I have the logs of my applications, and they're usually a bit volatile. The log switch doesn't stay there on the application for a long time, so Splunk can require that. It can take 15 days for the logs to be available to do some kind of research. I'm using Splunk to ingest application logs, create dashboards, and set up alerts.
Senior Support Engineer at a tech vendor with 10,001+ employees
The dashboards are great, and we get solid visibility across our environment
Pros and Cons
- "Splunk's dashboards are great."
- "The licensing model is expensive. We need to monitor the amount of data ingested because the cost is based on the data collected."
What is our primary use case?
How has it helped my organization?
The biggest benefit of Splunk is that we can retain logs and correlate the data. Telemetry data has a huge impact because it's much easier to see everything.
Splunk has significantly reduced our mean resolution time. The workflow at my company involves application microservices applications running on the cloud. These logs are highly volatile, so they're only retained for three to five minutes, and we had to reproduce an issue to trace why it failed. That meant we had to do everything again to capture the log at the moment. Now, we have the data to analyze one or two hours.
What is most valuable?
Splunk's dashboards are great. The solution provides end-to-end visibility across my environment. Visualizing large amounts of data is easier because we can correlate the data from any target source.
What needs improvement?
The licensing model is expensive. We need to monitor the amount of data ingested because the cost is based on the data collected.
Buyer's Guide
Splunk Observability Cloud
August 2026
Learn what your peers think about Splunk Observability Cloud. Get advice and tips from experienced pros sharing their opinions. Updated: August 2026.
913,924 professionals have used our research since 2012.
For how long have I used the solution?
I have used Splunk APM for three years now.
What do I think about the stability of the solution?
We have instances for production and development. I've never seen the production instance go down. Our development instance has gone down, but that's expected.
Which solution did I use previously and why did I switch?
I used tools like Elasticsearch, which is similar to Splunk. I've also used other observability tools like Grafana and Dynatrace, but they have different features.
What other advice do I have?
I rate Splunk APM 10 out of 10.
Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
Lead Infrastructure Domain Architect (Systems) at a healthcare company with 10,001+ employees
Log searching and log analytics come in handy; incredible tech support
Pros and Cons
- "The features I have found most valuable are log searching and log analytics, both of which are quick features."
- "There is a lot of room for improvement with the automation."
What is our primary use case?
Our primary use case for this solution is as a supplement to Dynatrace, so the log analytics is done in Splunk instead of Dynatrace.
How has it helped my organization?
We built a tool for firewall log monitoring and we powered all firewall logs to Splunk. In addition, we built a little dashboard that just specifies sources and the destination addresses and port numbers. It passes all the logs and tell us if there are any blocks or drops on the firewall level. This is a very useful tool for us.
What is most valuable?
The features I have found most valuable are log searching and log analytics, both of which are quick features.
What needs improvement?
There's a component in this solution that is particular and takes a lot of manual work and that is the automation. There is a lot of room for improvement with the automation. They should also improve the discovery and detection of all the infrastructure components so that it is more automated and takes less manual work.
For how long have I used the solution?
I have been using this solution for about five years.
What do I think about the stability of the solution?
I would rate the stability of this solution an eight, on a scale from one to 10, with one being the worst and 10 being the best.
What do I think about the scalability of the solution?
I would rate the scalability of this solution a nine, on a scale from one to 10, with one being the worst and 10 being the best.
How are customer service and support?
I would rate the technical support of this solution a 10, on a scale from one to 10, with one being the worst and 10 being the best.
How would you rate customer service and support?
Positive
How was the initial setup?
At first, we were deployed on-premises and then about one year ago we migrated to the cloud. So I would say they did most of the work around migration. There are around 1,000 users of this solution in our company.
What was our ROI?
We have seen the ROI.
What's my experience with pricing, setup cost, and licensing?
I would rate the pricing of this solution a two, on a scale from one to 10, with one being the most expensive and 10 being the best price.
What other advice do I have?
Our model of deployment is the cloud.
