Splunk Search

Firewall logs ingest- What is causing spike in firewall data?

Akdollar
New Member

My organization has a 10G a day data ingest subscription with splunk. Recently, every Tuesday,  our firewall data ingest will spike sending us over the 10G limit. How can I find out what is causing this Tuesdays spike? Any suggestion will be appreciated. 

Tags (1)
0 Karma

skramp
SplunkTrust
SplunkTrust

You have to investigate your data. Compare your number of events (and length), compare events by loglevel/allowDeny, figure out if your  sending or receiving behaviour is different for some devices/IPs etc.

0 Karma
Get Updates on the Splunk Community!

Splunk Decoded: Service Maps vs Service Analyzer Tree View vs Flow Maps

It’s Monday morning, and your phone is buzzing with alert escalations – your customer-facing portal is running ...

What’s New in Splunk Observability – September 2025

What's NewWe are excited to announce the latest enhancements to Splunk Observability, designed to help ITOps ...

Fun with Regular Expression - multiples of nine

Fun with Regular Expression - multiples of nineThis challenge was first posted on Slack #regex channel ...