We are a solution provider and Splunk is something that we provide as a service to our customers.
Senior Solutions Architect at a manufacturing company with 51-200 employees
Seamless integration with devices and operating systems, centralized management and control, and proactive support
Pros and Cons
- "The integration is seamless with many devices and operating systems."
- "Being a SIEM solution with a centralized dashboard, we would like to have more options to customize it."
What is our primary use case?
What is most valuable?
The most valuable feature is the reporting and the information that is provided by the tool.
It is very easy to implement a PoC using Splunk, which will show the value of the reporting and data that it provides.
The integration is seamless with many devices and operating systems.
It is flexible enough that you can choose what kind of deployment model you want.
They have a large solution toolkit that supports IoT, wherein businesses can get a lot of help with the centralized management functionality. There are also tools to assist from the security and SIEM perspective, and there is a centralized dashboard.
What needs improvement?
Being a SIEM solution with a centralized dashboard, we would like to have more options to customize it. It should be easy to customize dashboards.
When we are monitoring something, we would like to have a more granular outlook. Splunk has a good dashboard that is easier to use than some competing products, but better customizability would be a great help for the users.
For how long have I used the solution?
We have been working with Splunk for approximately three years.
Buyer's Guide
Splunk Enterprise Security
December 2024
Learn what your peers think about Splunk Enterprise Security. Get advice and tips from experienced pros sharing their opinions. Updated: December 2024.
831,020 professionals have used our research since 2012.
What do I think about the stability of the solution?
This product is very stable.
What do I think about the scalability of the solution?
Splunk is a very scalable solution. Being a Japanese product, they will ensure that all of the features work in any environment. It is very heterogeneous. It can integrate with Windows, Linux, AIX, HP-UX, and Solaris. It also supports IoT devices, mobile phones, and more.
We have more than 150,000 people using our services.
How are customer service and support?
The Splunk team has good, proactive support. Also in terms of assisting with the installation, they are quite good.
Which solution did I use previously and why did I switch?
Splunk is similar to IBM QRadar, which we also have experience with. However, Splunk has advanced SIEM features included with it, so we often use it to satisfy this requirement. Whenever an organization is looking to implement SIEM, they have the flexibility to choose Splunk, QRadar, or the ArcSight Logger solution.
One of the major differences that I see between Splunk and QRadar is that Splunk gives the users fewer devices, so they can do things quicker.
How was the initial setup?
The installation for Splunk is easier than competing products QRadar and ArcSight.
We have Splunk deployed on the cloud so that we can provide the service, but some of our customers have it installed on-premises.
All the user has to do is download the Splunk server agent, install it on the laptop or endpoint, integrate 50 or 100 devices, then see what kind of reporting is available.
What about the implementation team?
We have an in-house team for deployment in maintenance. Splunk is a tool that does not require much staff to maintain. The users can start with a PoC, simply learn it, and deploy it for themselves. They don't require subject experts to be hired for the installation and configuration.
What's my experience with pricing, setup cost, and licensing?
Price-wise, if you compare QRadar to Splunk for SIEM functionality then they are in the same range but when you integrate SOAR with these solutions, Splunk takes the lead and is more competitive.
What other advice do I have?
This is a product that I recommend for anybody who wants and advanced SIEM solutions. Of the three that I have used including QRadar and ArcSight, Splunk is the one that I prefer.
I would rate this solution a nine out of ten.
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
Senior Consultant at sectecs
Powerful programming language and search capability, but it is expensive and the vendor is inflexible
Pros and Cons
- "What I really like is that even if you have already collected the data, you can extract fields and can build searches."
- "I would like to see more SIEM functionality and a better ticket tool."
What is our primary use case?
My reason for implementing it was just to learn more about the product. I wanted to learn about the Splunk programming language, how to pipe searches, add logs, verify the logs, create fields, extract data into fields, build dashboards, and to get hands-on experience with the product.
What is most valuable?
The Splunk programming language allows you to pipe searches into another searches.
What I really like is that even if you have already collected the data, you can extract data and add fields which improves building searches. This is not the case with Elasticsearch, where this needs to be done upfront.
What needs improvement?
I really dislike how Splunk sales and partner manager behaves. I have faced several sales model and partnership changes. Also, the last time I wanted to by a license ro built a SIEM solution, they had removed the ability to purchase a splunk subscription or license from their website. In the past, there was a web page calculator it was possible to by online, but now it instructs to contact sales.
