Try our new research platform with insights from 80,000+ expert users
reviewer1062186 - PeerSpot reviewer
Sr. IT Manager at a pharma/biotech company with 10,001+ employees
Real User
Top 20
Good log aggregation and scales well, with good technical support that is responsive and helpful
Pros and Cons
  • "The most valuable feature is that it's very good for log aggregation."
  • "The implementation and the scanning of the logs can be difficult."

What is our primary use case?

We are using Splunk to look at the logs, and see what is happening.

What is most valuable?

The most valuable feature is that it's very good for log aggregation.

What needs improvement?

Splunk is very complex. The implementation and the scanning of the logs can be difficult.

For how long have I used the solution?

I have been using Splunk for approximately three years.

Buyer's Guide
Splunk Enterprise Security
April 2025
Learn what your peers think about Splunk Enterprise Security. Get advice and tips from experienced pros sharing their opinions. Updated: April 2025.
851,823 professionals have used our research since 2012.

What do I think about the stability of the solution?

In general, Splunk is stable.

What do I think about the scalability of the solution?

It's a scalable product. it's pretty good.

How are customer service and support?

Technical support is usually pretty good.

They are responsive, knowledgeable, and helpful.

How was the initial setup?

The initial setup was relatively straightforward.

What's my experience with pricing, setup cost, and licensing?

The price is comparable.

What other advice do I have?

I would rate Splunk and eight out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
PeerSpot user
VMware Engineer at First Data Corporation
Real User
In-depth logs but downloading and uploading logs have become an issue

How has it helped my organization?

100%. VMware needs log information to troubleshoot; it's not easy finding problems.

Downloading and uploading logs have become an issue.

What is most valuable?

  • In-depth logs
  • Add-ons 
  • The ability to ingest data from other tools
  • The detailed log view
  • It's easy to read

What needs improvement?

  • The amount of time it takes to troubleshoot not-easily-available data
  • Also, hours on the phone with VMware techs.

For how long have I used the solution?

Less than one year.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Buyer's Guide
Splunk Enterprise Security
April 2025
Learn what your peers think about Splunk Enterprise Security. Get advice and tips from experienced pros sharing their opinions. Updated: April 2025.
851,823 professionals have used our research since 2012.
Application Engineer at Expedia
Real User
The most valuable feature is its centralized log analytics
Pros and Cons
  • "We have a one stop dashboard for health of some of our services where you can click in and it takes you to other dashboards that have custom near real-time metrics that show the application's health."
  • "The historical data extraction needs improvement. I would like the capability of taking data and having it trend longer."

What is our primary use case?

The primary use case is for log analytics. Although, we have been using it as a hammer which hits all the nails. We have sort of overused it in some areas where it doesn't need to be used.

How has it helped my organization?

We have a one stop dashboard for health of some of our services where you can click in and it takes you to other dashboards that have custom near real-time metrics that show the application's health. From there, you can drill in to see the real deep dive example of what is happening in your environment. It has reduced our time to resolve incidents. 

What is most valuable?

The most valuable feature is its centralized log analytics.

What needs improvement?

The historical data extraction needs improvement. I would like the capability of taking data and having it trend longer. Splunk is good about viewing data within the last seven or 14 days, but if you want to see a year-over-year trend, you have to do a lot of work to get to that point. If there was a better way to extract the data point and put it into a long-term viewing ability for a year-over-year analysis, then compare that to your other business metrics. That is what I am looking for, as an example, for a call center you want to see the time it takes for your customer to be handled on their need comparatively to the system performance that is happening, then overlay that data. 

For how long have I used the solution?

Three to five years.

What do I think about the stability of the solution?

We put a lot of trust in it. It has been pretty rock-solid outside of a couple of changes that we made. Upgrades sometimes don't always go smoothly, but otherwise the system performs, and operates. 

What do I think about the scalability of the solution?

When we were trying to implement an enterprise solution on-premise, we had scaling issues. It was very difficult to search the data retention beyond a few days. A lot of talent was given to the ability to go into AWS and scale with our need. We still had to do some administrative things to prevent consumers from trying to search all records for all time in very inefficient searches. This could sometimes bring our core system functionality to a halt, so we had to do some user administration in it.

How is customer service and technical support?

I don't engage with the support directly. Another member of my team does. Any time that we have needed support, he hasn't had an issue opening a ticket and receiving the help that he needs.

How was the initial setup?

The integration and configuration in the AWS environment was pretty good. They have a consumption method for pretty much every service. They might be able to do a little better at advertising different patterns for best practices for different service, but overall there's a method to get everything.

