I use Splunk for testing purposes. It is used for school research and to learn how to use Splunk.
Splunk is mainly used for collecting logs and dashboards.
I use Splunk for testing purposes. It is used for school research and to learn how to use Splunk.
Splunk is mainly used for collecting logs and dashboards.
Splunk provides a free version so you can test it before purchasing. It's better than IBM, in my opinion, because it's an independent entity. IBM, for example, if you want to use EDR, and other features, you must use the features of other companies, such as ServiceNow and Jira.
I am still exploring the features provided in Splunk. As I have not used it for a long time, I don't have a clear vision of it.
As a student, I'd like to see more labs and things for students to test in order to learn.
Having a trial version or more training on Splunk would be helpful.
There is a free version, but it is insufficient for training and learning because it is a little bit difficult to work with, especially if you are a beginner. It's difficult to improve when you're just starting out with logs and SOC. As a result, we require a longer free version.
Splunk is not used in my company. During my internship, I am being taught how to use it at school.
I have been using Splunk for one month.
I did not have any issues with the stability of Splunk. It was quite stable.
There was technical assistance available. When you require assistance, they provide it, they will respond.
We integrate Jira with QRadar which is helpful.
The initial setup was simple because there is available support and tutorials.
I completed the installation with the help of some friends, in the IT department.
I'm only using the free version for the time being.
The cost is reasonable.
Splunk's costing is a little more difficult. The pricing method is complicated, and the way that costing is calculated in Splunk is a little more difficult.
When compared to QRadar, QRadar, it's simple to pay.
I did some research for a school project. I needed to compare it to Splunk and a few other tools. As a result, I'm not particularly interested in purchasing them.
I would rate Splunk an eight out of ten.
We are using Splunk for querying data from different sources.
Splunk has machine learning which is a valuable feature.
The algorithms customization of Splunk could improve. They have limited algorithms for machine learning support. If they can allow the user to add more machine learning algorithms, such as the ability to choose the algorithm that a user might want. Additionally, they should provide the required libraries for those algorithms, and then analyzes the data for use.
I have used Splunk within the past 12 months.
Splunk is a stable solution.
We have contacted the support and most of the reasons we have contact support has been project-related. For example, we want the APAs to work in a certain way or for certain fixes.
I have been using Splunk for approximately
We primarily use the solution for log management and security purposes.
The log management is great.
It has a very good alert tool that you can create with the logs that Splunk gets.
You can check up on security from the dashboards. We use some custom applications which we have created by ourselves. It's very helpful to have custom dashboards with knowledge of the system of what we monitor.
The initial setup is simple.
We have found the solution to be stable.
Its scalability is quite good.
Right now, everything is good. I don't really have notes for aspects of improvement.
There can be a bit of complexity around some fields during the initial setup. There are some places where you have to use regular expressions to parse logs. The part of parsing logs correctly is the most, let's say, difficult thing, and when this is done, all of the other things are easier. Anyway, the regex part is a very good feature and in my opinion, it should stay like it is, because it gives a lot of flexibility. Customers may learn to use it or use technical support.
The cost of the solution is a little bit high.
I've used the solution since 2016. I've used it for around six years at this point.
In terms of stability, it's reliable. There aren't bugs or glitches. it works well. It doesn't crash or freeze.
The solution is scalable. If a company needs to expand it, it can do so.
We have a technical support contract.
For the most part, we can do it probably ourselves. When technical support helps us, however, everything goes pretty smoothly. We are quite satisfied with them. We typically get immediate support and assistance.
The ease or difficulty of the initial setup depends on the infrastructure of the organization. However, when we have installed it, it was pretty simple. That said, there are some fields that are complex, and for this, we have support.
We did get support to assist us with a few complex fields.
We pay a yearly license. You do need to set up a contract for technical support.
While I don't have details about the exact pricing, my understanding is that it can be a bit expensive.
We are a customer and an end-user.
I would rate the solution at a nine out of ten. We've been very happy with its capabilities in general.
The only downside is the pricing. If the price would be lower, you would have the possibility to buy more capacity for parsing logs per day. In Splunk, you have a daily limit of logs that will be parsed. If you place that limit several times, the Splunk license will be blocked and you have to talk with support to get a recovery license. With the capacity, you can include, let's say, 30 servers, but if you want to include another 20 servers, you have to buy an additional license, which is very costly.
That said, for medium and large enterprise businesses it's really necessary to have. Even in smaller businesses, it is good to have. It's just the price that would stop small businesses from taking it on.
If a small business has less than 500 MB logs/day, they may use a splunk free license.
The project we are working on with Splunk is short as the customer has given us two months to implement. My company is a Splunk partner.
Splunk is quite flexible for our customers. Splunk does not filter from a specific lock, you can define it later.
I would like Splunk to add more integration. QRadar has many indications with more products than Splunk.
I have been working with Splunk for three months.
Splunk is quite good if you want to scale it.
My client has some pain points with QRadar and does not feel the kilogram function is accurate. Other features do not match with the customer behavior as well. They want to replace QRadar with Splunk because they are familiar with this solution.
The initial setup of Splunk is complex. It requires a lot of equipment and uploads.
My company provides the implementation and maintenance services to our customers.
Splunk licensing requires you to purchase licenses for any feature per user. For example, if you need UEBA, it is difficult to propose in the project. QRadar has a free upcharge for UEBA. Customers cannot calculate the additional costs based on gigabytes per day because they can not forecast the future.
Due to the cost of Splunk, I recommend it for larger companies. Splunk is powerful when sorting huge amounts of data.
Implementation of Splunk takes preparation. It requires a lot of resources and needs the infrastructure to support the project.
I would rate the solution an 8 out of 10.
The connections to the database are very good and updating the data files is simple to do. The dashboards are useful and user-friendly.
We had some connections issues with the solution at the beginning.
I have used Splunk within the last 12 months.
Splunk is a highly stable solution.
The scalability is good.
We have approximately 50 users using this solution in my organization.
I am satisfied with the support from Splunk.
We were previously using Excel.
We used a consultant for the implementation of the solution. The full process took approximately one week.
We had a big problem with communication sometimes during the implementation. Some files in our network were a little difficult to receive. This was our fault because of some of our firewall configurations.
We have a five-person maintenance team that works on this solution.
I rate Splunk an eight out of ten.
I need the product for SIEM, Security Identity Event Management. I also need it for security operations, automated response, as well as mapping adjusting of security components as well. It helps us with how best to look at various events, and orchestrate between various different hyper-scalers.
The solution has made us more secure and has allowed for more definable mapping.
The SIEM is the most valuable feature of the product.
Having a better integration method and then ingesting and mapping the information have been somewhat easier than some of the other tools that I've used previously (other than QRadar and Rapid7).
The initial setup is pretty simple.
The solution is scalable.
Stability has been quite good.
The pricing is pretty decent.
The documentation is in definite need of improvement.
There are pieces of it that are somewhat just daunting and there should be better orchestration and automation.
I've done some automation with it, with Terraform, and also with some other sources. If it wasn't so proprietary, that would be ideal.
I'd like to have it so that Splunk integrates better with Terraform and Python.
I've used the solution for eight years. I've used it for quite a while.
Splunk is probably the best brand in terms of stability. I'd rate its reliability at a four out of five. There aren't bugs or glitches. It doesn't crash or freeze.
The scalability is great. I'd give it a score of four out of five. If a company needs to expand, it can do so.
We have 450 people in our organization that use the product. We've also done this for clients that needed access for over 200,000 people.
We use the solution extensively and likely will increase usage.
The support is okay, however, there are a couple of things that they couldn't figure out and they couldn't help me with automation or stuff like that. It could have been better from there, however, it's not that bad.
I've previously used QRadar and it wasn't ideal.
There were certain times I integrated with other solutions too.
The initial implementation is pretty simple and straightforward. It's not too complex. I'd rate the experience at an eight out of ten.
The initial deployment took us about two weeks or so.
The amount of personnel you need for deployment and maintenance tasks depends on the size of the deployment. Typically, it's just one or two people. That said, it needs to be proportionate to certain sizes. Usually, the staff is from procurement or provisioning.
I handled the implementation myself. I didn't need any outside assistance from any integrators. I'm a consultant myself.
We've seen quite extensive ROI, however, it's more of a qualitative assessment and I don't have numbers to share. It works well and customers are happy. That's what counts.
It's a little bit more expensive than some of the other tools. It's not as expensive as QRadar. That said, it's more expensive than LogRhythm or Sentinel.
There aren't really other fees beyond the standard costs of licensing.
I evaluated other things. I also integrated with other solutions too. I decided to go with Splunk due to the fact that it worked well.
I'm a consultant. I'm also a customer and use it myself.
We use multiple deployment models, including public and private clouds.
We typically use the latest version of the solution.
I'd advise potential new users to get a proper plan. They should have a good partner or someone that can help them and quickly map and orchestrate.
I'd rate the solution at a ten out of ten.
Splunk has a great platform. Their edge is in their lock management and being a very powerful lock server. Recently, they added some licensing and updated correlation rules to act as a SIEM Solution. They seem to be penetrating the market in a proper way.
I have been using Splunk for more than five or six years.
Splunk solutions are much more expensive than others. Especially when it comes to megaprojects or deals, there's a lot of competition when it comes to financials.
I would rate this solution a seven out of ten. Splunk has a user-friendly interface and GUI. Its architecture is also much more sophisticated than others.
The solution is primarily a SIEM tool and it basically helps companies with security.
It's basically one of the best SIEM products on the market.
The scalability is great.
We have found the solution to be stable.
Technical support is helpful. They respond in a timely manner.
I'd like to see more documentation on the product.
The initial setup is not straightforward.
You do need a lot of training and certification with this product. Other than that, it's pretty good.
I've been dealing with the solution for about three years. It's been a while.
The stability of the product is very good. The performance is reliable. There are no bugs or glitches. it doesn't crash or freeze. We've had no issues.
The scalability of the solution is great. If a company needs to expand it, it can do so. It's not a problem.
We have about nine customers that are using Splunk.
I've dealt with technical support and it's pretty good. They are helpful. I find them responsive.
The initial setup is not straightforward. It depends upon the IT infrastructure that the customer has. If they have a lot of security solutions, such as DLP and other security solutions, then it is more complicated. The more you have the more complicated it gets.
The deployment of Splunk takes about three weeks.
We have six or seven team members within our organization that can handle deployment and maintenance tasks.
I handled the implementation myself. It was done in-house.
Splunk requires a paid license. There's no free option. Customers have to pay for the license, implementation, support - everything.
The solution can be deployed both on-premises and on the cloud.
I'd rate the solution at a nine out of ten. We've been very happy with the product.
I would recommend the solution. It really is the best.