We use it for log analysis and alerting, and our stock analysts use it.
I have used the product for more than five years. Then, in the cloud, I have used it for probably a year. It scales better in the cloud than on-premise.
We use it for log analysis and alerting, and our stock analysts use it.
I have used the product for more than five years. Then, in the cloud, I have used it for probably a year. It scales better in the cloud than on-premise.
It is a place for all our logs, and everything goes in one place. The stock analysts and security people use one single dashboard (one single location) to check our logs.
Every product needs improvement. If we can get a faster product, we will take it. There are new services which are coming up. If Splunk can catch up with the speed of Amazon, and with the integration, instead of us waiting for another year or so, that would be good.
We would like more integrations with other cloud products, not just AWS, e.g., Azure.
The stability is good. We stress it at 98 percent.
The AWS scalability is pretty good. We currently have it running on three servers.
Other teams have told me that the technical support is pretty good.
For the few integrations that we have already made, these have been easy to do.
We have seen ROI.
Splunk is not free.
I would recommend trying different stuff based on your company's needs and log types.
We like the product.
Its performance, scalability and most importantly the innovative way of collecting and presenting data.
Fast search! Imagine a scenario with an application environment where a couple of modules are based at a different servers. There is a system issue and a check needs to be completed in a timely manner. Traditionally engineers would have to login to the servers, navigate to different folders and load the log files to check for errors. Splunk can give this at a glance for all of the systems at once! Furthermore a “trap” of known errors could be saved and a real time alert setup to send an email in a meaningful way with relevant details (e.g. priority, affected systems) and instructions what needs to be done next.
Helpful for systems support, monitoring of the operations and deliveries, analysing trends and performance. Great for making sense of the application log’s events for business needs - e.g. requests per day, completed tasks per user, exceptions, KPI etc.
It can be easier to setup and adding new sources which Splunk are improving with every new version.
I have used it for two years.
No issues encountered.
It's running great given the information it processes.
Really scalable solution. Could be split into soft/hard forwarders if needed and even completed in an HA setup.
Splunk have dedicated staff trying to change the world for the better.
Technical Support:Splunk have introduced their own certification path which guarantees that the technical support will have the needed expertise.
I am familiar that there are other solutions out there but I haven't used them. Started with Splunk.
The initial setup requires some good analysis - what would be collected, from where, how to group the incoming data in virtual folders and indexes so it make sense and ease/scope the search later on. Apart from that the initial application setup is straightforward.
Implemented in house with the support of the vendor with high level of expertise.
I'm not sure about the money but in saved time and a new kind of visibility for the system/business process this product has been revolutionary in the working environment. The demand for deeper integration and more details hasn't stopped since the initial implementation and we have moved on from just technical and business reports, KPI reports from other systems and we keep building new alerts, dashboards and reports as per new requirements.
Not sure about the cost but I have heard it can get pretty costly for an Enterprise grade scale as the environment I work in. For home it is free up to 500Mb a day. Day-to-day cost for the product itself is costing just system resources, however the development work that needs to be completed for new requests and keeping the old one up-to-date can raise the budget according to the expertise needed.
Go for it and be brave. Experiment, add, remove, modify. Keep what is not working until it is working how you want and then delete the rest. Make a library of useful search queries and a diagram of systems and related files included in the indexes. Do not allow access for everyone to run DB queries as per the other forms of DB access. Install 3rd party modules and play with them. Collect system events for the OS and relate it to application performance. Trap the errors you have identified, create alerts and follow name convention for email subject (e.g. priority, type, system, description).
The solution is primarily used to monitor the operating system for threats, specifically related to login threats. If someone trying to log-in, or somebody trying to break into the system, the idea is it will check that and catch things. It's mainly for external threats to the operating system.
The solution has improved our organization by providing a comprehensive picture of any external threats to the operating system. It improves asset control.
The logs on the solution are excellent. Mostly I see just the reports or the outcome, however, with the log portion, where you could actually take log entries and pass them through the system in order to create events or conditions, and get reports. You can set up your conditions to the logs that you invested into Splunk, and get the reports or the output that you want.
We're still going through it at this time. However, there are a few changes that could be made.
It could be more user friendly, in terms of the end-user experience. The end-user aspect of it could be more enhanced, whereby you could probably have a lot more people that could sign into the tool and look at the reports, and have the reports actually laid out in plain English. Usually, with tools like Audit Vault and Splunk, if you're not the IT person and you're not trained on that system and you're seeing all of the outputs, the language is something you have to convert.
Therefore, the end-user experience could be improved so that when you get those alerts and notifications, you could have supervisors and different people actually knowing what those reports mean instead of having someone convert them into something more easily digestible.
There should be more enhancements done to the end-user dashboards. Improved dashboards are always good. If you have an IT tech that's up there, and they're looking at the dashboards and they're seeing everything, it would help they could do events and have a dashboard that they could log into as a supervisor and see everything, and just get specific reports for specific areas.
We've been using the solution for three years.
I can't really speak to the solution's stability beyond how I use it, which is for training. However, I've never experienced bugs or glitches on it and therefore believe it to be very reliable.
The solution seems to be very adaptable, and if not, we'll figure it out what to do in the next couple of years when the program has developed more, and the general capabilities become apparent.
It is a log parsing tool, so if you take any type of log, operational or financial or security logs, and you put it in there, hopefully, we will find out that a log is a log, and you just create your events and you get the output that you want. Therefore, I don't foresee an issue with scalability per se.
