No more typing reviews! Try our Samantha, our new voice AI agent.
PeerSpot user
Engineer, Infrastructure Applications at a healthcare company with 1,001-5,000 employees
Real User
Top 20
Jun 5, 2017
Ingests machine data and helps to analyze and visualize it.
Pros and Cons
  • "The breadth of the data sources that Splunk can ingest data from is broad and deep and it does an exemplary job at handling structured data."
  • "Splunk has a single purpose in life: ingest machine data and help analyze and visualize that data."
  • "It requires a significant amount of relatively complex architecture once you push past the single server instance."
  • "Technical support is mediocre. Splunk is struggling to deliver a consistently exceptional support experience."

How has it helped my organization?

Imagine a single application with 17 application servers and dozens of log files per server that rotate as often as once per hour. How do you track and analyze anomalies in those log files with the ability to go back and correlate data for the past X weeks? That was use case for just our team, not to mention the hundreds of other application teams.

What is most valuable?

Splunk has a single purpose in life: ingest machine data and help analyze and visualize that data. The breadth of the data sources that Splunk can ingest data from is broad and deep and it does an exemplary job at handling structured data. It does a great job at handling unstructured data. Breaking data into key/value pairs so that it can be searched is relatively painless.

What needs improvement?

Deploying Splunk as scale is not easy. It requires a significant amount of relatively complex architecture once you push past the single server instance. Breaking out your search and indexing layer requires someone with Splunk experience. Want to add search layer replication for HA? Want to host in AWS and do cross-region index replication?

Splunk expertise is in high demand today and finding talented engineers to pull off your large-scale implementation is hard. Do your homework.

What do I think about the stability of the solution?

Out-of-the-box functions are nearly flawless, but when you push at the edges, then things start to get a little flexible in their eloquence. There is a robust community of support to help through most issues and the documentation is exceptional.

Buyer's Guide
Splunk Enterprise Security
May 2026
Learn what your peers think about Splunk Enterprise Security. Get advice and tips from experienced pros sharing their opinions. Updated: May 2026.
902,270 professionals have used our research since 2012.

What do I think about the scalability of the solution?

There were no issues with scalability, but we invested some serious time and resources to design a scalable infrastructure up front.

How are customer service and support?

Customer Service:

Customer service is excellent both during the purchase and ownership lifecycle.

Technical Support:

Technical support is mediocre. Splunk is struggling to deliver a consistently exceptional support experience. Their senior engineers are very talented, but those folks are in short supply and many of the most experienced engineers are making hundreds of dollars an hour as consultants not answering your support issues.

Which solution did I use previously and why did I switch?

No enterprise solution was in place.

How was the initial setup?

The initial setup was done without any prior experience and was up and running, including ingesting data, within a few hours. Setup at scale and scalability took months of effort.

What about the implementation team?

We hired a contractor with significant experience with Splunk, Elastic.io, AWS, and custom development. They were expensive, but worth every penny.

What was our ROI?

TBD.

What's my experience with pricing, setup cost, and licensing?

You will eat up whatever you purchase quickly. The level of insights that Splunk empowers is addictive.

Which other solutions did I evaluate?

We evaluated Graylog, Elastic.io, etc.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
MS Alam - PeerSpot reviewer
MS AlamSystem Administrator at a retailer with 5,001-10,000 employees
Real User

I am agree with you Mr. Joshua Biggley now days splunk have more demand.

See all 2 comments
PeerSpot user
Foundation Technology Specialist at a insurance company with 1,001-5,000 employees
Real User
May 26, 2017
Provides the ability to diagnose problems in production and non-production.
Pros and Cons
  • "The ability to rapidly diagnose problems in production and non-production, across hundreds of log files, is the most valuable feature."
  • "It is a challenge to manage the environment in such a way, that one’s log, even with the bandwidth license, isn’t exceeded."
  • "Official training, even CBT, is expensive so not many people are able to get certified."

How has it helped my organization?

MTTR is drastically reduced, because the developers and other IT support staff have instant access to log events.

People costs are saved by not having to involve the domain developers from multiple teams, when tracing a problem that spans multiple platforms.

Security is improved by not having to give as many people access to log on to the servers.

What is most valuable?

The ability to rapidly diagnose problems in production and non-production, across hundreds of log files, is the most valuable feature.

What needs improvement?

Official training, even CBT, is expensive so not many people are able to get certified. This leads/causes the users to make use of the most basic functionality only.

It is a challenge to manage the environment in such a way, that one’s log, even with the bandwidth license, isn’t exceeded. Splunk has moved towards not applying hard caps in data ingestion, and this will help us in the future.

However, I’d like an easier way to flag certain source log files as non-critical and have Splunk automatically disable those event sources when the license capacity exceeds an arbitrary value.

What do I think about the stability of the solution?

There were no stability issues.

What do I think about the scalability of the solution?

There were no scalability issues.

How are customer service and technical support?

Customer Service:

I haven't had the need to log any critical issues. Most of my support tickets have been revolved around configuration questions. I'm very happy with the way Splunk's support staff respond - they're pretty helpful. I think I've only had one situation where the response was acceptable, but not stellar.

Technical Support:

The technical support is good. I'm sometimes surprised when the support engineer doesn't immediately know the answer to my questions (as I feel they must be fairly common queries). But, this can probably be excused because of the breath of features Splunk Enterprise has.

Which solution did I use previously and why did I switch?

We were not using any other solution previously.

I evaluated ELK Stack but at the time, Splunk offered more flexibility, better support and was easier for us to implement.

How was the initial setup?

Initial setup was fairly straightforward, but we used an experienced implementation partner and ensured that our team was intimately involved in the installation/configuration process on a technical level.

What about the implementation team?

We used a combintation of in-house (ie. myself) and an experienced Splunk partner.

What's my experience with pricing, setup cost, and licensing?

The product has a lot of value, and I feel that we’re getting the value that we’re paying for.

Splunk Enterprise becomes extremely expensive after the 20GB/month license, but if you take care of what you log, i.e., by not logging excessive application events, then that license will get you a long way.

Which other solutions did I evaluate?

We looked at ELK Stack.

What other advice do I have?

Use an experienced Splunk architect to design your infrastructure configuration.

Ensure that your tech leads are intimately involved and understand exactly how the product fits together.

Manage your Splunk configuration in a repository (Git).

Educate the end users as quickly as possible to use the tool effectively.

Change practices and encourage staff to use Splunk instead of old ways of getting the data they need. Prevent, or limit, direct access to the servers or server log files if you can.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
MS Alam - PeerSpot reviewer
MS AlamSystem Administrator at a retailer with 5,001-10,000 employees
Real User

i am agree with splunk user who are saying splunk faster then other product.

See all 3 comments
Buyer's Guide
Splunk Enterprise Security
May 2026
Learn what your peers think about Splunk Enterprise Security. Get advice and tips from experienced pros sharing their opinions. Updated: May 2026.
902,270 professionals have used our research since 2012.
it_user664632 - PeerSpot reviewer
Senior IT Security Operations at a pharma/biotech company with 10,001+ employees
Real User
May 25, 2017
Security relies on this for event correlation and alerts.
Pros and Cons
  • "The speed of the search engine"
  • "We previously used ArcSight; Splunk is at another level, as it is easier, more stable, and faster."
  • "The administration of the cluster and app deployment to indexers or search heads can be done only using ssh access and command line, there is no GUI tools for that."

How has it helped my organization?

The network department, for example, has improved its efficiency by 30%. Security relies on this for event correlation and alerts.

What is most valuable?

  • The speed of the search engine
  • All the types of data sources that you configure can be forwarded to Splunk.
  • The ease-of-use

What needs improvement?

Cluster management can only be done via a command line. I would like them to add some GUI options for that. Permissions are not very flexible, so it would be nice to have more granular options, such as double factor authentication.

The administration of the cluster and app deployment to indexers or search
heads can be done only using ssh access and command line, there is no GUI
tools for that.

Permissions in the other hand could be improved by adding for example the
deny option to groups to see and index, etc. Also the authentication method
is just LDAP or spkunk, so some more security layers could be added as
second factor, etc


What do I think about the stability of the solution?

It is very stable.

What do I think about the scalability of the solution?

It scales out horizontally.

How are customer service and technical support?

The quality of support depends on the support and license. On the average, I would give them a rating of 6/10.

Which solution did I use previously and why did I switch?

We previously used ArcSight. Splunk is at another level. It is easier, more stable, and faster.

How was the initial setup?

It is very easy to set up on a standalone server. Of course, if you want a cluster, it is more complicated. In order to manage it, you need skilled people.

What's my experience with pricing, setup cost, and licensing?

It is not cheap :-)

Which other solutions did I evaluate?

We were using ArcSight before.

What other advice do I have?

My advice is to go ahead with it.

