Knowledge Management

How to avoid logs sizing & prioritizing without violating the license?

ghassentr
Engager

Hello,
We have installed the splunk’s siem locally in our infrastructure. Now, we are faced with a problem of logs sizing collected from network equipment and systems (AD / ASA / web server / IPS / IDS/ router ...) and log prioritization by platform (Unix systems/ Windows system/ Cisco systems).
Can you please give us, for example, the results of your expertise regarding the log sizing (example: AD generates x EPS / ASA generates y EPS ...) and the methodology of its prioritizing in order to
to avoid license violation?
Looking forward to your reply, I remain at your disposal for further information.
Thanks

0 Karma

horsefez
SplunkTrust
SplunkTrust

You could get in touch with the splunk guys in your area and ask them for a "data source assessment" (DSA)
They can give you a pretty good idea about what to expect from those log sources regarding the size and quantity of the events.

0 Karma

DalJeanis
SplunkTrust
SplunkTrust

That really is going to depend on your use case, and what kind of logging you find useful. Windows machine logs tend to be very chatty, so much of the logging either gets turned off at the machine, or blacklisted before indexing. YOu need to think in terms of "what do you absolutely want to retain, what do you prefer to retain, and what is absolute garbage?"

0 Karma
Get Updates on the Splunk Community!

What's new in Splunk Cloud Platform 9.1.2312?

Hi Splunky people! We are excited to share the newest updates in Splunk Cloud Platform 9.1.2312! Analysts can ...

What’s New in Splunk Security Essentials 3.8.0?

Splunk Security Essentials (SSE) is an app that can amplify the power of your existing Splunk Cloud Platform, ...

Let’s Get You Certified – Vegas-Style at .conf24

Are you ready to level up your Splunk game? Then, let’s get you certified live at .conf24 – our annual user ...