The technical support is pretty good. I would rate it at a seven out of ten. We're mostly happy with the level of service we receive from them.
What they probably need to do is help make the reports more manageable for the end-user or to help the end-user understand them more easily.
We didn't previously use a different solution. We've only ever really used Splunk.
The initial setup was not complex. It was pretty straightforward. It was already loaded on the environment. It's managed by a third party or service provider, therefore we just kind-of fell into the rhythm of using it pretty quickly.
We're just a customer. We don't have a business relationship with Splunk.
We're using the latest version of the solution.
I'd advise those considering the solution to do some basic training before jumping into using the solution. It will help you understand how everything is supposed to work.
I'd rate the solution at an eight out of ten, due to the fact that it's more flexible than other solutions. I like the idea of taking a log, any log, and putting it into a tool and creating your events and your conditions in order to get the output that you're looking for. It's more scalable and flexible than other options on the market.
Log collection and search.
The search and query feature is very fast but due to the log size limit (in trial version), we did not get the full benefit.
Selecting the relevant events and records.
Due to the size limit, we could not see the full product.
Alerts when a server is malfunctioning, monitors external attacks, and takes action to stop spreading viruses.
Searches logs from all devices and gives valuable information to the organisation, so it can drill down on all reports and security threats.
Make it easy to use and the cost cheaper. This will help all organisations to implement Splunk.
No, we have not suffered a network breach.
Yes, the solution has improved the efficiency of our security team.
No stability issues.
No scalability issues.
I have received a very good response from support that I have not seen in more than 10 years of my experience.
We are using OpManager to monitor server logs.
I implemented it myself.
It made our organization better through integration.
Make it cheaper to help small organisations implement it easier.
We evaluated QRadar.
I have been using Splunk to increase my security experience.
The analytics and querying the indices is super easy.
The data representation options in the dashboards are excellent.
Multiple datasource/filetypes are supported and each can be customized in a few clicks.
Security administration and user access control is pretty basic. This can be improved.
The user access control could be much more granular, so that the admins can control r/w/x access for specific features of the product like dashboards, etc.
If this is improved, with a mapping against LDAP roles, it would be excellent.
We had no stability issues.
We had no scalability issues.
Technical support and the online community are some of the best for any product.
We did not have a previous solution.
The setup was quite easy and there is lot of technical documentation for handholding you through the process.
Pricing and licensing is quite expensive. But for the value the product provides, it seems at par in the market.
We looked at IBM SmartCloud Analytics and Log Analytics.
Please watch out for the licensing agreement. There are a lot of IP specific clauses that Splunk has included in their license agreement. Per my understanding, any plugin available in the community cannot be used OOB, due to licensing restrictions. (This might be specific to our organization.)
It alerted many situations before other monitoring systems identified that there is a critical issue.
VMware and security device integration looks a bit complex.
I have used Splunk for almost three years.
As of now, we have had no issues with stability. It is running like a charm.
From a nodes perspective, there have been no scalability issues.
I can say that support is good.
We never used other solutions.
We used the Splunk Cluster setup. It was a bit complex to set up, but management-wise and stability-wise, it was awesome.
License costs fall under the NDA, but Splunk license costs are public, I believe.
We evaluated Logstash and others, but Splunk plays a pivotal role.
I would strongly recommend this product, as it would be very beneficial for service operations and management.
We are resellers. We provide solutions to our clients.
Splunk is primarily used for developing CM solutions that are based on the Splunk platform for future security operation center development.
We are concentrating on assisting in the development of a security monitor as well as analysis.
If I am not mistaken, it's a standard CM system for identification, security verification, and event monitoring.
In my opinion, it is too expensive for our projects.
It is very competitive for small and medium businesses. Perhaps some should be set aside for developing markets. To begin with, similar to the current market, there may be some special conditions for large transactions.
In the next releases, I would like to see more pricing flexibility. It's a subscription-based service, and they don't sell professional licenses.
In some cases, particularly with large projects, we are not competitive in terms of pricing when compared to IBM QRadar and other solutions; even if we offer the maximum discount available, our prices remain uncompetitive.
We have been selling Splunk for approximately five years.
The scalability is good. It can be added on-demand in increments of one gigabyte or ten gigabytes. It's a per-gigabyte license, and you can add whatever you need at the time.
Our projects are sized per our current IT infrastructure.
Splunk is used by 10 of our customers.
Our team provides technical support.
I have not communicated with technical support.
We no longer resell Checkmarks.
We were unable to assist in establishing their business on-premises because It could have been too expensive for our clientele.
Installing Splunk is not difficult, but it can be complicated in some cases.
The issue is the integration with the customer's system, as well as the configuration of the rules for correlation, log collecting, and analysis.
It has good documentation and guides, but the main works should be focused on customer needs and customer resources for monitoring.
It can take three months to complete the installation.
We have a team of three certified engineers who will deploy and maintain this solution.
The licensing fees and pricing models could be reduced.
It's a yearly subscription.
They don't sell professionally because it's a subscription service. As a result, it is only a subscription service that is dependent on the customer's IT infrastructure.
We do not sell Compliance Control Limited solutions because our focus is on auditing and independent security assessments. We put an end to our selling program with Checkmarks.
I would recommend this solution to others. Splunk is appropriate for small to medium-sized projects, and it should be calculated for large projects.
It's one of the best CM solutions on the market for monitoring, and correlation, as well as IT monitoring security.
I would rate Splunk an eight out of ten.
Splunk - SIEM