Can be useful, but difficult UI
What do you like best about the product?
It is useful to have a tool available that is for searching through logs. This makes finding errors in different environments including production or qa environments more streamlined and easier to track.
What do you dislike about the product?
The UI of splunk is not great. The indication that a search is searching is not super obvious. It took me a while to notice the very thin blur status bar. And learning to search with splunk takes reading the tutorials and playing around because it is not very intuitive.
What problems is the product solving and how is that benefiting you?
Splunk makes searching through logs easier. This makes finding bugs or large errors faster, and also makes tracking what happened in your application (when things were created and or modified) easier.
Recommendations to others considering the product:
I think it is a good buy for enterprise customers. If you work at a big company and need something tested that your legal team won't freak out over this could be a good option. I think for smaller startups you should shop around more before signing up.
Good Product; will not say the best
What do you like best about the product?
migrated to splunk within the last year from an internal inbuilt tool (don't know who made the decision to switch because i personally loved the internal one). It is definitely simple to use and a great way to look for logs for any production issues. The mobile support is a great way to keep up. Lets you customize the search strings that you specifically need and if you are developer, its a great way to pin-point to the exact trace.
What do you dislike about the product?
Quite Expensive; would prefer to have more customization especially with regard to date format. Need better dashboard facilities that can provide diverse reporting/analytics. Learning curve.
What problems is the product solving and how is that benefiting you?
centralizing the logging to one tool; we wanted something that can combine our website as well as mobile apps logging.
Recommendations to others considering the product:
check if its the right tool by using the trial version because its expensive to get; but has a lot of cool stuff that you could do with logs. Definitely a tool every dev/ops guys want
A great tool for monitoring log records in systems
What do you like best about the product?
The integration tools made it very easy to consume log files and track performance as well as order throughput. It made some unwieldy data very manageable with reporting, tracking and internal algorithms to track order closure as well as system to system performance.
What do you dislike about the product?
Once you see it work, there is not much to dislike
What problems is the product solving and how is that benefiting you?
We produce copious amounts of log records - which are helpful for troubleshooting.
The amount of data was too large to really use it for performance benchmarking or order tracking.
The Splunk tools and UI make it easy to see what you need when you need it.
Recommendations to others considering the product:
Try it out first - and if you don't see your grasp of the data and what it tells you then look again. It saves you huge amounts of time when tracking order closure and followthrough rates.
Vital for Mobile Apps
What do you like best about the product?
Splunk is a great tool to monitor apps performance. It has really accurate information, simple and clear dashboards and it is pretty easy to use. Furthermore, it has a really good dashboard for errors with an spectacular stacktrace tool that allows you to symbolicate code.
What do you dislike about the product?
In Mint Splunk you can not customise the metrics. For example, if you are checking popular OS for an App you can only retrieve five results. The same happens with popular App versions or most used devices.
What problems is the product solving and how is that benefiting you?
Splunk is perfect for us to check out mobile app performances. It really helps us to find out errors, crashes and bugs. It also help us to retrieve important metrics about sessions.
Recommendations to others considering the product:
It is a great tool that can be combined with NewRelic, Datadog or metrics retrieved by Google/Apple stores.
My experience with splunk
What do you like best about the product?
It is quite fast, programmable with python easy to use. It takes only 40 50 min to draw really complicated graphs with it
What do you dislike about the product?
IT is quite expensive comparing with elk stack and their business model is really weak. The second most important think is that they do not have data tables to represent information filter by fields etc.
What problems is the product solving and how is that benefiting you?
we are trying to collect all logs and alert teams with them depending on the rule we wrote.
Really good for identifying the production issues
What do you like best about the product?
Every time when we have production issues, the 1st thing is to open the splunk and check the error messages.
The other feature is also nice: keep tracking the production environment health status periodically. We did find some potential issues which our client did not report and fix them before our clients finding.
What do you dislike about the product?
The way of displaying the error log sometimes take time to scroll it when opening the item.
What problems is the product solving and how is that benefiting you?
Checking the production health status.
Quickly identifing the errors
Recommendations to others considering the product:
Quickly identifing the errors, periodically checking the production health status and performance. It works really well
Splunk is the de facto leader
What do you like best about the product?
* search bar and query language
* integrations / add ons
* source code access to splunk enterprise
* source code access to any splunk app
What do you dislike about the product?
* no real good support or process for app development and publishing
* app development is kind of weird and difficult
* really hard to debug configs and/or searches
* splunk doesn't have a solid identity anymore
* overly sales-heavy organisation; hard to find someone to actually help you
* documentation is written in a vacuum mostly, especially in respect to how to run / size it
* big learning curve for users slows adoption
* crap 2FA / SAML / enterprise auth support
* no publicly visible bug or feature request database
What problems is the product solving and how is that benefiting you?
* great flexibility in investigations
* decent return on investment
Recommendations to others considering the product:
come with an open mind, and open pockets
Excellent for trying out Splunk
I wanted to try out a few add-ons to Splunk and this worked perfectly for me. Having an AMI with a ready to go Splunk server and MongoDB combined with a recommended security group made it very easy to start using immediately. I was also able to install the Splunk Mobile Access Server on this instance and connected using the associated iOS and Android apps. If I had any recommendation for Splunk it would be to include the MAS on this AMI as well.
No complaints at all.
More time splunking. Less time installing.
Up and running with Splunk in minutes. This was so easy it was not even funny. It look me longer to set up data feeds than it did preparing Splunk to receive them.
Totally thrilled and pleased. This was a life saver.
Splunk's home for indexes is on the root partition by default. 8GB of SSD storage for the / partition will probably not be enough for you.
Add a 500GB or 1TB magnetic volume and move splunk's index home there before you get started.
Good but not ready for Production
I liked the fact that there was a splunk AMI and you can spin up splunk really fast. I was able to build an instance and be up in a matter of minutes. The issues I have with the AMI is that there is currently no support for the new C4 instances. I wanted to build a beefy splunk server with the latest CPUs since searches are CPU heavy and I'm not able to do that now. I also noticed that the AMI does not address disabling Transparent Huge Pages which splunk recommends. This can cause a 30% performance degradation. http://docs.splunk.com/Documentation/Splunk/6.2.3/ReleaseNotes/SplunkandTHP
So, because I couldn't use the instance I wanted, I can't really use this AMI for my needs. I can use it for testing no problem though. The THP issues is not that big because you can disable it easy enough but if splunk is touting this AMI as a recommended configuration I would like to see the THP addressed since it causes performance issues.