Try our new research platform with insights from 80,000+ expert users
reviewer1795125 - PeerSpot reviewer
Cyber Security Consultant at a tech services company with 10,001+ employees
Real User
Responsive, and available, technical support, that is easy to install
Pros and Cons
  • "It's better than IBM, in my opinion, because it's an independent entity."
  • ". Having a trial version or more training on Splunk would be helpful."

What is our primary use case?

I use Splunk for testing purposes. It is used for school research and to learn how to use Splunk. 

Splunk is mainly used for collecting logs and dashboards.

What is most valuable?

Splunk provides a free version so you can test it before purchasing.  It's better than IBM, in my opinion, because it's an independent entity. IBM, for example, if you want to use EDR, and other features, you must use the features of other companies, such as ServiceNow and Jira.

I am still exploring the features provided in Splunk. As I have not used it for a long time, I don't have a clear vision of it.

What needs improvement?

As a student, I'd like to see more labs and things for students to test in order to learn.

Having a trial version or more training on Splunk would be helpful.

There is a free version, but it is insufficient for training and learning because it is a little bit difficult to work with, especially if you are a beginner. It's difficult to improve when you're just starting out with logs and SOC. As a result, we require a longer free version.

For how long have I used the solution?

Splunk is not used in my company. During my internship, I am being taught how to use it at school.

I have been using Splunk for one month.

Buyer's Guide
Splunk Enterprise Security
November 2024
Learn what your peers think about Splunk Enterprise Security. Get advice and tips from experienced pros sharing their opinions. Updated: November 2024.
823,875 professionals have used our research since 2012.

What do I think about the stability of the solution?

I did not have any issues with the stability of Splunk. It was quite stable.

How are customer service and support?

There was technical assistance available. When you require assistance, they provide it, they will respond.

Which solution did I use previously and why did I switch?

We integrate Jira with QRadar which is helpful.

How was the initial setup?

The initial setup was simple because there is available support and tutorials.

What about the implementation team?

I completed the installation with the help of some friends, in the IT department.

What's my experience with pricing, setup cost, and licensing?

I'm only using the free version for the time being.

The cost is reasonable.

Splunk's costing is a little more difficult. The pricing method is complicated, and the way that costing is calculated in Splunk is a little more difficult.

When compared to QRadar, QRadar, it's simple to pay. 

Which other solutions did I evaluate?

I did some research for a school project. I needed to compare it to Splunk and a few other tools. As a result, I'm not particularly interested in purchasing them.

What other advice do I have?

I would rate Splunk an eight out of ten.

Which deployment model are you using for this solution?

Private Cloud
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
reviewer1789335 - PeerSpot reviewer
Senior Manager, Analytics & Insights at a consultancy with 10,001+ employees
Consultant
Effective machine learning, reliable, and responsive support
Pros and Cons
  • "Splunk has machine learning which is a valuable feature."
  • "The algorithms customization of Splunk could improve. They have limited algorithms for machine learning support. If they can allow the user to add more machine learning algorithms, such as the ability to choose the algorithm that a user might want. Additionally, they should provide the required libraries for those algorithms, and then analyzes the data for use."

What is our primary use case?

We are using Splunk for querying data from different sources.

What is most valuable?

Splunk has machine learning which is a valuable feature.

What needs improvement?

The algorithms customization of Splunk could improve. They have limited algorithms for machine learning support. If they can allow the user to add more machine learning algorithms, such as the ability to choose the algorithm that a user might want. Additionally, they should provide the required libraries for those algorithms, and then analyzes the data for use.

For how long have I used the solution?

I have used Splunk within the past 12 months.

What do I think about the stability of the solution?

Splunk is a stable solution.

How are customer service and support?

We have contacted the support and most of the reasons we have contact support has been project-related. For example, we want the APAs to work in a certain way or for certain fixes.

What other advice do I have?

I have been using Splunk for approximately 

Which deployment model are you using for this solution?

On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Buyer's Guide
Splunk Enterprise Security
November 2024
Learn what your peers think about Splunk Enterprise Security. Get advice and tips from experienced pros sharing their opinions. Updated: November 2024.
823,875 professionals have used our research since 2012.
reviewer1688463 - PeerSpot reviewer
Senior Technical Lead at a financial services firm with 10,001+ employees
Real User
Priced reasonably, effective log analysis, but artificial intelligence features need improvement
Pros and Cons
  • "We have found all the features useful. However, the dashboarding and logging have been very helpful. Additionally, the log analysis does a great job."
  • "The solution could improve by giving more email details."

What is most valuable?

We have found all the features useful. However, the dashboarding and logging have been very helpful. Additionally, the log analysis does a great job.

What needs improvement?

The solution could improve by giving more email details.

In a future release, the solution could improve on the artificial intelligence features, such as if an alert comes, it could automatically do logging from the system, get the KV knowledge base, and perform other functions. This would be a benefit.

