Splunk Volume License

Splunk Volume

Splunk Volume License
Splunk Volume License


Splunk Data Volume Calculation 

When uberAgent is used with Splunk license as a backend, a Splunk license is required. Splunk is licensed by daily indexed data volume, i.e., you pay for the total amount of data you send to Splunk per day. How long that data is stored does not matter, only how much new data you add. uberAgent is one of the potentially many data sources that put data into Splunk, contributing to the total data volume. 

Estimate or Measure 

Customers have a vested interest in knowing how much data each Splunk add-on generates so they can estimate costs before they buy. In the case of uberAgent, the data volume per host depends greatly on the environment, the types of applications used, the desktop configuration, background processes, the type of browser used and many other variables. For that reason, it is not possible to calculate the data volume with any reasonable accuracy without doing an actual proof of concept implementation (see below). However, if you just want some figures for a very rough first calculation, use the following values for typical clients and servers: 

  • Typical data volume per single-user client and day: 15 MB 
  • Typical data volume per multi-user (Citrix VAD/RDS) server and day: 65 MB 

To get accurate numbers install uberAgent and go to the Data Volume dashboard (see below). You can significantly reduce the data volume through an optimized configuration. 


The App Data Volume dashboard provides information about the quantity and types of data you collect in the Splunk App for VMware. You can get a quick view of the total volume of data created by the app. 

Use this dashboard to see: 

  • The total data volume over the last 24 hours. 
  • The breakdown of data by data type and unique sourcetypes for each of the data source collected. 
  • The installed Splunk App for VMware licenses. 
  • Daily data volume remaining. 


Dashboard description 

Panel  Description 
Overall Data Volume, over the last 24 hours  The total volume of data indexed in the last 24 hours. 
Detailed Data Volume, over the last 24 hours  Shows the volume of indexed data broken down by data type. The sourcetype vmware:events must be present for this panel to populate. 
Installed VMware App Licenses  Displays details for the installed Splunk App for VMware licenses. 
Daily Data Volume Remaining  Displays the remaining amount of data you can index. Indexed data volume is reported on a daily basis. 


How to use this page 

  • You can change the range of data that the dashboard displays by choosing the appropriate time range in the time picker at the top of the page and clicking “Search”. 
  • If you click on a node in either area chart, the Splunk App for Microsoft Exchange brings up the base search that produced the events at that point in time, along with the events that occurred at that point. 


How useful was this post?

Click on a star to rate it!

Average rating 5 / 5. Vote count: 3

No votes so far! Be the first to rate this post.

  • Home Page
  • Network Security License
  • Network Software License
  • Leave a Reply

    Your email address will not be published. Required fields are marked *