Likelihood to Recommend
It is well suited in environments where there is a high mail traffic to handle. [Cofense] Vision basically journals the exchange server and keeps a copy of the mail received in the environment. Really beneficial to revoke and quarantine the mail reported by one user, but footprint is there in other mailboxes as well. Less appropriate in the cases where there is no proper segregation of duties within the organization. As it is possible to see contents of the mail. Only authorized personnel should be able to use it.
Read full review
Splunk Enterprise Security will be more suited in research dense areas, and also have a good scope in defense-related projects, cyber specialists, etc. It is less recommended for normal companies where the hosted application data do not require high-security environments. Also, this requires special admins to configure and monitor the logs effectively.
Read full review Pros AutoQuaratine prevents in advance and eliminates possible malicious emails from users' inboxes. [Cofense Vision] optimizes protection against any phishing attack. It is simple, friendly and easy to use. [Cofense Vision provides] super detailed analysis reports. Read full review Its best feature is its user interface, which is easy to navigate and understand. All you need is a little tutorial on how to use the Splunk query language and you're done. Logs can be easily uploaded or shared across multiple platforms and display a highly insightful graphical representations of data using graphs, tables, and many other formats. Read full review Cons Its cost can be somewhat high when it comes to a small business, so it is perfectly suited to medium or large companies. It can throw problems when it comes to migrating said tool in the different versions of an email. Its configuration is simple, but it is important to fully understand its operation to give adequate responses to possible threats. It would be ideal if it could be integrated with your platform. Read full review ES on the cloud (SaaS) has too many limitations with platform administration. Supported integrations are not always on par with enterprise support especially when dependent on 3rd-party proprietary APIs. In later versions, unforeseen glitches seem to show up that have no resolution except version upgrade. This used to not be the case in prior versions which were very stable. Read full review Likelihood to Renew
We are very happy with Splunk and would advise anyone to take a serious look at it. It might look pricey but the rewards Splunk offers seem endless.
Read full review Usability
You definitely need to learn how to use Splunk to get the most of the tool. There are many courses available for free to get up to speed on the usability of the tool but it's not that simple. It will take time to digest all the data and to understand how to query for what you are looking for.
Read full review Reliability and Availability
I'm not an ES user, but, in my implementation I usually try to prevent all service stops to guarantee High availability to the final customers.
Read full review Performance
ES requires a very performant infrastructure: if it has it's performant, otherwise not. I had situation with a very performant infrastructure and I didn't notized that it was a distributed architecture, it seemed that there ware few data on my PC, othewise I experienced less performant infrastructures with less performaces.
Read full review Support Rating
It's good when it's responsive, but I've had times where I had to wait quite a while for a response. But these are typically the exceptions rather than the rule. When you do get a response it is always well-informed and appropriate. I would say they've been trending better over time with this.
Read full review In-Person Training
I experienced only on-line training, but the trainers were very professional and competent. Maybe it could be more useful if they also have an experience in projects because sometimes they didn't have a real project experience to communicate to the students. Anyway, it was very interesting and I learned many thing that's very difficoult (or maybe impossible!) to have by myself, aven if I have more than 10 years of Splunk activity experience.
Read full review Online Training
It was very interesting and I learned many thing that's very difficoult (or maybe impossible!) to have by myself. The only problem was that, when I worked with the Splunk Professional Services, I found some difference between the training contents and the information from PS. In addition is required a long experience on
for the data ingestion part, in other words I'm able to work with ES because I'm worling on Splunk since 11 years, otherwise I'd some problem.
Read full review Implementation Rating
It's a fantatic product and it was very useful the presence of Splunk Professional Services for the Design Phase and the final Health Check.
Read full review Alternatives Considered
Apple of Discord is the pricing as we were looking for an email security tool in reasonable pricing and Barracuda was undoubtedly efficient in action and was compatible with our business but it was highly expensive and then we made up our mind for another tool and Cofense Vision was offering almost the same as Barracuda but cheaper.
Read full review
- Schema on the fly indexing --> Gives you faster index searches. Even if you use Datamodes, it's 100x time faster as well. - Correlation with other domains easily gives you total visibility and reduces the time to investigate and understand the problem. - With lookups and trust, you can easily ingest your TI platforms and look for backlog and real-time data. - Splunkbase - RBA is using unsupervised learning also, so it's not like Qradar or
. If we look at Qradar or
, they are giving some magnitude values with static rules and define incident levels with that. - Advanced investigation option and out-of-box security metrics tell you that where you are.
Read full review Contract Terms and Pricing Model
for my exterience, unit pricing and billing frequency are correct. As I already said, I hint to have more discount flexibility, expecially with new customers, because there are competitors less expensive and very aggressive that are dangerous. In addition the possibility to don't pay the license for the development period could be a very interesting feature for the final customers.
Read full review Scalability
Splunk Enterprise Security deployment is quite flexible which many deployment modes are available. Configuration and management can be centralized at the cloud console which is very convenient for administrators. With the cloud deployment, it can reduce the possibility of hardware failure which can have better uptime. Most of the configurations can be deployed easily from the management console.
Read full review Professional Services
I had a fantastic experience with Splunk Professional Services: they worked with us in our last SON project (a SOC migration for a very large customer) and helped to build a multi tenent environment even if ES isn't a multi tenant platform. Th Splunk PS was a very professional and competent people, he is italian and was able to speak with our italian customers.
Read full review Return on Investment Many Phishing attacks are identified and prevented in an instant. Classification of activity helps analysts search and find which emails pose a larger threat. User interface and learning is simple and easy to use. Read full review ES has highly impacted ROI because as the customer of the ES the work we do for creating use cases for clients in terms of security-related aspects by their logs has given more return than investment. The correlation searches we run to get detailed results from the Data models are very less time-consuming than Splunk Enterprise itself we can get quick responses to the use cases and dashboards populated because of ES. The CIM compliance feature is ES has made more jobs easy in the terms of finding more Authentication related data we can get data onboarded in the Email data model from O365 and search is email data model instead of searching for particular indexes. Read full review ScreenShots