No more typing reviews! Try our Samantha, our new voice AI agent.
Gokul Sekar - PeerSpot reviewer
Senior Software Engineer at Torry Harris Business Solutions
MSP
Top 20
May 11, 2024
Offers powerful features for data exploration and analysis

What is our primary use case?

We use Splunk for onboarding updates, dashboards, application monitoring, and insights.

How has it helped my organization?

We are using it for event management. We don't have that much exposure on the security side.

What is most valuable?

It is very easy to use logs and create dashboards. You can define extractions for specific exceptions. Splunk can extract historical data and process upcoming data in real-time. You can easily modify, update, or edit extraction rules as needed. Additionally, you can create custom knowledge objects at any time. The platform allows you to restrict user access based on permissions. Even regular users can create reports and dashboards for their workflows.

What needs improvement?

Splunk Enterprise Platform needs some improvement. For instance, the dashboard sizing and customization options could be enhanced. There seems to be a limitation in adjusting the size of individual panels within a dashboard. This can be frustrating when comparing data across different panels, as users are forced to scroll continuously. Additionally, while Splunk offers some new features like student dashboards, modifying these dashboards requires a level of JavaScript expertise that not all users possess. Providing more user-friendly options for customization, such as adjusting colors and fonts directly from the user interface, could greatly improve the user experience.

Moreover, for users transitioning from other monitoring tools like Dynatrace, the interface may feel less intuitive and more cumbersome. Offering more intuitive visualization options and simplifying the customization process could bridge this gap and make Splunk more accessible to a wider range of users.

Buyer's Guide
Splunk Enterprise Platform
April 2026
Learn what your peers think about Splunk Enterprise Platform. Get advice and tips from experienced pros sharing their opinions. Updated: April 2026.
894,738 professionals have used our research since 2012.

For how long have I used the solution?

I have been using Splunk Enterprise Platform for seven years. We are using V9.0.4.1 of the solution.

What do I think about the stability of the solution?

The product is stable. I rate the solution’s stability a nine out of ten.

What do I think about the scalability of the solution?


How are customer service and support?

I've encountered numerous issues and challenges, but I've managed to overcome them. I rely on the Splunk community to find solutions whenever I face difficulties. I want to fully engage with the platform and be active in its development, but sometimes, I struggle to find the right resources or support.

How was the initial setup?

The initial setup is easy.

What's my experience with pricing, setup cost, and licensing?

Splunk Enterprise Platform can seem a bit costly compared to their five-year plans. There's a need to provide options, such as offering a free license for up to ten GB of data or a limited-time test and development license at no cost. For instance, if a company purchases a one-year product license, it could receive additional test and development licenses for free, up to a certain data limit. While there would naturally be some restrictions, such as limitations on certain features or functionalities, offering these options could encourage more people to adopt Splunk for their needs. Many individuals and stakeholders hesitate due to Splunk's perceived high costs when considering the additional expenses for enterprise support, operational support, and device licenses. Introducing more flexible licensing options could alleviate these concerns and attract more users to the platform, benefiting both Splunk and its customers.

What other advice do I have?

Our experience with the Splunk Enterprise Platform has been positive regarding administration and development. However, there are some concerns regarding visualization. Despite our team's proficiency in activating and completing tasks, the dashboard's complexity has decreased user satisfaction. Many users find the visualization lacking when viewing multiple panels simultaneously. They express difficulty in navigating the UI and feel uncomfortable with it. Addressing these concerns would enhance the overall user experience from end to end.

Overall, I rate the solution a nine out of ten.

Disclosure: My company has a business relationship with this vendor other than being a customer.
PeerSpot user
Praveen Sande - PeerSpot reviewer
Senior Splunk Engineer at Wipro Limited
Real User
Top 20
May 11, 2024
Offers extensive visibility into events with flexible scalability

How has it helped my organization?

Splunk Enterprise Platform is a powerful application that offers extensive visibility into events, notable occurrences, and correlations, providing robust capabilities.

What is most valuable?

The valuable feature is the onboarding of various logs using different methods. Additionally, it excels in content development and use case creation. I want to learn about upcoming technologies like Splunk Cloud and Azure integration. These platforms offer extensive capabilities for visualizing and manipulating data according to our requirements. Splunk's proficiency in field extractions and onboarding logs from diverse sources makes it highly capable. Its logging addition and parsing capabilities are particularly noteworthy.

