To gain deep visibility into our entire cloud infrastructure, we deployed the Splunk Cloud Platform. This tool allows us to monitor, analyze, and investigate all aspects of our cloud environment.

External reviews
External reviews are not included in the AWS star rating for the product.
Integrates seamlessly, improves security posture, and provides visibility
What is our primary use case?
How has it helped my organization?
Splunk Cloud Platform integrates seamlessly with other systems, including Slack. This allows us to receive real-time alerts triggered within the tool. We can then analyze the output and take timely action to resolve the issue, ensuring continued security.
Splunk Cloud Platform improved our security posture. We could easily and efficiently obtain detailed analyses of any log, including UPC flow logs and others, promptly. The benefits of Splunk Cloud Platform were visible within two days.
Splunk Cloud Platform does a good job helping to maintain the complaints and privacy regulations within our infrastructure.
Splunk Cloud Platform excels at correlating data from a wide range of sources, including applications, websites, and servers. It efficiently handles the challenge of managing large volumes of data. This has secured our data and demonstrably improved our security posture.
What is most valuable?
The ability to correlate data and then present it in a meaningful and valuable way is crucial. Splunk offered this functionality, providing us with insights into threats, vulnerabilities, and all the identity information we fed into it. We sought a SIEM tool because we lacked a solution that could effectively analyze recent data. We needed a tool that could not only ingest our data but also correlate it and present it in an easily understandable format.
What needs improvement?
The cost of Splunk Cloud Platform is high and has room for improvement.
The current visuals on the dashboard could be more impactful.
For how long have I used the solution?
We conducted a POC of Splunk Cloud Platform 6 months back.
What do I think about the stability of the solution?
During our POC, I did not encounter any stability issues with the Splunk Cloud Platform.
I would rate the resilience offered by Splunk Cloud Platform 8 out of 10.
What do I think about the scalability of the solution?
I would rate the scalability of Splunk Cloud Platform 9 out of 10.
How are customer service and support?
The technical support is good.
How would you rate customer service and support?
Positive
How was the initial setup?
The initial deployment was straightforward. Two people were required for the deployment.
What's my experience with pricing, setup cost, and licensing?
The Splunk Cloud Platform is expensive.
Which other solutions did I evaluate?
Splunk Cloud Platform performed well in the POC but the cost was higher than other tools.
We chose Palo Alto Networks over Splunk due to its combined advantage of cost-effectiveness and superior threat analysis capabilities.
What other advice do I have?
I would rate Splunk Cloud Platform eight out of ten.
Which deployment model are you using for this solution?
Offers real-time monitoring, seamless integration, and improves security posture
What is our primary use case?
We leverage the Splunk Cloud Platform for log ingestion. This allows us to create dashboards, alerts, and reports from security and application log data.
How has it helped my organization?
Splunk Cloud Platform offers real-time monitoring capabilities. It continuously ingests data from various sources, allowing us to track its flow. We can set up alerts to be notified of any anomalies, such as spikes in CPU or memory usage. These alerts can be configured to trigger email notifications, keeping us informed of potential issues. Additionally, Splunk Cloud Platform provides real-time dashboards that visualize the data as it's collected.
The federated search feature is useful for our cybersecurity team to complete their log analysis.
Splunk Cloud Platform offers seamless integration with other systems and applications. This is achieved through apps and add-ons developed by Splunk.
Splunk is a good reporting tool. It allows us to generate reports and attach them to emails in CSV or PDF format.
Splunk Cloud Platform has been instrumental in helping our cybersecurity team continuously monitor our data for anomalies and attacks. Its usefulness extends beyond security, though. Teams that ingest their logs into Splunk can monitor various services. If a service goes down, Splunk will trigger an alert. Splunk offers a robust monitoring suite, including dashboards, alerts, and reports. We can monitor system resources like memory and CPU consumption, application logs, Azure logs, and even Office 365 logs. For example, Splunk can reveal who sent emails, who participated in group email threads, and who added or removed members from Active Directory groups. This audit log capability allows us to investigate activity even months or years later. Splunk provides a wide range of use cases for our organization. We noticed these benefits as soon as Splunk started ingesting data.