For how long have I used the solution?

I have used Splunk for approximately five years.

How are customer service and support?

The technical support is good.

How was the initial setup?

The initial setup is complex.

What's my experience with pricing, setup cost, and licensing?

The price of Splunk is reasonable.

Which other solutions did I evaluate?

We have evaluated SoapUI and Postman, and we are still evaluating others.

What other advice do I have?

I rate Splunk a seven out of ten.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Senior Information Technology System Analyst at YASH Technologies
Real User
Impressive UI, many useful features, and very scalable, but needs alerting feature and better pricing and integration
Pros and Cons
  • "There are quite a lot of things that we find useful. Splunk agents are useful and good. Its UI is quite impressive."
  • "Its pricing model and integration with third-party services can be improved. We had faced an issue with integration. The alerting feature is currently not available with Splunk, but it is definitely available with Datadog and PagerDuty. They should include this feature. A few dashboards in Splunk look quite old and are not that modern. They aren't bad, but improving these dashboards will definitely make Splunk more attractive and usable. I read in a few blog posts that there were a few security incidents related to Splunk agents. So, it can be made more secure."

What is most valuable?

There are quite a lot of things that we find useful. Splunk agents are useful and good. Its UI is quite impressive.

What needs improvement?

Its pricing model and integration with third-party services can be improved. We had faced an issue with integration. 

The alerting feature is currently not available with Splunk, but it is definitely available with Datadog and PagerDuty. They should include this feature.

A few dashboards in Splunk look quite old and are not that modern. They aren't bad, but improving these dashboards will definitely make Splunk more attractive and usable.

I read in a few blog posts that there were a few security incidents related to Splunk agents. So, it can be made more secure.

For how long have I used the solution?

I have been using this solution for almost two years. I am using its latest version.

What do I think about the stability of the solution?

It is a stable product.

What do I think about the scalability of the solution?

Splunk is definitely scalable.

How are customer service and technical support?

I have not interacted with them. Another team is taking care of raising tickets with their technical support.

How was the initial setup?

It is quite simple.

What's my experience with pricing, setup cost, and licensing?

Its pricing model can be improved.

What other advice do I have?

A few years ago, I would have definitely recommended Splunk, but nowadays, better alternatives are available. We are currently exploring a few other alternatives, so I won't recommend Splunk as of now.

I would rate Splunk a seven out of ten.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
reviewer1062186 - PeerSpot reviewer
Sr. IT Manager at a pharma/biotech company with 10,001+ employees
Real User
Top 20
Good log aggregation and scales well, with good technical support that is responsive and helpful
Pros and Cons
  • "The most valuable feature is that it's very good for log aggregation."
  • "The implementation and the scanning of the logs can be difficult."

What is our primary use case?

We are using Splunk to look at the logs, and see what is happening.

What is most valuable?

The most valuable feature is that it's very good for log aggregation.

What needs improvement?

Splunk is very complex. The implementation and the scanning of the logs can be difficult.

For how long have I used the solution?

I have been using Splunk for approximately three years.

What do I think about the stability of the solution?

In general, Splunk is stable.

What do I think about the scalability of the solution?

It's a scalable product. it's pretty good.

How are customer service and technical support?

Technical support is usually pretty good.

They are responsive, knowledgeable, and helpful.

How was the initial setup?

The initial setup was relatively straightforward.

What's my experience with pricing, setup cost, and licensing?

The price is comparable.

What other advice do I have?

I would rate Splunk and eight out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
reviewer1062186 - PeerSpot reviewer
Sr. IT Manager at a pharma/biotech company with 10,001+ employees
Real User
Top 20
Log aggregation helps us quickly detect widespread threats, but it can be resource-heavy
Pros and Cons
  • "The most valuable feature is the log aggregation, being able to scan through all of the logs."
  • "Queries are not always as easy or straightforward as they might be, so it can be difficult to figure out what you need to look for."

What is our primary use case?

We use Splunk for log analysis and security monitoring.

How has it helped my organization?

Splunk allows us to look at logs from different groups within NIH and see if there's a widespread threat or issue.

What is most valuable?

The most valuable feature is the log aggregation, being able to scan through all of the logs.

What needs improvement?

Queries are not always as easy or straightforward as they might be, so it can be difficult to figure out what you need to look for.

In the next release of this product, I would like to see it offer more recommendations as to what needs to be done.

For how long have I used the solution?

We have been using Splunk for between two and three years.

What do I think about the stability of the solution?

In terms of stability, the product seems to work just fine. We haven't had any problems with it.

What do I think about the scalability of the solution?

It can be somewhat of a resource hog; some of the scans can take a while. We do plan to increase our usage in the future.

How are customer service and technical support?

Technical support for Splunk is good.

How was the initial setup?

