Monday, March 5, 2012

Splunk

Splunk is a company whose vision is to make machine data accessible, usable and valuable to everyone. “Machine data is one of the fastest growing pieces of "big data"--generated by websites, applications, servers, networks, mobile devices and the like that organizations rely on every day.” What that means is that Splunk turns all machine data into something that is valuable no matter what industry you currently are in. More than 90% of the data in today's organizations is unstructured data generated by machines. Older technologies could not handle this amount of data, but Splunk has the capability to structure it. Splunk collects, monitors, indexes and analyzes the machine data whether physical, virtual or in the cloud. There are many use cases that you can reference with Splunk. What I found was that one use case involving an investigator of a security case searched within Splunk and found some of the external database data very questionable. It is advised to search further for the location and phone number of the user. Another use case example is removing data that resides both in a database and outside the database. I see how Splunk could be very useful when trying to reference data that you have in multiple places. Sometimes when you have too much data, it is everywhere and hard to access, but if you could search easily through Splunk, you will not be stressed as to where that data resides. If it further structures that data, you can become organized and be able to analyze your data quickly. Splunk seems to me like a very useful tool. During research, I realized that Splunk was often thought of as just a security tool. However, it can be used for much more than that, particularly for application and server availablity. That basically means it is able to index new data without having to spend hours trying to configure the data. It is also considered cost effective to use Splunk because it works on total volume and not on licensing agreements per host.

No comments:

Post a Comment