Splunk has improved our decision-making process thanks to its clear dashboards that help us analyze information and make informed choices.
Splunk has been valuable as a compliance tool because it centralizes log ingestion. Any tool generating logs should be configured to send them to Splunk. This allows us to easily identify compliant applications – those whose logs are collected. Conversely, uncollected logs raise security concerns, as they represent a potential attack surface.
Splunk has significantly improved our organization's security posture. As a primary security tool, Splunk allows us to collect application logs, monitor activity for potential attacks, and conduct searches to identify suspicious behavior.
What is most valuable?
I like that Splunk Cloud Platform is managed by the vendor.
I like the Cloud monitoring console feature.
I like the support for all the apps and add-ons.
What needs improvement?
Splunk currently manages the components, which restricts our ability to access them directly. I would like to be granted read access to be able to review the components.
For how long have I used the solution?
I have been using Splunk Cloud Platform for one and a half years.
What do I think about the stability of the solution?
The Splunk Cloud Platform is stable as long as we perform proper maintenance to prevent bugs.
What do I think about the scalability of the solution?
This system is very scalable. That means it can be easily adapted to accommodate our needs. We can increase the number of licenses we use, or add more resources like CPU and memory. We can also request additional components, such as adding more user accounts if our team grows from four to eight members. Overall, the scalability of this system is a major advantage.
I would rate the scalability of Splunk Cloud Platform nine out of ten.
How are customer service and support?
Splunk Cloud Platform offers excellent technical support that is both knowledgeable and responsive.
How would you rate customer service and support?
Positive
How was the initial setup?
The initial setup is straightforward but it takes a month or two to complete because of the applications that need to be onboarded.
We first need to calculate the amount of data we need to ingest. Then, based on that amount, we can plan how much data we need to onboard and what components we'll need.
Two experienced people were involved in the deployment.
What about the implementation team?
The implementation was completed in-house.
What's my experience with pricing, setup cost, and licensing?
Splunk Cloud Platform is more expensive than some of its competitors, but it offers a wider range of features.
What other advice do I have?
I would rate the Splunk Cloud Platform eight out of ten.
Splunk Cloud Platform is deployed in multiple locations.
Splunk Cloud Platform requires maintenance.
I recommend the Splunk Cloud Platform to others.
If you're using cloud services, Splunk Cloud Platform is a good option. It minimizes management overhead for you since Splunk handles the underlying infrastructure. Splunk Enterprise however requires more resources to manage.
Which deployment model are you using for this solution?
Helps to improve our incident response time, provides multiple search modes, and is stable
What is our primary use case?
My manager typically requests dashboards, alerts, and scheduled reports. Based on their specific requirements, I create reports and dashboards that visualize the data. We leverage the Splunk Cloud Platform to fulfill these needs.
Additionally, my teammates may approach me for insights. I analyze the data and provide them with these insights, which they then use for team meetings and further data analysis. This ultimately helps them make informed decisions.
How has it helped my organization?
Splunk Cloud Platform improves our incident response time by enabling the retrieval of large data volumes. The platform offers impressive search speeds, and we don't need additional SQL commands to optimize response times.
We saw immediate benefits from the Splunk Cloud Platform. Being able to access and analyze logs provided valuable insights.
Splunk's impact on decision-making is significant. I have access to all the data I need, and it is always reliable.
What is most valuable?
Splunk Cloud Platform's search modes are a powerful feature. There are 3 main modes: Fast, Verbose, and Smart. These modes allow us to customize our search based on our needs, which can significantly improve our response time.
What needs improvement?
Splunk Cloud Platform's dashboard could benefit from some improvements. While it functions adequately, it appears very minimalistic. It's built using a simple XML format, and while newer dashboard options have been released, it still lacks the visual capabilities of tools like Power BI and Tableau. While I understand these are different platforms, having a more powerful dashboard option for the Splunk Cloud Platform would be valuable.
