Skip to content
Notifications
Clear all

Sumo Logic or Splunk for mid-market finance? Real pricing feedback

1 Posts
1 Users
0 Reactions
24 Views
(@devops_shift_lead)
Honorable Member
Joined: 6 months ago
Posts: 443
Topic starter   [#17342]

We're evaluating a centralized logging and observability platform for our stack. Finance sector, mid-market, ~500 hosts, hybrid cloud (AWS + on-prem VMs). Compliance requirements (SOX, PCI) are non-negotiable.

Shortlist is down to Sumo Logic and Splunk. Vendor demos are one thing, but I need real-world operational and cost data from teams who've run both in production. The pricing models are opaque until you're deep in the process.

Our key needs:
* Ingest ~2 TB/day of logs (app, security, network)
* Need 90-day hot retention for audit trails
* Must have robust K8s monitoring (EKS)
* Strong alerting and dashboarding for incident response

I've seen the list prices. What I'm looking for is the *actual* gotchas:
* What does the real monthly bill look like after committed use discounts? Does one platform have more predictable billing?
* How painful is the data onboarding? We're looking at a mix of FluentBit, OpenTelemetry Collector, and some legacy syslog.
* Any major performance differences in querying large datasets or building real-time dashboards?
* For those who switched from one to the other, what was the operational impact?

I'll start with our initial PoC data for Sumo Logic. The per-GB ingestion model gets tricky fast when you factor in parsing and indexing overhead. Our test load of 100 GB/day of raw logs ballooned to ~135 GB/day of indexed data after they applied their parsing rules. That's a significant multiplier.

```json
// Example Sumo Logic collector JSON for a K8s source
{
"api.version": "v1",
"source": {
"sourceType": "DockerLog",
"automaticDateParsing": true,
"multilineProcessingEnabled": false,
"useAutolineMatching": true,
"forceTimeZone": false,
"category": "prod/eks/application"
}
}
```

Splunk's licensing seems more straightforward (per GB/day) but I've heard the infrastructure overhead for heavy forwarding and indexers is non-trivial. For those running Splunk Cloud, how has support been for scaling ingest or handling compliance requests?

No marketing fluff, please. Pipeline logs, config snippets, and actual cost per GB/month are what I need to see.

-shift


shift left or go home


   
Quote