I use the Enterprise platform mainly to monitor infrastructure, applications, and some security logs.
External reviews
External reviews are not included in the AWS star rating for the product.
Offers excellent data analysis and visualization capabilities
What is our primary use case?
What is most valuable?
The most valuable feature of Splunk for data analysis is its ability to search using SPL and SQL. With SPL commands, you can analyze both structured and unstructured data and build visualizations, dashboards, and reports. Additionally, Splunk offers alerting mechanisms for proactive monitoring.
What needs improvement?
There is room for improvement in introducing more AI capabilities onto Splunk Enterprise Platform. While they might exist in other platforms like ITSI, enhancing the Enterprise Platform with AI features would benefit many users who predominantly use it.
For how long have I used the solution?
I have been using Splunk Enterprise Platform for almost three years.
What do I think about the stability of the solution?
I would rate the stability of Splunk at around a seven out of ten. While it is generally good, in complex environments, issues may arise due to the increased number of components and dependencies. However, overall, the stability is good.
What do I think about the scalability of the solution?
I would rate Splunk's scalability as a nine out of ten. It is the best log analysis application currently available. Scalability has allowed us to handle increasing volumes of data, enabling us to onboard additional customers and share infrastructure monitoring on the same setup. We have approximately 20 people using Splunk Enterprise Platform in our company.
How are customer service and support?
The technical support team could improve by providing more direct assistance rather than primarily relying on community resources for issue resolution. While they do understand the issues, they often refer to existing communities for solutions instead of directly addressing system-specific concerns. Overall, I would rate the support as a six out of ten.
How would you rate customer service and support?
Neutral
How was the initial setup?
The initial setup of Splunk Enterprise is relatively complex compared to other monitoring applications in the market. There is a need to focus on simplifying key components and reducing dependencies for a smoother setup process. For a large environment, the deployment of Splunk Enterprise typically takes around three months to set up completely.
What's my experience with pricing, setup cost, and licensing?
Splunk Enterprise Platform is a bit expensive.
What other advice do I have?
I use the Platform to monitor my IT infrastructure. There are apps for Linux and Windows servers that capture performance metrics like CPU and memory usage. These metrics are collected and sent to the blank index through forwarders.
Splunk helps with security information and event management by detecting and monitoring network equipment and firewalls. It saves searches for specific terms, like threats, in firewall logs. When a match is found, it alerts about potential security breaches, helping to detect and address them.
The real-time processing capability in Splunk enhances data monitoring by centrally collecting all data. This allows for easy searching and scheduling of searches, reducing the need for manual intervention.
The dashboard and visualization features in Splunk impact data analysis by providing a clear status of data analysis. Users can create customized views for management, helping them understand what is happening within the infrastructure more effectively.
I would recommend Splunk to others, especially from the CIM perspective. Its data analysis and visualization capabilities are unmatched, making it an excellent choice for SIM.
Overall, I would rate Splunk Enterprise Platform as a nine out of ten.
Which deployment model are you using for this solution?
Splunk Enterprise Review
2) Simple and powerful tool for SEIM.
3) Rich visualizations & Cutomizable dashboards to understand insights clearly.
4) Real time monitoring and alerting features are cheryy on top.
2) It also offers free version but have very limited functionality.
The valuable information
Splunk your Issues
Provides efficient monitoring capabilities and valuable transaction insights
What is our primary use case?
We use the product for real-time monitoring purposes.
What is most valuable?
The product's most valuable feature is the ability to explain the values and provide insights into transactions. It allows us to understand successful and failed transactions with a graphical representation easily.
What needs improvement?
Areas for improvement include enhancing dashboards, reports, alerts, and the monitoring console. With the monitoring console, users can track server performance metrics such as data ingestion, server uptime, CPU, and memory utilization. Integrations with third-party apps can provide comprehensive server monitoring capabilities. However, setting up such integrations may require significant time and effort, as experienced in the mentioned case took nearly 20 days to complete.
For how long have I used the solution?
We have been using Splunk Enterprise Platform for four years now.
