User Reviews Overview
About Splunk Enterprise
The Splunk Enterprise platform allows users to process and index most forms of data in their native format. It includes data indexing tools, which enable users to locate specific data across large data sets. The software is...
Learn moreAll Splunk Enterprise Reviews Apply filters
Browse Splunk Enterprise Reviews
All Splunk Enterprise Reviews Apply filters
- Industry: Pharmaceuticals
- Company size: 10,000+ Employees
- Used Daily for 2+ years
-
Review Source
Best SIEM in the market
My overall experience has been awsome so far. I would rate it 8.5/10.Splunk has been as effective soluntion when it comes to triaging and monitoring of day to alerts.
Pros
- Easy to triage and monitor alert (Very fast and gives effective results as compared to other produts)Arcsight,Devo etc- Customer Support is excellent- Threat Hunting can be done effectively with the help of Splunk(IOC based,Corellation based etc)- Log parising is very effective & intelligent.
Cons
- The only think i liked least about splunk is the cost involved/pricing model in case of high data volumes.
Alternatives Considered
ExabeamReasons for Choosing Splunk Enterprise
- Easy to use.- Alert corellation and mornitoring is more effective.- Log paring is very accurate and quick.Switched From
ArcSight- Industry: Internet
- Company size: 1,001–5,000 Employees
- Used Daily for 2+ years
-
Review Source
Big data is no problem for Splunk Enterprise
Splunk is a powerful and useful monitoring tool. Splunk's efficiency is enhanced by the ability to integrate third-party apps developed in-house. It's also interesting that we can incorporate a customs alert and dashboard. In most situations, it resolves the need to normalize data, allowing for the use of any and all data in business forecasting. It is analyzed for data that can be utilized to optimize spending plans and asset tracking.
Pros
Without worrying too much about data type or normalization, Splunk Enterprise can efficiently manage massive amounts of data from numerous sources. Data may be accessed in a flash, and there are a number of options for tailoring and integrating data analysis workflows to create bespoke dashboards or utilizing apps from our other product partners.
Cons
There isn't much I dislike about splunk, however if we have to be picky, it would be that it's more difficult to maintain as an administrator when splunk is installed on outdated architecture.
- Industry: Computer & Network Security
- Company size: 201–500 Employees
- Used Weekly for 1+ year
-
Review Source
Slunk comes with a hard to learn and proprietary Query Language
That monitoring tool is a really good support for our daily operations
Pros
It's a really good tool for monitoring and query logs
Cons
The proprietary Query language is difficult to use
Top Splunk Enterprise Alternatives
- Industry: Consumer Electronics
- Company size: 11–50 Employees
- Used Monthly for 1+ year
-
Review Source
I use Splunk Enterprise to analyze and visualize data for better decision-making.
Pros
Splunk Enterprise has powerful search capabilities and customizable dashboards.
Cons
The learning curve for setting up queries can be steep, and the pricing can be high for smaller teams.
- Industry: Education Management
- Company size: 11–50 Employees
- Used Daily for 1+ year
-
Review Source
Bettering Cybersecurity With Splunk Enterprise
Pros
It has amazing firewall protection features
It makes handling security monitoring and improving networks security easy
log monitoring is easy
Cons
No regrets as Splunk Enterprise meets needs.
- Industry: Computer Software
- Company size: 11–50 Employees
- Used Daily for 2+ years
-
Review Source
The most expensive tool, requiring highly-skilled employees, capable of limitless value
Splunk's SPL is a flexible, straight forward query-language with aspects of SQL, R, Python, and Bash. The fact that an analyst can learn to be an engineer through using the platform provides ease of growth. It is unmatched in its automation to make data actionable, while providing reporting and visualization capabilities.
Pros
Splunk is provides a single tool for log aggregation, log analysis, and visualizations. Threat hunting, applying threat intelligence, and incident response are easily repeatable; pushing organizations to proactive security processes.
Cons
Splunk is expensive, especially when an organizations is exploring and building new security or data use cases. It also requires a lot of engineering maintenance, making the quality of the data highly-dependent on the skill(s) of those supporting it. Many organizations do not maximize its benefit because it is poorly managed or supported by low-skilled employees.
