User Reviews Overview
About Splunk Enterprise
The Splunk Enterprise platform allows users to process and index most forms of data in their native format. It includes data indexing tools, which enable users to locate specific data across large data sets. The software is...
Learn moreAll Splunk Enterprise Reviews Apply filters
Browse Splunk Enterprise Reviews
All Splunk Enterprise Reviews Apply filters
- Industry: Semiconductors
- Company size: 10,000+ Employees
- Used Daily for 2+ years
-
Review Source
Powerful SIEM system that meets our expectations.
We are using Splunk Enterprise for log correlation, the analytics are accurate and it catches errors right away which improves our internal capabilities, it is a special service that collects data from different data sources very accurately to catch future issues, the reports are detailed and understandable. It has features that streamline manual work, improve our security and our protection in our IT infrastructure.
Pros
I really like the platform, the data collection is ideal and the reports are detailed, it is the most appropriate SIEM service to monitor our IT infrastructure, it is an ideal software to take preventive measures, it is easy to customize the dashboards, the monitoring is constant and it gives us security in real time, the alerts are accurate and it helps us understand what is happening and fix it before it becomes serious.
Cons
It is a somewhat expensive service but with more powerful features than other free SIEM systems, and it is a bit complex to set up and use for inexperienced users, so a lot of help should be sought from experienced staff and support team at first.
- Industry: Computer Software
- Company size: 11–50 Employees
- Used Daily for 2+ years
-
Review Source
The most expensive tool, requiring highly-skilled employees, capable of limitless value
Splunk's SPL is a flexible, straight forward query-language with aspects of SQL, R, Python, and Bash. The fact that an analyst can learn to be an engineer through using the platform provides ease of growth. It is unmatched in its automation to make data actionable, while providing reporting and visualization capabilities.
Pros
Splunk is provides a single tool for log aggregation, log analysis, and visualizations. Threat hunting, applying threat intelligence, and incident response are easily repeatable; pushing organizations to proactive security processes.
Cons
Splunk is expensive, especially when an organizations is exploring and building new security or data use cases. It also requires a lot of engineering maintenance, making the quality of the data highly-dependent on the skill(s) of those supporting it. Many organizations do not maximize its benefit because it is poorly managed or supported by low-skilled employees.
Alternatives Considered
Elastic StackReasons for Switching to Splunk Enterprise
Splunk scales in all aspects except price. Organizations that are serious about security and SIEM tools will see the value in their investment almost immediately. The insights from the analytics and development capabilities are not available in other tools with this level of ease.- Used Daily for 2+ years
-
Review Source
Spunk Review
Pros
It allows me to bring a lot of information into one friendly view. It's a great security audit tool.
Cons
It has limited functionality. It is a very memory intensive system. It does not integrate with Lennox.
Top Splunk Enterprise Alternatives
- Industry: Marketing & Advertising
- Company size: 10,000+ Employees
- Used Daily for Free Trial
-
Review Source
Splunk, a must try for all data management persons
Pros
1. Excellent ML background
2. Dashboard looks classy
3. Multiple external entries possible unlike a lot other tools
Cons
1. Very limited variations in reporting
2. Real-time model is not great
3. Not mobile friendly
- Industry: Information Technology & Services
- Company size: 51–200 Employees
- Used Daily for 1+ year
-
Review Source
Complete Security operations with Splunk
Splunk data visualization and its analytics handling chunks of data is exceptional.
Pros
Data visualization, Analytics skills with AI-powered and can handle data in TB/per day without any interruptions in services. Live dashboards, developing use-cases and their capabilities (correlation).
Cons
complex architecture and efficient skills are required, financial is also not feasible for small and medium customers. no inbuilt query builders for beginners to understand the platform.
Alternatives Considered
AlienVault OSSIMReasons for Choosing Splunk Enterprise
Its niche player was can handle only a few products data and not so feasible in terms of query building and customization in dashboards. Good for small businesses not for enterpraises.Switched From
AlienVault OSSIMReasons for Switching to Splunk Enterprise
Not so feasible in handling data and its simple architecture cannot handle logs from all the data sources.- Industry: Furniture
- Company size: 51–200 Employees
- Used Weekly for 2+ years
-
Review Source
The only tool you need to manage production data
I'm very pleased with the data management capabilities Splunk Enterprise has given us. Before we implemented it, we were really struggling to make sense of some of the big data we get from our machines, but now, we can get very detailed insights into hw the machines are performing at any time. It's helped us monitor performance, issues, and opportunities much easier.
Pros
I love how detailed you can have the dasboards and charts go. It supports tons of chart types, and custom reporting elements. But above all, with the automaetd monitoring, you can have access to continuous insights from large data you wouldn't have been able to make sense of otherwise.
Cons
It's quite difficult to set up in the beginning. It took us a lot longer than expected to map our production data onto the system. But once you have it up and running, it works like clockwork
Reasons for Switching to Splunk Enterprise
We had a bit of prior experience with Splunk Enterprise which made everything much easier. It also seemed like the superior option for manufacturing on technical documentation.- Industry: Computer & Network Security
- Company size: 10,000+ Employees
- Used Daily for 2+ years
-
Review Source
Splunk - Onestop Log Management & Forensics
Overall i like the product but as the user base grows the logs grows too. This busts the limits of the licensing.
We need to keep on doing housekeeping to ensure that our license limits is not crossed.
Pros
The ablitity to configure and tweak the use cases. Building Intelligence into forensics. The AI feature is gud but needs more enhancements.
Cons
The log management needs to be efficient , If the auditing logs is enabled then a huge influx of logs are pumed into splunk but no meaningful meaning can be derived.
Reasons for Switching to Splunk Enterprise
Splunk is a one whole package with features like AI & Forensics and also keeps you updated with the latest and newest threats..- Industry: Government Administration
- Company size: 51–200 Employees
- Used Daily for 2+ years
-
Review Source
Great Choice for an SIEM
Pros
Provides a single location for collecting and analyzing logs. Provides ease of use for non-technical users, but powerful features for security and IT. There is an add-on/app for anything you could imagine.
Cons
Some documentation is vague, and when certain things don't work, it can be difficult to find out a solution to the problem.
Alternatives Considered
Sumo LogicReasons for Switching to Splunk Enterprise
We needed a product that we could host ourselves.- Industry: Retail
- Company size: 10,000+ Employees
- Used Daily for 6-12 months
-
Review Source
A tool which is one for all
Splunk has made me realize the ability to correlate different data from different realms altogether and generate valuable insights.
Pros
The ability to use this software for security operations, data analysis, creating dashboards, generating tickets and everything else
Cons
Splunk uses its own SPL, which is not very easy to learn. However, there are lots of documentation that Splunk provides to its customers. There is paid training available which is useful for beginners to learn.
Alternatives Considered
IBM Security QRadarReasons for Switching to Splunk Enterprise
Splunk has much more capabilities than IBM QRadar. The ability to automate things using Splunk is extraordinary which makes Splunk the market leader.- Industry: Information Technology & Services
- Company size: 201–500 Employees
- Used Daily for 1+ year
-
Review Source
Manipulate You Data
Splunk is widely used for manipulation of data and we encounter the use of this tool almostl twice a week. Even though it costs much more but still we have not found any alternative that is able to offer all these functionalities.
Pros
Splunk is very easy to use due to high community support and many video tutorials available online for new users to learn.
Functionalities are robust and simple to use. Data retrieval and visualisation is nice and easy if you know the right querying process.
Machine Learning supports enhances performance for the cloud, especially. It collect wide variety of data and still it amaze you the way it retrievs it.
Cons
There are many tools available in market which are potential competitors of this tool and that too at reasonable pricing. Splunk offers more functionalities but costs you too much if you look at the work it does.
Complex queries may require large CPU usage and may even freeze or atleast slow down the system for a while. Need to be specific while querying the data.
- Industry: Information Technology & Services
- Company size: 5,001–10,000 Employees
- Used Daily for 1+ year
-
Review Source
A powerful log aggregation solution with immensely useful tools built-in for popular applicatio...
