Sign in
Categories
Your Saved List Become a Channel Partner Sell in AWS Marketplace Amazon Web Services Home Help

Splunk Enterprise

Splunk | 9.4.3

Linux/Unix, Amazon Linux 2023 - 64-bit Amazon Machine Image (AMI)

Reviews from AWS customer

16 AWS reviews

External reviews

445 reviews
from and

External reviews are not included in the AWS star rating for the product.


4-star reviews ( Show all reviews )

    UzairKhan

Delivers financial benefits and operational efficiency with impactful data analytics capabilities

  • May 09, 2025
  • Review provided by PeerSpot

What is our primary use case?

The use cases for Splunk Enterprise Platform vary depending on the specific scenario.

Splunk Enterprise Platform has different purposes, including data visualization and other applications.

What is most valuable?

In Splunk Enterprise Platform, the most impactful features for data analytics allow you to get into the repository.

There are financial benefits from using Splunk Enterprise Platform, and as a retailer, it provides better profit margins.

Splunk Enterprise enhances data analytics with its AI capabilities.

What needs improvement?

For future updates of Splunk Enterprise Platform, I would like to see integration by GUI.

The integration should be improved with the UI.

For how long have I used the solution?

I have been using Splunk Enterprise Platform for about two years.

What was my experience with deployment of the solution?

There are no significant challenges in deploying Splunk Enterprise Platform.

The challenges or pain points others should anticipate before implementing Splunk Enterprise Platform are mostly related to the integration part.

How was the initial setup?

The time it takes to deploy Splunk Enterprise Platform depends on the use cases.

It may take anywhere from a couple of hours to a couple of weeks for Splunk Enterprise Platform deployment.

What about the implementation team?

The same three people take part in the deployment of Splunk Enterprise Platform.

I do not take part in the deployment; my team does.

What other advice do I have?

My advice for those looking to implement Splunk Enterprise Platform is to know the product well and have hands-on workshops or create a lab to gain complete knowledge before proceeding.

Regarding maintenance, it does not require much as it is on-premises.

Overall, I would rate Splunk Enterprise Platform an eight.

Which deployment model are you using for this solution?

On-premises

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Other


    Information Technology and Services

Splunk enterprise is powerful and reliable

  • December 18, 2024
  • Review provided by G2

What do you like best about the product?
Real-time data insights and customizable dashboards
What do you dislike about the product?
Steep learning curve for beginners to master
What problems is the product solving and how is that benefiting you?
Splunk enterprise helps centralized logs, detect security threats and monitor system performance, making troubleshooting.


    reviewer2511618

Seamless integration streamlines fraud detection

  • November 11, 2024
  • Review provided by PeerSpot

What is our primary use case?

The main use case is to analyze the data log coming from other systems. We use Splunk to identify anomalies in transaction patterns, which may indicate irregular activity from certain customers. Our goal is to create alerts for stakeholders when such anomalies are detected.

How has it helped my organization?

Splunk has made our job easier by streamlining data searching and decision-making processes. By using it for fraud detection, we have potentially saved billions of Indonesian rupiah.

What is most valuable?

Splunk is very flexible in handling various formats of data as long as basic rules are adhered to. Its integration with other systems is seamless and can be done overnight. This ease of integration is its best advantage. Additionally, Splunk is adequate for real-time data processing.

What needs improvement?

The Splunk Processing Language (SPL) poses a steep learning curve for new users. The software could benefit from additional processing power, such as GPU support, for handling large volumes of data faster. The language could also be more user-friendly, similar to platforms where actions are easier through button clicks.

For how long have I used the solution?

I have used the solution for approximately three years.

What do I think about the stability of the solution?

I rarely encounter bugs or glitches during daily use. However, there was one instance where an issue required solutions from the headquarter's next upgrade session.

What do I think about the scalability of the solution?

Splunk is scalable, provided the supporting infrastructure, such as CPU and GPU processing, is also scalable.

How are customer service and support?

I rarely communicate with the Splunk headquarters, usually interacting with the local implementer.

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

We are not using anything else that functions like Splunk. However, for fraud detection, we also use GVD Instinct and FICO, along with Elasticsearch.

What about the implementation team?

I have not been involved in implementing it, except in integration, where I've found it easy.

What was our ROI?

We have been saving significant amounts through fraud detection. I cannot say precisely how much. Overall, Splunk has simplified our data management and decision-making processes.

What's my experience with pricing, setup cost, and licensing?

