Skip to main content
TrustRadius

Overview

What is Splunk Enterprise?

Splunk is software for searching, monitoring, and analyzing machine-generated big data, via a web-style interface. It captures, indexes and correlates real-time data in a searchable repository from which it can generate graphs, reports, alerts, dashboards and visualizations.

Read more
Recent Reviews

Splunk enterprise stable solution

7 out of 10
January 05, 2024
Splunk Enterprise is used in the company by the IT department. Mainly to monitor security events on process-relevant systems where the …
Continue reading

TrustRadius Insights

Valuable Log Gathering and Summarization: Users have expressed positive opinions about Splunk's ability to gather and summarize log …
Continue reading

Great if you have the money

7 out of 10
October 24, 2023
We use Splunk Enterprise as a SIEM and a separate pool to use for medical record auditing. The SIEM catalogues information from multiple …
Continue reading

Real-time smart meters

9 out of 10
August 17, 2021
Incentivized
Splunk is being using to track the status of electric utility smart meters which record customer energy usage. Smart meters send power …
Continue reading
Read all reviews

Awards

Products that are considered exceptional by their customers based on a variety of criteria win TrustRadius awards. Learn more about the types of TrustRadius awards to make the best purchase decision. More about TrustRadius Awards

Popular Features

View all 13 features
  • Custom dashboards and workspaces (54)
    8.5
    85%
  • Centralized event and log data collection (53)
    6.5
    65%
  • Event and log normalization/management (53)
    6.0
    60%
  • Correlation (52)
    6.0
    60%

Reviewer Pros & Cons

View all pros & cons
Return to navigation

Pricing

View all pricing
N/A
Unavailable

What is Splunk Enterprise?

Splunk is software for searching, monitoring, and analyzing machine-generated big data, via a web-style interface. It captures, indexes and correlates real-time data in a searchable repository from which it can generate graphs, reports, alerts, dashboards and visualizations.

Entry-level set up fee?

  • No setup fee

Offerings

  • Free Trial
  • Free/Freemium Version
  • Premium Consulting/Integration Services

Would you like us to let the vendor know that you want pricing?

40 people also want pricing

Alternatives Pricing

What is Blumira?

Blumira’s cloud SIEM platform offers both automated threat detection and response, enabling organizations of any size to more defend against cybersecurity threats in near real-time. It's goal is to ease the burden of alert fatigue, complexity of log management and lack of IT visibility.

Return to navigation

Product Demos

Splunk Incident Review Demo

YouTube

Splunk Threat Intelligence Demo

YouTube

Splunk Enterprise Security | Splunk Enterprise Installation | Splunk Training | Edureka

YouTube
Return to navigation

Features

Security Information and Event Management (SIEM)

Security Information and Event Management is a category of security software that allows security analysts to look at a more comprehensive view of security logs and events than would be possible by looking at the log files of individual, point security tools

7.4
Avg 7.8
Return to navigation

Product Details

What is Splunk Enterprise?

Splunk Enterprise enables users to find out what is happening in a business and take meaningful action. It automates the collection, indexing and alerting of machine data that's critical to operations, so that users can uncover the actionable insights from data — no matter the source or format. Leverage artificial intelligence and machine learning for predictive and proactive business decisions.

Splunk Enterprise Technical Details

Operating SystemsUnspecified
Mobile ApplicationNo

Frequently Asked Questions

Splunk is software for searching, monitoring, and analyzing machine-generated big data, via a web-style interface. It captures, indexes and correlates real-time data in a searchable repository from which it can generate graphs, reports, alerts, dashboards and visualizations.

SolarWinds Loggly and LogRhythm NextGen SIEM Platform are common alternatives for Splunk Enterprise.

Reviewers rate Incident indexing/searching highest, with a score of 8.9.

The most common users of Splunk Enterprise are from Enterprises (1,001+ employees).
Return to navigation

Comparisons

View all alternatives
Return to navigation

Reviews and Ratings

(455)

Community Insights

TrustRadius Insights are summaries of user sentiment data from TrustRadius reviews and, when necessary, 3rd-party data sources. Have feedback on this content? Let us know!

Valuable Log Gathering and Summarization: Users have expressed positive opinions about Splunk's ability to gather and summarize log messages from multiple sources. Many reviewers find this feature valuable, as it allows them to easily access and analyze log data in a centralized location without the need for manual aggregation.

Simplicity and Advanced Search Capabilities: Splunk's reporting functionality is highly regarded by users for its simplicity and advanced search capabilities. Several reviewers appreciate how easy it is to use Splunk's reporting features, while also being able to perform complex searches that provide detailed insights into their data.

