Try our new research platform with insights from 80,000+ expert users
it_user664635 - PeerSpot reviewer
Performance Consultant at a tech services company with 10,001+ employees
Real User
Some of the valuable features include data representation options and the analytics and querying of the indices.
Pros and Cons
  • "The data representation options in the dashboards are excellent."
  • "The user access control could be much more granular, so that the admins can control r/w/x access for specific features of the product like dashboards, etc."

What is most valuable?

The analytics and querying the indices is super easy.

The data representation options in the dashboards are excellent.

Multiple datasource/filetypes are supported and each can be customized in a few clicks.

What needs improvement?

Security administration and user access control is pretty basic. This can be improved.

The user access control could be much more granular, so that the admins can control r/w/x access for specific features of the product like dashboards, etc.

If this is improved, with a mapping against LDAP roles, it would be excellent.

What do I think about the stability of the solution?

We had no stability issues.

What do I think about the scalability of the solution?

We had no scalability issues.

Buyer's Guide
Splunk Enterprise Security
June 2025
Learn what your peers think about Splunk Enterprise Security. Get advice and tips from experienced pros sharing their opinions. Updated: June 2025.
861,490 professionals have used our research since 2012.

How are customer service and support?

Technical support and the online community are some of the best for any product.

Which solution did I use previously and why did I switch?

We did not have a previous solution.

How was the initial setup?

The setup was quite easy and there is lot of technical documentation for handholding you through the process.

What's my experience with pricing, setup cost, and licensing?

Pricing and licensing is quite expensive. But for the value the product provides, it seems at par in the market.

Which other solutions did I evaluate?

We looked at IBM SmartCloud Analytics and Log Analytics.

What other advice do I have?

Please watch out for the licensing agreement. There are a lot of IP specific clauses that Splunk has included in their license agreement. Per my understanding, any plugin available in the community cannot be used OOB, due to licensing restrictions. (This might be specific to our organization.)

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
it_user664626 - PeerSpot reviewer
Business Analyst at a retailer with 10,001+ employees
Vendor
Provides real-time and scheduled searches with alternate functionalities.

What is most valuable?

  • Flexibility when creating dashboards
  • Automated cron searches
  • Real-time and scheduled searches with alternate functionalities
  • User-base integration with LDAP

How has it helped my organization?

It alerted many situations before other monitoring systems identified that there is a critical issue.

What needs improvement?

VMware and security device integration looks a bit complex.

For how long have I used the solution?

I have used Splunk for almost three years.

What do I think about the stability of the solution?

As of now, we have had no issues with stability. It is running like a charm.

What do I think about the scalability of the solution?

From a nodes perspective, there have been no scalability issues.

How are customer service and technical support?

I can say that support is good.

Which solution did I use previously and why did I switch?

We never used other solutions.

How was the initial setup?

We used the Splunk Cluster setup. It was a bit complex to set up, but management-wise and stability-wise, it was awesome.

What's my experience with pricing, setup cost, and licensing?

License costs fall under the NDA, but Splunk license costs are public, I believe.

Which other solutions did I evaluate?

We evaluated Logstash and others, but Splunk plays a pivotal role.

What other advice do I have?

I would strongly recommend this product, as it would be very beneficial for service operations and management.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Buyer's Guide
Splunk Enterprise Security
June 2025
Learn what your peers think about Splunk Enterprise Security. Get advice and tips from experienced pros sharing their opinions. Updated: June 2025.
861,490 professionals have used our research since 2012.
it_user594183 - PeerSpot reviewer
Security Engineer at a retailer with 10,001+ employees
Real User
They provide predefined user cases. Scalability is always a question for this product.

What is most valuable?

They provide excellent predefined user cases.

How has it helped my organization?

This helps us in the footprinting of all the incidents.

What needs improvement?

When we deep dive into the events for the triggers, we have very little information in some instances.

For how long have I used the solution?

I have used Splunk for two years.

What do I think about the stability of the solution?

We raised support cases.

What do I think about the scalability of the solution?

Scalability is always a question for this product.

How are customer service and technical support?

Response from technical support can be improved. There was always a delay and we had to chase them.

Which solution did I use previously and why did I switch?

We didn’t have a previous solution.

How was the initial setup?

I was not present during the initial setup.

What's my experience with pricing, setup cost, and licensing?

Pricing and licensing are always high compared to other products in the market. Storage is very expensive as well.

What other advice do I have?

It is a good product, but expensive.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
MS Alam - PeerSpot reviewer
MS AlamSystem Administrator at Abdullah Al-Othaim Markets
Real User

Splunk license and storage pricing is high. please make it cheap then most off company can use this product.

it_user396600 - PeerSpot reviewer
Vice Manager at a comms service provider with 10,001+ employees
Vendor
Collects data from many sources. Has search, analysis, and visualization capabilities.

What is most valuable?

  • Collects data from any source
  • Powerful search, analysis, and visualization
  • Easy to build system on any platform
  • API and easily integrated search
  • Action script

How has it helped my organization?

We have over 7000 devices in our network infrastructure for monitoring, maintenance, and performance assessment.

We achieve this by collecting data and applying the analysis.

For how long have I used the solution?

I have used this solution for one year.

What do I think about the scalability of the solution?

We did not encounter any issues with scalability. Everything is normal with no bugs.

How are customer service and technical support?

It’s easy to obtain support from Splunk for technical issues. We also have enough knowledge ourselves to apply fixes.

Which solution did I use previously and why did I switch?

We used to deploy Elastic Stack. The search language of Splunk is easier and friendlier than Elastic Stack. It has helped me to search quickly and easily. Based on the results, it’s easy to visualize and add results to a previously built, personal dashboard.

What's my experience with pricing, setup cost, and licensing?

Licensing is free. Pricing is based on usage.

Which other solutions did I evaluate?

We evaluated Elastic Stack and Sumo Logic.

What other advice do I have?

If you are an enterprise and you need the best service for critical business analysis, Splunk would be one of the best choices.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
it_user363165 - PeerSpot reviewer
Products Manager at a tech services company with 5,001-10,000 employees
MSP
Valuable features include rapid search, data mining, and information propagation. The GUI should be improved.

What is most valuable?

Rapid search is a valuable feature. Performance and incident response were the top priorities for most MSSPs. Breaches of SLAs will have a negative impact on customer trust, which eventually leads to losing customer confidence on services to which they’re subscribing. Hence, the proactive approaches will be the main differentiator from one MSSP to the others.

How has it helped my organization?

It has been helping a lot of my clients with fast data mining and information propagation.

What needs improvement?

The GUI should be improved, in other words, the overall appearance.

For how long have I used the solution?

I am not the end-user. However, my job was more relevant as a consultant.

What do I think about the stability of the solution?

Performance upgrades are needed when more processing power is required.

What do I think about the scalability of the solution?

We have not had scalability issues.

How are customer service and technical support?

Technical support is good.

Which solution did I use previously and why did I switch?

The client was using an open source solution. They decided to switch to an enterprise product.

How was the initial setup?

The setup can be straightforward, if use cases are well defined.

What's my experience with pricing, setup cost, and licensing?

Overall, it the cost is reasonable and it is easy to upgrade.

Which other solutions did I evaluate?

Our client was considering the other solutions as well. However, due to their overall assessment, they still considered going with it.

What other advice do I have?

Start off with something at a comfortable level, expand gradually, and then move upwards, expanding steadily.

Disclosure: My company has a business relationship with this vendor other than being a customer. We are a distributor.
PeerSpot user
PeerSpot user
Sr. Program Manager at a consultancy with 51-200 employees
Consultant
It is able to configure and integrate various solutions into one tool and provide actionable results. You need a dedicated developer.

What is most valuable?

  • Can ingest data from various data sources.
  • Is very useful for organizations who are attempting to meet compliance requirements.
  • Is able to fully configure and integrate various solutions into one tool and provide actionable results.

