My primary use case for Splunk is for log file visualization and monitoring alert management.
Project Manager at a comms service provider with 10,001+ employees
This solution has an ability to do a quick search and immediately stop an incident from happening.
Pros and Cons
- "It has virtual visualization, and other products do not."
- "We had an instance when Splunk failed and it took us a couple of days to recover."
What is our primary use case?
How has it helped my organization?
The way this solution has improved our organization is by its ability to do a quick search and immediately stop an incident from happening.
What is most valuable?
The auto-notification abilities are a huge benefit for us.
What needs improvement?
After a crash, the product takes a while to recover.
Buyer's Guide
Splunk Enterprise Security
November 2024
Learn what your peers think about Splunk Enterprise Security. Get advice and tips from experienced pros sharing their opinions. Updated: November 2024.
823,795 professionals have used our research since 2012.
For how long have I used the solution?
One to three years.
What do I think about the stability of the solution?
Sometimes we have had instances when it will not run for a couple of days. There is room for improvement here.
What was our ROI?
There are lots of use cases and features that make Splunk a good choice for us.
What's my experience with pricing, setup cost, and licensing?
I have no opinion on the pricing of the product.
Which other solutions did I evaluate?
We considered Datadog and Zabbix. In comparison to those options, Splunk has virtual visualization. Furthermore, it can be a host on our environment. Typically, we cannot deploy SaaS on our environment, but with Splunk, we can.
What other advice do I have?
When Splunk failed, it took time to recover. We had to recover it from a snapshot. It took a couple of days, and it was as if it had crashed. But, the instance was resolved.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
The search function for splunk is like a google search, you just enter and it will quickly show you the results
Pros and Cons
- "The search function for spam is like a google search. You just enter and it will quickly show you the results."
- "Spam has different plugins but by default, the logs are not organized, it shows that there are roll-ups that are out of the box. I saw many plugins that can help improve or extend Splunk's functionality but I haven't tried any of them."
What is our primary use case?
Our primary use case of this solution is as a centralized lab collection.
What is most valuable?
The search function for splunk is like a google search. You just enter and it will quickly show you the results.
What needs improvement?
Splunk has different plugins but by default, the logs are not organized, it shows that there are roll-ups that are out of the box. I saw many plugins that can help improve or extend Splunk's functionality but I haven't tried many of them.
It would be best if they can incorporate all security locks with minimal incidents.
For how long have I used the solution?
One to three years.
What do I think about the scalability of the solution?
It's a little hard to scale on-prem.
How was the initial setup?
The initial setup was easy. It took us one to two days.
What's my experience with pricing, setup cost, and licensing?
It's a little bit expensive for a small to medium enterprise.
Which other solutions did I evaluate?
We also looked at AlienVault.
What other advice do I have?
I would rate this solution an eight out of ten. To make it a ten they should have more integration with outside vendors.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Buyer's Guide
Splunk Enterprise Security
November 2024
Learn what your peers think about Splunk Enterprise Security. Get advice and tips from experienced pros sharing their opinions. Updated: November 2024.
823,795 professionals have used our research since 2012.
Data Scientist at a tech vendor with 201-500 employees
Offers the ability to analyse huge amounts of sales data and accurate prediction of sales forecasting
Pros and Cons
- "The ability to analyze huge amounts of sales data and accurate prediction of sales forecasting is the most valuable feature."
- "Splunk needs to be able to hold more days of data. At the moment it only holds three months of data."
What is our primary use case?
We use a lot of sales metrics. We use machine learning models to provide sales forecasting. We create database connections and run a query on the database. The next step is to place the data into Splunk. We create indexes to get the data into the Splunk dashboard.
What is most valuable?
The ability to analyze huge amounts of sales data and accurate prediction of sales forecasting is the most valuable feature.
What needs improvement?
Splunk needs to be able to hold more days of data. At the moment it only holds three months of data. It needs more views and colors within the dashboard and the ability to have the flexibility to create a user-defined panel.
For how long have I used the solution?
We have been using Splunk for a year.
What do I think about the stability of the solution?
