Why Splunk?
Splunk is an enterprise platform for the central administration of raw IT data, such as log files, configurations and business data. Central indexing of data allows for system-wide searches that are interactive and take place in real time. Data can be linked and enriched using existing information and knowledge. All search results and analyses are visualised using easy-to-read graphics, and are available in real time and in the long term for audits, monitoring and alerting.
The log management cycle: