I would emphasize scalable and usable. One (1) person (not a software developer) with basic network, infrastructure, and hardware support from the facility can install Splunk indexers, search heads, and hundreds of forwarders in a relatively short amount of time. Splunk (paid) software is supported very well by Splunk Inc. Splunk (paid and free) software is supported very well by the Splunk community (Splunk Answers). Splunk is also very well documented with Admin manuals, config references, release notes, etc...- if you can read, then you can learn Splunk. With Splunk and basic internal support, one person can be in a position to answer questions like “what happened, when, and who did it?” in an environment with multiple networks, dozens of servers, and hundreds of users. For scalability from small networks to very large enterprises it might take more than one person – depends on the person and the enterprise.
... View more