event could be 20 bytes or 20000 bytes there's no reasonably conversion from events per day to volume per day. Once you have volume per day you can estimate storage per day at least roughly. The best way would still be to do a trial installation on the trial or free license.

View solution in original post

martin_mueller
SplunkTrust
SplunkTrust

Take the number of events per day and multiply with the average event length to get the anticipated volume per day. Then you can apply the regular rule of thumb that you'll need maybe 50% of the daily volume for daily storage. How much depends on the type of data.

This may sound overly obvious, but since an event could be 20 bytes or 20000 bytes there's no reasonably conversion from events per day to volume per day. Once you have volume per day you can estimate storage per day at least roughly. The best way would still be to do a trial installation on the trial or free license.

reswob4
Builder

Thanks. That helps.

0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...