Splunk Enterprise Reviews

4.6
Overall rating
Reviews

4.6
Overall rating
Reviews
Learn More

User Reviews Overview

About Splunk Enterprise

The Splunk Enterprise platform allows users to process and index most forms of data in their native format. It includes data indexing tools, which enable users to locate specific data across large data sets. The software is...

Learn more

Feature ratings

Value for Money
4.3
Features
4.5
Ease of Use
4.1
Customer Support
4.3

Browse Splunk Enterprise Reviews

221 of 221 reviews
Sort by:
Idaly
Idaly
  • Industry: Semiconductors
  • Company size: 10,000+ Employees
  • Used Daily for 2+ years
  • Review Source
Value for Money
4
Features
5
Ease of Use
4
Customer Support
5

5
Reviewed on 01/02/2023

Powerful SIEM system that meets our expectations.

We are using Splunk Enterprise for log correlation, the analytics are accurate and it catches errors right away which improves our internal capabilities, it is a special service that collects data from different data sources very accurately to catch future issues, the reports are detailed and understandable. It has features that streamline manual work, improve our security and our protection in our IT infrastructure.

Pros

I really like the platform, the data collection is ideal and the reports are detailed, it is the most appropriate SIEM service to monitor our IT infrastructure, it is an ideal software to take preventive measures, it is easy to customize the dashboards, the monitoring is constant and it gives us security in real time, the alerts are accurate and it helps us understand what is happening and fix it before it becomes serious.

Cons

It is a somewhat expensive service but with more powerful features than other free SIEM systems, and it is a bit complex to set up and use for inexperienced users, so a lot of help should be sought from experienced staff and support team at first.

shabbir
  • Industry: Information Technology & Services
  • Company size: 51–200 Employees
  • Used Daily for 1+ year
  • Review Source
Value for Money
5
Features
4
Ease of Use
4
Customer Support
4

5
Reviewed on 03/10/2021

Complete Security operations with Splunk

Splunk data visualization and its analytics handling chunks of data is exceptional.

Pros

Data visualization, Analytics skills with AI-powered and can handle data in TB/per day without any interruptions in services. Live dashboards, developing use-cases and their capabilities (correlation).

Cons

complex architecture and efficient skills are required, financial is also not feasible for small and medium customers. no inbuilt query builders for beginners to understand the platform.

Alternatives Considered

AlienVault OSSIM

Reasons for Choosing Splunk Enterprise

Its niche player was can handle only a few products data and not so feasible in terms of query building and customization in dashboards. Good for small businesses not for enterpraises.

Switched From

AlienVault OSSIM

Reasons for Switching to Splunk Enterprise

Not so feasible in handling data and its simple architecture cannot handle logs from all the data sources.
Verified Reviewer
  • Company size: 1,001–5,000 Employees
  • Used Weekly for 2+ years
  • Review Source
Value for Money
4
Features
4
Ease of Use
3
Customer Support
3

3
Reviewed on 16/11/2017

Great for aggregating systems information

Easily identifying trends between systems
Helps identifying problems

Pros

Makes it easy to identify trends within your environment. Once everything is aggregated it makes it easy for example, to see the knock on events of a network outage throughout the environment.

Cons

Web user interface is a bit clunky. Its very polished interface, but in many cases it's style over substance. When I'm debugging an issue I want to be able to drill down into the problem fast, and the shiny interface can be sluggish and slow you down.h

Top Splunk Enterprise Alternatives

Verified Reviewer
  • Industry: Banking
  • Company size: 10,000+ Employees
  • Used Daily for 6-12 months
  • Review Source
Value for Money
2
Features
4
Ease of Use
5
Customer Support
3

5
Reviewed on 11/11/2023

Splunk for Enterprise

A very helpful product that can improve your way to do business intelligence and forecasting.

Pros

Data visualization is very clear and easy to use.

Cons

The possible to share with many people data and dashboards.

Verified Reviewer
  • Industry: Financial Services
  • Company size: 10,000+ Employees
  • Used Daily for 2+ years
  • Review Source
Value for Money
5
Features
4
Ease of Use
5
Customer Support
5

5
Reviewed on 03/03/2020

Splunk is a great solution for SIEM and also for monitoring your infrastructure

We needed a way to monitor our internal environment and start to be more proactive with issues, so we started sending all of our logs to Splunk and we we able to get insights we did not know we needed. It is a great solution and they are constantly innovating.

