We use the solution mainly for security operations. We receive logs from different log sources.
Splunk Enterprise
SplunkExternal reviews
External reviews are not included in the AWS star rating for the product.
The product is very easy to use, the GUI is simple, and the technical support is responsive
What is our primary use case?
What is most valuable?
The product is very easy to use. We just have to run the agent and collect the log. We don't have many delays or problems. We faced an issue once or twice when there was a network issue and when the system was rebooted. The percentage of issues is very low compared to the overall deployment. It is 0.001%.
The solution supports our organization's security and compliance monitoring very much. We rely on the platform to detect abnormalities and to perform searches. If someone brings a compliance issue, we request logs from the platform to determine whether it happened. We use the tool’s search feature and Intel's machine learning platform to conduct our analysis.
We don't face any issues in real-time monitoring. There is no latency. We have options to create our own dashboards. The GUI is very simple. It's a simple platform. It is very easy to use.
What needs improvement?
The product doesn’t have prebuilt dashboards. It would be great if the product provided prebuilt dashboards. For example, we allowed some devices into our network through VPN, but there is no dashboard to combine two log sources and understand which user has logged in. So, we created our own dashboard with the available Splunk searches.
It’d be good if the solution provided more prebuilt dashboards and released them on the app platform. Then, we can deploy the dashboards straight away. Also, if the tool provides additional dashboards, we can reduce the resources needed to develop them. Since Splunk has overall visibility all around the globe, it can give better suggestions on the dashboards that we must use and how to project the data to the management.
We faced some issues in parsing when the load was too much. If we have a 100 MB log source, 80 MB will be parsed correctly, but we face issues with 20 MB. We raised a support ticket, and the support team suggested we increase the time interval between sending the logs to the Splunk forwarder to handle the processing correctly.
For how long have I used the solution?
I have been using the solution for two years. I am using the latest version of the solution.
What do I think about the stability of the solution?
The tool is stable enough. In my demo environment, I used my own physical machines to run it. I was able to ingest as many log sources as I wanted within the data limit, and it did not have any issues. The search is very responsive when compared to the other platforms. There was no lag.
Splunk has been supporting free text searches for two years. We can query anything out of the box without specifying any indexes. We can perform free-text queries. Usually, it takes very little time to produce the results if the data set is too small. If the data set is too large, the product suggests we finetune our search, and it provides us with hints on which indexes to specify. It has three different options: Fast mode, Push mode, and Smart mode. We can switch the modes to get results quicker. Later, we can change the mode back to do a deeper analysis.
What do I think about the scalability of the solution?
Scalability is not an issue for SMBs and moderately big companies. When we went beyond certain limits, like 700 Gbps or 800 Gbps, we faced some issues with the engine. So, we split up the platform and diverted some of the logs into different indexes. It solved the problem. Up to 500 Gbps per day is okay. When we go beyond that, a single instance cannot handle it. We need to split it up.
This issue was only with the on-premise version. We do not face such issues in the cloud. When customers wanted to renew their subscriptions, we suggested they move to the cloud. On-premise, we have to manage our indexes and searches, but in the cloud, it's done by the vendor. It's a plug-and-play process. Splunk automatically takes care of parsing. We have more than 30 customers.
How are customer service and support?
The technical support is very good. The team supported us even during the Christmas holidays. The support engineer walked us through every step. The team is always reachable. We never had issues while contacting them.
How was the initial setup?
I built some demo environments for my practice since Splunk was new to me two years ago. I used the free license. It was a pretty straightforward setup. I did not find any difficulties in setting up my lab environment. The deployment can be done within 15 minutes.
What was our ROI?
The return on investment is very good. It's very easy to use. Many of our customers decided to continue using Splunk because they have invested much in the training modules, the analysts are familiar with the tool, and it's very easy to search. Open-text queries are the best in Splunk. It is easy for our customers to perform the search. It's very lightweight compared to other solutions.
What's my experience with pricing, setup cost, and licensing?
Our customers pay for the licenses. It’s bundled together in a yearly subscription.
What other advice do I have?
There are some problems in managing the tool when it exceeds certain limits. Overall, I rate the product a nine out of ten.
