Getting Data In

Starting Splunk ES POV- Any advice?

cjharmening
Loves-to-Learn

Hello all, 

Starting end of next week my team will be doing a POV of Splunk ES as a possible replacement of our current SIEM.  We are looking at the cloud with workload pricing model.  

I am wondering if anyone can provide any tips or tricks related to doing a POV  of ES.  The sort of things you feel can be difficult or take time to complete, Monthly care and feeding of the Product that you and your team do.  How the Workload pricing actually computes in your environment ( example's say you have 100 SVG's and you send in 5 TB a day and do 1,000 searches...) .

I appreciate any insight anyone can provide.

 

Thank you 

 

Labels (1)
0 Karma
Get Updates on the Splunk Community!

SOC4Kafka - New Kafka Connector Powered by OpenTelemetry

The new SOC4Kafka connector, built on OpenTelemetry, enables the collection of Kafka messages and forwards ...

Your Voice Matters! Help Us Shape the New Splunk Lantern Experience

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Building Momentum: Splunk Developer Program at .conf25

At Splunk, developers are at the heart of innovation. That’s why this year at .conf25, we officially launched ...