Alternatives Considered
Elastic StackReasons for Switching to Splunk Enterprise
Splunk scales in all aspects except price. Organizations that are serious about security and SIEM tools will see the value in their investment almost immediately. The insights from the analytics and development capabilities are not available in other tools with this level of ease.- Industry: Semiconductors
- Company size: 10,000+ Employees
- Used Daily for 2+ years
-
Review Source
Best log monitoring tool
Pros
Powerful search language
Advanced visualisation
Flexibility to accept logs from any source
High availability
Ease of administration
Cons
The cost is too high compared to other log monitoring tools.
Alternatives Considered
DatadogReasons for Switching to Splunk Enterprise
Datadog is lacking features and is bot a specialised log monitoring tool- Industry: Information Technology & Services
- Company size: 11–50 Employees
- Used Daily for 1-5 months
-
Review Source
A better business companion when integrated with RPA
Overall, the experience was positive; even with a free trial license, it was much easier, and on the course and certification side, Splunk has a very good collection of videos and materials that help even a novice quickly setup the integration and indexing.
Pros
The most useful thing about Splunk is the ease of integration with application. With uipath on-premises it was very much helpful as the business users can monitor the actions of robots through spluink without entering into uipath orchestrator
Cons
Expression creation for indexing was bit hard as it is not user-friendly to business users if they wanted to create any new fields, also the forwarder was not able to directly connect with uipath cloud so that the logs has to be shifted to intermediate file before uploading into splunk, but that seems not an issue with splunk but more related to uipath cloud
Alternatives Considered
Microsoft Power BIReasons for Switching to Splunk Enterprise
Splunk was much cheaper than power bi and only little effort needed for implantation and the resources cost is also higher for power bi- Industry: Hospital & Health Care
- Company size: 10,000+ Employees
- Used Daily for 2+ years
-
Review Source
Splunk is a great data management tool
I use it daily to locate information on users and devices.
Pros
The ability to parse data and locate critical information is unparalleled
Cons
Search tools could be a little more user friendly.
- Industry: Financial Services
- Company size: 201–500 Employees
- Used Monthly for 1-5 months
-
Review Source
Splunk, a great tool for a security team's tool belt.
Pros
Splunk is a great tool for cyber security professionals wanting to build out their security infrastructure.
Cons
There are other options out there that doesn't require as much configuration.
- Industry: Telecommunications
- Company size: 51–200 Employees
- Used Daily for 1+ year
-
Review Source
Splunk an Enterprise Business intelligent user tool
Is a robust and intelligent management tool that enables everyone with user computer knowledge to navigate in real-time, consolidate vast data into a visualized report of dashboard features , reliable and web based, no major equipment required for setup, user need a smartphone or compute to access the platform through the web, you can navigate the system as long as you have computer knowledge without any training required(user friendly) .
Pros
It an intelligent business tool that provided me an opportunity to customize and build report from large volume of data from different departments within the 13 Africa countries in telecommunication sectors. The platform allows data to be consolidated accordingly to the organization need and produces visualized reports of dashboard features. I also noted that the system can analyst unstructured large volume of data speedily and is reliable and web based allowing for user flexible accessible from any part of the world if you have internet. The systems have been reliable and secured from the time (2 years) I started using it without any system intermittent, system errors and cyber-attack.
Cons
The system is built and use-able with structured and unstructured organization though the price in foreign currency could hamper small and medium organization to use it especially in most Africa country where the local currency has depreciated against the major trading foreign currency.so the Forex pricing is a challenge.
The navigation of the platform will require minor training though if the user is computer proficient, they would management with minor challenge and interpretation of the data. So, first time user it can be difficult to use it
It will depend on internet for access and internet tend to be pricey in most African country and therefore could increase the business cost for small and medium enterprise. It can increase business cost if not fully used
- Industry: Telecommunications
- Company size: 10,000+ Employees
- Used Daily for 6-12 months
-
Review Source
Best tool for Distributed logs data analysis
We have several micro-services deployed in production which require to lookup application access as well as server logs and analyze data for their usage. We created several reports/charts for visualization. We use splunk as security logs tool to see the firewall traffic, tracing any vulnerable access, any database related crash ..etc.
It helps easily to find issue and fixed quickly by black listed in system.