The administration of the cluster and app deployment to indexers or search
heads can be done only using ssh access and command line, there is no GUI
tools for that.

Permissions in the other hand could be improved by adding for example the
deny option to groups to see and index, etc. Also the authentication method
is just LDAP or spkunk, so some more security layers could be added as
second factor, etc


Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
PeerSpot user
IT Infrastructure Architect at a tech company with 201-500 employees
Consultant
Top 20
May 23, 2017
Does event matching between several appliances and correlates data from different sources.
Pros and Cons
  • "It helps us to detect viruses and security events from our network."
  • "It needs documentation, and "how-to-do" information. It's complicated to build reports and views."

What is most valuable?

  • Event matching between several appliances
  • Correlating data from different sources
  • Report viewer

How has it helped my organization?

It helps us to detect viruses and security events from our network.

What needs improvement?

It needs documentation, and "how-to-do" information. It's complicated to build reports and views.

For how long have I used the solution?

I have used Splunk for about two years.

What do I think about the stability of the solution?

There were no stability issues. It was running on a VM over Hyper-V.

What do I think about the scalability of the solution?

There were no scalability issues. It was running on a VM over Hyper-V.

How are customer service and technical support?

I used support a little bit for some templates for formatting data from Cisco and Fortinet logs. They were very fast with their response. I didn't have any support contract, but only entry level support.

Which solution did I use previously and why did I switch?

This was our first try for log analysis.

How was the initial setup?

The setup was easy.

What's my experience with pricing, setup cost, and licensing?

There is nothing to say. At that time, it was for GBs of data received.

Which other solutions did I evaluate?

We did not look at alternatives. It was a consulting provider recommendation. It was a rapid implementation to accomplish legal requirements. After we used it for a while, we decided to keep it.

What other advice do I have?

Check for the plugin to format data of already completed templates for the appliance to which you want to keep logs and events.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
PeerSpot user
Information Architect at a financial services firm with 5,001-10,000 employees
Real User
May 23, 2017
Provides visibility into business metrics and insights that deliver value.
Pros and Cons
  • "Splunk provides immediate visibility into key business metrics and new business insights that deliver immediate value."
  • "We usually have to follow up with technical support on our open cases."

How has it helped my organization?

It is deployed to investigate, detect, respond, and prevent security incidents and threats by providing valuable context and visual insights to make faster and smarter security decisions.

What is most valuable?

  • Splunk delivers a holistic view of an application (the big picture).
  • Splunk provides immediate visibility into key business metrics and new business insights that deliver immediate value.
  • Significant reduction in mean-time-to-investigate (MTTI) and mean-time-to-resolve (MTTR) production incidents from days to hours.
  • Splunk visualization capabilities help pinpoint problem areas, spikes, and anomalies easier and faster.
  • Ability to monitor and resolve integration problems before they impact the business user area.
  • Splunk is being used as part of the development life cycle, resulting in better quality and more efficient applications.
  • Provides additional insights into a 360 degree view of the customer.

What needs improvement?

We usually have to follow up with technical support on our open cases. Otherwise, Splunk listens to customers and is constantly incorporating their feedback in future releases.

What do I think about the stability of the solution?

There are no software stability issues. The issues so far have been internal.

What do I think about the scalability of the solution?

There are no scalability issues. If you are planning on using Splunk for security use cases, I would recommend you go with Linux for your OS.

How are customer service and technical support?

We have the enterprise level of support. This is one area Splunk could improve upon, since we usually have to follow up with them on our open cases.

Which solution did I use previously and why did I switch?

We did not have a previous solution.

How was the initial setup?

There were no issues with the initial setup. We utilized Splunk’s partner zones for the initial setup. In retrospect, we should have utilized Splunk Professional Services.

What's my experience with pricing, setup cost, and licensing?

Although Splunk is an expensive product, it is designed to be utilized across your organization in order to maximize your ROI and lower your TCO.

We contacted Gartner and other business associates to determine what others are paying for Splunk.

Which other solutions did I evaluate?

We started researching ELK (Elastic, Logstash, Kibana). But management was so impressed with Splunk that we ended this research.

What other advice do I have?

Ensure you have an executive sponsors to fully deploy Splunk across your organization to maximize your ROI and lower your TCO.

