Splunk: how to merge Oracle
and Log Management
Splunk is without any doubt one the best log
management tool worldwide.
In case of Oracle the integration, or better the
automatic information flow from Oracle towards Splunk isn't very simple.
For example feeding into Splunk an entire AWR
performance report is a very challenging because only two outputs are
possible and both of them are really hard to be successfully parsed by
Splunk:
- Text only
- Blanks are
used as normal and trailing characters
- In particular
by tables with performance information it's almost impossible to
distinguish where exactly one column terminates!
- HTML
- HTML tables
are as well very hard to be successfully parsed
- HTML code
mostly contains display related information, which are not required at
all and this makes parsing more difficult
In addition to these technical issues do you
really need all information you find within an AWR performance report?
No!
Together with GM2S you are able to achieve this
goal because:
- GM2S is able to clearly
indicate you which are the performance related information. You don't
need more than 5% of an AWR report for analyzing your performance.
Please be aware that the Splunk license cost strictly depends on the
volumes of the collected data: it doesn't make any sense to collect
useless information by paying even higher license costs
- GM2S is currently developing a
solution for automatically collecting directly into Splunk all relevant
performance information
If you need to integrate Oracle into your Splunk
configuration, do not hesitate to contact us!
|