
Splunk Cloud
Cloud monitoring has improved alerting and dashboards for production applications
What is our primary use case?
Currently, we are using dashboarding and alerting as our main use cases for Splunk Cloud Platform. We also have scheduled reports that run on a daily basis to feed data into those dashboards. We are actively using alerts to notify in Splunk Cloud Platform are monitoring, alerting, and all the notifications for the applications that we are hosting in production.
What is most valuable?
What I appreciate most about Splunk Cloud Platform is the ability to click and create dashboards and alerts very quickly without spending too much time writing SPL queries and getting results. Additionally, the platform is much faster than Splunk Enterprise, allowing us to see things churn quickly.
Splunk Cloud Platform's ability to scale aligns very well with our demand fluctuations, which is why we migrated to it. Splunk Enterprise was not scaling as our demand for Splunk usage grew, and we started experiencing issues with Splunk Enterprise. We migrated to Splunk Cloud Platform to support the additional usage from multiple users, and we are now expecting it to scale and help all the other additional users benefit from Splunk Cloud Platform.
What needs improvement?
I cannot provide detailed feedback on areas for improvement at this time because we have just migrated to Splunk Cloud Platform.
For how long have I used the solution?
I have been using Splunk Enterprise for almost seven years, and for Splunk Cloud Platform, we have recently migrated approximately one month ago.
How are customer service and support?
On a scale of one to ten, I would rate the customer service experience at seven because we have been receiving answers directly from a Splunk POC who has been on-premises helping us out. However, we have experienced delays in getting answers to some of the issues that we faced during migrations, and that has taken some time to get resolutions to, which is why I am rating it at seven.
What other advice do I have?
Something interesting that happened at the conference before we started is that I went into a session not knowing what to expect, and I went into a completely wrong session. When I checked my schedule, I realized this was not where I was supposed to be.
The session was about edge processor, and I did not know how to configure Splunk edge processor. It was a completely different session than what I had planned.
Since I joined this organization, Splunk has been a very important tool for collecting logins and events. We have been using Splunk Enterprise for a very long time, and very recently, we migrated from Splunk Enterprise to Splunk Cloud Platform. My role has been as an end user of Splunk to see how all the migrations have been completed and everything has been done successfully. In my current role, I am responsible for creating alerts and dashboards in Splunk Cloud Platform to assist the production environment and all the monitoring in the production environment.
We have not seen benefits right away because we have just started to migrate to Splunk Cloud Platform. We have been using Splunk Enterprise for a very long time. Splunk Enterprise has had its benefits, and now we want to migrate to cloud to see how that can help us.
My experiences with deploying Splunk Cloud Platform are that it is relatively new for us, but I can speak about Splunk Enterprise. Splunk Enterprise has really benefited us. We have been able to do a lot of analysis by using Splunk, and we have gained a lot of insight into our applications by using it. I would rate this review at nine overall.
Which deployment model are you using for this solution?
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Cloud dashboards and alerts have transformed how our team monitors production in real time
What is our primary use case?
Currently, our main use cases for Splunk Cloud Platform involve using dashboarding and alerting most of the time.
We also have scheduled reports that run daily to feed data into those dashboards, and we are actively using alerts to notify in the Webex channels about any issues that have occurred in production on a real-time basis.
What is most valuable?
I appreciate the fact that you can quickly click and create dashboards and alerts without having to spend too much time writing SPL queries to get your results.
Additionally, the fact that it is so much faster than Splunk Enterprise allows us to see things churn quickly.
Since the time I joined this organization, Splunk has been a very important tool for collecting the logins and the events. My organization has been using Splunk Enterprise for a very long time, and very recently, we migrated from Splunk Enterprise to Splunk Cloud Platform. My role has been as an end user of Splunk to see how all the migrations have completed successfully. Now in my current role, I am responsible for creating alerts and dashboards in Splunk Cloud Platform to assist with all the monitoring in the production environment.
What needs improvement?
I cannot say what improvements can be made right now because we have just migrated to Splunk Cloud Platform. I wish I could say more.
For how long have I used the solution?
I have been using Splunk Enterprise for almost seven years. With Splunk Cloud Platform, we have recently migrated, and it has been just over a month.
What do I think about the stability of the solution?