I would rate this solution as a whole a 10, on a scale from one to 10, with one being the worst and 10 being the best.
I would advise other people looking into this solution to do their due diligence and make sure they do their pre-work and post-work.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Buyer's Guide
Splunk Observability Cloud
August 2026
Learn what your peers think about Splunk Observability Cloud. Get advice and tips from experienced pros sharing their opinions. Updated: August 2026.
913,924 professionals have used our research since 2012.
Senior Consultant at Tata Consultancy
Enables us to directly search for a metric and straightaway create alert charts
Pros and Cons
- "The volume it handles is very good, including the number of metrics, the volume number of traces, and more."
- "There are some predefined metrics.......we may want to create customized metrics."
What is our primary use case?
Our primary use case for SignalFx was visualization, charting, and alerting. We also used it to fix our µAPM.
How has it helped my organization?
For one project I was working on, at least 15,000 people were using SignalFx. They used to monitor their application health in the SignalFx dashboard and get alerts from SignalFx. The users had different job profiles, such as engineers and architects.
What is most valuable?
One of the valuable features is that it is very user-friendly. We can directly search for a metric and create alert charts straightaway. There are multiple visualization options to create charts that allow users to create detectors and alerts and integrate them with downstream applications for getting notifications.
Moreover, the volume it handles is very good, including the number of metrics, the volume number of traces, and more.
What needs improvement?
There are some predefined metrics where we can directly install the SignalFx agent. It gives some informative CPU utilization where some things are inbuilt. But for specific applications, we may need to create customized metrics. Here, developer teams have an additional burden of creating the whole thing if they need to customize anything. The additional feature metric could be a custom metric edition. It would make it simple for any user or engineer to go beyond the default metrics and easily choose to add more metrics. It will help share dashboards, so when we have a single version, thousands of people can use the same single version of the dashboard.
The sharing option and custom metric would be the two additional features I would like to see in the improved version.
For how long have I used the solution?
I used SignalFx for six to eight months for my previous project, and the version I used was Splunk Observability. I used it last in October 2022; I am not using it right now.
What do I think about the stability of the solution?
It is a stable product. There used to be some unplanned maintenance or intermittent issues. Most of the time, we used to get alerts or notifications from the SignalFx team. So, out of 100, I would give it a 90. It was stable, but in that 10% of the occurrence, we faced various problems like loading traces, dashboards, and more. In that project, we had a limit of detectors and a limit of a metric time series, and several subscribed metrics. So, we used to get some notifications when it reached 80% or 90% of the usage. Thus, it is completely related to the subscription. But we faced the fact that the number of MTS reached the limit.
In terms of stability, we faced intermittent issues so I won't give it a 100%; it is 90%.
What do I think about the scalability of the solution?
It is scalable. Although the scalability depends on the subscription model, there are some related requests according to cost. For example, if I want to increase the metrics by up to 30%, store more metrics, or create more alerts, I can easily do it without impacting anything. For all those things, it is scalable.
How are customer service and support?
I used to create a support case in the SignalFx portal itself, and I used to call them on their toll-free number and engage them with issues. So I had some experience with their team and I rate them an eight out of ten.
I would rate it an eight because customer support won't provide back-to-back service. If I expect updates every hour, sometimes I may not get updates every hour. For example, if I need someone to explain the issue, there might be delays. If I need to get some root cause of an issue in real-time, that might take time. So considering these factoes, I rate them an eight out of ten.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
I have used some observability tools like Splunk, Instana, and Grafana. I found SignalFx the best one for visualization, and it is user-friendly too. For example, you can directly search for a metric, and we can create alert charts immediately. So there will be multiple visualization options to create graphs. From there, we can directly create detectors, create alerts, and integrate them with other downstream applications for getting notifications.
How was the initial setup?
The initial setup was simple, and we used some package installers. We had a restrictive code for binaries in Artifactory. So we directly used some package installers and pulled it in individual service. Also, it was integrated with Puppet, so installing the SignalFx agent and starting it was simple.
What about the implementation team?
I wanted to manually install, deploy, and download it on a single server, and the whole manual procedure took around 10 to 15 minutes. When I tested a group of services with the help of Puppet, even hundreds of servers were done within an hour or something.
So I was working on a banking project, and we had a private cloud there; SignalFx agents were installed on servers, and our metrics were derived from there.
Which other solutions did I evaluate?
My company used an inbuilt application built by in-house developers, which was developed 15 years ago. Those tools were somewhat outdated and could not serve the purpose of the ever-growing volumes and other issues. So they preferred to have some third-party tool to solve their problems, and they found SignalFx useful. As a user, I also thought SignalFx was much better than other visualizations.
What other advice do I have?
I would definitely recommend SignalFx. Compared to other installation tools, creating alerts, understanding charts, and creating dashboards is more straightforward.
The functions are complex but SingalFx is very user-friendly. There is very defined documentation for everything, whether I have to create an alert or use some aggregation. We will have a direct link that says something like, "Click here to read more" or "Click here to understand." Such links are there for everything. Moreover, if I want to create an alert, there will be multiple options; it will say, "What is the time of alert?" or "What is the threshold base?" All these details will be there; you will have a link to detailed documentation. It is a very user-friendly tool for any beginner.
I would rate it as nine out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Splunk Security Consultant at a tech services company with 11-50 employees
Makes troubleshooting easier and helps consolidate all the information in one place
Pros and Cons
- "Splunk Infrastructure Monitoring provided our customers with visibility into their overall infrastructure."
- "A wide variety of logging makes log onboarding difficult."
What is our primary use case?
My customers used the solution for application performance in uptime and networking.
How has it helped my organization?
Splunk Infrastructure Monitoring has helped our customer's organization by making troubleshooting easier. The solution helped them have a centralized place where they could dig in across multiple other tools and consolidate all the information in one place.
What is most valuable?
Splunk Infrastructure Monitoring provided our customers with visibility into their overall infrastructure. They could quickly start identifying where the problems were coming from. If something was going sideways, they could more easily target the specific pathways.
One of our customers was on-premises. The other was a hybrid with on-premises and private cloud.
I was on a team helping them build a brand new tool, which was instantaneous. Another team got it a while ago, and they weren't sure what to do with it. So, we came in and helped them over a six-week engagement. We pivoted them from not feeling like they were getting all that much value to getting good value. It was more of a learning curve situation.
Splunk's unified platform has helped our customers consolidate networking, security, and IT observability tools. I was on the team of a company that was helping build a brand-new monitoring solution. They had probably a dozen separate stand-alone silo tools that could not talk to each other.
Instead of logging on to 12 different places to check each tool individually, Splunk Infrastructure Monitoring helped consolidate everything into a single location for viewing. We didn't get them to the point where they were ready to fully decommission the other systems.
They were going to decommission 12 systems on the six-month game plan. By now, they would have realized the cost savings. It would have been a multimillion-dollar savings for them.
Our customer, with 12 separate systems, was all on-premises. Part of our other customer's footprint was in AWS. It was incredibly easy for our customers to monitor multiple cloud environments using Splunk Infrastructure Monitoring. It was a combination of cloud and on-premises for our customer.
The solution provided them with a single pane of glass where they didn't have to log into multiple places and see everything in a single location. You can develop dashboards that give you cross-platform visibility, which is a huge win.
What needs improvement?
A wide variety of logging makes log onboarding difficult. Over the years, Splunk has done various things to make it easier, so I want to give them props for that. However, the reality is that every vendor has its own logging format. Some vendors have multiple log formats because they change their own products over time.
They have different log formats for different products in their own suites, and no industry standard makes it chaotic. Splunk is probably the best product out there in terms of how they handle it, but it's not perfect yet. They need to keep pushing that cutting edge and trying to improve it. I have no idea how they could do that because they're trying to wrangle chaos, and it's hard.
For how long have I used the solution?
I have been using Splunk Infrastructure Monitoring for two years.
What do I think about the stability of the solution?
I think Splunk Infrastructure Monitoring is a solid product from an infrastructure perspective. I haven't seen any bugs in the tool. Like many things with Splunk, everybody knows there will be patches when there's a core upgrade. However, that's more with Splunk Core and not specifically the Splunk Infrastructure Monitoring part.
What do I think about the scalability of the solution?
The solution's scalability is wonderful. I've worked with customers as small as 25 gigs a day, which is tiny, all the way up to close to a petabyte a day. You have to make sure you scale the tool intelligently, but it's more of a budgetary constraint than a technical one. The solution handles the big ones beautifully if you have the budget to have the needed hardware.
How are customer service and support?
Splunk's technical support has significantly improved in the last year. The support went through a rough patch about a year and a half ago. I had to coerce customers to use it because it was really bad there for a while. Splunk's support has vastly improved recently, and I hope it continues to improve.
Those people who changed the attitude, mindset, and processes need all the accolades because it's so much better than it was. Unfortunately, that does mean that it was really bad at one point.
Splunk's technical support still has some room for improvement in certain areas. Mostly, you can tell the more junior people who just read off of a script and really don't know where to go. I always introduce myself as a consultant to let the support person know that I have already done the basic introductory troubleshooting, and they can skip the first ten pages in their script.
Some frontline people in Splunks' support team are wonderful and clearly have more experience. However, it is still obvious that they occasionally bring in somebody brand new who's a little lost.
I rate the technical support seven and a half to eight out of ten.
How would you rate customer service and support?
Positive
How was the initial setup?
I've worked with Core Splunk as a consultant for seven years and was a customer for seven years before that. So I've seen it all: the good, the bad, the ugly, and everything in between. Usually, the actual building of Splunk is super easy because I've done it so many times. Every customer's environment is unique in terms of how to get the data.
It's more about navigating the local customer's politics and archaic technical debts. Somebody thought that a certain architecture was a good idea ten years ago, but today, that doesn't make any sense whatsoever. Wrangling customer chaos is hard, but the Splunk piece is usually easy.
What other advice do I have?
There's always room for improvement, but Splunk Infrastructure Monitoring is a solid product overall. It definitely helps customers who have a lot of legacy systems that don't work well together.
Overall, I rate the solution an eight out of ten.
Disclosure: My company has a business relationship with this vendor other than being a customer. Consultant
Senior Cybersecurity Engineer at a energy/utilities company with 5,001-10,000 employees
Saves time and enables our teams to look at and troubleshoot issues themselves
Pros and Cons
- "Dashboards help the application support teams to have a quick look at how their systems are running. It helps other teams as well."
- "They can get more integration with a few more products. They can also update some of the dashboards that are in there now."
What is our primary use case?
We have a lot of applications that we monitor. We have a lot of hardware that runs on VMware. We monitor all of that as well.
How has it helped my organization?
Dashboards have been helpful because people can go and look for themselves how their systems are running. The requests for us to go look at something have gone down because people can go and do it themselves.
It is important for us that Splunk Infrastructure Monitoring has end-to-end visibility. Developers and those types of teams can look at and troubleshoot any kind of issues quickly.
Splunk Infrastructure Monitoring has helped reduce our mean time to resolve, but I do not know how much. We just help as needed, but for the most part, it is just the teams going in there and looking at things themselves.
Splunk Infrastructure Monitoring has helped improve our organization’s business resilience.
Different teams can see a lot of different aspects of what is going on. They can see network traffic. They can see applications, and they can see hardware peaks and performances. They can see everything they need.
We could see the value of Splunk Infrastructure Monitoring within a couple of weeks of implementing it.
What is most valuable?
Dashboards help the application support teams to have a quick look at how their systems are running. It helps other teams as well.
What needs improvement?
They can get more integration with a few more products.
They can also update some of the dashboards that are in there now.
It is pretty good in terms of the ability to predict, identify, and solve problems in real-time, but there is always room for improvement.
For how long have I used the solution?
I am in a new role. I have been there for two months. That is as long as I have been using it.
What do I think about the stability of the solution?
It is very stable. It is good.
What do I think about the scalability of the solution?
Its scalability is great.
How are customer service and support?
It is very good. I would rate them a nine out of ten. They are usually pretty helpful and knowledgeable.
How would you rate customer service and support?
Positive
How was the initial setup?
We have it on-prem, and we also have a cloud instance. Our cloud provider is AWS. We do not monitor multiple cloud environments.
Deploying it was pretty straightforward. We just had to make sure that we were getting the logs right and setting the apps right. That was pretty much it.
What was our ROI?
We have seen an ROI in terms of manhours and less work for everyone.
What's my experience with pricing, setup cost, and licensing?
I have always used Splunk.
What other advice do I have?
I would rate Splunk Infrastructure Monitoring a ten out of ten. It is great. It is much better than a lot of other products, so it is definitely up there.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Computer Engineer at Fuse engineering
Provides good metrics, scales well, and has good support
Pros and Cons
- "I have primarily used it to go back into the past and understand why something happened. It provides enough information to do research and figure things out."
- "One thing I recently ran into was that the logs on the server most often get Gzipped after they have been rotated. We found that we were not monitoring some of the things, so we had to go back and pull them in. Right now, it pulls one at a time, untars it, or unzips it, so I cannot look at the entire history. There can be an improvement in that area."
What is our primary use case?
We are monitoring our servers and their health. We are monitoring their functionality and supporting the Kubernetes platform.
How has it helped my organization?
Our team supports multiple different projects. They all have their own clusters and ways of operating, but we just use one Splunk Infrastructure Monitoring system.
Splunk Infrastructure Monitoring has helped improve our organization’s business resilience.
What is most valuable?
I have primarily used it to go back into the past and understand why something happened. It provides enough information to do research and figure things out.
What needs improvement?
One thing I recently ran into was that the logs on the server most often get Gzipped after they have been rotated. We found that we were not monitoring some of the things, so we had to go back and pull them in. Right now, it pulls one at a time, untars it, or unzips it, so I cannot look at the entire history. There can be an improvement in that area.
For how long have I used the solution?
I have been using Splunk Infrastructure Monitoring for four years.
What do I think about the stability of the solution?
It is stable.
What do I think about the scalability of the solution?
About a year ago, we added another 600 servers and scaled up. We are getting more in the next year or later this year. It works smoothly.
How are customer service and support?
They are good. I have a ticket open now. I told them to go ahead and close it because we thought it was a hardware issue, but they said that they would keep the case open till the hardware replacement to see if the issue goes away. That was pretty nice.
Which solution did I use previously and why did I switch?
All of our hardware is HPE-based. We rely mostly on OneView, but it does not give us the service aggregation and other things that Splunk Infrastructure Monitoring is giving us.
How was the initial setup?
One of the gentlemen on other teams came to ours. He is very knowledgeable about Splunk, so he helped with the implementation.
All of our servers are RHEL-based.
Which other solutions did I evaluate?
A different organization group within our organization had Splunk, and they liked it, so we just went with Splunk.
What other advice do I have?
I would rate Splunk Infrastructure Monitoring a ten out of ten.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Performance Test Engineer at Infosys
Provides end-to-end visibility, simplifies application performance monitoring, and makes monitoring logs easy
Pros and Cons
- "The most valuable feature is dashboard creation."
- "Splunk's functionality could be improved by adding database connectors for other platforms like AWS and Azure."
What is our primary use case?
We use Splunk APM for performance testing.
How has it helped my organization?
Splunk offers end-to-end visibility across our environment.
Splunk APM simplifies application performance monitoring. It also provides insights into data quality, including data security, integration, ingestion, and versioning of trace logs. We can directly inject data for monitoring purposes, trace the data flow, and monitor metric values.
Splunk can ingest data in any format, allowing us to easily monitor logs and identify blockages through timestamps, which saves us time.
What is most valuable?
