CyberSecurity Consultant at Information Technology Solutions- ITS
Real User
Fast and easy to use, but could be faster
Pros and Cons
  • "The solution is very fast and succinct."
  • "I feel the solution to be too slow."

What is most valuable?

The solution is very fast and succinct. 

What needs improvement?

When it comes to out of the box use cases, I feel the solution to be too slow. 

For how long have I used the solution?

I have not been working with Splunk for long. 

How was the initial setup?

The initial setup was simple. 

It took an hour. 

Buyer's Guide
Splunk Enterprise Security
March 2024
Learn what your peers think about Splunk Enterprise Security. Get advice and tips from experienced pros sharing their opinions. Updated: March 2024.
768,857 professionals have used our research since 2012.

Which other solutions did I evaluate?

Curator is more scalable than certain other solutions. 

What other advice do I have?

We are partners of Splunk and provide the solution to customers. 

I feel Splunk is easy to utilize. 

My company has an app. on which the solution is deployed on-premises on a single server. 

There is another team in my company that works with Splunk products. 

I rate Splunk as a seven-point-five out of ten. 

Which deployment model are you using for this solution?

On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
PeerSpot user
IT Infrastructure Architect at a tech company with 201-500 employees
Consultant
Does event matching between several appliances and correlates data from different sources.

What is most valuable?

  • Event matching between several appliances
  • Correlating data from different sources
  • Report viewer

How has it helped my organization?

It helps us to detect viruses and security events from our network.

What needs improvement?

It needs documentation, and "how-to-do" information. It's complicated to build reports and views.

For how long have I used the solution?

I have used Splunk for about two years.

What do I think about the stability of the solution?

There were no stability issues. It was running on a VM over Hyper-V.

What do I think about the scalability of the solution?

There were no scalability issues. It was running on a VM over Hyper-V.

How are customer service and technical support?

I used support a little bit for some templates for formatting data from Cisco and Fortinet logs. They were very fast with their response. I didn't have any support contract, but only entry level support.

Which solution did I use previously and why did I switch?

This was our first try for log analysis.

How was the initial setup?

The setup was easy.

What's my experience with pricing, setup cost, and licensing?

There is nothing to say. At that time, it was for GBs of data received.

Which other solutions did I evaluate?

We did not look at alternatives. It was a consulting provider recommendation. It was a rapid implementation to accomplish legal requirements. After we used it for a while, we decided to keep it.

What other advice do I have?

Check for the plugin to format data of already completed templates for the appliance to which you want to keep logs and events.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Buyer's Guide
Splunk Enterprise Security
March 2024
Learn what your peers think about Splunk Enterprise Security. Get advice and tips from experienced pros sharing their opinions. Updated: March 2024.
768,857 professionals have used our research since 2012.
PeerSpot user
BS Systems Engineer at a tech services company with 501-1,000 employees
Real User
Makes use of all logs and takes proactive actions
Pros and Cons
  • "Integrity with many vendors: This simplifies the implementation and integration with different devices"
  • "Enterprise security: Splunk must work on clarifying the solution to customers and explain how to gain more from it."

What is our primary use case?

We used it to create a full security operations center (SOC) for our IT department by adding all network and security devices, the AD, and mail servers to it. Then Splunk started to receive their logs, it analyzed them, and provided useful reports.  

How has it helped my organization?

It helps the IT staff to monitor the full structure. It also makes use of all logs and takes proactive actions.

What is most valuable?

Integrity with many vendors: This simplifies the implementation and integration with different devices. 

What needs improvement?

Enterprise security: Splunk must work on clarifying the solution to customers and explain how to gain more from it.

For how long have I used the solution?

One to three years.
Disclosure: My company has a business relationship with this vendor other than being a customer: We are a partner with Splunk.
PeerSpot user
PeerSpot user
SVP, Technical Operations at a tech vendor with 201-500 employees
Vendor
Splunk has great interoperability with other applications through their SplunkBase app store.

What is most valuable?

Splunk has great interoperability with other applications through their SplunkBase app store. The apps can quickly provide visibility and streamline complex data mining tasks.

What needs improvement?

Unlike other cloud based analytics platforms, at the time of this writing Splunk Cloud is a dedicated instance per customer rather than a shared tenancy platform. While this is beneficial from an overall performance standpoint, the product lacks the seamless integrations one has come to expect from a cloud solution. This translates to a much stronger reliance on Splunk's support organization out of necessity, as the customer cannot make most changes in a self-service manner.

For how long have I used the solution?

We have been a Splunk customer for five years.

What was my experience with deployment of the solution?

Our Splunk Cloud deployment was a migration from an on-premise implementation of Splunk. The migration took much longer than expected due to constraints within Splunk's cloud team, but there were no technical issues with the launch.

How is customer service and technical support?

Customer Service:

The customer support team at Splunk is very good.