The official license operates like a subscription with an annual fee. Our local implementer offers pricing based on reserved quota, such as 80 gigabytes per day, costing under one billion Indonesian rupiah, or around $70,000 USD. It is affordable and flexible.

Which other solutions did I evaluate?

Elasticsearch, Kibana, Check Point, and other solutions like Microsoft Teams, OneDrive, and SharePoint are used.

What other advice do I have?

Keep my identity anonymous; publishing my title is sufficient. It's important to master the SPL for efficient use. Seek solutions that better support GPU for real-time processing.

I'd rate the solution eight out of ten.

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Other


    Himanshu Tejwani

Enhanced efficiency with exceptional monitoring features

  • November 06, 2024
  • Review provided by PeerSpot

What is our primary use case?

Our use case for Splunk Enterprise Platform involved deploying the solution for a client requirement, focusing on their data monitoring and management needs.

How has it helped my organization?

Splunk Enterprise Platform has significantly improved operational efficiency by making it easier to monitor infrastructure, detect errors, and read logs. It has reduced troubleshooting efforts from one hundred percent to about twenty percent, thereby increasing productivity significantly. The platform's ability to monitor Docker containers directly has also been beneficial for us.

What is most valuable?

The most valuable features of Splunk Enterprise Platform include its performance, ease of implementation, and user interface, which are superior compared to other on-premises products.

What needs improvement?

Pricing is an area that needs improvement, as it is considered high. Additionally, the addition of AI capabilities would be beneficial for analyzing IP activity patterns and providing alerts. During the integration with Docker, we noticed that Splunk only shows container IDs and not their names, which is a drawback.

For how long have I used the solution?

I have used Splunk Enterprise Platform for one to two years for the projects I have mentioned.

What do I think about the stability of the solution?

Splunk Enterprise Platform is a stable solution, and I would rate its stability as nine out of ten.

What do I think about the scalability of the solution?

Splunk Enterprise Platform is scalable, though the implementation can be challenging. I would rate scalability as eight out of ten.

How are customer service and support?

We have not opted for paid support but have utilized community support, which is good but could benefit from more contributions. I rate the support a seven out of ten.

How would you rate customer service and support?

Neutral

Which solution did I use previously and why did I switch?

We have tried multiple products before, but they were difficult to implement. Splunk Enterprise Platform is much easier to implement and execute quickly, which is why we chose it.

How was the initial setup?

The initial setup was not considered easy and required learning and implementation by ourselves. It was an average difficulty process, not too difficult but not very easy either.

What about the implementation team?

The deployment and implementation were done by myself and one of my teammates, totaling two people involved in the process.

What was our ROI?

Monetary ROI was not directly measured, but using Splunk Enterprise Platform has reduced time spent on troubleshooting, therefore enhancing productivity.

What's my experience with pricing, setup cost, and licensing?

I would rate the pricing around three out of ten, considering the tool's cost. We haven't used any extra features, so I'm not sure about additional offerings.

Which other solutions did I evaluate?

We evaluated several other products, but they were found difficult to implement. Splunk was the easier solution.

What other advice do I have?

I highly recommend Splunk Enterprise Platform for organizations with large volumes of logs and multiple servers, as it provides good ROI for big companies. However, due to its cost, it may not be suitable for small organizations.

Which deployment model are you using for this solution?

On-premises


    Sudheer Kumar

Helps with monitoring and incident management

  • August 19, 2024
  • Review provided by PeerSpot

What is our primary use case?

I use the solution in my company to capture the events to deal with threat detection, incident response, and compliance reporting. For IT operation management, it gets complex to track the health and performance of IT infrastructure, including our network devices and applications, so Splunk Enterprise Platform can be used for centralized log management.

What is most valuable?

The most valuable feature of the tool for DevOps and from a continuous delivery perspective is that the tool is useful in areas like deployment, monitoring, and incident management.

What needs improvement?

If I compare Splunk Enterprise Platform with the other tools, the dashboard and the user interface need to be built at a console level and in a user-friendly mode. Sometimes, the tool looks a bit complex, and we can't find out the exact area where we need to make the changes in the configuration and changes for the log events monitoring. The dashboard and the console-level areas need to be made friendly.

The product's initial setup phase needs to be made easy since it looks like it is very complex compared to the other tools in the market.

For how long have I used the solution?

I have been using Splunk Enterprise Platform for three years.

What do I think about the stability of the solution?

