Try our new research platform with insights from 80,000+ expert users
Head Of Sales at Cascade Solutions Inc
Real User
Powerful lock server with sophisticated architecture
Pros and Cons
  • "Great platform with user-friendly interface and GUI."
  • "Splunk is more expensive than other solutions."

What is most valuable?

Splunk has a great platform. Their edge is in their lock management and being a very powerful lock server. Recently, they added some licensing and updated correlation rules to act as a SIEM Solution. They seem to be penetrating the market in a proper way.

For how long have I used the solution?

I have been using Splunk for more than five or six years.

What's my experience with pricing, setup cost, and licensing?

Splunk solutions are much more expensive than others. Especially when it comes to megaprojects or deals, there's a lot of competition when it comes to financials.

What other advice do I have?

I would rate this solution a seven out of ten. Splunk has a user-friendly interface and GUI. Its architecture is also much more sophisticated than others. 

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
PeerSpot user
Consultant at Splunxter, Inc.
Real User
Our clients are easily able to modify and evolve their implementations
Pros and Cons
  • "With good domain knowledge, one can build almost anything. If you throw in Alert Manager or an integration with ServiceNow. Then, you have your own SIEM"
  • "Our clients are easily able to modify and evolve their implementations."
  • "It needs a better way to export dynamic views without requiring a ton of code and user/pw."
  • "It needs integration with a configuration management solution."
  • "It needs integration with a configuration management solution."

What is our primary use case?

Security. We have built SIEM solutions three times from the ground up (not ES) using Splunk for some of the largest companies in the world.

How has it helped my organization?

Out clients went from unhappy using inflexible, poorly-supported products (in some cases barely functionally) to confident and excited when using Splunk. Not only are they able to do their security jobs and investigations, but they are also easily able to modify and evolve their implementations themselves to keep up with the shifting sands, which is the SecOps landscape.

What is most valuable?

  • Core Splunk
  • Saved searches
  • Dashboards (SimpleXML) 

With good domain knowledge, one can build almost anything. If you throw in Alert Manager or an integration with ServiceNow. Then, you have your own SIEM.

What needs improvement?

  • It needs integration with a configuration management solution. 
  • It could use better password management for forwarders. 
  • It needs a better way to export dynamic views without requiring a ton of code and user/pw.

For how long have I used the solution?

Almost 10 years.

What do I think about the stability of the solution?

Unfortunately, lately every release has a new memory leak.  Be SURE to upgrade late and READ THE RELEASE NOTES, especially the "Known Issues" section.

What do I think about the scalability of the solution?

We only ever have issues when deployed on VMs and the VM admins do not do what we tell them to do which is EXCLUSIVELY RESERVE OUR RESOURCES.

How are customer service and technical support?

It used to be great (but perhaps that was because my employer at the time was a key prospect in a vertical where Splunk had no customers) but Splunk support is definitely a victim of Splunk's explosive growth.  The first tier support is as bad as it is most places and getting worse all the time.  If you KNOW your problem is not run of the mill, ask for escalation immediately.  Also the clock on the case does not start until somebody adds a note to the case so always call in and ask if they got your diag file (always attach a diag) and the person who answers will have to add a note to the case which will start the clock.

Which solution did I use previously and why did I switch?

I have dabbled with LogRythm and ArcSight and they are both OK, but Time-To-Value is WAY shorter with Splunk, IMHO.

How was the initial setup?

Use bare metal severs on Linux and you will be fine.  Use Windows and you will have much trouble.  Use VMs and your admins will cheat you and you will have much trouble.  Do not use NAS!!!!

What about the implementation team?

In-house.  We at Splunxter are Splunk experts.  We can do anything with Splunk.  We always hit homeruns.

What was our ROI?

We usually get multi X-factor within a quarter.

What's my experience with pricing, setup cost, and licensing?

Get free PS if you can (ask) or USE THE DOCS.  The documentation will get you to success.  If you are not getting more value out of Splunk than the license you are paying, then you are doing something wrong and should spend a tiny bit more to get a consultant like Splunxter.com to help you.

