I used Splunk Cloud Platform for fraud detection. The first thing is fraud detection, and the second thing is understanding data better because of the data visualization that it has. The display that it has compared to a simple type of visualization is much clearer compared to any kind of thing you might notice on a super dense Wireshark.
Splunk Cloud [Private Offer Only]
Carahsoft Technology Corp.External reviews
External reviews are not included in the AWS star rating for the product.
Advanced alerts and clear visuals have improved fraud detection and data-driven decisions
What is our primary use case?
What is most valuable?
Data Visualization and IT Alerting and Incident Management are the main valuable features, primarily to get a better idea of what's going on.
When you do data reporting using Splunk Cloud Platform, because you have everything in front of you and it's so detailed and easy to read once you have the data. Another thing that makes it clear is because of the amount of evidence you have in front of you, the data is a lot more valuable. It's less of a human claim and more of evidence presented in front of you when you're trying to make any kind of claim on a certain thing going on.
I really do like about Splunk Cloud Platform the real-time alert where you can search for anything and the data is still stored there because at the end of the day, we are finally in a generation of cloud where everything is stored on a cloud platform to the point that you can search anything, as long as you do it in the appropriate way, you will find the results. It's in a good visual status with good visibility. I appreciate this feature.
What needs improvement?
To be honest, I don't think it's beginner-friendly. It takes time and multiple meetings to actually understand how to create different types of alerts or how to search for them. It's quite similar to how you might search on SQL, but that's asking another set of skills to have. I know there are tutorials on the website, but I feel if they rolled out more free courses on such things that provide a link to a free course for beginner training, I feel people would be interested in it.
For how long have I used the solution?
I ended up getting access around three to four months back. I was part of a team that was using it, so we got on a call together while I was observing them and using it while giving my input for a project.
What do I think about the stability of the solution?
I haven't really faced much of it, but my usage was pretty less intensive, so I can't really talk about it for everyone. From my perspective, because of my light amount of research and light usage of it, I would say it's been pretty good. I haven't experienced any stability issues.
What do I think about the scalability of the solution?
Splunk Cloud Platform is a good tool, but it's not the easiest to transfer between different teams because there's a lot of training involved in it. While I do the tool and I do feel it's really useful, if you ever notice in this current industry, people are wanting employees to learn Splunk Cloud Platform, or at least they want applicants who apply for a certain role to have known Splunk Cloud Platform because of not only how new it is or how recent it is after the cloud integration, but also just that it takes time to learn and takes time to be efficient at it.
How are customer service and support?
When you work in a corporation, you have people dedicated just for that.
How would you rate customer service and support?
Negative
Which solution did I use previously and why did I switch?
I've used Splunk Cloud Platform very briefly, not too much. I use ServiceNow, Confluence for documentation, and Keyfactor for generating certificates.
How was the initial setup?
It's kind of hard for me to say because I came from a corporation where Splunk Cloud Platform was already a part of the user group where I got access to it, so I didn't have to do any of that.
Which other solutions did I evaluate?
Any IT person would rather use the command prompt. Using a simple command prompt and trying to see based on the elevated access they have, you can always check what's going on. Wireshark itself is a really good tool and a really good alternative to have any kind of packet capture and read through the data to understand what's going on.
Splunk Cloud Platform is different because it offers real-time alert. Wireshark is something that you have to let things be and then later catch and see, while Splunk Cloud Platform updates on its own. It has a lot better visuals overall.
What other advice do I have?
Regarding whether Splunk Cloud Platform's ingest and visualization features have helped improve data reporting and the overall alerting mechanisms, I haven't had the chance to use it for myself, but from the time when I was researching them for the project that I was working on, it seemed to be really effective in at least the fraud department of the team to understand any type of price alerts when something is going on.
Regarding how easy or difficult it was for me to learn how to use it, I would say on a scale of easy with one being the easiest and ten being the hardest, I would say it was around a four or five. I've used other tools before, and I've used other things such as Wireshark and some others a lot before, so I had a much better grasp than a lot of beginners might have. Recently in a meeting where we were trying to teach a beginner about this, the main person who uses it had to go through multiple rounds of meetings to show them how to use it. While watching that, I realized the gap in knowledge between someone who's in IT for years versus someone who's trying to be more hands-on but is unfamiliar with the tool.
Cloud security service has transformed onboarding, reduced maintenance, and unified orchestration
What is our primary use case?
