AWS Everyday - Athena vs Splunk

4:29 · Watch on YouTube ↗

Transcript 590 words · about 4 min to read

Auto-generated captions from YouTube, not hand-corrected, so names and technical terms may be imperfect. The video is authoritative.

hey how's it going it's Keith Townsend from the CTO advisor which is cheaper's Blanc or Athena for a data query you know what that's the wrong question the question is what's your use case and where would you use Athena versus Splunk for those of you who are not aware Athena is a platform that allows you to Curie S3 objects navally using SQL commands and Splunk is a data analytics platform that's typically found in Enterprise I.T so how do the two solutions ingest data we have a

data source let's say that it is a application running on ec2 S3 and you have your infrastructure such as DNS Cloud watch Etc you can feed those data sources into S3 directly or adjust them into Splunk there is a abstraction layer that takes the data and the case a Athena it creates a table you can use something like AWS glue to automatically take your multiple data sources create a schema then as a end user you can carry each source based on your data analytics needs that's

about where the similarities and the solutions and S3 uses the the immense capability at Amazon's access compute they can natively give you the capability of not having have to worry about the underlying infrastructure so unlike in a Splunk where you have to spec out the size of ec2 uh instance you want to use the amount of EBS storage or their amount of S3 Source you want to use from the back end AWS takes care of all of that they manage it in both capacity and pricing

and you just run the furies up against the platform Splunk you have to take care of all that but what do you get in return with the spunk platform you get performance I want to know if malicious activity was happening against my load balancers during peak season or if it was just uh a issue with load that Curie will be turned back in a matter of seconds or minutes when I do the same thing with Splunk if I decides my Splunk infrastructure correctly I get that

response back immediately and in each case I paid for S3 the X3 period on the thing I pay for it by the drink so I did the math if I have 50 terabytes of data stored in S3 and I ran a query against that entire 50 terabyte uh set it would take cost me 250 dollars per Curry it's blocked that's built into the cost of the infrastructure and I get the results back again immediately so I can build tooling and reactions based on that I can

either do Lambda functions or I can have remediations or I can have flows that move to the knot Etc with S3 I don't have that reliability and I pay by the drink and my cost will go higher but if I don't need the results instantly this becomes a much cheaper and much more appealing solution because I don't have to manage the infrastructure I don't have to worry about infrastructure and I'm a big fan about not worrying about infrastructure but again if I need the results quick

and my business depends on its forecast unique value let me know do you not agree disagrees there are some other advantages disadvantages to S3 versus spunk and Athena versus spunk DMS are open on Twitter at CTO advisor or comment below talk to you next AWS every day properties