Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Does ClickHouse or anything else out there that even remotely compete with Splunk for adhoc troubleshooting/forensics/threat hunting type work?

I started off with Splunk and every time I try Elasticsearch I feel like I'm stuck in a cage. Probably why they can charge so much for it.



why is splunk better than ES?


I really want to answer you but I'm struggling a bit b/c I haven't worked with ES in a minute. Splunk just tends to be able to eat just about any kind of structured or unstructed content, operates on a pipeline concept similar to that of a unix shell or (gasp) powershell, and has a rich set of data manipulation of modification commands built in:

https://docs.splunk.com/Documentation/SplunkLight/7.3.6/Refe...

I primarily use it for security-related analysis, which is lowish on metrics and high on adhoc folding and mutilation of a very diverse set of data structures and types.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: