We have around 38 virtual machines, including the desktop. We have filled our gap network. Splunk Enterprise monitors all network layer traffic, starting with Cisco traffic port violations. We are monitoring Windows logs, CPU, RAM, and disk utilization in Windows.
External reviews
External reviews are not included in the AWS star rating for the product.
One of the best tools for Dashboards
The correlated data on the dashboards can also be used to deliver presentations to all stakeholders.
Compliance Monitoring
Team Performance Monitoring
Dashboards for Auditing
Dashboards for Delivering Presentations
Correlated data to drive governance on aspects which need more focus
A platform for monitoring storage, CPU, RAM, Windows logs, and Cisco network logs on large machines
What is our primary use case?
What is most valuable?
Splunk Enterprise is a wireless enterprise application that can be customized based on training. We can add new machines, Spring Forwarders, and whatever else we need to complete the job.
What needs improvement?
We have an enterprise system that we can only use up to 70% capacity. We have no Internet access. To ensure our system runs optimally, we must configure specific rules, such as RAM, CPU, and space utilization alerts. Also, it is tough for us to reach out to Splunk. We have another software called Nessus, which can be used for vulnerability scans to improve and expand our vulnerability management capabilities. We can add a vulnerability management tool and back network traffic monitoring. This would allow us to add everything into a single platform since we currently use multiple applications for eight solutions.
For how long have I used the solution?
I have been using Splunk Enterprise Platform since 2020. We are using the latest version of the solution.
What do I think about the stability of the solution?
The product is stable.
What do I think about the scalability of the solution?
We have 43 users using this platform.
How was the initial setup?
The initial setup is easy. We manage the installation of Splunk Enterprise Platform. On the first installation day, there are extensive procedures from Splunk and Honeywell. They are explaining how to install the software using Honeywell automation. They have provided a lot of documentation, but it is incomplete. It takes them two days to complete the installation, and then they train us for another week.
What's my experience with pricing, setup cost, and licensing?
We are using 11GB per day. Since I did all the analysis to determine how much we are consuming, we are currently utilizing around 5GB out of 11 GB. Therefore, we can reduce our usage from 11GB/day to 5GB/day. We reached out to Splunk, and they confirmed that this is possible. They also mentioned that there are commercial benefits to signing a longer-term contract. We are currently working on reducing our usage from 11GB/day to 5GB/day.
What other advice do I have?
We have annual automation for our automated building and availability building. The maintenance is easy. We will do a vulnerability scan. Then, we need to ask someone from the Splunk team to confirm that upgrading to this version of Windows or applying monthly or weekly patches will not impact the Splunk application. It's not easy or feasible to reach out to Splunk directly. Splunk is an enterprise software platform that monitors storage, CPU, RAM, Windows logs, and Cisco network logs on large machine setups. I suggest Splunk to anyone with these needs. Overall, I rate the solution an eight out of ten.
Splunk very useful for log monitoring
Versatile, adaptable, and applies to many use cases
What is our primary use case?
I use the platform to collect data and report to the clients that need reporting from Splunk. I work on gathering big data from all over my company and exporting it into proper reports.
What is most valuable?
What I find the most valuable about the platform is its DB Connect and its versatility in general. I also like its adaptability to any use case when it comes to collecting and analyzing data.
What needs improvement?
It is hard to say in what areas the platform could be improved since it's very versatile and applies to many use cases. It already has the functioning vetted into the core architecture of the product. In my opinion, there is no need for additional features because it already has many, and I haven't used them all.
For how long have I used the solution?
I've been using Splunk Enterprise Platform for two and a half years. I am a Splunk software architect and Splunk is the only platform I use.
What do I think about the stability of the solution?
It's a very stable platform. A ten out of ten.
What do I think about the scalability of the solution?
The scalability of Splunk is ten out of ten. It's one of the best platforms on the market. Approximately 1,000-2,000 people use the platform at our company, but only two people are needed to maintain it and I'm one of them. Everything is automated and it is very easy to manage 2,000 users on my own.
