---
icon: simple/splunk
title: "Splunk FAQ: cut costs without losing data"
description: "Cut Splunk costs by a modeled share: lossless in-stream compaction with the Receiver, S3 offload with the Retriever, and search-time expansion in SPL."
---

# Splunk
Cut [Splunk](https://www.log10x.com/splunk.html){target="_blank"} costs by a modeled share. Compaction removed 63.7% of captured bytes losslessly on the OpenTelemetry demo capture, [measured](https://github.com/log-10x/benchmarks/blob/main/otel-denominators/results/results.md){target="_blank"}. Go beyond Federated Search for S3 and Edge Processor: index your S3, stream regulated data, and optimize events losslessly across Splunk Cloud and Enterprise.

<div class="grid cards" markdown>

- :material-check-circle-outline: **[Compatibility](compatibility.md)**

    Dashboards, Universal Forwarders, testing on your environment, HEC integration, Splunk Enterprise on-prem, and the Cloud KV-Store pilot checklist.

- :material-database-check: **[KV Store](kv-store.md)**

    Validating the KV Store, diagnosing "Consume KV" silent failures, monitoring capacity, recovering from template/event ordering issues, and distributed-cluster setup.

- :material-currency-usd: **[Optimization](optimization.md)**

    How the 10x for Splunk app expands compact events, search-time overhead, license-tier reduction, and what happens to filtered events.

- :material-scale-balance: **[Comparisons](comparisons.md)**

    vs Splunk Ingest Actions, vs Federated Search for S3, vs Edge Processor, and supported version matrix + integration order.

</div>
