Notifications
Clear all
Topic starter
18/07/2026 5:42 am
Hi everyone. I've been evaluating Chronicle for our containerized environments and was surprised by the bill after ingesting all our verbose debug logs. 😅
A more experienced colleague suggested sampling these logs before they're sent. The idea is to only ingest a small percentage (like 1-5%) of debug-level entries, while keeping 100% of errors and warnings. This cut our volume dramatically. We use a simple fluentd filter to do this before the logs leave our Kubernetes cluster.
Has anyone else tried a similar approach? I'd be grateful for any tips on setting up a reliable sampling filter or other cost-saving strategies you've found useful. Thanks in advance for your insights.