The free version is limited to 500 megabytes and there is no alerting. Due to the missing feature on the Splunk webpage, I have ask Splunk Sales to purchase a license like 1Gyte a day or a license for max 2500 Euro/year to use it as a test or development instance for myself. Asking Splunk for a quote willing to pay for Splunk license to learn and to get used to the product, Splunk didn't get it managed to offer my a license neither arranging the partnership paperwork I have ask for. Sales people from Splunk where calling, each time after I left my details on ther trial download page. I explained my experience and concerns about Splunk in the past. All excuses received and promises that someone will contact me to solve the issues faced in the past, was leading in excactly nothing. Well Done Splunk.
Inflexible and expensive and I do not have much faith in the people working there because if someone is asking for a test environment and is willing to spend up to €2,500 a year, I can't understand why they are unable to provide a license. This could be a lost opportunity because they are not able to onboard a potential new partner.
They definitely need to boost their sales and partner program because it changes to often, where they are dropping partners and it is difficult to get in contact with somebody. This is something that needs to be improved.
I would like to see more SIEM functionality and embedded moduled such a ticket tool to make a end to end SIEM.
For how long have I used the solution?
I have been using Splunk for a few weeks.
What do I think about the scalability of the solution?
As I was using a test environment, I can't comment on scalability. It was just myself and a colleague who was using it as a test instance.
How are customer service and technical support?
I have not been in contact with technical support.
Which solution did I use previously and why did I switch?
I have worked a little bit with Elasticsearch. I also have an instance of SIEMonster running, and I'm trying to get used to it. I found that Splunk provided a good benefit compared to Elasticsearch.
With Elasticsearch, if you have already inserted the data then it's gone because you need to do the pre-filtering. Once you've inserted or ingested the raw data, using Logstash, for example, you are no longer able to build the fields such as IP address, hostname, username, and the other fields that you want to export. This unsorted, raw data that you have is really a drawback for Elasticsearch and some other products. This is something from Splunk that I consider to be a heavy feature, where you can just insert data and ingest it later on.
How was the initial setup?
really fast and easy to install a test instance.
What's my experience with pricing, setup cost, and licensing?
The pricing model is expensive and could lead into a budget nightmare based on the amount of data.
A better pricing plan would be an improvement.
Which other solutions did I evaluate?
I have done some research on LogRhythm, IBM QRadar, and ArcSight, but I don't have any hands-on experience yet.
I did a comparison for a customer two weeks ago and the outcome of my comparison was SIEMonster, effortable price model, even though it's a niche player, it's quite powerful. I also provided Splunk as a recommendation because it is a market leader, really powerful, and really good to use. I also recommended LogRhythm; it is also expensive but it's also really powerful, and the feedback of customers is really good.
With respect to Splunk, I would recommend it but when a customer is budget-driven then Splunk is not the solution. Money shouldn't be the question.
What other advice do I have?
This is a solution that I could recommend for somebody who wants a really powerful product. It is not an end to end orchestrated SIEM yet.
This is a product that I would generally recommend, although I would not do so if the customer is really budget-driven.
I would rate this solution a six out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Buyer's Guide
Splunk Enterprise Security
December 2024
Learn what your peers think about Splunk Enterprise Security. Get advice and tips from experienced pros sharing their opinions. Updated: December 2024.
831,020 professionals have used our research since 2012.
Sr. IT Manager at a pharma/biotech company with 10,001+ employees
Log aggregation helps us quickly detect widespread threats, but it can be resource-heavy
Pros and Cons
- "The most valuable feature is the log aggregation, being able to scan through all of the logs."
- "Queries are not always as easy or straightforward as they might be, so it can be difficult to figure out what you need to look for."
What is our primary use case?
We use Splunk for log analysis and security monitoring.
How has it helped my organization?
Splunk allows us to look at logs from different groups within NIH and see if there's a widespread threat or issue.
What is most valuable?
The most valuable feature is the log aggregation, being able to scan through all of the logs.
What needs improvement?
Queries are not always as easy or straightforward as they might be, so it can be difficult to figure out what you need to look for.
In the next release of this product, I would like to see it offer more recommendations as to what needs to be done.
For how long have I used the solution?
We have been using Splunk for between two and three years.
What do I think about the stability of the solution?
In terms of stability, the product seems to work just fine. We haven't had any problems with it.
What do I think about the scalability of the solution?
It can be somewhat of a resource hog; some of the scans can take a while. We do plan to increase our usage in the future.
How are customer service and technical support?
Technical support for Splunk is good.
How was the initial setup?
The initial setup is relatively straightforward.
What about the implementation team?
There were consultants involved in the deployment.
What other advice do I have?
I would rate this solution a seven out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Director at a tech services company with 10,001+ employees
It has the flexibility to do multiple analyses
Pros and Cons
- "It has helped us look at modern technology, as well as penetrate our legacy systems, to see where the bottlenecks are."
