What users are saying about
8 Ratings
<a href='https://www.trustradius.com/static/about-trustradius-scoring' target='_blank' rel='nofollow noopener noreferrer'>trScore algorithm: Learn more.</a>Score 8 out of 100
Based on 8 reviews and ratings
Top Rated
304 Ratings
<a href='https://www.trustradius.com/static/about-trustradius-scoring' target='_blank' rel='nofollow noopener noreferrer'>trScore algorithm: Learn more.</a>Score 8.7 out of 100
Based on 304 reviews and ratings
Likelihood to Recommend
Apache Flume
Apache Flume is well suited when the use case is log data ingestion and aggregate only, for example for compliance of configuration management. It is not well suited where you need a general-purpose real-time data ingestion pipeline that can receive log data and other forms of data streams (eg IoT, messages).

Verified User
Analyst in Information Technology
Airlines/Aviation Company, 51-200 employeesSplunk Enterprise
Pros: Splunk is very well suited if you have multiple log sources of related data. All of them can be correlated and tasks can be automated based on the requirement. Other than alerts, Splunk can also run a specific script of your choice, based on some defined conditions. Cons: If you have a few logs but a large number of log sources, Splunk can be very expensive.
Security Analyst
University of Colorado DenverHigher Education, 5001-10,000 employees
Feature Rating Comparison
Security Information and Event Management (SIEM)
Apache Flume
—
Splunk Enterprise
8.9
Centralized event and log data collection
Apache Flume
—
Splunk Enterprise
9.6
Correlation
Apache Flume
—
Splunk Enterprise
9.1
Event and log normalization
Apache Flume
—
Splunk Enterprise
9.1
Deployment flexibility
Apache Flume
—
Splunk Enterprise
8.6
Integration with Identity and Access Management Tools
Apache Flume
—
Splunk Enterprise
8.4
Custom dashboards and views
Apache Flume
—
Splunk Enterprise
9.1
Host and network-based intrusion detection
Apache Flume
—
Splunk Enterprise
8.5
Pros
Apache Flume
- Multiple sources of data (sources) and destinations (sinks) that allows you to move data form and to any relevant data storage
- It is very easy to setup and run
- Very open to personalization, you can create filters, enrichment, new sources and destinations
Global Technology Centre - Middleware
ProdubanFinancial Services, 10,001+ employees
Splunk Enterprise
- Allow for separation of control where we don't let some employees have access to production but still can diagnose issues.
- Common location to go for all logs even if the logs themselves aren't in the same place.
- Ability to ingest logs from different locations without having to change the code to put logs in a certain place (pro and con).

Verified User
Engineer in Engineering
Computer Software Company, 201-500 employeesCons
Apache Flume
- It is very specific for log data ingestion so it is pretty hard to use for anything else besides log data
- Data replication is not built in and needs to be added on top of Apache Flume (not a hard job to do though)

Verified User
Analyst in Information Technology
Airlines/Aviation Company, 51-200 employeesSplunk Enterprise
- Even though there is a search tool as a help function, you still have to read through many documentation to find the answers you're looking for and sometimes you don't find it. The help function in Splunk could be improved to be more intuitive or have a built-in help per report, panel or dashboard.
- Creating a Splunk dashboard is rather straightforward however, customization is not. Splunk could be improved to provide more tools or features for customization such as adding colors and font options for text and graphs or graphics.
- My dashboard has a lot of useful information and I want the important panels and reports at the top but there is no easy way to do this. Perhaps Splunk could be improved to allow features such as adding URL links to other dashboards or some other clever way to emphasize the important data in my dashboard without compromising space.

Verified User
Professional in Information Technology
Investment Management Company, 1001-5000 employeesLikelihood to Renew
Apache Flume
No score
No answers yet
No answers on this topic
Splunk Enterprise
Splunk Enterprise 10.0
Based on 17 answers
We are using Splunk extensively in our projects and we have recently upgraded to Splunk version 6.0 which is quite efficient and giving expected results. We keep track of updates and new features Splunk introduces periodically and try to introduce those features in our day to day activities for improvement in our reporting system and other tasks.

