Splunk Enterprise
Centralized log analytics has improved alerting and speeds up finding issues across servers
What is our primary use case?
The main use case for Splunk Enterprise Platform is collecting logs from across the enterprise and ingesting them so that we can use them to easily search and also for alerting if there are problems with all the different applications and pieces of software that we have installed here.
A simple example of how I use Splunk Enterprise Platform for alerting or searching is if we have a Linux server that is running out of memory. We have the Linux logs in Splunk and then we have an alert set up that if the memory gets below a certain threshold, then it creates a ticket for our team to address it. If the memory gets so low that it is a critical issue, then we get paged that it is an urgent issue we need to take care of.
What is most valuable?
Splunk Enterprise Platform is very user-friendly, and our users love the ability to use the search interface, which helps determine issues when you know something is happening, but you do not know where it is happening in all of our various items that exist, all the systems that produce logging data.
For our use case, the absolute best feature of Splunk Enterprise Platform is that you can get data into Splunk Enterprise Platform from anywhere, and that is really useful because there are just so many different sources.
We are primarily using Universal Forwarders, but we also use HEC forwarders and heavy forwarders to integrate different data sources.
Our users definitely love the ability to create their own dashboards in Splunk Enterprise Platform so that they can monitor the applications that they are involved in, making that a popular feature.
Splunk Enterprise Platform has made it a lot faster to find problems. This is very much Splunk Enterprise Platform's core functionality where instead of having to go and SSH into different servers and look at log files on each one, which can take a lot of time, you are able to search via the GUI and pull up logs across all of the applications being monitored.
What needs improvement?
I think making the user interface easier to navigate for users is important for improving Splunk Enterprise Platform. It may be that SPL2 takes care of some of this. I have not used that yet, but I know using just SPL, it takes quite a training for users to learn how to search Splunk Enterprise Platform most effectively.
I come from using Atlassian products a lot, and I found their documentation to be a lot easier to use, so I think Splunk Enterprise Platform could benefit from a lot more documentation out there. When I Google for an issue in Splunk Enterprise Platform, it is maybe 50-50 on whether I will pull back the information I need. It seems like I have to open a support request often with them.
For how long have I used the solution?
I have been using Splunk Enterprise Platform for about 10 years.
What do I think about the stability of the solution?
Splunk Enterprise Platform is stable, but it could be better.
What do I think about the scalability of the solution?
The scalability of Splunk Enterprise Platform is pretty good, as we have not had significant issues with scaling it.
How are customer service and support?
The customer support for Splunk Enterprise Platform could be better in that the support agents could be more knowledgeable. It takes a lot of communication to get them on board usually with what we are experiencing.
How was the initial setup?
It was fairly easy to do, and I appreciate the opportunity to provide feedback regarding my experience with Splunk Enterprise Platform.
What's my experience with pricing, setup cost, and licensing?
I believe that Splunk Enterprise Platform is expensive, but that is about all I know regarding pricing, setup cost, and licensing.
Which other solutions did I evaluate?
I know we evaluated options before choosing Splunk Enterprise Platform, but it has been several years ago and I was not involved in that process, so I do not know what the other options were.
What other advice do I have?
I would advise others looking into using Splunk Enterprise Platform to carefully evaluate if there is any less expensive option out there at this time that would do enough of what Splunk Enterprise Platform provides, as it is a very expensive product. I would rate my overall experience with Splunk Enterprise Platform an 8.
Admin role has gained deeper observability and now supports teams with efficient dashboards
What is our primary use case?
I am an admin for Splunk Enterprise Platform, so I mostly help other teams use it and enable it. I enable other teams to use dashboards or onboarding different apps and such.
More recently, we had an onboarding or ingestion of some extra data and as a POC for the HashiCorp app. It was a little challenging because we had to work around some of the different file types and they wanted them coming from specific locations to specific servers. That was a fun thing to do.
What is most valuable?
Splunk Enterprise Platform offers great observability into all my apps, as well as being able to use the GUI to edit different things and be able to provide the best experience for our internal teams so that way we can provide the best experience for our customers.
The overall visibility of Splunk Enterprise Platform is great, but I do really appreciate being able to do specific searches for different teams if they're missing data or if they need extra data in, as well as looking at dashboards and enabling those teams to have the most efficient and productive time.
