Knowledge Management

How to avoid logs sizing & prioritizing without violating the license?

ghassentr
Engager

Hello,
We have installed the splunk’s siem locally in our infrastructure. Now, we are faced with a problem of logs sizing collected from network equipment and systems (AD / ASA / web server / IPS / IDS/ router ...) and log prioritization by platform (Unix systems/ Windows system/ Cisco systems).
Can you please give us, for example, the results of your expertise regarding the log sizing (example: AD generates x EPS / ASA generates y EPS ...) and the methodology of its prioritizing in order to
to avoid license violation?
Looking forward to your reply, I remain at your disposal for further information.
Thanks

0 Karma

horsefez
Motivator

You could get in touch with the splunk guys in your area and ask them for a "data source assessment" (DSA)
They can give you a pretty good idea about what to expect from those log sources regarding the size and quantity of the events.

0 Karma

DalJeanis
Legend

That really is going to depend on your use case, and what kind of logging you find useful. Windows machine logs tend to be very chatty, so much of the logging either gets turned off at the machine, or blacklisted before indexing. YOu need to think in terms of "what do you absolutely want to retain, what do you prefer to retain, and what is absolute garbage?"

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Index This | What travels the world but is also stuck in place?

April 2026 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Discover New Use Cases: Unlock Greater Value from Your Existing Splunk Data

Realizing the full potential of your Splunk investment requires more than just understanding current usage; it ...

Continue Your Journey: Join Session 2 of the Data Management and Federation Bootcamp ...

As data volumes continue to grow and environments become more distributed, managing and optimizing data ...