What is our primary use case?
Splunk AppDynamics allows us to understand the mean time to resolution and decrease it by easily understanding the dependency of the full application flow map. For root cause analysis and other hidden aspects, we can see how code quality performs. SQL queries can be easily evaluated for quality, and when code quality is not good, we can identify slowness in specific classes and methods. We can see which parts of methods and SQL queries are facing slowness issues. After that, we can develop and change code, modify database queries, and easily see in the product environment without needing to debug facilities. We can see in real time whether code changes are affecting the system positively or negatively. There are many different advantages, and we can separate proactive and reactive sides.
When we collect different method parameters with the essentials of monitoring APM tools, we can easily combine business and operational development cycles in a single pane. For example, when development teams make process improvements to code to add new features to transactions, we can easily see how this feature affects customer experiences as performance metrics. If we can collect this kind of data, we can also easily combine business and operation metrics. For example, with a loan application from the customer side, such as a bank customer making a loan application over their mobile or internet banking application site, we can easily see how many successful transactions occur in real time from a business perspective, not just from the performance side. If we can collect these metrics, we can combine all performance and business metrics in a single pane, giving customer sites a very different and big picture view.
Splunk AppDynamics works for Java, .NET, .NET Core, Node.js, and PHP applications. We also work with some customers using SecureApp features, and customer feedback has been really valuable for us. From my customers' experience with this feature, the feedback is really positive. In the software development lifecycle, penetration testing or security testing before getting a project into live production environment is a very important process. You have to conduct penetration testing before going live with your project. However, this kind of penetration testing is a bit reactive and offline because you only perform this penetration testing from a synthetic point of view, for example weekly, monthly, or quarterly. With Splunk AppDynamics SecureApp solution, we can easily see our application's vulnerabilities, attacks, and exploits in real time. We can also see any vulnerability, even zero-day attacks, easily after they occur. This is a really cool and differentiating feature, though it is a very new feature in the APM market, almost two years old. Because of that, it is not well-known, but when we demonstrate it to customers in POC or demo sessions, most customers are impressed and want to try it in POC. After POC, some customers want to buy this feature while getting the APM solutions as well.
We can monitor what kind of vulnerabilities exist in the code and can easily show the business risk in the environment by making a business score, not relying on MITRE or CVE codes. The scoring also works from a business perspective. For example, if we have one vulnerability that may be medium severity, our internal scoring mechanism increases the business risk if the application touches databases or other inside applications. If the application is not communicating with other applications, databases, or other sources, the business risk may be lower than the other example because of the application's touching points. This is a really cool feature. We are not only reporting these vulnerabilities, but we are also blocking these attacks in real time. For example, when a Log4j2 vulnerability occurs on the system or any zero-day attacks happen, Splunk AppDynamics easily tags and understands this kind of attacks. If desired, it can easily block the application's attacks from the APM perspective. This is a really game-changer in my opinion.
What is most valuable?
I think one of the really strongest features of Splunk AppDynamics is the end-user experience monitoring. We have a really differentiated capability over our competitors. We can easily adapt our solution to the customer's application, internet banking solutions, or IoT devices all over the world. For example, when you get a new Volvo from any Volvo shop, that car has a built-in Splunk AppDynamics light agent to track their connected car applications. To give a specific example, Audi, Volvo, and four years ago BMW also use Splunk AppDynamics light agents to monitor IoT devices and connected car applications. Mercedes may have this kind of agreement as well. In summary, we can easily monitor mobile devices, including Android and iOS, browser-based applications, and also IoT devices. For example, in Turkey, I personally use IoT monitoring with my customers. We work with banks, and most customers monitor their ATM devices and POS devices via Splunk AppDynamics agents. I have personally implemented the IoT agent or Splunk AppDynamics agent into ATM devices and POS devices, as well as for some cinema companies' kiosk systems.
What needs improvement?
