We use the Splunk Enterprise Platform for logging and monitoring purposes. If users log into different databases and do something, we onboard database logs and other AWS logs to Splunk. Then, we create a dashboard alert report, and based on those dashboard alerts, we monitor users' actions. If they perform suspicious activities, we also send alerts. We use the solution to create dashboard alerts, reports, and some query language.
Splunk Software Developer at Tata Consultancy
Used for logging and monitoring purposes
Pros and Cons
- "The most valuable features of the solution are the load balancing technique, the forwarding technique, and SSL certification."
- "Sometimes, queries don't give proper results, and the indexes go down."
What is our primary use case?
What is most valuable?
The most valuable features of the solution are the load balancing technique, the forwarding technique, and SSL certification.
What needs improvement?
Sometimes, queries don't give proper results, and the indexes go down.
For how long have I used the solution?
I have been using Splunk Enterprise Platform for seven years.
Buyer's Guide
Splunk Enterprise Platform
April 2025

Learn what your peers think about Splunk Enterprise Platform. Get advice and tips from experienced pros sharing their opinions. Updated: April 2025.
851,604 professionals have used our research since 2012.
What do I think about the stability of the solution?
I rate the solution an eight out of ten for stability.
What do I think about the scalability of the solution?
I rate the solution’s scalability a nine out of ten.
How are customer service and support?
The solution’s technical support is good.
How was the initial setup?
The solution’s initial setup is easy.
What's my experience with pricing, setup cost, and licensing?
I have heard from my managers that Splunk Enterprise Platform is an expensive solution.
What other advice do I have?
The solution has helped us with our security information and event management. If someone performs deletion operations, we get an automated alert informing us that a privileged activity has been performed. We forward the logs in real-time. We are ingesting 10GB of data into the solution daily. We have some input filters in the solution's dashboard.
Overall, I rate the solution an eight out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.

Regional Director at iSecureMind
Real-time data analysis benefits but automation in role creation needs improvement
Pros and Cons
- "Splunk Enterprise Platform is a good tool to have, but it is expensive."
- "While Splunk Enterprise Platform is a good product, it is expensive. Additionally, it is complex for inexperienced cybersecurity engineers and requires experienced personnel to handle it effectively."
What is our primary use case?
We are working with AppDynamics, Splunk Enterprise Platform, and other Splunk products. However, the main use case here is with Splunk Enterprise Platform.
What is most valuable?
Splunk Enterprise Platform is a good tool to have, but it is expensive. The features that have proven most effective for real-time data analysis include parts of the platform and its automation capabilities. However, I want them to enhance their automation to cover every aspect, particularly the automation of roles creation.
What needs improvement?
While Splunk Enterprise Platform is a good product, it is expensive. Additionally, it is complex for inexperienced cybersecurity engineers and requires experienced personnel to handle it effectively.
For how long have I used the solution?
We have been providing Splunk Enterprise Platform for ten months.
How are customer service and support?
Splunk's technical support is at the same level for all products, although we have not opened many tickets.
How would you rate customer service and support?
Neutral
What's my experience with pricing, setup cost, and licensing?
Splunk Enterprise Platform is expensive.
Which other solutions did I evaluate?
The main competitor of Splunk in our region is Exabeam, which is less expensive. For small and medium companies, Fortinet is a competitor. Stellar Cyber has also recently entered the market.
What other advice do I have?
For smaller companies, I recommend Stellar Cyber as an alternative to Splunk Enterprise Platform. Stellar Cyber is easier to implement and integrate, and it has solid AI capabilities, especially for automation. It is also willing to adapt to customer requirements. I would rate Splunk Enterprise Platform overall somewhere between six and eight, depending on the size of the company.
Disclosure: My company has a business relationship with this vendor other than being a customer: Reseller
Last updated: Mar 25, 2025
Flag as inappropriateBuyer's Guide
Splunk Enterprise Platform
April 2025

Learn what your peers think about Splunk Enterprise Platform. Get advice and tips from experienced pros sharing their opinions. Updated: April 2025.
851,604 professionals have used our research since 2012.
Manager - Anti-Fraud Strategy & System Solution Officer at a financial services firm with 10,001+ employees
Seamless integration streamlines fraud detection
Pros and Cons
- "Splunk is very flexible in handling various formats of data as long as basic rules are adhered to."
