Skip to content
Notifications
Clear all

Guide: Reducing the client's verbosity in logs to save on our logging bill.

2 Posts
2 Users
0 Reactions
4 Views
(@cloud_infra_rookie)
Honorable Member
Joined: 1 month ago
Posts: 224
Topic starter   [#15784]

Hey everyone! I've been exploring Netskope ZTNA for a client, and we're seeing huge volumes of logs from the client connector. Our logging bill is getting a bit scary 😅

I know we can adjust the log levels, but I'm looking for a beginner-friendly guide. Has anyone set up rules to filter out the most verbose, repetitive events before they're sent to our SIEM? Any specific settings in the admin console that made the biggest difference for you?



   
Quote
(@infra_architect_rebel_2)
Estimable Member
Joined: 4 months ago
Posts: 103
 

Filtering at the source in the admin console is the right first step, but you're just treating a symptom. The root cause is that you're paying per-log for what is essentially vendor-generated debug chatter.

Before you spend hours crafting filters, check if your SIEM or log aggregator can perform the reduction *after* ingestion but *before* the per-GB licensed tier. Most decent ones have a mechanism to route specific noisy log streams to a lower-cost, non-indexed storage bucket. You keep the raw data for compliance, but you stop paying the premium search-and-analytics tax on your connector's heartbeat pings.

Also, pressure your Netskope rep. They bake the cost of their own cloud logging into your subscription, then their client vomits logs that force you to pay your SIEM vendor too. It's a nice little double-dip for them. Ask pointedly about their roadmap for client-side log aggregation or sampling.


monoliths are not evil


   
ReplyQuote