We are using Splunk to look at the logs, and see what is happening.
Sr. IT Manager at a pharma/biotech company with 10,001+ employees
Good log aggregation and scales well, with good technical support that is responsive and helpful
Pros and Cons
- "The most valuable feature is that it's very good for log aggregation."
- "The implementation and the scanning of the logs can be difficult."
What is our primary use case?
What is most valuable?
The most valuable feature is that it's very good for log aggregation.
What needs improvement?
Splunk is very complex. The implementation and the scanning of the logs can be difficult.
For how long have I used the solution?
I have been using Splunk for approximately three years.
Buyer's Guide
Splunk Enterprise Security
December 2024
Learn what your peers think about Splunk Enterprise Security. Get advice and tips from experienced pros sharing their opinions. Updated: December 2024.
831,020 professionals have used our research since 2012.
What do I think about the stability of the solution?
In general, Splunk is stable.
What do I think about the scalability of the solution?
It's a scalable product. it's pretty good.
How are customer service and support?
Technical support is usually pretty good.
They are responsive, knowledgeable, and helpful.
How was the initial setup?
The initial setup was relatively straightforward.
What's my experience with pricing, setup cost, and licensing?
The price is comparable.
What other advice do I have?
I would rate Splunk and eight out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
VMware Engineer at First Data Corporation
In-depth logs but downloading and uploading logs have become an issue
How has it helped my organization?
100%. VMware needs log information to troubleshoot; it's not easy finding problems.
Downloading and uploading logs have become an issue.
What is most valuable?
- In-depth logs
- Add-ons
- The ability to ingest data from other tools
- The detailed log view
- It's easy to read
What needs improvement?
- The amount of time it takes to troubleshoot not-easily-available data
- Also, hours on the phone with VMware techs.
For how long have I used the solution?
Less than one year.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Buyer's Guide
Splunk Enterprise Security
December 2024
Learn what your peers think about Splunk Enterprise Security. Get advice and tips from experienced pros sharing their opinions. Updated: December 2024.
831,020 professionals have used our research since 2012.
Application Engineer at Expedia
The most valuable feature is its centralized log analytics
Pros and Cons
- "We have a one stop dashboard for health of some of our services where you can click in and it takes you to other dashboards that have custom near real-time metrics that show the application's health."
- "The historical data extraction needs improvement. I would like the capability of taking data and having it trend longer."
What is our primary use case?
The primary use case is for log analytics. Although, we have been using it as a hammer which hits all the nails. We have sort of overused it in some areas where it doesn't need to be used.
How has it helped my organization?
We have a one stop dashboard for health of some of our services where you can click in and it takes you to other dashboards that have custom near real-time metrics that show the application's health. From there, you can drill in to see the real deep dive example of what is happening in your environment. It has reduced our time to resolve incidents.
What is most valuable?
The most valuable feature is its centralized log analytics.
What needs improvement?
The historical data extraction needs improvement. I would like the capability of taking data and having it trend longer. Splunk is good about viewing data within the last seven or 14 days, but if you want to see a year-over-year trend, you have to do a lot of work to get to that point. If there was a better way to extract the data point and put it into a long-term viewing ability for a year-over-year analysis, then compare that to your other business metrics. That is what I am looking for, as an example, for a call center you want to see the time it takes for your customer to be handled on their need comparatively to the system performance that is happening, then overlay that data.
For how long have I used the solution?
Three to five years.
What do I think about the stability of the solution?
We put a lot of trust in it. It has been pretty rock-solid outside of a couple of changes that we made. Upgrades sometimes don't always go smoothly, but otherwise the system performs, and operates.
What do I think about the scalability of the solution?
When we were trying to implement an enterprise solution on-premise, we had scaling issues. It was very difficult to search the data retention beyond a few days. A lot of talent was given to the ability to go into AWS and scale with our need. We still had to do some administrative things to prevent consumers from trying to search all records for all time in very inefficient searches. This could sometimes bring our core system functionality to a halt, so we had to do some user administration in it.
How is customer service and technical support?
I don't engage with the support directly. Another member of my team does. Any time that we have needed support, he hasn't had an issue opening a ticket and receiving the help that he needs.
How was the initial setup?
The integration and configuration in the AWS environment was pretty good. They have a consumption method for pretty much every service. They might be able to do a little better at advertising different patterns for best practices for different service, but overall there's a method to get everything.
What was our ROI?
We have had a reduction in the time it takes to resolve issues and correlate what has failed. This has significantly helped.
Which other solutions did I evaluate?
We looked at the Elk Stack, Kibana, and Sumo Logic.