We have not seen benefits right away because we have just started to migrate to Splunk Cloud Platform.
We have been using Splunk Enterprise for a very long time, which has had its benefits, and now we want to migrate to the cloud to see how that can help us.
What do I think about the scalability of the solution?
Splunk Cloud Platform's ability to scale is a very important feature because it aligns with our demand fluctuations, which is why we migrated to Splunk Cloud Platform.
Splunk Enterprise was not scaling as the demand for Splunk usage grew, leading us to face issues that encouraged our migration to Splunk Cloud Platform to support the additional usage from multiple users.
We now expect it to scale and help all additional users benefit from Splunk Cloud Platform.
How are customer service and support?
I rate the customer service technical support for Splunk Cloud Platform at seven, primarily because we have been getting answers from a Splunk POC who has been on-premises helping us out.
However, we have had some delays in getting answers to certain issues we faced during migrations, which has taken some time and resulted in some churn to get resolutions.
What other advice do I have?
Our team has primarily been using AWS services, and the entire team has been using it for all of the seven years we have been here.
Currently, our workloads vary from a very low client headcount early in the day to peak times during the evening hours when people are using more of the network.
Our top priority for using AWS Cloud includes having a lot of different advantages, one of the primary ones being the serverless concept. Instead of having fixed VMs where everything is being hosted, we are now hosted on the cloud, which alleviates worries about scaling our performance at scale. There are many different advantages for which we migrated from on-premises to cloud, including avoiding issues with failovers, which has been facilitated by using AWS.
For cloud migrations, you have to really be aware of what you need to migrate. You need to prioritize everything that you need to work with and also take into account everything that is being done step by step to ensure a smooth transition from your current on-premises resources to the cloud.
You need to start with prioritizing what you really need to migrate, beginning with a prioritizing list. From that point on, you take small steps to migrate whatever is important, followed by migrating the less critical jobs or aspects. Once the migration is done, you verify everything to ensure that your business-critical aspects are taken care of, and you are not missing anything.
My experiences with deploying Splunk Cloud Platform are relatively new, but I can discuss Splunk Enterprise, which has really benefited us significantly. We have been able to do a lot of analysis using Splunk, and we have gained a lot of insight into our applications through it.
Something interesting that happened at the conference before we started is that I went into a session not knowing what to expect, and I went into a completely wrong session that was about edge processor, which is not what I intended to attend.
When I checked my schedule, I realized this is not where I was supposed to be, and I did not even know how to configure Splunk edge processor, so it was a completely different session than what I planned.
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Monitoring has improved business insights while search guardrails still need refinement
What is our primary use case?
Splunk Cloud Platform serves as our primary observability solution, focusing on monitoring logs, metrics, and traces for our systems.
We primarily use Splunk Cloud Platform for log monitoring by setting up feature dashboards in my day-to-day work.
Dashboards are used to monitor business API and business-related metrics from logs, which enhances our workflow.
What is most valuable?
Splunk Cloud Platform offers exceptional features including quick upgrades, as Splunk Cloud receives the first upgrade for any GA release with rapid support.
Their team manages indexers and search head upgrades, allowing us to focus on bringing data and creating metrics from it and monitoring that output.
Splunk is very helpful in troubleshooting with its SPL, and the AI assistant significantly helps in troubleshooting issues.
Splunk MCP allows quick turnaround with integration into platforms.
The platform's ability to validate application logs, correlate microservices using trace IDs, and enhance security with threat detection greatly impacts our organization.
What needs improvement?
More guardrails can be implemented, and workload management can be improved in Splunk Cloud Platform.
Ad hoc searches are still being executed with index equal to star, which reveals opportunities for improvement, and there must be a way to enforce this.
Splunk should enforce predicates for users, requiring index equal to an index name instead of allowing index equal to star. This will improve compute utilization and help maintain stability in Splunk Cloud Platform.
For how long have I used the solution?
I have been working in my current field for the last six years.
We have been using Splunk Cloud Platform for the last six years.
What do I think about the stability of the solution?
Splunk Cloud Platform is stable.
What do I think about the scalability of the solution?
Scalability is good, as we work with our TAM to ensure our environment is right-sized, preventing any issues or load impacts.
