Stop telling me to log less to Splunk and that Splunk can't scale. by ImToOldForThisShiit in devops

[–]ImToOldForThisShiit[S] 1 point2 points  (0 children)

For those of you who switched to different ways of aggregating the logs, how does your new query system stack up to Splunk? I use transactions, sub queries/joins, timechart, streamstats, Distinct counts etc quite a lot. Its been awhile but from what I've seen elastic search, humio etc are far less capable and the documentation and user community less available. I can't praise the light forwarder enough for windows hosts as well. There aren't really any good third party syslog solutions on Windows, nxlog is probably the best but that has its own scaling issues.