We use Splunk Cloud Platform for security and want to implement it as a SIEM solution. We also want to replace our old legacy SIEM solution because we are adopting a cloud solution instead of an on-premises solution. Another use case is that we want to use this tool in our managed service offering. We do not use the solution to resell licenses to our customers, but rather to provide services to them. We appreciate the powerful integration that Splunk Cloud Platform offers, making it easy to integrate with any sources and any data. It is able to handle data that resides in an S3 bucket or elsewhere, not just ingested directly into the SIEM itself. We are also looking at Splunk Cloud Platform's strategy, which is very interesting because of the integration they will have regarding Agentic AI and automation. A unique solution for orchestration and automation, called SOAR in cybersecurity, combined with SIEM in a unique platform is a very interesting strategy from our point of view.
It is Enterprise Security in the cloud. This is a cloud solution.
What is most valuable?
Splunk Cloud Platform is a very mature solution and an enterprise-grade solution that brings the work we have to do with customers to an enterprise-grade level. It is something that we can manage from a single pane, and it is quite easy to deploy. I see a benefit that is not strictly related to the features that Splunk Cloud Platform offers, but it depends on the company belonging to Cisco now because we are a Cisco partner and Splunk Cloud Platform is a pillar, a vertical technology in the security area of the partnership. The benefit of partnering with Splunk Cloud Platform falls into the Cisco partnership and the benefits we can have in this important partnership we have as a company.
Compared to my previous situation, the first benefit of this solution is the speed and the effort reduction in terms of onboarding new customers and maintaining the entire platform. I will not have any more effort for system upgrades and infrastructure maintenance. This is one of the biggest benefits I can have from the solution. I save a lot of money because I do not have to spend resources anymore to maintain and operate the infrastructure and the systems.
What needs improvement?
I think it is really effective, and we are still at the beginning. The capability to search for insights is very powerful and also supported by AI and machine learning. The capabilities are increasing day by day, and new features are being released and will be released soon.
I am not able to answer right now, but I am confident they will be able to predict a trend because they promise they are able to do this using machine learning algorithms and Agentic AI features. They say they will be able to predict the behavior of your network or your infrastructure. I am really confident about this, and I hope it will be true because I need this.
There is something that they say will be improved, and I am still waiting for it. This is the Agentic AI elements inside the platform that I mentioned before. There is something present today, but the full feature is not released yet. From my point of view, it is a bit late. It is okay for me because we are adopting it and we can work on this, and it is acceptable for my timing. However, from a market perspective, they are a bit late. Competitors in some cases are earlier adopters. But I am sure they will release a very powerful tool, as per the Cisco approach. They want to win when they start doing something, and I am confident they will release a very powerful tool.
For how long have I used the solution?
I have been working with it for one month.
What do I think about the stability of the solution?
It is still a bit early to answer. We have just seen it on paper, and we have to check it.
Which solution did I use previously and why did I switch?
In my previous experience, I had enterprise security, but on-premises a few years ago, three years ago. It was integrated with another SOAR from another vendor.
How was the initial setup?
It is something that we can manage from a single pane. It is quite easy to deploy.
What's my experience with pricing, setup cost, and licensing?
Compared to my situation, it does not have any meaning because I have something legacy now. However, it is a good price on the market. It depends because if you look at the list price, it is a bit expensive from my point of view. But once you are in the partnership with Splunk Cloud Platform and with Cisco, you can have good discounts, you can make the deal and discuss, and they are willing to help you as a partner in finding the solution and finding your target. So it is good from my point of view. But if you look at the list price, it is expensive.
Which other solutions did I evaluate?
We evaluated QRadar, FortiSIEM, and Palo Alto SIEM. We chose Splunk Cloud Platform because of a combination of different aspects, not just for price or features. It is the whole combination of the features, the benefits, the cost, the partnership, and there is no one aspect leading the choice. It is a mix and a combination.
What other advice do I have?
Today, we are working with the SIEM solution, which is quite a legacy term. Saying SIEM is not really effective. It is the Enterprise Security solution, and we are now in the process to implement it. We are adopting the solution and are at the beginning. We have studied a lot, we are training people, and we are changing and modifying our process as per what the technology allows us to do. We are also evaluating the observability solution. We are working on two different paths, and one is at a more mature stage, while the other one is at an evaluation stage.
We are setting up alerts as expected.
