5 ms·
Why is Splunk among the bests for you? What is the cheaper alternative?
by milani 6y ago
Why is Splunk among the bests for you? What is the cheaper alternative?
- wenc 6y agoFor an on-prem general purpose logging server, it's fast and easy to maintain. The query engine supports fairly complex queries. Did I mention it's fast? Plus it's an industry standard so it's an easier sell in the enterprise. It's also actually not that expensive at low data volumes -- prices are comparable to Sumologic. Cheaper alternatives? You can roll your own logging server with fluentd and a database. Some folks will recommend elasticsearch, but we tried it and it was challenging to set up just right.
- mrweasel 6y agoThe minute you say “on-prem” a surprising number of sales people stop talking and just looks terrified. Running and managing an ELK stack is just a hassle and a managing nightmare conpared to Splunk. Humio is a great alternative, if you need something cheaper, but you have to give up a lot of features.
- haram_masala 6y agoSeconding this. If you want to do anything sophisticated in the ELK stack, you’ll eventually have to write some scripted indexes, and it’s a very bad joke how hard it is to do that.
- user5994461 6y agoI've managed a full elastic search + graylog cluster. It was very easy to setup and maintain. https://thehftguy.com/2016/09/12/250-gbday-of-logs-with-graylog-lessons-learned/ https://thehftguy.com/2016/09/12/250-gbday-of-logs-with-gray... By far elasticsearch is the easiest distributed database to setup and scale.
- gregimba 6y agoAt what scale is your on premise Splunk? As a member of a team maintaining very large on-prem Splunk service I haven't found maintaining Splunk to be an easy undertaking.
- wenc 6y ago1 server install of Splunk Enterprise. Less than 150mb a day ingest. We installed it over a year ago and haven’t touched it since, aside from updates.
- user5994461 6y agoA typical small deployment is more like 150 GB a day. No wonder you have no issues at that incredibly small scale.
- wenc 6y agoOops wrong number, 1GB a day, not 150MB. Yes, it's not big. But that's all we need.
- raverbashing 6y agoI feel Splunk is maybe quirky It has lots of query processing operations, sure. But it can't do (at least not easily) some things you could do with bash/grep in "traditional" settings (example, get the context between lines that match a pattern)
- CraigJPerry 6y agoThe equiv of grep -Cx in splunk is just hit the show source link in an event. Splunk has a more powerful feature though “| transaction“ - often in multithreaded logs i want the context but ignoring entries not from my thread. This feature does that
- thayne 6y agoI love the power of splunks query engine, there really isn't anything comparable that I know of. But setting up forwarders and injesting logs is quite a pain.
- sandermvanvliet 6y agoLogzIO is a hosted ELK stack and does a proper job for us.
- vyrotek 6y agoThere's www.humio.com
- rorykoehler 6y agoTry Graylog
- user5994461 6y agoI've used all of Splunk, ELK and Graylog. Should write a longer blog post on the differences. Splunk is miles ahead when it comes to search and visualizations. You can just do things and join that the other tools don't support at all. The only downside is speed, Splunk can only find a few hundreds thousands results a second so it's slow as hell when there are lots of matches. (Kibana doesn't give more than the first 500 results so it's totally cheating on that aspect). ElasticSearch and everything built on top of it has catastrophic issues with typing. Every field is typed, say integer or string, and sending/having data in the wrong type will prevent to do operations (smaller than, greater than, sum, additional) and can crash the database. It's wild whereas Splunk can ingest and aggregate mixed data just fine.
- dublin 6y agoFWIW, Awk and a good SyslogNG catcher is a really good old-school alternative to all these fancy expensive tools, and there is pretty much nothing that you can't do with them...
- user5994461 6y agoI'd certainly recommend syslog-ng rather than logstash, to forward logs to graylog/splunk/kibana. However there is no alternative to these when it comes to search and accessibility. SSH somewhere and awk is not a real option.