There is a lack of comprehensive learning materials offered by Splunk to prepare for their certifications.
Splunk uses SQL as its search language. One challenge I've encountered is with subsearches used in joins. These subsearches can only handle a maximum of 50,000 entries. If our data set is larger, we won't be able to join it using a subsearch. This limitation has been a significant obstacle for me. I've searched the Splunk community forums, and even reached out to my colleagues and seniors for a solution, but haven't found a definitive answer yet.
For how long have I used the solution?
I have been using Splunk Cloud Platform for 2 years.
What do I think about the stability of the solution?
It is reliable. In my experience working with virtual machines, any search lags are likely due to the VMs themselves, not Splunk.
I would rate the stability 8 out of 10.
What do I think about the scalability of the solution?
Splunk Cloud Platform is horizontal scaling. So it is easy to scale based on the data we are using.
I would rate the scalability of Splunk Cloud Platform 9 out of 10.
How was the initial setup?
Deploying Splunk Cloud Platform requires knowledge of the Splunk architecture, the deployment server, and the components.
What was our ROI?
We have seen a return on investment.
What's my experience with pricing, setup cost, and licensing?
The certifications are costly.
What other advice do I have?
I would rate Splunk Cloud Platform 8 out of 10.
The maintenance required is minimal.
The resilience of Splunk is good.
I recommend the product.
Splunk Cloud Platform is a powerful tool for handling big data. To get the most out of it, understanding both the developer and administrator sides is beneficial. The platform offers broad compatibility with various technologies and allows for easy scaling to accommodate your needs.
Speeds up our response and reduces the time we spend manually monitoring any logs for ticketing tools or servers
What is our primary use case?
We use Splunk Cloud for monitoring various ticketing tools, servers, applications, URLs, and client transactions. We're monitoring the transactions and data flow.
How has it helped my organization?
Splunk has sped up our response and reduced the time we spend manually monitoring any logs for ticketing tools or servers. It saves us around 2 hours daily.
What is most valuable?
We can onboard multiple data types for monitoring from various ports and use Splunk to monitor laptops or other devices directly. If everything is stored in our database, we can also monitor that and see who is logging in and when. You can monitor which files are being used most and which ones aren't. We can also check for any fraudulent activity in the system. The reporting is highly detailed.
Splunk is best when used for real-time monitoring. We can use AI and machine learning, too. Splunk plans to launch new observability features soon. The federated search feature has helped us eliminate redundancy in data servers and discontinue servers that aren't being used much. We can remove those servers from the environment to cut costs.
We can use Splunk to monitor multiple environments. The ease of monitoring depends on the source, application, or cloud environment size.
What needs improvement?
Sometimes, integrating with other systems is difficult, and it isn't feasible to connect with other applications, but it's easy most of the time. I rate Splunk 7 out of 10 for its ability to integrate with other systems.
Every time they launch new versions, we experience a few bugs. The most recent version had a couple of bugs in the databases. We contacted the vendor and got assistance solving these bugs, so the environment is more stable.
For how long have I used the solution?
I have used Splunk Cloud for 4 years.
What do I think about the stability of the solution?
I rate Splunk 8 out of 10 for stability. It has some bugs, but that is common in any product. At least, Splunk resolves bugs quickly.
What do I think about the scalability of the solution?
Splunk's scalability is nice.
How are customer service and support?
I rate Splunk's technical support 9 out of 10.
How would you rate customer service and support?
Positive
How was the initial setup?
Splunk is easy to deploy. We have it deployed across data centers at multiple locations. Splunk requires some maintenance after deployment.
What's my experience with pricing, setup cost, and licensing?
Splunk is a bit pricey, but it's reasonable for the features offered.
What other advice do I have?
I rate Splunk Cloud Platform 8 out of 10. I would definitely recommend Splunk to others.
Which deployment model are you using for this solution?