From a stability perspective, the tool is good. If any breakdowns exist, remediation and support are provided, so it is not a problem.

What do I think about the scalability of the solution?

The tool is used by around 5,000 employees and servers in my company.

How are customer service and support?

I have interacted with the solution's technical support. I rate the technical support a seven and a half out of ten.

How would you rate customer service and support?

Neutral

How was the initial setup?

The solution is deployed in an on-premises version.

What's my experience with pricing, setup cost, and licensing?

The tool is expensive.

What other advice do I have?

To first-time users, I can say that proper analysis and bandwidth utilization, cloud resource monitoring, and cost optimization are the things I would ask one to check in the tool.

It is not easy for beginners to use, and for freshers, it will take time to understand the tool.

From a security perspective, I rate the tool a nine out of ten. From a user and the console perspective, I rate the tool a seven out of ten.

In general, I rate the tool an eight out of ten.

Which deployment model are you using for this solution?

On-premises


    Luis P.

Splunk Review

  • July 16, 2024
  • Review provided by G2

What do you like best about the product?
a powerfull tool with alot of potencial to make more ease the work
What do you dislike about the product?
the app for integration for other tecnologys is limited after new version of splunk
What problems is the product solving and how is that benefiting you?
help to the monitoring infraestructure with dashboards and alerts to can more ease and simple to preven incidents


    Shivakumar V.

A tool to analyze your logs and data

  • April 28, 2024
  • Review provided by G2

What do you like best about the product?
It is easier to write SPL queries than SQL, and you can create your own custom Splunk commands where you can write your own Python scripts to handle complex data types like JSON, which has a nested level of 3 or 4. It is easy to create visualizations and get insights out of the data through commands like charts, stats, etc. It has a vast level of customer support, and when the developer or the user gets stuck, it has great documentation to resolve the issue.
What do you dislike about the product?
The resources splunk software takes when it handles a complex query makes you crazy and it has everything a developer needs, but when it comes to the licensing, it is a bit costly.
What problems is the product solving and how is that benefiting you?
The business problem that Splunk solved was creating a custom visualization using Java scripts for rendering a train track, like the current movement of the train on the map or track layout, and also the custom filters that are created with the help of Javascript. I think this is the best thing where I got the most out of Splunk Enterprise here.


    reviewer2393781

Used for application performance monitoring, database monitoring, and infrastructure monitoring

  • April 23, 2024
  • Review provided by PeerSpot

What is our primary use case?

Splunk Enterprise Platform is a basic monitoring tool used for application performance monitoring, database monitoring, and infrastructure monitoring. Currently, I use the solution for application monitoring and security monitoring. I use the tool to monitor security breaches or suspicious activities.

What is most valuable?

The solution is very good for monitoring compared to other tools. It provides an accurate solution. We used to get a free trial of around 60 days to test and get a good experience on Splunk.

What needs improvement?

The solution's license cost is high and can be improved. There are some limitations on data onboarding if you have huge data.

For how long have I used the solution?

I have been using Splunk Enterprise Platform for three to four years.

What do I think about the stability of the solution?

Compared to other monitoring tools, Splunk Enterprise Platform provides good stability.

What do I think about the scalability of the solution?

I haven’t faced any issues with the solution’s scalability.

How are customer service and support?

Splunk ITSI is very good for support, which includes getting an incident number and working on it.

What other advice do I have?

We need to integrate Splunk Enterprise Platform with other tools, which provide some security events. After integrating, you get the logs from that application's API. Once you get those logs, we will create a code per the business requirements and create an alert, report, or dashboard, whichever is needed.

Splunk Enterprise Platform works based on apps installed in Splunk. For example, if you want SQL data to get into Splunk, you need to install an SQL database plugin on the Splunk server. That plugin will capture the logs related to an SQL database with Splunk. After that, we write a query, pull out the data we need, and provide knowledge objects.

Visualization is very good in Splunk Enterprise Platform. The solution has good visualization elements like bar graphs, pie charts, line graphs, single visualizations, and maps. I would recommend the solution to other users.

Splunk Enterprise Platform is a very good tool for monitoring your day-to-day activity logs. This will eventually help you create reports or dashboards to monitor the business's progress.

Overall, I rate the solution seven and a half or eight out of ten.


    Praveen Sande

Offers extensive visibility into events with flexible scalability

  • April 22, 2024
  • Review provided by PeerSpot

How has it helped my organization?

