
Splunk Cloud
Unified monitoring has improved security visibility and accelerated incident investigations
What is our primary use case?
Splunk Cloud Platform serves as our main security monitoring solution, where we send all of our different data sources into it and use it as a SIEM to write correlation rules. Other use cases involve our application development team and application monitoring team, who use it to monitor different applications we have in the environment.
A specific example of how I use Splunk Cloud Platform for security monitoring is that we send DNS logs to it and run them through correlation rules looking for anomalous activity.
What is most valuable?
Splunk Cloud Platform's best features are its flexibility and customizability, which make it almost endless in the amount of things you can do on the platform. Support is very strong, and the documentation is excellent.
Splunk Cloud Platform has positively impacted my organization by increasing visibility and correlation of different data from different sources. That increased visibility and correlation has helped my team by eliminating various data silos and repositories where we may not be able to draw adequate conclusions. Having all that data in one place, normalized, and then having correlation rules run against it helps with fidelity and alerting, and it also speeds up investigation times.
What needs improvement?
Splunk Cloud Platform is a pretty robust platform, so I'm not certain how it can be improved. The flexibility and customization that are strengths of the tool can also be a weakness, as there is so much you can do in it that it can be overwhelming.
Regarding improvements on usability or onboarding for new users, I think onboarding for new users can be enhanced. I know Splunk training exists; it would be nice if there were something a little more curated because if you don't know what you need to learn, it can be overwhelming trying to go to Splunk training at Splunk University.
For how long have I used the solution?
I have been using Splunk Cloud Platform for about five years.
What do I think about the stability of the solution?
Splunk Cloud Platform is stable.
What do I think about the scalability of the solution?
Splunk Cloud Platform's ability to scale aligns well with my organization's demand fluctuations, and there is no impact on our IT resources. Scalability functionality is definitely there, even though we haven't had to take advantage of it.
How are customer service and support?
Customer support is strong; whenever I have an issue, I can put in a ticket or call and always get good help.
Which solution did I use previously and why did I switch?
I previously used LogRhythm before Splunk Cloud Platform. LogRhythm was difficult to manage, and its interfaces were clunky; it was not a very good product overall.
What's my experience with pricing, setup cost, and licensing?
My experience with pricing, setup cost, and licensing is that it was pretty confusing. When we initially got Splunk Cloud Platform, the SVC model, active storage, and archive storage were all pretty confusing. There could be more transparency about how things are licensed.
Which other solutions did I evaluate?
Before choosing Splunk Cloud Platform, we did look at other options, but it has been so long that I honestly cannot remember which ones.
What other advice do I have?
My advice for others looking into using Splunk Cloud Platform is to be clear on the pricing and what you need, as well as what Splunk Cloud Platform is going to provide. Having clear use cases about what you want Splunk Cloud Platform to do is important because it is very flexible, and if you don't know what you want to do with the tool, you can get lost. I would rate this product an eight overall.
Unified data dashboards have transformed desktop support and automated our inventory workflows
What is our primary use case?
My main use case for Splunk Cloud Platform involves working on desktop support and making dashboards for our inventory, which includes tracking computers going offline, handling break-fix issues, and managing various Windows projects.
For one of those projects, I pull data in from Active Directory, SCCM, Tririga, and CMDB, which are all multiple sources. In Active Directory, we have the version of the computer, whether it's Windows 10 or 11, and we have another external lookup that tells us when those are due for upgrade. So if a computer is due for upgrade, say in 2026 or 2027, I use Splunk Cloud Platform to filter that out through 3,500 machines, and it helps us keep track of where we are and what we need to do.
The biggest use involves all the data we pull from different sources such as AD, CMDB, Tririga, and ServiceNow, and we compile all that data into one table for compatibility comparisons. Sometimes they list different locations, and it helps us automatically create tickets if things are wrong, which we can then distribute to my tech team.
What is most valuable?
The best features Splunk Cloud Platform offers are primarily the lookups, as I rely heavily on them. I am not great with searches, but once I figure out the searches, I create big lookups that run every day, allowing me to pull all the data I need right from one master source, which is how I mostly use it.
