What is Splunk?
Splunk is a search engine for IT data. It's software that lets you search and analyze all the data your IT infrastructure generates from a single location in real time. We call this IT Search. No need for databases, connectors, custom parsers or proprietary consoles. Just your imagination and a web browser! Now you can troubleshoot IT problems and investigate security incidents in minutes, not hours or days. Monitor all your applications, servers and network devices from one place. Report on all your compliance controls in a fraction of the time.
Ready to join the Splunk community? Read on to learn more. Or download Splunk now for free.
It's Software — Download and Install It in 5 Minutes
Splunk is a self-contained software package that runs on all major operating systems - just pick your platform, download and install. You're up and running with a web interface for users and an engine for indexing your IT data.
Index Live Data
Splunk can index any IT data from any source in real time. We call this Universal Indexing. Point your servers or network devices' syslog at Splunk, set up WMI polling, monitor any live logfiles, enable change monitoring on your filesystem or the Windows registry, schedule a script to grab system metrics. No matter how you get the data, or what format it's in, Splunk will index it the same way - without any specific parsers or adapters to write or maintain. It stores both the raw data and the rich index in an efficient, compressed, filesystem-based datastore, with optional data signing and auditing if you need to prove data integrity.
Learn more about IT data
Deploy Splunk Everywhere
But what if the data you need isn't available over the network or visible to the server where Splunk is installed? No problem. You can deploy the same Splunk software across your staging and production environment servers to monitor local application logfiles, capture the output of status commands on a schedule, grab performance metrics or watch the file system for configuration, permissions and attribute changes. These Splunk forwarders securely send this data in real time to your central Splunk server. They run with a minimal footprint and can be centrally controlled with the Splunk built-in deployment server. You can even use them to clone data to multiple Splunk indexers for high availability and route a subset of the data to other systems.
Watch the "Deploying Splunk" video
Scale It Out
We've spent years tuning Splunk's core technology so it can index hundreds of gigabytes a day on a single commodity Windows, Linux or Unix server. But what if you have terabytes a day? No problem. You can add more index servers for different datasources, applications or datacenters. Or load balance data to multiple index servers. Users can see all these servers as a single logical datastore thanks to distributed search.
Watch the "Scale Splunk" video
Secure It and Set Up an Archiving Policy
Once all your IT data is continuously indexed by Splunk, you're in control of it. Integrate with LDAP and Active Directory and map groups to Splunk roles. Filter what data users see by role. Set up an archiving policy based on datastore size or age. And because all the data needed to troubleshoot, investigate security incidents and demonstrate compliance is persisted in Splunk, you can restrict access on sensitive production servers.
Watch the "Secure Splunk" video
Build and Deploy IT Apps
Now you’re indexing and leveraging all your IT data, wouldn’t it be great to install Apps on Splunk that let you do even more? Well you can. Choose from Apps for managing operating systems - Windows, Linux and Unix; for use cases - enterprise security, PCI compliance and change management; and for troubleshooting and reporting technologies - Blue Coat, Cisco and F5. Easily browse and dynamically switch between Apps running on your Splunk instance using the Splunk Launcher interface. Want to build your own? Splunk's App Development Framework makes it easy for customers, partners and the community to innovate on Splunk and get more from IT Search.
Browse Splunk Apps
