I used it in the SOC environment to get logs, create dashboards, and filter out data.
Tech Lead Security at a comms service provider with 51-200 employees
A great product with good indexing and data collection capabilities
Pros and Cons
- "The indexing and data collection are valuable."
- "Its search or filtering capability is nice, but it can be improved. It is currently a bit complicated, and it should be simplified. If we can write the search filter in a more simplified way, it would be better."
What is our primary use case?
What is most valuable?
The indexing and data collection are valuable.
What needs improvement?
Its search or filtering capability is nice, but it can be improved. It is currently a bit complicated, and it should be simplified. If we can write the search filter in a more simplified way, it would be better.
Their sales support and tech support need improvement. Their support is really bad.
For how long have I used the solution?
I used it for nearly one year in my previous organization. I last used it about seven months ago.
Buyer's Guide
Splunk Enterprise Security
November 2024
Learn what your peers think about Splunk Enterprise Security. Get advice and tips from experienced pros sharing their opinions. Updated: November 2024.
823,875 professionals have used our research since 2012.
What do I think about the stability of the solution?
It is stable.
What do I think about the scalability of the solution?
Its scalability is good.
How are customer service and support?
Their sales support and tech support are really bad. They take really long to respond.
Which solution did I use previously and why did I switch?
We were using AlienVault. We switched because we weren't really happy with it. So, we looked into different solutions, such as Splunk.
How was the initial setup?
Its initial setup was okay.
What about the implementation team?
We did it ourselves. We had around two people for deployment and maintenance, but we had around 15 users. They all were SOC people.
What's my experience with pricing, setup cost, and licensing?
We had a yearly subscription.
What other advice do I have?
I can recommend this solution to others. It is a great product.
I would rate it an eight out of 10.
Which deployment model are you using for this solution?
On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Information Security Analyst at a tech services company with 1,001-5,000 employees
Good integration, easy UI, and very stable and scalable
Pros and Cons
- "Its integration is most valuable. Its UI is also pretty much easy."
- "Its setup is a little bit complex for a distributed environment. Their support can also be better. If we miss the response for more than a week, they usually close the case. Sometimes, it can take us more than a week to reply."
What is most valuable?
Its integration is most valuable. Its UI is also pretty much easy.
What needs improvement?
Its setup is a little bit complex for a distributed environment.
Their support can also be better. If we raise a case with Splunk support and by any chance we missed to respond for more than a week, they usually close the case. Sometimes, it can take us more than a week to reply. In that case What they can do is they can send a followup mail before closing.
For how long have I used the solution?
I have been using this solution for a year now.
What do I think about the stability of the solution?
It is very stable haven't encounter any glitches or bugs till now.
What do I think about the scalability of the solution?
It is very much scalable. I am acting as an admin, and we have more than a hundred users of this solution in our company. We use it on a regular basis. We currently don't have any plan to increase its usage.
How are customer service and technical support?
I would rate them an eight out of ten. Their response speed is okay, but if, by any chance, we miss the response for more than a week, they usually close the case. Sometimes, it can take us more than a week to reply.
Which solution did I use previously and why did I switch?
This is the only solution that we have been using.
How was the initial setup?
Its setup is pretty much easy for standalone, but for a distributed environment, it is a little bit complex.
What other advice do I have?
I would recommend this solution to others, but it should meet their needs and architecture.
I would rate Splunk a nine out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Buyer's Guide
Splunk Enterprise Security
November 2024
Learn what your peers think about Splunk Enterprise Security. Get advice and tips from experienced pros sharing their opinions. Updated: November 2024.
823,875 professionals have used our research since 2012.
Vice Manager at a comms service provider with 10,001+ employees
Collects data from many sources. Has search, analysis, and visualization capabilities.
What is most valuable?
- Collects data from any source
- Powerful search, analysis, and visualization
- Easy to build system on any platform
- API and easily integrated search
- Action script
How has it helped my organization?
We have over 7000 devices in our network infrastructure for monitoring, maintenance, and performance assessment.
We achieve this by collecting data and applying the analysis.
For how long have I used the solution?
I have used this solution for one year.
What do I think about the scalability of the solution?
We did not encounter any issues with scalability. Everything is normal with no bugs.
How are customer service and technical support?
It’s easy to obtain support from Splunk for technical issues. We also have enough knowledge ourselves to apply fixes.
Which solution did I use previously and why did I switch?
