Mohan Battu - PeerSpot reviewer
Project Lead at a computer software company with 5,001-10,000 employees
Real User
Offers timestamp indexing and the easy-to-use visualization for data analysis
Pros and Cons
  • "Splunk's real-time processing capability has been pretty good for my use cases."
  • "There is room for improvement in terms of scalability."

What is our primary use case?

I have a variety of use cases. My company uses it for cloud-related operations, anomaly identification, and threat detection.

How has it helped my organization?

It's been very useful in regard to security information and threat management (SIEM). Splunk is a valuable tool for my organization.

What is most valuable?

The timestamp indexing and the easy-to-use visualization features are the most valuable features for data analysis.

Moreover, the dashboard and visualization features have made a big difference. We can quickly identify issues within the dashboards and easily generate insightful reports. If something goes down, we can easily detect the issue.

Splunk's real-time processing capability has been pretty good for my use cases.

What needs improvement?

There is room for improvement in terms of scalability. They can enhance the ability to handle increasing volumes of data. 

Buyer's Guide
Splunk Enterprise Platform
April 2024
Learn what your peers think about Splunk Enterprise Platform. Get advice and tips from experienced pros sharing their opinions. Updated: April 2024.
769,976 professionals have used our research since 2012.

For how long have I used the solution?

I have been using it for four years now. 

What do I think about the stability of the solution?

There have been occasional issues, but nothing major.

I would rate the stability an eight out of ten.

What do I think about the scalability of the solution?

I never had issues with scalability. My organization has 8,000 end users. 

I would rate the scalability an eight out of ten.

How are customer service and support?

The customer service and support are good. 

How would you rate customer service and support?

Positive

How was the initial setup?

In general, the initial setup is fairly easy.

Not everyone can do it. Some knowledge and experience would likely be helpful to get the most out of the setup.

Typically, the deployment would take around 16 to 20 hours.

What's my experience with pricing, setup cost, and licensing?

The pricing is about average.

What other advice do I have?

Overall, I would rate the solution an eight out of ten.

I would recommend using this solution. Overall, Splunk is a good tool for analysis and for representing data in a short span of time. It helps minimize unnecessary noise in the data.  

Which deployment model are you using for this solution?

On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Flag as inappropriate
PeerSpot user
Security Consultant at IBM Thailand
Real User
Top 5Leaderboard
The product is very easy to use, the GUI is simple, and the technical support is responsive
Pros and Cons
  • "The product is very easy to use."
  • "The product doesn’t have prebuilt dashboards."

What is our primary use case?

We use the solution mainly for security operations. We receive logs from different log sources.

What is most valuable?

The product is very easy to use. We just have to run the agent and collect the log. We don't have many delays or problems. We faced an issue once or twice when there was a network issue and when the system was rebooted. The percentage of issues is very low compared to the overall deployment. It is 0.001%.

The solution supports our organization's security and compliance monitoring very much. We rely on the platform to detect abnormalities and to perform searches. If someone brings a compliance issue, we request logs from the platform to determine whether it happened. We use the tool’s search feature and Intel's machine learning platform to conduct our analysis.

We don't face any issues in real-time monitoring. There is no latency. We have options to create our own dashboards. The GUI is very simple. It's a simple platform. It is very easy to use.

What needs improvement?

The product doesn’t have prebuilt dashboards. It would be great if the product provided prebuilt dashboards. For example, we allowed some devices into our network through VPN, but there is no dashboard to combine two log sources and understand which user has logged in. So, we created our own dashboard with the available Splunk searches.

It’d be good if the solution provided more prebuilt dashboards and released them on the app platform. Then, we can deploy the dashboards straight away. Also, if the tool provides additional dashboards, we can reduce the resources needed to develop them. Since Splunk has overall visibility all around the globe, it can give better suggestions on the dashboards that we must use and how to project the data to the management.

We faced some issues in parsing when the load was too much. If we have a 100 MB log source, 80 MB will be parsed correctly, but we face issues with 20 MB. We raised a support ticket, and the support team suggested we increase the time interval between sending the logs to the Splunk forwarder to handle the processing correctly.

For how long have I used the solution?

I have been using the solution for two years. I am using the latest version of the solution.

What do I think about the stability of the solution?

The tool is stable enough. In my demo environment, I used my own physical machines to run it. I was able to ingest as many log sources as I wanted within the data limit, and it did not have any issues. The search is very responsive when compared to the other platforms. There was no lag.

Splunk has been supporting free text searches for two years. We can query anything out of the box without specifying any indexes. We can perform free-text queries. Usually, it takes very little time to produce the results if the data set is too small. If the data set is too large, the product suggests we finetune our search, and it provides us with hints on which indexes to specify. It has three different options: Fast mode, Push mode, and Smart mode. We can switch the modes to get results quicker. Later, we can change the mode back to do a deeper analysis.

