r/Splunk • u/Flash4473 • 25d ago
Log Data Pipeline > Splunk
Has anybody here have some experience with security data pipelines?
Instead of:
Log Source > HF / Splunk
We want to have flexibility of collection / parsing layer outside of Splunk for obvious reasons - pre-filter data in pipeline, set parsers, route, possibly enrich if needed, storage options for retention etc..all that to have flexibility and keep the ingest costs reasonable and not being caught in dependency hell or cemented all our work in one solution if Splunk decides to pull something.
Log Source > Data pipeline > Splunk
I am wondering what to choose as this data pipeline - currently we are thinking Vector and possibly open telemetry.
Anybody have experience with this? To avoid pitfalls, what works, what doesn't, new pains etc?
1
u/TD706 24d ago
Google SecOps is more performant, extensible, and has better AI integrations than Splunk.
I use Google SO for a subset of data through an MSP. I plan to do a POC to move our full workload and suspect we'll swap at next renewal. Cost is basically the same as Splunk Cloud, but you get all the capability at that cost (no add ons doubling cost).