@pinVie - IMHO, I think you're asking the right question. Here is my take on the pros/cons:
Hunk
Pros:
1. Easy to use with pre-existing Hadoop clusters
2. No forwarder or indexer setup required
Cons:
3. Has inherent delay in search results that comes with traditional map reduce jobs
4. You have to manage a Hadoop cluster unless you use something like Amazon (Even there you'll have to manage it)
Splunk
Pros:
1. Speed (We did testing of the same scenario. In our scenario, with the same computer power, Splunk won)
2. Splunk Manages many of the details for you
3. Only need to manage one stack and not an outside cloud stack
4. Heard that Splunk is map/reduce written in c++ with python front end and it will be hard to beat the implementation
5. More mature product even though the Hunk team is very responsive
Cons:
1. Configuration will be more complex on the Splunk side. You will probably need an indexer cluster and forwarders to get your data into splunk.
2. Vendor Lock in. I've had customers say that if they want to do other things with the data they cannot manipulate the data once it is in Splunk and they were worried about their vendor lock in
... View more