We leverage the Splunk Cloud Platform for log ingestion. This allows us to create dashboards, alerts, and reports from security and application log data.
Splunk Cloud [Private Offer Only]
Carahsoft Technology Corp.External reviews
External reviews are not included in the AWS star rating for the product.
Offers real-time monitoring, seamless integration, and improves security posture
What is our primary use case?
How has it helped my organization?
Splunk Cloud Platform offers real-time monitoring capabilities. It continuously ingests data from various sources, allowing us to track its flow. We can set up alerts to be notified of any anomalies, such as spikes in CPU or memory usage. These alerts can be configured to trigger email notifications, keeping us informed of potential issues. Additionally, Splunk Cloud Platform provides real-time dashboards that visualize the data as it's collected.
The federated search feature is useful for our cybersecurity team to complete their log analysis.
Splunk Cloud Platform offers seamless integration with other systems and applications. This is achieved through apps and add-ons developed by Splunk.
Splunk is a good reporting tool. It allows us to generate reports and attach them to emails in CSV or PDF format.
Splunk Cloud Platform has been instrumental in helping our cybersecurity team continuously monitor our data for anomalies and attacks. Its usefulness extends beyond security, though. Teams that ingest their logs into Splunk can monitor various services. If a service goes down, Splunk will trigger an alert. Splunk offers a robust monitoring suite, including dashboards, alerts, and reports. We can monitor system resources like memory and CPU consumption, application logs, Azure logs, and even Office 365 logs. For example, Splunk can reveal who sent emails, who participated in group email threads, and who added or removed members from Active Directory groups. This audit log capability allows us to investigate activity even months or years later. Splunk provides a wide range of use cases for our organization. We noticed these benefits as soon as Splunk started ingesting data.
Splunk has improved our decision-making process thanks to its clear dashboards that help us analyze information and make informed choices.
Splunk has been valuable as a compliance tool because it centralizes log ingestion. Any tool generating logs should be configured to send them to Splunk. This allows us to easily identify compliant applications – those whose logs are collected. Conversely, uncollected logs raise security concerns, as they represent a potential attack surface.
Splunk has significantly improved our organization's security posture. As a primary security tool, Splunk allows us to collect application logs, monitor activity for potential attacks, and conduct searches to identify suspicious behavior.
What is most valuable?
I like that Splunk Cloud Platform is managed by the vendor.
I like the Cloud monitoring console feature.
I like the support for all the apps and add-ons.
What needs improvement?
Splunk currently manages the components, which restricts our ability to access them directly. I would like to be granted read access to be able to review the components.
For how long have I used the solution?
I have been using Splunk Cloud Platform for one and a half years.
What do I think about the stability of the solution?
The Splunk Cloud Platform is stable as long as we perform proper maintenance to prevent bugs.
What do I think about the scalability of the solution?
This system is very scalable. That means it can be easily adapted to accommodate our needs. We can increase the number of licenses we use, or add more resources like CPU and memory. We can also request additional components, such as adding more user accounts if our team grows from four to eight members. Overall, the scalability of this system is a major advantage.
I would rate the scalability of Splunk Cloud Platform nine out of ten.
How are customer service and support?
Splunk Cloud Platform offers excellent technical support that is both knowledgeable and responsive.
How would you rate customer service and support?
Positive
How was the initial setup?
The initial setup is straightforward but it takes a month or two to complete because of the applications that need to be onboarded.
We first need to calculate the amount of data we need to ingest. Then, based on that amount, we can plan how much data we need to onboard and what components we'll need.
Two experienced people were involved in the deployment.
What about the implementation team?
The implementation was completed in-house.
What's my experience with pricing, setup cost, and licensing?
Splunk Cloud Platform is more expensive than some of its competitors, but it offers a wider range of features.
What other advice do I have?
I would rate the Splunk Cloud Platform eight out of ten.
Splunk Cloud Platform is deployed in multiple locations.
Splunk Cloud Platform requires maintenance.
I recommend the Splunk Cloud Platform to others.
If you're using cloud services, Splunk Cloud Platform is a good option. It minimizes management overhead for you since Splunk handles the underlying infrastructure. Splunk Enterprise however requires more resources to manage.
Helps to improve our incident response time, provides multiple search modes, and is stable
What is our primary use case?
My manager typically requests dashboards, alerts, and scheduled reports. Based on their specific requirements, I create reports and dashboards that visualize the data. We leverage the Splunk Cloud Platform to fulfill these needs.
Additionally, my teammates may approach me for insights. I analyze the data and provide them with these insights, which they then use for team meetings and further data analysis. This ultimately helps them make informed decisions.
How has it helped my organization?
Splunk Cloud Platform improves our incident response time by enabling the retrieval of large data volumes. The platform offers impressive search speeds, and we don't need additional SQL commands to optimize response times.
We saw immediate benefits from the Splunk Cloud Platform. Being able to access and analyze logs provided valuable insights.
Splunk's impact on decision-making is significant. I have access to all the data I need, and it is always reliable.
What is most valuable?
Splunk Cloud Platform's search modes are a powerful feature. There are 3 main modes: Fast, Verbose, and Smart. These modes allow us to customize our search based on our needs, which can significantly improve our response time.
What needs improvement?
Splunk Cloud Platform's dashboard could benefit from some improvements. While it functions adequately, it appears very minimalistic. It's built using a simple XML format, and while newer dashboard options have been released, it still lacks the visual capabilities of tools like Power BI and Tableau. While I understand these are different platforms, having a more powerful dashboard option for the Splunk Cloud Platform would be valuable.
There is a lack of comprehensive learning materials offered by Splunk to prepare for their certifications.
Splunk uses SQL as its search language. One challenge I've encountered is with subsearches used in joins. These subsearches can only handle a maximum of 50,000 entries. If our data set is larger, we won't be able to join it using a subsearch. This limitation has been a significant obstacle for me. I've searched the Splunk community forums, and even reached out to my colleagues and seniors for a solution, but haven't found a definitive answer yet.
For how long have I used the solution?
I have been using Splunk Cloud Platform for 2 years.
What do I think about the stability of the solution?
It is reliable. In my experience working with virtual machines, any search lags are likely due to the VMs themselves, not Splunk.
I would rate the stability 8 out of 10.
What do I think about the scalability of the solution?
Splunk Cloud Platform is horizontal scaling. So it is easy to scale based on the data we are using.
I would rate the scalability of Splunk Cloud Platform 9 out of 10.
How was the initial setup?
Deploying Splunk Cloud Platform requires knowledge of the Splunk architecture, the deployment server, and the components.
What was our ROI?
We have seen a return on investment.
What's my experience with pricing, setup cost, and licensing?
The certifications are costly.
What other advice do I have?
I would rate Splunk Cloud Platform 8 out of 10.
The maintenance required is minimal.
The resilience of Splunk is good.
I recommend the product.
Splunk Cloud Platform is a powerful tool for handling big data. To get the most out of it, understanding both the developer and administrator sides is beneficial. The platform offers broad compatibility with various technologies and allows for easy scaling to accommodate your needs.
Speeds up our response and reduces the time we spend manually monitoring any logs for ticketing tools or servers
What is our primary use case?
We use Splunk Cloud for monitoring various ticketing tools, servers, applications, URLs, and client transactions. We're monitoring the transactions and data flow.
How has it helped my organization?
Splunk has sped up our response and reduced the time we spend manually monitoring any logs for ticketing tools or servers. It saves us around 2 hours daily.
What is most valuable?
We can onboard multiple data types for monitoring from various ports and use Splunk to monitor laptops or other devices directly. If everything is stored in our database, we can also monitor that and see who is logging in and when. You can monitor which files are being used most and which ones aren't. We can also check for any fraudulent activity in the system. The reporting is highly detailed.
Splunk is best when used for real-time monitoring. We can use AI and machine learning, too. Splunk plans to launch new observability features soon. The federated search feature has helped us eliminate redundancy in data servers and discontinue servers that aren't being used much. We can remove those servers from the environment to cut costs.
We can use Splunk to monitor multiple environments. The ease of monitoring depends on the source, application, or cloud environment size.
What needs improvement?
Sometimes, integrating with other systems is difficult, and it isn't feasible to connect with other applications, but it's easy most of the time. I rate Splunk 7 out of 10 for its ability to integrate with other systems.
Every time they launch new versions, we experience a few bugs. The most recent version had a couple of bugs in the databases. We contacted the vendor and got assistance solving these bugs, so the environment is more stable.
For how long have I used the solution?
I have used Splunk Cloud for 4 years.
What do I think about the stability of the solution?
I rate Splunk 8 out of 10 for stability. It has some bugs, but that is common in any product. At least, Splunk resolves bugs quickly.
What do I think about the scalability of the solution?
Splunk's scalability is nice.
How are customer service and support?
I rate Splunk's technical support 9 out of 10.
How would you rate customer service and support?
Positive
How was the initial setup?
Splunk is easy to deploy. We have it deployed across data centers at multiple locations. Splunk requires some maintenance after deployment.
What's my experience with pricing, setup cost, and licensing?
Splunk is a bit pricey, but it's reasonable for the features offered.
What other advice do I have?
I rate Splunk Cloud Platform 8 out of 10. I would definitely recommend Splunk to others.
Great support, good pricing model, and good integration with various clouds
What is our primary use case?
