Complete monitoring alerting and log search partner in RCA
Use Cases and Deployment Scope
In my organisation, we use Splunk for log monitoring, alerting and specific search in our application logs. For Us, We've set some alerts for error and exception msg for our application log so that we could get alerts for any issues and resolve those.Also while debugging the INCs, we use Splunk to search for specific error msg for our services. We are using Splunk at very broad level and almost we have Splunk setup for 480+ application services.
Pros
- Alert notification
- Msg search in application logs
- Count of exceptions and error for application logs
- Custom notification on specific indexes
Cons
- Seriously it needs new UI
- Better text highlights on search
- Maybe done search suggestions using AI based on past searches
Likelihood to Recommend
If you have application where you want to setup alerts of specific error or exception message to get notified or your applications are more customer centric and any missing data is crucial, honestly you need Splunk to help you in debugging and identifying the root cause, u can setup multiple indexes and monitor all your services to ensure no data or msg are getting missed due to any exceptions or error and if it gets you will get it through Splunk and it will be helpful in RCA and fixing the issue. If you want just monitoring then AppD is sufficient, u don't need Splunk.