Technical Support:

The technical support team at Splunk is highly responsive and knowledgeable.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Engineer at a integrator with 11-50 employees
Real User
Has the ability to add the functionality you want but it is expensive
Pros and Cons
  • "The initial setup is really straightforward. It's one of the easiest installations."
  • "They should make data onboarding easier."

What is our primary use case?

Our primary use case is for monitoring and cybersecurity.

What needs improvement?

The clusters are hard. It has too many moving parts. 

They should make data onboarding easier.

For how long have I used the solution?

One to three years.

What do I think about the scalability of the solution?

Its ability to scale nicely is one of Splunk's strengths. You just horizontally add another machine and you get your scalability.

How are customer service and technical support?


Which solution did I use previously and why did I switch?

Our clients switch from Nagios or other monitoring solutions because the other solutions were not as flexible as Splunk. With Splunk, you can do things very programmatically. With a help of a developer and included SDK you can add needed functionality.

How was the initial setup?

The initial setup is really straightforward. It's one of the easiest installations. 

This product doesn't have any kind of dependencies, it just worked from one package. Install it and boom, you have a working solution.

What about the implementation team?


What's my experience with pricing, setup cost, and licensing?

Splunk is on expensive side.

There are some premium add-ons like Splunk Enterprise Security or ITSI which makes it more expensive.

What other advice do I have?

I would advise to get Splunk professional services from Splunk.

Disclosure: My company has a business relationship with this vendor other than being a customer: Partner.
PeerSpot user
it_user1048674 - PeerSpot reviewer
Cyber Analyst with 501-1,000 employees
Real User
It has the ability to correlate results

What is our primary use case?

Testing for insider threat behavior.

How has it helped my organization?

It gave management confidence in current operations.

What is most valuable?

The ability to correlate results.

What needs improvement?

A few more analysis aids might help. The next release could have more intuitive help examples.

For how long have I used the solution?

One to three years.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
it_user363165 - PeerSpot reviewer
Products Manager at a tech services company with 5,001-10,000 employees
MSP
Valuable features include rapid search, data mining, and information propagation. The GUI should be improved.

What is most valuable?

Rapid search is a valuable feature. Performance and incident response were the top priorities for most MSSPs. Breaches of SLAs will have a negative impact on customer trust, which eventually leads to losing customer confidence on services to which they’re subscribing. Hence, the proactive approaches will be the main differentiator from one MSSP to the others.

How has it helped my organization?

It has been helping a lot of my clients with fast data mining and information propagation.

What needs improvement?

The GUI should be improved, in other words, the overall appearance.

For how long have I used the solution?

I am not the end-user. However, my job was more relevant as a consultant.

What do I think about the stability of the solution?

Performance upgrades are needed when more processing power is required.

What do I think about the scalability of the solution?

We have not had scalability issues.

How are customer service and technical support?

Technical support is good.

Which solution did I use previously and why did I switch?

The client was using an open source solution. They decided to switch to an enterprise product.

How was the initial setup?

The setup can be straightforward, if use cases are well defined.

What's my experience with pricing, setup cost, and licensing?

Overall, it the cost is reasonable and it is easy to upgrade.

Which other solutions did I evaluate?

Our client was considering the other solutions as well. However, due to their overall assessment, they still considered going with it.

What other advice do I have?

Start off with something at a comfortable level, expand gradually, and then move upwards, expanding steadily.

Disclosure: My company has a business relationship with this vendor other than being a customer: We are a distributor.
PeerSpot user
Project Manager at a comms service provider with 10,001+ employees
Real User
This solution has an ability to do a quick search and immediately stop an incident from happening.
Pros and Cons
  • "It has virtual visualization, and other products do not."
  • "We had an instance when Splunk failed and it took us a couple of days to recover."

What is our primary use case?

My primary use case for Splunk is for log file visualization and monitoring alert management.

How has it helped my organization?

The way this solution has improved our organization is by its ability to do a quick search and immediately stop an incident from happening.

What is most valuable?

The auto-notification abilities are a huge benefit for us.

What needs improvement?

After a crash, the product takes a while to recover.

For how long have I used the solution?

One to three years.

What do I think about the stability of the solution?

Sometimes we have had instances when it will not run for a couple of days. There is room for improvement here.

What was our ROI?

There are lots of use cases and features that make Splunk a good choice for us.

What's my experience with pricing, setup cost, and licensing?

I have no opinion on the pricing of the product. 

Which other solutions did I evaluate?

We considered Datadog and Zabbix. In comparison to those options, Splunk has virtual visualization. Furthermore, it can be a host on our environment. Typically, we cannot deploy SaaS on our environment, but with Splunk, we can. 

What other advice do I have?

When Splunk failed, it took time to recover. We had to recover it from a snapshot. It took a couple of days, and it was as if it had crashed.  But, the instance was resolved.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Buyer's Guide
Download our free Splunk Enterprise Security Report and get advice and tips from experienced pros sharing their opinions.
Updated: March 2024
Buyer's Guide
Download our free Splunk Enterprise Security Report and get advice and tips from experienced pros sharing their opinions.