I used it in my last organization for monitoring, intrusion detection, and intrusion prevention.
We wanted to take preventative actions so we implemented it.
How has it helped my organization?
The monthly security reports were detailed, and we got to know about a lot of vulnerabilities that we did not know about before.
It integrated well with other systems and applications in our environment. I would rate it a ten out of ten in terms of integration.
Splunk Cloud Platform had a good impact on decision-making processes in our organization.
It was helpful for data access for compliance and privacy regulations. I would rate it a nine out of ten in this aspect.
Splunk Cloud Platform had a very good impact on our organization’s security posture. The resilience that it offered was very important because we were dealing with client data.
For reporting, a lot of manual intervention was required to create the reports, but after that, it worked well.
What is most valuable?
Its interconnectivity with the cloud platforms, such as Azure and AWS, was valuable.
We had multiple cloud environments. It was easy to monitor multiple cloud environments using the Splunk Cloud Platform’s dashboard.
What needs improvement?
Considering its price point, it does not need any improvement. However, it does require manual implementation.
There can be more modules and more integration with other areas in the cloud and on-prem. I am not sure whether it includes network devices and things like that.
For how long have I used the solution?
I worked with this solution for one year and a half.
What do I think about the stability of the solution?
It is stable. I would rate it a ten out of ten for stability.
What do I think about the scalability of the solution?
It is scalable. I would rate it a ten out of ten for scalability and extensibility.
How are customer service and support?
I got great support from them every time. I would rate them a ten out of ten.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
We were not using any similar solution previously.
How was the initial setup?
It was deployed on a public cloud. Its setup was quite complicated. A lot of steps were involved in implementing it.
What about the implementation team?
We had some engineers from Splunk to advise on a couple of things.
We had three people involved in the deployment. They were all cloud engineers.
It did require maintenance. We had one person involved in the maintenance.
What's my experience with pricing, setup cost, and licensing?
It was a good model.
Which other solutions did I evaluate?
We evaluated other solutions, but I do not remember the names. I know there was one from AT&T.
What other advice do I have?
I would rate Splunk Cloud Platform a nine out of ten.
Boosts performance and helps simplify monitoring across platforms and data management
What is our primary use case?
We leverage the Splunk Cloud Platform to effectively manage the vast amounts of machine-generated data, thereby ensuring application management security compliance.
We implemented the Splunk Cloud Platform to enhance our customer experience and optimize the data storage costs. We can convert the log data into numerical data points when requested.
How has it helped my organization?
The Federated search helps retrieve data in a better way.
Splunk Cloud Platform simplifies monitoring across multiple cloud environments, providing real-time insights into operational flow. It also streamlines data conversion, reducing the data-driven process for the company.
Splunk Cloud Platform's machine learning and AI capabilities simplify data management and provide clear visibility into multiple environments.
The AI makes it easy to integrate with other systems and applications in our environment.
The Splunk Cloud Platform reporting provides good insight.
Splunk Cloud Platform significantly boosted our performance and cost-effectively optimized data sets, delivering immediate benefits.
Thanks to the Splunk Cloud Platform we can make decisions within the organization much faster.
Splunk Cloud Platform empowers our organization to access data efficiently, ensuring compliance with privacy and regulations through actionable insights.
Splunk Cloud Platform strengthens our security, particularly in handling complex processes.
What is most valuable?
The data management and instant search features are the most valuable ones for us, as they allow us to instantly retrieve information needed for reports and security compliance.
What needs improvement?
Splunk should increase the frequency of new feature releases, particularly those related to real-time operational flow monitoring and analytics reporting. It has been over a year since any significant updates were added to the Splunk Cloud Platform.
For how long have I used the solution?
I have been using the Splunk Cloud Platform for one year.
What do I think about the stability of the solution?
Splunk Cloud Platform is stable.
What do I think about the scalability of the solution?
Splunk Cloud Platform is scalable.
Splunk Cloud Platform's resilience is good.
How was the initial setup?
The initial deployment was straightforward. The deployment took around four hours and required two people.
Which other solutions did I evaluate?
We evaluated Victoria Experience but it was not suitable for our environment.
What other advice do I have?
I would rate Splunk Cloud Platform an eight out of ten.
We have around 150 users.
No maintenance is required from our end.
I recommend Splunk Cloud Platform. It helps monitor all the respective functions.
Which deployment model are you using for this solution?
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
A stable solution that can be used for security log monitoring and compliance
What is our primary use case?
The primary use cases of Splunk Cloud Platform are security log monitoring and compliance.
What is most valuable?
The most valuable feature of Splunk Cloud Platform is its flexibility and readiness because it's already prebuilt, and everything is click-to-go. Splunk has multiple features, but the cloud feature comes with that. It is built for a smaller organization, but that's how organizations grow. The solution is good for a new budding organizational group.
What needs improvement?
Splunk Cloud Platform should improve its integrations and consider multiple integrations or direct integration with other platforms like Microsoft Azure, Google Cloud, or AWS.
I would like to see more integrations because integration is related to bringing in more data. More integrations would increase the visibility and customer's point of scope. Customers are initially tied to one platform and stick to it because of its feasibility. Integration becomes a major challenge when they want to bring in different solutions.
Once they have different integrations from Splunk, they need not worry about security, things to monitor, or what compliance they must meet. Everything will be physical, and integration will bring in a lot of things.
For how long have I used the solution?
I have been working with Splunk Cloud Platform for one and a half years.
What do I think about the stability of the solution?
Splunk Cloud Platform is a stable solution.
How are customer service and support?
Splunk Cloud Platform's technical support is good. The support's technical capabilities are always great because everyone who is capable joins in and contributes. However, at a high level, we understand there is always a gap in automation. We have process automation that can be resolved or detected by customers.
The flaws in our cloud can be fixed. We can send an integration update to the customer and tell them that you must fix this so everything works fine. For a download-compatible system, you can update an older heavy forwarder version to a newer version to grasp the maximum out of it.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
I have worked with a lot of other products, but not as a cloud solution. I have designed cloud solutions for other products like what Splunk currently has. I have worked with IBM, which has its own cloud platform, cloud monitoring solutions, and security solutions. Similarly, we have other market solutions that will act as a security solution, but they are in different behaviors. We have designed one for other customers, which monitors other cloud and hybrid solutions.
Splunk is currently at the top rating because I haven't explored other ones. I started exploring Microsoft Sentinel, which is a good competition for the Splunk Cloud Platform, and it's a healthy competition. I would like to see a very light-flavored source solution integrated with the Splunk Cloud. Once people start tasting source solutions, they will surely explore them more because that's how hunger is created. Other solutions already have the source solution in them. For example, Sentinel has its own source solution, which they give as an integrated part.
How was the initial setup?
Splunk Cloud Platform’s initial setup was quite easy.
What about the implementation team?
The Splunk team was involved in the solution's deployment.
What's my experience with pricing, setup cost, and licensing?
Splunk Cloud Platform's pricing is a little on the higher end. When smaller organizations start their journey of onboarding log sources or security solutions, they think Splunk is quite worth it. But when they start growing, they feel it's quite eating up their budget on security. So, it is fine for smaller organizations. It all depends on how the discounts are provided.
What other advice do I have?
Splunk Cloud Platform is used in our customer's company. The solution is deployed on the Spunk Cloud in our organization.
Splunk Cloud Platform is a very good product in the market, and you can use it wisely. Compared to other products for the cloud solution, you can use Splunk Cloud Platform for a wide range of tools. Splunk Cloud Platform is the best product to onboard for a new startup or a working good industry with a very small number of people. You don't have to sit in an office and work. You can work it from anywhere and integrate the log sources. That's how easy it is.
The cloud is not for a bigger organization. The one which is sitting in the environment can be used. For example, if you have one terabyte of ingestion per day, that is not what we expect a bigger organization to ingest on a cloud. It would become quite expensive to store, manage, and process.
It is good for smaller organizations because they have around 25, 30, or 100 GB of ingestion per day. If you want to grow bigger and bigger, you can use a hybrid model. If that model is available, that would be great for bigger organizations. For example, the cloud is integrated into the cloud, and on-premise is integrated into data centers. That should work fine.
Splunk does the solution's maintenance. From our side, the local integration material has to be maintained as per the cloud instance. It all depends on the customer. If the customer is fully on the cloud, it should not be a problem. We still have to upgrade heavy forwarders, universal forwarders, and deployment servers. However, the rest is taken care of by Splunk itself.
Our customers monitor multiple cloud environments, which are distinguished in their environment. It is integrated in a different format and not directly integrated. Monitoring multiple cloud environments using the Splunk Cloud Platform’s dashboards is quite easy and reliable.
It's a standard thing. I don't know about other comparative tools, but the first time I used Splunk Cloud Platform, it was quite good enough and can be used for the current organization.
I rate Splunk Cloud Platform's integration with other systems and applications in our environment a seven to eight. This is an average rating where you can see that the growth still has to be achieved. Splunk Cloud Platform should work on its integration with third-party products.
Splunk Cloud Platform has different types of formats, and those are enough. The rest of the reporting, like the presentation, should be done by itself. No one gives those. The reporting that Splunk Cloud Platform currently provides is enough.
