We use a lot of sales metrics. We use machine learning models to provide sales forecasting. We create database connections and run a query on the database. The next step is to place the data into Splunk. We create indexes to get the data into the Splunk dashboard.
Data Scientist at a tech vendor with 201-500 employees
Offers the ability to analyse huge amounts of sales data and accurate prediction of sales forecasting
Pros and Cons
- "The ability to analyze huge amounts of sales data and accurate prediction of sales forecasting is the most valuable feature."
- "Splunk needs to be able to hold more days of data. At the moment it only holds three months of data."
What is our primary use case?
What is most valuable?
The ability to analyze huge amounts of sales data and accurate prediction of sales forecasting is the most valuable feature.
What needs improvement?
Splunk needs to be able to hold more days of data. At the moment it only holds three months of data. It needs more views and colors within the dashboard and the ability to have the flexibility to create a user-defined panel.
For how long have I used the solution?
We have been using Splunk for a year.
Buyer's Guide
Splunk Enterprise Security
June 2025

Learn what your peers think about Splunk Enterprise Security. Get advice and tips from experienced pros sharing their opinions. Updated: June 2025.
861,524 professionals have used our research since 2012.
What do I think about the stability of the solution?
The stability of Splunk is good enough.
What do I think about the scalability of the solution?
I think it's good, other than the ability to hold more than three months of data is lacking.
How was the initial setup?
The setup of Splunk was easy.
What about the implementation team?
There are six people in my team working with Splunk. I am not sure about other users, but we are a mix of data scientists, data engineers, software engineers, IT, and software engineers.
What other advice do I have?
I would rate Splunk as 8 out of 10.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.

Audit Remideation/Financial Manager at a tech services company with 1,001-5,000 employees
Flexible and scalable with good reporting
Pros and Cons
- "The logs on the solution are excellent."
- "It could be more user friendly, in terms of the end-user experience."
What is our primary use case?
The solution is primarily used to monitor the operating system for threats, specifically related to login threats. If someone trying to log-in, or somebody trying to break into the system, the idea is it will check that and catch things. It's mainly for external threats to the operating system.
How has it helped my organization?
The solution has improved our organization by providing a comprehensive picture of any external threats to the operating system. It improves asset control.
What is most valuable?
The logs on the solution are excellent. Mostly I see just the reports or the outcome, however, with the log portion, where you could actually take log entries and pass them through the system in order to create events or conditions, and get reports. You can set up your conditions to the logs that you invested into Splunk, and get the reports or the output that you want.
What needs improvement?
We're still going through it at this time. However, there are a few changes that could be made.
It could be more user friendly, in terms of the end-user experience. The end-user aspect of it could be more enhanced, whereby you could probably have a lot more people that could sign into the tool and look at the reports, and have the reports actually laid out in plain English. Usually, with tools like Audit Vault and Splunk, if you're not the IT person and you're not trained on that system and you're seeing all of the outputs, the language is something you have to convert.
Therefore, the end-user experience could be improved so that when you get those alerts and notifications, you could have supervisors and different people actually knowing what those reports mean instead of having someone convert them into something more easily digestible.
There should be more enhancements done to the end-user dashboards. Improved dashboards are always good. If you have an IT tech that's up there, and they're looking at the dashboards and they're seeing everything, it would help they could do events and have a dashboard that they could log into as a supervisor and see everything, and just get specific reports for specific areas.
For how long have I used the solution?
We've been using the solution for three years.
What do I think about the stability of the solution?
I can't really speak to the solution's stability beyond how I use it, which is for training. However, I've never experienced bugs or glitches on it and therefore believe it to be very reliable.
What do I think about the scalability of the solution?
The solution seems to be very adaptable, and if not, we'll figure it out what to do in the next couple of years when the program has developed more, and the general capabilities become apparent.
It is a log parsing tool, so if you take any type of log, operational or financial or security logs, and you put it in there, hopefully, we will find out that a log is a log, and you just create your events and you get the output that you want. Therefore, I don't foresee an issue with scalability per se.