Pros

Splunk makes it easy to search through various data including logs. In the past I have had to pour through logs in order to find the one lines among the 100 of thousands of lines. Splunk allows me to search through those logs in a matter of seconds vs the hours it used to take.

Cons

Most of enterprise setup is done through the command line. It would be nice to have cluster configuration (index creation) as part of the UI.

Alternatives Considered

Elastic Stack

Reasons for Switching to Splunk Enterprise

Spelunking was simple to setup and the customer service is great. It performed very well and proved to be a valuable assets to run in Production.
Verified Reviewer
  • Industry: Health, Wellness & Fitness
  • Company size: 1,001–5,000 Employees
  • Used Daily for 2+ years
  • Review Source
Value for Money
4
Features
5
Ease of Use
5
Customer Support
4

5
Reviewed on 27/05/2022

Splunk Enterprise, not just a SIEM

We have been using Splunk Enterprise, ES, ITSI, and other Splunk parts for 6+ years in production. This has helped us reduce staff in some cases, increase response time in most cases, and allow non-IT teams to get data and metrics in a fast efficient way.

Pros

The versatility is amazing. The same data in logs, such as IIS, can be used for Security, Application performance, and even error handling. This allows us to use one log to help multiple teams. This is just one example.

Cons

Start up takes someone who has had some training. While searching and output is easy, its the onboarding of custom apps that takes the know how.

Alternatives Considered

Sumo Logic

Reasons for Switching to Splunk Enterprise

Versatility with custom applications we create in house.
Verified Reviewer
  • Industry: Government Administration
  • Company size: 51–200 Employees
  • Used Daily for 2+ years
  • Review Source
Value for Money
5
Features
5
Ease of Use
4
Customer Support
4

5
Reviewed on 02/12/2021

Great Choice for an SIEM

Pros

Provides a single location for collecting and analyzing logs. Provides ease of use for non-technical users, but powerful features for security and IT. There is an add-on/app for anything you could imagine.

Cons

Some documentation is vague, and when certain things don't work, it can be difficult to find out a solution to the problem.

Alternatives Considered

Sumo Logic

Reasons for Switching to Splunk Enterprise

We needed a product that we could host ourselves.
Verified Reviewer
  • Industry: Retail
  • Company size: 10,000+ Employees
  • Used Daily for 6-12 months
  • Review Source
Value for Money
5
Features
5
Ease of Use
3
Customer Support
5

5
Reviewed on 16/10/2020

A tool which is one for all

Splunk has made me realize the ability to correlate different data from different realms altogether and generate valuable insights.

Pros

The ability to use this software for security operations, data analysis, creating dashboards, generating tickets and everything else

Cons

Splunk uses its own SPL, which is not very easy to learn. However, there are lots of documentation that Splunk provides to its customers. There is paid training available which is useful for beginners to learn.

Alternatives Considered

IBM Security QRadar

Reasons for Switching to Splunk Enterprise

Splunk has much more capabilities than IBM QRadar. The ability to automate things using Splunk is extraordinary which makes Splunk the market leader.
Jason
  • Industry: Financial Services
  • Company size: 1,001–5,000 Employees
  • Used Daily for 2+ years
  • Review Source
Value for Money
3
Features
4
Ease of Use
5
Customer Support
5

4
Reviewed on 20/09/2023

A valuable SIEM tool that aids Cyber defences

Overall a rather good experience based on the Customer Service we receive and the extent to which they make our use of the tool a good experience

Pros

The saying "you only get out what you put in" is rather apt when utilising Splunk as a SIEM tool - i.e. the more logs / data you can feed into the solution the better the results. Ingesting multiple log files from numerous systems / applications is essential when reviewing security incidents and ensures everything is in one place.

Cons

For all that is good with Splunk, the costs are rather high and could force Customers to other solutions unless they make themselves more competitive in the pricing market

Thomas
  • Industry: Information Services
  • Company size: 5,001–10,000 Employees
  • Used Daily for 2+ years
  • Review Source
Value for Money
N/A
Features
5
Ease of Use
3
Customer Support
N/A

4
Reviewed on 07/09/2023

Swiss Knife for everything about logs

Pros

The product has a ton of Features. Everything what you Need when working with logs is already implemented

Cons

Due to the rich set of capabilities regarding, searching, transforming and vizualzing data it‘s sometimes quite tricky to find all necessary query commands

Gabe
  • Industry: Information Technology & Services
  • Company size: 5,001–10,000 Employees
  • Used Daily for 1+ year
  • Review Source
Value for Money
3
Features
5
Ease of Use
4
Customer Support
5

5
Reviewed on 22/02/2018

A powerful log aggregation solution with immensely useful tools built-in for popular applicatio...

