Splunk Search

Help! I need to know if Splunk is capable of the following;

Charles_S
New Member

• Need to be able to view the health of the servers and applications running across all three datacentres in a single dashboard.
• Graphic representation and summary of collected data.
• Runs “on premises”
• Capacity monitoring
• Integration to other products to collate data… Apache logs, Nagios, Jenkins, etc.
• Can extend to cover servers in other cloud providers… AWS, Azure, etc
• Alert notification
• Capacity analysis
• “fault” tracking.
• LDAP integration
• API integration, show we want to automate monitoring of new servers from the shop.

Nice to have…
• Able to present a “restricted” view to projects of the data for just there dedicated server

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Yes, Splunk is capable of all that. The caveat is Splunk's capabilities are limited by the data given to it. For example, fault tracking is only possible if the faults are reported to Splunk, which means the right log files have to be monitored. You may need to modify your firewall to allow data to flow to Splunk from the various sources. There will be some effort required on your part - you may need to install Universal Forwarders on your servers to get data into Splunk; dashboards will have to be created; and so on.

You can post separate, more specific questions on this site if you need help getting going.

---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

Understanding Generative AI Techniques and Their Application in Cybersecurity

Watch On-Demand Artificial intelligence is the talk of the town nowadays, with industries of all kinds ...

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

Using the Splunk Threat Research Team’s Latest Security Content

REGISTER HERE Tech Talk | Security Edition Did you know the Splunk Threat Research Team regularly releases ...