How are customer service and technical support?
The technical support is pretty good. I would rate it at a seven out of ten. We're mostly happy with the level of service we receive from them.
What they probably need to do is help make the reports more manageable for the end-user or to help the end-user understand them more easily.
Which solution did I use previously and why did I switch?
We didn't previously use a different solution. We've only ever really used Splunk.
How was the initial setup?
The initial setup was not complex. It was pretty straightforward. It was already loaded on the environment. It's managed by a third party or service provider, therefore we just kind-of fell into the rhythm of using it pretty quickly.
What other advice do I have?
We're just a customer. We don't have a business relationship with Splunk.
We're using the latest version of the solution.
I'd advise those considering the solution to do some basic training before jumping into using the solution. It will help you understand how everything is supposed to work.
I'd rate the solution at an eight out of ten, due to the fact that it's more flexible than other solutions. I like the idea of taking a log, any log, and putting it into a tool and creating your events and your conditions in order to get the output that you're looking for. It's more scalable and flexible than other options on the market.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Buyer's Guide
Splunk Enterprise Security
June 2025

Learn what your peers think about Splunk Enterprise Security. Get advice and tips from experienced pros sharing their opinions. Updated: June 2025.
861,524 professionals have used our research since 2012.
System Administrator and DevOps Engineer at a tech services company with 10,001+ employees
Very straightforward, easy to configure, stable and scalable.
Pros and Cons
- "This is a straightforward solution, easy to configure."
- "This is a costly solution."
What is our primary use case?
Our primary use case of Splunk is for log monitoring and infrastructure monitoring. If we want to diagnose any issue in our application, we just push our application logs. This is on any client server using the universal forwarder logs on the Splunk server. After indexing, we can create a base log, and create attractive dashboards that are simple to understand and use. I'm a system administrator and we are customers of Splunk.
What is most valuable?
This is a straightforward solution, easy to configure and difficult to mess up.
What needs improvement?
Splunk is a very costly solution and I think it's the most expensive in the market in terms of costing. Splunk provides an application for infrastructure monitoring. If we're monitoring the docker with containers, we can't see the container name, only the ID. That's a big drawback.
For how long have I used the solution?
I've been using this solution for two years.
What do I think about the stability of the solution?
This is a stable solution. Deployment takes one person, it can be a system admin or an engineer.
What do I think about the scalability of the solution?
This is a scalable solution. We can do the clustering of it for large applications. We have around 15 users for this product.
How are customer service and technical support?
If I have any issues, I'll go to the community. I can generally get a response within a day. Although most of the documentation is good, some of it is unclear, particularly if you're new to the product.
How was the initial setup?
I think it takes around 10 minutes to install it on the server. On the client side, it takes around five minutes. I do the installation myself.
What other advice do I have?
If you're going with this solution, make sure that when implementing the ports are open. If they're not open, it creates problems with the server. Other than that, this is a very stable and very easy to configure product. We can easily deploy and easily use. Other similar solutions are difficult to configure, Splunk is the simplest. I've used three or four monitoring tools and Splunk is the easiest. If a company can afford it, this is a good product. We are planning to shift to another product because of the cost. We're searching for an open source or cheaper product.
I would rate this solution a nine out of 10. They lose one point for the price and lack of infrastructure support.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Engineer at a financial services firm with 201-500 employees
Great flexibility, pretty stable, and has great technical support
Pros and Cons
- "The flexibility of the solution is quite good."
- "The solution has a high learning curve for users. It's a little complicated when you're trying to figure out all the features and what they do."
What is our primary use case?
It's the primary place where I'd go to do an investigation if I want to see what's going on within an endpoint, or on a network, or with a user.
What is most valuable?
The flexibility of the solution is quite good.
The product is stable.
It offers good scalability if you are willing to pay.
The technical support on offer is responsive.
What needs improvement?
The solution has a high learning curve for users. It's a little complicated when you're trying to figure out all the features and what they do.