Pros
Splunk Enterprise is best tool to analyze the data based on different visualization. It help us to lookup distributed logs for micro-services . It enables field based lookup. For complex logging, we can use search query using expression. We can create multiple reports/charts for visualization such as a pie or bar chart for our data. Best feature what i like , We can visualize our search results and share them with others using dashboard panels. If Already have a dashboard, we can add a new panel from a report, clone from another dashboard, or add a prebuilt panel. Fully customization available. Interfaces is very flexible. We export it in different formats, or refresh it to visualize the newest data. Online Support is available through different community.
Cons
Search query builder is fully based on technical. for Non technical users, its really difficult to lookup logs. Sometimes, error thrown by query builder is more difficult to understand. Deep Learning is required to use splunk for production data. For Large application installation, it need to manage more.
- Industry: Education Management
- Company size: 201–500 Employees
- Used Daily for 1+ year
-
Review Source
Splunk Enterprise is a powerful data analytics software
I believe getting important data analysis in real-time saves us from threats
Pros
Splunk Enterprise offers real-time data analysis tools makes it possible for my institution to see and take immediate action against security risks, performance difficulties, and other operational concerns.
Cons
Splunk Enterprise is really expensive and it is a huge part in our annual budget because we require add-ons.
- Industry: Computer Software
- Company size: 10,000+ Employees
- Used Daily for 2+ years
-
Review Source
Great platform for data analysis and visualization
Splunk Enterprise is a great data analysis and visualization platform to show real time status with live dashboards.
Pros
Security Information and Event management, log analytics, custom dashboards and workspaces
Cons
Auto upgrade management and notifications for Add-ons. Leaning more towards config file based implementation instead of UI based implementation
Alternatives Considered
New RelicReasons for Switching to Splunk Enterprise
Product Features and pricing- Industry: Information Technology & Services
- Company size: 11–50 Employees
- Used Daily for 1+ year
-
Review Source
Splunk the best analytic tool
It gives best Return on Investment as analyzing the data and giving proper insights in form of Dashboards and notifying with help of Alerts if any kind of threat running in infrastructure and apart from that Deployment and use is very easy.
Pros
There are lot of features which Splunk offers -
1) We can onboard data from any server, device or system using Universal Forwarder
2) Onboarded data are later stored in Indexers and searched further in Search Head for analyzing the internal logs
3) Using the data we can create customizable Dashboards and get proper insights of data and create Alerts to identify any kind of Threat or anomalies running in environment
4) Deployment is very easy on-prem servers
5) We can also use Hybrid Deployment on Cloud as well.
Cons
1) As it give large amount of features but licensing is too high
2) There are lot of other Open Source software which can be used as alternative of Splunk as Analytic tool because Splunk is paid one.
- Industry: Financial Services
- Company size: 201–500 Employees
- Used Daily for 2+ years
-
Review Source
Best SIEM
Great SIEM that beats the competition, we utilized it for various functions
Pros
Splunk appsStrength and capabilitiesIntegration with most solutions
Cons
Resource utilizationLimited local partner support
Reasons for Switching to Splunk Enterprise
Overall functionalities- Industry: Computer Software
- Company size: 10,000+ Employees
- Used Daily for 2+ years
-
Review Source
Splunk helps us to walk in the darkness, for sure in the Prod arena
We are in Autodesk, use it much, as part of the monitoring tool. We like it and would like it to be improved and even more useful
Pros
Dashboards feature is amazing, I use it much. Alerts and queries are easy to set up. Mostly it works fast so it's kind of Dev friendly so it's easy to onboard the new guys
Cons
Alerts should have a better way to manage it. There should be a way to promote alerts to different environments - so we will be able to set the Dev/Stg/Prod
Sometimes some things that we want to do take a while searching on the internet for a solution - they might think how to do it better - maybe some examples or better documentation
- Industry: Mining & Metals
- Company size: 5,001–10,000 Employees
- Used Daily for 2+ years
-
Review Source
Great for log analysis
Splunk has been key in sever major issue root causes by analyzing logs and from that being able to build reports and determine causes of issues. In addition being able to trend and look for the data in the many logs is very helpful.
