I use Splunk Enterprise Platform to get logs from different devices in our organization, and after getting logs, it creates some alerts. I do further analysis on those alerts to determine if they are true positives or false positives.
Security Operations Center Analyst at a consultancy with 11-50 employees
Log alerts have improved correlation and support faster investigation of suspicious activity
Pros and Cons
- "Splunk Enterprise Platform provides better correlation of logs than IBM QRadar."
- "Splunk Enterprise Platform can improve in defense capabilities by blocking suspicious and malicious activities or preventing attacks."
What is our primary use case?
What is most valuable?
I appreciate that Splunk Enterprise Platform creates alerts based on pre-described rules. Splunk Enterprise Platform provides better correlation of logs than IBM QRadar. IBM QRadar is more graphically oriented and has a good user interface, but the backend and technical processes are not as strong as Splunk's.
What needs improvement?
Splunk Enterprise Platform can improve in defense capabilities by blocking suspicious and malicious activities or preventing attacks.
For how long have I used the solution?
I have been using Splunk Enterprise Platform for almost two years.
Buyer's Guide
Splunk Enterprise Platform
September 2026
Learn what your peers think about Splunk Enterprise Platform. Get advice and tips from experienced pros sharing their opinions. Updated: September 2026.
914,394 professionals have used our research since 2012.
What do I think about the stability of the solution?
I have experienced lagging sometimes with Splunk Enterprise Platform, but this is not the fault of Splunk; it is the fault of deployment and some other team members.
What do I think about the scalability of the solution?
Splunk Enterprise Platform is scalable.
Which solution did I use previously and why did I switch?
I used IBM QRadar previously. I prefer Splunk Enterprise Platform more.
How was the initial setup?
I appreciate the initial deployment part of Splunk Enterprise Platform because it is very easy. Compared to other products, Splunk deployment is straightforward.
What about the implementation team?
I don't get involved in maintenance, but Splunk Enterprise Platform requires maintenance, and the maintenance team is different in our company.
What was our ROI?
My company deals with the pricing, so I have no idea about it.
Which other solutions did I evaluate?
Splunk Enterprise Platform provides better correlation of logs than IBM QRadar. IBM QRadar is more graphically oriented and has a good user interface, but the backend and technical processes are not as strong as Splunk's.
What other advice do I have?
I have experienced lagging sometimes with Splunk Enterprise Platform, but this is not the fault of Splunk; it is the fault of deployment and some other team members. I am not familiar with the feature called Trusted Control Plane. I don't have any information about Federated Search. My company deals with the pricing, so I have no idea about it. Overall, I would give Splunk Enterprise Platform a score of eight point five out of ten. I would rate this product nine out of ten overall.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Last updated: Sep 15, 2026
Flag as inappropriateCitizen programming facilitates efficient threat detection and enhances business logic
Pros and Cons
- "Overall, I rate Splunk Enterprise Platform ten out of ten."
- "Splunk could improve by enhancing its graphical view functionality. Compared to other BI tools, Splunk's graphic features are limited; customers desire detailed, rich visual effects, like world maps showing threat attacks as animations."
What is our primary use case?
I focus on threat detection against stock trading systems. I am in charge of five to seven stock trading companies' B2C systems for detecting threat attacks. Our customers include several stock trading companies, banks and and large mobile careers in Japan.
How has it helped my organization?
We built a threat detection system for our client company, one of the biggest security company in Japan, using Splunk Enterprise Platform. We started a new business on this platform to provide threat detection systems to stock trading system companies and banks, expanding our customer base.
What is most valuable?
One valuable feature of Splunk Enterprise Platform is citizen programming, which allows users to manage and compute huge stream-based datasets easily using SPL language. The second feature is its ability to perform matrix-like stream calculations concurrently, improving upon traditional SIEM tools. Finally, Splunk's Machine Learning Toolkit is offered without charge, allowing users to incorporate machine learning in their business logic, aiding in procedures like threat hunting.
What needs improvement?