What do I think about the scalability of the solution?

Scalability is not an issue for SMBs and moderately big companies. When we went beyond certain limits, like 700 Gbps or 800 Gbps, we faced some issues with the engine. So, we split up the platform and diverted some of the logs into different indexes. It solved the problem. Up to 500 Gbps per day is okay. When we go beyond that, a single instance cannot handle it. We need to split it up.

This issue was only with the on-premise version. We do not face such issues in the cloud. When customers wanted to renew their subscriptions, we suggested they move to the cloud. On-premise, we have to manage our indexes and searches, but in the cloud, it's done by the vendor. It's a plug-and-play process. Splunk automatically takes care of parsing. We have more than 30 customers.

How are customer service and support?

The technical support is very good. The team supported us even during the Christmas holidays. The support engineer walked us through every step. The team is always reachable. We never had issues while contacting them.

How was the initial setup?

I built some demo environments for my practice since Splunk was new to me two years ago. I used the free license. It was a pretty straightforward setup. I did not find any difficulties in setting up my lab environment. The deployment can be done within 15 minutes.

What was our ROI?

The return on investment is very good. It's very easy to use. Many of our customers decided to continue using Splunk because they have invested much in the training modules, the analysts are familiar with the tool, and it's very easy to search. Open-text queries are the best in Splunk. It is easy for our customers to perform the search. It's very lightweight compared to other solutions.

What's my experience with pricing, setup cost, and licensing?

Our customers pay for the licenses. It’s bundled together in a yearly subscription.

What other advice do I have?

There are some problems in managing the tool when it exceeds certain limits. Overall, I rate the product a nine out of ten.

Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
Flag as inappropriate
PeerSpot user
Buyer's Guide
Splunk Enterprise Platform
April 2024
Learn what your peers think about Splunk Enterprise Platform. Get advice and tips from experienced pros sharing their opinions. Updated: April 2024.
769,976 professionals have used our research since 2012.
Adrian-Mache - PeerSpot reviewer
Solution Architect at a tech vendor with 10,001+ employees
Real User
Versatile, adaptable, and applies to many use cases
Pros and Cons
  • "What I find the most valuable about the platform is its DB Connect and its versatility in general. I also like its adaptability to any use case when it comes to collecting and analyzing data."
  • "The platform is too expensive for small businesses. Splunk should focus more on delivering something for small businesses and entrepreneurs."

What is our primary use case?

I use the platform to collect data and report to the clients that need reporting from Splunk. I work on gathering big data from all over my company and exporting it into proper reports.

What is most valuable?

What I find the most valuable about the platform is its DB Connect and its versatility in general. I also like its adaptability to any use case when it comes to collecting and analyzing data.

What needs improvement?

It is hard to say in what areas the platform could be improved since it's very versatile and applies to many use cases. It already has the functioning vetted into the core architecture of the product. In my opinion, there is no need for additional features because it already has many, and I haven't used them all.

For how long have I used the solution?

I've been using Splunk Enterprise Platform for two and a half years. I am a Splunk software architect and Splunk is the only platform I use.

What do I think about the stability of the solution?

It's a very stable platform. A ten out of ten.

What do I think about the scalability of the solution?

The scalability of Splunk is ten out of ten. It's one of the best platforms on the market. Approximately 1,000-2,000 people use the platform at our company, but only two people are needed to maintain it and I'm one of them. Everything is automated and it is very easy to manage 2,000 users on my own.

Which solution did I use previously and why did I switch?

I would compare Splunk Phantom with RSA NetWitness and Elasticsearch. All three solutions give the same output but in a different way. They analyze data in different ways. Each product has its scalability, versatility, and appliances in the current business needs of the company that uses it.

How was the initial setup?

The initial setup is very easy. At our company, we deployed Splunk ourselves because we are a team of Splunk architects and we have done it before.

What's my experience with pricing, setup cost, and licensing?

The platform is too expensive for small businesses. If you choose the free plan, it only has 15 GB of data per day, and it may not be enough to run a small business. You need to pay a subscription based on data ingestion, and that's very expensive. Splunk should focus more on delivering something for small businesses and entrepreneurs. I give the pricing a three or four out of ten. Although the product is pricey, it's truly magnificent.

Which other solutions did I evaluate?


What other advice do I have?

Overall, I give Splunk a nine out of ten and not a solid ten just because there are new updates every day and we don't know exactly what we need to search for since it's not that viewable. 

Which deployment model are you using for this solution?

