Overview
What is Splunk Cloud?
A data platform service thats help users search, analyze, visualize and act on data. The service can go live in as little as two days, and with an IT backend managed by Splunk experts, users can focus on acting on…
Security Excellence and IT Ops Insights at your fingertips in a single place
Splunk Cloud - king of log ingest
TrustRadius Insights
Splunk Cloud - Excellent product with steep learning curve
It is an effective tool that enables us to detect, analyze, and respond to threats more effectively
Good app monitoring data platform
Splunk Cloud, good for cloud-first companies.
Splunk Cloud provides quick and easy access to important metrics and logs!
Splunk Cloud: Find the needle in your haystack of data
A solid security and monitoring tool
Splunk Cloud is a great solution for SIEM
Powerful and versatile
Heavy Hitter SIEM!
Splunk Cloud -- A tool that helps monitor and solve problems.
Popular Features
- Event and log normalization/management (15)9.797%
- Correlation (15)9.797%
- Centralized event and log data collection (15)9.090%
- Deployment flexibility (15)9.090%
Reviewer Pros & Cons
Pricing
What is Splunk Cloud?
A data platform service thats help users search, analyze, visualize and act on data. The service can go live in as little as two days, and with an IT backend managed by Splunk experts, users can focus on acting on data. Search any kind of data in real-time to detect and prevent issues before they…
Entry-level set up fee?
- No setup fee
Offerings
- Free Trial
- Free/Freemium Version
- Premium Consulting/Integration Services
Would you like us to let the vendor know that you want pricing?
13 people also want pricing
Alternatives Pricing
What is Trellix Helix?
Trellix Helix (formerly FireEye Helix) is a SIEM solution providing a non-malware threat detection solution.
Product Demos
UiPath Robotic Process Monitoring for Splunk - Demo Walkthrough
Splunk Risk-Based Alerting Demo: Using MITRE ATT&CK + Enterprise Security (ES)—@Splunkofficial Cloud SecOps
Features
Security Information and Event Management (SIEM)
Security Information and Event Management is a category of security software that allows security analysts to look at a more comprehensive view of security logs and events than would be possible by looking at the log files of individual, point security tools
- 9Centralized event and log data collection(15) Ratings
Effectiveness of real-time centralized event and log data collection
- 9.7Correlation(15) Ratings
Correlation of logs and events to pinpoint significant threats
- 9.7Event and log normalization/management(15) Ratings
Ability to normalize event syntax so that logs can be compared and are machine-understandable
- 9Deployment flexibility(15) Ratings
Ability to tune system to maximize threat detection and minimize false positives
- 9.3Integration with Identity and Access Management Tools(13) Ratings
Integration with access control tools like Active Directory and LDAP
- 9.7Custom dashboards and workspaces(15) Ratings
dashboards that can be customized to meet the needs of specific groups
- 8.7Host and network-based intrusion detection(13) Ratings
Ability to detect both endpoint intrusion and network ingress detection
- 8.7Data integration/API management(5) Ratings
Ease and quality of data integrations between SIEM and other systems
- 9Behavioral analytics and baselining(4) Ratings
How effectively activity and behavior baselines are established and maintained
- 8.3Rules-based and algorithmic detection thresholds(6) Ratings
Effectiveness of manually-established rules and algorithmically-determined detection thresholds
- 8Response orchestration and automation(4) Ratings
Quality of built-in response orchestration and automation in Next-Gen SIEM
- 8.7Reporting and compliance management(6) Ratings
Ease and quality of reporting and compliance functions
- 9.3Incident indexing/searching(6) Ratings
Effectiveness of searching across structured and unstructured events and incidents within SIEM
Product Details
- About
- Competitors
- Tech Details
- FAQs
What is Splunk Cloud?
Splunk Cloud Competitors
Splunk Cloud Technical Details
Operating Systems | Unspecified |
---|---|
Mobile Application | No |
Frequently Asked Questions
Comparisons
Compare with
Reviews and Ratings
(123)Community Insights
- Business Problems Solved
- Pros
- Cons
Splunk Cloud is highly regarded for its efficient customer support and comprehensive services. Users appreciate its ability to perform security information and event management, providing real-time analysis. One of the standout features of Splunk Cloud is its user-friendly interface that allows users to create easily customizable dashboards and conveniently share them with others. The product has gained a reputation for being fast, reliable, and easy to navigate.
