Yes, what you want to do can certainly be done. For you it will take weeks of learning, trial and error. For a seasoned Splunk administrator, probably a day or two at most (though the analysis of the data is not described, so that is an unknown). If you want to do this by yourself you will have to dedicate a lot of time to making it happen. If it is worth that to you, go for it. If you want to do what you have described, though, you'll probably have to get a license, because the free version will not do everything that you want. If you need it soon, it would be best to hire someone with the expertise to do what you want, and learn from observing. There are the costs, either time or money, plus probably licensing fees in either case.
You aren't looking at a very difficult thing to do in Splunk, but it requires an understanding of the product that comes with a price.
... View more