We are integrating Splunk Cloud Platform SIEM solution with our SOAR solution, which is today from another vendor and not Splunk Cloud Platform. Then we will see tomorrow what we want to do if we want to use the unique platform, the unique Splunk Cloud Platform with SOAR, Agentic AI, SOC automation, and everything, or if we want to keep using our actual SOAR. We are integrating Splunk Cloud Platform with this SOAR.
My recommendation is to look at the future and look at the strategy. Do not look at the features today but look at the features tomorrow and not just at the technical features but at the whole strategy to integrate in one single platform all the capabilities that a SIEM solution or a log gathering solution might have. Putting together orchestration, observability, security, this kind of strategy is what an integrator should evaluate in my opinion.
I would rate this product an 8 out of 10.
Unified data monitoring has enabled proactive alerts and predictive analysis for daily operations
What is our primary use case?
The main use cases for Splunk Cloud Platform include data collection, parsing activities, use case building, data ingestion, and creating dashboards and reports. My clients use it for similar purposes.
What is most valuable?
The best thing about Splunk Cloud Platform is that you can bring any data and store it in one place. You can build meaningful insights from it, have the same data ingested, create beautiful insights, have alerting done on it, and have dashboards and reports built on top of it.
Splunk Cloud Platform's ingest and visualization features do not bind you with a limitation in the volume you want to ingest. Since we are using the compute-based licensing feature of Splunk Cloud Platform, there is no limitation to the volume of data we ingest on the platform. All Splunk Cloud Platform instances are also Smart Store supported, so that eases storage utilization concerns.
One of the best advantages of using Splunk Cloud Platform is that there are lots of proactive alert notifications from Splunk support if anything goes down on the infrastructure end or if there is anything wrong with your environment. Splunk support is on top of things, notifying you beforehand if something is going wrong and that their team is already aware and working on a fix.
What needs improvement?
I don't see any new requirements in terms of improvements for Splunk Cloud Platform at this time. Splunk's dashboarding, reporting, and visualizations are evolving at a larger scale with the new Splunk Dashboard Studio in place. There were some limitations with the classic dashboard where you had to be aware of different HTML, CSS, and custom JavaScript for better visualizations. That's being migrated towards Splunk Dashboard Studio, which is evolving at a great pace, providing similar functionalities. I have not faced any current challenges regarding Splunk Cloud Platform's limitations. I still think, however, that better configuration and customization options for workload management could be enhanced, but that applies to Splunk Enterprise as well. It's just my understanding and what I foresee, but I'm not sure if it will be a priority right now, as even without workload management, a lot can be done, and the product team might have a different roadmap.
For how long have I used the solution?
I have been working with Splunk Cloud Platform for almost six years.
How are customer service and support?
My feedback remains that you have your designated account manager who helps navigate all the cases. Sometimes, the support team may not be fully knowledgeable about the challenge you face, but through their internal escalation structure, they manage to find viable solutions sooner or later or provide updates on when issues will be fixed. I think their support is pretty good on that part.
How would you rate customer service and support?
Positive
How was the initial setup?
The best thing about the initial setup process of Splunk Cloud Platform is that you don't have to deploy your own Splunk Cloud Platform deployment; Splunk handles it for you. For the on-premises setup, you do need the initial configuration for end devices to send logs to Splunk Cloud Platform, but it's straightforward. It's just one package that you install on your end device, and after restarting, everything is sorted. There is no hassle in configuring Splunk Cloud Platform or getting on-premises devices to send data to it.
What other advice do I have?
We do use Splunk Cloud Platform's alerting mechanism. We have set up hundreds and thousands of alerts for different use cases. For example, if any of the data sources stop the ingestion or the volume has been relatively quite down, we have set up alerting for that. It creates a ServiceNow incident that falls under our team's responsibility and sends an email as a notification that this alert has been triggered, such as when XYZ feed has gone down or the data from XYZ feed has decreased up to 80% or 70%, whatever the threshold set. We definitely use all the different alerting mechanisms and alert actions provided by Splunk Cloud Platform.
Whenever we see a situation where we don't want to be reactive, we attempt to do a predictive analysis of the data ingested in our Splunk Cloud Platform. This analysis depends on an alert-to-alert basis. For instance, when talking about a data source going down, if the situation arises, we should be triggered at a threshold of around 80% decrease. In that situation, we keep a buffer of 10% and alert ourselves to notify at a 70% decrease in the feed so that we can take preemptive measures to ensure that the feed comes back online before the situation escalates.
