Skip to main content
TrustRadius

Overview

What is Splunk Enterprise?

Splunk is software for searching, monitoring, and analyzing machine-generated big data, via a web-style interface. It captures, indexes and correlates real-time data in a searchable repository from which it can generate graphs, reports, alerts, dashboards and visualizations.

Read more
Recent Reviews

Splunk enterprise stable solution

7 out of 10
January 05, 2024
Splunk Enterprise is used in the company by the IT department. Mainly to monitor security events on process-relevant systems where the …
Continue reading

TrustRadius Insights

Valuable Log Gathering and Summarization: Users have expressed positive opinions about Splunk's ability to gather and summarize log …
Continue reading

Great if you have the money

7 out of 10
October 24, 2023
We use Splunk Enterprise as a SIEM and a separate pool to use for medical record auditing. The SIEM catalogues information from multiple …
Continue reading

Real-time smart meters

9 out of 10
August 17, 2021
Incentivized
Splunk is being using to track the status of electric utility smart meters which record customer energy usage. Smart meters send power …
Continue reading
Read all reviews

Awards

Products that are considered exceptional by their customers based on a variety of criteria win TrustRadius awards. Learn more about the types of TrustRadius awards to make the best purchase decision. More about TrustRadius Awards

Popular Features

View all 13 features
  • Custom dashboards and workspaces (54)
    8.5
    85%
  • Centralized event and log data collection (53)
    6.5
    65%
  • Event and log normalization/management (53)
    6.0
    60%
  • Correlation (52)
    6.0
    60%

Reviewer Pros & Cons

View all pros & cons
Return to navigation

Pricing

View all pricing
N/A
Unavailable

What is Splunk Enterprise?

Splunk is software for searching, monitoring, and analyzing machine-generated big data, via a web-style interface. It captures, indexes and correlates real-time data in a searchable repository from which it can generate graphs, reports, alerts, dashboards and visualizations.

Entry-level set up fee?

  • No setup fee

Offerings

  • Free Trial
  • Free/Freemium Version
  • Premium Consulting/Integration Services

Would you like us to let the vendor know that you want pricing?

40 people also want pricing

Alternatives Pricing

What is Blumira?

Blumira’s cloud SIEM platform offers both automated threat detection and response, enabling organizations of any size to more defend against cybersecurity threats in near real-time. It's goal is to ease the burden of alert fatigue, complexity of log management and lack of IT visibility.

Return to navigation

Product Demos

Splunk Incident Review Demo

YouTube

Splunk Threat Intelligence Demo

YouTube

Splunk Enterprise Security | Splunk Enterprise Installation | Splunk Training | Edureka

YouTube
Return to navigation

Features

Security Information and Event Management (SIEM)

Security Information and Event Management is a category of security software that allows security analysts to look at a more comprehensive view of security logs and events than would be possible by looking at the log files of individual, point security tools

7.4
Avg 7.8
Return to navigation

Product Details

What is Splunk Enterprise?

Splunk Enterprise enables users to find out what is happening in a business and take meaningful action. It automates the collection, indexing and alerting of machine data that's critical to operations, so that users can uncover the actionable insights from data — no matter the source or format. Leverage artificial intelligence and machine learning for predictive and proactive business decisions.

Splunk Enterprise Technical Details

Operating SystemsUnspecified
Mobile ApplicationNo

Frequently Asked Questions

Splunk is software for searching, monitoring, and analyzing machine-generated big data, via a web-style interface. It captures, indexes and correlates real-time data in a searchable repository from which it can generate graphs, reports, alerts, dashboards and visualizations.

SolarWinds Loggly and LogRhythm NextGen SIEM Platform are common alternatives for Splunk Enterprise.

Reviewers rate Incident indexing/searching highest, with a score of 8.9.

The most common users of Splunk Enterprise are from Enterprises (1,001+ employees).
Return to navigation

Comparisons

View all alternatives
Return to navigation

Reviews and Ratings

(455)

Community Insights

TrustRadius Insights are summaries of user sentiment data from TrustRadius reviews and, when necessary, 3rd-party data sources. Have feedback on this content? Let us know!

Valuable Log Gathering and Summarization: Users have expressed positive opinions about Splunk's ability to gather and summarize log messages from multiple sources. Many reviewers find this feature valuable, as it allows them to easily access and analyze log data in a centralized location without the need for manual aggregation.

Simplicity and Advanced Search Capabilities: Splunk's reporting functionality is highly regarded by users for its simplicity and advanced search capabilities. Several reviewers appreciate how easy it is to use Splunk's reporting features, while also being able to perform complex searches that provide detailed insights into their data.

Effective Web Traffic Catching and Dashboards: The effectiveness of Splunk in catching web traffic and providing helpful dashboards is another aspect praised by users. Many reviewers highlight how Splunk's web monitoring capabilities enable them to track website activity effectively, while the intuitive dashboards allow for quick visualization and analysis of important metrics.

Confusing User Interface: Some users have reported that the user interface in Splunk can be perplexing, leading to difficulties in quickly performing tasks and navigating the software.

Limited Integration with Excel: Users have expressed their desire for improved integration between Splunk and Excel when it comes to creating reports and dashboards. They feel that better connectivity and seamless data transfer would enhance their workflow.

