Unified log analytics has transformed security monitoring and cuts breach detection to minutes
What is our primary use case?
Splunk Cloud Platform is my main use case, which we sell to our channel partners within the channel community that then sell it to their customers, primarily as a cloud-based platform that collects data, analytics, and monitoring. It is mainly used for log management, security monitoring, known as SIEM, IT operations monitoring, and customers can use it for infrastructure troubleshooting and compliance reporting, but primarily for getting real-time analytics. It is a useful SaaS cloud-hosted tool that manages infrastructure, upgrades, scaling, and maintenance for customers.
A specific example of how a customer uses Splunk Cloud Platform in their day-to-day operations is how it collects logs from Linux, Windows servers, Azure, and AWS. Teams can run powerful searches using SPL, search processing language, to find failed logins, investigate outages, and trace application errors. It also automatically alerts the team for system failures, CPU spikes, security threats when they occur, and API slowdowns, showcasing just a couple of examples of what our customers use Splunk Cloud Platform for.
Splunk Cloud Platform provides a complete picture regarding how customers use it. It includes capabilities around machine learning and dashboards that allow them to monitor KPIs, have a real-time operational view, and executive reporting from all the logs.
What is most valuable?
Splunk Cloud Platform's best features include its scalability, as it can handle terabytes of data and is probably one of the market leaders within SIEM capability, which is very strong. In this day and age, cybersecurity products need great integration, and it has a huge ecosystem that can integrate with over 1,200 integrations and applications. Another major positive is that it is cloud-managed, which means less infrastructure management. Finally, the main feature that many people value, and our customers provide feedback on, is real-time analytics with fast detection and troubleshooting.
Splunk Cloud Platform has positively impacted my organization by reducing the need for infrastructure management due to being a SaaS cloud platform. The main use case is detecting cyber attacks faster. For example, a large financial institution, a bank, used Splunk Cloud Platform and identified failed logins, impossible travel events, VPN anomalies, and endpoint alerts when attackers attempted credential stuffing. Without Splunk Cloud Platform, those alerts existed in multiple systems, and detection could take days, but with it, events were correlated correctly and raised a single notable event, triggering alarms immediately. This significantly improves mean time to detect and respond, reducing investigation time from hours to just 10 to 30 minutes for common incidents by providing a single pane of glass visibility for SOC teams.
What needs improvement?
Splunk Cloud Platform has areas for improvement, including the fact that it is obviously an enterprise tool and can be expensive, which is the biggest complaint I have noted. Costs can rise due to high data ingestion and long retention periods, along with a complex licensing structure that makes pricing difficult to predict as usage grows, especially since more systems send logs. There are also performance concerns at scale where users have reported slower searches and expensive long-term storage needs, particularly in multi-terabyte environments. Additionally, operational complexity exists as enterprises still need to do data onboarding, create dashboards, handle retention policies, access control, and performance tuning.
These are the three key areas of improvement I have identified.
For how long have I used the solution?
I have been using Splunk Cloud Platform for approximately three to four years at various different places of work.
What do I think about the stability of the solution?
Splunk Cloud Platform is undeniably stable, which is one of its key advantages. While it may come with a high price tag and face scalability issues, its stability is commendable, enabling easy visibility into logs, effective data ingestion, and successful operations with diverse integrations and third-party platforms.
What do I think about the scalability of the solution?
My customers typically leverage scalability and integration features across the main cloud providers, primarily AWS, integrating with CloudWatch, CloudTrail, S3, and Lambda for cloud security monitoring and audit logging. They also integrate with the entire Microsoft stack, including Defender for Cloud, Sentinel, Azure ID, and Azure Monitoring, as well as Google Cloud, where GCP integrates with Cloud Logging and Pub/Sub security command center. We also have integrations with major SIEMs including Sophos, CrowdStrike, and firewalls from Palo, Fortinet, Cisco, and Juniper, and identity management tools including Okta, Ping, and Duo. For threat intelligence, we get much of our integration from Recorded Future as our main integration, but they are just some of the top ones we integrate with effectively.