What needs improvement?

In Splunk Enterprise Platform, while the dashboard feature is powerful, it does have limitations in terms of the number of parameters that can be included in one dashboard. However, it's important to note that these limitations can be addressed through effective dashboard design and optimization techniques. Despite these constraints, Splunk offers extensive capabilities for creating insightful dashboards that can visualize relevant data effectively.

Splunk excels in providing accurate and valuable alerts and reports. These features are crucial in reducing manual efforts, minimizing human errors, and expediting incident resolution processes. With Splunk's alerting and reporting functionalities, users can fine-tune alerts, apply filters, and include necessary information for thorough investigation and analysis. These capabilities contribute significantly to enhancing operational efficiency and decision-making within organizations.

For how long have I used the solution?

I have been using Splunk Enterprise Platform for five years.

What do I think about the stability of the solution?

I rate the solution’s stability an eight out of ten.

What do I think about the scalability of the solution?

Scalability is very flexible. Without the Splunk support, we can deploy and scale up.

How are customer service and support?

The responsiveness of the support is very good. They will ask you if you are raising any P2, P1, or major incidents so they'll help us with immediate and accurate results.

How was the initial setup?

The initial setup is straightforward , with detailed deployment steps outlined in their documentation. Additionally, the Splunk community is a valuable resource where users can ask questions and receive expert solutions. 

What other advice do I have?

Splunk Enterprise Platform does not have a few application add-ons. Therefore, when we aim to integrate log sources from new or important ones that Splunk lacks add-ons for, we resort to developing custom add-ons. While this approach allows us to proceed with our work, it requires significant human effort and increases the likelihood of errors. Moreover, troubleshooting becomes time-consuming under these circumstances. Ideally, Splunk would offer add-ons for every possible application, significantly improving our efficiency and effectiveness.

The Splunk Enterprise Platform offers excellent visibility through real-time monitoring. Whenever any data matches our client's SQL code, it triggers an immediate alert, allowing us to respond to incidents swiftly. This capability is highly beneficial during any incident, making Splunk an invaluable tool.

There are various components, such as Universal Forwarder, Indexer, and Search Head. These components are relatively straightforward to set up. However, when implementing a distributed environment or setting up clustering, Splunk offers robust capabilities. Additionally, managing data storage sizing is also seamless.

Overall, I rate the solution an eight out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Buyer's Guide
Splunk Enterprise Platform
April 2026
Learn what your peers think about Splunk Enterprise Platform. Get advice and tips from experienced pros sharing their opinions. Updated: April 2026.
894,738 professionals have used our research since 2012.
reviewer2292963 - PeerSpot reviewer
Security Architect at a comms service provider with 10,001+ employees
Real User
Oct 20, 2023
A solution that offers a good analytics part along with great integration capabilities with other applications
Pros and Cons
  • "The most valuable feature of the solution is the analytics part."
  • "The support offered by Splunk Enterprise Platform has certain shortcomings that need improvement."

What is our primary use case?

My company uses Splunk Enterprise Platform for monitoring and user base filtering.

What is most valuable?

The most valuable feature of the solution is the analytics part. Integration with other applications is another valuable feature of Splunk Enterprise Platform.

What needs improvement?

Splunk Enterprise Platform is already a refined product, so I don't have any recommendations related to areas that need improvement.

The cost of Splunk Enterprise Platform is an area of concern where improvements can be made by bringing down the costs. Product-related, I don't have any feedback.

The support offered by Splunk Enterprise Platform has certain shortcomings that need improvement.

For how long have I used the solution?

I have been using Splunk Enterprise Platform for a few weeks since it was recently deployed in my company. I use the solution's latest version. My company operates as a service provider of the solution.

What do I think about the stability of the solution?

The product's stability is good. Stability-wise, I rate the solution a nine out of ten.

What do I think about the scalability of the solution?

Scalability-wise, I rate the solution a nine out of ten.

Around 5,000 people use the solution. Around 10 to 15 analysts use Splunk Enterprise Platform in my company.

The solution is used on a regular and daily basis in my company.

How are customer service and support?

I am moderately satisfied with the solution's technical support. I rate the technical support an eight out of ten.

How would you rate customer service and support?

