We use the Splunk Enterprise Platform for logging and monitoring purposes. If users log into different databases and do something, we onboard database logs and other AWS logs to Splunk. Then, we create a dashboard alert report, and based on those dashboard alerts, we monitor users' actions. If they perform suspicious activities, we also send alerts. We use the solution to create dashboard alerts, reports, and some query language.
Splunk Enterprise
SplunkExternal reviews
External reviews are not included in the AWS star rating for the product.
Used for logging and monitoring purposes
What is our primary use case?
What is most valuable?
The most valuable features of the solution are the load balancing technique, the forwarding technique, and SSL certification.
What needs improvement?
Sometimes, queries don't give proper results, and the indexes go down.
For how long have I used the solution?
I have been using Splunk Enterprise Platform for seven years.
What do I think about the stability of the solution?
I rate the solution an eight out of ten for stability.
What do I think about the scalability of the solution?
I rate the solution’s scalability a nine out of ten.
How are customer service and support?
The solution’s technical support is good.
How was the initial setup?
The solution’s initial setup is easy.
What's my experience with pricing, setup cost, and licensing?
I have heard from my managers that Splunk Enterprise Platform is an expensive solution.
What other advice do I have?
The solution has helped us with our security information and event management. If someone performs deletion operations, we get an automated alert informing us that a privileged activity has been performed. We forward the logs in real-time. We are ingesting 10GB of data into the solution daily. We have some input filters in the solution's dashboard.
Overall, I rate the solution an eight out of ten.
Offers timestamp indexing and the easy-to-use visualization for data analysis
What is our primary use case?
I have a variety of use cases. My company uses it for cloud-related operations, anomaly identification, and threat detection.
How has it helped my organization?
It's been very useful in regard to security information and threat management (SIEM). Splunk is a valuable tool for my organization.
What is most valuable?
The timestamp indexing and the easy-to-use visualization features are the most valuable features for data analysis.
Moreover, the dashboard and visualization features have made a big difference. We can quickly identify issues within the dashboards and easily generate insightful reports. If something goes down, we can easily detect the issue.
Splunk's real-time processing capability has been pretty good for my use cases.
What needs improvement?
There is room for improvement in terms of scalability. They can enhance the ability to handle increasing volumes of data.
For how long have I used the solution?
I have been using it for four years now.
What do I think about the stability of the solution?
There have been occasional issues, but nothing major.
I would rate the stability an eight out of ten.
What do I think about the scalability of the solution?
I never had issues with scalability. My organization has 8,000 end users.
I would rate the scalability an eight out of ten.
How are customer service and support?
The customer service and support are good.
How would you rate customer service and support?
Positive
How was the initial setup?
In general, the initial setup is fairly easy.
Not everyone can do it. Some knowledge and experience would likely be helpful to get the most out of the setup.
Typically, the deployment would take around 16 to 20 hours.
What's my experience with pricing, setup cost, and licensing?
The pricing is about average.
What other advice do I have?
Overall, I would rate the solution an eight out of ten.
I would recommend using this solution. Overall, Splunk is a good tool for analysis and for representing data in a short span of time. It helps minimize unnecessary noise in the data.
Splunk is a quite famous vendor in managing IT infrastructure with SIEM - now Enterprise.
Offers excellent data analysis and visualization capabilities
What is our primary use case?
I use the Enterprise platform mainly to monitor infrastructure, applications, and some security logs.
What is most valuable?
The most valuable feature of Splunk for data analysis is its ability to search using SPL and SQL. With SPL commands, you can analyze both structured and unstructured data and build visualizations, dashboards, and reports. Additionally, Splunk offers alerting mechanisms for proactive monitoring.
What needs improvement?
There is room for improvement in introducing more AI capabilities onto Splunk Enterprise Platform. While they might exist in other platforms like ITSI, enhancing the Enterprise Platform with AI features would benefit many users who predominantly use it.
For how long have I used the solution?
I have been using Splunk Enterprise Platform for almost three years.
What do I think about the stability of the solution?
I would rate the stability of Splunk at around a seven out of ten. While it is generally good, in complex environments, issues may arise due to the increased number of components and dependencies. However, overall, the stability is good.
What do I think about the scalability of the solution?
I would rate Splunk's scalability as a nine out of ten. It is the best log analysis application currently available. Scalability has allowed us to handle increasing volumes of data, enabling us to onboard additional customers and share infrastructure monitoring on the same setup. We have approximately 20 people using Splunk Enterprise Platform in our company.
How are customer service and support?
The technical support team could improve by providing more direct assistance rather than primarily relying on community resources for issue resolution. While they do understand the issues, they often refer to existing communities for solutions instead of directly addressing system-specific concerns. Overall, I would rate the support as a six out of ten.
How would you rate customer service and support?
Neutral
How was the initial setup?
