NetFlow Storage Calculator for Home Labs

August 17, 2026

NetFlow and IPFIX Sizing

NetFlow Storage Calculator

Estimate daily flow-log volume, retained disk footprint, write rate, and collector headroom from exporters, flow rate, record size, sampling, compression, and retention.

▣NetFlow/logging presets

⚙Flow collection inputs

Routers, firewalls, switches, AP controllers, or hypervisors.
Use emitted records after device sampling.
NetFlow v5 is small; IPFIX with fields is larger.
Used for original traffic estimate; storage uses emitted flows.
Hot searchable data kept on the collector.
Compression after parser/index overhead.
Metadata, time index, tags, and collector fields.
Used for headroom, reserve, and practical write target.
Stored per day
0 GB
after overhead and compression
Daily searchable flow-log growth.
Retention footprint
0 GB
including collector reserve
Disk target for the selected retention window.
Ingest write rate
0 MB/s
pre-compression data stream
Burst storage should exceed this comfortably.
Collector headroom
0%
versus selected profile FPS
Capacity remaining after current flow load.

Full breakdown

Total emitted flow rate0 flows/sec
Estimated original flow activity0 flows/sec
Raw NetFlow/IPFIX per day0 GB/day
After index/parser overhead0 GB/day
Compression factor applied0x
Retention window0 days
Collector reserve added0 GB
Selected collector limit0 flows/sec
Per-device daily average0 GB/day
Suggested disk classSSD
Enter your flow profile and calculate to size collector storage.

▦Equipment/spec comparison grid

Embedded Router Log Disk

1.5k
flows/sec target

Good for low-rate raw exports or short diagnostic windows on appliance storage.

Raspberry Pi 5 + SSD

6k
flows/sec target

Works well for nfdump, pmacct, or light ClickHouse with USB SSD storage.

Mini PC NVMe Collector

25k
flows/sec target

Balanced home lab target for VLAN labs, firewall telemetry, and month-long search.

NAS VM on HDD Pool

12k
flows/sec target

Fine for compressed retention, but random search can be slower on shared disks.

NUC Search Stack

50k
flows/sec target

Useful for enriched fields, dashboards, and frequent queries over recent data.

1U Xeon Collector

120k
flows/sec target

Comfortable for sampled 10G cores, multiple exporters, and heavier indexing.

Cloud VM Standard Disk

30k
flows/sec target

Easy for remote access, but watch sustained write limits and egress-heavy queries.

Object Archive Tier

8k
flows/sec target

Best for compressed long retention after hot data rolls off the collector.

ℹRecord and sampling reference

Flow sourceTypical emitted FPSAverage record sizeStorage note
Home NAT gateway25 to 80 flows/sec80 to 140 bytesUsually safe unsampled with short retention.
Stateful firewall with VLANs150 to 600 flows/sec120 to 180 bytesIndex overhead matters when tagging interfaces and zones.
Virtualization host or vSwitch250 to 1,200 flows/sec120 to 200 bytesEast-west traffic can raise flow rate without raising WAN use.
10G switch core1,000 to 8,000 flows/sec140 to 220 bytesSampling is common when bursts are frequent.
Sampled edge export100 to 2,000 emitted flows/sec120 to 200 bytesDisk stores sampled records; traffic estimate scales by sample ratio.

🗄Collector profile table

Collector profileFlow ingest targetReserve addedPractical disk class
Embedded Router Log Disk1,500 flows/sec5 GBAppliance flash or small SSD
Raspberry Pi 5 + SSD6,000 flows/sec15 GBUSB 3 SSD
Mini PC NVMe Collector25,000 flows/sec50 GBNVMe SSD
NAS VM on HDD Pool12,000 flows/sec80 GBNAS pool with SSD cache
NUC Search Stack50,000 flows/sec120 GBNVMe SSD, preferably mirrored
1U Xeon Collector120,000 flows/sec250 GBEnterprise SSD or NVMe

⏱Retention and compression guide

Use caseRetention windowCompression targetComment
Troubleshooting only7 to 14 days1.5x to 2.5xPrioritize recent query speed over deep history.
Home lab trend review30 days2.5x to 4xGood balance for dashboards and anomaly checks.
Security investigation60 to 90 days2.5x to 4xLeave headroom for extra tags and enrichment.
Long archive180 days or more4x to 6xMove older segments to compressed object or NAS storage.

⚖Common project sizes

ProjectExporter countStarting FPSSuggested collector
Single home router125 to 80 per deviceEmbedded disk or Pi + SSD
Firewall plus managed switch2 to 3100 to 250 per devicePi + SSD or mini PC
Proxmox and NAS lab4 to 6250 to 900 per deviceMini PC NVMe collector
Sampled 10G core2 to 51,000 to 5,000 emitted per deviceNUC search stack or 1U collector

✔Storage sizing tips

Size for emitted records first. Sampling reduces the records written to disk. The calculator still shows estimated original activity so you can explain what a 1:100 export represents.
Keep hot and cold data separate. Use fast local SSD or NVMe for searchable recent flow logs, then roll older compressed files to NAS or object storage when query speed matters less.