It depends on the industry, but for financial or banking industries, Splunk Cloud Platform plays a major role in decision-making. If I want to rate it, you have to consider ten out of ten as Splunk or any other tool before they make any decision. If they have Splunk already, they should consider Splunk as a major partner to integrate and bring in more services apart from bringing any other solutions. That will create a multiple-glass observation, which will not be an easy decision. If one of our customers has Splunk, they must consider it a priority before bringing in any other solution.
Splunk Cloud Platform helps our organization access data for compliance and privacy regulations. Right now, Splunk is so feasible that it can integrate with any tool, anytime, and in any data format. So, it should not be a problem. Anyone brings in data in any format, Splunk Cloud Platform will surely meet it. The only thing is they need a good engineer to design it properly so that it brings in data properly.
An organization that does not have a security posture review is considered a zero, not a negative. We don't know when it becomes negative. The day they bring Splunk into the environment, it will obviously increase their visibility. Every time the security posture increases, they get to know the flaws.
Their observation of 24/7 monitoring, compliance, log monitoring, and forensics will come into the picture. They can enable everything in a single solution or product.
Splunk Cloud Platform is a resilient model. SIEM tools can perform post-detection. SIEM is not an EDR tool because it doesn't automatically detect something. A SIEM tool is used for compliance and audit. It is helpful for future investigation because it can record logs and keep them aside.
However, a SIEM tool does not have an automatic detection module. Although it has a prediction model, it does not have an auto-detection or blocking model. It cannot be a resilient tool, but it can be a vigilant tool.
Overall, I rate Splunk Cloud Platform a nine out of ten.
Offers excellent visibility, and cloud performance, and requires zero maintenance on our end
What is our primary use case?
We use Splunk Cloud Platform to monitor our environment.
How has it helped my organization?
Monitoring multiple cloud environments is made easy with the Splunk Cloud Platform due to its fast ingestion and data recovery times.
Splunk's visibility into multiple environments is excellent. I have found that a hybrid environment works the best, as the login portion remains on-premises while the rest is in the cloud. This reduces the maintenance required on-premises.
There are two types of integration. The first involves bringing something into Splunk, while the second entails moving something out of Splunk. Bringing data into Splunk is relatively straightforward, with multiple options such as RAS, SysLog, and Splunk's built-in functions. However, exporting data from Splunk is more challenging and not as straightforward as the process of bringing data into Splunk.
Splunk Cloud Platform has influenced our decision-making processes. Splunk is primarily employed for security purposes; thus, it excels particularly in SIM. It encompasses an asset and identity framework that effectively gathers information about an organization's assets and individual identities, encompassing all users. Therefore, when considering Unified Business and SIM, Splunk proves to be highly proficient.
What is most valuable?
The cloud performance is good.
Not having to perform any maintenance because it is handled by Splunk saves our administrators time which is valuable.
What needs improvement?
Splunk should offer various options for real-time monitoring. If we could enhance the speed of data ingestion or data retrieval, that would be an added advantage. Additionally, there is room for improvement in SaaS-to-SaaS integration. I believe that reintroducing HTML dashboards would be beneficial, as they provide dedicated web features. This, in turn, gives users the flexibility and freedom to create custom dashboards more easily.
For how long have I used the solution?
I have been using Splunk Cloud Platform for five years.
What do I think about the stability of the solution?
I would rate the stability of the Splunk Cloud Platform as an eight out of ten. We still encounter some lagging and errors, but not as much as with the on-premises deployment.
How are customer service and support?
I occasionally get in touch with Splunk technical support, usually regarding data onboarding. These include routine activities like installing or uninstalling applications, as well as making changes to existing ones. On average, we submit at least one ticket per week to them.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
I have used many tools including Elastic, Grafana, Tableau, and Sumo Logic.
Splunk is indeed superior in many cases, but other tools are also making progress to catch up, with Elastic being one of them. They have begun developing their own SIM offering, complete with its own SIM features. Similar to Splunk Cloud, Elastic also has its Elastic Cloud Stack. Some of the features provided by Elastic seem to outperform Splunk. Therefore, there is room for Splunk to enhance these aspects. As for pricing, it could be more competitive, considering that other tools also provide the freedom to choose the Cloud Stack. Although Splunk offers this flexibility, the process often involves extensive discussions, making it less adaptable compared to other tools.
How was the initial setup?
The initial setup is somewhat complex regarding the CI/CD pipeline, and Splunk manages the deployment. Splunk provides a feature called ACS, which enables us to manage the deployment ourselves if desired, but it's simpler to have Splunk handle the deployment on our behalf.
The deployment took around one month and required ten people from Splunk's DevOps team.
What about the implementation team?
The implementation was completed by Splunk.
What's my experience with pricing, setup cost, and licensing?
The pricing is high for small organizations. The cost makes more sense for organizations that have a large amount of data ranges.
What other advice do I have?
I would rate Splunk Cloud Platform an eight out of ten.