- "The Splunk Processing Language (SPL) poses a steep learning curve for new users."
What is our primary use case?
The main use case is to analyze the data log coming from other systems. We use Splunk to identify anomalies in transaction patterns, which may indicate irregular activity from certain customers. Our goal is to create alerts for stakeholders when such anomalies are detected.
How has it helped my organization?
Splunk has made our job easier by streamlining data searching and decision-making processes. By using it for fraud detection, we have potentially saved billions of Indonesian rupiah.
What is most valuable?
Splunk is very flexible in handling various formats of data as long as basic rules are adhered to. Its integration with other systems is seamless and can be done overnight. This ease of integration is its best advantage. Additionally, Splunk is adequate for real-time data processing.
What needs improvement?
The Splunk Processing Language (SPL) poses a steep learning curve for new users. The software could benefit from additional processing power, such as GPU support, for handling large volumes of data faster. The language could also be more user-friendly, similar to platforms where actions are easier through button clicks.
For how long have I used the solution?
I have used the solution for approximately three years.
What do I think about the stability of the solution?
I rarely encounter bugs or glitches during daily use. However, there was one instance where an issue required solutions from the headquarter's next upgrade session.
What do I think about the scalability of the solution?
Splunk is scalable, provided the supporting infrastructure, such as CPU and GPU processing, is also scalable.
How are customer service and support?
I rarely communicate with the Splunk headquarters, usually interacting with the local implementer.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
We are not using anything else that functions like Splunk. However, for fraud detection, we also use GVD Instinct and FICO, along with Elasticsearch.
What about the implementation team?
I have not been involved in implementing it, except in integration, where I've found it easy.
What was our ROI?
We have been saving significant amounts through fraud detection. I cannot say precisely how much. Overall, Splunk has simplified our data management and decision-making processes.
What's my experience with pricing, setup cost, and licensing?
The official license operates like a subscription with an annual fee. Our local implementer offers pricing based on reserved quota, such as 80 gigabytes per day, costing under one billion Indonesian rupiah, or around $70,000 USD. It is affordable and flexible.
Which other solutions did I evaluate?
Elasticsearch, Kibana, Check Point, and other solutions like Microsoft Teams, OneDrive, and SharePoint are used.
What other advice do I have?
Keep my identity anonymous; publishing my title is sufficient. It's important to master the SPL for efficient use. Seek solutions that better support GPU for real-time processing.
I'd rate the solution eight out of ten.
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Other
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Last updated: Nov 17, 2024
Flag as inappropriateSecurity Consultant at IBM Thailand
The product is very easy to use, the GUI is simple, and the technical support is responsive
Pros and Cons
- "The product is very easy to use."
- "The product doesn’t have prebuilt dashboards."
What is our primary use case?
We use the solution mainly for security operations. We receive logs from different log sources.
What is most valuable?
The product is very easy to use. We just have to run the agent and collect the log. We don't have many delays or problems. We faced an issue once or twice when there was a network issue and when the system was rebooted. The percentage of issues is very low compared to the overall deployment. It is 0.001%.
The solution supports our organization's security and compliance monitoring very much. We rely on the platform to detect abnormalities and to perform searches. If someone brings a compliance issue, we request logs from the platform to determine whether it happened. We use the tool’s search feature and Intel's machine learning platform to conduct our analysis.
We don't face any issues in real-time monitoring. There is no latency. We have options to create our own dashboards. The GUI is very simple. It's a simple platform. It is very easy to use.
What needs improvement?
The product doesn’t have prebuilt dashboards. It would be great if the product provided prebuilt dashboards. For example, we allowed some devices into our network through VPN, but there is no dashboard to combine two log sources and understand which user has logged in. So, we created our own dashboard with the available Splunk searches.
It’d be good if the solution provided more prebuilt dashboards and released them on the app platform. Then, we can deploy the dashboards straight away. Also, if the tool provides additional dashboards, we can reduce the resources needed to develop them. Since Splunk has overall visibility all around the globe, it can give better suggestions on the dashboards that we must use and how to project the data to the management.