Pros
- Free to use for small 500MB or less daily ingress, quite nice for small use cases and learning
- No development work required to deploy and provide value.
- Deployment flexibility: client agents are available to use, or clientless configurations for multiple OS platforms. It's also very easy to deploy, not just flexible. its a very simple affair.
- Segmentation of logs: You can create separate instances of of logs to aggregate, based on organization needs. And those instances can have their own individual storage policies to optimize consumption of storage resources.
- Configuration design: Thoughtful and mature documentation and design of the application regarding enterprise-class scaling on network storage.
-POWERFUL tools: The user interface lends itself to learning more about your organization from the logs you collect, through metrics of trends of the logs being gathered. There are also specific modules/add-ons for popular applications to provide more value and event-based monitoring, all without having to develop in-house dashboards and intelligence of those logs.
- Customization: You can create your own queries of logs, and event-based alerts.
- Web-based GUI that clean is powerful
- Sales/Technical Reps are top notch in fielding questions and evaluating environment for deployment. They were extremely helpful in helping our organization develop procedures and scaling our environment for expansion with our existing infrastructure.
Cons
- Price: This product is not free for more than the minimal use. Pricing can be very expensive, relative to open source offerings. That is the trade-off you pay for not having in-house development of open source offerings. As this product is priced based on gigabytes of indexed logs, it is important to understand the scope of licensing necessary for your environment to determine if it is a good fit for your organization.
- Watch your saved queries and hardware resources: Users have the ability to create and save queries. Like in database queries, some are more efficient than others. Large inefficient queries can be very resource-intensive. If you notice slowness in day-to-day queries, or navigation in the UI, or resource use in contention, keep an eye on saved queries and user practices.
- Industry: Computer Software
- Company size: 1,001–5,000 Employees
- Used Daily for 2+ years
-
Review Source
Great, wholistic centralized monitoring solution
I've been using Splunk for over 8 years. I've seen it constantly improve and change a lot. I do enjoy it. Cloud is getting better and much better parity with on-prem
Pros
We use this as our SIEM. The ability to have the data ingest, visualization, alerting and correlation all in one product is very important to me from a security standpoint. We're cloud-first so having that ability with large cloud providers is important to me (AWS, Okta, GCP, etc)
Cons
The cost can be a little concerning and htere is a bit of a learning curve when you first get into Splunk. User groups, their forum and pro serv all help with that.
Reasons for Switching to Splunk Enterprise
Better product.- Industry: Financial Services
- Company size: 10,000+ Employees
- Used Daily for 2+ years
-
Review Source
Best friend for debugging
Splunk basically makes debugging and monitoring easier and touch less. I can easily debug by starring the rolling logs from different instances in single screen.
I can monitor multiple components and multiple metrics, without running commands manually with custom plugins.
Pros
Splunk comes with lot of in-built templates for each and every feature like log visualisation, dashboarding, traces,etc This makes the developers life lot easier. I can't think of any other logging tool that is snappy as well as accurate.
I love the fact how easily I can plug it in my docker-compose to push container logs.
Cons
Even though, it offers numerous features for different needs, each feature has its own learning curve. For instance log visualisation needs querying skills, which may be in natural language but it takes bit of time to get familiar.
- Industry: Computer Software
- Company size: 10,000+ Employees
- Used Daily for 6-12 months
-
Review Source
Splunk: A Monitoring Tool for all your needs
If i have put a word it would say "Fantastic". The functionalities Splunk provides eases team to manage/monitor their IT infrastructure and internal application you will be well aware about the performance of your applications. Setup alerting and take necessary actions in stipulated time to overcome all the issues which may affect your application performance.
Pros
Splunk offers various features whether you need to setup monitoring on your server, application logs based on logs ingestion set alerts so that teams got notified on real time and take actions accordingly. In this way, it helps to monitor application which are mission critical. You can make dashboards in Splunk where you can configure various components such indexes, data inputs and schedule reports as well. To achieve additional functionalities we can install third party apps as well such as AWS Add on for cloud watch log ingestion.
