Splunk Enterprise
Splunk Enterprise
Overview
Recent Reviews
Awards
Products that are considered exceptional by their customers based on a variety of criteria win TrustRadius awards. Learn more about the types of TrustRadius awards to make the best purchase decision. More about TrustRadius Awards
Popular Features
View all 13 featuresCustom dashboards and workspaces (101)
9.9
99%
Correlation (50)
9.8
98%
Event and log normalization/management (99)
9.6
96%
Centralized event and log data collection (51)
9.3
93%
Reviewer Pros & Cons
View all pros & consVideo Reviews
Leaving a video review helps other professionals like you evaluate products. Be the first one in your network to record a review of Splunk Enterprise, and make your voice heard!
Pricing
View all pricingEntry-level set up fee?
- No setup fee
Offerings
- Free Trial
- Free/Freemium Version
- Premium Consulting / Integration Services
Would you like us to let the vendor know that you want pricing?
11 people want pricing too
Alternatives Pricing
Features Scorecard
Security Information and Event Management (SIEM)
8.7
87%
Product Details
What is Splunk Enterprise?
Splunk Enterprise enables users to find out what is happening in a business and take meaningful action. It automates the collection, indexing and alerting of machine data that's critical to operations, so that users can uncover the actionable insights from data — no matter the source or format. Leverage artificial intelligence and machine learning for predictive and proactive business decisions.
Splunk Enterprise Integrations
Splunk Enterprise Competitors
Splunk Enterprise Technical Details
Operating Systems | Unspecified |
---|---|
Mobile Application | No |
Comparisons
View all alternativesCompare with
Frequently Asked Questions
What is Splunk Enterprise?
Splunk is software for searching, monitoring, and analyzing machine-generated big data, via a web-style interface. It captures, indexes and correlates real-time data in a searchable repository from which it can generate graphs, reports, alerts, dashboards and visualizations.
What are Splunk Enterprise's top competitors?
SolarWinds Loggly, Sematext Infrastructure Monitoring, and LogRhythm NextGen SIEM Platform are common alternatives for Splunk Enterprise.
What is Splunk Enterprise's best feature?
Reviewers rate Custom dashboards and workspaces highest, with a score of 9.9.
Who uses Splunk Enterprise?
The most common users of Splunk Enterprise are from Enterprises (1,001+ employees) and the Information Technology & Services industry.
Reviews and Ratings
 (386)
Reviews
(1-25 of 67)- Popular Filters
Companies can't remove reviews or game the system. Here's why
June 17, 2022
Splunk Enterprise Rocks !!
We use Splunk Enterprise to do various types of monitoring across organizations using a clustered environment with distributed indexers, search heads, UF, and HFW i.e. Application Monitoring of various ETL tools such as Mulesoft, Airflow, Stream sets, etc REST API Monitoring Database monitoring HEC monitoring
- Act as a Search Head, Indexer and Forwarder
- Have full features to install Add-Ons
- Is On-Prem, so we have full control on created lookups on file system
- Better SPL Intelligence
- Add-On's auto upgrade management and notifications
- Implement more features on UI instead of config based implementations
August 17, 2021
Real-time smart meters
Splunk is being using to track the status of electric utility smart meters which record customer energy usage. Smart meters send power outage & restoration notifications which we track in real-time with splunk. This capability is very important for enhancing our situational awareness to help ensure we deliver safe and reliable electricity to our customers.
- Real-time status
- Data integration
- Live dashboards
- Automated machine learning
- Extract transform and loading
- Data modeling
August 09, 2021
Splunk Enterprise in the Cloud empowers me as an analyst
Splunk Enterprise is the basis for our log correlation and analysis. We're using it primarily for IT Security, and occasionally to assist with operations was helpful. It is the basis of our SIEM, Splunk Enterprise security. We pull in events from a wide variety of data sources. The ability of Splunk to ingest and normalize just about any sort of data is one of its strongest points.
