Splunk Enterprise Review Insights

Score8.6 out of 10

560 Reviews and Ratings

Back to Reviews

Insights from Splunk Enterprise Reviewers

Based on 37 verified reviews published in the last 18 months

What other products like Splunk Enterprise have you used or evaluated?

37 answered

Reviewers evaluating Splunk Enterprise have also considered a range of alternative solutions, primarily focusing on security information and event management (SIEM) and observability platforms. These categories represent the most frequently cited alternatives, each mentioned by 8% of reviewers. The competitive landscape includes established SIEM solutions such as IBM Security QRadar and Securonix, indicating that organizations often compare Splunk's capabilities against dedicated security analytics platforms. Similarly, observability platforms like Dynatrace and Datadog are frequently evaluated alongside Splunk, suggesting a need for comprehensive monitoring across diverse IT environments. A smaller segment of reviewers, 5%, also reported experience with messaging queue technologies like Apache Kafka, which can be used for data ingestion similar to some Splunk functionalities. Additionally, cloud-focused observability tools, including Elastic Observability and Splunk AppDynamics, were mentioned by 5% of the review base, highlighting the increasing importance of cloud-native monitoring in their evaluations. The overall sentiment regarding these alternative products is mixed, reflecting the diverse experiences and specific use cases that drive product selection.

SIEM Solutions

3 mentions

Reviewers frequently consider dedicated SIEM platforms as alternatives or complementary tools to Splunk Enterprise, ref…

Reviewers frequently consider dedicated SIEM platforms as alternatives or complementary tools to Splunk Enterprise, reflecting a need for robust security information and event management capabilities. These comparisons often involve industry leaders like IBM Security QRadar and Securonix, suggesting a focus on advanced threat detection and compliance reporting.

Observability Platforms

3 mentions

A notable portion of the review base, 8%, also evaluates comprehensive observability platforms in conjunction with or a…

A notable portion of the review base, 8%, also evaluates comprehensive observability platforms in conjunction with or as alternatives to Splunk Enterprise. These platforms, including Dynatrace and Datadog, are typically considered for their capabilities in application performance monitoring, infrastructure monitoring, and log management, overlapping with Splunk's operational intelligence strengths.

Messaging Queues

2 mentions

Some reviewers, representing 5% of the sample, have experience with messaging queue systems such as Apache Kafka and Ra…

Some reviewers, representing 5% of the sample, have experience with messaging queue systems such as Apache Kafka and RabbitMQ. These technologies are often used for high-throughput data ingestion and stream processing, which can be part of a larger data pipeline that might also integrate with or feed into a platform like Splunk.

Cloud Observability

2 mentions

Cloud-specific observability tools, mentioned by 5% of reviewers, are also part of the evaluation landscape, indicating…

Cloud-specific observability tools, mentioned by 5% of reviewers, are also part of the evaluation landscape, indicating a growing emphasis on monitoring cloud-native environments. Products like Elastic Observability and Splunk AppDynamics are considered for their specialized capabilities in tracking performance and security within cloud infrastructures.

What are the 3-5 most important use cases for this product in your organization?

37 answered

Reviewers primarily utilize this product for operational intelligence, with a strong focus on log management and real-time incident response. A significant portion of the feedback, cited by 14% of reviewers, highlights the product's effectiveness in log analysis and monitoring, including the collection and ingestion of logs from critical applications and servers. Closely related, an equal proportion of reviewers, 14%, emphasize its utility for alerting and notifications, particularly for creating alerts based on log data to detect cybersecurity risks and monitor application health. Beyond these core functions, the product also serves specialized security use cases, such as SOC detection and firewall rule analysis, as noted by 5% of the reviews. Additionally, 5% of reviewers find the product valuable for application troubleshooting and ensuring application availability, leveraging its data insights to diagnose and resolve performance issues.

