---
icon: material/currency-usd
title: "Optimization"
---

How the 10x for Splunk app expands compact events at search time, search-time overhead, potential license-tier reduction, and what happens to events the Receiver filters out.

??? tenx-costopt "How does the 10x for Splunk app expand optimized events"

    On Splunk and self-hosted Elasticsearch or OpenSearch, the Receiver compacts events losslessly before they hit Splunk, so the saving lands on your license bill. The open-source [10x for Splunk](https://doc.log10x.com/apps/receiver/compact/splunk/){target="_blank"} app keeps that saving invisible to searchers: it automatically expands compact events back to their full original form before displaying results.

    **How it works:**

    1. A dedicated `/tenx-search` REST endpoint accepts a normal search
    2. The handler rewrites the search to include the `tenx-inflate` macro and creates a Splunk search job
    3. The macro joins compact events with templates from the KV Store
    4. Full-fidelity events returned with original field names and values

    **Storage architecture:**

    - Templates stored in the `tenx_dml` KV Store collection
    - Compact events carry sourcetype `tenx_encoded` (in your existing index)
    - Hash references link events to their templates

    **Built-in Analytics Dashboard shows:**

    - Total compact events and active templates
    - Reduction ratio and storage savings
    - Event volume trends over time
    - Top templates by usage
    - Expansion success rate

    **User experience:** Classic dashboards keep their panel SPL unchanged. From the search bar a query is wrapped in the app's `tenxsearch` command, since Splunk's search page loads no app JavaScript. Scheduled alerts are compiled once at save time into a native saved search. All three read the original full-fidelity data.

    **Open source:** Available on [GitHub](https://github.com/log-10x/splunk-app){target="_blank"}.

??? tenx-costopt "What is the search-time overhead in Splunk"

    A one-time template resolution matches search terms against the templates. Per-event expansion uses a KV Store primary-key lookup and native SPL functions, negligible overhead per event. Dashboard panels keep their SPL; a search-bar query carries the `tenxsearch` wrapper; scheduled alerts run unchanged after a one-time save-time compile.

    The 10x Engine processes events at sub-millisecond per event, 100+ GB/day on a single node (512 MB heap, 2 threads). For resource requirements and Kubernetes resource specs, see [Node counting](https://doc.log10x.com/faq/pricing/node-counting/).

??? tenx-costopt "Can 10x reduce our Splunk license tier"

    Yes. Volume reduction lands on the license bill because Splunk bills on uncompressed ingest, and combined with filtering the pipeline cuts billed volume by a modeled 60–70%, enough to move you to a lower license tier. See [pricing](../../pricing/) for details.

    Splunk's list rate runs around $6/GB, so every GB/day removed from sustained ingest compounds across the year. The exact tier boundary you cross depends on your contract; measure the sustained post-optimization average before renegotiating.

    **License renewal strategy:** Deploy 10x ahead of renewal to demonstrate sustained reduction, then negotiate the new tier based on the post-optimization average.

    **Typical deployment sequence:**

    - **Cost analysis:** Agentless analysis via the [MCP server](https://github.com/log-10x/log10x-mcp){target="_blank"}'s SIEM-sample tool (read-only Splunk REST API query). Or deploy the [Reporter](https://doc.log10x.com/apps/reporter/){target="_blank"} DaemonSet for cost visibility before logs reach Splunk.
    - **Deploy:** Deploy the [Receiver in Compact mode](https://doc.log10x.com/apps/receiver/compact/){target="_blank"} alongside your forwarders via [Helm](https://doc.log10x.com/apps/receiver/deploy/){target="_blank"}
    - **Validate:** Measure sustained reduction, validate with Splunk license usage reports
    - **Renewal:** Negotiate new tier based on demonstrated lower ingestion

    **Splunk Cloud:** Works with Ingest-based pricing. Directly reduces GB ingested, lowering monthly costs proportionally.

??? tenx-costopt "What happens to logs filtered by the Receiver"

    The [Receiver in Filter mode](https://doc.log10x.com/apps/receiver/){target="_blank"} identifies low-priority logs (excessive debug, health checks, noise) based on your configured budget and severity thresholds. You control what happens to the filtered logs:

    - **Offload to [S3](https://doc.log10x.com/run/input/objectStorage/){target="_blank"}/object storage:** Route to low-cost storage for compliance. Query via Athena or fetch back to Splunk on demand.
    - **Route to different Splunk index:** Send to a cheaper "cold" index with longer retention but lower priority.
    - **Drop completely:** Eliminate entirely after a validation period.

    The Receiver exports [cost metrics](https://doc.log10x.com/run/output/metric/){target="_blank"} per [event type](https://doc.log10x.com/run/initialize/message/){target="_blank"} (volume filtered, spend rate, and sampling ratios), queryable via the [Prometheus Metrics API](https://doc.log10x.com/api/metrics/){target="_blank"}.
