All Apps and Add-ons

What are the differences between Splunk app for infrastructure and Splunk app for Windows Infrastructure/Splunk app for Unix

iom100uk
Explorer

I have about 20 windows hosts and 20 linux hosts which I'd like to collect metrics and logs/events from.

How do I choose between running the app for Splunk app for Windows Infrastructure (with relevant addons), and the Splunk app for Unix/Linux (+addons) vs the Splunk app for infrastructure (SAI)?

Is there a comparison somewhere to help me choose?

if it matters we're newbies to Splunk, just getting going with Splunk Enterprise 8.

0 Karma
1 Solution

bashby_splunk
Splunk Employee
Splunk Employee

There are a few reasons to use the Splunk App for Infrastructure (SAI) over host-specific monitoring solutions. Here are some that come to mind right now:

  • SAI is great for centralized monitoring of different host types (e.g., Windows and Linux hosts).
  • SAI uses metrics indexes for metrics storage. This is more efficient than storing metrics in events indexes, and you can use metrics-specific search commands like mstats for data you collect with SAI collection agents. For more info, check out https://docs.splunk.com/Documentation/Splunk/8.0.1/Metrics/Overview.
  • If you have ITSI, you can integrate entities from SAI with ITSI, and create ITSI services from SAI entities.

View solution in original post

0 Karma

bashby_splunk
Splunk Employee
Splunk Employee

There are a few reasons to use the Splunk App for Infrastructure (SAI) over host-specific monitoring solutions. Here are some that come to mind right now:

  • SAI is great for centralized monitoring of different host types (e.g., Windows and Linux hosts).
  • SAI uses metrics indexes for metrics storage. This is more efficient than storing metrics in events indexes, and you can use metrics-specific search commands like mstats for data you collect with SAI collection agents. For more info, check out https://docs.splunk.com/Documentation/Splunk/8.0.1/Metrics/Overview.
  • If you have ITSI, you can integrate entities from SAI with ITSI, and create ITSI services from SAI entities.
0 Karma

iom100uk
Explorer

As it happens we had a Splunk consultant on site last week who confirmed this. Collecting metrics into the metrics index is the future, and it provides us with a neat route into ITSI. The older dedicated apps are effectively a dead end - I wish I hadn't spent time with them now.

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @iom100uk,
I usually install the dedicated Monitoring Apps, I don't like the Splunk App for Infrastructure.
I found that the last has less features.

Ciao.
Giuseppe

0 Karma
Get Updates on the Splunk Community!

Splunk Observability Cloud | Unified Identity - Now Available for Existing Splunk ...

Raise your hand if you’ve already forgotten your username or password when logging into an account. (We can’t ...

Index This | How many sides does a circle have?

February 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

Registration for Splunk University is Now Open!

Are you ready for an adventure in learning?   Brace yourselves because Splunk University is back, and it's ...