Make use of Splunk Professional Services.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Alireza Ghahrood - PeerSpot reviewer
Alireza GhahroodConsultant & Instructor -Cyber Security,GovernanceRIskCompliance (CISO as a Services) at a consultancy with 51-200 employees
Top 5Real User

If there's gold in log files, Splunk will help you to find it. Splunk bridges the gap between simple log management and security information and event management products from vendors such as ArcSight, RSA, Q1 Labs and Symantec.

Splunk lets you gather log data from systems and devices, and run queries on that data to find issues and debug problems. Splunk's capabilities also include reporting and alerting, pushing it ever-so-slightly into the world of SIEM.

What separates out Splunk from the world of Syslog servers and SIEM tools is Splunk Apps, a library of nearly 200 addons that make Splunk smarter about particular types of log information, change its look-and-feel or add new types of analysis.

it_user664635 - PeerSpot reviewer
Performance Consultant at a tech services company with 10,001+ employees
Real User
May 17, 2017
Some of the valuable features include data representation options and the analytics and querying of the indices.
Pros and Cons
  • "The data representation options in the dashboards are excellent."
  • "Technical support and the online community are some of the best for any product."
  • "Security administration and user access control is pretty basic. The user access control could be much more granular, so that the admins can control r/w/x access for specific features of the product like dashboards, etc."

What is most valuable?

The analytics and querying the indices is super easy.

The data representation options in the dashboards are excellent.

Multiple datasource/filetypes are supported and each can be customized in a few clicks.

What needs improvement?

Security administration and user access control is pretty basic. This can be improved.

The user access control could be much more granular, so that the admins can control r/w/x access for specific features of the product like dashboards, etc.

If this is improved, with a mapping against LDAP roles, it would be excellent.

What do I think about the stability of the solution?

We had no stability issues.

What do I think about the scalability of the solution?

We had no scalability issues.

How are customer service and technical support?

Technical support and the online community are some of the best for any product.

Which solution did I use previously and why did I switch?

We did not have a previous solution.

How was the initial setup?

The setup was quite easy and there is lot of technical documentation for handholding you through the process.

What's my experience with pricing, setup cost, and licensing?

Pricing and licensing is quite expensive. But for the value the product provides, it seems at par in the market.

Which other solutions did I evaluate?

We looked at IBM SmartCloud Analytics and Log Analytics.

What other advice do I have?

Please watch out for the licensing agreement. There are a lot of IP specific clauses that Splunk has included in their license agreement. Per my understanding, any plugin available in the community cannot be used OOB, due to licensing restrictions. (This might be specific to our organization.)

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
it_user664626 - PeerSpot reviewer
Business Analyst at a retailer with 10,001+ employees
Vendor
May 16, 2017
Provides real-time and scheduled searches with alternate functionalities.
Pros and Cons
  • "I would strongly recommend this product, as it would be very beneficial for service operations and management."
  • "VMware and security device integration looks a bit complex."

What is most valuable?

  • Flexibility when creating dashboards
  • Automated cron searches
  • Real-time and scheduled searches with alternate functionalities
  • User-base integration with LDAP

How has it helped my organization?

It alerted many situations before other monitoring systems identified that there is a critical issue.

What needs improvement?

VMware and security device integration looks a bit complex.

For how long have I used the solution?

I have used Splunk for almost three years.

What do I think about the stability of the solution?

As of now, we have had no issues with stability. It is running like a charm.

What do I think about the scalability of the solution?

From a nodes perspective, there have been no scalability issues.

How are customer service and technical support?

I can say that support is good.

Which solution did I use previously and why did I switch?

We never used other solutions.

How was the initial setup?

We used the Splunk Cluster setup. It was a bit complex to set up, but management-wise and stability-wise, it was awesome.

What's my experience with pricing, setup cost, and licensing?

License costs fall under the NDA, but Splunk license costs are public, I believe.

Which other solutions did I evaluate?

We evaluated Logstash and others, but Splunk plays a pivotal role.

What other advice do I have?

I would strongly recommend this product, as it would be very beneficial for service operations and management.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
it_user594183 - PeerSpot reviewer
Security Engineer at a retailer with 10,001+ employees
Real User
May 16, 2017
They provide predefined user cases. Scalability is always a question for this product.
Pros and Cons
  • "They provide excellent predefined user cases."
  • "Scalability is always a question for this product."

What is most valuable?

They provide excellent predefined user cases.

How has it helped my organization?

This helps us in the footprinting of all the incidents.

What needs improvement?

When we deep dive into the events for the triggers, we have very little information in some instances.

For how long have I used the solution?

I have used Splunk for two years.

What do I think about the stability of the solution?

