Hi Nathan,
in addition to what Frank said correctly, I would start with coalescing turned off when onboarding new logsource. This is especially true for Windows based logsources as they contain many custom properties which are not checked for coalescing criteria. When you do incident forensics thats not what you want as you are missing valuable info. Same is true for many other logsources as NG firewalls, cloud based logsources etc.
If your really want to turn it on check a 24h interval of logged events first.
BTW the additional storage consumption is relatively low as date gets compressed anyway as soon as data are coming in. Unfortunately coalescing is still turned on by default afaik.
BR
Karl
------------------------------
[Karl] [Jaeger] [Business Partner]
[QRadar Specialist]
[pro4bizz]
[Karlsruhe] [Germany]
[4972190981722]
------------------------------