NetFlow, sFlow, and IPFIX collectors vary by parser, fields, tags, and database engine. Treat the result as a sizing target, then validate with a day of real exports before committing long retention.

NetFlow shows what passes through your network and where it goes. If something doesn’t look right you collect some Netflow data. Seems easy enough, right? Until you get a storage drive hooked up, and after three days its filled up.

Often the problem isn’t with the data so much as it is failing to consider hidden multipliers which can cause even a modest flow rate to become a storage issue. Flow logs are treated by most home lab enthusiasts as static text file. They’re not static files. They are a dynamic record that expands based on both tags applied and fields enabled.

How to Plan Your Network Storage

To understand how it works, isolate the variables. On one side, you’ve got your flows per second coming out of each exporter (the device from which data originates). Then there’s the size of the records flowing out. Depending on if you’re using old NetFlow v5 format, or the newer, more moddern IPFIX format, this will vary widely. And finally, you have the collectors receiving the data. How much flow per second are you getting? Where are they located? Do you have a redundant site?

The page calculates answer for you. It takes all of this as input. Along with retention times and compression ratios, and spits out a real-world disk requirement. But unless you know what drives those inputs, you won’t understand the math. You shouldn’t trust the answer blindly.

After all, sampling isn’t simply a number; it’s a tradeoff. If you sample at 1:1, then you capture everything but you’ll overwhelm a low-end collector. Sample at 1:100 and you save disk space but risk missing brief connection that signals an intrusion attempt. You need to know what kind of truth you want based off your own specific use case.

Another source of confusion is compression. Many people think it saves space linearly. In fact, it’s impossible to compress flow data until it has been indexed. First the collector has to go through the records and add some metadata to them. Then it creates indexes for searching.

That’s called index overhead. It’s the silent killer when you plan for storage. You will likely ignore it, size your drive by raw bytes, and find yourself 30 percent short in a week. The page has a reference table laying it out. It shows how different collector profiles takes into account this metadata burden.

Light logging can be handled by a Raspberry Pi, but try to add lots of heavy indexing and it will go to a crawl. You have to balance the price of storing the data versus the speed of retrieving it. Spinning disks is terrible at random I/O, so frequent queries require fast NVMe drives. However, without rotating out old data, those same NVMe drives will run out of capacity much quicker.

How long you want to retain data also determines how much you’ll spend on hardware. To troubleshoot recent problems, thirty days of data is often good enough while still not too costly. If you need to extend that to ninety days or longer, you’ll need a multi-level solution. Hot data will remain on fast local storage so it’s immediately accessible. Cold data will get migrated to lower-cost, slower media where it can remain compressed and mostly unaccessed. Two years of searchable flow logs stored on a single consumer-grade SSD isn’t just expensive; it’s a recipe for poor performance and premature drive death.

Consumer SSDs has limited write endurance, and flow logging is a constant, relentless write operation.

And then there’s the issue of collector headroom. Don’t ever size your collector to run at maximum capacity. Flow rates can increase dramatically during a software update, or backup window. Your collector will drop packets if it’s already maxed out and dropped flows are worse than no flows. They leave holes in your timeline making forensic analysis pretty much impossible. Having 25% or more headroom guarantees that transient spikes won’t ruin your data integrity. A little bit of buffer buys you a lot of peace of mind.

How complex do you want to get? That’s where the collector profile matters. If you’re OK with relatively basic queries, then sticking something together on a Raspberry Pi like nfdump is low maintenance and will get the job done. But you don’t have many bells and whistles there (for example, you can’t really search). If you need rich search functionality, something like an Elasticsearch based stack running on a NUC requires more configuration as well as more resources.

Ultimately, the tool will help guide you towards matching your expected flow rate with a corresponding class of hardware. However, it won’t make that decision for you. Do you care about real time anomaly detection? Or are you only interested in having a historical record that you can go back and look at following an incident?

Ultimately, it’s all about setting your expectations around storage size. No unlimited everything for free, got it? Pick two: unlimited resolution or unlimited retention or zero cost.

Start with a minimal viable data set, see what your real growth looks like in a week, and add more as needed. Better to add drives when you need them rather than starting with a choking system from day one. Aim to provide sustainable visibility, not a full hard drive. Keep your headroom generous, your cold data cheap, and your hot data fast. That’ll keep the logs flowing and the lights on.

NetFlow Storage Calculator for Home Labs

Related posts

Leave a Comment