Security Basics mailing list archives

Re: SIM Suggestions


From: "Kurt Buff" <kurt.buff () gmail com>
Date: Thu, 31 Jul 2008 12:22:55 -0700

On Wed, Jul 30, 2008 at 8:01 AM, Ramki B Ramakrishnan <bramkie () gmail com> wrote:
Splunk is good for log analysis and AFIK more economical...

http://www.splunk.com/applications

Any views on Splunk would add value to this thread.

-----
Ramki B. Ramakrishnan
Security Enthusiast
GIAC:GSEC, CvA


Yes, I have a view. I just took a look at their pricing, and there is
no way on Earth I can afford their pricing. Between my Windows
servers, my *nix servers and my firewall, I generate easily 2gb of
logs to my syslog server daily, and I don't log all I'd like to
gather. But, for a manufacturing company with fewer than 300 people,
this will never fly.

Insanely overpriced, and no matter how good it is, I'll not be able to use it.

Bummer.

Kurt


Current thread: