(And Why Our Security Budget Loves Us Now)
Let’s start with a scene you might recognize.
My last team managed infrastructure for a mid-sized fintech. We ran Kubernetes in AWS. We used Datadog for observability. And we poured all our security logs into Splunk. Our security team loved us for it. The compliance team loved us for it. And then, one morning, our CFO did not.
He printed out our cloud spend report, walked over to the CISO, and pointed at a single line item.
“Splunk: $650K this year. Growing.”
Then he asked the question nobody in the room had an answer for.
“What exactly are we paying for? And why would we make this trade twice?”
Cut to this year. Different company, different team. Same problem — we generate hundreds of gigabytes of logs a day. Same regulatory requirements — we handle PII, PCI-DSS, CCPA, and SOC2 audits. Same need for real-time threat detection and historical forensics.
Only this time, our Splunk equivalent costs us $28K a year. Not $650K.
The bill shows up on AWS, not on a vendor invoice. We own the encryption keys. We control the data retention policies. We can run a compliance export in minutes, without filing a support ticket.
Here’s what changed.
We Stopped Paying for Data Just to Move It
The first thing I learned in my old job: your Splunk bill mostly pays for data transfer.
Every authentication event, every NGINX log, every Kubernetes pod log, every database query – has to travel from your infrastructure to Splunk’s platform. Splunk charges you to ingest it. The cloud provider charges you to egress it.
When we looked at our AWS bill, we realized we were paying $45K a year in egress fees just to move logs to Splunk. That expense lived on a different spreadsheet. It was invisible to our security team.
We were paying twice: once to move the data, once to store it.
In the new world, we don’t move logs. We compress them and drop them into an S3 bucket in the same region as our workload. Egress cost: $0.
We Started Compressing Differently
Everyone compresses logs. But not like this.
Standard compression (gzip, zstd) treats logs as a blob of text. It’s okay — you get 3× to 5× reduction.
Property-aware compression understands what’s inside the log:
json
{
"timestamp": "2024-09-02T14:30:00Z",
"service": "auth-service",
"level": "INFO",
"message": "User logged in",
"user_id": "u-12345",
"ip": "10.0.0.1"
}
It knows:
timestamp is a predictable sequence
service repeats with low entropy
level repeats even more
user_id and ip fields are structured
Instead of compressing the JSON as text, it compresses each field separately, using the optimal algorithm for that data type.
The result is 50× to 100× compression versus raw storage. Not 3×. Not 5×. 50× or more.
Suddenly, storing a year’s worth of security logs costs pennies instead of six figures.
We Asked a Different Question
When I was costing out Splunk, I asked:
“What’s the cheapest way to get what we need?”
The conversation was always about cutting — turning off log sources, filtering events before they get sent, sampling high-volume streams.
“Do we really need DEBUG logs? Do we need all audit events?”
That question made everyone nervous. Security didn’t want gaps in coverage. Compliance couldn’t risk audit failures. But finance was pushing hard.
This time, I asked:
“What if we could keep 100% of our logs, but store them for 90% less?”
Suddenly, the conversation changed.
The Switch Was Less Scary Than We Thought
So here’s what moving off Splunk actually looked like, timeline included:
Day 1–7: Parallel deployment. We set up a new BYOC SIEM platform in our own AWS account. Redirected logs to both Splunk and the new platform at the same time.
Day 8–14: Validation. Ran identical queries in both systems, compared results row by row. Built dashboards to alert us if logs diverged.
Day 15–28: Feature parity. Rebuilt our critical alerts ('failed login spike', 'unusual data export', 'privilege escalation attempt') in the new system. Recreated compliance dashboards for SOC2 and PCI-DSS.
Day 29–35: Cutover. Shut off new logs to Splunk. Left the old data to expire naturally (90-day retention). Started routing everything to BYOC.
Day 36 onward: We have everything Splunk gave us: log search, alerting, dashboards, correlation, compliance exports – at <10% the cost.
The Math That Convinced Our CFO
Here’s the three-year comparison that ended the finance vs. security tension for us.
Cost Category Splunk + AWS Fees BYOC + AWS Fees
Splunk licensing (100 GB/day) $560K – $750K/year $0
AWS egress fees $45K/year $0
AWS compute/storage Included in Splunk infra $45K/year
Professional services (config/tuning) $30K/year $5K/year (one-time)
Annual Total $635K – $825K $50K – $55K
3-Year Total $1.9M – $2.47M $150K – $165K
Don’t take my word for it. Here’s how to check it yourself:
Grab your Splunk contact’s per-GB/day rate. Multiply by your daily GB ingested.
