Cloud analytics have transformed log insights and automated maintenance for our teams
What is our primary use case?
For Splunk Cloud Platform, we perform analytics with a large scale of data pipelines and log data. We query logs and build dashboards to support our operational and business insights. We mainly work with Splunk Processing Language to query logs, identify patterns, and support troubleshooting and reporting.
We definitely use the ML toolkit for regression and anomaly detection. We also use Splunk Processing Language, and after the recent update, the new AI feature has been introduced that suggests queries to us. This feature has saved us considerable time.
Regarding native models, we only use the ML toolkit. I am unaware of the other models that Splunk provides. Specifically for the ML toolkit, we use it for anomaly detection and regression. In terms of cloud, we only use the ML toolkit.
What is most valuable?
I love how everything is handled by Splunk Cloud Platform itself. We do not have to manage migrations, updates, and other maintenance tasks. That is one of the major benefits of using Splunk Cloud Platform.
We definitely contact them and they help us during upgrade times. For example, if we want to upgrade Splunk Forwarder on a cloud instance or a Splunk Indexer in a cloud instance, they definitely assist us.
Splunk Cloud Platform is highly scalable. It is one of the best SIEM tools across the world because it is valuable not only for monitoring but also for security analysis, dashboards, and other features compared to other tools.
What needs improvement?
For betterment, there is definitely a cost concern. The cost is high, so there should be a somewhat lower cost. I am expecting a more competitive pricing structure from Splunk Cloud Platform, but otherwise it is fine.
For how long have I used the solution?
We have been working with this solution for the past 14 months.
What do I think about the stability of the solution?
I experienced stability issues once or twice during an upgrade, but the rest of the time it is fine. It is highly stable and scalable for us.
What do I think about the scalability of the solution?
Splunk Cloud Platform is highly scalable. It is one of the best SIEM tools across the world because it is valuable not only for monitoring but also for security analysis, dashboards, and other features compared to other tools.
How are customer service and support?
The customer service team is quite fast. They take around two to three hours to reply back and they solve our problems.
Which solution did I use previously and why did I switch?
We have not had any issues regarding maintenance because everything has been handled by the Splunk team itself. That is the best aspect of Splunk Cloud Platform, so we have not experienced any problems so far.
How was the initial setup?
The initial setup was easy for us because we took training from Splunk. It was quite easy for us.
What about the implementation team?
The implementation timeline depends on the use case, whether you are a Splunk Admin or a Splunk Power User. For a Power User, it took around three to four months to learn it. For an Admin's use case, it is very hard and took around a year. You also need certification to prove that you are a Splunk Admin.
The implementation process is quite easy because we have created custom applications regarding the upgrade of Splunk Enterprise Platform. We have another application called Splunk Forwarder through which pre-checks and post-checks are performed by our custom-made application. It is quite easy for us.
What other advice do I have?
We also use Splunk SOAR in addition to Splunk Cloud Platform. My overall review rating for this solution is 9 out of 10.
Which deployment model are you using for this solution?
Public Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Centralized monitoring has reduced outage investigations and improves security incident response
What is our primary use case?
My main use case for Splunk Cloud Platform is monitoring servers for logs in case of outages.
A specific example of how I use Splunk Cloud Platform for server monitoring and outage prevention is that the servers' logs are monitored for errors that could cause the server to go down.
In my daily tasks, Splunk Cloud Platform is also used for security, to detect attacks.
What is most valuable?
The best features that Splunk Cloud Platform offers include its ability to detect fraud, outages, slowness, suspicious access, operational failures, or intrusion attempts.
What makes work easier for the team is that they have a centralized tool in which they can identify these attempts and thus be able to act on the people who are trying to do it.
The team has leveraged this tool to respond to incidents by having everything centralized in Splunk Cloud Platform instead of going out to look for separate logs from each team.
The main advantage of having the logs centralized in Splunk Cloud Platform is that I don't have to access different places to get them.
Splunk Cloud Platform has positively impacted my organization by reducing the time for investigations of outages or attacks on servers.
