Best of Breed
What do you like best about the product?
Splunk Enterprise is the best of what's out there for event correlation. It is very extensible and can take almost any kind of data with a little work. FANTASTIC for searching data and identifying correlations and patterns, or a lack of correlation and patterns to identify the anomalies.
What do you dislike about the product?
It is pretty expensive when you start to ingest all the data and setting up alerts and automated detections is more difficult, but it can be done.
What problems is the product solving and how is that benefiting you?
Incident response and malware hunting are much easier to do, including scoping an incident
Recommendations to others considering the product:
Make sure you have enough infrastructure and it is configured properly
Splunk is a game changer
What do you like best about the product?
Splunk Enterprise has allowed us to easily sort data from multiple sources in easy to manipulate and view dashboards and reports in way we could never do before.
What do you dislike about the product?
The only thing I can say that I dislike about Splunk is that it has made our customer think that our job is a piece of cake because of how quickly we can answer their questions!
What problems is the product solving and how is that benefiting you?
Consolidated log review that has allowed us to answer questions faster than ever before and identify issues and metrics that we could not have done easily before the implementation of splunk.
Recommendations to others considering the product:
You won't be sorry
Transcendental Meditation as Software (TMaS)
What do you like best about the product?
Oh, to begin at the start is akin to creating pottery from clay. Forming the vase of data from the clay of disparity, one can simply design such meaning and substance from meaningless data, and share amongst peers and enemies alike.
What do you dislike about the product?
Sometimes, the rapid evolution causes internal strife, but nary is it a problem, as support and documentation rules all.
What problems is the product solving and how is that benefiting you?
Verily, we beseech thee to not find a benefit. Optimization of Continuouse Integration, Notification of downtime and reporting of such, monitoring the temperature for optimal Feng shui, among other glorious and grand moments, one must have a sense of pride and accomplishment.
Recommendations to others considering the product:
Consult professional services and the community. http://splk.it/slack . Find a user, ask them questions, and join the revolution!
Splunk helps the uncover the hidden secret in data very quickly to all levels in an organization.
What do you like best about the product?
Quickly ingest any data ( machine , structured or unstructured), and produce analytics and visualization to drive the business value.
What do you dislike about the product?
It is little bit expensive in terms of License cost but we can still do somethings with the free license limit.
What problems is the product solving and how is that benefiting you?
Increase automation and resource optimization through monitoring and analytics. Identified opportunities to save cost, resources and time.
Recommendations to others considering the product:
Splunk is a great product which will help to quickly realize the value of data and demonstrate to clients.
The most versatile data mining product I know of
What do you like best about the product?
Splunk takes in any data in almost any form (as long as it is human readable text) and allows searching, manipulation, transformation, calculation, etc. and then presents it in a multitude of ways to make the data tell a helpful story. That is superior to products that make you set up each type of data in a set format. We have data that varies greatly even among similar software products.
What do you dislike about the product?
Bugs, though to be honest, I haven't run across many, and they seem to get fixed pretty quickly. I've run into some that usually have a workaround, which makes it easier to deal with the bug.
What problems is the product solving and how is that benefiting you?
We use Splunk for many purposes. Developers use it to find coding problems, operations uses it to find operational issues, managers look at reporting and forecasting.
Recommendations to others considering the product:
Learn as much as you can before implementing a large installation, or use professional services to get you started. You can keep from making lots of bad mistakes by doing so. Many people go into the implementation making simple, but critical mistakes that can be hard to rectify. These are things that are documented, but people don't take the time to find out about them, so they make those mistakes anyway.
Quickk and easy set up and useful for simple testing
I read one review that said that THP was not supported on the instance, but I checked on mine and it was properly configured. I did have a couple of errors that showed that there may have been some files that were not verified as being Splunk installed and that the instance fell below the suggested minimums for running Splunk, but I was just using a Free EC2 instance to try things out.
The web interface came up quickly and with out problems and I was able to install apps quickly and easily. I added some data and had things working well quite quickly. I would like to try a larger AMI instance, but for the testing I did. It was quite usable.
Trying Splunk AMI for the first time
I use Splunk Enterprise Security at work.
Currently studying for my architect certification. I know Splunk AMI on AWS will be the perfect platform for my lab.
Splunk is just couple of clicks away!
I've been using Splunk Enterprise on premises for few years.
And it is hands down the best product I've come across in 15+ sysadmin years.
No, really, I've seen some really nice pieces of software but none of them comes even close. And the Splunk AMI just makes the starting the use of all Splunk Enterprise features so much faster that it is a no-brainer. New or old Splunk user: Grab it. Throw some data, any data, to it and start Splunkin' !
Consolidated Management
What do you like best about the product?
Splunk is simply awesome. You can integrate it with almost all vendors.
What do you dislike about the product?
Norhing to dislike so far so good . But can get better !
What problems is the product solving and how is that benefiting you?
Incident Analysis
Great tool for watching for threats on your network
What do you like best about the product?
The dashboards that Splunk uses (that are able to be customized to your needs) are second to none.
What do you dislike about the product?
Splunk has a pricing model where the cost of their software has to do with the amount of data that it ingests. I would rather see something that was done on a node basis rather than total amount of data.
What problems is the product solving and how is that benefiting you?
Splunk helps my company better monitor the network for suspicious activity.
Recommendations to others considering the product:
Splunk takes a bit to get running. I would suggest that anyone looking into implementing Splunk send any team member planning to use this software to the vendor training courses.