Try our new research platform with insights from 80,000+ expert users
Sagar Shekhar - PeerSpot reviewer
Cyber Security Analyst at TIAA
Real User
Top 5
A stable tool with an easy setup phase that provides ease of use to its users
Pros and Cons
  • "The initial setup of Splunk Real User Monitoring (RUM) was easy."
  • "The initial setup of Splunk Real User Monitoring (RUM) was easy. The solution is deployed on-premises."

What is our primary use case?

In my company, we use Red Canary MDR to perform MITRE ATT&CK, after which I import the lot or whatever commands were run by Red Canary MDR to my Splunk system for further analysis. I use a type of real-time monitoring by Splunk.

What is most valuable?

The most valuable feature of the solution is the way it formats the raw data and helps make the understanding process much easier for the users. When you see the unformatted lots, it looks gibberish, especially for first-time users who may not understand a lot of things, but using Splunk Real User Monitoring (RUM) can make their job easier.

What needs improvement?

I had tried onboarding Splunk Real User Monitoring (RUM) on the cloud, but unfortunately, I couldn't onboard it on the cloud. It is an issue from my end that Splunk can try to improve.

For how long have I used the solution?

I have used Splunk Real User Monitoring (RUM) for over half a year. I use the solution with an enterprise license for a trial period of six months. I am a customer of Splunk.

Buyer's Guide
Splunk Observability Cloud
June 2025
Learn what your peers think about Splunk Observability Cloud. Get advice and tips from experienced pros sharing their opinions. Updated: June 2025.
861,524 professionals have used our research since 2012.

What do I think about the stability of the solution?

It is a stable solution.

What do I think about the scalability of the solution?

Everyone in the SOC team, consisting of 50 to 100 people in my new company, uses Splunk Real User Monitoring (RUM).

How was the initial setup?

The initial setup of Splunk Real User Monitoring (RUM) was easy.

The solution is deployed on-premises.

Which other solutions did I evaluate?

My company decided to go with Splunk Real User Monitoring (RUM) over other solutions since it has the ability to format raw data making the job of the organization easier.

What other advice do I have?

I recommend the tool to those planning to use it since even though similar tools are available in the market, Splunk Real User Monitoring (RUM) is easier to use, especially for businesses.

I rate the overall solution a nine out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Senior Consultant at Tata Consultancy
Real User
Enables us to directly search for a metric and straightaway create alert charts 
Pros and Cons
  • "The volume it handles is very good, including the number of metrics, the volume number of traces, and more."
  • "There are some predefined metrics.......we may want to create customized metrics."

What is our primary use case?

Our primary use case for SignalFx was visualization, charting, and alerting. We also used it to fix our µAPM.

How has it helped my organization?

For one project I was working on, at least 15,000 people were using SignalFx. They used to monitor their application health in the SignalFx dashboard and get alerts from SignalFx. The users had different job profiles, such as engineers and architects.

What is most valuable?

One of the valuable features is that it is very user-friendly. We can directly search for a metric and create alert charts straightaway. There are multiple visualization options to create charts that allow users to create detectors and alerts and integrate them with downstream applications for getting notifications.

Moreover, the volume it handles is very good, including the number of metrics, the volume number of traces, and more.

What needs improvement?

There are some predefined metrics where we can directly install the SignalFx agent. It gives some informative CPU utilization where some things are inbuilt. But for specific applications, we may need to create customized metrics. Here, developer teams have an additional burden of creating the whole thing if they need to customize anything. The additional feature metric could be a custom metric edition. It would make it simple for any user or engineer to go beyond the default metrics and easily choose to add more metrics. It will help share dashboards, so when we have a single version, thousands of people can use the same single version of the dashboard.

The sharing option and custom metric would be the two additional features I would like to see in the improved version.

For how long have I used the solution?

I used SignalFx for six to eight months for my previous project, and the version I used was Splunk Observability. I used it last in October 2022; I am not using it right now.

What do I think about the stability of the solution?

It is a stable product. There used to be some unplanned maintenance or intermittent issues. Most of the time, we used to get alerts or notifications from the SignalFx team. So, out of 100, I would give it a 90. It was stable, but in that 10% of the occurrence, we faced various problems like loading traces, dashboards, and more. In that project, we had a limit of detectors and a limit of a metric time series, and several subscribed metrics. So, we used to get some notifications when it reached 80% or 90% of the usage. Thus, it is completely related to the subscription. But we faced the fact that the number of MTS reached the limit.

