Refine your search:

5
2

We're investigating how to best help customers who are using both Splunk and other operations management/monitoring tools in complex IT environments.

What we've been hearing is that customers prefer using Splunk for long-term reporting and correlation of IT data, even if the original data is gathered by other tools. What we're also hearing is that customers often have functional Tier-1 operations processes which are tightly linked with existing tools like Nagios or Remedy, and they want Splunk to work well with those existing processes.

So we're thinking that our top integration priorities should be to make it easier to:

  1. Get data from other management tools into Splunk. For example, get events and alerts from SCOM into splunk so you can report on that data and correlate it to not-from-SCOM data already in Splunk.
  2. Send alerts to other management tools. For example, raise an alert in Nagios or create a ticket in Remedy in response to a Splunk alert.

The first supports data consolidation, reporting, and correlation scenarios. The second supports consolidation of alerting and tier-1 responsibilty in IT.

Do these sound like the right priorities, and are they in the right order? What else should we be thinking about when it comes to integration with operations management tools?

asked 22 Apr '10, 17:31

Justin%20Grant's gravatar image

Justin Grant
1.7k181860
accept rate: 50%

edited 21 May '10, 17:45

Lowell's gravatar image

Lowell ♦
11.1k91289

Is this question for customers? To me internally it sounds right. There's a sort of timeliness and load distribution piece in here as well.

(22 Apr '10, 18:11) jrodman ♦

it's a question for everyone-- Splunk customers as well as folks working for Splunk who understand customer needs.

(22 Apr '10, 19:11) Justin Grant

7 Answers:

I would definitely like to see that. Along with that I also like to see an integration with Xymon, a monitoring tool (http://hobbitmon.sourceforge.net/)

link

answered 24 Apr '10, 01:12

vadud3's gravatar image

vadud3
59112
accept rate: 0%

2) is more important to me as just about everything we have can already feed into splunk. Ho0wever, we've had many requests to get data OUT of splunk and into other systems. Sending the data over syslog isn't very helpful in our case, but rather we need to extract the data from splunk and send it using other agents.

link

answered 26 Apr '10, 19:19

oreoshake's gravatar image

oreoshake
5702326
accept rate: 31%

There is also another type of integration, and that is to call and use Splunk query results (passing in a Splunj query or parameters to a Splunk query) in other apps, and not just wait for alerts to fire.

link

answered 26 Apr '10, 21:38

gkanapathy's gravatar image

gkanapathy ♦
32.4k4827
accept rate: 41%

Our primary interest would be in allowing ad hoc searching of event data that is generated by Entuity Eye of the Storm (EYE). This is a rich data source containing events relating to many parts of a monitored network. Within EYE, users are members of one or more user groups and these user groups have permission settings that determine which groups of managed devices the users have access to. Users can therefore have overlapping access to details of some devices but details of other devices may be denied to them but not others. The integration to Splunk would ideally preserve the user permissions so that one common user login would cause the appropriate access rights to be granted. This would avoid any need to independently manage access rights on both products.

link

answered 12 May '10, 19:22

jdiamond's gravatar image

jdiamond
1
accept rate: 0%

We have a significant amount of data that lives in other systems (perf data, for example) and happen to expose service interfaces to get at that data. Rather than importing that data into splunk, I'd like to be able to somehow call those services from splunk so I can correlate across. A good example would be correlating number of hits/errors to java heap utilization, where historical java heap utilization is a service call away in another system.

link

answered 21 May '10, 22:36

adavep's gravatar image

adavep
11
accept rate: 0%

I would love to be able to send alerts out via snmp and syslog and forward logs via syslog or other means to help integrate between various data sources.

link

answered 20 Jan '12, 00:04

dutchie's gravatar image

dutchie
202
accept rate: 0%

Would you like to include network information in your log analysis? If so, have a look at Network Device Monitor for NetFlow Standard on Splunkbase It's only a sample app. There's much more to NetFlow than just watching how much http data is passing through a router :-)

link

answered 04 Apr '12, 12:26

ibalabine's gravatar image

ibalabine
212
accept rate: 0%

Post your answer
toggle preview

Follow this question

Log In to enable email subscriptions

RSS:

Answers

Answers + Comments

Markdown Basics

  • *italic* or _italic_
  • **bold** or __bold__
  • link:[text](http://url.com/ "Title")
  • image?![alt text](/path/img.jpg "Title")
  • numbered list: 1. Foo 2. Bar
  • to add a line break simply add two spaces to where you would like the new line to be.
  • basic HTML tags are also supported

Tags:

×141
×19
×4
×1

Asked: 22 Apr '10, 17:31

Seen: 2,744 times

Last updated: 04 Apr '12, 12:26

Copyright © 2005-2012 Splunk Inc. All rights reserved.