There are numerous tools that offer real-time reporting and alerting capabilities. Splunk is indeed effective, but due to the prerequisite of registering logs beforehand, a delay is inevitably introduced. Therefore, while Splunk is suitable for real-time reporting alerts, it may not be as optimal as some alternative solutions.
Resilience has added value and contributed to the improvement of our organization. This is highly significant. In most cases, the SOC team relies on the tool for issue mitigation and ticket resolution. Therefore, it is crucial for Splunk to remain consistently up-to-date and respond as quickly as possible. This holds immense importance.
The extensibility is good, but there is room for improvement, especially in integrating certain logs. Enhancing the process of incorporating raised logs is possible. In most cases now there are limitations on log creation. Previously, a direct option existed to import logs. However, this process has been altered, requiring users to develop an add-on for log integration, leading to increased complexity. Furthermore, users are expected to have knowledge of Python. This can be problematic in cases where users lack such expertise. Therefore, this aspect could certainly be enhanced.
For those who want to evaluate Splunk, it comes down to the volume of data. If they are dealing with a substantial amount of data flowing into their SIM, Splunk would be the superior option. Splunk effectively manages extensive datasets in comparison to other technologies. It also offers numerous additional functionalities, such as an enterprise security suite, assets, and identity framework. Moreover, it has undergone industry testing and has been employed in the field for a considerable duration. In contrast to other organizations, they provide a wealth of features.
Does not require backend maintenance, is easily integrated and utilized
What is our primary use case?
We utilize the Splunk Cloud Platform for log ingestion related to security and troubleshooting purposes.
How has it helped my organization?
Splunk Cloud Platform helps us with our security incident response. The cloud security logs are integrated with all the cloud providers.
The federated search feature enables us to search between Europe and the US, from one Splunk instance to another, all from a single location. This federated search simplifies how we handle data, making it easy to swiftly search for and manage information.
We monitor several cloud environments and find it easy to utilize the Splunk Cloud Platform for this purpose. Each cloud provider offers its own prebuilt dashboard, or customers can create their own.
The Splunk Cloud Platform offers excellent visibility into multiple environments. In the past, we utilized hybrid integrations, and they seamlessly worked right out of the box.
The reporting functionality provided by the Splunk Cloud Platform resembles that of the on-premise platform. It is readily available without requiring integration or the installation of reporting visualizations.
From a security standpoint, the Splunk Cloud Platform provides us with comprehensive visibility into all security logs. This enables us to implement security incident responses with great efficiency. Additionally, we have discovered that internal employees, such as product teams, are utilizing the platform as intended for various other use cases. For instance, it has proven valuable in troubleshooting performance issues and monitoring within Kubernetes. As such, we are leveraging a wide array of use cases within the company.
Splunk is a highly mature software that has been in the market for many years, which greatly influenced our decision-making process. Another factor was the user-friendly nature of the latest version, making it easy to initiate. We don't require a large workforce for installing components; it's as simple as out-of-the-box. Consequently, minimal time investment is needed for training.
The Splunk Cloud Platform assists us in accessing data to meet critical compliance and privacy regulations. For instance, this is particularly important for regulations such as GDPR and HIPAA. We are utilizing Splunk Cloud with a specific focus on HIPAA compliance, allocating extra attention to this aspect. In the case of GDPR, Splunk offers a range of built-in capabilities. For instance, it allows for log masking. Moreover, there are novel features available in Splunk Cloud, such as ingest actions. This feature is exceptionally useful as it enables us to mask the data before it's ingested into Splunk. Consequently, this approach ensures our adherence to compliance regulations, exemplified by GDPR.
The Splunk Cloud Platform has had a significant impact on our organization's security posture. It serves as our primary visibility tool and is the main source of trust for all login activities. Without Splunk, we would lose essential visibility and access to security updates. Currently, Splunk stands as one of the primary tools we utilize due to its utmost importance.
What is most valuable?
The most valuable feature is we don't have to deal with any back-end server maintenance because the solution is cloud-based.
What needs improvement?
The on-premises version of Splunk includes all the integrations, while the Cloud platform lacks certain integrations and is limited in terms of the number of supported apps.
The Splunk Cloud Platform is not a very mature solution; it has only been on the market for four or five years. While they have made significant improvements, there are still limitations, such as the absence of CLI access. Therefore, there are several limitations that still exist with the CLI.
The standard support has room for improvement.
For how long have I used the solution?
I have been using Splunk Cloud Platform for four years.
What do I think about the stability of the solution?
The Splunk Cloud Platform offers 99.9 percent availability, ensuring that we never experience downtime.
What do I think about the scalability of the solution?
I would give Splunk Cloud Platforms' scalability an eight out of ten.
How are customer service and support?
