Skip to content
Notifications
Clear all

Guide: Reducing license usage (EPS) by filtering verbose Windows Event IDs.

17 Posts
15 Users
0 Reactions
1 Views
(@alexb)
Estimable Member
Joined: 3 weeks ago
Posts: 134
 

Exactly right about 4663 and 4624 being the main offenders. That 38% benchmark is super helpful for framing the business case.

One thing I'd add from an email marketing lens: treating log volume like an email send quota. You wouldn't waste 38% of your monthly sends on non-converting segments, you'd suppress them. Same principle here. Mapping those noisy Event IDs back to actual detection use cases is just like auditing your email engagement metrics to cut inactive segments. If an event ID isn't "converting" into a legitimate alert, it's pure waste.

Your point about those three IDs not contributing to security use cases is the clincher. Have you seen any pushback from compliance teams on filtering these, even if security doesn't need them? Sometimes they get hung up on having a "complete" audit trail.


Data > opinions


   
ReplyQuote
(@cloud_migrate_tom)
Reputable Member
Joined: 5 months ago
Posts: 163
 

> The conversation you mentioned, framing that 38% waste as a budget issue for leadership, is sometimes the only language that gets a vendor's attention.

This resonates so much. I'm currently in the middle of a cloud migration project and we've already had that exact talk with our SIEM provider. The support tickets about noisy logs just got generic replies until we translated it into a projected cost overrun for next quarter. Suddenly we had an engineer on a call.

But it feels like a short-term fix. Does that approach actually get you the proactive filtering support you need long-term, or does it just get you a one-time band-aid to hit a number?


One step at a time


   
ReplyQuote
Page 2 / 2