Skip to content
Logmetry

Route before you index

Splunk is the SIEM most SOCs grew up in: a Universal Forwarder on every host, Heavy Forwarders parsing and routing in the middle, indexers storing what arrives, and search heads where the detections live as correlation searches over CIM-normalized data models. It is licensed by the GB per day that crosses into the indexers, and only that meter counts. We keep the detections your SOC trusts, govern what enters that per-GB index, and land everything else in full-fidelity storage you own.

How a Splunk estate looks today

A Splunk estate pays per GB at the indexer door for everything it keeps, and what never earns that price is simply never collected.

How a Splunk estate looks todaySplunk universal forwarders on every host and network devices feed heavy forwarders, which send everything into the indexers, where the licence meters every GB per day on entry. Search heads and your detections read the index. Most of the telemetry the estate produces is sampled, dropped, or never collected, because keeping it at per-GB prices never earned a business case.YOUR ESTATEServers, VMs, containersUNIVERSAL FORWARDERSSplunk's agent, one per hostNetwork and syslog devicesMost of itSAMPLED, DROPPED,OR NEVER COLLECTEDAll of itHEAVY FORWARDERSParsing and routing,before the meterPER GB, PER DAYSPLUNKLicensed by daily ingest, on entryINDEXERSThe licensed tierSEARCH HEADSYour SOC's detectionsand saved searchesWHAT YOU PAY FOREvery GB entering the indexis licensed, searched or not.Firewall allow logs alone aretypically 60-70% of Splunkingest.Renewal uplift compoundson the whole base.What was never collectedcannot be investigated.
How a Splunk estate looks today. Every GB crossing into the indexers is licensed on entry, searched or not, and what never earned the per-GB price was simply never collected.

What Splunk does best

Splunk is the most mature detection estate in the industry. The search language is unmatched for investigation, the app and TA ecosystem covers almost every source that exists, and your SOC has years of muscle memory, saved searches, and tuned detections living in it. That is real value, and ripping it out would burn it.

The pressure is the meter, not the platform. Splunk licenses by daily GB ingested, and renewal uplift commonly runs around 9% a year, so a contract grows even when you add no new sources. Most of that volume earns nothing: firewall allow logs are typically 60-70% of Splunk ingest and almost nobody searches them, and duplicate events commonly account for 30-50% of what gets indexed.

What we do to a Splunk estate

Keep it and govern what flows in, shrink its footprint, cut what it costs, extend it with an agent, and replace only where replacement is honest.

The Logmetry Blueprint applied to a Splunk estateThe same estate and forwarders now feed a control layer you own. It lands everything, enriched and at full fidelity, in a lake in your own storage, and forwards only what earns the index into a smaller Splunk, metered per GB on a fraction of the volume. Search heads and detections are unchanged. An agent you own picks up each alert Splunk fires and investigates it against the Lake. Pins mark the five verbs: replace on the control layer, cut on the meter, shrink on the indexers, keep on the search heads, extend on the agent.YOUR ESTATEServers, VMs, containersUNIVERSAL FORWARDERSKept. Tuned at config levelNetwork and syslog devicesAll of itYOUR GROUNDTHE CONTROL LAYERParsed, enriched,reduced, routedAs code, in your reposREverything, full fidelityTHE LAKE, YOURSPER GB, PER DAYOnly what earns the indexCSPLUNKKept, smaller, unchanged for your SOCINDEXERSSSEARCH HEADSDetections unchangedKThe alertYOUR AGENTRuns your runbooks,on models you swapEIt queries your historyWHAT CHANGEDThe meter bills a fraction,detections keep their inputs.Full history lands in storageyou own, replayable on demand.Leaving, if ever, is a routingchange, not a rebuild.
The Logmetry Blueprint applied. The control layer keeps a full-fidelity copy in a Lake you own and forwards only high-value data into the index. The pins mark where each of the five verbs acts.
KKeep

The detections, the saved searches, the correlation searches, and the estate your SOC knows by heart. Nothing about how your team works in Splunk changes, and nothing they built there is thrown away.

SShrink

Firewall allow logs, debug output, and duplicates route to full-fidelity open-format storage instead of the per-GB index, and stay replayable.

CCut

The renewal uplift then applies to a much smaller base, and the reduction is proven source by source rather than promised, with the before and after measured in writing on your own top talkers.

EExtend

An agent you own investigates the alerts Splunk fires, reading enriched history from the Lake beside it.

RReplace

Never. Splunk is a SIEM and we sit in front of SIEMs, not in place of them. If you ever choose to leave, the exit is a parallel run and a routing change, and the choice stays yours.

The letters mark where each verb acts in the drawing above

How the control layer changes the Splunk math

A control layer in front of Splunk inspects every event in flight, keeps a full-fidelity copy in cheap open-format storage, and forwards only high-value data into the per-GB index.

We work at config level: forwarders and inputs, props and transforms, CIM alignment. Normalization moves upstream into the control layer, so parsing logic is maintained once instead of per source inside Splunk. Nothing is dropped silently, and the filtered copy stays queryable for investigation, audit, and compliance.

When the day comes to evaluate an alternative, the same layer runs Splunk and a candidate platform in parallel on live data, so the decision is made on evidence and the cutover is a routing change.

Asked about Splunk estates

Does reducing Splunk ingest mean losing data?

No. Reduction is a routing decision, not deletion. Everything lands in full-fidelity open-format storage you own, and any of it replays into Splunk or any other destination when an investigation or audit wants it. What changes is what pays analytics-tier pricing.

Will our detections break?

The routing split is designed against your detection set: high-value security events keep flowing to Splunk unchanged, and every change is validated with your rules firing on real data before it ships. Detections keep their inputs, on a fraction of the volume.

Do you migrate teams off Splunk?

Only when you choose to go, and honestly when you ask. The control layer runs old and new platforms in parallel on the same routed feed, so a migration becomes proof first, cutover second. Until then, the same layer makes staying dramatically cheaper.

Start with the review

You share your diagrams, we review them with you, and you leave with your version of the Logmetry Blueprint drawn on your Splunk estate. No system access, no obligation.