Cons
From Admin perspective, I found user access management a little difficult. The roles of access management becomes complicated because some time the config files for that didn't came very handy. Other then that I think all in all Splunk provides fulfill all of the requirements.
- Industry: Information Technology & Services
- Company size: 501–1,000 Employees
- Used Daily for 1+ year
-
Review Source
Splunk review
Overall, it is a very good monitoring tool for an support team and developers for doing root cause analysis.
Pros
Splunk Visually represents the logs mainly from production servers in the web UI .
People who Usually has no access to logs in production servers, will access the logs through splunk UI with very simplified and friendly search query.
It has lot of features like you can query for particular date and time range with specific characters. The search engine is very fast which will bring the query response effectively.
we can access all types of logs including XML and JSON.
we can create a custom dashboard with custom query for each projects and can relatively trigger the email to the support team in case of any issues.
This tool is boon for production support team in any enterprise company.
Cons
Licensing cost is quite higher for enterprise usage.
Query response time will be slow when you are searching for relatively longer history(Eg. 3 months old data)
- Industry: Information Technology & Services
- Company size: 10,000+ Employees
- Used Daily for 2+ years
-
Review Source
Get useful insights into your logs with Splunk Enterprise.
We majorly use Splunk enterprise for IT security and log analysis. It is a powerful log analytics solution. We use it to collect data from several sources, analyze and transform it into meaningful metrics.
Pros
Its been a while since I started using Splunk Enterprise. I love its ability to cumulate data and logs from multiple sources and correlate them to help find incidents and their root cause. It consolidates logs and manages them form a central place. It is a great tool for log analysis as it segregates data and provides in depth profiling. Splunk enterprise also automates alerts and indexes on logs received.
Cons
It has a complex architecture making the learning curve quite steep
- Industry: Information Technology & Services
- Company size: 1,001–5,000 Employees
- Used Weekly for 6-12 months
-
Review Source
Best Tool for Monitoring Purposes.
As a user of Splunk, we generally used to monitor the log provided by the server clusters belonging to a tool called API Connect. As the logs are stored in Splunk, we tally the transaction count from API Connect tool and filter the log search in Splunk with a particular search query. We can download the logs of particular time and date of API Connect servers in case of transaction count issues. We create a dashboard for all the individual API's transaction count in terms of total transaction count of all API's. In this way, it makes our work easier to find out which API has the highest transaction count. We even use Splunk to know the state of the machine. Reports generated by the Splunk helps us to find out the API with the highest response time. In this way, Splunk makes our work a lot easier as it is very fast and highly secure.
Pros
1) Accepts multiple data formats like CSV, JSON, XML
2) Does the hard work for us i.e converting machine data to a human-readable format.
3) Can create customized alerts to serve our business purpose.
4) Searching on the based on queries is pretty simple.
5) We can create dashboards to analyze and visualize our search results.
6) Can export the log content to our Personal computers.
7) Setting up plugins and integrating with any tool that needs monitoring is pretty easy.
8) Technical support for the Splunk is very quick as they have a dedicated staff for that.
Cons
I did not find any flaws with this software.
- Industry: Management Consulting
-
Review Source
Finding Splunk Before Splunk Finds You
Pros
Splunk is more than a tool or a product, it is a big data platform. Splunk can be used as a simple log aggregator all the way to a Big Data engine to find efficiency in operations of the Internet of Things. Splunk is less about its abilities, and more about your imagination about what you can do with Splunk. That is the beauty of the platform. Splunk shines in providing operational intelligence about systems and processes. Finding out how your systems are operating, how your processes are functioning leads to quick resolution of problems and points to where budgets are best spent.
Cons
Splunk is deceptively easy to set up and use. But like learning to play chess, you can learn the moves in half an hour, but take a lifetime to master. Splunk quickly provides value, but requires imagination and creativity as well as wide ranging knowledge of systems and processes to move to the next level. Not every organization needs that kind of talent to get a great return from Splunk, but the companies who compete and win will.
