Community
Free
No license required
Discover where to look.
- Full synthetic demo
- Real-environment Quickscan
- Observed ingest
- Candidate counts
- Potential optimization estimate
- Top candidate preview
Local-first Splunk ingest analysis
Log Spend Auditor analyzes aggregated ingest and usage metadata on your own machine and shows which Splunk datasets deserve a closer look.
Regular $99 · One-time purchase · License does not expire
Launch price limited to the first 10 redemptions.
splunk-spend-auditor quickscan --from-csv sample-data/case_mixed
Highest-impact candidates
The problem
Splunk environments accumulate datasets whose operational value may no longer justify their cost. Log Spend Auditor helps teams decide where investigation is worthwhile.
Results are recommendations for human review. The tool never tells you to delete data, and it does not promise savings.
New sources accumulate over time.
Historical sources may no longer justify their cost.
Review data before making retention or onboarding decisions.
How it works
Read-only Splunk REST or CSV.
Metadata stays on your machine.
Quickscan or full Pro audit.
Works with real Splunk data through the REST API or CSV exports. Designed for Splunk teams.
Architecture
From Splunk ingest metadata to actionable findings — entirely on your machine.
01Input
Aggregated ingest + usage signals
No raw Splunk events required.
02Collect
03Analyze
04Act
Community discovers the problem. Pro explains the problem.
Your Splunk data stays with you.
Findings are candidates for human review. Log Spend Auditor does not change Splunk configuration, delete data or disable indexes; you decide what action to take.
Community vs Pro
Both editions are the same Linux application. Start with Community. Upgrade to Pro in the same application — no reinstall required.
Free
No license required
Discover where to look.
$69
launch price
$99 regular
Understand why, and what to review.
Regular price $99 · One-time purchase. Launch price limited to the first 10 redemptions.
Start with Community. Upgrade to Pro in the same application — no reinstall required. Findings are recommendations for human review; no savings are guaranteed.
Security and privacy
The analysis uses aggregated ingest and usage metadata. No raw Splunk events are sent to Log Spend Auditor servers.
The analysis runs on your machine. No SaaS backend is required.
It does not modify Splunk configuration or data.
The product collects no usage telemetry or analytics.
Splunk credentials are read locally and are not uploaded to us.
Reports are generated and stored on your machine.
Used only for Pro license activation, deactivation and periodic revalidation. No Splunk customer data is sent to it.
The demo and the Community Quickscan do not contact Lemon Squeezy. Details are in the Privacy page.
Platforms
Available now
Built and tested on Ubuntu 22.04 LTS
Requires glibc 2.35 or newer
Coming later
Coming later
Run a Quickscan on your own machine. Your Splunk data stays there.
Regular $99 · One-time purchase · License does not expire
Launch price limited to the first 10 redemptions.