Effective Web Traffic Catching and Dashboards: The effectiveness of Splunk in catching web traffic and providing helpful dashboards is another aspect praised by users. Many reviewers highlight how Splunk's web monitoring capabilities enable them to track website activity effectively, while the intuitive dashboards allow for quick visualization and analysis of important metrics.

Confusing User Interface: Some users have reported that the user interface in Splunk can be perplexing, leading to difficulties in quickly performing tasks and navigating the software.

Limited Integration with Excel: Users have expressed their desire for improved integration between Splunk and Excel when it comes to creating reports and dashboards. They feel that better connectivity and seamless data transfer would enhance their workflow.

Steep Learning Curve: Several users have mentioned the complexity of Splunk's architecture, requiring a dedicated team of engineers to effectively manage and optimize its performance. This steep learning curve can pose challenges for new users who may need additional time and resources to fully grasp the intricacies of the platform.

Based on user reviews, the following recommendations emerged for using Splunk:

  • Ensure the correct subscription: Users emphasized the importance of having the correct subscription for Splunk to avoid login issues and fully utilize its features. They recommend careful planning of the deployment and learning as much as possible before implementing a large installation.

  • Thoroughly investigate anomalies: While Splunk's great dashboards for troubleshooting are praised, users advise against relying solely on system alerts generated by Splunk. They suggest continuing to investigate any anomalies and carefully setting up sources and background data in Splunk.

  • Utilize Splunk's log analysis capabilities: Many users recommend Splunk as a valuable tool for log analysis and improving the quality of current processes. They find it helpful for debugging integration issues and consider it suitable for large-scale applications/systems. Users appreciate its ability to connect to individual boxes and view multiple logs simultaneously.

It should be noted that some users suggest that there may be better and cheaper alternatives for small to medium-sized businesses, while others propose improvements to the search result UI and pricing structure to attract more users in the industry.

Attribute Ratings

Reviews

(1-25 of 69)
Companies can't remove reviews or game the system. Here's why
Score 7 out of 10
Vetted Review
Verified User
It will be suitable for large organizations. Easier to train users and scales well. Unfortunately, it will be too expensive for small businesses and enterprises.It is a consistent solution. By combining multiple tools from the same company, you can get a stable environment.My experience shows that it is not the most flexible solution on the market. Before selecting a SIEM solution, gather requirements and choose a solution according to your needs. If your organization has standard needs, Splunk will not be a bad choice.
Score 7 out of 10
Vetted Review
Verified User
Primary issue with Splunk Enterprise is cost. The licenses can get extremely expensive very quickly in my opinion. If the organization can afford to have all of their data in it then the program is amazing. We have been able to solve multiple problems or find things that would normally take hours within seconds with the tool
Score 9 out of 10
Vetted Review
Verified User
Incentivized
Splunk is well suited almost anywhere an Enterprise can afford it. It does require some technical chops to support an on-prem installation, but less so with a Cloud subscription. If it involves data there is a good chance that is possible with Splunk. In particular, it is a great base for Security use cases, especially for disparate and non-standard data sources.
Score 10 out of 10
Vetted Review
Verified User
Incentivized
Good for event correlation from multiple data sources, web monitoring, systems and application monitoring. Good as security information and event management tool. It collects data from logs and custom applications helping the business make informed decisions across the organization. Gain insights to drive operational performance and business results. Splunk's rich visualizations make results easy to understand and take necessary actions.
Score 9 out of 10
Vetted Review
Verified User
Incentivized
Overall security monitoring: It can take data in and correlate it across very different datasets. Some tools require you to ingest and format it their way, but being able to do ad-hoc searching during an incident has proven to be very valuable.
Score 10 out of 10
Vetted Review
Verified User
Incentivized
Splunk Enterprise is mostly suited for organizations where enough budget is available to maintain along with having dedicated resource[s] for it. While [it's] a great tool, you need to skilled resource[s] to get the best out of it.
April 14, 2020

Splunk leads the pack

Score 9 out of 10
Vetted Review
Verified User
Incentivized
Splunk is a great fit for organizations that need to consolidate log data. It's also a great fit for organizations that need to provide access to data to different teams of engineers. We send all of our log data to Splunk, index and report on it then provide access to different teams based on need.
Ahmet Fatih IRKLI | TrustRadius Reviewer
Score 10 out of 10
Vetted Review
Verified User
I definitely recommend Splunk Enterprise to security and network teams as it is perfectly scalable for any size environment.
  • Network teams can easily see if there is a problem with the network device.
  • The security team can easily be notified about anomalies that may due to an intrusion.
  • The support team can follow the situation of assets and tools.
  • It can be integrated with most of the tools available on the market.
Score 7 out of 10
Vetted Review
Verified User
Incentivized
Splunk is good for log analyzing from enterprise level of applications on different logs and consolidating results as reports. We can use such data to make forecasts for future trends if issues would occur more or less frequently.