Boosts performance and helps simplify monitoring across platforms and data management
What is our primary use case?
We leverage the Splunk Cloud Platform to effectively manage the vast amounts of machine-generated data, thereby ensuring application management security compliance.
We implemented the Splunk Cloud Platform to enhance our customer experience and optimize the data storage costs. We can convert the log data into numerical data points when requested.
How has it helped my organization?
The Federated search helps retrieve data in a better way.
Splunk Cloud Platform simplifies monitoring across multiple cloud environments, providing real-time insights into operational flow. It also streamlines data conversion, reducing the data-driven process for the company.
Splunk Cloud Platform's machine learning and AI capabilities simplify data management and provide clear visibility into multiple environments.
The AI makes it easy to integrate with other systems and applications in our environment.
The Splunk Cloud Platform reporting provides good insight.
Splunk Cloud Platform significantly boosted our performance and cost-effectively optimized data sets, delivering immediate benefits.
Thanks to the Splunk Cloud Platform we can make decisions within the organization much faster.
Splunk Cloud Platform empowers our organization to access data efficiently, ensuring compliance with privacy and regulations through actionable insights.
Splunk Cloud Platform strengthens our security, particularly in handling complex processes.
What is most valuable?
The data management and instant search features are the most valuable ones for us, as they allow us to instantly retrieve information needed for reports and security compliance.
What needs improvement?
Splunk should increase the frequency of new feature releases, particularly those related to real-time operational flow monitoring and analytics reporting. It has been over a year since any significant updates were added to the Splunk Cloud Platform.
For how long have I used the solution?
I have been using the Splunk Cloud Platform for one year.
What do I think about the stability of the solution?
Splunk Cloud Platform is stable.
What do I think about the scalability of the solution?
Splunk Cloud Platform is scalable.
Splunk Cloud Platform's resilience is good.
How was the initial setup?
The initial deployment was straightforward. The deployment took around four hours and required two people.
Which other solutions did I evaluate?
We evaluated Victoria Experience but it was not suitable for our environment.
What other advice do I have?
I would rate Splunk Cloud Platform an eight out of ten.
We have around 150 users.
No maintenance is required from our end.
I recommend Splunk Cloud Platform. It helps monitor all the respective functions.
Which deployment model are you using for this solution?
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Offers excellent visibility, and cloud performance, and requires zero maintenance on our end
What is our primary use case?
We use Splunk Cloud Platform to monitor our environment.
How has it helped my organization?
Monitoring multiple cloud environments is made easy with the Splunk Cloud Platform due to its fast ingestion and data recovery times.
Splunk's visibility into multiple environments is excellent. I have found that a hybrid environment works the best, as the login portion remains on-premises while the rest is in the cloud. This reduces the maintenance required on-premises.
There are two types of integration. The first involves bringing something into Splunk, while the second entails moving something out of Splunk. Bringing data into Splunk is relatively straightforward, with multiple options such as RAS, SysLog, and Splunk's built-in functions. However, exporting data from Splunk is more challenging and not as straightforward as the process of bringing data into Splunk.
Splunk Cloud Platform has influenced our decision-making processes. Splunk is primarily employed for security purposes; thus, it excels particularly in SIM. It encompasses an asset and identity framework that effectively gathers information about an organization's assets and individual identities, encompassing all users. Therefore, when considering Unified Business and SIM, Splunk proves to be highly proficient.
What is most valuable?
The cloud performance is good.
Not having to perform any maintenance because it is handled by Splunk saves our administrators time which is valuable.
What needs improvement?
Splunk should offer various options for real-time monitoring. If we could enhance the speed of data ingestion or data retrieval, that would be an added advantage. Additionally, there is room for improvement in SaaS-to-SaaS integration. I believe that reintroducing HTML dashboards would be beneficial, as they provide dedicated web features. This, in turn, gives users the flexibility and freedom to create custom dashboards more easily.
For how long have I used the solution?
I have been using Splunk Cloud Platform for five years.
What do I think about the stability of the solution?
I would rate the stability of the Splunk Cloud Platform as an eight out of ten. We still encounter some lagging and errors, but not as much as with the on-premises deployment.
How are customer service and support?
I occasionally get in touch with Splunk technical support, usually regarding data onboarding. These include routine activities like installing or uninstalling applications, as well as making changes to existing ones. On average, we submit at least one ticket per week to them.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
I have used many tools including Elastic, Grafana, Tableau, and Sumo Logic.
Splunk is indeed superior in many cases, but other tools are also making progress to catch up, with Elastic being one of them. They have begun developing their own SIM offering, complete with its own SIM features. Similar to Splunk Cloud, Elastic also has its Elastic Cloud Stack. Some of the features provided by Elastic seem to outperform Splunk. Therefore, there is room for Splunk to enhance these aspects. As for pricing, it could be more competitive, considering that other tools also provide the freedom to choose the Cloud Stack. Although Splunk offers this flexibility, the process often involves extensive discussions, making it less adaptable compared to other tools.
How was the initial setup?
The initial setup is somewhat complex regarding the CI/CD pipeline, and Splunk manages the deployment. Splunk provides a feature called ACS, which enables us to manage the deployment ourselves if desired, but it's simpler to have Splunk handle the deployment on our behalf.
The deployment took around one month and required ten people from Splunk's DevOps team.
What about the implementation team?
The implementation was completed by Splunk.
What's my experience with pricing, setup cost, and licensing?
The pricing is high for small organizations. The cost makes more sense for organizations that have a large amount of data ranges.
What other advice do I have?
I would rate Splunk Cloud Platform an eight out of ten.
There are numerous tools that offer real-time reporting and alerting capabilities. Splunk is indeed effective, but due to the prerequisite of registering logs beforehand, a delay is inevitably introduced. Therefore, while Splunk is suitable for real-time reporting alerts, it may not be as optimal as some alternative solutions.
Resilience has added value and contributed to the improvement of our organization. This is highly significant. In most cases, the SOC team relies on the tool for issue mitigation and ticket resolution. Therefore, it is crucial for Splunk to remain consistently up-to-date and respond as quickly as possible. This holds immense importance.
The extensibility is good, but there is room for improvement, especially in integrating certain logs. Enhancing the process of incorporating raised logs is possible. In most cases now there are limitations on log creation. Previously, a direct option existed to import logs. However, this process has been altered, requiring users to develop an add-on for log integration, leading to increased complexity. Furthermore, users are expected to have knowledge of Python. This can be problematic in cases where users lack such expertise. Therefore, this aspect could certainly be enhanced.
For those who want to evaluate Splunk, it comes down to the volume of data. If they are dealing with a substantial amount of data flowing into their SIM, Splunk would be the superior option. Splunk effectively manages extensive datasets in comparison to other technologies. It also offers numerous additional functionalities, such as an enterprise security suite, assets, and identity framework. Moreover, it has undergone industry testing and has been employed in the field for a considerable duration. In contrast to other organizations, they provide a wealth of features.
Which deployment model are you using for this solution?
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Does not require backend maintenance, is easily integrated and utilized
What is our primary use case?
We utilize the Splunk Cloud Platform for log ingestion related to security and troubleshooting purposes.
How has it helped my organization?
Splunk Cloud Platform helps us with our security incident response. The cloud security logs are integrated with all the cloud providers.
The federated search feature enables us to search between Europe and the US, from one Splunk instance to another, all from a single location. This federated search simplifies how we handle data, making it easy to swiftly search for and manage information.
We monitor several cloud environments and find it easy to utilize the Splunk Cloud Platform for this purpose. Each cloud provider offers its own prebuilt dashboard, or customers can create their own.
The Splunk Cloud Platform offers excellent visibility into multiple environments. In the past, we utilized hybrid integrations, and they seamlessly worked right out of the box.
The reporting functionality provided by the Splunk Cloud Platform resembles that of the on-premise platform. It is readily available without requiring integration or the installation of reporting visualizations.
