I have a variety of use cases. My company uses it for cloud-related operations, anomaly identification, and threat detection.
Project Lead at a computer software company with 5,001-10,000 employees
Offers timestamp indexing and the easy-to-use visualization for data analysis
Pros and Cons
- "Splunk's real-time processing capability has been pretty good for my use cases."
- "There is room for improvement in terms of scalability."
What is our primary use case?
How has it helped my organization?
It's been very useful in regard to security information and threat management (SIEM). Splunk is a valuable tool for my organization.
What is most valuable?
The timestamp indexing and the easy-to-use visualization features are the most valuable features for data analysis.
Moreover, the dashboard and visualization features have made a big difference. We can quickly identify issues within the dashboards and easily generate insightful reports. If something goes down, we can easily detect the issue.
Splunk's real-time processing capability has been pretty good for my use cases.
What needs improvement?
There is room for improvement in terms of scalability. They can enhance the ability to handle increasing volumes of data.
Buyer's Guide
Splunk Enterprise Platform
January 2025
Learn what your peers think about Splunk Enterprise Platform. Get advice and tips from experienced pros sharing their opinions. Updated: January 2025.
832,138 professionals have used our research since 2012.
For how long have I used the solution?
I have been using it for four years now.
What do I think about the stability of the solution?
There have been occasional issues, but nothing major.
I would rate the stability an eight out of ten.
What do I think about the scalability of the solution?
I never had issues with scalability. My organization has 8,000 end users.
I would rate the scalability an eight out of ten.
How are customer service and support?
The customer service and support are good.
How would you rate customer service and support?
Positive
How was the initial setup?
In general, the initial setup is fairly easy.
Not everyone can do it. Some knowledge and experience would likely be helpful to get the most out of the setup.
Typically, the deployment would take around 16 to 20 hours.
What's my experience with pricing, setup cost, and licensing?
The pricing is about average.
What other advice do I have?
Overall, I would rate the solution an eight out of ten.
I would recommend using this solution. Overall, Splunk is a good tool for analysis and for representing data in a short span of time. It helps minimize unnecessary noise in the data.
Which deployment model are you using for this solution?
On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Solution Architect at a tech vendor with 10,001+ employees
Versatile, adaptable, and applies to many use cases
Pros and Cons
- "What I find the most valuable about the platform is its DB Connect and its versatility in general. I also like its adaptability to any use case when it comes to collecting and analyzing data."
- "The platform is too expensive for small businesses. Splunk should focus more on delivering something for small businesses and entrepreneurs."
What is our primary use case?
I use the platform to collect data and report to the clients that need reporting from Splunk. I work on gathering big data from all over my company and exporting it into proper reports.
What is most valuable?
What I find the most valuable about the platform is its DB Connect and its versatility in general. I also like its adaptability to any use case when it comes to collecting and analyzing data.
What needs improvement?
It is hard to say in what areas the platform could be improved since it's very versatile and applies to many use cases. It already has the functioning vetted into the core architecture of the product. In my opinion, there is no need for additional features because it already has many, and I haven't used them all.
For how long have I used the solution?
I've been using Splunk Enterprise Platform for two and a half years. I am a Splunk software architect and Splunk is the only platform I use.
What do I think about the stability of the solution?
It's a very stable platform. A ten out of ten.
What do I think about the scalability of the solution?
The scalability of Splunk is ten out of ten. It's one of the best platforms on the market. Approximately 1,000-2,000 people use the platform at our company, but only two people are needed to maintain it and I'm one of them. Everything is automated and it is very easy to manage 2,000 users on my own.
Which solution did I use previously and why did I switch?
I would compare Splunk Phantom with RSA NetWitness and Elasticsearch. All three solutions give the same output but in a different way. They analyze data in different ways. Each product has its scalability, versatility, and appliances in the current business needs of the company that uses it.
How was the initial setup?
The initial setup is very easy. At our company, we deployed Splunk ourselves because we are a team of Splunk architects and we have done it before.