We faced some issues in parsing when the load was too much. If we have a 100 MB log source, 80 MB will be parsed correctly, but we face issues with 20 MB. We raised a support ticket, and the support team suggested we increase the time interval between sending the logs to the Splunk forwarder to handle the processing correctly.
For how long have I used the solution?
I have been using the solution for two years. I am using the latest version of the solution.
What do I think about the stability of the solution?
The tool is stable enough. In my demo environment, I used my own physical machines to run it. I was able to ingest as many log sources as I wanted within the data limit, and it did not have any issues. The search is very responsive when compared to the other platforms. There was no lag.
Splunk has been supporting free text searches for two years. We can query anything out of the box without specifying any indexes. We can perform free-text queries. Usually, it takes very little time to produce the results if the data set is too small. If the data set is too large, the product suggests we finetune our search, and it provides us with hints on which indexes to specify. It has three different options: Fast mode, Push mode, and Smart mode. We can switch the modes to get results quicker. Later, we can change the mode back to do a deeper analysis.
What do I think about the scalability of the solution?
Scalability is not an issue for SMBs and moderately big companies. When we went beyond certain limits, like 700 Gbps or 800 Gbps, we faced some issues with the engine. So, we split up the platform and diverted some of the logs into different indexes. It solved the problem. Up to 500 Gbps per day is okay. When we go beyond that, a single instance cannot handle it. We need to split it up.
This issue was only with the on-premise version. We do not face such issues in the cloud. When customers wanted to renew their subscriptions, we suggested they move to the cloud. On-premise, we have to manage our indexes and searches, but in the cloud, it's done by the vendor. It's a plug-and-play process. Splunk automatically takes care of parsing. We have more than 30 customers.
How are customer service and support?
The technical support is very good. The team supported us even during the Christmas holidays. The support engineer walked us through every step. The team is always reachable. We never had issues while contacting them.
How was the initial setup?
I built some demo environments for my practice since Splunk was new to me two years ago. I used the free license. It was a pretty straightforward setup. I did not find any difficulties in setting up my lab environment. The deployment can be done within 15 minutes.
What was our ROI?
The return on investment is very good. It's very easy to use. Many of our customers decided to continue using Splunk because they have invested much in the training modules, the analysts are familiar with the tool, and it's very easy to search. Open-text queries are the best in Splunk. It is easy for our customers to perform the search. It's very lightweight compared to other solutions.
What's my experience with pricing, setup cost, and licensing?
Our customers pay for the licenses. It’s bundled together in a yearly subscription.
What other advice do I have?
There are some problems in managing the tool when it exceeds certain limits. Overall, I rate the product a nine out of ten.
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
Delivers financial benefits and operational efficiency with impactful data analytics capabilities
Pros and Cons
- "Splunk Enterprise enhances data analytics with its AI capabilities."
What is our primary use case?
The use cases for Splunk Enterprise Platform vary depending on the specific scenario.
Splunk Enterprise Platform has different purposes, including data visualization and other applications.
Splunk Enterprise Platform has different purposes, including data visualization and other applications.
What is most valuable?
In Splunk Enterprise Platform, the most impactful features for data analytics allow you to get into the repository.
There are financial benefits from using Splunk Enterprise Platform, and as a retailer, it provides better profit margins.
Splunk Enterprise enhances data analytics with its AI capabilities.
There are financial benefits from using Splunk Enterprise Platform, and as a retailer, it provides better profit margins.
Splunk Enterprise enhances data analytics with its AI capabilities.
What needs improvement?
For future updates of Splunk Enterprise Platform, I would like to see integration by GUI.
The integration should be improved with the UI.
The integration should be improved with the UI.
For how long have I used the solution?
I have been using Splunk Enterprise Platform for about two years.
What was my experience with deployment of the solution?
There are no significant challenges in deploying Splunk Enterprise Platform.
The challenges or pain points others should anticipate before implementing Splunk Enterprise Platform are mostly related to the integration part.
The challenges or pain points others should anticipate before implementing Splunk Enterprise Platform are mostly related to the integration part.
How was the initial setup?
The time it takes to deploy Splunk Enterprise Platform depends on the use cases.
It may take anywhere from a couple of hours to a couple of weeks for Splunk Enterprise Platform deployment.
