IT service analytics:
- Server machine data
- Monitoring data
- Alerting data
- ITSI KPIs
- Real-time reporting
- Month-over-month reporting.
IT service analytics:
It allows for transparency into IT metrics for insightful business analytics.
It brings together all sorts of data. It has the ability to correlate data, analyze and review it. This makes weekly ops reviews and monthly executive management reporting much easier by saving hours of collecting data. Report automation has been a life saver.
Previously, only the service owner could see the data and he might have gone to several places to obtain it. Now, it is all in one place and easy to access.
The ability to see logs and correlate them using Splunk has greatly improved our organization's functionality with auditing and troubleshooting.
Splunk's capability to receive any types of logs and index them is a very good feature. To get visibility from your network devices, servers, and security devices is a great feature.
Better directions on search head clusters. A lot of the documentation that I saw was either old or out of date. I believe I ended up doing a lot of searching and ended up not completing the feature. I opted out of creating a search head cluster.
Not at all.
None.
Customer Service:
Excellent. I didn't call often however, when I did they pretty much solved my problem.
Technical Support:
Excellent. I didn't call often however, when I did they pretty much solved my problem.
No solution was available at the time.
No the initial setup was fairly basic.
In-house. We had professional services however, we did the install prior to the consultant arriving. So, his workload was light considering we had already installed and configured the Splunk servers.
We purchased and paid for it as an annual subscription for three years and working on purchasing the Perpetual edition.
Pricing is pretty fair. However, I would suggest you trial for at least 90 days if you can get the sales person to offer you the option to renew your 30 day trial a couple of more times to evaluate. The 30 day trial is not enough.
The other SIEM solution providers we looked at were ArcSight, QRadar and SolarWinds LEM.
Splunk is a good product. Pricing is a bit high however, after it's installed you can understand why and get caught up in reading the logs that are available.
It is deployed to investigate, detect, respond, and prevent security incidents and threats by providing valuable context and visual insights to make faster and smarter security decisions.
We usually have to follow up with technical support on our open cases. Otherwise, Splunk listens to customers and is constantly incorporating their feedback in future releases.
There are no software stability issues. The issues so far have been internal.
There are no scalability issues. If you are planning on using Splunk for security use cases, I would recommend you go with Linux for your OS.
We have the enterprise level of support. This is one area Splunk could improve upon, since we usually have to follow up with them on our open cases.
We did not have a previous solution.
There were no issues with the initial setup. We utilized Splunk’s partner zones for the initial setup. In retrospect, we should have utilized Splunk Professional Services.
Although Splunk is an expensive product, it is designed to be utilized across your organization in order to maximize your ROI and lower your TCO.
We contacted Gartner and other business associates to determine what others are paying for Splunk.
We started researching ELK (Elastic, Logstash, Kibana). But management was so impressed with Splunk that we ended this research.
Ensure you have an executive sponsors to fully deploy Splunk across your organization to maximize your ROI and lower your TCO.
Make use of Splunk Professional Services.
If there's gold in log files, Splunk will help you to find it. Splunk bridges the gap between simple log management and security information and event management products from vendors such as ArcSight, RSA, Q1 Labs and Symantec.
Splunk lets you gather log data from systems and devices, and run queries on that data to find issues and debug problems. Splunk's capabilities also include reporting and alerting, pushing it ever-so-slightly into the world of SIEM.
What separates out Splunk from the world of Syslog servers and SIEM tools is Splunk Apps, a library of nearly 200 addons that make Splunk smarter about particular types of log information, change its look-and-feel or add new types of analysis.
The connections to the database are very good and updating the data files is simple to do. The dashboards are useful and user-friendly.
We had some connections issues with the solution at the beginning.
I have used Splunk within the last 12 months.
Splunk is a highly stable solution.
The scalability is good.
We have approximately 50 users using this solution in my organization.
I am satisfied with the support from Splunk.
We were previously using Excel.
We used a consultant for the implementation of the solution. The full process took approximately one week.
We had a big problem with communication sometimes during the implementation. Some files in our network were a little difficult to receive. This was our fault because of some of our firewall configurations.
We have a five-person maintenance team that works on this solution.
I rate Splunk an eight out of ten.
We primarily use it for SIEM.
It has a big user base, so the community is useful.
The community surrounding the product is okay, but I would like more material supplied by Splunk around some more common integration stuff. I wish there was a bigger library, because we are building stuff. Where I often feel like other people have done things before, we are reinventing the wheel. While it is not a core piece of our organization and it is not a priority, it does inform our SIEM platform. It would be nice if there was a little more cookie cutter solutioning inside of it, and that they would take a little more time to shake it out.
The first year and a half was a little wacky with its usefulness, but now it is a solid piece of our infrastructure.
We don't have any issues with it now. We had some issues in the past, but we chalked those up to user error. We didn't know what we were doing at first.
We haven't had any issues with it.
I haven't heard any complaints about the technical support.
The integration with all our tool sets felt like we were reinventing the wheel, which was a pain point for us.
It would be nice if the pricing were cheaper. However, we did purchase it.
We evaluated Alert Logic and Splunk. We still use both products heavily.
We have different use cases for the products. At first, Splunk was free, so we started to take more advantage of it.
Do your homework and make sure it fits your needs.
The product is pretty good. We are pretty satisfied with it. It does what it does.
We host the product on AWS, but we did not purchase it on the AWS Marketplace.
Enterprise security is the solution’s most valuable feature.
Its reporting functionality is excellent.
I really like the user interface and how it works.
It’s scalable.
The solution is stable.