Setup and maintenance would not be easy, so always plan ahead. Also always do health check for stability on some of the Splunk components such as indexers and HFs.
Fraser Clark | TrustRadius Reviewer
Score 10 out of 10
Vetted Review
Verified User
Incentivized
Splunk is excellent in most situations where log collection and aggregation is needed. It can work as a small scale syslog server and be built on from that.
The obvious wall is the cost of the product and for that reason I would say smaller businesses would not be suited to this as there are free solutions that could bridge this gap.
Score 9 out of 10
Vetted Review
Verified User
Incentivized
Splunk Enterprise is well-suited for any requirement to aggregate vast sums of data, no matter how structured or unstructured, and search across it all at speed, or report on it with visualizations, etc.

It's not suited for scenarios where you want to report on a single set of data, say, in a traditional way, for example, a typical scheduled report out of a finance system.
Score 9 out of 10
Vetted Review
Verified User
Incentivized
Splunk Enterprise is very well suited for correlating all the logs that need to be monitored and to be analyzed. It has performed very well with a vast amount of logs data. Furthermore, Splunk Enterprise can be pumped in and do parsing for numerous security device logs.
However, it needs certain technical skills to be able to correlate the logs and do the query in the Splunk Enterprise.
Score 10 out of 10
Vetted Review
Verified User
Incentivized
If the organization is looking for a powerful SIEM solution and has the budget, then I would recommend Splunk Enterprise. Using the tool can be as simple or as complicated as you want it. My only hesitation will be the complexity of implementation. For smaller organizations, it shouldn't be an issue, but larger ones may find it challenging to follow Splunk Enterprise's best practices for implementation.
Johanes Siregar | TrustRadius Reviewer
Score 8 out of 10
Vetted Review
Verified User
Incentivized
Splunk Light is perfect to be used by a small organization or a team within a large organization with internal IT policy which required any solution must be deployed within the organization's premise. It performs very well for event log monitoring and alerting purpose. It is also relatively quick to deploy and easy to manage.
ShuYun Du | TrustRadius Reviewer
Score 9 out of 10
Vetted Review
Verified User
Incentivized
Splunk is the best tool to use for log mining. It is also good at combining multiple sources of logs together and creates a single pane of glass. It can do lots of APM monitoring however at the end of the day it is more of a log mining tool but not an APM tool. It is best to use for business analyzing, debugging and fraud investigation. When it comes to monitoring part, get a proper APM tool will be a better idea.
November 20, 2019

Splunk: The log expert

Kuntal Das | TrustRadius Reviewer
Score 10 out of 10
Vetted Review
Verified User
Incentivized
Pros: Splunk is very well suited if you have multiple log sources of related data. All of them can be correlated and tasks can be automated based on the requirement. Other than alerts, Splunk can also run a specific script of your choice, based on some defined conditions.
Cons: If you have a few logs but a large number of log sources, Splunk can be very expensive.
Johann Davila | TrustRadius Reviewer
Score 10 out of 10
Vetted Review
Verified User
Incentivized
It is well suited with real-time monitoring and notifications sent when issues occur. It has been very helpful to monitor issues that applications are having so that we can get the right team to address these issues to get the company back up and running to continue business as normal.
Score 8 out of 10
Vetted Review
Verified User
Incentivized
When needed to search for some specific event information triggered by end-user or by any other service, Splunk Enterprise tool can give that information and by reviewing the log of the event you can find a lot of needed information that could help you to find the solution or resolve the issue on the spot.
Score 8 out of 10
Vetted Review
Verified User
Splunk is the best tool to work on if there is a need for analyzing the logs and the organization’s inside data. The way employees use search engines and browse for their personal use they can be caught easily. Also, if there are some outside threats within the company you can analyze those by setting up alerts.
Score 6 out of 10
Vetted Review
Verified User
Incentivized
Splunk Light is highly useful for smaller companies without regulatory requirements for logging of data. It has all of the main features required for basic troubleshooting and log retention for internal use. Splunk Light is not a good fit for large deployments as it's not capable of high availability, data modeling, SSO, or clustering will cause issues.
Score 9 out of 10
Vetted Review
Verified User
Incentivized
Splunk is an excellent central logging system. For companies concerned about the cost, you can combine Splunk with an open-source logging engine such as rsyslog and only ingest the logs you need to search. Splunk is an excellent tool for handling web and systems logging and can help quickly identify issues in both.
Return to navigation