Parameters — flow rate
220 B is what one record takes as uncompressed JSON, exactly as the sensor writes it to the spool.
Move this to see what share of the cap an outage that long would take.
How many packets one conversation shares on average before rotating. Lower it to simulate a scan or a flood.
Spool usage at the simulated outage HEALTHY
Realistic case
Time to fill the cap
Worst case — every packet a new flow
Time to fill the cap
Reference scenarios
| Scenario | New flows | GB/h | Coverage with 40 GB |
|---|
These are not measurements of any deployment: they are stated assumptions — 800 B packets, 20 packets per flow, 220 B per record — computed with the same formulas as this page. Press "use" to load one into flow-rate mode and adjust it.
The maths is simple and in plain sight: bytes per second = flows per second × bytes per record. What it does not model is compression at rest, nor how fast the collector drains the spool once it returns — which is why it gives the pessimistic case, the one worth sizing against.