Log Analysis and Monitoring

5 mentions

Reviewers frequently use the product for comprehensive log management, including the collection, ingestion, and analysi…

Reviewers frequently use the product for comprehensive log management, including the collection, ingestion, and analysis of logs from various applications. This capability is crucial for understanding system behavior and maintaining operational oversight, as noted by 14% of reviewers. Users value its ability to keep and analyze logs from sensitive applications.

Alerting and Notifications

5 mentions

The product is highly valued for its real-time alerting capabilities, allowing organizations to create actionable notif…

The product is highly valued for its real-time alerting capabilities, allowing organizations to create actionable notifications based on log data. This functionality is particularly important for proactive issue detection, including cybersecurity threats and application performance anomalies, as highlighted by 14% of reviewers. Users leverage it for application alerting and KPI-based issue detection.

Security Use Cases

2 mentions

Beyond general alerting, reviewers specifically leverage the product for dedicated security operations, such as Securit…

Beyond general alerting, reviewers specifically leverage the product for dedicated security operations, such as Security Operations Center (SOC) detection. Its analytical features aid in identifying potential threats and analyzing network activity for security purposes, a use case mentioned by 5% of the reviews. This includes activity analysis for firewall rules.

Application Troubleshooting

2 mentions

The product assists organizations in diagnosing and resolving issues within their application environments. Reviewers f…

The product assists organizations in diagnosing and resolving issues within their application environments. Reviewers find it beneficial for application troubleshooting and ensuring continuous availability, providing insights that help maintain system performance, as indicated by 5% of the feedback. This helps in maintaining overall application health.

What are some additional ways that your organization might be able to use Splunk Enterprise in the future?

37 answered

Reviewers anticipate expanding the utility of Splunk Enterprise into several key areas to enhance operational efficiency and data leverage. A small number of reviewers, representing 8% of the sample, foresee significant opportunities in AI and Automation, particularly for streamlining security tasks and data management. Additionally, 5% of reviewers identified potential for advanced Data Integration with other enterprise tools to enrich analytics and reporting. A similar proportion of reviewers, 5%, also noted future applications in Observability, suggesting a desire to broaden monitoring capabilities, though some indicated current limitations in log integration.

AI and Automation

3 mentions

A small but notable segment of reviewers, 8% of the sample, envisions significant future applications for AI and automa…

A small but notable segment of reviewers, 8% of the sample, envisions significant future applications for AI and automation within Splunk. These include advanced threat hunting capabilities, utilizing AI for proactive data monitoring, and automating the onboarding of new applications to reduce manual development effort.

Observability

2 mentions

Some reviewers express interest in leveraging Splunk for enhanced observability features in the future. This indicates…

Some reviewers express interest in leveraging Splunk for enhanced observability features in the future. This indicates a desire to extend Splunk's monitoring capabilities beyond traditional logging, though one reviewer noted that current integration with logs might require further development.

Data Integration

2 mentions

Reviewers also see potential for deeper data integration with other organizational tools, representing 5% of the feedba…

Reviewers also see potential for deeper data integration with other organizational tools, representing 5% of the feedback. Specific suggestions include integrating with audit tools for direct reporting and enriching data from platforms like ServiceNow with Splunk's hit count information.

What are some unexpected or innovative ways that your organization has been able to use Splunk Enterprise?

37 answered

Reviews indicate that organizations are extending Splunk Enterprise's capabilities beyond traditional use cases, leveraging it for innovative data management and operational insights. A notable emerging pattern, cited by 5% of reviewers, involves using Splunk as a conduit for data export to cloud storage platforms like AWS, transforming and securing log data. Similarly, 5% of reviewers highlighted its integration with other enterprise tools, such as ServiceNow and ITSM platforms, to automate incident generation and team notifications. Another unexpected application, also mentioned by 5% of reviewers, is the monitoring of non-IT related data, suggesting a broader applicability for the platform's analytical capabilities beyond its core IT operations and security functions. These instances collectively point to Splunk Enterprise being adapted for diverse organizational needs, acting as a flexible data pipeline and monitoring solution.

