There are several methods one can use to determine the average volume per host, this is another one.
We wrote this one with the Unix and Windows TAs in mind. Here is how you use it:
1) Index data from a good number of hosts, to get a better average.
2) Configure the TAs on those hosts with everything enabled that you think you might want.
3) Collect data for a week or longer, to get a better average.
4) Use the multi-select form options in this App to:
a. Select any number of indexes to analyze
b. Remove outlier hosts
c. Remove sources that you are no longer interested in
The result is an "Average DAILY Data Ingestion per Host" panel that will allow you to plan for your future expansion.
But wait, how do you configure this App? There are no configuration step, just install the App on a Search Head and you are off to the races.
This App was co-developed by James Donn and Franco Ferrero Poschetto.
Please provide feedback and/or enhancement requests to jim@splunk.com. I will respond within three business days or sooner to address any issues that are reported.
Updated app.conf to remove a checksum.
Resolved a issue with searching license_usage.log.
Added another dashboard from a feature request.
Data Volume Estimator - Max: Start with all data sources selected, and remove what you do not like.
Data Volume Estimator - Min: Start with NO data sources selected, and add what you like.
Fixed time picker to effect all drop down menus.
Added icons.
As a Splunkbase app developer, you will have access to all Splunk development resources and receive a 10GB license to build an app that will help solve use cases for customers all over the world. Splunkbase has 1000+ apps from Splunk, our partners and our community. Find an app for most any data source and user need, or simply create your own with help from our developer portal.