The initial setup is relatively straightforward.

What about the implementation team?

There were consultants involved in the deployment.

What other advice do I have?

I would rate this solution a seven out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Director158d - PeerSpot reviewer
Director at a tech services company with 10,001+ employees
Real User
It has the flexibility to do multiple analyses
Pros and Cons
  • "It has helped us look at modern technology, as well as penetrate our legacy systems, to see where the bottlenecks are."
  • "The product is adept at log mining."
  • "If it could be made available as a service, this would be much better than as a product."

What is our primary use case?

  • Log mining
  • Log analysis

How has it helped my organization?

It has helped us look at modern technology, as well as penetrate our legacy systems, to see where the bottlenecks are.

What is most valuable?

  • The product is adept at log mining.
  • It has the flexibility to do multiple analyses.
  • It works across heterogeneous environments in different ways. 

What needs improvement?

I have not tested the hybrid model yet. I don't know whether all its integrations and interfaces will work between the cloud and on-premise model. I also don't know if across multiple clouds all the products will perform properly.

If it could be made available as a service, this would be much better than as a product.

For how long have I used the solution?

One to three years.

What do I think about the stability of the solution?

It is stable under production environments.

What do I think about the scalability of the solution?

The scalability is decent. We have implemented it in our production environment, and it scales.

What was our ROI?

We have seen ROI and improvements as we have continued to use the product, but they are more reactive. We want to be proactive on an enterprise-wide scale.

Which other solutions did I evaluate?

We considered Oracle Enterprise Manager, but Splunk is way more powerful. Splunk is product-agnostic, as it can move across different platforms and products. 

What other advice do I have?

Explore Splunk. The product has a lot of depth.

It works with multiple products which are scheduling systems to ERPs to legacy, and it works perfectly fine.

I use the on-premise version. I have not had the opportunity to explore the AWS on Splunk version yet.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Yosef Tavin - PeerSpot reviewer
DevOps Engineer at BigPanda
Vendor
Top 10
A full monitoring and alerting solution for operations and application analysis
Pros and Cons
  • "It is a one stop shop as a full monitoring and alerting solution for operations and application analysis for most of our back-end systems."
  • "We used it to create a custom anomaly detection data model to monitor the activity of our back-end services on an hourly basis relative to the past three months of activity."
  • "It needs to improve the way to install third-party apps and enable installation without logging into splunk.com."

What is our primary use case?

We use Splunk for a few different use cases:

  1. We package it as part of one of our on-premise software offerings which includes our in-house customized dashboards.
  2. We use it for Application Monitoring of many of our back-end systems. Monitoring is done completely through Splunk by forwarding application and other logs to Splunk and many configured customized alerts and dashboards for the Ops, Dev, product, and management teams.
  3. We created a custom anomaly detection data model to monitor the activity of our back-end services on an hourly basis relative to the past three months of activity.

How has it helped my organization?

It has improved our organization in many ways:

  1. Having Splunk as part of one of our software products was our choice for giving our customers a great user experience.
  2. It is a one stop shop as a full monitoring and alerting solution for operations and application analysis for most of our back-end systems.

What is most valuable?

  • The easy automatic field parsing of logs. 
  • Data model acceleration
  • The ability to easily have access and install Splunk add-on plugins and custom apps. This greatly assists with using it to connect to various systems easily and use it as a centralized data sink.

What needs improvement?

It needs to improve the way to install third-party apps and enable installation without logging into splunk.com.

For how long have I used the solution?

One to three years.

What do I think about the stability of the solution?

Not at all.

What do I think about the scalability of the solution?

Not really.

How is customer service and technical support?

Their support is pretty good, but not amazing. Although we have our own in-house Splunk expert who worked for Splunk themselves for a few years, we do not really need external support that much. We basically use them for licensing stuff. 

The forums are pretty thorough, so technically we have not had much need for support.

How was the initial setup?

The initial setup is easy. Although, we currently use just a single server and not multi-server clustered instances. 

For our Linux instance setup, an upgrade is very easy. It is all managed by about three simple Bash scripts.

What's my experience with pricing, setup cost, and licensing?

It is possible to use a developer's license, which is up to 10GB per day of volume traffic, which is usually enough for most use cases.

Which other solutions did I evaluate?

We evaluated ELK Stack and QlikView.

What other advice do I have?

We are a Splunk Partner, since after much deliberation, we decided to choose Splunk as a component of one of our on-premise software offerings.

Disclosure: My company has a business relationship with this vendor other than being a customer: We are a Splunk Partner.
PeerSpot user
Buyer's Guide
Download our free Splunk Enterprise Security Report and get advice and tips from experienced pros sharing their opinions.
Updated: November 2024
Buyer's Guide
Download our free Splunk Enterprise Security Report and get advice and tips from experienced pros sharing their opinions.