From a security standpoint, the Splunk Cloud Platform provides us with comprehensive visibility into all security logs. This enables us to implement security incident responses with great efficiency. Additionally, we have discovered that internal employees, such as product teams, are utilizing the platform as intended for various other use cases. For instance, it has proven valuable in troubleshooting performance issues and monitoring within Kubernetes. As such, we are leveraging a wide array of use cases within the company.
Splunk is a highly mature software that has been in the market for many years, which greatly influenced our decision-making process. Another factor was the user-friendly nature of the latest version, making it easy to initiate. We don't require a large workforce for installing components; it's as simple as out-of-the-box. Consequently, minimal time investment is needed for training.
The Splunk Cloud Platform assists us in accessing data to meet critical compliance and privacy regulations. For instance, this is particularly important for regulations such as GDPR and HIPAA. We are utilizing Splunk Cloud with a specific focus on HIPAA compliance, allocating extra attention to this aspect. In the case of GDPR, Splunk offers a range of built-in capabilities. For instance, it allows for log masking. Moreover, there are novel features available in Splunk Cloud, such as ingest actions. This feature is exceptionally useful as it enables us to mask the data before it's ingested into Splunk. Consequently, this approach ensures our adherence to compliance regulations, exemplified by GDPR.
The Splunk Cloud Platform has had a significant impact on our organization's security posture. It serves as our primary visibility tool and is the main source of trust for all login activities. Without Splunk, we would lose essential visibility and access to security updates. Currently, Splunk stands as one of the primary tools we utilize due to its utmost importance.
What is most valuable?
The most valuable feature is we don't have to deal with any back-end server maintenance because the solution is cloud-based.
What needs improvement?
The on-premises version of Splunk includes all the integrations, while the Cloud platform lacks certain integrations and is limited in terms of the number of supported apps.
The Splunk Cloud Platform is not a very mature solution; it has only been on the market for four or five years. While they have made significant improvements, there are still limitations, such as the absence of CLI access. Therefore, there are several limitations that still exist with the CLI.
The standard support has room for improvement.
For how long have I used the solution?
I have been using Splunk Cloud Platform for four years.
What do I think about the stability of the solution?
The Splunk Cloud Platform offers 99.9 percent availability, ensuring that we never experience downtime.
What do I think about the scalability of the solution?
I would give Splunk Cloud Platforms' scalability an eight out of ten.
How are customer service and support?
Technical support needs more knowledgeable people.
How would you rate customer service and support?
Neutral
Which solution did I use previously and why did I switch?
We used Sumo Logic in the past, but it wasn't an enterprise-grade solution, so it couldn't support the scale we required. Additionally, Sumo Logic lacked support for many integrations. The Splunk Cloud Platform fulfills our scaling requirements and integration needs. Moreover, our team possesses skills that align well with Splunk, making it a better fit for us.
How was the initial setup?
The Initial deployment was very straightforward because we had the skills. But I would not say that this is straightforward without the skills. We need to learn at least the basics.
The deployment took six months to create this multi-tenant environment because it's a highly specialized setting. It's distinct from a typical Splunk deployment that might only take a day or two. However, the process of configuring, migrating all the data from Sumo Logic to the new Splunk Cloud, and setting up the multi-tenant system along with product dashboards, required approximately six months of effort on our part.
What was our ROI?
We utilize Splunk in a multi-tenant manner, wherein we allocate costs back to the product teams in each department based on their usage. We are a healthcare company engaged in the development of healthcare applications tailored for doctors and hospitals. Splunk plays a pivotal role in assisting us with this endeavor. I would estimate that we have experienced a return on investment of approximately 30 to 40 percent.
What's my experience with pricing, setup cost, and licensing?
The cost of the Splunk Cloud Platform is high, and in addition to the standard licensing fee, we also have a premium support fee.
