Try our new research platform with insights from 80,000+ expert users
Sontas Jiamsripong - PeerSpot reviewer
Account Presale at a tech services company with 1,001-5,000 employees
Real User
A flexible solution
Pros and Cons
  • "Splunk is quite flexible for our customers. Splunk does not filter from a specific lock, you can define it later."
  • "I would like Splunk to add more integration. QRadar has many indications with more products than Splunk."

What is our primary use case?

The project we are working on with Splunk is short as the customer has given us two months to implement. My company is a Splunk partner.

What is most valuable?

Splunk is quite flexible for our customers. Splunk does not filter from a specific lock, you can define it later.

What needs improvement?

I would like Splunk to add more integration. QRadar has many indications with more products than Splunk.

For how long have I used the solution?

I have been working with Splunk for three months.

Buyer's Guide
Splunk Enterprise Security
April 2025
Learn what your peers think about Splunk Enterprise Security. Get advice and tips from experienced pros sharing their opinions. Updated: April 2025.
851,823 professionals have used our research since 2012.

What do I think about the scalability of the solution?

Splunk is quite good if you want to scale it.

Which solution did I use previously and why did I switch?

My client has some pain points with QRadar and does not feel the kilogram function is accurate. Other features do not match with the customer behavior as well. They want to replace QRadar with Splunk because they are familiar with this solution.

How was the initial setup?

The initial setup of Splunk is complex. It requires a lot of equipment and uploads.

What about the implementation team?

My company provides the implementation and maintenance services to our customers.

What's my experience with pricing, setup cost, and licensing?

Splunk licensing requires you to purchase licenses for any feature per user. For example, if you need UEBA, it is difficult to propose in the project. QRadar has a free upcharge for UEBA. Customers cannot calculate the additional costs based on gigabytes per day because they can not forecast the future.

What other advice do I have?

Due to the cost of Splunk, I recommend it for larger companies. Splunk is powerful when sorting huge amounts of data. 

Implementation of Splunk takes preparation. It requires a lot of resources and needs the infrastructure to support the project.

I would rate the solution an 8 out of 10.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
PeerSpot user
reviewer1478619 - PeerSpot reviewer
IT System Developer/Admin at a manufacturing company with 10,001+ employees
Real User
A stable, scalable solution with comprehensive dashboards and helpful technical support
Pros and Cons
  • "The scalability of the solution is amazing because it can collect a lot of data and you can have your own structure to monitor this data."
  • "An area of improvement would be the licensing of the solution. They need a free license, which would allow faster lead times."

What is our primary use case?

The primary use case of this solution is to monitor Cyber Mission databases.

I create the diagrams to create an architecture that is then implemented. However, creating these diagrams are for my own learnings since these implementations are usually already available in the cloud office logs.

What is most valuable?

The features I have found most valuable are the dashboards. 

I monitor the complete capacity that users are using in the company.

What needs improvement?

An area of improvement would be the licensing of the solution. They need a free license, which would allow faster lead times.

They also need to update their documentation.

What do I think about the stability of the solution?

The solution is stable.

What do I think about the scalability of the solution?

The scalability of the solution is amazing because it can collect a lot of data and you can have your own structure to monitor this data.

How are customer service and technical support?

The customer service/technical support was helpful and they answered my questions as best they could.

How was the initial setup?

The setup was easy, but you have to have a VPN connection depending on the security protocols in place.

What about the implementation team?

The deployment was in-house and took about two days with the correct licenses and permissions.

What other advice do I have?

It is important to define different guidelines to integrate Splunk in development, QA, and production deployments. Additionally, define the applications that will be used and the configuration of the databases to collect the data. If this is not done, there will be a lot of issues due to, for example, master access or permissions to use the database collector and blocks.

Which deployment model are you using for this solution?

Hybrid Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Amazon Web Services (AWS)
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Buyer's Guide
Splunk Enterprise Security
April 2025
Learn what your peers think about Splunk Enterprise Security. Get advice and tips from experienced pros sharing their opinions. Updated: April 2025.
851,823 professionals have used our research since 2012.
General Manager at Intersoft S.A.
Reseller
A great solution for application management, security and compliance
Pros and Cons
  • "The correlation capabilities are the first value that our clients say they like with Splunk."
  • "The difficult part is related to integration with sources of data that are used to create the logs as this depends on the infrastructure of the client."

What is our primary use case?

We use Splunk for security and also PCI compliance.

We have installed and implemented this solution for several clients in Bolivia with our team. We have received training from Splunk directly, and we have also provided training to our clients.

We deploy two versions: one for on-premise and one for the cloud.

Most of our customers purchase Splunk because they required a tool for gathering and collecting all of the logs from the infrastructure in order to make a correlation between data and to spot patterns surrounding security incidents.

What is most valuable?

The correlation capabilities are the first value that our clients say they like with Splunk. Another benefit is that they can connect to any device or log from any device from anywhere.

It's easy, the tool is very easy to install and set up. 

What needs improvement?

They could have more dashboards done or predefined so our clients could use them directly in order to have more information ready to use.

The difficult part is related to integration with sources of data that are used to create the logs as this depends on the infrastructure of the client.

For how long have I used the solution?

We have been using this solution for more than five years.

What do I think about the stability of the solution?

Stability-wise, it's great.

What do I think about the scalability of the solution?

We do not require much scalability here because the clients are not so big; however, the hardware where we installed the products was enough to handle all the transactions of Splunk.

How are customer service and technical support?

The support is not so good, I would only give them a rating of six or seven.

They should provide support in Spanish here in Latin America. Their response time to inquires or requirement tickets is too long. It should be shorter.

How was the initial setup?

Deployment took us two weeks.

What other advice do I have?

I would recommend Splunk to any company: small, medium, and large.

Splunk is a great tool but you should get a partner who knows what they are doing, implementation-wise. 

On a scale from one to ten, I would give Splunk a rating of nine.

Disclosure: My company has a business relationship with this vendor other than being a customer: Reseller
PeerSpot user
Software Engineer at Tableau Software
Real User
It has reduced the time to resolution and time to investigate, but the search query is slow
Pros and Cons
  • "It has reduced the time to resolution, time to investigate, and time to troubleshoot for debugging issues."
  • "Out-of-the-box, it seems very powerful."
  • "My company could benefit from doing more Splunk training with Splunk consultants teaching us how to use it."

What is our primary use case?

We use it for searching logs in a production environment.

How has it helped my organization?

It has reduced the time to resolution, time to investigate, and time to troubleshoot for debugging issues. 

What is most valuable?

Being able to search across all the different production environments at the same time, then being able to do search queries to scope out specific environments, specific components, or specific logs from different languages, such as Java or C++. Thus, being able to have really fine grain control on log searching is really good.

Out-of-the-box, it seems very powerful.

What needs improvement?

The search query seems slow, but I am not sure if that is just because it is searching millions upon millions of lines of text. Also, I just started using it, so I might have no idea what I am doing. I could probably speed up the queries by improving my search skills.

My company could benefit from doing more Splunk training with Splunk consultants teaching us how to use it. It is possible that we have already done this and I haven't participate, but this type of training would be helpful.

For how long have I used the solution?

Less than one year.

What do I think about the stability of the solution?

It is always up when I need to search. I am probably not using it that much. I will maybe search a couple times a day for something specific, so I am not using it too much. I know plenty of the people who are doing a lot more for debugging, and who use it a lot all day.

What do I think about the scalability of the solution?

It seems like it scales well. We have hundreds of production and development environments, and we are searching on all of them. Therefore, it seems like the scale is good. 

We have hundreds of production environments, and each production environment has ten to 20 host machines. Each production environment can manage tens of thousands of customers.