What's my experience with pricing, setup cost, and licensing?
The platform is too expensive for small businesses. If you choose the free plan, it only has 15 GB of data per day, and it may not be enough to run a small business. You need to pay a subscription based on data ingestion, and that's very expensive. Splunk should focus more on delivering something for small businesses and entrepreneurs. I give the pricing a three or four out of ten. Although the product is pricey, it's truly magnificent.
Which other solutions did I evaluate?
What other advice do I have?
Overall, I give Splunk a nine out of ten and not a solid ten just because there are new updates every day and we don't know exactly what we need to search for since it's not that viewable.
Which deployment model are you using for this solution?
Hybrid Cloud
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
Buyer's Guide
Splunk Enterprise Platform
January 2025
Learn what your peers think about Splunk Enterprise Platform. Get advice and tips from experienced pros sharing their opinions. Updated: January 2025.
832,138 professionals have used our research since 2012.
Software Engineer II at Carelon Global Solutions
Enables us to collect, index, and analyze data from various sources, such as apps, servers, network devices and security systems
What is our primary use case?
The solution is used for basically, to monitor various logs, so it is the application logs, some kind we are monitoring databases.
How has it helped my organization?
Splunk is providing, like, proactive monitoring using desserts and all. So these things have improved a lot. Like, in our done day to day activities and all. So whenever we are seeing any kind of alerts and also on that basis, we are going to create alert.
What is most valuable?
For monitoring security data is the most valuable feature.
What needs improvement?
Currently, I think things are good only. There are certain things which is not which is there in the other platform like UAE, UBA is there. Like, Splunk is having another product itself. But the thing is, like, if that can be incorporated with the Splunk Enterprise three version. So it will be helpful for the users to explore more on that one.
For how long have I used the solution?
I have been using Splunk Enterprise Platform for five years.
What do I think about the stability of the solution?
The stability is a nine out of ten meaning the solution is highly stable.
What do I think about the scalability of the solution?
It is a scalable solution. Around thousand plus users are using the solution.
Which solution did I use previously and why did I switch?
I have been using this Splunk only from my, like, a shorting of the career. During this period, I have been using AppDynamics and NetSync as well.
How was the initial setup?
Normally so for trial version, it is easy. So it depends on how much data you are ingesting. So if you are going for the Flushing environment, so that setup Could be somewhat difficult, but, normally, it will be easy only.
What was our ROI?
I have seen a Return on Investment.
What's my experience with pricing, setup cost, and licensing?
Costing depends on, like, how much data you are investing. So that will increase your cost.
What other advice do I have?
I will rate the overall solution a nine out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer:
Security Architect at a comms service provider with 10,001+ employees
A solution that offers a good analytics part along with great integration capabilities with other applications
Pros and Cons
- "The most valuable feature of the solution is the analytics part."
- "The support offered by Splunk Enterprise Platform has certain shortcomings that need improvement."
What is our primary use case?
My company uses Splunk Enterprise Platform for monitoring and user base filtering.
What is most valuable?
The most valuable feature of the solution is the analytics part. Integration with other applications is another valuable feature of Splunk Enterprise Platform.
What needs improvement?
Splunk Enterprise Platform is already a refined product, so I don't have any recommendations related to areas that need improvement.
The cost of Splunk Enterprise Platform is an area of concern where improvements can be made by bringing down the costs. Product-related, I don't have any feedback.
The support offered by Splunk Enterprise Platform has certain shortcomings that need improvement.
For how long have I used the solution?
I have been using Splunk Enterprise Platform for a few weeks since it was recently deployed in my company. I use the solution's latest version. My company operates as a service provider of the solution.
What do I think about the stability of the solution?
The product's stability is good. Stability-wise, I rate the solution a nine out of ten.
What do I think about the scalability of the solution?
Scalability-wise, I rate the solution a nine out of ten.