Technical support needs more knowledgeable people.
How would you rate customer service and support?
Neutral
Which solution did I use previously and why did I switch?
We used Sumo Logic in the past, but it wasn't an enterprise-grade solution, so it couldn't support the scale we required. Additionally, Sumo Logic lacked support for many integrations. The Splunk Cloud Platform fulfills our scaling requirements and integration needs. Moreover, our team possesses skills that align well with Splunk, making it a better fit for us.
How was the initial setup?
The Initial deployment was very straightforward because we had the skills. But I would not say that this is straightforward without the skills. We need to learn at least the basics.
The deployment took six months to create this multi-tenant environment because it's a highly specialized setting. It's distinct from a typical Splunk deployment that might only take a day or two. However, the process of configuring, migrating all the data from Sumo Logic to the new Splunk Cloud, and setting up the multi-tenant system along with product dashboards, required approximately six months of effort on our part.
What was our ROI?
We utilize Splunk in a multi-tenant manner, wherein we allocate costs back to the product teams in each department based on their usage. We are a healthcare company engaged in the development of healthcare applications tailored for doctors and hospitals. Splunk plays a pivotal role in assisting us with this endeavor. I would estimate that we have experienced a return on investment of approximately 30 to 40 percent.
What's my experience with pricing, setup cost, and licensing?
The cost of the Splunk Cloud Platform is high, and in addition to the standard licensing fee, we also have a premium support fee.
Now, we are paying less because, instead of being charged based on ingestion, we are paying for SVCs, which stands for Splunk Virtual Compute. This implies that our costs have decreased. Despite ingesting a larger volume of logs, our expenses are lower than they were before. However, it's important to note that if our usage of the tool increases, our expenses will also increase. Therefore, this represents a distinct licensing model from Splunk's.
What other advice do I have?
I would give Splunk Cloud Platform an eight out of ten. Splunk Cloud has shown significant improvement over the past four years, and I highly recommend it.
We operate two distinct Splunk Cloud platforms: one in Europe and another in the US. These platforms are linked through a federated search. This setup ensures that specific data, such as European data stored in the AWS cloud, is directed to the European Splunk platform, while data from the US Cloud is directed to the US Splunk platform. However, it's worth noting that all users primarily log into the Splunk US Cloud. From this point, they have the capability to transmit data to the Splunk Europe platform.
We have around 400 users.
The maintenance is primarily conducted by Splunk on the backend, and any on-premises maintenance we perform has been reduced by 80 percent.
The value that Resilience provides for SIEM solutions is significant for us. Therefore, if we inquire with various customers, they might provide different perspectives. However, concerning security, this holds substantial value. I would assert that it's the primary tool in our arsenal; indeed, we do possess other security tools, but the most frequently utilized one, which also delivers the utmost value, is undoubtedly Splunk.
The method to expand a SIEM system is achieved by extending the licenses. This expansion enables greater capabilities, increased log retention, and the ability to process more logs. In our specific scenario, we were previously restricted by the capacity of the ingest license. Our log ingestion was limited to, for instance, one terabyte per day. However, with the introduction of this new licensing model that's based on CPU usage, we now have the flexibility to ingest any amount of data while paying according to our actual tool usage. Consequently, if we intend to expand for additional servers, we simply need to contact Splunk and communicate our requirement for increased server capacity to enhance system performance. This process is streamlined because we aren't required to take any additional actions ourselves.
I would highly recommend Splunk Cloud because we don't require personnel for maintenance or server installation and management, as all these backend tasks are taken care of. Additionally, for those who are currently using a competitor of Splunk for SIEM purposes, I would also recommend transitioning to Splunk if they have the budget for it.
Which deployment model are you using for this solution?
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Integrates well, provides good visibility, and reduces maintenance work
How has it helped my organization?
Splunk Cloud Platform was very useful for us. With the on-prem setup, we had to maintain all the servers and take care of the upgrades, whereas with Splunk Cloud Platform, we did not have to bother about that. Everything was handled by the Splunk support team.
It was sufficient for us to monitor multiple cloud environments. The visibility that it provided into multiple environments was good.
We used Splunk Cloud Platform for business processes and security. It helped us a lot. On the business side, as a banking organization, it was helpful for reports and alerts. On the security side as well, Splunk was helpful. We could see any security breach. It was also helpful for smooth operations. If any issue happened or any server was down, it automatically alerted us.
What is most valuable?
Everything is maintained by the Splunk support team. Users do not have to maintain any physical servers. They do not have to maintain indexes and searches. It reduces a lot of work on the user side.
We integrated it with other applications in our environment. It integrates well. We did not face any issues on the integration side.
The reporting offered by Splunk Cloud Platform is also good.
What needs improvement?
