The Splunk renewal came in at $3.7M. For context, that was more than they spent on their core banking middleware. The problem wasn't Splunk - it was that 73% of what they were ingesting was debug logs and health checks.
Regional Bank (Top 25 US)
Financial Services - Enterprise IT
Observability Cost Optimization & Security Event Processing
Expanso
Pilot in 4 weeks, full rollout in 9 weeks
$2.3M annual savings (7-month payback)
Every December, the Splunk renewal triggered the same conversation: why is this so expensive? The infrastructure team knew the answer - 73% of what they ingested was noise. But they didn't have a way to filter it without building custom solutions for each of their 247 log sources.
We deployed Expanso collectors at each major log source. The collectors classify logs on arrival - debug gets dropped, security events get priority, PII gets masked. Splunk only ingests what someone might actually look at.
Each log line gets classified on arrival. DEBUG and TRACE drop immediately. INFO aggregates into hourly summaries. WARN, ERROR, and security events forward in real-time. Simple rules, massive reduction.
Credit card numbers, SSNs, and account IDs get masked before logs leave the source server. No PII ever reaches Splunk. GDPR and PCI auditors stopped asking questions.
Authentication failures, privilege escalations, and anomaly patterns get extracted and enriched before forwarding. Security team gets structured events, not grep sessions.
The next Splunk renewal came in at $1.4M. Security team response time improved because they weren't searching through terabytes of health checks. The CFO stopped asking about observability costs.
"I used to spend half my day searching for the needle. Now the needle comes to me and the haystack stays in the barn. Also my CFO stopped asking me to explain why Splunk costs more than our trading platform."Director of Security Operations, Regional Bank

If you're paying to store logs no one looks at, we should talk. We've cut Splunk, Datadog, and Elastic bills by filtering noise at the source.