I think it handles large data very well. It seems to regulate and maintain itself very well. It corrects itself back on course to resolve those errors.
What needs improvement?
I am pretty new to the product, so I haven't really found anything specific. I would really appreciate being able to see who edited certain dashboards or alerts. I think that would be really helpful in the future.
For how long have I used the solution?
I have been using Splunk Enterprise Platform for about eight months.
What do I think about the stability of the solution?
It has been reliable.
What do I think about the scalability of the solution?
It seems to scale very well, and we have never had issues with licensing or pushing up that license usage.
How are customer service and support?
I have interacted with Splunk support and we have weekly or biweekly meetings with them. It has been great to be able to talk through some of the issues that we have, along with getting some links or putting in a support ticket.
What other advice do I have?
I would say look into how you would use Splunk Enterprise Platform and maybe compare other options as well. Also, I have always had a really good experience with Splunk and onboarding has been pretty easy, as well as it being super scalable, allowing you to have great observability. It is really good at self-regulating. Any issues or errors, for example a slowed queue or suddenly ingesting a lot of data, it is really good at regulating itself. I think that is great. I would rate this product a 9 out of 10.
Monitoring has reduced outages and provides live insight into video on demand success rates
What is our primary use case?
My main use case for Splunk Enterprise Platform is to monitor the video on demand success rate for our video platform.
A specific example of how I use Splunk Enterprise Platform for monitoring the video on demand success rate is that we monitor the success rate of video on demand plays on different markets where customers will order a video on demand program that will play on their set-top box. We collect a lot of log data for that and if a video on demand session fails, it logs an alarm code that will be monitored through our Splunk Enterprise Platform dashboards. It allows us to show the successful setup rate. It gives us information on the user, their MAC address, so we can see if all of the failed attempts are from the same user or different users. It also shows us different markets and allows us to narrow in on what device it might have failed in on based on what alarm ID it flags.
What is most valuable?
The best features Splunk Enterprise Platform offers include the customization because the way we have our dashboards set up helps us identify anomalies or if we have something that is happening or if an issue is cleared or not.
Regarding the customization aspect, we have it set up to graph the success rate over time, and the way the graph shows not only the success rate but failures on the same graph makes it easy to identify those anomalies. It will have a success rate line and then if there is a failure and the success rate line goes down, there is another line on the same graph that will show how many failures there were at that time.
Splunk Enterprise Platform has positively impacted my organization by helping us reduce our outages through monitoring.
Monitoring with Splunk Enterprise Platform has reduced outages for us because it is live data and that has allowed us to see trends in an area and anticipate if something is going to happen in a market that we need to get on top of.
What needs improvement?
I do not have any suggestions on how Splunk Enterprise Platform can be improved because I am happy with it.
If I had to think of one area where Splunk Enterprise Platform could be better or easier to use, helpful hints maybe could be added where you hover over something and it gives you some ideas of what you can do for that feature.
For how long have I used the solution?
I have been using Splunk Enterprise Platform for approximately five years.
What do I think about the stability of the solution?
Splunk Enterprise Platform is stable.
What do I think about the scalability of the solution?
Its scalability is easy.
How are customer service and support?
I have no complaints concerning customer support for Splunk Enterprise Platform.
Which solution did I use previously and why did I switch?
I did not previously use a different solution before Splunk Enterprise Platform in my department.
How was the initial setup?
My experience with pricing, setup cost, and licensing is great; I just log in. I was given a login and that is how I worked it. I do not think my department dealt with any of that; that is a whole other department within our organization.
What was our ROI?
I would say we probably do benefit from having Splunk Enterprise Platform because we use it every day and they have expanded our use of it and they have even decided to migrate it into the cloud versus trying to use other open platform systems. We continue to use it, which would tell me that it has been beneficial.
Which other solutions did I evaluate?
Before choosing Splunk Enterprise Platform, I did not evaluate other options.
What other advice do I have?
My advice to others looking into using Splunk Enterprise Platform is to research the product and utilize all the support that Splunk provides. I have rated this review a ten out of ten.
Which deployment model are you using for this solution?
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Centralized logs have transformed user behavior analysis and now speed up daily investigations
What is our primary use case?
My main use case for Splunk Enterprise Platform is as a log consolidation tool.
