Senior Network & Security Architect at a insurance company with 501-1,000 employees
Real User
Central locale for our cybersecurity
Pros and Cons
  • "It is quite extensible. It is a platform that we can build our use instead of each case instead of each case being limited or restricted to each capability. This is probably the best feature."
  • "I would like to see future development in terms of ML (Machine Learning)."
  • "I think the tech support response time could be a bit better. Sometimes I need to wait more than 24 hours for a response to my tickets."

What is our primary use case?

Splunk is our central locale for cybersecurity and protection.

How has it helped my organization?

Once we onboarded all of the required needs, it created a lot of visibility for us.

What is most valuable?

It is quite extensible. It is a platform that we can build our use of each case instead of each case being limited or restricted to each capability. This is probably the best feature.

What needs improvement?

I would like to see future development in terms of ML (Machine Learning). 

Buyer's Guide
Splunk Enterprise Security
May 2024
Learn what your peers think about Splunk Enterprise Security. Get advice and tips from experienced pros sharing their opinions. Updated: May 2024.
772,679 professionals have used our research since 2012.

For how long have I used the solution?

One to three years.

What do I think about the stability of the solution?

It is a stable product.

What do I think about the scalability of the solution?

It can be scaled quite easily in comparison to other products on the market.

How are customer service and support?

The tech support response time could be a bit better. Sometimes I need to wait more than 24 hours for a response to my tickets.

How was the initial setup?

I was not involved with the initial setup.

What's my experience with pricing, setup cost, and licensing?

The price could be improved.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
PeerSpot user
Technical Lead at Wipro Technologies
Real User
Capability to expand functionality through custom code for data inputs, commands, visualization, alerts, and machine learning
Pros and Cons
  • "We can ingest and correlate data from virtually any type of system."
  • "Capability to expand the functionality through custom code for data inputs, commands, visualization, alerts, and machine learning."
  • "Missing capability for audio/video and image processing."
  • "While scheduled reports can be embedded, Splunk dashboard can not be embedded directly without enabling cross origin."

What is our primary use case?

We use Splunk for infrastructure monitoring, application monitoring and in the security space for our organization as well as for our customers.

How has it helped my organization?

Since Splunk is a platform for data, we can ingest and correlate data from virtually any type of system.

It has a fast turnaround time for setting up monitoring/alerting and forecasting of trends as per our customers' requirements.

What is most valuable?

The following are top three features that I find quite valuable:

  1. Capability to expand the functionality through custom code for data inputs, commands, visualization, alerts, and machine learning.
  2. Quick turnaround time for setting up monitoring and alerting with built-in capabilities, plenty of enterprise grade apps available on Splunkbase, and custom coding based on Splunk development skill level.
  3. Free Splunk license for PoCs on personal machines and the ability to scale the PoC to an enterprise level app.

What needs improvement?

  • Scheduled PDF generation does not work well for all visualizations, and it does not work for custom visualizations.
  • While scheduled reports can be embedded, Splunk dashboard can not be embedded directly without enabling cross origin.
  • Missing capability for audio/video and image processing.

For how long have I used the solution?

More than five years.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Buyer's Guide
Splunk Enterprise Security
May 2024
Learn what your peers think about Splunk Enterprise Security. Get advice and tips from experienced pros sharing their opinions. Updated: May 2024.
772,679 professionals have used our research since 2012.
it_user717477 - PeerSpot reviewer
Account Manager at a tech services company with 10,001+ employees
Real User
Proactively monitor threats and reduces threat footprint, though professional support is too expensive
Pros and Cons
  • "Deployment server for deploying changes in one go."
  • "Professional support is great, but too expensive."

How has it helped my organization?

It was used for security event management on landscape hosted over AWS.

It helped the organisation to proactively monitor threats and reduce its threat footprint.

What is most valuable?

Deployment server for deploying changes in one go.

What do I think about the stability of the solution?

It is quite stable.

What do I think about the scalability of the solution?

No.

How are customer service and technical support?

Professional support is great, but too expensive. Otherwise content published over website is good.

Which solution did I use previously and why did I switch?

Not applicable.

What's my experience with pricing, setup cost, and licensing?

Do proper estimation on log ingestion per day as that will impact pricing and licensing.

Which other solutions did I evaluate?

It was the customer's choice.

What other advice do I have?

It provides a great range of plugins and one can really take great advantage of utilising inbuilt dashboards to derive the desired monitoring.

Our company consults for different customers and are in a good position to recommend the best solution to our clients.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Presales IT at a tech services company with 201-500 employees
MSP
Good product that satisfies our customers
Pros and Cons
  • "The product is good, it satisfies our customers."
  • "The prices are complicated as we operate in a small third-world country."

What is our primary use case?

Our company is an IT service provider. We are resellers of Splunk. One of our clients that we monitor is a laboratory that uses this solution.

Splunk is a change management solution. We use the solution as a log collector, and to analyze and provide alerts from the IT instructor.

What is most valuable?

The product is good, it satisfies our customers.

What needs improvement?

The price of Splunk is too high for our market.

For how long have I used the solution?

Our company has been a reseller of Splunk for less than six months.

What do I think about the stability of the solution?

Splunk is stable.

What do I think about the scalability of the solution?

This is a scalable solution.

How are customer service and support?

We have had no concerns with customer service.

How was the initial setup?