Around 5,000 people use the solution. Around 10 to 15 analysts use Splunk Enterprise Platform in my company.
The solution is used on a regular and daily basis in my company.
How are customer service and support?
I am moderately satisfied with the solution's technical support. I rate the technical support an eight out of ten.
How would you rate customer service and support?
Positive
How was the initial setup?
Splunk Enterprise Platform was easy to implement. I rate the product's implementation phase an eight out of ten, where one is difficult, and ten is easy.
The solution is deployed on an on-premises model.
The solution's deployment phase was carried out over a period of one or two months.
What's my experience with pricing, setup cost, and licensing?
I rate the product's pricing a ten on a scale of one to ten, where one is cheap, and ten is expensive. It is a very pricey tool.
What other advice do I have?
I would recommend the product to those who plan to use it, provided the pricing of the solution is brought down.
I rate the overall product an eight out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer: MSP
Support Engineer at Wipro Limited
Good infrastructure and easy to maintain
Pros and Cons
- "Easy setup and maintenance"
- "Things have to be managed manually"
What is our primary use case?
We use Splunk Enterprise for data visualization.
We use Splunk administration rather than Splunk development.
We provide support to users so they can access our Splunk application and use it however they want. For example, if they are not able to view some of the logs that are coming from their servers in our Splunk, then we usually check all the logs here that have been missed and forward the ones that were not forwarded.
Also, sometimes they use their access to install some apps. We have Splunk apps and they want us to create an app for their usage. We also need to create these apps in the Splunk application. Sometimes they aren't able to download or upload files into Splunk or other websites. They aren't able to download these reports as PDF files. We usually work on this and try to resolve it as quickly as possible.
How has it helped my organization?
We use Splunk for cyber security. We have a lot of teams who use Splunk for different purposes. The security team uses it to authorize log-ins, so in case something happens, Splunk monitors it. Also, the development team uses it to monitor data while they're creating a new application.
What is most valuable?
In the enterprise platform, all of the clusters and indexes are under our maintenance. If required, we can make changes and see the logs manually by getting into the servers.
What needs improvement?
Things have to be managed manually in Splunk Enterprise, which is not the case in Splunk Cloud, where the client could manage it on their own.
It would be useful if Splunk Enterprise Platform could monitor the application URL, to check whether it's responsive or not.
For how long have I used the solution?
I've been using it for a year and a half.
What do I think about the stability of the solution?
It is completely stable and the infrastructure is good. We have no issues with our Splunk Enterprise Platform.
How are customer service and support?
We contact technical support whenever there's an issue with logs and they work through it with us.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
We use both Splunk Cloud and Splunk Enterprise. We might opt for Splunk Cloud in the future since it's less expensive, but we are currently using both.
How was the initial setup?
The deployment takes about a day. I would say that the initial setup is quite a complex thing to do because there are a lot of things that have to be done for clustering all the features and indexing and then forwarding data to the indexes. When it comes to applications, we have to replicate the data. The process takes time. Once everything is done, we still need to monitor the infrastructure constantly.
It is easy to maintain if you are familiar with the deployment model.
Which other solutions did I evaluate?
I have hands-on experience with AWS, Linux, Ansible, and Terraform and with programs like Python, Java, and SQL as well. I also use tools like Catchpoint, Nagios, and Grafana.
What other advice do I have?
I would suggest using Splunk Cloud first, and then Splunk Enterprise because the maintenance and the infrastructure management are easy. I would rate it an eight out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Security Architect at XVE Security
A customizable solution that can be used as a Security Incident and Event Management (SIEM) tool
Pros and Cons
- "The most valuable feature of Splunk Enterprise Platform is that it's a customizable solution."
- "Splunk Enterprise Platform should include more integrations with other security tools."
What is our primary use case?
We use Splunk Enterprise Platform as a Security Incident and Event Management (SIEM) tool.
What is most valuable?
The most valuable feature of Splunk Enterprise Platform is that it's a customizable solution.