It may take anywhere from a couple of hours to a couple of weeks for Splunk Enterprise Platform deployment.
What about the implementation team?
The same three people take part in the deployment of Splunk Enterprise Platform.
I do not take part in the deployment; my team does.
I do not take part in the deployment; my team does.
What other advice do I have?
My advice for those looking to implement Splunk Enterprise Platform is to know the product well and have hands-on workshops or create a lab to gain complete knowledge before proceeding.
Regarding maintenance, it does not require much as it is on-premises.
Overall, I would rate Splunk Enterprise Platform an eight.
Regarding maintenance, it does not require much as it is on-premises.
Overall, I would rate Splunk Enterprise Platform an eight.
Which deployment model are you using for this solution?
On-premises
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Other
Disclosure: My company has a business relationship with this vendor other than being a customer: Reseller
Last updated: May 9, 2025
Flag as inappropriateLead Security Engineer at AeoLogic Technologies
Helps with monitoring and incident management
Pros and Cons
- "From a stability perspective, the tool is good."
- "he product's initial setup phase needs to be made easy since it looks like it is very complex compared to the other tools in the market."
What is our primary use case?
I use the solution in my company to capture the events to deal with threat detection, incident response, and compliance reporting. For IT operation management, it gets complex to track the health and performance of IT infrastructure, including our network devices and applications, so Splunk Enterprise Platform can be used for centralized log management.
What is most valuable?
The most valuable feature of the tool for DevOps and from a continuous delivery perspective is that the tool is useful in areas like deployment, monitoring, and incident management.
What needs improvement?
If I compare Splunk Enterprise Platform with the other tools, the dashboard and the user interface need to be built at a console level and in a user-friendly mode. Sometimes, the tool looks a bit complex, and we can't find out the exact area where we need to make the changes in the configuration and changes for the log events monitoring. The dashboard and the console-level areas need to be made friendly.
The product's initial setup phase needs to be made easy since it looks like it is very complex compared to the other tools in the market.
For how long have I used the solution?
I have been using Splunk Enterprise Platform for three years.
What do I think about the stability of the solution?
From a stability perspective, the tool is good. If any breakdowns exist, remediation and support are provided, so it is not a problem.
What do I think about the scalability of the solution?
The tool is used by around 5,000 employees and servers in my company.
How are customer service and support?
I have interacted with the solution's technical support. I rate the technical support a seven and a half out of ten.
How would you rate customer service and support?
Neutral
How was the initial setup?
The solution is deployed in an on-premises version.
What's my experience with pricing, setup cost, and licensing?
The tool is expensive.
What other advice do I have?
To first-time users, I can say that proper analysis and bandwidth utilization, cloud resource monitoring, and cost optimization are the things I would ask one to check in the tool.
It is not easy for beginners to use, and for freshers, it will take time to understand the tool.
From a security perspective, I rate the tool a nine out of ten. From a user and the console perspective, I rate the tool a seven out of ten.
In general, I rate the tool an eight out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Last updated: Aug 26, 2024
Flag as inappropriateTechnology and Digitization Lead at JLL
An easy-to-use and easy-to-configure solution that can be used to monitor network traffic
Pros and Cons
- "Splunk Enterprise Platform is an easy-to-use and easy-to-configure solution."
- "There should be continuous customer engagement and training programs on the new features and capabilities introduced by the solution."
What is our primary use case?
We monitor our airtight network traffic using the Splunk Enterprise Platform. We also use the solution for port monitoring, to monitor which ports are closed, which are open, and flapping if in any port. We use it to check our server performance to see if it gets choked because of high CPU or RAM utilization.
What is most valuable?
Splunk Enterprise Platform is an easy-to-use and easy-to-configure solution.
What needs improvement?
There should be continuous customer engagement and training programs on the new features and capabilities introduced by the solution.
For how long have I used the solution?
I have been using Splunk Enterprise Platform for four years.
What do I think about the stability of the solution?
I rate Splunk Enterprise Platform a nine out of ten for stability.
What do I think about the scalability of the solution?
Splunk Enterprise Platform is a scalable solution. Two people are using the solution in our organization to monitor data.
I rate Splunk Enterprise Platform ten out of ten for scalability.
How was the initial setup?
The solution’s initial setup is easy.
