Hi Zate,
Bro compresses its log files using gzip, so you can get the
uncompressed size of the log files using "gzip -l". A little bash-fu
will give you a nice listing of each day in the /nsm/bro/logs/ archive
and their uncompressed sizes:
cd /nsm/bro/logs/; for i in ????-??-??; do cd $i; echo -n "$i - ";
gzip -l *.log.gz | grep "(totals)" | awk '{print $2}'; cd ..; done
Having said that, keep in mind that ELSA can save you a lot of money
in Splunk licensing costs. If you have any questions about ELSA,
please let us know!
Thanks,
Doug
On Tue, Apr 30, 2013 at 2:08 PM, Zate <
zat...@gmail.com> wrote:
> Any way to get an indication of how much data you'd be sending to splunk? To know what size license to look at?
>
> I was considering just putting the Bro logs in there and the splunk alerts.
>
> I know the amount will differ for everyone, what I am after is some commands or ways to look on my install and see how much data I am generating roughly per 24h period that would go into splunk.
Doug Burks
http://securityonion.blogspot.com