No more typing reviews! Try our Samantha, our new voice AI agent.
reviewer2500098 - PeerSpot reviewer
Senior Cybersecurity Engineer at a energy/utilities company with 5,001-10,000 employees
Real User
Jul 8, 2024
Saves time and enables our teams to look at and troubleshoot issues themselves
Pros and Cons
  • "Dashboards help the application support teams to have a quick look at how their systems are running. It helps other teams as well."
  • "They can get more integration with a few more products. They can also update some of the dashboards that are in there now."

What is our primary use case?

We have a lot of applications that we monitor. We have a lot of hardware that runs on VMware. We monitor all of that as well.

How has it helped my organization?

Dashboards have been helpful because people can go and look for themselves how their systems are running. The requests for us to go look at something have gone down because people can go and do it themselves.

It is important for us that Splunk Infrastructure Monitoring has end-to-end visibility. Developers and those types of teams can look at and troubleshoot any kind of issues quickly.

Splunk Infrastructure Monitoring has helped reduce our mean time to resolve, but I do not know how much. We just help as needed, but for the most part, it is just the teams going in there and looking at things themselves.

Splunk Infrastructure Monitoring has helped improve our organization’s business resilience.

Different teams can see a lot of different aspects of what is going on. They can see network traffic. They can see applications, and they can see hardware peaks and performances. They can see everything they need.

We could see the value of Splunk Infrastructure Monitoring within a couple of weeks of implementing it.

What is most valuable?

Dashboards help the application support teams to have a quick look at how their systems are running. It helps other teams as well.

What needs improvement?

They can get more integration with a few more products.

They can also update some of the dashboards that are in there now.

It is pretty good in terms of the ability to predict, identify, and solve problems in real-time, but there is always room for improvement.

Buyer's Guide
Splunk Observability Cloud
July 2026
Learn what your peers think about Splunk Observability Cloud. Get advice and tips from experienced pros sharing their opinions. Updated: July 2026.
908,858 professionals have used our research since 2012.

For how long have I used the solution?

I am in a new role. I have been there for two months. That is as long as I have been using it.

What do I think about the stability of the solution?

It is very stable. It is good.

What do I think about the scalability of the solution?

Its scalability is great.

How are customer service and support?

It is very good. I would rate them a nine out of ten. They are usually pretty helpful and knowledgeable.

How was the initial setup?

We have it on-prem, and we also have a cloud instance. Our cloud provider is AWS. We do not monitor multiple cloud environments.

Deploying it was pretty straightforward. We just had to make sure that we were getting the logs right and setting the apps right. That was pretty much it.

What was our ROI?

We have seen an ROI in terms of manhours and less work for everyone.

What's my experience with pricing, setup cost, and licensing?

I have always used Splunk.

What other advice do I have?

I would rate Splunk Infrastructure Monitoring a ten out of ten. It is great. It is much better than a lot of other products, so it is definitely up there.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Computer Engineer at Fuse engineering
Real User
Jun 30, 2024
Provides good metrics, scales well, and has good support
Pros and Cons
  • "I have primarily used it to go back into the past and understand why something happened. It provides enough information to do research and figure things out."
  • "One thing I recently ran into was that the logs on the server most often get Gzipped after they have been rotated. We found that we were not monitoring some of the things, so we had to go back and pull them in. Right now, it pulls one at a time, untars it, or unzips it, so I cannot look at the entire history. There can be an improvement in that area."

What is our primary use case?

We are monitoring our servers and their health. We are monitoring their functionality and supporting the Kubernetes platform.

How has it helped my organization?

Our team supports multiple different projects. They all have their own clusters and ways of operating, but we just use one Splunk Infrastructure Monitoring system.

Splunk Infrastructure Monitoring has helped improve our organization’s business resilience.

What is most valuable?

I have primarily used it to go back into the past and understand why something happened. It provides enough information to do research and figure things out.

What needs improvement?

One thing I recently ran into was that the logs on the server most often get Gzipped after they have been rotated. We found that we were not monitoring some of the things, so we had to go back and pull them in. Right now, it pulls one at a time, untars it, or unzips it, so I cannot look at the entire history. There can be an improvement in that area.