How are customer service and support?
Customer support is very good, and we have a dedicated TAM as well as a dedicated engineer to assist us.
Which solution did I use previously and why did I switch?
We did not use any other solution previously. We were using Splunk Enterprise before migrating to Splunk Cloud Platform, so we have always been Splunk customers.
What was our ROI?
We are utilizing federated search with S3 in our organization, redirecting 20 terabytes of low-value logs into S3.
Using federated search heavily allows us to save significantly on costs, which is a very important metric for us.
What's my experience with pricing, setup cost, and licensing?
My experience with pricing, setup costs, and licensing has been very good, as we did not face any issues.
We're receiving all the needed support from the start.
What other advice do I have?
Teams should evaluate their business use case and compare whether that use case can be effectively implemented with Splunk Cloud Platform.
It's important to determine the retention period for logs and to identify high-value logs versus low-value logs; high-value logs can go directly into Splunk Cloud Platform while low-value logs can be redirected to S3, utilizing federated search with S3 for low-value log management.
I would rate this solution a 7 overall.
Which deployment model are you using for this solution?
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Cloud monitoring has transformed our security insights and reduces incidents across applications
What is our primary use case?
My main use case for Splunk Cloud Platform is general Splunk usage. Instead of on-prem, we are using cloud.
A quick specific example of how I'm using Splunk Cloud Platform is application monitoring, security monitoring, and enterprise security. Specifically for security monitoring, I'm looking for application-related logging, trying to understand how the applications are progressing, and monitoring the status of the servers and other infrastructure.
What is most valuable?
The best features Splunk Cloud Platform offers include ease of use, good integration, and easy scalability.
Regarding how the integration works and how the scalability has helped my team, when SVC usage is high or if there is lots of data coming in, the scalability is helping us with indexer clustering.
Splunk Cloud Platform has positively impacted my organization by reducing a lot of time, reducing a lot of incidents, and helping in mitigating issues without major downtimes.
Regarding time saved, we have caught many anomalies and issues related to applications or security data coming in through the data, which gave us proactive monitoring as well related to those.
What needs improvement?
I think Splunk Cloud Platform can be improved with some improvements on the ingestion pipelines related to edge processors, including all protocols, not only the HEC or other features. Improvements on the HEC side of things would be beneficial.
For how long have I used the solution?
I have been using Splunk Cloud Platform for almost 10 plus years.
What do I think about the stability of the solution?
Regarding Splunk Cloud Platform's stability, I would say it is kind of stable, though not completely.
What do I think about the scalability of the solution?
Splunk Cloud Platform's scalability is pretty much easy. It is auto-scaling, so we are not even bothering much about it.
How are customer service and support?
I find the customer support to be good enough.
Which solution did I use previously and why did I switch?
We previously used an on-prem solution.
What was our ROI?
I have not seen a return on investment yet; it is just the starting for us and it is completely a non-matured setup as of now on our side.
What's my experience with pricing, setup cost, and licensing?
My experience with pricing, setup cost, and licensing is pretty much seamless.
Which other solutions did I evaluate?
Before choosing Splunk Cloud Platform, we evaluated our on-prem solution.
What other advice do I have?
My advice to others looking into using Splunk Cloud Platform is to review your data. Do not bring all data; just bring in only what you need. I would rate this product an 8.
Which deployment model are you using for this solution?
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Cloud logging has transformed availability and now supports fast alerts and responsive dashboards
What is our primary use case?
My main use case for Splunk Cloud Platform includes observability, log management, alerting, dashboarding, and serving as a centralized logging platform.
We have multiple customers in the company that forward their logs to Splunk Cloud Platform, and I help them onboard their applications, as well as creating their dashboards and alerts on Splunk Cloud Platform. I also use the Model Context Protocol, the Splunk MCP server, so that they can use the Agentic AI, as well as their Q and Cloud CLIs to query the platform using MCP.
What is most valuable?
The best features Splunk Cloud Platform offers include accessibility, uptime, redundancy, availability, and ease of use.
I find myself relying on availability the most day-to-day, as well as the features that are available such as MCP.
Splunk Cloud Platform has positively impacted my organization because earlier we were an on-premise enterprise having issues with availability and management. The cloud platform has made availability much better, and customers love the experience as it is very quick and responsive.
