Emad Ul Haq - PeerSpot reviewer
Network & Telco Lead at a energy/utilities company with 501-1,000 employees
Real User
Top 10
Provides log collection and analysis

What is our primary use case?

  • Log collection and analysis
  • Reporting for the whole enterprise environment.

How has it helped my organization?

Improved visibility.

What is most valuable?

Log search and alerting/reporting.

What needs improvement?

Code understanding requirement is complicated for most users.

Buyer's Guide
Splunk Enterprise Security
April 2024
Learn what your peers think about Splunk Enterprise Security. Get advice and tips from experienced pros sharing their opinions. Updated: April 2024.
769,976 professionals have used our research since 2012.

For how long have I used the solution?

One to three years.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
PeerSpot user
Sr. Program Manager at a consultancy with 51-200 employees
Consultant
It is able to configure and integrate various solutions into one tool and provide actionable results. You need a dedicated developer.

What is most valuable?

  • Can ingest data from various data sources.
  • Is very useful for organizations who are attempting to meet compliance requirements.
  • Is able to fully configure and integrate various solutions into one tool and provide actionable results.

How has it helped my organization?

My use of Splunk at my previous place of employment improved how we functioned.

For how long have I used the solution?

I have used Splunk for three years.

What do I think about the stability of the solution?

We didn’t have any stability issues.

What do I think about the scalability of the solution?

We didn’t have any scalability issues.

How are customer service and technical support?

During our use of Splunk, we had professional services assisting and not actual technical support. However, the professional services team was great.

Which solution did I use previously and why did I switch?

Our organization did not have an established SIEM tool.

How was the initial setup?

The initial setup is straightforward, depending on the level of implementation of the tool.

What's my experience with pricing, setup cost, and licensing?

Take into consideration the labor costs for a dedicated Splunk developer who can craft the required queries needed for each organization. Organizations usually have their own form of implementation of each tool.

Which other solutions did I evaluate?

We didn’t evaluate any alternatives.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Buyer's Guide
Splunk Enterprise Security
April 2024
Learn what your peers think about Splunk Enterprise Security. Get advice and tips from experienced pros sharing their opinions. Updated: April 2024.
769,976 professionals have used our research since 2012.
it_user121728 - PeerSpot reviewer
Head of Service Integrity with 1,001-5,000 employees
Vendor
It can probably do anything if you tweak it enough but it's not cheap.

Splunk is really good at log parsing events over time. It is quick to drill in and analyze and it is quick to build a presentation layer and automate reporting. I love it for problem analysis and event management however it is not a capacity management tool. 

It can be a cm tool but not a good tool for projections etc. There are many tools that claim to be cm tools but they are usually expensive and miss the basic day to day challenges of capacity management. Eg: excluding backups from day peaks, removing outliers, forward trending, accepting data from any source. Start by getting your key data extracted from reliable sources and other tools.

The charting and presentation layer is impressive and quick. It can probably do anything if you tweak it enough. I would call it a very handy tool but probably not the tool. It is not that cheap either. I have used it personally to analyze big data as well as creating knowledge from some ordinary logging. I then created some pretty cool dashboards but they were more operational dashboards.

I don't think we could afford it as a capacity tool but we can use the data it simplified.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Tech Lead Security at a comms service provider with 51-200 employees
Real User
A great product with good indexing and data collection capabilities
Pros and Cons
  • "The indexing and data collection are valuable."
  • "Its search or filtering capability is nice, but it can be improved. It is currently a bit complicated, and it should be simplified. If we can write the search filter in a more simplified way, it would be better."

What is our primary use case?

I used it in the SOC environment to get logs, create dashboards, and filter out data.

What is most valuable?

The indexing and data collection are valuable. 

What needs improvement?

Its search or filtering capability is nice, but it can be improved. It is currently a bit complicated, and it should be simplified. If we can write the search filter in a more simplified way, it would be better.

Their sales support and tech support need improvement. Their support is really bad.

For how long have I used the solution?

I used it for nearly one year in my previous organization. I last used it about seven months ago.

What do I think about the stability of the solution?

It is stable.

What do I think about the scalability of the solution?

