Splunk IT Cloud
What do you like best about the product?
It's one of the top notch search engine which is best in competitor.
What do you dislike about the product?
Lenghty process of replicating any events.
What problems is the product solving and how is that benefiting you?
It is helping our organisation in correlation of different logs and giving the output as required by the analyst.
Nice experience overall
What do you like best about the product?
Helps to build custom metrics to code it yourself properly
What do you dislike about the product?
Not feasible for large data volumes.difficult to setup
What problems is the product solving and how is that benefiting you?
Better data processing and storage
Splunk IT cloud review
What do you like best about the product?
Splunk IT is one of the leading SIEM tool with robust feature which helps to drill out minute details for any investigations. It comes with good visualization options with easy understanding of data.
What do you dislike about the product?
Running different scripts for fetching details is very time taking. Also, it is very costly compared to other SIEM platforms.
What problems is the product solving and how is that benefiting you?
It is helping to build multiple visualizations dashboards with respect to incidents, investigations, tracking malicious content and integration with multiple solutions gives easy tracking of different data within the organization.
Splunk IT cloud
What do you like best about the product?
Splunk IT comes under one of the leading SIEM solution, as it has robust feature to drill out minute details for any occurrences.
What do you dislike about the product?
For fetching any details one has to run different scripts which is not common at every time and it needs to be remebered.
What problems is the product solving and how is that benefiting you?
Quering, automation, corelation engine
Splunkd
What do you like best about the product?
Centralized log management for all windows, Linux, network logs
What do you dislike about the product?
Splunk IT Cloud doesn't have anything to dislike.
What problems is the product solving and how is that benefiting you?
Centralized log management tool to store the historical logs.
Splunk IT cloud with Azure
What do you like best about the product?
Splunk IT cloud seems very helpful while working on Azure cloud. Redis data, response time, cpu and memory for the required data helps alot in monitoring. Writing query and river flow structure monitoring seems helpful to me in comparison to other monitoring tools
What do you dislike about the product?
Cribil changes has always troubled me. Also sometimes, creating query with rex has little issues. Main trouble is regex while creating my own field doesn't seems to be working proper as I did yesterday.
What problems is the product solving and how is that benefiting you?
Monitoring over the other tools is quite not familiar and flexible for the users. Data for each second gives you good view and clearance regarding the logs in performance testing. So it is actually helping much better
Make staff's jobs better for resiliency purposes, reporting, and whatever they need to do
What is our primary use case?
We're looking to migrate an acquisition into the Splunk environment. We acquired a company and their Splunk environment was small and separate. We didn't want to have to maintain old Windows environments in unique use cases so we wanted to migrate it to the cloud as a proof of concept.
In their case, they had global data domicile requirements. We didn't have the same global deployment for our other larger environment that they did. So it made sense for us to migrate them to a bunch of small cloud stacks that were globally positioned rather than deploy a bunch of tiny enterprise environments to do the same thing.
The solutions are segregated at the moment. We're currently migrating the ACS environment. We have our own Splunk Enterprise implementation that we still use for Azure currently. It's fine, it doesn't drop.
How has it helped my organization?
It has definitely improved our organization by virtue of reducing the amount of overhead we would have had for those environments. Having to implement, maintain, or even update the existing stuff would have been extremely time-consuming. Splunk Cloud handles all of that for us. So it's definitely been helpful from that perspective. It's allowed them to maintain upgrades for far further than they are. Some of the hosts of that environment were still on version 7 so they could get upgraded feature parity.
They do well at empowering staff by providing business resilience. Users have the capability to utilize Splunk in ways to make their jobs better for resiliency purposes, reporting, and whatever it is that they need to do. Splunk is a very powerful platform in that way.
What is most valuable?
In their case, they had global data domicile requirements. We didn't have the same global deployment for our other larger environment that they did. So it made sense for us to migrate them to a bunch of small cloud stacks that were globally positioned rather than deploy a bunch of tiny enterprise environments to do the same thing.