In my day-to-day work, we receive email logs, web logs, and any kind of user activity logs, and we investigate based on anomalies in user activity.
We initiated user behavior analysis, so we're looking for variations from a known baseline.
What is most valuable?
Splunk Enterprise Platform's best features include the ability to ingest data from any source without having to spend too much time getting the data into a set format.
The flexibility in data ingestion makes ingesting new data sources very easy and very quick for our team, allowing us to have new data sources online within a couple of days.
Splunk Enterprise Platform has positively impacted our organization by giving us insights into user behavior that we didn't have before, enabling us to track and monitor user activity that would otherwise have been missed.
It has led to faster investigations, as typically, we can go from query to resolution within a day.
What needs improvement?
The ability to delete data is something I would suggest for improvement, as at the moment, you can delete data from search, but you can't delete data permanently, which is an issue sometimes.
For how long have I used the solution?
I have been using Splunk Enterprise Platform for 15 years.
What do I think about the stability of the solution?
Splunk Enterprise Platform is stable.
What do I think about the scalability of the solution?
For our scale, Splunk Enterprise Platform's scalability is fine, as we have a relatively small license.
How are customer service and support?
Customer support for Splunk Enterprise Platform is good, but technical support is variable.
I would rate customer support an eight on a scale of one to ten.
Which solution did I use previously and why did I switch?
We did not use a different solution before Splunk Enterprise Platform; this was our first.
How was the initial setup?
I wasn't involved with the initial purchase, but I understand the pricing, setup cost, and licensing are quite expensive.
What was our ROI?
I can't share any exact figures regarding return on investment, but we've had Splunk Enterprise Platform for 15 years, so I would say they're happy with their ROI.
What's my experience with pricing, setup cost, and licensing?
I wasn't involved with the initial purchase, but I understand the pricing, setup cost, and licensing are quite expensive.
Which other solutions did I evaluate?
I evaluated other options before choosing Splunk Enterprise Platform; I can't remember them all, but I think Elasticsearch was one of them.
What other advice do I have?
My advice to others looking into using Splunk Enterprise Platform is to make sure you have a defined use case you can measure against.
Splunk Enterprise Platform is deployed on-premises in our organization.
We don't have it at that scale, but I'm sure Splunk Enterprise Platform would work very well for managing data sovereignty at a petabyte scale within our environment.
We don't use the trusted control plane, so I don't have experiences in maintaining granular control over data using it.
We won't be using Splunk Enterprise Platform with any AI because of the client data we hold, which affects how we manage access to our operational data.
My impression of Splunk Enterprise Platform's approach to managing governance within a private network environment is very good.
The cost of it keeps it from being a perfect ten for me.
For manual searches, we are very happy with the outputs of Splunk Enterprise Platform.
I would rate this product an overall nine out of ten.
Centralized monitoring has improved cloud VM insights and supports proactive CPU management
What is our primary use case?
Splunk Enterprise Platform is used primarily for our SOC and ingesting all metrics and data from all the virtual machines that we're running in our cloud environment.
A specific example of how I use Splunk Enterprise Platform in my daily work is monitoring CPU usage for VMs, and if CPU credits run out on a burstable instance, we know to add more credits or reconsider how we're using that VM.
What is most valuable?
The latest best feature Splunk Enterprise Platform offers is probably MCP server, where people in the organization don't need to have knowledge of SPL and syntax; they can just query Splunk Enterprise Platform directly.
MCP server has changed the way my team works and collaborates by democratizing the use of Splunk Enterprise Platform so we don't have to go to someone that knows how to use it; anybody can spin up the co-pilot agent and start querying.
Splunk Enterprise Platform has positively impacted our organization by providing insight into our environment in a centralized manner so that we don't have to set up alerts in a bunch of different places; we just have to look at one place to get what we need.
Splunk Enterprise Platform helped save time; we've had a few issues where VMs stopped responding and we had trouble figuring out what was going on, but we just went on Splunk Enterprise Platform and it was easy to see the data there.
What needs improvement?
Splunk Enterprise Platform can improve by taking more positive steps towards user-friendliness so that more people can access it without having to go through a bunch of training to learn how to use it.
For how long have I used the solution?
I have been using Splunk Enterprise Platform for about a year and a half.
What do I think about the stability of the solution?
