Try our new research platform with insights from 80,000+ expert users
Software Engineer at Tableau Software
Real User
It has reduced the time to resolution and time to investigate, but the search query is slow
Pros and Cons
  • "It has reduced the time to resolution, time to investigate, and time to troubleshoot for debugging issues."
  • "Out-of-the-box, it seems very powerful."
  • "My company could benefit from doing more Splunk training with Splunk consultants teaching us how to use it."

What is our primary use case?

We use it for searching logs in a production environment.

How has it helped my organization?

It has reduced the time to resolution, time to investigate, and time to troubleshoot for debugging issues. 

What is most valuable?

Being able to search across all the different production environments at the same time, then being able to do search queries to scope out specific environments, specific components, or specific logs from different languages, such as Java or C++. Thus, being able to have really fine grain control on log searching is really good.

Out-of-the-box, it seems very powerful.

What needs improvement?

The search query seems slow, but I am not sure if that is just because it is searching millions upon millions of lines of text. Also, I just started using it, so I might have no idea what I am doing. I could probably speed up the queries by improving my search skills.

My company could benefit from doing more Splunk training with Splunk consultants teaching us how to use it. It is possible that we have already done this and I haven't participate, but this type of training would be helpful.

Buyer's Guide
Splunk Enterprise Security
December 2024
Learn what your peers think about Splunk Enterprise Security. Get advice and tips from experienced pros sharing their opinions. Updated: December 2024.
831,020 professionals have used our research since 2012.

For how long have I used the solution?

Less than one year.

What do I think about the stability of the solution?

It is always up when I need to search. I am probably not using it that much. I will maybe search a couple times a day for something specific, so I am not using it too much. I know plenty of the people who are doing a lot more for debugging, and who use it a lot all day.

What do I think about the scalability of the solution?

It seems like it scales well. We have hundreds of production and development environments, and we are searching on all of them. Therefore, it seems like the scale is good. 

We have hundreds of production environments, and each production environment has ten to 20 host machines. Each production environment can manage tens of thousands of customers.

Maybe going to AWS and scaling it better would be more cost-effective for our company. However, I am not involved in those decisions.

How are customer service and support?

I have not used technical support.

Which other solutions did I evaluate?

We have other log searching tools, but we have standardized on Splunk. 

What other advice do I have?

It is a great product. We have a lot of different tools to do this type of debugging. Yet, it is one of the first ones that I will reach for, and I think that is a good sign.

It works well and is the industry standard for log searching. It probably has other features too. Therefore, if you use it, I would recommend the training, so you know what you are doing. 

I am using the on-premise version.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Yosef Tavin - PeerSpot reviewer
DevOps Engineer at BigPanda
Vendor
Top 10
A full monitoring and alerting solution for operations and application analysis
Pros and Cons
  • "It is a one stop shop as a full monitoring and alerting solution for operations and application analysis for most of our back-end systems."
  • "We used it to create a custom anomaly detection data model to monitor the activity of our back-end services on an hourly basis relative to the past three months of activity."
  • "It needs to improve the way to install third-party apps and enable installation without logging into splunk.com."

What is our primary use case?

We use Splunk for a few different use cases:

  1. We package it as part of one of our on-premise software offerings which includes our in-house customized dashboards.
  2. We use it for Application Monitoring of many of our back-end systems. Monitoring is done completely through Splunk by forwarding application and other logs to Splunk and many configured customized alerts and dashboards for the Ops, Dev, product, and management teams.
  3. We created a custom anomaly detection data model to monitor the activity of our back-end services on an hourly basis relative to the past three months of activity.

How has it helped my organization?

It has improved our organization in many ways:

  1. Having Splunk as part of one of our software products was our choice for giving our customers a great user experience.
  2. It is a one stop shop as a full monitoring and alerting solution for operations and application analysis for most of our back-end systems.

What is most valuable?

  • The easy automatic field parsing of logs. 
  • Data model acceleration
  • The ability to easily have access and install Splunk add-on plugins and custom apps. This greatly assists with using it to connect to various systems easily and use it as a centralized data sink.

What needs improvement?

It needs to improve the way to install third-party apps and enable installation without logging into splunk.com.

For how long have I used the solution?

One to three years.

What do I think about the stability of the solution?

Not at all.

What do I think about the scalability of the solution?

Not really.

How is customer service and technical support?

Their support is pretty good, but not amazing. Although we have our own in-house Splunk expert who worked for Splunk themselves for a few years, we do not really need external support that much. We basically use them for licensing stuff. 

The forums are pretty thorough, so technically we have not had much need for support.

How was the initial setup?

The initial setup is easy. Although, we currently use just a single server and not multi-server clustered instances. 

For our Linux instance setup, an upgrade is very easy. It is all managed by about three simple Bash scripts.

What's my experience with pricing, setup cost, and licensing?

It is possible to use a developer's license, which is up to 10GB per day of volume traffic, which is usually enough for most use cases.

Which other solutions did I evaluate?

We evaluated ELK Stack and QlikView.

What other advice do I have?

We are a Splunk Partner, since after much deliberation, we decided to choose Splunk as a component of one of our on-premise software offerings.