Splunk Enterprise Platform is a powerful application that offers extensive visibility into events, notable occurrences, and correlations, providing robust capabilities.

What is most valuable?

The valuable feature is the onboarding of various logs using different methods. Additionally, it excels in content development and use case creation. I want to learn about upcoming technologies like Splunk Cloud and Azure integration. These platforms offer extensive capabilities for visualizing and manipulating data according to our requirements. Splunk's proficiency in field extractions and onboarding logs from diverse sources makes it highly capable. Its logging addition and parsing capabilities are particularly noteworthy.

What needs improvement?

In Splunk Enterprise Platform, while the dashboard feature is powerful, it does have limitations in terms of the number of parameters that can be included in one dashboard. However, it's important to note that these limitations can be addressed through effective dashboard design and optimization techniques. Despite these constraints, Splunk offers extensive capabilities for creating insightful dashboards that can visualize relevant data effectively.

Splunk excels in providing accurate and valuable alerts and reports. These features are crucial in reducing manual efforts, minimizing human errors, and expediting incident resolution processes. With Splunk's alerting and reporting functionalities, users can fine-tune alerts, apply filters, and include necessary information for thorough investigation and analysis. These capabilities contribute significantly to enhancing operational efficiency and decision-making within organizations.

For how long have I used the solution?

I have been using Splunk Enterprise Platform for five years.

What do I think about the stability of the solution?

I rate the solution’s stability an eight out of ten.

What do I think about the scalability of the solution?

Scalability is very flexible. Without the Splunk support, we can deploy and scale up.

How are customer service and support?

The responsiveness of the support is very good. They will ask you if you are raising any P2, P1, or major incidents so they'll help us with immediate and accurate results.

How was the initial setup?

The initial setup is straightforward , with detailed deployment steps outlined in their documentation. Additionally, the Splunk community is a valuable resource where users can ask questions and receive expert solutions. 

What other advice do I have?

Splunk Enterprise Platform does not have a few application add-ons. Therefore, when we aim to integrate log sources from new or important ones that Splunk lacks add-ons for, we resort to developing custom add-ons. While this approach allows us to proceed with our work, it requires significant human effort and increases the likelihood of errors. Moreover, troubleshooting becomes time-consuming under these circumstances. Ideally, Splunk would offer add-ons for every possible application, significantly improving our efficiency and effectiveness.

The Splunk Enterprise Platform offers excellent visibility through real-time monitoring. Whenever any data matches our client's SQL code, it triggers an immediate alert, allowing us to respond to incidents swiftly. This capability is highly beneficial during any incident, making Splunk an invaluable tool.

There are various components, such as Universal Forwarder, Indexer, and Search Head. These components are relatively straightforward to set up. However, when implementing a distributed environment or setting up clustering, Splunk offers robust capabilities. Additionally, managing data storage sizing is also seamless.

Overall, I rate the solution an eight out of ten.

Which deployment model are you using for this solution?

On-premises


    ABBURI AJAY

Used for logging and monitoring purposes

  • April 12, 2024
  • Review provided by PeerSpot

What is our primary use case?

We use the Splunk Enterprise Platform for logging and monitoring purposes. If users log into different databases and do something, we onboard database logs and other AWS logs to Splunk. Then, we create a dashboard alert report, and based on those dashboard alerts, we monitor users' actions. If they perform suspicious activities, we also send alerts. We use the solution to create dashboard alerts, reports, and some query language.

What is most valuable?

The most valuable features of the solution are the load balancing technique, the forwarding technique, and SSL certification.

What needs improvement?

Sometimes, queries don't give proper results, and the indexes go down.

For how long have I used the solution?

I have been using Splunk Enterprise Platform for seven years.

What do I think about the stability of the solution?

I rate the solution an eight out of ten for stability.

What do I think about the scalability of the solution?

I rate the solution’s scalability a nine out of ten.

How are customer service and support?

The solution’s technical support is good.

How was the initial setup?

The solution’s initial setup is easy.

What's my experience with pricing, setup cost, and licensing?

I have heard from my managers that Splunk Enterprise Platform is an expensive solution.

What other advice do I have?

The solution has helped us with our security information and event management. If someone performs deletion operations, we get an automated alert informing us that a privileged activity has been performed. We forward the logs in real-time. We are ingesting 10GB of data into the solution daily. We have some input filters in the solution's dashboard.

Overall, I rate the solution an eight out of ten.

Which deployment model are you using for this solution?

On-premises