For how long have I used the solution?

I have been using Splunk Infrastructure Monitoring for four years.

What do I think about the stability of the solution?

It is stable.

What do I think about the scalability of the solution?

About a year ago, we added another 600 servers and scaled up. We are getting more in the next year or later this year. It works smoothly.

How are customer service and support?

They are good. I have a ticket open now. I told them to go ahead and close it because we thought it was a hardware issue, but they said that they would keep the case open till the hardware replacement to see if the issue goes away. That was pretty nice.

Which solution did I use previously and why did I switch?

All of our hardware is HPE-based. We rely mostly on OneView, but it does not give us the service aggregation and other things that Splunk Infrastructure Monitoring is giving us.

How was the initial setup?

One of the gentlemen on other teams came to ours. He is very knowledgeable about Splunk, so he helped with the implementation.

All of our servers are RHEL-based.

Which other solutions did I evaluate?

A different organization group within our organization had Splunk, and they liked it, so we just went with Splunk.

What other advice do I have?

I would rate Splunk Infrastructure Monitoring a ten out of ten.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Buyer's Guide
Splunk Observability Cloud
July 2026
Learn what your peers think about Splunk Observability Cloud. Get advice and tips from experienced pros sharing their opinions. Updated: July 2026.
908,858 professionals have used our research since 2012.
Performance Test Engineer at Infosys
MSP
May 12, 2024
Provides end-to-end visibility, simplifies application performance monitoring, and makes monitoring logs easy
Pros and Cons
  • "The most valuable feature is dashboard creation."
  • "Splunk's functionality could be improved by adding database connectors for other platforms like AWS and Azure."

What is our primary use case?

We use Splunk APM for performance testing. 

How has it helped my organization?

Splunk offers end-to-end visibility across our environment.

Splunk APM simplifies application performance monitoring. It also provides insights into data quality, including data security, integration, ingestion, and versioning of trace logs. We can directly inject data for monitoring purposes, trace the data flow, and monitor metric values.

Splunk can ingest data in any format, allowing us to easily monitor logs and identify blockages through timestamps, which saves us time.

What is most valuable?

The most valuable feature is dashboard creation. This allows us to easily monitor everything by setting the data we want to see. For example, imagine we're working on a project within the application. There might be different environments, such as development, testing, and production environments. In the production environment, we can use dashboards to monitor customer activity, like account creation or other user data. This gives us a clear view of how transactions are performing and user response times. This dashboard creation feature is one of the most beneficial aspects of Splunk that I've used in a long time. While Splunk offers many features, including integration with various DevOps tools, its core strength lies in data monitoring and collection.

What needs improvement?

Splunk's functionality could be improved by adding database connectors for other platforms like AWS and Azure.

For how long have I used the solution?

I have been using Splunk APM for one year.

Which solution did I use previously and why did I switch?

We previously used a legacy application for monitoring and when it was decommissioned we adopted Splunk APM.

What's my experience with pricing, setup cost, and licensing?

Splunk offers a 14-day free trial and after that, we have to pay but the cost is reasonable.

What other advice do I have?

I would rate Splunk APM eight out of ten.

Splunk APM requires minimal maintenance and can be monitored by a team of three.

Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
PeerSpot user
Yaseen Shaikh - PeerSpot reviewer
Splunk and AppDynamics SME at Saudi Networkers Services
Real User
Mar 6, 2024
Improves operational efficiency and integrates very well
Pros and Cons
  • "I find the monitoring console very helpful. With one click, I can see how we are performing, and at the same time, I can see what data is flowing."
  • "The clustering part of indexes can be more refined."

What is our primary use case?

We mostly work with developers. They run some pipelines, and they use Splunk as a platform to identify the errors, instead of themselves debugging the logs and understanding what the issue is. This is one side of the business. On the other side of the business, we use the Splunk database for frozen buckets where we archive the data.