Splunk Enterprise Platform is stable.
What do I think about the scalability of the solution?
Splunk Enterprise Platform's scalability is very good; we can just start plugging in indexes as we need.
How are customer service and support?
The customer support has been acceptable; we had an issue that we thought should be easily solvable or something that works out of the box, but it didn't.
Which solution did I use previously and why did I switch?
I previously used Microsoft Sentinel and switched because we had more places we needed to ingest data from.
What was our ROI?
I have not seen a return on investment and think we have some internal issues; we really just got Splunk Enterprise Platform for our SOC.
What's my experience with pricing, setup cost, and licensing?
My experience with pricing, setup cost, and licensing has been fairly straightforward; the partner we had to help us set up was pretty good.
What other advice do I have?
I cannot comment on Splunk Enterprise Platform's capability to manage data sovereignty at a petabyte scale within my environment because we're not at that level.
We haven't been using Splunk Enterprise Platform's federated search for querying data in place, so there hasn't been much evolution or primary drivers for either expanding or limiting its use.
I have no experience in maintaining granular control over data using the trusted control plane within Splunk Enterprise Platform; we don't use it much.
I learned a lot at this conference about how we can manage access to our operational data through Splunk Enterprise Platform; we're not quite at that level, but once we are, then I'll have more feedback.
I don't think we use the feature to track specific metrics to evaluate the success of reducing TCO with Splunk Enterprise Platform's non-indexing analytics approach.
My advice to others looking into using Splunk Enterprise Platform is to start small; ingest a little bit of data that you can start to see returns on right away, and then expand from there as you learn how it works. My overall review rating for Splunk Enterprise Platform is eight out of ten.
Log investigations have become faster and data now clearly supports executive decisions
What is our primary use case?
In one example, I was investigating some traffic where we were getting hit on one of our servers and we were trying to see where it was coming from and if our managed rule set was working properly as we configured it. Navigating to Splunk Enterprise Platform, I was able to query for all the traffic coming from the nefarious IPs and also grab the locations of where they were going, where they were coming from, and if they were blocked or not. From that, I exported that data into an Excel sheet and used that to build bar charts or pie charts to present to executive leadership on what was going on.
I think it is a great additive to being in the cloud. As I mentioned, we are an AWS shop. Having Splunk Enterprise Platform has made our lives easier because outside of being engineers, we are all still the analysts as well. We still do all of the investigative work and log analysis. Splunk Enterprise Platform makes it very easy for us to parse and grab data that we would need in a given investigation. I am really happy with the product.
What is most valuable?
It has given us, from an engineering perspective, the ability and the scalability to move at haste when it is time to investigate different alerts that we need to triage. Things that may be false positive or true positive, we are able to delineate really fast, and also gather important data for those C-suite folks who may need the type of data to support KPIs and things of that nature.
What needs improvement?
For how long have I used the solution?
What other advice do I have?
I would say around AI, everyone needs to improve their governance and security. As great as AI is, it is also scary. While I as the engineer do enjoy having an agentic friend helping me out and making things more efficient, guardrails are still needed to be implemented as we move further into this agentic space.
I think they are pretty accurate. I have not had any issues at this point, but as we go and continue to do our research and due diligence, I am sure things will get better.
Continue doing the homework, continue researching, continue using the tool to the best of its capabilities, and building out your data sets as you see fit. I would rate this product a nine out of ten.
Which deployment model are you using for this solution?
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Centralized monitoring has provided full visibility and simplified audits for our on-premise network
What is our primary use case?
My main use case for Splunk Enterprise Platform is gaining insights, visibility, and maintenance for on-premise infrastructure.
For insights, visibility, or maintenance, we have a Splunk forwarder on all of our Windows servers, desktop endpoints, Linux servers, and we collect Cisco switch IOS data. For our CCRI, we are required to collect logs from all those devices. Thanks to Splunk Enterprise Platform and SPL, I was able to write queries that would prove that all of our devices were online, checking in, and reporting. I was also able to show us what is actively online at any given time.
What is most valuable?
The best features Splunk Enterprise Platform offers include a robust environment and platform for all the various devices on the network, an easy ability to update, a great support team from Splunk, which helps us stay on track and expand our functionality, and an ecosystem with so many options to improve visibility of durability and everything else.
