Tech Support Supervisor at a government with 10,001+ employees
Real User
We can identify an issue in real time and save a few hours every day
Pros and Cons
  • "The Splunk Cloud Platform has reduced our mean time to resolve. It has easily saved 20 to 30 minutes every time someone gets locked out. We get 10 or 15 instances per day where people get locked out. It definitely saves a few hours per day."
  • "I have not come across anything that I would consider missing as such. If anything, sometimes we have dashboards that would not go into the dark mode. It is a minor issue, but it is the only thing that I wish was there. The dark mode would definitely help."

What is our primary use case?

We have a lot of third-party contractors that come in on our network and do the work. We use it to pretty much check what they are doing and make sure they are not doing anything that they are not supposed to be doing.

We do a lot of user interaction. We have users logging in, and we mainly look into failures and what is causing them to get locked out. We do a lot of that.

We also have Duo. We use Splunk Cloud Platform to keep an eye on who is using Duo, where they have failures, and why. We have quite a few people who are not supposed to be using Duo, and then they end up, for whatever reason, on the Duo side of the house. We use it to keep an eye on them so that we can help them get back to where they are supposed to be.

How has it helped my organization?

The improvement is in terms of helping those users who get locked out because we have that happen quite often. Daily, we have users getting locked out, and using Splunk makes it so much easier to help them. Rather than trying to go to the server and find those logs, we can just go to Splunk and then the dashboard for that particular user and find out exactly which machine is causing the lockout.

It helps us to easily find out which machine is causing the lockout. A lot of people know that customers can exaggerate. We can bring that back into perspective. They might say that they get locked out every day, whereas it might be once a week. We can see that. We do have a dashboard that tells us who is locked out right now. We do use that, and it helps us a lot because even before the user realizes it, we can go back and help. That helps us because they almost do not even know that it is happening. We can see it in real time, and we can fix it and unlock it. If it is something that is reoccurring, we can say, "You have been getting locked out multiple times in the same place for the last couple of hours. Go check this." We can also see why they were locked out. If somebody is putting in the wrong password, we can ignore that and unlock it. We, of course, are going to see where it is coming from. If we see some weird IP address or some weird computer that looks like it belongs to us, we will address that, but it helps us to help the user quickly. We are told what is happening as opposed to having to ask what is happening. We have definitely seen time to value. Instead of having to research, we are told it is there.

The Splunk Cloud Platform has reduced our mean time to resolve. It has easily saved 20 to 30 minutes every time someone gets locked out. We get 10 or 15 instances per day where people get locked out. It definitely saves a few hours per day.

Splunk Cloud Platform definitely frees us up to handle true problems and do true troubleshooting as opposed to handling lock-out issues. It is, of course, big for the user, but it is minute for us because it is answering a question that does not really matter to us. It matters to the user, but for us, we can just unlock their account, and we can figure out why at another time, whereas now, we can unlock their account and figure out why immediately. For example, if it was a machine that they logged into but they do not remember, or they have a cell phone that they logged into but they have not changed their password on, we can figure that out a lot quicker. That helps them quicker. It keeps us from having to go back to that user, and we can knock that out right then and there.

We have not gone into its ability to predict, identify, and solve problems in real time because we use it more after the fact. We do have an MSP, and they handle more of the security side. Their software does real-time monitoring, and they get alerts. We use the Splunk Cloud Platform to see what has already happened.

What is most valuable?

All the features are very equal for me. I do not use any one feature more than the other. They all are pretty equal to me.

What needs improvement?

It works as needed, and it does everything that we want to do. I have not come across anything that I would consider missing as such. If anything, sometimes we have dashboards that would not go into the dark mode. It is a minor issue, but it is the only thing that I wish was there. The dark mode would definitely help.

Buyer's Guide
Splunk Cloud Platform
April 2024
Learn what your peers think about Splunk Cloud Platform. Get advice and tips from experienced pros sharing their opinions. Updated: April 2024.
770,292 professionals have used our research since 2012.