Hybrid Cloud
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
Flag as inappropriate
PeerSpot user
ABBURI AJAY - PeerSpot reviewer
Splunk Software Developer at Tata Consultancy
Real User
Used for logging and monitoring purposes
Pros and Cons
  • "The most valuable features of the solution are the load balancing technique, the forwarding technique, and SSL certification."
  • "Sometimes, queries don't give proper results, and the indexes go down."

What is our primary use case?

We use the Splunk Enterprise Platform for logging and monitoring purposes. If users log into different databases and do something, we onboard database logs and other AWS logs to Splunk. Then, we create a dashboard alert report, and based on those dashboard alerts, we monitor users' actions. If they perform suspicious activities, we also send alerts. We use the solution to create dashboard alerts, reports, and some query language.

What is most valuable?

The most valuable features of the solution are the load balancing technique, the forwarding technique, and SSL certification.

What needs improvement?

Sometimes, queries don't give proper results, and the indexes go down.

For how long have I used the solution?

I have been using Splunk Enterprise Platform for seven years.

What do I think about the stability of the solution?

I rate the solution an eight out of ten for stability.

What do I think about the scalability of the solution?

I rate the solution’s scalability a nine out of ten.

How are customer service and support?

The solution’s technical support is good.

How was the initial setup?

The solution’s initial setup is easy.

What's my experience with pricing, setup cost, and licensing?

I have heard from my managers that Splunk Enterprise Platform is an expensive solution.

What other advice do I have?

The solution has helped us with our security information and event management. If someone performs deletion operations, we get an automated alert informing us that a privileged activity has been performed. We forward the logs in real-time. We are ingesting 10GB of data into the solution daily. We have some input filters in the solution's dashboard.

Overall, I rate the solution an eight out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Flag as inappropriate
PeerSpot user
Security Architect at a comms service provider with 10,001+ employees
Real User
Top 20
A solution that offers a good analytics part along with great integration capabilities with other applications
Pros and Cons
  • "The most valuable feature of the solution is the analytics part."
  • "The support offered by Splunk Enterprise Platform has certain shortcomings that need improvement."

What is our primary use case?

My company uses Splunk Enterprise Platform for monitoring and user base filtering.

What is most valuable?

The most valuable feature of the solution is the analytics part. Integration with other applications is another valuable feature of Splunk Enterprise Platform.

What needs improvement?

Splunk Enterprise Platform is already a refined product, so I don't have any recommendations related to areas that need improvement.

The cost of Splunk Enterprise Platform is an area of concern where improvements can be made by bringing down the costs. Product-related, I don't have any feedback.

The support offered by Splunk Enterprise Platform has certain shortcomings that need improvement.

For how long have I used the solution?

I have been using Splunk Enterprise Platform for a few weeks since it was recently deployed in my company. I use the solution's latest version. My company operates as a service provider of the solution.

What do I think about the stability of the solution?

The product's stability is good. Stability-wise, I rate the solution a nine out of ten.

What do I think about the scalability of the solution?

Scalability-wise, I rate the solution a nine out of ten.

Around 5,000 people use the solution. Around 10 to 15 analysts use Splunk Enterprise Platform in my company.

The solution is used on a regular and daily basis in my company.

How are customer service and support?

I am moderately satisfied with the solution's technical support. I rate the technical support an eight out of ten.

How would you rate customer service and support?

Positive

How was the initial setup?

Splunk Enterprise Platform was easy to implement. I rate the product's implementation phase an eight out of ten, where one is difficult, and ten is easy.

The solution is deployed on an on-premises model.

The solution's deployment phase was carried out over a period of one or two months.

What's my experience with pricing, setup cost, and licensing?

I rate the product's pricing a ten on a scale of one to ten, where one is cheap, and ten is expensive. It is a very pricey tool.

What other advice do I have?

I would recommend the product to those who plan to use it, provided the pricing of the solution is brought down.

I rate the overall product an eight out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer: MSP
Flag as inappropriate
PeerSpot user
Cemil Altug - PeerSpot reviewer
Hybrid Cyber Security Team Lead at Dndx CyberSecurity
Real User
Top 5Leaderboard
A complete solution to collect logs with faster response

What is most valuable?

The product comes with a faster installation and response time. When I search something on the log, they give the result in a few seconds. Even if I didn’t have EDR, I can investigate rules in Splunk.

What needs improvement?

The solution is only meant for big companies.

For how long have I used the solution?

I have been using the Splunk Enterprise Platform for three years. 

What do I think about the stability of the solution?

I rate the solution’s stability a ten out of ten.

What do I think about the scalability of the solution?

We have around ten people working with the solution.

I rate the solution’s scalability a ten out of ten.

How are customer service and support?

I didn’t contacted the customer support. Spunk has a website and community which has everything you need.

How was the initial setup?