What about the implementation team?
One or two hours is enough to deploy the solution, but its configuration will take time, based on the users. Just one person is enough to deploy the solution.
What was our ROI?
We have seen a return on investment with Splunk Enterprise Platform for security and performance use cases.
What's my experience with pricing, setup cost, and licensing?
The solution’s pricing is moderate. We have to pay a yearly licensing fee for the solution, and there is an additional cost for support.
What other advice do I have?
Splunk Enterprise Platform is a good and easy-to-use solution. It has to be regularly upgraded to the changing network or customer needs.
Overall, I rate Splunk Enterprise Platform an eight out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
System Engineer at a consultancy with 10,001+ employees
Helps to filter and analyze log data
Pros and Cons
- "The most valuable feature I've found in the Splunk Enterprise Platform is its log readability and filtering capabilities. The filters on the left side are particularly useful, allowing me to quickly narrow down the data to what's relevant for any application or server service. The interesting fields feature helps me get the values I need most of the time."
- "Splunk Enterprise Platform could improve in the area of basic log readability. When performing basic searches without advanced filters, the logs often contain timestamps and various unknown codes or other elements that can be confusing. Removing or simplifying these parts would make it easier for users who are not developers or do not have a development background to understand and find relevant information easily."
What is our primary use case?
We use the solution to manage a large volume of data from our servers for the project I'm currently working on. Since we don't need all the data, we filter out and extract the specific information required for our applications. Depending on our needs, we use it to filter, investigate, and analyze log data for any errors or requirements.
What is most valuable?
The most valuable feature I've found in the Splunk Enterprise Platform is its log readability and filtering capabilities. The filters on the left side are particularly useful, allowing me to quickly narrow down the data to what's relevant for any application or server service. The interesting fields feature helps me get the values I need most of the time.
Additionally, the dashboard and report creation aspects are excellent, especially for automation. Integrating Splunk Enterprise Platform with Power Automate and other automation tools allows me to create precise reports that keep my team updated. The tool is not difficult for a beginner to learn.
What needs improvement?
Splunk Enterprise Platform could improve in the area of basic log readability. When performing basic searches without advanced filters, the logs often contain timestamps and various unknown codes or other elements that can be confusing. Removing or simplifying these parts would make it easier for users who are not developers or do not have a development background to understand and find relevant information easily.
If I could add a feature to the Splunk Enterprise Platform to make my life easier, I'd like to add an internal automation tool. We can use third-party automation tools like Power Automate, but it would be better if Splunk Enterprise Platform had its built-in tool.
This tool could automate reports and make sending emails with Excel attachments or other formats to specific people easier. We're currently using third-party tools for this, but having it as a first-party feature would be better.
For how long have I used the solution?
I have been using the product for more than two years.
What do I think about the stability of the solution?
I haven't found any bugs while working with the application.
What do I think about the scalability of the solution?
My company has more than 100 product users.
How are customer service and support?
I haven't contacted the support team yet. I get information from my seniors and leads.
What other advice do I have?
Before using the Splunk Enterprise Platform, basic knowledge of log analytics tools like Logstash is beneficial. While it does not require specific prerequisites, having some background knowledge will help. Remember that Splunk is a paid service, unlike other log analytics tools like ELK Stack, which may offer free versions.
I rate the overall solution a nine out of ten.
Which deployment model are you using for this solution?
Hybrid Cloud
Disclosure: I am a real user, and this review is based on my own experience and opinions.

Buyer's Guide
Download our free Splunk Enterprise Platform Report and get advice and tips from experienced pros
sharing their opinions.
Updated: April 2025
Popular Comparisons
Apache Superset
Buyer's Guide
Download our free Splunk Enterprise Platform Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- What's your experience or opinion about Spotfire vs. Tableau vs. Qlik?
- A journalist is writing a story about which Data Visualization software product to choose. Can you help him?
- What enterprise data analytics platform has the most powerful data visualization capabilities?
- When evaluating Data Visualization, what aspect do you think is the most important to look for?
- What are the best self-service and Excel-like filtering / display tools?
- What data visualization tool/s do you find to be the best?
- Why is Data Visualization important for companies?
- How many users on average are licensed users of Data Visualization software in a company?