In terms of stability, we faced intermittent issues so I won't give it a 100%; it is 90%.

What do I think about the scalability of the solution?

It is scalable. Although the scalability depends on the subscription model, there are some related requests according to cost. For example, if I want to increase the metrics by up to 30%, store more metrics, or create more alerts, I can easily do it without impacting anything. For all those things, it is scalable.

How are customer service and support?

I used to create a support case in the SignalFx portal itself, and I used to call them on their toll-free number and engage them with issues. So I had some experience with their team and I rate them an eight out of ten.

I would rate it an eight because customer support won't provide back-to-back service. If I expect updates every hour, sometimes I may not get updates every hour. For example, if I need someone to explain the issue, there might be delays. If I need to get some root cause of an issue in real-time, that might take time. So considering these factoes, I rate them an eight out of ten.

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

I have used some observability tools like Splunk, Instana, and Grafana. I found SignalFx the best one for visualization, and it is user-friendly too. For example, you can directly search for a metric, and we can create alert charts immediately. So there will be multiple visualization options to create graphs. From there, we can directly create detectors, create alerts, and integrate them with other downstream applications for getting notifications.

How was the initial setup?

The initial setup was simple, and we used some package installers. We had a restrictive code for binaries in Artifactory. So we directly used some package installers and pulled it in individual service. Also, it was integrated with Puppet, so installing the SignalFx agent and starting it was simple.

What about the implementation team?

I wanted to manually install, deploy, and download it on a single server, and the whole manual procedure took around 10 to 15 minutes. When I tested a group of services with the help of Puppet, even hundreds of servers were done within an hour or something. 

So I was working on a banking project, and we had a private cloud there; SignalFx agents were installed on servers, and our metrics were derived from there.

Which other solutions did I evaluate?

My company used an inbuilt application built by in-house developers, which was developed 15 years ago. Those tools were somewhat outdated and could not serve the purpose of the ever-growing volumes and other issues. So they preferred to have some third-party tool to solve their problems, and they found SignalFx useful. As a user, I also thought SignalFx was much better than other visualizations.

What other advice do I have?

I would definitely recommend SignalFx. Compared to other installation tools, creating alerts, understanding charts, and creating dashboards is more straightforward. 

The functions are complex but SingalFx is very user-friendly. There is very defined documentation for everything, whether I have to create an alert or use some aggregation. We will have a direct link that says something like, "Click here to read more" or  "Click here to understand." Such links are there for everything. Moreover, if I want to create an alert, there will be multiple options; it will say, "What is the time of alert?" or "What is the threshold base?" All these details will be there; you will have a link to detailed documentation. It is a very user-friendly tool for any beginner. 

I would rate it as nine out of ten. 

Which deployment model are you using for this solution?

On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Buyer's Guide
Splunk Observability Cloud
June 2025
Learn what your peers think about Splunk Observability Cloud. Get advice and tips from experienced pros sharing their opinions. Updated: June 2025.
861,524 professionals have used our research since 2012.
reviewer2499615 - PeerSpot reviewer
Splunk engineer at a computer software company with 51-200 employees
MSP
Helps organizations achieve compliance control and provides all the data to users in a single place
Pros and Cons
  • "The tool's stability is great."
  • "There is not a lot of support for the tool's on-premises version, especially since everything is on the cloud."

What is our primary use case?

I use the solution in my company for our customers who use the tool for auditing and compliance in the area of DoD/AC. My company's customers have compliance controls, and STIG controls that they have to satisfy for their ETL processes.

How has it helped my organization?

The tool has helped our customer's organization in achieving compliance control. When our customer's organization has an inspection or when the DoD inspects their infrastructure, they can show their auditors that they are compliant. They can show the auditors the dashboards and verify that they are ingesting data from the sources and how all their hosts are being monitored. They can show everything to auditors, check the box, make sure that everything looks green, and then they continue to have authorization to operate.

What is most valuable?

The most valuable piece of Splunk Infrastructure Monitoring for our company's customers revolves around the data for everything. Everything produces data, and all the data can get ingested, whether it is Windows, RHEL, VMware products, Pure Storage products, or a custom product. Configuring data ingestion and performing everything in Splunk Infrastructure Monitoring is possible. At the same time, a lot of the other SIEM tools focus on a specific type of data. The benefit of Splunk Infrastructure Monitoring is that one can see all their data in one place.