The time I have managed to reduce in investigations thanks to Splunk Cloud Platform is about 25%, since having everything centralized is the first starting point to look for that information.
What needs improvement?
If Splunk Cloud Platform could be made less complex, it would be beneficial since Splunk specialists are required to perform the installation.
My experience with Splunk Cloud Platform's app ecosystem is that it's a bit complex and support from a Splunk specialist is required to manage updates.
I perceive the scalability capability of Splunk Cloud Platform in relation to my organization's demand fluctuations as a bit challenging.
The use of native models versus third-party integrations within Splunk Cloud Platform's environment is a bit complex, as a specialist is required to do the mappings between third-party integrations and native models.
For how long have I used the solution?
I have been using Splunk Cloud Platform for more than 3 years.
What do I think about the stability of the solution?
I consider Splunk Cloud Platform to be stable.
What do I think about the scalability of the solution?
I rate the scalability of Splunk Cloud Platform an eight.
The hardest part that leads me to give it an eight in scalability is the licensing.
How are customer service and support?
I rate Splunk Cloud Platform's customer support an 8 out of 10.
Which solution did I use previously and why did I switch?
No tool was used before Splunk Cloud Platform.
How was the initial setup?
If Splunk Cloud Platform could be made less complex, it would be beneficial since Splunk specialists are required to perform the installation.
What about the implementation team?
My experience with the pricing, implementation costs, and licensing of Splunk Cloud Platform is that the licensing is expensive, but since the investment is being made, it has to be used.
What was our ROI?
There has been a bit of return on investment with the time savings, but because of the licensing, we have broken even.
Splunk Cloud Platform's subscription model has a big impact on my organization's financial planning regarding data platform investments, as all of that has to be taken into consideration to plan for the following year, taking into account growth.
What's my experience with pricing, setup cost, and licensing?
My experience with the pricing, implementation costs, and licensing of Splunk Cloud Platform is that the licensing is expensive, but since the investment is being made, it has to be used.
Which other solutions did I evaluate?
Before choosing Splunk Cloud Platform, I evaluated other options such as Datadog, Dynatrace, and Elastic.
What other advice do I have?
I would rate Splunk Cloud Platform an eight on a scale from 1 to 10.
I give Splunk Cloud Platform an eight because the licensing is expensive and can become complex.
My advice to others who are considering using Splunk Cloud Platform is to take into account the learning curve, the implementation curve—which are both quite steep—and the licensing costs, so that it doesn't consume their entire budget.
Since I'm installed in the cloud, I can only speak about the cloud when it comes to the visibility that this solution provides.
I am not using the AI solutions at the moment, so I cannot comment on the zero-configuration functionality for artificial intelligence models in Splunk Cloud Platform.
Which deployment model are you using for this solution?
Private Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Unified log analytics has transformed security monitoring and cuts breach detection to minutes
What is our primary use case?
Splunk Cloud Platform is my main use case, which we sell to our channel partners within the channel community that then sell it to their customers, primarily as a cloud-based platform that collects data, analytics, and monitoring. It is mainly used for log management, security monitoring, known as SIEM, IT operations monitoring, and customers can use it for infrastructure troubleshooting and compliance reporting, but primarily for getting real-time analytics. It is a useful SaaS cloud-hosted tool that manages infrastructure, upgrades, scaling, and maintenance for customers.
A specific example of how a customer uses Splunk Cloud Platform in their day-to-day operations is how it collects logs from Linux, Windows servers, Azure, and AWS. Teams can run powerful searches using SPL, search processing language, to find failed logins, investigate outages, and trace application errors. It also automatically alerts the team for system failures, CPU spikes, security threats when they occur, and API slowdowns, showcasing just a couple of examples of what our customers use Splunk Cloud Platform for.
Splunk Cloud Platform provides a complete picture regarding how customers use it. It includes capabilities around machine learning and dashboards that allow them to monitor KPIs, have a real-time operational view, and executive reporting from all the logs.