The daily lookups and master source help tremendously because before Splunk Cloud Platform, I kept everything in Excel lookups, making multiple VLOOKUPs from different data sources almost weekly, which took a lot of time, filtering, and sorting. Now with Splunk Cloud Platform, it all happens automatically every day, and I can simply look at the results instead of continuously finding all the info.
Splunk Cloud Platform has positively impacted my organization tremendously since we have had it. While I provided my use cases, there are other departments with their own as well, including our scientists who can now see their data on Splunk Cloud Platform TVs showing whether computers are up or down. There is also a security team that utilizes Splunk Cloud Platform for their security measures. While I do not have information on what they do, they are the ones that brought it in and helped us set our setup. So my whole company is pretty much running on Splunk Cloud Platform now.
What needs improvement?
Regarding improvements for Splunk Cloud Platform, I do not have any complaints as I think it is pretty good already.
For how long have I used the solution?
I have been using Splunk Cloud Platform for about three to four years.
What do I think about the stability of the solution?
Splunk Cloud Platform is stable.
What do I think about the scalability of the solution?
The ability of Splunk Cloud Platform to scale aligns well with my organization's data demand fluctuations. My company has significant data needs, and the data engineers I communicate with are skilled at scalability and making searches smaller to avoid being too large. Overall, they do well.
How are customer service and support?
Customer support is great; I attend the convention every year and can talk to whoever I need. I have taken classes and had discussions with proctors, and everyone has been very helpful.
Which solution did I use previously and why did I switch?
I have not previously used a different solution; I am a first-time learner in this.
What was our ROI?
There is definitely a time and resource saving for my company with Splunk Cloud Platform. I do not know the pricing, so I cannot provide a return on investment, but I feel it has been very helpful for my team.
Which other solutions did I evaluate?
I did not evaluate other options before choosing Splunk Cloud Platform, as all I used before was Excel. Splunk Cloud Platform is my first platform.
What other advice do I have?
Without looking directly at metrics, I can say it has saved me hours and days in a month. It has had a massive impact on my field. I could not live without it, as I do everything pretty much on Splunk Cloud Platform at work to keep us organized. It has been amazing.
I give Splunk Cloud Platform a rating of 10 out of 10. I choose a 10 because I enjoy having a single data source for all my data sets, and it has made my life much easier in managing our data sets, projects, and the various uses I get out of it.
I cannot provide insight into Splunk Cloud Platform's governance and security regarding AI capabilities, as I am not familiar with the AI features in Splunk Cloud Platform yet. I have only used some outside AI, such as Cloud Code, to help me create dashboards, which is really the most use I get out of it, not within Splunk Cloud Platform.
I feel that the accuracy and reliability of output in Splunk Cloud Platform depend on the person coding it. If the coding is right, it will be reliable, but I need to validate it, just as with anything else. If not, then it is going to be wrong, but that would not be on Splunk Cloud Platform; it would be on the person coding it.
I have only used cloud, so I have not experienced hybrid or on-premises. The cloud works fairly well; however, some really large searches can take some time, but since I mostly work in lookups, I have my setup to be pretty snappy, so I do not run into too many issues.
I have zero interest in Splunk Cloud Platform's AI models, using some external AI for help rather than the internal AI models, which I do not think my company has even adopted yet.
I do not know much about Splunk Cloud Platform's app ecosystem as it has not been an area I have gotten involved in yet. I know they exist, but I have just not worked with them.
I have only used Splunk Cloud Platform's internal models, so I have no experience with third-party integrations, leaving me unsure about any influence they may have on my data strategy.
The subscription model does not impact my financial planning for data platform investments, as I do not purchase Splunk Cloud Platform or anything; I am just a power user of it.
For others looking into using Splunk Cloud Platform, I advise to sit down and learn it. That is what I did. I did not know how to code or anything; I used some AI to help me get started and then kept learning. The more I learned, the more I saw how useful it was, and it has been great.
Which deployment model are you using for this solution?
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Centralized logging has improved security visibility and accelerated incident response
What is our primary use case?
My main use case for Splunk Cloud Platform is security operations. For security operations, we ingest all internal logging into Splunk Cloud Platform, and that's where we get and do all of our internal review for malicious activity.
