ℹ️ Preview calculator: calculation logic is still being verified. Output may not reflect realistic engineering values. Details

Network Forensics Storage Calculator

Calculate SIEM and network forensics storage requirements

Average number of log events ingested per second from all sources (firewalls, servers, endpoints, etc.).
EPS
Average size of a single log event. Syslog: ~200-500 bytes. JSON/structured: 500-2000 bytes. Full packet metadata: 1000-5000 bytes.
bytes
How long log data must be stored. Compliance requirements: PCI-DSS 1 year, HIPAA 6 years, SOX 7 years.
days
Log compression ratio. Typical: 5:1 to 10:1 for text logs. Enter the ratio (e.g., 5 means 5x compression).
:1

Results

Daily Raw Volume
Daily Compressed Volume
Total Compressed Storage
Indexing Overhead (20%)
Total Storage Required
Ingest RateMB/s
How it works: Daily volume = EPS × event_size × 86400 seconds. Compressed = raw / compression_ratio. Index overhead adds 20% for search indexes (Elasticsearch, Splunk). Total = (compressed × retention_days) × 1.20. Common compliance: PCI-DSS 1yr, HIPAA 6yr, SOX 7yr.