icon/x Created with Sketch.

Splunk Cookie Policy

We use our own and third-party cookies to provide you with a great online experience. We also use these cookies to improve our products and services, support our marketing campaigns, and advertise to you on our website and other websites. Some cookies may continue to collect information after you have left our website. Learn more (including how to update your settings) here.
Accept Cookie Policy

Accept License Agreements

This app is provided by a third party and your right to use the app is in accordance with the license provided by that third-party licensor. Splunk is not responsible for any third-party apps and does not provide any warranty or support. If you have any questions, complaints or claims with respect to this app, please contact the licensor directly.

Thank You

Downloading Sizing Inputs Calculator for Splunk
SHA256 checksum (sizing-inputs-calculator-for-splunk_106.tgz) 30c4930347866a0fd15f5d04d61ec8c66e699db3c46f633d94aa00aac316891e
To install your download
For instructions specific to your download, click the Details tab after closing this window.

Flag As Inappropriate

Sizing Inputs Calculator for Splunk

Splunk AppInspect Passed
Admins: Please read about Splunk Enterprise 8.0 and the Python 2.7 end-of-life changes and impact on apps and upgradeshere.
The Sizing Inputs Calculator for Splunk is only intended for use in collaboration with your Splunk Account team.

The Sizing Inputs Calculator for Splunk does not collect or transmit customer data.

The Sizing Inputs Calculator for Splunk is used by your Splunk Account team to accelerate the discovery of technical details for sizing the Splunk architecture.

The Sizing Inputs Calculator for Splunk app includes a dashboard with details of the existing Splunk deployment. This dashboard will generate the following metrics:

- Physical CPU Cores, Memory Size (GB)
- Storage Information
- Additional Headroom
- Daily Indexing Volume
- Daily Search Count
- Scheduled/Data Model Acceleration Searches
- Search Concurrency
- Sourcetypes & Daily Ingestion Volume - Enterprise Security
- Ad Hoc Searches Count
- Historical Data Searches
- Correlation Search - Enterprise Security
- Built-in Saved Search - Enterprise Security
- Daily Search Count - Enterprise Security
- Historical Data Searches - Enterprise Security

*See the details tab for more specific instructions about this app.



  • The Sizing Inputs Calculator for Splunk requires visibility to all Search Heads and Indexers in the deployment. Therefore, it is recommended to install the Sizing Inputs Calculator for Splunk on a Splunk instance that has a Monitoring Console, or a Splunk instance for which all search heads and indexers are set up as search peers.
  • The Sizing Inputs Calculator for Splunk assumes that the instance it is running on conforms to the Splunk recommended hardware. If the instance this app is running on does not conform to the Splunk recommended hardware, there may not be enough concurrent searches for the dashboard to render.


Install the Sizing Inputs Calculator for Splunk in accordance to the documentation for a Single Server Install.


This app uses a search macro to easily select the earliest time (in days) that the searches should look back. The macro is called earliest and it is currently set to look back 7 days by default.

For example, the Daily Search Count search utilizes the earliest search macro:

`earliest` latest=@d index=_audit host=* action=search sourcetype=audittrail search_id!="*rsa_*" search_id!="*subsearch*" | timechart span=1d dc(search_id) AS "Daily Search Count" | stats perc95("Daily Search Count") AS "Daily Search Count"

This earliest macro can easily be edited to change to look back a different time range that that set by default:

  1. Select Settings > Advanced Search > Search macros
  2. Click on the earliest macro and change its definition (earliest=-7day@day) as desired


After installing the Sizing Inputs Calculator for Splunk, users can navigate to the Sizing Inputs Calculator for Splunk app to view a dashboard that renders sizing information about the deployment. Users should share this information back to their Splunk Account team by exporting the dashboard as a PDF.

Known Issues

There are no known issues at this time.


Click on the “Questions on Splunk Answers” link on the right side to post any questions.

Release Notes

Version 1.0.6
Aug. 28, 2020


Subscribe Share

AppInspect Tooling

Splunk AppInspect evaluates Splunk apps against a set of Splunk-defined criteria to assess the validity and security of an app package and components.

Are you a developer?

As a Splunkbase app developer, you will have access to all Splunk development resources and receive a 10GB license to build an app that will help solve use cases for customers all over the world. Splunkbase has 1000+ apps and add-ons from Splunk, our partners and our community. Find an app or add-on for most any data source and user need, or simply create your own with help from our developer portal.

Follow Us:
© 2005-2020 Splunk Inc. All rights reserved.
Splunk®, Splunk>®, Listen to Your Data®, The Engine for Machine Data®, Hunk®, Splunk Cloud™, Splunk Light™, SPL™ and Splunk MINT™ are trademarks and registered trademarks of Splunk Inc. in the United States and other countries. All other brand names, product names, or trademarks belong to their respective owners.