Which other solutions did I evaluate?

No,we went with the free trial and got so much value so quickly we bought in.

What other advice do I have?

You can also get GREAT help at answers.splunk.com.

Disclosure: My company has a business relationship with this vendor other than being a customer: We are a Splunk-focused consulting company, but not a Splunk Partner. I am also a member of the "Splunk Trust", Splunk's "MVP" program.
PeerSpot user
Buyer's Guide
Splunk Enterprise Security
April 2025
Learn what your peers think about Splunk Enterprise Security. Get advice and tips from experienced pros sharing their opinions. Updated: April 2025.
851,823 professionals have used our research since 2012.
System Administrator and DevOps Engineer at a tech services company with 10,001+ employees
Real User
Very straightforward, easy to configure, stable and scalable.
Pros and Cons
  • "This is a straightforward solution, easy to configure."
  • "This is a costly solution."

What is our primary use case?

Our primary use case of Splunk is for log monitoring and infrastructure monitoring. If we want to diagnose any issue in our application, we just push our application logs. This is on any client server using the universal forwarder logs on the Splunk server. After indexing, we can create a base log, and create attractive dashboards that are simple to understand and use. I'm a system administrator and we are customers of Splunk. 

What is most valuable?

This is a straightforward solution, easy to configure and difficult to mess up. 

What needs improvement?

Splunk is a very costly solution and I think it's the most expensive in the market in terms of costing. Splunk provides an application for infrastructure monitoring. If we're monitoring the docker with containers, we can't see the container name, only the ID. That's a big drawback.

For how long have I used the solution?

I've been using this solution for two years. 

What do I think about the stability of the solution?

This is a stable solution. Deployment takes one person, it can be a system admin or an engineer.

What do I think about the scalability of the solution?

This is a scalable solution. We can do the clustering of it for large applications. We have around 15 users for this product. 

How are customer service and technical support?

If I have any issues, I'll go to the community. I can generally get a response within a day. Although most of the documentation is good, some of it is unclear, particularly if you're new to the product. 

How was the initial setup?

I think it takes around 10 minutes to install it on the server. On the client side, it takes around five minutes. I do the installation myself. 

What other advice do I have?

If you're going with this solution, make sure that when implementing the ports are open. If they're not open, it creates problems with the server. Other than that, this is a very stable and very easy to configure product. We can easily deploy and easily use. Other similar solutions are difficult to configure, Splunk is the simplest. I've used three or four monitoring tools and Splunk is the easiest. If a company can afford it, this is a good product. We are planning to shift to another product because of the cost. We're searching for an open source or cheaper product.

I would rate this solution a nine out of 10. They lose one point for the price and lack of infrastructure support.

Which deployment model are you using for this solution?

On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Mick - PeerSpot reviewer
Sr. Production Support Analyst at Electric Reliability Council of Texas
User
Quickly searches logs, performance data, and other inputs to assist with troubleshooting
Pros and Cons
  • "The ability to quickly search logs, performance data, and other inputs has helped tremendously with troubleshooting."

    What is our primary use case?

    Operational intelligence monitoring for several different systems. We collect logs from applications and performance data from hardware, as well as information pulled from databases.

    How has it helped my organization?

    The ability to quickly search logs, performance data, and other inputs has helped tremendously with troubleshooting. The visualizations are easy and well received by business and management users. 

    What is most valuable?

    It is ease to integrate with other solutions, like Slack, JIRA, Remedy, etc. 

    For how long have I used the solution?

    Three to five years.

    How is customer service and technical support?

    The user community is extremely beneficial, particularly with Splunk Answers and the Slack User Groups.

    What's my experience with pricing, setup cost, and licensing?

    The licensing model can be expensive, but the value it provides is significant.

    What other advice do I have?

    The recent acquisition of Phantom makes the future seem bright with more automated responses.

    Disclosure: I am a real user, and this review is based on my own experience and opinions.
    PeerSpot user
    it_user717477 - PeerSpot reviewer
    Account Manager at a tech services company with 10,001+ employees
    Real User
    Proactively monitor threats and reduces threat footprint, though professional support is too expensive
    Pros and Cons
    • "Deployment server for deploying changes in one go."
    • "Professional support is great, but too expensive."

