What is our primary use case?
I work in a financial domain company where we manage customer applications and use Splunk Observability Cloud for event connectors, metrics, and traces.
We monitor our applications and track customer journeys as our metrics and traces for improving our applications' visibility and reliability of our platform.
What is most valuable?
When I compare Splunk Observability Cloud with other products available in the market, I feel it is very comprehensive.
It gives me the flexibility of parsing data, and at the same time, I can write SQL queries, search my data, have an alert mechanism, dashboards for visualizations, create reports, and monitor my infrastructure using that application.
Multiple benefits come from having Splunk.
This single product can handle my infrastructure observability end-to-end, not just for the application, but also for the underlying infrastructure.
Splunk Observability Cloud has helped to improve not just the operational performance but also the entire enterprise platform reliability, as well as the availability of the entire platform, which has greatly increased because of it.
If something is about to happen or some of my servers are having issues, Splunk triggers an alert before something actually happens in the production.
It gives me that flexibility, so I can monitor and check the health of my underlying infrastructure.
Before something major happens, it alerts me so that I can look into this, investigate, and fix it.
The out-of-the-box customizable dashboards provided by Splunk are really good.
Whatever my requirement is, whether tree leaves or chloropleth or any other kind of dashboard, they are really good.
The customization helps me to create a view that is specific to my requirement, so they are really helpful.
What needs improvement?
The tool is very good, but I feel it is very bulky.
For a huge organization, it is easy to get the license and manage costs, but for smaller organizations with just fifteen or sixteen people who have limited data ingestion, it will be a little expensive.
Managing Splunk requires professional people; you need a team to oversee the entire Splunk setup, not just one engineer.
If Splunk could provide at least a beta version that is not this enterprise-heavy, that would be a great thing.
The pros of Splunk Observability Cloud are that it is enterprise-specific and a very comprehensive and extensive tool that covers almost all wider areas where an observability platform is required.
The cons are that it is quite heavy; you require dedicated servers to handle your Splunk Enterprise instances, rather than just being able to install Splunk onto an application server or any other server.
You need a heavy infrastructure to maintain these Splunk Enterprise instances.
For how long have I used the solution?
I have been using Splunk Observability Cloud for the last six or seven years.
What do I think about the stability of the solution?
Splunk Observability Cloud is very stable.
I have never seen any glitches or experienced any lag unless the underlying server is unhealthy or the underlying infrastructure is not good; Splunk remains very stable.
What do I think about the scalability of the solution?
Splunk Observability Cloud scales very well with the growing needs of my organization.
Scaling up and scaling out is easy, but only if I know how it has been installed and how it has been set up.
I just create other instances following the same standards as the initial ones.
However, if the pre-work is not done well, then it becomes very complex.
How are customer service and support?
The technical support team of Splunk is very prompt and helpful.
There are three mechanisms to reach out to them: via call, email, or chat support.
Email responses take twenty-four hours, call support is instant, and we have opened on-demand services with this plan.
I would rate their services as eight point five out of ten.
Whenever we raise cases with the Splunk team, they are very prompt, and we have that on-demand support, which is really good.
Which solution did I use previously and why did I switch?
I have previously used Cribl, which we use very extensively along with Splunk for our observability, in addition to Grafana and an in-house tool called ELK.
How was the initial setup?
The initial setup and deployment part of Splunk Observability Cloud is complex; it is not straightforward.
To set it up in a professional way, as an enterprise would, requires a lot of professional hands.
It is not as easy as just installing and being ready to use.
To make the best use of it, everything has to be standardized.
What's my experience with pricing, setup cost, and licensing?
I find it cost-effective in larger organizations like financial companies such as Goldman Sachs, JPMorgan, or Chase. For huge enterprises, it is easy to get licenses and set up a team, which they actually need because these organizations require professional people to take care of observability.
In reference to smaller startups with just fifteen employees whose requirements are not much but want to set up observability, it may be different.
However, for my organization, it is very cost-effective.
Which other solutions did I evaluate?
I directly purchased Splunk from Splunk Enterprise, not through the AWS Marketplace.
What other advice do I have?
I am using Splunk, Cribl, ELK, and Grafana.
These are the platforms that I am using.
The customizable dashboards in Splunk are definitely helpful when it comes to showcasing IT performance to business leaders.
The reason is that leadership does not have much time to go through events and summaries, so they visualize.
When we present anything in visualized form, it is catchy and easy for them to look into the KPIs and metrics rather than going through the entire data and summary.
I do not think there are any missing features in Splunk that I would like to see included in the future.
As far as I have explored Splunk, I feel it is a very comprehensive tool.
It does not miss out on anything.
I would give a really positive review about the No-Sample Tracing feature in Splunk.
It is a good feature that Splunk has.
Having this AI-powered analytics and guidance from Splunk helps me in issue resolutions.
Splunk has that AI capability, which aids in writing the queries, and if I want to create something, instead of navigating and doing it myself, I can just create a prompt, and the prompt helps me to create those kinds of features in my Splunk.
We are using the ability to enrich data with custom metrics in Splunk Observability Cloud.
We create Excel files, upload them, and that reads specific items, enriches the data, and removes duplicates and unnecessary events, providing the key-value pairs that are actually required for us. It is very helpful.
My advice for others looking into implementing Splunk Observability Cloud is straightforward.
If a person who is purchasing Splunk Enterprise has more than five hundred users, it is good to go for it.
Splunk Observability Cloud is very effective.
If I were to rate it out of ten, I would generally give it somewhere around eight or eight point five.
Splunk Observability Cloud has effectively helped me lower my downtime.
Since I have a platform that is constantly monitoring my infrastructure and keeping an eye on the health and metrics of my infrastructure, if any applications or servers are about to go down, there is a lot of noise on that specific infrastructure, and it triggers an alert so that I know what is about to happen.
I can investigate that before something actually breaks.
At the same time, if something goes down, I actually know the root cause of where it has broken.
It has helped me greatly.
Instead of investigating end-to-end, I know the root cause prior and where to look into, so it has helped us a lot.
I gave this review a rating of nine out of ten.