Splunk Storage Calculator

Splunk Storage Sizing
Input Data

Estimate the amount of data based on a number of events per second - this calculates based on a typical event size. The more data you send to Splunk Enterprise, the more time Splunk needs to index it into results that you can search, report, and generate alerts on.

Estimate the average daily amount of data to be ingested. The more data you send to Splunk Enterprise, the more time Splunk needs to index it into results that you can search, report, and generate alerts on.

50
20 bytes
1 GB
0.01
0.1

Daily Data Volume: 50.0 GB (100 events/s * 500 bytes avg. event size * 3600 seconds/hour * 24 hours/day)

Data Retention

Specify the amount of time to retain data for each category. Data will be rolled through each category dependant on its age.

1 days
1 days
1 days
Retention Time
Hot, Warm
Cold
Archived

Total = 90 days

Architecture

Specify the number of nodes required. The more data to ingest, the greater the number of nodes required. Adding more nodes will improve indexing throughput and search performance.

Use Case / App
1 GB
2 node(s)
1
1
Storage Required

This is a breakdown of the overall storage requirement.