Pros
We use this tool primarily as a repository for syslog messages for infrastructure. It allows us to quickly analyze the logs and patterns to determine issues based on patterns. In addition it alerts very well from text based trigger alerts. These features are very easy to use and dependable.
Cons
I do not have any cons for this software. Mainly as a user it does exactly what I need it to do with no overhead and confusing interfaces.
- Used Daily for 2+ years
-
Review Source
Great log analysis software
Pros
Integrates with almost all the software seamlessly..where there is a software application that produces log, splunk can be easily integrated.
Gives very powerful insights into the logs
Alerts can be setup on the logs, and notifications sent out which is great again for managing the health of your application
Cons
The query language, though powerful, has a learning curve. Particularly as one goes towards complex queries. If it could be made closer to natural language, it would be so much smoother to learn. Hope that will happen sometime in future.
- Used Daily for 2+ years
-
Review Source
A tool that every sys admin needs to have
Pros
I'm not sure from where to start in this case.
We use splunk for many things but mostly to analyze the traffic on the network / firewalls. It provides us with a nice overview of what's going on. It makes it very easy to spot spikes on the network and it will provide you also with deep analyzes.
For us it's an indispensable tool, probably the best tool we have.
Cons
To search for something is not always easy, however there are a lot of forums online, so finding help is not that difficult.
- Industry: Automotive
- Company size: 10,000+ Employees
- Used Daily for 1+ year
-
Review Source
Splunk is a lifesaver!
It’s been wonderful. I was able to take most of my forwarded lambdas and charts them to watch duration and throughput. Notifications and alerts let me know if things are out of whack. Such a relief to know Splunk is watching my back!
Pros
If you need real-time grokking into your infrastructure, look no further than Splunk. I love love love the dashboards. It’s easy to tell a story with your data, and the live search is so FAST!
Cons
SPL is a little hard to get used to, but once you get the hang of it, it’s not so bad. I recommend downloading their community edition for some great examples of queries and dashboards.
- Industry: Information Technology & Services
- Company size: 10,000+ Employees
- Used Daily for 2+ years
-
Review Source
This is the tool every devops should have expertise on!
Made life easier for all SRE/DevOps oncall.
Pros
First of all you don't need to login to your servers. Just configure splunk forwarder on all of your server and have peace of mind. During outages you dont have to panic and just rely on Splunk and be sure that you will have your root cause visible in splunk.
Cons
Kernel huge page issues, Search head clustering, Index clusetering. These features are as good as costly too. For SHC and IC it does need all same config hosts.
- Industry: Banking
- Company size: 201–500 Employees
- Used Daily for 2+ years
-
Review Source
Best SIEM out there.
Pros
I used a lot of SIEMs in my career,
Splunk is the best one out there.
Comfortable, Easy to use, Great big data platform.
Cons
Easy to use, versatile, A lot of options, dashboards
- Industry: Information Technology & Services
- Company size: Self Employed
- Used Daily for 2+ years
-
Review Source
Excellent product
I have worked with dozens of companies to implement Splunk. My experiences have bee overwhelming positive.
Pros
When you need to store, correlate, and search large amounts of data, especially System Log data, there is no tool that even comes close to Splunk. It's power and flexibility is amazing.
Cons
Very expensive. Difficult to implement until all moving parts are understood. Steep learning curve for beginners.
- Industry: Computer Software
- Company size: 201–500 Employees
- Used Weekly for 6-12 months
-
Review Source
Premium but pricey log management and analytics tool
Having a enterprise-ready centralized logging tool is critical for production success.
Pros
Splunk integrates with almost all popular enterprise software products including VMware, AWS, Azure, etc. Most customers use it primarily to do log analysis but it can also perform data analytics for business reporting. The UI is very straightforward and enables you to quickly search through large datasets using SPL. We were able to quickly locate the source of the issues by using Splunk to triangulate logs from several different components. There is a Splunk Cloud version with a free trial if you are aiming to do some integration work and testing. Finally, like all monitoring tools, Splunk offers AI and machine learning for even better predictive analytics.
Cons
Splunk is expensive and probably not for smaller startup companies. The pricing is tiered and is subscription-based so if you start to ingest a lot of data, look out. It can eat into most of your IT budget and Splunk by itself doesn't handle all the Day 2 operations that are needed.