In terms of machine learning, we are using the Splunk-supported machine learning toolkit that also has new features for artificial intelligence. We do use them for outlier detection and predictive analysis in terms of different alerting we have enabled in our environment.
To predict trends in our data, the example I shared previously involves understanding if the volume is going down or not. We do this using the machine learning toolkit itself. We have our data ingested into Splunk Cloud Platform, and each index and source type has some dedicated volume getting ingested daily. We create an average of the total volume ingested over the past 60 days, 45 days, and 90 days, and then we identify the volume ingested yesterday. We compare it with the average of the last 45 days and try to detect any deviation. All of this is part of the machine learning toolkit application itself. That's how predictive analysis and outlier detection work, and we're using that in our daily operations as well.
With different vendors, there is no problem having Splunk Cloud Platform integrated with them. For example, we already have our alerting enabled so that whenever any alert gets triggered, an incident is created in ServiceNow. I have also worked on integrating Jira and other different Atlassian products with Splunk Cloud Platform. It's user-friendly and straightforward to integrate Splunk Cloud Platform with different vendors without much issue.
For any organizations looking to configure Splunk Cloud Platform, I believe it's a simple process. It's just important to stick to the fundamentals and understand how Splunk Cloud Platform operates. The documentation is quite clear. One notable advantage of Splunk Cloud Platform is the Ingest Processor and Edge Processor, which help optimize data before feeding into Splunk Cloud Platform. We've seen a reduction of around 40% to 60% in the total volume ingested using efficient data pipelines. We provide services for optimizing data pipelines and feeds, and those tools can be quite helpful. But if you're looking to configure Splunk Cloud Platform for on-premises servers, downloading the universal forwarder package from the Splunk Cloud Platform search head is all you need.
I would rate this product a 9 out of 10.
Security monitoring has improved and provides timely alerts for cyber threats
What is our primary use case?
Splunk Cloud Platform is used as a way for companies to enhance their cybersecurity and ensure security. In cybersecurity, it is important to protect against all malwares, and the platform is effective in searching vulnerabilities or searching threats.
What is most valuable?
Splunk Cloud Platform's ingest and visualization features help with data reporting. The platform's alerting mechanism is valuable, as there is software that makes alarms in case of attacks. Splunk Cloud Platform is used as a way for companies to enhance their cybersecurity as a question of security to ensure the security.
What needs improvement?
I think that Splunk Cloud Platform is good, and I rate it seven or eight.
For how long have I used the solution?
We have worked with Splunk Cloud Platform for approximately three years. We have also been working with Splunk Observability Cloud for approximately three years.
What do I think about the stability of the solution?
Splunk Cloud Platform is a good platform for us.
How are customer service and support?
The technical support of Splunk is good as well, and they are helpful.
How would you rate customer service and support?
Positive
What was our ROI?
Implementation has some benefit for the company.
What's my experience with pricing, setup cost, and licensing?
We think that the price of the product is quite reasonable.
What other advice do I have?
We have clients that use Splunk, but we do not use Splunk ourselves. As a person with deployment experience, I find it difficult to answer the question about implementation because we are obliged to have a platform. There are many platforms, and the implementation is not simple, but we have no special difficulties with Splunk. We think that integration of Splunk Cloud Platform with third-party tools is easy to implement.
Security monitoring has become proactive with customizable alerts and clear dashboards
What is our primary use case?
My major use case for Splunk Cloud Platform is for SOC, SIEM mostly.
What is most valuable?
What I like about Splunk Cloud Platform is the easy reading of the dashboards and finding the data, which brought me the biggest benefits.
The alerting mechanism in Splunk Cloud Platform is customizable, so we could adapt it to our needs and assign the right priorities and based on this, define the action.
Visualization features and ingesting in Splunk Cloud Platform helped to improve my data reporting, but that was also a different team that was providing the log ingestion.
Other features that were really great in Splunk Cloud Platform include real-life monitoring, so we could have logs right away, and parsing was fine, so when it was correctly ingested and Splunk Cloud Platform parsed it correctly, then we had no issues with receiving the correct alerts.
What needs improvement?
Splunk Cloud Platform could improve in how quickly it reacts to users reporting issues.
Splunk Cloud Platform can be complex depending on the log source in terms of deployment.
For how long have I used the solution?
I used Splunk Cloud Platform for seven years.
