Tuesday, February 17, 2009

What is Splunk

Splunk is an IT information search solution that indexes data and enables users to analyze, alert and report on all their IT data from every application, server and device; all in one place. It enables you to fi nd and fi x problems, investigate security incidents before attackers cover their tracks and generate compliance reports quickly and easily.

Splunk continuously indexes all your IT data by time so you can see change in action. And it dynamically interprets the data when you perform a search, eliminating the need to keep up
with ever changing data formats. It doesn’t require special agents, adapters or parsers for specifi c data formats and you get the correlation you need without writing lots of elaborate rules.

Splunk can integrate with your existing enterprise management, security and compliance tools right out of the box. The Splunk toolbar makes it simple to launch searches from any webbased
application and Splunk alerts can be sent to any of your existing consoles. It can even index the data already collected by your existing management tools to extend the life of your investments.

In my words : "A smart tool to know the health of your servers"