Try our new research platform with insights from 80,000+ expert users
Derek Hemsley - PeerSpot reviewer
Cyber Security Detection Engineering Associate & Director at a healthcare company with 10,001+ employees
Real User
Top 20
Good for data aggregation and correlation for centralized logging and monitoring
Pros and Cons
  • "The most valuable feature of Splunk Cloud Platform is the ability to correlate events together and combine the data into one event."
  • "Splunk Cloud Platform should have better integrations with its suite of tools."

What is our primary use case?

We use Splunk Cloud Platform for data aggregation and correlation for centralized logging and monitoring.

How has it helped my organization?

Splunk Cloud Platform has helped our organization reduce risk and allow for threat investigation to catch potential malicious traffic before it causes damage.

What is most valuable?

The most valuable feature of Splunk Cloud Platform is the ability to correlate events together and combine the data into one event.

The benefits we saw from using Splunk Cloud Platform are the time to detect and the ability to investigate faster.

Our organization monitors multiple cloud environments. Splunk Cloud Platform's direct cloud connection capabilities make data transfer easy.

Splunk Cloud Platform's end-to-end visibility into your cloud-native environment is key for security posture.

Splunk Cloud Platform has helped reduce our mean time to resolve by a significant portion.

Splunk Cloud Platform has helped improve our organization’s business resilience.

We have seen time to value using Splunk Cloud Platform. We immediately saw time to value after implementing the solution.

The consolidation of tools gives one place to look for logs and events. I wish there were more ways to consolidate the consoles.

Splunk Cloud Platform is easy to use, and users can quickly understand and do pretty much anything that their minds can create.

What needs improvement?

Splunk Cloud Platform should have better integrations with its suite of tools. Splunk Cloud Platform should include a more seamless connection with ES.

Buyer's Guide
Splunk Cloud Platform
July 2025
Learn what your peers think about Splunk Cloud Platform. Get advice and tips from experienced pros sharing their opinions. Updated: July 2025.
865,295 professionals have used our research since 2012.

For how long have I used the solution?

I have been using Splunk Cloud Platform for eight years.

What do I think about the stability of the solution?

The solution provides good stability.

What do I think about the scalability of the solution?

As long as you have money, scaling the solution is easy.

How are customer service and support?

Our direct customer support team is very responsive. However, it's very hit or miss with Splunk tickets and trying to reach out. Most likely, we get escalated because they can't help us. It's very hard to work through issues that need to be resolved quickly via email. The conversations back and forth take a long time, and technical support takes a while to resolve urgent issues.

How would you rate customer service and support?

Neutral

How was the initial setup?

The Splunk engagement in the deployment was helpful, but there were many issues after implementing everything. So, it was smooth but with many hiccups.

What's my experience with pricing, setup cost, and licensing?

Splunk Cloud Platform is an expensive solution.

What other advice do I have?

Overall, I rate the solution an eight out of ten.

Which deployment model are you using for this solution?

Public Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Amazon Web Services (AWS)
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Ian Gatundu - PeerSpot reviewer
System engineer at Agile Cloud Ltd
Real User
Top 10
It improves our visibility and decision-making while helping us meet compliance standards
Pros and Cons
  • "The Cloud Platform interface is cleaner than Splunk Enterprise's monitoring console. You can easily understand what's happening with your indexes. It's more refined than Splunk Enterprise's console, but they have the same feel and function."
  • "The only disadvantage of Splunk Cloud compared to Splunk Enterprise Security is that you only have two options for long-term storage: AWS S3 Buckets and GCP."

What is our primary use case?

We use Splunk Cloud Platform to ingest data from on-prem environments. Most people have Splunk Enterprise Security running on a server, but Splunk developed the Splunk Cloud Platform to ingest the data into the cloud. It works like Splunk Enterprise, but you must download apps to get some features. Our clients are mostly large enterprises in the financial industry. 

How has it helped my organization?

Splunk Cloud Platform improves our visibility and decision-making. Splunk helps us meet compliance standards. It's certified for multiple standards, such as PCI, GDPR, and HIPAA.

What is most valuable?

