TrustRadius: an HG Insights company

Splunk Cloud Platform

Score8 out of 10

156 Reviews and Ratings

What is Splunk Cloud Platform?

Splunk Cloud Platform is a data platform service thats help users search, analyze, visualize and act on data. The service can go live in as little as two days, and with an IT backend managed by Splunk experts.

Top Performing Features

  • Event and log normalization/management

    Ability to normalize event syntax so that logs can be compared and are machine-understandable

    Category average: 8.5

  • Centralized event and log data collection

    Effectiveness of real-time centralized event and log data collection

    Category average: 8.4

  • Custom dashboards and workspaces

    dashboards that can be customized to meet the needs of specific groups

    Category average: 8.6

Areas for Improvement

  • Response orchestration and automation

    Quality of built-in response orchestration and automation in Next-Gen SIEM

    Category average: 7.9

  • Deployment flexibility

    Ability to tune system to maximize threat detection and minimize false positives

    Category average: 7.7

  • Behavioral analytics and baselining

    How effectively activity and behavior baselines are established and maintained

    Category average: 8.2

Splunk Cloud Platform - a nice SIEM

Use Cases and Deployment Scope

We used it for logging all data and then feed all that data into some security models and used it as a SIEM.

Pros

  • Incredibly powerful and customizable.
  • Easy to ingest logs.
  • Built in dashboards are good.

Cons

  • Tedious to use at first.
  • Slightly outdated UI.
  • Sometimes slow.

Return on Investment

  • Hard to use, training takes a while.
  • Pricey for what you get.
  • Saves a lot of time when doing investigations.

Usability

Alternatives Considered

Microsoft Sentinel and Darktrace

Other Software Used

Microsoft Sentinel, SentinelOne Singularity

Splunk Cloud Platform assessment

Use Cases and Deployment Scope

The current use case is using Splunk Cloud Platform to look for cyber security threats. While there are other tools being used to look for cybersecurity threats. Splunk Cloud Platform has proven to be a reliable and trusted source.

It's also used monitor login attempts and watch traffic patterns and trends. Dashboards have long been used in this product and will continue.

Pros

  • Monitoring
  • Dashboards
  • Searching

Cons

  • Cost
  • Configuration
  • Maintenance

Return on Investment

  • Reduced MTTR by 25%
  • Preventing breaches justifies investment
  • High licensing costs
  • Need for skilled senior personnel to operate

Usability

Alternatives Considered

Datadog, Elastic Security and Microsoft Sentinel

Other Software Used

PagerDuty, Splunk SOAR, DataSet by SentinelOne, Zeek Network Security Monitor

Perfect fit for our needs in analyzing data

Use Cases and Deployment Scope

We are using Splunk Cloud Platform mainly for data quality management, especially for monitoring important interfaces and data insufficiencies.

Additionally, we use it to monitor automation performance of our Automation Suite, including 250 productice automations from various providers. Splunk Cloud Platform is great at identifying patterns where automations are failing, summarizing that information and enhancing it with context and sending it out to another tool carrying out the orchestration for us. With Splunk Cloud Platform, we also make sure to minimize maintenance pings by summarizing likewise events in one protocol.

Pros

  • Statistics
  • Pre built functions
  • Orchestration/Queue mgmt

Cons

  • Debugging
  • Third party integrations
  • Logon speed

Return on Investment

  • Increased time for value deriving tasks
  • More efficient maintenance and debugging processes
  • Overall increase in transparency on maintenance issues
  • Improved data quality and consistency

Usability

Alternatives Considered

Microsoft Power BI

Other Software Used

UiPath Automation Platform, Microsoft Power Automate, Celonis

One-size-fits-all indexed monitoring solution with stromg search capabilities

Use Cases and Deployment Scope

Splunk Cloud Platform is our near-real-time monitoring machine for observation of more than 200 automated systems. It indicates faulted processes, inefficiencies in operations and sends out webhook pings to our developers to fix these. Without Splunk Cloud Platform‘s search pricessing capabilities, we would never be able to cover all systems executions, screen logs for systematic errors and give direct advise on the fix.

Pros

  • Search processing
  • Indexing of fields (automatic and custom)
  • Performance

Cons

  • Debugging tools
  • Implementation of AI components
  • Third-party integrations

Return on Investment

  • Saved a lot of time on maintenance / observation
  • Professionalization of automation services
  • Improved reliance and time to fix

Usability

Alternatives Considered

Celonis and Microsoft Power Automate

Other Software Used

UiPath Automation Platform, Bizagi Digital Business Platform, Celonis

Best logging and Future SIEM tool

Use Cases and Deployment Scope

We use to be Splunk Enterprise customer but local storage for logs was challenging. Moving to cloud indirectly we have now unlimited storage and scale up easy when our requirements change.

Pros

  • Storage

Cons

  • Access over private links

Return on Investment

  • Meets our dynamic / constant expanding needs

Usability

Alternatives Considered

FortiAnalyzer

Other Software Used

IBM Security QRadar SIEM