Splunk could improve by enhancing its graphical view functionality. Compared to other BI tools, Splunk's graphic features are limited; part of customers desire detailed, rich visual effects, like world maps showing threat attacks as animations. Additionally, the deep learning capabilities need enhancing, especially on Splunk Cloud, where customers find it challenging to use deep learning tools without setting up backend computing resources.
For how long have I used the solution?
I have over 14 years of experience with Splunk Enterprise Platform, beginning my first evaluation in 2011.
What do I think about the stability of the solution?
I would rate the stability of Splunk Enterprise Platform as a seven. While it requires managing configuration files and processing scale-out operations manually, limiting its auto-scaling capabilities, it still performs adequately.
What do I think about the scalability of the solution?
I rate the scalability of Splunk Enterprise Platform as an eight. Some products can automatically scale, but Splunk Enterprise requires manual configuration changes to achieve scale, which is slightly outdated compared to modern technologies.
How are customer service and support?
I rate Splunk Japan's customer service as an eight. Although I generally provide support myself and do not often rely on Splunk support, this rating reflects general consultant feedback.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
I previously used Elastic Search and Kibana, but switched to Splunk for ease of use and to define business entities such as branches, channels, and stock accounts.
How was the initial setup?
Standalone Installation was very easy. Designing and capacity planning for a distributed cluster environment was not easy.
What about the implementation team?
I am a Splunk consultant and implement customer solutions myself.
What's my experience with pricing, setup cost, and licensing?
I rate the pricing of Splunk as nine out of ten. The pricing model is based on ingesting data sizes, not user count, and includes a free tier for up to 500 MB of daily data, differentiating it from user-based pricing BI-tools.
Which other solutions did I evaluate?
I evaluated ArcSight and Manage Engine and made our selection.
# After using Splunk for several years, I conducted further evaluations, but our selection remained unchanged.
# Datadog was ideal for bug traceback during APM operations.
# Exabeam was ideal for use case-centric threat detection.
What other advice do I have?
Overall, I rate Splunk Enterprise Platform ten out of ten. I am dissatisfied with Splunk’s graphics view and deep learning capabilities; they could be better, especially on Splunk Cloud. While I was able to enhance the platform using technologies like JavaScript, most of my clients struggle.However, it will be sufficient for the next few years with it's strong Machine Learning capability.
Also, it would be preferable for Splunk SOAR to include sequential Splunk task execution and MCP/A2A support features.
Which deployment model are you using for this solution?
Hybrid Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Disclosure: My company has a business relationship with this vendor other than being a customer. Implementer
Buyer's Guide
Splunk Enterprise Platform
September 2026
Learn what your peers think about Splunk Enterprise Platform. Get advice and tips from experienced pros sharing their opinions. Updated: September 2026.
914,394 professionals have used our research since 2012.
Principal Siem Engineer at a tech vendor with 201-500 employees
Platform has unified security and operations data and delivers strong value across enterprises
Pros and Cons
- "Splunk Enterprise Platform is exceptional as a SIEM platform, with the breadth and depth built over the last 20 years."
- "Regarding pricing, I find that Splunk is quite expensive, and I have seen customers getting migrated since the last two years."
What is our primary use case?
I was a partner with Splunk for around six years, and later I moved to customer projects. As part of Splunk, I worked as a professional services consultant, and later I began working with multiple customers through a different company as an independent consultant.
Splunk Enterprise Platform is exceptional as a SIEM platform, with the breadth and depth built over the last 20 years. The main benefit is that it serves both core operations and security through Enterprise Security.
My experience maintaining granular control over the trusted control plane within Splunk involves working with numerous log types that can be ingested, whether from custom application events, OS events, access and identity information, or security or EDR events.
Regarding AI usage in RBAC, I have primarily used it for use case management and taking actions once a security notable event is generated.
I have used Splunk Federated Search, which I implemented for one of my customers about a year ago.
In my experience with Federated Search, I will provide some context on why it was introduced. Splunk was pushing more on Splunk Cloud platform, which is one of their SaaS-based offerings.
What is most valuable?