Its scalability is good.

How are customer service and support?

Their sales support and tech support are really bad. They take really long to respond.

Which solution did I use previously and why did I switch?

We were using AlienVault. We switched because we weren't really happy with it. So, we looked into different solutions, such as Splunk.

How was the initial setup?

Its initial setup was okay.

What about the implementation team?

We did it ourselves. We had around two people for deployment and maintenance, but we had around 15 users. They all were SOC people.

What's my experience with pricing, setup cost, and licensing?

We had a yearly subscription.

What other advice do I have?

I can recommend this solution to others. It is a great product. 

I would rate it an eight out of 10.

Which deployment model are you using for this solution?

On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
President at a non-profit with self employed
Reseller
Expensive, but easy data gathering and reliable
Pros and Cons
  • "The solution allows easy gathering and ingestion of the data."
  • "The solution could improve by increasing the performance. We have run into problems when large amounts of data are processed."

What is our primary use case?

We use Splunk for analyzing data.

What is most valuable?

The solution allows easy gathering and ingestion of the data.

What needs improvement?

The solution could improve by increasing the performance. We have run into problems when large amounts of data are processed.

For how long have I used the solution?

I have been using Splunk within the past 12 months.

What do I think about the stability of the solution?

The solution has been stable.

What do I think about the scalability of the solution?

Our customers are mostly enterprise-sized companies using this solution. 

How are customer service and technical support?

Splunk has many partners that provide customer support that can be used.

How was the initial setup?

The initial setup is not easy. Customers have to learn the Splunk language and it is hard to operate it by themselves. They will need Splunk engineers to assist in their projects.

What about the implementation team?

You will need a Splunk implementation specialist for the deployment.

What's my experience with pricing, setup cost, and licensing?

My customers have found the price of the solution to be high.

What other advice do I have?

I rate Splunk a five out of ten.

Disclosure: My company has a business relationship with this vendor other than being a customer:
PeerSpot user
it_user396600 - PeerSpot reviewer
Vice Manager at a comms service provider with 10,001+ employees
Vendor
Collects data from many sources. Has search, analysis, and visualization capabilities.

What is most valuable?

  • Collects data from any source
  • Powerful search, analysis, and visualization
  • Easy to build system on any platform
  • API and easily integrated search
  • Action script

How has it helped my organization?

We have over 7000 devices in our network infrastructure for monitoring, maintenance, and performance assessment.

We achieve this by collecting data and applying the analysis.

For how long have I used the solution?

I have used this solution for one year.

What do I think about the scalability of the solution?

We did not encounter any issues with scalability. Everything is normal with no bugs.

How are customer service and technical support?

It’s easy to obtain support from Splunk for technical issues. We also have enough knowledge ourselves to apply fixes.

Which solution did I use previously and why did I switch?

We used to deploy Elastic Stack. The search language of Splunk is easier and friendlier than Elastic Stack. It has helped me to search quickly and easily. Based on the results, it’s easy to visualize and add results to a previously built, personal dashboard.

What's my experience with pricing, setup cost, and licensing?

Licensing is free. Pricing is based on usage.

Which other solutions did I evaluate?

We evaluated Elastic Stack and Sumo Logic.

What other advice do I have?

If you are an enterprise and you need the best service for critical business analysis, Splunk would be one of the best choices.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
PeerSpot user
Integration Architect at a manufacturing company with 1,001-5,000 employees
Vendor
Fast availability of operational data spread across several servers is nice, but the MES is a complex system.

What is most valuable?

What Splunk calls operational intelligence: fast availability of operational data spread across several servers to prevent or react faster to outages or performance decreases.

How has it helped my organization?

MES is a complex and very critical distributed system here. Production WIP is directly connected to it and ICT is required to provide a continuous availability and very stable performance (line production has a costant speed, software cannot slowdown). Collect operational data from hardware, middleware and application software can potentially improve ICT proactive and reactive tasks.

For how long have I used the solution?

I've ever used it, just studied it.

Which solution did I use previously and why did I switch?

We also use a traditional monitor, and Microsoft SCOM.

What was our ROI?

