We use the solution for patching.
Splunk Enterprise
SplunkExternal reviews
External reviews are not included in the AWS star rating for the product.
Good Product - Bad News Cisco
Easy To integrated Source
Easy to scale
Useful to set up alerts and reports to manage the logs and log metrics
What is our primary use case?
What is most valuable?
It's not just one feature I like the most. Every person wants to collect and rate logs, and I value how the Splunk Enterprise Platform handles this.The most valuable part for us is setting up the alerts and reports to manage the logs and log metrics. We use it to support every tool across the entire bank.We are the ones who manage all the data, and if there's any issue, everything depends on the Splunk Enterprise Platform.
The tool uses upgraded rules restricting access to specific people, ensuring that only certain individuals can edit. Everyone else has read-only access. Splunk Enterprise Platform's dashboard and visualization features are good. These features are some of the best parts of the software because you can customize the dashboard however you need. The user interface is perfect and keeps getting better with new updates. It's very user-friendly, allowing everyone to create their dashboards easily.
What needs improvement?
The Splunk Enterprise Platform has room for improvement, particularly in automating the permissions process during app promotions. Currently, permissions are manually set when different teams request an application move to production, which is time-consuming. Automating this process would streamline operations by automatically assigning the appropriate permissions and roles to specific services or teams, reducing the need to review each request ticket manually.
For how long have I used the solution?
I have been using the tool for one year and five months.
What do I think about the stability of the solution?
I would rate the tool's stability as ten out of ten. It provides outstanding security and is also very user-friendly.
What do I think about the scalability of the solution?
We have encountered issues with scaling up and handling increasing data volumes, but we address them according to customer requirements. As for scalability, I would rate it a nine out of ten.
How are customer service and support?
The solution's support uses a ticketing system to address dashboards, alerts, reports, etc. If server issues or alerts are triggered, they respond by raising a ticket. They investigate the problem by checking logs and assessing any impact on disk storage.
I handle smaller support tasks myself but escalate them to my head for high-priority issues.
What about the implementation team?
My company's senior SMEs help with the deployment process.
What's my experience with pricing, setup cost, and licensing?
The solution's pricing increases with the amount of data used. This pricing model is acceptable because it aligns with the security features provided. It ensures that the price reflects the level of security and the amount of data we're managing.
What other advice do I have?
Currently, we are on-prem. However, we have started cloud migration in the last few months. I rate the overall solution a ten out of ten. In daily life, every IT company should use it to monitor its logs. It is an emerging tool.
Splunk enterprise is best next GEN SIEM solution
Dashboards that allows customers to visualize the data the way they want.
Multi correlation that allows to correlate & create the best usecase to minimise false positives.
The valuable information
Provides efficient monitoring capabilities and valuable transaction insights
What is our primary use case?
We use the product for real-time monitoring purposes.
What is most valuable?
The product's most valuable feature is the ability to explain the values and provide insights into transactions. It allows us to understand successful and failed transactions with a graphical representation easily.
What needs improvement?
Areas for improvement include enhancing dashboards, reports, alerts, and the monitoring console. With the monitoring console, users can track server performance metrics such as data ingestion, server uptime, CPU, and memory utilization. Integrations with third-party apps can provide comprehensive server monitoring capabilities. However, setting up such integrations may require significant time and effort, as experienced in the mentioned case took nearly 20 days to complete.
For how long have I used the solution?
We have been using Splunk Enterprise Platform for four years now.
What do I think about the stability of the solution?
I rate the platform's stability an eight out of ten.
What do I think about the scalability of the solution?
The product is highly scalable.
How was the initial setup?
The complexity of the initial setup largely depends on the level of experience. I find it straightforward due to my proficiency in establishing connectivity, creating DNS, and performing installation configuration. I rate the process a nine and a half out of ten.
The time required for deployment varies depending on the process in place. If changes need to be made within a specific window, such as raising an instance, the window period opens only for a set duration. Deployment in such cases involves raising a change request and obtaining approval, which can take up to seven days. However, from a technical perspective, initial deployment typically takes up to one or two hours. Yet, procedural requirements, like awaiting change request approval, may prolong the process, necessitating additional days of waiting before deployment can proceed.
What's my experience with pricing, setup cost, and licensing?
The product is expensive, and the cost depends on the amount of data ingestion.
What other advice do I have?
When clients request specific data for a particular period, we retrieve the relevant information from our servers and generate statistics. Later, we create reports, alerts, and dashboards based on the requested data. This process involves fetching the necessary data attributes, such as service names, and displaying their corresponding values in the generated reports, alerts, and dashboards.
The platform's alerting capabilities enable the automation of alerts based on predefined conditions. When specific results exceed predefined thresholds, alerts are triggered automatically. For example, if a value exceeds a specified threshold, an email alert is generated and sent to the relevant stakeholders, prompting them to take appropriate action. This automated alerting mechanism enhances operational efficiency by promptly notifying stakeholders of critical events, allowing them to respond swiftly and effectively to potential issues or deviations from expected outcomes.
I recommend Splunk to other people. It's a very good tool, offering many features that surpass other tools like Kaspersky. Its comprehensive monitoring capabilities and insightful analytics make it a valuable user asset.
I rate it a ten out of ten.
Splunk Enterprise a monitoring tool....
Amazing Platform for Data analysis and Logs Validation
A great tool for consolidated logging and monitoring
Best log analysis and monitoring tool
Splunk also has the ability to create alerts and reports based on the logs analysis.