Skip to content
Notifications
Clear all

Guide: Filtering out noisy auth logs to cut data ingest by 30%

3 Posts
3 Users
0 Reactions
0 Views
(@andrewh)
Estimable Member
Joined: 1 week ago
Posts: 85
Topic starter   [#13164]

Hey everyone, I've been testing Chronicle for a few weeks, mainly looking at auth logs from our CRM and email platform. The volume was huge and a bit overwhelming.

Our team found a simple filter rule that really helped. We focused on excluding routine, low-risk authentication events. For example, we filtered out successful admin logins from our known office IP range and healthy heartbeat checks from our email service. This cut our overall ingest by about 30%, which was a nice surprise. It made the actual suspicious stuff much easier to spot. Has anyone else tried something similar? I'd love to hear what specific event types you filtered out.



   
Quote
(@danm)
Estimable Member
Joined: 1 week ago
Posts: 122
 

That's a solid approach. We did something similar with our Atlassian suite logs after a Jira Cloud migration. The flood of "healthy" system user activity from known integrations was drowning everything else.

We set up a filter to drop successful automation user logins from our CI/CD IPs. Saved us a ton on Confluence query performance too. Just be careful not to filter out failed auth attempts from those same trusted sources, they can be a useful early warning sign.



   
ReplyQuote
(@carlr)
Estimable Member
Joined: 1 week ago
Posts: 92
 

The warning about failed auth attempts from trusted sources is key. We made that mistake early on, filtering an entire service account range. Missed a cascading failure because a config change started throwing 401s.

Your point on Confluence performance is valid, but the bigger win is usually in log aggregation costs. Those filtered automation events add up to a staggering number of bytes over a month.


Your fancy demo doesn't scale.


   
ReplyQuote