The feature I rely on the most or find the most valuable in my day-to-day work is the ability to keep eyes and ears on our network and be able to search for any events that need attention and make sure the network and all the devices are online.
Splunk Enterprise Platform positively impacts my organization by helping us keep all of our devices online and healthy and helped us prove we meet the requirements for the CCRI audit.
What needs improvement?
When we had a consultant come on site, they installed a bunch of apps, and some of those did not work. In order to go back and clean everything up, we have to go into the back end. It would be helpful if there were a way to look into the installed apps, which ones are being used, and which ones are not being used.
For how long have I used the solution?
I have been using Splunk Enterprise Platform for two years.
What do I think about the stability of the solution?
Splunk Enterprise Platform has experienced stability issues.
What do I think about the scalability of the solution?
Splunk Enterprise Platform's scalability for my needs is very good. It scales extremely easily because of our distributed environment and our deployment server, we can expand as needed very easily.
How are customer service and support?
The customer support is second to none. It is some of the best customer support I have experienced in the IT world in 20 years.
What about the implementation team?
Because Splunk Enterprise Platform is such a solid product, we only have two admins. One of them is a Linux administrator, which manages the back end, and then there is me, which is the Splunk admin, which is responsible for searches, dashboards, and setting up alerts. We have been able to keep a small team of only two people and have complete oversight over our network and all of our devices.
What was our ROI?
Because Splunk Enterprise Platform is such a solid product, we only have two admins. One of them is a Linux administrator, which manages the back end, and then there is me, which is the Splunk admin, which is responsible for searches, dashboards, and setting up alerts. We have been able to keep a small team of only two people and have complete oversight over our network and all of our devices.
What other advice do I have?
Regarding Splunk Enterprise Platform's AI capabilities, we have not used it because it is on classified systems, which are air-gapped networks.
I have not used Federated Search.
In maintaining granular control over data using the Trusted Control Plane within Splunk Enterprise Platform, we have a few users from cybersecurity who have everything under the Power User role, and then we have admins. That is all.
Regarding Splunk Enterprise Platform's approach to managing governance within a private network environment, we use mostly business process as opposed to the technology, so we have not explored that yet, and I would be actually interested in learning about it.
The advice I would give to others looking into using Splunk Enterprise Platform is to understand that it is closer to a marathon than a sprint. If you are new to Splunk Enterprise Platform, it will take a little time to wrap your head around it and understand it. The value is there and your skills will grow over time, and you should contribute time every day or every week to learning and expanding your knowledge in Splunk Enterprise Platform. It is an excellent product.
The people in the Splunk world have been awesome. The conference is awesome. Splunk Enterprise Platform is awesome, and the value is awesome. I would rate this review a 9.
Security monitoring has identified insider threats and supports flexible app-driven analytics
What is our primary use case?
My main use case for Splunk Enterprise Platform is security monitoring. Over the past 13 years, I have performed a variety of different roles relating to Splunk, covering ITSI, IT Ops, and Enterprise Security, but predominantly at the moment, my focus is on security monitoring use cases.
I typically use Splunk Enterprise Platform for security monitoring to identify insider threats and unusual behaviors with internal actors as well as external customers who use our services. There is a variety of different use cases within that scope, but the main security focus is on identifying insider threats, using a variety of data sources such as AWS logs and Azure logs, correlating different things between logins, activity, and proximity.
How has it helped my organization?
Splunk Enterprise Platform has positively impacted my organization by giving us access to the security monitoring tooling that we need to operate. We are also able to use a lot of that same data for other purposes. For example, data coming in from the website can also be used for IT Ops monitoring of the website, which we can leverage for security and IT Ops. For other source types such as authentication from Entra ID or Okta, we are able to diagnose issues and assess the frequency of usage within the team, alongside security use cases. It gives us many options for using that same data.
What is most valuable?
In my opinion, the best features Splunk Enterprise Platform offers are its flexibility and ability to accomplish a variety of different things depending on the requirement. There are thousands of apps on Splunkbase which are very good for extending the capabilities. I do quite a lot of app development myself, contributing back to the community from that perspective.
