We primarily use the solution for security and operations monitoring.
Managing Director at Hayyan Horizons
Low-maintenance and stable with very useful dashboards
Pros and Cons
- "The log aggregation is great."
- "Technical support needs to be more responsive."
What is our primary use case?
How has it helped my organization?
Gives full visibility on operational and security posture in our organization. Integrations is straightforward and effective.
What is most valuable?
The log aggregation is great.
The solution offers good data analytics.
The dashboards are very helpful.
The initial setup is simple and straightforward.
The solution is low-maintenance.
It's a stable product.
We have found that the solution scales well.
What needs improvement?
The TERM licensing model is still not very useful. It's not helping us. They used to have a perpetual licensing model. Now Splunk is offering annual term/subscription only. That's costly and it's more expensive and it's putting some burden on us.
Technical support needs to be more responsive.
We would like to see more AI. Through AI, artificial intelligence, not machine learning only. We want to see more AI-enabled kinds of functionalities just to reduce dependencies on manual interventions. We do that, however, automation and artificial intelligence-based kind of automation we would really like to see.
Buyer's Guide
Splunk Enterprise Security
October 2024
Learn what your peers think about Splunk Enterprise Security. Get advice and tips from experienced pros sharing their opinions. Updated: October 2024.
815,854 professionals have used our research since 2012.
For how long have I used the solution?
I've been using the solution for six years. I've used it for a while at this point.
What do I think about the stability of the solution?
It's not high maintenance. There are software or upgrade releases every now and then, however, in general, the product is very stable. There are no bugs or glitches. It doesn't crash or freeze.
What do I think about the scalability of the solution?
We have 17 people that are using the solution currently.
It's very easy to scale the product if you need to.
How are customer service and support?
We use technical support every now and then. The response times are not very good. This is the thing that I would need to see improvement on and probably in that area only. They are that good when they started handling cases, however, they take too much time to respond to customer requests.
Which solution did I use previously and why did I switch?
We did not use anything else on the production scale. Our first experience was with Splunk.
How was the initial setup?
The solution is straightforward and simple to set up. It's not complex at all.
What about the implementation team?
We handled the process internally. We did not need the assistance of any integrators or consultants.
What's my experience with pricing, setup cost, and licensing?
Filter the noise out.
Which other solutions did I evaluate?
Yes all the other competitors, Splunk by far is the best.
What other advice do I have?
We're a partner and a customer.
I'm using the latest version of the solution.
I would highly recommend the solution. It's the best product out there. It's definitely easy to set up. The use cases are multiple. It's not restrictive in terms of the efficiency of the platform. Just make sure that you have enough resources or good counsel from people who can help with the use cases. If you do the sky would be the limit. It is a good solution.
I'd rate the solution at a ten out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
Founder at a marketing services firm with 11-50 employees
Easy to deploy and relatively simple learning curve; could be more user friendly
Pros and Cons
- "Easy to deploy and simple to use."
- "Could be more user friendly."
What is our primary use case?
We're using the solution to try to build a virtual network and put Splunk inside it and do some kind of transcentralization with a log server. Our aim is to track connections, network traffic and some personal databases. I'm the founder of the company and we are customers of Splunk.
What is most valuable?
Splunk can quickly be deployed and it's not difficult to learn the solution.
What needs improvement?
The solution could be more user friendly and it's difficult to know at this stage whether our requirements will be met by the solution.
For how long have I used the solution?
I've been using this solution for a couple of months.
What do I think about the stability of the solution?
The solution is stable.
What do I think about the scalability of the solution?
Scalability is good with Splunk.
How was the initial setup?
The initial setup doesn't take much time especially if there's good bandwidth. In a small company deployment might take a month or two. If you have 100 devices then a technical team of three should be sufficient. They would need to be able to deal with log analysis, forensics and have general knowledge about admin systems. In time, we would expect to have thousands of users.
What's my experience with pricing, setup cost, and licensing?
I think Splunk is expensive compared to other tools at the purchase stage. It's possible that if we can keep control of the costs involved down the track, it won't be so bad.
Which other solutions did I evaluate?
We studied four or five tools including Logrhythm and Exabeam. We went with Splunk for now and will see how that goes.
What other advice do I have?
I think this is a good solution and rate it a seven out of 10.
Which deployment model are you using for this solution?
On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Buyer's Guide
Splunk Enterprise Security
October 2024
Learn what your peers think about Splunk Enterprise Security. Get advice and tips from experienced pros sharing their opinions. Updated: October 2024.
815,854 professionals have used our research since 2012.
CSSP Manager at a tech services company with 51-200 employees
Good at log collection and log management; not ideal for monitoring
Pros and Cons
- "Good for log collection and log management."
- "This is not really a monitoring solution."
What is our primary use case?
I'm the CSSP manager and we are customers of Splunk.
What is most valuable?
Splunk is good at log collection and log management.
What needs improvement?
I'm a security manager and Splunk is not a good solution for my needs and not as good as other products I've used. I really think they just overreached and are marketing the solution as something that it really isn't. It's really not an SIEM product. It's really not a monitoring solution. If Splunk wants to get into SIEM, they need to make a totally new product. They should just leave SIEM, it's not their thing, not what they do. They're good at log collection and indexing. Stick to it. There are some things with log collection and log retention capabilities that they could actually improve instead of trying to create products for all these other different areas. I don't want their next release, I would rather just kind of scale back on some of the extras, and just really focus on log collection and log retention. I'd like to have more options on how I can perform those features with their products. I'd like to see a lot more integration with other products.
For how long have I used the solution?
I've been using this solution for three years.
What do I think about the stability of the solution?
Once you set up the solution, you don't really have to worry about it. It's very stable. I like the fact that you can pretty much just patch the OS, and it doesn't really affect how Splunk runs. With a lot of products, you almost have to wait for that company to implement a new patch or version of the product before you can upgrade the server it's on, or anything like that. Or you can't upgrade, you just have to go with whatever they give you, because they're giving you an appliance or something. I like the fact that Splunk allows you to integrate and still run as Splunk and still be compliant with most vulnerabilities out there without affecting functionality.
What do I think about the scalability of the solution?
The solution is extremely scalable. We probably have about five or six users, so all our system administrators use it, they're the ones that implement it. Right now, just the CIO, the CTO, and there's a ISSM who has access. There are plans to add more people once we fully implement the Enterprise Security solution. We have admins responsible for maintenance.
How was the initial setup?
The initial setup is kind of complex but I think it's an issue we have and not connected to the solution. We're still deploying. The company didn't have an implementation strategy, they're kind of just flying by the seat of their pants which wasn't a great plan. We're doing it ourselves, we didn't use an integrator.
What's my experience with pricing, setup cost, and licensing?
We have a 100 gig annual license. I'm not sure of the cost. Their licensing is based on the amount of data you collect. There is an additional cost for Enterprise Security. If there are any other kind of applications, the APIs that we created that we want to add, there are costs for most of those as well. Their pricing structure really could use a revamp. They really need to review and look at that and see if there's a better way that they can do it. Elasticsearch is a little cheaper and a better product in my view.
What other advice do I have?
It's important to prepare. You can't just get a solution and start to implement it. A big part of that needs to be preparation, and in IT, we're not great at that. I would go with Elastic, a similar product but better. The licensing is a little different but it gives you a little more freedom to do things. It's really flexible with what you can do and versatile in how you can use it. Splunk is still top when it comes to log collection. If you wanted anything more than that, you should probably look into using several different products. There isn't really one product that you're going to find that's going to give you that coverage and I just like the versatility of using several different products. There are some other things you can use that actually do a better job at the correlation part.
I would rate this solution a seven out of 10.
Which deployment model are you using for this solution?
Hybrid Cloud
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Sr. Manager Information Security at Tapal Tea (Private) Limited
The search and query feature is very fast but due to the log size limit, we did not get the full benefit
What is our primary use case?
Log collection and search.
How has it helped my organization?
The search and query feature is very fast but due to the log size limit (in trial version), we did not get the full benefit.
What is most valuable?
Selecting the relevant events and records.
What needs improvement?
Due to the size limit, we could not see the full product.
For how long have I used the solution?
Trial/evaluations only.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
QA Lead at a financial services firm with 11-50 employees
It has helped with troubleshooting, making it easier
Pros and Cons
- "It provides logs in one place, so they are easy to find. It collects the logs from multiple places, then you have just one place where you see the whole flow from the front-end to the back-end."
- "The search could be improved. Now, it is a bit difficult to write search queries because they become quite long, then maintaining those long search queries is a quite challenging."
What is our primary use case?
We use it mostly for log monitoring, and also for trying to raise alarms.
How has it helped my organization?
It has helped with troubleshooting, making it easier. Now, we have one place where we can find logs and errors. There is no need to go to the actual server to search for the log file.
What is most valuable?
It provides logs in one place, so they are easy to find. It collects the logs from multiple places, then you have just one place where you see the whole flow from the front-end to the back-end. This is the best thing.
What needs improvement?
The search could be improved. Now, it is a bit difficult to write search queries because they become quite long, then maintaining those long search queries is a quite challenging.
For how long have I used the solution?
Three to five years.
What do I think about the stability of the solution?
I have not had any issues with it, and we have the whole banking infrastructure running on it.
What do I think about the scalability of the solution?
The scalability is okay as far as I have seen and used it. We have dozens of different environment environments using the same Splunk instruments, and it has been able to scale.
How is customer service and technical support?
I have not used technical support.
What other advice do I have?
Splunk's website is quite useful. You can find a lot of information on it. I would recommend to use it and try to figure out the product's features and what you can actually do with Splunk. You can do a lot of things with Splunk, but you need to know what to do first.
I have used both the AWS and on-premise versions, but in two different environment, so I am unable to compare the versions.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Senior Network Security Engineer at Starz Entertainment
In the event of an incident, it has a rapid response search environment
Pros and Cons
- "It has a rapid response search environment in the event of an incident."
- "The correlation searches (properly configured) populate the Incident Management dashboard and provide me a quick birds-eye view of my most important concerns."
- "The use cases provided by Splunk are a good starting point, but could cover many additional topics to ensure that a smaller or less experienced shop might maximize the value of an ES deployment."
What is our primary use case?
Although my company uses Splunk extensively, my use case is primarily the Enterprise Security add-on.
How has it helped my organization?
Splunk has enabled us to utilize many different data sources and is easy-to-use. It has a rapid response search environment in the event of an incident.
What is most valuable?
The correlation searches (properly configured) populate the Incident Management dashboard and provide me a quick birds-eye view of my most important concerns.
What needs improvement?
ES is very powerful, but it requires a mature security posture at the company to take advantage of it currently. The use cases provided by Splunk are a good starting point, but could cover many additional topics to ensure that a smaller or less experienced shop might maximize the value of an ES deployment.
For how long have I used the solution?
Less than one year.
Which solution did I use previously and why did I switch?
We were using a different SIEM, which was old-fashioned and very structured.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Business Analyst at a retailer with 10,001+ employees
Provides real-time and scheduled searches with alternate functionalities.
What is most valuable?
- Flexibility when creating dashboards
- Automated cron searches
- Real-time and scheduled searches with alternate functionalities
- User-base integration with LDAP
How has it helped my organization?
It alerted many situations before other monitoring systems identified that there is a critical issue.
What needs improvement?
VMware and security device integration looks a bit complex.
For how long have I used the solution?
I have used Splunk for almost three years.
What do I think about the stability of the solution?
As of now, we have had no issues with stability. It is running like a charm.
What do I think about the scalability of the solution?
From a nodes perspective, there have been no scalability issues.
How are customer service and technical support?
I can say that support is good.
Which solution did I use previously and why did I switch?
We never used other solutions.
How was the initial setup?
We used the Splunk Cluster setup. It was a bit complex to set up, but management-wise and stability-wise, it was awesome.
What's my experience with pricing, setup cost, and licensing?
License costs fall under the NDA, but Splunk license costs are public, I believe.
Which other solutions did I evaluate?
We evaluated Logstash and others, but Splunk plays a pivotal role.
What other advice do I have?
I would strongly recommend this product, as it would be very beneficial for service operations and management.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Technical manager at a tech services company with 11-50 employees
Stable and easy to use
Pros and Cons
- "The most valuable features are how stable and easy to use Splunk is."
- "This solution could be improved by better pricing in general and by easier installation."
What is our primary use case?
My primary use case is for log management. It's mostly deployed on-premises, but it can be cloud-based as well.
What is most valuable?
The most valuable features are how stable and easy to use Splunk is.
What needs improvement?
This solution could be improved by better pricing in general and by easier installation.
For how long have I used the solution?
I have been a partner of Splunk for three years.
What do I think about the stability of the solution?
This solution is stable.
How are customer service and support?
Technical support is customer-friendly.
How was the initial setup?
The initial installation is not straightforward. It needs two or three days, depending on the size of the company. But it can be done with one senior engineer.
What about the implementation team?
I implemented through an in-house team.
What's my experience with pricing, setup cost, and licensing?
Splunk has a subscription and a perpetual license.
This product could use better pricing.
What other advice do I have?
I would rate Splunk a nine out of ten. I recommend this product to others who are considering implementing it.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
Buyer's Guide
Download our free Splunk Enterprise Security Report and get advice and tips from experienced pros
sharing their opinions.
Updated: October 2024
Product Categories
Security Information and Event Management (SIEM) Log Management IT Operations AnalyticsPopular Comparisons
CrowdStrike Falcon
Microsoft Power BI
Microsoft Sentinel
SentinelOne Singularity Complete
Microsoft Defender XDR
Azure Monitor
IBM Security QRadar
Elastic Security
AppDynamics
Buyer's Guide
Download our free Splunk Enterprise Security Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- What are some of the best features and use-cases of Splunk?
- What SOC product do you recommend?
- Splunk as an Enterprise Class monitoring solution -- thoughts?
- What is the biggest difference between Dynatrace and Splunk?
- IBM QRadar is rated above competitors (McAfee, Splunk, LogRhythm) in Gartner's 2020 Magic Quandrant. Agree/Disagree?
- What are the advantages of ELK over Splunk?
- How does Splunk compare with Azure Monitor?
- New risk scoring framework in the Splunk App for Enterprise Security -- thoughts?
- Splunk vs. Elastic Stack
- What is a better choice, Splunk or Azure Sentinel?