As an add-on to Splunk uberAgent cannot be used without a Splunk license. Splunk is licensed by daily indexed traffic, i.e. you pay for the total amount of data you send to Splunk per day. How long that data is stored does not matter, only how much new data you add. uberAgent is one of potentially many data sources that put data into Splunk, contributing to the total data volume.
Estimate or Measure?
Customers have a vested interest in knowing how much data each Splunk add-on generates so they can estimate costs before they buy. In the case of uberAgent the data volume per host depends greatly on the environment, the types of applications used, the desktop configuration, background processes, type of browser used and many other variables. For that reason it is not possible to calculate the data volume with any reasonable accuracy without doing an actual proof of concept implementation (see below). However, if you just want some figures for a very rough first calculation use the following values for typical clients and servers:
- Typical data volume per single-user client and day: 15 MB
- Typical data volume per multi-user RDS/XenApp server and day: 65 MB
To get accurate numbers install uberAgent and go to the Data Volume dashboard (see below). You can significantly reduce the data through optimized configuration.
Data Volume Dashboard
If you already have uberAgent installed, you can simply look up the data volume generated by going to the Data Volume dashboard:
Make sure you have configured Splunk correctly or the data volume dashboard may not be able to display values for all metrics.
Reducing the Data Volume
Once you have your first installation set up you might want to fine-tune and possibly reduce the data volume. Luckily that is easily possible. Here is how to reduce uberAgent’s data volume.
Do you have questions that were not answered here? Please ask us, we are happy to help!