- Cybersecurity defense
- Web app monitoring
- VMware monitoring
Principal Consultant at a computer software company with 51-200 employees
Positive features include replication capabilities, software development kits, and its architecture
Pros and Cons
- "Positive features include replication capabilities, software development kits, and the architecture."
- "The solution could use a different licensing model."
- "An improved user interface along with multi-tenancy support would be beneficial."
What is our primary use case?
How has it helped my organization?
- Troubleshooting
- Cyber defense
What is most valuable?
- Drill down
- Apps
- REST API
- Software development kits
- Architecture
- Replication capabilities
What needs improvement?
- Multi-tenancy support
- Improved user interface
- Non-proprietary search language
- Different licensing model
Buyer's Guide
Splunk Enterprise Security
December 2024
Learn what your peers think about Splunk Enterprise Security. Get advice and tips from experienced pros sharing their opinions. Updated: December 2024.
831,020 professionals have used our research since 2012.
For how long have I used the solution?
One to three years.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Java Technical Lead at a insurance company
The visibility is amazing with easy dashboard creation
Pros and Cons
- "It is easy to use in any environment."
- "The visibility is amazing with easy dashboard creation."
- "Not even Splunk's support guy, who came to our firm, could help with defining proper role management."
- "Make it easier to include roles and user controls, as it is horrible now."
What is our primary use case?
- Log monitoring and alerts
- Looking up information
- Dashboards for nice, fast information about various application servers.
How has it helped my organization?
- It is easier to find problems and exceptions.
- It is used by any factor in the firm.
- Easy dashboards creation.
- The visibility is amazing.
What is most valuable?
- Regex for fields creation is great.
- High availability
- Easy to use in any environment.
What needs improvement?
Make it easier to include roles and user controls, as it is horrible now.
For how long have I used the solution?
More than five years.
How is customer service and technical support?
Not even Splunk's support guy, who came to our firm, could help with defining proper role management.
What's my experience with pricing, setup cost, and licensing?
It is a pretty high cost solution, but if your organization has the funds, it can bring many benefits.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Buyer's Guide
Splunk Enterprise Security
December 2024
Learn what your peers think about Splunk Enterprise Security. Get advice and tips from experienced pros sharing their opinions. Updated: December 2024.
831,020 professionals have used our research since 2012.
Vice Manager at a comms service provider with 10,001+ employees
Collects data from many sources. Has search, analysis, and visualization capabilities.
What is most valuable?
- Collects data from any source
- Powerful search, analysis, and visualization
- Easy to build system on any platform
- API and easily integrated search
- Action script
How has it helped my organization?
We have over 7000 devices in our network infrastructure for monitoring, maintenance, and performance assessment.
We achieve this by collecting data and applying the analysis.
For how long have I used the solution?
I have used this solution for one year.
What do I think about the scalability of the solution?
We did not encounter any issues with scalability. Everything is normal with no bugs.
How are customer service and technical support?
It’s easy to obtain support from Splunk for technical issues. We also have enough knowledge ourselves to apply fixes.
Which solution did I use previously and why did I switch?
We used to deploy Elastic Stack. The search language of Splunk is easier and friendlier than Elastic Stack. It has helped me to search quickly and easily. Based on the results, it’s easy to visualize and add results to a previously built, personal dashboard.
What's my experience with pricing, setup cost, and licensing?
Licensing is free. Pricing is based on usage.
Which other solutions did I evaluate?
We evaluated Elastic Stack and Sumo Logic.
What other advice do I have?
If you are an enterprise and you need the best service for critical business analysis, Splunk would be one of the best choices.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Sr. Program Manager at a consultancy with 51-200 employees
It is able to configure and integrate various solutions into one tool and provide actionable results. You need a dedicated developer.
What is most valuable?
- Can ingest data from various data sources.
- Is very useful for organizations who are attempting to meet compliance requirements.
- Is able to fully configure and integrate various solutions into one tool and provide actionable results.
How has it helped my organization?
My use of Splunk at my previous place of employment improved how we functioned.
For how long have I used the solution?
I have used Splunk for three years.
What do I think about the stability of the solution?
We didn’t have any stability issues.
What do I think about the scalability of the solution?
We didn’t have any scalability issues.