You can integrate any other tool or any other solution, including existing solutions, with Splunk. They have a good setup.
The log analysis is something that is good. In general, data analysis is something you can do in Splunk in various ways. You can leverage it as per your requirements or as per your investigations. You can write your own queries and complicated queries, and you can have your own alerts. You can correlate events. It’s very flexible.
It is one of the best tools that I'm using. I don't have any feedback as such right now regarding improvements. I'm not also an expert, so maybe I'm missing something.
Writing queries is a bit complicated sometimes. If they could provide some building queries, that would be great.
It's been a while. For maybe four years, I've used Splunk, however, I'm not an expert on it.
It's a stable solution. We are not going to get rid of it anytime soon. It’s reliable. There are no bugs or glitches and it doesn’t crash or freeze. The performance is good.
The solution scales very well.
I wasn't part of the engineering side, so I never got a chance to contact the support team directly.
We have a SIEM solution, however, now the company is also trying to move to an Excel solution since the automation is better on their side. We aren't going to get rid of it or did not have any other SIEM solution in their mind when they were acquiring it. However, if any XOR solution works perfectly for us, the company might consider moving out of Splunk.
A different organization would have a different setup of Splunk. If you ask me, mostly, it is a simple setup. However, here in my current organization, it is mostly on the cloud, and a lot of things are integrated in a bit of a complex manner. I also understand that this changes from organization to organization in terms of how they will leverage it.
I’ve never looked into ROI and have not been a part of conversations concerning ROI.
I don’t have any idea what the cost of the solution is. I don’t handle the licensing.
A company that wants to leverage Splunk should understand its environment first - including the organization, the network infrastructure, and the overall infrastructure. Then, based on requirements, they should go ahead with any SIEM solution. Splunk is kind of an expensive tool to have. Therefore, the company should be clear about what requirements they have, what they need, and whether they want to use Splunk. It is very crucial to understand your requirements and your network or your environment first before going ahead.
I’d rate the solution eight out of ten.
Overall, it's a good tool. It's a very intelligent tool. It definitely depends on how you are going to use it. However, I love the product. I love Splunk. I want to learn more about it as much as I can.
Security. We have built SIEM solutions three times from the ground up (not ES) using Splunk for some of the largest companies in the world.
Out clients went from unhappy using inflexible, poorly-supported products (in some cases barely functionally) to confident and excited when using Splunk. Not only are they able to do their security jobs and investigations, but they are also easily able to modify and evolve their implementations themselves to keep up with the shifting sands, which is the SecOps landscape.
With good domain knowledge, one can build almost anything. If you throw in Alert Manager or an integration with ServiceNow. Then, you have your own SIEM.
Almost 10 years.
Unfortunately, lately every release has a new memory leak. Be SURE to upgrade late and READ THE RELEASE NOTES, especially the "Known Issues" section.
We only ever have issues when deployed on VMs and the VM admins do not do what we tell them to do which is EXCLUSIVELY RESERVE OUR RESOURCES.
It used to be great (but perhaps that was because my employer at the time was a key prospect in a vertical where Splunk had no customers) but Splunk support is definitely a victim of Splunk's explosive growth. The first tier support is as bad as it is most places and getting worse all the time. If you KNOW your problem is not run of the mill, ask for escalation immediately. Also the clock on the case does not start until somebody adds a note to the case so always call in and ask if they got your diag file (always attach a diag) and the person who answers will have to add a note to the case which will start the clock.
I have dabbled with LogRythm and ArcSight and they are both OK, but Time-To-Value is WAY shorter with Splunk, IMHO.
Use bare metal severs on Linux and you will be fine. Use Windows and you will have much trouble. Use VMs and your admins will cheat you and you will have much trouble. Do not use NAS!!!!
In-house. We at Splunxter are Splunk experts. We can do anything with Splunk. We always hit homeruns.
We usually get multi X-factor within a quarter.
Get free PS if you can (ask) or USE THE DOCS. The documentation will get you to success. If you are not getting more value out of Splunk than the license you are paying, then you are doing something wrong and should spend a tiny bit more to get a consultant like Splunxter.com to help you.
No,we went with the free trial and got so much value so quickly we bought in.
You can also get GREAT help at answers.splunk.com.
We use Splunk for security and also PCI compliance.
We have installed and implemented this solution for several clients in Bolivia with our team. We have received training from Splunk directly, and we have also provided training to our clients.
We deploy two versions: one for on-premise and one for the cloud.
Most of our customers purchase Splunk because they required a tool for gathering and collecting all of the logs from the infrastructure in order to make a correlation between data and to spot patterns surrounding security incidents.
The correlation capabilities are the first value that our clients say they like with Splunk. Another benefit is that they can connect to any device or log from any device from anywhere.
It's easy, the tool is very easy to install and set up.
They could have more dashboards done or predefined so our clients could use them directly in order to have more information ready to use.
The difficult part is related to integration with sources of data that are used to create the logs as this depends on the infrastructure of the client.
We have been using this solution for more than five years.
Stability-wise, it's great.
We do not require much scalability here because the clients are not so big; however, the hardware where we installed the products was enough to handle all the transactions of Splunk.
The support is not so good, I would only give them a rating of six or seven.
They should provide support in Spanish here in Latin America. Their response time to inquires or requirement tickets is too long. It should be shorter.
Deployment took us two weeks.
I would recommend Splunk to any company: small, medium, and large.
Splunk is a great tool but you should get a partner who knows what they are doing, implementation-wise.
On a scale from one to ten, I would give Splunk a rating of nine.
splunk is user friendly-Better than other similar products