3 ms·
Speaking frankly, unless a Splunk alternative implements API compatibility for search, it’s a nonstarter in the marketplace. At the enterprise I work at, develo
by condiment 8y ago
Speaking frankly, unless a Splunk alternative implements API compatibility for search, it’s a nonstarter in the marketplace. At the enterprise I work at, developers and operations teams both use splunk to observe and analyze application behavior, and have thousands of dashboards and alerts set up and integrated into mature operational processes. Migrating this over to another application is nontrivial. And the biggest problem isn’t even a technical one, it’s a social one - how do you train three hundred engineers to use a different log search tool.
I would absolutely love to see a competitor emerge that addressed the migration problem through a compatible search api. Handling other timeseries data like metrics would just be icing on the cake.
- bovermyer 8y agoJust because it's not API-compatible with Splunk doesn't mean it's a "nonstarter." Splunk is far from the only way to do what it does.
- condiment 8y agoI don’t disagree. What I meant was that it’s a nonstarter for replacing any existing installation of splunk, which is desirable for me as an enterprise customer who spends a nontrivial amount of money every year on this sort of tool. There are a lot of obstacles to replacing an existing, effective implementation of a tool, and I listed what they are in the hopes that somebody pays attention.
- cthuen 8y agoI get what you're saying. I don't think you're wrong. This isn't currently a priority for us but I hope that someday someone builds something like that. That's one of the aspirations of releasing a Community Edition. Our API docs are open: https://dev.gravwell.io/docs/#!api/api.md https://dev.gravwell.io/docs/#!api/api.md
- bovermyer 8y agoThat's fair, and I sympathize with that position.
- madhadron 8y agoAs a former Splunk employee, I would be really sad to see Splunk's search language enshrined as a standard. It wasn't designed, it grew organically from a set of shell scripts. It has no grammar, and using it effectively is largely knowing a grab bag of special commands that someone hacked on to fix a specific weakness of the language. Interestingly, you don't need a special language. The relational calculus is isomorphic to the regularity calculus, which, in practical terms, means that SQL is a perfectly good language for Splunk's use case.