For how long have I used the solution?

We have been using the Splunk Cloud Platform for about three years.

What do I think about the stability of the solution?

It has always worked when we needed it.

What do I think about the scalability of the solution?

We are a very small shop. We only have 150 gigs a day, and we are not anywhere near that 150. However, from what I see, if there is an easy transition from 150 gigs to 300 terabytes, that is easy scalability.

Which solution did I use previously and why did I switch?

We did not use any similar solution.

How was the initial setup?

I was not involved in its deployment. It was already implemented.

What other advice do I have?

Splunk Cloud Platform has been able to provide business resilience by empowering our staff, but currently, only two of us use it. One thing about coming to the Splunk conference is that we learn a lot. It is a lot more than what we probably can do. We also learned that for most people here, Splunk is a big part of their job. That is their main focus, whereas we have so many different things. We use Splunk; we do a little bit of networking. We do troubleshooting from swapping computers to the almost top level of moving cables.

I would rate the Splunk Cloud Platform a ten out of ten.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
Flag as inappropriate
PeerSpot user
Sr BigData Infrastructure Architect at a hospitality company with 10,001+ employees
Real User
Add oversight to your business with complete log reporting although it may strain your budget
Pros and Cons
  • "This is a complete log reporting tool."
  • "The log search capabilities are very good."
  • "The pricing model makes the product costly."
  • "The dashboards should be easier to customize."

What is our primary use case?

Splunk is an event log manager. We have reservation and event logging dashboards integrated from the data dock to Splunk and we have all the specific dashboards that we work with in Splunk for log management.  

How has it helped my organization?

We became pretty complete with our reporting using Splunk for all the log and event capabilities. I would rate this product as somewhere around seven or eight-out-of-ten for the logging capabilities and how that has added to the oversight of our business.  

What is most valuable?

The log event capabilities and the flexibility in the search engine for finding what we need in the logs are some of the more valuable features in this product.  

What needs improvement?

The pricing models should be improved and optimized. Right now, the pricing is a bit too expensive.  

One other thing you need is more ability to customize the dashboard to the way you want to have it. If you had a template that you could create and label inside of Splunk that would be good.  

One good thing that could be added to the AWS side of the solution is that you should have an OPS (Operation Alert) alert built into the dashboard that comes with Splunk. That would be very useful. For example, if you have a pre-defined template creator to fill in the information to forms that are loaded. That would be really beneficial.  

For how long have I used the solution?

I have been using Splunk Cloud for more than four years now, in total.  

What do I think about the stability of the solution?

We have not experienced or even heard much about bugs or other problems people are having with Splunk. It seems pretty stable.  

What do I think about the scalability of the solution?

Scalability is good, but the cost factor in scaling is really high. That is the reason why we are interested in working with products and solutions that will help us optimize our costs and may be looking into other solutions.  

We probably have something around a hundred users who work with Splunk. Mainly they are architects, enterprise architects, and data-link architects. We also have business analyst systems. We have not had a problem in changing or growing these roles.  

How are customer service and technical support?

I have not had direct experience with the Splunk technical support because I leave it to the other teams in our organization because I am not really in a position to use Splunk support.  

Which solution did I use previously and why did I switch?

I have only been working with Splunk for these past three years. I am not too much of an expert. I left my role as an officer in an organization in 2014, so from 2014 to 2017 I was not in touch with the advancements of products in the industry. But I was using other solutions prior to Splunk.  

How was the initial setup?

The setup and installation of the product are straightforward.  

What's my experience with pricing, setup cost, and licensing?

The pricing model makes this an expensive solution.  

What other advice do I have?

Advice-wise, I do not really have much to say to potential users considering the solution as something to apply as an end-user. My job role is data organization so it might not be appropriate for me to give these opinions. This seems to me to have more to do with system functionality. But from my side, I am good with the product.  

