I think Box is great for research teams or anyone that has a large number of files that need to be securely stored. Particularly in the case of social science research, where it is important to protect identifying data, Box is a great option. In cases where teams need a more reliable means for real-time collaboration, I would probably consider a different alternative
Well suited: Splunk ES is highly recommended in an environment with many data sources and experienced computer engineers. It has a steep learning curve, but once that hurdle is crossed, it is absolutely a beast. It is also very expensive, so a company putting a high amount of budget in Security is needed. Not well suited: Splunk ES is not recommended if a company has only a few sources and some non-technical IT users. The price won't justify the fewer data sources and scratching just the surface level. Moreover, non-technical IT users would be better off with something that has a query builder, unlike Splunk.
The main feature that I like the most in Box is that it makes collaboration seamless, workers can easily check the documents any time and make changes according to the needs.
Box manages and backs up all of your files on its cloud servers, and provides a very nice interface for creating, viewing, editing, and collaborating on the most commonly used file types (PDF, XLS, DOC, etc.).
Over the past few years, Box has built on top of its basic cloud storage management with a host of other tools, such as workflows, AI, monitoring, and analytics.
It is helping us to make good connections with clients and our workers themselves as to its syncing and viewing feature to all is very much helpful and easy to go.
Advanced Threat Detection and Correlation: ES stands out in its ability to detect sophisticated threats by correlating data from multiple sources. For instance, it can identify unusual patterns in user behavior, cross-referencing with network logs to flag potential insider threats.
Real-time Monitoring and Alerting: ES offers robust real-time monitoring capabilities. It excels in promptly alerting us to critical security events, such as suspicious network traffic spikes or unauthorized access attempts, allowing for immediate response.
Comprehensive Log Analysis: ES ingests and analyzes an extensive range of log data. It's particularly adept at parsing and making sense of complex log formats, making it a versatile tool for understanding system activities and security events.
ES on the cloud (SaaS) has too many limitations with platform administration.
Supported integrations are not always on par with enterprise support especially when dependent on 3rd-party proprietary APIs.
In later versions, unforeseen glitches seem to show up that have no resolution except version upgrade. This used to not be the case in prior versions which were very stable.
I like the security features and I like the website. It's easy to use and create and move things around as needed. The main reason for a lower rating is because the Box Sync app is just not a good program. It's a memory hog, it's slow, transfer speeds are slow, and it's not the most efficient route. If you have a large Box account and you need to get a computer up to speed on a large amount of data within Box, you are in for the long haul. Last time I had to do this, it took 3 days to sync all of the files and we are talking around 100 GB worth of data
Everything with Box is seamless. It can be integrated into virtually any other software or application. You can even get the app for your phone or tablet to work on the go. File syncing is so quick. The only reason I gave it a 9 is the issue I discussed earlier about the local file application rebooting and not continuing to sync files. Other than that, it's great!
Maintaining hundreds or even 1000+ SOC use cases is really difficult, considering that the Data sources may not always send the data. A module that detects data freshness issues and detect data format changes would be a great help. the main challenge today using Splunk Enterprise Security is making sure that the detection rules are still working properly given all the changes that occur in data source applications. Also, maintaining the data collects on tens of thousands of servers and more than 100k workstations is a real company IT challenge: the splunkbase forwarder may not support old OS anymore, while these are the most important to monitor. Moving to the Open Telemetry collector has become essential so that only 1 agent is required for both SIEM and application observability.
Yeah, it's always worked, I've never had any kind of connection issues, the only issues I've had it I've been on our end when the Internet hasn't worked.
The general operation and management of Box is very efficient, both when accessing the account, and when adding files, downloading or modifying any document directly. The web platform, mobile and desktop versions work really well and quickly, making all the work and process flow smoothly and without setbacks. So far I have not been able to observe any inconvenience
It takes a long time for items to load if you are just generally searching through logs. It is best to use the data models which load faster but can be strange in terms of what is coming from which logs where. Yes, you can look it up, but this also requires familiarity with where things are and how to look them up.
I found their support community lacking in clarity when I experienced a login issue. The error messaging was poor on my Box Sync application. I did not reach out to support staff for help, instead, I reasoned that I should try downloading the Box Sync application again and reinstall it. That fixed my issue, thankfully. I think a less computer-savvy user would've been much more frustrated.
It's good when it's responsive, but I've had times where I had to wait quite a while for a response. But these are typically the exceptions rather than the rule. When you do get a response it is always well-informed and appropriate. I would say they've been trending better over time with this.
I experienced only on-line training, but the trainers were very professional and competent. Maybe it could be more useful if they also have an experience in projects because sometimes they didn't have a real project experience to communicate to the students. Anyway, it was very interesting and I learned many thing that's very difficoult (or maybe impossible!) to have by myself, aven if I have more than 10 years of Splunk activity experience.
The documentation is good. Since Box is a popular service, there were also a number of YouTube videos and other sources that were helpful as we were considering the product and planning for deployment. Also, the ability to try the free version helped to prepare us.
It was very interesting and I learned many thing that's very difficoult (or maybe impossible!) to have by myself. The only problem was that, when I worked with the Splunk Professional Services, I found some difference between the training contents and the information from PS. In addition is required a long experience on Splunk Enterprise for the data ingestion part, in other words I'm able to work with ES because I'm worling on Splunk since 11 years, otherwise I'd some problem.
Be careful with settings. It is easy to get overwhelmed with updates. For example, you don’t want to be updated when doing historical data uploads. I recommend taking off notifications initially and then turn on post you have done your historical data upload.
They are kind of the same. And both of them do their job as promised. But for company and project wise I think that Box slightly wins for some points. Which [makes him] win over Google Drive (don't forget that Google Drive is very easy to use and has a lot [of] nice features too).
Splunk enterprise is the only solution that we’ve been able to identify that provides risk based alerting, which allows our SOC to reduce analyst fatigue which would be a huge problem without it. Before RBA, there were thousands of alerts a day and it was impossible to review all of them
for my exterience, unit pricing and billing frequency are correct. As I already said, I hint to have more discount flexibility, expecially with new customers, because there are competitors less expensive and very aggressive that are dangerous. In addition the possibility to don't pay the license for the development period could be a very interesting feature for the final customers.
- 8 out of 10 and took 2 for the data pipeline and administration part. Even if you'd like to improve yourself or your team, you have to pay a lot of money and it could be more than GIAC education + cert. - Normalization for Data models and CPU-based searches can be a problem sometimes.
I had a fantastic experience with Splunk Professional Services: they worked with us in our last SON project (a SOC migration for a very large customer) and helped to build a multi tenent environment even if ES isn't a multi tenant platform. Th Splunk PS was a very professional and competent people, he is italian and was able to speak with our italian customers.
Box has been an only positive experience. It provides a seamless way for me and my team to collaborate on documents in such a way where we're not sending the document back/forth via email. It's a huge timesaver.
Box reduces the risk of sharing a sensitive document to the wrong person via email.
Box has provided a platform where my team can share notes in meetings - this has helped streamline and organize our meetings. Our meetings are more productive and actionable.
ES has highly impacted ROI because as the customer of the ES the work we do for creating use cases for clients in terms of security-related aspects by their logs has given more return than investment.
The correlation searches we run to get detailed results from the Data models are very less time-consuming than Splunk Enterprise itself we can get quick responses to the use cases and dashboards populated because of ES.
The CIM compliance feature is ES has made more jobs easy in the terms of finding more Authentication related data we can get data onboarded in the Email data model from O365 and search is email data model instead of searching for particular indexes.