What is most valuable?
The best features Splunk Cloud Platform offers include its overall usability, which is good, as well as the native connectors with other applications that help in getting data from major applications like Okta and more. Additionally, features related to identity and asset management are also beneficial.
Splunk Cloud Platform has positively impacted our organization by allowing visibility into our organization in a positive light. It has also provided a central logging source for many of our applications, which has been good. It has improved incident response time as our partnering SOC uses the platform to surface alerts, reducing time. In terms of compliance, it serves as a source of audit evidence and allows us to ingest and hold logs longer than other apps natively hold.
What needs improvement?
Splunk Cloud Platform is on the pricier side for ingest and storage costs. There are many different features and things to use, with many built well. However, certain areas could improve usability, making it more applicable across different companies and more adaptable to various situations rather than being targeted to a single use case. Usability could improve in certain areas, including AI feature enhancements, and I find myself gravitating towards using Claude rather than Splunk Cloud Platform app or UI itself. Ingesting and storing data within Splunk Cloud Platform is expensive.
From my experience with Splunk Cloud Platform, the accuracy and reliability of output are relatively low when creating SPL and using it to find trends within the ingested data. I have seen better accuracy with the MCP, but the native AI capabilities within the console are not very accurate.
Over the last three years since our last contract, we've gone from 100 gigabytes of ingest to 300 gigabytes of ingest. In terms of scaling with the company, we have repeatedly hit the issue of trying to get as much data in as possible while being cost-conscious. Therefore, we're at a borderline of it being able to scale and it not scaling.
For how long have I used the solution?
I have been using Splunk Cloud Platform for two years.
What do I think about the stability of the solution?
I find Splunk Cloud Platform to be stable.
What do I think about the scalability of the solution?
Splunk Cloud Platform is scalable.
How are customer service and support?
The customer support is pretty timely. I would rate the customer support a seven out of ten.
Which solution did I use previously and why did I switch?
I have not previously used a different solution.
What was our ROI?
I think we're on the verge of seeing a return on investment with AI capabilities, especially related to AI-generated AI SOC or replacing our SOC needs. In the past few years, the return on investment has been mainly observed in the visibility aspect, but I wouldn't say there's been much impact on human or job duty aspects so far.
What's my experience with pricing, setup cost, and licensing?
I have not dealt with pricing, setup cost, or licensing myself, but I have heard secondhand about our involvement with pricing and our last license increase.
Which other solutions did I evaluate?
Before choosing Splunk Cloud Platform, I did not evaluate other options.
What other advice do I have?
Regarding governance and security in Splunk Cloud Platform, I think it provides a reliable source for audit logs and allows evidence to be tied out for compliance items.
Splunk Cloud Platform is deployed in our organization using a public cloud. We use AWS as our cloud provider. I don't think we purchased Splunk Cloud Platform through the AWS Marketplace.
I can only speak to the visibility into cloud environments, as I don't have experience with on-premises or hybrid setups. I have not had any experience with the zero-setup feature for AI models in Splunk Cloud Platform.
Our perception of using native models over third-party integrations in Splunk Cloud Platform's environment is that we have specific models approved for our data, which is the main focus of our strategy.
My experience with Splunk Cloud Platform's app ecosystem is that updates are pretty simple, and I haven't had any issues with that. Overall, the experience is pretty fluid.
My advice for others looking into using Splunk Cloud Platform is to understand the data you want to ingest and also consider if there are other tools that could better search a large amount of data for your needs, as it depends on the size of the company and the overall staff. I would rate this product an eight out of ten overall.
Which deployment model are you using for this solution?
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Logging platform has improved dashboard visibility and simplifies troubleshooting for dev teams
What is our primary use case?
My main use case for Splunk Cloud Platform is building dashboards and alerts to help aid our Dev team and video team troubleshoot.
For our acquisitions team, I set up an alert to track the provider issues that cause the errors. From them, it leads to how many times a provider goes down, and it sends it to a web hook.
We mainly use Splunk Cloud Platform to troubleshoot through our logs and find areas of weakness or help us determine where something has gone wrong with our microservices through AWS.
What is most valuable?
