LinuxQuestions.org
Welcome to the most active Linux Forum on the web.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Server
User Name
Password
Linux - Server This forum is for the discussion of Linux Software used in a server related context.

Notices


Reply
  Search this Thread
Old 04-03-2007, 09:39 AM   #1
richinsc
Member
 
Registered: Mar 2007
Location: Utah
Distribution: Ubuntu Linux (20.04)
Posts: 224

Rep: Reputation: 32
Anyone Tried Splunk


Has Anyone here tired splunk. This advertisement is going on my screen to day. It looks promising but wanting to know what others opinions are. Is it able monitor multiple servers or does each server need it's own install.. I am of course talking about one web server but mutiple servers being monitored by splunk.

Tell me you thoughts about this. Makes a great edition to server management. Also is there any other "like" packages that you would recommend.

Last edited by richinsc; 04-03-2007 at 09:39 AM. Reason: Corrected Spelling
 
Old 04-03-2007, 10:26 AM   #2
mcupples
Member
 
Registered: Jun 2006
Location: Orlando
Distribution: FC3, FC5, CentOS4, Ubuntu 6.06
Posts: 57

Rep: Reputation: 15
Yeah, I just installed it. Doesn't appear to do anything but pretty up the logs a bit and make it easier to search through them. Naturally, it asks you to buy it immediately, but it appears to not be too intrusive.

I was going to install it on my mail server when I got this message:

"Your datastore's directory structure does not seem to be correct. Do you want Splunk to correct it? [y/N]:"

That scares me. I'm going to google that right now.
 
Old 04-03-2007, 04:59 PM   #3
itisgreen
LQ Newbie
 
Registered: Apr 2007
Posts: 3

Rep: Reputation: 0
I've been running Splunk for about 6 months now. I love it. Its much more than just making the logs pretty, it like google for everything in my infrastructure (logs, conf files, emails, you name it).

I have Splunk agents that forward to a central index (this required me purchasing a professional license) and I have other boxes that are using syslog-ng data to forward data over TCP 514 to my Splunk index.

That message you saw at startup: "Your datastore's directory structure does not seem to be correct. Do you want Splunk to correct it? [y/N]:" is refering to Splunk's index (they sometimes refer to the index as the datastore). My guess is that the location you specified for your index did not exist and Splunk was asking if you wanted it to create them or you moved your index but didn't update one of the conf files. Their support team is one of the most responsive groups I've dealt with, I bet if you sent them a note about your problem you would get a response in under a day.
 
Old 04-04-2007, 08:13 AM   #4
mcupples
Member
 
Registered: Jun 2006
Location: Orlando
Distribution: FC3, FC5, CentOS4, Ubuntu 6.06
Posts: 57

Rep: Reputation: 15
Awesome. I never considered contacting them directly as I'm using the free version. I've actually just started using logs (gasp, I know) so this seems useful. I'm fairly sure our company will never blow $2,500 on systems administration tools.
 
Old 04-21-2007, 11:27 PM   #5
richinsc
Member
 
Registered: Mar 2007
Location: Utah
Distribution: Ubuntu Linux (20.04)
Posts: 224

Original Poster
Rep: Reputation: 32
Wondering if it would be a good solution for home use. I can't blow 2500 dollars on a sys admin tool just for the index forwarding...That is what I would need to because of the fact that I have multiple systems and would need to have information forwarded to index server to thereby display the information, I can see where it would save me time from having to log into each system.
 
Old 04-23-2007, 11:35 AM   #6
itisgreen
LQ Newbie
 
Registered: Apr 2007
Posts: 3

Rep: Reputation: 0
I bet you could get away with a free license if your home load is under 500mb and you had all of your machines forward their logs via syslog. Your splunk instance could listen on 514 or tail the central syslog file
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Why this site always pop-up a splunk page? suiyi2599 General 1 04-02-2007 10:18 PM
LXer: Search your IT data with Splunk LXer Syndicated Linux News 0 02-20-2007 05:01 PM
Those Splunk ads - what ? bgeddy LQ Suggestions & Feedback 4 02-04-2007 03:31 AM
runner.splunk.com Hitboxx LQ Suggestions & Feedback 3 01-24-2007 07:09 PM
LXer: Splunk Ensures Developers get Their Open Source at Oregon State ... LXer Syndicated Linux News 0 06-26-2006 09:21 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Server

All times are GMT -5. The time now is 02:27 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration