No more typing reviews! Try our Samantha, our new voice AI agent.
reviewer1478619 - PeerSpot reviewer
IT System Developer/Admin at a manufacturing company with 10,001+ employees
Real User
Jan 3, 2021
A stable, scalable solution with comprehensive dashboards and helpful technical support
Pros and Cons
  • "The scalability of the solution is amazing because it can collect a lot of data and you can have your own structure to monitor this data."
  • "An area of improvement would be the licensing of the solution. They need a free license, which would allow faster lead times."

What is our primary use case?

The primary use case of this solution is to monitor Cyber Mission databases.

I create the diagrams to create an architecture that is then implemented. However, creating these diagrams are for my own learnings since these implementations are usually already available in the cloud office logs.

What is most valuable?

The features I have found most valuable are the dashboards. 

I monitor the complete capacity that users are using in the company.

What needs improvement?

An area of improvement would be the licensing of the solution. They need a free license, which would allow faster lead times.

They also need to update their documentation.

What do I think about the stability of the solution?

The solution is stable.

Buyer's Guide
Splunk Enterprise Security
August 2026
Learn what your peers think about Splunk Enterprise Security. Get advice and tips from experienced pros sharing their opinions. Updated: August 2026.
914,109 professionals have used our research since 2012.

What do I think about the scalability of the solution?

The scalability of the solution is amazing because it can collect a lot of data and you can have your own structure to monitor this data.

How are customer service and support?

The customer service/technical support was helpful and they answered my questions as best they could.

How was the initial setup?

The setup was easy, but you have to have a VPN connection depending on the security protocols in place.

What about the implementation team?

The deployment was in-house and took about two days with the correct licenses and permissions.

What other advice do I have?

It is important to define different guidelines to integrate Splunk in development, QA, and production deployments. Additionally, define the applications that will be used and the configuration of the databases to collect the data. If this is not done, there will be a lot of issues due to, for example, master access or permissions to use the database collector and blocks.

Which deployment model are you using for this solution?

Hybrid Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Amazon Web Services (AWS)
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
reviewer1453023 - PeerSpot reviewer
CSSP Manager at a tech services company with 51-200 employees
MSP
Dec 20, 2020
Good at log collection and log management; not ideal for monitoring
Pros and Cons
  • "Splunk is good at log collection and log management."
  • "This is not really a monitoring solution."
  • "I'm a security manager and Splunk is not a good solution for my needs and not as good as other products I've used."

What is our primary use case?

I'm the CSSP manager and we are customers of Splunk. 

What is most valuable?

Splunk is good at log collection and log management.

What needs improvement?

I'm a security manager and Splunk is not a good solution for my needs and not as good as other products I've used. I really think they just overreached and are marketing the solution as something that it really isn't. It's really not an SIEM product. It's really not a monitoring solution. If Splunk wants to get into SIEM, they need to make a totally new product. They should just leave SIEM, it's not their thing, not what they do. They're good at log collection and indexing. Stick to it. There are some things with log collection and log retention capabilities that they could actually improve instead of trying to create products for all these other different areas. I don't want their next release, I would rather just kind of scale back on some of the extras, and just really focus on log collection and log retention. I'd like to have more options on how I can perform those features with their products. I'd like to see a lot more integration with other products.

For how long have I used the solution?

I've been using this solution for three years. 

What do I think about the stability of the solution?

Once you set up the solution, you don't really have to worry about it. It's very stable. I like the fact that you can pretty much just patch the OS, and it doesn't really affect how Splunk runs. With a lot of products, you almost have to wait for that company to implement a new patch or version of the product before you can upgrade the server it's on, or anything like that. Or you can't upgrade, you just have to go with whatever they give you, because they're giving you an appliance or something. I like the fact that Splunk allows you to integrate and still run as Splunk and still be compliant with most vulnerabilities out there without affecting functionality.

What do I think about the scalability of the solution?

The solution is extremely scalable. We probably have about five or six users, so all our system administrators use it, they're the ones that implement it. Right now, just the CIO, the CTO, and there's a ISSM who has access. There are plans to add more people once we fully implement the Enterprise Security solution. We have admins responsible for maintenance.

How was the initial setup?

The initial setup is kind of complex but I think it's an issue we have and not connected to the solution. We're still deploying. The company didn't have an implementation strategy, they're kind of just flying by the seat of their pants which wasn't a great plan. We're doing it ourselves, we didn't use an integrator. 

What's my experience with pricing, setup cost, and licensing?

We have a 100 gig annual license. I'm not sure of the cost. Their licensing is based on the amount of data you collect. There is an additional cost for Enterprise Security. If there are any other kind of applications, the APIs that we created that we want to add, there are costs for most of those as well. Their pricing structure really could use a revamp. They really need to review and look at that and see if there's a better way that they can do it. Elasticsearch is a little cheaper and a better product in my view. 

What other advice do I have?

It's important to prepare. You can't just get a solution and start to implement it. A big part of that needs to be preparation, and in IT, we're not great at that. I would go with Elastic, a similar product but better. The licensing is a little different but it gives you a little more freedom to do things. It's really flexible with what you can do and versatile in how you can use it. Splunk is still top when it comes to log collection. If you wanted anything more than that, you should probably look into using several different products. There isn't really one product that you're going to find that's going to give you that coverage and I just like the versatility of using several different products. There are some other things you can use that actually do a better job at the correlation part. 

I would rate this solution a seven out of 10. 

Which deployment model are you using for this solution?

Hybrid Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Buyer's Guide
Splunk Enterprise Security
August 2026
Learn what your peers think about Splunk Enterprise Security. Get advice and tips from experienced pros sharing their opinions. Updated: August 2026.
914,109 professionals have used our research since 2012.
Santhosh Kandadi - PeerSpot reviewer
Assistant Vice President at Synchrony
Real User
Dec 19, 2020
Easy to use with a simple setup and great integration capabilities
Pros and Cons
  • "The initial setup is pretty straightforward."
  • "Its ease of usage and its many integrations make it a great product."
  • "On-premises scaling of the solution is a bit more limited than it is on the cloud."

What is our primary use case?

We primarily use the solution for monitoring our infrastructure.

What is most valuable?

The models that we use are pretty mature at this point, which means we can be assured we are given the best use cases right out of the box.

We can just plug into the applications and everything is set up. There's very little configuration necessary.

The integrations that are offered with different tools are all very good. They offer integrations for all levels of security and have offerings from some of the other major solutions in the space.

The initial setup is pretty straightforward.

What needs improvement?

Over the years, I know they've been doing what they can to continue to add integration capabilities to their solution. If they continue to do that, that would be ideal. However, beyond that, there really aren't any features that I find to be lacking in any part of the solution.

On-premises scaling of the solution is a bit more limited than it is on the cloud.

The pricing of the solution needs to be a bit lower.

It would be ideal if the hardware could meet more universal global regulatory requirements. It would be great it the solution better aligned with global standards.

For how long have I used the solution?

I've been working with the solution for three to four years at this point.

What do I think about the scalability of the solution?

In terms of the cloud, scalability is very straightforward. It's just about as expansive as we want to go. When it comes to an on-premise deployment, there might be some scalability limitations. We've found we just have to cut hard on the resources as it does a lot of processing. Whereas the cloud is easy and has very little limitation, I'd advise others that on-premise may have some difficulties. 

On-premises, it's definitely on the customer to ensure they have the right plates. If they're concerned and they need 100% scalability, it's best to be on the cloud.

How are customer service and technical support?

Technical support is very good. They know their product and they are responsive to requests. We're satisfied with the level of service provided to us.

How was the initial setup?

We didn't have any issues with the initial setup. It's not too complex. We found the process to be very straightforward and very simple.

What's my experience with pricing, setup cost, and licensing?

While I do understand that it is a premium tool, they could work to make it a bit less in terms of cost. It's a bit expensive.

What other advice do I have?

We use a mixture of public and private cloud deployments.

I would definitely recommend the solution, having seen it work for others so well. Its ease of usage and its man integrations make it a great product. The way you can access whatever you need on the solution is very similar to a Google bar where you can search for anything you need. It's just a super quick responsive, product.

Overall, I would rate it a perfect ten out of ten. We have no complaints.

Which deployment model are you using for this solution?

Public Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
it_user1234167 - PeerSpot reviewer
General Manager at Intersoft S.A.
Reseller
Dec 16, 2020
A great solution for application management, security and compliance
Pros and Cons
  • "The correlation capabilities are the first value that our clients say they like with Splunk."
  • "I would recommend Splunk to any company: small, medium, and large."
  • "The difficult part is related to integration with sources of data that are used to create the logs as this depends on the infrastructure of the client."
  • "The support is not so good, I would only give them a rating of six or seven."

What is our primary use case?

We use Splunk for security and also PCI compliance.

We have installed and implemented this solution for several clients in Bolivia with our team. We have received training from Splunk directly, and we have also provided training to our clients.

We deploy two versions: one for on-premise and one for the cloud.

Most of our customers purchase Splunk because they required a tool for gathering and collecting all of the logs from the infrastructure in order to make a correlation between data and to spot patterns surrounding security incidents.

What is most valuable?

The correlation capabilities are the first value that our clients say they like with Splunk. Another benefit is that they can connect to any device or log from any device from anywhere.

It's easy, the tool is very easy to install and set up. 

What needs improvement?

They could have more dashboards done or predefined so our clients could use them directly in order to have more information ready to use.

The difficult part is related to integration with sources of data that are used to create the logs as this depends on the infrastructure of the client.

For how long have I used the solution?

We have been using this solution for more than five years.

What do I think about the stability of the solution?

Stability-wise, it's great.

What do I think about the scalability of the solution?

We do not require much scalability here because the clients are not so big; however, the hardware where we installed the products was enough to handle all the transactions of Splunk.

How are customer service and technical support?

The support is not so good, I would only give them a rating of six or seven.

They should provide support in Spanish here in Latin America. Their response time to inquires or requirement tickets is too long. It should be shorter.

How was the initial setup?

Deployment took us two weeks.

What other advice do I have?

I would recommend Splunk to any company: small, medium, and large.

Splunk is a great tool but you should get a partner who knows what they are doing, implementation-wise. 

On a scale from one to ten, I would give Splunk a rating of nine.

Disclosure: My company has a business relationship with this vendor other than being a customer. Reseller
PeerSpot user
reviewer1062186 - PeerSpot reviewer
Sr. IT Manager at a pharma/biotech company with 10,001+ employees
Real User
Dec 16, 2020
Good log aggregation and scales well, with good technical support that is responsive and helpful
Pros and Cons
  • "The most valuable feature is that it's very good for log aggregation."
  • "Splunk is very complex. The implementation and the scanning of the logs can be difficult."

What is our primary use case?

We are using Splunk to look at the logs, and see what is happening.

What is most valuable?

The most valuable feature is that it's very good for log aggregation.

What needs improvement?

Splunk is very complex. The implementation and the scanning of the logs can be difficult.

For how long have I used the solution?

I have been using Splunk for approximately three years.

What do I think about the stability of the solution?

In general, Splunk is stable.

What do I think about the scalability of the solution?

It's a scalable product. it's pretty good.

How are customer service and technical support?

Technical support is usually pretty good.

They are responsive, knowledgeable, and helpful.

How was the initial setup?

The initial setup was relatively straightforward.

What's my experience with pricing, setup cost, and licensing?

The price is comparable.

What other advice do I have?

I would rate Splunk and eight out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Data Scientist at a tech vendor with 201-500 employees
Real User
Dec 14, 2020
Offers the ability to analyse huge amounts of sales data and accurate prediction of sales forecasting
Pros and Cons
  • "The ability to analyze huge amounts of sales data and accurate prediction of sales forecasting is the most valuable feature."
  • "Splunk needs to be able to hold more days of data. At the moment it only holds three months of data."

What is our primary use case?

We use a lot of sales metrics. We use machine learning models to provide sales forecasting. We create database connections and run a query on the database. The next step is to place the data into Splunk. We create indexes to get the data into the Splunk dashboard.

What is most valuable?

The ability to analyze huge amounts of sales data and accurate prediction of sales forecasting is the most valuable feature. 

What needs improvement?

Splunk needs to be able to hold more days of data. At the moment it only holds three months of data. It needs more views and colors within the dashboard and the ability to have the flexibility to create a user-defined panel.

For how long have I used the solution?

We have been using Splunk for a year. 

What do I think about the stability of the solution?

The stability of Splunk is good enough.

What do I think about the scalability of the solution?

I think it's good, other than the ability to hold more than three months of data is lacking.

How was the initial setup?

The setup of Splunk was easy.

What about the implementation team?

There are six people in my team working with Splunk. I am not sure about other users, but we are a mix of data scientists, data engineers, software engineers, IT, and software engineers.

What other advice do I have?

I would rate Splunk as 8 out of 10.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
reviewer1062186 - PeerSpot reviewer
Sr. IT Manager at a pharma/biotech company with 10,001+ employees
Real User
Dec 8, 2020
Log aggregation helps us quickly detect widespread threats, but it can be resource-heavy
Pros and Cons
  • "The most valuable feature is the log aggregation, being able to scan through all of the logs."
  • "Queries are not always as easy or straightforward as they might be, so it can be difficult to figure out what you need to look for."

What is our primary use case?

We use Splunk for log analysis and security monitoring.

How has it helped my organization?

Splunk allows us to look at logs from different groups within NIH and see if there's a widespread threat or issue.

What is most valuable?

The most valuable feature is the log aggregation, being able to scan through all of the logs.

