Setting expectations
I expect that every organization is different with respect to their criteria for what they are alerting on. However, I can tell you from working across many sectors, and at some major institutions, that leadership generally wants the same thing no matter what company you work for. Allow me to give you a breakdown list of what leaderships' expectations are of Splunk and its alerting capabilities, across industries.
Splunk should be able to:
Alert on the future
Predict the future
Automatically know when all users are experiencing problems simultaneously
Tame dragons
Slay gods
Perform prophetic-like miracles in real-time
Save them billions of dollars
Automate their departments' workflow
After all, it is a Big Data platform with machine learning capabilities, right?
I am exaggerating here, but Splunk is both a big data platform and one that has machine learning capabilities. Contrary to popular belief it is not SkyNet nor the Matrix. I've checked under the hood; I didn't see Arnold...