Site Search

Splunk

Splunk

More than 18,500 companies in 115 countries use Splunk

Here's why companies choose Splunk.

Reason 1: A wide range of applications that expand business opportunities in the digital age

We are now in an era where various things are “connected” centered on data. By being “connected,” the scope of cybersecurity to consider has expanded further, and its importance has increased. In addition, it is clear that the promotion of DX (digital transformation) and business transformation utilizing AI will lead to an increase in corporate value.

Splunk helps you solve all your data challenges. Not only as a "cyber security measure", but also for "IT infrastructure management" to understand the entire system, and "IoT/M2M" such as logs of various equipment at manufacturing sites and the operation status of equipment introduced to customers. , "Web analytics" that analyzes web access to discover new customer requirements, etc., can be used in a wide range of businesses.

We confidently recommend Splunk as the best tool for expanding business opportunities for companies in the digital age.

Reason 2: Collect and visualize data from any source

Collects, integrates, analyzes, and visualizes huge and diverse machine data logs in real time, regardless of data source or location, such as servers, network devices, business systems, facility equipment, and various sensors installed in products. increase. Log formats differ for each system and device, but since Splunk does not implement an RDB (relational database) internally, it is possible to centrally manage logs without being aware of differences in formats. If it is text format, you can easily integrate and utilize data in different formats such as systems and servers without being conscious of it.

Reason 3: Real-time, high-speed search and analysis of huge amounts of data

"Splunk" automatically separates events based on timestamps and performs indexing by segment processing, whether it is for huge amounts of data generated daily in real time or for historical data. It is possible to search the data of various devices and systems in real time. This makes it possible to quickly find the necessary data from a huge amount of data. You can also set up alert notifications by saving search patterns and running them periodically. Search results can be extracted by simply drilling down on the search results.

Reason 4: Easy to scale

Since Splunk is highly scalable software, it is possible to flexibly scale out according to the scale of the system. can be added to extend the resource.

Reason 5: Case studies that can be learned from leading companies

Splunkは既に全世界115ヵ国、18,500社以上の企業が導入しています。マクニカも日本国内500社以上の企業へ導入を支援してきました。

You can see the wide range of Splunk use cases through case studies.

Macnica 's strengths

Macnica has been handling Splunk for over 10 years and is the primary sales agent with the No. 1 track record of implementing Splunk in Japan, supporting numerous companies.

Macnica has a large number of Splunk-certified engineers and Splunk-certified sales staff. We provide one-stop support from proposals to implementation, construction, and operation to help customers solve problems and make decisions in areas such as cybersecurity, IT infrastructure management, IoT/M2M, and web analytics.

OriginalApps

Appsとは、Splunk社やユーザーコミュニティなどから提供される各種アプリケーション、デバイス用の公開テンプレートです。Appsを利用する事により、ログ分析、ダッシュボード、レポート作成などが効率的に行えます。マクニカでは、Splunkをより効果的にご利用いただけるよう、様々なオリジナルAppsを提供しています。

original service

Macnica offers a variety of services to make using Splunk easier.

  • Dashboard Maintenance Pack / Creation Pack
    We will take care of setting maintenance and creating new dashboards that are essential for Splunk operation. Click here for details
  • Version upgrade service
    We support regular version upgrade work before EOS. Click here for details
  • SIEM operation monitoring service
    Only SOC operations can be outsourced, solving the shortage of correlation analysis skills and analyst man-hours. Click here for details

Splunk FAQ

We publish technical "Frequently Asked Questions" that occur when using Splunk. Information is being updated sequentially.

Host a community for Splunk users only

We regularly host the Macnica Networks Splunk Circle user community with end-user companies who have purchased Splunk through Macnica. From Macnica, we will introduce the latest product update information and overseas examples with Tips. In addition, by sharing and exchanging information with other user companies, it is used as a place to exchange opinions not only on how to use Splunk, but also on IT systems in general.

Splunker's Blog

We provide a variety of useful information about Splunk.

Splunk https://cms.macnica.co.jp/cgi-bin/mt/mt.cgi?__mode=list&_type=entry&blog_id=100 https://www.macnica.co.jp/business/security/manufacturers/splunk/ Why choose Splunk? https://cms.macnica.co.jp/cgi-bin/mt/mt.cgi?__mode=list&_type=entry&blog_id=101 https://www.macnica.co.jp/business/security/manufacturers/splunk/reason.html Splunk Enterprise 10.0 Release https://cms.macnica.co.jp/cgi-bin/mt/mt.cgi?__mode=view&_type=entry&id=148619&blog_id=103 https://www.macnica.co.jp/business/security/manufacturers/splunk/ver10_0.html Splunk Enterprise 9.3 Release https://cms.macnica.co.jp/cgi-bin/mt/mt.cgi?__mode=list&_type=entry&blog_id=103 Splunk Enterprise 9.4 Release https://cms.macnica.co.jp/cgi-bin/mt/mt.cgi?__mode=list&_type=entry&blog_id=103 H2 Edge Processor Function

  • Overview
    • The Edge Processor service is now available in Splunk Enterprise version 10.0.
  • Edge Processor Features
    • It can receive data from various sources and route it to multiple destinations for each log type.
    • It is possible to process and format data close to the data source before sending it to various destinations.
    • Filtering, masking, format conversion, etc.
You can use it in situations like this! !
  • Cut out unnecessary parts of data before sending!
    You can filter and send unnecessary logs and duplicate data, reducing machine load, license consumption, storage costs, etc.
  • Secure design that protects confidential information on-site
    Confidential data can be masked before transmission, making it safe to use even in environments with strict security policies.
  • Send data freely to where it is needed
    A single piece of data can be flexibly distributed to Splunk Enterprise/Cloud and S3. Routing, such as "this log should be visualized" or "this should be stored," can be easily configured using a GUI.

Viewing the H2 forwarder configuration file

  • You can now view the effective settings for a forwarder from the Agent Management screen.
    • Starting with Splunk Enterprise version 10.0, the "Deployment Server" has been renamed to "Agent Management."
You can use it in situations like this! !
  • I want to check if the forwarder settings are correct.
  • I want to manage and monitor remote server settings from Splunk Web

Moving H2 indexed data

  • You can now move stored data to a different index using the split-buckets command.

*This feature is only available in the standalone indexer.
Not supported on indexer clusters or in Splunk Cloud.
*In version 10.0, this function is only valid for event data.
Moving summary or metric data is not supported.

You can use it in situations like this! !
  • I want to move data that was saved in the wrong index.
  • I want to split an index that has become too large in data.
  • I want to change the retention and disclosure policy for specific data.

Inquiry/Document request

In charge of Macnica Splunk Co., Ltd.

Weekdays: 9:00-17:00