What needs improvement?

There is not a lot of support for the tool's on-premises version, especially since everything is on the cloud. In my company, we had a really good demo this morning on Keynote, which touches on the APM part, and it was super cool. There was also a demo on AI assistant, which was super cool. It is hard to increase the options for a particular customer when so much of the stuff is limited to the cloud, and there is so much focus on the cloud part.

For how long have I used the solution?

I have been using Splunk Infrastructure Monitoring for three years for my customer, who has been using it for longer than when I started to use it.

What do I think about the stability of the solution?

The tool's stability is great.

What do I think about the scalability of the solution?

The tool's scalability is great. My company just moved Splunk from VMs to containers for our customers, so I would say that we have put it on Kubernetes on Tanzu, which has been great for them.

How are customer service and support?

Support is an area I have not really reached out to on behalf of our customers. I usually just go to Splunk Answers or rely on my colleagues to get what I need. My company has never opened a support ticket with Splunk for our customers.

Which solution did I use previously and why did I switch?

I don't know what one of my company's customers had used before Splunk Infrastructure Monitoring. They may have used some other solutions, but I have been on contract with them for three years.

What was our ROI?

In terms of ROI, I can say that I have seen a decreased amount of time spent on our company's end validating data ingested from an auditing perspective, especially when we are talking about their authorization to operate. With the tool, it is much quicker to view all your data in one place than it is to go show an auditor 15 different data sources. You can show it all together to the auditor.

What's my experience with pricing, setup cost, and licensing?

Licensing cost is the biggest argument I get from those divesting from Splunk. There are those within our organization who say we are going to go to other tools since Splunk is too expensive. Till now, I have been able to ask others to look at the value Splunk adds to the company, and I have been able to convince them that it is worth it, but that might not always be the case if licensing continues to be an issue, especially if costs continue the way they are and if other solutions offer more competitive pricing for similar results.

What other advice do I have?

The tool is not used to monitor multiple cloud environments.

It is not important for our company that Splunk Infrastructure Monitoring provides end-to-end visibility into your cloud-native environment.

The tool has helped improve our organization's business resilience.

The tool does the job very well. It is easy for me to use, especially as a trained person in Splunk products. The tool also does the job very well. With the tool in place, I can get Windows or RHEL. I can do things like scripted input on a forwarder. Splunk Universal Forwarder are so much more than if I just use Syslog, for example, to just get data. I can do a lot more with Splunk than just ingesting data via something like Syslog.

I rate the tool an eight out of ten.

Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
PeerSpot user
Senior Support Engineer at a tech vendor with 10,001+ employees
Real User
Top 20
The dashboards are great, and we get solid visibility across our environment
Pros and Cons
  • "Splunk's dashboards are great."
  • "The licensing model is expensive. We need to monitor the amount of data ingested because the cost is based on the data collected."

What is our primary use case?

I have the logs of my applications, and they're usually a bit volatile. The log switch doesn't stay there on the application for a long time, so Splunk can require that. It can take 15 days for the logs to be available to do some kind of research. I'm using Splunk to ingest application logs, create dashboards, and set up alerts. 

How has it helped my organization?

The biggest benefit of Splunk is that we can retain logs and correlate the data. Telemetry data has a huge impact because it's much easier to see everything. 

Splunk has significantly reduced our mean resolution time. The workflow at my company involves application microservices applications running on the cloud. These logs are highly volatile, so they're only retained for three to five minutes, and we had to reproduce an issue to trace why it failed. That meant we had to do everything again to capture the log at the moment.  Now, we have the data to analyze one or two hours.

What is most valuable?

Splunk's dashboards are great. The solution provides end-to-end visibility across my environment. Visualizing large amounts of data is easier because we can correlate the data from any target source. 

What needs improvement?

The licensing model is expensive. We need to monitor the amount of data ingested because the cost is based on the data collected. 

For how long have I used the solution?

I have used Splunk APM for three years now.

What do I think about the stability of the solution?

We have instances for production and development. I've never seen the production instance go down. Our development instance has gone down, but that's expected. 

Which solution did I use previously and why did I switch?

I used tools like Elasticsearch, which is similar to Splunk. I've also used other observability tools like Grafana and Dynatrace, but they have different features.

What other advice do I have?

I rate Splunk APM 10 out of 10.

Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
PeerSpot user
Ayush Rohilla - PeerSpot reviewer
Works at a tech company with 1,001-5,000 employees
Real User
Top 10
Troubleshoots quickly and offers end-to-end visibility across the environment
Pros and Cons
  • "It is a good tool. It allows you to set alerts for application and infrastructure monitoring, and it allows you to create dashboards."
  • "They can improve the flow system and the keyword language. It has predefined keywords, but they can be improved."

What is our primary use case?

I am a technology analyst. I have been working on a financial project in the US. For this project, I used Splunk APM for troubleshooting and reviewing the logs, and finding errors. Most of our APIs ran on Splunk APM, and we used it to find errors in our production environment.

We are no longer using Splunk APM. We have switched to Dynatrace.

How has it helped my organization?

Splunk APM is very good for monitoring purposes. You can watch application-to-application flows. If you just click on a flow, you can go step by step and debug an issue. The places with errors are marked in red. The API or the application in which you are getting an error is red. From there, you can go to the log or the error, and then the person responsible for that particular API or application has to fix it.

Splunk APM gives tools for user monitoring, logs observability, infrastructure monitoring, synthetic monitoring, and automated on-call. 

Splunk APM provides real-time data. In the logs, if you want to see errors related to status 404, you can just write one keyword, and you will get the results.

Splunk APM offers end-to-end visibility across the environment, but it also depends on how your business is set up on Splunk APM.

Splunk APM helped to reduce our mean time to resolve (MTTR). Previously, I had to log into my VPN, run commands, and see the logs. After having Splunk APM, I could click on one link and go through the logs. 

We could set up Splunk APM based on our environment. I worked on one project with Splunk APM. In that project, we faced a lot of issues, and I resolved the issues with the help of Splunk APM. I found the accurate logs and the easiest way to resolve the errors.

What is most valuable?

Splunk APM is the most advanced application for performance monitoring and troubleshooting for cloud-native applications and microservices.

The ability to troubleshoot is valuable. While running any product or API, we need to troubleshoot issues. We need to find the error in the logs. In Splunk APM, we have the section logs. In that section, we can search with any particular keywords. Before Splunk APM, I also worked with Splunk Enterprise where we have various dashboards to monitor. 

It is an application performance monitoring and observability tool. It is a very good tool. You need to use the documentation on Splunk's website. From there, you can learn many things. I have Splunk certification. You can dive deep into it. For me, it gives end-to-end visibility into our production environment.

What needs improvement?

They can improve the flow system and the keyword language. It has predefined keywords, but they can be improved. I also use LogMeIn where I can use predefined keywords to see the logs. 

They should give us the option to use our own language to search. For example, I should be able to search for an ID name along with an error or status code. 

For how long have I used the solution?

I worked with Splunk APM for one and a half years.

What do I think about the stability of the solution?

I have not faced any downtime. I have worked with Splunk APM for one and a half years, and I did not face any downtime during this duration of time.

What do I think about the scalability of the solution?

I have never faced any issues with scalability.

How are customer service and support?

I did not have any need to contact support because I did not face any issues. 

Which solution did I use previously and why did I switch?

We used another solution previously. In Splunk Enterprise, it is easier to create dashboards. You can easily set up application alerts and infra alerts. You can search with metrics and you can set alerts based on a specific error. Whenever that error occurs, you will receive an alert.

How was the initial setup?

I am not involved in its deployment. In terms of maintenance, it is owned and managed by Splunk. Everything is maintained by Splunk. I have not faced any downtime with Splunk APM. I have also used Splunk Enterprise previously. With both of these products, I did not face any downtime. 

What's my experience with pricing, setup cost, and licensing?

The pricing is reasonable.

What other advice do I have?

It is a good tool. It allows you to set alerts for application and infrastructure monitoring, and it allows you to create dashboards. You can set alerts based on the threshold or traffic.

For logging purposes, Splunk APM is very good, but we should be able to use our own search query language. Currently, we can only search based on the predefined tags.

Overall, I would rate Splunk APM a nine out of ten.

Which deployment model are you using for this solution?

Hybrid Cloud
Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
PeerSpot user
Mr at a educational organization with 1,001-5,000 employees
Real User
Enables users to forward logs to a centralized location and intuitive dashboard functionality
Pros and Cons
  • "I like the fact that Splunk APM makes it easy to connect to the application database and run queries against the data."
  • "I've been using the Splunk query language, and it can be a bit time-consuming to set up the queries I need."

