i'm working with a costumer which wants to replace arcsight with splunk.
we're moving some systems from the arcsight and while we added "Fireglass" (by symantec) to monitoring we saw extreme growth in the license which almost caused to violations.
while digging in at the logs we saw that some sites, like youtube takes something like 1000 events for time frame of 1 minute. looking deeper i could see that all the video\audio traffic was sent as well. the customer told me that in Arcsight there's an option for "aggregation and filtration", which he can take the number of logs which are the same and merge them as one event, and ingest the whole traffic.
here's an explanation about the operation from the Arcsight side: