Installation

How do I size Splunk license using the number of events generated by assets?

Afef
Communicator

Hello,

I want to size splunk licence using number of events generated by assets.

Any help please ?

Labels (1)
0 Karma

vnakra_splunk
Splunk Employee
Splunk Employee

Late to the party, but may be useful for anyone who comes looking in the future. There's no reliable way to convert from EPS to GB/day. There are many approaches to get closer in the blog I wrote here: http://blogs.splunk.com/2016/05/06/what-size-should-my-splunk-license-be/

0 Karma

dflodstrom
Builder

Try this extremely helpful tool http://splunk-sizing.appspot.com/#ar=0&cr=90&hwr=30&i=12&sf=1&v=300

There is a box at the top you can check to use Events/Sec instead of size.

Afef
Communicator

Thanks, but this will size storage not licence. Did you have another idea ?

0 Karma

aweitzman
Motivator

Since the Splunk license is volume-based, you're better off using the total size of the content generated by your assets. Some events are bigger than others.

That said, the easiest way to do this is to download the free Splunk Enterprise, install it, point everything you have at it, and run it for two days. (Don't run it more than that, because then the free version will stop working.) Then look at how much volume you have indexed, and use those numbers to determine what your license ought to be.

(Of course, two days isn't a very big sample size, but it's better than nothing.)

Afef
Communicator

Thanks, but i need ti size data using number of events / day ! I have this only information. I can't test splunk no more. It's for a customer.

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Thanks for the Memories! Splunk University, .conf25, and our Community

Thank you to everyone in the Splunk Community who joined us for .conf25, which kicked off with our iconic ...

Data Persistence in the OpenTelemetry Collector

This blog post is part of an ongoing series on OpenTelemetry. What happens if the OpenTelemetry collector ...

Introducing Splunk 10.0: Smarter, Faster, and More Powerful Than Ever

Now On Demand Whether you're managing complex deployments or looking to future-proof your data ...