It's pretty important to us that Splunk has end-to-end visibility to our native cloud environment. We need to be able to figure out where the points of failure are. Knowing whether it's a forward, on our end, an index, the cloud environment, a firewall, or something else entirely is important to troubleshooting that kind of process.
Splunk has helped to reduce our mean time to resolve. For the specific use case, the ability to bring in more Splunk data and market makes work consistently accessible.
I think that Splunk's ability to predict, identify and solve problems in real time is better than what we use it for. Our observability journey is still pretty early so we haven't done a lot of predictive detection that is possible to do with Splunk. It looks like it can do the things that we needed to do in a pretty effective way. We just haven't done that yet.
What needs improvement?
Some of the implementation is challenging. They're not very proxy-aware. Their recommendation is to set up an intermediate forward in a DMZ environment or something like that. That's not always the most convenient way to do things. It would be better if we could use an HTTP proxy, send data out via HEC, HTTP, or in a way that is proxy-aware.
For how long have I used the solution?
We did the POC six months to a year ago. We've been in the process of migrating some smaller use cases over the last three or four months.
What do I think about the stability of the solution?
We haven't used it a lot but it's been pretty stable.
How are customer service and support?
Splunk support is pretty good. There's some work to be done. When I provide them with a bunch of data, they don't need to ask me some of the initial questions. But otherwise, they're pretty good.
How would you rate customer service and support?
What was our ROI?
I have seen ROI. The adoption of the company has increased dramatically. We have hundreds of alerts, hundreds of reports, and hundreds of dashboards that people use for their business cases, whether it's deliverables, resiliency, or troubleshooting.
What's my experience with pricing, setup cost, and licensing?
Splunk is expensive. We have had some challenges in ensuring that all data is available in Splunk due to its cost. It has definitely proven its value in the data that we have brought in. From a resiliency and reporting perspective, those things are all very valuable. But it's certainly not the most cost-effective product in the world.
It is a valuable product, but it is certainly challenging at times to be able to bring in as much data as I would want due to the cost of the product.
What other advice do I have?
I would rate Splunk Cloud Platform an eight out of ten.
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Amazon Web Services (AWS)
We have good visibility and we don't have to maintain the infrastructure
What is our primary use case?
We collect almost everything that we log and push it into the Splunk Cloud Platform. That is pretty much our use case. It is mostly for our cyber monitoring tool, firewalls, normal cyber logs, Windows event logs, etc.
How has it helped my organization?
Splunk Cloud Platform has helped improve our organization's business resilience a little bit. It is a big organization, and I am just a little part of it. Its impact on the whole business has been a little bit.
We use ES for correlation, incident handling, and things like that. It reduces the mean time to resolve a little bit as compared to the other SIEMs that we were using. We are not using SOAR right now, but that is where we want to be.
What is most valuable?
I like the fact that we do not have to maintain all the cloud infrastructure. That is probably the main thing about the Splunk Cloud Platform. We do not have to worry about maintaining the infrastructure that is out there. We just push things up and maintain our infrastructure on-premises. This is important for us because we just do not have the manpower and resources to manage all the infrastructure.
We used to use another SIEM with which we constantly had to replace hardware and things like that, so it is a good benefit to have that cloud infrastructure there whether it is coming from a SaaS environment or we just build it in the cloud.
What needs improvement?
One thing that is a stickler for us is the ability to download apps. I guess it depends on what kind of license you have. It allows some of them if I want, but this is something that we need on a day-to-day basis. When one of my customers needs an app, and I am able to find that app on the Splunk base, I have to create a ticket and wait for five days for them to download the app into the cloud environment. That is probably one of the main things. It is painful because I have to wait to get that app in the cloud.
Another issue is that if I build my own app to some configuration, I cannot load it up there myself. They have to vet it, which is important but it takes a long time to do all that.
For how long have I used the solution?
We have been using this solution for a little less than one year.
What do I think about the stability of the solution?
What do I think about the scalability of the solution?
Scalability does not apply to our environment. Because it is a cloud, scalability is relative to how much you can afford. It scales itself if your data increases because it is a cloud environment.
How are customer service and support?
Splunk's support is very good, but because the cloud environment was pretty new, I ran into a couple of stumbling blocks with the support for the Splunk Cloud Platform. However, it started to get a lot better. Currently, it is a lot better than when I first started. At that time, a lot of the support staff was probably new to the whole cloud environment, and I realized that. We were the first DOD department to go into the cloud, so it was tough in the beginning with their support. I would rate them a nine out of ten.
How would you rate customer service and support?
Which solution did I use previously and why did I switch?
We were using ArcSight. The decision to switch to Splunk did not come from me. It was the decision of the company itself. It was a requirement. We could not track the up/down status with the other SIEM. Splunk can do that better. That was one thing.
Another thing was the way Splunk can put things like MITRE ATT&CK into their platform. The way it handles rules and things like that makes it a lot better with the processing power. Splunk is search-based, whereas ArcSight is real-time. It fires the minute an event comes up, whereas Splunk has a separate way of doing it. They run a search every hour or so. It is not resource intensive. A lot of times, I can only turn on a minimum amount of rules, especially correlation rules, in ArcSight. I used to have about 300 or so in ArcSight. I probably have about 400 or 500 in Splunk, so the hardware processing power is a lot better.
How was the initial setup?
I was involved in its deployment. Its complexity level was 50/50, but that was expected because of the lack of training initially. We had an awesome team from Splunk that helped us out. They were there for us for at least a month. They helped us and then trained us on the environment. By the time they left, we were good to go.
What was our ROI?
The return on investment is not in a monetary sense. Things are a lot less stressful in our environment. We are able to see things that we were not able to see before. It gives us a little calm because we know if something is up or down. We are able to see things that we could not see before in other SIEMs. So, there is a reduction in the stress level.
We have seen a time to value. I can do plenty of things a lot faster than I could previously.
Which other solutions did I evaluate?
We evaluated Sentinel, QRadar, and LogRhythm. All of them were very good SIEMs, but we had a lot of challenges when it came to getting them certified on government L5. IBM has its own private cloud. They do not use AWS. We did not have that issue with Sentinel, but it is not as robust. Even though it is at a high level in terms of industry-level SIEM, it could not meet our requirements. It is still a challenge. Sentinel is the only one that is a competition to Splunk if you talk about cloud, not on-premises. It is native to the cloud.
What other advice do I have?
It is awesome. I love it. Anything is possible in Splunk. I have gone through a lot of challenges with use cases. When I needed to figure something out, I got it resolved sooner or later. I either got Splunk support or I went to the community and looked it up. I have never run into anything that I could not do with Splunk. It is very good.
Overall, I would rate the Splunk Cloud Platform a nine out of ten.
Has end-to-end visibility in our native environments
What is our primary use case?
We're migrating our on-prem environment to Splunk Cloud Platform. We're consolidating two separate Spark clusters because of a merger. Our primary use case is for unifying all of that data into one place.
How has it helped my organization?
It's made searching for data easier. Users like it. We're still in the migration process, but overall, it's a lot easier to use.
What is most valuable?
It's important to use that Splunk has end-to-end visibility in our native environments. We have to have that visibility because we manage multiple app applications that rely on it.
Splunk helped to improve our organization's business resilience. That's very important to us. Our users rely on Splunk heavily for the health of their applications. It helps them to get ahead of issues, and if there is an outage, it enables them to resolve them faster.
Splunk gives the different application owners the ability to configure alerting specific to their needs so they can customize it however they want. If they know their applications better than you know, admins, I'll give them that flexibility.
What needs improvement?
The administration could use improvement. We have to rely on support more often than we're used to.
For how long have I used the solution?
We have been using Splunk Cloud Platform for nine months.
What do I think about the stability of the solution?
Stability has so far been good. We haven't had any issues.