What is our primary use case?

I use Splunk primarily from a gateway operations perspective. I work on application support. As part of that support, we regularly monitor the application dashboards built in Splunk using the logs. I covered this earlier this month.

How has it helped my organization?

The real problem we were facing was that we were unable to get all of our logs into a single place. We have an on-premise application with multiple servers across different data centers, and we needed to be able to view all of the logs together in order to troubleshoot any problems. That's why we started using Splunk to forward all of our logs to a single location.

Moreover, Splunk APM gives us end-to-end visibility across our entire on-premise environment. 

Another biggest benefit I've seen is the ability to quickly identify problems using Splunk alerting. We set up alerts against our application metrics, and this has helped us to resolve major issues much sooner. We can now identify problems as soon as they occur, which gives us time to take corrective action before they impact our users.

Splunk has reduced the amount of time our operations team spends investigating problems. This has freed up our engineers to focus on other tasks, such as improving our application performance and adding new features.

What is most valuable?

I like the fact that Splunk APM makes it easy to connect to the application database and run queries against the data. I also like the fact that Splunk APM allows me to use log forwarders to forward logs to a central location, where I can then build dashboards to view the data. The dashboards are probably my favorite feature of Splunk APM.

What needs improvement?

I've been using the Splunk query language, and it can be a bit time-consuming to set up the queries I need. I've had to look at a lot of community forums to find the filters I need, and it can be difficult to get the details I need.

For how long have I used the solution?

I have experience building dashboards and other things with Splunk APM.

I've been using Splunk APM for over a year now. As part of my job in application support, I regularly create and maintain dashboards for our applications using Splunk APM. I also use dashboards to create alerts based on certain metrics.

Moreover, I'm currently working on a project to create a new dashboard for our customer support application.

What do I think about the stability of the solution?

The stability of the solution is good because I have never had outages I have seen so far. In terms of usage, it's good in terms of availability.

How are customer service and support?

I haven't had to contact the support yet. We have a separate team that maintains and builds our relationship with Splunk, so they would be the ones to contact if we had any issues.

What about the implementation team?

The solution doesn't require any maintenance. 

Which other solutions did I evaluate?

We used New Relic and AppDynamics before Splunk. AppDynamics was our APM tool, and I'm still using New Relic for monitoring Splunk. New Relic is great for log monitoring, and it's our main tool for internal application monitoring.

What other advice do I have?

With Splunk APM as an enterprise solution, various factors come into play. Right now, considerations include pricing and how they envision the solution to work for them. Some might want the solution to be cloud-based. It largely depends on the volumes they anticipate. Organizations must decide how much they're willing to invest, especially when comparing it to other investments they've made. With the current economic recession and organizations looking to cut costs, it's crucial to evaluate the volumes and aspects of Splunk that are most relevant to them.

Overall, I would rate the solution an eight out of ten. 

Which deployment model are you using for this solution?

On-premises
Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
PeerSpot user
Senior Network Administrator at a comms service provider with 51-200 employees
Real User
Top 20
The solution has enabled us to be more proactive, so we can identify and respond to an issue before there is a failure
Pros and Cons
  • "Splunk Infrastructure Monitoring gives us complete visibility without the need for storage."
  • "Splunk could be better integrated with configuration manager solutions so we can automatically resolve issues without human interference."

What is our primary use case?

We use Splunk Infrastructure Monitoring to get an overview of what's happening in our customers' infrastructure. We're monitoring our servers, network, IoT devices, etc. We're a service provider, so the solution is installed in one place. 

How has it helped my organization?

Splunk Infrastructure Monitoring has enabled us to be more proactive. We can identify and respond to an issue before there is a failure. It has helped us significantly. For example, if somebody is attacking us we can detect that there is an increase in traffic and investigate to see if it's legitimate. We can block them or take other actions before it becomes a problem. 

What is most valuable?

Splunk Infrastructure Monitoring gives us complete visibility without the need for storage. We can visualize our infrastructure. Where is the traffic going? Are there any attacks? What are our vulnerabilities?

What needs improvement?

Splunk could be better integrated with configuration manager solutions so we can automatically resolve issues without human interference. 

For how long have I used the solution?

We have used Splunk Infrastructure Monitoring since 2015.

What do I think about the stability of the solution?

Splunk Infrastructure Monitoring is stable. 

What do I think about the scalability of the solution?

Splunk is scalable. It's easy to add more devices as needed. 

