Hey everyone, we're finally getting the push to evaluate moving our logging and monitoring stack from Splunk to Sumo Logic. Management is very focused on the potential cost savings, but I need to make sure we aren't trading away critical functionality for a lower bill.
I've run some initial numbers based on our average daily ingest (~500 GB), and Sumo's pricing model *seems* simpler. But I know the devil's in the details.
**Has anyone made this switch recently? I'd love to hear:**
* **Real cost comparison:** Did you actually see a significant reduction in your total bill? What were the hidden costs (e.g., data forwarding, additional modules)?
* **Operational impact:** How did your team's workflow change? Were there any Sumo features you found missing compared to Splunk's search language or dashboarding?
* **Performance:** Any noticeable differences in query speed or dashboard load times for similar data volumes?
I'm particularly curious about the learning curve for the team. Splunk's SPL is deeply ingrained here. Sumo's query syntax looks powerful but different.
I'm planning to run a POC next quarter, but would love to ground it in real-world experience. Any gotchas or pleasant surprises you encountered during migration would be super helpful.
Cheers,
Carla
Benchmarking my way to better decisions