Gmail Calendar Documents Reader Web more »
Recently Visited Groups | Help | Sign in
Google Groups Home
splunk?
There are currently too many topics in this group that display first. To make this topic appear first, remove this option from another topic.
There was an error processing your request. Please try again.
flag
  9 messages - Collapse all  -  Translate all to Translated (View all originals)
The group you are posting to is a Usenet group. Messages posted to this group will make your email address visible to anyone on the Internet.
Your reply message has not been sent.
Your post was successful
 
From:
To:
Cc:
Followup To:
Add Cc | Add Followup-to | Edit Subject
Subject:
Validation:
For verification purposes please type the characters you see in the picture below or the numbers you hear by clicking the accessibility icon. Listen and type the numbers you hear
 
Steve Conover  
View profile  
 More options Nov 6, 10:41 am
From: Steve Conover <scono...@gmail.com>
Date: Fri, 6 Nov 2009 07:41:46 -0800
Local: Fri, Nov 6 2009 10:41 am
Subject: splunk?
I hope this is an appropriate forum for this kind of question, if not
please rebuke away.

Does anyone here use splunk?  If so, I'm particularly interested in
how you make use of it (as a fancy log grepper, as a visualization
tool, etc).

Regards,
Steve


    Reply    Reply to author    Forward  
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
Ilan Rabinovitch  
View profile  
 More options Nov 6, 2:47 pm
From: Ilan Rabinovitch <i...@fonz.net>
Date: Fri, 06 Nov 2009 11:47:34 -0800
Local: Fri, Nov 6 2009 2:47 pm
Subject: Re: splunk?
On 11/06/2009 07:41 AM, Steve Conover wrote:
> I hope this is an appropriate forum for this kind of question, if not
> please rebuke away.

> Does anyone here use splunk?  If so, I'm particularly interested in
> how you make use of it (as a fancy log grepper, as a visualization
> tool, etc).

We've been using it for both searching/grepping through logs, as well as
visualizing data in them.
Its also been pretty helpful to use it for alerting based on specific
patterns in the logs, and generating nightly or weekly reports with
statistics on our logged events.

    Reply    Reply to author    Forward  
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
Brian Dunbar  
View profile  
 More options Nov 6, 4:28 pm
From: Brian Dunbar <brian.dun...@gmail.com>
Date: Fri, 6 Nov 2009 15:28:48 -0600
Local: Fri, Nov 6 2009 4:28 pm
Subject: Re: splunk?

On Fri, Nov 6, 2009 at 9:41 AM, Steve Conover <scono...@gmail.com> wrote:
> I hope this is an appropriate forum for this kind of question, if not
> please rebuke away.

> Does anyone here use splunk?  If so, I'm particularly interested in
> how you make use of it (as a fancy log grepper, as a visualization
> tool, etc).

> Regards,
> Steve

We're still demoing it.  So far it's been awesome for troubleshooting
by grepping logs and event-based alerts.

No visualization or statistics, yet.

My biggest problem is remembering to use it: you spend a few years
grepping a log file from terminal it's hard to remember in a crunch to
switch gears .

--
Brian Dunbar
Geidus

"Display some adaptability"


    Reply    Reply to author    Forward  
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
Allen Bettilyon  
View profile  
 More options Nov 6, 5:17 pm
From: Allen Bettilyon <abettil...@gmail.com>
Date: Fri, 6 Nov 2009 15:17:57 -0700
Local: Fri, Nov 6 2009 5:17 pm
Subject: Re: splunk?

We've found it to be quite helpful in exposing production log data to other
groups in the organization that wouldn't otherwise have production level
access.

--
/ab

    Reply    Reply to author    Forward  
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
Patrick Debois  
View profile  
 More options Nov 7, 6:08 am
From: Patrick Debois <patrick.deb...@gmail.com>
Date: Sat, 07 Nov 2009 12:08:18 +0100
Local: Sat, Nov 7 2009 6:08 am
Subject: Re: splunk?
I've used it in the past to correlate log files together within an
identity and access mgt project:
we had syslog files, but also application logs, and network logs,
firewall logs, database logs.

