We have around 1,000 users and have found the built in reporting on the Ironport Web to be lacking in functionality. I'm thinking the Splunk with the Advanced Web Reporting add-on might work better. In particular I would like to be able to do the following, and have these questions:
1. I would like to run reports on full departments via their active directory OU's for example for summaries of their Ironport Categories they accessed/etc. This doesn't appear possible in the built in reporting, you seem to have to run either a summary for all users or one user at a time. Is this something that Splunk and the advanced web reporting add on would let us do?
2. Can you now virtualize Splunk and the Advanced Web Reporting add-on for use with an Ironport S380 or does it still need a dedicated server?
3. What is a ballpark cost for the Splunk Serrver software? What about the Advanced Web Reporting software, does Cisco charge extra for that too?
Let me know what you think.
Jim