Likelihood to Recommend It has been brilliant for us in terms of understanding the behaviour affecting our endpoints and assets. We have full visibility of our alerts, which menas we can act on them immediately. We use a single pain of glass with dashboards that can be easily drilled down into to get further information. It has laso helped us eo create bespoke reports for senios Managmeent, while at the same time supports other teams like Network Mnagement and Operations.
Read full review Splunk is excellent when all your data is in one location. Its ability to correlate all that data is intuitive (once the hurdle of learning the query language is overcome). It is also easy to standardize the presentation of information to the company. When data is siloed/standalone, other systems can be cheaper and faster to implement.
Read full review Pros Rapid7 InsightIDR does a very good job at keeping virus definitions up to date so that our threat intelligence is very up to date when knowing what to protect against. It helps us by scanning all of our infrastructure components and highlights where improvements need to be made in security so we can be proactive with our security initiatives. It has automated response mechanisms to triage and resolve any potentials risks allowing us to save time in the long run. Read full review This SIEM consolidates multiple data points and offers several features and benefits, creating custom dashboards and managing alert workflows. Splunk Cloud provides a simple way to have a central monitoring and security solution. Though it does not have a huge learning curve, you should spend some time learning the basics. Splunk Cloud enables me to create and schedule statistical reports on network use for Management. Read full review Cons Sometimes Rapid7 InsightIDR will be too locked down and without knowing will block applications and processes needed for day to day operation. System scans with Rapid7 InsightIDR can be very bandwidth-heavy on the network and system resources. From a recent incident, we have seen more and more false positives from Rapid7 InsightIDR on areas that we know are secure. Read full review The SPL programming language that the queries are built in is not very intuitive. There should be a better repository of pre-built queries for what I would think of as common Active Directory usage monitoring. I would like to see more free training/familiarization information made available. Read full review Usability Overall, it is very usable. I would like if recent searches were saved for longer because I always have to refer to my notes when I'm looking for something specific and it's been a few weeks. But that's a small issue, and the actual search and browsing interface is easy to use and powerful.
Read full review Support Rating Splunk Cloud support is sorely lacking unfortunately. The portal where you submit tickets is not very good and is lacking polish. Tickets are left for days without any updates and when chased it is only sometimes you get a reply back. I get the feeling the support team are very understaffed and have far too much going on. From what I know, Splunk is aware of this and seem to be trying to remedy it.
Read full review Alternatives Considered The biggest advantage it has the lightweight agent and smooth and less traffic chaos in network during log collection. Cloud Security always require extra efforts but InsightIDR reduce that burden as it has highly anticipated agents to which knows what they need to do when they captured malicious traffic.log collection and threat intelligence is major part in and xdr and here it stand out along others in the market, I started my career as qualys administration but I like InsightIDR much now.
Read full review Splunk Cloud blows
Sumo Logic out of the water. The experience is night and day. We went from several highly stressed IT security professionals who were unsure if the data they were getting was valuable, to very happy IT security professionals who can now be more proactive and get all the information they need.
Read full review Return on Investment Rapid7 InsightIDR has allowed us to be proactive in securing our systems as the vulnerability scans give us a lens at what we need to fortify when it comes to security. In recent incidents its allowed us to save time and money as it mostly detects issues accurately and we are able to bring systems back quickly without too much downtime for the business. With recent updates, we are confident that Rapid7 InsightIDR is a good solution for the long run as they are always making adjustments to their platform and improving it with every release. Read full review End-end visibility across your departmental silos Strengthen the overall global monitoring posture Move from Reactive to Proactive Monitoring Highly secure environment at your finger-tips Takes you away from managing infrastructure/administration, allows saving time & money. Reduce the overall TCO (Total Cost of Ownership) Read full review ScreenShots