The solution needs a bit more functionality. For example, being able to save a search and select it when you're doing an investigation. I know you can create dashboards and things like that, however, sometimes being able to have a pre-saved search and just fill in whatever value you need would make everything so much easier.
For how long have I used the solution?
I've been using Splunk for four years so far. It's been a while.
What do I think about the stability of the solution?
I haven't had any stability issues with it. It's pretty stable. There aren't bugs or glitches. It doesn't crash or feeze.
What do I think about the scalability of the solution?
You can scale the solution, however, users need to be aware of the product increasing in cost as well.
How are customer service and technical support?
The technical support is very good. We're quite satisfied with the level of service provided. They are knowledgeable and responsive.
Which solution did I use previously and why did I switch?
When I came to the company, they were already using Splunk. It's only now that we're looking to possibly move to another vendor. The cost of Splunk is much too high.
How was the initial setup?
I wasn't here when this solution was put into place, however, from looking at the documentation and things like that, the setup is pretty involved. I'd say it's a bit more complex than straightforward.
What's my experience with pricing, setup cost, and licensing?
We find the solution to be quite expensive. Therefore, we're looking for other options.
I don't know of the exact costs, as licensing is handled by another department.
What other advice do I have?
We're just users. We don't have a business relationship with Splunk.
We're on a variation of version seven. I'm not sure of the exact one. It's not quite the latest.
I'd advise new users, if they have the budget for it, to go and take the training that they offer. Or, for casual users, you just want to spend as much time watching YouTube videos as you can. It will help lessen the learning curve.
As a solution, it's still pretty much industry standard. I would give it a nine out of ten overall, even though I have my gripes with it.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Engineer at a integrator with 11-50 employees
Has the ability to add the functionality you want but it is expensive
Pros and Cons
- "The initial setup is really straightforward. It's one of the easiest installations."
- "They should make data onboarding easier."
What is our primary use case?
Our primary use case is for monitoring and cybersecurity.
What needs improvement?
The clusters are hard. It has too many moving parts.
They should make data onboarding easier.
For how long have I used the solution?
One to three years.
What do I think about the scalability of the solution?
Its ability to scale nicely is one of Splunk's strengths. You just horizontally add another machine and you get your scalability.
How are customer service and technical support?
Which solution did I use previously and why did I switch?
Our clients switch from Nagios or other monitoring solutions because the other solutions were not as flexible as Splunk. With Splunk, you can do things very programmatically. With a help of a developer and included SDK you can add needed functionality.
How was the initial setup?
The initial setup is really straightforward. It's one of the easiest installations.
This product doesn't have any kind of dependencies, it just worked from one package. Install it and boom, you have a working solution.
What about the implementation team?
What's my experience with pricing, setup cost, and licensing?
Splunk is on expensive side.
There are some premium add-ons like Splunk Enterprise Security or ITSI which makes it more expensive.
What other advice do I have?
I would advise to get Splunk professional services from Splunk.
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner.
Architecture and Security Team Leader at CV Akbar Panjaya
It helps us uncover bottlenecks in the network, but needs better local technical support
Pros and Cons
- "It helps us uncover bottlenecks in the network."
- "it can explain to management about what kind of traffic is visiting the network. It can also explain other traffic coming in and out, along with protecting against malware."
- "The product was difficult to back up the first time."
- "Splunk needs local technical support."
What is our primary use case?
We were using Splunk for our networking to know exactly what kind of the traffic was going from one network to another network because we had a lot of the connections on other sites.
How has it helped my organization?
it can explain to management about what kind of traffic is visiting the network. It can also explain other traffic coming in and out, along with protecting against malware.
What is most valuable?
All the features are valuable. It helps us uncover bottlenecks in the network.
What needs improvement?
Splunk should be able to integrate with other product using the free version.
The product was difficult to back up the first time.
For how long have I used the solution?
One to three years.
What do I think about the stability of the solution?
The stability is fine.
We have two people maintaining it.
How are customer service and technical support?
