Splunk Search

What's the difference between an event and a log

aruncp333
Explorer

Can anyone explain me what's the difference between an event and a log.

According to me, an event is set of logs generated after matching a correlation.

Tags (1)
0 Karma

woodcock
Esteemed Legend

Really you have 3 terms event, log, and result.

An event is a thing that happened anywhere at any time. It might be in Splunk and it might not. A log is the digital exhaust of that event; it is the plain-text vestige that indicates than an event happened. A result is each thing that is returned from a Splunk search.

0 Karma

aruncp333
Explorer

That's interesting, Dal.

Further I have a follow up question.

Question: How can I propose splunk sizing if the customer is having existing solution in terms of events per second (EPS).

Let's say, 1000,000EPS conversion to Splunk/day license sizing.

Thanks in advance.

0 Karma

DalJeanis
Legend

An "event" is any one record returned from an index or search. It could be a single log, or a single record that contains a count of logs, or a single record that says "100".

A "log" is a specific type of event, specifically documenting that something happened at a particular time.

0 Karma
Get Updates on the Splunk Community!

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics GA in US-AWS!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...