Disclosure: My company has a business relationship with this vendor other than being a customer: We are a Splunk Partner.
PeerSpot user
Buyer's Guide
Splunk Enterprise Security
December 2024
Learn what your peers think about Splunk Enterprise Security. Get advice and tips from experienced pros sharing their opinions. Updated: December 2024.
831,020 professionals have used our research since 2012.
Mick - PeerSpot reviewer
Sr. Production Support Analyst at Electric Reliability Council of Texas
User
Quickly searches logs, performance data, and other inputs to assist with troubleshooting
Pros and Cons
  • "The ability to quickly search logs, performance data, and other inputs has helped tremendously with troubleshooting."

    What is our primary use case?

    Operational intelligence monitoring for several different systems. We collect logs from applications and performance data from hardware, as well as information pulled from databases.

    How has it helped my organization?

    The ability to quickly search logs, performance data, and other inputs has helped tremendously with troubleshooting. The visualizations are easy and well received by business and management users. 

    What is most valuable?

    It is ease to integrate with other solutions, like Slack, JIRA, Remedy, etc. 

    For how long have I used the solution?

    Three to five years.

    How is customer service and technical support?

    The user community is extremely beneficial, particularly with Splunk Answers and the Slack User Groups.

    What's my experience with pricing, setup cost, and licensing?

    The licensing model can be expensive, but the value it provides is significant.

    What other advice do I have?

    The recent acquisition of Phantom makes the future seem bright with more automated responses.

    Disclosure: I am a real user, and this review is based on my own experience and opinions.
    PeerSpot user
    PeerSpot user
    Senior Manager of Network with 1,001-5,000 employees
    Vendor
    Splunk is great for Syslog capabilites. For normal device management, you can't go wrong with SolarWinds.

    I'd go with Splunk for logging. For Syslog capabilities, Splunk wins outright from my experience. It's quick, very customizable, and there are many different modules some specific for vendors and devices. (Cisco Security Suite for one). 

    If you are really into SolarWinds and want to use them for Syslog then I would go with Kiwi. SolarWinds NPM has a syslog collector but under heavy load (a few hundred devices) it will get bogged down real quick in my experience.

    If you are looking for normal device management then NPM, NCM, NTA are the way to go. You can't go wrong with SolarWinds.

    Disclosure: I am a real user, and this review is based on my own experience and opinions.
    PeerSpot user
    it_user167895 - PeerSpot reviewer
    it_user167895Project Manager and consultant enterprise IT tooling at a consultancy with 51-200 employees
    Consultant

    Kiwi syslog for SolarWinds must be seen as a patch for SolarWinds Orion NPM. SolarWinds will release a LOG management module for the Orion NPM platform but this product is in an early state of log collecting, searching and filtering. Splunk can be a good tactical solution to filter out and forward important events to SolarWinds Orion NPM

    See all 2 comments
    Regional Head at a tech services company with 51-200 employees
    Real User
    Good technical support, scalable, and very stable
    Pros and Cons
    • "It's basically one of the best SIEM products on the market."
    • "You do need a lot of training and certification with this product."

    What is our primary use case?

    The solution is primarily a SIEM tool and it basically helps companies with security.

    What is most valuable?

    It's basically one of the best SIEM products on the market.

    The scalability is great.

    We have found the solution to be stable. 

    Technical support is helpful. They respond in a timely manner. 

    What needs improvement?

    I'd like to see more documentation on the product.

    The initial setup is not straightforward.

    You do need a lot of training and certification with this product. Other than that, it's pretty good.

    For how long have I used the solution?

    I've been dealing with the solution for about three years. It's been a while. 

    What do I think about the stability of the solution?

    The stability of the product is very good. The performance is reliable. There are no bugs or glitches. it doesn't crash or freeze. We've had no issues. 

    What do I think about the scalability of the solution?

    The scalability of the solution is great. If a company needs to expand it, it can do so. It's not a problem.

    We have about nine customers that are using Splunk.

    How are customer service and support?

    I've dealt with technical support and it's pretty good. They are helpful. I find them responsive. 

    How was the initial setup?

    The initial setup is not straightforward. It depends upon the IT infrastructure that the customer has. If they have a lot of security solutions, such as DLP and other security solutions, then it is more complicated. The more you have the more complicated it gets.

    The deployment of Splunk takes about three weeks.

    We have six or seven team members within our organization that can handle deployment and maintenance tasks. 

    What about the implementation team?

    I handled the implementation myself. It was done in-house. 

    What's my experience with pricing, setup cost, and licensing?

    Splunk requires a paid license. There's no free option. Customers have to pay for the license, implementation, support - everything.

    What other advice do I have?

    The solution can be deployed both on-premises and on the cloud. 

    I'd rate the solution at a nine out of ten. We've been very happy with the product.

    I would recommend the solution. It really is the best.

    Which deployment model are you using for this solution?

    Public Cloud
    Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
    PeerSpot user
    IT & Cloud Architect at AiM Services SA
    Reseller
    We use it for reporting and monitoring of all solutions in the company
    Pros and Cons
    • "We can present to our management in real time the security of the batch management for the PCs, security regarding the network equipment. We're currently working in the Azure Cloud project, so we can send any logs from the cloud to Splunk. We can monitor them and we can present to the managers and customers. It's a very good solution for reporting. We use Splunk for reporting and monitoring of any solution in the company."
    • "The security can be improved."