- "The product is adept at log mining."
- "If it could be made available as a service, this would be much better than as a product."
What is our primary use case?
- Log mining
- Log analysis
How has it helped my organization?
It has helped us look at modern technology, as well as penetrate our legacy systems, to see where the bottlenecks are.
What is most valuable?
- The product is adept at log mining.
- It has the flexibility to do multiple analyses.
- It works across heterogeneous environments in different ways.
What needs improvement?
I have not tested the hybrid model yet. I don't know whether all its integrations and interfaces will work between the cloud and on-premise model. I also don't know if across multiple clouds all the products will perform properly.
If it could be made available as a service, this would be much better than as a product.
For how long have I used the solution?
One to three years.
What do I think about the stability of the solution?
It is stable under production environments.
What do I think about the scalability of the solution?
The scalability is decent. We have implemented it in our production environment, and it scales.
What was our ROI?
We have seen ROI and improvements as we have continued to use the product, but they are more reactive. We want to be proactive on an enterprise-wide scale.
Which other solutions did I evaluate?
We considered Oracle Enterprise Manager, but Splunk is way more powerful. Splunk is product-agnostic, as it can move across different platforms and products.
What other advice do I have?
Explore Splunk. The product has a lot of depth.
It works with multiple products which are scheduling systems to ERPs to legacy, and it works perfectly fine.
I use the on-premise version. I have not had the opportunity to explore the AWS on Splunk version yet.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Director of IT at BLUE LAKE RANCHERIA
Aggregation searches have reduced time and difficulty of identifying trends and conditions which need to reviewed
Pros and Cons
- "Splunk has significantly reduced the time in performing the task of aggregating logs, reviewing as well as time spent during investigations."
- "Aggregation searches have reduced time and difficulty of identifying trends and conditions which need to reviewed."
- "The case management area of the ES could be improved. The ability to move cases through various stages and states. The ability to close a case would be key improvement."
What is our primary use case?
We primary use Splunk for log aggregation and search across multiple systems with Splunk Enterprise Security layered on top.
How has it helped my organization?
Splunk has significantly reduced the time in performing the task of aggregating logs, reviewing as well as time spent during investigations. This has not only
increased our speed of response, but our efficiency dealing with the issue(s)
raised.
What is most valuable?
Aggregation searches, allowing for conditions to be automatically found in the data, have reduced time and difficulty of identifying trends and conditions which need to reviewed.
What needs improvement?
The case management area of the ES could be improved. The ability to move cases through various stages and states. The ability to close a case would be key improvement.
For how long have I used the solution?
One to three years.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Junior SAP Security Engineer at Sagesse Tech
Helps reduce our alert volume, speed up security investigations, and normalize data
Pros and Cons
- "The graph visualization is the most valuable feature."
- "The UI can be difficult to understand for non-technical people."
What is our primary use case?
We use Splunk Enterprise Security for our enterprise security.
How has it helped my organization?
Adding more use cases to Splunk can improve our threat detection speed.
It has helped normalize our data.
Splunk Enterprise Security has helped reduce our alert volume and speed up our security investigations.
What is most valuable?
The graph visualization is the most valuable feature.
What needs improvement?
Splunk Enterprise Security needs to improve its stability.
The UI can be difficult to understand for non-technical people.
For how long have I used the solution?
I have been using Splunk Enterprise Security for four months.
What do I think about the stability of the solution?
I would rate the stability of Splunk Enterprise Security a four out of ten. Some bugs cause downtime.
What do I think about the scalability of the solution?
I would rate the scalability a six out of ten.
What other advice do I have?
I would rate Splunk Enterprise Security an eight out of ten.
Splunk Enterprise Security's robust framework enables it to support a wider range of use cases, making it more adaptable and versatile for tackling diverse security challenges.
We have Splunk Enterprise Security deployed across multiple locations.
Splunk Enterprise Security's visualizations are detailed and help users normalize data, making it extremely useful.
The vast array of use cases enabled by Splunk Enterprise Security empowers security teams to address diverse threats and enhance overall security posture.
Which deployment model are you using for this solution?
Private Cloud
Disclosure: I am a real user, and this review is based on my own experience and opinions.
IT System Developer/Admin at a manufacturing company with 10,001+ employees
A stable, scalable solution with comprehensive dashboards and helpful technical support
Pros and Cons
- "The scalability of the solution is amazing because it can collect a lot of data and you can have your own structure to monitor this data."
- "An area of improvement would be the licensing of the solution. They need a free license, which would allow faster lead times."
What is our primary use case?
The primary use case of this solution is to monitor Cyber Mission databases.
