External reviews
External reviews are not included in the AWS star rating for the product.
Awesome SIEM Tool Small and Medium Organizations
What do you like best about the product?
Its User Friendly for beginners to maintain and come with a Built-in case management system. Also gives a response very fast for any logs which come in Splunk. It makes integration very easy for other tools and technology.
What do you dislike about the product?
The license cost of the Enterprise is prohibitive because of the budget. So the startup organization can't afford the license. It also required a very steep learning Curve. And the tricky part is Automation.
What problems is the product solving and how is that benefiting you?
The best part of the Enterprise version is that it has many features compared to the free or community versions. Which also gives a huge drop back on the security capabilities of large organizations.
- Leave a Comment |
- Mark review as helpful
Powerful SIEM
What do you like best about the product?
Splunk can do a lot many things which free to use SIEM tools do nothave. It comes with ML/AL inbuilt and can also be used with different data sources by default.
What do you dislike about the product?
The price can be a little bit costly for new start-ups. The navigation in the app also needs to be changed so that we can get to the logs/alerts faster. It is kind of resource heavy.
What problems is the product solving and how is that benefiting you?
Understanding of different logs and data sources. It also gives us trends and provides us with reports that we can use for our internal audit and monitoring of security.
Best SIEM for medium-large oragnizations
What do you like best about the product?
Easy to maintain and comes in-built case management system. Fast response for any logs which come into Splunk. Easy integration with major tools and technology.
What do you dislike about the product?
The licensing cost for the enterprise version can be costly and may not be over budget for startups. The navigation panel needs to be improve so that we can find details easily.
What problems is the product solving and how is that benefiting you?
The enterprise version has many features which the free/community version does not have. This does increase our Security capabilities in a big enterprise environment.
I really love working on slunk enterprise as it is user friendly.
What do you like best about the product?
It's GUI very gives all the features the same as the backend as well. Also, love the case management feature as well.
What do you dislike about the product?
It is pretty costly. That's the only backdrop I see.
What problems is the product solving and how is that benefiting you?
I use Splunk for SIEM and case management as well for monitoring purposes.
Splunk is very good product such a great experience while using Splunk.
What do you like best about the product?
Splunk provides excellent service because we need to cover all the tools logs and give all the expected values also while analyzing records, it provides such an excellent service.
What do you dislike about the product?
Most probably not muck dislike, but sometimes it's taking much time for the given output of queries, but the whole scenario, it's a great product. Not another aversion from my end.
What problems is the product solving and how is that benefiting you?
One Time i was an issue while catching the cloud logs from the tool console. So I used the Splunk tool, which provided me with complete records for all the required time.
A must have tool to know your environment better and troubleshoot issues
What do you like best about the product?
I use Splunk every day to troubleshoot network-related issues and identify the root cause of the problems. Splunk is a great tool to correlate the event logs from multiple sources and get a deeper understanding of what is happening in your environment. Splunk is a powerful tool to visualize the events logs and highly customizable queries, get metrics and monitor any abnormality in your environment.
What do you dislike about the product?
Due to the scale of our environment, I have observed performance issues sometimes, queries are queued, and it takes time to return the query result.
What problems is the product solving and how is that benefiting you?
Cyber threat management, even correlation, Log management, and efficient incident management.
Making Tenable.io talk to Splunk
What do you like best about the product?
Integrating Tenable.io with Splunk was far easier than I initially thought. All thanks to a nifty Plugin that does all the hard work for you.
Enter your details in the plugin for both sides of communication, and there you go. It can't get easier than that.
Enter your details in the plugin for both sides of communication, and there you go. It can't get easier than that.
What do you dislike about the product?
The plugin only worked on version 4, which gave some issues in the beginning, but after upgrading, all went well.
Only other potential issue i foresee is that newbies might get a little overwhelmed with the cheer amount of data that can be imported.
Only other potential issue i foresee is that newbies might get a little overwhelmed with the cheer amount of data that can be imported.
What problems is the product solving and how is that benefiting you?
Importing any telemetry data into Splunk makes monitoring much easier as I don't nessacarily need to log into Tenable,io and Splunk Interface. Splunk can feed me all the info I need and want
Very powerful software for data analysis
What do you like best about the product?
Easy to create quick report and custom logs
What do you dislike about the product?
The dashboard could be more streamlined and intuitive
What problems is the product solving and how is that benefiting you?
Manage, store and analyze large amount of data
Integration with Zscaler
What do you like best about the product?
GUI is very easy to understand and configure.
It will not take more than 5mins to integrate with zscaler.
We can export the logs in pdf format which is very easy to read.
It will not take more than 5mins to integrate with zscaler.
We can export the logs in pdf format which is very easy to read.
What do you dislike about the product?
Applying filters to search the logs because it is very difficult to apply the correct filter. Need some document for filters.
What problems is the product solving and how is that benefiting you?
In zscaler we can not check live logs without SIEM. So we integrated Splunk with Zscaler and that resolved our issue.
Splunk is the tool to make sense of data
What do you like best about the product?
Versatility and flexibility, a vast range of add-ons, great community and support, various options for different budgets, good integration options with various tools and vendors.
What do you dislike about the product?
Splunk is not easy to start up with and it requires good Linux and Systems skills. A very steep learning curve should be anticipated. Deployment automation can be hard or not possible at all.
What problems is the product solving and how is that benefiting you?
We use Splunk for multiple purposes: data aggregation from variuos log and stream sources, correlation and analysis, reporting and alerting. Splunk's strongest suit is to ingest unstructured data and convert it to structured, thus providing us the sense of data.
showing 31 - 40