    What is our primary use case?

    Our primary use case is reporting from the Windows administration. We have SCCM that configures the manager to update every PC workstation and server in the company. We have a lot of PCs and servers in our environment and we use Splunk for the gathering of the PCs and Windows service. We also use it to collect information from the security tools, for example, to provide the management information about how the everyday connection is. 

    How has it helped my organization?

    We can present to our management in real time the security of the batch management for the PCs, security regarding the network equipment. We're currently working in the Azure Cloud project, so we can send any logs from the cloud to Splunk. We can monitor them and we can present to the managers and customers. It's a very good solution for reporting. We use Splunk for reporting and monitoring of any solution in the company.

    What needs improvement?

    The security can be improved. 

    What do I think about the scalability of the solution?

    It is scalable. We have five admins so far that we have in the solution. We have two as techs to develop the design on the world map of the solution, and we have the end users, so 80,000 users altogether. 

    How was the initial setup?

    The initial setup was complex. We have two data centers in France, two in Germany, and we have 18 countries in the world. It's a big company and we have a lot of services, servers, etc. So the setup is more complex.

    What other advice do I have?

    I would rate this solution a perfect ten out of ten. 

    Disclosure: My company has a business relationship with this vendor other than being a customer: Reseller.
    PeerSpot user
    PeerSpot user
    Security Engineer at Information Innovators Inc. (Triple-i)
    Real User
    Correlates logs throughout the enterprise for searching and use in investigations
    Pros and Cons
    • "We primarily use it to correlate logs throughout the enterprise for both searching and use in investigations."
    • "It can be tough to get a hold of somebody in technical support depending on the complexity of the issue."
    • "The Enterprise Security app could be improved. We have had trouble with it working from the first day."

    What is our primary use case?

    We primarily use it to correlate logs throughout the enterprise for both searching and use in investigations.

    How has it helped my organization?

    We previously did not have a good centralized solution which could ingest just about any log type, which has been a plus.

    What is most valuable?

    The search application has been the most useful. We have also liked the reporting features and dashboard capabilities.

    What needs improvement?

    The Enterprise Security app could be improved. We have had trouble with it working from the first day.  

    For how long have I used the solution?

    More than five years.

    What do I think about the stability of the solution?

    Yes, there have been issues with the Enterprise Security application instance.  

    What do I think about the scalability of the solution?

    No issues.

    How are customer service and technical support?

    It has been a weak point, but has improved over the years. It can be tough to get a hold of somebody depending on the complexity of the issue.  

    Which solution did I use previously and why did I switch?

    Years ago, we did use another solution, but I am not sure it exists any longer. We have been using Splunk for many years.  

    How was the initial setup?

    We had professional services set it up, as it was quite complex.  

    What about the implementation team?

    Vendor implementation, and I would rate them as a seven out of 10.  

    What was our ROI?

    Excellent overall. 

    What's my experience with pricing, setup cost, and licensing?

    It can be expensive, especially the licensing costs. However, there is added value in what it can do, not just log aggregation.  

    Which other solutions did I evaluate?

    We evaluated Trustwave and QRadar.

    What other advice do I have?

    It is a great product overall. I would like to see improvements on the Enterprise Security app/SIEM functionality.  

    Disclosure: I am a real user, and this review is based on my own experience and opinions.
    PeerSpot user
    PeerSpot user
    Business Intelligence Engineer at SONIFI Solutions, Inc.
    Real User
    Allows us to dig into raw events
    Pros and Cons
    • "Splunk allows us to find insights that we were not able to with traditional BI tools using ETL​. It allows us to dig into raw events."
    • "Splunk is extremely flexible, which allows us to create custom visualizations along with other customizations."
    • "The product was designed for security and IT with business intelligence needs, such as PDF exporting, but this has not been the highest priority. While the functionality is there, it could be developed more."

    What is our primary use case?

    Primary use is business intelligence. 

    How has it helped my organization?

    Splunk allows us to find insights that we were not able to with traditional BI tools using ETL. It allows us to dig into raw events. 

    What is most valuable?

    Splunk is extremely flexible, which allows us to create custom visualizations along with other customizations. The flexibility of Splunk as well as the resources available for learning and support are the best in the business. 

    What needs improvement?

    The product was designed for security and IT with business intelligence needs, such as PDF exporting, but this has not been the highest priority. While the functionality is there, it could be developed more. 

    For how long have I used the solution?

    More than five years.

    What do I think about the scalability of the solution?

    We ingest roughly 30GB/day. We have a small environment, but it provides big insights. 

    Disclosure: I am a real user, and this review is based on my own experience and opinions.
    PeerSpot user
    Buyer's Guide
    Download our free Splunk Enterprise Security Report and get advice and tips from experienced pros sharing their opinions.
    Updated: December 2024
    Buyer's Guide
    Download our free Splunk Enterprise Security Report and get advice and tips from experienced pros sharing their opinions.