Re: [lopsa-discuss] splunk alternatives

2010-03-03 Thread Joseph Kern
I agree about splunk, it's a great product. On Wed, Mar 3, 2010 at 4:26 AM, Trey Darley wrote: > My experience with the product has been very good. It's incredibly > capable. I do wish that O'Reilly would do a Splunk in a Nutshell book, > though, as the documentation could be better. > > Cheers,

Re: [lopsa-discuss] splunk alternatives

2010-03-03 Thread Trey Darley
My experience with the product has been very good. It's incredibly capable. I do wish that O'Reilly would do a Splunk in a Nutshell book, though, as the documentation could be better. Cheers, --Trey ++-++ Trey Darley - Brussel

Re: [lopsa-discuss] splunk alternatives

2010-03-01 Thread david
u are really pumping out the logs. Maybe I missed >>>> it, but did you state how many logs you are producing as a log/sec or >>>> kb/sec estimate? >>>> >>>> --- >>>> Puryear IT, LLC - Baton Rouge, LA - http://www.puryear-it.com/ >>>&

Re: [lopsa-discuss] splunk alternatives

2010-03-01 Thread Rob Das
x/UNIX technologies >>> >>> Download our free ebook "Best Practices for Linux and UNIX Servers" >>> http://www.puryear-it.com/pubs/linux-unix-best-practices/ >>> >>> >>> -Original Message- >>> From: discuss-boun...@lop

Re: [lopsa-discuss] splunk alternatives

2010-03-01 Thread david
; >> Download our free ebook "Best Practices for Linux and UNIX Servers" >> http://www.puryear-it.com/pubs/linux-unix-best-practices/ >> >> >> -----Original Message- >> From: discuss-boun...@lopsa.org [mailto:discuss-boun...@lopsa.org] On >> Behalf Of da..

Re: [lopsa-discuss] splunk alternatives

2010-03-01 Thread Rob Das
r-it.com/pubs/linux-unix-best-practices/ > > > -Original Message- > From: discuss-boun...@lopsa.org [mailto:discuss-boun...@lopsa.org] On > Behalf Of da...@lang.hm > Sent: Monday, March 01, 2010 1:00 PM > To: Rob Das > Cc: discuss@lopsa.org > Subject: Re: [lopsa-discuss]

Re: [lopsa-discuss] splunk alternatives

2010-03-01 Thread Rob Das
s after > now', but you cannot say 'do this search on data that arrived/arrives after > 5 min ago' > > David Lang > > On Mon, 1 Mar 2010, Rob Das wrote: > > Date: Mon, 1 Mar 2010 10:26:38 -0800 >> From: Rob Das >> To: discuss@lopsa.org >>

Re: [lopsa-discuss] splunk alternatives

2010-03-01 Thread Dustin Puryear
uryear-it.com/pubs/linux-unix-best-practices/ -Original Message- From: discuss-boun...@lopsa.org [mailto:discuss-boun...@lopsa.org] On Behalf Of da...@lang.hm Sent: Monday, March 01, 2010 1:00 PM To: Rob Das Cc: discuss@lopsa.org Subject: Re: [lopsa-discuss] splunk alternatives Rob,

Re: [lopsa-discuss] splunk alternatives

2010-03-01 Thread david
y 'do this search on data that arrived/arrives after 5 min ago' David Lang On Mon, 1 Mar 2010, Rob Das wrote: Date: Mon, 1 Mar 2010 10:26:38 -0800 From: Rob Das To: discuss@lopsa.org Subject: [lopsa-discuss] splunk alternatives First, please forgive me if this email is overly long.

[lopsa-discuss] splunk alternatives

2010-03-01 Thread Rob Das
First, please forgive me if this email is overly long. Yes, SEC and Splunk are different in many ways - both useful in the right context. I have a few questions. How much data per day are you talking about? Are you interested in looking at historical data and comparing it against current data?

Re: [lopsa-discuss] splunk alternatives

2010-03-01 Thread Paul DiSciascio
I have two demo instances installed, and it's very pretty, but I think it's much more feature-rich than what I need for the problem I'm trying to solve. I dont really need the alerting and monitoring features as much as just simple searching and filtering. I just dropped in phplogcon, and it's a

Re: [lopsa-discuss] splunk alternatives

2010-03-01 Thread Tom Limoncelli
Have you tried Splunk yourself? My friends that have downloaded the free demo have ended up finding the money for it. It is that good. Tom On Sun, Feb 28, 2010 at 8:32 PM, Paul DiSciascio wrote: > I'm looking for a good way to share log files on a centralized syslog server > with about 10-20

Re: [lopsa-discuss] splunk alternatives

2010-02-28 Thread Joshua Penix
On Feb 28, 2010, at 5:32 PM, Paul DiSciascio wrote: > I'm looking for a good way to share log files on a centralized syslog server > with about 10-20 people/developers who are familiar with the log formats but > not very much with unix tools. I'd give phpLogCon a look: http://www.phplogcon.com

Re: [lopsa-discuss] splunk alternatives

2010-02-28 Thread david
On Sun, 28 Feb 2010, Doug Hughes wrote: > Paul DiSciascio wrote: >> I'm looking for a good way to share log files on a centralized syslog >> server with about 10-20 people/developers who are familiar with the log >> formats but not very much with unix tools. They want an easy way to >> dig thr

Re: [lopsa-discuss] splunk alternatives

2010-02-28 Thread Doug Hughes
Paul DiSciascio wrote: > I'm looking for a good way to share log files on a centralized syslog server > with about 10-20 people/developers who are familiar with the log formats but > not very much with unix tools. They want an easy way to dig thru the logs > and filter out junk they're not inte

[lopsa-discuss] splunk alternatives

2010-02-28 Thread Paul DiSciascio
I'm looking for a good way to share log files on a centralized syslog server with about 10-20 people/developers who are familiar with the log formats but not very much with unix tools. They want an easy way to dig thru the logs and filter out junk they're not interested in, but still have near