Splunk ITSI

In Splunk IT Service Intelligence, what are the required log sources and expected volumes of data?

evelenke
Contributor

Hi Splunkers,

I will appreciate any approximate estimates on expected volumes and sources of data that will satisfy general needs for a nice functionality of ITSI in a mixed environment with, for example, 100 or 1000 hosts.

0 Karma
1 Solution

chrisyounger
SplunkTrust
SplunkTrust

Hi @evelenke

This is an almost impossible question to answer as it can be heavily customised and all customers are different.

Here is some very very rough numbers for you to consider, but please talk to your Splunk sales rep:

Windows servers: ~ 250MB/server
Unix servers: ~500MB/day
Virtualization logs: ~500MB/day
Cloud logs: ~500MB/day
Other monitoring, such as website checks etc: 250MB/day

Hope this is helpful. I have take the numbers from the Splunk DSA checklist, but you should not rely on these figures for anything.

View solution in original post

chrisyounger
SplunkTrust
SplunkTrust

Hi @evelenke

This is an almost impossible question to answer as it can be heavily customised and all customers are different.

Here is some very very rough numbers for you to consider, but please talk to your Splunk sales rep:

Windows servers: ~ 250MB/server
Unix servers: ~500MB/day
Virtualization logs: ~500MB/day
Cloud logs: ~500MB/day
Other monitoring, such as website checks etc: 250MB/day

Hope this is helpful. I have take the numbers from the Splunk DSA checklist, but you should not rely on these figures for anything.

evelenke
Contributor

Any rough calculation is helpful, thanks a lot!

0 Karma
Get Updates on the Splunk Community!

Splunk Search APIを使えば調査過程が残せます

   このゲストブログは、JCOM株式会社の情報セキュリティ本部・専任部長である渡辺慎太郎氏によって執筆されました。 Note: This article is published in both Japanese ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...