Try our new research platform with insights from 80,000+ expert users
it_user859770 - PeerSpot reviewer
consultant at a non-profit with 1,001-5,000 employees
User
Easily tracks problems and their status
Pros and Cons
  • "I like the ease with which dashboards can be created."
  • "Splunk has give us the capability to easily track problems and their status."
  • "The only thing which can be improved is that they are too subjective on whom their Splunk4Good initiative can be applied. They market it as you only need to be a nonprofit, but there is more to it."

What is our primary use case?

We use Splunk for both monitoring and SIEM. Our security operations group uses Splunk to track user accounts which may have been compromised as well as follow those accounts through the organization.

How has it helped my organization?

Splunk has give us the capability to easily track problems and their status. Our security operations team has been able to use it to track where people login and what they do on those machines.

What is most valuable?

Personally, I like the capability of removing sensitive data before it goes into Splunk. I also like the ease with which dashboards can be created.

What needs improvement?

I like Splunk. The only thing which can be improved is that they are too subjective on whom their Splunk4Good initiative can be applied. They market it as you only need to be a nonprofit, but there is more to it.

Buyer's Guide
Splunk Enterprise Security
June 2025
Learn what your peers think about Splunk Enterprise Security. Get advice and tips from experienced pros sharing their opinions. Updated: June 2025.
861,490 professionals have used our research since 2012.

For how long have I used the solution?

More than five years.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
PeerSpot user
Splunk Architect at The Johns Hopkins University Applied Physics Laboratory
Real User
Speeds up root cause analysis and can help identify issues
Pros and Cons
  • "Speeds up root cause analysis and can help identify issues that your organization never realized were occurring."
  • "It helps streamline troubleshooting and log analysis."
  • "​On the technical side, it would be nice to see aspects of the recent acquisition of Phantom make it into the core Splunk Enterprise, not just become a part of the premium Enterprise Security.​"
  • "It can be tough to determine if you are getting all of the value out of your investment at times."

What is our primary use case?

Central repository for log collection and analysis in a complex environment. We have used it for a variety of use cases involving SIEM and operational support.

How has it helped my organization?

Speeds up root cause analysis and can help identify issues that your organization never realized were occurring. It helps streamline troubleshooting and log analysis.

What is most valuable?

It has a low barrier to entry, but it is extremely extensible, allowing it to be tailored to highly specific use cases. It makes searching through a wider variety of logs much quicker and enables you to correlate events from one log to another.

What needs improvement?

It can be tough to determine if you are getting all of the value out of your investment at times. However, our sales seems to be flexible and will work on an organization to organization basis to negotiate license terms. 

For how long have I used the solution?

One to three years.

How is customer service and technical support?

On the technical side, it would be nice to see aspects of the recent acquisition of Phantom make it into the core Splunk Enterprise, not just become a part of the premium Enterprise Security.

What's my experience with pricing, setup cost, and licensing?

Pricing can be a limiting factor. You have to continuously tune what you are bringing in and make sure what you bring in is of value. 

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Buyer's Guide
Splunk Enterprise Security
June 2025
Learn what your peers think about Splunk Enterprise Security. Get advice and tips from experienced pros sharing their opinions. Updated: June 2025.
861,490 professionals have used our research since 2012.
PeerSpot user
BS Systems Engineer at a tech services company with 501-1,000 employees
Real User
Makes use of all logs and takes proactive actions
Pros and Cons
  • "Integrity with many vendors: This simplifies the implementation and integration with different devices"
  • "Enterprise security: Splunk must work on clarifying the solution to customers and explain how to gain more from it."

What is our primary use case?

We used it to create a full security operations center (SOC) for our IT department by adding all network and security devices, the AD, and mail servers to it. Then Splunk started to receive their logs, it analyzed them, and provided useful reports.  

How has it helped my organization?

It helps the IT staff to monitor the full structure. It also makes use of all logs and takes proactive actions.

What is most valuable?

Integrity with many vendors: This simplifies the implementation and integration with different devices. 

What needs improvement?

Enterprise security: Splunk must work on clarifying the solution to customers and explain how to gain more from it.

For how long have I used the solution?

One to three years.
Disclosure: My company has a business relationship with this vendor other than being a customer. We are a partner with Splunk.
PeerSpot user
PeerSpot user
System Administrator at Abdullah Al-Othaim Markets
Real User
Searches logs from all devices and gives valuable information to the organisation
Pros and Cons
  • "Alerts when a server is malfunctioning, monitors external attacks, and takes action to stop spreading viruses."
  • "Make it easy to use and the cost cheaper. This will help all organisations to implement Splunk."

What is our primary use case?

  • Searches the logs for all network devices and server. 
  • Monitors clients' hardware, networking, and security operations. 
  • It is good for the administrator to use it when maintaining the whole IT Infrastructure.

How has it helped my organization?

Alerts when a server is malfunctioning, monitors external attacks, and takes action to stop spreading viruses.

What is most valuable?

Searches logs from all devices and gives valuable information to the organisation, so it can drill down on all reports and security threats. 

What needs improvement?

Make it easy to use and the cost cheaper. This will help all organisations to implement Splunk

Network Breach

No, we have not suffered a network breach.

Efficiency of Security Team

Yes, the solution has improved the efficiency of our security team.

For how long have I used the solution?

Trial/evaluations only.

What do I think about the stability of the solution?

No stability issues.

What do I think about the scalability of the solution?

No scalability issues.

How are customer service and technical support?

I have received a very good response from support that I have not seen in more than 10 years of my experience. 

Which solution did I use previously and why did I switch?

We are using OpManager to monitor server logs. 

What about the implementation team?

I implemented it myself.

What was our ROI?

It made our organization better through integration.

What's my experience with pricing, setup cost, and licensing?

Make it cheaper to help small organisations implement it easier. 

Which other solutions did I evaluate?

We evaluated QRadar.

What other advice do I have?

I have been using Splunk to increase my security experience. 

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
MS Alam - PeerSpot reviewer
MS AlamSystem Administrator at Abdullah Al-Othaim Markets
Real User

splunk is google for all logs in organisation.

PeerSpot user
Infrastructure Engineer at Zirous, Inc.
Real User
Top 20
Monitors all machine logins and actions taken on those machines under each user
Pros and Cons
  • "The ability to view all of these different logs, then drilling down into specific times or into specific data sources, has proved to be the greatest aspect in decreasing our troubleshooting overhead time."
  • "We did not encounter any issues with scalability. It is almost seamless to add new index (storage) or search (used to analyze the data) nodes to the cluster."
  • "I feel as though a major focus of upcoming releases should be set on Machine Learning, Predictive Analytics, and I would enjoy to see more security focused add-ons and apps developed by the vendor."

What is our primary use case?

Our primary use case of Splunk has been on the implementation side for clients. Splunk has proven, on multiple occasions, to be extremely useful in the proactive monitoring of clients' hardware, networking, and security operations. Some use cases that we have implemented include, but are not limited to, proactive account lockouts based on machine learning of a typical person's average number of failed login attempts, aggregation of a servers logs in order to predict downtime/maintenance/hardware failures quite accurately, as well as helping administrators of all sorts to gain a full picture of their environments under a single screen.

How has it helped my organization?

Splunk has helped our organization mainly on our increased use of the security side. We use Splunk to monitor all machine logins (both successful and unsuccessful) and actions taken on those machines under each user. We have set up some predictive and proactive models, which are programmed to take action on anything outside of the normal usage. These actions range from alerts being sent to the Splunk page, administrators being notified, and if escalated enough, automatic account locks.

What is most valuable?

The ability to view all of these different logs, then drilling down into specific times or into specific data sources, has proved to be the greatest aspect in decreasing our troubleshooting overhead time. The added security has proven effective as well, but given that we have not yet created the perfect model, we still find ourselves striving to develop a more efficient and predictive security analysis and action plan within Splunk.

What needs improvement?

Splunk has continually been increasing its features and also expanding and perfecting its core functionality. I would like to see it to continue to improve its predictive analytics and machine learning tools. It is not to be said that they are currently lacking, I don't believe it is, but given the current state and direction of the Information Technology world, I feel as though a major focus of upcoming releases should be set on Machine Learning, Predictive Analytics, and I would enjoy to see more security focused add-ons and apps developed by the vendor.

