Hi I’m not sure if there is any official calculations available? You could do some estimates based on knowledge of your replication factor and amount of ingestion and searches. Splunk will replicate all buckets between sites as soon as events are written on primary bucket. Actually splunk inform sending HF / UF (if you have indexAck configured) after replication has done, not before. Also searches are using bandwidth based on your queries. Bad queries use more bandwidth and better less. r. Ismo