In terms of scalability, I would rate Splunk Enterprise Platform between nine and ten because all you have to do is add one indexer to the platform. Splunk architects and consultants are involved in that process, but it is quite fast.
What needs improvement?
One area that has room for improvement is the log onboarding problem with all the AI aspects, which has not yet been solved.
For how long have I used the solution?
I have been using this solution for around eight years.
How are customer service and support?
My experience with technical support leads me to rate it between six and seven, leaning toward seven, as they have outsourced most of the support, and support in some regions is not excellent.
How was the initial setup?
The deployment model of my clients is a mix, as I have a few customers who ingest between 40 to 50 terabytes a day who are on enterprise, and there are a few clients with around four to five terabytes a day on cloud.
I would say the deployment planning and architecting is medium to hard, but once that is planned, the deployment itself is easy.
What was our ROI?
In terms of Total Cost of Ownership (TCO), I would say it is consistently net-net positive because Splunk Enterprise Platform is one of the platforms where all the logs of the entire organization are ingested.
What's my experience with pricing, setup cost, and licensing?
Regarding pricing, I find that Splunk is quite expensive, and I have seen customers getting migrated since the last two years.
Which other solutions did I evaluate?
In comparison with major vendors on the market, I see Splunk Enterprise Platform as still being the market leader, at least in terms of SIEM.
What other advice do I have?
I have a team reporting to me, as I work for a company, serving a bunch of Splunk customers and other SIEM customers.
In my organization, there are around four to five specialists who work with Splunk.
My clients are enterprise and medium to large businesses.
Splunk Enterprise Platform requires regular maintenance, and I find it easy to maintain.
My impression of Splunk's approach to managing governance within private network environments is that it is straightforward.
I suggest conducting a POC first and having one real customer who uses Splunk, because it will not work if you are just installing it locally.
I would rate this solution a nine overall.
Disclosure: My company has a business relationship with this vendor other than being a customer. partner
Last updated: Jul 22, 2026
Flag as inappropriateManager Recruitment at tata elxsi
User-friendly interface accelerates task approval but update confirmations occasionally delay
Pros and Cons
- "Splunk Enterprise Platform saves approximately 20 to 30 percent of my time without having to perform different actions separately."
- "The only problem I have with Splunk Enterprise Platform is that sometimes when I update a review, it takes time to receive confirmation emails."
What is our primary use case?
I normally use Splunk Enterprise Platform for review purposes. It is very easy and convenient. Its GUI is easy for me to review and approve all those things.
What is most valuable?
Splunk Enterprise Platform is very easy and convenient to use. The graphical user interface is easy for me to review and approve tasks. It saves time by allowing me to perform actions on a single platform instead of managing them separately. Additionally, its real-time processing capability is very good.
What needs improvement?
The only problem I have with Splunk Enterprise Platform is that sometimes when I update a review, it takes time to receive confirmation emails. This happens very rarely, maybe once or twice a month. I feel this can be improved in terms of performance.
For how long have I used the solution?
I have been using Splunk Enterprise Platform for three years.
What do I think about the stability of the solution?
Splunk Enterprise Platform is very stable.
What do I think about the scalability of the solution?
Splunk Enterprise Platform is scalable to some extent, which is acceptable. However, when I connect via VPN, it may take time to launch.
How are customer service and support?
I haven't got any support yet, so I can't comment on this as of now.
How would you rate customer service and support?
What was our ROI?
Splunk Enterprise Platform saves approximately 20 to 30 percent of my time without having to perform different actions separately.
What other advice do I have?
My overall experience with Splunk Enterprise Platform rates around seven out of ten points. The main issues are regarding updating reviews and scalability, which may take some time when connecting via VPN. I would rate the overall solution 7 out of 10.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Regional Director at iSecureMind Integrated Solutions
Real-time data analysis benefits but automation in role creation needs improvement
Pros and Cons
- "Splunk Enterprise Platform is a good tool to have, but it is expensive."
- "While Splunk Enterprise Platform is a good product, it is expensive. Additionally, it is complex for inexperienced cybersecurity engineers and requires experienced personnel to handle it effectively."
What is our primary use case?
We are working with AppDynamics, Splunk Enterprise Platform, and other Splunk products. However, the main use case here is with Splunk Enterprise Platform.
What is most valuable?
Splunk Enterprise Platform is a good tool to have, but it is expensive. The features that have proven most effective for real-time data analysis include parts of the platform and its automation capabilities. However, I want them to enhance their automation to cover every aspect, particularly the automation of roles creation.
What needs improvement?
While Splunk Enterprise Platform is a good product, it is expensive. Additionally, it is complex for inexperienced cybersecurity engineers and requires experienced personnel to handle it effectively.
For how long have I used the solution?
We have been providing Splunk Enterprise Platform for ten months.
How are customer service and support?
Splunk's technical support is at the same level for all products, although we have not opened many tickets.
How would you rate customer service and support?
Neutral
What's my experience with pricing, setup cost, and licensing?
Splunk Enterprise Platform is expensive.
Which other solutions did I evaluate?
The main competitor of Splunk in our region is Exabeam, which is less expensive. For small and medium companies, Fortinet is a competitor. Stellar Cyber has also recently entered the market.
What other advice do I have?
For smaller companies, I recommend Stellar Cyber as an alternative to Splunk Enterprise Platform. Stellar Cyber is easier to implement and integrate, and it has solid AI capabilities, especially for automation. It is also willing to adapt to customer requirements. I would rate Splunk Enterprise Platform overall somewhere between six and eight, depending on the size of the company.
Disclosure: My company has a business relationship with this vendor other than being a customer. Reseller
Manager - Anti-Fraud Strategy & System Solution Officer at a financial services firm with 10,001+ employees
Seamless integration streamlines fraud detection
Pros and Cons
- "Splunk is very flexible in handling various formats of data as long as basic rules are adhered to."
- "The Splunk Processing Language (SPL) poses a steep learning curve for new users."
What is our primary use case?
The main use case is to analyze the data log coming from other systems. We use Splunk to identify anomalies in transaction patterns, which may indicate irregular activity from certain customers. Our goal is to create alerts for stakeholders when such anomalies are detected.
How has it helped my organization?
Splunk has made our job easier by streamlining data searching and decision-making processes. By using it for fraud detection, we have potentially saved billions of Indonesian rupiah.
What is most valuable?
Splunk is very flexible in handling various formats of data as long as basic rules are adhered to. Its integration with other systems is seamless and can be done overnight. This ease of integration is its best advantage. Additionally, Splunk is adequate for real-time data processing.
What needs improvement?
The Splunk Processing Language (SPL) poses a steep learning curve for new users. The software could benefit from additional processing power, such as GPU support, for handling large volumes of data faster. The language could also be more user-friendly, similar to platforms where actions are easier through button clicks.
For how long have I used the solution?
I have used the solution for approximately three years.
What do I think about the stability of the solution?
I rarely encounter bugs or glitches during daily use. However, there was one instance where an issue required solutions from the headquarter's next upgrade session.
What do I think about the scalability of the solution?
Splunk is scalable, provided the supporting infrastructure, such as CPU and GPU processing, is also scalable.
How are customer service and support?
I rarely communicate with the Splunk headquarters, usually interacting with the local implementer.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
We are not using anything else that functions like Splunk. However, for fraud detection, we also use GVD Instinct and FICO, along with Elasticsearch.
What about the implementation team?
I have not been involved in implementing it, except in integration, where I've found it easy.
What was our ROI?
We have been saving significant amounts through fraud detection. I cannot say precisely how much. Overall, Splunk has simplified our data management and decision-making processes.
What's my experience with pricing, setup cost, and licensing?
The official license operates like a subscription with an annual fee. Our local implementer offers pricing based on reserved quota, such as 80 gigabytes per day, costing under one billion Indonesian rupiah, or around $70,000 USD. It is affordable and flexible.
Which other solutions did I evaluate?
Elasticsearch, Kibana, Check Point, and other solutions like Microsoft Teams, OneDrive, and SharePoint are used.