- Gets data from anywhere
- Variety of supported alert types
- Real-time insights
- They should not remove support for Duo 2fa.
July 20, 2021
Robust IT Operations and SIEM Management Solution
Splunk Enterprise is used by our Infrastructure and Enterprise Monitoring Team and Security Teams to monitor our infrastructure. Monitoring is enabled for the overall health of our systems. Data is collected from multiple data sources. Logs are analyzed and converted to meaningful metrics for the team to proactive monitor and take corrective actions.
Splunk has the ability to correlate data from disparate data sources and provide root cause hence reducing MTTR and improving our SLA's with our customers. The events logged in Splunk help our IT Analyst and Security Analyst take proactive action before impacting the services which our customer uses. The Event Correlation helps us find RCA and improve MTTD and MTTR.
Splunk has the ability to correlate data from disparate data sources and provide root cause hence reducing MTTR and improving our SLA's with our customers. The events logged in Splunk help our IT Analyst and Security Analyst take proactive action before impacting the services which our customer uses. The Event Correlation helps us find RCA and improve MTTD and MTTR.
- Collect data from multiple data sources and correlate. Reduce alert noise from multiple monitoring systems.
- Monitor alerts and report on data collected. Create custom dashboards.
- Powerful machine learning and AiOPS functionality.
- Helps with our security compliance and addresses the security team's need to remain PCI compliant.
- Splunk data sizing and data collected. Worked with Professional Service to scale our environment.
- Capacity data storage for Splunk data.
- TuningSplunk analytics dashboards for performance.
July 19, 2021
Great for almost anything
We use this across our different departments for security, app performance monitoring, host monitoring, data intelligence, correlation, alerting and much more. It's a Swiss Army Knife of IT products.
- The power of it. It's a very good tool that does amazing things. Nothing comes close to it.
- It can ingest any data and present it in a digestible, searchable format.
- Flat file format makes it very fast and the best visualizations I've seen.
- It can be cost prohibitive, but I still think it's worth it.
- Training users is a little bit steeper, but once they have it, it's very powerful.
Splunk Enterprise is being used by mostly IT Department. [It's] being used to monitor security monitoring purpose[s] along with [business-relevant] use case monitoring.
- Data Normalization
- Correlation
- Data Analytics
- Use Case Development Capability
- Cost
April 14, 2020
Splunk leads the pack
Splunk is our one stop shop for all log data. We send logs from everything from servers, routers, firewalls, switches, sans and applications there to be analyzed and reviewed by different teams. This solves a critical issue by ensuring all teams are working from the same information. Prior to consolidating onto Splunk a number of different sources of truth leading different teams to work with different information.
- Single source of truth for all log files.
- Alerting system based on captured log data.
- Reporting/Dashboard system to present data.
- Complex overall architecture.
- Long implementation time.
- High cost.
- Requires on-going staff time to keep running effectively.
March 12, 2020
One Splunk to rule them all!
Splunk Enterprise is used across the whole department in our organization for Security information
and event management. It improves our security aspect of the assets by collecting logs. Splunk offers log collection from all types of assets in the environment varying from vulnerability scanning tools to network devices. Centralizing all these logs and managing them from one place is the real deal. It manages huge amounts of log data with a robust operation. Every day our environment creates dozens of logs and Splunk enables us to
see anomalies with alarms.
- Maximize endpoint logging.
- Can find and store logs from all types of assets.
- Customization of dashboards.
- Creating apps based on your needs.
- Alarm feature alerts relevant people in the organization.
- Data visualization.
- Search queries can be saved for future or even can be converted to apps.
- Slow interface.
March 06, 2020
Splunk Enterprise review
Currently our bank has different departments with their own Splunk infrastructure. We are currently building a larger infrastructure to incorporate all departments to join this centralized infrastructure with Splunk Enterprise. As Splunk is used for log analyzing, it is used for reports on different metrics built from logs collected from different servers. We try to consolidate the logs and put results onto a more centralized data center set as well.