We can easily integrate it with other tools for monitoring our entire IT data infrastructure. I also handle AppDynamics. We have integrated Splunk and AppDynamics. With one click, we can understand what the actual issue is. It brings down the time to resolve. We have had some good experiences.

How has it helped my organization?

It improves our operational efficiency every day. In my previous company, we had integrated it with ServiceNow. For defined alerting conditions, it could directly open up a ticket for the right team. We did not have to look into a thousand cases to understand a problem.

In terms of integrations, most of the plugins are already available. If a plugin is not available, even then it is pretty easy to integrate. There are multiple ways to integrate. You can use the REST API and just forward the data. It can be easily integrated.

It makes it easy to have end-to-end visibility in the cloud environment. There are multiple types of devices in an environment. You might have AWS, Microsoft Azure, or something else. It operates beautifully. It is easy to integrate. This is the best part.

I am in the banking industry. It helps to keep track of how well our application is performing when somebody tries to do a transaction. There are multiple pieces to it, and we keep track of everything. We have our own business dashboard that the top-tier leaders can look into. All the visibility is there because of it.

What is most valuable?

I find the monitoring console very helpful. With one click, I can see how we are performing, and at the same time, I can see what data is flowing.

What needs improvement?

The clustering part of indexes can be more refined.

They can cut down a bit at the monetary level for the long-time customers. We recently had a scenario where we were in discussions to see if there was any flexibility from Splunk's side.

For how long have I used the solution?

I have been using this solution for the past two years. I have also used it in my previous company.

What do I think about the scalability of the solution?

It is pretty scalable. I would rate it a nine out of ten for scalability.

Which solution did I use previously and why did I switch?

I have worked with Kibana and Logstash, but they are not comparable to this solution.

What's my experience with pricing, setup cost, and licensing?

It is expensive.

What other advice do I have?

Overall, I would rate it an eight out of ten.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
System Administrator at Nournet communications
Real User
Aug 14, 2023
User-friendly, offers good visibility through the logs, and helps identify issues in our environment
Pros and Cons
  • "The most valuable feature is log reporting."
  • "The price has room for improvement."

What is our primary use case?

We use Splunk Infrastructure Monitoring because it is a durable solution for our environment.

How has it helped my organization?

Splunk Infrastructure Monitoring is easy to use.

The dashboards are good.

Splunk Infrastructure Monitoring has helped improve our operational performance and efficiency. 

Splunk Infrastructure Monitoring has helped reduce our MTTD by 90 percent.

Our MTTR is good thanks to Splunk Infrastructure Monitoring.

What is most valuable?

The most valuable feature is log reporting.

What needs improvement?

The price has room for improvement.

For how long have I used the solution?

I have been using Splunk Infrastructure Monitoring for five years.

What do I think about the stability of the solution?

I would rate the stability of Splunk Infrastructure Monitoring ten out of ten.

What do I think about the scalability of the solution?

Splunk Infrastructure Monitoring is scalable.

How are customer service and support?

I have used the technical support a few times and they were good.

How would you rate customer service and support?

Positive

What's my experience with pricing, setup cost, and licensing?

I would rate the price of Splunk Infrastructure Monitoring as an eight out of ten, with ten being the most expensive.

What other advice do I have?

I rate Splunk Infrastructure Monitoring ten out of ten.

Splunk Infrastructure Monitoring is a good service that provides visibility into our environment.

I recommend Splunk Infrastructure Monitoring to organizations for the logs that will help identify errors in their devices and assist them in resolving the issues.

One person is required to maintain Splunk Infrastructure Monitoring.

Which deployment model are you using for this solution?

Hybrid Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
reviewer2499615 - PeerSpot reviewer
Splunk engineer at a computer software company with 51-200 employees
MSP
Jul 3, 2024
Helps organizations achieve compliance control and provides all the data to users in a single place
Pros and Cons
  • "The tool's stability is great."
  • "There is not a lot of support for the tool's on-premises version, especially since everything is on the cloud."

What is our primary use case?

I use the solution in my company for our customers who use the tool for auditing and compliance in the area of DoD/AC. My company's customers have compliance controls, and STIG controls that they have to satisfy for their ETL processes.