How are customer service and technical support?
During our use of Splunk, we had professional services assisting and not actual technical support. However, the professional services team was great.
Which solution did I use previously and why did I switch?
Our organization did not have an established SIEM tool.
How was the initial setup?
The initial setup is straightforward, depending on the level of implementation of the tool.
What's my experience with pricing, setup cost, and licensing?
Take into consideration the labor costs for a dedicated Splunk developer who can craft the required queries needed for each organization. Organizations usually have their own form of implementation of each tool.
Which other solutions did I evaluate?
We didn’t evaluate any alternatives.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Head of Service Integrity with 1,001-5,000 employees
It can probably do anything if you tweak it enough but it's not cheap.
Splunk is really good at log parsing events over time. It is quick to drill in and analyze and it is quick to build a presentation layer and automate reporting. I love it for problem analysis and event management however it is not a capacity management tool.
It can be a cm tool but not a good tool for projections etc. There are many tools that claim to be cm tools but they are usually expensive and miss the basic day to day challenges of capacity management. Eg: excluding backups from day peaks, removing outliers, forward trending, accepting data from any source. Start by getting your key data extracted from reliable sources and other tools.
The charting and presentation layer is impressive and quick. It can probably do anything if you tweak it enough. I would call it a very handy tool but probably not the tool. It is not that cheap either. I have used it personally to analyze big data as well as creating knowledge from some ordinary logging. I then created some pretty cool dashboards but they were more operational dashboards.
I don't think we could afford it as a capacity tool but we can use the data it simplified.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Telecom Tech at a university with 501-1,000 employees
Easy to configure with user-friendly alerts and good search functionality
Pros and Cons
- "We can easily configure things as required in relation to our use cases."
- "From the commercial point of view, they have to bring down their costs."
What is most valuable?
We enjoy the whole solution. It is meeting our requirements, especially the SIM solution.
The alerts are very user-friendly.
We can easily configure things as required in relation to our use cases.
The search functionality is good. It works like Google.
Onboarding is quite easy.
The scalability is good.
Product-wise, the performance is good.
What needs improvement?
From the commercial point of view, they have to bring down their costs. It's a bit pricey right now. The license is quite expensive.
Much like the SOAR platform, which has security, orchestration, and automation response, all of that should be part of the SIM solution itself. Currently, it is actually separated. We understand that we have to integrate a SIM with a SOAR platform, however, if they could combine these two products together, that would be ideal. It would make things easy to implement and make more automation possible to avoid false-positive alerts.
For how long have I used the solution?
We've been using the solution for the last four years. It's been a while.
What do I think about the stability of the solution?
The performance is good. It's stable. There are no bugs or glitches. It doesn't crash or freeze.
What do I think about the scalability of the solution?
The scalability of the solution is very good. If a company needs to expand, it can do so. It's easy.
What's my experience with pricing, setup cost, and licensing?
The solution can be expensive. It's not cheap.
What other advice do I have?
We are customers and end-users.
I'd rate the solution at a nine out of ten.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Técnico Judiciário at a government with 1,001-5,000 employees
Has the ability to log more logs than similar solutions and is more efficient than its competitors
Pros and Cons
- "It can log more logs than other solutions. It's a good way to troubleshoot problems."
- "Cybersecurity and infrastructure monitoring have room for improvement."
What is our primary use case?
We use it to do SIEM.
How has it helped my organization?
It can log more logs than other solutions. It's a good way to troubleshoot problems.
What is most valuable?
Splunk is a good solution to collect more events than other solutions. It's a good solution, for me, for this reason.
What needs improvement?
Cybersecurity and infrastructure monitoring have room for improvement.
For how long have I used the solution?
Less than one year.
How was the initial setup?
On a scale from one to ten I would rate the initial setup a seven for its complexity.
Which other solutions did I evaluate?
We also looked at AlienVault.
What other advice do I have?
I would rate it an eight out of ten.
Splunk is more efficient than other solutions but it's also more expensive.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Director of Information Security with 201-500 employees
Extremely scalable but they need to make purpose-built modules more robust
Pros and Cons
- "It's extremely scalable. It's a very robust solution and certainly has the capability of handling far bigger data requirements than a lot of the other tools. Generally what ends up happening with me is that my clients tend, for the most part, to be mid-tier organizations where the cost of that solutions would be accompanying requirements for people just becomes way too prohibitive. Especially considering the model that they use for costing, which is based on the volume of data. Of course, they're going to put everything including the Coke machine as the ability to collect data off of it, because of course the more they can put through the tool the more money they make."