Splunk Cloud Platform's scalability works well, especially for smaller businesses, but can present issues for larger enterprises facing stricter regulations and greater integration requirements.
How are customer service and support?
Customer support with Splunk Cloud Platform is really good. The CSMs and account managers in the channel team are great, providing assistance not just with selling the product but also for implementation, deployment, and aftercare. I would rate customer support a nine on a scale of one to ten. There have been a couple of instances where issues arose, which is why it does not earn a full ten, but overall, it stands out as a really good platform and contributes to why they remain number one in the business.
Which solution did I use previously and why did I switch?
I have not personally switched from a different solution to Splunk Cloud Platform, but we utilize various different solutions for SIEM, including QRadar and Exabeam, alongside newer tools including DataDog and Elastic.
How was the initial setup?
My experience with pricing, setup costs, and licensing is that while the setup costs are straightforward and not overly burdensome, licensing for small to mid-sized enterprises is favorable. Highly regulated businesses, including financial services and banks, tend to use Splunk Cloud Platform regularly, and while it is a high-quality product, the costs can elevate significantly as scalability needs grow within larger enterprises.
What about the implementation team?
My partners deploy Splunk Cloud Platform in several different ways. My partners typically purchase Splunk Cloud Platform through distribution and channel partners, rather than directly.
What was our ROI?
I have observed a robust return on investment with Splunk Cloud Platform, particularly in how quickly it enables the detection of breaches. We see logs between 10 to 30 minutes in contrast to six hours with other platforms, marking a substantial ROI for organizations needing to prevent breaches that can cost from tens of thousands to the average ransomware cost in the UK of 3.2 million last year. Being able to resolve issues quickly not only saves money but also minimizes the need for additional security personnel, thanks to the effectiveness of its log prioritization and integration capabilities.
Which other solutions did I evaluate?
Before choosing Splunk Cloud Platform, the primary alternative evaluated was DataDog, although that was not my decision directly.
What other advice do I have?
The aforementioned examples are the best ones to highlight regarding positive outcomes about how Splunk Cloud Platform has helped my organization or my customers.
My partners typically purchase Splunk Cloud Platform through distribution and channel partners, rather than directly. My impressions of Splunk Cloud Platform's visibility into multiple environments, including cloud, on-premises, and hybrid are very positive. It excels at monitoring across these environments and provides high capabilities, especially strong in centralizing visibility. This is facilitated by effective cloud monitoring alongside mature on-premises monitoring, all visible in a unified dashboard for SIEM use, supporting massive scales and deep forensic investigation across all these monitoring types.
My impression of Splunk Cloud Platform's zero setup feature for AI models is mixed, as there have been a couple of problems. Data is never standardized among organizations, leading to different log formats and inconsistent field naming. Therefore, AI cannot understand the data without mapping it first. Moreover, there is a need for context rather than just raw data, and integration remains unavoidable. Splunk Cloud Platform's zero setup AI concept feels more like a marketing idea than reality, as it requires careful scrutiny in enterprise environments. The main blockers noted remain related to data integration and standardization.
My experience with Splunk Cloud Platform's application ecosystem is that it is easy to manage for small and simple environments, as management involves just installing the application and configuring the data. However, for enterprise environments, management becomes really complex when dealing with multiple applications and teams, especially in larger organizations or heavily regulated industries including financial services and banking, where governance is stringent.
Splunk Cloud Platform scales extremely well at enterprise and hyperscale levels with some cost and architecture considerations. It can ingest almost limitless data and scale impressively, but higher data volumes present challenges, including costs, poor data hygiene, slower searches, and operational complexities that arise even in cloud environments. Despite these challenges, Splunk Cloud Platform scales extremely well technically; however, in real-life enterprise contexts, the main scaling limitation is not infrastructure but rather cost, data volume discipline, and query efficiency.