What do I think about the stability of the solution?
I rate the platform's stability an eight out of ten.
What do I think about the scalability of the solution?
The product is highly scalable.
How was the initial setup?
The complexity of the initial setup largely depends on the level of experience. I find it straightforward due to my proficiency in establishing connectivity, creating DNS, and performing installation configuration. I rate the process a nine and a half out of ten.
The time required for deployment varies depending on the process in place. If changes need to be made within a specific window, such as raising an instance, the window period opens only for a set duration. Deployment in such cases involves raising a change request and obtaining approval, which can take up to seven days. However, from a technical perspective, initial deployment typically takes up to one or two hours. Yet, procedural requirements, like awaiting change request approval, may prolong the process, necessitating additional days of waiting before deployment can proceed.
What's my experience with pricing, setup cost, and licensing?
The product is expensive, and the cost depends on the amount of data ingestion.
What other advice do I have?
When clients request specific data for a particular period, we retrieve the relevant information from our servers and generate statistics. Later, we create reports, alerts, and dashboards based on the requested data. This process involves fetching the necessary data attributes, such as service names, and displaying their corresponding values in the generated reports, alerts, and dashboards.
The platform's alerting capabilities enable the automation of alerts based on predefined conditions. When specific results exceed predefined thresholds, alerts are triggered automatically. For example, if a value exceeds a specified threshold, an email alert is generated and sent to the relevant stakeholders, prompting them to take appropriate action. This automated alerting mechanism enhances operational efficiency by promptly notifying stakeholders of critical events, allowing them to respond swiftly and effectively to potential issues or deviations from expected outcomes.
I recommend Splunk to other people. It's a very good tool, offering many features that surpass other tools like Kaspersky. Its comprehensive monitoring capabilities and insightful analytics make it a valuable user asset.
I rate it a ten out of ten.
Which deployment model are you using for this solution?
Helps to monitor logs from various sources but improvement is needed in support
What is our primary use case?
We use the tool to monitor logs from various sources. Multiple users send their logs to the Splunk Enterprise Platform using different methods, including Universal Forwarder and AWS services like S3. Additionally, we utilize tools like AWS Genesys for log transmission.
What is most valuable?
The product helps monitor and visualize data. It allows you to handle various tasks. You can store, visualize, and analyze data with the Splunk Enterprise Platform. It offers features like virtual folders and heavy folders for filtering data. Additionally, you can create dashboards to showcase data to different teams and stakeholders. The tool also enables the creation of analytics and alerts and sends reports, making it a valuable tool for our system.
The dashboard and visualization features are good for data analysis. With features like the Studio dashboard introduced in versions 8 to 9, users find it much easier to create dashboards without knowledge of languages like XML.
What needs improvement?
Based on my experience, I've noticed areas for improvement, particularly in support. Developers typically interact with support personnel who may lack technical expertise when raising support tickets. This can result in delays as initial interactions involve sharing documents before escalation to higher support levels.
For how long have I used the solution?
I have been using the product for four years.
What do I think about the stability of the solution?
I rate the tool's stability an eight out of ten.
What do I think about the scalability of the solution?
The tool's scalability is good, and it is based on licensing. My company has more than 10,000 users.
Which solution did I use previously and why did I switch?
I used Dynatrace before the Splunk Enterprise Platform.
How was the initial setup?
The tool's deployment can be complex for the first time. It can become more manageable after that.
What's my experience with pricing, setup cost, and licensing?
If you exceed your licensed limit, the product will issue a warning, typically a five-license warning. Additionally, they send daily email notifications informing you about the breach. This prompts you to consider options such as minimizing logs or acquiring additional licensing to address the issue.
It can be perceived as expensive, especially for organizations dealing with large volumes of data, such as in the banking sector, where numerous logs are generated every second. While other tools are available at lower costs, some teams may consider open-source or lower-cost alternatives, especially if they have funding constraints.
What other advice do I have?
Regarding security and event management, the tool is handled by a different team. They utilize security enterprise tools, including SIEM, to manage security. Splunk Enterprise Platform's real-time processing capability significantly enhances our data monitoring. I would rate it an eight out of ten.