The initial setup of Splunk Enterprise is relatively complex compared to other monitoring applications in the market. There is a need to focus on simplifying key components and reducing dependencies for a smoother setup process. For a large environment, the deployment of Splunk Enterprise typically takes around three months to set up completely.
What's my experience with pricing, setup cost, and licensing?
Splunk Enterprise Platform is a bit expensive.
What other advice do I have?
I use the Platform to monitor my IT infrastructure. There are apps for Linux and Windows servers that capture performance metrics like CPU and memory usage. These metrics are collected and sent to the blank index through forwarders.
Splunk helps with security information and event management by detecting and monitoring network equipment and firewalls. It saves searches for specific terms, like threats, in firewall logs. When a match is found, it alerts about potential security breaches, helping to detect and address them.
The real-time processing capability in Splunk enhances data monitoring by centrally collecting all data. This allows for easy searching and scheduling of searches, reducing the need for manual intervention.
The dashboard and visualization features in Splunk impact data analysis by providing a clear status of data analysis. Users can create customized views for management, helping them understand what is happening within the infrastructure more effectively.
I would recommend Splunk to others, especially from the CIM perspective. Its data analysis and visualization capabilities are unmatched, making it an excellent choice for SIM.
Overall, I would rate Splunk Enterprise Platform as a nine out of ten.
Splunk Enterprise Review
2) Simple and powerful tool for SEIM.
3) Rich visualizations & Cutomizable dashboards to understand insights clearly.
4) Real time monitoring and alerting features are cheryy on top.
2) It also offers free version but have very limited functionality.
Splunk your Issues
Helps to monitor logs from various sources but improvement is needed in support
What is our primary use case?
We use the tool to monitor logs from various sources. Multiple users send their logs to the Splunk Enterprise Platform using different methods, including Universal Forwarder and AWS services like S3. Additionally, we utilize tools like AWS Genesys for log transmission.
What is most valuable?
The product helps monitor and visualize data. It allows you to handle various tasks. You can store, visualize, and analyze data with the Splunk Enterprise Platform. It offers features like virtual folders and heavy folders for filtering data. Additionally, you can create dashboards to showcase data to different teams and stakeholders. The tool also enables the creation of analytics and alerts and sends reports, making it a valuable tool for our system.
The dashboard and visualization features are good for data analysis. With features like the Studio dashboard introduced in versions 8 to 9, users find it much easier to create dashboards without knowledge of languages like XML.
What needs improvement?
Based on my experience, I've noticed areas for improvement, particularly in support. Developers typically interact with support personnel who may lack technical expertise when raising support tickets. This can result in delays as initial interactions involve sharing documents before escalation to higher support levels.
For how long have I used the solution?
I have been using the product for four years.
What do I think about the stability of the solution?
I rate the tool's stability an eight out of ten.
What do I think about the scalability of the solution?
The tool's scalability is good, and it is based on licensing. My company has more than 10,000 users.
Which solution did I use previously and why did I switch?
I used Dynatrace before the Splunk Enterprise Platform.
How was the initial setup?
The tool's deployment can be complex for the first time. It can become more manageable after that.
What's my experience with pricing, setup cost, and licensing?
If you exceed your licensed limit, the product will issue a warning, typically a five-license warning. Additionally, they send daily email notifications informing you about the breach. This prompts you to consider options such as minimizing logs or acquiring additional licensing to address the issue.
It can be perceived as expensive, especially for organizations dealing with large volumes of data, such as in the banking sector, where numerous logs are generated every second. While other tools are available at lower costs, some teams may consider open-source or lower-cost alternatives, especially if they have funding constraints.
What other advice do I have?
Regarding security and event management, the tool is handled by a different team. They utilize security enterprise tools, including SIEM, to manage security. Splunk Enterprise Platform's real-time processing capability significantly enhances our data monitoring. I would rate it an eight out of ten.
Enables us to collect, index, and analyze data from various sources, such as apps, servers, network devices and security systems
What is our primary use case?
The solution is used for basically, to monitor various logs, so it is the application logs, some kind we are monitoring databases.
How has it helped my organization?
Splunk is providing, like, proactive monitoring using desserts and all. So these things have improved a lot. Like, in our done day to day activities and all. So whenever we are seeing any kind of alerts and also on that basis, we are going to create alert.
What is most valuable?
For monitoring security data is the most valuable feature.
What needs improvement?
Currently, I think things are good only. There are certain things which is not which is there in the other platform like UAE, UBA is there. Like, Splunk is having another product itself. But the thing is, like, if that can be incorporated with the Splunk Enterprise three version. So it will be helpful for the users to explore more on that one.
For how long have I used the solution?
I have been using Splunk Enterprise Platform for five years.
What do I think about the stability of the solution?
The stability is a nine out of ten meaning the solution is highly stable.
What do I think about the scalability of the solution?
It is a scalable solution. Around thousand plus users are using the solution.
Which solution did I use previously and why did I switch?
