±Forensic Focus Partners

±Your Account


Nickname
Password


Forgotten password/username?


Membership:
New Today: 3
New Yesterday: 7
Overall: 27330
Visitors: 65

±Follow Forensic Focus

Join our LinkedIn group

Subscribe to news

Subscribe to forums

Subscribe to blog

Subscribe to tweets

Splunk alternatives

Forensic software discussion (commercial and open source/freeware). Strictly no advertising.
Reply to topicReply to topic Printer Friendly Page
Forum FAQSearchView unanswered posts
 
  

Splunk alternatives

Post Posted: Wed Feb 13, 2013 6:46 am

Hey guys,

I'm looking for a good, freeware alternative for Splunk. I'm more than OK with an open source solution.
In my search, I stumbled upon the ManageEngine EventLog Analyzer which is quite good, but not exactly what I'm looking.

I would love to hear with what tools you are working for log analysis and aggregation.

Thanks  

WarlocK88
Member
 
 
  

Re: Splunk alternatives

Post Posted: Thu Feb 28, 2013 9:01 am

Try Kiwi Syslog server. The free version is good, but doesn't come with the agent software. You can get round this by setting up SNMP trapping. Which leads to the question as to what it is your're monitoring, servers, network devices, both?

SNMP works well for network devices, not so great in my opinion on windows machines. An agent software like Snare (free) is pretty good and combined with Kiwi Syslog offers a pretty decent syslog system in all.

In terms of log analysis, not familiar with any decent freeware tools besides splunk. You could always learn a scripting language like Perl, which isn't too hard, tons of free tutorials out there, and great for log analysis.  

Migs
Newbie
 
 
  

Re: Splunk alternatives

Post Posted: Fri May 10, 2013 9:55 am

Post is old, but for reference you might also be of interest in ELSA (dev now supported by Mandiant).

ELSA
code.google.com/p/ente...d-archive/  

wexxlar
Newbie
 
 
Reply to topicReply to topic

Share this forum topic to encourage more replies



Page 1 of 1