- Industry: Consumer Services
- Company size: 201–500 Employees
- Used Daily for 2+ years
-
Review Source
Software is fantastic once you get it fed the data. Setup can be a bear.
Software saves a great deal of time tracking down errors and issues in the network. Was able to spot a security issue using the software we might never have even noticed otherwise.
Pros
Fast consolidation of disparate logs in an easy to search way for troubleshooting. I can find problems within my organization very quickly. Sales team was very responsive in getting me a trial license to estimate my needs.
Cons
Set up takes some time and planning. The Licensing scheme can be pretty expensive and until you've got it up and running it can be hard to estimate how much license you need.
- Industry: Computer Networking
- Company size: 51–200 Employees
- Used Daily for 2+ years
-
Review Source
Splunk vs Humio and Devo
The APIs and plugin are great. the parsers are just fantastic. It can log anything and everything.
Pros
We have been using splunk for over 5 years now. nothing beats splunk in the market place. The only concern we have the pricing and the resource to support it. it's just too expensive
Cons
Too expensive and it's too hard to manage. You have to find a very qualified and very expensive resource to support it.
- Industry: Oil & Energy
- Company size: 10,000+ Employees
- Used Daily for 1+ year
-
Review Source
Helps you predict IT problems
Splunk Enterprise's real-time monitoring keeps us ahead of potential problems. A must-have tool!
Pros
Splunk Enterprise is a great tool for security analytics, IT operations, and business intelligence. I especially like the way it can help me identify potential threats and improve our IT infrastructure.
Cons
The pricing for Splunk Enterprise may be out of reach for some small businesses.
- Industry: Telecommunications
- Company size: 2–10 Employees
- Used Weekly for 1+ year
-
Review Source
Powerhouse in data management and analysis
A complex but rewarding journey of data exploration and anomaly detection.
Pros
Powerful and versatile data mining tool with excellent integration capabilities.
Cons
Challenging initial setup and learning curve, particularly with query language and high cost.
- Industry: Information Technology & Services
- Company size: 1,001–5,000 Employees
- Used Daily for 1+ year
-
Review Source
Splunk Enterprise Reivew
My overall experience with splunk is too good. It helps our organization to set a real time monitoring system which keeps checking our server health and alert us if anything goes wrong. So, team can quickly resolve the issue and minimize the business impact.
Pros
Real Time monitoring is the best feature which we like most about this software. It helps to send the notification or alerts if they are something wrong is going on in the server. So, team member can quickly resolve the issue.
Cons
As of now, i don't have anything which i don't like about this software.
- Industry: Chemicals
- Company size: 201–500 Employees
- Used Weekly for 2+ years
-
Review Source
Very reliable and powerful resource
On business side we have a lot of logs, informations provided for a very different resources, the most beautiful thing about Splunk is to consolidate everything on just one place, and the ease to extract this information make Splunk the most powerful resource to gather and extract data from every resource that you have logs, even if you are using Windows or Linux, Splunk covers both.
Pros
Ease of use, you can extract any kind of information using commands provided by the software vendor. The other good thing about this software is the easy implentation on the servers, and the configuration is basic.
Cons
For people that are not used to use command lines, it might be a liitle bit difficult on the beggining.
- Industry: Computer Software
- Company size: 501–1,000 Employees
- Used Weekly for 2+ years
-
Review Source
Monitoring Tool Splunk
With Splunk anything identified with the application backend logs and observing, it's extremely suitable to utilize, in light of which we can make different dashboards. For server Monitoring, Splunk logs are not exceptionally accommodating. It totally depends on log explanations, assuming articulation isn't organized in standard organization, and it gives mistaken outcomes.
Pros
Splunk Light is ideal for independent on-premise organization.
Augment endpoint logging.
Can find and store logs from a wide range of resources.
Customization of dashboards.
Making applications dependent on your requirements.
Cons
Complex generally design.
Long execution time.
The instrument needs to incorporate AI to comprehend the framework logs and alarming ought to be founded on the auto learning.