The best features Splunk Cloud Platform offers are that it is easy to learn and the accessibility to the different features as well as step-by-step processes.
What makes it easy to learn is the querying style in Splunk, which is straightforward and simple in syntax.
Splunk Cloud Platform positively impacts our organization by allowing us to go through our logs more simply and filter out different material that we are looking at, as well as collect logs in one place for us to search through and build comprehensive dashboards to show leadership and dev.
Splunk Cloud Platform has reduced our errors and has helped us troubleshoot significantly with the alerts that we have set up with the logging that it offers. We have been able to trace issues faster and get more engineers to locate the errors, so visibility has been excellent.
What needs improvement?
I have not had too much interaction with Splunk Cloud Platform, with only three months of experience using it. I have not come across any flaws yet, but I am sure as always, things will come up.
For how long have I used the solution?
I have been using Splunk Cloud Platform for three months.
What do I think about the stability of the solution?
Splunk Cloud Platform has been stable for the past three months.
What other advice do I have?
I have not used Splunk Cloud Platform's AI capabilities.
I have not used Splunk Cloud Platform's zero-setup feature for AI models.
I do not have experience managing updates within Splunk Cloud Platform's app ecosystem.
The solution's visibility into multiple environments, such as cloud, on-premises, and hybrid, is very useful, but I am very siloed, so I do not really work with anything else. I would rate this product an 8.
Which deployment model are you using for this solution?
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Advanced automation has boosted threat detection and supports faster malware incident response
What is our primary use case?
My main use case for Splunk Cloud Platform is to detect malware and respond to incidents.
What is most valuable?
The best features Splunk Cloud Platform offers include Splunk SOAR, the automation, and playbooks.
Splunk Cloud Platform has positively impacted my organization by enhancing the observability of the environment, allowing us to detect threats faster.
What needs improvement?
One way Splunk Cloud Platform can be improved is in usability, as the platform is difficult to navigate, and it can be hard to find all features.
For how long have I used the solution?
I have been using Splunk Cloud Platform for one year.
What other advice do I have?
There are no other improvements I think Splunk Cloud Platform needs; it is excellent.
Unified monitoring has improved incident response while query optimization still needs work
What is our primary use case?
The main use cases for Splunk Cloud Platform involve forwarding logs from our application database using Splunk Forwarder to the Splunk tools so that we can have dashboards to check in case of any production issues, vulnerabilities, or incident cases.
What is most valuable?
What I appreciate about Splunk Cloud Platform is that observability is strong, and we can have real-time data with fast time to value. We can conduct advanced searches by leveraging the search processing language, and AI assistants are available to query and analyze data sets. This makes it excellent for unified observability and advanced searches.
Splunk Cloud Platform improves the way the organization functions by being used during SIEM and ITSM tickets to enhance infrastructure monitoring so that we can have customizable dashboards, interactive visualization, and out-of-the-box reporting for all stakeholders, whether technical or non-technical. Through this, we can achieve unified observability and full-stack visibility.
What needs improvement?
I would like to see Splunk Cloud Platform become more user-friendly compared to others. For example, Grafana is very user-friendly where you can easily create graphs.
Regarding missing features or functionalities, I believe index management and performance optimization should be enhanced so that we can optimize the SPL queries instead of using transactions whenever feasible.
For how long have I used the solution?
I have been working in my current field and in the industry for around 13.5 years.
What do I think about the stability of the solution?
I find Splunk Cloud Platform to be stable overall.
What do I think about the scalability of the solution?
Regarding the platform's ability to scale aligning with my organization's demand fluctuations, scalability requires some changes to our architecture involving planning related to the framework so it can adapt to growing data volume and user demands. Every day MFT and integration demands are increasing, so we must choose the right topologies for a scalable architecture, and role distribution should be in place. We need to use load balancing and capacity planning. We should take advantage of what Splunk Enterprise is providing by reviewing components such as Splunk Enterprise deployment, distributing indexing and searching so that we can use that platform to manage all user objects and data storage.
How are customer service and support?
I evaluate customer service and technical support from Splunk to be good. On a scale of one to ten, I would rate the technical support about nine.