What needs improvement?
Splunk Enterprise Platform needs a bit of tuning, and it would be beneficial if it came with some prebuilt use cases.
Splunk Enterprise Platform should include more integrations with other security tools.
For how long have I used the solution?
I have been using Splunk Enterprise Platform for six years.
What do I think about the stability of the solution?
I rate Splunk Enterprise Platform a nine out of ten for stability.
What do I think about the scalability of the solution?
I rate Splunk Enterprise Platform an eight to nine out of ten for scalability.
How are customer service and support?
The technical support team's initial response is too late.
I rate the solution's technical support a five or six out of ten.
How would you rate customer service and support?
Neutral
How was the initial setup?
The solution's initial setup is average and a little bit tricky. On a scale from one to ten, where one is difficult, and ten is easy, I rate Splunk Enterprise Platform a three out of ten for the ease of its initial setup.
What about the implementation team?
Splunk Enterprise Platform was deployed in a month in our organization.
What's my experience with pricing, setup cost, and licensing?
Splunk Enterprise Platform is an expensive solution.
On a scale from one to ten, where one is cheap, and ten is expensive, I rate the solution's pricing a nine out of ten.
What other advice do I have?
I am working with the latest version of Splunk Enterprise Platform. Splunk Enterprise Platform is deployed on-cloud in our organization.
I recommend that users not expect value from Splunk Enterprise Platform immediately. It might take time to set it up and get any value out of it.
Overall, I rate Splunk Enterprise Platform a nine out of ten.
Disclosure: My company has a business relationship with this vendor other than being a customer: Implementer
Software engineer at Torry Harris Business Solutions
Provides efficient monitoring capabilities and valuable transaction insights
Pros and Cons
- "The product's most valuable feature is the ability to explain the values and provide insights into transactions."
- "Areas for improvement include enhancing dashboards, reports, alerts, and the monitoring console."
What is our primary use case?
We use the product for real-time monitoring purposes.
What is most valuable?
The product's most valuable feature is the ability to explain the values and provide insights into transactions. It allows us to understand successful and failed transactions with a graphical representation easily.
What needs improvement?
Areas for improvement include enhancing dashboards, reports, alerts, and the monitoring console. With the monitoring console, users can track server performance metrics such as data ingestion, server uptime, CPU, and memory utilization. Integrations with third-party apps can provide comprehensive server monitoring capabilities. However, setting up such integrations may require significant time and effort, as experienced in the mentioned case took nearly 20 days to complete.
For how long have I used the solution?
We have been using Splunk Enterprise Platform for four years now.
What do I think about the stability of the solution?
I rate the platform's stability an eight out of ten.
What do I think about the scalability of the solution?
The product is highly scalable.
How was the initial setup?
The complexity of the initial setup largely depends on the level of experience. I find it straightforward due to my proficiency in establishing connectivity, creating DNS, and performing installation configuration. I rate the process a nine and a half out of ten.
The time required for deployment varies depending on the process in place. If changes need to be made within a specific window, such as raising an instance, the window period opens only for a set duration. Deployment in such cases involves raising a change request and obtaining approval, which can take up to seven days. However, from a technical perspective, initial deployment typically takes up to one or two hours. Yet, procedural requirements, like awaiting change request approval, may prolong the process, necessitating additional days of waiting before deployment can proceed.
What's my experience with pricing, setup cost, and licensing?
The product is expensive, and the cost depends on the amount of data ingestion.
What other advice do I have?
When clients request specific data for a particular period, we retrieve the relevant information from our servers and generate statistics. Later, we create reports, alerts, and dashboards based on the requested data. This process involves fetching the necessary data attributes, such as service names, and displaying their corresponding values in the generated reports, alerts, and dashboards.
