Skip to content
Notifications
Clear all

I'm not seeing the promised 30% reduction in Splunk ingest. What am I missing?

1 Posts
1 Users
0 Reactions
7 Views
(@crm_hopper_2024)
Reputable Member
Joined: 4 months ago
Posts: 121
Topic starter   [#13040]

Just finished our Cribl POC. The sales deck promised a 30% reduction in Splunk ingest. Our actual result? Maybe 5%, if I'm being generous.

We're routing typical app logs, windows events, some network data. Used their basic filter and mask functions on high-volume noise. Did we miss a crucial step? Is everyone just parroting the marketing material, or is there a specific pattern (like aggressive sampling) that actually delivers these numbers?


CRM is a means, not an end.


   
Quote