Which solution did I use previously and why did I switch?
Currently there are no IBM solutions in use, but earlier I worked on App Connect Enterprise and IBM Integration Bus, which are integration-related technologies.
How was the initial setup?
The setup process of Splunk is straightforward. If we can provide the process document, it is easy. We conducted some development depending on the forwarder. By using the universal forwarder, we collected logs. We have to set up the indexes and search heads for medium enterprises. For large enterprises, the setup is more complex because we need clustering mechanisms such as load balancing, search head cluster, and index cluster. We can accomplish this by using the universal forwarder and indexes; Splunk will manage the indexes, storage, and upgrades, but as a customer we must manage the universal forwarder, data onboarding, and dashboards. These parts depend on the skill sets we have available.
What about the implementation team?
My company has a business relationship with Splunk as we are a customer, and they onboard the vendor as per their policy. We are managing them and are not part of that setup.
What was our ROI?
I find Splunk Cloud Platform to be cost-effective. If we optimize it, we can achieve ROI by seeing reduced downtime and improved operational efficiency. We can make changes in one go by having perfect compliance automation related to GDPR and PCI DSS.
The key differences and strengths of Splunk Cloud Platform in comparison to other technologies indicate that Splunk Cloud provides consolidated capabilities such as SIEM, log management, reporting tools, and monitoring dashboards that deliver better performance in monitoring. Depending on cost, if we optimize that very effectively, we can achieve good ROI by reducing ingested data volume, using data retention tiers, or summary indexing. Through this approach we can improve Splunk Cloud Platform ROI and use that tool very effectively.
What's my experience with pricing, setup cost, and licensing?
Regarding the pricing aspect, setup cost, and licensing of Splunk Cloud Platform, I have not directly joined that process, but it depends on the ingestion volume. It is based on the volume of data ingested per day, so we have to exclude unnecessary data sources and remove duplicate events to optimize cost improvement areas. We can establish data retention policies depending on hot and warm data so that the data will have summary indexing and reduce infrastructure cost and storage cost. We should have the right size infrastructure, and we have to monitor that license usage.
Which other solutions did I evaluate?
The key differences and strengths of Splunk Cloud Platform in comparison to other technologies indicate that Splunk Cloud provides consolidated capabilities such as SIEM, log management, reporting tools, and monitoring dashboards that deliver better performance in monitoring. Depending on cost, if we optimize that very effectively, we can achieve good ROI by reducing ingested data volume, using data retention tiers, or summary indexing. Through this approach we can improve Splunk Cloud Platform ROI and use that tool very effectively.
The main drawbacks of Splunk Cloud Platform include that while it removes the infrastructure management overhead, it has limitations such as volume growth becoming expensive. The licensing is typically based on ingestion volume or workload, so we must optimize that, and there is no direct access to the underlying server; we must use forwarding tools. Some advanced configurations are needed to support tickets or manage change processes. These are dependencies where we have to rely on vendor dependencies for maintenance windows. Data residency and compliance concerns also exist, where scenarios such as GDPR, banking, and healthcare have strict regulations regarding where data must be stored, so we have to consider that concern when making the decision.
What other advice do I have?
Generally, most enterprises find that Splunk Cloud Platform is reducing operational overhead, and we should focus more on security. It is a good choice when needing a managed service or for cloud-first organizations. For security and compliance, when custom scripts and third-party add-ons are needed, there are restrictions, and for very large volumes of multiple terabytes, it is not advisable because the licensing cost is very high and optimization will be critical. If complete administrative control is needed, we can avoid using Splunk Cloud Platform. I would rate this review overall as a seven out of ten.
Which deployment model are you using for this solution?
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Advanced ai-driven threat hunting has improved detection speed and streamlined investigations
What is our primary use case?
I was a consumer using Splunk Cloud Platform at that time. I have been familiar with Splunk Cloud Platform. I was a user of Splunk Cloud Platform and a customer also.
What is most valuable?
Splunk Cloud Platform is a data analysis tool that works on big data and unstructured data. What I appreciated about it is that Splunk data processing is very good. When I performed search and threat hunting on Splunk, I was very satisfied.
