Deployment sizing worksheet
Enter the customer’s ingest, retention, and architecture. The worksheet returns indexer count, tiered storage per node and across the cluster, a server bill of materials including premium apps, and a matching indexes.conf.
Planning estimate only. Output is a starting point for an architecture conversation, not a validated design. Real requirements shift with data mix, field cardinality, search concurrency, and compression. Validate against a pilot before you buy hardware. See the full disclaimer.
Start from a reference size
Daily ingest
Retention
Splunk’s published aggregate is 15% rawdata + 35% tsidx ≈ 50% of pre-indexed volume. Raise tsidx for highly structured, high-cardinality sources.
Architecture
Premium apps licensed separately
Design point year 3
Deployment topology
Storage by tier
| Tier | Multiplier | Per indexer | All indexers |
|---|
Server bill of materials
| Role | Qty | Cores / vCPU | RAM | Storage each |
|---|
Design notes and constraints
indexes.conf per indexer · single volume set
Sources for the constants used above
- 15% rawdata + 35% tsidx ≈ 50% of pre-indexed volume — Splunk Enterprise Capacity Planning Manual, Estimate your storage requirements.
- Clustered storage = (RF × rawdata) + (SF × tsidx) — a searchable copy carries rawdata plus tsidx; the remaining replicated copies carry rawdata only.
- 100 GB/day per indexer with Enterprise Security — ES deployment sizing table: 300 GB/day on 3 indexers, 1 TB/day on 10, 15 TB/day on 150. Performance reference for Splunk Enterprise Security.
- Data model acceleration = daily volume × 3.4 per year — 100 GB/day needs roughly 340 GB extra across the indexers for a year of accelerations. Configure data models for Splunk Enterprise Security.
- ITSI: 1 indexer per 100 GB indexed; roughly one added indexer and search head per 500 KPIs; 30 GB free in $SPLUNK_HOME for the KV store; dedicated search head, never shared with ES — Plan your ITSI deployment.
- SOAR on-premises: 1 server-class CPU (4–8 cores), 16 GB RAM minimum / 32 GB recommended, and three 500 GiB volumes — home, data, vault — for 1.5 TB total — System requirements for production use.
- ES Premier bundles SOAR with unlimited seats plus native UEBA; ES Essentials is the former ES — Installing Splunk Enterprise Security Premier.
- The ITSI summary-index estimate is a heuristic — KPIs × entities × intervals per day × ~400 bytes. Splunk publishes no figure for it. Validate against itsi_summary in a pilot before committing to it.
Disclaimer and terms of use
Estimates only. This worksheet applies publicly documented Splunk sizing formulas to the values you enter. It produces planning estimates, not a validated architecture, a bill of sale, or a commitment of any kind. It has not been reviewed or certified by Splunk or Cisco.
Your inputs drive the output. Results are only as accurate as the assumptions entered. Actual indexer counts, storage consumption, and hardware requirements vary materially with data mix, event structure, field cardinality, compression, search concurrency, correlation and acceleration load, retention policy, and platform version. Splunk’s own guidance directs customers to Professional Services for architecture validation above 1 TB/day with Enterprise Security.
No warranty. This tool is provided “as is,” without warranty of any kind, express or implied, including any warranty of accuracy, merchantability, or fitness for a particular purpose. August Schell accepts no liability for any loss, cost, procurement decision, or damage — direct, indirect, incidental, or consequential — arising from use of or reliance on these results. Verify all figures against a pilot deployment and a formal architecture review before making purchasing or design commitments.
Trademarks. Splunk, Splunk Enterprise, Splunk Enterprise Security, Splunk SOAR, and Splunk IT Service Intelligence are trademarks of Splunk LLC, a Cisco company. August Schell is an independent systems integrator. This tool is not affiliated with, authored by, endorsed by, or sponsored by Splunk or Cisco.
Your data stays in your browser. All calculations run locally in this page. Nothing you enter is transmitted, logged, or stored by August Schell.
Sizing a real deployment? These numbers open the conversation — they don’t close it. August Schell architects Splunk environments for federal customers, including clustered indexer tiers, premium app deployments, and ingest pipeline design.
