What is the relationship between size of logs received by Splunk indexing servers versus indexing volume? On the load balancer we see similar amount of data sent to each Splunk server. But their indexing volumes are drastically different.
typically, the compressed, persisted data that Splunk extracts from your data inputs amounts to approximately 10% of the raw data that comes into Splunk. the indexes that are created to access this data can be anywhere from 10% to 110% of the size of the data that comes in. this value is affected strongly by how many unique terms occur in your data.