Asking Vendors to Create Usable Log Data

Here at Splunk, we often talk about best practices to create log events regardless if they are written to file, a network port, or come from the standard output of some program. Since this has been discussed before, I won’t enumerate these practices here, but I will allude to them for the purposes of this topic. Furthermore, adding useful information to your generated log events so they can be used for multiple contexts, a concept in line with semantic logging, discussed in this video by Rob Das, compliments the best practices. This is great for log events (or time series events as I use this phrase interchangeably with log events) that you yourself can generate, but what…

» Continue reading

Webinar: How to use Log Files to Create Advanced Analytics and Reporting

On Wednesday, Nov 16th at 9 am PDT, Peter Zadrozny, Developer Evangelist at Splunk (and author of many Java based books and ex-CTO of BEA Systems Europe), will be presenting on “How to Use Log files to Create Advanced Analytics and Reporting”.

In this webinar Peter will discuss:

  • Importance of building a better foundation for your applications
  • Better logging practices to embed in-depth analysis functions within your application
  • Using the freely available operational information in logs for effective and intelligent reporting and analytics for your application
  • Strategic value that Splunk delivers in driving operational and business value through reporting and analytics

This presentation will be followed by an audience Q&A.

Mark your calendars – register here for…

» Continue reading

Event Correlation

It has been a while since anyone has written a direct blog entry on event correlation here at Splunk so I thought I would write one today. Event correlation can loosely be defined as a technique to relate any number of events with some identifiable patterns (and optionally act upon the relationship). Security vendors may narrowly claim that event correlation is the ability to correlate security related events and alert upon their existence. This is a subset of what event correlation can be. For instance, in a hypothetical case,  I can correlate that if it rains on a major Monday holiday, end of day total sales are lower than average sales for a brick and mortar retail shop. This case…

» Continue reading

Largest SplunkLive yet hits the Nation’s Capital featuring IT Gurus from The Washington Post and Federal Agencies

More than 200 people joined us last week in Washington, DC for our largest SplunkLive ever–doubling the number of attendees from the 2009 SplunkLive DC event! Representatives from great companies like BAE, Comcast, Lockheed Martin, McAfee, Qwest Communications, Verizon and representatives from nearly every branch of Federal government were in attendance.

Splunk’s Co-Founders Erik Swan and Rob Das started the day detailing why they created Splunk. Everyone knew there was value in IT data, but the way to search and understand it was complex and troublesome. Google was great for easily and logically finding information on the World Wide Web. Why not apply the same thinking to our log files and IT data? And…

» Continue reading