Just finished a 3-year Splunk ES run for a ~500 person tech company. The sticker price is one thing, but the operational costs can really sneak up on you.
Beyond the core license, watch out for:
* **Professional Services:** Almost mandatory for initial deployment and major upgrades. That's a six-figure line item.
* **App/Add-on Costs:** Need specific data sources (cloud, network, endpoint)? Many require separate paid apps or TA purchases.
* **Storage & Ingestion Overages:** This is the big one. ES searches are heavy. Your data volume will balloon, leading to constant cost monitoring and painful "right-sizing" meetings.
* **Expertise Tax:** Hiring or training analysts/engineers who know SPL and ES's specific data model isn't cheap.
Would love to compare notes with others in a similar boat. What was the biggest hidden cost driver for you? Staffing? The infrastructure to run it?
data over opinions
That "expertise tax" hit us hard too. We built a team around it, and then when Splunk raised prices, we couldn't justify keeping those specialized roles. So the hidden cost became severance packages, honestly.
Did you feel locked in because of that specific SPL knowledge? Was it hard to even evaluate alternatives after investing so much in training?