What needs improvement?

Queries are not always as easy or straightforward as they might be, so it can be difficult to figure out what you need to look for.

In the next release of this product, I would like to see it offer more recommendations as to what needs to be done.

For how long have I used the solution?

We have been using Splunk for between two and three years.

What do I think about the stability of the solution?

In terms of stability, the product seems to work just fine. We haven't had any problems with it.

What do I think about the scalability of the solution?

It can be somewhat of a resource hog; some of the scans can take a while. We do plan to increase our usage in the future.

How are customer service and technical support?

Technical support for Splunk is good.

How was the initial setup?

The initial setup is relatively straightforward.

What about the implementation team?

There were consultants involved in the deployment.

What other advice do I have?

I would rate this solution a seven out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
reviewer1317924 - PeerSpot reviewer
Audit Remideation/Financial Manager at a tech services company with 1,001-5,000 employees
Real User
Nov 28, 2020
Flexible and scalable with good reporting
Pros and Cons
  • "The logs on the solution are excellent."
  • "The solution has improved our organization by providing a comprehensive picture of any external threats to the operating system and improves asset control."
  • "It could be more user friendly, in terms of the end-user experience."

What is our primary use case?

The solution is primarily used to monitor the operating system for threats, specifically related to login threats. If someone trying to log-in, or somebody trying to break into the system, the idea is it will check that and catch things. It's mainly for external threats to the operating system.

How has it helped my organization?

The solution has improved our organization by providing a comprehensive picture of any external threats to the operating system. It improves asset control.

What is most valuable?

The logs on the solution are excellent. Mostly I see just the reports or the outcome, however, with the log portion, where you could actually take log entries and pass them through the system in order to create events or conditions, and get reports. You can set up your conditions to the logs that you invested into Splunk, and get the reports or the output that you want. 

What needs improvement?

We're still going through it at this time. However, there are a few changes that could be made.

It could be more user friendly, in terms of the end-user experience. The end-user aspect of it could be more enhanced, whereby you could probably have a lot more people that could sign into the tool and look at the reports, and have the reports actually laid out in plain English. Usually, with tools like Audit Vault and Splunk, if you're not the IT person and you're not trained on that system and you're seeing all of the outputs, the language is something you have to convert.

Therefore, the end-user experience could be improved so that when you get those alerts and notifications, you could have supervisors and different people actually knowing what those reports mean instead of having someone convert them into something more easily digestible. 

There should be more enhancements done to the end-user dashboards. Improved dashboards are always good. If you have an IT tech that's up there, and they're looking at the dashboards and they're seeing everything, it would help they could do events and have a dashboard that they could log into as a supervisor and see everything, and just get specific reports for specific areas.

For how long have I used the solution?

We've been using the solution for three years.

What do I think about the stability of the solution?

I can't really speak to the solution's stability beyond how I use it, which is for training. However, I've never experienced bugs or glitches on it and therefore believe it to be very reliable.

What do I think about the scalability of the solution?

The solution seems to be very adaptable, and if not, we'll figure it out what to do in the next couple of years when the program has developed more, and the general capabilities become apparent. 

It is a log parsing tool, so if you take any type of log, operational or financial or security logs, and you put it in there, hopefully, we will find out that a log is a log, and you just create your events and you get the output that you want. Therefore, I don't foresee an issue with scalability per se.

How are customer service and technical support?

The technical support is pretty good. I would rate it at a seven out of ten. We're mostly happy with the level of service we receive from them.

What they probably need to do is help make the reports more manageable for the end-user or to help the end-user understand them more easily.

Which solution did I use previously and why did I switch?

We didn't previously use a different solution. We've only ever really used Splunk.

How was the initial setup?

The initial setup was not complex. It was pretty straightforward. It was already loaded on the environment. It's managed by a third party or service provider, therefore we just kind-of fell into the rhythm of using it pretty quickly.

What other advice do I have?

We're just a customer. We don't have a business relationship with Splunk.

We're using the latest version of the solution.

I'd advise those considering the solution to do some basic training before jumping into using the solution. It will help you understand how everything is supposed to work.

I'd rate the solution at an eight out of ten, due to the fact that it's more flexible than other solutions. I like the idea of taking a log, any log, and putting it into a tool and creating your events and your conditions in order to get the output that you're looking for. It's more scalable and flexible than other options on the market.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
System Administrator and DevOps Engineer at a tech services company with 10,001+ employees
Real User
Nov 26, 2020
Very straightforward, easy to configure, stable and scalable.
Pros and Cons
  • "This is a straightforward solution, easy to configure."
  • "Other than that, this is a very stable and very easy to configure product."
  • "This is a costly solution."
  • "Splunk is a very costly solution and I think it's the most expensive in the market in terms of costing."

