Splunk Enterprise

Daily ingested volume (not license usage?) search

SplunkExplorer
Contributor

Hi Splunkers, I have to calculate daily ingested volume in a Splunk Enteprise environment.
Here on community I found a lot of post, and related answer, to a similar question: daily license consumption, but I don't know if it is what I need.
I mean: we know that, once data are ingested by Splunk, compression factor is applied and, in a non clustered environment, it is more or less 50%. So, for example, if I have 100 GB data ingested by day, final size on disk will be 50 GB .

Well, I have to calculate total GB BEFORE compression is applied. So, in my above example, search/method I need should NOT return 50 GB as final result, but 100 GB.
Moreover, in my current env, I have an Indexers cluster. 

So, what is not clear is: daily consumed License, is what I need?
I mean: when I see daily consumed license by my environment, GB returned are the ingested one BEFORE compression, or the Compressed one?

 

Labels (2)
0 Karma
1 Solution

SplunkExplorer
Contributor
0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Tech Talk Recap | Mastering Threat Hunting

Mastering Threat HuntingDive into the world of threat hunting, exploring the key differences between ...

Observability for AI Applications: Troubleshooting Latency

If you’re working with proprietary company data, you’re probably going to have a locally hosted LLM or many ...

Splunk AI Assistant for SPL vs. ChatGPT: Which One is Better?

In the age of AI, every tool promises to make our lives easier. From summarizing content to writing code, ...