[#] Thu Mar 19 2015 12:32:31 EDT from LoanShark @ Uncensored

One of the most powerful things we do with Splunk is the "transaction" filter. I don't see any direct replacement with logstash... this is statically configured and seems to have limitations, but it's somewhere in the ballpark:

not quite close enough, transaction is an ad-hoc query:

[#] Thu Mar 19 2015 12:54:57 EDT from dothebart @ Uncensored

probably one would want something like that:

this is the logstash alternative:

(the credativ guys work with it)

Another tool /me wouldn't use... but may be interesting ;-)



[#] Thu Mar 19 2015 12:58:14 EDT from dothebart @ Uncensored

I like very much this one:

(have a look at the crazy videos ;-)

It uses a pimped collectd as some of the data sources.

[#] Thu Mar 19 2015 14:19:39 EDT from LoanShark @ Uncensored

OK, for one thing, I hadn't correctly understood how logstash fits together with the rest of its ecosystem. Logstash is like splunkforwarder, I guess- it's a piece of low-level plumbing.

The querying all happens in elasticsearch:

[#] Thu Mar 19 2015 23:00:07 EDT from ax25 @ Uncensored

Not similar at all, but I do use this for viewing / checking combined logs from systems:

Epylog -

It lets you boil down combined syslogs from multiple systems, and get rolled up reports on logins, and a free-for-all report of anything that was not parsed in an email.

It takes quite a bit of time to get what they call the "weeder" to build up to rid yourself of the background noise from the reports, and it does take ocasional changes to regexes on lines to account for some daemons changed log output for warnings, etc, but I find it worthwhile.  Once you have your "don't care" lines out of the report, you will be left with the ones to either investigate and act on or just add to the don't care if they turn out to be a more of just miss-placed info output.

You can set up your own roll up reports, but I have not played with that as of yet.

[#] Mon Mar 23 2015 08:15:36 EDT from LoanShark @ Uncensored

Not the splunk way - there are no "don't care" records, you throw everything in the big index and figure out how to query it later.

[#] Wed Apr 29 2015 11:15:28 EDT from LoanShark @ Uncensored

Been talking to some former coworkers (now at NYTimes, ghod help them) and one of the Splunk alternatives they are looking at is Sumologic:

(^^ one of my litmus tests for a Splunk replacement)

[#] Wed Apr 29 2015 12:37:52 EDT from fleeb @ Uncensored

When you go to this site, you may be treated to the following popup:

This page ws unable to display a Google Maps element. The provided Google API key is invalid or this site is not authorized to use it. Error Code:

So, they hope to supplant Splunk, but...?

[#] Fri Jun 05 2015 09:48:33 EDT from IGnatius T Foobar @ Uncensored

Evidently their Big Data got so big it popped out of the screen.

(By the way, we ended up just buying a bigger Splunk license.)