Now, we are paying less because, instead of being charged based on ingestion, we are paying for SVCs, which stands for Splunk Virtual Compute. This implies that our costs have decreased. Despite ingesting a larger volume of logs, our expenses are lower than they were before. However, it's important to note that if our usage of the tool increases, our expenses will also increase. Therefore, this represents a distinct licensing model from Splunk's.
What other advice do I have?
I would give Splunk Cloud Platform an eight out of ten. Splunk Cloud has shown significant improvement over the past four years, and I highly recommend it.
We operate two distinct Splunk Cloud platforms: one in Europe and another in the US. These platforms are linked through a federated search. This setup ensures that specific data, such as European data stored in the AWS cloud, is directed to the European Splunk platform, while data from the US Cloud is directed to the US Splunk platform. However, it's worth noting that all users primarily log into the Splunk US Cloud. From this point, they have the capability to transmit data to the Splunk Europe platform.
We have around 400 users.
The maintenance is primarily conducted by Splunk on the backend, and any on-premises maintenance we perform has been reduced by 80 percent.
The value that Resilience provides for SIEM solutions is significant for us. Therefore, if we inquire with various customers, they might provide different perspectives. However, concerning security, this holds substantial value. I would assert that it's the primary tool in our arsenal; indeed, we do possess other security tools, but the most frequently utilized one, which also delivers the utmost value, is undoubtedly Splunk.
The method to expand a SIEM system is achieved by extending the licenses. This expansion enables greater capabilities, increased log retention, and the ability to process more logs. In our specific scenario, we were previously restricted by the capacity of the ingest license. Our log ingestion was limited to, for instance, one terabyte per day. However, with the introduction of this new licensing model that's based on CPU usage, we now have the flexibility to ingest any amount of data while paying according to our actual tool usage. Consequently, if we intend to expand for additional servers, we simply need to contact Splunk and communicate our requirement for increased server capacity to enhance system performance. This process is streamlined because we aren't required to take any additional actions ourselves.
I would highly recommend Splunk Cloud because we don't require personnel for maintenance or server installation and management, as all these backend tasks are taken care of. Additionally, for those who are currently using a competitor of Splunk for SIEM purposes, I would also recommend transitioning to Splunk if they have the budget for it.
Which deployment model are you using for this solution?
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
One of the Great Tool
Make staff's jobs better for resiliency purposes, reporting, and whatever they need to do
What is our primary use case?
We're looking to migrate an acquisition into the Splunk environment. We acquired a company and their Splunk environment was small and separate. We didn't want to have to maintain old Windows environments in unique use cases so we wanted to migrate it to the cloud as a proof of concept.
In their case, they had global data domicile requirements. We didn't have the same global deployment for our other larger environment that they did. So it made sense for us to migrate them to a bunch of small cloud stacks that were globally positioned rather than deploy a bunch of tiny enterprise environments to do the same thing.
The solutions are segregated at the moment. We're currently migrating the ACS environment. We have our own Splunk Enterprise implementation that we still use for Azure currently. It's fine, it doesn't drop.
How has it helped my organization?
It has definitely improved our organization by virtue of reducing the amount of overhead we would have had for those environments. Having to implement, maintain, or even update the existing stuff would have been extremely time-consuming. Splunk Cloud handles all of that for us. So it's definitely been helpful from that perspective. It's allowed them to maintain upgrades for far further than they are. Some of the hosts of that environment were still on version 7 so they could get upgraded feature parity.
They do well at empowering staff by providing business resilience. Users have the capability to utilize Splunk in ways to make their jobs better for resiliency purposes, reporting, and whatever it is that they need to do. Splunk is a very powerful platform in that way.
What is most valuable?
In their case, they had global data domicile requirements. We didn't have the same global deployment for our other larger environment that they did. So it made sense for us to migrate them to a bunch of small cloud stacks that were globally positioned rather than deploy a bunch of tiny enterprise environments to do the same thing.
It's pretty important to us that Splunk has end-to-end visibility to our native cloud environment. We need to be able to figure out where the points of failure are. Knowing whether it's a forward, on our end, an index, the cloud environment, a firewall, or something else entirely is important to troubleshooting that kind of process.