The most valuable feature is dashboard creation. This allows us to easily monitor everything by setting the data we want to see. For example, imagine we're working on a project within the application. There might be different environments, such as development, testing, and production environments. In the production environment, we can use dashboards to monitor customer activity, like account creation or other user data. This gives us a clear view of how transactions are performing and user response times. This dashboard creation feature is one of the most beneficial aspects of Splunk that I've used in a long time. While Splunk offers many features, including integration with various DevOps tools, its core strength lies in data monitoring and collection.
What needs improvement?
Splunk's functionality could be improved by adding database connectors for other platforms like AWS and Azure.
For how long have I used the solution?
I have been using Splunk APM for one year.
Which solution did I use previously and why did I switch?
We previously used a legacy application for monitoring and when it was decommissioned we adopted Splunk APM.
What's my experience with pricing, setup cost, and licensing?
Splunk offers a 14-day free trial and after that, we have to pay but the cost is reasonable.
What other advice do I have?
I would rate Splunk APM eight out of ten.
Splunk APM requires minimal maintenance and can be monitored by a team of three.
Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
Splunk and AppDynamics SME at Saudi Networkers Services
Improves operational efficiency and integrates very well
Pros and Cons
- "I find the monitoring console very helpful. With one click, I can see how we are performing, and at the same time, I can see what data is flowing."
- "The clustering part of indexes can be more refined."
What is our primary use case?
We mostly work with developers. They run some pipelines, and they use Splunk as a platform to identify the errors, instead of themselves debugging the logs and understanding what the issue is. This is one side of the business. On the other side of the business, we use the Splunk database for frozen buckets where we archive the data.
We can easily integrate it with other tools for monitoring our entire IT data infrastructure. I also handle AppDynamics. We have integrated Splunk and AppDynamics. With one click, we can understand what the actual issue is. It brings down the time to resolve. We have had some good experiences.
How has it helped my organization?
It improves our operational efficiency every day. In my previous company, we had integrated it with ServiceNow. For defined alerting conditions, it could directly open up a ticket for the right team. We did not have to look into a thousand cases to understand a problem.
In terms of integrations, most of the plugins are already available. If a plugin is not available, even then it is pretty easy to integrate. There are multiple ways to integrate. You can use the REST API and just forward the data. It can be easily integrated.
It makes it easy to have end-to-end visibility in the cloud environment. There are multiple types of devices in an environment. You might have AWS, Microsoft Azure, or something else. It operates beautifully. It is easy to integrate. This is the best part.
I am in the banking industry. It helps to keep track of how well our application is performing when somebody tries to do a transaction. There are multiple pieces to it, and we keep track of everything. We have our own business dashboard that the top-tier leaders can look into. All the visibility is there because of it.
What is most valuable?
I find the monitoring console very helpful. With one click, I can see how we are performing, and at the same time, I can see what data is flowing.
What needs improvement?
The clustering part of indexes can be more refined.
They can cut down a bit at the monetary level for the long-time customers. We recently had a scenario where we were in discussions to see if there was any flexibility from Splunk's side.
For how long have I used the solution?
I have been using this solution for the past two years. I have also used it in my previous company.
What do I think about the scalability of the solution?
It is pretty scalable. I would rate it a nine out of ten for scalability.
Which solution did I use previously and why did I switch?
I have worked with Kibana and Logstash, but they are not comparable to this solution.
What's my experience with pricing, setup cost, and licensing?
It is expensive.
What other advice do I have?
Overall, I would rate it an eight out of ten.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Cloud Solutions Architect at Core4ce, LLC
Very easy to monitor multiple cloud environments but licensing should be simplified
Pros and Cons
- "It is very easy to monitor multiple cloud environments. It's like a single pane of glass for us. We can use it to monitor our on-prem and both of our cloud environments as opposed to having different tools for each environment. It makes it all come together in one tool."
- "We still use Splunk Enterprise licensing. A lot of the newer features go into Splunk Cloud before Enterprise. We're not looking to switch our licensing over, so we're falling behind on the newer features."