How has it helped my organization?

The tool has helped our customer's organization in achieving compliance control. When our customer's organization has an inspection or when the DoD inspects their infrastructure, they can show their auditors that they are compliant. They can show the auditors the dashboards and verify that they are ingesting data from the sources and how all their hosts are being monitored. They can show everything to auditors, check the box, make sure that everything looks green, and then they continue to have authorization to operate.

What is most valuable?

The most valuable piece of Splunk Infrastructure Monitoring for our company's customers revolves around the data for everything. Everything produces data, and all the data can get ingested, whether it is Windows, RHEL, VMware products, Pure Storage products, or a custom product. Configuring data ingestion and performing everything in Splunk Infrastructure Monitoring is possible. At the same time, a lot of the other SIEM tools focus on a specific type of data. The benefit of Splunk Infrastructure Monitoring is that one can see all their data in one place.

What needs improvement?

There is not a lot of support for the tool's on-premises version, especially since everything is on the cloud. In my company, we had a really good demo this morning on Keynote, which touches on the APM part, and it was super cool. There was also a demo on AI assistant, which was super cool. It is hard to increase the options for a particular customer when so much of the stuff is limited to the cloud, and there is so much focus on the cloud part.

For how long have I used the solution?

I have been using Splunk Infrastructure Monitoring for three years for my customer, who has been using it for longer than when I started to use it.

What do I think about the stability of the solution?

The tool's stability is great.

What do I think about the scalability of the solution?

The tool's scalability is great. My company just moved Splunk from VMs to containers for our customers, so I would say that we have put it on Kubernetes on Tanzu, which has been great for them.

How are customer service and support?

Support is an area I have not really reached out to on behalf of our customers. I usually just go to Splunk Answers or rely on my colleagues to get what I need. My company has never opened a support ticket with Splunk for our customers.

Which solution did I use previously and why did I switch?

I don't know what one of my company's customers had used before Splunk Infrastructure Monitoring. They may have used some other solutions, but I have been on contract with them for three years.

What was our ROI?

In terms of ROI, I can say that I have seen a decreased amount of time spent on our company's end validating data ingested from an auditing perspective, especially when we are talking about their authorization to operate. With the tool, it is much quicker to view all your data in one place than it is to go show an auditor 15 different data sources. You can show it all together to the auditor.

What's my experience with pricing, setup cost, and licensing?

Licensing cost is the biggest argument I get from those divesting from Splunk. There are those within our organization who say we are going to go to other tools since Splunk is too expensive. Till now, I have been able to ask others to look at the value Splunk adds to the company, and I have been able to convince them that it is worth it, but that might not always be the case if licensing continues to be an issue, especially if costs continue the way they are and if other solutions offer more competitive pricing for similar results.

What other advice do I have?

The tool is not used to monitor multiple cloud environments.

It is not important for our company that Splunk Infrastructure Monitoring provides end-to-end visibility into your cloud-native environment.

The tool has helped improve our organization's business resilience.

The tool does the job very well. It is easy for me to use, especially as a trained person in Splunk products. The tool also does the job very well. With the tool in place, I can get Windows or RHEL. I can do things like scripted input on a forwarder. Splunk Universal Forwarder are so much more than if I just use Syslog, for example, to just get data. I can do a lot more with Splunk than just ingesting data via something like Syslog.

I rate the tool an eight out of ten.

Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
PeerSpot user
Senior Network Administrator at a comms service provider with 51-200 employees
Real User
Aug 4, 2023
The solution has enabled us to be more proactive, so we can identify and respond to an issue before there is a failure
Pros and Cons
  • "Splunk Infrastructure Monitoring gives us complete visibility without the need for storage."
  • "Splunk could be better integrated with configuration manager solutions so we can automatically resolve issues without human interference."

What is our primary use case?

We use Splunk Infrastructure Monitoring to get an overview of what's happening in our customers' infrastructure. We're monitoring our servers, network, IoT devices, etc. We're a service provider, so the solution is installed in one place. 