Maybe going to AWS and scaling it better would be more cost-effective for our company. However, I am not involved in those decisions.

How is customer service and technical support?

I have not used technical support.

Which other solutions did I evaluate?

We have other log searching tools, but we have standardized on Splunk. 

What other advice do I have?

It is a great product. We have a lot of different tools to do this type of debugging. Yet, it is one of the first ones that I will reach for, and I think that is a good sign.

It works well and is the industry standard for log searching. It probably has other features too. Therefore, if you use it, I would recommend the training, so you know what you are doing. 

I am using the on-premise version.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
PeerSpot user
Systems Analyst Staff - SW Eng Compute Analytics Lead at Qualcomm
Real User
Allows for transparency into IT metrics for insightful business analytics
Pros and Cons
  • "It allows for transparency into IT metrics for insightful business analytics."
  • "It has the ability to correlate data, analyze and review it."
  • "Free-floating panels in the dashboards are like a glass table."
  • "It needs more formatting control without having to be an admin."

What is our primary use case?

IT service analytics: 

  • Server machine data
  • Monitoring data
  • Alerting data
  • ITSI KPIs
  • Real-time reporting
  • Month-over-month reporting.

How has it helped my organization?

It allows for transparency into IT metrics for insightful business analytics.

What is most valuable?

It brings together all sorts of data. It has the ability to correlate data, analyze and review it. This makes weekly ops reviews and monthly executive management reporting much easier by saving hours of collecting data. Report automation has been a life saver.

What needs improvement?

  • Free-floating panels in the dashboards are like a glass table. 
  • It needs more formatting control without having to be an admin.

For how long have I used the solution?

Three to five years.

Which solution did I use previously and why did I switch?

Previously, only the service owner could see the data and he might have gone to several places to obtain it. Now, it is all in one place and easy to access. 

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
reviewer1524594 - PeerSpot reviewer
Senior Solutions Architect at a manufacturing company with 51-200 employees
Real User
Seamless integration with devices and operating systems, centralized management and control, and proactive support
Pros and Cons
  • "The integration is seamless with many devices and operating systems."
  • "Being a SIEM solution with a centralized dashboard, we would like to have more options to customize it."

What is our primary use case?

We are a solution provider and Splunk is something that we provide as a service to our customers.

What is most valuable?

The most valuable feature is the reporting and the information that is provided by the tool.

It is very easy to implement a PoC using Splunk, which will show the value of the reporting and data that it provides.

The integration is seamless with many devices and operating systems.

It is flexible enough that you can choose what kind of deployment model you want.

They have a large solution toolkit that supports IoT, wherein businesses can get a lot of help with the centralized management functionality. There are also tools to assist from the security and SIEM perspective, and there is a centralized dashboard.

What needs improvement?

Being a SIEM solution with a centralized dashboard, we would like to have more options to customize it. It should be easy to customize dashboards.

When we are monitoring something, we would like to have a more granular outlook. Splunk has a good dashboard that is easier to use than some competing products, but better customizability would be a great help for the users.

For how long have I used the solution?

We have been working with Splunk for approximately three years.

What do I think about the stability of the solution?

This product is very stable.

What do I think about the scalability of the solution?

Splunk is a very scalable solution. Being a Japanese product, they will ensure that all of the features work in any environment. It is very heterogeneous. It can integrate with Windows, Linux, AIX, HP-UX, and Solaris. It also supports IoT devices, mobile phones, and more.

We have more than 150,000 people using our services.

How are customer service and technical support?

The Splunk team has good, proactive support. Also in terms of assisting with the installation, they are quite good.

Which solution did I use previously and why did I switch?

Splunk is similar to IBM QRadar, which we also have experience with. However, Splunk has advanced SIEM features included with it, so we often use it to satisfy this requirement. Whenever an organization is looking to implement SIEM, they have the flexibility to choose Splunk, QRadar, or the ArcSight Logger solution.

