What is our primary use case?
We use the solution for tracking successful and unsuccessful logins. We track privileged account activities and also a variety of other things, like developing use cases for data exfiltration or integration with ETRs and other security tools for data analysis.
How has it helped my organization?
We wanted to solve the issue of unauthorized access, brute force attacks, and exfiltration. It's helped with MITRE ATT&CK frameworks.
The organization has been able to quickly triage issues and investigate if something is a true threat or not. Most times, it helps our security posture. The level of confidence we have is high. With Splunk, you can query accounts when you see some strange activity.
What is most valuable?
It gives me notifications of notable events.
The default dashboard is very good. We can see our security posture from there.
On-prem and cloud data analysis are good. You can aggregate it if you need to in order to get good data.
Splunk has proven to be great when tracking down anomalous behavior. The logs are excellent. It is the platform in the industry. You can integrate anything. The amount of information and usability you get out of Splunk is very good.
We do use the Threat Intelligence Manager. It can be integrated with third parties. The actionable intelligence we get is useful. There is sequencing where you can gauge some actionable steps.
I use the MITRE ATT&CK framework when I am developing a new use case. It helps us discover the overall scope of an incident. Using Splunk is essential in developing that.
It's good for analyzing malicious activities and detecting breaches. I'd rate it highly in its capabilities. However, if you don't have the knowledge, it may be difficult. You might get a lot of false positives.
It's helped us detect threats very fast, in almost real time.
We have reduced our alert volume. I'm not sure of the exact number, however, instead of having 100 to 200 false positives, we might get 20 to 30.
It has helped us speed up our security investigation, although I don't handle it directly. I simply do triage, and it definitely helps there.
What needs improvement?
There are a lot of false positives which can cause a lot of fatigue.
Sometimes, there is latency in the logs.
When you deploy Splunk, you need a high level of knowledge. You really need to know what you are doing. It requires a lot of things.
They need to come up with straight steps to get things done, to have a step-by-step process to achieve this or that.
For how long have I used the solution?
I've been using the solution since 2020.
What do I think about the stability of the solution?
The stability is okay.
Splunk would tell you, especially on the different licenses they have, your storage, and your level of ingesting, it can vary.
Splunk needs to be more clear between storage and performance.
We worked with a client where almost immediately their storage was already in red. They didn't understand their storage needs as that wasn't clear.
What do I think about the scalability of the solution?
The solution cuts across countries. I'm not sure how many end-users we have.
The scalability is okay. It scales well even though you have to consider your licensing and storage.
How are customer service and support?
Technical support is good.
How would you rate customer service and support?
Which solution did I use previously and why did I switch?
I have used ELK previously.
How was the initial setup?
I have been involved in the deployment of Splunk in the past.
The initial setup is not so straightforward for those new to it. I'm accredited and have four years of implementation. You really need that level of knowledge. It's straightforward to make a feed, make it compliant, and do field mapping, however, there are many things you need to do before deployment.
We had six to eight people deploying Splunk. They were all mostly Splunk professionals, who understood the product and devised a plan and timeline for implementation. We integrated the relevant stakeholders into the process. We were connecting to the Splunk Cloud.
There is a little bit of maintenance required to maintain the infrastructure.
What about the implementation team?
We used all in-house resources to implement Splunk.
What was our ROI?
I have witnessed an ROI while using Splunk. There were some incidents previously in which the company lost millions of dollars. Bringing in Splunk has curbed that.
What's my experience with pricing, setup cost, and licensing?
The pricing is on the high side. It's not a solution for SMEs.
Which other solutions did I evaluate?
I'm not sure if any other options were evaluated by the company.
What other advice do I have?
Currently, we are just Splunk customers.
We do not monitor various clouds; we only monitor one. However, they have a good solution in that we don't need to worry about maintenance if we do.
We've never used the Mission Control feature.
If someone is looking for the cheapest SIEM solution, there are a lot of open-source options out there. However, Splunk definitely is an option. If a company is bigger, it would benefit from Splunk. They will be paying some money for it, however, it's worth it.
Resilience is important. To some extent, Splunk addresses this as we haven't had any issues. It's important to have resiliency. If your solution is not resilient, you risk security issues.
I'd rate the solution eight out of ten.
I would advise others to spell out what you really need and make it measurable so that you will understand if Splunk is right for you. If you are going to use Splunk, it's important to do your due diligence.
Which deployment model are you using for this solution?
Private Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Amazon Web Services (AWS)
Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.