The stability of Splunk is good enough.
What do I think about the scalability of the solution?
I think it's good, other than the ability to hold more than three months of data is lacking.
How was the initial setup?
The setup of Splunk was easy.
What about the implementation team?
There are six people in my team working with Splunk. I am not sure about other users, but we are a mix of data scientists, data engineers, software engineers, IT, and software engineers.
What other advice do I have?
I would rate Splunk as 8 out of 10.
Which deployment model are you using for this solution?
On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Security Professional at a tech services company with 51-200 employees
Good data analysis and visualizations, absolutely stable, and scalable
Pros and Cons
- "The data analysis part is good in Splunk, which is something that I like the most. It is also quite easy to use. Its dashboards, visualizations, and analytics are good."
- "It currently has limited default rules and customizations. If they can concentrate more on the compliance part and the security information part, it would be helpful. The platform part is good, but it requires many features from the security aspect."
What is our primary use case?
We are using it for security information and event management (SIEM). We have started to use Splunk recently, and we are in the implementation phase as of now.
What is most valuable?
The data analysis part is good in Splunk, which is something that I like the most. It is also quite easy to use. Its dashboards, visualizations, and analytics are good.
What needs improvement?
It currently has limited default rules and customizations. If they can concentrate more on the compliance part and the security information part, it would be helpful. The platform part is good, but it requires many features from the security aspect.
For how long have I used the solution?
I have been using this solution for a couple of months.
What do I think about the stability of the solution?
It is absolutely stable.
What do I think about the scalability of the solution?
It is scalable. We have approximately 25 users.
How was the initial setup?
It was easy to install. Its configuration and development are the critical parts, and there are a limited number of people in the market with such a skill set. It takes some time to find people with the right skill set and get it implemented properly. It took approximately three months.
What about the implementation team?
I have a team of a few Splunk consultants who are currently managing it for me. For a mid-sized organization, at least 15 persons are required to manage the entire Splunk instance.
What other advice do I have?
I would recommend this solution to others. I would rate Splunk an eight out of ten.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Enterprise Architect and Business with 5,001-10,000 employees
It is easy to use, and easy to implement.
Pros and Cons
- "This solution helps us increase our productivity."
- "It is easy to use, and easy to implement."
- "I would like to see ability to master management. In terms of clustering, how it manages clustering needs improvement."
What is our primary use case?
It helps increase our productivity.
How has it helped my organization?
We are saving a lot of time by being in one place instead of several servers.
What is most valuable?
The most valuable features are understanding the visualization compass on the dashboard, as well as the reports on the dashboards.
What needs improvement?
I would like to have the ability to master the management of clustering.
For how long have I used the solution?
One to three years.
How was the initial setup?
It is easy to implement.
What other advice do I have?
It is easy to use, and easy to implement.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Buyer's Guide
Download our free Splunk Enterprise Security Report and get advice and tips from experienced pros
sharing their opinions.
Updated: November 2024
Product Categories
Security Information and Event Management (SIEM) Log Management IT Operations AnalyticsPopular Comparisons
CrowdStrike Falcon
Microsoft Sentinel
IBM Security QRadar
Elastic Security
LogRhythm SIEM
Sumo Logic Security
Rapid7 InsightIDR
Fortinet FortiSIEM
AlienVault OSSIM
Cortex XSIAM
Securonix Next-Gen SIEM
USM Anywhere
Buyer's Guide
Download our free Splunk Enterprise Security Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- What are some of the best features and use-cases of Splunk?
- What SOC product do you recommend?
- Splunk as an Enterprise Class monitoring solution -- thoughts?
- What is the biggest difference between Dynatrace and Splunk?
- IBM QRadar is rated above competitors (McAfee, Splunk, LogRhythm) in Gartner's 2020 Magic Quandrant. Agree/Disagree?
- What are the advantages of ELK over Splunk?
- How does Splunk compare with Azure Monitor?
- New risk scoring framework in the Splunk App for Enterprise Security -- thoughts?
- Splunk vs. Elastic Stack
- What is a better choice, Splunk or Azure Sentinel?