The Cloud Platform interface is cleaner than Splunk Enterprise's monitoring console. You can easily understand what's happening with your indexes. It's more refined than Splunk Enterprise's console, but they have the same feel and function. 

It's easy to monitor multiple cloud environments because you can create custom dashboards for any use case you may have. It offers good visibility because it integrates with the ITSI app, providing a clear overview of your environment. 

Integrating Splunk with other components on the cloud and network resources is effortless because it can collect data from various sources, including stored data from long-term storage.

Splunk's reporting offers a good visualization of your data. You can visualize the statistics based on your searches. It produces some helpful graphs that enable you to easily compare what's happening in your search. It's very comprehensive. 

What needs improvement?

The only disadvantage of Splunk Cloud compared to Splunk Enterprise Security is that you only have two options for long-term storage: AWS S3 Buckets and GCP.

For how long have I used the solution?

We started using Splunk Cloud Platform in January 2024, so it has only been a few months. 

What do I think about the stability of the solution?

I rate Splunk Cloud 10 out of 10 for stability. Okay. Splunk is trying to push more people to the cloud, so they've made it really stable. 

What do I think about the scalability of the solution?

I rate Splunk 10 out of 10 for scalability. Scalability depends on whether your on-prem deployment is stable and deployed properly, as the Splunk Cloud Platform is an extension of Splunk Enterprise Security. It's easy to build another use case. or add servers, so I feel it's highly scalable. 

How are customer service and support?

I rate Splunk support nine out of 10. We provide frontline support to our clients, but we periodically pass them on to the vendor. 

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

We previously used IBM and Fortinet. We prefer Splunk because of its integration. You can integrate multiple solutions and customize it for your environment depending on your use case. 

How was the initial setup?

Deploying Splunk Cloud Platform is pretty straightforward once you have the enterprise environment set up on-prem. You download the cloud app and extension. The deployment time depends on the size of your environment. It takes about a day for a small environment. A large-scale deployment can take up to a week if you have multiple tiers and a disaster-recovery site. 

After deployment, the product requires continuous engagement with the Splunk team. You must continue to fine-tune it to ensure everything runs smoothly. However, there isn't much maintenance once it is tuned and deployed properly. 

What's my experience with pricing, setup cost, and licensing?

Splunk is a bit more expensive than some solutions, but customers can derive more value from it due to the features it has.

What other advice do I have?

I rate Splunk Cloud Platform nine out of 10. I recommend ingesting data into the cloud if possible. Even if you have an on-prem environment, it still helps to ingest data into the cloud. 

Which deployment model are you using for this solution?

Public Cloud
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
PeerSpot user
Buyer's Guide
Splunk Cloud Platform
July 2025
Learn what your peers think about Splunk Cloud Platform. Get advice and tips from experienced pros sharing their opinions. Updated: July 2025.
865,295 professionals have used our research since 2012.
Ritesh Vishwakarma - PeerSpot reviewer
Engineer at a tech services company with 501-1,000 employees
Real User
Top 10
Gives us better buffering performance and lower latency if we use the right components
Pros and Cons
  • "In an enterprise, you need a universal or heavy forwarder. If you don't have that, you need an HSE token or API request call and all the different components. In Splunk Cloud, you just have one instance to search all the data in your index. You don't need to manage it because Splunk handles that."
  • "First-time users may struggle with the user interface. When I first used Splunk, I entered my username and password. After that, we get a dashboard on the left side with apps. At the top, you can click the gear icon to view the settings. Within those settings, there's a distributed console option with several settings. It's a bit overwhelming for a beginner. The user knows what they want and can search for it in the search bar. If I see several apps, my first instinct is to scroll down to find the app, or perhaps you will find that search and report. That bugged me when I was learning."

What is our primary use case?

One client wanted their data in a readable format. He was in the UK, but his data center was in the US, so he tried to forward his data to the indexer. Because of the time zones, he faced some time stamping issues. They reached out to us to open a case that got assigned to me.

I learned which US time zone the data center was in and set the time stamps in the future. We changed the preferences to convert it into GMT so that whenever the data is onboarded to the indexes via universal or heavy forwarder, we can fetch the data in real-time.