- Log analyzing.
- Reports.
- Forecast (ML model).
- Stability on some components (e.g. indexers).
- Complexity of install and maintenance of infrastructure.
February 29, 2020
Splunk Enterprise - Log collection & aggregation
Splunk was initially purchased to be our replacement for our syslog server, but it has grown into much much more and this is because of how easy it is to get logs into Splunk and the flexibility of what can be done with those logs.
We are now using it as a security tool, ingesting logs from lots of different sources and even our cloud platforms.
Currently it is just our IT team that use Splunk.
We are now using it as a security tool, ingesting logs from lots of different sources and even our cloud platforms.
Currently it is just our IT team that use Splunk.
- Dashboards/visualisations.
- Can ingest any type of data.
- Flexibility with filtering, etc.
- Steep learning curve.
- Full stack reporting (though with SignalFX being purchased by Splunk, this is clearly a high priority).
- Team needed to manage large installations.
February 29, 2020
Won't you take me to Splunkytown
We're using Splunk Enterprise to assist us with IT Operations and IT Security. We came to look at Splunk because when I entered the company I found over 500 devices with no centralized logging in any way, no ability to pinpoint problems across the whole organization whether historic or predictable and things like this. Splunk is helping us deliver a predictable, robust operation of our infrastructure instead of reacting to problems and working to find just what was affected and when.
We believe we can apply Splunk to other data, in time, specifically aiding the company with analyzing financial information, but this is not yet an active project.
We believe we can apply Splunk to other data, in time, specifically aiding the company with analyzing financial information, but this is not yet an active project.
- Fast, efficient
- Solid community of experts and training materials
- Ingests data from many sources, with a large number of partner relationships
- There is a high learning curve. If you go to a Splunk demo or class, get inspired, then install it yourself, you'll have no idea what you're meant to do. It's not intuitive to the first-time user in any way.
- Pricing can be confusing. People ask how much data you want to ingest, and you don't know until after you've been using Splunk. It's not easy to sign up and start without guesswork.
- I found online help pages are broken or out-of-date, or incomplete. e.g. pages on setting up the Java-based SQL Server driver don't even tell you where to download it or where to install it.
February 27, 2020
Excellent product for our cybersecurity team
Splunk Enterprise has been used by our Cybersecurity Department for almost five years to be the single dashboard for our Security Incident and Event Monitoring. On top of that, we are also using the Enterprise Security, and it helps us to focus on the most notable events that need to be followed up asap.
- Central dashboard for all logs
- Enterprise Security
- Better dashboard graphics
February 26, 2020
Splunk Enterprise: A powerful, but expensive tool
Splunk Enterprise is used as a repository for all our server and network infrastructure logs. This allows us to go to one place to review logs and potentially find a relationship between different systems with specific issues. For example, seeing failed login attempts to our switches and learning that a server was using old credentials.
- Robust collection of plugins to support specific applications
- Relatively easy to use
- Strong and helpful support
- Difficult to master
- Can be very complicated to implement into an environment
- Very expensive
February 23, 2020
Monitor log and alert quickly with the speed of Splunk Light
Splunk Light is being used by our Operational and Maintenance team for transaction logging and event monitoring. It was the right solution for our organization since our IT internal policy stipulates that any solution which interacts with our subscriber's activity data must be deployed on-premise. Moreover, since we only have a handful of O&M team, Splunk Light is a lot more convenient to deploy and manage.
- Splunk Light is perfect for standalone on-premise deployment.
- Mainly works well for a small team
- Scalability might be an issue
- A small limit on the number of the user also poses a challenge for large team collaboration.
February 20, 2020
Splunk is a single tool that does everything
We use Splunk to integrate all the logs for each of the applications. Building dashboards and alerts base on the logs by the Application team's requirement. The Application team will be able to search through their log from one centralized place rather than logging into multiple servers to try to define the issue manually. With the Splunk search language, it is very easy to look for possible errors within a certain time frame. Our organization also use Splunk for fraud investigation purpose. We have more than 100 application teams using Splunk today and most of them are using it for troubleshooting purposes when there is an issue that has occurred.
