Hello I have just installed splunk on my work and have the firewalls and wireless stuff send syslog to it. Im also looking for some monitoring of the server. Now i wonder if its best to put on something like ossec and integrate it with splunk or use splunks own tool for monitoring servers? The same with nagios and have it send events with syslog to the splunk server or is splunks own tools for doing the same stuff as good?
Some things to keep in mind when making this decision:
http://splunkbase.splunk.com/apps/All/4.x/app:Splunk+for+Nagios
http://splunkbase.splunk.com/apps/All/4.x/app:Splunk+for+Unix+and+Linux
Hope this helps.
Thanks! Yeah maybe its best to deploy both nagios and ossec and intergrate them with splunk to get the best out of it.