Hi,
The license size you need depends specifically on the amount of data that your Exchange environment generates. The more data that comes out of your Exchange environment, the bigger a license you require.
For example, let's say you have a 10-host Exchange server environment (6 Mailbox, 2 Client Access, 2 Hub/Edge Transport). Each of those hosts generates about 150 MB of Exchange-specific data (some higher, some lower). Therefore, you would need at least a 2 GB per day license to cover just the Exchange Server traffic (1.5 GB + 25% overhead). This is in addition to the license you need for regular Splunk Enterprise to cover the Windows and Active Directory license data.
Remember, you can run the app in trial mode (with no restrictions) for 60 days, just like you can Splunk Enterprise. So, the best way to determine how much license you need is to install an instance with the app and run it for a day or two, determine the daily indexing volume, then get a license that covers that volume plus 5-10% overhead.
Additional information can be found here.
... View more