We used it to create a full security operations center (SOC) for our IT department by adding all network and security devices, the AD, and mail servers to it. Then Splunk started to receive their logs, it analyzed them, and provided useful reports.
BS Systems Engineer at a tech services company with 501-1,000 employees
Makes use of all logs and takes proactive actions
Pros and Cons
- "Integrity with many vendors: This simplifies the implementation and integration with different devices"
- "Enterprise security: Splunk must work on clarifying the solution to customers and explain how to gain more from it."
What is our primary use case?
How has it helped my organization?
It helps the IT staff to monitor the full structure. It also makes use of all logs and takes proactive actions.
What is most valuable?
Integrity with many vendors: This simplifies the implementation and integration with different devices.
What needs improvement?
Enterprise security: Splunk must work on clarifying the solution to customers and explain how to gain more from it.
Buyer's Guide
Splunk Enterprise Security
December 2024
Learn what your peers think about Splunk Enterprise Security. Get advice and tips from experienced pros sharing their opinions. Updated: December 2024.
831,020 professionals have used our research since 2012.
For how long have I used the solution?
One to three years.
Disclosure: My company has a business relationship with this vendor other than being a customer: We are a partner with Splunk.
Technical Director at a consultancy with 11-50 employees
It allows us to store raw data and use it repeatedly for different domains.
How has it helped my organization?
We are using it for operational intelligence. We are using Splunk as a data lake for machine data. We gather all our machine data from the IT infrastructure and monitor its health.
What is most valuable?
Splunk's schema-on-read technology is one of the most valuable characteristics of this solution. It allows us to store raw data and use it repeatedly for different domains. You don't need to prepare the data upfront.
Splunk's Search Processing Language (SPL) is another beneficial feature. It is a very powerful tool that gives you the ability to do almost anything with your data.
What needs improvement?
Visualizations can improve. There are some performance and stability issues with the visualization layer.
What do I think about the stability of the solution?
There were stability issues, but only with the visualization layer.
What do I think about the scalability of the solution?
There were no scalability issues.
How are customer service and technical support?
The technical support is quite good.
Which solution did I use previously and why did I switch?
Previously, we worked with different vendors and solutions.
How was the initial setup?
The setup was very straightforward.
What's my experience with pricing, setup cost, and licensing?
The price is pretty high for our region.
Which other solutions did I evaluate?
We did a SIEM solutions review with this and other systems for one of our customers.
What other advice do I have?
This is the right choice if you are looking for a platform that can combine all machine-generated data and use it for various use cases from different domains.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Buyer's Guide
Splunk Enterprise Security
December 2024
Learn what your peers think about Splunk Enterprise Security. Get advice and tips from experienced pros sharing their opinions. Updated: December 2024.
831,020 professionals have used our research since 2012.
Enterprise Client Executive at a tech services company with 11-50 employees
Good user community, good support, and very powerful
Pros and Cons
- "The Splunk user community and forum are most valuable."
- "Its interface could be improved."
What is our primary use case?
We use it for security operations and management.
What is most valuable?
The Splunk user community and forum are most valuable.
What needs improvement?
Its interface could be improved.
For how long have I used the solution?
We have been a reseller for three years.
What do I think about the stability of the solution?
It is stable. It is very powerful.
How are customer service and support?
Their support is good.
How was the initial setup?
Its initial setup is complex. You're going to need deployment services from somebody who is an expert in the product. You would need at least two users.
What other advice do I have?
It is hard to integrate because it can do so many things. A lot of people think it is a set-it-and-forget-it solution, but it is a full-time job for somebody. I would advise others to plan and prepare for ongoing management. It requires a dedicated person for management.
Compared to other SIEMs, it is a 10 out of 10.
Disclosure: My company has a business relationship with this vendor other than being a customer:
Engineer at a integrator with 11-50 employees
Has the ability to add the functionality you want but it is expensive
Pros and Cons
- "The initial setup is really straightforward. It's one of the easiest installations."
- "They should make data onboarding easier."
What is our primary use case?
Our primary use case is for monitoring and cybersecurity.
What needs improvement?
The clusters are hard. It has too many moving parts.
They should make data onboarding easier.
For how long have I used the solution?
One to three years.
What do I think about the scalability of the solution?
Its ability to scale nicely is one of Splunk's strengths. You just horizontally add another machine and you get your scalability.
How are customer service and technical support?
Which solution did I use previously and why did I switch?
Our clients switch from Nagios or other monitoring solutions because the other solutions were not as flexible as Splunk. With Splunk, you can do things very programmatically. With a help of a developer and included SDK you can add needed functionality.
How was the initial setup?
The initial setup is really straightforward. It's one of the easiest installations.
This product doesn't have any kind of dependencies, it just worked from one package. Install it and boom, you have a working solution.
What about the implementation team?
What's my experience with pricing, setup cost, and licensing?
Splunk is on expensive side.
There are some premium add-ons like Splunk Enterprise Security or ITSI which makes it more expensive.
What other advice do I have?
I would advise to get Splunk professional services from Splunk.
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner.
IT Infrastructure Architect at a tech company with 201-500 employees
Does event matching between several appliances and correlates data from different sources.
What is most valuable?
- Event matching between several appliances
- Correlating data from different sources
- Report viewer
How has it helped my organization?
It helps us to detect viruses and security events from our network.
What needs improvement?
It needs documentation, and "how-to-do" information. It's complicated to build reports and views.
For how long have I used the solution?
I have used Splunk for about two years.
What do I think about the stability of the solution?
