Skip to main content
TrustRadius
Splunk Log Observer

Splunk Log Observer

Overview

What is Splunk Log Observer?

Splunk's Log Observer reduce time troubleshooting. The live Tail allows SREs and developers to filter and watch critical logs without having to learn a query language.

Read more
Recent Reviews

TrustRadius Insights

Splunk Log Observer has been widely used by a range of users to effectively monitor and investigate various logs, providing valuable …
Continue reading

Splunk Report.

8 out of 10
September 17, 2022
Incentivized
I used Splunk Log Observer for checking logs and debugging the development and production environment. I extensively used Splunk Log …
Continue reading
Read all reviews

Awards

Products that are considered exceptional by their customers based on a variety of criteria win TrustRadius awards. Learn more about the types of TrustRadius awards to make the best purchase decision. More about TrustRadius Awards

Return to navigation

Pricing

View all pricing

Entry-level set up fee?

  • No setup fee
For the latest information on pricing, visithttps://www.splunk.com/en_us/software/p…

Offerings

  • Free Trial
  • Free/Freemium Version
  • Premium Consulting/Integration Services

Starting price (does not include set up fee)

  • $6.25 per month per host
Return to navigation

Product Details

What is Splunk Log Observer?

Splunk Log Observer is a logging solution designed for DevOps. Splunk Log Observer enables DevOps teams to understand the “why” behind application behavior. Splunk Log Observer sets up in minutes and connects to the critical developer and SRE-oriented logs. Splunk Log Observer enables browsing and exploration of logs. And, with Splunk Log Observer Connect, existing Splunk Enterprise customers can now explore existing logs in Observability Cloud through the no-code interface for faster troubleshooting.

Splunk Log Observer Video

In this video, the TrustRadius team is going to share with you some of the top log data management tools: New Relic, Splunk Log Observer, and LogicMonitor. These tools are great for enterprise log management.

Splunk Log Observer Competitors

Splunk Log Observer Technical Details

Deployment TypesSoftware as a Service (SaaS), Cloud, or Web-Based
Operating SystemsUnspecified
Mobile ApplicationNo

Frequently Asked Questions

Splunk's Log Observer reduce time troubleshooting. The live Tail allows SREs and developers to filter and watch critical logs without having to learn a query language.

Splunk Log Observer starts at $6.25.

New Relic, Sumo Logic, and LogDNA are common alternatives for Splunk Log Observer.

The most common users of Splunk Log Observer are from Enterprises (1,001+ employees).
Return to navigation

Comparisons

View all alternatives
Return to navigation

Reviews and Ratings

(16)

Community Insights

TrustRadius Insights are summaries of user sentiment data from TrustRadius reviews and, when necessary, 3rd-party data sources. Have feedback on this content? Let us know!

Splunk Log Observer has been widely used by a range of users to effectively monitor and investigate various logs, providing valuable insights into their infrastructure. With the ability to handle both internal and cloud environments, users have found this product invaluable for troubleshooting issues with software. Whether it's monitoring servers, cloud instances, or API logs, Splunk Log Observer offers real-time system monitoring capabilities that aid in quick problem resolution.

One key feature that users have found particularly useful is the alert functionality of Splunk Log Observer. It allows for the detection of errors and code breaks, enabling teams to address them promptly. In addition, users have leveraged this product to build customized dashboards, facilitating the debugging process and improving overall efficiency.

While some users have encountered occasional slow response times with Splunk Log Observer, these issues were promptly addressed by escalating them to the Splunk team. Overall, this product has proven its effectiveness in handling technical operations in production data centers and cloud environments, aiding in log analysis, debugging, and trend detection. From monitoring security incidents to reporting errors and failures in applications, Splunk Log Observer has been a go-to solution for operational and support teams seeking detailed insights and efficient problem-solving capabilities.

Attribute Ratings

Reviews

(1-5 of 5)
Companies can't remove reviews or game the system. Here's why
September 17, 2022

Traipsing through data.

Score 9 out of 10
Vetted Review
Verified User
Incentivized
We use Splunk Log Observer to detect trends and to help solve problems if/when they occur. It also helps us with scheduling changes and maintenance based on load.
  • Handles big data.
  • Enables detailed search with queries.
  • Gives a visual as well as detailed information.
  • The query language isn't intuitive.
Splunk Log Observer is good for monitoring. If you don't have adequate logging in your code, Splunk doesn't help. So you need program skills/experience to make the most of Splunk.
  • None in particular.
  • Splunk is a part in our toolbox and helpful that way.
  • Not directly.
I had not considered other products because Splunk Log Observer was in use in my company before I started working there.
September 17, 2022

Splunk Report.

Score 8 out of 10
Vetted Review
Verified User
Incentivized
I used Splunk Log Observer for checking logs and debugging the development and production environment. I extensively used Splunk Log Observer alert, which helped me and my team to know if anything went wrong or unexpectedly broke the code with Exception. It is quite useful for debugging and involving team members to get alert and work towards that. We built the dashboard also using Splunk logs on Splunk Log Observer to ease debugging. But one business problem we used to face quite often with Splunk Log Observer with its response time. Sometimes, it used to become so slow to use. After escalating the problem with the Splunk team, it used to get fixed on half day time frame or sometimes full day time they used to take to fix the problem.
  • Easy debugging.
  • Dashboard support.
  • Can be extended to different AZ and environment easily.
  • Query based on different fields and timing.
  • Improvement in response time.
  • Quick resolve by Splunk in case of any issue.
  • Some improvement on UI.
  • Time zone based data search on timing params.
It is suitable for fast debugging and providing support. It is not suitable if you need all time fast response time log observer. Because sometimes, during critical debugging, it becomes quite slow to get data.
  • Query
  • Splunk Dashboard.
  • Alert & Notification.
  • Different AZ's and env support.
  • Quite positive if time works well and give logs on time.
  • Negative when it becomes slow in critical timing. It impacts the business as it takes more time to get the root cause of undesirable output from code.
We believe that it's less vulnerable to security aspects as compared to others.
Giuseppe Cusello | TrustRadius Reviewer
Score 10 out of 10
Vetted Review
Verified User
Incentivized
I'm implementing and implementing log Observability solutions based on Splunk for some of our customers.
  • Monitor infrastructures to identify problems or anomalies.
  • Business insights.
  • Security monitoring.
  • Business Insights (this is a feature not usually implemented).
  • Infrastructure monitoring.
  • Service chain monitoring.
  • Security monitoring.
We used it many times and for many customers for infrastructure monitoring. For some of them, we implemented a monitoring cockpit for business insights and specialized cockpits for managers and executives.
  • The possibility to have in one console information from etherogenous systems
  • Turn key features to monitor infrastructures and services through the Service chain monitoring
  • The customers can have views specialized for different levels (analysts, operators, managers, executives, etc...)
  • They can have one console to have information from many heterogeneous data sources.
Splunk requires less work for data in gestion and parsing. Splunk has more efficient data display features.
5
Consulting and system integration.
5
Product Specialists, Consultants, and Architects.
  • Internet banking business insight.
  • Infrastructure monitoring.
  • Security Asset Management.
  • Anti Fraud Reporting.
  • We implemented an holistic approach to data presentation using Splunk.
  • We'd like to improve the actual business insight features.
  • We continue to integrate Splunk with other platforms.
I'm a Splunk specialist, and I'm involved in its use and improvement.
Yes
In the past, we replaced HP Arcsight and RSA Security Analytics, but more for Security Use Cases. But in our vision, observability and Security and strictly integrated.
  • Product Features
  • Product Usability
  • Product Reputation
  • Prior Experience with the Product
We know Splunk very well. Splunk has fantastic features for data indexing and integration.
No, no change!
  • Implemented in-house
Yes
Data ingestion and normalization. Service Chains definition. Use Cases Analysis. Existing Correlation Searches analysis and activation. Correlation Searches customization or design and development.
Change management was a minor issue with the implementation
Mainly ITSI or other implementations map the existing organizations and try to adapt to them.
  • First, implementation wasn't so easy because it required a deep knowledge of the features, then they were easier.
Follow a training before starting.
Splunk support is very quick and efficient. Pre-sale specialists are very skilled and available.
We are skilled in our activities, but sometimes we use it for a certification requested by some customers. And they were very professional.
No
Our first implementation of ITSI was supported by Splunk Professional Services: they were ready to analyze the situation, and they shared their competencies with us.
It gives access to data features for every level of users: from managers and executives to Analysts, each one with the correct level of observation and analysis.
  • Service chain.
  • Drilldown features from aggregated data to analytic views.
  • It isn't so easy to customize, it requires a deep knowledge.
Score 9 out of 10
Vetted Review
Verified User
Incentivized
We utilized Splunk Log Observer to handle technical operations for our production on-premise data centers and cloud instances. We switched to this product since our company needed a solution that allowed for real-time system monitoring. Our overall experience with this product has been incredibly positive.
  • User-friendly interface.
  • Real-time system monitoring.
  • Customized Dashboard for different use cases.
  • Limited API functionality.
  • Cloud version Splunk does not offer integration compared to that of the on-premise one.
Fixing, enhancing, and optimizing our program application has never been easier, but Splunk has improved it to the point where it now analyses our production projects in actuality and provides us with the elements and causes of any errors so that we can address them before they cause us permanent damage. Splunk Log Observer is one of the most expensive platforms, and it is best suited for a large organization with a more user base. This product is highly scalable due to its big data architecture. If you are a small/medium organization, this product may not be a good fit.
  • Dashboard
  • Extensive search options thru its own language called Splunk processing language (SPL).
  • Scalability
  • Significantly reduced the MTTR (Mean Time To Recovery), which in turn has improved the end-user experience tremendously.
  • Meets compliance requirements of security policies, audit, regulation, and forensics.
  • Helps us to track/manage the resource usage on our cloud instances which has a direct implication on the recurring cost.
Sumologic.
September 09, 2022

Splunk log Observer Review

Mayank Thirani | TrustRadius Reviewer
Score 7 out of 10
Vetted Review
Verified User
Incentivized
Splunk Log Observer provides good alerting system. It provides Critical alerts and monitor the system accordingly keeping the logs.
  • Triggered Critical Alert
  • Log observer in detailed view
  • Infrastructure Monitoring
  • Integrating the system with Slack channels
  • Saving the logs in different cloud provider
  • Viewing the logs at more fine grained level based on user roles and permissions
Well suited scenarios:
Whenever we would like to monitor the infrastructure (small or big), this elastic search log observer provides the detailed view of logs at different levels and triggers the alert accordingly.
Less appropriate scenarios:
When a specific user privilege wants to see the logs only at one level (not deep dive), it does not provide that fine grained permission.
  • Alerting system
  • Infrastructure Monitoring
  • Setting up Splunk Synthetic monitoring to configure performance tests, notifications
  • Finding and fixing problems quickly with Log Observer
  • Logs access quickly to gather more data and verify the data ingestions
  • Able to understand what application performance monitoring is and alerts our infrastructure easily
Splunk Log Observer provides easy setup and ease of admin features and direction of product was better compared to Lightstep
Return to navigation