How to estimate Splunk storage size

Daily logs GB After compression and TSIDX creation your data will be 75% of its original size Data Retention number of days Total Storage Before Replication GB With ideal load balancing across 2 indexers, Each indexer storage requirement GB  Your RF=2/SF=2 clustering across two indexers will mean that each indexer will need 2X that storage GB
 Palo Alto Firewall  10  7.5  30  225  112.5  450
Linux syslog 20 15 60 900 450 1800
Windows logs 10 7.5 60 450 225 1350
Proxy logs 15 11.25 90 1012.5 506.25 2025
Application logs 10 7.5 90 675 337.5 1350
Web logs 35 26.25 90 2362.5 1181.25 4725
Daily Total 100 75 5625 2812.5 11250
Please follow and like us: