splunk-platform-sizing

Convert daily ingest, retention, and workload inputs into Splunk deployment sizing recommendations.

36|7|Updated Mar 17, 2026
One-click install
npx skills add https://github.com/chambear2809/splunk-cisco-skills --skill splunk-platform-sizing
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: splunk-platform-sizing
Source: https://github.com/chambear2809/splunk-cisco-skills/tree/main/skills/splunk-platform-sizing
Command: npx skills add https://github.com/chambear2809/splunk-cisco-skills --skill splunk-platform-sizing

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill requires credential_helpers.sh, and includes scripts (resource) components.

What problem does it solve?

Sizing Splunk deployments for capacity planning is challenging; this skill converts a use-case (daily ingest, retention, workload, premium apps, HA) into a concrete, ready-to-apply sizing plan.

Core Features & Use Cases

  • Renders a sizing report and a machine-readable sizing.json for all deployment targets (All-In-One, distributed, Kubernetes, and Cloud) based on user inputs.
  • Calculates indexer counts, search-head requirements, storage needs, and reference hardware tailored to premium apps (ES, ITSI) and multisite scenarios.
  • Provides hand-offs to the appropriate Splunk deployment skills to execute the sizing plan, including SVA mapping and topology.

Quick Start

Run the sizing script with your daily ingest, retention, and HA settings to generate a sizing report.

Frequently Asked Questions about splunk-platform-sizing

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I calculate Splunk indexer counts and storage for capacity planning?

Calculate Splunk indexer counts and storage by converting daily ingest, retention, and workload inputs into deployment recommendations. This sizing process generates a machine-readable sizing.json and a detailed report without requiring live Splunk access.

Can I size Splunk on Kubernetes deployments using daily ingest metrics?

Yes, you can size Splunk on Kubernetes deployments using daily ingest metrics. The sizing skill calculates requirements for both Splunk Operator for Kubernetes (SOK) and POD architectures, tailoring indexer counts and reference hardware to your workload.

What inputs do I need to generate a Splunk Cloud sizing recommendation?

To generate a Splunk Cloud sizing recommendation, you need daily ingest volume, data retention periods, workload types, and high availability (HA) settings. These inputs calculate effective ingest, search-head requirements, and reference hardware.

Does Splunk capacity planning support premium apps like ES and ITSI?

Splunk capacity planning supports premium apps like ES and ITSI by tailoring indexer counts, search-head requirements, and reference hardware to the specific workload demands of these applications during the sizing calculation.

What is the best way to plan a distributed Splunk Validated Architecture?

The best way to plan a distributed Splunk Validated Architecture is to map daily ingest and retention inputs to SVA topologies. This approach calculates multisite scenarios, storage needs, and deployment hand-offs without live Splunk access.

Do I need live Splunk access to size a deployment with this capacity planning tool?

No, you do not need live Splunk access to size a deployment. The capacity planning tool converts use-case inputs like daily ingest and retention into concrete deployment recommendations and topology hand-offs entirely offline.