How has it helped my organization?
Right now it improves the gap between our on-prem data centers and our cloud environment. We've been using Splunk on-prem for eight or nine years now and it's been useful seeing existing tools that we've used like Splunk integrate into cloud environments and bridge that gap. We use the integration the most.
It has reduced our mean time to resolve. It's been easy to aggregate logs and infrastructure data in one place, making it easier to find a single point as opposed to jumping around tools. It's ten to fifteen percent better. It makes aggregating data and logs faster for our cloud purposes.
What is most valuable?
There's a feature that allows you to connect to AWS infrastructure that we've been using. Its integration with the cloud is what we're looking forward to the most.
It is very easy to monitor multiple cloud environments. It's like a single pane of glass for us. We can use it to monitor our on-prem and both of our cloud environments as opposed to having different tools for each environment. It makes it all come together in one tool.
It's fairly important that it has end-to-end visibility into our native environment. We host a lot of other programs in our program. We host an infrastructure platform. It's good to have the integration that we can pass on to our customers to show them that there are tools they can use to better their program while we're using them to better ours. So it's been pretty beneficial.
Splunk's ability to predict, identify, and solve problems in real-time is good. I was very happy with the keynote. A lot of the use of machine learning is cool. We're excited to get our hands on that once it makes its way to Enterprise.
What needs improvement?
We still use Splunk Enterprise licensing. A lot of the newer features go into Splunk Cloud before Enterprise. We're not looking to switch our licensing over, so we're falling behind on the newer features. I know Splunk has plans to move their cloud features into Enterprise at some point. The only improvement we would like is to have more features put into Enterprise that focus on the cloud. Some people come from an on-prem environment and slowly move to cloud and would have to make a full jump into the Splunk Cloud licensing to get any of the cool Cloud features.
For how long have I used the solution?
The program that I'm on has been using Splunk Infrastructure Monitoring for around three years now. We started off mainly on-prem for data centers and we've slowly migrated into AWS and Azure for cloud footprint.
The company has been using Splunk since we were a lot smaller. We were using Splunk for data logs, aggregation, and things like that.
What do I think about the stability of the solution?
It's very stable. We've never had issues with that. Anytime we do have stability issues, it's something that we can work on to fix. It's not an inherent flaw with the product.
What do I think about the scalability of the solution?
Scalability is excellent. That's what Splunk is designed for, big data aggregation. It's been very easy and seamless to scale up over the years.
How are customer service and support?
I've only had a couple of Splunk support cases, and they've been very, very prompt in responding, especially compared to some of the other big enterprise tools we use.
How would you rate customer service and support?
Positive
What was our ROI?
We have seen ROI. It's made onboarding better and it's easier for engineers in our project because there's a single pane to view all of these different environments.
We have seen time to value. It makes it a lot easier to train new people and get them spun up. We had our cloud environment for a couple of years before we started integrating with Splunk. It was a pretty quick improvement within a couple of months, noticing how beneficial it was to have a single pane of glass in all of our different environments.
What's my experience with pricing, setup cost, and licensing?
I understand Splunk wants people to move towards Cloud licensing for a lot of the newer features, especially for multi-cloud. It would be nice to see those in Enterprise. I understand why they do it but that is my main concern.
What other advice do I have?
I would rate Splunk Infrastructure Monitoring a seven out of ten. There's more we can do with it. We just haven't explored it.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Mr at a educational organization with 1,001-5,000 employees
Enables users to forward logs to a centralized location and intuitive dashboard functionality
Pros and Cons
- "I like the fact that Splunk APM makes it easy to connect to the application database and run queries against the data."
- "I've been using the Splunk query language, and it can be a bit time-consuming to set up the queries I need."
What is our primary use case?
I use Splunk primarily from a gateway operations perspective. I work on application support. As part of that support, we regularly monitor the application dashboards built in Splunk using the logs. I covered this earlier this month.
How has it helped my organization?