Which solution did I use previously and why did I switch?
I would compare Splunk Phantom with RSA NetWitness and Elasticsearch. All three solutions give the same output but in a different way. They analyze data in different ways. Each product has its scalability, versatility, and appliances in the current business needs of the company that uses it.
How was the initial setup?
The initial setup is very easy. At our company, we deployed Splunk ourselves because we are a team of Splunk architects and we have done it before.
What's my experience with pricing, setup cost, and licensing?
The platform is too expensive for small businesses. If you choose the free plan, it only has 15 GB of data per day, and it may not be enough to run a small business. You need to pay a subscription based on data ingestion, and that's very expensive. Splunk should focus more on delivering something for small businesses and entrepreneurs. I give the pricing a three or four out of ten. Although the product is pricey, it's truly magnificent.
Which other solutions did I evaluate?
What other advice do I have?
Overall, I give Splunk a nine out of ten and not a solid ten just because there are new updates every day and we don't know exactly what we need to search for since it's not that viewable.
Which deployment model are you using for this solution?
A complete solution to collect logs with faster response
What is most valuable?
The product comes with a faster installation and response time. When I search something on the log, they give the result in a few seconds. Even if I didn’t have EDR, I can investigate rules in Splunk.
What needs improvement?
The solution is only meant for big companies.
For how long have I used the solution?
I have been using the Splunk Enterprise Platform for three years.
What do I think about the stability of the solution?
I rate the solution’s stability a ten out of ten.
What do I think about the scalability of the solution?
We have around ten people working with the solution.
I rate the solution’s scalability a ten out of ten.
How are customer service and support?
I didn’t contacted the customer support. Spunk has a website and community which has everything you need.
How was the initial setup?
The initial setup is easy. For deployment, I created a Splunk demo on my computer and on a POC environment. I ran the demo for 10 clients on 10 machines, and it took about 20 minutes.
What's my experience with pricing, setup cost, and licensing?
Spunk is used by big companies like with 2000 clients.
I rate the solution’s pricing one out of ten.
What other advice do I have?
There are around ten engineer required for troubleshooting of the solution.
I recommend the solution to other organisation since it is very responsive.
Overall, I rate the solution a ten out of ten.
Which deployment model are you using for this solution?
Great platform to create dashboard,monitor, analyze big data
Splunk drain for logging and alert
A highly versatile data collection and monitoring tool
What is our primary use case?
We use the monitoring solution. People might ask me to create a new request, maybe for a specific Windows event log, which is how we create a ticket for an incident. Most of the time, this creates a new alert for people. It can be a little complex. We can also create dashboards with some information for other teams. Dashboard alerting is a big part of the work.
Though we use Splunk for monitoring, for me, it is more software that collects lots of data and can then be used for alerting.
We use a custom environment.
What is most valuable?
The best thing about Splunk is you can collect all the data you want, and you can play with the data and do what you want. You can modify the data and collect all the information into one dashboard. It's very cool. In other monitoring software like Zabbix, you can't easily do something like this. With Splunk, it's very easy. You need to understand Splunk's language, but you can do what you want after that. You can correlate your data with CSV files. Splunk can monitor, extract, transform, and load software.
What needs improvement?
Splunk is not an out-of-the-box solution like Micro Focus or Zabbix. You have to create your request to collect the data and add crucial components to the software. You have add-ons created by Splunk or the community but don't have out-of-the-box monitoring items in the software. For example, FETCH CUP with Micro Focus is agentless monitoring, has a lot of out-of-box items, and is easy to use. You will find it difficult to use Splunk initially, which could use improvement. However, I know there is another module from Splunk that focuses on fast and secure monitoring with more out-of-box add-ons, but I haven't used it since when I started using it, it lacked out-of-box items. All the same, Splunk could be more user-friendly for new users.