We primarily use virtualization and deploy in Docker containers. We seldom use any physical servers. It's mostly deployed in a cloud environment or a virtual machine. It's typically Docker but sometimes Azure.

How has it helped my organization?

Splunk Cloud saved us a lot of money because we're working with databases like MongoDB and Oracle and using Splunk as a sync tool. It has its own indexes that cut costs by 15 to 20 percent. 

It also improves our decision-making process. In one scenario, we compared the client's data from last year to this April and saw the year-on-year profit and loss. We could see which projects were successful. Compared to another SIEM or monitoring tool, it saved us time because the data is presented in a clean, customizable dashboard. 

What is most valuable?

In an enterprise, you need a universal or heavy forwarder. If you don't have that, you need an HSE token or API request call and all the different components. In Splunk Cloud, you just have one instance to search all the data in your index. You don't need to manage it because Splunk handles that. 

If you are using Splunk Enterprise, you need to understand, from A to Z, how the indexes and searches work and where the data is coming from. Splunk Cloud has a beautiful, user-friendly UI that lets you navigate all the settings.

It doesn't matter where the data comes from for integration. The dashboard gives you a brief overview. 

When we're onboarding all that data using heavy forwarders, Splunk gives us better buffering performance and lower latency if we use the right components. If I use a light or universal forwarder, it often doesn't parse on the other end. Our projects use heavy forwarders and put those data into the index services while defining which indexes they should index. We are also micromanaging where that data should be. 

The reporting is good so far. Sometimes, I help my clients improve their user experience. As an engineer, I would suggest that if a solution has back-end compatibility, clients should get out of their comfort zone and customize another app to create a dashboard or something else.

What needs improvement?

First-time users may struggle with the user interface. When I first used Splunk, I entered my username and password. After that, we get a dashboard on the left side with apps. At the top, you can click the gear icon to view the settings. Within those settings, there's a distributed console option with several settings. It's a bit overwhelming for a beginner. The user knows what they want and can search for it in the search bar. If I see several apps, my first instinct is to scroll down to find the app, or perhaps you will find that search and report. That bugged me when I was learning.

Application support is another problem. We created a custom Palo Alto app that isn't fully supported by the latest version of Splunk. We had to downgrade to older versions to use the custom app properly. That was one problem we faced daily with one client. 

For how long have I used the solution?

I have been using the Splunk Cloud Platform for two years.

What do I think about the stability of the solution?

I rate Splunk Cloud seven out of 10 for stability. 

What do I think about the scalability of the solution?

I rate Splunk Cloud eight out of 10 for scalability.

How are customer service and support?

I rate Splunk support six out of 10. They're knowledgeable, but their response times are sometimes slow. 

How would you rate customer service and support?

Neutral

Which solution did I use previously and why did I switch?

We have Prometheus, but that only monitors Grafana and shows you a dashboard. Splunk is not just monitoring or grabbing data you search for. I've worked with cloud and enterprise. When we started using Splunk Cloud, we used it more like a dashboard to search data. Based on my understanding, I could create applications. 

After moving into the enterprise side, I understood Splunk even more, including its components, bucket lifecycles, and how the indexes and configurations work. It's not simply transferring data from one to another. I can grab data from any system that consists of raw data. Splunk can also identify those data in the timestamp index form. We don't have any other vendors to compare it to. 

How was the initial setup?

Deploying Splunk Cloud Platform is straightforward unless you use an automation tool like Ansible, Puppet, or Chef. It takes four to five hours. Installation can take a day in some cases, but it typically can be completed in less than five hours unless you're dealing with more complex data.

What's my experience with pricing, setup cost, and licensing?

Splunk Cloud is affordable, depending on your license. I don't know how much it costs exactly, but my colleague said it depends on your licensing and which features you use. 

What other advice do I have?

I rate Splunk Cloud Platform eight out of 10. I would recommend this product. 

Which deployment model are you using for this solution?