We used to deploy Elastic Stack. The search language of Splunk is easier and friendlier than Elastic Stack. It has helped me to search quickly and easily. Based on the results, it’s easy to visualize and add results to a previously built, personal dashboard.
What's my experience with pricing, setup cost, and licensing?
Licensing is free. Pricing is based on usage.
Which other solutions did I evaluate?
We evaluated Elastic Stack and Sumo Logic.
What other advice do I have?
If you are an enterprise and you need the best service for critical business analysis, Splunk would be one of the best choices.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Integration Architect at a manufacturing company with 1,001-5,000 employees
Fast availability of operational data spread across several servers is nice, but the MES is a complex system.
What is most valuable?
What Splunk calls operational intelligence: fast availability of operational data spread across several servers to prevent or react faster to outages or performance decreases.
How has it helped my organization?
MES is a complex and very critical distributed system here. Production WIP is directly connected to it and ICT is required to provide a continuous availability and very stable performance (line production has a costant speed, software cannot slowdown). Collect operational data from hardware, middleware and application software can potentially improve ICT proactive and reactive tasks.
For how long have I used the solution?
I've ever used it, just studied it.
Which solution did I use previously and why did I switch?
We also use a traditional monitor, and Microsoft SCOM.
What was our ROI?
Every stop or slowdown of the production line means lost of money, e.g. 30% reduction when compared to the current baseline.
What's my experience with pricing, setup cost, and licensing?
Every stop or slowdown of the production line means lost of money, e.g. 30% of reduction compare to the current baseline.
Which other solutions did I evaluate?
IBM QRadar
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Manager, Enterprise Risk Consulting at a tech company with 1,001-5,000 employees
Great Log Management and Investigation tool, but Operational SIEM capability needs improvement
Valuable Features
Great Log management capabilities with flexible and comprehensive search capabilities. Scalable and Easy to use.
Room for Improvement
Operational Workflow, Use Case Framework, and ticketing systems to make it suitable for SOC environments
Use of Solution
3 years
Scalability Issues
Splunk is extremely scalable with the limit being the hardware in use.
Customer Service and Technical Support
If you get the right people engaged, support can be a bliss.
Initial Setup
Setup is simple and straight forward.
Other Advice
http://infosecnirvana.com/splunk-enterprise-need-know/
Disclosure: I am a real user, and this review is based on my own experience and opinions.
CEO at a tech services company with 11-50 employees
Simple to install, with good monitoring, and correlation capabilities
Pros and Cons
- "The scalability is good."
- "In the next releases, I would like to see more pricing flexibility."
What is our primary use case?
We are resellers. We provide solutions to our clients.
Splunk is primarily used for developing CM solutions that are based on the Splunk platform for future security operation center development.
We are concentrating on assisting in the development of a security monitor as well as analysis.
If I am not mistaken, it's a standard CM system for identification, security verification, and event monitoring.
What needs improvement?
In my opinion, it is too expensive for our projects.
It is very competitive for small and medium businesses. Perhaps some should be set aside for developing markets. To begin with, similar to the current market, there may be some special conditions for large transactions.
In the next releases, I would like to see more pricing flexibility. It's a subscription-based service, and they don't sell professional licenses.
In some cases, particularly with large projects, we are not competitive in terms of pricing when compared to IBM QRadar and other solutions; even if we offer the maximum discount available, our prices remain uncompetitive.
For how long have I used the solution?
We have been selling Splunk for approximately five years.
What do I think about the scalability of the solution?
The scalability is good. It can be added on-demand in increments of one gigabyte or ten gigabytes. It's a per-gigabyte license, and you can add whatever you need at the time.
Our projects are sized per our current IT infrastructure.
Splunk is used by 10 of our customers.
How are customer service and support?
Our team provides technical support.
I have not communicated with technical support.
Which solution did I use previously and why did I switch?
We no longer resell Checkmarks.
We were unable to assist in establishing their business on-premises because It could have been too expensive for our clientele.
How was the initial setup?
Installing Splunk is not difficult, but it can be complicated in some cases.
The issue is the integration with the customer's system, as well as the configuration of the rules for correlation, log collecting, and analysis.
It has good documentation and guides, but the main works should be focused on customer needs and customer resources for monitoring.
It can take three months to complete the installation.
We have a team of three certified engineers who will deploy and maintain this solution.
What's my experience with pricing, setup cost, and licensing?
The licensing fees and pricing models could be reduced.
It's a yearly subscription.
