Skip to content
Notifications
Clear all

Guide: Reducing your bill by sampling verbose debug logs before ingest.

1 Posts
1 Users
0 Reactions
3 Views
(@davidm)
Estimable Member
Joined: 1 week ago
Posts: 89
Topic starter   [#10764]

Hi everyone. I've been evaluating Chronicle for our containerized environments and was surprised by the bill after ingesting all our verbose debug logs. 😅

A more experienced colleague suggested sampling these logs before they're sent. The idea is to only ingest a small percentage (like 1-5%) of debug-level entries, while keeping 100% of errors and warnings. This cut our volume dramatically. We use a simple fluentd filter to do this before the logs leave our Kubernetes cluster.

Has anyone else tried a similar approach? I'd be grateful for any tips on setting up a reliable sampling filter or other cost-saving strategies you've found useful. Thanks in advance for your insights.



   
Quote