When comparing Loggly vs Splunk, the Slant community recommends Loggly for most people. In the question“What are the best log aggregation & monitoring tools?” Loggly is ranked 6th while Splunk is ranked 8th. The most important reason people chose Loggly is:
Ranked in these QuestionsQuestion Ranking
Pro Easy to set up
You only have to set up a HTTP JSON input and there are community examples to guide you.
Pro Supports raw text, syslogs, and JSON
Raw text, syslogs, and JSON can be fed to Loggly.
Pro Easy to use, powerful search
It's human readable, intuitive, fast and with auto-complete to boot. And if you need more advanced functionality out of your queries, 120+ page search manual will give you an insight in how much is actually possible.
Pro Widely used
De facto standard for log aggregation, monitoring, analysis and reporting.
Pro Real-time graphs
You can create visualizations that update in real time.
OS X, Linux & Windows are supported. You can also access Splunk from iOS and Android devices.
Pro Free version
With restrictions on log size and devices a free version is available.
Splunk can turn searches into alerts.
Pro Understands data in any format or language
Pro Extendable via a large selection of apps
Additional functionality can be added with over 500 apps.
Pro Scales effortlessly
It is built for enterprise use, meaning it scales easily.
Con Difficult to setup
Setup is not easy, the whole process is disjointed, with open source libraries that regularly change and out of date installation instructions.
Loggly QUICKLY overflows the 200mb daily free allowance.
Con The UI is confusing
The UI is very difficult to use, but it does offer a lot of features.
Con Timestamps are in UTC in the UI, and can't be converted
Loggly shows all timestamps in UTC, and the bookmarklet that's supposed to convert them to local time doesn't work.
Splunk is pretty expensive compared to other solutions.
The interface and service are very antiquated