Data Export to AWS

2 mentions

Reviewers have found an innovative use for Splunk Enterprise by employing it as an intermediary for exporting processed…

Reviewers have found an innovative use for Splunk Enterprise by employing it as an intermediary for exporting processed data to Amazon Web Services (AWS) for long-term storage. This approach, noted by 5% of reviewers, allows organizations to leverage Splunk's monitoring and transformation capabilities before securely archiving logs in cloud storage solutions like S3. This extends Splunk's role from purely an analysis tool to a component within a broader data lifecycle management strategy.

Integration with Other Tools

2 mentions

Organizations are integrating Splunk Enterprise with other critical business tools to enhance operational efficiency an…

Organizations are integrating Splunk Enterprise with other critical business tools to enhance operational efficiency and incident response workflows. Cited by 5% of reviewers, this integration often involves connecting Splunk with platforms like ServiceNow and other IT Service Management (ITSM) systems. The primary benefit is the automated generation of incidents and notifications to relevant teams based on alerts triggered within Splunk, streamlining the resolution process.

Monitoring Non-IT Data

2 mentions

An unexpected application of Splunk Enterprise, mentioned by 5% of reviewers, is its use for monitoring data that falls…

An unexpected application of Splunk Enterprise, mentioned by 5% of reviewers, is its use for monitoring data that falls outside traditional IT infrastructure. Reviewers reported using the platform to track non-IT related metrics, such as monitoring 'wastes' or 'drops.' This demonstrates Splunk's adaptability as a general-purpose data analysis engine, capable of providing insights into diverse operational areas beyond its conventional scope.

What positive or negative impact (i.e. Return on Investment or ROI) has Splunk Enterprise had on your overall business objectives?

37 answered

Splunk Enterprise significantly contributes to organizational objectives primarily through enhanced operational efficiency and robust security capabilities. Reviewers frequently highlight its ability to enable faster identification and resolution of issues, a benefit cited by 32% of the reviews. This capability is often linked to substantial reductions in Mean Time To Resolution (MTTR) and improved root cause analysis, saving significant operational hours. The platform also bolsters overall system oversight, with 14% of reviewers noting improved monitoring and visibility across diverse systems. Furthermore, Splunk Enterprise is recognized for providing valuable data analysis and insights, mentioned by 11% of reviewers, which aids in applying specific business logic and understanding application performance. Its role in detecting and responding to security incidents, including identifying breaches and correlating threats, is also a key positive impact, noted by 8% of the feedback. However, a notable concern affecting return on investment is the high cost associated with Splunk Enterprise, particularly its licensing model, which was raised by 14% of reviewers, indicating that while the benefits are substantial, the financial outlay can be a significant consideration.

Faster issue identification and resolution

12 mentions

Reviewers consistently report that Splunk Enterprise significantly accelerates the process of identifying and resolving…

Reviewers consistently report that Splunk Enterprise significantly accelerates the process of identifying and resolving operational issues, leading to improved operational excellence. This includes quicker troubleshooting, faster root cause analysis, and reduced downtime, with some users noting substantial time savings for their teams.

Improved Monitoring and Visibility

5 mentions

Many reviewers appreciate Splunk Enterprise's ability to enhance monitoring capabilities, providing greater observabili…

Many reviewers appreciate Splunk Enterprise's ability to enhance monitoring capabilities, providing greater observability across various systems and applications. This centralized log and machine data collection improves the overall understanding of system health and performance.

Cost and Licensing Concerns

5 mentions

A significant concern among reviewers revolves around the high cost associated with Splunk Enterprise, particularly its…

A significant concern among reviewers revolves around the high cost associated with Splunk Enterprise, particularly its licensing model. The ingestion-based pricing structure is frequently cited as a challenge, leading to high total cost of ownership as data volume increases.

Data Analysis and Insights

4 mentions

Reviewers find Splunk Enterprise highly effective for data analysis, enabling organizations to derive valuable business…

Reviewers find Splunk Enterprise highly effective for data analysis, enabling organizations to derive valuable business insights from their collected data. The platform's custom dashboard capabilities allow for the application of specific company logic, enhancing strategic decision-making.