- Log mining.
- Able to consume multiple log sources.
- Provides the possibility to upgrade the Splunk UF from a deployment server.
- Splunk search language can be very expensive if the users do not know what they are doing.
February 18, 2020
Splunk-ing across the Enterprise
Splunk is utilized for creation of dashboards and log queries across many areas.
- Quick log queries across different types of infrastructure
- Adaptable dashboards for digesting large amounts of continuous data
- Easy access and sharing of information via URL links
- Building Splunk queries can be comber some without intricate knowledge of Splunk and the applications involved
- Dashboard duplication for different areas can be difficult
- Capturing all necessary data from cloud platforms is not always straightforward
November 22, 2019
Using Splunk in Educational Sectors
Splunk Enterprise has been used across University of Minnesota as one of our IT monitoring and alerting tools. This has been a big help for our user base to provide timed email alerts as well as monitoring all of the threshold parameters we set up. We have a dedicated admin to make sure the Splunk agents have been deployed and configured across all the client tools.
- Timely alerting
- Sharing with end users automatically
- Less impact
- Sometime we see the Splunk agent taking higher CPU from OS prospects
- Similar issues have been noticed in Oracle Databases
November 20, 2019
Splunk: The log expert
Splunk Enterprise is a brilliant tool that we use in the University of Colorado, Denver to analyze logs obtained from various sources. Our team is responsible for maintaining the security of our campus and the University of Colorado, Anschutz medical campus.
The log sources are typically firewall logs, email logs, logs from the Intrusion detection system (IDS), logs of different services running on the google cloud, etc. It offers a very easy interface and a query language. We can build our own alarm rule and UI within it for visualization. The rules will run at a time defined by the user and will send metrics to the email. It helped in automating blacklisting as now we can get the most troublesome IP addresses and block them in a minute. It also helped us in tracing a list of most vulnerable on the campus. The most powerful feature is the correlation of log sources. Correlation of log sources is a very taxing process for any software. Splunk handles this gracefully. By correlating firewall traffic, wireless and IDS traffic we once spotted a machine that had a trojan in it and was trying to spread itself laterally through open SMB ports.
The log sources are typically firewall logs, email logs, logs from the Intrusion detection system (IDS), logs of different services running on the google cloud, etc. It offers a very easy interface and a query language. We can build our own alarm rule and UI within it for visualization. The rules will run at a time defined by the user and will send metrics to the email. It helped in automating blacklisting as now we can get the most troublesome IP addresses and block them in a minute. It also helped us in tracing a list of most vulnerable on the campus. The most powerful feature is the correlation of log sources. Correlation of log sources is a very taxing process for any software. Splunk handles this gracefully. By correlating firewall traffic, wireless and IDS traffic we once spotted a machine that had a trojan in it and was trying to spread itself laterally through open SMB ports.
- It is very useful in creating custom rules for analyzing system logs and display relevant information. The query language is very easy to learn.
- We can create custom UI to visualize the output of our data. The interface is very flexible. It also allows the sharing of rules among users.
- There is an open online community to help others. Stackoverflow also has a splunk community. These resources make it more convenient to learn.
- They can introduce a query builder for non-technical users.
- The query error messages could be more specific.
November 16, 2019
A real-time monitoring system
Splunk is used by our Engineering Department. Splunk has been a valuable and useful tool for our company to monitor errors occurring at all times. We love the real-time monitoring system that helps us detect errors and get the right people to handle them when needed to get things back up and running.
- Love the real-time monitoring system.
- Easy to use.
- I have no suggestions.
Splunk Enterprise tool is being used across our Digital department. Using this tool we are able to search and analyze event logs of our customer sessions. We can see the error trends of our Digital Services. Set up alerts for multiple KPIs and create dashboards for monitoring the health of our Digital products.