Review-Splunk
Easy to configure and set Alerts.
If you stuck, people around you know about this platform and can help.
Convinient.
We can use custom dashboards and use it as per our need.
we can integrate this with Microsoft Exchange and get realtime messages/emails.
Splunk Enterprise - All in one platform for analyzing and monitoring data
It is easy to integrate with number of applications like Jira,AWS,Splunk security,etc.
Can be easily used by all team members to analyze data for indexing and searching.
It can be implemented with other splunk services.
It has great customer support available via chat,email,chatbot,slack,etc.
It can be frequently used by various team members for different roles.
1. For large enterprise it is costly and has to buy license for all employees to access the application.
2. Desktop application is faster than the web application so sometimes it crash.
Splunk's performance in the financial industry is really amazing
one of the most reliable SIEM solution
A powerful tool for point-in-time security detection with stability
What is our primary use case?
We use Splunk Enterprise Platform for point-in-time security detection. It can be applied to security and IT operations scenarios, offering control and insight into user activity, registration processes, and customer data.
What is most valuable?
The solution has a status query and feed. I can reach them by phone at the residential. It is stable and has a fast response.
What needs improvement?
The product is expensive.
What do I think about the stability of the solution?
The product is stable.
I rate the solution’s stability a nine out of ten.
What other advice do I have?
Splunk Enterprise is a powerful platform. It's a leader in its field with a large and active community. Users can access support in various ways, including forums and documentation.
Overall, I rate the solution an eight out of ten.
A highly scalable solution that can be used for security, IT monitoring, and observability
What is most valuable?
Splunk Enterprise Platform can be used for security, IT monitoring, and observability.
What needs improvement?
The solution’s pricing could be improved.
For how long have I used the solution?
I have been working with Splunk Enterprise Platform for six years.
What do I think about the stability of the solution?
Splunk Enterprise Platform is a stable solution.
I rate the solution an eight or nine out of ten for stability.
What do I think about the scalability of the solution?
Splunk Enterprise Platform has very high scalability.
What's my experience with pricing, setup cost, and licensing?
Customers need to pay a yearly licensing fee for Splunk Enterprise Platform.
On a scale from one to ten, where one is cheap, and ten is expensive, I rate the solution's pricing around seven or eight out of ten.
What other advice do I have?
I would recommend Splunk Enterprise Platform to other users.
Overall, I rate Splunk Enterprise Platform an eight out of ten.
Splunk
A scalable tool that offers SIEM and SOAR functionalities to users
What is our primary use case?
Splunk Enterprise Platform is useful as a tool for its SIEM and SOAR functionalities.
What is most valuable?
The most valuable features of the solution stem from the fact that it provides local support to users in Indonesia. The features that Splunk Enterprise Platform provides to users are the same as the ones provided by ArcSight, so I cannot compare both products.
What needs improvement?
The solution has certain shortcomings when it comes to APIs, making it in an area where improvements are required.
Integration is an area that can be considered as one of the challenges we face with the solution in our company. From an improvement perspective, the solution should make the integration of the product with other tools in the market possible.
For how long have I used the solution?
I have been using Splunk Enterprise Platform for almost three years.
What do I think about the stability of the solution?
It is a stable solution. The product stays stable from the development stage to the production environment. Stability-wise, I rate the solution an eight out of ten.
What do I think about the scalability of the solution?
It is a scalable solution.
Around 1,400 employees in our company use the solution.
My company does plan to increase the use of the solution.
Which solution did I use previously and why did I switch?
I have experience with ArcSight.
How was the initial setup?
The product's initial setup phase was very complex.
During the product's first time deployment, the product is dispatched to the user for assessment, after which a user can deploy it and take care of the areas from implementation to production.
The solution is deployed on a hybrid cloud.
The solution can be deployed in three to five months.
Around seven people are required to manage the deployment and maintenance of the product.
What about the implementation team?
The deployment can be carried out with the help of our company's in-house team.
What's my experience with pricing, setup cost, and licensing?
There are yearly payments to be made towards the licensing costs attached to the solution.
What other advice do I have?
I can recommend the product after considering the needs and budget of the customers, as well as the company's size.
I rate the overall tool an eight out of ten.