Uptime has significantly improved since moving to Splunk Cloud Platform, as well as the support that we get from our support peers at Splunk and Cisco, which is very helpful. The availability of the platform in general has improved, and queries run faster.
What needs improvement?
Splunk Cloud Platform can be improved by providing dedicated documentation, especially regarding the edge processors and MCP, along with continuous updates. Sometimes the model we face gets updated without notifying us, so we need proactive notifications if something is being changed on the back end to notify customers before they see issues.
For how long have I used the solution?
I have been using Splunk Cloud Platform for six months.
What do I think about the stability of the solution?
Splunk Cloud Platform is stable most of the time.
What do I think about the scalability of the solution?
Splunk Cloud Platform is highly scalable.
How are customer service and support?
The customer support is rated eight out of ten.
Which solution did I use previously and why did I switch?
Earlier, we were using a fully on-premise solution, and therefore we had all our servers, search heads, and indexers managed by us. Now we have moved to the cloud.
How was the initial setup?
We did not purchase Splunk Cloud Platform through the AWS marketplace because we already had a license with Splunk Cloud Platform running the enterprise license, and we just migrated it to the cloud.
What was our ROI?
I cannot share metrics, but we have seen a return on investment.
Which other solutions did I evaluate?
I did not evaluate other options before choosing Splunk Cloud Platform.
What other advice do I have?
I would rate Splunk Cloud Platform a 10 out of 10.
I chose this rating because the issues we were seeing previously with the on-premise platform are now much better handled, and we do not see them anymore. We do see some new issues occur, but we are learning as we go.
Regarding Splunk Cloud Platform's AI capabilities, I have not used its governance and security features, but I have appreciated the ability to secure data.
The accuracy of Splunk Cloud Platform's output is very good, and the reliability is always also very good.
My impressions of Splunk Cloud Platform's visibility into multiple environments are that we are completely on cloud. Earlier, we were on-premise, and while I have not used Splunk Cloud Platform in a hybrid environment or an on-premise environment, we truly love the cloud environment as it enhances the availability and speed of the platform, and the support provided is very useful.
Regarding Splunk Cloud Platform's zero setup feature for AI models, it works in the best way possible because it is very quick.
My experience with Splunk Cloud Platform's app ecosystem is that it is very easy to manage updates within this ecosystem.
The platform's ability to scale aligns very well with my organization's demand fluctuations, and this has a positive impact on our IT resources as it is very scalable, allowing us to deploy apps very quickly. As the organization demand grows, we can make that happen very quickly too, so the turnaround for customers is very quick.
I use a hybrid of native models over third-party integrations in Splunk Cloud Platform's environment, as some third-party integrations are much more resilient and much more developed than Splunk Cloud Platform's native integrations.
I would highly advise Splunk Cloud Platform to all other users or customers. I recommend they ensure that their support with Splunk and Cisco folks has been confirmed and documented appropriately. Documentation needs to be improved, but the platform overall is very stable and very useful. My overall rating for Splunk Cloud Platform is 10 out of 10.
Which deployment model are you using for this solution?
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Cloud monitoring has improved visibility and simplifies secure access and cost optimization
What is our primary use case?
We use Splunk Cloud Platform for three main purposes: Core, Enterprise Security, and ITSI. These are the three key platforms we utilize for Splunk Cloud Platform.
Splunk Cloud Platform is easy to manage and has a lot of automation in place where my end users can access and provide data detections, anomaly detections, and use it for certain use cases where they can create notables or use Enterprise Security. There are many features that they have seen which are more advanced when compared to the enterprise platform we had previously.
Many users are trying to build custom queries with their limited knowledge of Splunk Searching SPL2, so they use our Cloud AI feature where they can create searches, optimize the queries, and perform valuable visualizations from it.
What is most valuable?
The best features Splunk Cloud Platform offers include easily manageable instances where there is no need to manage dedicated infrastructure in our data centers, providing a lot of value to end users who can access and provide visibility from any place. Additionally, whenever a new user comes into the organization, it is very easy to handle their access-related issues using SAML, and the authentication process is very straightforward without the hurdles we had on-premises. It also features easily understandable code that they can build.