- Captures multiple different information about a customer and his/her session.
- Intuitive and informative search options.
- Option to set up precise alerts for different KPIs.
- The speed of the tool could be improved.
- It could store and allow to search for historical data older than 60 days (may be related to our company license).
- Dashboard creation could be more user-friendly.
May 21, 2019
Splunk, a great tool!
Splunk is being used by the entire organization for searching and reporting and to analyze the logs and entire organization’s data. Splunk is a great tool to work on. It helps in finding various threats inside and outside the organization. Five stars.
- Versatile
- Intelligent
- Reporting
- Searching
- Log analysis
- Costly
- Needs training to work on
- Needs hands on experience to get used to
We installed Splunk Light to get our feet wet with centralized log management. The primary use was in our network and security department. Splunk Light allowed us to quickly and easily search across all of our device logs, as well as gave us the ability to correlate log entries between machines. It also helped us satisfy our compliance requirements for logging.
- Monitoring and Alerting: Creating custom actions based on log entries was the largest unexpected bonus for us. While we had other software configured to do this job Splunk was easy to implement and could be managed by a larger number of our team members.
- Cross-Device Analysis: Seeing data from all of your devices in one location makes following event chains much easier.
- Vendor Specific Add-ons: There is a large library of vendor-specific add-ons for the software allowing for automatic formatting and action for certain types of logs, greatly reducing the man-hours required to get started.
- Splunk Light doesn't include the ability to create data models or tables without paying for a large upgrade. This is a rather basic feature, I wish it had been included.
- High Availability is another basic feature that is excluded, greatly limiting Splunk Light's usefulness.
Splunk is an excellent logging platform, allowing for short and long term log storage with top tier indexing and searching capabilities. We have deployed Splunk to aggregate all logs and act as a central logging platform throughout the company. This helps us solve operational issues by providing a centralized log monitoring platform to be used by our operations group. It also helps solve regulatory issues by being the central logging platform with strict access controls as well as tiered storage and archiving capabilities.
- Tight access control via a variety of mechanisms to restrict users to specific logs.
- Solves regulatory controls by providing access control and archival storage capabilities.
- Provides a quick mechanism to search across multiple logs for issues between systems.
- Splunk can be expensive since it's based on the amount of logging you do. The capabilities definitely make up for the cost, but there is a high bar to entry.
- Splunk can be overly confusing for new users. The capabilities are quite vast and sometimes daunting.
February 28, 2019
Excellent tool for analyzing logs
Splunk Enterprise is used to monitor both Prod as well as all our lower environments. It is used for analyzing logs and tracing transactions. We write Splunk queries and create dashboards for monitoring several Key Performance Indicators. We first analyze metrics over a particular period of them to understand the trend and then set up alerts on these metrics for threshold violations.
- Simplifies analyzing of big logs finds and helps in finding issues faster.
- Splunk Alerts are great to be notified of possible issues so that necessary actions can be taken to avoid it from becoming a problem to our end users.
- Dashboard reports can be scheduled to be generated and share with key stakeholders.
- Comparison of two or more time series data in a single graph.
- Search and make suggestions on Splunk commands as we type on the search window.
January 02, 2019
a very good log handling and analysis tool
Splunk is not used across my organization. It is being used by some of us and for some specific task. And yes, it is also used by other departments as well but according to their need. Specifically, we are using this tool for monitoring the application logs and doing some analysis over it. Splunk provides a very easy way to search your logs and perform some basic analysis.
- Log search is very good with this tool.
- Splunk search query language is just very good. You can easily run some analysis using this language
- Generating reports is a very good feature of this tool.
- Detecting anomalies and reporting them is just fantastic.
- Splunk requires some learning to use all of its features. Understanding its SPL is not very easy, and it will take long enough time to learn it.
- Regular expression is a bit tedious to learn and then use, it needs a good understanding of regular expression.
- I don't know why, but sometimes its search keeps on going forever and then I had to manually kill that job to start it again.