Try our new research platform with insights from 80,000+ expert users
PeerSpot user
SVP, Technical Operations at a tech vendor with 201-500 employees
Vendor
Splunk has great interoperability with other applications through their SplunkBase app store.

What is most valuable?

Splunk has great interoperability with other applications through their SplunkBase app store. The apps can quickly provide visibility and streamline complex data mining tasks.

What needs improvement?

Unlike other cloud based analytics platforms, at the time of this writing Splunk Cloud is a dedicated instance per customer rather than a shared tenancy platform. While this is beneficial from an overall performance standpoint, the product lacks the seamless integrations one has come to expect from a cloud solution. This translates to a much stronger reliance on Splunk's support organization out of necessity, as the customer cannot make most changes in a self-service manner.

For how long have I used the solution?

We have been a Splunk customer for five years.

What was my experience with deployment of the solution?

Our Splunk Cloud deployment was a migration from an on-premise implementation of Splunk. The migration took much longer than expected due to constraints within Splunk's cloud team, but there were no technical issues with the launch.

Buyer's Guide
Splunk Enterprise Security
August 2024
Learn what your peers think about Splunk Enterprise Security. Get advice and tips from experienced pros sharing their opinions. Updated: August 2024.
800,688 professionals have used our research since 2012.

How are customer service and support?

Customer Service:

The customer support team at Splunk is very good.

Technical Support:

The technical support team at Splunk is highly responsive and knowledgeable.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Cyber Security Consultant at a computer software company with 11-50 employees
MSP
Customizable and has average installation difficulty
Pros and Cons
  • "I have found the installation can be of medium difficulty to very complex depending on the use case."
  • "There is improvement needed when importing from some types of data sources."

What needs improvement?

There is improvement needed when importing from some types of data sources. Most of the time you have to do some customization for the data because not everything is working the way it should. Additionally, in other solutions, it is easier to build use cases.

For how long have I used the solution?

I have been using this solution for approximately three years.

Which solution did I use previously and why did I switch?

I have previously used Curator and it was much easier to use than this solution.

How was the initial setup?

I have found the installation can be of medium difficulty to very complex depending on the use case. It is not easy for new customers. You need to have the experience to be able to do it.

What other advice do I have?

When using this solution for Security Information Management(SIM), I highly recommend importing data sources from the whole cycle for the service security chain. Some people only use main inputs and not all of the data sources they have. They might not have some data sources, in this case, you can purchase one or there are free open-source ones available. You will then have this data source that can enrich your life because many correlations are done with this data. 

I rate Splunk an eight out of ten.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Buyer's Guide
Splunk Enterprise Security
August 2024
Learn what your peers think about Splunk Enterprise Security. Get advice and tips from experienced pros sharing their opinions. Updated: August 2024.
800,688 professionals have used our research since 2012.
Security Professional at a tech services company with 51-200 employees
Real User
Good data analysis and visualizations, absolutely stable, and scalable
Pros and Cons
  • "The data analysis part is good in Splunk, which is something that I like the most. It is also quite easy to use. Its dashboards, visualizations, and analytics are good."
  • "It currently has limited default rules and customizations. If they can concentrate more on the compliance part and the security information part, it would be helpful. The platform part is good, but it requires many features from the security aspect."

What is our primary use case?

We are using it for security information and event management (SIEM). We have started to use Splunk recently, and we are in the implementation phase as of now.

What is most valuable?

The data analysis part is good in Splunk, which is something that I like the most. It is also quite easy to use. Its dashboards, visualizations, and analytics are good.

What needs improvement?

It currently has limited default rules and customizations. If they can concentrate more on the compliance part and the security information part, it would be helpful. The platform part is good, but it requires many features from the security aspect.

For how long have I used the solution?

I have been using this solution for a couple of months.

What do I think about the stability of the solution?

It is absolutely stable.

What do I think about the scalability of the solution?

It is scalable. We have approximately 25 users.

How was the initial setup?

It was easy to install. Its configuration and development are the critical parts, and there are a limited number of people in the market with such a skill set. It takes some time to find people with the right skill set and get it implemented properly. It took approximately three months.

What about the implementation team?

I have a team of a few Splunk consultants who are currently managing it for me. For a mid-sized organization, at least 15 persons are required to manage the entire Splunk instance.

What other advice do I have?

I would recommend this solution to others. I would rate Splunk an eight out of ten.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Engineer at a integrator with 11-50 employees
Real User
Has the ability to add the functionality you want but it is expensive
Pros and Cons
  • "The initial setup is really straightforward. It's one of the easiest installations."
  • "They should make data onboarding easier."

What is our primary use case?

Our primary use case is for monitoring and cybersecurity.

What needs improvement?

The clusters are hard. It has too many moving parts. 

They should make data onboarding easier.

For how long have I used the solution?

One to three years.

What do I think about the scalability of the solution?

Its ability to scale nicely is one of Splunk's strengths. You just horizontally add another machine and you get your scalability.

How are customer service and technical support?


Which solution did I use previously and why did I switch?

Our clients switch from Nagios or other monitoring solutions because the other solutions were not as flexible as Splunk. With Splunk, you can do things very programmatically. With a help of a developer and included SDK you can add needed functionality.

How was the initial setup?

The initial setup is really straightforward. It's one of the easiest installations. 

This product doesn't have any kind of dependencies, it just worked from one package. Install it and boom, you have a working solution.

