Overall Satisfaction with Splunk Enterprise
Splunk is mainly used to log analysis and alerting of events, both business and technical events
- Business event alerting
- Technical Event alerting
- Graphing of information found in the data
- Users CAN write queries that are non-optimized causing both performance problems or unexpected (as in not what they wanted) results. It would be great if Splunk engineers could come up with some way to 'model' the queries and instruct users on query performance gave x number of records... and possibly an example of results - say using 100-1000 records - so that the user can see what they're going to get.
- We make each user group pay for the data that their systems index. We have not had any negative reactions indicating that the tool doesn't meet their needs