Which deployment model are you using for this solution?
Enables us to collect, index, and analyze data from various sources, such as apps, servers, network devices and security systems
What is our primary use case?
The solution is used for basically, to monitor various logs, so it is the application logs, some kind we are monitoring databases.
How has it helped my organization?
Splunk is providing, like, proactive monitoring using desserts and all. So these things have improved a lot. Like, in our done day to day activities and all. So whenever we are seeing any kind of alerts and also on that basis, we are going to create alert.
What is most valuable?
For monitoring security data is the most valuable feature.
What needs improvement?
Currently, I think things are good only. There are certain things which is not which is there in the other platform like UAE, UBA is there. Like, Splunk is having another product itself. But the thing is, like, if that can be incorporated with the Splunk Enterprise three version. So it will be helpful for the users to explore more on that one.
For how long have I used the solution?
I have been using Splunk Enterprise Platform for five years.
What do I think about the stability of the solution?
The stability is a nine out of ten meaning the solution is highly stable.
What do I think about the scalability of the solution?
It is a scalable solution. Around thousand plus users are using the solution.
Which solution did I use previously and why did I switch?
I have been using this Splunk only from my, like, a shorting of the career. During this period, I have been using AppDynamics and NetSync as well.
How was the initial setup?
Normally so for trial version, it is easy. So it depends on how much data you are ingesting. So if you are going for the Flushing environment, so that setup Could be somewhat difficult, but, normally, it will be easy only.
What was our ROI?
I have seen a Return on Investment.
What's my experience with pricing, setup cost, and licensing?
Costing depends on, like, how much data you are investing. So that will increase your cost.
What other advice do I have?
I will rate the overall solution a nine out of ten.
Which deployment model are you using for this solution?
Useful for cloud-based monitoring but improvement is needed for providing a shareable format
What is our primary use case?
We used the product for cloud-based monitoring or systems monitoring.
What is most valuable?
The key difference I noticed for my use case, which involved understanding user behaviors and responses to digital elements, was that I could obtain more detailed reporting than what was possible with Amplitude. I could download a file with very specific information, which was helpful.
I did not use it for real-time monitoring. My focus was on investigating incident reports to understand the extent of user impact. Primarily, I utilized the Splunk Enterprise Platform to analyze user behavior.
I found the incident notification to be very helpful. While Splunk Enterprise Platform provided detailed data, it didn't seem to check as many boxes for user behavior as Amplitude did. At the same time, I'm not sure if Amplitude offers features for monitoring or incident coverage.
Its ability to access granular details in Excel was beneficial. It's always helpful to transition from visualizations to detailed user reports.
What needs improvement?
The tool lacked in providing a shareable format. I had to use pivot tables and manually parse and edit the data to create a visualization-friendly format. It was helpful when we had an issue. What would make it stronger is if it were more proactive. For example, if it highlighted major incidents and their impact on users without digging through notifications, that would be better. Typically, the first question we get is, "Oh, we had an incident. How bad was it? How many customers were impacted?" So having that information pop up from the notification would be helpful.
What do I think about the stability of the solution?
Splunk Enterprise Platform is stable.
What do I think about the scalability of the solution?
I saw no issues or reasons to think that the product wouldn't scale over time. Our data is growing.
How are customer service and support?
I haven't contacted the tool's support.
What other advice do I have?
I rate the overall product a seven out of ten.
I would recommend it for incident management reporting. I would not advise it for understanding user behavior or usage. If I had to choose between Splunk Enterprise Platform and Amplitude, I would probably go with Amplitude, but I also have no familiarity with what their incident reporting is like.
"Splint!It's a thrilling and overzealously discovery of new network assets".
Absolutely great for use of repository of secure keeping of data.
It's have a great dashboard for data visualization.
It's spectacular for events tracking for quick action.
Bodacious for it's realtime alerts of any threat in network enterprise for quick action.
With the help of machine learning it's very great for automated responses.