Splunk Stream

User Manual

This documentation does not apply to the most recent version of Splunk Stream. For documentation on the most recent version, go to the latest release.

Use Stream Estimate to preview index volume

The Stream Estimate dashboard shows index volume statistics for all streams in Estimate mode. Streams in Estimate mode generate data index volume statistics without sending the actual data to your indexers.

Use the Stream Estimate dashboard to preview the amount of data that you might need to index for any stream. This information can help you calculate your indexer requirements and configure your streams so that you capture only the data you require for analysis.

The Stream Estimate dashboard lets you monitor these data index volume stats:

  • Total Events
  • Total Incoming Traffic (MB)
  • Total Outgoing Traffic (MB)
  • Total Traffic (MB)
  • Splunk Index Volume (MB)

In the Splunk App for Stream main menu, click Stream Estimate.

Stream estimate.png

Note: Streams in Enabled mode generate data index volume stats based on the actual amount of data sent to your indexers. View index volume stats for all enabled streams in the Stream Data Volumes dashboard. For more information, see Admin Dashboards in this manual.

For more information on the Estimate mode, see Configure Streams in this manual.

Last modified on 01 April, 2020
Distributed Forwarder Management   Stream Informational Dashboards

This documentation applies to the following versions of Splunk Stream: 7.1.2, 7.1.3, 7.2.0


Was this topic useful?







You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters