We are a solution provider and Splunk is one of the products that we distribute.
The primary use case is for SIEM and we have approximately 35 customers.
We are a solution provider and Splunk is one of the products that we distribute.
The primary use case is for SIEM and we have approximately 35 customers.
The fact that Splunk is a platform and not just a SIEM solution is a key benefit.
Our customers like that they can use Splunk to optimize their security.
The Splunk licensing model should be more flexible.
The support that is included with the standard licensing fee is very bad.
We have been working with Splunk since 2017.
Stability-wise, it's perfect. We haven't had any problem with Splunk. It's good software.
One of the key benefits and differences with this software is that the customer can scale up as much as they need to. Our largest Splunk customer is using between three and four petabytes of data per day.
If you don't pay extra for technical support then it is very bad. If you pay extra for it, then the technical support is normal.
I am familiar with other products and Splunk can handle much more data than IBM QRadar or any other competing product.
Direct competitors are more flexible when it comes to licensing.
We have not had any problems installing Splunk.
For a standard case, it takes between one and two weeks to install correctly and deploy. This is for situations where the client has less than 50 gigabytes of data per day.
Problems during the implementation are typically due to something on the customer's side. For example, if the client does not have somebody that is responsible for the deployment, helping to speed up the various procedures, then this is a key problem for us.
It takes two people to deploy and maintain.
Splunk is not a cheap solution and the license is billed annually. The licensing model should be improved and the price should be lower, in general.
You can purchase additional technical support, which is much better than the support that is included.
I would rate this solution an eight out of ten.
There are many use cases for Splunk, we commonly use it for log management and analytics.
The most valuable feature of Splunk is the management and built-in workflows.
The analytics of Splunk could be improved.
I have been using Splunk for approximately four years.
Splunk is a highly stable solution.
I have found Splunk to be scalable.
We have 15 members of our organization that use this solution.
We used to support a few times and our experience was good.
I would rate the support from Splunk a four out of five.
I have previously used RSA and I prefer Splunk.
The implementation of slunk is not straightforward. It is of a moderate difficulty level.
We used an integrator to do the implementation.
There is an annual license required to use this solution.
I have evaluated other solutions, such as IBM QRadar.
This solution has good technology.
I rate Splunk an eight out of ten.
We have found all the features useful. However, the dashboarding and logging have been very helpful. Additionally, the log analysis does a great job.
The solution could improve by giving more email details.
In a future release, the solution could improve on the artificial intelligence features, such as if an alert comes, it could automatically do logging from the system, get the KV knowledge base, and perform other functions. This would be a benefit.
I have used Splunk for approximately five years.
The technical support is good.
The initial setup is complex.
The price of Splunk is reasonable.
We have evaluated SoapUI and Postman, and we are still evaluating others.
I rate Splunk a seven out of ten.
We primarily use the solution for security and operations monitoring.
Gives full visibility on operational and security posture in our organization. Integrations is straightforward and effective.
The log aggregation is great.
The solution offers good data analytics.
The dashboards are very helpful.
The initial setup is simple and straightforward.
The solution is low-maintenance.
It's a stable product.
We have found that the solution scales well.
The TERM licensing model is still not very useful. It's not helping us. They used to have a perpetual licensing model. Now Splunk is offering annual term/subscription only. That's costly and it's more expensive and it's putting some burden on us.
Technical support needs to be more responsive.
We would like to see more AI. Through AI, artificial intelligence, not machine learning only. We want to see more AI-enabled kinds of functionalities just to reduce dependencies on manual interventions. We do that, however, automation and artificial intelligence-based kind of automation we would really like to see.
I've been using the solution for six years. I've used it for a while at this point.
It's not high maintenance. There are software or upgrade releases every now and then, however, in general, the product is very stable. There are no bugs or glitches. It doesn't crash or freeze.
We have 17 people that are using the solution currently.
It's very easy to scale the product if you need to.
We use technical support every now and then. The response times are not very good. This is the thing that I would need to see improvement on and probably in that area only. They are that good when they started handling cases, however, they take too much time to respond to customer requests.
We did not use anything else on the production scale. Our first experience was with Splunk.
The solution is straightforward and simple to set up. It's not complex at all.
We handled the process internally. We did not need the assistance of any integrators or consultants.
Filter the noise out.
Yes all the other competitors, Splunk by far is the best.
We're a partner and a customer.
I'm using the latest version of the solution.