What do I think about the stability of the solution?
Splunk Cloud Platform was stable, and I did not see any performance issues or downtime, although it happened; the issue was that we had to really fine-tune the log quality so that it would not be ingested too much and handled for nothing.
What do I think about the scalability of the solution?
Regarding the scalability of Splunk Cloud Platform, I would say it is scalable, but maybe the pricing may affect the scalability because it may not be that beneficial to onboard too many log sources if they generate too many false positives and then you reach over the limit of the license.
How are customer service and support?
I would rate the technical support for Splunk Cloud Platform probably a three, because there was some support, but I remember that we were using our proxy company to submit it for us because they were bigger and maybe more convincing to Splunk.
How would you rate customer service and support?
Negative
How was the initial setup?
The biggest issue during deployment of Splunk Cloud Platform was correct log parsing.
What about the implementation team?
I can describe the impact of integration with third-party solutions in Splunk Cloud Platform as limited experience since I was the only one on the receiving end of it, and I was not integrating it with any solutions or with any other vendors; we also had the company who was supporting us in the configuration part, so we didn't even have to do it fully by ourselves.
What was our ROI?
I don't see ROI with Splunk Cloud Platform, such as time saving or money saving because I'm security operations, so I don't think in management terms.
What other advice do I have?
I have about the same amount of experience in this domain with SOC solutions, as I haven't worked with SOC SIEM solutions such as Splunk Cloud Platform before, so it's the same. My overall review rating for Splunk Cloud Platform is 8.
Cloud monitoring has simplified administration and improved integrations for faster operations
What is our primary use case?
My usual use cases for Splunk Cloud Platform involve being an admin where we used to build Splunk clusters or distributed environments from scratch on the on-premises system, but now we have everything up and running on Splunk Cloud Platform, which operates on AWS. Splunk has developed it on AWS. Currently, as an admin, I just need to maintain and configure it according to our needs. It functions as a software as a service now, meaning we don't configure it from scratch the way we used to do with installation, configuration, and setup of the configs as we required. Now, it is software as a service that we use for both Splunk and Observability.
How has it helped my organization?
Splunk Cloud Platform has greatly improved my daily operations through enhanced integration with third-party tools. Earlier integrations from on-premises Splunk to third-party tools were quite difficult, lacking the necessary add-ons or applications that could be directly used from the UI. Now on Splunk Cloud Platform, they have introduced new add-ons and plugins that allow us to utilize and pass credentials directly for integration with third-party applications, making the process very efficient and fast. We have multiple new add-ons that let us connect directly to clouds such as AWS, Azure, and Google, as well as event management applications such as ServiceNow, requiring only the credentials and service accounts and eliminating the need to configure from scratch.
What is most valuable?
The features of Splunk Cloud Platform that I have found most valuable and useful relate to licensing. Previously, it was a daily quota that we purchased on-premises, but currently it is based on SVC, or Splunk virtual compute, which is based on CPU and memory utilization of the cloud for billing. There are two license types: Victoria and Base. As we utilize the SVCs, we are charged accordingly, and we have the option to purchase a fixed number of SVCs or pay based on how many we actually use.
The effectiveness of Splunk Cloud Platform's search capabilities in uncovering operational insights is notable because as an admin or developer, we utilize saved searches that run on schedules that we set. The search capability utilizes the same compute assigned, and compared to on-premises, it is very efficient and fast because on-premises we had fixed compute assigned with limits set for searching per role or application. In the cloud, we find it very easy and fast to use.
Splunk Cloud Platform helps in proactive issue resolution by allowing us to set alerts based on data flow to find errors or anomalies that need identification. The saved searches run based on these conditions to find errors or identify anything unusual in the data. We get alerts based on the conditions we set, which is quite effective.
What needs improvement?
Areas of Splunk Cloud Platform that could be improved or enhanced in the future include data visualization, as the way we use data for security and other purposes could further benefit from enhanced visualization to support monitoring, threat analysis, and other aspects.
For how long have I used the solution?
Overall, I would rate Splunk Cloud Platform an eight out of ten as a solution for us.
What do I think about the stability of the solution?
Regarding stability and reliability so far, we are not yet live and are still in the migration process, but comparing it to on-premises, it seems promising.
What do I think about the scalability of the solution?
My thoughts on the scalability of Splunk Cloud Platform are that it scales up quite well. However, I haven't encountered any specific scenarios to validate it thoroughly yet, but overall, it appears to be good.