The initial setup of Splunk is somewhat difficult because it was our first time implementing the solution. It was a similar situation to implementing other CM tools like FortiSIEM.

What about the implementation team?

Splunk required two engineers to implement, and we will add another one to maintain the solution.

What's my experience with pricing, setup cost, and licensing?

The prices are complicated as we operate in a small third-world country.

Which other solutions did I evaluate?

We give support for VMware and other technologies. We purchased Splunk because our customers were asking for our services to take control of the implementation from another company.

What other advice do I have?

If you are considering Splunk and you like what you are seeing; my advice would be to go for it.

I would rate Splunk an 8 out of 10.

Disclosure: My company has a business relationship with this vendor other than being a customer:
PeerSpot user
Cyber Security Consultant at a tech services company with 11-50 employees
Real User
Customizable and has average installation difficulty
Pros and Cons
  • "I have found the installation can be of medium difficulty to very complex depending on the use case."
  • "There is improvement needed when importing from some types of data sources."

What needs improvement?

There is improvement needed when importing from some types of data sources. Most of the time you have to do some customization for the data because not everything is working the way it should. Additionally, in other solutions, it is easier to build use cases.

For how long have I used the solution?

I have been using this solution for approximately three years.

Which solution did I use previously and why did I switch?

I have previously used Curator and it was much easier to use than this solution.

How was the initial setup?

I have found the installation can be of medium difficulty to very complex depending on the use case. It is not easy for new customers. You need to have the experience to be able to do it.

What other advice do I have?

When using this solution for Security Information Management(SIM), I highly recommend importing data sources from the whole cycle for the service security chain. Some people only use main inputs and not all of the data sources they have. They might not have some data sources, in this case, you can purchase one or there are free open-source ones available. You will then have this data source that can enrich your life because many correlations are done with this data. 

I rate Splunk an eight out of ten.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Security Professional at a tech services company with 51-200 employees
Real User
Top 20
Good data analysis and visualizations, absolutely stable, and scalable
Pros and Cons
  • "The data analysis part is good in Splunk, which is something that I like the most. It is also quite easy to use. Its dashboards, visualizations, and analytics are good."
  • "It currently has limited default rules and customizations. If they can concentrate more on the compliance part and the security information part, it would be helpful. The platform part is good, but it requires many features from the security aspect."

What is our primary use case?

We are using it for security information and event management (SIEM). We have started to use Splunk recently, and we are in the implementation phase as of now.

What is most valuable?

The data analysis part is good in Splunk, which is something that I like the most. It is also quite easy to use. Its dashboards, visualizations, and analytics are good.

What needs improvement?

It currently has limited default rules and customizations. If they can concentrate more on the compliance part and the security information part, it would be helpful. The platform part is good, but it requires many features from the security aspect.

For how long have I used the solution?

I have been using this solution for a couple of months.

What do I think about the stability of the solution?

It is absolutely stable.

What do I think about the scalability of the solution?

It is scalable. We have approximately 25 users.

How was the initial setup?

It was easy to install. Its configuration and development are the critical parts, and there are a limited number of people in the market with such a skill set. It takes some time to find people with the right skill set and get it implemented properly. It took approximately three months.

What about the implementation team?

I have a team of a few Splunk consultants who are currently managing it for me. For a mid-sized organization, at least 15 persons are required to manage the entire Splunk instance.

What other advice do I have?

I would recommend this solution to others. I would rate Splunk an eight out of ten.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Técnico Judiciário at a government with 1,001-5,000 employees
Real User
Has the ability to log more logs than similar solutions and is more efficient than its competitors
Pros and Cons
  • "It can log more logs than other solutions. It's a good way to troubleshoot problems."
  • "Cybersecurity and infrastructure monitoring have room for improvement."

What is our primary use case?

We use it to do SIEM. 

How has it helped my organization?

It can log more logs than other solutions. It's a good way to troubleshoot problems.

What is most valuable?

Splunk is a good solution to collect more events than other solutions. It's a good solution, for me, for this reason.

What needs improvement?

Cybersecurity and infrastructure monitoring have room for improvement. 

For how long have I used the solution?

Less than one year.

How was the initial setup?

On a scale from one to ten I would rate the initial setup a seven for its complexity. 

Which other solutions did I evaluate?

We also looked at AlienVault.

What other advice do I have?

I would rate it an eight out of ten. 

Splunk is more efficient than other solutions but it's also more expensive. 

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Principal Consultant at a computer software company with 51-200 employees
User
Positive features include replication capabilities, software development kits, and its architecture
Pros and Cons
  • "Positive features include replication capabilities, software development kits, and the architecture."
  • "The solution could use a different licensing model."
  • "An improved user interface along with multi-tenancy support would be beneficial."

What is our primary use case?

  • Cybersecurity defense
  • Web app monitoring
  • VMware monitoring

How has it helped my organization?

  • Troubleshooting
  • Cyber defense

What is most valuable?

  • Drill down
  • Apps
  • REST API
  • Software development kits
  • Architecture
  • Replication capabilities

What needs improvement?

  • Multi-tenancy support
  • Improved user interface
  • Non-proprietary search language
  • Different licensing model

For how long have I used the solution?

One to three years.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Buyer's Guide
Download our free Splunk Enterprise Security Report and get advice and tips from experienced pros sharing their opinions.
Updated: May 2024
Buyer's Guide
Download our free Splunk Enterprise Security Report and get advice and tips from experienced pros sharing their opinions.