What is most valuable?
Splunk Cloud Platform's best features include its scalability, as it can handle terabytes of data and is probably one of the market leaders within SIEM capability, which is very strong. In this day and age, cybersecurity products need great integration, and it has a huge ecosystem that can integrate with over 1,200 integrations and applications. Another major positive is that it is cloud-managed, which means less infrastructure management. Finally, the main feature that many people value, and our customers provide feedback on, is real-time analytics with fast detection and troubleshooting.
Splunk Cloud Platform has positively impacted my organization by reducing the need for infrastructure management due to being a SaaS cloud platform. The main use case is detecting cyber attacks faster. For example, a large financial institution, a bank, used Splunk Cloud Platform and identified failed logins, impossible travel events, VPN anomalies, and endpoint alerts when attackers attempted credential stuffing. Without Splunk Cloud Platform, those alerts existed in multiple systems, and detection could take days, but with it, events were correlated correctly and raised a single notable event, triggering alarms immediately. This significantly improves mean time to detect and respond, reducing investigation time from hours to just 10 to 30 minutes for common incidents by providing a single pane of glass visibility for SOC teams.
What needs improvement?
Splunk Cloud Platform has areas for improvement, including the fact that it is obviously an enterprise tool and can be expensive, which is the biggest complaint I have noted. Costs can rise due to high data ingestion and long retention periods, along with a complex licensing structure that makes pricing difficult to predict as usage grows, especially since more systems send logs. There are also performance concerns at scale where users have reported slower searches and expensive long-term storage needs, particularly in multi-terabyte environments. Additionally, operational complexity exists as enterprises still need to do data onboarding, create dashboards, handle retention policies, access control, and performance tuning.
These are the three key areas of improvement I have identified.
For how long have I used the solution?
I have been using Splunk Cloud Platform for approximately three to four years at various different places of work.
What do I think about the stability of the solution?
Splunk Cloud Platform is undeniably stable, which is one of its key advantages. While it may come with a high price tag and face scalability issues, its stability is commendable, enabling easy visibility into logs, effective data ingestion, and successful operations with diverse integrations and third-party platforms.
What do I think about the scalability of the solution?
My customers typically leverage scalability and integration features across the main cloud providers, primarily AWS, integrating with CloudWatch, CloudTrail, S3, and Lambda for cloud security monitoring and audit logging. They also integrate with the entire Microsoft stack, including Defender for Cloud, Sentinel, Azure ID, and Azure Monitoring, as well as Google Cloud, where GCP integrates with Cloud Logging and Pub/Sub security command center. We also have integrations with major SIEMs including Sophos, CrowdStrike, and firewalls from Palo, Fortinet, Cisco, and Juniper, and identity management tools including Okta, Ping, and Duo. For threat intelligence, we get much of our integration from Recorded Future as our main integration, but they are just some of the top ones we integrate with effectively.
Splunk Cloud Platform's scalability works well, especially for smaller businesses, but can present issues for larger enterprises facing stricter regulations and greater integration requirements.
How are customer service and support?
Customer support with Splunk Cloud Platform is really good. The CSMs and account managers in the channel team are great, providing assistance not just with selling the product but also for implementation, deployment, and aftercare. I would rate customer support a nine on a scale of one to ten. There have been a couple of instances where issues arose, which is why it does not earn a full ten, but overall, it stands out as a really good platform and contributes to why they remain number one in the business.
Which solution did I use previously and why did I switch?
I have not personally switched from a different solution to Splunk Cloud Platform, but we utilize various different solutions for SIEM, including QRadar and Exabeam, alongside newer tools including DataDog and Elastic.
How was the initial setup?
My experience with pricing, setup costs, and licensing is that while the setup costs are straightforward and not overly burdensome, licensing for small to mid-sized enterprises is favorable. Highly regulated businesses, including financial services and banks, tend to use Splunk Cloud Platform regularly, and while it is a high-quality product, the costs can elevate significantly as scalability needs grow within larger enterprises.
What about the implementation team?