What other advice do I have?
Keep my identity anonymous; publishing my title is sufficient. It's important to master the SPL for efficient use. Seek solutions that better support GPU for real-time processing.
I'd rate the solution eight out of ten.
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Other
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Delivers financial benefits and operational efficiency with impactful data analytics capabilities
Pros and Cons
- "Splunk Enterprise enhances data analytics with its AI capabilities."
What is our primary use case?
The use cases for Splunk Enterprise Platform vary depending on the specific scenario.
Splunk Enterprise Platform has different purposes, including data visualization and other applications.
Splunk Enterprise Platform has different purposes, including data visualization and other applications.
What is most valuable?
In Splunk Enterprise Platform, the most impactful features for data analytics allow you to get into the repository.
There are financial benefits from using Splunk Enterprise Platform, and as a retailer, it provides better profit margins.
Splunk Enterprise enhances data analytics with its AI capabilities.
There are financial benefits from using Splunk Enterprise Platform, and as a retailer, it provides better profit margins.
Splunk Enterprise enhances data analytics with its AI capabilities.
What needs improvement?
For future updates of Splunk Enterprise Platform, I would like to see integration by GUI.
The integration should be improved with the UI.
The integration should be improved with the UI.
For how long have I used the solution?
I have been using Splunk Enterprise Platform for about two years.
What was my experience with deployment of the solution?
There are no significant challenges in deploying Splunk Enterprise Platform.
The challenges or pain points others should anticipate before implementing Splunk Enterprise Platform are mostly related to the integration part.
The challenges or pain points others should anticipate before implementing Splunk Enterprise Platform are mostly related to the integration part.
How was the initial setup?
The time it takes to deploy Splunk Enterprise Platform depends on the use cases.
It may take anywhere from a couple of hours to a couple of weeks for Splunk Enterprise Platform deployment.
It may take anywhere from a couple of hours to a couple of weeks for Splunk Enterprise Platform deployment.
What about the implementation team?
The same three people take part in the deployment of Splunk Enterprise Platform.
I do not take part in the deployment; my team does.
I do not take part in the deployment; my team does.
What other advice do I have?
My advice for those looking to implement Splunk Enterprise Platform is to know the product well and have hands-on workshops or create a lab to gain complete knowledge before proceeding.
Regarding maintenance, it does not require much as it is on-premises.
Overall, I would rate Splunk Enterprise Platform an eight.
Regarding maintenance, it does not require much as it is on-premises.
Overall, I would rate Splunk Enterprise Platform an eight.
Which deployment model are you using for this solution?
On-premises
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Other
Disclosure: My company has a business relationship with this vendor other than being a customer. Reseller
Technical Lead at a financial services firm with 10,001+ employees
Helps to monitor logs from various sources but improvement is needed in support
Pros and Cons
- "The product helps monitor and visualize data. It allows you to handle various tasks. You can store, visualize, and analyze data with the Splunk Enterprise Platform. It offers features like virtual folders and heavy folders for filtering data. Additionally, you can create dashboards to showcase data to different teams and stakeholders. The tool also enables the creation of analytics and alerts and sends reports, making it a valuable tool for our system."
- "Based on my experience, I've noticed areas for improvement, particularly in support. Developers typically interact with support personnel who may lack technical expertise when raising support tickets. This can result in delays as initial interactions involve sharing documents before escalation to higher support levels."
What is our primary use case?
We use the tool to monitor logs from various sources. Multiple users send their logs to the Splunk Enterprise Platform using different methods, including Universal Forwarder and AWS services like S3. Additionally, we utilize tools like AWS Genesys for log transmission.
What is most valuable?
The product helps monitor and visualize data. It allows you to handle various tasks. You can store, visualize, and analyze data with the Splunk Enterprise Platform. It offers features like virtual folders and heavy folders for filtering data. Additionally, you can create dashboards to showcase data to different teams and stakeholders. The tool also enables the creation of analytics and alerts and sends reports, making it a valuable tool for our system.
