Splunk Search

Help! I need to know if Splunk is capable of the following;

Charles_S
New Member

• Need to be able to view the health of the servers and applications running across all three datacentres in a single dashboard.
• Graphic representation and summary of collected data.
• Runs “on premises”
• Capacity monitoring
• Integration to other products to collate data… Apache logs, Nagios, Jenkins, etc.
• Can extend to cover servers in other cloud providers… AWS, Azure, etc
• Alert notification
• Capacity analysis
• “fault” tracking.
• LDAP integration
• API integration, show we want to automate monitoring of new servers from the shop.

Nice to have…
• Able to present a “restricted” view to projects of the data for just there dedicated server

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Yes, Splunk is capable of all that. The caveat is Splunk's capabilities are limited by the data given to it. For example, fault tracking is only possible if the faults are reported to Splunk, which means the right log files have to be monitored. You may need to modify your firewall to allow data to flow to Splunk from the various sources. There will be some effort required on your part - you may need to install Universal Forwarders on your servers to get data into Splunk; dashboards will have to be created; and so on.

You can post separate, more specific questions on this site if you need help getting going.

---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...

Get the T-shirt to Prove You Survived Splunk University Bootcamp

As if Splunk University, in Las Vegas, in-person, with three days of bootcamps and labs weren’t enough, now ...

Wondering How to Build Resiliency in the Cloud?

IT leaders are choosing Splunk Cloud as an ideal cloud transformation platform to drive business resilience,  ...