Splunking Great.
Use Cases and Deployment Scope
With so many disparate systems finding a single fault point within all the interconnected applications is very difficult. Splunk enables us to centrally locate all logs and metrics from the full stack of systems - including network, identity, cyber, application, database, etc etc. AND THEN correlate all this information into meaningful dashboards that tell stories about the data and state of our environments.
Pros
- Dashboarding
- Data Selection and Processing.
- Ingestion Techniques.
Cons
- Easier Plugin Creation.
- Free Tier Cloud.
- Query Language Builder.
Likelihood to Recommend
Splunk is excellent when all your data is in one location. Its ability to correlate all that data is intuitive (once the hurdle of learning the query language is overcome). It is also easy to standardize the presentation of information to the company. When data is siloed/standalone, other systems can be cheaper and faster to implement.
