product
- Why choose Splunk
- Installation record
- price
- Splunk Enterprise Security
- Splunk Phantom (SOAR)
- Splunk ITSI (Next Generation IT Operations)
- Splunk Observability Cloud
- Splunk UBA
- Macnica CSIRT App Basic
- App for Splunk for Financial Institutions
- Splunk Analytics for Hadoop
- About Apps
- Splunk Edge Hub
- What is Splunk
service
- Dashboard/SPL Creation Pack [Implementation/Building Support]
- Version upgrade service [implementation and construction support]
- Smart Security Monitoring App [Original App/Service]
- Splunk × LANSCOPE Original App [Original App/Service]
- Security Monitoring App for Box [Original App/Service]
- Cloud Security Monitoring App [Original App/Service]
- List of services
- Macnica Premium Support for Splunk (utilization support, version upgrade monitoring)
- Macnica Premium Support for Splunk Skill Up Package
Specifications/Technical Information
Application for evaluation machine
- FAQ

Splunk
Splunk
function
Data collection
Agentless or dedicated agent collection
As shown in the figure below, you can collect information that is not output as a log by loading the log data by mounting it to the directory where the log file is saved, or by executing a script file (created separately). is possible. It also supports collection via network such as Syslog and SNMP. It is also possible to install a dedicated agent on the target system and collect data via the agent.

You can select the import method according to your needs and environment
search
Fast search for any data
You can quickly search for only the information you want to see by entering keywords or special commands in the search box. In addition, since it is possible to intuitively narrow down the search results by mouse operation only, intuitive narrowing down is possible.
Selecting the search target period (time range)
- historical, real-time, custom
- Select by mouse operation from the timeline chart
- zoom in/out, mouse drag
Flexible search method
- Keywords, Boolean Operations, Wildcards
- Search assist (past history, display of candidates)
- Search commands (statistical analysis, data processing)
- Saved Search: save, share/reuse search criteria
analysis
Easy analysis with form search function
It is possible to create a pre-defined search box that allows you to search by simply entering an IP address.
- Predefine search forms to help perform simple searches
- Easy standard search
- available to everyone
- Easy customization and operation in multiple forms
Reporting dashboard
Various reports and visualization functions
It is possible to create a report from the search results with one click.
- Easily create graphs and reports such as charts, graphs, and tables based on search results
- Create a dashboard based on the report. Centralized display of various information
- Understand trends graphically. Promoting awareness through visualization
- Scheduled automatic report generation
- Regular delivery by e-mail (PDF, etc.)
- real time report
Extremely fast reporting
intelligent dashboard
Easily share your analysis results with anyone
Whether you're running Splunk on Linux, Unix, Mac, or Windows, you can now download report results in PDF format or email them to administrators.
アラート
Alerts can be sent and actions can be taken based on search results
It is possible to apply the search formula used for the search as it is as an alert rule.
- Flexible conditions, schedules and threshold settings
- Real-time alert
- List display by alert console
- Automatic execution of various actions
- E-mail notification
Results can also be attached (CSV, PDF*)
*PDF report is available only for Linux version.
*Separate PDF software required - Other alert notifications
RSS, SNMP, etc. - script execution
- E-mail notification
High availability through clustering
Index Replication technology makes it possible to replicate data between multiple Index servers. This makes it possible to prevent data loss in the event of a failure of one or more Index servers and achieve high availability in cases where multiple Index servers are operated.
Other items added
About API linkage
It is possible to link with external web etc. by REST API.

Weekdays: 9:00-17:00
Inquiry/Document request
In charge of Macnica Splunk Co., Ltd.
- TEL:045-476-2010
- E-mail:splunk-sales@macnica.co.jp
Weekdays: 9:00-17:00