What about the implementation team?


What's my experience with pricing, setup cost, and licensing?

Splunk is on expensive side.

There are some premium add-ons like Splunk Enterprise Security or ITSI which makes it more expensive.

What other advice do I have?

I would advise to get Splunk professional services from Splunk.

Disclosure: My company has a business relationship with this vendor other than being a customer: Partner.
PeerSpot user
it_user1048674 - PeerSpot reviewer
Cyber Analyst with 501-1,000 employees
Real User
It has the ability to correlate results

What is our primary use case?

Testing for insider threat behavior.

How has it helped my organization?

It gave management confidence in current operations.

What is most valuable?

The ability to correlate results.

What needs improvement?

A few more analysis aids might help. The next release could have more intuitive help examples.

For how long have I used the solution?

One to three years.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
it_user363165 - PeerSpot reviewer
Products Manager at a tech services company with 5,001-10,000 employees
MSP
Valuable features include rapid search, data mining, and information propagation. The GUI should be improved.

What is most valuable?

Rapid search is a valuable feature. Performance and incident response were the top priorities for most MSSPs. Breaches of SLAs will have a negative impact on customer trust, which eventually leads to losing customer confidence on services to which they’re subscribing. Hence, the proactive approaches will be the main differentiator from one MSSP to the others.

How has it helped my organization?

It has been helping a lot of my clients with fast data mining and information propagation.

What needs improvement?

The GUI should be improved, in other words, the overall appearance.

For how long have I used the solution?

I am not the end-user. However, my job was more relevant as a consultant.

What do I think about the stability of the solution?

Performance upgrades are needed when more processing power is required.

What do I think about the scalability of the solution?

We have not had scalability issues.

How are customer service and technical support?

Technical support is good.

Which solution did I use previously and why did I switch?

The client was using an open source solution. They decided to switch to an enterprise product.

How was the initial setup?

The setup can be straightforward, if use cases are well defined.

What's my experience with pricing, setup cost, and licensing?

Overall, it the cost is reasonable and it is easy to upgrade.

Which other solutions did I evaluate?

Our client was considering the other solutions as well. However, due to their overall assessment, they still considered going with it.

What other advice do I have?

Start off with something at a comfortable level, expand gradually, and then move upwards, expanding steadily.

Disclosure: My company has a business relationship with this vendor other than being a customer: We are a distributor.
PeerSpot user
Project Manager at a comms service provider with 10,001+ employees
Real User
This solution has an ability to do a quick search and immediately stop an incident from happening.
Pros and Cons
  • "It has virtual visualization, and other products do not."
  • "We had an instance when Splunk failed and it took us a couple of days to recover."

What is our primary use case?

My primary use case for Splunk is for log file visualization and monitoring alert management.

How has it helped my organization?

The way this solution has improved our organization is by its ability to do a quick search and immediately stop an incident from happening.

What is most valuable?

The auto-notification abilities are a huge benefit for us.

What needs improvement?

After a crash, the product takes a while to recover.

For how long have I used the solution?

One to three years.

What do I think about the stability of the solution?

Sometimes we have had instances when it will not run for a couple of days. There is room for improvement here.

What was our ROI?

There are lots of use cases and features that make Splunk a good choice for us.

What's my experience with pricing, setup cost, and licensing?

I have no opinion on the pricing of the product. 

Which other solutions did I evaluate?

We considered Datadog and Zabbix. In comparison to those options, Splunk has virtual visualization. Furthermore, it can be a host on our environment. Typically, we cannot deploy SaaS on our environment, but with Splunk, we can. 

What other advice do I have?

When Splunk failed, it took time to recover. We had to recover it from a snapshot. It took a couple of days, and it was as if it had crashed.  But, the instance was resolved.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Net Sec at a tech services company with 11-50 employees
Real User
The search function for splunk is like a google search, you just enter and it will quickly show you the results
Pros and Cons
  • "The search function for spam is like a google search. You just enter and it will quickly show you the results."
  • "Spam has different plugins but by default, the logs are not organized, it shows that there are roll-ups that are out of the box. I saw many plugins that can help improve or extend Splunk's functionality but I haven't tried any of them."

What is our primary use case?

Our primary use case of this solution is as a centralized lab collection.

What is most valuable?

The search function for splunk is like a google search. You just enter and it will quickly show you the results. 

What needs improvement?

Splunk has different plugins but by default, the logs are not organized, it shows that there are roll-ups that are out of the box. I saw many plugins that can help improve or extend Splunk's functionality but I haven't tried many of them.

It would be best if they can incorporate all security locks with minimal incidents. 

For how long have I used the solution?

One to three years.

What do I think about the scalability of the solution?

It's a little hard to scale on-prem. 

How was the initial setup?

The initial setup was easy. It took us one to two days. 

What's my experience with pricing, setup cost, and licensing?

It's a little bit expensive for a small to medium enterprise.

Which other solutions did I evaluate?

We also looked at AlienVault.

What other advice do I have?

I would rate this solution an eight out of ten. To make it a ten they should have more integration with outside vendors. 

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Buyer's Guide
Download our free Splunk Enterprise Security Report and get advice and tips from experienced pros sharing their opinions.
Updated: August 2024
Buyer's Guide
Download our free Splunk Enterprise Security Report and get advice and tips from experienced pros sharing their opinions.