Pros

- Free to use for small 500MB or less daily ingress, quite nice for small use cases and learning
- No development work required to deploy and provide value.
- Deployment flexibility: client agents are available to use, or clientless configurations for multiple OS platforms. It's also very easy to deploy, not just flexible. its a very simple affair.
- Segmentation of logs: You can create separate instances of of logs to aggregate, based on organization needs. And those instances can have their own individual storage policies to optimize consumption of storage resources.
- Configuration design: Thoughtful and mature documentation and design of the application regarding enterprise-class scaling on network storage.
-POWERFUL tools: The user interface lends itself to learning more about your organization from the logs you collect, through metrics of trends of the logs being gathered. There are also specific modules/add-ons for popular applications to provide more value and event-based monitoring, all without having to develop in-house dashboards and intelligence of those logs.
- Customization: You can create your own queries of logs, and event-based alerts.
- Web-based GUI that clean is powerful
- Sales/Technical Reps are top notch in fielding questions and evaluating environment for deployment. They were extremely helpful in helping our organization develop procedures and scaling our environment for expansion with our existing infrastructure.

Cons

- Price: This product is not free for more than the minimal use. Pricing can be very expensive, relative to open source offerings. That is the trade-off you pay for not having in-house development of open source offerings. As this product is priced based on gigabytes of indexed logs, it is important to understand the scope of licensing necessary for your environment to determine if it is a good fit for your organization.
- Watch your saved queries and hardware resources: Users have the ability to create and save queries. Like in database queries, some are more efficient than others. Large inefficient queries can be very resource-intensive. If you notice slowness in day-to-day queries, or navigation in the UI, or resource use in contention, keep an eye on saved queries and user practices.

Verified Reviewer
  • Industry: Computer Software
  • Company size: 1,001–5,000 Employees
  • Used Daily for 2+ years
  • Review Source
Value for Money
3
Features
4
Ease of Use
3
Customer Support
3

4
Reviewed on 11/05/2021

Great, wholistic centralized monitoring solution

I've been using Splunk for over 8 years. I've seen it constantly improve and change a lot. I do enjoy it. Cloud is getting better and much better parity with on-prem

Pros

We use this as our SIEM. The ability to have the data ingest, visualization, alerting and correlation all in one product is very important to me from a security standpoint. We're cloud-first so having that ability with large cloud providers is important to me (AWS, Okta, GCP, etc)

Cons

The cost can be a little concerning and htere is a bit of a learning curve when you first get into Splunk. User groups, their forum and pro serv all help with that.

Alternatives Considered

Datadog and Elastic Stack

Reasons for Switching to Splunk Enterprise

Better product.
Verified Reviewer
  • Industry: Financial Services
  • Company size: 10,000+ Employees
  • Used Daily for 2+ years
  • Review Source
Value for Money
5
Features
4
Ease of Use
4
Customer Support
5

5
Reviewed on 13/10/2022

Best friend for debugging

Splunk basically makes debugging and monitoring easier and touch less. I can easily debug by starring the rolling logs from different instances in single screen.
I can monitor multiple components and multiple metrics, without running commands manually with custom plugins.

Pros

Splunk comes with lot of in-built templates for each and every feature like log visualisation, dashboarding, traces,etc This makes the developers life lot easier. I can't think of any other logging tool that is snappy as well as accurate.
I love the fact how easily I can plug it in my docker-compose to push container logs.

Cons

Even though, it offers numerous features for different needs, each feature has its own learning curve. For instance log visualisation needs querying skills, which may be in natural language but it takes bit of time to get familiar.

David
David
  • Industry: Entertainment
  • Used Daily for 2+ years
  • Review Source
Value for Money
4
Features
5
Ease of Use
5
Customer Support
4

5
Reviewed on 07/02/2018

Offers more than you think

We've used the software to detect layer 7 attacks, unearth issues we didn't realize were happening and gives us end to end insight into our stack.

Pros

The system is highly intuitive to use. It is faster than other solutions I've used on the market and has a huge library of 3rd party plugins to get more from the system. It is easy to create scheduled searches, dashboards, reports etc. but there are a number of additional plugins (at an extra cost) to help with security, single pane of glass and metric collection.

