Showing posts with label splunk. Show all posts
Showing posts with label splunk. Show all posts

Wednesday, May 25, 2022

Splunk



Splunk is the data platform software that powers enterprise's observability, unified security and limitless custom applications in hybrid environments.


What is Splunk used for?

  • Splunk is used for monitoring and searching through big data which is pulled from various sources and accepts data in any format. 
  • It indexes and correlates information in a container that makes it searchable, and makes it possible to generate alerts, reports and visualizations.
  • It has a huge market in the IT infra and business.


Why is Splunk so popular?

  • It is Scalable and has no Backend
  • This makes Splunk available on multiple platforms and can be installed speedily on any software. If one server is not enough another can be added easily and data is distributed across both these servers evenly.


What is the difference between Splunk and Tableau?

  • Splunk is used to monitor all machine activities including logins and actions taken on those machines under each user.
  • Tableau provides pattern-based visualizations under a huge pile of data, on a real-time basis.

Splunk Dashboard
  • made up of panels.
  • A panel can contain modules such as  search boxes, fields, charts, tables and lists
  • A dashboard panel is usually connected to reports
  • there will be a Dashboard Editor to create and edit dashboard.
  • The Dashboard Editor can be used to quickly add set of saved reports to a dashboard.

Operations on Splunk Dashboard
  • change dashboard permissions or roles.
  • change dashboard panel visualizations.
  • edit the XML config of a dashboard.

Splunk Dashboard App
  • a new and advanced feature to give a new visual editing experience for building dashboard.
  • 2 new workflows.
  • absolute and grid layouts.
  • visualizations in both single instances and distributed environments.



app can export selected individual visualizations and can export to png image or pdf format. while classic only in pdf.



Installing Splunk

1. Create Splunk Account
2. 



Fluentd

Open-source log data collector > why logs? - for compliance (auditing, company, business) - for security (transparency, monitoring, admin...