Knowledge Management

How to avoid logs sizing & prioritizing without violating the license?

ghassentr
Engager

Hello,
We have installed the splunk’s siem locally in our infrastructure. Now, we are faced with a problem of logs sizing collected from network equipment and systems (AD / ASA / web server / IPS / IDS/ router ...) and log prioritization by platform (Unix systems/ Windows system/ Cisco systems).
Can you please give us, for example, the results of your expertise regarding the log sizing (example: AD generates x EPS / ASA generates y EPS ...) and the methodology of its prioritizing in order to
to avoid license violation?
Looking forward to your reply, I remain at your disposal for further information.
Thanks

0 Karma

horsefez
SplunkTrust
SplunkTrust

You could get in touch with the splunk guys in your area and ask them for a "data source assessment" (DSA)
They can give you a pretty good idea about what to expect from those log sources regarding the size and quantity of the events.

0 Karma

DalJeanis
SplunkTrust
SplunkTrust

That really is going to depend on your use case, and what kind of logging you find useful. Windows machine logs tend to be very chatty, so much of the logging either gets turned off at the machine, or blacklisted before indexing. YOu need to think in terms of "what do you absolutely want to retain, what do you prefer to retain, and what is absolute garbage?"

0 Karma
Get Updates on the Splunk Community!

Welcome to the Splunk Community!

(view in My Videos) We're so glad you're here! The Splunk Community is place to connect, learn, give back, and ...

Tech Talk | Elevating Digital Service Excellence: The Synergy of Splunk RUM & APM

Elevating Digital Service Excellence: The Synergy of Real User Monitoring and Application Performance ...

Adoption of RUM and APM at Splunk

    Unleash the power of Splunk Observability   Watch Now In this can't miss Tech Talk! The Splunk Growth ...