Sign in
Categories
Your Saved List Become a Channel Partner Sell in AWS Marketplace Amazon Web Services Home Help

Splunk Enterprise

Splunk | 9.2.1

Linux/Unix, Amazon Linux 2 - 64-bit Amazon Machine Image (AMI)

Reviews from AWS Marketplace

14 AWS reviews

External reviews

402 reviews
from G2

External reviews are not included in the AWS star rating for the product.


    Haibo Y.

Really good for identifying the production issues

  • March 28, 2016
  • Review verified by G2

What do you like best about the product?
Every time when we have production issues, the 1st thing is to open the splunk and check the error messages.
The other feature is also nice: keep tracking the production environment health status periodically. We did find some potential issues which our client did not report and fix them before our clients finding.
What do you dislike about the product?
The way of displaying the error log sometimes take time to scroll it when opening the item.
What problems is the product solving and how is that benefiting you?
Checking the production health status.
Quickly identifing the errors
Recommendations to others considering the product:
Quickly identifing the errors, periodically checking the production health status and performance. It works really well


    Computer Software

Splunk is the de facto leader

  • March 24, 2016
  • Review verified by G2

What do you like best about the product?
* search bar and query language
* integrations / add ons
* source code access to splunk enterprise
* source code access to any splunk app
What do you dislike about the product?
* no real good support or process for app development and publishing
* app development is kind of weird and difficult
* really hard to debug configs and/or searches
* splunk doesn't have a solid identity anymore
* overly sales-heavy organisation; hard to find someone to actually help you
* documentation is written in a vacuum mostly, especially in respect to how to run / size it
* big learning curve for users slows adoption
* crap 2FA / SAML / enterprise auth support
* no publicly visible bug or feature request database
What problems is the product solving and how is that benefiting you?
* great flexibility in investigations
* decent return on investment
Recommendations to others considering the product:
come with an open mind, and open pockets


    Doug Toppin

Excellent for trying out Splunk

  • September 03, 2015
  • Review verified by AWS Marketplace

I wanted to try out a few add-ons to Splunk and this worked perfectly for me. Having an AMI with a ready to go Splunk server and MongoDB combined with a recommended security group made it very easy to start using immediately. I was also able to install the Splunk Mobile Access Server on this instance and connected using the associated iOS and Android apps. If I had any recommendation for Splunk it would be to include the MAS on this AMI as well.
No complaints at all.


    Chad Brigance

More time splunking. Less time installing.

  • June 12, 2015
  • Review verified by AWS Marketplace

Up and running with Splunk in minutes. This was so easy it was not even funny. It look me longer to set up data feeds than it did preparing Splunk to receive them.

Totally thrilled and pleased. This was a life saver.

Splunk's home for indexes is on the root partition by default. 8GB of SSD storage for the / partition will probably not be enough for you.

Add a 500GB or 1TB magnetic volume and move splunk's index home there before you get started.


    AWS Admins

Good but not ready for Production

  • June 03, 2015
  • Review verified by AWS Marketplace

I liked the fact that there was a splunk AMI and you can spin up splunk really fast. I was able to build an instance and be up in a matter of minutes. The issues I have with the AMI is that there is currently no support for the new C4 instances. I wanted to build a beefy splunk server with the latest CPUs since searches are CPU heavy and I'm not able to do that now. I also noticed that the AMI does not address disabling Transparent Huge Pages which splunk recommends. This can cause a 30% performance degradation. http://docs.splunk.com/Documentation/Splunk/6.2.3/ReleaseNotes/SplunkandTHP

So, because I couldn't use the instance I wanted, I can't really use this AMI for my needs. I can use it for testing no problem though. The THP issues is not that big because you can disable it easy enough but if splunk is touting this AMI as a recommended configuration I would like to see the THP addressed since it causes performance issues.


    David Greenwood

One-click Splunk!

  • March 12, 2015
  • Review verified by AWS Marketplace

From no Splunk to Splunk in minutes. I was able to start collecting and analysing my data within the hour.