Splunk Cloud Platform supports AI automation and can empower analysts to use AI assistance and agentic playbooks to accelerate threat detection, investigation, and mean time to detect or mean time to respond.
Since Splunk already offers me an embedded AI solution, why would I go to any other AI solution? Splunk is helping us in the new era of AI.
What needs improvement?
There is always room for improvement. Splunk can improve because it is a very expensive product. Because of the cost, we do not have as many skilled resources for Splunk, which makes it very difficult to find a compatible resource to help us troubleshoot.
For how long have I used the solution?
I have worked with Splunk Cloud Platform for around 10 to 11 months.
What do I think about the stability of the solution?
Splunk Cloud Platform is a very vendor-diverse product. You can integrate almost anything around the infrastructure. It totally supports integration.
What do I think about the scalability of the solution?
Splunk Cloud Platform is currently the best option in the market if you have the capacity to pay what Splunk requires. If you are tight on budget, you can consider other options. With respect to price, Splunk is the best solution, but it is expensive.
When comparing it with LogRhythm, LogRhythm is for small organizations, but Splunk has financial considerations. Splunk has more advantages than LogRhythm when comparing from a financial perspective.
How are customer service and support?
Splunk Cloud Platform is currently owned by Cisco, and Cisco has very great support in my region.
Which solution did I use previously and why did I switch?
I was only using Splunk Cloud Platform.
How was the initial setup?
If you are planning to deploy Splunk Cloud Platform, there is a whole lot of architecture planning involved. You need to plan accordingly as per your infrastructure needs.
What about the implementation team?
I was on the technical side, and the finances were managed by the governance team. I cannot answer questions regarding the subscription model and pricing structure.
What was our ROI?
Splunk Cloud Platform is a Gartner leading product. Splunk is superior in comparison with any other SIEM.
What's my experience with pricing, setup cost, and licensing?
Splunk Cloud Platform is a Gartner leading product. Splunk is superior in comparison with any other SIEM.
Which other solutions did I evaluate?
Splunk Cloud Platform should be improved in certain aspects. In comparison with QRadar, QRadar has dedicated log sources, but Splunk does not have dedicated log sources. We can only sort the log sources from the IPs or hostnames. Splunk can do that, or if they do not do that, it will not affect anything, but it could be beneficial for a SOC analyst to specify the data source.
What other advice do I have?
I cannot suggest additional features that could improve the rating further. I gave this review a rating of 9.
Daily analytics have transformed how I monitor searches, alerts, and integrations at scale
What is our primary use case?
My use case for Splunk Cloud Platform involves working in an organization that provides a daily full dashboard showing daily searches, daily ingestion, daily alerts, and more.
What is most valuable?
I really appreciate the ingestion features of Splunk Cloud Platform, which allow us to ingest data in various ways such as through an HEC token or Splunk Heavy Forwarder. Creating dashboards is very easy; currently, they provide two ways: a drag-and-drop grid layout or the traditional coding method.
I find the search capabilities effective because SPL, Splunk Query Language, is very easy to use. They are currently providing SPL2 with AI enhancing features that make searching really easy.
I use the alerting mechanisms with Splunk queries, having created multiple alerts that can send emails or display in the dashboard, making the alerting mechanism very helpful.
In terms of visualization features, creating dashboards on Splunk Cloud Platform is really easy, especially with the grid platform for drag-and-drop. The dashboard analytics feature is very helpful and fun to use.
I would describe the impact of integrations with third-party tools as powerful. We use add-ons like AWS CloudWatch, and integrating with any app on Splunk Cloud Platform is very easy.
What needs improvement?
Splunk Cloud Platform has room for improvement because managing the architecture for a newcomer, such as an intern, can be hard. They could provide better documentation and videos to help with learning.
I find the documentation of Splunk Cloud Platform fine in what I have learned, but having more visual videos to accompany the documents would be helpful for learners.
For how long have I used the solution?
I have been using Splunk Cloud Platform for six months in my training as well as in production, learning about creating apps, creating custom commands, and creating dashboards and analytical capabilities.
What's my experience with pricing, setup cost, and licensing?
The pricing of Splunk Cloud Platform is a concern for me; it is very costly, making it hard for small to medium vendors to afford.