How are customer service and support?

I rate Splunk support an eight out of ten. 

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

Before Splunk, we used multiple vendors, including Cisco, SolarWinds NPM, and WhatsUp Gold. 

How was the initial setup?

The deployment process isn't complicated. We installed Splunk on a VM and started it. We have a team to deploy and monitor it.

What was our ROI?

Splunk is worth the investment. When an incident happens, you need reports immediately, and Splunk is the best monitoring solution for this. 

What's my experience with pricing, setup cost, and licensing?

Splunk is expensive, but it's the best solution for the job. 

What other advice do I have?

I rate Splunk Infrastructure Monitoring a nine out of ten. Splunk is a responsive piece of software. It's user-friendly and easy to get the data you need. I advise people to take the time to learn how to create reports and analytics.  

Which deployment model are you using for this solution?

On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Peder Illum - PeerSpot reviewer
Consultant at Medcom
Consultant
Top 10
Gives us early warning on problems that could arise
Pros and Cons
  • "Splunk has drawn our attention to how the network is running. If there are alarms on things that are not functioning, it gives us early warning on problems that could arise."
  • "It's a bit difficult to use. It takes some time to get into it and to get it to do what you would like it to do. It is not straightforward to use it."

What is our primary use case?

We have used Splunk to give us insight into the NetFlow of the traffic running through our network. We connect different networks but we only use on-prem. We are in the middle of a spider web, providing these services to different networks. We are trying to gain visibility into the traffic that traverses our network internally.

We are interested in the traffic volume because the services we are looking at are endpoint-encrypted, meaning encrypted traffic between a service provider and a client in another network. So we are not able to look into the media stream.

The networks we are connecting have their own security boundaries and their own security levels, and we don't mess with that. We are just trying to let them talk together. 

We have been using Splunk for monitoring who is logging in and how and when.

How has it helped my organization?

It has given us visibility into what is going on in the network, such as how much traffic is running to and from the services, but we are not using Splunk in a straightforward way. When we are looking into reports on how much data has been used, we need to look into another system and enrich it with data from Splunk.

Splunk has drawn our attention to how the network is running. If there are alarms on things that are not functioning, it gives us early warning on problems that could arise.

In terms of operational performance, the efficiency, Splunk has helped us improve. We could have found other tools that would have given us the same efficiency, but this was the tool that we chose. From that perspective, it has been of value to us.

It would have helped us reduce our mean time to detect but I can only guess at how much; perhaps by 25 percent. And we would see a similar reduction for mean time to resolve.

What needs improvement?

It's a bit difficult to use. It takes some time to get into it and to get it to do what you would like it to do. It is not straightforward to use it. Once you have the dashboards for collecting and analyzing transactions configured, they are okay, but it takes some time to do it. Configuration could be easier.

For how long have I used the solution?

We have been using Splunk for about eight years.

What do I think about the scalability of the solution?

We have not looked at Splunk as a means of being able to scale, but we have not been hindered by using Splunk. Our goal has not been growth, but maintaining stable and secure networking, and this is what we have achieved. But with or without Splunk, we would have achieved that anyway.

How are customer service and support?

We really haven't had any technical issues where we involved Splunk's support.

Which solution did I use previously and why did I switch?

We did not have a previous solution like Splunk, other than in-house-developed tools. We got acquainted with Splunk as part of the tender for our network infrastructure, and from that perspective, it has been okay.

What's my experience with pricing, setup cost, and licensing?

Splunk has been fairly expensive, but it has been predictable. You are not punished if you are looking into much more data if you are, for example, under attack. Other tools could be more expensive to use if they charge per incident or the amount of data you are looking into. With other solutions, you could be punished if you need to index more data because of an attack, such as a DDoS attack, and you need to do some forensics on the data.

What other advice do I have?

Why shift to something you don't know when you are, perhaps, happy enough with the tool that you already have? Think about whether you could develop that tool into something that would give you the visibility you would like to have, instead of using Splunk. Are you looking into incidents, traffic flows, indexing per day, or is the issue that you're looking for an alternative with a better price? Think about why you are considering shifting from a tool that you already know.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Buyer's Guide
Download our free Splunk Observability Cloud Report and get advice and tips from experienced pros sharing their opinions.
Updated: June 2025
Buyer's Guide
Download our free Splunk Observability Cloud Report and get advice and tips from experienced pros sharing their opinions.