<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to calculate how much splunk license is enough in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/How-to-calculate-how-much-splunk-license-is-enough/m-p/559010#M92476</link>
    <description>&lt;P&gt;Thank you for the prompt reply, however, we haven't started indexing the data and we do not know the size of the events yet. The estimate license needs to be confirmed beforehand( which sounds odd to me too).&lt;BR /&gt;I would may be assume each event size as ~10kb ( since each record has around 200 fields) and calculate the size.&lt;BR /&gt;&lt;BR /&gt;Thank You.&lt;/P&gt;</description>
    <pubDate>Mon, 12 Jul 2021 04:55:12 GMT</pubDate>
    <dc:creator>architkhanna</dc:creator>
    <dc:date>2021-07-12T04:55:12Z</dc:date>
    <item>
      <title>How to calculate how much splunk license is enough</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-calculate-how-much-splunk-license-is-enough/m-p/558829#M92446</link>
      <description>&lt;P&gt;I have a splunk Cluster where instances are of following configurations.&lt;BR /&gt;&lt;BR /&gt;--&amp;gt; 16vCPU&lt;/P&gt;&lt;P&gt;--&amp;gt; 64GB Memory&lt;/P&gt;&lt;P&gt;--&amp;gt; 400GB Disk Size.&lt;BR /&gt;&lt;BR /&gt;The source ,&amp;nbsp; from where my app pulls data , 150k records are generated each day. How do we confirm on the license part which needs to be installed for this scenario? Is there a straight away formula to calculate that?&lt;BR /&gt;TIA.&lt;/P&gt;</description>
      <pubDate>Fri, 09 Jul 2021 12:02:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-calculate-how-much-splunk-license-is-enough/m-p/558829#M92446</guid>
      <dc:creator>architkhanna</dc:creator>
      <dc:date>2021-07-09T12:02:14Z</dc:date>
    </item>
    <item>
      <title>Re: How to calculate how much splunk license is enough</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-calculate-how-much-splunk-license-is-enough/m-p/558837#M92450</link>
      <description>&lt;P&gt;If your app is the only one sending data to Splunk then the license needed is 150k x the average size of a record plus a small margin for occasional overages.&lt;/P&gt;&lt;P&gt;If there are other apps sending data then add in the amount they will send each day.&lt;/P&gt;</description>
      <pubDate>Fri, 09 Jul 2021 13:11:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-calculate-how-much-splunk-license-is-enough/m-p/558837#M92450</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2021-07-09T13:11:48Z</dc:date>
    </item>
    <item>
      <title>Re: How to calculate how much splunk license is enough</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-calculate-how-much-splunk-license-is-enough/m-p/558840#M92452</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/209826"&gt;@architkhanna&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;the best approach is to analyze license consuption for a period.&lt;/P&gt;&lt;P&gt;Anyway, you could calculate license consuption identifying an average dimension for the events, so if they have around 1kB each one, you could have:&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;150,000*1k/1024=140 MB&lt;/P&gt;&lt;P&gt;then you could add a 30% of tolerance, but anyway you need less than 500MB that's the minimum license.&lt;/P&gt;&lt;P&gt;Are you sure that 150k is the number of events per day and not eps?&amp;nbsp;&lt;/P&gt;&lt;P&gt;in this other case the license consuption is very different:&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;150,000*3600*24*1k/1024/1024/1024=12 TB&lt;/P&gt;&lt;P&gt;Check the exact number of events!&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 09 Jul 2021 13:46:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-calculate-how-much-splunk-license-is-enough/m-p/558840#M92452</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2021-07-09T13:46:38Z</dc:date>
    </item>
    <item>
      <title>Re: How to calculate how much splunk license is enough</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-calculate-how-much-splunk-license-is-enough/m-p/559010#M92476</link>
      <description>&lt;P&gt;Thank you for the prompt reply, however, we haven't started indexing the data and we do not know the size of the events yet. The estimate license needs to be confirmed beforehand( which sounds odd to me too).&lt;BR /&gt;I would may be assume each event size as ~10kb ( since each record has around 200 fields) and calculate the size.&lt;BR /&gt;&lt;BR /&gt;Thank You.&lt;/P&gt;</description>
      <pubDate>Mon, 12 Jul 2021 04:55:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-calculate-how-much-splunk-license-is-enough/m-p/559010#M92476</guid>
      <dc:creator>architkhanna</dc:creator>
      <dc:date>2021-07-12T04:55:12Z</dc:date>
    </item>
    <item>
      <title>Re: How to calculate how much splunk license is enough</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-calculate-how-much-splunk-license-is-enough/m-p/559018#M92478</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/209826"&gt;@architkhanna&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;as me and&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/213957"&gt;@richgalloway&lt;/a&gt;&amp;nbsp;said, you have two choises:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;to make a PoC to see you data e.g. from one server and make a calculation,&lt;/LI&gt;&lt;LI&gt;to see the dimension of a single event, calculate dimension x number of events,&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;adding a margin in both cases.&lt;/P&gt;&lt;P&gt;At first glance, 10 kb seems a bit too much for a single event, as it means an average of 10,000 characters for each event (in your case 200 fields each one with 50 chars!), just as an example a Windows event (that is among the most verbose) is always less than 1kb and if we talk about Linux, we normally have less of 0.1 kb.&lt;/P&gt;&lt;P&gt;Anyway, put e.g. 1000 events in a file and see its dimension.&lt;/P&gt;&lt;P&gt;At the same time, check the number og events, because 150k events are the usual number of few windows servers or 2-3 Domain Controllers.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Mon, 12 Jul 2021 06:19:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-calculate-how-much-splunk-license-is-enough/m-p/559018#M92478</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2021-07-12T06:19:09Z</dc:date>
    </item>
  </channel>
</rss>