- "The tool itself is very difficult to configure. It's great for its number of inputs, for the different types of systems devices, and things that it could collect information from. To actually make good use of it, you need a fairly dedicated team of people that have some reasonably good programming or modeling skills to be able to do the things that you need to do with it. Whereas a lot of the other tools are better packaged for that, and so require a lot less training and a lot less dedication."
What is our primary use case?
- SIEM
- Security information
- Event management
What needs improvement?
The tool itself is very difficult to configure. It's great for its number of inputs, for the different types of systems devices, and things that it could collect information from. To actually make good use of it, you need a fairly dedicated team of people that have some reasonably good programming or modeling skills to be able to do the things that you need to do with it. Whereas a lot of the other tools are better packaged for that, and so require a lot less training and a lot less dedication.
What they need to do more than anything else is, they need to take a serious look at purpose-built modules like the SIEM and put a lot more effort into making them more robust. If they did that I think they would have a better chance on the market. The base tool was great, and if the organization that they're looking to sell into requires a good, solid logging solution then they would have a very good sales statement to make because you could get the logging solution you need that could give you the SIEM at the same time.
What do I think about the scalability of the solution?
It's extremely scalable. It's a very robust solution and certainly has the capability of handling far bigger data requirements than a lot of the other tools. Generally what ends up happening with me is that my clients tend, for the most part, to be mid-tier organizations where the cost of that solution would be accompanying requirements for people just becomes way too prohibitive. Especially considering the model that they use for costing, which is based on the volume of data. Of course, they're going to put everything including the Coke machine as the ability to collect data off of it, because of course the more they can put through the tool the more money they make.
Which solution did I use previously and why did I switch?
- AlienVault
- LogRhthym
- ArcSight
- QRadar
I've used a whole bunch of different solutions. For a SIEM based solution, they are more purpose-built for that function. Where Splunk is purpose-built for a general logging and data capture solution so you'd be able to capture a lot of different information.
How was the initial setup?
Anything that's not out of the box requires codding. Even up until recently when they finally released their SIEM or their security add-on. Before then there was not security stuff at all. I would actually have to go in and code that within the system to able to do the necessary searches to pull that information. Where a lot of the other tools, they already have those preconfigured which means I don't have to go and recreate the wheel. Now, we finally figured that out to a certain degree, and started putting the new tool in a place that gives you some SIEM functionality.
What other advice do I have?
As a logging solution, I would say it's probably an eight or nine. If you're talking about the SIEM I'd say it's probably about a five. For logging, I think they would have to change the costing model. The costing model is way out of line. It's built for very large organizations.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Buyer's Guide
Download our free Splunk Enterprise Security Report and get advice and tips from experienced pros
sharing their opinions.
Updated: December 2024
Product Categories
Security Information and Event Management (SIEM) Log Management IT Operations AnalyticsPopular Comparisons
CrowdStrike Falcon
Microsoft Sentinel
IBM Security QRadar
Elastic Security
LogRhythm SIEM
Sumo Logic Security
Rapid7 InsightIDR
Fortinet FortiSIEM
AlienVault OSSIM
Cortex XSIAM
Securonix Next-Gen SIEM
USM Anywhere
ManageEngine Log360
Buyer's Guide
Download our free Splunk Enterprise Security Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- Which would you recommend to your boss, IBM QRadar or Splunk?
- What are some of the best features and use-cases of Splunk?
- What SOC product do you recommend?
- Splunk as an Enterprise Class monitoring solution -- thoughts?
- What is the biggest difference between Dynatrace and Splunk?
- IBM QRadar is rated above competitors (McAfee, Splunk, LogRhythm) in Gartner's 2020 Magic Quandrant. Agree/Disagree?
- What are the advantages of ELK over Splunk?
- How does Splunk compare with Azure Monitor?
- New risk scoring framework in the Splunk App for Enterprise Security -- thoughts?
- Splunk vs. Elastic Stack