When comparing Splunk vs Rocana, the Slant community recommends Splunk for most people. In the question“What are the best log management, aggregation & monitoring tools?” Splunk is ranked 11th while Rocana is ranked 16th. The most important reason people chose Splunk is:
It's human readable, intuitive, fast and with auto-complete to boot. And if you need more advanced functionality out of your queries, [120+ page search manual](http://docs.splunk.com/index.php?title=Documentation:Splunk:Search:Whatsinthismanual:6.0beta&action=pdfbook) will give you an insight in how much is actually possible.
Ranked in these QuestionsQuestion Ranking
Pro Easy to use, powerful search
It's human readable, intuitive, fast and with auto-complete to boot. And if you need more advanced functionality out of your queries, 120+ page search manual will give you an insight in how much is actually possible.
Pro Widely used
De facto standard for log aggregation, monitoring, analysis and reporting.
Pro Scales effortlessly
It is built for enterprise use, meaning it scales easily.
Pro Real-time graphs
You can create visualizations that update in real time.
OS X, Linux & Windows are supported. You can also access Splunk from iOS and Android devices.
Pro Free version
With restrictions on log size and devices a free version is available.
Splunk can turn searches into alerts.
Pro Understands data in any format or language
Pro Extendable via a large selection of apps
Additional functionality can be added with over 500 apps.
Pro Great "out-of-the-box" analytics
Beyond simple rules-based alerting, Rocana Ops creates statistical models for each of the metrics you want to track and evaluates as data streams in to provide nearly instantaneous feedback on how your systems are performing. Unique WARN (Weighted Analytic Risk Notifications) Scores indicate components that are trending to the good or bad. Users can create custom metrics, which get evaluated just the same as "out-of-the-box" metrics.
Pro Highly scalable
Collect and analyze multiple TBs of data per day, built on Hadoop components Rocana Ops is a highly-distributed system offering massive scalability using commodity hardware. Rocana has customers collecting 10+ TBs of log data per day.
Rocana One free option provides up to 1TB of daily data volume for free.
Splunk is pretty expensive compared to other solutions.
The interface and service are very antiquated
Con Seriously SLOW ingest
Their docs and sales say it will ingest up to 20k EPS, but reality is more like 1k eps per server.
Con Complex set up process
Appears to be an expensive solution.
Con Doesn't run on a laptop
Well, maybe you can squeeze Rocana Ops on a laptop, but it is designed as a highly-distributed, fault-tolerant system and requires a Hadoop distro as the underlying platform.