We use Splunk Infrastructure Monitoring to get an overview of what's happening in our customers' infrastructure. We're monitoring our servers, network, IoT devices, etc. We're a service provider, so the solution is installed in one place.
Splunk Observability Cloud
SplunkExternal reviews
External reviews are not included in the AWS star rating for the product.
The solution has enabled us to be more proactive, so we can identify and respond to an issue before there is a failure
What is our primary use case?
How has it helped my organization?
Splunk Infrastructure Monitoring has enabled us to be more proactive. We can identify and respond to an issue before there is a failure. It has helped us significantly. For example, if somebody is attacking us we can detect that there is an increase in traffic and investigate to see if it's legitimate. We can block them or take other actions before it becomes a problem.
What is most valuable?
Splunk Infrastructure Monitoring gives us complete visibility without the need for storage. We can visualize our infrastructure. Where is the traffic going? Are there any attacks? What are our vulnerabilities?
What needs improvement?
Splunk could be better integrated with configuration manager solutions so we can automatically resolve issues without human interference.
For how long have I used the solution?
We have used Splunk Infrastructure Monitoring since 2015.
What do I think about the stability of the solution?
Splunk Infrastructure Monitoring is stable.
What do I think about the scalability of the solution?
Splunk is scalable. It's easy to add more devices as needed.
How are customer service and support?
I rate Splunk support an eight out of ten.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
Before Splunk, we used multiple vendors, including Cisco, SolarWinds NPM, and WhatsUp Gold.
How was the initial setup?
The deployment process isn't complicated. We installed Splunk on a VM and started it. We have a team to deploy and monitor it.
What was our ROI?
Splunk is worth the investment. When an incident happens, you need reports immediately, and Splunk is the best monitoring solution for this.
What's my experience with pricing, setup cost, and licensing?
Splunk is expensive, but it's the best solution for the job.
What other advice do I have?
I rate Splunk Infrastructure Monitoring a nine out of ten. Splunk is a responsive piece of software. It's user-friendly and easy to get the data you need. I advise people to take the time to learn how to create reports and analytics.
Splunk Observability Cloud
Splunk Observability Cloud Review
Splunk Observability
Amazing product.
Splunk Observability Cloud (SignalFX) - All in one solution for Cloud Apps
Splunk is my go to tool for all things observabilty!
Empowering Insights, Simplifying Troubleshooting with Splunk Observability Cloud
It combines the greatest aspects of in-the-moment log analysis, individualized alerts and communication tools, enabling IT teams to proactively handle issues and enhance system performance.
Splunk Observability Cloud has is an essential tool for any organization serious about managing the health and performance of its systems with its straightforward user interface and unrivaled scalability.
creating customised visualizations may sometimes require a significant amount of work and skill in the Splunk query language. It's bit tedious to learn initially for a new user
Gives us early warning on problems that could arise
What is our primary use case?
We have used Splunk to give us insight into the NetFlow of the traffic running through our network. We connect different networks but we only use on-prem. We are in the middle of a spider web, providing these services to different networks. We are trying to gain visibility into the traffic that traverses our network internally.
We are interested in the traffic volume because the services we are looking at are endpoint-encrypted, meaning encrypted traffic between a service provider and a client in another network. So we are not able to look into the media stream.
The networks we are connecting have their own security boundaries and their own security levels, and we don't mess with that. We are just trying to let them talk together.
We have been using Splunk for monitoring who is logging in and how and when.
How has it helped my organization?
It has given us visibility into what is going on in the network, such as how much traffic is running to and from the services, but we are not using Splunk in a straightforward way. When we are looking into reports on how much data has been used, we need to look into another system and enrich it with data from Splunk.
Splunk has drawn our attention to how the network is running. If there are alarms on things that are not functioning, it gives us early warning on problems that could arise.
In terms of operational performance, the efficiency, Splunk has helped us improve. We could have found other tools that would have given us the same efficiency, but this was the tool that we chose. From that perspective, it has been of value to us.
It would have helped us reduce our mean time to detect but I can only guess at how much; perhaps by 25 percent. And we would see a similar reduction for mean time to resolve.
What needs improvement?
It's a bit difficult to use. It takes some time to get into it and to get it to do what you would like it to do. It is not straightforward to use it. Once you have the dashboards for collecting and analyzing transactions configured, they are okay, but it takes some time to do it. Configuration could be easier.
For how long have I used the solution?
We have been using Splunk for about eight years.
What do I think about the scalability of the solution?
We have not looked at Splunk as a means of being able to scale, but we have not been hindered by using Splunk. Our goal has not been growth, but maintaining stable and secure networking, and this is what we have achieved. But with or without Splunk, we would have achieved that anyway.
