<?xml version="1.0" encoding="utf-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	>
<channel>
	<title>Comments on: Distributed Logging: Syslog-ng &amp; Splunk</title>
	<atom:link href="http://www.igvita.com/2008/10/22/distributed-logging-syslog-ng-splunk/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.igvita.com/2008/10/22/distributed-logging-syslog-ng-splunk/</link>
	<description>A goal is a dream with a deadline.</description>
	<pubDate>Sun, 05 Jul 2009 04:03:23 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.7.1</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: Steve</title>
		<link>http://www.igvita.com/2008/10/22/distributed-logging-syslog-ng-splunk/comment-page-1/#comment-149112</link>
		<dc:creator>Steve</dc:creator>
		<pubDate>Tue, 25 Nov 2008 21:59:56 +0000</pubDate>
		<guid isPermaLink="false">http://www.igvita.com/?p=196#comment-149112</guid>
		<description>Just a fix to Kent's post - you had the address wrong (or it has changed):

http://developers.facebook.com/scribe/</description>
		<content:encoded><![CDATA[<p>Just a fix to Kent&#8217;s post - you had the address wrong (or it has changed):</p>
<p><a href="http://developers.facebook.com/scribe/" rel="nofollow">http://developers.facebook.com/scribe/</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: edward</title>
		<link>http://www.igvita.com/2008/10/22/distributed-logging-syslog-ng-splunk/comment-page-1/#comment-142217</link>
		<dc:creator>edward</dc:creator>
		<pubDate>Thu, 30 Oct 2008 19:32:01 +0000</pubDate>
		<guid isPermaLink="false">http://www.igvita.com/?p=196#comment-142217</guid>
		<description>is facebook's &lt;b&gt;open-souce&lt;/b&gt; dist. log solution better than spluks? Have anybody tried ?</description>
		<content:encoded><![CDATA[<p>is facebook&#8217;s <b>open-souce</b> dist. log solution better than spluks? Have anybody tried ?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Kent</title>
		<link>http://www.igvita.com/2008/10/22/distributed-logging-syslog-ng-splunk/comment-page-1/#comment-141733</link>
		<dc:creator>Kent</dc:creator>
		<pubDate>Sat, 25 Oct 2008 00:06:29 +0000</pubDate>
		<guid isPermaLink="false">http://www.igvita.com/?p=196#comment-141733</guid>
		<description>Splunk is great but their licensing model is fundamentally flawed for encouraging broad adoption because you get financial PUNISHED heavily for using it for what it's best at; aggregating and analyzing lots of log data.  It's always made me sad.  I spoke to someone from Splunk back at the first CloudCamp SF and they said they were working on that.  But, alas, nothing I've seen yet.  I'll have to follow up.

I just saw that Facebook released their dist. logging solution open source as well.  But, I haven't messed with it at all.  Would be good to hear any feedback.
http://developer.facebook.com/scribe/</description>
		<content:encoded><![CDATA[<p>Splunk is great but their licensing model is fundamentally flawed for encouraging broad adoption because you get financial PUNISHED heavily for using it for what it&#8217;s best at; aggregating and analyzing lots of log data.  It&#8217;s always made me sad.  I spoke to someone from Splunk back at the first CloudCamp SF and they said they were working on that.  But, alas, nothing I&#8217;ve seen yet.  I&#8217;ll have to follow up.</p>
<p>I just saw that Facebook released their dist. logging solution open source as well.  But, I haven&#8217;t messed with it at all.  Would be good to hear any feedback.<br />
<a href="http://developer.facebook.com/scribe/" rel="nofollow">http://developer.facebook.com/scribe/</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Ilya Grigorik</title>
		<link>http://www.igvita.com/2008/10/22/distributed-logging-syslog-ng-splunk/comment-page-1/#comment-141663</link>
		<dc:creator>Ilya Grigorik</dc:creator>
		<pubDate>Fri, 24 Oct 2008 02:10:24 +0000</pubDate>
		<guid isPermaLink="false">http://www.igvita.com/?p=196#comment-141663</guid>
		<description>Dmitriy, there is an entire collection of generic *nix network loggers: syslogd, socklog, rsyslog (as Mark mentioned). Also, every language has a collection of logger implementations (Java, for one, seems to have a few too many). In Ruby land, a good one is: analogger (same guys that did swiftiply). 

