Out clients went from unhappy using inflexible, poorly-supported products (in some cases barely functionally) to confident and excited when using Splunk. Not only are they able to do their security jobs and investigations, but they are also easily able to modify and evolve their implementations themselves to keep up with the shifting sands, which is the SecOps landscape.
Unfortunately, lately every release has a new memory leak. Be SURE to upgrade late and READ THE RELEASE NOTES, especially the "Known Issues" section.
We only ever have issues when deployed on VMs and the VM admins do not do what we tell them to do which is EXCLUSIVELY RESERVE OUR RESOURCES.
It used to be great (but perhaps that was because my employer at the time was a key prospect in a vertical where Splunk had no customers) but Splunk support is definitely a victim of Splunk's explosive growth. The first tier support is as bad as it is most places and getting worse all the time. If you KNOW your problem is not run of the mill, ask for escalation immediately. Also the clock on the case does not start until somebody adds a note to the case so always call in and ask if they got your diag file (always attach a diag) and the person who answers will have to add a note to the case which will start the clock.
I have dabbled with LogRythm and ArcSight and they are both OK, but Time-To-Value is WAY shorter with Splunk, IMHO.
Use bare metal severs on Linux and you will be fine. Use Windows and you will have much trouble. Use VMs and your admins will cheat you and you will have much trouble. Do not use NAS!!!!
In-house. We at Splunxter are Splunk experts. We can do anything with Splunk. We always hit homeruns.
We usually get multi X-factor within a quarter.
Get free PS if you can (ask) or USE THE DOCS. The documentation will get you to success. If you are not getting more value out of Splunk than the license you are paying, then you are doing something wrong and should spend a tiny bit more to get a consultant like Splunxter.com to help you.
No,we went with the free trial and got so much value so quickly we bought in.
You can also get GREAT help at answers.splunk.com.