I would highly recommend the solution. It's the best product out there. It's definitely easy to set up. The use cases are multiple. It's not restrictive in terms of the efficiency of the platform. Just make sure that you have enough resources or good counsel from people who can help with the use cases. If you do the sky would be the limit. It is a good solution.
I'd rate the solution at a ten out of ten.
We have multiple use cases, almost 200 plus use cases. An example, travel activities where you log in.
The solution has plenty of features that are good.
I have been using the solution for two years.
It is a stable solution.
In my experience, it has been scalable. We have five users using the solution in our company.
The installation is straightforward.
Deployment is not difficult but the lock sources and configurations can take time. We have a team of 15 technicians that do the deployments.
The solution is a little expensive.
I would recommend this solution.
I rate Splunk a six out of ten.
I'm the CSSP manager and we are customers of Splunk.
Splunk is good at log collection and log management.
I'm a security manager and Splunk is not a good solution for my needs and not as good as other products I've used. I really think they just overreached and are marketing the solution as something that it really isn't. It's really not an SIEM product. It's really not a monitoring solution. If Splunk wants to get into SIEM, they need to make a totally new product. They should just leave SIEM, it's not their thing, not what they do. They're good at log collection and indexing. Stick to it. There are some things with log collection and log retention capabilities that they could actually improve instead of trying to create products for all these other different areas. I don't want their next release, I would rather just kind of scale back on some of the extras, and just really focus on log collection and log retention. I'd like to have more options on how I can perform those features with their products. I'd like to see a lot more integration with other products.
I've been using this solution for three years.
Once you set up the solution, you don't really have to worry about it. It's very stable. I like the fact that you can pretty much just patch the OS, and it doesn't really affect how Splunk runs. With a lot of products, you almost have to wait for that company to implement a new patch or version of the product before you can upgrade the server it's on, or anything like that. Or you can't upgrade, you just have to go with whatever they give you, because they're giving you an appliance or something. I like the fact that Splunk allows you to integrate and still run as Splunk and still be compliant with most vulnerabilities out there without affecting functionality.
The solution is extremely scalable. We probably have about five or six users, so all our system administrators use it, they're the ones that implement it. Right now, just the CIO, the CTO, and there's a ISSM who has access. There are plans to add more people once we fully implement the Enterprise Security solution. We have admins responsible for maintenance.
The initial setup is kind of complex but I think it's an issue we have and not connected to the solution. We're still deploying. The company didn't have an implementation strategy, they're kind of just flying by the seat of their pants which wasn't a great plan. We're doing it ourselves, we didn't use an integrator.
We have a 100 gig annual license. I'm not sure of the cost. Their licensing is based on the amount of data you collect. There is an additional cost for Enterprise Security. If there are any other kind of applications, the APIs that we created that we want to add, there are costs for most of those as well. Their pricing structure really could use a revamp. They really need to review and look at that and see if there's a better way that they can do it. Elasticsearch is a little cheaper and a better product in my view.
It's important to prepare. You can't just get a solution and start to implement it. A big part of that needs to be preparation, and in IT, we're not great at that. I would go with Elastic, a similar product but better. The licensing is a little different but it gives you a little more freedom to do things. It's really flexible with what you can do and versatile in how you can use it. Splunk is still top when it comes to log collection. If you wanted anything more than that, you should probably look into using several different products. There isn't really one product that you're going to find that's going to give you that coverage and I just like the versatility of using several different products. There are some other things you can use that actually do a better job at the correlation part.
I would rate this solution a seven out of 10.
Splunk is our central locale for cybersecurity and protection.
Once we onboarded all of the required needs, it created a lot of visibility for us.
It is quite extensible. It is a platform that we can build our use of each case instead of each case being limited or restricted to each capability. This is probably the best feature.
I would like to see future development in terms of ML (Machine Learning).
It is a stable product.
It can be scaled quite easily in comparison to other products on the market.
The tech support response time could be a bit better. Sometimes I need to wait more than 24 hours for a response to my tickets.
I was not involved with the initial setup.
The price could be improved.
I work with Splunk, as a contractor, so I use it in many different areas. Most often it is used to get performance insights on applications or servers. Recently, I have used it in more of an endpoint security mindset.
My whole organization is built around Splunk. We provide Splunk PS to many different companies. If Splunk did not have such a good presence, we could not exist.
The best features would have to be the ability to ingest any data and display it in a way that anyone can understand.
It needs more thoroughly tested releases. Every new big version (6, 7, etc.) has had so many bugs that it makes me wary of customers upgrading right away.