[163605] in North American Network Operators' Group
Re: Prism continued
daemon@ATHENA.MIT.EDU (Noon Silk)
Thu Jun 13 03:02:30 2013
In-Reply-To: <CAHsqw9sivWnTeZ=76dDHFGJchJkGWaovK+C2k7STH7CgHNMwmw@mail.gmail.com>
Date: Thu, 13 Jun 2013 17:02:08 +1000
From: Noon Silk <noonslists@gmail.com>
To: Jonathan Lassoff <jof@thejof.com>
Cc: "nanog@nanog.org" <nanog@nanog.org>
Errors-To: nanog-bounces+nanog.discuss=bloom-picayune.mit.edu@nanog.org
On Thu, Jun 13, 2013 at 11:35 AM, Jonathan Lassoff <jof@thejof.com> wrote:
>
> In the PRISM context, I highly doubt their using Splunk for any kind
> of analysis beyond systems and network management. It's not good at
> indexing non-texty-things.
> What if you need to search for events that were geographically
> proximate to one another? That takes a special kind of index.
I was under the impression stuff like Palantir was used a bit, in this
context (but I don't even have nth-hand evidence for that.)
--
Noon Silk