# ELK vs Splunk

**URL:** <https://discuss.elastic.co/t/elk-vs-splunk/96700>\
**Category:** Kibana\
**Created:** [August 11, 2017, 4:49am UTC](https://discuss.elastic.co/t/elk-vs-splunk/96700 "2017-08-11T04:49:13Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![akash.01](https://avatars.discourse-cdn.com/v4/letter/a/77aa72/32.png) [@akash.01](https://discuss.elastic.co/u/akash.01)\
**Post date:** [August 11, 2017, 4:49am UTC](https://discuss.elastic.co/t/elk-vs-splunk/96700/1 "2017-08-11T04:49:13Z")

</div>

I am very new to ELK. In my organization We are thinking of migrating from Splunk Enterprise to ELK. But before doing that I was asked to test whether we are able to run all the use cases we have built on Splunk in ELK. I have completed till indexing the data. Now the problem is with querying. In splunk lets say I use a simple query "index=bluecoat category="Phishing"|table user source\_ip". This would create a table with the user with source\_ip who have visited sites categorized as phishing. Can someone help me whether this can be done using Kibana or any other app? Is it even possible to do so. Any help at the earliest would be appreciated.

---

<div class="post-metadata">

**Author:** ![shaktigupta200](https://avatars.discourse-cdn.com/v4/letter/s/b4bc9f/32.png) [@shaktigupta200](https://discuss.elastic.co/u/shaktigupta200)\
**Post date:** [August 11, 2017, 7:41am UTC](https://discuss.elastic.co/t/elk-vs-splunk/96700/2 "2017-08-11T07:41:44Z")

</div>

Kibana is a great tool to be work with. My organization is using ELK and it provides all the logging solution.

---

<div class="post-metadata">

**Author:** ![akash.01](https://avatars.discourse-cdn.com/v4/letter/a/77aa72/32.png) [@akash.01](https://discuss.elastic.co/u/akash.01)\
**Post date:** [August 11, 2017, 7:59am UTC](https://discuss.elastic.co/t/elk-vs-splunk/96700/3 "2017-08-11T07:59:17Z")

</div>

Sorry, but does that answer my question?

---

<div class="post-metadata">

**Author:** ![stiltz](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stiltz/32/39714_2.png) [@stiltz](https://discuss.elastic.co/u/stiltz)\
**Post date:** [August 11, 2017, 8:33pm UTC](https://discuss.elastic.co/t/elk-vs-splunk/96700/4 "2017-08-11T20:33:16Z")

</div>

You can certainly do this...  
I would run a search in Discover with the following parameters:

1. Select your BlueCoat index
2. Your query would look something like this: **category:Phishing**
3. Save your query
4. Create a new visualization by going to the **Visualize** tab
5. Create a new Data table visualization from the search you just saved
6. Add a metric, split rows, with the term for source IP. You'll get a count by source IP. like this: ![image](https://us1.discourse-cdn.com/elastic/original/3X/e/1/e1741cf4e22093da39fb614b79a108bcf9568d32.png)  
and you'll end up with something like this:

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/a/4/a40ffea9c12fc63fdc5e45ee3b9231c2209565f4.png)

You can add more buckets to get more granular or flip it to destination hostname/ip, whatever you want.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 8, 2017, 8:33pm UTC](https://discuss.elastic.co/t/elk-vs-splunk/96700/5 "2017-09-08T20:33:19Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