We chose Splunk because their cost is better, the maintenance factor is a little higher, and the core functionality is higher than what other products provide. The core functionality is out-of-the-box. E.g., with a Toyota Scion, you can customize the parts to make it whatever you want, but it's a lot of work to get there. Where if you buy a Cadillac, you pay the Cadillac's price, but it's a Cadillac. It will work right out-of-the-box.
What other advice do I have?
It works well when searching logs. If you looked to try to do things beyond this, the problem that we ran into is that we treated it as the hammer which hits all nails. That is not really feasible, and there are other tools out there that can do more specialized things.
User administration is key. Trying to prevent users from being able search records all the time is a huge problem. You need a tight approval process on dashboards, making sure the dashboards are queried in the most efficient way possible.
The on-premise version that we had was not scalable at all. It was very difficult to use. We have EC2 instances in the cloud with Splunk installed, which is more scalable and easier to use. It now works much better.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Security Architect at a energy/utilities company with 1,001-5,000 employees
Some of the valuable features Machine learning, Common Information Model, and Log storage.
Pros and Cons
- "Ease of correlation, creating correlation searches are easy and you can combine multiple sources with little effort"
- "The GUI can be improved to include some of the capabilities that other BI solutions have."
How has it helped my organization?
- We can do things in minutes instead of days.
- We solve issues which we could not before since we have the data.
- We can quickly search for almost anything across many log sources in seconds
- Teams have the dashboards or alerts that they need
What is most valuable?
There are too many features to list, but here are a few:
- Schema on the fly
- Ease of on-boarding data
- Machine learning
- Apps or Splunk base.
- Great list of apps to use and also build upon once you learn more about how Splunk works.
- We build many of our own apps by leveraging the logic in the others.
- Ease of correlation, creating correlation searches are easy and you can combine multiple sources with little effort
- Data Models Acceleration for super fast searches across tens of millions of events
- Common Information Model
- Security Essentials App
- Enterprise Security
- Splunk SPL (Search Processing Language) is easy to learn and has IDE like capabilities
- Log storage or compression is great and retention is not an issue
- Dashboards are simple to create and the input options like Time Range, Text
- Drop-downs are simple to create.
- Integration with cloud solutions is great and keeps getting better.
- Can get info from rest API’s easily and there are apps for services like ServiceNow, Azure, Office365, etc.
What needs improvement?
The GUI can be improved to include some of the capabilities that other BI solutions have. Basically, the layout is a little restrictive where you can’t resize all the panels to exactly how you would like them without tweaking some XML code. Over the years, they have really been improving in this area. I would think that will continue and this could become a non-issue.
What do I think about the stability of the solution?
There were no issues with stability.
What do I think about the scalability of the solution?
There were no issues with scalability.
How are customer service and technical support?
Technical support is excellent. They also have Splunk Answers, which is community driven and it great.
Which solution did I use previously and why did I switch?
We were not able to get the value we needed from the previous solution. It was too difficult or complex. With Splunk, we can do things we want and things we have not even dreamed of yet.
How was the initial setup?
The initial setup was straightforward. We had the POC up in minutes. Within days, we got more value out of this solution than our existing solution.
What's my experience with pricing, setup cost, and licensing?
While licensing can be a concern, there are ways to reduce the licensing costs including filtering some events. We have replaced many solutions with Splunk, which have more than paid for the Splunk licensing.
Which other solutions did I evaluate?
We evaluated ArcSight, QRadar, and LogRhythm.
What other advice do I have?
Do a PoC and you will be amazed. Also, check out the Splunk .conf sessions to see what is possible. If you are into security, watch Mark Russinovich’s RSA 2017 presentation about Sysmon. Check out free EDR type capabilities.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Security Architect at a computer software company with 51-200 employees
Cloud-ready, with forums and README tutorials that cover everything you need to know
Pros and Cons
- "Splunk would be my choice for the presentation layer because it comes with inbuilt reports and a dashboard that you can customize."
- "I haven't found a way for me to create my own plugins and integrate them into Splunk, but this isn't necessarily a limitation; it could simply be a lack of knowledge on my part."
What is our primary use case?
Splunk just acts as an extra presentation layer, and we tried it because of the plugins they have to try and get more logs into the environment.
What is most valuable?
Splunk would be my choice for the presentation layer because it comes with inbuilt reports and a dashboard that you can customize.
What needs improvement?
Aside from the 5GB limit on the community version, I believe it is the same as ELK. It's a useful tool, and nothing comes to mind right now.
I haven't found a way for me to create my own plugins and integrate them into Splunk, but this isn't necessarily a limitation; it could simply be a lack of knowledge on my part.
What do I think about the stability of the solution?
Splunk is a stable solution. I am very happy with the stability of Splunk.
What do I think about the scalability of the solution?