How are customer service and support?
My opinion on the technical support and customer service of Splunk, based on my cases, is that it is quite good with the credits we have along with the vendor. However, when we don't have credits, they charge us based on time as well as the criticality of the issue.
How would you rate customer service and support?
Positive
What other advice do I have?
In my opinion, there is room for improvement, as we used to raise multiple issues via the process, but they pick them up slowly, and the response times are not as prompt as we would like.
Regarding how Splunk Cloud Platform's ingest and visualization features help improve my data reporting, I have some insights on dashboards, but from a fully comprehensive perspective of data flow and ingestion, I haven't been hands-on that much. As an admin, I have worked on the infrastructure side of it, so I am unable to provide thorough feedback on that.
I would rate Splunk Cloud Platform an eight out of ten overall as a solution for our organization.
Which deployment model are you using for this solution?
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
AI-driven analytics significantly enhance operational decision-making
What is our primary use case?
Currently, I am working with Splunk Cloud Platform and other things for my clients.
I have been working with Splunk Cloud Platform for around 2 years now while integrating it.
What is most valuable?
What I appreciate about Splunk Cloud Platform is that it's an AI-driven SIEM platform, and for data fusion stock, we require Splunk Cloud Platform because none other than Splunk Cloud Platform can have this data-driven stock implemented; it allows you to get into the data repository.
The real-time search capability of this product enhances operational decision-making, and it's very convincing; this aspect is very convincing from Splunk Cloud Platform's side.
What needs improvement?
The disadvantage of Splunk Cloud Platform is that its integration process should be improved.
The challenges I have encountered while integrating Splunk Cloud Platform include that integration is a bit difficult due to the coding required for the integrations.
For how long have I used the solution?
I have been working with Splunk Cloud Platform for around 2 years now while integrating it.
What was my experience with deployment of the solution?
I would say that it was a bit difficult to deploy Splunk Cloud Platform; the user interface is easy, but deployment is difficult because it needs coding to integrate things.
What do I think about the scalability of the solution?
I think it's a scalable solution; it's pretty much scalable.
How are customer service and support?
I can rate the technical support of Splunk Cloud Platform as eight; they are quite helpful.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
We are system integrators, but the client chose another vendor instead of NNTT.
How was the initial setup?
The deployment took around 3 to 4 months.
What about the implementation team?
Three people took part in deployment from my side.
It was indeed a huge deployment; it was one of the banks in Pakistan, so we required three resources to get it done.
What was our ROI?
Splunk Cloud Platform has impacted operational costs; it's a bit expensive, but it provides value for money.
What's my experience with pricing, setup cost, and licensing?
If I were to rate the price for the product from 1 to 10, I would rate it nine.
What other advice do I have?
I am currently working with the solution, but I need to know from which NNTT.
The interface is okay; its interface is good, and user interface is good.
I would recommend Splunk Cloud Platform to other users and organizations because it adds value to the organization; you can do different things with it because it's a pure analytical tool, not only a SIEM tool.
I am mostly focused on Splunk Cloud Platform because I chose this vendor due to the feature set that was offered by Splunk Cloud Platform; it was not being offered by any other vendor.
Splunk Cloud Platform is the vendor I am referring to, not NNTT.
Maintenance for Splunk Cloud Platform has been done manually, not automatically.
Usually, one person takes part in maintenance.
Regarding the number of users for Splunk Cloud Platform, it involves discussing the number of organizations or the number of people working in those organizations.
In general, I would rate Splunk Cloud Platform a nine.
Gives us better buffering performance and lower latency if we use the right components
What is our primary use case?
One client wanted their data in a readable format. He was in the UK, but his data center was in the US, so he tried to forward his data to the indexer. Because of the time zones, he faced some time stamping issues. They reached out to us to open a case that got assigned to me.
I learned which US time zone the data center was in and set the time stamps in the future. We changed the preferences to convert it into GMT so that whenever the data is onboarded to the indexes via universal or heavy forwarder, we can fetch the data in real-time.
We primarily use virtualization and deploy in Docker containers. We seldom use any physical servers. It's mostly deployed in a cloud environment or a virtual machine. It's typically Docker but sometimes Azure.
How has it helped my organization?
Splunk Cloud saved us a lot of money because we're working with databases like MongoDB and Oracle and using Splunk as a sync tool. It has its own indexes that cut costs by 15 to 20 percent.