Splunk does not actually save resources for us because it only helps with security. We have to buy more computational power for advanced usage.
Which other solutions did I evaluate?
I compare Splunk Cloud Platform with others like CrowdStrike and NG-SIEMs. While they are similar, Splunk is really way ahead, providing everything required.
For small and middle-class organizations, I would not recommend Splunk Cloud Platform because there are cheaper tools available. However, I would recommend it for very large organizations.
What other advice do I have?
Time-wise, Splunk Cloud Platform does save me time because if I am ingesting daily 2TB of data, I create the dashboard one time, and it updates automatically, allowing me to do data analytics more easily. I would rate this product a 9.
Centralized monitoring has accelerated incident investigations and provides hybrid security visibility
What is our primary use case?
In my daily work as an SOC L1, my use cases involve using Splunk Cloud Platform primarily for centralized log management and real-time incident detection. It acts as our central nervous system for security data. We stream logs from our other tools such as Wazuh directly into Splunk Cloud Platform, and the biggest use case for us is the speed of investigation. When an alert comes in, I can search through a massive amount of data in seconds to trace exactly what happened. It helps us to visualize the attack chain and prioritize what actually needs attention.
What is most valuable?
The biggest thing I appreciate about Splunk Cloud Platform is the stability of this platform. It is always up, and I have never had to worry about maintenance or downtime interrupting my shift. Search performance is another huge advantage, allowing me to query massive data sets in seconds when I am hunting for a specific log.
Since we are using Splunk Cloud Platform, the initial deployment is easy because we do not have to deal with the back-end infrastructure, which is a huge relief. It is a true SaaS experience, so you are not spending time patching servers or worrying about hardware capability. For me as an L1, the deployment part is really about onboarding our data sources. Once you have the connector set up pulling the logs from device endpoints and other tools such as Wazuh, it is fairly smooth.
For me as an analyst, maintaining Splunk Cloud Platform is really about keeping the data pipeline healthy. My focus is on making sure our Universal Forwarders are pushing data properly from our endpoints or other tools. I also keep an eye on index health and manage our retention policies so we do not exceed our storage systems.
About the app ecosystem within Splunk Cloud Platform, instead of us having to spend hours or days manually figuring out how to parse logs or map them to a common information model such as CIM, we can usually grab the right app from Splunkbase, and it does the heavy lifting for us, normalizing the data so that when I run a search, the fields are already in a structured and searchable format. It saves me so much time in day-to-day investigations, and because I do not have to worry about whether the log format is broken, the app handles that translation.
About visibility within Splunk Cloud Platform, the hybrid visibility is actually one of its strongest points. Since we handle a mix of environments for our clients according to their requirements, being able to pull everything into one central place is critical for us. We use Universal Forwarders on our on-premises servers to securely stream logs up to the Splunk Cloud Platform instance. For me, it effectively erases the boundary between on-premises and cloud. It does not matter if the log is coming from a server in our local data center or a cloud-hosted app. It all lands in that same single pane of glass.
What needs improvement?
The biggest downside about Splunk Cloud Platform for me is the cost. It is definitely on the expensive side, and you have to be very careful about what you ingest from sources. We are always mindful of our log volume because if you are not constantly tuning your filters or managing what data goes in, the cost can add up fairly quickly.
What do I think about the scalability of the solution?
In terms of scalability, Splunk Cloud Platform is one of the things that makes my L1 task much easier. As we onboard more devices or increase our log ingestions and stay ahead of threats, I never have to worry about the platform hitting the wall. With Splunk Cloud Platform, it just handles it. I have noticed that even when we ramp up the data from other tools such as Wazuh or add new endpoints, the search speed remains really consistent. It does not get sluggish or slow down, which is huge when I am in the middle of an investigation.
How are customer service and support?
We have a team to contact for technical support for Splunk Cloud Platform. I have not really been involved in that technical support phase, and I do not have much knowledge about that process or what is going on in the background. I would give around an eight out of ten for technical support for Splunk Cloud Platform.
Which other solutions did I evaluate?
I have not currently used any alternatives to Splunk Cloud Platform. I have not gained hands-on experience with other cloud platforms.