How has it helped my organization?

Splunk Infrastructure Monitoring has enabled us to be more proactive. We can identify and respond to an issue before there is a failure. It has helped us significantly. For example, if somebody is attacking us we can detect that there is an increase in traffic and investigate to see if it's legitimate. We can block them or take other actions before it becomes a problem. 

What is most valuable?

Splunk Infrastructure Monitoring gives us complete visibility without the need for storage. We can visualize our infrastructure. Where is the traffic going? Are there any attacks? What are our vulnerabilities?

What needs improvement?

Splunk could be better integrated with configuration manager solutions so we can automatically resolve issues without human interference. 

For how long have I used the solution?

We have used Splunk Infrastructure Monitoring since 2015.

What do I think about the stability of the solution?

Splunk Infrastructure Monitoring is stable. 

What do I think about the scalability of the solution?

Splunk is scalable. It's easy to add more devices as needed. 

How are customer service and support?

I rate Splunk support an eight out of ten. 

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

Before Splunk, we used multiple vendors, including Cisco, SolarWinds NPM, and WhatsUp Gold

How was the initial setup?

The deployment process isn't complicated. We installed Splunk on a VM and started it. We have a team to deploy and monitor it.

What was our ROI?

Splunk is worth the investment. When an incident happens, you need reports immediately, and Splunk is the best monitoring solution for this. 

What's my experience with pricing, setup cost, and licensing?

Splunk is expensive, but it's the best solution for the job. 

What other advice do I have?

I rate Splunk Infrastructure Monitoring a nine out of ten. Splunk is a responsive piece of software. It's user-friendly and easy to get the data you need. I advise people to take the time to learn how to create reports and analytics.  

Which deployment model are you using for this solution?

On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Ayush Rohilla - PeerSpot reviewer
Works at a tech company with 1,001-5,000 employees
Real User
Jul 31, 2023
Troubleshoots quickly and offers end-to-end visibility across the environment
Pros and Cons
  • "It is a good tool. It allows you to set alerts for application and infrastructure monitoring, and it allows you to create dashboards."
  • "They can improve the flow system and the keyword language. It has predefined keywords, but they can be improved."

What is our primary use case?

I am a technology analyst. I have been working on a financial project in the US. For this project, I used Splunk APM for troubleshooting and reviewing the logs, and finding errors. Most of our APIs ran on Splunk APM, and we used it to find errors in our production environment.

We are no longer using Splunk APM. We have switched to Dynatrace.

How has it helped my organization?

Splunk APM is very good for monitoring purposes. You can watch application-to-application flows. If you just click on a flow, you can go step by step and debug an issue. The places with errors are marked in red. The API or the application in which you are getting an error is red. From there, you can go to the log or the error, and then the person responsible for that particular API or application has to fix it.

Splunk APM gives tools for user monitoring, logs observability, infrastructure monitoring, synthetic monitoring, and automated on-call. 

Splunk APM provides real-time data. In the logs, if you want to see errors related to status 404, you can just write one keyword, and you will get the results.

Splunk APM offers end-to-end visibility across the environment, but it also depends on how your business is set up on Splunk APM.

Splunk APM helped to reduce our mean time to resolve (MTTR). Previously, I had to log into my VPN, run commands, and see the logs. After having Splunk APM, I could click on one link and go through the logs. 

We could set up Splunk APM based on our environment. I worked on one project with Splunk APM. In that project, we faced a lot of issues, and I resolved the issues with the help of Splunk APM. I found the accurate logs and the easiest way to resolve the errors.

What is most valuable?

Splunk APM is the most advanced application for performance monitoring and troubleshooting for cloud-native applications and microservices.

The ability to troubleshoot is valuable. While running any product or API, we need to troubleshoot issues. We need to find the error in the logs. In Splunk APM, we have the section logs. In that section, we can search with any particular keywords. Before Splunk APM, I also worked with Splunk Enterprise where we have various dashboards to monitor. 

It is an application performance monitoring and observability tool. It is a very good tool. You need to use the documentation on Splunk's website. From there, you can learn many things. I have Splunk certification. You can dive deep into it. For me, it gives end-to-end visibility into our production environment.

What needs improvement?

They can improve the flow system and the keyword language. It has predefined keywords, but they can be improved. I also use LogMeIn where I can use predefined keywords to see the logs. 

They should give us the option to use our own language to search. For example, I should be able to search for an ID name along with an error or status code. 

For how long have I used the solution?

I worked with Splunk APM for one and a half years.

What do I think about the stability of the solution?

I have not faced any downtime. I have worked with Splunk APM for one and a half years, and I did not face any downtime during this duration of time.

What do I think about the scalability of the solution?

I have never faced any issues with scalability.

How are customer service and support?

I did not have any need to contact support because I did not face any issues. 

Which solution did I use previously and why did I switch?

We used another solution previously. In Splunk Enterprise, it is easier to create dashboards. You can easily set up application alerts and infra alerts. You can search with metrics and you can set alerts based on a specific error. Whenever that error occurs, you will receive an alert.

How was the initial setup?

I am not involved in its deployment. In terms of maintenance, it is owned and managed by Splunk. Everything is maintained by Splunk. I have not faced any downtime with Splunk APM. I have also used Splunk Enterprise previously. With both of these products, I did not face any downtime. 

What's my experience with pricing, setup cost, and licensing?

The pricing is reasonable.

What other advice do I have?

It is a good tool. It allows you to set alerts for application and infrastructure monitoring, and it allows you to create dashboards. You can set alerts based on the threshold or traffic.

For logging purposes, Splunk APM is very good, but we should be able to use our own search query language. Currently, we can only search based on the predefined tags.

Overall, I would rate Splunk APM a nine out of ten.

Which deployment model are you using for this solution?

Hybrid Cloud
Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
PeerSpot user
Peder Illum - PeerSpot reviewer
Consultant at Medcom
Consultant
Jul 26, 2023
Gives us early warning on problems that could arise
Pros and Cons
  • "Splunk has drawn our attention to how the network is running. If there are alarms on things that are not functioning, it gives us early warning on problems that could arise."
  • "It's a bit difficult to use. It takes some time to get into it and to get it to do what you would like it to do. It is not straightforward to use it."

What is our primary use case?

We have used Splunk to give us insight into the NetFlow of the traffic running through our network. We connect different networks but we only use on-prem. We are in the middle of a spider web, providing these services to different networks. We are trying to gain visibility into the traffic that traverses our network internally.

We are interested in the traffic volume because the services we are looking at are endpoint-encrypted, meaning encrypted traffic between a service provider and a client in another network. So we are not able to look into the media stream.

The networks we are connecting have their own security boundaries and their own security levels, and we don't mess with that. We are just trying to let them talk together. 

We have been using Splunk for monitoring who is logging in and how and when.

How has it helped my organization?

It has given us visibility into what is going on in the network, such as how much traffic is running to and from the services, but we are not using Splunk in a straightforward way. When we are looking into reports on how much data has been used, we need to look into another system and enrich it with data from Splunk.

Splunk has drawn our attention to how the network is running. If there are alarms on things that are not functioning, it gives us early warning on problems that could arise.

In terms of operational performance, the efficiency, Splunk has helped us improve. We could have found other tools that would have given us the same efficiency, but this was the tool that we chose. From that perspective, it has been of value to us.

It would have helped us reduce our mean time to detect but I can only guess at how much; perhaps by 25 percent. And we would see a similar reduction for mean time to resolve.

What needs improvement?

It's a bit difficult to use. It takes some time to get into it and to get it to do what you would like it to do. It is not straightforward to use it. Once you have the dashboards for collecting and analyzing transactions configured, they are okay, but it takes some time to do it. Configuration could be easier.

For how long have I used the solution?

We have been using Splunk for about eight years.

What do I think about the scalability of the solution?

We have not looked at Splunk as a means of being able to scale, but we have not been hindered by using Splunk. Our goal has not been growth, but maintaining stable and secure networking, and this is what we have achieved. But with or without Splunk, we would have achieved that anyway.