What was our ROI?

We have had a reduction in the time it takes to resolve issues and correlate what has failed. This has significantly helped.

Which other solutions did I evaluate?

We looked at the Elk Stack, Kibana, and Sumo Logic.

We chose Splunk because their cost is better, the maintenance factor is a little higher, and the core functionality is higher than what other products provide. The core functionality is out-of-the-box. E.g., with a Toyota Scion, you can customize the parts to make it whatever you want, but it's a lot of work to get there. Where if you buy a Cadillac, you pay the Cadillac's price, but it's a Cadillac. It will work right out-of-the-box.

What other advice do I have?

It works well when searching logs. If you looked to try to do things beyond this, the problem that we ran into is that we treated it as the hammer which hits all nails. That is not really feasible, and there are other tools out there that can do more specialized things.

User administration is key. Trying to prevent users from being able search records all the time is a huge problem. You need a tight approval process on dashboards, making sure the dashboards are queried in the most efficient way possible. 

The on-premise version that we had was not scalable at all. It was very difficult to use. We have EC2 instances in the cloud with Splunk installed, which is more scalable and easier to use. It now works much better.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
PeerSpot user
Splunker at freelancer
Real User
Quickly search for almost anything across many log sources in seconds
Pros and Cons
  • "We can do things in minutes instead of days."
  • "We solve issues that we previously could not since we now have the data."
  • "We can quickly search for almost anything across many log sources in seconds."
  • "The GUI could be improved to include some of the capabilities that other BI solutions have. The layout is a little restrictive where you can’t resize all the panels to exactly how you would like them without tweaking some XML code."
  • "AngularJS/ReactJS inclusion could be made easier in GUI."

What is our primary use case?

The primary use case is to analyse and monitor big data, creating various dashboards, alerts, etc.

How has it helped my organization?

  • We can do things in minutes instead of days.
  • We solve issues that we previously could not since we now have the data.
  • We can quickly search for almost anything across many log sources in seconds.
  • Teams have the dashboards or alerts that they need.

What is most valuable?

There are too many features to list, but here are a few:

  • Schema on the fly
  • Ease of onboarding data
  • Machine learning
  • Apps or Splunkbase.
  • Great list of apps to use and build upon once you learn more about how Splunk works.
  • Ease of correlation, creating correlation searches (easy), and you can combine multiple sources with little effort.
  • Data Models Acceleration for super fast searches across tens of millions of events.
  • Common Information Model
  • Security Essentials App
  • Enterprise Security
  • Splunk SPL (Search Processing Language) is easy to learn and has IDE like capabilities.
  • Log storage or compression is great and retention is not an issue.
  • Dashboards are simple to create and has input options, like time range and text.
  • Drop-downs are simple to create.
  • The integration with cloud solutions is great and keeps getting better.

What needs improvement?

The GUI could be improved to include some of the capabilities that other BI solutions have. The layout is a little restrictive where you can’t resize all the panels to exactly how you would like them without tweaking some XML code. Over the years, they have really been improving in this area. I would think that will continue and this will become a non-issue.

Also, AngularJS/ReactJS inclusion could be made easier in GUI.

For how long have I used the solution?

One to three years.

What was our ROI?

Personnel costs are saved by not having to involve domain developers from multiple teams when tracing a problem that spans multiple platforms.

What other advice do I have?

We build many of our own apps by leveraging the logic in others.

Disclosure: My company has a business relationship with this vendor other than being a customer:
PeerSpot user
PeerSpot user
Splunk Administrator at Arizona State University
Real User
Provides important insights to more efficiently make decisions and take action
Pros and Cons
  • "My favorite example of improving of organization is saving a $60k/mo in payroll fraud and $10k/mo in wasted API credits by using simple searches and clear reports."
  • "Splunk's schema on demand is incredibly useful. I do not have to worry about what my users will need when we onboard their data."
  • "While Splunkbase (the app repository) has a lot of great content, some apps are terribly old and could stand to be updated or purged."
  • "Some of the terminology can be confusing, even for seasoned vets. Renaming components at this point would be a serious undertaking. However, it might be beneficial in the long run."

What is our primary use case?

We use Splunk primarily to provide our security and ops groups with important insights to more efficiently make decisions and take action.

How has it helped my organization?

My favorite example of improving of organization is saving a $60k/mo in payroll fraud and $10k/mo in wasted API credits by using simple searches and clear reports.

What is most valuable?

