Splunk

Splunk

function

Data collection

Agentless or dedicated agent collection

As shown in the figure below, you can collect information that is not output as a log by loading the log data by mounting it to the directory where the log file is saved, or by executing a script file (created separately). is possible. It also supports collection via network such as Syslog and SNMP. It is also possible to install a dedicated agent on the target system and collect data via the agent.

Agentless or dedicated agent collection

You can select the import method according to your needs and environment

(*1) It is necessary to set up a separate daemon on the Splunk server.
(*2) It is possible to receive syslog directly or import it via syslogd.

search

Fast search for any data

You can quickly search for only the information you want to see by entering keywords or special commands in the search box. In addition, since it is possible to intuitively narrow down the search results by mouse operation only, intuitive narrowing down is possible.

Selecting the search target period (time range)

  • historical, real-time, custom
  • Select by mouse operation from the timeline chart
    • zoom in/out, mouse drag

Flexible search method

  • Keywords, Boolean Operations, Wildcards
  • Search assist (past history, display of candidates)
  • Search commands (statistical analysis, data processing)
  • Saved Search: save, share/reuse search criteria
  • Fast search for any data

analysis

Easy analysis with form search function

It is possible to create a pre-defined search box that allows you to search by simply entering an IP address.

  • Predefine search forms to help perform simple searches
  • Easy standard search
  • available to everyone
  • Easy customization and operation in multiple forms
  • Easy analysis with form search function

Reporting dashboard

Various reports and visualization functions

It is possible to create a report from the search results with one click.

  • Easily create graphs and reports such as charts, graphs, and tables based on search results
  • Create a dashboard based on the report. Centralized display of various information
  • Understand trends graphically. Promoting awareness through visualization
  • Scheduled automatic report generation
  • Regular delivery by e-mail (PDF, etc.)
  • real time report
  • Fast search for any data

Extremely fast reporting

Report Acceleration technology dramatically reduces the time it takes to create reports. You can easily create a report by selecting the check Box. In addition, by automatically accumulating reports periodically as summaries, it is possible to quickly display reports covering a long period of time.

  • Extremely fast reporting

intelligent dashboard

With the dynamic drill-down function, the field value clicked on the dashboard is entered as it is in the next dashboard or search box on the search screen, enabling drill-down in one step and clicking on the dashboard. The ability to drill down by clicking is now more convenient and easier to use.

  • intelligent dashboard

Easily share your analysis results with anyone

Whether you're running Splunk on Linux, Unix, Mac, or Windows, you can now download report results in PDF format or email them to administrators.

  • Easily share your analysis results with anyone

アラート

Alerts can be sent and actions can be taken based on search results

It is possible to apply the search formula used for the search as it is as an alert rule.

  • Flexible conditions, schedules and threshold settings
  • Real-time alert
  • List display by alert console
  • Automatic execution of various actions
    • E-mail notification
      Results can also be attached (CSV, PDF*)
      *PDF report is available only for Linux version.
      *Separate PDF software required
    • Other alert notifications
      RSS, SNMP, etc.
    • script execution

High availability through clustering

Index Replication technology makes it possible to replicate data between multiple Index servers. This makes it possible to prevent data loss in the event of a failure of one or more Index servers and achieve high availability in cases where multiple Index servers are operated.

Other items added

About API linkage

It is possible to link with external web etc. by REST API.

Inquiry/Document request

In charge of Macnica Splunk Co., Ltd.

Mon-Fri 8:45-17:30