Splunk Enterprise 9.2, sending OTLP through the collector. We just turned on LLM tracing for a couple of apps and the daily volume jumped way more than I estimated because the spans carry the full prompt and response text. Some of these events are huge. Right now everything lands in the same index as our regular APM traces with the generic OTLP sourcetype. Team is now asking questions about the prompt contents (customer data ends up in there) and I don't have a good answer. Is anyone splitting these out? And do you bother with a custom sourcetype or just filter on the gen_ai fields at search time? Trying not to redo this twice. Thanks in advance.
... View more