Public Cloud
Disclosure: My company has a business relationship with this vendor other than being a customer. partner (consultant)
PeerSpot user
reviewer2499690 - PeerSpot reviewer
Principal Site Reliability Engineer at a pharma/biotech company with 1,001-5,000 employees
Real User
Information is easier to get now that it is all aggregated and centralized in one place with one interface
Pros and Cons
  • "Previously when in our company, we had logs everywhere on multiple systems, it was a really big pain for me trying to find what I wanted. Now that it is all aggregated and centralized in one place with one interface, it is just a lot easier to get the information that I need."

    What is our primary use case?

    I use Splunk Cloud Platform to analyze our company's logs and the applications that we run.

    How has it helped my organization?

    Previously when in our company, we had logs everywhere on multiple systems, it was a really big pain for me trying to find what I wanted. Now that it is all aggregated and centralized in one place with one interface, it is just a lot easier to get the information that I need.

    What is most valuable?

    The most valuable feature of the solution stems from the fact that I just like having one single point where all of our logs are aggregated and then having one interface that I can query and find the information that I want out of it.

    My organization monitors multiple cloud environments and even the on-premises part. I would say that so far, it has been fine and easy to use to monitor multiple cloud environments using Splunk Cloud Platform. The tool works effectively, and it gets stuff from our on-premises servers into the cloud. It gets stuff from AWS into the cloud. I am able to, you know, use the single interface to access all the information I need.

    It is very important for our organization that Splunk Cloud Platform has end-to-end visibility into your cloud-native environment. It is important since it helps to be able to see all the aspects of what our services are doing and how they are operating.

    It helps with the mean time to resolve since it makes it easier to find the errors as they have occurred, so it has been a helpful tool.

    I don't know how much the product has helped my organization improve business resilience.

    I wouldn't know if my company has experienced any cost-efficiency by splitting to Splunk Cloud Platform.

    I know that Splunk's unified platform helps consolidate networking, security, and IT observability tools for our company. Our company has an InfoSec team using it for their SCIM stuff, and then we have IT using it for some of the things they need to gather. Multiple teams in my company have benefited from using the tool. The consolidation of tools does impact our organization since I think it is probably easier for everyone to get access to stuff because everything is in one place, and it is one of the biggest impacts of the product I can think of right now. Instead of having things spread out across multiple vendors and multiple tools, it is all kind of in one thing that we can get at, and so it is probably easier for us to train people, and we know, like, how to access the solution since it is just one thing we have to learn.

    What needs improvement?

    I am relatively new to the platform. So far, I have been able to use it to do what I need. I know that there are a lot more features and functionality that I don't even know yet, so I am still on the learning side. I don't really have any recommendations related to things that need to be improved in the tool.

    So far, it meets my needs, so I don't need to see any additional features in the tool.

    For how long have I used the solution?

    I have been using Splunk Cloud Platform for six months. My company is just a customer of the solution.

    What do I think about the stability of the solution?

    I have not had a problem with the tool's stability. It has been available every time I needed it, and it has captured every information we have sent to it. It has been not just a good but a great solution.

    What do I think about the scalability of the solution?

    I think the tool's scalability is fine. I have not run into any issues with the tool's scalability, so I guess it's good.

    How are customer service and support?

    I have not had the chance to interact with Splunk's customer service or support, so I can't really evaluate them.

    Which solution did I use previously and why did I switch?

    I don't know if there was some other solution used previously in my company. My company is just a customer of the tool.

    How was the initial setup?

    The product was deployed before I joined the organization.

    The solution is deployed on a hybrid cloud model, and my company has opted for AWS.

    What about the implementation team?

    I believe that my company approached an integrator to help with the deployment of the product, but I am not sure about it.

    What was our ROI?

    I don't know about the ROI part.

    What's my experience with pricing, setup cost, and licensing?

    I don't know about the pricing, setup cost, and licensing part.

    What other advice do I have?

    I rate the solution a ten out of ten.

    Which deployment model are you using for this solution?