Interface-wise, I think the product is good.  

Security-wise, it is all approved from the CSOs (Chief Security Officer) perspective.  

Enhancement-wise, we have to put in a lot of effort. The end-users who are working with the solution should know SQL. If they lack training in SQL, there will not really be a use case for them.  

Whatever the use cases we had for Splunk, we were able to make it work.  

Cost optimization is the only thing that needs to be reconsidered.  

On a scale from one to ten (where one is the worst and ten is the best), I would rate this product overall around seven, or somewhere between six to eight. Six to eight so make that around seven-out-of-ten.  

Which deployment model are you using for this solution?

Private Cloud
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Buyer's Guide
Splunk Cloud Platform
April 2024
Learn what your peers think about Splunk Cloud Platform. Get advice and tips from experienced pros sharing their opinions. Updated: April 2024.
770,292 professionals have used our research since 2012.
DevOps engineer at a tech vendor with 10,001+ employees
MSP
Easy to use and has good reporting but bulk data search can be better
Pros and Cons
  • "As compared to other tools, it is very easy. It is very easy to learn. It also integrates well."
  • "The search for bulk data needs to be improved. When we were looking for the flow, we had to search really hard. I wanted to request the Splunk team to add some features for better search because getting the flow of the bulk data was sometimes hard."

What is our primary use case?

I was working as a DevOps engineer in India. I was working for the payments domain of a client. We were mostly using Splunk for monitoring the production, deployment of API, and traffic. 

How has it helped my organization?

We had two cloud platforms. When I joined the team, we were deploying all our APIs in Pivotal Cloud Foundry (PCF). We then migrated to AWS Kubernetes. We were able to monitor both platforms in Splunk. When we migrated to Kubernetes, Splunk helped us. When we were having the transaction loss, we were able to find out which node was throwing the error. We were able to fetch the details according to the nodes in Splunk. We were using different keywords on these platforms for fetching the data. 

We could create our own query, and we could create our own alerts for a particular API. We could also configure these alert notifications to be mailed to particular managers and owners. We could just go through the alert to check if the API was running well or needed to be fixed.

What is most valuable?

As compared to other tools, it is very easy. It is very easy to learn. It also integrates well. 

The reporting features are very good. The dashboards are very nice. We could create our own dashboards to monitor any volume dips or transaction loss. 

What needs improvement?

The search for bulk data needs to be improved. When we were looking for the flow, we had to search really hard. I wanted to request the Splunk team to add some features for better search because getting the flow of the bulk data was sometimes hard.

For how long have I used the solution?

I have worked with this solution for almost three years.

What do I think about the stability of the solution?

It is stable, but we did experience two or three downtimes.

Which solution did I use previously and why did I switch?

We had three or four monitoring tools other than Splunk. We had AppDynamics, Grafana, and others, but we were mostly concentrating on Splunk because we were able to fetch all the details from a particular transaction using Splunk. We were able to create our own dashboard so that we get alerts regarding errors or transaction loss for the customer. The most useful thing was that when we were fetching details from a payment ID or a grid, we were able to track the complete workflow for that API. We were also able to fetch the details about whether the issue was in our team or the external team. We were able to track that very accurately using Splunk.

How was the initial setup?

It is not that complex. We just need the knowledge. We just need to know how to query the alert and set up dashboards. As compared to AppDynamics and Grafana, it is a lot easier.

Our dev team could set up a dashboard and deploy everything in two weeks.

What's my experience with pricing, setup cost, and licensing?

It is not that expensive.

What other advice do I have?

If the company is working on API-based deployment and API-based developments, then I would recommend Splunk. It is useful for tracking the flow and fetching the data.

Overall, I would rate it a seven out of ten.

Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
Flag as inappropriate
PeerSpot user
Senior Analyst at a computer software company with 11-50 employees
Real User
Top 5
It's a good solution that can index a large amount of data in a short time.
Pros and Cons
  • "The Splunk search is powerful compared to similar solutions. We get millions of data points within seconds."
  • "The Splunk interface is on-premises, so we have limited access to Splunk Cloud. Splunk support is not so good on Splunk Cloud. The Splunk side of the Splunk Cloud should also be more customizable. Integrating Splunk UBA, Splunk Phantom, and Splunk Cloud is also a bit difficult."

What is most valuable?

The Splunk search is powerful compared to similar solutions. We get millions of data points within seconds.

What needs improvement?

The Splunk interface is on-premises, so we have limited access to Splunk Cloud. Splunk support is not so good on Splunk Cloud. The Splunk side of the Splunk Cloud should also be more customizable. Integrating Splunk UBA, Splunk Phantom, and Splunk Cloud is also a bit difficult. 

For how long have I used the solution?

I've been using Splunk Cloud for about four years. 

What do I think about the stability of the solution?

Splunk Cloud is reliable. 

What do I think about the scalability of the solution?

Splunk Cloud's scalability is pretty good. 

How are customer service and support?

Splunk support isn't so great. It takes a lot of time for them to respond. 

How was the initial setup?

The initial setup is straightforward. 

What about the implementation team?

We deployed Splunk in-house.

What's my experience with pricing, setup cost, and licensing?

The license costs around 100,000-150,000 rupees. Splunk Cloud is the basic version. It costs extra if you need Splunk interface or Splunk ICSA. Those are premium additions. There are additional costs if you want to use the other premium aspects of Splunk.

What other advice do I have?

I rate Splunk Cloud eight out of 10. It's a good solution that can index data in a short time. That's one advantage of Splunk over other solutions. However, the support isn't good, and you can't customize the Splunk interface. 

Which deployment model are you using for this solution?

Public Cloud
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
PeerSpot user
CYBERSECURITY ANALYST at a tech services company with 1-10 employees
Real User
Good visibility and speed with reasonable pricing
Pros and Cons
  • "We only buy the services we need. We don't have to pay for other things we don't."
  • "They need to provide more training options."

What is our primary use case?

Splunk Cloud helps us to combine all our environments. For example, multiple business units can be combined into one even if they are in different geographic locations. 

What is most valuable?

It helps us with hosting from different geographical locations. 

The speed of the cloud environment is great. 

We only buy the services we need. We don't have to pay for other things we don't. It makes the pricing very economical. 

We use the solution's federated search feature. It's easy for us to use. It helps us search logs, analyze, and manage data.

We are able to monitor multiple cloud environments using our Splunk Cloud dashboards. It makes the process very simple. We just have to maintain different teams for different environments.

The solution is great within hybrid environments. It gives us good visibility across everything. 

It works well for sizable environments. 

The product integrates well with other systems and applications in our environment. We haven't had any issues with integration at all. However, if we ran into issues, we could call Splunk support. Having an issue would be a very rare event. 

Reporting is very good. It's the same for all Splunk solutions. Having multi-cloud instances in one place is great.

We have multiple business units and easily integrate them into the cloud, as well as different infrastructures from different areas. We can deploy a Splunk agent on any cloud - AWS, Google, etc.

The company can access data easily for compliance and privacy regulations. The privacy aspect has been very good.

Having resilience has been very helpful in our organization. 

What needs improvement?

Training should be free of cost. They need to provide more training options. 

There are no missing features at this time. 

For how long have I used the solution?

I've been using the solution for two and a half years. 

What do I think about the stability of the solution?

The solution is stable.

What do I think about the scalability of the solution?

We have 30 people using the solution in our organization. The product is scalable.

How are customer service and support?

Technical support has been good. 

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

We did also use LogRhythm. It has a very good UI in comparison to Splunk, yet it doesn't have as many capabilities and does have a few more restrictions. That said, it's a good product for creating use cases and automation, which is easier than Splunk. We moved to Splunk as LogRhythm did have some restrictions. 