The real problem we were facing was that we were unable to get all of our logs into a single place. We have an on-premise application with multiple servers across different data centers, and we needed to be able to view all of the logs together in order to troubleshoot any problems. That's why we started using Splunk to forward all of our logs to a single location.
Moreover, Splunk APM gives us end-to-end visibility across our entire on-premise environment.
Another biggest benefit I've seen is the ability to quickly identify problems using Splunk alerting. We set up alerts against our application metrics, and this has helped us to resolve major issues much sooner. We can now identify problems as soon as they occur, which gives us time to take corrective action before they impact our users.
Splunk has reduced the amount of time our operations team spends investigating problems. This has freed up our engineers to focus on other tasks, such as improving our application performance and adding new features.
What is most valuable?
I like the fact that Splunk APM makes it easy to connect to the application database and run queries against the data. I also like the fact that Splunk APM allows me to use log forwarders to forward logs to a central location, where I can then build dashboards to view the data. The dashboards are probably my favorite feature of Splunk APM.
What needs improvement?
I've been using the Splunk query language, and it can be a bit time-consuming to set up the queries I need. I've had to look at a lot of community forums to find the filters I need, and it can be difficult to get the details I need.
For how long have I used the solution?
I have experience building dashboards and other things with Splunk APM.
I've been using Splunk APM for over a year now. As part of my job in application support, I regularly create and maintain dashboards for our applications using Splunk APM. I also use dashboards to create alerts based on certain metrics.
Moreover, I'm currently working on a project to create a new dashboard for our customer support application.
What do I think about the stability of the solution?
The stability of the solution is good because I have never had outages I have seen so far. In terms of usage, it's good in terms of availability.
How are customer service and support?
I haven't had to contact the support yet. We have a separate team that maintains and builds our relationship with Splunk, so they would be the ones to contact if we had any issues.
What about the implementation team?
The solution doesn't require any maintenance.
Which other solutions did I evaluate?
We used New Relic and AppDynamics before Splunk. AppDynamics was our APM tool, and I'm still using New Relic for monitoring Splunk. New Relic is great for log monitoring, and it's our main tool for internal application monitoring.
What other advice do I have?
With Splunk APM as an enterprise solution, various factors come into play. Right now, considerations include pricing and how they envision the solution to work for them. Some might want the solution to be cloud-based. It largely depends on the volumes they anticipate. Organizations must decide how much they're willing to invest, especially when comparing it to other investments they've made. With the current economic recession and organizations looking to cut costs, it's crucial to evaluate the volumes and aspects of Splunk that are most relevant to them.
Overall, I would rate the solution an eight out of ten.
Which deployment model are you using for this solution?
On-premises
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
Last updated: Jul 1, 2026
Flag as inappropriateBuyer's Guide
Download our free Splunk Observability Cloud Report and get advice and tips from experienced pros
sharing their opinions.
Updated: August 2026
Product Categories
Application Performance Monitoring (APM) and Observability Network Monitoring Software IT Infrastructure Monitoring Cloud Monitoring Software Container Management Digital Experience Monitoring (DEM)Popular Comparisons
Microsoft Defender for Cloud
Splunk AppDynamics
SolarWinds NPM
PRTG Network Monitor
Red Hat OpenShift
LogicMonitor
WhatsUp Gold
Buyer's Guide
Download our free Splunk Observability Cloud Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- When evaluating Application Performance Management, what aspect do you think is the most important to look for?
- APM tools for a Managed Service Provider - Dynatrace vs. AppDynamics vs. Aternity vs. Ruxit
- What solution would you recommend for monitoring traffic utilization of leased lines?
- How Much Should I Budget for an APM Solution?
- Which is the best AANPM product? Should we be considering anything besides for Riverbed?
- Who Uses APM?
- What is your favorite tool for Application Performance Monitoring?
- How does synthetic monitoring differ from real user monitoring?
- Differences between SiteScope and dynaTrace?
- Splunk as an Enterprise Class monitoring solution -- thoughts?



















