Getting Data In

How to get the total size of data in a distributed Splunk deployment ignoring replication

vzedbny
Engager

I would like to add a new indexer site to our distributed Splunk deployment but would like this new site to contain a single copy of all of the data that's currently in the deployment. To do this, I want to get the size of the entirety of 1 copy of our Splunk data. This will help me size the new site.

We have a monitoring console and the Indexes and Volumes metric has an "Index Size" -> "Total Across Deployment".
Does that number include replicated data or is this the total size of 1 copy of the data?

0 Karma

codebuilder
Influencer

Yes, that number includes replication. Divide the numbers by your replication factor.

----
An upvote would be appreciated and Accept Solution if it helps!
Get Updates on the Splunk Community!

Good Sourcetype Naming

When it comes to getting data in, one of the earliest decisions made is what to use as a sourcetype. Often, ...

See your relevant APM services, dashboards, and alerts in one place with the updated ...

As a Splunk Observability user, you have a lot of data you have to manage, prioritize, and troubleshoot on a ...

Splunk App for Anomaly Detection End of Life Announcement

Q: What is happening to the Splunk App for Anomaly Detection?A: Splunk is officially announcing the ...