How to Use This Tool
Translate measured event size and burst rate into bandwidth, utilization and daily storage. Estimate syslog ingest bandwidth, processing utilization and daily storage from event rate, serialized bytes, burst and retention inputs.
The decision this tool supports
A pipeline can fit average daily storage while brief event bursts exceed parser or network capacity and create an unseen queue. This page keeps the decision bounded to peak input bandwidth and the supporting outputs shown beside it. Syslog Ingest Capacity does not import an account, infer a market rate, or silently substitute an industry average.
Inputs and units
The Syslog Ingest Capacity calculation uses Sustained events per second, Average serialized event size, Peak burst multiplier, Processor capacity, Retention duration. Keep all money values in one currency and all time, distance, mass, energy or volume entries in the unit printed beside the field. Mixing Syslog Ingest Capacity scopes can produce a plausible number with the wrong meaning.
- Sustained events per second is entered in events/s.
- Average serialized event size is entered in bytes.
- Peak burst multiplier is entered in times.
- Processor capacity is entered in events/s.
- Retention duration is entered in days.
Formula and worked check
Peak Mbps = sustained events/s × burst multiplier × serialized bytes/event × 8 ÷ 1,000,000; daily GB uses sustained rate × 86,400. Twenty thousand 900-byte events/s with a 2× burst require 288 Mbps and use 80% of a 50,000-event/s processor; raw daily volume is 1,555.2 GB. The Syslog Ingest Capacity default is an executable known-answer case, not a benchmark or recommendation. Change one input and verify that the direction of peak input bandwidth still matches the stated relationship.
How to interpret the result
Keep peak utilization below the team's chosen operating margin and add measured protocol, retry, indexing and replication overhead separately. The additional Syslog Ingest Capacity outputs expose the denominator, comparison, capacity or reverse value needed to audit the primary result instead of presenting one unexplained number.
Assumptions
- Average event bytes are measured after serialization.
- Burst multiplier applies to event rate, not size.
- Retention output is uncompressed raw ingest volume.
Save the Syslog Ingest Capacity input values and date with any material decision. A later Syslog Ingest Capacity rerun is reproducible only when the same assumptions and units are available.
Limitations and safety boundary
It excludes framing, TLS, batching, compression, parsing amplification, queue duration, indexing, replicas, sampling and event-size tails. Syslog Ingest Capacity is an estimate and cannot replace a contract, local code, licensed professional, calibrated measurement, lender statement or platform report where one governs the decision.
Source and privacy
The Syslog Ingest Capacity definition or rule was checked against OpenTelemetry — Logs data model on 2026-08-26. Recheck OpenTelemetry — Logs data model when a specification or policy behind Syslog Ingest Capacity can change. Syslog Ingest Capacity arithmetic runs in this browser tab; ecech does not receive the values through a calculation API.
Sources & assumptions
Tool Spec v2 · verified 2026-08-26. Platform rules and fees can change; the editable inputs remain authoritative for your account.
Official references
- OpenTelemetry — Logs data model (checked 2026-08-26)
Model assumptions
- Average event bytes are measured after serialization.
- Burst multiplier applies to event rate, not size.
- Retention output is uncompressed raw ingest volume.
- It excludes framing, TLS, batching, compression, parsing amplification, queue duration, indexing, replicas, sampling and event-size tails.