Every stop or slowdown of the production line means lost of money, e.g. 30% reduction when compared to the current baseline.

What's my experience with pricing, setup cost, and licensing?

Every stop or slowdown of the production line means lost of money, e.g. 30% of reduction compare to the current baseline.

Which other solutions did I evaluate?

IBM QRadar

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
PeerSpot user
Solutions Consultant at a tech services company with 1,001-5,000 employees
Real User
Easy to use, provides a lot of analytics, and allows you to do pretty much whatever you want
Pros and Cons
  • "It provides a lot of analytics with the underlying AI engine, and it is a lot easier than other solutions. There are some products that do automated AI-based detection and drawing up charts, but for network monitoring and all of the monitoring aspects, it is quite a nice tool. It is very convenient for business users because they get more or less a lot of data readily available. If you're familiar with the Splunk query language, you can pretty much do whatever you want."
  • "If you have to do your own stuff, such as customized charts, it is a little bit more work, but once you're familiar with the Splunk query language, you can pretty much do whatever you want. In terms of features, it should probably have the features that other competitors provide."

What is most valuable?

It provides a lot of analytics with the underlying AI engine, and it is a lot easier than other solutions. There are some products that do automated AI-based detection and drawing up charts, but for network monitoring and all of the monitoring aspects, it is quite a nice tool.

It is very convenient for business users because they get more or less a lot of data readily available. If you're familiar with the Splunk query language, you can pretty much do whatever you want.

What needs improvement?

If you have to do your own stuff, such as customized charts, it is a little bit more work, but once you're familiar with the Splunk query language, you can pretty much do whatever you want. In terms of features, it should probably have the features that other competitors provide.

For how long have I used the solution?

I have been using this solution for about three to four months.

What do I think about the scalability of the solution?

I'm not sure. I do not really throw a lot of data in it, but it has been authenticated very nicely. It manages indexes and all of these things very nicely. I have not been privy to any production systems where you have millions of lines of log coming in every second. It works very well for the data that I have. It should be able to handle a lot of data. That's the whole purpose of it, and that's why Splunk has become so popular. It is an enterprise monitoring tool, and a lot of customers have Splunk in their ecosystem.

How are customer service and technical support?

They have pretty much good documentation and good training. Their documentation is a lot better than Qlik Sense.

Which solution did I use previously and why did I switch?

Splunk is an enterprise monitoring tool. Qlik Sense can do a little bit of log monitoring, but it is mostly used for dashboard reporting, whereas Splunk is more around monitoring and figuring out threats and all such things. They are different, but both deal with the data and allow you to create operation reports. 

Power BI is another tool that a lot of our customers use, but Splunk is quite often requested. It is also a lot more popular than Qlik Sense. We have a fair number of Qlik Sense customers.  

We usually sell Blue Prism to business users who are more concerned with the reporting aspect, which is why they would like to have easy tools like Qlik Sense in their ecosystem, but on the infrastructure side, it would be Splunk for enterprise monitoring.

How was the initial setup?

Simple environments are easier to install. Because there is a lot of data log monitoring, once you have a production system, there is some amount of work in setting it up, especially making it SSL Secure and exposing it on the internet. There are multiple components behind it, so you need to ensure that all these things are set up correctly. These kinds of things are not required on a cloud platform because you are just uploading data. You really don't have much access to the backend.

Splunk also has a cloud version, which I haven't looked at, but I have used Qlik Sense's cloud platforms. With on-premises, you are in control of pretty much how you set up all the data that you are sending out. A lot of our customers have the issue that if it is a cloud platform, they cannot really send out the data to any of these cloud platforms. So, there are data residence and other issues.

What's my experience with pricing, setup cost, and licensing?

It is economical than other solutions.

What other advice do I have?

I would definitely recommend Splunk. It is quite a decent tool, and it is there in a lot of enterprises.

I would rate Splunk an eight out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer: partner
PeerSpot user
Buyer's Guide
Download our free Splunk Enterprise Security Report and get advice and tips from experienced pros sharing their opinions.
Updated: April 2024
Buyer's Guide
Download our free Splunk Enterprise Security Report and get advice and tips from experienced pros sharing their opinions.