Event Correlation engine which helps in identifying the right alarm [parent event] where the issue occurs is really awesome.
Does not allow proper connection to our ticketing system Does not properly correlate events Does not remove alerts already worked Does not allow comments
The fact that it is possible to search on Splunk; You don't have to access your actual servers to see logs; There are enormous search and reporting capabilities;
There are certain functionalities that don't come out of the box and require additional licensing if you truly want to get the best use of the tool. This process could be more transparent
Event Correlation engine which helps in identifying the right alarm [parent event] where the issue occurs is really awesome.
The fact that it is possible to search on Splunk; You don't have to access your actual servers to see logs; There are enormous search and reporting capabilities;
Does not allow proper connection to our ticketing system Does not properly correlate events Does not remove alerts already worked Does not allow comments
There are certain functionalities that don't come out of the box and require additional licensing if you truly want to get the best use of the tool. This process could be more transparent