Splunk has helped to reduce our mean time to resolve. For the specific use case, the ability to bring in more Splunk data and market makes work consistently accessible.
I think that Splunk's ability to predict, identify and solve problems in real time is better than what we use it for. Our observability journey is still pretty early so we haven't done a lot of predictive detection that is possible to do with Splunk. It looks like it can do the things that we needed to do in a pretty effective way. We just haven't done that yet.
What needs improvement?
Some of the implementation is challenging. They're not very proxy-aware. Their recommendation is to set up an intermediate forward in a DMZ environment or something like that. That's not always the most convenient way to do things. It would be better if we could use an HTTP proxy, send data out via HEC, HTTP, or in a way that is proxy-aware.
For how long have I used the solution?
We did the POC six months to a year ago. We've been in the process of migrating some smaller use cases over the last three or four months.
What do I think about the stability of the solution?
We haven't used it a lot but it's been pretty stable.
How are customer service and support?
Splunk support is pretty good. There's some work to be done. When I provide them with a bunch of data, they don't need to ask me some of the initial questions. But otherwise, they're pretty good.
How would you rate customer service and support?
Positive
What was our ROI?
I have seen ROI. The adoption of the company has increased dramatically. We have hundreds of alerts, hundreds of reports, and hundreds of dashboards that people use for their business cases, whether it's deliverables, resiliency, or troubleshooting.
What's my experience with pricing, setup cost, and licensing?
Splunk is expensive. We have had some challenges in ensuring that all data is available in Splunk due to its cost. It has definitely proven its value in the data that we have brought in. From a resiliency and reporting perspective, those things are all very valuable. But it's certainly not the most cost-effective product in the world.
It is a valuable product, but it is certainly challenging at times to be able to bring in as much data as I would want due to the cost of the product.
What other advice do I have?
I would rate Splunk Cloud Platform an eight out of ten.
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Has end-to-end visibility in our native environments
What is our primary use case?
We're migrating our on-prem environment to Splunk Cloud Platform. We're consolidating two separate Spark clusters because of a merger. Our primary use case is for unifying all of that data into one place.
How has it helped my organization?
It's made searching for data easier. Users like it. We're still in the migration process, but overall, it's a lot easier to use.
What is most valuable?
It's important to use that Splunk has end-to-end visibility in our native environments. We have to have that visibility because we manage multiple app applications that rely on it.
Splunk helped to improve our organization's business resilience. That's very important to us. Our users rely on Splunk heavily for the health of their applications. It helps them to get ahead of issues, and if there is an outage, it enables them to resolve them faster.
Splunk gives the different application owners the ability to configure alerting specific to their needs so they can customize it however they want. If they know their applications better than you know, admins, I'll give them that flexibility.
What needs improvement?
The administration could use improvement. We have to rely on support more often than we're used to.
For how long have I used the solution?
We have been using Splunk Cloud Platform for nine months.
What do I think about the stability of the solution?
Stability has so far been good. We haven't had any issues.
How are customer service and support?
Their support is great, especially the agent that we have now. They're very responsive, willing to help out, and give suggestions.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
We previously used Splunk Enterprise. We switched to Cloud Platform because we wanted to consolidate a couple of instances to one place and we're moving our security team to the cloud.
How was the initial setup?
I wasn't involved in the setup directly but I was aware of what they were doing. The setup is a little complex. We had some issues we had to deal with. Bringing both environments together and getting the different environments to communicate with Splunk Cloud was complex. We have a lot of data. Getting a handle on that before we were able to start sending data to the cloud was complex.
What's my experience with pricing, setup cost, and licensing?
It's expensive. We're still trying to figure out Cloud licensing.
What other advice do I have?
It's not so easy to monitor multi-cloud environments using Splunk. We have some difficulties, but we have some things in place, but it's not easy.
I would rate Splunk Cloud Platform an eight out of ten. There's a lot we haven't tapped into yet, so the rating can go up.