How to Analyse the application Logs before implementing splunk , to come up with alerts/dashboard and reports ?

Hi all,

How to analyse the unstructured log and come up with a plan to create the appropriate alerts/dashboard and reports before going to splunk implementation .

Thank you all for your valuable time ..

I would recommend downloading the free version of Splunk on your desktop/laptop and ingesting a sample of the log. This will allow you to analyze the log and play with it before pushing it to your production Splunk instance. This is assuming you already have Splunk in production. Either way, you can download Splunk from splunk.com and use it for free for up to 500MB of ingestion per day.


or you can ask the log developer what to pay attention to and what they need to be alerted or reported on

