We are a solution provider and Splunk is one of the products that we distribute.
The primary use case is for SIEM and we have approximately 35 customers.
We are a solution provider and Splunk is one of the products that we distribute.
The primary use case is for SIEM and we have approximately 35 customers.
The fact that Splunk is a platform and not just a SIEM solution is a key benefit.
Our customers like that they can use Splunk to optimize their security.
The Splunk licensing model should be more flexible.
The support that is included with the standard licensing fee is very bad.
We have been working with Splunk since 2017.
Stability-wise, it's perfect. We haven't had any problem with Splunk. It's good software.
One of the key benefits and differences with this software is that the customer can scale up as much as they need to. Our largest Splunk customer is using between three and four petabytes of data per day.
If you don't pay extra for technical support then it is very bad. If you pay extra for it, then the technical support is normal.
I am familiar with other products and Splunk can handle much more data than IBM QRadar or any other competing product.
Direct competitors are more flexible when it comes to licensing.
We have not had any problems installing Splunk.
For a standard case, it takes between one and two weeks to install correctly and deploy. This is for situations where the client has less than 50 gigabytes of data per day.
Problems during the implementation are typically due to something on the customer's side. For example, if the client does not have somebody that is responsible for the deployment, helping to speed up the various procedures, then this is a key problem for us.
It takes two people to deploy and maintain.
Splunk is not a cheap solution and the license is billed annually. The licensing model should be improved and the price should be lower, in general.
You can purchase additional technical support, which is much better than the support that is included.
I would rate this solution an eight out of ten.
My primary use case is for log management. It's mostly deployed on-premises, but it can be cloud-based as well.
The most valuable features are how stable and easy to use Splunk is.
This solution could be improved by better pricing in general and by easier installation.
I have been a partner of Splunk for three years.
This solution is stable.
Technical support is customer-friendly.
The initial installation is not straightforward. It needs two or three days, depending on the size of the company. But it can be done with one senior engineer.
I implemented through an in-house team.
Splunk has a subscription and a perpetual license.
This product could use better pricing.
I would rate Splunk a nine out of ten. I recommend this product to others who are considering implementing it.
I use this solution for data visualization.
The most valuable features of the solution are it is straightforward to use and the documentation is good for finding out how to get the data you are looking for.
The solution could improve by making it more business analysis oriented. The way it is now is designed more for developers.
I have been using Splunk for two weeks.
The solution is stable, I have not experienced any bugs or glitches.
The solution is scalable and it is a requirement of my company to have scalable solutions.
I have used previously Qlik Sense and Kibana.
I did the training with Slunk and once I had the training the installation was easy.
I have evaluated Tableau.
My advice to others is not to be intimidated by the solution and to give it a try. It will become easier over time.
I rate Splunk an eight out of ten.
Its integration is most valuable. Its UI is also pretty much easy.
Its setup is a little bit complex for a distributed environment.
Their support can also be better. If we raise a case with Splunk support and by any chance we missed to respond for more than a week, they usually close the case. Sometimes, it can take us more than a week to reply. In that case What they can do is they can send a followup mail before closing.
I have been using this solution for a year now.
It is very stable haven't encounter any glitches or bugs till now.
It is very much scalable. I am acting as an admin, and we have more than a hundred users of this solution in our company. We use it on a regular basis. We currently don't have any plan to increase its usage.
I would rate them an eight out of ten. Their response speed is okay, but if, by any chance, we miss the response for more than a week, they usually close the case. Sometimes, it can take us more than a week to reply.
This is the only solution that we have been using.
Its setup is pretty much easy for standalone, but for a distributed environment, it is a little bit complex.
I would recommend this solution to others, but it should meet their needs and architecture.
I would rate Splunk a nine out of ten.
They provide excellent predefined user cases.
This helps us in the footprinting of all the incidents.
When we deep dive into the events for the triggers, we have very little information in some instances.
I have used Splunk for two years.
We raised support cases.
Scalability is always a question for this product.
Response from technical support can be improved. There was always a delay and we had to chase them.
We didn’t have a previous solution.
I was not present during the initial setup.
Pricing and licensing are always high compared to other products in the market. Storage is very expensive as well.
It is a good product, but expensive.
I used it in the SOC environment to get logs, create dashboards, and filter out data.
The indexing and data collection are valuable.
Its search or filtering capability is nice, but it can be improved. It is currently a bit complicated, and it should be simplified. If we can write the search filter in a more simplified way, it would be better.
Their sales support and tech support need improvement. Their support is really bad.
I used it for nearly one year in my previous organization. I last used it about seven months ago.
It is stable.
Its scalability is good.
Their sales support and tech support are really bad. They take really long to respond.
We were using AlienVault. We switched because we weren't really happy with it. So, we looked into different solutions, such as Splunk.
Its initial setup was okay.
We did it ourselves. We had around two people for deployment and maintenance, but we had around 15 users. They all were SOC people.
We had a yearly subscription.
I can recommend this solution to others. It is a great product.
I would rate it an eight out of 10.
I am just a user, and from a user's perspective, it does the job.
It has quite extensive support in terms of integration. If you want to do anything, there are tools for that.
Its reporting can be improved. That's the only complaint I have heard. I don't need the reporting part, but I know that other people in the organization need it.
In terms of new features, I got everything that I needed from the tool. If they want to expand the capabilities to different things, they can cover topics besides log aggregation, etc.
I have been using this solution for two years. I am not using it on a daily basis.
It is stable. We don't seem to have any problems related to bugs. We are very happy with it.
We have our own internal team for its maintenance.
I would recommend this solution. If you are a technical person, it does what you need. If you are not a technical person and you require graphs, that's a different story.
I would rate Splunk a ten out of ten because I have no problems with it.
Because I'm security focused, I prefer the security features such as Splunk Phantom and Splunk Enterprise Security.
We need to get a Splunk Cloud instance inside South Africa's borders. At this stage, we are pushing Splunk Cloud, but it is not yet within South Africa's borders. So we've got data sovereignty issues, especially with government organizations.
Technical support could be improved as well.
Splunk can be an expensive solution. I think that they need to change their pricing model. At present, it is based on the number of gigabytes that you ingest into the Splunk system. Their competitors are now starting with a pricing model where you pay per device talking back. If Splunk could have a similar alternative, it would then allow people to choose the data model they want such as set data or a set number of devices.
I have been using Splunk for three years.
The technical support here in South Africa hasn't been great, but I understand why as we make up less than 3% of Splunk's total revenue in the world.
The initial setup isn't overly complex, but it's not easy either.
The pricing model is based on the number of gigabytes that you ingest into the Splunk system. So it can be an expensive solution.
Plan your requirements properly from the beginning so that you can get the most value in a shorter space of time.
On a scale from one to ten, I would rate Splunk at six.
Splunk license and storage pricing is high. please make it cheap then most off company can use this product.