Look for “AWS Data Transfer” on your cloud bill – filter by Splunk IP ranges.
Add your Splunk professional services spend (config tuning, updates, new data sources).
Multiply by 3 years.
If you’re like 95% of regulated teams, you will find a 6-figure bill – and a conscious choice to either accept it, or start cutting logs.
What About Our Existing Skills?
Our security analysts knew Splunk’s SPL (Search Processing Language). Splunk’s query language looks like this:
index=firewall src_ip=10.0.0.1 | stats count by dest_port
Modern BYOC platforms intentionally use familiar SQL-like syntax:
SELECT dest_port, COUNT(*) FROM firewall WHERE src_ip = '10.0.0.1' GROUP BY dest_port
The training curve was measured in hours, not weeks. Our analysts adjusted.
We also kept our dashboards. Here’s one we rebuilt for AWS CloudTrail monitoring:
sql
SELECT
userIdentity.arn,
COUNT(*) AS event_count
FROM cloudtrail_logs
WHERE
eventTime >= NOW() - INTERVAL '1' HOUR
AND errorCode IS NOT NULL
GROUP BY userIdentity.arn
ORDER BY event_count DESC
Same alerting logic, same visualizations, same RCA workflow – just fewer zeroes on the invoice.
The Compliance Layer Nobody Talks About
Running a regulated workload changes the SIEM conversation.
Our Splunk environment:
Used Splunk Cloud’s FedRAMP-authorized tenant
Charged us 40% more for the compliance tier
Limited our administrator access
Required Splunk employees (with Splunk credentials) to perform maintenance
Our BYOC environment:
Runs in AWS GovCloud (already FedRAMP authorized)
Costs the same as commercial AWS
Gives us full admin control
Keeps all access within our identity provider (Okta)
Allows us to encrypt logs with our own KMS keys, and control who can decrypt
When the auditor asks “who can read these logs?” we point to an IAM role and an Okta group. Not a Splunk support FAQ.
The Uncomfortable Truth Nobody Wants to Say
Spending $650K on Splunk is not an engineering failure. It’s a historical artifact.
Splunk was invented when “big data” meant gigabytes, not terabytes. Its pricing model made perfect sense – charge per GB, because storage and compute were expensive, and indexing needed dedicated infrastructure.
But in 2025:
S3 storage costs $0.023/GB/month
Serverless query engines (Trino, Presto) scan terabytes in seconds
Compression algorithms can achieve 100× ratios on structured logs
Kubernetes makes deploying distributed platforms a Terraform apply away
We’re not paying for Splunk’s technology anymore. We’re paying for Splunk’s 2003 pricing model. We’re paying for Splunk’s 40% FedRAMP premiums. We’re paying for Splunk’s shareholder returns.
That’s a choice. It’s not a law.
Questions Our Team Asked Before Switching
Q: What if we lose logs during migration? A: We ran both platforms side-by-side for four weeks. If logs diverged, alarms fired. They didn’t.
Q: What about historical Splunk data? A: We left it to expire naturally (we had 90-day hot retention). Could have exported it, but the migration cost wasn’t worth it for old logs.
Q: How do we handle incidents without Splunk’s security apps? A: We rebuilt our critical use cases natively. Turns out we didn’t need 90% of the apps – we built the 10% that mattered.
Q: What if this new platform can’t scale? A: It runs in our AWS account. We scale the underlying infrastructure with our workload – horizontal scaling is built into the architecture.
Q: Is this secure enough for our threat model? A: More secure. Logs never leave our cloud boundary. They’re encrypted with our KMS keys. We control all access policies.
The Bottom Line
We use a BYOC SIEM now because:
It costs 90% less
We own the data, the keys, the access controls
We can prove to auditors exactly who can and cannot read logs
We keep 100% of our logs – no sampling, no filtering, no gaps
We don’t use it because Splunk is “bad.” We use it because the economics of SIEM changed, and we changed with them.
If your Splunk bill is starting to look like a mortgage payment, the conversation is worth having. Start with a simple question at your next team sync:
“If we were building our security monitoring from scratch today, with everything we know now about cost, compliance, and threats – what would we build?”
Would you choose Splunk again?
Our team didn’t.
Further Reading
Splunk's Ingestion Pricing Model
Lossless vs. Gzip for Logs
AWS Egress Costs
Let’s Talk
Drop your Splunk story in the comments. How big is your bill this year? Are you cutting logs to save money? I’m reading every one.
Top comments (0)