The dashboard and visualization features are good for data analysis. With features like the Studio dashboard introduced in versions 8 to 9, users find it much easier to create dashboards without knowledge of languages like XML.
What needs improvement?
Based on my experience, I've noticed areas for improvement, particularly in support. Developers typically interact with support personnel who may lack technical expertise when raising support tickets. This can result in delays as initial interactions involve sharing documents before escalation to higher support levels.
For how long have I used the solution?
I have been using the product for four years.
What do I think about the stability of the solution?
I rate the tool's stability an eight out of ten.
What do I think about the scalability of the solution?
The tool's scalability is good, and it is based on licensing. My company has more than 10,000 users.
Which solution did I use previously and why did I switch?
I used Dynatrace before the Splunk Enterprise Platform.
How was the initial setup?
The tool's deployment can be complex for the first time. It can become more manageable after that.
What's my experience with pricing, setup cost, and licensing?
If you exceed your licensed limit, the product will issue a warning, typically a five-license warning. Additionally, they send daily email notifications informing you about the breach. This prompts you to consider options such as minimizing logs or acquiring additional licensing to address the issue.
It can be perceived as expensive, especially for organizations dealing with large volumes of data, such as in the banking sector, where numerous logs are generated every second. While other tools are available at lower costs, some teams may consider open-source or lower-cost alternatives, especially if they have funding constraints.
What other advice do I have?
Regarding security and event management, the tool is handled by a different team. They utilize security enterprise tools, including SIEM, to manage security. Splunk Enterprise Platform's real-time processing capability significantly enhances our data monitoring. I would rate it an eight out of ten.
Which deployment model are you using for this solution?
Hybrid Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Monitoring expet at Air Liquide
A highly versatile data collection and monitoring tool
Pros and Cons
- "The best thing about Splunk is you can collect all the data you want, and you can play with the data and do what you want."
- "Splunk is not an out-of-the-box solution like Micro Focus or Zabbix. You have to create your request to collect the data and add crucial components to the software."
What is our primary use case?
We use the monitoring solution. People might ask me to create a new request, maybe for a specific Windows event log, which is how we create a ticket for an incident. Most of the time, this creates a new alert for people. It can be a little complex. We can also create dashboards with some information for other teams. Dashboard alerting is a big part of the work.
Though we use Splunk for monitoring, for me, it is more software that collects lots of data and can then be used for alerting.
We use a custom environment.
What is most valuable?
The best thing about Splunk is you can collect all the data you want, and you can play with the data and do what you want. You can modify the data and collect all the information into one dashboard. It's very cool. In other monitoring software like Zabbix, you can't easily do something like this. With Splunk, it's very easy. You need to understand Splunk's language, but you can do what you want after that. You can correlate your data with CSV files. Splunk can monitor, extract, transform, and load software.
What needs improvement?
Splunk is not an out-of-the-box solution like Micro Focus or Zabbix. You have to create your request to collect the data and add crucial components to the software. You have add-ons created by Splunk or the community but don't have out-of-the-box monitoring items in the software. For example, FETCH CUP with Micro Focus is agentless monitoring, has a lot of out-of-box items, and is easy to use. You will find it difficult to use Splunk initially, which could use improvement. However, I know there is another module from Splunk that focuses on fast and secure monitoring with more out-of-box add-ons, but I haven't used it since when I started using it, it lacked out-of-box items. All the same, Splunk could be more user-friendly for new users.
For how long have I used the solution?
I've worked with the solution for about two years.
What do I think about the stability of the solution?
I rate Splunk's stability a nine out of ten because it's very stable. I don't face issues with projects.
What do I think about the scalability of the solution?
You can scale Splunk. It works with an indexer which indexes search data. If you want more power, you can add more indexers, so I rank Splunk's scalability an eight out of ten.
How was the initial setup?
With all the documentation available, the initial setup is not difficult. If all you want is a stand-alone app in Splunk to handle all the processes, you just need to create a project in the data server, which is easy.
What's my experience with pricing, setup cost, and licensing?
