Try our new research platform with insights from 80,000+ expert users
reviewer1688463 - PeerSpot reviewer
Senior Technical Lead at a financial services firm with 10,001+ employees
Real User
Priced reasonably, effective log analysis, but artificial intelligence features need improvement
Pros and Cons
  • "We have found all the features useful. However, the dashboarding and logging have been very helpful. Additionally, the log analysis does a great job."
  • "The solution could improve by giving more email details."

What is most valuable?

We have found all the features useful. However, the dashboarding and logging have been very helpful. Additionally, the log analysis does a great job.

What needs improvement?

The solution could improve by giving more email details.

In a future release, the solution could improve on the artificial intelligence features, such as if an alert comes, it could automatically do logging from the system, get the KV knowledge base, and perform other functions. This would be a benefit.

For how long have I used the solution?

I have used Splunk for approximately five years.

How are customer service and support?

The technical support is good.

Buyer's Guide
Splunk Enterprise Security
December 2024
Learn what your peers think about Splunk Enterprise Security. Get advice and tips from experienced pros sharing their opinions. Updated: December 2024.
831,020 professionals have used our research since 2012.

How was the initial setup?

The initial setup is complex.

What's my experience with pricing, setup cost, and licensing?

The price of Splunk is reasonable.

Which other solutions did I evaluate?

We have evaluated SoapUI and Postman, and we are still evaluating others.

What other advice do I have?

I rate Splunk a seven out of ten.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Managing Director at Hayyan Horizons
Real User
Low-maintenance and stable with very useful dashboards
Pros and Cons
  • "The log aggregation is great."
  • "Technical support needs to be more responsive."

What is our primary use case?

We primarily use the solution for security and operations monitoring.

How has it helped my organization?

Gives full visibility on operational and security posture in our organization. Integrations is straightforward and effective.

What is most valuable?

The log aggregation is great.

The solution offers good data analytics.

The dashboards are very helpful.

The initial setup is simple and straightforward. 

The solution is low-maintenance.

It's a stable product.

We have found that the solution scales well. 

What needs improvement?

The TERM licensing model is still not very useful. It's not helping us. They used to have a perpetual licensing model. Now Splunk is offering annual term/subscription only. That's costly and it's more expensive and it's putting some burden on us.

Technical support needs to be more responsive. 

We would like to see more AI. Through AI, artificial intelligence, not machine learning only. We want to see more AI-enabled kinds of functionalities just to reduce dependencies on manual interventions. We do that, however, automation and artificial intelligence-based kind of automation we would really like to see.

For how long have I used the solution?

I've been using the solution for six years. I've used it for a while at this point. 

What do I think about the stability of the solution?

It's not high maintenance. There are software or upgrade releases every now and then, however, in general, the product is very stable. There are no bugs or glitches. It doesn't crash or freeze. 

What do I think about the scalability of the solution?

We have 17 people that are using the solution currently. 

It's very easy to scale the product if you need to.

How are customer service and technical support?

We use technical support every now and then. The response times are not very good. This is the thing that I would need to see improvement on and probably in that area only. They are that good when they started handling cases, however, they take too much time to respond to customer requests.

Which solution did I use previously and why did I switch?

We did not use anything else on the production scale. Our first experience was with Splunk.

How was the initial setup?

The solution is straightforward and simple to set up. It's not complex at all.

What about the implementation team?

We handled the process internally. We did not need the assistance of any integrators or consultants. 

What's my experience with pricing, setup cost, and licensing?

Filter the noise out.

Which other solutions did I evaluate?

Yes all the other competitors, Splunk by far is the best.

What other advice do I have?

We're a partner and a customer. 

I'm using the latest version of the solution. 

I would highly recommend the solution. It's the best product out there. It's definitely easy to set up. The use cases are multiple. It's not restrictive in terms of the efficiency of the platform. Just make sure that you have enough resources or good counsel from people who can help with the use cases. If you do the sky would be the limit. It is a good solution.

I'd rate the solution at a ten out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
PeerSpot user
Buyer's Guide
Splunk Enterprise Security
December 2024
Learn what your peers think about Splunk Enterprise Security. Get advice and tips from experienced pros sharing their opinions. Updated: December 2024.
831,020 professionals have used our research since 2012.
reviewer1404306 - PeerSpot reviewer
SOC Analyst at a wholesaler/distributor with 10,001+ employees
Real User
Plenty of features, stable, but is expensive
Pros and Cons
  • "The solution has plenty of features that are good."
  • "Deployment is not difficult but the lock sources and configurations can take time."

What is our primary use case?

We have multiple use cases, almost 200 plus use cases. An example, travel activities where you log in.

What is most valuable?

The solution has plenty of features that are good.

For how long have I used the solution?

I have been using the solution for two years.

