Refine your search:

Splunk has many capabilities for correlating events over time, by keyword, by dynamic transactions, and more. It also allows users to take action in an adhoc manner or via scheduled automated action. Does Splunk consider itself a CEP engine with the ability to identify patterns and complex events?

asked 22 Jul '10, 23:35

hulahoop's gravatar image

hulahoop ♦
2.6k141151
accept rate: 40%

edited 30 Aug '10, 18:18

Justin%20Grant's gravatar image

Justin Grant
1.7k181860

Question sounds like a trap. We know what Splunk does and how it does it. The definition of CEP is somewhat fluid and "being used as a CEP engine" even more so. There is a class of items that is commonly considered CEP, and they have certain characteristics in common. Does Splunk have enough of those characteristics that you want to call it that? I don't know, but I don't think that the labeling really matters. Can Splunk handle and process the events the way you need them to be handled and processed, and let you define rules in an acceptable way? That seems like a more substantial question.

(23 Jul '10, 00:55) gkanapathy ♦

3 Answers:

Absolutely. Splunk Enterprise Security Suite is an implementation of such a CEP. On a periodic basis, search jobs run that analyze events as they are stored in Splunk. ESS has rules drive the creation of "notable events" -- those being the real "event" and not the "symptom". I liken a notable event to an earthquake. Log messages are not "events", they are a recording of things that have happened in the infrastructure. In the same way "the building is shaking" is not an event, whereas "An earthquake is happening" is the event--comprised of many symptoms and data that classify it as an earthquake. The building could be shaking for many reasons, but when you are notified an earthquake is occuring, the reason is obvious. An earthquake is a complex event. In IT--often in security, Splunk ESS's "notable events" are the result of Complex Event Processing--These being description of the actual event which is made up of rules that have triggered off of many log messages.

link

answered 20 Aug '10, 14:01

Michael%20Wilde's gravatar image

Michael Wilde ♦
495520
accept rate: 57%

Thank you, Michael! Nice analogy.

(30 Aug '10, 18:06) hulahoop ♦

Is Splunk's CEP engine homegrown? Or is it using an open-source CEP engine, such as EsperTech?

link

answered 04 Oct '12, 14:26

shalin's gravatar image

shalin
11
accept rate: 0%

The human being is the complex engine - well, some human beings. Splunk is the facilitator.

link

answered 23 Jul '10, 04:41

araitz's gravatar image

araitz ♦
7.9k3925
accept rate: 46%

Post your answer
toggle preview

Follow this question

Log In to enable email subscriptions

RSS:

Answers

Answers + Comments

Markdown Basics

  • *italic* or _italic_
  • **bold** or __bold__
  • link:[text](http://url.com/ "Title")
  • image?![alt text](/path/img.jpg "Title")
  • numbered list: 1. Foo 2. Bar
  • to add a line break simply add two spaces to where you would like the new line to be.
  • basic HTML tags are also supported

Tags:

×47
×1

Asked: 22 Jul '10, 23:35

Seen: 2,133 times

Last updated: 04 Oct '12, 14:26

Copyright © 2005-2012 Splunk Inc. All rights reserved.