How are customer service and support?

We really haven't had any technical issues where we involved Splunk's support.

Which solution did I use previously and why did I switch?

We did not have a previous solution like Splunk, other than in-house-developed tools. We got acquainted with Splunk as part of the tender for our network infrastructure, and from that perspective, it has been okay.

What's my experience with pricing, setup cost, and licensing?

Splunk has been fairly expensive, but it has been predictable. You are not punished if you are looking into much more data if you are, for example, under attack. Other tools could be more expensive to use if they charge per incident or the amount of data you are looking into. With other solutions, you could be punished if you need to index more data because of an attack, such as a DDoS attack, and you need to do some forensics on the data.

What other advice do I have?

Why shift to something you don't know when you are, perhaps, happy enough with the tool that you already have? Think about whether you could develop that tool into something that would give you the visibility you would like to have, instead of using Splunk. Are you looking into incidents, traffic flows, indexing per day, or is the issue that you're looking for an alternative with a better price? Think about why you are considering shifting from a tool that you already know.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Robert Cheruiyot - PeerSpot reviewer
IT Security Consultant at Microlan Kenya Limited
Real User
Apr 13, 2023
Simple to install and configure with many interesting features
Pros and Cons
  • "It's a very easy-to-use solution."
  • "They need more EDR functionalities."

What is our primary use case?

We primarily use the solution for network monitoring and to identify threats. It is a security measure. 

How has it helped my organization?

If anything suspicious happens in the banking system, the solution would be able to identify the threat. We've also been able to identify malicious domains and phishing attacks. 

What is most valuable?

The product provides a lot of valuable features. 

It's helpful for identifying threats. The solution helps protect against phishing and malicious domains.

We we see any spikes in the CPU, it might be a sign of suspicious activity, and we can monitor it to protect our company. 

It's a very easy-to-use solution. It's simple to install and configure.

The solution is stable.

It is scalable.

What needs improvement?

They need to offer better endpoint protection. They don't have their own platform for endpoint protection. It would be helpful if they added something that addressed that. They need more EDR functionalities. 

Support could be faster. 

For how long have I used the solution?

I've used the solution for five years now. 

What do I think about the stability of the solution?

The solution is stable. It's reliable and the performance is good. There are no bugs or glitches and t doesn't crash or freeze. 

What do I think about the scalability of the solution?

The solution is really scalable. You can easily add more components and different vendors. 

We're an IT service provider. We don't use Splunk ourselves. However, a bank we work for has about 500 employees right now that would be leveraging Splunk. 

How are customer service and support?

We tend to support our customers. We can troubleshoot for customers.

We also use Splunk technical support, and they aren't too bad. They could be faster and improve their response time. 

Which solution did I use previously and why did I switch?

We also use Cisco for EDR since Splunk doesn't really have any EDR options. 

How was the initial setup?

The simplicity of the setup is great. It's easy to configure. Splunk is very straightforward. 

To have the solution up and running, you can deploy it in three hours. There might be more integration that needs to be done on top of that. There are a few other items that may make the deployment a bit longer, depending on the setup. 

Installing the system is very easy. However, for it to be useful, you need to customize it to integrate with your current use cases. You might have to spend some time testing use cases. It's important to understand the use cases before doing the configurations.

We have a manager and a few engineers that can handle deployment and maintenance tasks. 

What about the implementation team?

We're a service provider and can implement the solution for clients. 

What's my experience with pricing, setup cost, and licensing?

We use a free version of the solution. There is also an enterprise option as well. 

The product has a fairly flexible licensing model. You buy based on your requirements, whether it is six months or a year.

What other advice do I have?

We are using the latest version of the product. 

I'd rate the solution eight out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
PeerSpot user
Buyer's Guide
Download our free Splunk Observability Cloud Report and get advice and tips from experienced pros sharing their opinions.
Updated: July 2026
Buyer's Guide
Download our free Splunk Observability Cloud Report and get advice and tips from experienced pros sharing their opinions.