What do I think about the stability of the solution?

It is a stable solution. 

What do I think about the scalability of the solution?

In my experience, it has been scalable. We have five users using the solution in our company.

How was the initial setup?

The installation is straightforward.

What about the implementation team?

Deployment is not difficult but the lock sources and configurations can take time. We have a team of 15 technicians that do the deployments.

What's my experience with pricing, setup cost, and licensing?

The solution is a little expensive.

What other advice do I have?

I would recommend this solution.

I rate Splunk a six out of ten.

Which deployment model are you using for this solution?

Private Cloud
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
reviewer1453023 - PeerSpot reviewer
CSSP Manager at a tech services company with 51-200 employees
MSP
Good at log collection and log management; not ideal for monitoring
Pros and Cons
  • "Good for log collection and log management."
  • "This is not really a monitoring solution."

What is our primary use case?

I'm the CSSP manager and we are customers of Splunk. 

What is most valuable?

Splunk is good at log collection and log management.

What needs improvement?

I'm a security manager and Splunk is not a good solution for my needs and not as good as other products I've used. I really think they just overreached and are marketing the solution as something that it really isn't. It's really not an SIEM product. It's really not a monitoring solution. If Splunk wants to get into SIEM, they need to make a totally new product. They should just leave SIEM, it's not their thing, not what they do. They're good at log collection and indexing. Stick to it. There are some things with log collection and log retention capabilities that they could actually improve instead of trying to create products for all these other different areas. I don't want their next release, I would rather just kind of scale back on some of the extras, and just really focus on log collection and log retention. I'd like to have more options on how I can perform those features with their products. I'd like to see a lot more integration with other products.

For how long have I used the solution?

I've been using this solution for three years. 

What do I think about the stability of the solution?

Once you set up the solution, you don't really have to worry about it. It's very stable. I like the fact that you can pretty much just patch the OS, and it doesn't really affect how Splunk runs. With a lot of products, you almost have to wait for that company to implement a new patch or version of the product before you can upgrade the server it's on, or anything like that. Or you can't upgrade, you just have to go with whatever they give you, because they're giving you an appliance or something. I like the fact that Splunk allows you to integrate and still run as Splunk and still be compliant with most vulnerabilities out there without affecting functionality.

What do I think about the scalability of the solution?

The solution is extremely scalable. We probably have about five or six users, so all our system administrators use it, they're the ones that implement it. Right now, just the CIO, the CTO, and there's a ISSM who has access. There are plans to add more people once we fully implement the Enterprise Security solution. We have admins responsible for maintenance.

How was the initial setup?

The initial setup is kind of complex but I think it's an issue we have and not connected to the solution. We're still deploying. The company didn't have an implementation strategy, they're kind of just flying by the seat of their pants which wasn't a great plan. We're doing it ourselves, we didn't use an integrator. 

What's my experience with pricing, setup cost, and licensing?

We have a 100 gig annual license. I'm not sure of the cost. Their licensing is based on the amount of data you collect. There is an additional cost for Enterprise Security. If there are any other kind of applications, the APIs that we created that we want to add, there are costs for most of those as well. Their pricing structure really could use a revamp. They really need to review and look at that and see if there's a better way that they can do it. Elasticsearch is a little cheaper and a better product in my view. 

What other advice do I have?

It's important to prepare. You can't just get a solution and start to implement it. A big part of that needs to be preparation, and in IT, we're not great at that. I would go with Elastic, a similar product but better. The licensing is a little different but it gives you a little more freedom to do things. It's really flexible with what you can do and versatile in how you can use it. Splunk is still top when it comes to log collection. If you wanted anything more than that, you should probably look into using several different products. There isn't really one product that you're going to find that's going to give you that coverage and I just like the versatility of using several different products. There are some other things you can use that actually do a better job at the correlation part. 

I would rate this solution a seven out of 10. 

Which deployment model are you using for this solution?

Hybrid Cloud
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Senior Network & Security Architect at a insurance company with 501-1,000 employees
Real User
Central locale for our cybersecurity
Pros and Cons
  • "It is quite extensible. It is a platform that we can build our use instead of each case instead of each case being limited or restricted to each capability. This is probably the best feature."
  • "I would like to see future development in terms of ML (Machine Learning)."
  • "I think the tech support response time could be a bit better. Sometimes I need to wait more than 24 hours for a response to my tickets."

What is our primary use case?

Splunk is our central locale for cybersecurity and protection.

How has it helped my organization?

Once we onboarded all of the required needs, it created a lot of visibility for us.

What is most valuable?

It is quite extensible. It is a platform that we can build our use of each case instead of each case being limited or restricted to each capability. This is probably the best feature.

What needs improvement?

I would like to see future development in terms of ML (Machine Learning). 

For how long have I used the solution?

