We're primarily a FOSS shop, so using Splunk to centralise our logging is just too expensive for us (500mb/day is not enough). Then I saw what awesomeness you can do ...
We've got a pretty sizable Splunk deployment going, about 1.5TB/day of application logs coming in. There is discussion about starting an initiative to set some enterprise-wide standards for logging ...