All Apps and Add-ons

What are the differences between Splunk app for infrastructure and Splunk app for Windows Infrastructure/Splunk app for Unix

iom100uk
Explorer

I have about 20 windows hosts and 20 linux hosts which I'd like to collect metrics and logs/events from.

How do I choose between running the app for Splunk app for Windows Infrastructure (with relevant addons), and the Splunk app for Unix/Linux (+addons) vs the Splunk app for infrastructure (SAI)?

Is there a comparison somewhere to help me choose?

if it matters we're newbies to Splunk, just getting going with Splunk Enterprise 8.

0 Karma
1 Solution

bashby_splunk
Splunk Employee
Splunk Employee

There are a few reasons to use the Splunk App for Infrastructure (SAI) over host-specific monitoring solutions. Here are some that come to mind right now:

  • SAI is great for centralized monitoring of different host types (e.g., Windows and Linux hosts).
  • SAI uses metrics indexes for metrics storage. This is more efficient than storing metrics in events indexes, and you can use metrics-specific search commands like mstats for data you collect with SAI collection agents. For more info, check out https://docs.splunk.com/Documentation/Splunk/8.0.1/Metrics/Overview.
  • If you have ITSI, you can integrate entities from SAI with ITSI, and create ITSI services from SAI entities.

View solution in original post

0 Karma

bashby_splunk
Splunk Employee
Splunk Employee

There are a few reasons to use the Splunk App for Infrastructure (SAI) over host-specific monitoring solutions. Here are some that come to mind right now:

  • SAI is great for centralized monitoring of different host types (e.g., Windows and Linux hosts).
  • SAI uses metrics indexes for metrics storage. This is more efficient than storing metrics in events indexes, and you can use metrics-specific search commands like mstats for data you collect with SAI collection agents. For more info, check out https://docs.splunk.com/Documentation/Splunk/8.0.1/Metrics/Overview.
  • If you have ITSI, you can integrate entities from SAI with ITSI, and create ITSI services from SAI entities.
0 Karma

iom100uk
Explorer

As it happens we had a Splunk consultant on site last week who confirmed this. Collecting metrics into the metrics index is the future, and it provides us with a neat route into ITSI. The older dedicated apps are effectively a dead end - I wish I hadn't spent time with them now.

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @iom100uk,
I usually install the dedicated Monitoring Apps, I don't like the Splunk App for Infrastructure.
I found that the last has less features.

Ciao.
Giuseppe

0 Karma
Get Updates on the Splunk Community!

What's new in Splunk Cloud Platform 9.1.2312?

Hi Splunky people! We are excited to share the newest updates in Splunk Cloud Platform 9.1.2312! Analysts can ...

What’s New in Splunk Security Essentials 3.8.0?

Splunk Security Essentials (SSE) is an app that can amplify the power of your existing Splunk Cloud Platform, ...

Let’s Get You Certified – Vegas-Style at .conf24

Are you ready to level up your Splunk game? Then, let’s get you certified live at .conf24 – our annual user ...