What is our primary use case?

Our primary use case of Splunk is for log monitoring and infrastructure monitoring. If we want to diagnose any issue in our application, we just push our application logs. This is on any client server using the universal forwarder logs on the Splunk server. After indexing, we can create a base log, and create attractive dashboards that are simple to understand and use. I'm a system administrator and we are customers of Splunk. 

What is most valuable?

This is a straightforward solution, easy to configure and difficult to mess up. 

What needs improvement?

Splunk is a very costly solution and I think it's the most expensive in the market in terms of costing. Splunk provides an application for infrastructure monitoring. If we're monitoring the docker with containers, we can't see the container name, only the ID. That's a big drawback.

For how long have I used the solution?

I've been using this solution for two years. 

What do I think about the stability of the solution?

This is a stable solution. Deployment takes one person, it can be a system admin or an engineer.

What do I think about the scalability of the solution?

This is a scalable solution. We can do the clustering of it for large applications. We have around 15 users for this product. 

How are customer service and technical support?

If I have any issues, I'll go to the community. I can generally get a response within a day. Although most of the documentation is good, some of it is unclear, particularly if you're new to the product. 

How was the initial setup?

I think it takes around 10 minutes to install it on the server. On the client side, it takes around five minutes. I do the installation myself. 

What other advice do I have?

If you're going with this solution, make sure that when implementing the ports are open. If they're not open, it creates problems with the server. Other than that, this is a very stable and very easy to configure product. We can easily deploy and easily use. Other similar solutions are difficult to configure, Splunk is the simplest. I've used three or four monitoring tools and Splunk is the easiest. If a company can afford it, this is a good product. We are planning to shift to another product because of the cost. We're searching for an open source or cheaper product.

I would rate this solution a nine out of 10. They lose one point for the price and lack of infrastructure support.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
reviewer1200885 - PeerSpot reviewer
Engineer at a financial services firm with 201-500 employees
Real User
Nov 24, 2020
Great flexibility, pretty stable, and has great technical support
Pros and Cons
  • "The flexibility of the solution is quite good."
  • "The solution has a high learning curve for users. It's a little complicated when you're trying to figure out all the features and what they do."

What is our primary use case?

It's the primary place where I'd go to do an investigation if I want to see what's going on within an endpoint, or on a network, or with a user.

What is most valuable?

The flexibility of the solution is quite good.

The product is stable.

It offers good scalability if you are willing to pay.

The technical support on offer is responsive.

What needs improvement?

The solution has a high learning curve for users. It's a little complicated when you're trying to figure out all the features and what they do.

The solution needs a bit more functionality. For example, being able to save a search and select it when you're doing an investigation. I know you can create dashboards and things like that, however, sometimes being able to have a pre-saved search and just fill in whatever value you need would make everything so much easier.

For how long have I used the solution?

I've been using Splunk for four years so far. It's been a while.

What do I think about the stability of the solution?

I haven't had any stability issues with it. It's pretty stable. There aren't bugs or glitches. It doesn't crash or feeze.

What do I think about the scalability of the solution?

You can scale the solution, however, users need to be aware of the product increasing in cost as well.

How are customer service and technical support?

The technical support is very good. We're quite satisfied with the level of service provided. They are knowledgeable and responsive.

Which solution did I use previously and why did I switch?

When I came to the company, they were already using Splunk. It's only now that we're looking to possibly move to another vendor. The cost of Splunk is much too high.

How was the initial setup?

I wasn't here when this solution was put into place, however, from looking at the documentation and things like that, the setup is pretty involved. I'd say it's a bit more complex than straightforward.

What's my experience with pricing, setup cost, and licensing?

We find the solution to be quite expensive. Therefore, we're looking for other options.

I don't know of the exact costs, as licensing is handled by another department.

What other advice do I have?

We're just users. We don't have a business relationship with Splunk.

We're on a variation of version seven. I'm not sure of the exact one. It's not quite the latest.

I'd advise new users, if they have the budget for it, to go and take the training that they offer. Or, for casual users, you just want to spend as much time watching YouTube videos as you can. It will help lessen the learning curve.

As a solution, it's still pretty much industry standard. I would give it a nine out of ten overall, even though I have my gripes with it.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Buyer's Guide
Download our free Splunk Enterprise Security Report and get advice and tips from experienced pros sharing their opinions.
Updated: August 2026
Buyer's Guide
Download our free Splunk Enterprise Security Report and get advice and tips from experienced pros sharing their opinions.