No more typing reviews! Try our Samantha, our new voice AI agent.
reviewer2499690 - PeerSpot reviewer
Principal Site Reliability Engineer at a pharma/biotech company with 1,001-5,000 employees
Real User
Jul 3, 2024
Information is easier to get now that it is all aggregated and centralized in one place with one interface
Pros and Cons
  • "Previously when in our company, we had logs everywhere on multiple systems, it was a really big pain for me trying to find what I wanted. Now that it is all aggregated and centralized in one place with one interface, it is just a lot easier to get the information that I need."

    What is our primary use case?

    I use Splunk Cloud Platform to analyze our company's logs and the applications that we run.

    How has it helped my organization?

    Previously when in our company, we had logs everywhere on multiple systems, it was a really big pain for me trying to find what I wanted. Now that it is all aggregated and centralized in one place with one interface, it is just a lot easier to get the information that I need.

    What is most valuable?

    The most valuable feature of the solution stems from the fact that I just like having one single point where all of our logs are aggregated and then having one interface that I can query and find the information that I want out of it.

    My organization monitors multiple cloud environments and even the on-premises part. I would say that so far, it has been fine and easy to use to monitor multiple cloud environments using Splunk Cloud Platform. The tool works effectively, and it gets stuff from our on-premises servers into the cloud. It gets stuff from AWS into the cloud. I am able to, you know, use the single interface to access all the information I need.

    It is very important for our organization that Splunk Cloud Platform has end-to-end visibility into your cloud-native environment. It is important since it helps to be able to see all the aspects of what our services are doing and how they are operating.

    It helps with the mean time to resolve since it makes it easier to find the errors as they have occurred, so it has been a helpful tool.

    I don't know how much the product has helped my organization improve business resilience.

    I wouldn't know if my company has experienced any cost-efficiency by splitting to Splunk Cloud Platform.

    I know that Splunk's unified platform helps consolidate networking, security, and IT observability tools for our company. Our company has an InfoSec team using it for their SCIM stuff, and then we have IT using it for some of the things they need to gather. Multiple teams in my company have benefited from using the tool. The consolidation of tools does impact our organization since I think it is probably easier for everyone to get access to stuff because everything is in one place, and it is one of the biggest impacts of the product I can think of right now. Instead of having things spread out across multiple vendors and multiple tools, it is all kind of in one thing that we can get at, and so it is probably easier for us to train people, and we know, like, how to access the solution since it is just one thing we have to learn.

    What needs improvement?

    I am relatively new to the platform. So far, I have been able to use it to do what I need. I know that there are a lot more features and functionality that I don't even know yet, so I am still on the learning side. I don't really have any recommendations related to things that need to be improved in the tool.

    So far, it meets my needs, so I don't need to see any additional features in the tool.

    Buyer's Guide
    Splunk Cloud Platform
    July 2026
    Learn what your peers think about Splunk Cloud Platform. Get advice and tips from experienced pros sharing their opinions. Updated: July 2026.
    908,858 professionals have used our research since 2012.

    For how long have I used the solution?

    I have been using Splunk Cloud Platform for six months. My company is just a customer of the solution.

    What do I think about the stability of the solution?

    I have not had a problem with the tool's stability. It has been available every time I needed it, and it has captured every information we have sent to it. It has been not just a good but a great solution.

    What do I think about the scalability of the solution?

    I think the tool's scalability is fine. I have not run into any issues with the tool's scalability, so I guess it's good.

    How are customer service and support?

    I have not had the chance to interact with Splunk's customer service or support, so I can't really evaluate them.

    Which solution did I use previously and why did I switch?

    I don't know if there was some other solution used previously in my company. My company is just a customer of the tool.

    How was the initial setup?

    The product was deployed before I joined the organization.

    The solution is deployed on a hybrid cloud model, and my company has opted for AWS.

    What about the implementation team?

    I believe that my company approached an integrator to help with the deployment of the product, but I am not sure about it.

    What was our ROI?

    I don't know about the ROI part.

    What's my experience with pricing, setup cost, and licensing?

    I don't know about the pricing, setup cost, and licensing part.

    What other advice do I have?

    I rate the solution a ten out of ten.

    Which deployment model are you using for this solution?

    Hybrid Cloud

    If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

    Amazon Web Services (AWS)
    Disclosure: My company does not have a business relationship with this vendor other than being a customer.
    PeerSpot user
    reviewer2499189 - PeerSpot reviewer
    Senior technical consultant at a healthcare company with 1,001-5,000 employees
    Real User
    Jun 23, 2024
    Offers good dashboards that show us search or user search activity

    What is our primary use case?

    It's a better pricing model. The main aspect is that we don't have to manage our infrastructure. Since we migrated, we've found we don't have as many outages. 

    This allows our admins to focus more on the day-to-day onboarding instead of wasting time dealing with outages.

    How has it helped my organization?

    Our organization monitors multiple cloud environments. We monitor AWS. We have other logging platforms that monitor our infrastructure as well.

    It's very important for our organization that Splunk Cloud Platform has end-to-end visibility into our cloud-native provider environments. With the increasing changes in technology, being able to consistently get insights into those new data sources in a quick amount of time is everything.

    Moreover, we have seen a reduction in our mean lead time to resolve (MTTR). Our enterprise has some of those dashboards for incidents. Splunk is mainly used to resolve those incidents and identify what's wrong. Over year over year, these times are lower. And Splunk has helped with that. There's other operational things that are probably helping too, Splunk plays a big part, so it is helpful.

    What is most valuable?

    I like the Splunk Monitor console. I like how Splunk continually updates it with new features. We don't have to do anything on our end, we just get access to that. 

    Splunk has some good dashboards that show us search or user search activity. There are some things that could cause the environment to go awry, like skip searches or searches that are more intensive. 

    By being able to identify those, we could reach out to those customers and work with them on improving their standard practice. Since moving to SaaS, we're able to focus more on that.

    What needs improvement?

    There's one specific use case I work with. I work with some Splunk experts, and it lacks workload management rules.

    It can identify specific dashboards e.g., or all-time searches. When I try to track back to the user, I don't have additional information within those logs to help me know, "This is the dashboard this guy accessed."

    Instead of relying on those particular workload management logs, I have to do an investigation that takes time. It takes too much time when it shouldn't.

    For how long have I used the solution?

    It's only been a full year so far. We migrated recently.

    What do I think about the stability of the solution?

    Stability has been so far, so good. Data is growing, not just for us but for everyone. From what we've seen, it looks like it's handling it accordingly.

    How are customer service and support?

    We frequently engage with support now since we have a lot of incidents. They consistently ask for feedback on our support cases. We recently had something that was very urgent. Splunk was able to escalate it accordingly and get back to us with a solution. It means a lot to my management.

    Which solution did I use previously and why did I switch?

    We've been with Splunk for several years now.

    How was the initial setup?

    For the cloud, the deployment is easy. 

    We just have the standard. We download our packages, upload them via the cloud, upload our apps, and use the App Inspect. 

    Before on-prem, we had some CI/CD pipelines to deploy on-prem. Those change calls lasted up to an hour and a half just to verify the change was successful and that everything was coming in as expected. 

    Cloud is just uploaded and deployed in a matter of minutes. That's a big plus. It saves us time and a lot of hassle. 

    What was our ROI?

    We use our valuable time and do not waste effort. We just work on more important things like onboarding new data sources as log data continues to grow.

    By being able to have more time to onboard data sources with customers, we provide our company more visibility and value into our entire environment.

    What other advice do I have?

    I have no major gripes other than some detailed grievances, so I would rate it an eight out of ten. 

    Disclosure: My company does not have a business relationship with this vendor other than being a customer.
    PeerSpot user
    Buyer's Guide
    Splunk Cloud Platform
    July 2026
    Learn what your peers think about Splunk Cloud Platform. Get advice and tips from experienced pros sharing their opinions. Updated: July 2026.
    908,858 professionals have used our research since 2012.
    reviewer2272479 - PeerSpot reviewer
    IT Engineer at a venture capital & private equity firm with 1,001-5,000 employees
    Real User
    May 12, 2024
    Integrates seamlessly, improves security posture, and provides visibility
    Pros and Cons
    • "The ability to correlate data and then present it in a meaningful and valuable way is crucial."
    • "The current visuals on the dashboard could be more impactful."

    What is our primary use case?

    To gain deep visibility into our entire cloud infrastructure, we deployed the Splunk Cloud Platform. This tool allows us to monitor, analyze, and investigate all aspects of our cloud environment.

    How has it helped my organization?

    Splunk Cloud Platform integrates seamlessly with other systems, including Slack. This allows us to receive real-time alerts triggered within the tool. We can then analyze the output and take timely action to resolve the issue, ensuring continued security.

    Splunk Cloud Platform improved our security posture. We could easily and efficiently obtain detailed analyses of any log, including UPC flow logs and others, promptly. The benefits of Splunk Cloud Platform were visible within two days.

    Splunk Cloud Platform does a good job helping to maintain the complaints and privacy regulations within our infrastructure.

    Splunk Cloud Platform excels at correlating data from a wide range of sources, including applications, websites, and servers. It efficiently handles the challenge of managing large volumes of data. This has secured our data and demonstrably improved our security posture.

    What is most valuable?

    The ability to correlate data and then present it in a meaningful and valuable way is crucial. Splunk offered this functionality, providing us with insights into threats, vulnerabilities, and all the identity information we fed into it. We sought a SIEM tool because we lacked a solution that could effectively analyze recent data. We needed a tool that could not only ingest our data but also correlate it and present it in an easily understandable format.

    What needs improvement?

    The cost of Splunk Cloud Platform is high and has room for improvement.

    The current visuals on the dashboard could be more impactful.

    For how long have I used the solution?

    We conducted a POC of Splunk Cloud Platform 6 months back.

    What do I think about the stability of the solution?

    During our POC, I did not encounter any stability issues with the Splunk Cloud Platform.

    I would rate the resilience offered by Splunk Cloud Platform 8 out of 10.

    What do I think about the scalability of the solution?

    I would rate the scalability of Splunk Cloud Platform 9 out of 10.

    How are customer service and support?

    The technical support is good.

    How would you rate customer service and support?

    Positive

    How was the initial setup?

    The initial deployment was straightforward. Two people were required for the deployment.

    What's my experience with pricing, setup cost, and licensing?

    The Splunk Cloud Platform is expensive.

    Which other solutions did I evaluate?

    Splunk Cloud Platform performed well in the POC but the cost was higher than other tools.

    We chose Palo Alto Networks over Splunk due to its combined advantage of cost-effectiveness and superior threat analysis capabilities.

    What other advice do I have?

    I would rate Splunk Cloud Platform eight out of ten.

    Which deployment model are you using for this solution?

    Public Cloud
    Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
    PeerSpot user
    SIEM Engineer at a manufacturing company with 11-50 employees
    Real User
    Sep 5, 2023
    Offers excellent visibility, and cloud performance, and requires zero maintenance on our end
    Pros and Cons
    • "he cloud performance is good."
    • "Splunk should offer various options for real-time monitoring."

    What is our primary use case?

    We use Splunk Cloud Platform to monitor our environment.

    How has it helped my organization?

    Monitoring multiple cloud environments is made easy with the Splunk Cloud Platform due to its fast ingestion and data recovery times.

    Splunk's visibility into multiple environments is excellent. I have found that a hybrid environment works the best, as the login portion remains on-premises while the rest is in the cloud. This reduces the maintenance required on-premises.

    There are two types of integration. The first involves bringing something into Splunk, while the second entails moving something out of Splunk. Bringing data into Splunk is relatively straightforward, with multiple options such as RAS, SysLog, and Splunk's built-in functions. However, exporting data from Splunk is more challenging and not as straightforward as the process of bringing data into Splunk.

    Splunk Cloud Platform has influenced our decision-making processes. Splunk is primarily employed for security purposes; thus, it excels particularly in SIM. It encompasses an asset and identity framework that effectively gathers information about an organization's assets and individual identities, encompassing all users. Therefore, when considering Unified Business and SIM, Splunk proves to be highly proficient. 

    What is most valuable?

    The cloud performance is good.

    Not having to perform any maintenance because it is handled by Splunk saves our administrators time which is valuable.

    What needs improvement?

    Splunk should offer various options for real-time monitoring. If we could enhance the speed of data ingestion or data retrieval, that would be an added advantage. Additionally, there is room for improvement in SaaS-to-SaaS integration. I believe that reintroducing HTML dashboards would be beneficial, as they provide dedicated web features. This, in turn, gives users the flexibility and freedom to create custom dashboards more easily.

    For how long have I used the solution?

    I have been using Splunk Cloud Platform for five years.

    What do I think about the stability of the solution?

    I would rate the stability of the Splunk Cloud Platform as an eight out of ten. We still encounter some lagging and errors, but not as much as with the on-premises deployment.

    How are customer service and support?

    I occasionally get in touch with Splunk technical support, usually regarding data onboarding. These include routine activities like installing or uninstalling applications, as well as making changes to existing ones. On average, we submit at least one ticket per week to them.

    How would you rate customer service and support?

    Positive

    Which solution did I use previously and why did I switch?

    I have used many tools including Elastic, Grafana, Tableau, and Sumo Logic.

    Splunk is indeed superior in many cases, but other tools are also making progress to catch up, with Elastic being one of them. They have begun developing their own SIM offering, complete with its own SIM features. Similar to Splunk Cloud, Elastic also has its Elastic Cloud Stack. Some of the features provided by Elastic seem to outperform Splunk. Therefore, there is room for Splunk to enhance these aspects. As for pricing, it could be more competitive, considering that other tools also provide the freedom to choose the Cloud Stack. Although Splunk offers this flexibility, the process often involves extensive discussions, making it less adaptable compared to other tools.

    How was the initial setup?

    The initial setup is somewhat complex regarding the CI/CD pipeline, and Splunk manages the deployment. Splunk provides a feature called ACS, which enables us to manage the deployment ourselves if desired, but it's simpler to have Splunk handle the deployment on our behalf.

    The deployment took around one month and required ten people from Splunk's DevOps team.

    What about the implementation team?

    The implementation was completed by Splunk.

    What's my experience with pricing, setup cost, and licensing?

    The pricing is high for small organizations. The cost makes more sense for organizations that have a large amount of data ranges.

    What other advice do I have?

    I would rate Splunk Cloud Platform an eight out of ten.

    There are numerous tools that offer real-time reporting and alerting capabilities. Splunk is indeed effective, but due to the prerequisite of registering logs beforehand, a delay is inevitably introduced. Therefore, while Splunk is suitable for real-time reporting alerts, it may not be as optimal as some alternative solutions.

    Resilience has added value and contributed to the improvement of our organization. This is highly significant. In most cases, the SOC team relies on the tool for issue mitigation and ticket resolution. Therefore, it is crucial for Splunk to remain consistently up-to-date and respond as quickly as possible. This holds immense importance.

    The extensibility is good, but there is room for improvement, especially in integrating certain logs. Enhancing the process of incorporating raised logs is possible. In most cases now there are limitations on log creation. Previously, a direct option existed to import logs. However, this process has been altered, requiring users to develop an add-on for log integration, leading to increased complexity. Furthermore, users are expected to have knowledge of Python. This can be problematic in cases where users lack such expertise. Therefore, this aspect could certainly be enhanced.

    For those who want to evaluate Splunk, it comes down to the volume of data. If they are dealing with a substantial amount of data flowing into their SIM, Splunk would be the superior option. Splunk effectively manages extensive datasets in comparison to other technologies. It also offers numerous additional functionalities, such as an enterprise security suite, assets, and identity framework. Moreover, it has undergone industry testing and has been employed in the field for a considerable duration. In contrast to other organizations, they provide a wealth of features.

    Which deployment model are you using for this solution?

    Public Cloud

    If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

    Other
    Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
    PeerSpot user
    John David Cabanglan - PeerSpot reviewer
    Splunk Architect Application Software Developer at a tech vendor with 10,001+ employees
    MSP
    Aug 24, 2023
    Resilient, helps with decision making, and is very fast
    Pros and Cons
    • "The cloud is very fast."
    • "Support could be improved."

    What is our primary use case?

    I use the solution to create alerts for different servers. I also create dashboards in Splunk.

    How has it helped my organization?

    We have a lot of servers. It was hard to track which were down as we didn't have a monitoring platform. Splunk changes that. It receives data and if it doesn't get any data, it creates an alert so we are notified if something is down.

    We also use it for making reports to help make management easier. 

    The monitoring of servers for high CPU utilization helps us out. If there are offline servers or high utilizations, we can see the incidents and optimize our processes. 

    What is most valuable?

    The cloud is very fast. We have a lot of data in our Splunk instance and it isn't slow in any way. 

    The maintenance is good. We have good support if we have queries or issues. With on-premises Splunk, if we ran into issues, we'd have to figure things out ourselves. With the cloud version, it's easier to get support. 

    We can monitor multiple cloud environments, including Azure and AWS

    It can be difficult to monitor cloud platforms. We are integrating more cloud servers and patching data sources from those servers. It's very easy to use Splunk and have everything go to the dashboards.

    We get good visibility into multiple environments. We can easily search from Splunk Cloud to our on-prem or AWS directly. We also do not ingest the data in order to see it.

    We can easily integrate with other systems. It's very helpful. We can leverage Splunk to gather any specific reports we want with this integration capability. 

    The reporting is very good. Every month we have a call with Splunk personnel and they'll show us reports to show high usage for search, for example. From our side, we can change or update in order to optimize our systems. 

    The cloud has helped us with decision-making. It helps make maintenance decisions very easy.

    It's very resilient. 

    What needs improvement?

    Testing can handle a lot of logs, however, we are unsure if the speed will be affected.

    When we are using OneDrive or SharePoint, as a developer, we'd like to have better integration between the two.

    There are some issues with Splunk blocking some shared mailboxes. 

    Support could be improved. 

    For how long have I used the solution?

    I have been using the solution for five years.

    What do I think about the stability of the solution?

    The Splunk cloud is very stable. I've never experienced crashing. If there are issues, they will notify us. It doesn't take long to resolve issues at all. Things tend to be resolved in an hour or so. 

    What do I think about the scalability of the solution?

    The solution is very scalable. 

    I haven't experienced the extensibility, or the ability to extend the system, however, my understanding is that it is very good. We have yet to upgrade it.

    How are customer service and support?

    When we have high-priority tickets, it's hard getting help efficiently. We'd prefer to call. It takes time to get someone to help. We've had to submit tickets via the portal, and they asked us to call instead. It's hard to get above P1.

    It would be ideal to get a specific phone number or email so that we do not have to wait hours to get help.

    We do have different Splunk support services where we talk to them bi-weekly, and at that point, we can talk about any high-priority issues. They do try to help us with queries. 

    How would you rate customer service and support?

    Positive

    Which solution did I use previously and why did I switch?

    We previously used Splunk on-premises. 

    How was the initial setup?

    I do not have any experience with the initial setup. Since it is a cloud deployment, Splunk handles the maintenance mainly.

    What's my experience with pricing, setup cost, and licensing?

    I'm not aware of the exact pricing. That said, my understanding is that it is very reasonable. However, every application has a price. We need separate licenses for everything. They don't have any bundles. 

    What other advice do I have?

    For the first few years, I used the solution on-premises, and then I moved over to the cloud. 

    I use the classic dashboard; I don't yet use the studio. 

    It has not yet affected our security posture. 

    We have not yet explored federated search. 

    I'd rate the solution ten out of ten.

    If a user is planning to use the Cloud Platform is to consider the pricing. It's fast to access and there is no downtime. It's very good from a user perspective. I'm happy with it. It's helpful.

    Users should work to maximize the power of Splunk to get the most out of it. Leverage the applications, including security. 

    Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor. The reviewer's company has a business relationship with this vendor other than being a customer: Partner
    PeerSpot user
    Automation Developer at TNS
    MSP
    Aug 7, 2023
    Reduces infrastructure overhead, but the process for custom apps can be streamlined
    Pros and Cons
    • "Not having to manage Splunk Cloud's infrastructure is valuable."
    • "They can streamline the process of creating custom apps."

    What is our primary use case?

    On Splunk Cloud, I mainly look for errors in applications or issues that come up with our internal applications. I have also used it to create dashboards and display customer data to customers in an effective way so that they have insights into their data.

    How has it helped my organization?

    There is less overhead now for infrastructure management. There are fewer issues that we have to worry about on the infrastructure side. This has freed up more of our resources' time to work toward initiatives on the Splunk platform itself. It is hard to measure the time savings. If one resource was working on it, that resource could save anywhere between 15 to 20 hours a week.

    It must have reduced our MTTR, but I have been with Splunk for as long as I have been in my current environment, so I do not have anything to compare it with.

    It helped improve our organization’s business resilience. The solution helps us find where errors are and potentially where threats are a lot faster. We can more effectively push out alerts not only to our team but also to the teams across the enterprise. It is nice to have on hand.

    It is quite effective at helping us identify problems very quickly. We do not participate in real-time searches within our Splunk environment, but close to real-time is possible, and it is quite effective.

    What is most valuable?

    Not having to manage Splunk Cloud's infrastructure is valuable. Being able to deploy within the cloud and not having to manually manage our configs on the infrastructure side and set up our own architectures has been the biggest help.

    Other than that, the new Dashboard Studio has been a pretty big win, but I do not know whether that is more cloud-specific or not. Dashboard Studio has a cleaner look for customers that want to see their data but not necessarily search. For the customers that want to see their data, having an easy and effective way to drag and drop to see where things are going to be if they want to change them has been pretty beneficial.

    What needs improvement?

    They can streamline the process of creating custom apps. I do not have a lot of experience with it. It was not very difficult for me to do so, but there is probably a better way to present the ability for people to push their own custom apps to the platform and go through Splunk's manual and automatic reviewing process.

    For how long have I used the solution?

    I have been using this solution for about three years.

    What do I think about the stability of the solution?

    I have not seen any downsides when it comes to uptime and availability. Being in the cloud reduces downtime, especially compared to being on-prem where if something goes wrong, you will have to go in and fix that infrastructure yourself.  I have not necessarily seen significant downtime with Splunk Cloud or on-prem at this time.

    What do I think about the scalability of the solution?

    I quite enjoy the fact that if we need more indexes or search heads, it is very easy to plug and play with Splunk Cloud. With the infrastructure model that we had before, we would have to go in, set up a new search head out to the cluster, and add a new indexer to the cluster if we needed it. It will have more benefits going forward as we move more and more into the cloud.

    How are customer service and support?

    I have worked with Splunk support, and I would rate them an eight out of ten. It depends on where you are and what project you are working on at the time. It would be quite beneficial to work with them if you have a specific project that you are working on, and they have some insight into it. I do not work with support too often myself. Usually, one of our Splunk Infrastructure managers works with them, but there is always room for improvement. Availability in terms of making the time to gain insight into specific projects and problems that we are having is an area that can be improved.

    How would you rate customer service and support?

    Positive

    Which solution did I use previously and why did I switch?

    My company has been with Splunk for quite some time now. We are well integrated at this point, and we are in the process of migrating over to Splunk Cloud specifically. We used Splunk on-prem for a while. We are currently in a hybrid situation, and we are making our way toward being completely on the cloud.

    How was the initial setup?

    I help from time to time with the migration process, but I am not necessarily in charge of the total migration functions that we currently have today. The most I have done in terms of deploying to the cloud was creating a custom alert action for the cloud environment, which is one of my biggest contributions so far. I am not completely in charge of it, but from time to time, I will assist in the migration process. It is a bit of a learning curve, but once you get more and more familiarized with the cloud and how to benefit from it by using features like federated search, it becomes easier. It is somewhere in between in terms of complexity.

    What was our ROI?

    We would have seen an ROI. I do not have a specific number, but assuming that we did not have Splunk Cloud, we would have to manage our own infrastructure. Not having to manage nearly as much infrastructure and not having to have the personnel to manage that infrastructure on a regular basis, frees up that time for them to do what they are really designed to do. This has definitely added value.

    What's my experience with pricing, setup cost, and licensing?

    I am a little bit familiar with the pricing and licensing model. I am not sure about the particular pieces of the actual price that we have, but I do like the idea of going towards a more CPU-based approach rather than the ingesting approach. This CPU-based approach gives us the ability to ingest more data if we need it.

    What other advice do I have?

    The biggest value that I get from attending Splunk conferences is the insights from everybody here. You have people from many different companies doing very different things and deploying very different models within their different Splunk instances. You get an idea of where everybody lands and maybe grab some ideas that you would not necessarily have thought of by looking at it from the inside of someone who is in a completely different field than you are.

    There is definitely a big difference between Splunk Cloud and on-prem. For me, one of Splunk on-prem's biggest features is being able to deploy my own custom applications internally, which is something that is a bit of a process with Splunk Cloud. So, given the information that I have, I would rate it a seven out of ten.

    Disclosure: My company does not have a business relationship with this vendor other than being a customer.
    PeerSpot user
    reviewer2499666 - PeerSpot reviewer
    Director, Operations at a hospitality company with 10,001+ employees
    Real User
    Jul 9, 2024
    Good reliability snf definitely saved us time
    Pros and Cons
    • "The most valuable features are reliability and logging. It's in the cloud so it has more stability and easy maintenance."
    • "The support from the Splunk team is generally good, but sometimes, there's a lack of coordination between our account reps and the hands-on technical people. This misalignment can lead to issues with getting what we need done and what is happening."

    What is our primary use case?

    We use it for security investigations and alerting.

    What is most valuable?

    The most valuable features are reliability and logging. It's in the cloud so it has more stability and easy maintenance. 

    What needs improvement?

    The support from the Splunk team is generally good, but sometimes, there's a lack of coordination between our account reps and the hands-on technical people. This misalignment can lead to issues with getting what we need done and what is happening.

    For how long have I used the solution?

    I have been using it for about two years.

    What do I think about the stability of the solution?

    From what I've seen so far, stability has been great.

    How are customer service and support?

    The actual technical reps we've had have been fair. I'd rate them a seven on a scale from one to ten.

    How would you rate customer service and support?

    Neutral

    Which solution did I use previously and why did I switch?

    We previously used LogRhythm. We switched to Splunk. It was an on-prem setup, so it was tough to maintain. It wasn't very reliable, and we always had to deal with hardware issues.

    How was the initial setup?

    I haven't been hands-on with the deployment, but Splunk's deployment has been smooth. We also have Enterprise Security, which has been a little more difficult.

    What was our ROI?

    We have not calculated in dollars, but it has definitely saved us time.

    Which other solutions did I evaluate?

    We evaluated other options. I wasn't directly involved in all the decision-making processes, but from a user standpoint, it was the cost and the future possibilities of adding SOAR that made Splunk Cloud Platform seem like the best option for us.

    What other advice do I have?

    I would rate it an eight out of ten, mainly due to the difficulty we've had with the Enterprise Security side.

    Disclosure: My company does not have a business relationship with this vendor other than being a customer.
    PeerSpot user
    reviewer2500047 - PeerSpot reviewer
    Systems Operations Senior Specialist at a financial services firm with 5,001-10,000 employees
    Real User
    Jul 9, 2024
    Shows us valuable information in an easy-to-understand way
    Pros and Cons
    • "Splunk reduced our mean time to resolve by 30%. If an application starts misbehaving, we send logs to Splunk and check to see what's going on and see what's happening."
    • "Since I work on data collection from external sources and send them into Splunk, I miss its ability to collect that data through REST API applications."

    What is our primary use case?

    My role is in observability. 

    Some of our internal systems send data into Splunk Cloud. We had dashboards for our team's KPIs. We can check to see how fast the team reacts to events. Those reaction times a recordreed and sent to Splunk. From there, we can draw some dashboards. We can check to see who is doing well and who needs to improve. The power Splunk admins started moving into the Cloud.

    The primary use cases are for team KPIs, log analytics, and error search. We would look for the relation of different events and draw dashboards to see how bad things were veering off from the timeline that we wanted to see. 

    How has it helped my organization?

    Splunk helped us shape the picture of our team and enabled management to see who should be rewarded and who should be coached. It helped outline where KPIs were not being met. We could sit down and discuss what happened, and why it did not go as planned, and then we could make improvements in the processes. It helped us draw a broader picture of the entire team's capabilities.

    With Splunk, everything is centralized, everything is in one place. We don't have to scramble and approach Splunk admins where to look. 

    In terms of networking, we managed to build good dashboards. We have a lot of firewalls and rules. If a new service comes up, if they don't have a firewall and nothing works, we can look at the Splunk dashboard and see the particular network flow and see if firewalls are blocking traffic. This is a Splunk function that people are happy and excited about. It shows us valuable information in an easy-to-understand way.

    What is most valuable?

    It's very important for us that Cloud Platform offers end-to-end visibility into our cloud-native environment. More and more functions are moving to the cloud, so it's not only for observability to see the system, but it's also for management and senior management to see that all of their applications are running as intended. If we try to spread out applications through multiple vendors, multiple regions, access groups, and whatnot, it becomes pretty important. It may become a challenge because of that spread. It brings resilience, but it also makes it more difficult to look after everything.

    We want to achieve having everything in a single view. Senior management wants to make sure that everything is running well. The application team's developers want to have a granular review. 

    Splunk reduced our mean time to resolve by 30%. If an application starts misbehaving, we send logs to Splunk and check to see what's going on and see what's happening.

    The dashboards are the most valuable feature. It's all of the information in one place. We can build it ourselves, so we can make it the way we like. 

    What needs improvement?

    Since I work on data collection from external sources and send them into Splunk, I miss its ability to collect that data through REST API applications. I would like the ability to configure an endpoint, set it on Splunk, and set a schedule for it to pull information every ten minutes, and pull this endpoint information. I could search through it, look for keywords, restructure the data that's brought back to me, and then store it in the Splunk index. This is not available and if it is available, it is bare bones. I would like Splunk to have this function by default.

    For how long have I used the solution?

    We started using Splunk seven years ago. We started with Splunk on-prem and then moved to Splunk Cloud. 

    What do I think about the stability of the solution?

    I never had any stability issues. 

    How are customer service and support?

    I use support rarely but so far, it's been fine. 

    I would rate it an eight out of ten. My cases weren't that critical so it took a little longer to solve. 

    How would you rate customer service and support?

    Positive

    What's my experience with pricing, setup cost, and licensing?

    We have not achieved cost efficiencies by switching to Splunk. There will be some cost discussions in cost optimization. 

    We log a lot of data which may have impacted our licensing cost.

    Which other solutions did I evaluate?

    We also looked at Datadog but it wasn't cost-efficient to log with two tools.

    What other advice do I have?

    We monitor multiple cloud environments. I heard that it's more straightforward to monitor multiple cloud environments with AWS. Azure doesn't work as intended, there were some issues collecting data from it.

    I would rate Splunk Cloud Platform seven out of ten. I really miss REST API abilities. 

    Disclosure: My company does not have a business relationship with this vendor other than being a customer.
    PeerSpot user
    reviewer2499168 - PeerSpot reviewer
    Consultant at a tech services company with 201-500 employees
    Consultant
    Jul 3, 2024
    Allows app and add-on installations without worrying about accidental breakdowns
    Pros and Cons
    • "I like the idea of being able to list the IPs that we want without having to open up a ticket to get it done so that way if anything changes we can add a new IP."
    • "Splunk Cloud's SVC licensing model lacks transparency."

    What is our primary use case?

    The Splunk Cloud platform is for anyone who wants to save money and doesn't want to manage an on-prem infrastructure. I like the Cloud platform because we don't have to handle any maintenance. Any server downtime, upgrades, or patches are no longer our responsibility, which is great. That's the biggest advantage of Splunk Cloud.

    How has it helped my organization?

    Before COVID-19, the Splunk Cloud platform was much more difficult to manage. I've heard it causes a lot of frustration. Thankfully, it's come a long way since then. Now, it's user-friendly and allows app and add-on installations without worrying about accidental breakdowns.

    I wouldn't have released Splunk Cloud myself when they did but the shift to remote work during COVID-19 drove everyone to the cloud, making the Splunk Cloud platform a great solution. While the updates focus on features, patches, and maintenance, there's nothing about the Splunk Cloud platform itself that I love other than the fact that we can use it in the cloud without the hassle of any on-prem requirements.

    The importance of having one cloud platform depends on an organization's data goals, but at the end of the day, we onboarded the data because it's important. So as long as we have a use case, it's high up there.

    Splunk Cloud Platform has improved our mean time to resolve incidents 100 percent. The cloud eliminates the need for upgrades to multi-cluster environments and the risk of errors during configuration, which can cause major problems. While we are not responsible for any Cloud maintenance, Splunk's support is helpful for escalations. Their clear communication about maintenance minimizes the need for their involvement.

    While I can't speak to personal cost savings, moving to Splunk Cloud likely saves on storage costs compared to on-premises setups. This is especially valuable because many organizations use Splunk alongside other security products for specific needs. However, some competitors offer better data storage and faster results as add-ons for Splunk. Overall, the biggest cost savings come from eliminating the need for in-house server maintenance, storage management, and future data migrations. This reduces headaches and frees up IT resources, even if the migration itself wasn't a major issue.

    What is most valuable?

    I like the idea of being able to list the IPs that we want without having to open up a ticket to get it done so that way if anything changes we can add a new IP. The platform itself is the most valuable because if we're using the product, we're paying a lot for it. So we're searching our data and doing the triage we need to with the events. In reality, our biggest benefit of the Splunk Cloud Platform is not having the hassle on-prem.

    What needs improvement?

    Splunk Cloud's SVC licensing model lacks transparency. Customers are unsure of how SVC consumption translates to costs, and there's no easy way to identify what's driving SVC usage within the platform. While some external applications provide limited insight, Splunk Cloud itself doesn't offer a clear view into SVC consumption. This lack of clarity makes it difficult to explain cost spikes to customers, as the cause could be anything within the platform.

    For how long have I used the solution?

    I have been using the Splunk Cloud Platform for four years.

    What do I think about the stability of the solution?

    The Splunk Cloud Platform is stable.

    What do I think about the scalability of the solution?

    I have some concerns about the SVC licensing model for deployments under 1 terabyte, and it's separate from Splunk Cloud. The bigger challenge customers face is managing the surge of data and historical information they ingest. This can lead to situations like an admin setting up numerous queries and then leaving, making users hesitant to disable them for fear of breaking something. While this can happen with any product with unchecked admin access, Splunk and Splunk Cloud themselves function as intended for large-scale environments. Ultimately, it's up to the customer to manage their Splunk instance effectively.

    How are customer service and support?

