|
|
|
|
|
by hedora
2166 days ago
|
|
Also, splunk is considerably more difficult to use (no CLI, loses jobs, etc) and less powerful (no joins, incomplete results) than a farm of Linux log servers and some ssh tooling, such as cluster ssh, or whatever. There’s also the question of whether the splunk log agents are more or less of a pain to administer than whatever log management they replace. Finally, there’s the question of how the resulting reports shape people’s behavior and productivity. If you add that all up, learning it is a waste of time for people that can code up a join in perl from muscle memory, but it saves training time for people that can’t. In the end, every one less productive than they would be with some other tool. |
|