Monitor Akamai data in Splunk, cloud service SLAs, visibility of apps, security incidents/events, Cloud Monitor real-time HTTP feed delivers data in JSON format
Using Splunk Light (free up to 500MB), to monitor docker environments w/o cloud, 2 Data Volume Containers, ports: 8000 web access, 9997 data fm forwarders.
Define use cases for fraud-categorize & prioritize; data & its threshold & algorithm rules, index data using Splunk SPL (search processing language) in realtime
Separate content w/ tabs in dashboards, activate tabs for searches by clicking-preventing over-showing or executing too much content at once, faster load times
New twist to extract/translate/load process (ETL) is Splunk & DB Connect, moving data fm DB to Splunk to Indexer machines; Create reports w/o knowing SQL & more
Estimating storage size for Splunk Index can get complicated; see simply web-based tool for sizing using Mustafa’s calculation + nice interface. Check it out.