    Hybrid Cloud

    If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

    Amazon Web Services (AWS)
    Disclosure: My company does not have a business relationship with this vendor other than being a customer.
    PeerSpot user
    Nagendra Nekkala. - PeerSpot reviewer
    Senior Manager ICT & at Bangalore International Airport Limited
    Real User
    Top 5Leaderboard
    Boosts performance and helps simplify monitoring across platforms and data management
    Pros and Cons
    • "The data management and instant search features are the most valuable ones for us, as they allow us to instantly retrieve information needed for reports and security compliance."
    • "Splunk should increase the frequency of new feature releases, particularly those related to real-time operational flow monitoring and analytics reporting."

    What is our primary use case?

    We leverage the Splunk Cloud Platform to effectively manage the vast amounts of machine-generated data, thereby ensuring application management security compliance.

    We implemented the Splunk Cloud Platform to enhance our customer experience and optimize the data storage costs. We can convert the log data into numerical data points when requested.

    How has it helped my organization?

    The Federated search helps retrieve data in a better way.

    Splunk Cloud Platform simplifies monitoring across multiple cloud environments, providing real-time insights into operational flow. It also streamlines data conversion, reducing the data-driven process for the company.

    Splunk Cloud Platform's machine learning and AI capabilities simplify data management and provide clear visibility into multiple environments.

    The AI makes it easy to integrate with other systems and applications in our environment.

    The Splunk Cloud Platform reporting provides good insight.

    Splunk Cloud Platform significantly boosted our performance and cost-effectively optimized data sets, delivering immediate benefits.

    Thanks to the Splunk Cloud Platform we can make decisions within the organization much faster.

    Splunk Cloud Platform empowers our organization to access data efficiently, ensuring compliance with privacy and regulations through actionable insights.

    Splunk Cloud Platform strengthens our security, particularly in handling complex processes.

    What is most valuable?

    The data management and instant search features are the most valuable ones for us, as they allow us to instantly retrieve information needed for reports and security compliance.

    What needs improvement?

    Splunk should increase the frequency of new feature releases, particularly those related to real-time operational flow monitoring and analytics reporting. It has been over a year since any significant updates were added to the Splunk Cloud Platform.

    For how long have I used the solution?

    I have been using the Splunk Cloud Platform for one year.

    What do I think about the stability of the solution?

    Splunk Cloud Platform is stable.

    What do I think about the scalability of the solution?

    Splunk Cloud Platform is scalable.

    Splunk Cloud Platform's resilience is good.

    How was the initial setup?

    The initial deployment was straightforward. The deployment took around four hours and required two people.

    Which other solutions did I evaluate?

    We evaluated Victoria Experience but it was not suitable for our environment.

    What other advice do I have?

    I would rate Splunk Cloud Platform an eight out of ten.

    We have around 150 users.

    No maintenance is required from our end.

    I recommend Splunk Cloud Platform. It helps monitor all the respective functions.

    Which deployment model are you using for this solution?

    Private Cloud

    If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

    Amazon Web Services (AWS)
    Disclosure: My company does not have a business relationship with this vendor other than being a customer.
    PeerSpot user
    Darshan G Waghmare - PeerSpot reviewer
    Senior Project Engineer at Wipro Limited
    Real User
    Top 20
    Offers alert scheduling, dashboard creation, and log monitoring
    Pros and Cons
    • "It is a stable product."

      What is our primary use case?

      My primary use case is for monitoring security logs and system logs. Apart from that, we create monitoring alerts and dashboards. 

      We also use it for Splunk application configuration, troubleshooting, and server patching. We have many other operations.

      How has it helped my organization?

      Integration with other systems and applications in the environment is easy. For example, we have Fortinet analyzer. We have to pull the logs from network devices into Splunk. We use Cribl pipeline. 

      For Cribl pipeline, we get that data to the Splunk syslog servers. From Splunk syslog servers, we're getting it into the indexes.

      According to the license, suppose we have to onboard thousands of servers. Suppose a scenario, for thousands of servers, the user or client requires only specific events. So for that, we use props and cons and regex for specific events. And only specific events will be calculated in the license. That will consume the license also.

      What is most valuable?

      The incident response time depends on the query and alert configuration, and also on the environment and how the logs are streamed. By analyzing these factors, it takes a maximum of one to two days for one incident.