How are customer service and support?
Their support is great, especially the agent that we have now. They're very responsive, willing to help out, and give suggestions.
How would you rate customer service and support?
Which solution did I use previously and why did I switch?
We previously used Splunk Enterprise. We switched to Cloud Platform because we wanted to consolidate a couple of instances to one place and we're moving our security team to the cloud.
How was the initial setup?
I wasn't involved in the setup directly but I was aware of what they were doing. The setup is a little complex. We had some issues we had to deal with. Bringing both environments together and getting the different environments to communicate with Splunk Cloud was complex. We have a lot of data. Getting a handle on that before we were able to start sending data to the cloud was complex.
What's my experience with pricing, setup cost, and licensing?
It's expensive. We're still trying to figure out Cloud licensing.
What other advice do I have?
It's not so easy to monitor multi-cloud environments using Splunk. We have some difficulties, but we have some things in place, but it's not easy.
I would rate Splunk Cloud Platform an eight out of ten. There's a lot we haven't tapped into yet, so the rating can go up.
Reduces troubleshooting time and improves customer experience
What is our primary use case?
We use it for security monitoring and application monitoring.
How has it helped my organization?
We monitor multiple cloud environments. We monitor AWS and Oracle Cloud. It is easy to get all the data into Splunk from our AWS and Oracle Cloud. The integration is comparatively easy when it comes to on-prem versus Splunk Cloud.
It has end-to-end visibility into our cloud-native environment, which is pretty important for us. About 80% of our infrastructure is on AWS. It is pretty important for our digital resiliency to monitor our AWS and Oracle Cloud platforms end to end.
It definitely reduces our mean time to resolve, but I am not sure exactly how much time it has reduced because as a Splunk Cloud customer, we provide our platform to our application teams.
What is most valuable?
We have Splunk Enterprise Security and our regular Splunk Enterprise. We use Splunk Enterprise Security for monitoring all our security use cases and our regular Splunk Enterprise for application monitoring. We have our own custom digital apps that we monitor on the enterprise cloud, and all our enterprise security monitoring happens on the Splunk Enterprise Security app. There are so many custom applications that we currently support.
We do digital transaction monitoring, so when a customer sends some money to a different customer, we monitor the end-to-end transaction of that customer when it happens on the digital platform. It is pretty important for our L1 and L2 teams to monitor that end-to-end transaction.
With Splunk in place, we can identify the bottlenecks where transactions are getting held and immediately take necessary actions to release the transaction and reach the customer. That improves the transaction time frame. There is improvement in terms of how many analysts are monitoring how many transactions and how fast transactions are happening from end to end. It improves our performance and customer experience. It is also easy to monitor end to end transactions.
What needs improvement?
They can offer more self-service capability to their customers. Currently, most of the things happen behind the Splunk Cloud Platform. As a customer, I do not have an opportunity to see my platform. If they can offer more self-service to see the health of my endpoints and stack, it would be appreciated.
Their support also needs improvement. I have had issues with the support team. When I run into issues, it is always hard to get hold of them and get things done with the support team. Other than that, product-wise, it is very good.
For how long have I used the solution?
I have been using the Splunk Cloud Platform for more than four years.
What do I think about the stability of the solution?
Its stability is 99.5%, but I have had pretty bad incidents in the last couple of years. Last month, we had an outage for the whole day. Support-wise, I am not happy.
What do I think about the scalability of the solution?
In typical cloud infrastructure, you can add your EC2 on demand based on the load of your customers, but with the Splunk Cloud, that is not the case. They assign a fixed number of searches and indexes. They have named it as a cloud, but it is still an on-prem instance sitting in their cloud, so in terms of scalability, I do not see much advantage with Splunk Cloud because, at the end of the day, you get approval from your Splunk account team or a management team to add a new instance into your cluster.
How are customer service and support?