From an app development perspective, there has been a significant push in the last couple of years on new ways of working and building apps with Splunk's provided tooling. The UCC app builder is quite good for starting with a barebones app and building it out. Additionally, there is good new technology around Splunk UI toolkit which allows developers to build richer visual apps. I believe that this empowers developers and enables them to build premium looking and capable products within Splunk Enterprise Platform, facilitating companies' closer integration with Splunk Enterprise Platform.
The extensibility of it is excellent, and it is easy to integrate with, access data, and dashboards from anywhere, including mobile. It is versatile from that front, and the type of apps that can be built on it range massively between dashboards and custom REST interfaces that can be integrated to other systems.
What needs improvement?
Certain parts of Splunk Enterprise Platform, such as the KV store, are quite monolithic and tightly coupled into Splunk Enterprise Platform. It would be beneficial to deploy Splunk Enterprise Platform while using different KV stores and technologies; for example, if we are running in the cloud, it would be beneficial to leverage cloud vendor turnkey services and abstract them away from Splunk Enterprise Platform. This would let us tie it into existing systems and benefit from the scaling involved.
For how long have I used the solution?
I have been using Splunk Enterprise Platform for 13 years.
What do I think about the stability of the solution?
Splunk Enterprise Platform is stable.
What do I think about the scalability of the solution?
It scales very well, and I have never had any issues with the scaling.
How are customer service and support?
Customer support is good. I have always worked well with the account team to ensure that anything needing escalation gets addressed. However, in the last couple of years, the support staff do not necessarily understand the problems I report and sometimes simply regard them as bugs. They expect me to provide diagnostics rather than testing them upfront, which is frustrating, but otherwise, support is very good.
Which solution did I use previously and why did I switch?
We have typically used tools such as Grafana for metrics, AWS CloudTrail, and AWS CloudWatch logs for viewing logs, but now we have everything centralized in Splunk Enterprise Platform.
What about the implementation team?
I work with partners, but I am not myself a partner. I deliver consultancy work via other partners, but we are not partners ourselves.
What was our ROI?
I do not have specific metrics about return on investment, such as fewer employees needed, money saved, or time saved.
What's my experience with pricing, setup cost, and licensing?
I do not get too involved in the licensing, so I do not really have much of an opinion on that. However, regarding setup cost, the reference hardware is provided and seems to be overkill for some of the host types. I believe it would be beneficial to understand where savings could be made by running slightly smaller compute for things such as license servers since I do not think the reference hardware is always necessary and could reduce setup and operational costs.
What other advice do I have?
I would advise others to use the free training available initially so they can start using Splunk Enterprise Platform on the right foot. This allows running better, cleaner searches with fewer resources and easier platform navigation. Building a team of skilled individuals to handle data onboarding, search writing, and platform management is essential, along with implementing governance around data ingestion to avoid overloading the system.
With the use of SmartStore, we have been able to reduce our storage usage, which I believe has also saved us money. I do not have specific numbers on how much that has saved, but by moving to SmartStore, we run fewer fast disks that are ultimately more expensive, pushing data to SmartStore and leveraging its capabilities.
I have not worked at anything to the petabyte scale. I have worked at the terabyte level but not at the petabyte level, so I am not fully aware of what kind of problems we might encounter. The scaling work I have done in the past has been quite seamless, scaling very well linearly. I have confidence in the capabilities of other petabyte-level customers, so I believe it could be achieved.
We have not actually explored federated search to S3 yet, but we have done federated search between Splunk Enterprise Platform instances in the past, and that worked very well. I hope federated search for S3 will let us ingest less data and store more directly in S3 from the source, saving us on workload and resources required for ingestion and storage on disk, as we can leverage cheaper S3 storage.
In my organizational context, the AI workload inputs and functionality is managed in the same role-based access control methods as the existing knowledge objects, API endpoints, and capabilities. I would hope that what the AI agents can access is managed in the same way, ensuring specific roles only access necessary data. Splunk Enterprise Platform's role-based access control model works well for knowledge objects and indexes, and I hope that extends equally to AI.
We are able to use single sign-on for login in our private network, which helps. Everything done within the platform is in the audit index, which we regularly monitor and manage to understand what our users are doing. I would rate this product a 9 out of 10.
Centralized monitoring has boosted daily threat detection and streamlined compliance audits
What is our primary use case?
Splunk Enterprise Platform is my main tool for security use cases.
I use Splunk Enterprise Platform for monitoring and detecting threats.
