@Eldemallawy Estimating the Splunk data volume within an environment is not an easy task due to several factors: number of devices, logging level set on devices, data types collected per device, u...
See more...
@Eldemallawy Estimating the Splunk data volume within an environment is not an easy task due to several factors: number of devices, logging level set on devices, data types collected per device, user levels on devices, load volumes on devices, volatility of all data sources, not knowing what the end logging level will be, not knowing which events can be discarded. Estimate Indexing Volume 1. Verify raw log sizes. 2. Daily, Peak, retained, future volume. 3. Total number of data sources and hosts. 4. Add volume estimates to data source inventory/spreadsheet. Estimate index volume size: 1. For syslog type data, index occupies ~50% of original size. 2. 15% of raw data ( compression ) 3. 35% for associated index files.