We use it for logging, essentially for auditing and troubleshooting errors in production and finding out what happened.
I have used the product personally for five years and at my current company for a year and a half.
We use it for logging, essentially for auditing and troubleshooting errors in production and finding out what happened.
I have used the product personally for five years and at my current company for a year and a half.
I haven't had any problems with it so far.
There are a lot of plugins to integrate this. The client site login is pretty extensible and probably cost-effective. Plus, it is easy to configure.
I would like some additional AI capabilities to provide additional information about things going wrong and things going well.
It is very stable. We have not had any problems.
We had to upgrade when it was on-premise, but then we went to cloud version, which is very good.
It is pretty scalability, even though we have a lot of logs. It runs well.
I assume that the pricing is reasonable, because if it was too costly, there are other alternatives. However, with some of the other solutions, you have to spend time on them and manage them yourself. It might also take you three times to get it right. So, Splunk may be more costly upfront, but in the long run, it saves on time and man-hours.
I would consider ELK Kibana a competitor for this solution. If you have time, and you want to do it yourself, you can save a little money going with Kibana. However, Splunk is pretty good and I would recommend an enterprise to switch to Splunk.
It helps increase our productivity.
We are saving a lot of time by being in one place instead of several servers.
The most valuable features are understanding the visualization compass on the dashboard, as well as the reports on the dashboards.
I would like to have the ability to master the management of clustering.
It is easy to implement.
It is easy to use, and easy to implement.
My primary use case for Splunk is for log file visualization and monitoring alert management.
The way this solution has improved our organization is by its ability to do a quick search and immediately stop an incident from happening.
The auto-notification abilities are a huge benefit for us.
After a crash, the product takes a while to recover.
Sometimes we have had instances when it will not run for a couple of days. There is room for improvement here.
There are lots of use cases and features that make Splunk a good choice for us.
I have no opinion on the pricing of the product.
We considered Datadog and Zabbix. In comparison to those options, Splunk has virtual visualization. Furthermore, it can be a host on our environment. Typically, we cannot deploy SaaS on our environment, but with Splunk, we can.
When Splunk failed, it took time to recover. We had to recover it from a snapshot. It took a couple of days, and it was as if it had crashed. But, the instance was resolved.
I work in the HIPAA industry. I work at a healthcare company in Puerto Rico. HIPAA requires us to go over security risks. Our use case right now is to be compliant.
In our hierarchy, we have 1000 servers and 16,000 endpoints. We also have 100 entry points and 3000 VPN connections. It's huge.
Manually, it used to take us a whole day to do strong monitoring. Now, it takes a maximum of two hours because of this product.
It creates a single pane of glass. Plus, it gives us the liberty to do more in terms of use cases, especially since HIPAA wants use cases. We must monitor them. Therefore, we can also add our own correlations for all our use cases.
The dashboard centralizes the daily routine. We used to do this by hand. Now, we go through daily checklists, using the dashboard and setting up the alarms. It helps us to cut down the time on this routine.
I am a cybersecurity director. I manage five different business lines. Every morning, we used to have to go to different tools to get our daily routines done. With Splunk, centralized as it is, we can see everything in one place. We use it not only for monitoring events, but in case we need to do a group call. We can see what's going on, viewing all of the offenses and security events which are happening in our infrastructure.
The Web Application Firewall will send you too much information because it's more dedicated to security than a normal firewall.
It was pretty straightforward. I even did a couple of logs myself.
We implement through a vendor.
We were using QRadar as a POC. We were using for real at our cloud but also it was a POC for us because we were watching the product. But, QRadar needs a lot of fine tuning.
We use Splunk for a few different use cases:
It has improved our organization in many ways:
It needs to improve the way to install third-party apps and enable installation without logging into splunk.com.
Not at all.
Not really.
Their support is pretty good, but not amazing. Although we have our own in-house Splunk expert who worked for Splunk themselves for a few years, we do not really need external support that much. We basically use them for licensing stuff.
The forums are pretty thorough, so technically we have not had much need for support.
The initial setup is easy. Although, we currently use just a single server and not multi-server clustered instances.
For our Linux instance setup, an upgrade is very easy. It is all managed by about three simple Bash scripts.
It is possible to use a developer's license, which is up to 10GB per day of volume traffic, which is usually enough for most use cases.
We evaluated ELK Stack and QlikView.
We are a Splunk Partner, since after much deliberation, we decided to choose Splunk as a component of one of our on-premise software offerings.
Splunk is a SIEM, a Security Information and Event Management solution. It is used, for example, for monitoring security logs and security information in companies and organizations. It is also used for correlation, meaning making policies, for detecting/monitoring attacks, and the like; for monitoring security logs, security events, preventing hackers from attacking. It's really for business continuity.
For a long period of time we analyzed logs, traffic, something like tcpdump. Splunk UBA is useful for fraud detection and for detection of APTs, advanced persistent threats. It's really important for our business because I work a PSP, a payment service provider, e-payments.
UBA, User Behavior Analytics.
In the next release of Splunk, I think the machine learning should be emphasized. Now, it's really important to analyze Big Data, data mining. A SIEM solution, like Splunk, needs an improved data mining solution, artificial intelligence. Splunk would be the best if it improved these features.
It's stable and very safe.
Splunk's scalability is good for an enterprise situation. It's scalable in all situations.
For us, technical support has been good. Splunk has good documentation and it is really easy to work with Splunk and the Splunk community.
I used ELK. It was good. It is an open-source solution, but there is some complexity in configuring it, working with it.
In choosing a vendor I use industry reviews to find feedback from the community that works with the solution.
The initial setup was straightforward.
There are a lot of solutions: IBM QRadar, Splunk, LogRhythm. Splunk was good for us because of the support, the documentation, the scalability, the stability. It gives us everything that we need in our business, everything necessary for helping us do our job.
There are three top SIEM solutions in the world: Splunk, LogRhythm, IBM QRadar. I think Splunk is the best.
I would rate Splunk at eight out of 10. The vendor needs to work on this solution to make it better and better. I would recommend this solution but it depends on the situation, the country, the support from the vendor.
We use Splunk for infrastructure monitoring, application monitoring and in the security space for our organization as well as for our customers.
Since Splunk is a platform for data, we can ingest and correlate data from virtually any type of system.
It has a fast turnaround time for setting up monitoring/alerting and forecasting of trends as per our customers' requirements.
The following are top three features that I find quite valuable: