My company uses Splunk Enterprise Platform for monitoring and user base filtering.
External reviews
External reviews are not included in the AWS star rating for the product.
A solution that offers a good analytics part along with great integration capabilities with other applications
What is our primary use case?
What is most valuable?
The most valuable feature of the solution is the analytics part. Integration with other applications is another valuable feature of Splunk Enterprise Platform.
What needs improvement?
Splunk Enterprise Platform is already a refined product, so I don't have any recommendations related to areas that need improvement.
The cost of Splunk Enterprise Platform is an area of concern where improvements can be made by bringing down the costs. Product-related, I don't have any feedback.
The support offered by Splunk Enterprise Platform has certain shortcomings that need improvement.
For how long have I used the solution?
I have been using Splunk Enterprise Platform for a few weeks since it was recently deployed in my company. I use the solution's latest version. My company operates as a service provider of the solution.
What do I think about the stability of the solution?
The product's stability is good. Stability-wise, I rate the solution a nine out of ten.
What do I think about the scalability of the solution?
Scalability-wise, I rate the solution a nine out of ten.
Around 5,000 people use the solution. Around 10 to 15 analysts use Splunk Enterprise Platform in my company.
The solution is used on a regular and daily basis in my company.
How are customer service and support?
I am moderately satisfied with the solution's technical support. I rate the technical support an eight out of ten.
How would you rate customer service and support?
Positive
How was the initial setup?
Splunk Enterprise Platform was easy to implement. I rate the product's implementation phase an eight out of ten, where one is difficult, and ten is easy.
The solution is deployed on an on-premises model.
The solution's deployment phase was carried out over a period of one or two months.
What's my experience with pricing, setup cost, and licensing?
I rate the product's pricing a ten on a scale of one to ten, where one is cheap, and ten is expensive. It is a very pricey tool.
What other advice do I have?
I would recommend the product to those who plan to use it, provided the pricing of the solution is brought down.
I rate the overall product an eight out of ten.
Which deployment model are you using for this solution?
A platform for monitoring storage, CPU, RAM, Windows logs, and Cisco network logs on large machines
What is our primary use case?
We have around 38 virtual machines, including the desktop. We have filled our gap network. Splunk Enterprise monitors all network layer traffic, starting with Cisco traffic port violations. We are monitoring Windows logs, CPU, RAM, and disk utilization in Windows.
What is most valuable?
Splunk Enterprise is a wireless enterprise application that can be customized based on training. We can add new machines, Spring Forwarders, and whatever else we need to complete the job.
What needs improvement?
We have an enterprise system that we can only use up to 70% capacity. We have no Internet access. To ensure our system runs optimally, we must configure specific rules, such as RAM, CPU, and space utilization alerts. Also, it is tough for us to reach out to Splunk. We have another software called Nessus, which can be used for vulnerability scans to improve and expand our vulnerability management capabilities. We can add a vulnerability management tool and back network traffic monitoring. This would allow us to add everything into a single platform since we currently use multiple applications for eight solutions.
For how long have I used the solution?
I have been using Splunk Enterprise Platform since 2020. We are using the latest version of the solution.
What do I think about the stability of the solution?
The product is stable.
What do I think about the scalability of the solution?
We have 43 users using this platform.
How was the initial setup?
The initial setup is easy. We manage the installation of Splunk Enterprise Platform. On the first installation day, there are extensive procedures from Splunk and Honeywell. They are explaining how to install the software using Honeywell automation. They have provided a lot of documentation, but it is incomplete. It takes them two days to complete the installation, and then they train us for another week.
What's my experience with pricing, setup cost, and licensing?
We are using 11GB per day. Since I did all the analysis to determine how much we are consuming, we are currently utilizing around 5GB out of 11 GB. Therefore, we can reduce our usage from 11GB/day to 5GB/day. We reached out to Splunk, and they confirmed that this is possible. They also mentioned that there are commercial benefits to signing a longer-term contract. We are currently working on reducing our usage from 11GB/day to 5GB/day.
What other advice do I have?
We have annual automation for our automated building and availability building. The maintenance is easy. We will do a vulnerability scan. Then, we need to ask someone from the Splunk team to confirm that upgrading to this version of Windows or applying monthly or weekly patches will not impact the Splunk application. It's not easy or feasible to reach out to Splunk directly. Splunk is an enterprise software platform that monitors storage, CPU, RAM, Windows logs, and Cisco network logs on large machine setups. I suggest Splunk to anyone with these needs. Overall, I rate the solution an eight out of ten.
A highly versatile data collection and monitoring tool
What is our primary use case?
We use the monitoring solution. People might ask me to create a new request, maybe for a specific Windows event log, which is how we create a ticket for an incident. Most of the time, this creates a new alert for people. It can be a little complex. We can also create dashboards with some information for other teams. Dashboard alerting is a big part of the work.
Though we use Splunk for monitoring, for me, it is more software that collects lots of data and can then be used for alerting.
