Log Spend Auditor Download Free

Splunk ingest cost analysis · Linux x86_64

Find where your Splunk ingest budget is going — without sending your data anywhere.

Log Spend Auditor is a local-first command-line tool for Splunk teams. It analyzes aggregated ingest and usage metadata on your own machine to show which datasets are worth a closer look.

Regular price $99 · One-time purchaseLaunch price limited to the first 10 redemptions.

  • Local-first
  • Read-only
  • No telemetry

Available now Linux x86_64  ·  macOS and Windows coming later

$ splunk-spend-auditor quickscan \
    --from-csv sample-data/case_mixed

Observed ingest:   199.9 GB/day
Datasets analyzed: 12

Possible waste: 2 datasets, 67.9 GB/day
Review (manual validation recommended):
              2 datasets, 9.4 GB/day

Highest-impact candidates:
-app:verbose_debugPOSSIBLE_WASTE38.0 GB/day-windows:eventlog_rawPOSSIBLE_WASTE29.9 GB/day-integration:partner_feedREVIEW9.1 GB/day
Abridged Quickscan output on the synthetic sample data bundled with the tool. Not customer data. Candidates are for human review, not instructions to delete data.

The problem

Ingest grows faster than its value is reviewed.

Splunk environments accumulate datasets whose operational value may no longer justify their cost. Before anyone changes retention or onboarding, they need evidence.

  • Ingest tends to climb. New sources are onboarded; old ones are rarely revisited.
  • Evidence comes first. Usage and ingest signals show where a conversation is worth having.
  • Humans decide. Results are candidates for review. The tool never tells you to delete data and does not promise savings.
Illustration: ingest rising while reviewed value stays flat Conceptual illustration, not measured data. A rising line labeled ingest diverges from a flatter line labeled reviewed value. Ingest Reviewed value time →
Conceptual illustration, not measured data.

How it works

From connection to candidates in three steps.

  1. Connect or export

    Use read-only Splunk REST access or CSV input.

    REST · CSV
  2. Analyze locally

    Log Spend Auditor evaluates ingest and usage metadata on your machine.

    runs on your machine
  3. Review opportunities

    Community identifies where to look; Pro provides deeper evidence, explanations and reports.

    Quickscan · Audit

Works with real Splunk data through the REST API or CSV exports. Designed for Splunk teams.

Community vs Pro

Community discovers the problem. Pro explains the problem.

Both editions are the same Linux application. Start with Community. Upgrade to Pro in the same application — no reinstall required.

Community

Discover where to look.

FreeNo license required

  • Full synthetic demo
  • Real-environment Quickscan
  • Observed ingest
  • Candidate counts
  • Potential optimization estimate
  • Top candidate preview
Download Community — Free
Launch price

Pro

Understand why, and what to review.

$69launch · $99 regular price

  • One-time purchase
  • 1 active installation
  • License does not expire
  • Full audit
  • Complete dataset inventory
  • Evidence and explanations
  • Data Value Score
  • Recommendations
  • HTML + Markdown reports
Buy Pro — $69 Launch Price

Regular price $99 · One-time purchase. Launch price limited to the first 10 redemptions.

Start with Community. Upgrade to Pro in the same application — no reinstall required. Findings are recommendations for human review; no savings are guaranteed.

Security and privacy

Local-first by design.

Read-only analysis that runs on your machine. No SaaS backend required.

Your machine

Splunk (read-only) or CSV Log Spend Auditor Local reports

Analysis data stays here.

Licensing only

Lemon Squeezy

Pro license activation and periodic revalidation only.

  • Runs locally

    Log Spend Auditor runs on your machine. The analysis does not need a SaaS backend.

  • Read-only workflow

    It does not modify Splunk configuration or data.

  • No telemetry

    The product collects no usage telemetry or analytics.

  • No raw Splunk events sent to us

    The analysis uses aggregated ingest and usage metadata. No raw Splunk events are sent to Log Spend Auditor servers.

  • Credentials remain local

    Splunk credentials are read locally and are not uploaded to us.

  • Licensing is separate

    Lemon Squeezy is contacted only for Pro license activation, deactivation and periodic revalidation. No Splunk customer data is sent to it.

The demo and the Community Quickscan do not contact Lemon Squeezy. Details are in the Privacy page.

Platforms

Linux x86_64 today. macOS and Windows later.

  • Linux x86_64

    Available now

    Built and tested on Ubuntu 22.04 LTS.

    Requires glibc 2.35 or newer.

  • macOS

    Coming later

    Not available yet.

  • Windows

    Coming later

    Not available yet.

See where your Splunk ingest budget is going.

Start with Community for free. Your Splunk data stays on your machine.

Regular price $99 · One-time purchaseLaunch price limited to the first 10 redemptions.

Local-first · Read-only · No telemetry · No raw Splunk events sent to us