My partners deploy Splunk Cloud Platform in several different ways. My partners typically purchase Splunk Cloud Platform through distribution and channel partners, rather than directly.
What was our ROI?
I have observed a robust return on investment with Splunk Cloud Platform, particularly in how quickly it enables the detection of breaches. We see logs between 10 to 30 minutes in contrast to six hours with other platforms, marking a substantial ROI for organizations needing to prevent breaches that can cost from tens of thousands to the average ransomware cost in the UK of 3.2 million last year. Being able to resolve issues quickly not only saves money but also minimizes the need for additional security personnel, thanks to the effectiveness of its log prioritization and integration capabilities.
Which other solutions did I evaluate?
Before choosing Splunk Cloud Platform, the primary alternative evaluated was DataDog, although that was not my decision directly.
What other advice do I have?
The aforementioned examples are the best ones to highlight regarding positive outcomes about how Splunk Cloud Platform has helped my organization or my customers.
My partners typically purchase Splunk Cloud Platform through distribution and channel partners, rather than directly. My impressions of Splunk Cloud Platform's visibility into multiple environments, including cloud, on-premises, and hybrid are very positive. It excels at monitoring across these environments and provides high capabilities, especially strong in centralizing visibility. This is facilitated by effective cloud monitoring alongside mature on-premises monitoring, all visible in a unified dashboard for SIEM use, supporting massive scales and deep forensic investigation across all these monitoring types.
My impression of Splunk Cloud Platform's zero setup feature for AI models is mixed, as there have been a couple of problems. Data is never standardized among organizations, leading to different log formats and inconsistent field naming. Therefore, AI cannot understand the data without mapping it first. Moreover, there is a need for context rather than just raw data, and integration remains unavoidable. Splunk Cloud Platform's zero setup AI concept feels more like a marketing idea than reality, as it requires careful scrutiny in enterprise environments. The main blockers noted remain related to data integration and standardization.
My experience with Splunk Cloud Platform's application ecosystem is that it is easy to manage for small and simple environments, as management involves just installing the application and configuring the data. However, for enterprise environments, management becomes really complex when dealing with multiple applications and teams, especially in larger organizations or heavily regulated industries including financial services and banking, where governance is stringent.
Splunk Cloud Platform scales extremely well at enterprise and hyperscale levels with some cost and architecture considerations. It can ingest almost limitless data and scale impressively, but higher data volumes present challenges, including costs, poor data hygiene, slower searches, and operational complexities that arise even in cloud environments. Despite these challenges, Splunk Cloud Platform scales extremely well technically; however, in real-life enterprise contexts, the main scaling limitation is not infrastructure but rather cost, data volume discipline, and query efficiency.
In comparing native models to third-party integrations within Splunk Cloud Platform's environment, I find that native Splunk scores high in integration quality and stability. However, it lacks the customization and innovation speed found with third-party options. Native models require very low maintenance effort, which contrasts with the medium to high maintenance needed for third-party applications. Each model has its advantages: the native model excels in core SIEM engines and performance-critical workloads, while third-party models handle data ingestion for external systems and industry-specific applications effectively. Therefore, a hybrid approach, leveraging the reliability of native capabilities with the flexibility of third-party applications, is ideal.
Splunk Cloud Platform's subscription model significantly impacts financial planning for data platform investments by being quite complex and opaque. The licensing and subscription model are tough to decipher initially, largely due to the relationship between ingestion levels, data scaling, and the associated costs that increase with usage. Customers usually find that as they scale, their expenditure rises, with no clear set cost available when they first begin using it.
Splunk Cloud Platform is a market leader known for its strengths in enterprise-scale log analysis, advanced security monitoring, complex event correlation, and deep search capabilities. It is also highly customizable, making it an excellent choice for organizations unperturbed by cost and seeking a cloud-native design, especially if they have a SOC environment and a large IT estate. I would rate this product a nine out of ten overall.
Which deployment model are you using for this solution?
Public Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Amazon Web Services (AWS)