Cons

It offers challenges for a decentralized working model. Where Splunk is centrally managed, it is easy to ensure that best practices are maintained. Where the system is opened up for an entire department to utilize and on-board their logs, it becomes more difficult. However, with some creative thinking and good process, this issue can be overcome.

Frank
  • Industry: Computer Software
  • Company size: 5,001–10,000 Employees
  • Used Weekly for 2+ years
  • Review Source
Value for Money
N/A
Features
4
Ease of Use
3
Customer Support
N/A

5
Reviewed on 20/12/2020

Doing setup redundant servers without Splunk

Saved my a$$ many times. In a multi-server environment, if you don't have Splunk or something like it, it will be a nightmare to try and coordinate the various log files involved.

Pros

Several of our applications are distributed across multiple systems. It is the same software running on each server but doing the same job for different users. Each server would generate its own log files. When things went wrong, we used Splunk to be able to see what was going on on each server. Click a few buttons and you get two logs from two different servers listed together coordinated by time. But that leads you to discover that the issue came from a separate upstream or downstream server, then bring in those logs too . . . all coordinated by time. Don't get me wrong, the IT guys love these tools for their own enterprise reasons, but as a server stack developer, this was a resource I used OFTEN.

Cons

I never fully grokked their SQL like language. I could do basic things daily without issue. However, I often had to hit the documentation to do anything more than a simple "find this" query.

Alex
  • Industry: Telecommunications
  • Company size: 1,001–5,000 Employees
  • Used Daily for 2+ years
  • Review Source
Value for Money
N/A
Features
5
Ease of Use
5
Customer Support
5

5
Reviewed on 15/02/2022

Excellent product

Pros

It is an easy to use solution, the implementation is a bit more difficult.

Cons

So far, this is a good solution that I use every day.

Alternatives Considered

IBM Security QRadar
shashank
  • Industry: Information Technology & Services
  • Company size: 1,001–5,000 Employees
  • Used Weekly for 6-12 months
  • Review Source
Value for Money
5
Features
5
Ease of Use
5
Customer Support
5

5
Reviewed on 15/04/2019

Best Tool for Monitoring Purposes.

As a user of Splunk, we generally used to monitor the log provided by the server clusters belonging to a tool called API Connect. As the logs are stored in Splunk, we tally the transaction count from API Connect tool and filter the log search in Splunk with a particular search query. We can download the logs of particular time and date of API Connect servers in case of transaction count issues. We create a dashboard for all the individual API's transaction count in terms of total transaction count of all API's. In this way, it makes our work easier to find out which API has the highest transaction count. We even use Splunk to know the state of the machine. Reports generated by the Splunk helps us to find out the API with the highest response time. In this way, Splunk makes our work a lot easier as it is very fast and highly secure.

Pros

1) Accepts multiple data formats like CSV, JSON, XML
2) Does the hard work for us i.e converting machine data to a human-readable format.
3) Can create customized alerts to serve our business purpose.
4) Searching on the based on queries is pretty simple.
5) We can create dashboards to analyze and visualize our search results.
6) Can export the log content to our Personal computers.
7) Setting up plugins and integrating with any tool that needs monitoring is pretty easy.
8) Technical support for the Splunk is very quick as they have a dedicated staff for that.

Cons

I did not find any flaws with this software.

Verified Reviewer
  • Industry: Computer Software
  • Company size: 51–200 Employees
  • Used Daily for 1+ year
  • Review Source
Value for Money
4
Features
4
Ease of Use
4
Customer Support
4

5
Reviewed on 18/09/2022

Number 1 SIEM

I was very happy with splunk and I suggest it to everyone

Pros

I think Splunk is first and best software in the field, easy to use, does what it had promised,

Cons

pricing could be better, they could be more flexible, support is a bit slow

Verified Reviewer
  • Used Daily for 2+ years
  • Review Source
Value for Money
4
Features
5
Ease of Use
4
Customer Support
5

5
Reviewed on 14/02/2018

A tool that every sys admin needs to have

Pros

I'm not sure from where to start in this case.

We use splunk for many things but mostly to analyze the traffic on the network / firewalls. It provides us with a nice overview of what's going on. It makes it very easy to spot spikes on the network and it will provide you also with deep analyzes.

For us it's an indispensable tool, probably the best tool we have.