How was the initial setup?

I have previously done deployments of Splunk. The setup is pretty straightforward. 

Were a system integrator of Splunk. We help clients set up the solution. 

We've had six or seven people setting up the solution. 

The maintenance is pretty manageable. I'd rate maintenance needs seven out of ten. 

What was our ROI?

I'm not sure if we have noted any ROI while using Splunk.

What's my experience with pricing, setup cost, and licensing?

The pricing is reasonable. They provide good options for licensing. 

Which other solutions did I evaluate?

I did not evaluate any other options. 

What other advice do I have?

We are integrators and also users of Splunk. 

We have multiple solutions we use for security, of which Splunk is one of them. So far, it's been very good from a security perspective, although we don't solely rely on it.

I'd recommend users work with Splunk in the cloud environment. I'd recommend the product in general to others. 

I would rate the solution nine out of ten. 

Which deployment model are you using for this solution?

Public Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Amazon Web Services (AWS)
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Flag as inappropriate
PeerSpot user
Director - Corporate Infrastructure at a tech services company with 10,001+ employees
Real User
Meets our requirements from a cost and requirements perspective
Pros and Cons
  • "For my current requirements, the tool theme seems to be meeting my requirements, from a cost and requirements perspective."
  • "The only thing I would say is an issue is the cost. It matches other products. The costs can be justified for the value that we gain. The entire threat analysis stack should come in a bundle. If the cost was matchable with other products I think Splunk would pick up in the market."

What is our primary use case?

We use it for Log Management and also for another bit of management. It feeds data into Splunk and Splunk writes the rules and based on that, it will pick up incidents. 

It is good from a cost perspective, in terms of the cost of the data you're looking at. There is no cost barrier. 

What is most valuable?

For my current requirements, the tool theme seems to be meeting my requirements, from a cost and requirements perspective.

What needs improvement?

The only thing I would say is an issue is the cost. It matches other products. The costs can be justified for the value that we gain. The entire threat analysis stack should come in a bundle. If the cost was matchable with other products I think Splunk would pick up in the market. 

I did evaluate other products and installations. I can't compare it to Splunk. 

For how long have I used the solution?

I have been using Splunk Cloud for a year. 

What do I think about the scalability of the solution?

There are two people who are part of admin that use Splunk in my company. 

We have a policy where we have to keep the domain controllers on lock with sensitive servers for about 90 days. We look at the controls around once a week to check if they need to be attended to. 

How are customer service and technical support?

We initially contacted their support during the implementation. It was not for a very complex issue. It was more for a consultation. 

Their support is good. 

How was the initial setup?

I was new to Splunk and had a problem with understanding the forwarders and worker safety management.

My team was able to install it themselves. 

In terms of how long it took to deploy, between coding, testing, and other things, it took about four weeks to complete the project to complete the initial installation. Altogether it was four to five weeks. They should improve the customization. 

Which other solutions did I evaluate?

Splunk is a leader in its marker. 

Splunk offers more features than its competitors. Other solutions are not on the same level to be able to compare them. 

What other advice do I have?

I would rate Splunk a nine out of ten. 

The queries and pulling out the exact reports is a little challenging. I get complaints about it. I would like to see more reports or default out of the box reports. That would be more useful, useful, and then people can avoid writing inquiries.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Owner at a reseller with 1-10 employees
Reseller
Quick to set up and the technical support is invaluable
Pros and Cons
  • "The most valuable feature of Splunk Cloud is the quick setup."
  • "The only thing that is missing from Splunk Cloud is the command-line interface."

What is our primary use case?

We are a Splunk reseller and Splunk Cloud is one of the main products that we work with.

Our customers implement this product for log management, application management, application testing, and process management. They also have it for customer service use cases.

What is most valuable?

The most valuable feature of Splunk Cloud is the quick setup.

What needs improvement?