You must buy a license with the on-prem version, usually through an intermediary. In France, it's Accenture. There are cloud solutions where Splunk handles the servers and patching directly, and you just use the solution.
The solution is expensive, so I rate its pricing a four out of ten. Though the solution is expensive, it depends on which company purchases the product.
Which other solutions did I evaluate?
Though I haven't used it, Grafana is also a CM that can collect data.
What other advice do I have?
I didn't create the custom environment we use at my organization. Still, it doesn't seem too difficult to build things because there is a lot of online documentation and videos. You can also get training with Splunk. You have a lot of data to help you when you want to create a new environment.
I rate Splunk Enterprise Platform an eight out of ten. The solution is very powerful, and I like to play with data to do what I want.
Which deployment model are you using for this solution?
Hybrid Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Product Owner at ABN AMRO Bank N.V.
Enables us to create dashboards and do analysis but has limitations
Pros and Cons
- "Splunk can be used primarily to port log files, allowing for easy and quick management of large amounts of logs. However, this can also be a drawback due to the configuration, parsing, and dashboard creation limitations. Communication is stream-based, which means you need to do a lot of pre-emptive setup to get a nice export."
What is our primary use case?
We use Splunk to create dashboards and do analysis.
What is most valuable?
What needs improvement?
Splunk can be used primarily to port log files, allowing for easy and quick management of large amounts of logs. However, this can also be a drawback due to the configuration, parsing, and dashboard creation limitations. Communication is stream-based, which means you need to do a lot of pre-emptive setup to get a nice export. Another issue with Splunk is its streamlined nature; it reruns the query whenever you refresh a dashboard. This becomes problematic if you have a large volume of log files, as it can be slow, resource-intensive, and require significant storage space.
It is designed to process and analyze log files. You feed log files into the platform, automatically extracting different fields. This allows you to filter and manipulate the data in a stream-based manner. Essentially, you pass a log file through various filters sequentially, enhancing or reducing its size by adding or removing information. However, this stream-based approach can make it challenging to create detailed dashboards easily. The platform primarily focuses on log files and is unsuitable for real-time data analysis.
For how long have I used the solution?
I have been using Splunk Enterprise Platform for one or two years.
What do I think about the stability of the solution?
The product is stable.
I rate the solution’s stability a six out of ten.
What do I think about the scalability of the solution?
It can be very slow if you have a lot of data, and scaling it up for better performance can be quite expensive.
A thousand users use this solution. We have many systems and a lot of data.
It is centrally deployed and used extensively across various systems. I use it daily, but sometimes I only use it once a month. It depends on the data I need or the issue I'm investigating.
I rate the solution’s scalability a four out of ten.
How was the initial setup?
The initial setup is straightforward.
What other advice do I have?
I wouldn't recommend Splunk Enterprise Platform because it's slow and has significant limitations.
Overall, I rate the solution a six out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Buyer's Guide
Download our free Splunk Enterprise Platform Report and get advice and tips from experienced pros
sharing their opinions.
Updated: September 2026
Popular Comparisons
Tableau Enterprise
Informatica PowerCenter
SAP BusinessObjects Business Intelligence
ThoughtSpot
Splunk ITSI (IT Service Intelligence)
SAS Visual Analytics
Splunk Cloud Platform
Apache Superset
Splunk On-Call
RStudio Connect
Splunk Security Essentials
Buyer's Guide
Download our free Splunk Enterprise Platform Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- What's your experience or opinion about Spotfire vs. Tableau vs. Qlik?
- A journalist is writing a story about which Data Visualization software product to choose. Can you help him?
- What enterprise data analytics platform has the most powerful data visualization capabilities?
- When evaluating Data Visualization, what aspect do you think is the most important to look for?
- What are the best self-service and Excel-like filtering / display tools?
- What data visualization tool/s do you find to be the best?
- Why is Data Visualization important for companies?
- Which Data Visualization tools are good at collaboration and support the tracking of insight actions?
- How many users on average are licensed users of Data Visualization software in a company?


