We use a custom environment.
What is most valuable?
The best thing about Splunk is you can collect all the data you want, and you can play with the data and do what you want. You can modify the data and collect all the information into one dashboard. It's very cool. In other monitoring software like Zabbix, you can't easily do something like this. With Splunk, it's very easy. You need to understand Splunk's language, but you can do what you want after that. You can correlate your data with CSV files. Splunk can monitor, extract, transform, and load software.
What needs improvement?
Splunk is not an out-of-the-box solution like Micro Focus or Zabbix. You have to create your request to collect the data and add crucial components to the software. You have add-ons created by Splunk or the community but don't have out-of-the-box monitoring items in the software. For example, FETCH CUP with Micro Focus is agentless monitoring, has a lot of out-of-box items, and is easy to use. You will find it difficult to use Splunk initially, which could use improvement. However, I know there is another module from Splunk that focuses on fast and secure monitoring with more out-of-box add-ons, but I haven't used it since when I started using it, it lacked out-of-box items. All the same, Splunk could be more user-friendly for new users.
For how long have I used the solution?
I've worked with the solution for about two years.
What do I think about the stability of the solution?
I rate Splunk's stability a nine out of ten because it's very stable. I don't face issues with projects.
What do I think about the scalability of the solution?
You can scale Splunk. It works with an indexer which indexes search data. If you want more power, you can add more indexers, so I rank Splunk's scalability an eight out of ten.
How was the initial setup?
With all the documentation available, the initial setup is not difficult. If all you want is a stand-alone app in Splunk to handle all the processes, you just need to create a project in the data server, which is easy.
What's my experience with pricing, setup cost, and licensing?
You must buy a license with the on-prem version, usually through an intermediary. In France, it's Accenture. There are cloud solutions where Splunk handles the servers and patching directly, and you just use the solution.
The solution is expensive, so I rate its pricing a four out of ten. Though the solution is expensive, it depends on which company purchases the product.
Which other solutions did I evaluate?
Though I haven't used it, Grafana is also a CM that can collect data.
What other advice do I have?
I didn't create the custom environment we use at my organization. Still, it doesn't seem too difficult to build things because there is a lot of online documentation and videos. You can also get training with Splunk. You have a lot of data to help you when you want to create a new environment.
I rate Splunk Enterprise Platform an eight out of ten. The solution is very powerful, and I like to play with data to do what I want.
Which deployment model are you using for this solution?
Good infrastructure and easy to maintain
What is our primary use case?
We use Splunk Enterprise for data visualization.
We use Splunk administration rather than Splunk development.
We provide support to users so they can access our Splunk application and use it however they want. For example, if they are not able to view some of the logs that are coming from their servers in our Splunk, then we usually check all the logs here that have been missed and forward the ones that were not forwarded.
Also, sometimes they use their access to install some apps. We have Splunk apps and they want us to create an app for their usage. We also need to create these apps in the Splunk application. Sometimes they aren't able to download or upload files into Splunk or other websites. They aren't able to download these reports as PDF files. We usually work on this and try to resolve it as quickly as possible.
How has it helped my organization?
We use Splunk for cyber security. We have a lot of teams who use Splunk for different purposes. The security team uses it to authorize log-ins, so in case something happens, Splunk monitors it. Also, the development team uses it to monitor data while they're creating a new application.
What is most valuable?
In the enterprise platform, all of the clusters and indexes are under our maintenance. If required, we can make changes and see the logs manually by getting into the servers.
What needs improvement?
Things have to be managed manually in Splunk Enterprise, which is not the case in Splunk Cloud, where the client could manage it on their own.
It would be useful if Splunk Enterprise Platform could monitor the application URL, to check whether it's responsive or not.
For how long have I used the solution?
I've been using it for a year and a half.
What do I think about the stability of the solution?
It is completely stable and the infrastructure is good. We have no issues with our Splunk Enterprise Platform.
How are customer service and support?
We contact technical support whenever there's an issue with logs and they work through it with us.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
We use both Splunk Cloud and Splunk Enterprise. We might opt for Splunk Cloud in the future since it's less expensive, but we are currently using both.
How was the initial setup?
The deployment takes about a day. I would say that the initial setup is quite a complex thing to do because there are a lot of things that have to be done for clustering all the features and indexing and then forwarding data to the indexes. When it comes to applications, we have to replicate the data. The process takes time. Once everything is done, we still need to monitor the infrastructure constantly.
It is easy to maintain if you are familiar with the deployment model.
Which other solutions did I evaluate?
I have hands-on experience with AWS, Linux, Ansible, and Terraform and with programs like Python, Java, and SQL as well. I also use tools like Catchpoint, Nagios, and Grafana.
What other advice do I have?
I would suggest using Splunk Cloud first, and then Splunk Enterprise because the maintenance and the infrastructure management are easy. I would rate it an eight out of ten.