Previously, during our enterprise phase, we used LDAP as the authentication IAM feature. Now we have started using SAML based on the Azure Cloud platform, which allows us to easily authenticate or grant access to any user without time-consuming approvals. The easiest task in cloud is directly through SAML, where we can grant access to any end user whenever they need access to Splunk Cloud Platform.
In Splunk Cloud Platform, we do get all the relevant information either through XML code that we can deploy to set up any SAML authentication or SAML configurations. That is all process-related, but I have not seen any other good examples apart from providing access to the end users.
The main positive impact of Splunk Cloud Platform on my organization is in terms of cost and infrastructure. These are the two main things that changed our company's Splunk usage, allowing us to provide all integrations and analysis directly from the cloud instead of depending on multiple environments.
What needs improvement?
Improving Splunk Cloud Platform could be achieved by adding more advanced features such as using AI or observability to build custom props and generating basic templates based on the data, which would help end users who are not familiar with Splunk SPL2 or SPL3. Splunk should provide basic templates to enable end users to build their dashboards based on the data that is already ingested. I refer to this as automating the knowledge objects necessary for users.
The main change I have personally experienced is the need for low-level expertise in Splunk among new users who come and go daily. Since I cannot sit and train each individual, having basic templates and analysis based on data would help our end users effectively build the visualizations they need.
Regarding Splunk Cloud Platform's zero-setup feature for AI models, we still are not utilizing it fully within our organization, so I cannot answer that question.
When I add any data to Splunk for monitoring, it should automatically detect the data and recommend which data models I need to use. It would be greatly appreciated if Splunk could facilitate this feature.
For how long have I used the solution?
I have been using Splunk Cloud Platform since 2022.
What do I think about the stability of the solution?
Splunk Cloud Platform is not entirely stable. In the last couple of months, we have experienced issues with instances approaching max resources without alerts, and there have been problems on the AWS side as well, where instances have gone down.
What do I think about the scalability of the solution?
The scalability of Splunk Cloud Platform is good, although our organization is not currently scaled automatically. It is one of the positive features of Splunk Cloud Platform, as it adapts to increased resource consumption from add-ons whenever we request scaling for the necessary environment.
Assessing the platform's ability to scale in alignment with our organization's demand fluctuations can be challenging, and I do not have a clear answer at this moment.
How are customer service and support?
Customer support is great; I would say it is effective as they respond in a timely manner and acknowledge cases properly.
Which solution did I use previously and why did I switch?
While in the enterprise, we used a perpetual license with limited capacity, such as 15 terabytes, which caused us to encounter many issues when over the limit. With the cloud solution, we gain the flexibility to request increases in resources handled by Splunk Cloud Platform, which greatly benefits us compared to perpetual licensing.
What was our ROI?
I have seen a significant return on investment by identifying unnecessary applications still ingesting data, which were not in use but kept servers running. We have observed between five to seven percent of the overall enterprise-wide applications that were flagged for frequent analysis and necessary cleanup, which saved my SVCs and licenses, ultimately translating to significant cost savings for my organization.
Which other solutions did I evaluate?
Before choosing Splunk Cloud Platform, we evaluated other options such as Kibana, which is another visualization tool, SolarWinds for server metrics monitoring, and Dynatrace for similar service-related information. We currently use both Dynatrace and Splunk Cloud Platform, but our main use cases are centered around Splunk Cloud Platform for enterprise security and ITSI.
What other advice do I have?
In on-premises, I have everything under my control regarding analysis, configuration, setup, and installations. However, in the cloud, it is useful as many things get automated and managed by Splunk Cloud Platform. Sometimes, I do not feel confident that the configurations I made are getting reflected in the cloud because I cannot instantly check the metrics, such as pre-deployment and post-deployment resource usage. I have noticed that Splunk Cloud Platform Monitoring Console is still not equipped with the instance resource usage dashboard, which we manage manually. I would appreciate if we can add a Monitoring Console dashboard for monitoring the resources of instances in our SaaS platform.
When compared to on-premises, I feel much more comfortable managing app upgrades or app installations in Splunk Cloud Platform. There are three different platforms: one for Core, one for ITSI, and one for Enterprise Security. I have full control over app upgrades or installations in Core instances, which automatically deploy to indexers. However, for Enterprise Security and ITSI, I need to open a support case, making it less easy for me to manage everything myself on the premium app instances.