      Alert scheduling, dashboard creation, and log monitoring are the most valuable features. 

      Federated search depends on the data we pull. We have three types of searches. We use federated search for long-running queries.

      We have, like, 20% of MacBook Cloud environment. It is easy to monitor multiple cloud environments, but there are some onboarding challenges. We are onboarding from the back end and also using Hacktoken. Apart from that, we get data to Splunk using Cripple pipelines from Syslog servers.

      Reporting is like this: if critical data is used by the client, we send it to the data user according to the schedule.

      For log monitoring, we can definitely suggest Splunk is a good tool. And it helps with decision making processes.

      For monitoring security logs, it's the best tool.

      For how long have I used the solution?

      I use Splunk Cloud. Previously, I used Splunk Enterprise, but after that, we migrated to Splunk Cloud.

      I have been using Splunk Cloud for more than three years. 

      What do I think about the stability of the solution?

      It is a stable product. Right now, we are migrating from Datadog to Splunk, so I guess that's why Splunk is better than other tools.

      How was the initial setup?

      It's deployed across multiple locations.

      It does require maintenance. It depends on what Splunk vendor is being used.

      What's my experience with pricing, setup cost, and licensing?

      The pricing depends on the logs and how many logs we monitor. On a daily basis, it depends on the events. Those licenses will be calculated in Splunk Cloud.

      What other advice do I have?

      Overall, I would rate the solution a seven out of ten, with ten being best. 

      All the features for log monitoring, security, alerting, indexing of the data, parsing of the data are good. That feature makes sense and is helpful to everyone.

      I would recommend it to others. 

      Which deployment model are you using for this solution?

      Public Cloud
      Disclosure: My company does not have a business relationship with this vendor other than being a customer.
      PeerSpot user
      reviewer2499573 - PeerSpot reviewer
      4 System Engineer at a religious institution with 10,001+ employees
      Real User
      Helps improve visibility, reduce administrative work, and save costs
      Pros and Cons
      • "Splunk Cloud has helped us to be able to focus on getting more information out of our data."
      • "We're interested in learning more about the new AI features, especially the natural language to SPL conversion."

      What is our primary use case?

      Our security team uses the Splunk Cloud Platform heavily. We index that data that is relevant to security for over a year. Most of our indexes, we only keep for 30 to 45 days. But for security, we keep it for a year here. It is an essential tool for our security team in investigating incidents and looking at the potential compromises, and exploits, of all those types of things. That's one example.

      I'm one of two Splunk Engineers in the organization and almost every department uses Splunk. We create dashboards for different organizations. For example, We have temples all over the world. We produce statistics for the temples about how many people have visited each day, and how many sessions were done in different languages. That type of thing is all done through Splunk dashboards. Our missionary department has over 80,000 missionaries all over the world, statistics about what they are doing and the applications they are using are all done through Splunk.

      How has it helped my organization?

      Splunk Cloud Platform helped remove a lot of that administrative work, but also, it's much easier on the cloud for us to ramp up our SVC units if we see more demand and to be able to add more storage to our indexers. That's one thing for us as administrators that helps to be able to ramp it up quickly. When we were using Splunk Enterprise, that was a much more involved process, but now with Splunk Cloud, it's much easier to ramp that up. My partner and I are good at making sure that all of our users are using Splunk efficiently. We give them training regularly to make sure that their queries are well written, that they're not using indexes they shouldn't be, and that they're using the proper commands to be able to get the information they want. We do have to do this periodically because more and more of our users are using Splunk frequently, and we'll have to talk to a Splunk rep to increase our SVCs. For us, as administrators, that's very helpful.

      We monitor multiple cloud environments using Splunk Cloud. It's been quite easy for us. We have an in-house Cloud Foundry and we use AWS and Azure quite a bit. We haven't had problems integrating or monitoring with any of those platforms. It's been great for us.

      The end-to-end visibility that Splunk Cloud Platform has in our cloud-native environments is important. We do a lot of correlation across the entire enterprise. We need to have good visibility into all of our logs across all of our cloud Platforms, and in-house on-premise stuff, which we're getting with Splunk.