Positive

How was the initial setup?

Splunk Enterprise Platform was easy to implement. I rate the product's implementation phase an eight out of ten, where one is difficult, and ten is easy.

The solution is deployed on an on-premises model.

The solution's deployment phase was carried out over a period of one or two months.

What's my experience with pricing, setup cost, and licensing?

I rate the product's pricing a ten on a scale of one to ten, where one is cheap, and ten is expensive. It is a very pricey tool.

What other advice do I have?

I would recommend the product to those who plan to use it, provided the pricing of the solution is brought down.

I rate the overall product an eight out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer. MSP
PeerSpot user
Adrian-Mache - PeerSpot reviewer
Solution Architect at a tech vendor with 10,001+ employees
Real User
Sep 11, 2023
Versatile, adaptable, and applies to many use cases
Pros and Cons
  • "What I find the most valuable about the platform is its DB Connect and its versatility in general. I also like its adaptability to any use case when it comes to collecting and analyzing data."
  • "The platform is too expensive for small businesses. Splunk should focus more on delivering something for small businesses and entrepreneurs."

What is our primary use case?

I use the platform to collect data and report to the clients that need reporting from Splunk. I work on gathering big data from all over my company and exporting it into proper reports.

What is most valuable?

What I find the most valuable about the platform is its DB Connect and its versatility in general. I also like its adaptability to any use case when it comes to collecting and analyzing data.

What needs improvement?

It is hard to say in what areas the platform could be improved since it's very versatile and applies to many use cases. It already has the functioning vetted into the core architecture of the product. In my opinion, there is no need for additional features because it already has many, and I haven't used them all.

For how long have I used the solution?

I've been using Splunk Enterprise Platform for two and a half years. I am a Splunk software architect and Splunk is the only platform I use.

What do I think about the stability of the solution?

It's a very stable platform. A ten out of ten.

What do I think about the scalability of the solution?

The scalability of Splunk is ten out of ten. It's one of the best platforms on the market. Approximately 1,000-2,000 people use the platform at our company, but only two people are needed to maintain it and I'm one of them. Everything is automated and it is very easy to manage 2,000 users on my own.

Which solution did I use previously and why did I switch?

I would compare Splunk Phantom with RSA NetWitness and Elasticsearch. All three solutions give the same output but in a different way. They analyze data in different ways. Each product has its scalability, versatility, and appliances in the current business needs of the company that uses it.

How was the initial setup?

The initial setup is very easy. At our company, we deployed Splunk ourselves because we are a team of Splunk architects and we have done it before.

What's my experience with pricing, setup cost, and licensing?

The platform is too expensive for small businesses. If you choose the free plan, it only has 15 GB of data per day, and it may not be enough to run a small business. You need to pay a subscription based on data ingestion, and that's very expensive. Splunk should focus more on delivering something for small businesses and entrepreneurs. I give the pricing a three or four out of ten. Although the product is pricey, it's truly magnificent.

Which other solutions did I evaluate?


What other advice do I have?

Overall, I give Splunk a nine out of ten and not a solid ten just because there are new updates every day and we don't know exactly what we need to search for since it's not that viewable. 

Which deployment model are you using for this solution?

Hybrid Cloud
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
PeerSpot user
Mohan Battu - PeerSpot reviewer
Project Lead at a computer software company with 5,001-10,000 employees
Real User
Apr 30, 2024
Offers timestamp indexing and the easy-to-use visualization for data analysis
Pros and Cons
  • "Splunk's real-time processing capability has been pretty good for my use cases."
  • "There is room for improvement in terms of scalability."

What is our primary use case?

I have a variety of use cases. My company uses it for cloud-related operations, anomaly identification, and threat detection.

How has it helped my organization?

It's been very useful in regard to security information and threat management (SIEM). Splunk is a valuable tool for my organization.

What is most valuable?

The timestamp indexing and the easy-to-use visualization features are the most valuable features for data analysis.

Moreover, the dashboard and visualization features have made a big difference. We can quickly identify issues within the dashboards and easily generate insightful reports. If something goes down, we can easily detect the issue.

Splunk's real-time processing capability has been pretty good for my use cases.

What needs improvement?

There is room for improvement in terms of scalability. They can enhance the ability to handle increasing volumes of data. 

For how long have I used the solution?

