Getting Data In

hot/warm buckets

pbrinkman
Path Finder

hi all,

I have seperate drive for my hot/warm and cold data.
The hot/warm drive is near capacity.

Looking to find an easy way to calculate how much data each index will hold.
One example index config set is as below

10955Mb ingest per day (10.9Gb)
MazDataSize = 750mb (max size in MB for a hot bucket to reach before it rolls to warm)
maxWarmDBCount = 436 (max number of warm buckets)
maxtotalDataSize = 4328249mb (4328Gb) (maximum size of the index (in Mb)
frozenTimePeriodinSecs = 34128000 (395days in seconds)(number of seconds after which indexed data rolls to frozen)
overall retention = 395 (13months)
overall warm in days = 30

I would like to know how i can work out what size this indexed data should take up on my hot/warm and cold drives.
The split of the 4328Gb between the hot/warm & cold drives over 13months.
Does anyone know how best to calculate this ?

Cheers
Paul

0 Karma

harsmarvania57
Ultra Champion

Hi,

Have you looked at https://splunk-sizing.appspot.com/, it will be a good starting point.

kmorris_splunk
Splunk Employee
Splunk Employee

I was just about to share the same thing. This is a great tool for this task. You can play around with different retention times for hot/warm, cold, and archived (frozen).

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Unlocking Unified Insights: New Gigamon Federated Search App for Splunk

In today’s data-heavy environment, organizations are caught in a data distribution dilemma. As data volumes ...

GA: New Data Management App in Splunk Platform

Streamlining Data Management: Introducing a unified experience in Splunk Managing data at scale shouldn’t feel ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...