The initial setup is easy. For deployment, I created a Splunk demo on my computer and on a POC environment. I ran the demo for 10 clients on 10 machines, and it took about 20 minutes.



What's my experience with pricing, setup cost, and licensing?

Spunk is used by big companies like with 2000 clients. 

I rate the solution’s pricing one out of ten.

What other advice do I have?

There are around ten engineer required for troubleshooting of the solution.

I recommend the solution to other organisation since it is very responsive.

Overall, I rate the solution a ten out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer:
Flag as inappropriate
PeerSpot user
Security Architect
Real User
Top 20
A customizable solution that can be used as a Security Incident and Event Management (SIEM) tool
Pros and Cons
  • "The most valuable feature of Splunk Enterprise Platform is that it's a customizable solution."
  • "Splunk Enterprise Platform should include more integrations with other security tools."

What is our primary use case?

We use Splunk Enterprise Platform as a Security Incident and Event Management (SIEM) tool.

What is most valuable?

The most valuable feature of Splunk Enterprise Platform is that it's a customizable solution.

What needs improvement?

Splunk Enterprise Platform needs a bit of tuning, and it would be beneficial if it came with some prebuilt use cases.

Splunk Enterprise Platform should include more integrations with other security tools.

For how long have I used the solution?

I have been using Splunk Enterprise Platform for six years.

What do I think about the stability of the solution?

I rate Splunk Enterprise Platform a nine out of ten for stability.

What do I think about the scalability of the solution?

I rate Splunk Enterprise Platform an eight to nine out of ten for scalability.

How are customer service and support?

The technical support team's initial response is too late.

I rate the solution's technical support a five or six out of ten.

How would you rate customer service and support?

Neutral

How was the initial setup?

The solution's initial setup is average and a little bit tricky. On a scale from one to ten, where one is difficult, and ten is easy, I rate Splunk Enterprise Platform a three out of ten for the ease of its initial setup.

What about the implementation team?

Splunk Enterprise Platform was deployed in a month in our organization.

What's my experience with pricing, setup cost, and licensing?

Splunk Enterprise Platform is an expensive solution.

On a scale from one to ten, where one is cheap, and ten is expensive, I rate the solution's pricing a nine out of ten.

What other advice do I have?

I am working with the latest version of Splunk Enterprise Platform. Splunk Enterprise Platform is deployed on-cloud in our organization.

I recommend that users not expect value from Splunk Enterprise Platform immediately. It might take time to set it up and get any value out of it.

Overall, I rate Splunk Enterprise Platform a nine out of ten.

Disclosure: My company has a business relationship with this vendor other than being a customer: Implementer
Flag as inappropriate
PeerSpot user
Senior Software Engineer at a tech services company with 10,001+ employees
Real User
Used for application performance monitoring, database monitoring, and infrastructure monitoring
Pros and Cons
  • "The solution is very good for monitoring compared to other tools."
  • "The solution's license cost is high and can be improved."

What is our primary use case?

Splunk Enterprise Platform is a basic monitoring tool used for application performance monitoring, database monitoring, and infrastructure monitoring. Currently, I use the solution for application monitoring and security monitoring. I use the tool to monitor security breaches or suspicious activities.

What is most valuable?

The solution is very good for monitoring compared to other tools. It provides an accurate solution. We used to get a free trial of around 60 days to test and get a good experience on Splunk.

What needs improvement?

The solution's license cost is high and can be improved. There are some limitations on data onboarding if you have huge data.

For how long have I used the solution?

I have been using Splunk Enterprise Platform for three to four years.

What do I think about the stability of the solution?

Compared to other monitoring tools, Splunk Enterprise Platform provides good stability.

What do I think about the scalability of the solution?

I haven’t faced any issues with the solution’s scalability.

How are customer service and support?

Splunk ITSI is very good for support, which includes getting an incident number and working on it.

What other advice do I have?

We need to integrate Splunk Enterprise Platform with other tools, which provide some security events. After integrating, you get the logs from that application's API. Once you get those logs, we will create a code per the business requirements and create an alert, report, or dashboard, whichever is needed.

Splunk Enterprise Platform works based on apps installed in Splunk. For example, if you want SQL data to get into Splunk, you need to install an SQL database plugin on the Splunk server. That plugin will capture the logs related to an SQL database with Splunk. After that, we write a query, pull out the data we need, and provide knowledge objects.

Visualization is very good in Splunk Enterprise Platform. The solution has good visualization elements like bar graphs, pie charts, line graphs, single visualizations, and maps. I would recommend the solution to other users.

Splunk Enterprise Platform is a very good tool for monitoring your day-to-day activity logs. This will eventually help you create reports or dashboards to monitor the business's progress.

Overall, I rate the solution seven and a half or eight out of ten.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
Flag as inappropriate
PeerSpot user