Deployment Architecture

Sizing new installation, calculate storage from events

reswob4
Builder

Hi,
we are preparing to deploy splunk and I have a question about sizing. All the documentation I've found so far talk about size of the storage per day in GB and the tools that I have found calculate that storage against existing splunk installs or demo installs. All I have currently is the calculation of events per day our (smallish) network will generate. Is there a way (or an article or link or previous discussion) to translate events per day into storage per day?

The events are mostly from windows servers and firewall logs.

Thanks.

Tags (1)
0 Karma
1 Solution

martin_mueller
SplunkTrust
SplunkTrust

Take the number of events per day and multiply with the average event length to get the anticipated volume per day. Then you can apply the regular rule of thumb that you'll need maybe 50% of the daily volume for daily storage. How much depends on the type of data.

This may sound overly obvious, but since an event could be 20 bytes or 20000 bytes there's no reasonably conversion from events per day to volume per day. Once you have volume per day you can estimate storage per day at least roughly. The best way would still be to do a trial installation on the trial or free license.

View solution in original post

kojoson
New Member

what was the required size of the storage per day in GB?

0 Karma

martin_mueller
SplunkTrust
SplunkTrust

Take the number of events per day and multiply with the average event length to get the anticipated volume per day. Then you can apply the regular rule of thumb that you'll need maybe 50% of the daily volume for daily storage. How much depends on the type of data.

This may sound overly obvious, but since an event could be 20 bytes or 20000 bytes there's no reasonably conversion from events per day to volume per day. Once you have volume per day you can estimate storage per day at least roughly. The best way would still be to do a trial installation on the trial or free license.

reswob4
Builder

Thanks. That helps.

0 Karma
Get Updates on the Splunk Community!

Aligning Observability Costs with Business Value: Practical Strategies

 Join us for an engaging Tech Talk on Aligning Observability Costs with Business Value: Practical ...

Mastering Data Pipelines: Unlocking Value with Splunk

 In today's AI-driven world, organizations must balance the challenges of managing the explosion of data with ...

Splunk Up Your Game: Why It's Time to Embrace Python 3.9+ and OpenSSL 3.0

Did you know that for Splunk Enterprise 9.4, Python 3.9 is the default interpreter? This shift is not just a ...