I have been using this Splunk only from my, like, a shorting of the career. During this period, I have been using AppDynamics and NetSync as well.
How was the initial setup?
Normally so for trial version, it is easy. So it depends on how much data you are ingesting. So if you are going for the Flushing environment, so that setup Could be somewhat difficult, but, normally, it will be easy only.
What was our ROI?
I have seen a Return on Investment.
What's my experience with pricing, setup cost, and licensing?
Costing depends on, like, how much data you are investing. So that will increase your cost.
What other advice do I have?
I will rate the overall solution a nine out of ten.
"Splint!It's a thrilling and overzealously discovery of new network assets".
Absolutely great for use of repository of secure keeping of data.
It's have a great dashboard for data visualization.
It's spectacular for events tracking for quick action.
Bodacious for it's realtime alerts of any threat in network enterprise for quick action.
With the help of machine learning it's very great for automated responses.
The product is very easy to use, the GUI is simple, and the technical support is responsive
What is our primary use case?
We use the solution mainly for security operations. We receive logs from different log sources.
What is most valuable?
The product is very easy to use. We just have to run the agent and collect the log. We don't have many delays or problems. We faced an issue once or twice when there was a network issue and when the system was rebooted. The percentage of issues is very low compared to the overall deployment. It is 0.001%.
The solution supports our organization's security and compliance monitoring very much. We rely on the platform to detect abnormalities and to perform searches. If someone brings a compliance issue, we request logs from the platform to determine whether it happened. We use the tool’s search feature and Intel's machine learning platform to conduct our analysis.
We don't face any issues in real-time monitoring. There is no latency. We have options to create our own dashboards. The GUI is very simple. It's a simple platform. It is very easy to use.
What needs improvement?
The product doesn’t have prebuilt dashboards. It would be great if the product provided prebuilt dashboards. For example, we allowed some devices into our network through VPN, but there is no dashboard to combine two log sources and understand which user has logged in. So, we created our own dashboard with the available Splunk searches.
It’d be good if the solution provided more prebuilt dashboards and released them on the app platform. Then, we can deploy the dashboards straight away. Also, if the tool provides additional dashboards, we can reduce the resources needed to develop them. Since Splunk has overall visibility all around the globe, it can give better suggestions on the dashboards that we must use and how to project the data to the management.
We faced some issues in parsing when the load was too much. If we have a 100 MB log source, 80 MB will be parsed correctly, but we face issues with 20 MB. We raised a support ticket, and the support team suggested we increase the time interval between sending the logs to the Splunk forwarder to handle the processing correctly.
For how long have I used the solution?
I have been using the solution for two years. I am using the latest version of the solution.
What do I think about the stability of the solution?
The tool is stable enough. In my demo environment, I used my own physical machines to run it. I was able to ingest as many log sources as I wanted within the data limit, and it did not have any issues. The search is very responsive when compared to the other platforms. There was no lag.
Splunk has been supporting free text searches for two years. We can query anything out of the box without specifying any indexes. We can perform free-text queries. Usually, it takes very little time to produce the results if the data set is too small. If the data set is too large, the product suggests we finetune our search, and it provides us with hints on which indexes to specify. It has three different options: Fast mode, Push mode, and Smart mode. We can switch the modes to get results quicker. Later, we can change the mode back to do a deeper analysis.
What do I think about the scalability of the solution?
Scalability is not an issue for SMBs and moderately big companies. When we went beyond certain limits, like 700 Gbps or 800 Gbps, we faced some issues with the engine. So, we split up the platform and diverted some of the logs into different indexes. It solved the problem. Up to 500 Gbps per day is okay. When we go beyond that, a single instance cannot handle it. We need to split it up.
This issue was only with the on-premise version. We do not face such issues in the cloud. When customers wanted to renew their subscriptions, we suggested they move to the cloud. On-premise, we have to manage our indexes and searches, but in the cloud, it's done by the vendor. It's a plug-and-play process. Splunk automatically takes care of parsing. We have more than 30 customers.
How are customer service and support?
The technical support is very good. The team supported us even during the Christmas holidays. The support engineer walked us through every step. The team is always reachable. We never had issues while contacting them.
How was the initial setup?
I built some demo environments for my practice since Splunk was new to me two years ago. I used the free license. It was a pretty straightforward setup. I did not find any difficulties in setting up my lab environment. The deployment can be done within 15 minutes.
What was our ROI?
The return on investment is very good. It's very easy to use. Many of our customers decided to continue using Splunk because they have invested much in the training modules, the analysts are familiar with the tool, and it's very easy to search. Open-text queries are the best in Splunk. It is easy for our customers to perform the search. It's very lightweight compared to other solutions.
What's my experience with pricing, setup cost, and licensing?
Our customers pay for the licenses. It’s bundled together in a yearly subscription.
What other advice do I have?
There are some problems in managing the tool when it exceeds certain limits. Overall, I rate the product a nine out of ten.