The platform's alerting capabilities enable the automation of alerts based on predefined conditions. When specific results exceed predefined thresholds, alerts are triggered automatically. For example, if a value exceeds a specified threshold, an email alert is generated and sent to the relevant stakeholders, prompting them to take appropriate action. This automated alerting mechanism enhances operational efficiency by promptly notifying stakeholders of critical events, allowing them to respond swiftly and effectively to potential issues or deviations from expected outcomes.
I recommend Splunk to other people. It's a very good tool, offering many features that surpass other tools like Kaspersky. Its comprehensive monitoring capabilities and insightful analytics make it a valuable user asset.
I rate it a ten out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer: Integrator
Security Engineer at Spire Solutions
A platform to monitor, alert, report, and analyze vulnerabilities
What is our primary use case?
We use the solution to monitor, alert, report, and analyze.
How has it helped my organization?
In identity and asset management, Splunk will detect any vulnerabilities , or if any upgrade patching is improperly done, it will send an alert to the specific admin team, indicating the need to patch their servers.
What is most valuable?
The feature of Splunk Enterprise Platform is its comprehensive capabilities, consolidating various functionalities into a single tool. It excels in searching, reporting, and learning. Additionally, it offers automation and integration features for generating reports at specified business times. One prominent feature widely utilized by companies is enterprise security, crucial for cybersecurity purposes.
What needs improvement?
The solution could enhance automation capabilities. Currently, the process involves daily manual checks for potential issues, maintenance tasks, and planning for automation. Rather than relying solely on daily activities, there's a need to implement automation solutions for streamlined operations.
The main issue with the Splunk Enterprise Platform is its licensing cost, which can be high for small companies. Many businesses are migrating from Splunk to alternative tools. If Splunk were to lower its licensing fees or offer discounts, it would likely retain more customers.
For how long have I used the solution?
I have been using Splunk Enterprise Platform for seven years. We are using 9.0.1.2 of the solution.
What do I think about the stability of the solution?
The solution is stable. There is no impact. I can rate it a nine out of ten.
What do I think about the scalability of the solution?
When increasing your volume of data, high availability is crucial. With Splunk's robust clustering and enrollment features, data availability remains constant. If one site experiences downtime, the other will seamlessly take over, ensuring continuous data availability without any loss or impact.
10,000 users are using this solution.
How are customer service and support?
As part of our operations focus, we often encounter numerous ticketed issues. Our team is dedicated to addressing these concerns and ensuring the best possible service for our customers.
How would you rate customer service and support?
Positive
How was the initial setup?
Deployment typically takes just a fraction of an hour or two hours. Implementation can be completed within a single day, often within 24 hours.
What other advice do I have?
Splunk Enterprise Platform allows customized data processing, making it highly versatile and easy to maintain. It seamlessly handles tasks like data masking and filtering, ensuring efficient data management.
When it comes to the visualization on the dashboard within the Splunk Enterprise Platform, we do have the chart available, and all its features are included. Additionally, if you require customization for a new customer's preferences, we can implement it using HTML or XML code. The primary approach for developing dashboards is based on XML. Therefore, if you need specific features like radio buttons or checkboxes, they are readily available for inclusion in the dashboards.
I recommend the solution.
Overall, I rate the solution a nine out of ten.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Last updated: May 11, 2024
Flag as inappropriateBuyer's Guide
Download our free Splunk Enterprise Platform Report and get advice and tips from experienced pros
sharing their opinions.
Updated: January 2025
Popular Comparisons
Apache Superset
Buyer's Guide
Download our free Splunk Enterprise Platform Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- What's your experience or opinion about Spotfire vs. Tableau vs. Qlik?
- A journalist is writing a story about which Data Visualization software product to choose. Can you help him?
- What enterprise data analytics platform has the most powerful data visualization capabilities?
- When evaluating Data Visualization, what aspect do you think is the most important to look for?
- What are the best self-service and Excel-like filtering / display tools?
- What data visualization tool/s do you find to be the best?
- Why is Data Visualization important for companies?
- How many users on average are licensed users of Data Visualization software in a company?