Verified User
Consultant in Information Technology
Retail Company, 10,001+ employeesUsability
Apache Flume
No score
No answers yet
No answers on this topic
Splunk Enterprise
Splunk Enterprise 9.0
Based on 3 answers
You can literally throw in a single word into Splunk and it will pull back all instances of that word across all of your logs for the time span you select (provided you have permission to see that data). We have several users who have taken a few of the free courses from Splunk that are able to pull data out of it everyday with little help at all.
Splunk Architect / Engineer
CRGT Inc.Information Technology and Services, 1001-5000 employees
Reliability and Availability
Apache Flume
No score
No answers yet
No answers on this topic
Splunk Enterprise
Splunk Enterprise 10.0
Based on 1 answer
When properly setup and configured, Splunk is extremely reliable.

Verified User
Engineer in Other
Computer Software Company, 1001-5000 employeesSupport Rating
Apache Flume
Apache Flume 5.0
Based on 2 answers
Apache Flume is open-source so support is limited. Never the less, it has great documentation and best practices documents from their end-users so it is not hard to use, setup and configure.

Verified User
Analyst in Information Technology
Airlines/Aviation Company, 51-200 employeesSplunk Enterprise
Splunk Enterprise 8.7
Based on 24 answers
Splunk maintains a well resourced support system that has been consistent since we purchased the product. They help out in a timely manner and provide expert level information as needed. We typically open cases online and communicate when possible via e-mail and are able to resolve most issues with that method.

Verified User
Engineer in Information Technology
Information Technology & Services Company, 201-500 employeesImplementation Rating
Apache Flume
No score
No answers yet
No answers on this topic
Splunk Enterprise
Splunk Enterprise 9.0
Based on 2 answers
Smooth without too many major issues.

Verified User
Consultant in Information Technology
Transportation/Trucking/Railroad Company, 1001-5000 employeesAlternatives Considered
Apache Flume
Apache Flume is a very good solution when your project is not very complex at transformation and enrichment, and good if you have an external management suite like Cloudera, Hortonworks, etc. But it is not a real EAI or ETL like AB Initio or Attunity so
you need to know exactly what you want.On the other hand being an opensource project give Apache a lot of room to personalize thanks to its plug-able architecture and has a very nice performance having a very low CPU and Memory footprint, a single server can do the job on many occasions, as opposed to the multi-server architecture of paid products.
you need to know exactly what you want.On the other hand being an opensource project give Apache a lot of room to personalize thanks to its plug-able architecture and has a very nice performance having a very low CPU and Memory footprint, a single server can do the job on many occasions, as opposed to the multi-server architecture of paid products.
Global Technology Centre - Middleware
ProdubanFinancial Services, 10,001+ employees
Splunk Enterprise
Splunk is proving to be a formidable replacement for Qradar, which we had as our previous SIEM. Qradar was powerful, but not easy to customize and quite limited. Splunk is not per se a "SIEM" but it can be in the way you used it. Also there is an Enterprise Security App that is available to buy and sit on top of Splunk, and that will take care of any concerns with needing a full-fledged SIEM. Splunk wins.

Verified User
Manager in Information Technology
Higher Education Company, 501-1000 employeesScalability
Apache Flume
No score
No answers yet
No answers on this topic
Splunk Enterprise
Splunk Enterprise 9.1
Based on 1 answer
Splunk can scale in to the petabyte per day range which of course is awesome
Regional Director
ePlus inc.Information Technology and Services, 501-1000 employees
Return on Investment
Apache Flume
- Flume has simplified a lot many of our ingest procedures, easier to deploy and integrate than a classical EAI, reducing the time to market
- But opposed to EAIs if the project starts to grow in complexity Apache Flume project may not be as suitable
Global Technology Centre - Middleware
ProdubanFinancial Services, 10,001+ employees
Splunk Enterprise
- I'm not a data analyst so I can not provide concrete examples on how the business has benefited from implementing Splunk. However, the analysts I have worked with have provided a wealth of support in reducing workstation issues across the enterprise. This alone reduces the time it takes to determine where the exact problem lies between a workstation and the servers it tries to communicate with.

Verified User
Professional in Professional Services
Information Technology and Services Company, 51-200 employeesPricing Details
Apache Flume
General
Free Trial
—Free/Freemium Version
—Premium Consulting/Integration Services
—Entry-level set up fee?
No
Splunk Enterprise
General
Free Trial
Yes
Free/Freemium Version
Yes
Premium Consulting/Integration Services
—Entry-level set up fee?
No