What is our primary use case?
We just started implementing Splunk Observability Cloud in my company as an ongoing project.
Our main use case for Splunk Observability Cloud is for our digital team for our website healthpartners.com, and that's the reason we decided to bring in a unified monitoring platform instead of using different monitoring tools. We are working with other teams as well at the same time, bringing their metrics and traces into Splunk Observability Cloud from other monitoring tools.
The other use case that we're working on regarding Splunk Observability Cloud is synthetic monitoring, and right now, we have some legacy solutions that have been used for the health checks, browser tests, and API tests, which have been moved over from a different tool to Splunk Observability Cloud. There is also one team that I'm currently talking to where we have set up the health checks in a legacy way using REST API inputs on the heavy forwarder, and we are planning to move that to Splunk Observability Cloud as well.
What is most valuable?
In my opinion, the best features Splunk Observability Cloud offers are the dashboards and some of the alerting features that I appreciate. I have also just found out that they are adding the incidents feature, which is really interesting, and I would to know more about that as well in the alert section to group all the alerts in a single incident, so that is going to be great.
For the alerting features of Splunk Observability Cloud, right now, we have been setting detectors for all the synthetic monitoring tests that were set up and also some of the host metrics, and we are testing it out, notifying those alerts and sending them to the teams, and that has been helpful even for our team. For the dashboards, so far, there is one dashboard that was built for us, the gateway monitoring dashboard where we send metrics via the gateway, and when something happens on the gateway side, if there's a delay or if the metric stops streaming into Splunk Observability Cloud, we can check the dashboard, so I appreciate that feature too.
Regarding the features of Splunk Observability Cloud, maybe the fleet management is what I'm looking forward to, as I know that feature has been added recently and we are able to see the gateway collectors showing up on there. I am more interested to see how the OTel collectors or anything else show up in there, and how that can be useful for our team.
What needs improvement?
I don't think I've seen any missing features of Splunk Observability Cloud so far, as I'm still exploring it and learning as we work on the project, so I think it is going to be great.
I can't think of anything at this time, but the new incident feature is great, and I heard for the DB monitoring, there is something that is going to be added in Splunk Observability Cloud where we can add custom attributes in there, which might be helpful in the future.
What do I think about the stability of the solution?
Splunk Observability Cloud is stable in my experience so far.
What do I think about the scalability of the solution?
I cannot say with certainty at this time regarding Splunk Observability Cloud's scalability, as we're still in the middle of the project, so I don't know how scalable this is. Right now, there's one task that I'm working on to bring in the SQL servers for DB monitoring into Splunk Observability Cloud, and right now, we don't have licensing for it, so we are working on getting the licensing. I would love to see once we have those metrics into Splunk Observability Cloud, how that is going to work and how scalable it is.
How are customer service and support?
I did interact with Splunk Observability Cloud's customer support, and it is working and is good so far.
Which solution did I use previously and why did I switch?
There are multiple different tools that have been used in my company; it's not just one. We have Foglight, Prometheus, Grafana, and we are moving towards having a unified monitoring tool or unified solution, which is the reason for the switch or migrating over.
How was the initial setup?
I was not involved in any discussions about pricing, setup cost, or licensing for Splunk Observability Cloud, so I have very minimal experience with that.
What was our ROI?
I haven't seen any return on investment yet, but I do definitely expect to see ROI soon, once we bring in everything and reduce workload.
What's my experience with pricing, setup cost, and licensing?
I was not involved in any discussions about pricing, setup cost, or licensing for Splunk Observability Cloud, so I have very minimal experience with that.
Which other solutions did I evaluate?
I am not sure if any other options or proofs of concept have been done before choosing Splunk Observability Cloud, as it was a higher-ups decision to go with it.
What other advice do I have?
I have heard from one of the teams when they set up the synthetic monitoring, so they gave really positive feedback to us, which was good. The other teams, the problems they had with the other monitoring tools, I feel have been solved with Splunk Observability Cloud to some extent, so that is going well so far.
I think one of the issues that they had was with the alerting from their tool, and there is this one person who works with the developer teams and gathers all the information regarding the browser tests and API tests. He sets it up for the alerting; right now, we have the ServiceNow webhook integration that was set up to notify or generate the ServiceNow incident, and the way it was set up in Splunk Observability Cloud is that whenever the incident clears itself, it will notify the team, but it won't close the ticket out, so they can take a look and have human eyes on it before they close it out, and that was positive feedback that was given to me.
Regarding Splunk Observability Cloud's AI capabilities, we haven't had the AI capabilities enabled for our instance yet, so we have not had the AI assistant or any other features, but I'm looking forward to learning more or understanding the AI capabilities once we deep dive into the project.
For others looking into using Splunk Observability Cloud, I would first recommend taking a basic education course; if it is a user, maybe a free course or a basic course to understand how Splunk Observability Cloud works and what features are inside it. If it is a power user or admin, I think we need to provide the documentation to the users on how easily they can log in, go between the features, and understand where they can find the dashboards, alerting, metrics, and so on.
I'm looking forward to implementing, completing the project, and starting to use it, as well as our users starting to use Splunk Observability Cloud soon. I would rate this product an eight out of ten.
Which deployment model are you using for this solution?
Hybrid Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Disclosure: My company does not have a business relationship with this vendor other than being a customer.