I have been using it for four years now. 

What do I think about the stability of the solution?

There have been occasional issues, but nothing major.

I would rate the stability an eight out of ten.

What do I think about the scalability of the solution?

I never had issues with scalability. My organization has 8,000 end users. 

I would rate the scalability an eight out of ten.

How are customer service and support?

The customer service and support are good. 

How would you rate customer service and support?

Positive

How was the initial setup?

In general, the initial setup is fairly easy.

Not everyone can do it. Some knowledge and experience would likely be helpful to get the most out of the setup.

Typically, the deployment would take around 16 to 20 hours.

What's my experience with pricing, setup cost, and licensing?

The pricing is about average.

What other advice do I have?

Overall, I would rate the solution an eight out of ten.

I would recommend using this solution. Overall, Splunk is a good tool for analysis and for representing data in a short span of time. It helps minimize unnecessary noise in the data.  

Which deployment model are you using for this solution?

On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Kundan Nagare - PeerSpot reviewer
Senior Consultant at Infosys
MSP
Apr 17, 2024
Offers excellent data analysis and visualization capabilities
Pros and Cons
  • "The most valuable feature of Splunk for data analysis is its ability to search using SPL and SQL."
  • "There is room for improvement in introducing more AI capabilities onto Splunk Enterprise Platform."

What is our primary use case?

I use the Enterprise platform mainly to monitor infrastructure, applications, and some security logs.

What is most valuable?

The most valuable feature of Splunk for data analysis is its ability to search using SPL and SQL. With SPL commands, you can analyze both structured and unstructured data and build visualizations, dashboards, and reports. Additionally, Splunk offers alerting mechanisms for proactive monitoring.

What needs improvement?

There is room for improvement in introducing more AI capabilities onto Splunk Enterprise Platform. While they might exist in other platforms like ITSI, enhancing the Enterprise Platform with AI features would benefit many users who predominantly use it.

For how long have I used the solution?

I have been using Splunk Enterprise Platform for almost three years.

What do I think about the stability of the solution?

I would rate the stability of Splunk at around a seven out of ten. While it is generally good, in complex environments, issues may arise due to the increased number of components and dependencies. However, overall, the stability is good.

What do I think about the scalability of the solution?

I would rate Splunk's scalability as a nine out of ten. It is the best log analysis application currently available. Scalability has allowed us to handle increasing volumes of data, enabling us to onboard additional customers and share infrastructure monitoring on the same setup. We have approximately 20 people using Splunk Enterprise Platform in our company.

How are customer service and support?

The technical support team could improve by providing more direct assistance rather than primarily relying on community resources for issue resolution. While they do understand the issues, they often refer to existing communities for solutions instead of directly addressing system-specific concerns. Overall, I would rate the support as a six out of ten.

How would you rate customer service and support?

Neutral

How was the initial setup?

The initial setup of Splunk Enterprise is relatively complex compared to other monitoring applications in the market. There is a need to focus on simplifying key components and reducing dependencies for a smoother setup process. For a large environment, the deployment of Splunk Enterprise typically takes around three months to set up completely.

What's my experience with pricing, setup cost, and licensing?

Splunk Enterprise Platform is a bit expensive.

What other advice do I have?

I use the Platform to monitor my IT infrastructure. There are apps for Linux and Windows servers that capture performance metrics like CPU and memory usage. These metrics are collected and sent to the blank index through forwarders.

Splunk helps with security information and event management by detecting and monitoring network equipment and firewalls. It saves searches for specific terms, like threats, in firewall logs. When a match is found, it alerts about potential security breaches, helping to detect and address them.

The real-time processing capability in Splunk enhances data monitoring by centrally collecting all data. This allows for easy searching and scheduling of searches, reducing the need for manual intervention.

The dashboard and visualization features in Splunk impact data analysis by providing a clear status of data analysis. Users can create customized views for management, helping them understand what is happening within the infrastructure more effectively.

I would recommend Splunk to others, especially from the CIM perspective. Its data analysis and visualization capabilities are unmatched, making it an excellent choice for SIM.

Overall, I would rate Splunk Enterprise Platform as a nine out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
ABBURI AJAY - PeerSpot reviewer
Splunk Software Developer at Tata Consultancy
Real User
Apr 15, 2024
Used for logging and monitoring purposes
Pros and Cons
  • "The most valuable features of the solution are the load balancing technique, the forwarding technique, and SSL certification."
  • "Sometimes, queries don't give proper results, and the indexes go down."

