Ask HN: Splunk vs. ELK vs. others?
Can anyone recommend whether the cost of Splunk is worth it for a startup or it's better invest time in using open source solutions?
Can anyone recommend whether the cost of Splunk is worth it for a startup or it's better invest time in using open source solutions?
If you have more money than time, use Splunk.
If you are on AWS, dump your logs into Redshift -- you already know SQL and you don't have to learn another query language; and it's easy to see how to run extract/transform/load jobs. If you're on GCP, I'd investigate BigQuery before bothering with Splunk or Sumologic.
Few things to keep in mind when you do that:
Create separate schemas for your raw data and your analysis. Dump the logs into a "raw schema", run your aggregations, and write the results to a "data schema". Once your data grows and you're running more reports, it will make your life much easier.
Separate your users from the start. Create a user each for your data loads, for your aggregations and for your ad-hoce analysis. As you ramp up query volume, the separation of concerns will make it easier to use the Redshift workload manager and keep concurrency high.
Ping me if you have more questions about the set-up. lars @ intermix dot io
This isn't entirely true, you can have a generic logstash-* index and dump log lines into it (say sending from syslog). All you need is a timestamp and a string.
Later on you can reindex that data at anytime, using logstash (and/or elastic curator) and then reinterpret that data into a different index in which you will be able to graph on Kibana.
ELK is doing both centralized logging and service metrics.
Usually services log to syslog which ends up in a file like /var/log/$service.log and then we use filebeats (also from elastic) to send that file to an ELK server.