Splunk's schema on demand is incredibly useful. I do not have to worry about what my users will need when we onboard their data. They can make connections that we could not have foreseen. They dig deeper when they are searching.

What needs improvement?

Some of the terminology can be confusing, even for seasoned vets. Renaming components at this point would be a serious undertaking. However, it might be beneficial in the long run.

While Splunkbase (the app repository) has a lot of great content, some apps are terribly old and could stand to be updated or purged.

For how long have I used the solution?

One to three years.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
PeerSpot user
Principal Engineer at Publix Super Markets
Real User
A more secure, robust environment, which keeps out harmful software
Pros and Cons
  • "Visualizations are the best way to understand deviation techniques from the norm."
  • "We have a more secure, robust environment, which keeps the harmful software out of the zone required."
  • "More training on PetaData using artificial intelligence techniques to identify the events which are not normal and exceptions that would help the organization identify threats and malware on the go with results."

What is our primary use case?

Security and incident management, which is helpful when organizing the data from different systems and running analysis on all the data together.

How has it helped my organization?

We have a more secure, robust environment, which keeps the harmful software out of the zone required.

What is most valuable?

The most valuable features are:

  • Risk analysis
  • Machine Learning Toolkit
  • dbConnect
  • Cisco products
  • eStreamer
  • SIEM

Visualizations are the best way to understand deviation techniques from the norm.

What needs improvement?

More training on PetaData using artificial intelligence techniques to identify the events which are not normal and exceptions that would help the organization identify threats and malware on the go with results.

For how long have I used the solution?

Three to five years.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
PeerSpot user
Business Intelligence Developer at Arizona State University
Real User
Search language is easy to understand and teach to new users
Pros and Cons
  • "Support is quick and competent."
  • "Search language is easy to understand and teach to new users."
  • "Certain sections of the developer documentation could use some updating and clarification."
  • "Search head clustering is often temperamental in its current state and should be improved, replaced by something better, or be reverted to search head pooling."

What is our primary use case?

  • Monitoring IT and other processes for a large university.
  • Leveraging alerts and dashboards to detect and predict security breaches and other events.

How has it helped my organization?

Splunk has enabled us to detect, even predict potential security issues, before they become severe. It has enabled our operations and development teams to more efficiently monitor and troubleshoot their systems.

What is most valuable?

The search language is easy to understand and teach to new users. The SDK is comprehensive and has incredible levels of integration with the platform and data. 

What needs improvement?

  • Certain sections of the developer documentation could use some updating and clarification.
  • Search head clustering is often temperamental in its current state and should be improved, replaced by something better, or be reverted to search head pooling. 
  • Some terminology is vague and confusing (examples: deployer versus deployment server or search head versus search peer).

For how long have I used the solution?

Three to five years.

How is customer service and technical support?

Support is quick and competent.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
PeerSpot user
Information Security Engineer/Architect at The Church of Jesus Christ of Latter-day Saints
Real User
Helped us consolidate all our solutions into an easy tool to use for various employees
Pros and Cons
  • "It helped us consolidate all our solutions into an easy tool to use for various employees."
  • "More control with Splunk Cloud as it seems a bit limited. I used to manage an on-premise instance of Splunk Enterprise and really liked having more control over it."

What is our primary use case?

We use Splunk for operations, application monitoring, and security. We are both cloud and on-premise based, so it has been very versatile for us. 

How has it helped my organization?

It helped us consolidate all our solutions into an easy tool to use for various employees.

What is most valuable?

  • Unstructured data
  • Linking things together
  • Building out stuff which is actionable.

Once you learn SPL and what data you need to obtain and merge together, it is really useful. 

What needs improvement?

More control with Splunk Cloud as it seems a bit limited. I used to manage an on-premise instance of Splunk Enterprise and really liked having more control over it. 

For how long have I used the solution?

More than five years.

What do I think about the stability of the solution?

No stability issues.

What do I think about the scalability of the solution?

No scalability issues.

Which solution did I use previously and why did I switch?

While we did not have a previous solution, we took what little of Splunk that we have been using and have increased it greatly.

What was our ROI?

We are a nonprofit, so it is hard to quantify. 

What's my experience with pricing, setup cost, and licensing?

Be upfront about your needs and expectations. Splunk is one of the top SIEM solutions to work with. 

Which other solutions did I evaluate?

No.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Buyer's Guide
Download our free Splunk Enterprise Security Report and get advice and tips from experienced pros sharing their opinions.
Updated: April 2025
Buyer's Guide
Download our free Splunk Enterprise Security Report and get advice and tips from experienced pros sharing their opinions.