    How has it helped my organization?

    It was used for security event management on landscape hosted over AWS.

    It helped the organisation to proactively monitor threats and reduce its threat footprint.

    What is most valuable?

    Deployment server for deploying changes in one go.

    What do I think about the stability of the solution?

    It is quite stable.

    What do I think about the scalability of the solution?

    No.

    How are customer service and technical support?

    Professional support is great, but too expensive. Otherwise content published over website is good.

    Which solution did I use previously and why did I switch?

    Not applicable.

    What's my experience with pricing, setup cost, and licensing?

    Do proper estimation on log ingestion per day as that will impact pricing and licensing.

    Which other solutions did I evaluate?

    It was the customer's choice.

    What other advice do I have?

    It provides a great range of plugins and one can really take great advantage of utilising inbuilt dashboards to derive the desired monitoring.

    Our company consults for different customers and are in a good position to recommend the best solution to our clients.

    Disclosure: I am a real user, and this review is based on my own experience and opinions.
    PeerSpot user
    PeerSpot user
    Security Architect at a energy/utilities company with 1,001-5,000 employees
    Vendor
    Some of the valuable features Machine learning, Common Information Model, and Log storage.
    Pros and Cons
    • "Ease of correlation, creating correlation searches are easy and you can combine multiple sources with little effort"
    • "The GUI can be improved to include some of the capabilities that other BI solutions have."

    How has it helped my organization?

    • We can do things in minutes instead of days.
    • We solve issues which we could not before since we have the data.
    • We can quickly search for almost anything across many log sources in seconds
    • Teams have the dashboards or alerts that they need

    What is most valuable?

    There are too many features to list, but here are a few:

    • Schema on the fly
    • Ease of on-boarding data
    • Machine learning
    • Apps or Splunk base.
    • Great list of apps to use and also build upon once you learn more about how Splunk works.
    • We build many of our own apps by leveraging the logic in the others.
    • Ease of correlation, creating correlation searches are easy and you can combine multiple sources with little effort
    • Data Models Acceleration for super fast searches across tens of millions of events
    • Common Information Model
    • Security Essentials App
    • Enterprise Security
    • Splunk SPL (Search Processing Language) is easy to learn and has IDE like capabilities
    • Log storage or compression is great and retention is not an issue
    • Dashboards are simple to create and the input options like Time Range, Text
    • Drop-downs are simple to create.
    • Integration with cloud solutions is great and keeps getting better.
    • Can get info from rest API’s easily and there are apps for services like ServiceNow, Azure, Office365, etc.

    What needs improvement?

    The GUI can be improved to include some of the capabilities that other BI solutions have. Basically, the layout is a little restrictive where you can’t resize all the panels to exactly how you would like them without tweaking some XML code. Over the years, they have really been improving in this area. I would think that will continue and this could become a non-issue.

    What do I think about the stability of the solution?

    There were no issues with stability.

    What do I think about the scalability of the solution?

    There were no issues with scalability.

    How are customer service and technical support?

    Technical support is excellent. They also have Splunk Answers, which is community driven and it great.

    Which solution did I use previously and why did I switch?

    We were not able to get the value we needed from the previous solution. It was too difficult or complex. With Splunk, we can do things we want and things we have not even dreamed of yet.

    How was the initial setup?

    The initial setup was straightforward. We had the POC up in minutes. Within days, we got more value out of this solution than our existing solution.

    What's my experience with pricing, setup cost, and licensing?

    While licensing can be a concern, there are ways to reduce the licensing costs including filtering some events. We have replaced many solutions with Splunk, which have more than paid for the Splunk licensing.

    Which other solutions did I evaluate?

    We evaluated ArcSight, QRadar, and LogRhythm.

    What other advice do I have?

    Do a PoC and you will be amazed. Also, check out the Splunk .conf sessions to see what is possible. If you are into security, watch Mark Russinovich’s RSA 2017 presentation about Sysmon. Check out free EDR type capabilities.