Splunk can be scaled to any environment. The way it's designed, it's cloud-ready, and it has a lot of performance, in-built indexing, and performance tuning options. Splunk is easily scalable.
How are customer service and support?
I am happy to report that I've never needed to contact technical support. The README tutorials and the existing forums provide me with practically everything I need. So far, I haven't had to do so. This should be a testament to the solution.
Which solution did I use previously and why did I switch?
We broaden the scope of IT governance and IT security.
We look at everything from SIEM to network management to endpoint protection, server protection, database protection, and anything else that can aid in visibility, policy enforcement, and monitoring.
Our organization is using a combination of Splunk and Elasticsearch. We get most of what we need from the ELK suite. ELK Stack is usually the primary focus.
ELK has the same inbuilt reports and dashboards that you can customize, but ELK is better for central logging and log aggregation. Once they've all been aggregated, you'll be able to run any kind of queries and APIs to query the logs on ELK and then use Splunk as a presentation layer for the consumers to use.
Security tools, in my opinion, are business tools and should be used by businesses rather than security engineers. I'm experimenting with a hybrid of the two, in which ELK serves as the engine for central logging and Splunk handles the presentation layer and aggregation of additional third-party logs from tools that might be difficult to integrate into ELK.
I would rate Elasticsearch a ten out of ten.
How was the initial setup?
It's a cloud-ready package. It has the same characteristics as ELK. From a deployment standpoint, I don't have any issues with it. The material is freely accessible to anyone who wishes to use it. There is a virtual machine option. You can get a virtual machine by downloading it. The deployment options are simply numerous, and it is up to the implementer.
It wasn't that difficult for me. There are no complaints from me. The material is present, and there are numerous options for deployment. It's relatively simple to go from zero to viewing data with Splunk. ELK is the same way. It is now up to the implementers and their environment to provide you with more data about it.
What's my experience with pricing, setup cost, and licensing?
They could improve their discounts. I think it's a good solution, and it's gaining a lot of traction, maybe they are recouping their R&D costs, Further reductions would be fantastic, and I believe that more and more people would flock to it.
Which other solutions did I evaluate?
We provide IT consulting services. Our customers occasionally ask us to assist them in locating specific solutions.
What other advice do I have?
I would recommend this solution to others who are interested in using this solution.
I would say the forums and READMEs provide more than enough information about Splunk. Most people struggle because they move too quickly through the implementation process. As long as you follow the guidelines, particularly the specifications for environment requirements and implementation methodology, these solutions should work out of the box.
Splunk is a very good solution, I would rate it a ten out of ten.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Cyber Security Consultant at a tech services company with 10,001+ employees
Responsive, and available, technical support, that is easy to install
Pros and Cons
- "It's better than IBM, in my opinion, because it's an independent entity."
- ". Having a trial version or more training on Splunk would be helpful."
What is our primary use case?
I use Splunk for testing purposes. It is used for school research and to learn how to use Splunk.
Splunk is mainly used for collecting logs and dashboards.
What is most valuable?
Splunk provides a free version so you can test it before purchasing. It's better than IBM, in my opinion, because it's an independent entity. IBM, for example, if you want to use EDR, and other features, you must use the features of other companies, such as ServiceNow and Jira.
I am still exploring the features provided in Splunk. As I have not used it for a long time, I don't have a clear vision of it.
What needs improvement?
As a student, I'd like to see more labs and things for students to test in order to learn.
Having a trial version or more training on Splunk would be helpful.
There is a free version, but it is insufficient for training and learning because it is a little bit difficult to work with, especially if you are a beginner. It's difficult to improve when you're just starting out with logs and SOC. As a result, we require a longer free version.
For how long have I used the solution?
Splunk is not used in my company. During my internship, I am being taught how to use it at school.
I have been using Splunk for one month.
What do I think about the stability of the solution?
I did not have any issues with the stability of Splunk. It was quite stable.
How are customer service and support?
There was technical assistance available. When you require assistance, they provide it, they will respond.
Which solution did I use previously and why did I switch?
We integrate Jira with QRadar which is helpful.
How was the initial setup?
The initial setup was simple because there is available support and tutorials.
What about the implementation team?
I completed the installation with the help of some friends, in the IT department.
What's my experience with pricing, setup cost, and licensing?
I'm only using the free version for the time being.
The cost is reasonable.
Splunk's costing is a little more difficult. The pricing method is complicated, and the way that costing is calculated in Splunk is a little more difficult.
When compared to QRadar, QRadar, it's simple to pay.
Which other solutions did I evaluate?
I did some research for a school project. I needed to compare it to Splunk and a few other tools. As a result, I'm not particularly interested in purchasing them.
