Sasquatch vs Splunk ES

Splunk makes you drop data.
We keep every byte.

Cut compute and storage by more than 80% — losslessly, in the cloud you already own.

Splunk meters every gigabyte, doubles it with the Enterprise Security add-on, then bills again for ES Premier and SOAR — in Splunk's own cloud. Sasquatch keeps every byte losslessly, MITRE-mapped, with agentic AI, in the cloud you own — for a fraction.

100 GB / day of security logs (~3 TB/mo) · annual list · every figure traces to a published rate.

Lossless, SHA-256 verified Your S3 / GCS / Azure Published-rate sourced
Compute + storage · same workload
Splunk ESBaseline
Sasquatch80%+ less

And a fraction of the total Splunk ES bill — lossless, in the cloud you already own.

What the switch is worth
0%+
less compute + storage · lossless · in your cloud
01Where the bill goes

One line item, not a meter stack.

The Splunk ES bill splits across a stack of separately metered line items. Sasquatch is one rate on the compressed bytes you keep — the same workload, a fraction of the footprint. Each block is a real line item; the length is its share.

Splunk ES
List baseline
3 metered lines
Platform ingest / SVC (100 GB/d)
Enterprise Security add-on
Platform ingest / SVC (100 GB/d)46%
Enterprise Security add-on41%
ES Premier / SOAR / apps13%
Sasquatch
One rate
the whole bill, compressed
Yeti SIEM platform
Yeti SIEM platform100%
Egress (compressed)<1%
S3 storage<1%
02The meter stack

One rate. Ingest + ES + Premier + SOAR.

The same workload, two monthly statements. One is a single line you can forecast to the byte; the other is a stack of meters, each on its own unit, re-negotiated at every renewal.

SasquatchMonthly statement
Compressed bytes ingestedone flat rate
Host / node meternot billed
Event indexing taxnot billed
Per-seat / per-identitynot billed
Retention tiernot billed
Meters to forecast1

One line, one unit — forecast it to the byte.

Splunk ESMonthly statement
Platform ingest / SVC~$900-1,100/GB-day/yr
Enterprise SecurityES add-on, ~2× base
ES Premier (UEBA)higher tier · replaces UBA
Splunk SOARper-user seat
Annual renewal upliftclimbs at renewal
Meters to forecast5

5 meters, each on its own unit — re-forecast every renewal.

03The compression

3 TB in. 20 GB out.

The full bar is the raw workload. The fill is what actually survives to disk after each product compresses it — shorter is cheaper to store, forever.

Sasquatch
Schema-aware Zstd · per-event · verified
raw 3 TB20 GB on disk
~1% of raw remains
Lossless. SHA-256(decompress(compress(x))) == SHA-256(x).
Splunk ES~0×
Indexer compression ~2× — but licensed on ingested GB (pre-compression) or per SVC, never on stored bytes.
raw 3 TB~1.5 TB on disk
50% of raw remains
Wire-only compression — bytes uncompressed at intake.
04Where the bytes live

Compressed at the edge — or after the bill?

SasquatchSources → 150× compress → your bucket → Yeti SIEM + AI
Your sources
syslog / API / agents
Edge compress 150×
3 TB → 20 GB
Your S3 / GCS / Azure
your KMS key
Yeti SIEM + AI
voice + agentic RCA
Splunk ESSources → Splunk ingest → indexers → SPL + ES
Your security sources
forwarders / HEC / API
Splunk ingest
100 GB/day · ingest or SVC
Splunk Cloud indexers
vendor-hosted store
SPL · ES · Mission Control
Splunk query
05Capability matrix

Where each tool wins.

Sasquatch ships 3,700+ detections out of the box, MITRE ATT&CK-mapped, with UEBA, threat intel, voice, and agentic AI investigation, all on lossless retention in your own cloud. The incumbents meter you per GB-day or per-MPS and keep your data in theirs.

Sasquatch ahead on 7 Both ship 7
Capability
Sasquatch
Splunk ES
Where Sasquatch pulls ahead
Lossless full-fidelity retention
Store in your own cloud + KMS
Compression ratio (security logs)
150×~2×
No per-EPS / per-GB-day metering
Voice — talk to your SIEM
Agentic AI investigation
Agent files your ITSM ticket
Table stakes — both ship it
Air-gapped / sovereign deploy
Pre-built detection content
3,700+
MITRE ATT&CK mapping
UEBA / behavioral analytics
SOAR / automated response
Compliance reporting packs
Threat-intel feed integrations

See it on your own Splunk ES footprint.

We map the same workload onto Sasquatch in the cloud you already own — lossless, 75% cheaper — and walk you through the reduction line by line. Nothing leaves your environment.