What other pieces of software are there in this class? Who are the competitors?
Their search interface and field extraction let you perform complex queries on your logs. We used the following query to identify users that were having a bad time on the site, by counting slow queries by user and adding them up:
"slow query" source="/var/log/application.log" | rex field=_raw "in (?<time>\\d+)ms" | search time>2000 | rex field=_raw "User: (?<login>[^\\s]+) " | top login
You can do much more complex queries--it's better to think of Splunk as a temporal database than a log aggregator.
Does anyone know if Graylog or other logging solutions can do the same thing? Splunk is amazing, but it's annoying to manage the infrastructure and it's crazy expensive.