Using Splunk Light (free up to 500MB), to monitor docker environments w/o cloud, 2 Data Volume Containers, ports: 8000 web access, 9997 data fm forwarders.
Define use cases for fraud-categorize & prioritize; data & its threshold & algorithm rules, index data using Splunk SPL (search processing language) in realtime
Separate content w/ tabs in dashboards, activate tabs for searches by clicking-preventing over-showing or executing too much content at once, faster load times
New twist to extract/translate/load process (ETL) is Splunk & DB Connect, moving data fm DB to Splunk to Indexer machines; Create reports w/o knowing SQL & more
Estimating storage size for Splunk Index can get complicated; see simply web-based tool for sizing using Mustafa’s calculation + nice interface. Check it out.
3rd UK debate tracked on tweets w/o Cameron & Clegg, still talked about even when absent; Splunk tracks findings-positive, negative, overall sentiments & tweets
Better ways to do tedious spreadsheet searches in Splunk: import files, manipulate data using search language, use lookup for logs by matching lookup criteria.