I can mention two different things. First, Splunk AppDynamics is mostly compared with the Dynatrace solution because they are a really good solution. They offer on-premises options as well. I know Datadog is another good solution, but it only works with SaaS solutions. New Relic and Grafana are also good solutions, but Splunk AppDynamics and Dynatrace are the only on-premises options in the marketplace. Because of that, I want to compare with Dynatrace. Dynatrace has a OneAgent mechanism, while Splunk AppDynamics has a smart agent mechanism. The idea is quite similar, but when you use the Dynatrace OneAgent solution, because you are giving administrator and root rights, it is a bit easier but unsafe. For Splunk AppDynamics, you do not need to give the agent administrator or root privilege, but because of that, its capabilities are a bit limited. I cannot directly say this is a negative thing because it depends on the perspective. For example, if you really stick to security mechanisms, security teams can say that Dynatrace is easy to install and monitor, but from the security perspective, it is terrible and awful because you are giving full administrator and root privileges to Dynatrace. Splunk AppDynamics could improve their installation process, which would be an incredible thing on Splunk AppDynamics' side.
Second, most products, even Dynatrace, Splunk AppDynamics, and Datadog, are always saying they are making AIOps, root cause analysis, and anomaly detection features, but even Splunk AppDynamics, these kinds of features are not working fine because of the nature of the metrics. Most of the customers are not supplying the hygiene of metrics. If you do not supply or make your environment's metrics hygienic, you cannot give the AIOps perspective to customers. The statement that these vendors can make root cause analysis automatically or have automatic detection features and capabilities cannot be truthfully said. To sum this up, this is not only a Splunk AppDynamics problem. From my personal perspective, this is all APM vendors' problem. The features that all these APM vendors need to improve are the AIOps features. These are really at the beginning of the AIOps era. Everyone is talking about AI, and it turns out to be a common hype in the technology market. We may see the real effect of this AIOps era maybe two or three years from today.
For how long have I used the solution?
It is almost at the beginning of the story. When I started with Splunk AppDynamics, there was no acquisition between Splunk and AppDynamics, and AppDynamics was also its own company. This has been 14 years.
What about the implementation team?
Implementation can be divided into two different parts. One part of the implementation process goes over the controller side, which can also be called the control plane side. One engineer is enough to install and prepare within two hours. However, the agent side is a bit more complicated because it depends on the customer's situation. If the customer has more than 100 or 1,000 different servers, mostly in production environments, we need to agree on when we deploy agents because we need to restart their applications. This creates some outages in their production environment. First, we need to agree on the timeline and project plan. It depends on the customer's decision. If we have a chance, at one time, we can also deploy more than 500 different agents at the same time, maybe within half a day, because we have really good playbooks and automation scripts working over Ansible, Chef, Puppet, or different automation tools that we can easily integrate. Implementation is easy, but the agent side depends on the customer's decision based on their project coverage or decision. It can take two days, or maybe two weeks or two months, depending on how big their environment is and how many licenses they get. For example, if they get more than 1,000 licenses for more than 1,000 hosts, it depends on their decision and project plan. It can take two months, one month, three weeks, or two weeks. It is a very variable thing.
What other advice do I have?
I am working for my own business. Previously, I was in my former company, but I quit and built my own company. We are operating in the same area, and nothing has changed significantly in my life.
Over the last 14 years, we have made maybe more than 500 different installations, maybe much more than that. I do not know exactly, but in the last four years, we have prepared our own scripts and playbooks. It is really very simple to build a Splunk AppDynamics platform over the on-premises data center. Even if the customer wants to use the high availability option, if they have a limited environment or limited hardware resources, we can easily build all these components in one server. Because of that, it can be very simple when working only with one server. However, most customers in Turkey, including fintech-based, banking, government, and some really huge enterprises, need to use the high availability options, which means using more than six different separate servers. With our playbook and the solution's flexibility, Splunk AppDynamics is very flexible for this kind of model, and it takes no more than two, three, or four hours.
I would rate this solution an 8 out of 10.
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner