Splunk Enterprise · on-premises Indexer · storage · premium app sizing Formulas per Splunk documentation

Deployment sizing worksheet

Enter the customer’s ingest, retention, and architecture. The worksheet returns indexer count, tiered storage per node and across the cluster, a server bill of materials including premium apps, and a matching indexes.conf.

Planning estimate only. Output is a starting point for an architecture conversation, not a validated design. Real requirements shift with data mix, field cardinality, search concurrency, and compression. Validate against a pilot before you buy hardware. See the full disclaimer.

Start from a reference size

Daily ingest

Retention

Splunk’s published aggregate is 15% rawdata + 35% tsidx ≈ 50% of pre-indexed volume. Raise tsidx for highly structured, high-cardinality sources.

Architecture

Premium apps licensed separately

Design point year 3

Design ingest
Indexers
Usable storage / indexer
hot+warm, cold, summaries
Total indexed storage
across all indexers

Deployment topology

Storage by tier

TierMultiplierPer indexerAll indexers

Server bill of materials

RoleQtyCores / vCPURAMStorage each

Design notes and constraints

indexes.conf per indexer · single volume set


    

Sources for the constants used above

  1. 15% rawdata + 35% tsidx ≈ 50% of pre-indexed volume — Splunk Enterprise Capacity Planning Manual, Estimate your storage requirements.
  2. Clustered storage = (RF × rawdata) + (SF × tsidx) — a searchable copy carries rawdata plus tsidx; the remaining replicated copies carry rawdata only.
  3. 100 GB/day per indexer with Enterprise Security — ES deployment sizing table: 300 GB/day on 3 indexers, 1 TB/day on 10, 15 TB/day on 150. Performance reference for Splunk Enterprise Security.
  4. Data model acceleration = daily volume × 3.4 per year — 100 GB/day needs roughly 340 GB extra across the indexers for a year of accelerations. Configure data models for Splunk Enterprise Security.
  5. ITSI: 1 indexer per 100 GB indexed; roughly one added indexer and search head per 500 KPIs; 30 GB free in $SPLUNK_HOME for the KV store; dedicated search head, never shared with ESPlan your ITSI deployment.
  6. SOAR on-premises: 1 server-class CPU (4–8 cores), 16 GB RAM minimum / 32 GB recommended, and three 500 GiB volumes — home, data, vault — for 1.5 TB totalSystem requirements for production use.
  7. ES Premier bundles SOAR with unlimited seats plus native UEBA; ES Essentials is the former ESInstalling Splunk Enterprise Security Premier.
  8. The ITSI summary-index estimate is a heuristic — KPIs × entities × intervals per day × ~400 bytes. Splunk publishes no figure for it. Validate against itsi_summary in a pilot before committing to it.

Sizing a real deployment? These numbers open the conversation — they don’t close it. August Schell architects Splunk environments for federal customers, including clustered indexer tiers, premium app deployments, and ingest pipeline design.

Talk to an architect