In comparing native models to third-party integrations within Splunk Cloud Platform's environment, I find that native Splunk scores high in integration quality and stability. However, it lacks the customization and innovation speed found with third-party options. Native models require very low maintenance effort, which contrasts with the medium to high maintenance needed for third-party applications. Each model has its advantages: the native model excels in core SIEM engines and performance-critical workloads, while third-party models handle data ingestion for external systems and industry-specific applications effectively. Therefore, a hybrid approach, leveraging the reliability of native capabilities with the flexibility of third-party applications, is ideal.
Splunk Cloud Platform's subscription model significantly impacts financial planning for data platform investments by being quite complex and opaque. The licensing and subscription model are tough to decipher initially, largely due to the relationship between ingestion levels, data scaling, and the associated costs that increase with usage. Customers usually find that as they scale, their expenditure rises, with no clear set cost available when they first begin using it.
Splunk Cloud Platform is a market leader known for its strengths in enterprise-scale log analysis, advanced security monitoring, complex event correlation, and deep search capabilities. It is also highly customizable, making it an excellent choice for organizations unperturbed by cost and seeking a cloud-native design, especially if they have a SOC environment and a large IT estate. I would rate this product a nine out of ten overall.
Which deployment model are you using for this solution?
Public Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Amazon Web Services (AWS)
Centralized monitoring has improved real-time insights and alerting for daily operations
What is our primary use case?
We have used Splunk Cloud Platform for the past one year. We use Splunk Cloud Platform for system monitoring and alerts, and we have personal dashboards to monitor our activities. We ingest logs and monitor all of our operations. We also use AWS along with Splunk Cloud Platform.
What is most valuable?
The powerful search capabilities using SPL are what I appreciate about Splunk Cloud Platform. The second feature we value is its real-time monitoring and alerting.
The best feature is that Splunk Cloud Platform is handled by the Splunk team itself, including installation and all related tasks. We do not have to touch anything; we simply use it for our case.
SPL search capability is one of the primary tools we use every day. We have different search queries configured for alerts, dashboards, and all related functions. It is one of the major tools we use in our daily operations.
Overall, Splunk Cloud Platform is cost-efficient for us because we are Splunk partners, and it offers better performance. It has improved our faster query execution and includes an inbuilt dashboard with better dashboard performance. We gain more meaningful insights using Splunk Cloud Platform compared to other SIEM tools.
What needs improvement?
The initial learning curve should be more personalized for new users who just started using Splunk Cloud Platform. Additionally, the documentation should be more beginner-friendly.
For how long have I used the solution?
I have been using Splunk Cloud Platform for the past one year.
What do I think about the stability of the solution?
Splunk Cloud Platform is working fine for us; it is superb.
What do I think about the scalability of the solution?
It is super scalable for us, whether you consider horizontal or vertical scaling. We are expanding in both directions, so it is highly scalable for us.
How are customer service and support?
We have escalated questions regarding Splunk Cloud to Splunk. During the upgrade, we experienced some issues with our forwarders not coming up and some issues with our search head. All of the issues were resolved. We raised support cases and our issues were solved by the Splunk team itself. It has been good for us so far.
Which solution did I use previously and why did I switch?
We directly use Splunk Cloud Platform.
How was the initial setup?
The initial setup was straightforward.
What about the implementation team?
It is super smooth; Splunk Cloud Platform integrates with ServiceNow smoothly. We have experienced no problems so far in that regard.
What was our ROI?
We have seen a return on investment with Splunk Cloud Platform at 30 to 40 percent.
What's my experience with pricing, setup cost, and licensing?
We are Splunk partners, so in Splunk Cloud Platform, pricing is not an issue. It is balanced, and from a pricing perspective, it is good for us.
What other advice do I have?
If you are looking for a SIEM tool that has all the capabilities, you should definitely opt for Splunk Cloud Platform. I would rate this solution a 9 out of 10.
Which deployment model are you using for this solution?
