What is our primary use case?
My usual use cases for Splunk Cloud Platform involve being an admin where we used to build Splunk clusters or distributed environments from scratch on the on-premises system, but now we have everything up and running on Splunk Cloud Platform, which operates on AWS. Splunk has developed it on AWS. Currently, as an admin, I just need to maintain and configure it according to our needs. It functions as a software as a service now, meaning we don't configure it from scratch the way we used to do with installation, configuration, and setup of the configs as we required. Now, it is software as a service that we use for both Splunk and Observability.
How has it helped my organization?
Splunk Cloud Platform has greatly improved my daily operations through enhanced integration with third-party tools. Earlier integrations from on-premises Splunk to third-party tools were quite difficult, lacking the necessary add-ons or applications that could be directly used from the UI. Now on Splunk Cloud Platform, they have introduced new add-ons and plugins that allow us to utilize and pass credentials directly for integration with third-party applications, making the process very efficient and fast. We have multiple new add-ons that let us connect directly to clouds such as AWS, Azure, and Google, as well as event management applications such as ServiceNow, requiring only the credentials and service accounts and eliminating the need to configure from scratch.
What is most valuable?
The features of Splunk Cloud Platform that I have found most valuable and useful relate to licensing. Previously, it was a daily quota that we purchased on-premises, but currently it is based on SVC, or Splunk virtual compute, which is based on CPU and memory utilization of the cloud for billing. There are two license types: Victoria and Base. As we utilize the SVCs, we are charged accordingly, and we have the option to purchase a fixed number of SVCs or pay based on how many we actually use.
The effectiveness of Splunk Cloud Platform's search capabilities in uncovering operational insights is notable because as an admin or developer, we utilize saved searches that run on schedules that we set. The search capability utilizes the same compute assigned, and compared to on-premises, it is very efficient and fast because on-premises we had fixed compute assigned with limits set for searching per role or application. In the cloud, we find it very easy and fast to use.
Splunk Cloud Platform helps in proactive issue resolution by allowing us to set alerts based on data flow to find errors or anomalies that need identification. The saved searches run based on these conditions to find errors or identify anything unusual in the data. We get alerts based on the conditions we set, which is quite effective.
What needs improvement?
Areas of Splunk Cloud Platform that could be improved or enhanced in the future include data visualization, as the way we use data for security and other purposes could further benefit from enhanced visualization to support monitoring, threat analysis, and other aspects.
For how long have I used the solution?
Overall, I would rate Splunk Cloud Platform an eight out of ten as a solution for us.
What do I think about the stability of the solution?
Regarding stability and reliability so far, we are not yet live and are still in the migration process, but comparing it to on-premises, it seems promising.
What do I think about the scalability of the solution?
My thoughts on the scalability of Splunk Cloud Platform are that it scales up quite well. However, I haven't encountered any specific scenarios to validate it thoroughly yet, but overall, it appears to be good.
How are customer service and support?
My opinion on the technical support and customer service of Splunk, based on my cases, is that it is quite good with the credits we have along with the vendor. However, when we don't have credits, they charge us based on time as well as the criticality of the issue.
How would you rate customer service and support?
What other advice do I have?
In my opinion, there is room for improvement, as we used to raise multiple issues via the process, but they pick them up slowly, and the response times are not as prompt as we would like.
Regarding how Splunk Cloud Platform's ingest and visualization features help improve my data reporting, I have some insights on dashboards, but from a fully comprehensive perspective of data flow and ingestion, I haven't been hands-on that much. As an admin, I have worked on the infrastructure side of it, so I am unable to provide thorough feedback on that.
I would rate Splunk Cloud Platform an eight out of ten overall as a solution for our organization.
Which deployment model are you using for this solution?
Public Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Amazon Web Services (AWS)
Disclosure: My company does not have a business relationship with this vendor other than being a customer.