How has it helped my organization?

My use of Splunk at my previous place of employment improved how we functioned.

For how long have I used the solution?

I have used Splunk for three years.

What do I think about the stability of the solution?

We didn’t have any stability issues.

What do I think about the scalability of the solution?

We didn’t have any scalability issues.

How are customer service and technical support?

During our use of Splunk, we had professional services assisting and not actual technical support. However, the professional services team was great.

Which solution did I use previously and why did I switch?

Our organization did not have an established SIEM tool.

How was the initial setup?

The initial setup is straightforward, depending on the level of implementation of the tool.

What's my experience with pricing, setup cost, and licensing?

Take into consideration the labor costs for a dedicated Splunk developer who can craft the required queries needed for each organization. Organizations usually have their own form of implementation of each tool.

Which other solutions did I evaluate?

We didn’t evaluate any alternatives.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
PeerSpot user
Technical Director at a consultancy with 11-50 employees
Real User
It allows us to store raw data and use it repeatedly for different domains.

How has it helped my organization?

We are using it for operational intelligence. We are using Splunk as a data lake for machine data. We gather all our machine data from the IT infrastructure and monitor its health.

What is most valuable?

Splunk's schema-on-read technology is one of the most valuable characteristics of this solution. It allows us to store raw data and use it repeatedly for different domains. You don't need to prepare the data upfront.

Splunk's Search Processing Language (SPL) is another beneficial feature. It is a very powerful tool that gives you the ability to do almost anything with your data.

What needs improvement?

Visualizations can improve. There are some performance and stability issues with the visualization layer.

What do I think about the stability of the solution?

There were stability issues, but only with the visualization layer.

What do I think about the scalability of the solution?

There were no scalability issues.

How are customer service and technical support?

The technical support is quite good.

Which solution did I use previously and why did I switch?

Previously, we worked with different vendors and solutions.

How was the initial setup?

The setup was very straightforward.

What's my experience with pricing, setup cost, and licensing?

The price is pretty high for our region.

Which other solutions did I evaluate?

We did a SIEM solutions review with this and other systems for one of our customers.

What other advice do I have?

This is the right choice if you are looking for a platform that can combine all machine-generated data and use it for various use cases from different domains.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Alireza Ghahrood - PeerSpot reviewer
Alireza GhahroodConsultant & Instructor -Cyber Security,GovernanceRIskCompliance (CISO as a Services) at Independent
Top 10Real User

Splunk's schema-on-read technology is one of the most valuable characteristics of this solution. It allows us to store raw data and use it repeatedly for different domains. You don't need to prepare the data upfront.

PeerSpot user
Integration Architect at a manufacturing company with 1,001-5,000 employees
Vendor
Fast availability of operational data spread across several servers is nice, but the MES is a complex system.

What is most valuable?

What Splunk calls operational intelligence: fast availability of operational data spread across several servers to prevent or react faster to outages or performance decreases.

How has it helped my organization?

MES is a complex and very critical distributed system here. Production WIP is directly connected to it and ICT is required to provide a continuous availability and very stable performance (line production has a costant speed, software cannot slowdown). Collect operational data from hardware, middleware and application software can potentially improve ICT proactive and reactive tasks.

For how long have I used the solution?

I've ever used it, just studied it.

Which solution did I use previously and why did I switch?

We also use a traditional monitor, and Microsoft SCOM.

What was our ROI?

Every stop or slowdown of the production line means lost of money, e.g. 30% reduction when compared to the current baseline.

What's my experience with pricing, setup cost, and licensing?

Every stop or slowdown of the production line means lost of money, e.g. 30% of reduction compare to the current baseline.

Which other solutions did I evaluate?

IBM QRadar

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Buyer's Guide
Download our free Splunk Enterprise Security Report and get advice and tips from experienced pros sharing their opinions.
Updated: June 2025
Buyer's Guide
Download our free Splunk Enterprise Security Report and get advice and tips from experienced pros sharing their opinions.