Cons

To search for something is not always easy, however there are a lot of forums online, so finding help is not that difficult.

Mark
Mark
  • Industry: Religious Institutions
  • Company size: 1,001–5,000 Employees
  • Used Weekly for 2+ years
  • Review Source
Value for Money
N/A
Features
5
Ease of Use
3
Customer Support
4

4
Reviewed on 08/11/2018

Excellent logging and troubleshooting tool

As a software quality assurance engineer, I love that I can setup a single dashboard where I can then view the same data from any lane I select from a dropdown. If I see a problem in the Test lane, I can quickly check all of the other lanes for the same issue by simply changing the dropdown value.

Pros

Splunk can give you extreme insights into how your systems and software are functioning. Not only is the search very flexible and powerful, the customizable dashboards give a status report at a glance into trends, problems and performance. You can also set up email alerts when errors occur limiting the need to have Splunk opened on your machine all the time.

Cons

Splunk has a learning curve. They have extensive documentation but it isn't intuitive and some features are buried pretty deep. We have an onsite expert who holds bimonthly meetings to answer questions in a group forum.

Biswajit
  • Industry: Information Technology & Services
  • Company size: 10,000+ Employees
  • Used Daily for 2+ years
  • Review Source
Value for Money
4
Features
4
Ease of Use
4
Customer Support
4

4
Reviewed on 18/01/2018

This is the tool every devops should have expertise on!

Made life easier for all SRE/DevOps oncall.

Pros

First of all you don't need to login to your servers. Just configure splunk forwarder on all of your server and have peace of mind. During outages you dont have to panic and just rely on Splunk and be sure that you will have your root cause visible in splunk.

Cons

Kernel huge page issues, Search head clustering, Index clusetering. These features are as good as costly too. For SHC and IC it does need all same config hosts.

Mahipal Singh
  • Industry: Information Technology & Services
  • Company size: 1,001–5,000 Employees
  • Used Daily for 1+ year
  • Review Source
Value for Money
5
Features
5
Ease of Use
5
Customer Support
5

5
Reviewed on 30/07/2022

Splunk Enterprise Reivew

My overall experience with splunk is too good. It helps our organization to set a real time monitoring system which keeps checking our server health and alert us if anything goes wrong. So, team can quickly resolve the issue and minimize the business impact.

Pros

Real Time monitoring is the best feature which we like most about this software. It helps to send the notification or alerts if they are something wrong is going on in the server. So, team member can quickly resolve the issue.

Cons

As of now, i don't have anything which i don't like about this software.

Joe
  • Industry: Information Technology & Services
  • Company size: 11–50 Employees
  • Used Daily for 1-5 months
  • Review Source
Value for Money
4
Features
5
Ease of Use
4
Customer Support
4

4
Reviewed on 07/04/2023

Splunk Enterprise software review

It is great at working with big data coming from different data sets and sources

Pros

I am able to quickly act on pending issues as and when they arise and data is well protected because of their authorization features

Cons

We had to purchase additional computers with higher specs than what we previously had to be able to use Splunk effectively

Verified Reviewer
  • Industry: Information Technology & Services
  • Company size: 1,001–5,000 Employees
  • Used Weekly for 2+ years
  • Review Source
Value for Money
N/A
Features
4
Ease of Use
4
Customer Support
N/A

5
Reviewed on 10/11/2022

Helpful tool for troubleshooting and analyzing data/logs

The overall experience has been good. Splunk definitely helped improve our troubleshooting capabilities.

Pros

Splunk is great for monitoring, logging, and analyzing the large volume of data on the servers. Our support teams use Splunk to collect data/logs from the servers and troubleshoot product related issues. We introduced Splunk few years ago in our organization and it helped improve our defect/issue analysis and problem solving abilities

Cons

While Splunk is not too complex, it also requires a certain level of skillset to decipher the information. It may take a while to figure things out if you are a new user, or someone with limited technical knowledge

Edward
  • Industry: Banking
  • Company size: 10,000+ Employees
  • Used Daily for 2+ years
  • Review Source
Value for Money
N/A
Features
5
Ease of Use
3
Customer Support
5

5
Reviewed on 14/01/2023

Splunk Enterprise Review

Good overall experience. It’s an expensive product and there is a learning curve, but it’s an amazing ing product once you are accustomed to using it

Pros

The ability to set up queries and get data back quickly is invaluable

Cons

Learning to structure queries is a bit of a challenge in the beginning

221 reviews