      We use a lot of different monitoring tools, not just Splunk. We use Nagios, ThousandEyes, AppDynamics, and Dynatrace. Splunk is an important part of that. It is a mission-critical application for us. The alerts we set up in Splunk are ones we can't do with the other tools. Every one of those tools is a key piece of what we do as a monitoring team, but what we love about Splunk is that we can create alerts that we can't do with the other tools. That has helped us reduce our mean time to resolution.

      The Splunk Cloud Platform has helped improve our organization's business resilience. Splunk helps predict, identify, and solve problems in real-time. What we love about Splunk is its flexibility to pull out data that we can't see in other applications or that the commercial office software has not produced itself. But through the logs and being able to adjust it to Splunk and being able to write the queries that we need to, we can pull that data out, and it helps us to be much more efficient in predicting potential problems because we know our applications well and know the red flags to watch for. We can create the alerts needed to predict when something can potentially go down or have problems.

      We have seen cost efficiency by switching to the Splunk Cloud Platform. The biggest part for my partner and me is that Splunk Admins saves us time. I used to be the guy who would patch all of our enterprise indexers, servers, and distribution servers. That would take me quite a bit of time. Even though we had automated scripts that would do a lot of that, it still took a fair chunk of time to go out and do the maintenance and patching required. That freed up a lot of our time, made us a lot more efficient, and allowed us to work on other projects we couldn't do before. I do front-end development for some other products, but I didn't have the time before, and switching to Splunk Cloud has freed us up. Being able to ramp up our SVCs and storage is much easier than it was before. We had to spin up virtual servers, provision them, and ensure licensing. With Splunk Cloud, it's much faster and easier. The total cost of ownership has improved.

      What is most valuable?

      Before we started using Splunk Cloud, we were using Splunk Enterprise. My partner and I were spending quite a bit of our time keeping the servers patched, up to date, and running the way that we wanted them to. Now that's all gone with Splunk Cloud. That has freed up a lot of our time so that I can spend most of our time helping people, learning SPL, and helping them with their dashboards, alerts, and reports. Splunk Cloud has helped us to be able to focus on getting more information out of our data. Whereas before, we were doing mostly administrative stuff. Now we don't have to do that anymore.

      What needs improvement?

      We're interested in learning more about the new AI features, especially the natural language to SPL conversion. While we jokingly worry these features might replace us, our main focus is helping users understand Splunk and build dashboards. We're curious how these AI features will integrate into our work, how many people will use them, and if there will still be a need for our Splunk expertise. Overall, we're excited to see how AI will impact our work.

      For how long have I used the solution?

      I have been using Splunk Cloud Platform for three years.

      What do I think about the stability of the solution?

      Splunk Cloud Platform has been extremely stable. In some of the major upgrades, like, when we switched over to version nine there were a few hiccups that caused performance slowdown, but as far as stability, it's been great. In the last year, it's been extremely stable and very performant. It's just in the months after some of the changes over to version nine, we had a few problems, but nothing since then.

      What do I think about the scalability of the solution?

      We have no concerns about scalability. We frequently upgrade the number of SVC units we require. We're using Splunk Cloud enterprise-wide. We're getting more and more departments using Splunk or asking to use it. Everything is on Splunk on a basic level. Security is a big deal. All our virtual servers, cloud environments, and everything that ties into security are already being adjusted to Splunk. As far as the application level, people want to get more information out of their application or data. We don't have problems, questions, or concerns about scalability. We know it's there.

      How are customer service and support?

      We have a big instance in the cloud, and we have occasionally had a few issues here and there that took some time to resolve. For the most part, the customer service and resolution of issues have been very responsive from Splunk. We just had a handful of issues here and there but for the most part, the support has been good.

      How would you rate customer service and support?

      Positive

      Which solution did I use previously and why did I switch?

      We have been using Splunk for many years. Before Splunk Cloud, we were using Splunk Enterprise.

      How was the initial setup?

      The deployment was straightforward because we migrated from Splunk Enterprise on-premises to the Splunk Cloud Platform.

      What about the implementation team?

