Deployment Architecture

Sizing new installation, calculate storage from events

reswob4
Builder

Hi,
we are preparing to deploy splunk and I have a question about sizing. All the documentation I've found so far talk about size of the storage per day in GB and the tools that I have found calculate that storage against existing splunk installs or demo installs. All I have currently is the calculation of events per day our (smallish) network will generate. Is there a way (or an article or link or previous discussion) to translate events per day into storage per day?

The events are mostly from windows servers and firewall logs.

Thanks.

Tags (1)
0 Karma
1 Solution

martin_mueller
SplunkTrust
SplunkTrust

Take the number of events per day and multiply with the average event length to get the anticipated volume per day. Then you can apply the regular rule of thumb that you'll need maybe 50% of the daily volume for daily storage. How much depends on the type of data.

This may sound overly obvious, but since an event could be 20 bytes or 20000 bytes there's no reasonably conversion from events per day to volume per day. Once you have volume per day you can estimate storage per day at least roughly. The best way would still be to do a trial installation on the trial or free license.

View solution in original post

martin_mueller
SplunkTrust
SplunkTrust

Take the number of events per day and multiply with the average event length to get the anticipated volume per day. Then you can apply the regular rule of thumb that you'll need maybe 50% of the daily volume for daily storage. How much depends on the type of data.

This may sound overly obvious, but since an event could be 20 bytes or 20000 bytes there's no reasonably conversion from events per day to volume per day. Once you have volume per day you can estimate storage per day at least roughly. The best way would still be to do a trial installation on the trial or free license.

reswob4
Builder

Thanks. That helps.

0 Karma
Get Updates on the Splunk Community!

Join Us for Splunk University and Get Your Bootcamp Game On!

If you know, you know! Splunk University is the vibe this summer so register today for bootcamps galore ...

.conf24 | Learning Tracks for Security, Observability, Platform, and Developers!

.conf24 is taking place at The Venetian in Las Vegas from June 11 - 14. Continue reading to learn about the ...

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...