What other advice do I have?
I would give Splunk Cloud Platform an 8.5 overall rating for everything. We are a customer of Splunk Cloud Platform.
Custom views and shared dashboards have improved how I organize and collaborate on sensitive data
What is our primary use case?
My usual use cases for Splunk Cloud Platform include data, data integration, and dashboards. I currently have three use cases.
What is most valuable?
I find the features and capabilities of Splunk Cloud Platform to be highly valuable because of how customizable it is for my view and the data we need to put into it. The ability to organize the data and set up different views is particularly useful.
I also appreciate how easy it is to work with coworkers on the platform to collaborate on the same issues.
The tangible benefits I've observed since starting with Splunk Cloud Platform are significant. It's pretty much the standard for what we use it for. If we're working with a consultant or we bring in someone new, most people know the platform or at least have been exposed to it. This exposure and the platform's big name and familiarity make it easy to direct people around in it, show them the data, and collaborate.
What needs improvement?
I'm not quite sure how Splunk Cloud Platform could be improved or enhanced. I would suggest keeping what works. Sometimes it can feel slightly slow in what it brings up, but I don't know if a lot of times that's on our end with the data that's getting in. Staying up to date with current trends and technologies will be good enough for me. It's already a good platform, and I wouldn't recommend too many changes or tweaks.
The major thing that could be optimized is the speed, so it could be a bit faster.
For how long have I used the solution?
I've been working with Splunk Cloud Platform for about three years.
What do I think about the stability of the solution?
Splunk Cloud Platform has been living up to my expectations regarding reliability and stability so far.
I think we rarely ever have Splunk Cloud Platform crash or error out where we're not able to bring up the site and access what we need to do in it. Usually, in the rare case that it does happen, it's usually back up within 20 to 30 minutes. Stability-wise, sometimes it'll get slow, but usually, if we are patient, it pulls up everything we need it to.
What do I think about the scalability of the solution?
I believe Splunk Cloud Platform scales pretty well. We use it for quite a bit of the data and things that we house and have coming in, and it's usually pretty snappy. Every once in a while, we may have to reload something or have trouble putting in data, but this happens maybe once every couple of days or so, which is expected for how heavy we use it. For the most part, it's pretty smooth.
How are customer service and support?
I do not often communicate with the technical support of Splunk Cloud Platform. I've never communicated with their support.
Which solution did I use previously and why did I switch?
I did not use a different solution for the same use cases before Splunk Cloud Platform.
Which other solutions did I evaluate?
I did not evaluate other options before choosing Splunk Cloud Platform; it was recommended.
What other advice do I have?
Once everything was set up better for me, Splunk Cloud Platform provides pretty good visibility into the different data we put into it. I would rate the visibility and ease at about a seven out of ten.
I measure that ease by looking at failure rates, how long it takes to update anything, and the UI and how easy it is. I am confident and happy with these metrics.
I would rate the scalability level of Splunk Cloud Platform at about an eight.
I have not used the zero-setup feature for AI models in Splunk Cloud Platform. We have not really integrated that feature at all.
I decided to go with Splunk Cloud Platform because it is an industry widely used platform. It was vetted by the US government as a right to use, and that compliance is needed for the work I do. It's a vetted, trusted platform to move and organize very sensitive data.
I believe there was some Splunk training through a link. I'm not sure if it was on the website, training, documentation, and videos and things on just best use cases and features. That was a little while ago, though.
The materials I felt were surface level, good-to-know information. They were helpful, but very basic.
It was a while ago, and that was just my impression of it back then. I'm not exactly sure if I would want them to provide more detailed information at this stage.
I don't deal with the pricing side of it. I wouldn't know how the subscription model impacts my financial planning for data platform investments.
I prefer native models in Splunk's environment. I prefer it because it keeps me in control more and keeps the data local.
This preference influences my data strategy because it'll allow us to be within our own environment, not have to obfuscate or change the way we would use a model that wasn't local to us. Instead of having to navigate around or omit or change details, we can upload what we need to and know that the data won't go past our service.
My overall rating for Splunk Cloud Platform is an eight out of ten.