What other advice do I have?
I would rate Splunk an eight out of ten.
Which deployment model are you using for this solution?
Private Cloud
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Senior Manager, Analytics & Insights at a consultancy with 10,001+ employees
Effective machine learning, reliable, and responsive support
Pros and Cons
- "Splunk has machine learning which is a valuable feature."
- "The algorithms customization of Splunk could improve. They have limited algorithms for machine learning support. If they can allow the user to add more machine learning algorithms, such as the ability to choose the algorithm that a user might want. Additionally, they should provide the required libraries for those algorithms, and then analyzes the data for use."
What is our primary use case?
We are using Splunk for querying data from different sources.
What is most valuable?
Splunk has machine learning which is a valuable feature.
What needs improvement?
The algorithms customization of Splunk could improve. They have limited algorithms for machine learning support. If they can allow the user to add more machine learning algorithms, such as the ability to choose the algorithm that a user might want. Additionally, they should provide the required libraries for those algorithms, and then analyzes the data for use.
For how long have I used the solution?
I have used Splunk within the past 12 months.
What do I think about the stability of the solution?
Splunk is a stable solution.
How are customer service and support?
We have contacted the support and most of the reasons we have contact support has been project-related. For example, we want the APAs to work in a certain way or for certain fixes.
What other advice do I have?
I have been using Splunk for approximately
Which deployment model are you using for this solution?
On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Senior Information Technology System Analyst at YASH Technologies
Impressive UI, many useful features, and very scalable, but needs alerting feature and better pricing and integration
Pros and Cons
- "There are quite a lot of things that we find useful. Splunk agents are useful and good. Its UI is quite impressive."
- "Its pricing model and integration with third-party services can be improved. We had faced an issue with integration. The alerting feature is currently not available with Splunk, but it is definitely available with Datadog and PagerDuty. They should include this feature. A few dashboards in Splunk look quite old and are not that modern. They aren't bad, but improving these dashboards will definitely make Splunk more attractive and usable. I read in a few blog posts that there were a few security incidents related to Splunk agents. So, it can be made more secure."
What is most valuable?
There are quite a lot of things that we find useful. Splunk agents are useful and good. Its UI is quite impressive.
What needs improvement?
Its pricing model and integration with third-party services can be improved. We had faced an issue with integration.
The alerting feature is currently not available with Splunk, but it is definitely available with Datadog and PagerDuty. They should include this feature.
A few dashboards in Splunk look quite old and are not that modern. They aren't bad, but improving these dashboards will definitely make Splunk more attractive and usable.
I read in a few blog posts that there were a few security incidents related to Splunk agents. So, it can be made more secure.
For how long have I used the solution?
I have been using this solution for almost two years. I am using its latest version.
What do I think about the stability of the solution?
It is a stable product.
What do I think about the scalability of the solution?
Splunk is definitely scalable.
How are customer service and technical support?
I have not interacted with them. Another team is taking care of raising tickets with their technical support.
How was the initial setup?
It is quite simple.
What's my experience with pricing, setup cost, and licensing?
Its pricing model can be improved.
What other advice do I have?
A few years ago, I would have definitely recommended Splunk, but nowadays, better alternatives are available. We are currently exploring a few other alternatives, so I won't recommend Splunk as of now.
I would rate Splunk a seven out of ten.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Buyer's Guide
Download our free Splunk Enterprise Security Report and get advice and tips from experienced pros
sharing their opinions.
Updated: December 2024
Product Categories
Security Information and Event Management (SIEM) Log Management IT Operations AnalyticsPopular Comparisons
CrowdStrike Falcon
Microsoft Sentinel
IBM Security QRadar
Elastic Security
LogRhythm SIEM
Sumo Logic Security
Rapid7 InsightIDR
Fortinet FortiSIEM
AlienVault OSSIM
Cortex XSIAM
Securonix Next-Gen SIEM
USM Anywhere
ManageEngine Log360
Buyer's Guide
Download our free Splunk Enterprise Security Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- Which would you recommend to your boss, IBM QRadar or Splunk?
- What are some of the best features and use-cases of Splunk?
- What SOC product do you recommend?
- Splunk as an Enterprise Class monitoring solution -- thoughts?
- What is the biggest difference between Dynatrace and Splunk?
- IBM QRadar is rated above competitors (McAfee, Splunk, LogRhythm) in Gartner's 2020 Magic Quandrant. Agree/Disagree?
- What are the advantages of ELK over Splunk?
- How does Splunk compare with Azure Monitor?
- New risk scoring framework in the Splunk App for Enterprise Security -- thoughts?
- Splunk vs. Elastic Stack
agree with you Mr. Kent this machine have more valuable feature.