If we would have put everything within the database , the schema would
have to be adapted constantly because of the
different file formats. Splunk allowed us to store this in one central
repository, but still define different field by specifying
formatters/parsers of each format.
in this way we could easily slurp in all different/custom log formats
every legacy application produced instead of writing custom agents.

biggest bummer for us, was that the license depends on the daily volume
you can process with it, which could grow a lot if you need to do
archiving of it.


    Reply    Reply to author    Forward  
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
Gildas Le Nadan  
View profile  
 More options Nov 7, 7:40 am
From: Gildas Le Nadan <3ntr0...@gmail.com>
Date: Sat, 07 Nov 2009 13:40:52 +0100
Local: Sat, Nov 7 2009 7:40 am
Subject: Re: splunk?
 > Steve Conover wrote:
[snip]
 >> Does anyone here use splunk?  If so, I'm particularly interested in
 >> how you make use of it (as a fancy log grepper, as a visualization
 >> tool, etc).
Patrick Debois wrote:

[snip]

> biggest bummer for us, was that the license depends on the daily volume
> you can process with it, which could grow a lot if you need to do
> archiving of it.

Hi,

There was a discussion about splunk! during the "tools" session of
DevOpsDAys'09.

I think Patrick is right to mention the price as the biggest
showstopper, as there was a consensus on the fact an OSS replacement for
Splunk! was one of the dearly missed tool.

Lindsay Holmwood made mention of a prototype/QnD tool based on mysql he
wrote, but I don't know if he has posted/published it yet (and
functionaly it is probably quite far from splunk! anyway).

Cheers,
Gildas


    Reply    Reply to author    Forward  
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
Paul Nasrat  
View profile  
 More options Nov 7, 8:17 am
From: Paul Nasrat <pnas...@googlemail.com>
Date: Sat, 7 Nov 2009 13:17:00 +0000
Subject: Re: splunk?
2009/11/7 Gildas Le Nadan <3ntr0...@gmail.com>:

> There was a discussion about splunk! during the "tools" session of
> DevOpsDAys'09.

> I think Patrick is right to mention the price as the biggest
> showstopper, as there was a consensus on the fact an OSS replacement for
> Splunk! was one of the dearly missed tool.

> Lindsay Holmwood made mention of a prototype/QnD tool based on mysql he
> wrote, but I don't know if he has posted/published it yet (and
> functionaly it is probably quite far from splunk! anyway).

So what is the core value of splunk that we'd want in an OSS tool (or
set of tools)?

Thinking about the problem I think it falls into several components:

*) Host based Log Collection (live tailing, etc)
*) Log Aggregation (getting it efficiently across the network)
*) Log analysis
*) Visualisation
*) Search/Query

I really like what Data Wrangling have done with wikipedia's squid
logs plus hadoop:

http://www.trendingtopics.org/

It is open source and uses a combination of Hive/Hadoop Streaming
(python) to do the analysis with a rails app and google visualisations
and charts for the front end.

Paul


    Reply    Reply to author    Forward  
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
Steve Conover  
View profile  
 More options Nov 9, 8:11 pm
From: Steve Conover <scono...@gmail.com>
Date: Mon, 9 Nov 2009 17:11:36 -0800
Local: Mon, Nov 9 2009 8:11 pm
Subject: Re: splunk?
Thanks for everyone's responses, this was very helpful.

-Steve


    Reply    Reply to author    Forward  
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
Kris Buytaert  
View profile  
 More options Nov 12, 5:00 am
From: Kris Buytaert <Kris.Buyta...@gmail.com>
Date: Thu, 12 Nov 2009 11:00:38 +0100
Local: Thurs, Nov 12 2009 5:00 am
Subject: Re: splunk?

So I missed that session .. and it has been ages since I looked at
Splunk, to me it looked like a log parser..

Would Rivermuse as an eventhandling platform be a potential
replacement ?

greetings

Kris


    Reply    Reply to author    Forward  
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
End of messages
« Back to Discussions « Newer topic     Older topic »

Create a group - Google Groups - Google Home - Terms of Service - Privacy Policy
©2009 Google