The support that we get from Splunk is not always great. Whenever we have issues, we have to chase them to get the answers. When we have an incident, identifying the root cause of that incident with the Splunk Cloud support team is always a pain. The Splunk team should improve their customer support experience. I love the product, but the only issue is getting support. I would rate them a three out of ten.
How would you rate customer service and support?
Which solution did I use previously and why did I switch?
We had IBM QRadar, and we moved from IBM QRadar to Splunk Cloud. Cost-wise, Splunk is a premium solution. We pay more, but we get a better experience with Splunk Cloud Platform. It is easy to manage. There is a better user experience. When it comes to identifying issues, it is pretty easy with Splunk. Cost-wise, we have not saved much, but in terms of resiliency and digital experience, we get a lot from Splunk.
We get a lot of capabilities with Splunk Cloud and Splunk Enterprise Security. We also do application monitoring, and we wanted to embed both solutions into one. That is the whole reason we got Splunk.
We have a bunch of tools, not just Splunk, in our ecosystem. Splunk is one of our tools for monitoring purposes. We have other tools for alert management, global alert repository, etc. In our ecosystem, Splunk serves the main purpose of detecting and bringing the issues to our analysts to resolve them. Splunk plays a vital role.
How was the initial setup?
I was initially involved in the whole migration process. We used to have the Splunk on-prem instance, and only application teams were utilizing it. We bought the Splunk Cloud Platform, and we merged both the application and security into the Splunk Cloud Platform.
Cloud deployment is pretty easy because you do not have to manage any of your infrastructure. They take care of that.
What was our ROI?
We could see its time to value in roughly one year to sixteen months. We started the migration and moved to the cloud, and in a year to sixteen months, we could see a return on investment.
The ROI is in terms of the mean time to resolve the issues. We could do all of our security monitoring and enterprise security. We integrated security monitoring with our SOAR platform. We have so many L1 and L2 teams using Splunk day in and day out to monitor the transactions. They definitely have more visibility and reduced mean time to resolve the issues. They can identify an issue pretty fast.
What's my experience with pricing, setup cost, and licensing?
Currently, we have the ingest-based license. They are offering SVC-based licenses as well, but I am not a fan of SVC-based licensing. At the end of the day, I want to predict my budget and how much I am going to pay to the vendor so that I can plan my yearly budget.
I would always suggest going with the ingest-based license because you can control how much you want to ingest. It feels like you will be paying less when you switch to SVC-based licensing, but this is not true because you cannot control your users and what kind of searches they want to run. If you go for that, you will need a whole lot of manual effort to control your users.
Which other solutions did I evaluate?
We evaluated Elasticsearch. We evaluated Exabeam. We evaluated one more solution. Among all the solutions in the market, Splunk is the best.
The good thing with Splunk is that you can search your data across all the indexes pretty fast. The way the processing language works with Splunk is awesome. Most of my analysts can search the data as quickly as possible, whereas, with the other solution, there was always a lag while searching for data. With Elasticsearch, you have very limited capability to search across the whole platform. It is very easy with Splunk. The secret sauce of Splunk is the way they index the data. That is the main difference between Splunk and its competitors.
What other advice do I have?
I would rate the Splunk Cloud Platform a nine out of ten. The product is good. The only issue is the support.
The primary benefit that I get from attending the Splunk Conference is to be able to see all the new features that Splunk is releasing and how to use them and implement them in my infrastructure, platform, or ecosystem. I also get to know how other organizations are using Splunk to solve their use cases. Another thing is that we have so many vendors utilizing Splunk as their base and building so many new products. I visited one of the booths, and I was very impressed with their booth. They are doing all the content validation, security validation, and simulation of attacks. They are using their tool, and they have integrated it with Splunk. They are bringing all the data into Splunk to showcase how to maintain the hygiene of the content. That impressed me a lot. When I attend Splunk conferences, I get to see how others are utilizing Splunk as their base and building new tools out of that. It gives me some ideas of how to implement it in our organization. Of course, we cannot implement everything, but at least we can see the best fit for our platform.