    Disclosure: I am a real user, and this review is based on my own experience and opinions.
    PeerSpot user
    MS Alam - PeerSpot reviewer
    MS AlamSystem Administrator at Abdullah Al-Othaim Markets
    Real User

    agree with you Mr. Kent this machine have more valuable feature.

    PeerSpot user
    Senior Manager of Network with 1,001-5,000 employees
    Vendor
    Splunk is great for Syslog capabilites. For normal device management, you can't go wrong with SolarWinds.

    I'd go with Splunk for logging. For Syslog capabilities, Splunk wins outright from my experience. It's quick, very customizable, and there are many different modules some specific for vendors and devices. (Cisco Security Suite for one). 

    If you are really into SolarWinds and want to use them for Syslog then I would go with Kiwi. SolarWinds NPM has a syslog collector but under heavy load (a few hundred devices) it will get bogged down real quick in my experience.

    If you are looking for normal device management then NPM, NCM, NTA are the way to go. You can't go wrong with SolarWinds.

    Disclosure: I am a real user, and this review is based on my own experience and opinions.
    PeerSpot user
    it_user167895 - PeerSpot reviewer
    it_user167895Project Manager and consultant enterprise IT tooling at a consultancy with 51-200 employees
    Consultant

    Kiwi syslog for SolarWinds must be seen as a patch for SolarWinds Orion NPM. SolarWinds will release a LOG management module for the Orion NPM platform but this product is in an early state of log collecting, searching and filtering. Splunk can be a good tactical solution to filter out and forward important events to SolarWinds Orion NPM

    See all 2 comments
    Regional Head at a tech services company with 51-200 employees
    Real User
    Good technical support, scalable, and very stable
    Pros and Cons
    • "It's basically one of the best SIEM products on the market."
    • "You do need a lot of training and certification with this product."

    What is our primary use case?

    The solution is primarily a SIEM tool and it basically helps companies with security.

    What is most valuable?

    It's basically one of the best SIEM products on the market.

    The scalability is great.

    We have found the solution to be stable. 

    Technical support is helpful. They respond in a timely manner. 

    What needs improvement?

    I'd like to see more documentation on the product.

    The initial setup is not straightforward.

    You do need a lot of training and certification with this product. Other than that, it's pretty good.

    For how long have I used the solution?

    I've been dealing with the solution for about three years. It's been a while. 

    What do I think about the stability of the solution?

    The stability of the product is very good. The performance is reliable. There are no bugs or glitches. it doesn't crash or freeze. We've had no issues. 

    What do I think about the scalability of the solution?

    The scalability of the solution is great. If a company needs to expand it, it can do so. It's not a problem.

    We have about nine customers that are using Splunk.

    How are customer service and support?

    I've dealt with technical support and it's pretty good. They are helpful. I find them responsive. 

    How was the initial setup?

    The initial setup is not straightforward. It depends upon the IT infrastructure that the customer has. If they have a lot of security solutions, such as DLP and other security solutions, then it is more complicated. The more you have the more complicated it gets.

    The deployment of Splunk takes about three weeks.

    We have six or seven team members within our organization that can handle deployment and maintenance tasks. 

    What about the implementation team?

    I handled the implementation myself. It was done in-house. 

    What's my experience with pricing, setup cost, and licensing?

    Splunk requires a paid license. There's no free option. Customers have to pay for the license, implementation, support - everything.

    What other advice do I have?

    The solution can be deployed both on-premises and on the cloud. 

    I'd rate the solution at a nine out of ten. We've been very happy with the product.

    I would recommend the solution. It really is the best.

    Which deployment model are you using for this solution?

    Public Cloud
    Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
    PeerSpot user
    Buyer's Guide
    Download our free Splunk Enterprise Security Report and get advice and tips from experienced pros sharing their opinions.
    Updated: April 2025
    Buyer's Guide
    Download our free Splunk Enterprise Security Report and get advice and tips from experienced pros sharing their opinions.