Consolidating search apps

Consolidating search apps starts to come in handy when we want to begin to develop the ever-elusive single pane of glass. There is usually a very large amount of data gathered in Splunk, though many people create disparate apps for a unique purpose. Take for instance a Network app that has all router/firewall/switch logs, and then an Active Directory app that has all Microsoft Active Directory data, as well as a Juniper SRX app in order to pay attention to the Quality Assurance environment. While these provide value to a user, the visualization often gets cumbersome on login as you have logs of different apps and titles to sift through to find the data you want to see. App consolidation is a great way to make everything ...

Get Splunk Best Practices now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.