I create the diagrams to create an architecture that is then implemented. However, creating these diagrams are for my own learnings since these implementations are usually already available in the cloud office logs.
What is most valuable?
The features I have found most valuable are the dashboards.
I monitor the complete capacity that users are using in the company.
What needs improvement?
An area of improvement would be the licensing of the solution. They need a free license, which would allow faster lead times.
They also need to update their documentation.
What do I think about the stability of the solution?
The solution is stable.
What do I think about the scalability of the solution?
The scalability of the solution is amazing because it can collect a lot of data and you can have your own structure to monitor this data.
How are customer service and technical support?
The customer service/technical support was helpful and they answered my questions as best they could.
How was the initial setup?
The setup was easy, but you have to have a VPN connection depending on the security protocols in place.
What about the implementation team?
The deployment was in-house and took about two days with the correct licenses and permissions.
What other advice do I have?
It is important to define different guidelines to integrate Splunk in development, QA, and production deployments. Additionally, define the applications that will be used and the configuration of the databases to collect the data. If this is not done, there will be a lot of issues due to, for example, master access or permissions to use the database collector and blocks.
Which deployment model are you using for this solution?
Hybrid Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Amazon Web Services (AWS)
Disclosure: I am a real user, and this review is based on my own experience and opinions.
System Administrator and DevOps Engineer at a tech services company with 10,001+ employees
Very straightforward, easy to configure, stable and scalable.
Pros and Cons
- "This is a straightforward solution, easy to configure."
- "This is a costly solution."
What is our primary use case?
Our primary use case of Splunk is for log monitoring and infrastructure monitoring. If we want to diagnose any issue in our application, we just push our application logs. This is on any client server using the universal forwarder logs on the Splunk server. After indexing, we can create a base log, and create attractive dashboards that are simple to understand and use. I'm a system administrator and we are customers of Splunk.
What is most valuable?
This is a straightforward solution, easy to configure and difficult to mess up.
What needs improvement?
Splunk is a very costly solution and I think it's the most expensive in the market in terms of costing. Splunk provides an application for infrastructure monitoring. If we're monitoring the docker with containers, we can't see the container name, only the ID. That's a big drawback.
For how long have I used the solution?
I've been using this solution for two years.
What do I think about the stability of the solution?
This is a stable solution. Deployment takes one person, it can be a system admin or an engineer.
What do I think about the scalability of the solution?
This is a scalable solution. We can do the clustering of it for large applications. We have around 15 users for this product.
How are customer service and technical support?
If I have any issues, I'll go to the community. I can generally get a response within a day. Although most of the documentation is good, some of it is unclear, particularly if you're new to the product.
How was the initial setup?
I think it takes around 10 minutes to install it on the server. On the client side, it takes around five minutes. I do the installation myself.
What other advice do I have?
If you're going with this solution, make sure that when implementing the ports are open. If they're not open, it creates problems with the server. Other than that, this is a very stable and very easy to configure product. We can easily deploy and easily use. Other similar solutions are difficult to configure, Splunk is the simplest. I've used three or four monitoring tools and Splunk is the easiest. If a company can afford it, this is a good product. We are planning to shift to another product because of the cost. We're searching for an open source or cheaper product.
I would rate this solution a nine out of 10. They lose one point for the price and lack of infrastructure support.
Which deployment model are you using for this solution?
On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Buyer's Guide
Download our free Splunk Enterprise Security Report and get advice and tips from experienced pros
sharing their opinions.
Updated: December 2024
Product Categories
Security Information and Event Management (SIEM) Log Management IT Operations AnalyticsPopular Comparisons
CrowdStrike Falcon
Microsoft Sentinel
IBM Security QRadar
Elastic Security
LogRhythm SIEM
Sumo Logic Security
Rapid7 InsightIDR
Fortinet FortiSIEM
AlienVault OSSIM
Cortex XSIAM
Securonix Next-Gen SIEM
USM Anywhere
ManageEngine Log360
Buyer's Guide
Download our free Splunk Enterprise Security Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- Which would you recommend to your boss, IBM QRadar or Splunk?
- What are some of the best features and use-cases of Splunk?
- What SOC product do you recommend?
- Splunk as an Enterprise Class monitoring solution -- thoughts?
- What is the biggest difference between Dynatrace and Splunk?
- IBM QRadar is rated above competitors (McAfee, Splunk, LogRhythm) in Gartner's 2020 Magic Quandrant. Agree/Disagree?
- What are the advantages of ELK over Splunk?
- How does Splunk compare with Azure Monitor?
- New risk scoring framework in the Splunk App for Enterprise Security -- thoughts?
- Splunk vs. Elastic Stack