Security Breach and Incident Detection

3 mentions

Splunk Enterprise is valued for its critical role in enhancing an organization's security posture, specifically in dete…

Splunk Enterprise is valued for its critical role in enhancing an organization's security posture, specifically in detecting security breaches and correlating various security events. This capability helps in identifying and responding to threats like password spray attacks and other malicious activities.

Besides Splunk Enterprise, what other software do you regularly use? How likely would you be to recommend it to a friend or colleague?

37 answered

Reviewers frequently utilize a diverse array of software alongside Splunk Enterprise, primarily focusing on enhancing monitoring, cloud infrastructure management, development workflows, and security operations. Monitoring and observability tools are the most commonly mentioned category, cited by 19% of reviewers, indicating a strong need for comprehensive system oversight beyond Splunk's core capabilities. Cloud platforms and services also feature prominently, with 14% of reviewers noting their use of major providers like AWS and Azure for infrastructure and application deployment. Development tools and platforms, including version control and CI/CD systems, are used by 11% of the review sample to streamline software creation and deployment. An equal percentage of reviewers, 11%, integrate specialized security and threat detection software to bolster their defensive postures. While most categories reflect a mixed sentiment due to the variety of tools mentioned, a smaller segment of 5% of reviewers expressed positive experiences with specific Cisco products, highlighting their reliability and integration.

Monitoring and Observability

7 mentions

Reviewers frequently integrate a range of monitoring and observability tools to complement Splunk Enterprise, with this…

Reviewers frequently integrate a range of monitoring and observability tools to complement Splunk Enterprise, with this category being the most cited by 19% of the sample. The diverse tools mentioned, such as Datadog, Dynatrace, and New Relic, suggest a need for specialized insights into application performance, infrastructure health, and log analysis that may extend beyond their primary Splunk usage. This indicates a preference for a multi-tool approach to achieve comprehensive operational visibility.

Cloud Platforms and Services

5 mentions

Cloud platforms and services are regularly used by 14% of reviewers, indicating a significant reliance on external infr…

Cloud platforms and services are regularly used by 14% of reviewers, indicating a significant reliance on external infrastructure and platform solutions in conjunction with Splunk. Reviewers mentioned major providers like Google Cloud Platform, AWS, and Azure Cloud Services, suggesting that these environments are central to their IT operations and application deployment strategies. The integration of these services often involves managing data and logs generated within these cloud ecosystems.

Development Tools and Platforms

4 mentions

Development tools and platforms are utilized by 11% of the reviewers, highlighting their importance in the software dev…

Development tools and platforms are utilized by 11% of the reviewers, highlighting their importance in the software development lifecycle. Tools such as GitHub and Jenkins are frequently mentioned, indicating their role in version control, continuous integration, and continuous delivery pipelines. These platforms are essential for managing code, automating builds, and facilitating collaborative development efforts.

Security and Threat Detection

4 mentions

Approximately 11% of reviewers integrate specialized security and threat detection software alongside Splunk Enterprise…

Approximately 11% of reviewers integrate specialized security and threat detection software alongside Splunk Enterprise to enhance their cybersecurity posture. The mentioned tools, including SentinelOne Singularity, Cisco Secure Endpoint, and Palo Alto Networks Cortex XSOAR, suggest a focus on endpoint protection, security orchestration, and firewall management. This indicates a strategy to leverage multiple solutions for comprehensive threat intelligence and response capabilities.

Cisco Products

2 mentions

Cisco products are regularly used by 5% of reviewers, who generally express positive experiences with these solutions.…

Cisco products are regularly used by 5% of reviewers, who generally express positive experiences with these solutions. Specific mentions include network controllers, wireless access points, and security tools like Cisco Duo. Reviewers appreciate the reliability and performance of these hardware and software components within their IT infrastructure.