Splunk Enterprise

Daily ingested volume (not license usage?) search

SplunkExplorer
Contributor

Hi Splunkers, I have to calculate daily ingested volume in a Splunk Enteprise environment.
Here on community I found a lot of post, and related answer, to a similar question: daily license consumption, but I don't know if it is what I need.
I mean: we know that, once data are ingested by Splunk, compression factor is applied and, in a non clustered environment, it is more or less 50%. So, for example, if I have 100 GB data ingested by day, final size on disk will be 50 GB .

Well, I have to calculate total GB BEFORE compression is applied. So, in my above example, search/method I need should NOT return 50 GB as final result, but 100 GB.
Moreover, in my current env, I have an Indexers cluster. 

So, what is not clear is: daily consumed License, is what I need?
I mean: when I see daily consumed license by my environment, GB returned are the ingested one BEFORE compression, or the Compressed one?

 

Labels (2)
0 Karma
1 Solution

SplunkExplorer
Contributor
0 Karma
Get Updates on the Splunk Community!

New This Month in Splunk Observability Cloud - Metrics Usage Analytics, Enhanced K8s ...

The latest enhancements across the Splunk Observability portfolio deliver greater flexibility, better data and ...

Alerting Best Practices: How to Create Good Detectors

At their best, detectors and the alerts they trigger notify teams when applications aren’t performing as ...

Discover Powerful New Features in Splunk Cloud Platform: Enhanced Analytics, ...

Hey Splunky people! We are excited to share the latest updates in Splunk Cloud Platform 9.3.2408. In this ...