What is our primary use case?

We use the Splunk Enterprise Platform for logging and monitoring purposes. If users log into different databases and do something, we onboard database logs and other AWS logs to Splunk. Then, we create a dashboard alert report, and based on those dashboard alerts, we monitor users' actions. If they perform suspicious activities, we also send alerts. We use the solution to create dashboard alerts, reports, and some query language.

What is most valuable?

The most valuable features of the solution are the load balancing technique, the forwarding technique, and SSL certification.

What needs improvement?

Sometimes, queries don't give proper results, and the indexes go down.

For how long have I used the solution?

I have been using Splunk Enterprise Platform for seven years.

What do I think about the stability of the solution?

I rate the solution an eight out of ten for stability.

What do I think about the scalability of the solution?

I rate the solution’s scalability a nine out of ten.

How are customer service and support?

The solution’s technical support is good.

How was the initial setup?

The solution’s initial setup is easy.

What's my experience with pricing, setup cost, and licensing?

I have heard from my managers that Splunk Enterprise Platform is an expensive solution.

What other advice do I have?

The solution has helped us with our security information and event management. If someone performs deletion operations, we get an automated alert informing us that a privileged activity has been performed. We forward the logs in real-time. We are ingesting 10GB of data into the solution daily. We have some input filters in the solution's dashboard.

Overall, I rate the solution an eight out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
LeslieTaylor - PeerSpot reviewer
Consultant at Pyramid Consulting
Real User
Mar 12, 2024
Useful for cloud-based monitoring but improvement is needed for providing a shareable format
Pros and Cons
  • "I found the incident notification to be very helpful."
  • "The tool lacked in providing a shareable format. I had to use pivot tables and manually parse and edit the data to create a visualization-friendly format. It was helpful when we had an issue. What would make it stronger is if it were more proactive. For example, if it highlighted major incidents and their impact on users without digging through notifications, that would be better. Typically, the first question we get is, "Oh, we had an incident. How bad was it? How many customers were impacted?" So having that information pop up from the notification would be helpful."

What is our primary use case?

We used the product for cloud-based monitoring or systems monitoring. 

What is most valuable?

The key difference I noticed for my use case, which involved understanding user behaviors and responses to digital elements, was that I could obtain more detailed reporting than what was possible with Amplitude. I could download a file with very specific information, which was helpful.


I did not use it for real-time monitoring. My focus was on investigating incident reports to understand the extent of user impact. Primarily, I utilized the Splunk Enterprise Platform to analyze user behavior.

I found the incident notification to be very helpful. While Splunk Enterprise Platform provided detailed data, it didn't seem to check as many boxes for user behavior as Amplitude did. At the same time, I'm not sure if Amplitude offers features for monitoring or incident coverage.

Its ability to access granular details in Excel was beneficial. It's always helpful to transition from visualizations to detailed user reports. 

What needs improvement?

The tool lacked in providing a shareable format. I had to use pivot tables and manually parse and edit the data to create a visualization-friendly format. It was helpful when we had an issue. What would make it stronger is if it were more proactive. For example, if it highlighted major incidents and their impact on users without digging through notifications, that would be better. Typically, the first question we get is, "Oh, we had an incident. How bad was it? How many customers were impacted?" So having that information pop up from the notification would be helpful.

What do I think about the stability of the solution?

Splunk Enterprise Platform is stable. 

What do I think about the scalability of the solution?

I saw no issues or reasons to think that the product wouldn't scale over time. Our data is growing. 

How are customer service and support?

I haven't contacted the tool's support. 

What other advice do I have?

I rate the overall product a seven out of ten.

I would recommend it for incident management reporting. I would not advise it for understanding user behavior or usage. If I had to choose between Splunk Enterprise Platform and Amplitude, I would probably go with Amplitude, but I also have no familiarity with what their incident reporting is like.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Buyer's Guide
Download our free Splunk Enterprise Platform Report and get advice and tips from experienced pros sharing their opinions.
Updated: April 2026
Buyer's Guide
Download our free Splunk Enterprise Platform Report and get advice and tips from experienced pros sharing their opinions.