The versatility of Splunk Cloud makes it an invaluable tool across various departments within organizations. For the IT department, it helps monitor devices that generate logs, enabling them to address log retention and conduct security investigations. Moreover, Splunk Cloud is widely used throughout businesses to solve a range of problems, such as monitoring Active Directory Events, identifying misconfigurations, excessive usage, improper procedures, and security events. Additionally, teams including DevOps, Security, sales, support, and operations benefit from Splunk Cloud's capabilities as it centralizes server logs and provides insights into interruptions in service, anomalous activities, and security-related events.
Splunk Cloud eliminates the need to host infrastructure and pay upfront licensing costs by delivering Splunk-as-a-Service securely on the public cloud. It supports all Splunkbase apps, including premium applications with pre-packaged searches, dashboards, and reports. This makes it easier for businesses to log user events in mobile applications and backend services while gaining visibility into key metrics through comprehensive reports and dashboards.
A significant use case of Splunk Cloud lies in its role as a SIEM solution for aggregating log data and generating alerts when necessary. It replaces less robust solutions for enhanced security measures. Moreover, Splunk Cloud proves valuable in providing visibility into cloud infrastructure and various providers. It aids in identifying anomalies, events of interest, and indicators of compromise.
Overall, Splunk Cloud presents itself as an indispensable tool that offers a wide range of use cases across different departments within an organization. Its powerful features, efficient support, and user-friendly interface make it a popular choice for businesses seeking effective log management, security analysis, and real-time monitoring.
Effective SIEM Solution: Users have found Splunk Cloud to be a simple and effective solution for consolidating multiple data points and managing alert workflows. Several reviewers have mentioned that it has helped them streamline their security operations and improve incident response.
User-Friendly Interface: The user-friendly interface of Splunk Cloud has been praised by many users, with some describing it as intuitive and easy to navigate. This allows users to easily create custom dashboards for everyday monitoring of multiple parameters without the need for extensive training or technical expertise.
Powerful Search Capabilities: Many reviewers have highlighted Splunk Cloud's powerful query language and fast search indexing capabilities. This enables quick and accurate searching through large volumes of information, such as Windows Server Logs, making it easier for users to find the insights they need in a timely manner.
Cons:
- Lagging behind competitors: Some users have expressed that Splunk Cloud lags behind its competitors in terms of features and functionality. They feel that the enterprise versions are always one version behind the consumer versions, which hinders their ability to take advantage of the latest enhancements and improvements.
- Expensive cost: The cost of Splunk Cloud is considered expensive compared to its competitors. Users would like to see more cost-effective pricing options that align with their budget constraints and provide better value for money.
- Complex query language: The SPL programming language used for queries in Splunk Cloud is not intuitive, according to users. They find it challenging to write complex queries efficiently and would appreciate a better repository of pre-built queries for common usage monitoring, making it easier for them to analyze data without extensive knowledge of coding.
Attribute Ratings
Reviews
(1-15 of 15)Splunking Great.
- Dashboarding
- Data Selection and Processing.
- Ingestion Techniques.
- Easier Plugin Creation.
- Free Tier Cloud.
- Query Language Builder.
- Easy to get data in
- Rich user experience
- Wide range of Splunk & Community add-ons
- Unable to download configuration changes easily
Splunk Cloud - king of log ingest
Using Splunk Cloud simplifies the solution as we do not have to maintain and manage infrastructure.
- Log ingest / parsing
- role based access to specific logs
- log event searching
- alerts and dashboards
- Filter of incoming logs from cloud sources - needs drastically improved UI
- Mission Control - nice concept, not there in implementation
- Searching through logs/data
- Data ingestion
- Documentation for add-ons and apps
- Support for Splunk Cloud
If you only have one data source (syslog from network devices for example) I would say it is less appropriate and would be overkill.
It is an effective tool that enables us to detect, analyze, and respond to threats more effectively
- This SIEM consolidates multiple data points and offers several features and benefits, creating custom dashboards and managing alert workflows.
- Splunk Cloud provides a simple way to have a central monitoring and security solution. Though it does not have a huge learning curve, you should spend some time learning the basics.
- Splunk Cloud enables me to create and schedule statistical reports on network use for Management.
- Splunk Cloud generally lags behind its competitors. Enterprise versions are always one version behind those available to consumers.
- It is expensive as compared to its competitors. They should come up with cost-effective prices.
Good app monitoring data platform
Since we have multiple environments, it's very convenient to stream all logs/metrics into Splunk Cloud, and see them from one centralized place.
- Display log events in a very nice way for humans to read
- Very easy and powerful to create dashboards
- Very fast and reliable
- Since it's a managed cloud service, it doesn't offer the capability to edit the config files directly. So if the web UI doesn't support something, we can't change it.
From a cost perspective, it's not the cheapest one in the market.
Splunk Cloud, good for cloud-first companies.
- Integration with Okta for IAM-related security events and monitoring.
- Integration with AWS for CloudTrail and CloudWatch logs
- Integration with Mimecast for email monitoring and integration
- Deploying apps require a support ticket and can have a long turnaround time.
- Making changes to conf files requires a ticket and if it's not through an approved process, then Puppet will reset it to what it was previously
- Custom apps have to be very well written to make it through the approval process.
- Excellent dashboards that provide a quick view of important data.
- Easy to create dashboards.
- Filtering within the dashboards provides updated dashboards quickly.
- Exporting is easy.
- While the dashboards are intuitive, setting them up isn't always as easy. A more intuitive interface would help ensure all users can easily set up dashboards to get the information they need.
- Excellent tool for correlating logs from hundreds of servers and digging into events for a specific time period.
- Based on issues found Splunk allows for simple and complex monitoring to alert when the same event or problem is seen again.
- Advanced dashboard tools allow for unique and creative perspectives on how to display data in ways relevant to each department in our organization.
- Some of their more advanced features, like ITSI, Machine Learning, or Security Analytics, can be very challenging to setup and configure.
- Splunk Cloud support has been a challenge in the past. They are getting better, but they have had problems responding in a timely manner to issues.
- These are only some minor observations of things I have had to deal with. In general, Splunk is a solid product that is fantastic to use.
A solid security and monitoring tool
- Ease of use.
- There is not a big learning curve.
- It could be cheaper.
Splunk Cloud is a great solution for SIEM
Data is the new Oil!!
- With Splunk Cloud you get the advantage of moving from POC to Production in a matter of days rather than in months allowing the Business to gain a lot.
- Takes you away from managing infrastructure/administration, allows saving time & money. Reduce the overall TCO (Total Cost of Ownership)
- Move from Reactive to Proactive Monitoring
- Highly secure environment at your finger-tips
- I can see that Splunk Cloud can still improve in the form of SLA.
One shouldn't use Splunk Cloud for learning or testing purpose. Such things can be done or fulfilled by Splunk Enterprise as well and would be way cheaper then Splunk Cloud.
Powerful and versatile
- Powerful query language.
- Very fast search indexing.
- Intuitive UI.
- The query language is well-documented but has a bit of a learning curve.
- I wish copy/pasting JSON from the logs were easier without going to the completely raw (condensed) form.
Heavy Hitter SIEM!
- Splunk is extremely versatile and can consume just about any kind of log out there.
- Splunk's search function is very powerful, and allows for some very complex search criteria. Narrowing and/or expanding search results is as simple as a click of the mouse.
- There are many different apps/plugins that can be added to Splunk that provide built-in reporting and alerting on certain kinds of events, meaning you don't have to be an expert to use Splunk.
- There is a bit of a learning curve to figure out how to initially use it.
- When SAML is set up, there is no apparent way to log out.
- Splunk Cloud allows me to search the volumes of information help in Windows Server Logs quickly and accurately.
- Splunk Cloud allows me to create Dashboards for everyday monitoring of multiple parameters.
- Splunk Cloud allows me to create and schedule reports for Management on network usage and statistics.
- The SPL programming language that the queries are built in is not very intuitive.
- There should be a better repository of pre-built queries for what I would think of as common Active Directory usage monitoring.
- I would like to see more free training/familiarization information made available.