    Many people complain about back-and-forth interactions with Splunk support. It feels like a repetitive loop of explaining the problem, being asked for information and questioning why it's needed. There's frustration on both sides: support needs details to diagnose the issue, while users might feel it's a simple problem and supplying extra information is unnecessary. This can be true for any customer support experience.

    How was the initial setup?

    Splunk Cloud deployment complexity varies by use case. Starting fresh is simple: install, configure, and point data to the cloud. However, migrating from on-premises to the cloud with existing data can be complex. Deciding what data to migrate and the migration process itself adds significant challenges, although these are likely to become easier over time.

    What was our ROI?

    Splunk Cloud's value is clear: it eliminates maintenance headaches and simplifies connection, offering a hassle-free experience.

    What's my experience with pricing, setup cost, and licensing?

    The lack of transparency around the SVC licensing makes it difficult to explain the costs to our clients.

    What other advice do I have?

    I would rate the Splunk Cloud Platform nine out of ten. The rating is not because of customer service. I am strictly looking at the product. I've worked with it for seven years. I've been on over 70 engagements with other customers over those years, and I rarely find a use case that a customer can't solve when it comes to an architect-type scenario, which is great. It's the same thing for data. For the most part, if you know you have data and can get it written down to a file, you can adjust it, which is phenomenal. The on-prem infrastructure consists of only 12 CPUs and 12 RAM if it's hardware, and then you double it if it's virtual. Overall that's very inexpensive to stand up major components. I'm not including storage or any other sizing that can get more complicated. Overall, it doesn't ask much from actual servers if you want to host it on-prem. Even managing it yourself on-prem, is not terrible. The commands are still there, the resources are there to do it yourself. You have community groups out there that help you with questions. There are tons of providers out there that can get you from point A to point B. 

    I have always used Splunk but I am open to learning Chronicle soon depending on industry trends. While I believe Splunk remains the top SIEM tool. According to Gartner, competitors like Azure and Oracle are emerging. However, I have not needed to look for other solutions.

    Which deployment model are you using for this solution?

    Public Cloud
    Disclosure: My company has a business relationship with this vendor other than being a customer. Consultant
    PeerSpot user
    Principal, Cybersecty and Infra at PNM Resources Inc
    Real User
    Jun 30, 2024
    Improves availability and makes infrastructure administration easy
    Pros and Cons
    • "There is definitely the ease of the infrastructure administration. It frees up a lot of time."
    • "I would love to be able to manage my own apps."

    What is our primary use case?

    We are onboarding everything on it. We have infrastructure, applications, and network-related things on it.

    How has it helped my organization?

    The availability has improved. There is the ease of upgrades. We are able to show value quicker with some of our add-ons and things like that because of the stability in the base.

    It is extremely important to me that Splunk Cloud Platform has end-to-end visibility into our cloud-native environment.

    Splunk Cloud Platform has definitely helped reduce our mean time to resolve. It is a little hard to measure. It has at least saved 3% of our time.

    Splunk's unified platform has helped consolidate networking, security, and IT observability tools. There is ease on resources.

    What is most valuable?

    There is definitely the ease of the infrastructure administration. It frees up a lot of time.

    What needs improvement?

    I would love to be able to manage my own apps. 

    For how long have I used the solution?

    I have been using Splunk Cloud Platform for two years.

    What do I think about the stability of the solution?

    Stability and scalability have been the main benefits of this solution.

    How are customer service and support?

    We have had some confusion around some of our requests, but I understand. We have to work through and get proper responses.

    How would you rate customer service and support?

    Neutral

    Which solution did I use previously and why did I switch?

    We were using on-prem Splunk.

    How was the initial setup?

    There was a professional service involved. I came into the team right at the time of the cutover. They were pushed into the cloud because things had gotten so out of control on-prem, so we had to clean that up first, and then finish the migration. It was kind of bumpy, but we got through.

    We are using AWS. It is managed by Splunk.

    What about the implementation team?

    We had Aquila as our partner for help with implementation.

    What was our ROI?

    We are definitely starting to see an ROI. We have been focused on metrics because we are trying to get very comprehensive and overall monitoring of the environment both from the security standpoint and the infrastructure standpoint.

    We have not yet seen any cost efficiencies by switching to Splunk Cloud Platform. We are still maturing it out.

    What's my experience with pricing, setup cost, and licensing?

    As far as the pricing goes, it was what was expected. It is a premium product. There were no surprises there.

    Which other solutions did I evaluate?

    We did not evaluate other solutions. We have always been with Splunk.

    What other advice do I have?

    We are not monitoring multiple cloud environments, but it seems it would be easy to monitor them.

    Overall, I would rate Splunk Cloud Platform an eight out of ten. There is always room for improvement, but it has been good.

    Disclosure: My company does not have a business relationship with this vendor other than being a customer.
    PeerSpot user
    Buyer's Guide
    Download our free Splunk Cloud Platform Report and get advice and tips from experienced pros sharing their opinions.
    Updated: July 2026
    Buyer's Guide
    Download our free Splunk Cloud Platform Report and get advice and tips from experienced pros sharing their opinions.