In addition to monitoring, I use it for threat detection and incident response within my security framework.
What is most valuable?
Continuous monitoring is the best feature that Splunk Enterprise Platform offers.
Continuous monitoring helps my team day to day by allowing us to stay compliant with our regulations and ensuring that no threats or serious incidents are taking place.
Splunk Enterprise Platform has positively impacted my organization by allowing us to gain a centralized monitoring platform where I can centralize all of my logs.
Since centralizing my logs with Splunk Enterprise Platform, it has improved compliance audits.
For how long have I used the solution?
I have been using Splunk Enterprise Platform for one year.
What do I think about the stability of the solution?
Splunk Enterprise Platform is stable.
What do I think about the scalability of the solution?
Splunk Enterprise Platform's scalability is really good. It is not too hard to add indexers or increase ingestion capacity or search capabilities by adding more search heads, so I would rate it pretty well.
How are customer service and support?
Customer support is very good.
Which solution did I use previously and why did I switch?
I did not previously use a different solution before Splunk Enterprise Platform.
What was our ROI?
I have seen a return on investment with Splunk Enterprise Platform as it has saved us time, since I don't have to go and fetch logs from specific tools, as they all come in through Splunk Enterprise Platform.
What other advice do I have?
Regarding Splunk Enterprise Platform's AI capabilities, I think it is important that it has the capability to use local models or in-house built models that conform to the environment that Splunk Enterprise Platform's architecture is in or Splunk Enterprise Platform's stack is in.
I cannot say much about its accuracy and reliability of output as I have not used it too often.
Overall, my experience with maintaining Splunk Enterprise Platform in an on-premises environment is pretty good, although there are some things that would be better in the cloud, reducing overhead for engineers or administrators, such as compliance.
I track daily ingestion rates to see metrics related to my usage.
My advice to others looking into using Splunk Enterprise Platform is to go through Splunk training courses, as they offer a lot of hands-on, valuable training to get you set up and ready to run your environment.
I give this product an overall rating of 10.
Logging and alerts have improved incident response and now support proactive server monitoring
What is our primary use case?
My main use case for Splunk Enterprise Platform is logging and alerting.
A specific example of how I use Splunk Enterprise Platform for logging and alerting is monitoring server resource utilization as well as uptime and whether servers are offline.
When a server goes offline or resource utilization spikes, an alert is generated and sent via text message to me so that I can respond quickly.
What is most valuable?
The best feature Splunk Enterprise Platform offers is usability.
What specifically stands out to me about usability is the dashboards and alert setup.
Splunk Enterprise Platform has positively impacted my organization by allowing us to respond quickly to servers being offline or having resources consumed too heavily.
I have seen improvements in both response time and avoiding outages because of Splunk Enterprise Platform. Splunk Enterprise Platform is stable and seems to be pretty scalable. Customer support for Splunk Enterprise Platform is fairly good.
What needs improvement?
I think having a dashboard of SPL queries would be really helpful to improve Splunk Enterprise Platform.
For how long have I used the solution?
I have been using Splunk Enterprise Platform for three years.
What do I think about the stability of the solution?
Splunk Enterprise Platform is stable.
What do I think about the scalability of the solution?
Splunk Enterprise Platform seems to be pretty scalable.
How are customer service and support?
Customer support for Splunk Enterprise Platform is fairly good.
What was our ROI?
I cannot provide exact metrics regarding return on investment, but I know the time saved has been very significant.
What other advice do I have?
Regarding Splunk Enterprise Platform's AI capabilities, I find its governance and security intriguing; I do not know a great deal about it, but I have been intrigued by what the possibilities could be.
I am very confident in the accuracy and reliability of output from Splunk Enterprise Platform.
We are not really at the petabyte scale for managing data sovereignty with Splunk Enterprise Platform.
Our use of Splunk Enterprise Platform's Federated Search has evolved for querying data in place; we have expanded it for more visibility for more users, not just IT-based users.
We do not use the trusted control plane within Splunk Enterprise Platform for maintaining granular control over data, so I cannot comment on its effectiveness.
Splunk Enterprise Platform's governance and role-based access controls will be a big part of managing access to our operational data as we consider new use cases such as agentic AI.
My advice for others looking into using Splunk Enterprise Platform is to take your time and learn what you are doing.