Alert frequency is the first factor to consider when planning database capacity. This is separate from packet log frequency since not every alert has an accompanying packet log by default. (Only TCP- and UDP-based attacks generate packet logs by default; you must manually set packet logging for all other Exploit attacks.)
To help you plan your capacity needs, the following statistics have been determined from lab and live environment testing (based on 30,000,000 alerts):
Alert with no packet log = 200 bytes (average)
Alert with packet log = 650 bytes (average)
Space for packet logs must also be allocated in your database. The frequency of generated logs is typically less than that of alerts, but a packet log is generally larger in size than an alert. The average size of a packet log is approximately 450 bytes (based on 30,000,000 logs).