Wednesday, November 5, 2008

Splunk Log monitoring and index

http://www.splunk.com/

Free-format search tool handles disparate event types, eases admin headaches

Splunk is a free-format search tool that helps you correlate time- and date-based events across a huge number of logs -- Apache, FTP, security, MTA, DBMS, and so on. Splunk pulls in data from log files, then indexes and organizes it, determines similarities and differences between events, and allows you to search across all events by time, date, and keywords. Splunk Professional beefs up Splunk Server, handling greater log volume and more servers, and includes a rich scripting language as well as features such as automatic data collection.

http://loganalysis.blogspot.com/2006/01/splunk-review-free-version.html

Free VS Enterprise
Main difference is free version only indexes 500MB a day.
http://www.splunk.com/article/2018

No comments: