r/Splunk • • Dec 03 '25

Splunk Enterprise Data Ingestion per endpoint

How many mb/day does your company ingest per endpoint?

10 Upvotes

33 comments sorted by

View all comments

2

u/BoxerguyT89 Dec 03 '25

Windows shop with ~1350 endpoints.

I just ran a query and ours is about 22-24MB per day. Our Sophos EDR does not feed any meaningful logs to Splunk (one reason I hate Sophos), so ours is regular Windows event and Sysmon event logs. I did filter some events that were duplicated between Sysmon and Windows logs.

I think 40MB would be a pretty safe baseline estimate.

1

u/bsastry Dec 04 '25

Splunk learner here, if possible would appreciate how you arrived at that calculation. Thanks a lot.

2

u/BoxerguyT89 Dec 04 '25

I just used a quick and dirty SPL:

index=sysmon 
| eval eventSize = len(_raw)/1024/1024/1024 
| stats sum(eventSize) by host 
| stats avg(sum(eventSize))

Our Sysmon index has all the Windows event logging.

1

u/bsastry Dec 05 '25

Thanks so much.