What you run · Splunk
Route before you index
Splunk is the SIEM most SOCs grew up in: a Universal Forwarder on every host, Heavy Forwarders parsing and routing in the middle, indexers storing what arrives, and search heads where the detections live as correlation searches over CIM-normalized data models. It is licensed by the GB per day that crosses into the indexers, and only that meter counts. We keep the detections your SOC trusts, govern what enters that per-GB index, and land everything else in full-fidelity storage you own.
01Today
How a Splunk estate looks today
A Splunk estate pays per GB at the indexer door for everything it keeps, and what never earns that price is simply never collected.
What Splunk does best
Splunk is the most mature detection estate in the industry. The search language is unmatched for investigation, the app and TA ecosystem covers almost every source that exists, and your SOC has years of muscle memory, saved searches, and tuned detections living in it. That is real value, and ripping it out would burn it.
The pressure is the meter, not the platform. Splunk licenses by daily GB ingested, and renewal uplift commonly runs around 9% a year, so a contract grows even when you add no new sources. Most of that volume earns nothing: firewall allow logs are typically 60-70% of Splunk ingest and almost nobody searches them, and duplicate events commonly account for 30-50% of what gets indexed.
02The five verbs
What we do to a Splunk estate
Keep it and govern what flows in, shrink its footprint, cut what it costs, extend it with an agent, and replace only where replacement is honest.
The detections, the saved searches, the correlation searches, and the estate your SOC knows by heart. Nothing about how your team works in Splunk changes, and nothing they built there is thrown away.
Firewall allow logs, debug output, and duplicates route to full-fidelity open-format storage instead of the per-GB index, and stay replayable.
The renewal uplift then applies to a much smaller base, and the reduction is proven source by source rather than promised, with the before and after measured in writing on your own top talkers.
An agent you own investigates the alerts Splunk fires, reading enriched history from the Lake beside it.
Never. Splunk is a SIEM and we sit in front of SIEMs, not in place of them. If you ever choose to leave, the exit is a parallel run and a routing change, and the choice stays yours.
The letters mark where each verb acts in the drawing above
03The approach
How the control layer changes the Splunk math
A control layer in front of Splunk inspects every event in flight, keeps a full-fidelity copy in cheap open-format storage, and forwards only high-value data into the per-GB index.
We work at config level: forwarders and inputs, props and transforms, CIM alignment. Normalization moves upstream into the control layer, so parsing logic is maintained once instead of per source inside Splunk. Nothing is dropped silently, and the filtered copy stays queryable for investigation, audit, and compliance.
When the day comes to evaluate an alternative, the same layer runs Splunk and a candidate platform in parallel on live data, so the decision is made on evidence and the cutover is a routing change.
04Questions
Asked about Splunk estates
Does reducing Splunk ingest mean losing data?
No. Reduction is a routing decision, not deletion. Everything lands in full-fidelity open-format storage you own, and any of it replays into Splunk or any other destination when an investigation or audit wants it. What changes is what pays analytics-tier pricing.
Will our detections break?
The routing split is designed against your detection set: high-value security events keep flowing to Splunk unchanged, and every change is validated with your rules firing on real data before it ships. Detections keep their inputs, on a fraction of the volume.
Do you migrate teams off Splunk?
Only when you choose to go, and honestly when you ask. The control layer runs old and new platforms in parallel on the same routed feed, so a migration becomes proof first, cutover second. Until then, the same layer makes staying dramatically cheaper.
Start with the review
You share your diagrams, we review them with you, and you leave with your version of the Logmetry Blueprint drawn on your Splunk estate. No system access, no obligation.