Getting Data In

Advice on personal experience of data count of data sources per host

hensgr
New Member

Hey all. So my company has recently acquired 200GB added on top of our current licence. We are interested in 3 different log sources and wondering what the data size per day is per host in your experience?

It would be good to know if you have heavily filtered the input or not, but it would be good for scoping if I could have an idea of metrics:
Powershell logs
Sysmon
Winevent logs on users machines

0 Karma
1 Solution

richgalloway
SplunkTrust
SplunkTrust

While you may get some useful estimates from other people's experiences, nothing beats estimating using your own data.

Turn on those sources on 1-10 hosts and measure how much your data ingestion increases. Use that figure to extrapolate the total license usage increase for those sources on all hosts.

---
If this reply helps you, Karma would be appreciated.

View solution in original post

0 Karma

richgalloway
SplunkTrust
SplunkTrust

While you may get some useful estimates from other people's experiences, nothing beats estimating using your own data.

Turn on those sources on 1-10 hosts and measure how much your data ingestion increases. Use that figure to extrapolate the total license usage increase for those sources on all hosts.

---
If this reply helps you, Karma would be appreciated.
0 Karma

hensgr
New Member

Totally appreciate the point and I have suggested this but you can understand the complexities to getting this done in a heavily bureaucratic environment. Just at a finger in the air for now so I am interested in what other people's experiences are.

0 Karma
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Dynamic formatting from XML events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Stronger Security with Federated Search for S3, GCP SQL & Australian Threat ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...