Documentation: 3.1
Print Version Contents
This page last updated: 07/13/07 09:07am

Search

What search technology underlies Splunk? Lucene?

Splunk has developed its own search technology specifically designed for the unique problem of indexing IT data in real-time. Splunk's R&D team includes some of the world's foremost search engine architects and they've spent years solving problems that are unique to this class of data.

Does Splunk do correlation?

Yes, Splunk has many features that correlate data. Splunk automatically classifies datasources and events, so that you can search for all occurrences of the same type of events over time, and alert based on seeing more than a certain threshold of a like set of events. It also automatically finds relationships based on values in the events, such as shared usernames and threadids. You can correlate data on an ad hoc basis by navigating events sharing IP addresses, user names and other values just by pointing and clicking. It provides robust alerting. Splunk 3.0's expanded search language lets you perform complex correlation within a single search, such as finding all IP addresses with more than10 firewall denies that also have accepts.

Previous: Data Management    |    Next: Licensing

Comments

No comments have been submitted.

Log in to comment.