Hi Splunkers,
I will appreciate any approximate estimates on expected volumes and sources of data that will satisfy general needs for a nice functionality of ITSI in a mixed environment with, for example, 100 or 1000 hosts.
Hi @evelenke
This is an almost impossible question to answer as it can be heavily customised and all customers are different.
Here is some very very rough numbers for you to consider, but please talk to your Splunk sales rep:
Windows servers: ~ 250MB/server
Unix servers: ~500MB/day
Virtualization logs: ~500MB/day
Cloud logs: ~500MB/day
Other monitoring, such as website checks etc: 250MB/day
Hope this is helpful. I have take the numbers from the Splunk DSA checklist, but you should not rely on these figures for anything.
Hi @evelenke
This is an almost impossible question to answer as it can be heavily customised and all customers are different.
Here is some very very rough numbers for you to consider, but please talk to your Splunk sales rep:
Windows servers: ~ 250MB/server
Unix servers: ~500MB/day
Virtualization logs: ~500MB/day
Cloud logs: ~500MB/day
Other monitoring, such as website checks etc: 250MB/day
Hope this is helpful. I have take the numbers from the Splunk DSA checklist, but you should not rely on these figures for anything.
Any rough calculation is helpful, thanks a lot!