Installation

How do I size Splunk license using the number of events generated by assets?

Afef
Communicator

Hello,

I want to size splunk licence using number of events generated by assets.

Any help please ?

Labels (1)
0 Karma

vnakra_splunk
Splunk Employee
Splunk Employee

Late to the party, but may be useful for anyone who comes looking in the future. There's no reliable way to convert from EPS to GB/day. There are many approaches to get closer in the blog I wrote here: http://blogs.splunk.com/2016/05/06/what-size-should-my-splunk-license-be/

0 Karma

dflodstrom
Builder

Try this extremely helpful tool http://splunk-sizing.appspot.com/#ar=0&cr=90&hwr=30&i=12&sf=1&v=300

There is a box at the top you can check to use Events/Sec instead of size.

Afef
Communicator

Thanks, but this will size storage not licence. Did you have another idea ?

0 Karma

aweitzman
Motivator

Since the Splunk license is volume-based, you're better off using the total size of the content generated by your assets. Some events are bigger than others.

That said, the easiest way to do this is to download the free Splunk Enterprise, install it, point everything you have at it, and run it for two days. (Don't run it more than that, because then the free version will stop working.) Then look at how much volume you have indexed, and use those numbers to determine what your license ought to be.

(Of course, two days isn't a very big sample size, but it's better than nothing.)

Afef
Communicator

Thanks, but i need ti size data using number of events / day ! I have this only information. I can't test splunk no more. It's for a customer.

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Community Content Calendar, September edition

Welcome to another insightful post from our Community Content Calendar! We're thrilled to continue bringing ...

Splunkbase Unveils New App Listing Management Public Preview

Splunkbase Unveils New App Listing Management Public PreviewWe're thrilled to announce the public preview of ...

Leveraging Automated Threat Analysis Across the Splunk Ecosystem

Are you leveraging automation to its fullest potential in your threat detection strategy?Our upcoming Security ...