One to three years.

What do I think about the stability of the solution?

It is a stable product.

What do I think about the scalability of the solution?

It can be scaled quite easily in comparison to other products on the market.

How is customer service and technical support?

The tech support response time could be a bit better. Sometimes I need to wait more than 24 hours for a response to my tickets.

How was the initial setup?

I was not involved with the initial setup.

What's my experience with pricing, setup cost, and licensing?

The price could be improved.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Security1747 - PeerSpot reviewer
Security Architect at a comms service provider with 10,001+ employees
Real User
It is a place for all our logs and everything goes in one place.
Pros and Cons
  • "The stock analysts and security people use one single dashboard (one single location) to check our logs."
  • "It scales better in the cloud than on-premise."
  • "We would like more integrations with other cloud products, not just AWS, e.g., Azure."
  • "There are new services which are coming up. If Splunk can catch up with the speed of Amazon, and with the integration, instead of us waiting for another year or so, that would be good."

What is our primary use case?

We use it for log analysis and alerting, and our stock analysts use it.

I have used the product for more than five years. Then, in the cloud, I have used it for probably a year. It scales better in the cloud than on-premise.

How has it helped my organization?

It is a place for all our logs, and everything goes in one place. The stock analysts and security people use one single dashboard (one single location) to check our logs.

What is most valuable?

  • Easy indexing.
  • The solution is faster.

What needs improvement?

Every product needs improvement. If we can get a faster product, we will take it. There are new services which are coming up. If Splunk can catch up with the speed of Amazon, and with the integration, instead of us waiting for another year or so, that would be good.

We would like more integrations with other cloud products, not just AWS, e.g., Azure.

For how long have I used the solution?

More than five years.

What do I think about the stability of the solution?

The stability is good. We stress it at 98 percent.

What do I think about the scalability of the solution?

The AWS scalability is pretty good. We currently have it running on three servers.

How is customer service and technical support?

Other teams have told me that the technical support is pretty good.

How was the initial setup?

For the few integrations that we have already made, these have been easy to do.

What was our ROI?

We have seen ROI.

What's my experience with pricing, setup cost, and licensing?

Splunk is not free.

What other advice do I have?

I would recommend trying different stuff based on your company's needs and log types.

We like the product.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
PeerSpot user
Data Scientist Intern at Splunxter, Inc.
Real User
Can ingest any data and display it in a way that anyone can understand
Pros and Cons
  • "The ability to ingest any data and display it in a way that anyone can understand."
  • "It needs more thoroughly tested releases. Every new big version (6, 7, etc.) has had so many bugs that it makes me wary of customers upgrading right away."

What is our primary use case?

I work with Splunk, as a contractor, so I use it in many different areas. Most often it is used to get performance insights on applications or servers. Recently, I have used it in more of an endpoint security mindset. 

How has it helped my organization?

My whole organization is built around Splunk. We provide Splunk PS to many different companies. If Splunk did not have such a good presence, we could not exist.

What is most valuable?

The best features would have to be the ability to ingest any data and display it in a way that anyone can understand.

What needs improvement?

It needs more thoroughly tested releases. Every new big version (6, 7, etc.) has had so many bugs that it makes me wary of customers upgrading right away.

For how long have I used the solution?

One to three years.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
PeerSpot user
Senior Network Security Engineer at Starz Entertainment
Real User
In the event of an incident, it has a rapid response search environment
Pros and Cons
  • "It has a rapid response search environment in the event of an incident."
  • "The correlation searches (properly configured) populate the Incident Management dashboard and provide me a quick birds-eye view of my most important concerns."
  • "The use cases provided by Splunk are a good starting point, but could cover many additional topics to ensure that a smaller or less experienced shop might maximize the value of an ES deployment."

What is our primary use case?

Although my company uses Splunk extensively, my use case is primarily the Enterprise Security add-on.

How has it helped my organization?

Splunk has enabled us to utilize many different data sources and is easy-to-use. It has a rapid response search environment in the event of an incident.

What is most valuable?

The correlation searches (properly configured) populate the Incident Management dashboard and provide me a quick birds-eye view of my most important concerns.

What needs improvement?

ES is very powerful, but it requires a mature security posture at the company to take advantage of it currently. The use cases provided by Splunk are a good starting point, but could cover many additional topics to ensure that a smaller or less experienced shop might maximize the value of an ES deployment.

For how long have I used the solution?

Less than one year.

Which solution did I use previously and why did I switch?

We were using a different SIEM, which was old-fashioned and very structured.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Buyer's Guide
Download our free Splunk Enterprise Security Report and get advice and tips from experienced pros sharing their opinions.
Updated: December 2024
Buyer's Guide
Download our free Splunk Enterprise Security Report and get advice and tips from experienced pros sharing their opinions.