The only thing that is missing compared with Splunk Enterprise is the ability to manually edit all config files. This task is easily handled with support tickets but sometimes is would be nice to experiment directly.

For how long have I used the solution?

I have been selling Splunk products for ten years.

What do I think about the stability of the solution?

We have not heard any complaints about stability. 

What do I think about the scalability of the solution?

Scalability with Splunk is the best because it scales to anything. Their promise to users is scalability and availability. Our customers range in size from very small companies to large ones.

How are customer service and technical support?

Over the past ten years that we have been selling Splunk products, they have been in constant contact for support. I would say that it is invaluable. They have great response time and great skills, and I couldn't compare it with any other software company.

How was the initial setup?

Installing Splunk Cloud, itself, is nothing. The length of time for the total deployment depends on how many log sources that you have. It can be completed in a matter of hours.

What about the implementation team?

Being a cloud-based product, Splunk does all of the maintenance. We don't have to do anything to maintain it.

What's my experience with pricing, setup cost, and licensing?

The licensing costs depend on the data ingest volume. If you weigh the costs and the benefits, the benefits are great and it is money well spent. 

What other advice do I have?

I feel that Splunk Cloud is good as it is. It is the best tool on the market.

My advice to anybody who is considering this solution is to start now and don't wait. Every day that you wait, you can be wasting time and money.

I would rate this solution a nine out of ten.

Which deployment model are you using for this solution?

Public Cloud
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
PeerSpot user
it_user1061643 - PeerSpot reviewer
Lead Developer, Solution Analyst at a university with 10,001+ employees
Real User
A flexible and feature-rich product, but the documentation needs to be improved
Pros and Cons
  • "The most valuable feature for me is the flexibility of being able to send the log to the https endpoint."
  • "Although there is documentation available, it is really hard for me to find relevant topics on what it is that I'm searching for."

What is our primary use case?

We have a public URL that allows anyone to authenticate for ADFS. This allows them to connect using Active Directory. 

What is most valuable?

The most valuable feature for me is the flexibility of being able to send the log to the https endpoint. I know that it is possible to export the logs, although it is easier for me to communicate with the endpoints concerning what I am interested in.

This is a feature-rich product.

What needs improvement?

Although there is documentation available, it is really hard for me to find relevant topics on what it is that I'm searching for. For example, when something goes wrong, I can spend hours trying to figure out the problem and have nothing to refer to. I find that it confuses me somewhat, so it is something that can be improved.

I feel that technical support can be improved because it is always done through the use of a support ticket, which is not very convenient.

Setting up and configuring integrations are not easy to do. 

For how long have I used the solution?

We implement this solution within the past year.

What do I think about the stability of the solution?

Splunk Cloud is quite stable. I do not remember having any issues with bugs or glitches.

What do I think about the scalability of the solution?

I would expect that the scalability is quite good, albeit expensive.

How are customer service and technical support?

Technical support is okay, although they are not as quick to respond as I believe they should be. I feel that some of the support processes are not very convenient.

How was the initial setup?

The initial setup is straightforward, although we still revisit it. We started several months ago and are still trying to set it up in a more structured way. Really, we are still in the deployment stage in some regards because we are struggling with exactly how it should be set up.

What about the implementation team?

We had some assistance from a consultant after the initial setup was completed. It worked well for simple uses, but now, we have some help in trying to configure it to meet our needs.

What's my experience with pricing, setup cost, and licensing?

The price is something that people complain about.

What other advice do I have?

My advice to anybody who is implementing Splunk Cloud is to dedicate the time and resources required to learn it and use it. Investigate the features.

I would rate this solution a seven out of ten.

Which deployment model are you using for this solution?

Public Cloud
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Buyer's Guide
Download our free Splunk Cloud Platform Report and get advice and tips from experienced pros sharing their opinions.
Updated: April 2024
Buyer's Guide
Download our free Splunk Cloud Platform Report and get advice and tips from experienced pros sharing their opinions.