I prefer using third-party integrations such as Cribl and BindPlane over native models in Splunk Cloud Platform environment. These third-party solutions offer better comfort for data parsing and routing to multiple destinations, which I have not found as effective in Splunk Cloud Platform.
The subscription model impacts our financial planning for data platform investments as we base costs on SVCs, which are sufficient for our ingestion needs. However, I do not have much financial planning to discuss on the governance aspect.
I would rate this review an 8 overall.
Which deployment model are you using for this solution?
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Platform has streamlined fraud investigations and has improved data operations efficiency
What is our primary use case?
My main use case for Splunk Cloud Platform is data operations. We ingest all of our feeds into the platform and normalize the data for Enterprise Security and notable use as a specific example of how I use Splunk Cloud Platform for data operations. I think it's a unique case because we are doing retail fraud instead of the normal security authentication and governance.
What is most valuable?
The best features Splunk Cloud Platform offers include GUI access for a lot of operational commands. For example, we're able to restart our search heads, create indexes, and HEC tokens on the front end. Having GUI access for those operational commands helps my team day-to-day as it saves time and reduces errors.
Splunk Cloud Platform has positively impacted my organization by offering a one-stop shop to get a lot of things done. In one place now, we're able to triage incidents much faster within the platform and create our apps to upload easily, which has had a significant impact on my workflow and team.
What needs improvement?
I think Splunk Cloud Platform could be improved by having a little more access to the backend for admins.
For how long have I used the solution?
I have been using Splunk Cloud Platform for three and a half years.
What do I think about the stability of the solution?
Splunk Cloud Platform is stable.
What do I think about the scalability of the solution?
The scalability of Splunk Cloud Platform is pretty easy and pretty good as we have a lot of data. The platform's ability to scale aligns pretty well with my organization's demand fluctuations, and we haven't had major issues regarding scalability.
How are customer service and support?
The customer support for Splunk Cloud Platform is helpful. My experience with Splunk Cloud Platform's app ecosystem is that it's pretty easy to manage updates within this ecosystem. If we are having issues, our Splunk support is pretty quick to hop on a call or get an email to help us when we create a ticket.
Which solution did I use previously and why did I switch?
I did not previously use a different solution; I've only used Splunk.
What was our ROI?
I have seen a return on investment as we have had money saved with investigations and we are able to keep the team to a minimum with the support of the platform.
Which other solutions did I evaluate?
Before choosing Splunk Cloud Platform, I did not evaluate other options as I was not a part of that decision, but previously, I did on-prem.
What other advice do I have?
My advice for others looking into using Splunk Cloud Platform is to create and document protocols for your data before launching. The subscription model impacts my financial planning for data platform investments by working pretty well, and we're currently working on reducing our licensing by working on our feeds before they're indexed. I rate this product an 8.
Proactive monitoring has reduced downtime and now improves performance across our environments
What is our primary use case?
My main use case for Splunk Cloud Platform is performance monitoring. For performance monitoring, I get the data in from our workloads into the platform and then write searches in order to set up alerts on certain thresholds for that data. That is the main way I use Splunk Cloud Platform.
What is most valuable?
In my opinion, the best features Splunk Cloud Platform offers are the flexibility to complete virtually any use case. That flexibility has made a difference for my team by allowing us to help other IT teams with increasing efficiency. Splunk Cloud Platform has positively impacted my organization by allowing us to be more proactive with our monitoring. Being more proactive has changed things for my team by allowing us to decrease downtime of business applications.
What needs improvement?
Splunk Cloud Platform could be improved by integrating AI agents into the platform since they should be a native feature, similar to how they are a feature in observability.
For how long have I used the solution?
I have been using Splunk Cloud Platform for over five years.
What do I think about the stability of the solution?
Splunk Cloud Platform is stable.
What do I think about the scalability of the solution?
Splunk Cloud Platform's scalability is pretty good.
How are customer service and support?
Customer support for Splunk Cloud Platform can be improved.
Which solution did I use previously and why did I switch?
We previously used a different platform before Splunk Cloud Platform, but I do not want to say the name, and the reason for the switch was more flexibility.
What was our ROI?
I have seen a return on investment with Splunk Cloud Platform, and there is definitely efficiency that was created with time saved, though I do not have a hard number for you.
What other advice do I have?
Overall, Splunk Cloud Platform is very good, but there are some areas of improvement that are still needed, which is why I would rate it an eight out of ten.
Regarding Splunk Cloud Platform's AI capabilities, I do not think I have any issues with its governance and security. However, I think its accuracy and reliability of output are not very good right now. I think AI features need a lot of help in Splunk Cloud Platform.
My experience with Splunk Cloud Platform's app ecosystem is that it is not too difficult to manage updates, but the biggest pain point is with vendors making apps compatible with new versions of Splunk Cloud Platform.
Splunk Cloud Platform does a good job of letting me see what is happening across all my different environments such as my cloud systems, my on-premises systems, and my hybrid setups. The platform's ability to scale aligns well with my organization's demand fluctuations, and it does a good job.
My advice to others looking into using Splunk Cloud Platform is to learn the platform first.
Centralized logging has improved enterprise visibility and strengthened security monitoring
What is our primary use case?
Splunk Cloud Platform is used for enterprise logging, including infrastructure logs, application logs, and networking logs. It serves the entire enterprise with substantial ingestion coming in from different sources onto the platform.
Splunk Cloud Platform offers logging and Autologs specializations. Cloud logging is embedded as a birthright within Splunk Cloud Platform, so anything which is onboarded as a new asset, whether a device, an application, or a server, is getting enabled through Splunk Cloud.
Splunk Cloud Platform is deployed in the organization on public cloud. AWS is used as the cloud provider. Splunk Cloud Platform was purchased directly through a vendor.
The organization has everything within all the environments including cloud, on-premises, and a mix of other tools as well.
What is most valuable?
Splunk Cloud Platform offers logging and Autologs specializations. Cloud logging is embedded as a birthright within Splunk Cloud Platform, so anything which is onboarded as a new asset, whether a device, an application, or a server, is getting enabled through Splunk Cloud.
It has impacted positively because the entire enterprise logging is enabled within Splunk Cloud Platform, whether from servers, applications, network devices, and logs coming from other application tools or platforms.
Improved security has been achieved because a lot of security logs are ingested to Splunk Cloud Platform, where they are being used to identify security vulnerabilities and checkpoints. Splunk Cloud Platform does provide a lot of governance and security because many enterprise security teams are involved in using it.
What needs improvement?
Provisioning MCT access for all the application users and ensuring open telemetry is embedded with the AI-assisted capabilities in Splunk Cloud Platform will go a long way. The AI assistant for Splunk Cloud has just been started and looks promising, but more exploration is needed.
Splunk Cloud Platform has the ability to transform as the organization scales, but better visualization is needed to see how the data is being ingested, the volume that is being traversed, and the data management overall for the indexes.
The integrations need to be more proactive within Splunk Cloud Platform so that the organization can get into the data strategy and employ the broader teams.
For how long have I used the solution?
Splunk Cloud Platform has been used for a couple of years.
What do I think about the stability of the solution?
Splunk Cloud Platform is stable because the organization is on the SaaS.
What do I think about the scalability of the solution?
Splunk Cloud Platform is very much scalable.
How are customer service and support?
The customer support is quite good, and the right level of engagement has been achieved.
Which solution did I use previously and why did I switch?
Splunk Cloud Platform is the only solution being used for the logs.
How was the initial setup?
The setup is easier because all the logs can be poured in one place and the queries can be indexed to get through with all those positions.
What was our ROI?
Time is saved because index queries can be provided to the application team, helping them see the logs during any troubleshooting.
What's my experience with pricing, setup cost, and licensing?
Pricing for Splunk Cloud Platform is on the higher side, but the setup is very much acceptable, and it is good that observability cloud will be available in a few months.
Which other solutions did I evaluate?
No other options were evaluated before choosing Splunk Cloud Platform.
What other advice do I have?
There is no major impact on financial planning for data platform investments, as there is a three-year deal with Splunk, so the organization should be good. The review rating for Splunk Cloud Platform is eight out of ten.
Which deployment model are you using for this solution?
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Cyber team has improved threat response and now conducts faster investigations with flexible storage
What is our primary use case?
Splunk Cloud Platform is used for our cybersecurity use cases.
We have alerting set up that is used in tandem with our SOAR platform, which is Tines, to pull the alerts and send them over to SOC. Security-related logs such as Windows, Okta logs, cloud-based AWS, and Google Cloud are all being sent to Splunk Cloud Platform in order to allow for cybersecurity incident investigation, alerting, and threat hunting.
Because we are a cybersecurity team, we rely on logs sent from our business units. We operate our Cyber Splunk on a model that allows access from business units. Each business unit has their own set of indexes. We control access this way so that it is self-serve for businesses while cyber still retains control and overview of all content that goes into our Cyber Splunk.
What is most valuable?
The best features are the ease of use because platform maintenance is abstracted from us. We do not have to worry about that aspect. I also appreciate Splunk Cloud Platform licensing model, which allowed us to not worry about our daily ingest so much as basically tweak retention based on our current needs, which is very flexible. I also value the storage model of Splunk Cloud Platform where we could split our logs between active storage and archive storage and restore from archive as needed for investigations or audit purposes.
One of the logs that we are sending to Cyber Splunk is CrowdStrike, but they are very large. It is very noisy and chatty. So, we only keep around 35 days of logs in active storage. That satisfies our current alerting needs and day-to-day investigations and threat hunting. However, there are sometimes incidents that require us to look further back. In those cases, we can restore back up to 90 days going back. That was a very easy process and very straightforward.
It has simplified our cyber operations. It has helped us respond to threats and investigations much quicker than with our previous SIEM. It is honestly less headache for me as an admin and it is much easier because a lot of people in the industry in cyber know Splunk already. So there is no entry barrier. It is much easier to start using Splunk Cloud Platform right away. There is a wealth of information available, including training materials and documentation on the web. So for us, it has just made everything easier.
What needs improvement?
Building stronger capability to use federated searches to make this process easier would be beneficial. I also think that the current iteration of Splunk Cloud Platform's AI assistant is not great. I did not have much success using it. So, I think that should be improved upon.
The AI assistant that we are using right now does not seem to be very accurate. Although, this may simply be because it needs more time to learn about our data. I am not certain, but we had mixed results with that.
For how long have I used the solution?
We have been using Splunk Cloud Platform for about three years.
What do I think about the stability of the solution?
We have experienced stability issues.
What do I think about the scalability of the solution?
I do not think that it has any negative impact. We have not experienced any scalability issues. Scaling was seamless. We do not really notice it at our scale. Our Splunk Cloud Platform footprint is relatively small. So we simply did not experience any impact at all.
To us, it is easy. It scales with our needs. It is easy to request additional licensing. So I do not have any complaints about it. It is an all-positive experience.
How are customer service and support?
Customer support is very good.
Which solution did I use previously and why did I switch?
We used Devo before that.
Devo did not provide the same level of availability and resilience as Splunk Cloud Platform. It was not as polished and well-developed a product as Splunk Cloud Platform. So it did not have the same capabilities.
How was the initial setup?
Splunk Cloud Platform is a public cloud deployment.
What about the implementation team?
We purchased through our vendor.
What was our ROI?
I do not have any metrics from different departments handling that. I can say that we definitely have fewer resources needed to manage the platform. We definitely have fewer support tickets open than with our previous SIEM platform. Overall, our spend is about the same for much better capabilities. That is really what I can say about it.
What's my experience with pricing, setup cost, and licensing?
It was a very good experience. Pricing is relatively clear and easy to understand. That is something that worked well for us.
Which other solutions did I evaluate?
We did not evaluate alternate solutions.
What other advice do I have?
It is quite easy to manage apps. Because there are so many apps, it is sometimes difficult because Splunk apps are generally the most well-behaved apps, but there are also third-party and vendor apps that sometimes do not follow best practices. So managing them may be sometimes challenging, but overall, I would say it is a very easy and good process.
I think that the advice is to use Splunk Cloud Platform because it is a great platform and it is much easier to maintain than on-premises Splunk, or it is really the best product out there. I cannot really say much else; it is way ahead of the competition. I would rate this platform a 10 out of 10.