      We used an in-house Splunk consultant who worked with us for six to nine months to transition from Enterprise. He was efficient but it was a big process. It took at least six months to fully transition over because of our big footprint.

      What was our ROI?

      We saw a return on investment when we switched to the cloud platform from Enterprise. We were able to consolidate everything with the cloud.

      What's my experience with pricing, setup cost, and licensing?

      We were involved in the renewal process, and our organization does reviews of all our partnerships that we have every two to three years to ensure they are meeting our needs, there isn't a better solution out there, and we won't save money by going somewhere else. It's usually a four to six-week process when reviewing software and partnerships, and every time we go through Splunk, the review only lasts one day. We love Splunk and we're not switching.

      What other advice do I have?

      I would rate Splunk Cloud Platform ten out of ten.

      Which deployment model are you using for this solution?

      Public Cloud

      If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

      Amazon Web Services (AWS)
      Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
      PeerSpot user
      Ankit_Mittal - PeerSpot reviewer
      Data Engineering Senior Analyst at Accenture
      Real User
      Top 10
      Speeds up our response and reduces the time we spend manually monitoring any logs for ticketing tools or servers
      Pros and Cons
      • "Splunk has sped up our response and reduced the time we spend manually monitoring any logs for ticketing tools or servers. It saves us around two hours daily."
      • "Every time they launch new versions, we experience a few bugs. The most recent version had a couple of bugs in the databases. We contacted the vendor and got assistance solving these bugs, so the environment is more stable."

      What is our primary use case?

      We use Splunk Cloud for monitoring various ticketing tools, servers, applications, URLs, and client transactions. We're monitoring the transactions and data flow. 

      How has it helped my organization?

      Splunk has sped up our response and reduced the time we spend manually monitoring any logs for ticketing tools or servers. It saves us around 2 hours daily. 

      What is most valuable?

      We can onboard multiple data types for monitoring from various ports and use Splunk to monitor laptops or other devices directly. If everything is stored in our database, we can also monitor that and see who is logging in and when. You can monitor which files are being used most and which ones aren't. We can also check for any fraudulent activity in the system. The reporting is highly detailed.

      Splunk is best when used for real-time monitoring. We can use AI and machine learning, too. Splunk plans to launch new observability features soon. The federated search feature has helped us eliminate redundancy in data servers and discontinue servers that aren't being used much. We can remove those servers from the environment to cut costs. 

      We can use Splunk to monitor multiple environments. The ease of monitoring depends on the source, application, or cloud environment size. 

      What needs improvement?

      Sometimes, integrating with other systems is difficult, and it isn't feasible to connect with other applications, but it's easy most of the time. I rate Splunk 7 out of 10 for its ability to integrate with other systems. 

      Every time they launch new versions, we experience a few bugs. The most recent version had a couple of bugs in the databases. We contacted the vendor and got assistance solving these bugs, so the environment is more stable. 

      For how long have I used the solution?

      I have used Splunk Cloud for 4 years. 

      What do I think about the stability of the solution?

      I rate Splunk 8 out of 10 for stability. It has some bugs, but that is common in any product. At least, Splunk resolves bugs quickly. 

      What do I think about the scalability of the solution?

      Splunk's scalability is nice. 

      How are customer service and support?

      I rate Splunk's technical support 9 out of 10. 

      How would you rate customer service and support?

      Positive

      How was the initial setup?

      Splunk is easy to deploy. We have it deployed across data centers at multiple locations. Splunk requires some maintenance after deployment. 

      What's my experience with pricing, setup cost, and licensing?

      Splunk is a bit pricey, but it's reasonable for the features offered. 

      What other advice do I have?

      I rate Splunk Cloud Platform 8 out of 10. I would definitely recommend Splunk to others. 

      Which deployment model are you using for this solution?

      Private Cloud
      Disclosure: My company has a business relationship with this vendor other than being a customer. partner/customer
      PeerSpot user
      Buyer's Guide
      Download our free Splunk Cloud Platform Report and get advice and tips from experienced pros sharing their opinions.
      Updated: July 2025
      Buyer's Guide
      Download our free Splunk Cloud Platform Report and get advice and tips from experienced pros sharing their opinions.