We raised support cases.

What do I think about the scalability of the solution?

Scalability is always a question for this product.

How are customer service and technical support?

Response from technical support can be improved. There was always a delay and we had to chase them.

Which solution did I use previously and why did I switch?

We didn’t have a previous solution.

How was the initial setup?

I was not present during the initial setup.

What's my experience with pricing, setup cost, and licensing?

Pricing and licensing are always high compared to other products in the market. Storage is very expensive as well.

What other advice do I have?

It is a good product, but expensive.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
MS Alam - PeerSpot reviewer
MS AlamSystem Administrator at a retailer with 5,001-10,000 employees
Real User

Splunk license and storage pricing is high. please make it cheap then most off company can use this product.

it_user396600 - PeerSpot reviewer
Vice Manager at a comms service provider with 10,001+ employees
Vendor
May 15, 2017
Collects data from many sources. Has search, analysis, and visualization capabilities.
Pros and Cons
  • "If you are an enterprise and you need the best service for critical business analysis, Splunk would be one of the best choices."

    What is most valuable?

    • Collects data from any source
    • Powerful search, analysis, and visualization
    • Easy to build system on any platform
    • API and easily integrated search
    • Action script

    How has it helped my organization?

    We have over 7000 devices in our network infrastructure for monitoring, maintenance, and performance assessment.

    We achieve this by collecting data and applying the analysis.

    For how long have I used the solution?

    I have used this solution for one year.

    What do I think about the scalability of the solution?

    We did not encounter any issues with scalability. Everything is normal with no bugs.

    How are customer service and technical support?

    It’s easy to obtain support from Splunk for technical issues. We also have enough knowledge ourselves to apply fixes.

    Which solution did I use previously and why did I switch?

    We used to deploy Elastic Stack. The search language of Splunk is easier and friendlier than Elastic Stack. It has helped me to search quickly and easily. Based on the results, it’s easy to visualize and add results to a previously built, personal dashboard.

    What's my experience with pricing, setup cost, and licensing?

    Licensing is free. Pricing is based on usage.

    Which other solutions did I evaluate?

    We evaluated Elastic Stack and Sumo Logic.

    What other advice do I have?

    If you are an enterprise and you need the best service for critical business analysis, Splunk would be one of the best choices.

    Disclosure: My company does not have a business relationship with this vendor other than being a customer.
    PeerSpot user
    it_user363165 - PeerSpot reviewer
    Products Manager at a tech services company with 5,001-10,000 employees
    MSP
    May 11, 2017
    Valuable features include rapid search, data mining, and information propagation. The GUI should be improved.
    Pros and Cons
    • "It has been helping a lot of my clients with fast data mining and information propagation."
    • "The GUI should be improved, in other words, the overall appearance."

    What is most valuable?

    Rapid search is a valuable feature. Performance and incident response were the top priorities for most MSSPs. Breaches of SLAs will have a negative impact on customer trust, which eventually leads to losing customer confidence on services to which they’re subscribing. Hence, the proactive approaches will be the main differentiator from one MSSP to the others.

    How has it helped my organization?

    It has been helping a lot of my clients with fast data mining and information propagation.

    What needs improvement?

    The GUI should be improved, in other words, the overall appearance.

    For how long have I used the solution?

    I am not the end-user. However, my job was more relevant as a consultant.

    What do I think about the stability of the solution?

    Performance upgrades are needed when more processing power is required.

    What do I think about the scalability of the solution?

    We have not had scalability issues.

    How are customer service and technical support?

    Technical support is good.

    Which solution did I use previously and why did I switch?

    The client was using an open source solution. They decided to switch to an enterprise product.

    How was the initial setup?

    The setup can be straightforward, if use cases are well defined.

    What's my experience with pricing, setup cost, and licensing?

    Overall, it the cost is reasonable and it is easy to upgrade.

    Which other solutions did I evaluate?

    Our client was considering the other solutions as well. However, due to their overall assessment, they still considered going with it.

    What other advice do I have?

    Start off with something at a comfortable level, expand gradually, and then move upwards, expanding steadily.

    Disclosure: My company has a business relationship with this vendor other than being a customer. We are a distributor.
    PeerSpot user
    Buyer's Guide
    Download our free Splunk Enterprise Security Report and get advice and tips from experienced pros sharing their opinions.
    Updated: May 2026
    Buyer's Guide
    Download our free Splunk Enterprise Security Report and get advice and tips from experienced pros sharing their opinions.