Knowledge Management

Splunk Cumulative Raw Data Size vs Index Disk Usage

crsciarri
Engager

Hi,

Can someone clarify the difference between the cumulative raw data size found in the cluster settings on a splunk master and the index disk usage for an index in Splunk SOS. The disk usage value in SOS is about three times larger than the value for cumulative raw data size. Currently on Splunk 6.0.3.

Tags (1)

jagadeeshm
Contributor

I am seeing the same behavior. Actual size on disk is atleast 10 times larger than the cumulative raw data size. Any further updates on this question?

0 Karma

musskopf
Builder

As far I understand the cumulative Raw is actually the raw data indexed itself. The Index Disk Usage is the raw data indexed and everything else Splunk creates/saves to disk for that specific index.

In may case it's normally the opposite, the space in disk is 3 times smaller in most of my indexes. I believe it depends on data compression and field extraction (during indexing phase).

0 Karma
Get Updates on the Splunk Community!

Reduce and Transform Your Firewall Data with Splunk Data Management

Managing high-volume firewall data has always been a challenge. Noisy events and verbose traffic logs often ...

Automatic Discovery Part 1: What is Automatic Discovery in Splunk Observability Cloud ...

If you’ve ever deployed a new database cluster, spun up a caching layer, or added a load balancer, you know it ...

Real-Time Fraud Detection: How Splunk Dashboards Protect Financial Institutions

Financial fraud isn't slowing down. If anything, it's getting more sophisticated. Account takeovers, credit ...