It also improves our decision-making process. In one scenario, we compared the client's data from last year to this April and saw the year-on-year profit and loss. We could see which projects were successful. Compared to another SIEM or monitoring tool, it saved us time because the data is presented in a clean, customizable dashboard.
What is most valuable?
In an enterprise, you need a universal or heavy forwarder. If you don't have that, you need an HSE token or API request call and all the different components. In Splunk Cloud, you just have one instance to search all the data in your index. You don't need to manage it because Splunk handles that.
If you are using Splunk Enterprise, you need to understand, from A to Z, how the indexes and searches work and where the data is coming from. Splunk Cloud has a beautiful, user-friendly UI that lets you navigate all the settings.
It doesn't matter where the data comes from for integration. The dashboard gives you a brief overview.
When we're onboarding all that data using heavy forwarders, Splunk gives us better buffering performance and lower latency if we use the right components. If I use a light or universal forwarder, it often doesn't parse on the other end. Our projects use heavy forwarders and put those data into the index services while defining which indexes they should index. We are also micromanaging where that data should be.
The reporting is good so far. Sometimes, I help my clients improve their user experience. As an engineer, I would suggest that if a solution has back-end compatibility, clients should get out of their comfort zone and customize another app to create a dashboard or something else.
What needs improvement?
First-time users may struggle with the user interface. When I first used Splunk, I entered my username and password. After that, we get a dashboard on the left side with apps. At the top, you can click the gear icon to view the settings. Within those settings, there's a distributed console option with several settings. It's a bit overwhelming for a beginner. The user knows what they want and can search for it in the search bar. If I see several apps, my first instinct is to scroll down to find the app, or perhaps you will find that search and report. That bugged me when I was learning.
Application support is another problem. We created a custom Palo Alto app that isn't fully supported by the latest version of Splunk. We had to downgrade to older versions to use the custom app properly. That was one problem we faced daily with one client.
For how long have I used the solution?
I have been using the Splunk Cloud Platform for two years.
What do I think about the stability of the solution?
I rate Splunk Cloud seven out of 10 for stability.
What do I think about the scalability of the solution?
I rate Splunk Cloud eight out of 10 for scalability.
How are customer service and support?
I rate Splunk support six out of 10. They're knowledgeable, but their response times are sometimes slow.
How would you rate customer service and support?
Neutral
Which solution did I use previously and why did I switch?
We have Prometheus, but that only monitors Grafana and shows you a dashboard. Splunk is not just monitoring or grabbing data you search for. I've worked with cloud and enterprise. When we started using Splunk Cloud, we used it more like a dashboard to search data. Based on my understanding, I could create applications.
After moving into the enterprise side, I understood Splunk even more, including its components, bucket lifecycles, and how the indexes and configurations work. It's not simply transferring data from one to another. I can grab data from any system that consists of raw data. Splunk can also identify those data in the timestamp index form. We don't have any other vendors to compare it to.
How was the initial setup?
Deploying Splunk Cloud Platform is straightforward unless you use an automation tool like Ansible, Puppet, or Chef. It takes four to five hours. Installation can take a day in some cases, but it typically can be completed in less than five hours unless you're dealing with more complex data.
What's my experience with pricing, setup cost, and licensing?
Splunk Cloud is affordable, depending on your license. I don't know how much it costs exactly, but my colleague said it depends on your licensing and which features you use.
What other advice do I have?
I rate Splunk Cloud Platform eight out of 10. I would recommend this product.
Good for data aggregation and correlation for centralized logging and monitoring
What is our primary use case?
We use Splunk Cloud Platform for data aggregation and correlation for centralized logging and monitoring.
How has it helped my organization?
Splunk Cloud Platform has helped our organization reduce risk and allow for threat investigation to catch potential malicious traffic before it causes damage.
What is most valuable?
The most valuable feature of Splunk Cloud Platform is the ability to correlate events together and combine the data into one event.
The benefits we saw from using Splunk Cloud Platform are the time to detect and the ability to investigate faster.
Our organization monitors multiple cloud environments. Splunk Cloud Platform's direct cloud connection capabilities make data transfer easy.
Splunk Cloud Platform's end-to-end visibility into your cloud-native environment is key for security posture.
Splunk Cloud Platform has helped reduce our mean time to resolve by a significant portion.
Splunk Cloud Platform has helped improve our organization’s business resilience.