There were no stability issues. It was running on a VM over Hyper-V.
What do I think about the scalability of the solution?
There were no scalability issues. It was running on a VM over Hyper-V.
How are customer service and technical support?
I used support a little bit for some templates for formatting data from Cisco and Fortinet logs. They were very fast with their response. I didn't have any support contract, but only entry level support.
Which solution did I use previously and why did I switch?
This was our first try for log analysis.
How was the initial setup?
The setup was easy.
What's my experience with pricing, setup cost, and licensing?
There is nothing to say. At that time, it was for GBs of data received.
Which other solutions did I evaluate?
We did not look at alternatives. It was a consulting provider recommendation. It was a rapid implementation to accomplish legal requirements. After we used it for a while, we decided to keep it.
What other advice do I have?
Check for the plugin to format data of already completed templates for the appliance to which you want to keep logs and events.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Cyber Security Consultant at a computer software company with 11-50 employees
Customizable and has average installation difficulty
Pros and Cons
- "I have found the installation can be of medium difficulty to very complex depending on the use case."
- "There is improvement needed when importing from some types of data sources."
What needs improvement?
There is improvement needed when importing from some types of data sources. Most of the time you have to do some customization for the data because not everything is working the way it should. Additionally, in other solutions, it is easier to build use cases.
For how long have I used the solution?
I have been using this solution for approximately three years.
Which solution did I use previously and why did I switch?
I have previously used Curator and it was much easier to use than this solution.
How was the initial setup?
I have found the installation can be of medium difficulty to very complex depending on the use case. It is not easy for new customers. You need to have the experience to be able to do it.
What other advice do I have?
When using this solution for Security Information Management(SIM), I highly recommend importing data sources from the whole cycle for the service security chain. Some people only use main inputs and not all of the data sources they have. They might not have some data sources, in this case, you can purchase one or there are free open-source ones available. You will then have this data source that can enrich your life because many correlations are done with this data.
I rate Splunk an eight out of ten.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Fast and easy to use, but could be faster
Pros and Cons
- "The solution is very fast and succinct."
- "I feel the solution to be too slow."
What is most valuable?
The solution is very fast and succinct.
What needs improvement?
When it comes to out of the box use cases, I feel the solution to be too slow.
For how long have I used the solution?
I have not been working with Splunk for long.
How was the initial setup?
The initial setup was simple.
It took an hour.
Which other solutions did I evaluate?
Curator is more scalable than certain other solutions.
What other advice do I have?
We are partners of Splunk and provide the solution to customers.
I feel Splunk is easy to utilize.
My company has an app. on which the solution is deployed on-premises on a single server.
There is another team in my company that works with Splunk products.
I rate Splunk as a seven-point-five out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Project Manager at a comms service provider with 10,001+ employees
This solution has an ability to do a quick search and immediately stop an incident from happening.
Pros and Cons
- "It has virtual visualization, and other products do not."
- "We had an instance when Splunk failed and it took us a couple of days to recover."
What is our primary use case?
My primary use case for Splunk is for log file visualization and monitoring alert management.
How has it helped my organization?
The way this solution has improved our organization is by its ability to do a quick search and immediately stop an incident from happening.
What is most valuable?
The auto-notification abilities are a huge benefit for us.
What needs improvement?
After a crash, the product takes a while to recover.
For how long have I used the solution?
One to three years.
What do I think about the stability of the solution?
Sometimes we have had instances when it will not run for a couple of days. There is room for improvement here.
What was our ROI?
There are lots of use cases and features that make Splunk a good choice for us.
What's my experience with pricing, setup cost, and licensing?
I have no opinion on the pricing of the product.
Which other solutions did I evaluate?
We considered Datadog and Zabbix. In comparison to those options, Splunk has virtual visualization. Furthermore, it can be a host on our environment. Typically, we cannot deploy SaaS on our environment, but with Splunk, we can.
What other advice do I have?
When Splunk failed, it took time to recover. We had to recover it from a snapshot. It took a couple of days, and it was as if it had crashed. But, the instance was resolved.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Buyer's Guide
Download our free Splunk Enterprise Security Report and get advice and tips from experienced pros
sharing their opinions.
Updated: December 2024
Product Categories
Security Information and Event Management (SIEM) Log Management IT Operations AnalyticsPopular Comparisons
CrowdStrike Falcon
Microsoft Sentinel
IBM Security QRadar
Elastic Security
LogRhythm SIEM
Sumo Logic Security
Rapid7 InsightIDR
Fortinet FortiSIEM
AlienVault OSSIM
Cortex XSIAM
Securonix Next-Gen SIEM
USM Anywhere
ManageEngine Log360
Buyer's Guide
Download our free Splunk Enterprise Security Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- Which would you recommend to your boss, IBM QRadar or Splunk?
- What are some of the best features and use-cases of Splunk?
- What SOC product do you recommend?
- Splunk as an Enterprise Class monitoring solution -- thoughts?
- What is the biggest difference between Dynatrace and Splunk?
- IBM QRadar is rated above competitors (McAfee, Splunk, LogRhythm) in Gartner's 2020 Magic Quandrant. Agree/Disagree?
- What are the advantages of ELK over Splunk?
- How does Splunk compare with Azure Monitor?
- New risk scoring framework in the Splunk App for Enterprise Security -- thoughts?
- Splunk vs. Elastic Stack
Splunk's schema-on-read technology is one of the most valuable characteristics of this solution. It allows us to store raw data and use it repeatedly for different domains. You don't need to prepare the data upfront.