I am just a user, and from a user's perspective, it does the job.
It has quite extensive support in terms of integration. If you want to do anything, there are tools for that.
Splunk is really good at log parsing events over time. It is quick to drill in and analyze and it is quick to build a presentation layer and automate reporting. I love it for problem analysis and event management however it is not a capacity management tool.
It can be a cm tool but not a good tool for projections etc. There are many tools that claim to be cm tools but they are usually expensive and miss the basic day to day challenges of capacity management. Eg: excluding backups from day peaks, removing outliers, forward trending, accepting data from any source. Start by getting your key data extracted from reliable sources and other tools.
The charting and presentation layer is impressive and quick. It can probably do anything if you tweak it enough. I would call it a very handy tool but probably not the tool. It is not that cheap either. I have used it personally to analyze big data as well as creating knowledge from some ordinary logging. I then created some pretty cool dashboards but they were more operational dashboards.
I don't think we could afford it as a capacity tool but we can use the data it simplified.
I am just a user, and from a user's perspective, it does the job.
It has quite extensive support in terms of integration. If you want to do anything, there are tools for that.
Its reporting can be improved. That's the only complaint I have heard. I don't need the reporting part, but I know that other people in the organization need it.
In terms of new features, I got everything that I needed from the tool. If they want to expand the capabilities to different things, they can cover topics besides log aggregation, etc.
I have been using this solution for two years. I am not using it on a daily basis.
It is stable. We don't seem to have any problems related to bugs. We are very happy with it.
We have our own internal team for its maintenance.
I would recommend this solution. If you are a technical person, it does what you need. If you are not a technical person and you require graphs, that's a different story.
I would rate Splunk a ten out of ten because I have no problems with it.