Having said that, in terms of actual log analysis, I'm not aware of any good alternative for log analysis. phpLogCon is one, but it's not nearly as exciting.</description>
		<content:encoded><![CDATA[<p>Dmitriy, there is an entire collection of generic *nix network loggers: syslogd, socklog, rsyslog (as Mark mentioned). Also, every language has a collection of logger implementations (Java, for one, seems to have a few too many). In Ruby land, a good one is: analogger (same guys that did swiftiply). </p>
<p>Having said that, in terms of actual log analysis, I&#8217;m not aware of any good alternative for log analysis. phpLogCon is one, but it&#8217;s not nearly as exciting.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Vysnu &#187; Magnolia&#160;Post</title>
		<link>http://www.igvita.com/2008/10/22/distributed-logging-syslog-ng-splunk/comment-page-1/#comment-141588</link>
		<dc:creator>Vysnu &#187; Magnolia&#160;Post</dc:creator>
		<pubDate>Thu, 23 Oct 2008 07:04:06 +0000</pubDate>
		<guid isPermaLink="false">http://www.igvita.com/?p=196#comment-141588</guid>
		<description>[...] Developer News, Interviews and LinksRating: &#9733; &#9733; &#9733; &#9733;&#160;&#9733; Distributed Logging: Syslog-ng &amp; Splunk -&#160;igvita.comRating: &#9733; &#9733; &#9733; [...]</description>
		<content:encoded><![CDATA[<p>[...] Developer News, Interviews and LinksRating: &#9733; &#9733; &#9733; &#9733;&nbsp;&#9733; Distributed Logging: Syslog-ng &#38; Splunk -&nbsp;igvita.comRating: &#9733; &#9733; &#9733; [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Dmitriy</title>
		<link>http://www.igvita.com/2008/10/22/distributed-logging-syslog-ng-splunk/comment-page-1/#comment-141577</link>
		<dc:creator>Dmitriy</dc:creator>
		<pubDate>Thu, 23 Oct 2008 02:06:39 +0000</pubDate>
		<guid isPermaLink="false">http://www.igvita.com/?p=196#comment-141577</guid>
		<description>Ilya,
Mind posting what you have in mind for distributed log aggregators other than Splunk?</description>
		<content:encoded><![CDATA[<p>Ilya,<br />
Mind posting what you have in mind for distributed log aggregators other than Splunk?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Ilya Grigorik</title>
		<link>http://www.igvita.com/2008/10/22/distributed-logging-syslog-ng-splunk/comment-page-1/#comment-141548</link>
		<dc:creator>Ilya Grigorik</dc:creator>
		<pubDate>Wed, 22 Oct 2008 17:52:52 +0000</pubDate>
		<guid isPermaLink="false">http://www.igvita.com/?p=196#comment-141548</guid>
		<description>Tobi, perhaps lower the logging level? Or, I'm not sure how Splunk licensing is structured, but theoretically, you could run multiple instances. Albeit, of course, you loose the ability to query all of the data if you go down that route.

Last but not least, it's a hefty price tag, but it's a perpetual license.</description>
		<content:encoded><![CDATA[<p>Tobi, perhaps lower the logging level? Or, I&#8217;m not sure how Splunk licensing is structured, but theoretically, you could run multiple instances. Albeit, of course, you loose the ability to query all of the data if you go down that route.</p>
<p>Last but not least, it&#8217;s a hefty price tag, but it&#8217;s a perpetual license.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: tobi</title>
		<link>http://www.igvita.com/2008/10/22/distributed-logging-syslog-ng-splunk/comment-page-1/#comment-141545</link>
		<dc:creator>tobi</dc:creator>
		<pubDate>Wed, 22 Oct 2008 17:13:31 +0000</pubDate>
		<guid isPermaLink="false">http://www.igvita.com/?p=196#comment-141545</guid>
		<description>At our log volume we would pay more than 20k for splunk :-(</description>
		<content:encoded><![CDATA[<p>At our log volume we would pay more than 20k for splunk :-(</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Ilya Grigorik</title>
		<link>http://www.igvita.com/2008/10/22/distributed-logging-syslog-ng-splunk/comment-page-1/#comment-141543</link>
		<dc:creator>Ilya Grigorik</dc:creator>
		<pubDate>Wed, 22 Oct 2008 16:44:24 +0000</pubDate>
		<guid isPermaLink="false">http://www.igvita.com/?p=196#comment-141543</guid>
		<description>Ah, that's awesome. Syslog-ng can also do TLS, but like Splunk, it requires a premium license to make that work. Thanks for the tip Mark.</description>
		<content:encoded><![CDATA[<p>Ah, that&#8217;s awesome. Syslog-ng can also do TLS, but like Splunk, it requires a premium license to make that work. Thanks for the tip Mark.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Mark</title>
		<link>http://www.igvita.com/2008/10/22/distributed-logging-syslog-ng-splunk/comment-page-1/#comment-141540</link>
		<dc:creator>Mark</dc:creator>
		<pubDate>Wed, 22 Oct 2008 16:04:50 +0000</pubDate>
		<guid isPermaLink="false">http://www.igvita.com/?p=196#comment-141540</guid>
		<description>If you look @ rsyslog it can also do ssl tunneled syslog, which is ideal if you have an ec2 cloud and an offsite syslog &amp; splunk setup.</description>
		<content:encoded><![CDATA[<p>If you look @ rsyslog it can also do ssl tunneled syslog, which is ideal if you have an ec2 cloud and an offsite syslog &amp; splunk setup.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