How are customer service and support?
We really haven't had any technical issues where we involved Splunk's support.
Which solution did I use previously and why did I switch?
We did not have a previous solution like Splunk, other than in-house-developed tools. We got acquainted with Splunk as part of the tender for our network infrastructure, and from that perspective, it has been okay.
What's my experience with pricing, setup cost, and licensing?
Splunk has been fairly expensive, but it has been predictable. You are not punished if you are looking into much more data if you are, for example, under attack. Other tools could be more expensive to use if they charge per incident or the amount of data you are looking into. With other solutions, you could be punished if you need to index more data because of an attack, such as a DDoS attack, and you need to do some forensics on the data.
What other advice do I have?
Why shift to something you don't know when you are, perhaps, happy enough with the tool that you already have? Think about whether you could develop that tool into something that would give you the visibility you would like to have, instead of using Splunk. Are you looking into incidents, traffic flows, indexing per day, or is the issue that you're looking for an alternative with a better price? Think about why you are considering shifting from a tool that you already know.
Troubleshoots quickly and offers end-to-end visibility across the environment
What is our primary use case?
I am a technology analyst. I have been working on a financial project in the US. For this project, I used Splunk APM for troubleshooting and reviewing the logs, and finding errors. Most of our APIs ran on Splunk APM, and we used it to find errors in our production environment.
We are no longer using Splunk APM. We have switched to Dynatrace.
How has it helped my organization?
Splunk APM is very good for monitoring purposes. You can watch application-to-application flows. If you just click on a flow, you can go step by step and debug an issue. The places with errors are marked in red. The API or the application in which you are getting an error is red. From there, you can go to the log or the error, and then the person responsible for that particular API or application has to fix it.
Splunk APM gives tools for user monitoring, logs observability, infrastructure monitoring, synthetic monitoring, and automated on-call.
Splunk APM provides real-time data. In the logs, if you want to see errors related to status 404, you can just write one keyword, and you will get the results.
Splunk APM offers end-to-end visibility across the environment, but it also depends on how your business is set up on Splunk APM.
Splunk APM helped to reduce our mean time to resolve (MTTR). Previously, I had to log into my VPN, run commands, and see the logs. After having Splunk APM, I could click on one link and go through the logs.
We could set up Splunk APM based on our environment. I worked on one project with Splunk APM. In that project, we faced a lot of issues, and I resolved the issues with the help of Splunk APM. I found the accurate logs and the easiest way to resolve the errors.
What is most valuable?
Splunk APM is the most advanced application for performance monitoring and troubleshooting for cloud-native applications and microservices.
The ability to troubleshoot is valuable. While running any product or API, we need to troubleshoot issues. We need to find the error in the logs. In Splunk APM, we have the section logs. In that section, we can search with any particular keywords. Before Splunk APM, I also worked with Splunk Enterprise where we have various dashboards to monitor.
It is an application performance monitoring and observability tool. It is a very good tool. You need to use the documentation on Splunk's website. From there, you can learn many things. I have Splunk certification. You can dive deep into it. For me, it gives end-to-end visibility into our production environment.
What needs improvement?
They can improve the flow system and the keyword language. It has predefined keywords, but they can be improved. I also use LogMeIn where I can use predefined keywords to see the logs.
They should give us the option to use our own language to search. For example, I should be able to search for an ID name along with an error or status code.
For how long have I used the solution?
I worked with Splunk APM for one and a half years.
What do I think about the stability of the solution?
I have not faced any downtime. I have worked with Splunk APM for one and a half years, and I did not face any downtime during this duration of time.
What do I think about the scalability of the solution?
I have never faced any issues with scalability.
How are customer service and support?
I did not have any need to contact support because I did not face any issues.
Which solution did I use previously and why did I switch?
We used another solution previously. In Splunk Enterprise, it is easier to create dashboards. You can easily set up application alerts and infra alerts. You can search with metrics and you can set alerts based on a specific error. Whenever that error occurs, you will receive an alert.
How was the initial setup?
I am not involved in its deployment. In terms of maintenance, it is owned and managed by Splunk. Everything is maintained by Splunk. I have not faced any downtime with Splunk APM. I have also used Splunk Enterprise previously. With both of these products, I did not face any downtime.
What's my experience with pricing, setup cost, and licensing?
The pricing is reasonable.
What other advice do I have?
It is a good tool. It allows you to set alerts for application and infrastructure monitoring, and it allows you to create dashboards. You can set alerts based on the threshold or traffic.
For logging purposes, Splunk APM is very good, but we should be able to use our own search query language. Currently, we can only search based on the predefined tags.
Overall, I would rate Splunk APM a nine out of ten.