For how long have I used the solution?
I've worked with the solution for about two years.
What do I think about the stability of the solution?
I rate Splunk's stability a nine out of ten because it's very stable. I don't face issues with projects.
What do I think about the scalability of the solution?
You can scale Splunk. It works with an indexer which indexes search data. If you want more power, you can add more indexers, so I rank Splunk's scalability an eight out of ten.
How was the initial setup?
With all the documentation available, the initial setup is not difficult. If all you want is a stand-alone app in Splunk to handle all the processes, you just need to create a project in the data server, which is easy.
What's my experience with pricing, setup cost, and licensing?
You must buy a license with the on-prem version, usually through an intermediary. In France, it's Accenture. There are cloud solutions where Splunk handles the servers and patching directly, and you just use the solution.
The solution is expensive, so I rate its pricing a four out of ten. Though the solution is expensive, it depends on which company purchases the product.
Which other solutions did I evaluate?
Though I haven't used it, Grafana is also a CM that can collect data.
What other advice do I have?
I didn't create the custom environment we use at my organization. Still, it doesn't seem too difficult to build things because there is a lot of online documentation and videos. You can also get training with Splunk. You have a lot of data to help you when you want to create a new environment.
I rate Splunk Enterprise Platform an eight out of ten. The solution is very powerful, and I like to play with data to do what I want.
Which deployment model are you using for this solution?
Great tool for log aggregator and searching
Good infrastructure and easy to maintain
What is our primary use case?
We use Splunk Enterprise for data visualization.
We use Splunk administration rather than Splunk development.
We provide support to users so they can access our Splunk application and use it however they want. For example, if they are not able to view some of the logs that are coming from their servers in our Splunk, then we usually check all the logs here that have been missed and forward the ones that were not forwarded.
Also, sometimes they use their access to install some apps. We have Splunk apps and they want us to create an app for their usage. We also need to create these apps in the Splunk application. Sometimes they aren't able to download or upload files into Splunk or other websites. They aren't able to download these reports as PDF files. We usually work on this and try to resolve it as quickly as possible.
How has it helped my organization?
We use Splunk for cyber security. We have a lot of teams who use Splunk for different purposes. The security team uses it to authorize log-ins, so in case something happens, Splunk monitors it. Also, the development team uses it to monitor data while they're creating a new application.
What is most valuable?
In the enterprise platform, all of the clusters and indexes are under our maintenance. If required, we can make changes and see the logs manually by getting into the servers.
What needs improvement?
Things have to be managed manually in Splunk Enterprise, which is not the case in Splunk Cloud, where the client could manage it on their own.
It would be useful if Splunk Enterprise Platform could monitor the application URL, to check whether it's responsive or not.
For how long have I used the solution?
I've been using it for a year and a half.
What do I think about the stability of the solution?
It is completely stable and the infrastructure is good. We have no issues with our Splunk Enterprise Platform.
How are customer service and support?
We contact technical support whenever there's an issue with logs and they work through it with us.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
We use both Splunk Cloud and Splunk Enterprise. We might opt for Splunk Cloud in the future since it's less expensive, but we are currently using both.
How was the initial setup?
The deployment takes about a day. I would say that the initial setup is quite a complex thing to do because there are a lot of things that have to be done for clustering all the features and indexing and then forwarding data to the indexes. When it comes to applications, we have to replicate the data. The process takes time. Once everything is done, we still need to monitor the infrastructure constantly.
It is easy to maintain if you are familiar with the deployment model.
Which other solutions did I evaluate?
I have hands-on experience with AWS, Linux, Ansible, and Terraform and with programs like Python, Java, and SQL as well. I also use tools like Catchpoint, Nagios, and Grafana.
What other advice do I have?
I would suggest using Splunk Cloud first, and then Splunk Enterprise because the maintenance and the infrastructure management are easy. I would rate it an eight out of ten.