I faced a few minor issues with Splunk Cloud Platform. In the case of knowledge objects, even a Splunk admin does not have access to delete them. If we want to remove a knowledge object, we need to contact Splunk support and raise a case. After that, they delete it. They should give us access to delete knowledge objects.
Everything else was good. It already had all the features. We did not require any new features.
For how long have I used the solution?
I used this solution for almost ten months in my previous organization. Currently, I am not using it. I last used it about five months ago.
What do I think about the stability of the solution?
It was stable. We did not see many issues. Any issues were on the physical servers, not on the Splunk Cloud side.
What do I think about the scalability of the solution?
It is scalable. We had more than 2,000 users in our organization. It was being used by more than 150 departments.
Onboarding end-users was easy. I was a Splunk admin, and I was also an end-user. I could provide access to other end-users directly.
How are customer service and support?
Their technical support was good. I would rate them a five out of ten because we worked in the Australian time zone, and the tech support team that we usually got did not have much knowledge. They took time to resolve issues.
How would you rate customer service and support?
Neutral
Which solution did I use previously and why did I switch?
In our organization, we used multiple products. We had Dynatrace and other products, but we mostly preferred Splunk. It was more user-friendly than others, and we could search everything easily. We could create dashboards. Other products were more difficult.
How was the initial setup?
It took us a long time to switch from on-prem to the cloud. It took almost four to five months.
What about the implementation team?
We took the help of the Splunk team for migration, but after that, we did not take their help. We took care of onboarding and other things. It was easy. If any issue came up, we contacted the Splunk support team.
What's my experience with pricing, setup cost, and licensing?
I do not have much idea about the price. We previously used 1 GB at the cost of $600. Both on-prem and cloud licenses have the same price. There is no difference.
It did not impact the cost because the costs of the on-prem license and the cloud license are the same. We did not have any issues with that. Overall, its price is reasonable.
What other advice do I have?
I would recommend moving to the cloud because you do not have to maintain physical servers and infrastructure. Everything is handled by the cloud provider.
Overall, I would rate Splunk Cloud Platform a nine out of ten.
Good visibility and speed with reasonable pricing
What is our primary use case?
Splunk Cloud helps us to combine all our environments. For example, multiple business units can be combined into one even if they are in different geographic locations.
What is most valuable?
It helps us with hosting from different geographical locations.
The speed of the cloud environment is great.
We only buy the services we need. We don't have to pay for other things we don't. It makes the pricing very economical.
We use the solution's federated search feature. It's easy for us to use. It helps us search logs, analyze, and manage data.
We are able to monitor multiple cloud environments using our Splunk Cloud dashboards. It makes the process very simple. We just have to maintain different teams for different environments.
The solution is great within hybrid environments. It gives us good visibility across everything.
It works well for sizable environments.
The product integrates well with other systems and applications in our environment. We haven't had any issues with integration at all. However, if we ran into issues, we could call Splunk support. Having an issue would be a very rare event.
Reporting is very good. It's the same for all Splunk solutions. Having multi-cloud instances in one place is great.
We have multiple business units and easily integrate them into the cloud, as well as different infrastructures from different areas. We can deploy a Splunk agent on any cloud - AWS, Google, etc.
The company can access data easily for compliance and privacy regulations. The privacy aspect has been very good.
Having resilience has been very helpful in our organization.
What needs improvement?
Training should be free of cost. They need to provide more training options.
There are no missing features at this time.
For how long have I used the solution?
I've been using the solution for two and a half years.
What do I think about the stability of the solution?
The solution is stable.
What do I think about the scalability of the solution?
We have 30 people using the solution in our organization. The product is scalable.
How are customer service and support?
Technical support has been good.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
We did also use LogRhythm. It has a very good UI in comparison to Splunk, yet it doesn't have as many capabilities and does have a few more restrictions. That said, it's a good product for creating use cases and automation, which is easier than Splunk. We moved to Splunk as LogRhythm did have some restrictions.
How was the initial setup?
I have previously done deployments of Splunk. The setup is pretty straightforward.
Were a system integrator of Splunk. We help clients set up the solution.
We've had six or seven people setting up the solution.
The maintenance is pretty manageable. I'd rate maintenance needs seven out of ten.
What was our ROI?
I'm not sure if we have noted any ROI while using Splunk.
What's my experience with pricing, setup cost, and licensing?
The pricing is reasonable. They provide good options for licensing.
Which other solutions did I evaluate?
I did not evaluate any other options.
What other advice do I have?
We are integrators and also users of Splunk.
We have multiple solutions we use for security, of which Splunk is one of them. So far, it's been very good from a security perspective, although we don't solely rely on it.
I'd recommend users work with Splunk in the cloud environment. I'd recommend the product in general to others.
I would rate the solution nine out of ten.