Splunk needs local technical support.
Which solution did I use previously and why did I switch?
We did not use another solution previously.
How was the initial setup?
The deployment was great and took three to four days.
What's my experience with pricing, setup cost, and licensing?
The pricing and licensing of the product are quite high.
What other advice do I have?
Splunk is great product, especially for my organization.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Centralized log monitoring is pivotal for us
Pros and Cons
- "The most valuable feature of Splunk is the log monitoring."
- "If possible, we would like to have not only a log monitoring system but a network monitoring feature in this solution as well."
What is our primary use case?
We need something to collect all our logs in a centralized solution. We have several servers but we don't have any log collection system.
How has it helped my organization?
Without Splunk or a similar product, if I want to check the log files every day, I have to log in to the individual hardware components in our system. I have to log in to the firewall, I have to log in to Windows. There are so many devices I would have to manually log into, one-by-one. It would take a very long time for me.
Also, we don't have a dashboard so we don't know which issues are critical. When we use a centralized log monitoring system we can see things on the dashboard and it is easier for the IT manager or an IT engineer to take corrective action in the system.
What is most valuable?
The most valuable feature of Splunk is the log monitoring.
What needs improvement?
If possible, we would like to have not only a log monitoring system but a network monitoring feature in this solution as well.
What do I think about the stability of the solution?
It's very stable.
Which solution did I use previously and why did I switch?
Up until we trialed Splunk we did not have any solution. We used Splunk because we don't have anything to monitor our system. I contacted our local vendor in Vietnam, and they suggest using the trial version of Splunk to see how it works in our environment. This is the main reason I trialed Splunk. We just used the trial version in our office and, since it expired, we haven't used it.
How was the initial setup?
For me, the initial setup was not too complex. For an IT person like me, it was okay.
Our local vendor knows Splunk very well. He had already implemented Splunk for another customer. I called him to our office to have him install the Splunk. It took a couple of hours for him to finish.
What about the implementation team?
We used a consultant for the deployment, from KDDI Vietnam. Our experience with him was good.
What other advice do I have?
Because it was a trial version, I was the only one who used it in our company.
I kept some snapshots from our trial with the Splunk system and we are preparing a proposal to submit to our manager in Vietnam. If in the near future we have enough money to purchase the system, we will invest in this system for our company.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Sr. Manager Information Security at Tapal Tea (Private) Limited
The search and query feature is very fast but due to the log size limit, we did not get the full benefit
What is our primary use case?
Log collection and search.
How has it helped my organization?
The search and query feature is very fast but due to the log size limit (in trial version), we did not get the full benefit.
What is most valuable?
Selecting the relevant events and records.
What needs improvement?
Due to the size limit, we could not see the full product.
For how long have I used the solution?
Trial/evaluations only.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.

Buyer's Guide
Download our free Splunk Enterprise Security Report and get advice and tips from experienced pros
sharing their opinions.
Updated: June 2025
Product Categories
Security Information and Event Management (SIEM) Log Management IT Operations AnalyticsPopular Comparisons
CrowdStrike Falcon
Microsoft Sentinel
IBM Security QRadar
Elastic Security
Splunk AppDynamics
Elastic Observability
Grafana Loki
Security Onion
Palantir Foundry
Cortex XSIAM
Buyer's Guide
Download our free Splunk Enterprise Security Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- Which would you recommend to your boss, IBM QRadar or Splunk?
- What are some of the best features and use-cases of Splunk?
- What SOC product do you recommend?
- Splunk as an Enterprise Class monitoring solution -- thoughts?
- What is the biggest difference between Dynatrace and Splunk?
- IBM QRadar is rated above competitors (McAfee, Splunk, LogRhythm) in Gartner's 2020 Magic Quandrant. Agree/Disagree?
- What are the advantages of ELK over Splunk?
- How does Splunk compare with Azure Monitor?
- New risk scoring framework in the Splunk App for Enterprise Security -- thoughts?
- Splunk vs. Elastic Stack