Public Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Centralized log insights have improved incident response and operational visibility
What is our primary use case?
In our organization, we use Splunk Cloud Platform for log management, operational visibility, security monitoring, and for ingesting logs and fast data. We focus on creating dashboards and configuring alerts for the overall visibility of our systems and for the monitoring and observability aspect.
What is most valuable?
I appreciate that Splunk Cloud Platform accepts all of my data. All of my data from different firewalls and applications gets to the one platform. Another valuable feature is the SPL query. After my data is centralized, I can use SPL queries for better analyzing and searching my data so I can detect anomalies or threats or for incident response. If any of my deployments fail, I can quickly respond to the incident.
Operational insights are crucial because my application logs are there, my firewall logs are generating there, and any new deployment from the CI/CD is there. This generates logs there. If any deployment has failed or if any application is failing, it increases my overall operational efficiency and helps my team with incidents.
The search capabilities of Splunk Cloud Platform are very powerful and can give me deep analysis of the events. The dashboards and the visual capabilities of Splunk Cloud Platform are also excellent. Dashboard Studio allows me to highly customize and create visually rich dashboards. The infrastructure features such as Smart Store and proactive monitoring help me in my day-to-day operations of the company.
We use Splunk Cloud Platform's alerting mechanism. We have integrated an API with ServiceNow, which works well for us.
The third-party tool integration with Splunk Cloud Platform is beneficial for us. We were using third-party tools before Splunk Cloud Platform. When we introduced Splunk Cloud Platform to our organization, it was very helpful that it could be integrated with third-party tools, so we did not need to change our tools. Splunk Enterprise tools for security and other functions can also be integrated with this platform. That is also a good feature for us.
What needs improvement?
One improvement I would suggest is in the cost part. Splunk Cloud Platform cost is generally generated on high data volume. It can be relatively expensive for a smaller company. Our company is in the mid-term range, but the cost could be improved. Additionally, the learning curve for SPL is a little bit hard for beginners, otherwise it is fine.
For how long have I used the solution?
I have been personally using Splunk Cloud Platform for the last one year, but my company has been using it for the last two to three years. However, I recently joined three months ago.
How are customer service and support?
Technical support for Splunk Cloud Platform is good and proactive. In some cases, the initial responses may not fully address the issue. However, through escalation, the support team usually provides effective solutions and is very helpful.
Which solution did I use previously and why did I switch?
We first used Grafana and Prometheus for the monitoring and observability. We had used open source tools as well. For the security and better visibility, my organization switched to Splunk Cloud Platform.
How was the initial setup?
Splunk Cloud Platform is a public cloud SaaS deployment. The initial setup was very fast and we do not need to maintain any infrastructure or backend infrastructure. This is a huge benefit for us.
Splunk Cloud Platform handles the platform deployment. From the user side, the main task was only to install forwarders and configure data ingestion, which was also quite a simpler task.
What was our ROI?
The ROI with Splunk Cloud Platform is on the higher part. It has improved the efficiency of our overall organization. The incident response time to any failure has increased more than 50 percent. The overall visibility of the system, architecture, and infrastructure has increased. All of our data is going on the one platform. These are all the ROIs which we get from Splunk Cloud Platform.
What other advice do I have?
We have not used Splunk Cloud Platform's machine learning tools yet, but we are planning to use them for threat detection and anomalies, so it can detect that threat by itself through automation. We are planning to use it in the future.
Splunk Cloud Platform has improved the efficiency and reduced the manual effort for us. It has improved faster detection and the response time has decreased significantly. The data pipeline optimization feature reduces the ingestion volume for us. These metrics are very helpful for us, and it also reduces the cost through data pipeline optimization.
My advice would be to fully utilize Splunk Cloud Platform by ingesting as much data as possible and to invest time in learning SPL and best practices for leveraging the Splunk community. My overall rating for this product is 9 out of 10.
Which deployment model are you using for this solution?
Public Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?