From what I saw (there are videos on youtube), it can capture SMF records as 
they are created, and then transfer them to a splunk indexer.

The important part is 'as they are created', so that you see the information in 
splunk in real time.


 From what I read, Irontream is a lot more than just transferring files.
Not so lot, but it is just different animal.
Ironstream purpose is to transmit logs to remote server.
So it has to READ the log in real time (IMHO this is the most important
feature) and send it over a network.

Radoslaw Skorupka
Lodz, Poland