Network Breach

We did about a year and a half ago. The implementation was able to notify me 34 seconds after the initial breach had happened, but our implementation was already configured to auto-logout any "suspicious" users (our internal networking team had set this detection code up) which alleviated the problem, before it really became a problem for us.

Efficiency of Security Team

Immensely, I cannot stress enough the positive impact this has had on our security team.

Events per Day

Our personal implementation brings in only around 48GB to 48.5GB of events per day. Depending on the amount of remote workers in the office, it averages around 50 million events daily.

For how long have I used the solution?

One to three years.

What do I think about the stability of the solution?

We did not encounter any issues with stability.

What do I think about the scalability of the solution?

We did not encounter any issues with scalability. It is almost seamless to add new index (storage) or search (used to analyze the data) nodes to the cluster.

How are customer service and technical support?

I have not personally dealt with customer service/technical support.

Which solution did I use previously and why did I switch?

We did not use a different solution before. The closest thing that we would have done to this would have been personally scraping logs reactively, which cost us roughly two to three hours per issue that arose purely through log searching and remediation.

How was the initial setup?

The initial setup is very straightforward, unzipping a tar, creating a service, starting the service.

What about the implementation team?

My team was the team who had set up this implementation. I would be remiss if I didn't say that our level of expertise is quite high with an average of 4 Splunk certifications per person on my team.

What was our ROI?

ROI is estimated at saving my team roughly 10 to 12 man hours per week in troubleshooting for our company as well as what our profits had been from our services of installing, configuring, and supporting other clients with the product.

What's my experience with pricing, setup cost, and licensing?

Setup cost is cheap: It is free, it is user-friendly, and it is fast. 

I would highly recommend anyone evaluating this option to download the free trial which allows for the ingestion of 500MB of data per day in order to get a feel for what Splunk does at its core. It will get pricey once your ingestion rates start to sky rocket, but I would consider it expensive given the amount of information that it allows you to analyze and react on straight out-of-the-box.

Which other solutions did I evaluate?

We evaluated the ELK Stack, of which recently we have implemented with a customer who was looking for a more lightweight, cheaper alternative that would work "Good Enough". They felt they did not need all of the bells and whistles that came with Splunk.

What other advice do I have?

If you have an R&D department within your company that is looking for something new to increase the efficiencies and effectiveness of your company's operations, I would highly recommend having them get the free trial to test out.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
it_user717477 - PeerSpot reviewer
Account Manager at a tech services company with 10,001+ employees
Real User
Proactively monitor threats and reduces threat footprint, though professional support is too expensive
Pros and Cons
  • "Deployment server for deploying changes in one go."
  • "Professional support is great, but too expensive."

How has it helped my organization?

It was used for security event management on landscape hosted over AWS.

It helped the organisation to proactively monitor threats and reduce its threat footprint.

What is most valuable?

Deployment server for deploying changes in one go.

What do I think about the stability of the solution?

It is quite stable.

What do I think about the scalability of the solution?

No.

How are customer service and technical support?

Professional support is great, but too expensive. Otherwise content published over website is good.

Which solution did I use previously and why did I switch?

Not applicable.

What's my experience with pricing, setup cost, and licensing?

Do proper estimation on log ingestion per day as that will impact pricing and licensing.

Which other solutions did I evaluate?

It was the customer's choice.

What other advice do I have?

It provides a great range of plugins and one can really take great advantage of utilising inbuilt dashboards to derive the desired monitoring.

Our company consults for different customers and are in a good position to recommend the best solution to our clients.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
PeerSpot user
Security Architect at a energy/utilities company with 1,001-5,000 employees
Vendor
Some of the valuable features Machine learning, Common Information Model, and Log storage.
Pros and Cons
  • "Ease of correlation, creating correlation searches are easy and you can combine multiple sources with little effort"
  • "The GUI can be improved to include some of the capabilities that other BI solutions have."

How has it helped my organization?

  • We can do things in minutes instead of days.
  • We solve issues which we could not before since we have the data.
  • We can quickly search for almost anything across many log sources in seconds
  • Teams have the dashboards or alerts that they need

What is most valuable?

There are too many features to list, but here are a few:

  • Schema on the fly
  • Ease of on-boarding data
  • Machine learning
  • Apps or Splunk base.
  • Great list of apps to use and also build upon once you learn more about how Splunk works.
  • We build many of our own apps by leveraging the logic in the others.
  • Ease of correlation, creating correlation searches are easy and you can combine multiple sources with little effort
  • Data Models Acceleration for super fast searches across tens of millions of events
  • Common Information Model
  • Security Essentials App
  • Enterprise Security
  • Splunk SPL (Search Processing Language) is easy to learn and has IDE like capabilities
  • Log storage or compression is great and retention is not an issue
  • Dashboards are simple to create and the input options like Time Range, Text
  • Drop-downs are simple to create.
  • Integration with cloud solutions is great and keeps getting better.
  • Can get info from rest API’s easily and there are apps for services like ServiceNow, Azure, Office365, etc.

What needs improvement?

The GUI can be improved to include some of the capabilities that other BI solutions have. Basically, the layout is a little restrictive where you can’t resize all the panels to exactly how you would like them without tweaking some XML code. Over the years, they have really been improving in this area. I would think that will continue and this could become a non-issue.

What do I think about the stability of the solution?

There were no issues with stability.

What do I think about the scalability of the solution?

There were no issues with scalability.

How are customer service and technical support?

Technical support is excellent. They also have Splunk Answers, which is community driven and it great.

Which solution did I use previously and why did I switch?

We were not able to get the value we needed from the previous solution. It was too difficult or complex. With Splunk, we can do things we want and things we have not even dreamed of yet.

How was the initial setup?

The initial setup was straightforward. We had the POC up in minutes. Within days, we got more value out of this solution than our existing solution.

What's my experience with pricing, setup cost, and licensing?

While licensing can be a concern, there are ways to reduce the licensing costs including filtering some events. We have replaced many solutions with Splunk, which have more than paid for the Splunk licensing.

Which other solutions did I evaluate?

We evaluated ArcSight, QRadar, and LogRhythm.

What other advice do I have?

Do a PoC and you will be amazed. Also, check out the Splunk .conf sessions to see what is possible. If you are into security, watch Mark Russinovich’s RSA 2017 presentation about Sysmon. Check out free EDR type capabilities.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
MS Alam - PeerSpot reviewer
MS AlamSystem Administrator at Abdullah Al-Othaim Markets
Real User

agree with you Mr. Kent this machine have more valuable feature.

PeerSpot user
SVP, Technical Operations at a tech vendor with 201-500 employees
Vendor
Splunk has great interoperability with other applications through their SplunkBase app store.

What is most valuable?

Splunk has great interoperability with other applications through their SplunkBase app store. The apps can quickly provide visibility and streamline complex data mining tasks.

What needs improvement?

Unlike other cloud based analytics platforms, at the time of this writing Splunk Cloud is a dedicated instance per customer rather than a shared tenancy platform. While this is beneficial from an overall performance standpoint, the product lacks the seamless integrations one has come to expect from a cloud solution. This translates to a much stronger reliance on Splunk's support organization out of necessity, as the customer cannot make most changes in a self-service manner.

For how long have I used the solution?

We have been a Splunk customer for five years.

What was my experience with deployment of the solution?

Our Splunk Cloud deployment was a migration from an on-premise implementation of Splunk. The migration took much longer than expected due to constraints within Splunk's cloud team, but there were no technical issues with the launch.

How is customer service and technical support?

Customer Service:

The customer support team at Splunk is very good.

Technical Support:

The technical support team at Splunk is highly responsive and knowledgeable.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Buyer's Guide
Download our free Splunk Enterprise Security Report and get advice and tips from experienced pros sharing their opinions.
Updated: June 2025
Buyer's Guide
Download our free Splunk Enterprise Security Report and get advice and tips from experienced pros sharing their opinions.