One of the major differences that I see between Splunk and QRadar is that Splunk gives the users fewer devices, so they can do things quicker. 

How was the initial setup?

The installation for Splunk is easier than competing products QRadar and ArcSight.

We have Splunk deployed on the cloud so that we can provide the service, but some of our customers have it installed on-premises.

All the user has to do is download the Splunk server agent, install it on the laptop or endpoint, integrate 50 or 100 devices, then see what kind of reporting is available.

What about the implementation team?

We have an in-house team for deployment in maintenance. Splunk is a tool that does not require much staff to maintain. The users can start with a PoC, simply learn it, and deploy it for themselves. They don't require subject experts to be hired for the installation and configuration.

What's my experience with pricing, setup cost, and licensing?

Price-wise, if you compare QRadar to Splunk for SIEM functionality then they are in the same range but when you integrate SOAR with these solutions, Splunk takes the lead and is more competitive.

What other advice do I have?

This is a product that I recommend for anybody who wants and advanced SIEM solutions. Of the three that I have used including QRadar and ArcSight, Splunk is the one that I prefer.

I would rate this solution a nine out of ten.

Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
PeerSpot user
PeerSpot user
Director of IT at BLUE LAKE RANCHERIA
Real User
Aggregation searches have reduced time and difficulty of identifying trends and conditions which need to reviewed
Pros and Cons
  • "Splunk has significantly reduced the time in performing the task of aggregating logs, reviewing as well as time spent during investigations."
  • "Aggregation searches have reduced time and difficulty of identifying trends and conditions which need to reviewed."
  • "The case management area of the ES could be improved. The ability to move cases through various stages and states. The ability to close a case would be key improvement."

What is our primary use case?

We primary use Splunk for log aggregation and search across multiple systems with Splunk Enterprise Security layered on top. 

How has it helped my organization?

Splunk has significantly reduced the time in performing the task of aggregating logs, reviewing as well as time spent during investigations. This has not only
increased our speed of response, but our efficiency dealing with the issue(s)
raised.

What is most valuable?

Aggregation searches, allowing for conditions to be automatically found in the data, have reduced time and difficulty of identifying trends and conditions which need to reviewed.

What needs improvement?

The case management area of the ES could be improved. The ability to move cases through various stages and states. The ability to close a case would be key improvement.

For how long have I used the solution?

One to three years.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
reviewer1762323 - PeerSpot reviewer
Cybersecurity Senior Manager at a tech services company with 10,001+ employees
Real User
Simple data file updates, good support, and useful dashboards
Pros and Cons
  • "The connections to the database are very good and updating the data files is simple to do. The dashboards are useful and user-friendly."
  • "We had some connections issues with the solution at the beginning."

What is most valuable?

The connections to the database are very good and updating the data files is simple to do. The dashboards are useful and user-friendly.

What needs improvement?

We had some connections issues with the solution at the beginning.

For how long have I used the solution?

I have used Splunk within the last 12 months.

What do I think about the stability of the solution?

Splunk is a highly stable solution.

What do I think about the scalability of the solution?

The scalability is good.

We have approximately 50 users using this solution in my organization.

How are customer service and support?

I am satisfied with the support from Splunk.

Which solution did I use previously and why did I switch?

We were previously using Excel.

What about the implementation team?

We used a consultant for the implementation of the solution. The full process took approximately one week.

We had a big problem with communication sometimes during the implementation. Some files in our network were a little difficult to receive. This was our fault because of some of our firewall configurations.

We have a five-person maintenance team that works on this solution.

What other advice do I have?

I rate Splunk an eight out of ten.

Which deployment model are you using for this solution?

Hybrid Cloud
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Buyer's Guide
Download our free Splunk Enterprise Security Report and get advice and tips from experienced pros sharing their opinions.
Updated: April 2025
Buyer's Guide
Download our free Splunk Enterprise Security Report and get advice and tips from experienced pros sharing their opinions.