<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Monitoring Approach Strategy in Monitoring Splunk</title>
    <link>https://community.splunk.com/t5/Monitoring-Splunk/Monitoring-Approach-Strategy/m-p/112534#M7574</link>
    <description>&lt;P&gt;Hi All&lt;/P&gt;

&lt;P&gt;I am looking for "Best Practice" type information on a Monitoring Approach Strategy.  These would be things like:&lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;What to log? (Windows, Linux, etc.)&lt;/LI&gt;
&lt;LI&gt;What events to monitor?&lt;/LI&gt;
&lt;LI&gt;What events to tune?&lt;/LI&gt;
&lt;LI&gt;What do you do with the output?&lt;/LI&gt;
&lt;/UL&gt;

&lt;P&gt;Any help anyone can provide would be appreciated.&lt;/P&gt;

&lt;P&gt;Thanks&lt;/P&gt;</description>
    <pubDate>Mon, 31 Mar 2014 09:02:44 GMT</pubDate>
    <dc:creator>sbucchianeri</dc:creator>
    <dc:date>2014-03-31T09:02:44Z</dc:date>
    <item>
      <title>Monitoring Approach Strategy</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Monitoring-Approach-Strategy/m-p/112534#M7574</link>
      <description>&lt;P&gt;Hi All&lt;/P&gt;

&lt;P&gt;I am looking for "Best Practice" type information on a Monitoring Approach Strategy.  These would be things like:&lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;What to log? (Windows, Linux, etc.)&lt;/LI&gt;
&lt;LI&gt;What events to monitor?&lt;/LI&gt;
&lt;LI&gt;What events to tune?&lt;/LI&gt;
&lt;LI&gt;What do you do with the output?&lt;/LI&gt;
&lt;/UL&gt;

&lt;P&gt;Any help anyone can provide would be appreciated.&lt;/P&gt;

&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Mon, 31 Mar 2014 09:02:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Monitoring-Approach-Strategy/m-p/112534#M7574</guid>
      <dc:creator>sbucchianeri</dc:creator>
      <dc:date>2014-03-31T09:02:44Z</dc:date>
    </item>
    <item>
      <title>Re: Monitoring Approach Strategy</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Monitoring-Approach-Strategy/m-p/112535#M7575</link>
      <description>&lt;P&gt;That would totally depend on your use cases.&lt;/P&gt;

&lt;P&gt;Compliance? Security? Operations? Development? Billing? Business Intelligence? &lt;/P&gt;

&lt;P&gt;Sorry, but you need to refine your question a bit before you can get any good answers.&lt;/P&gt;</description>
      <pubDate>Mon, 31 Mar 2014 15:11:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Monitoring-Approach-Strategy/m-p/112535#M7575</guid>
      <dc:creator>kristian_kolb</dc:creator>
      <dc:date>2014-03-31T15:11:38Z</dc:date>
    </item>
    <item>
      <title>Re: Monitoring Approach Strategy</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Monitoring-Approach-Strategy/m-p/112536#M7576</link>
      <description>&lt;P&gt;Apologies.  I am looking for a balance between Security, Compliance &amp;amp; Operations for the Financial Services industry.  Hope that helps.&lt;/P&gt;</description>
      <pubDate>Mon, 31 Mar 2014 16:41:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Monitoring-Approach-Strategy/m-p/112536#M7576</guid>
      <dc:creator>sbucchianeri</dc:creator>
      <dc:date>2014-03-31T16:41:37Z</dc:date>
    </item>
    <item>
      <title>Re: Monitoring Approach Strategy</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Monitoring-Approach-Strategy/m-p/112537#M7577</link>
      <description>&lt;P&gt;Assuming that you are new to Splunk, but not new to computers in a Financial Services industry, then you should step back and consider your environment.  &lt;/P&gt;

&lt;P&gt;Somewhere in your organization the computers and servers you use were built and are maintained according to some form of Security/Compliance Guidelines.  Those guidelines specify what you want to log, and why you want to log it.&lt;/P&gt;

&lt;P&gt;Those are the things that you want to monitor and analyze with Splunk.  You will probably find that each of those (and there are probably many) are separate topics here on Answers.&lt;/P&gt;

&lt;P&gt;For example, when a Windows server was put into production it was preconfigured by someone at your shop to log a specific set of events, for a specific reason.  We do not know that information.&lt;/P&gt;</description>
      <pubDate>Mon, 31 Mar 2014 18:00:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Monitoring-Approach-Strategy/m-p/112537#M7577</guid>
      <dc:creator>lukejadamec</dc:creator>
      <dc:date>2014-03-31T18:00:09Z</dc:date>
    </item>
    <item>
      <title>Re: Monitoring Approach Strategy</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Monitoring-Approach-Strategy/m-p/112538#M7578</link>
      <description>&lt;P&gt;+1. The question is still a bit open-ended. &lt;/P&gt;

&lt;P&gt;What types of systems, standard applications, bespoke applications, what compliance framework (if any)...etc&lt;/P&gt;</description>
      <pubDate>Mon, 31 Mar 2014 18:09:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Monitoring-Approach-Strategy/m-p/112538#M7578</guid>
      <dc:creator>kristian_kolb</dc:creator>
      <dc:date>2014-03-31T18:09:17Z</dc:date>
    </item>
  </channel>
</rss>

