<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Bandwidth usage for 200 GB of data from heavy forwarder to indexers in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Bandwidth-usage-for-200-GB-of-data-from-heavy-forwarder-to/m-p/308848#M58115</link>
    <description>&lt;P&gt;Hello,&lt;BR /&gt;
I understand from some of the links that using UFs as intermediate forwarding layer add metadata at &lt;STRONG&gt;stream level&lt;/STRONG&gt; while using HFs as intermediate layer add metadata at &lt;STRONG&gt;event level&lt;/STRONG&gt;.  &lt;/P&gt;

&lt;P&gt;What is the general increase of daily log transmission size, (say when we are expecting 200 GB of daily data) when passing through this on-premise intermediate layer to Splunk Indexers hosted on an external cloud? &lt;/P&gt;

&lt;P&gt;Please advice. &lt;/P&gt;</description>
    <pubDate>Mon, 16 Oct 2017 23:43:32 GMT</pubDate>
    <dc:creator>pranitprakash</dc:creator>
    <dc:date>2017-10-16T23:43:32Z</dc:date>
    <item>
      <title>Bandwidth usage for 200 GB of data from heavy forwarder to indexers</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Bandwidth-usage-for-200-GB-of-data-from-heavy-forwarder-to/m-p/308848#M58115</link>
      <description>&lt;P&gt;Hello,&lt;BR /&gt;
I understand from some of the links that using UFs as intermediate forwarding layer add metadata at &lt;STRONG&gt;stream level&lt;/STRONG&gt; while using HFs as intermediate layer add metadata at &lt;STRONG&gt;event level&lt;/STRONG&gt;.  &lt;/P&gt;

&lt;P&gt;What is the general increase of daily log transmission size, (say when we are expecting 200 GB of daily data) when passing through this on-premise intermediate layer to Splunk Indexers hosted on an external cloud? &lt;/P&gt;

&lt;P&gt;Please advice. &lt;/P&gt;</description>
      <pubDate>Mon, 16 Oct 2017 23:43:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Bandwidth-usage-for-200-GB-of-data-from-heavy-forwarder-to/m-p/308848#M58115</guid>
      <dc:creator>pranitprakash</dc:creator>
      <dc:date>2017-10-16T23:43:32Z</dc:date>
    </item>
    <item>
      <title>Re: Bandwidth usage for 200 GB of data from heavy forwarder to indexers</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Bandwidth-usage-for-200-GB-of-data-from-heavy-forwarder-to/m-p/308849#M58116</link>
      <description>&lt;P&gt;The blog post &lt;A href="https://www.splunk.com/blog/2016/12/12/universal-or-heavy-that-is-the-question.html"&gt;Universal or Heavy, that is the question?&lt;/A&gt; shows you the bandwidth usage difference between universal and heavy forwarders.&lt;/P&gt;

&lt;P&gt;If you use SSL the data is compressed with an approx 10 to 1 ratio, so there will be a drastic difference with SSL on vs SSL off.&lt;/P&gt;

&lt;P&gt;The general answer is it depends, however you can refer to &lt;A href="https://answers.splunk.com/answers/2014/what-is-the-minimum-network-bandwidth-required-for-splunk-forwarding.html"&gt;this answer about minimum bandwidth&lt;/A&gt; or &lt;A href="https://answers.splunk.com/answers/340084/how-to-search-how-much-bandwidth-a-forwarder-is-us.html"&gt;this answer about measuring bandwidth used.&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;The 200GB/day doesn't mean that much in terms of bandwidth usage, if you had a perfect distribution that would be just over 8GB/hour + overheads or approx 2400 kb/s, and if you multiply that by 8 it would be kilobits per second, however if you use SSL and you take into account the overheads this number will obviously change.&lt;BR /&gt;
Also there is a good chance you will have more data at particular times (which you can control by throttling the forwarder as per this &lt;A href="https://answers.splunk.com/answers/2014/what-is-the-minimum-network-bandwidth-required-for-splunk-forwarding.html"&gt;answer&lt;/A&gt;)...&lt;/P&gt;</description>
      <pubDate>Tue, 17 Oct 2017 11:42:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Bandwidth-usage-for-200-GB-of-data-from-heavy-forwarder-to/m-p/308849#M58116</guid>
      <dc:creator>gjanders</dc:creator>
      <dc:date>2017-10-17T11:42:56Z</dc:date>
    </item>
    <item>
      <title>Re: Bandwidth usage for 200 GB of data from heavy forwarder to indexers</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Bandwidth-usage-for-200-GB-of-data-from-heavy-forwarder-to/m-p/308850#M58117</link>
      <description>&lt;P&gt;Hey @pranitprakash, if they answered your question don't forget to "accept" the answer to award karma points/ close the post.&lt;/P&gt;</description>
      <pubDate>Tue, 17 Oct 2017 14:53:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Bandwidth-usage-for-200-GB-of-data-from-heavy-forwarder-to/m-p/308850#M58117</guid>
      <dc:creator>lfedak_splunk</dc:creator>
      <dc:date>2017-10-17T14:53:52Z</dc:date>
    </item>
  </channel>
</rss>