They don't sell professionally because it's a subscription service. As a result, it is only a subscription service that is dependent on the customer's IT infrastructure.
What other advice do I have?
We do not sell Compliance Control Limited solutions because our focus is on auditing and independent security assessments. We put an end to our selling program with Checkmarks.
I would recommend this solution to others. Splunk is appropriate for small to medium-sized projects, and it should be calculated for large projects.
It's one of the best CM solutions on the market for monitoring, and correlation, as well as IT monitoring security.
I would rate Splunk an eight out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer: Reseller
Product Manager, FX Solutions at a tech services company with 10,001+ employees
Easy to use, informative documentation for data retrieval, and easy to install
Pros and Cons
- "The most valuable features of the solution are it is straightforward to use and the documentation is good for finding out how to get the data you are looking for."
- "The solution could improve by making it more business analysis oriented. The way it is now is designed more for developers."
What is our primary use case?
I use this solution for data visualization.
What is most valuable?
The most valuable features of the solution are it is straightforward to use and the documentation is good for finding out how to get the data you are looking for.
What needs improvement?
The solution could improve by making it more business analysis oriented. The way it is now is designed more for developers.
For how long have I used the solution?
I have been using Splunk for two weeks.
What do I think about the stability of the solution?
The solution is stable, I have not experienced any bugs or glitches.
What do I think about the scalability of the solution?
The solution is scalable and it is a requirement of my company to have scalable solutions.
Which solution did I use previously and why did I switch?
I have used previously Qlik Sense and Kibana.
How was the initial setup?
I did the training with Slunk and once I had the training the installation was easy.
Which other solutions did I evaluate?
I have evaluated Tableau.
What other advice do I have?
My advice to others is not to be intimidated by the solution and to give it a try. It will become easier over time.
I rate Splunk an eight out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Architecture and Security Team Leader at CV Akbar Panjaya
It helps us uncover bottlenecks in the network, but needs better local technical support
Pros and Cons
- "It helps us uncover bottlenecks in the network."
- "it can explain to management about what kind of traffic is visiting the network. It can also explain other traffic coming in and out, along with protecting against malware."
- "The product was difficult to back up the first time."
- "Splunk needs local technical support."
What is our primary use case?
We were using Splunk for our networking to know exactly what kind of the traffic was going from one network to another network because we had a lot of the connections on other sites.
How has it helped my organization?
it can explain to management about what kind of traffic is visiting the network. It can also explain other traffic coming in and out, along with protecting against malware.
What is most valuable?
All the features are valuable. It helps us uncover bottlenecks in the network.
What needs improvement?
Splunk should be able to integrate with other product using the free version.
The product was difficult to back up the first time.
For how long have I used the solution?
One to three years.
What do I think about the stability of the solution?
The stability is fine.
We have two people maintaining it.
How are customer service and technical support?
Splunk needs local technical support.
Which solution did I use previously and why did I switch?
We did not use another solution previously.
How was the initial setup?
The deployment was great and took three to four days.
What's my experience with pricing, setup cost, and licensing?
The pricing and licensing of the product are quite high.
What other advice do I have?
Splunk is great product, especially for my organization.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Buyer's Guide
Download our free Splunk Enterprise Security Report and get advice and tips from experienced pros
sharing their opinions.
Updated: November 2024
Product Categories
Security Information and Event Management (SIEM) Log Management IT Operations AnalyticsPopular Comparisons
CrowdStrike Falcon
Microsoft Sentinel
IBM Security QRadar
Elastic Security
LogRhythm SIEM
Sumo Logic Security
Rapid7 InsightIDR
Fortinet FortiSIEM
AlienVault OSSIM
Cortex XSIAM
Securonix Next-Gen SIEM
USM Anywhere
Buyer's Guide
Download our free Splunk Enterprise Security Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- What are some of the best features and use-cases of Splunk?
- What SOC product do you recommend?
- Splunk as an Enterprise Class monitoring solution -- thoughts?
- What is the biggest difference between Dynatrace and Splunk?
- IBM QRadar is rated above competitors (McAfee, Splunk, LogRhythm) in Gartner's 2020 Magic Quandrant. Agree/Disagree?
- What are the advantages of ELK over Splunk?
- How does Splunk compare with Azure Monitor?
- New risk scoring framework in the Splunk App for Enterprise Security -- thoughts?
- Splunk vs. Elastic Stack
- What is a better choice, Splunk or Azure Sentinel?