We have seen time to value using Splunk Cloud Platform. We immediately saw time to value after implementing the solution.
The consolidation of tools gives one place to look for logs and events. I wish there were more ways to consolidate the consoles.
Splunk Cloud Platform is easy to use, and users can quickly understand and do pretty much anything that their minds can create.
What needs improvement?
Splunk Cloud Platform should have better integrations with its suite of tools. Splunk Cloud Platform should include a more seamless connection with ES.
For how long have I used the solution?
I have been using Splunk Cloud Platform for eight years.
What do I think about the stability of the solution?
The solution provides good stability.
What do I think about the scalability of the solution?
As long as you have money, scaling the solution is easy.
How are customer service and support?
Our direct customer support team is very responsive. However, it's very hit or miss with Splunk tickets and trying to reach out. Most likely, we get escalated because they can't help us. It's very hard to work through issues that need to be resolved quickly via email. The conversations back and forth take a long time, and technical support takes a while to resolve urgent issues.
How would you rate customer service and support?
Neutral
How was the initial setup?
The Splunk engagement in the deployment was helpful, but there were many issues after implementing everything. So, it was smooth but with many hiccups.
What's my experience with pricing, setup cost, and licensing?
Splunk Cloud Platform is an expensive solution.
What other advice do I have?
Overall, I rate the solution an eight out of ten.
Which deployment model are you using for this solution?
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
No infrastructure maintenance frees up a lot of time and improves efficiency
What is our primary use case?
We use it a lot for IT operations. We monitor various services that we manage.
We do not monitor a multi-cloud environment. We have a single stack.
How has it helped my organization?
It is very stable. Many things get managed at the backend. The infrastructure is managed by Splunk. We just have to focus on the use cases and the value we can drive from Splunk. Being able to focus only on the outcome of the product is valuable for any organization.
There has not been a significant difference when it comes to the meantime to resolution because it all depends on the use case and how much time it takes to run. However, as an admin, just focusing on giving valuable insights and not having to manage the infrastructure has been the most beneficial. Otherwise, the quality of the use cases is still the same. There is no difference as such.
What is most valuable?
Not having to maintain any infrastructure is valuable. That frees up a lot of time as well.
What needs improvement?
We are on the classic Cloud that is hosted on GCP. There are a lot of functionalities that are missing for Splunk Cloud hosted on GCP but they are available on AWS. Adding more IPs to allow lists and many other functionalities are not supported on Splunk Cloud hosted on GCP. One good example is the ingest action which is not there in Splunk Cloud hosted on GCP. I wish they would add these missing features to the GCP platform.
For how long have I used the solution?
I have been using Splunk Cloud Platform for a year.
What do I think about the stability of the solution?
It is very stable.
What do I think about the scalability of the solution?
We definitely have room to scale. In the future, we might scale our environment. The amount of ingestion is going to increase.
How are customer service and support?
I would rate them a seven out of ten based on my experience. There were many instances where we did not receive proper help, so we had to escalate the issue through our account team and our customer success manager.
After the migration, whenever there was any maintenance, there would be an email saying that it was just maintenance. There were not many details about it. Once we started talking about it and giving feedback, they started adding more information. There are still some gaps in the support or the quality of service. From that perspective, I would rate them a seven out of ten.
How would you rate customer service and support?
Neutral
Which solution did I use previously and why did I switch?
We migrated to Splunk Cloud Platform from on-prem Splunk Enterprise a year ago. The main reason was to have no infrastructure management on our side. That was the main reason we shifted from Splunk Enterprise to Splunk Cloud Platform.
How was the initial setup?
It was completely a smooth transition. There was a lot of data that we moved from on-premise to cloud. The transition was definitely smooth. The licensing and pricing were handled by the higher management. I have no idea about it, but the entire process of moving the data over was very smooth.
We are using Splunk Cloud hosted on GCP.
What about the implementation team?
We utilized the professional services from Splunk for the migration, but after the migration, we have been taking care of everything.
Which other solutions did I evaluate?
We did not look into any other solution. We are totally into Splunk. We wanted a no-infrastructure-management environment and a better solution, so we moved to Splunk Cloud Platform.
What other advice do I have?
Splunk's unified platform has not helped consolidate networking, security, and IT observability tools. The only product we use is Splunk Cloud. We are not using any of the other products like ITES, enterprise security, etc. No consolidation is required for us.
I would rate Splunk Cloud Platform an eight out of ten.