Knowledge Management

Splunk Cumulative Raw Data Size vs Index Disk Usage

crsciarri
Engager

Hi,

Can someone clarify the difference between the cumulative raw data size found in the cluster settings on a splunk master and the index disk usage for an index in Splunk SOS. The disk usage value in SOS is about three times larger than the value for cumulative raw data size. Currently on Splunk 6.0.3.

Tags (1)

jagadeeshm
Contributor

I am seeing the same behavior. Actual size on disk is atleast 10 times larger than the cumulative raw data size. Any further updates on this question?

0 Karma

musskopf
Builder

As far I understand the cumulative Raw is actually the raw data indexed itself. The Index Disk Usage is the raw data indexed and everything else Splunk creates/saves to disk for that specific index.

In may case it's normally the opposite, the space in disk is 3 times smaller in most of my indexes. I believe it depends on data compression and field extraction (during indexing phase).

0 Karma
Get Updates on the Splunk Community!

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

 Prepare to elevate your security operations with the powerful upgrade to Splunk Enterprise Security 8.x! This ...

Get Early Access to AI Playbook Authoring: Apply for the Alpha Private Preview ...

Passionate about security automation? Apply now to our AI Playbook Authoring Alpha private preview ...

Reduce and Transform Your Firewall Data with Splunk Data Management

Managing high-volume firewall data has always been a challenge. Noisy events and verbose traffic logs often ...