Steep Learning Curve: Several users have mentioned the complexity of Splunk's architecture, requiring a dedicated team of engineers to effectively manage and optimize its performance. This steep learning curve can pose challenges for new users who may need additional time and resources to fully grasp the intricacies of the platform.

Based on user reviews, the following recommendations emerged for using Splunk:

  • Ensure the correct subscription: Users emphasized the importance of having the correct subscription for Splunk to avoid login issues and fully utilize its features. They recommend careful planning of the deployment and learning as much as possible before implementing a large installation.

  • Thoroughly investigate anomalies: While Splunk's great dashboards for troubleshooting are praised, users advise against relying solely on system alerts generated by Splunk. They suggest continuing to investigate any anomalies and carefully setting up sources and background data in Splunk.

  • Utilize Splunk's log analysis capabilities: Many users recommend Splunk as a valuable tool for log analysis and improving the quality of current processes. They find it helpful for debugging integration issues and consider it suitable for large-scale applications/systems. Users appreciate its ability to connect to individual boxes and view multiple logs simultaneously.

It should be noted that some users suggest that there may be better and cheaper alternatives for small to medium-sized businesses, while others propose improvements to the search result UI and pricing structure to attract more users in the industry.

Attribute Ratings

Reviews

(1-25 of 69)
Companies can't remove reviews or game the system. Here's why
Score 7 out of 10
Vetted Review
Verified User
  • Ingest data and present it in a easy to read and process format
  • Correlation
  • Analysis and presentation of data
  • Ease of operation and maintenance compared to other solutions of its kind
  • Easier to implement and maintain than other solutions
  • It would be useful to have more standardization of some of the information stored
  • An expensive solution
  • Documentation could be more accurate and up-to-date
Score 8 out of 10
Vetted Review
Verified User
Incentivized
  • Act as a Search Head, Indexer and Forwarder
  • Have full features to install Add-Ons
  • Is On-Prem, so we have full control on created lookups on file system
  • Better SPL Intelligence
  • Add-On's auto upgrade management and notifications
  • Implement more features on UI instead of config based implementations
Score 10 out of 10
Vetted Review
Verified User
Incentivized
  • Collect data from multiple data sources and correlate. Reduce alert noise from multiple monitoring systems.
  • Monitor alerts and report on data collected. Create custom dashboards.
  • Powerful machine learning and AiOPS functionality.
  • Helps with our security compliance and addresses the security team's need to remain PCI compliant.
  • Splunk data sizing and data collected. Worked with Professional Service to scale our environment.
  • Capacity data storage for Splunk data.
  • TuningSplunk analytics dashboards for performance.
Score 9 out of 10
Vetted Review
Verified User
Incentivized
  • The power of it. It's a very good tool that does amazing things. Nothing comes close to it.
  • It can ingest any data and present it in a digestible, searchable format.
  • Flat file format makes it very fast and the best visualizations I've seen.
  • It can be cost prohibitive, but I still think it's worth it.
  • Training users is a little bit steeper, but once they have it, it's very powerful.
April 14, 2020

Splunk leads the pack

Score 9 out of 10
Vetted Review
Verified User
Incentivized
  • Single source of truth for all log files.
  • Alerting system based on captured log data.
  • Reporting/Dashboard system to present data.
  • Complex overall architecture.
  • Long implementation time.
  • High cost.
  • Requires on-going staff time to keep running effectively.
Ahmet Fatih IRKLI | TrustRadius Reviewer
Score 10 out of 10
Vetted Review
Verified User
  • Maximize endpoint logging.
  • Can find and store logs from all types of assets.
  • Customization of dashboards.
  • Creating apps based on your needs.
  • Alarm feature alerts relevant people in the organization.
  • Data visualization.
  • Search queries can be saved for future or even can be converted to apps.
  • Slow interface.
Fraser Clark | TrustRadius Reviewer
Score 10 out of 10
Vetted Review
Verified User
Incentivized
  • Dashboards/visualisations.
  • Can ingest any type of data.
  • Flexibility with filtering, etc.
  • Steep learning curve.
  • Full stack reporting (though with SignalFX being purchased by Splunk, this is clearly a high priority).
  • Team needed to manage large installations.
Score 9 out of 10
Vetted Review
Verified User
Incentivized
  • Fast, efficient
  • Solid community of experts and training materials
  • Ingests data from many sources, with a large number of partner relationships
  • There is a high learning curve. If you go to a Splunk demo or class, get inspired, then install it yourself, you'll have no idea what you're meant to do. It's not intuitive to the first-time user in any way.
  • Pricing can be confusing. People ask how much data you want to ingest, and you don't know until after you've been using Splunk. It's not easy to sign up and start without guesswork.
  • I found online help pages are broken or out-of-date, or incomplete. e.g. pages on setting up the Java-based SQL Server driver don't even tell you where to download it or where to install it.
Daniel Garrett | TrustRadius Reviewer
Score 8 out of 10
Vetted Review
Verified User
Incentivized
  • Quick log queries across different types of infrastructure
  • Adaptable dashboards for digesting large amounts of continuous data
  • Easy access and sharing of information via URL links
  • Building Splunk queries can be comber some without intricate knowledge of Splunk and the applications involved
  • Dashboard duplication for different areas can be difficult
  • Capturing all necessary data from cloud platforms is not always straightforward
November 20, 2019

Splunk: The log expert

Kuntal Das | TrustRadius Reviewer
Score 10 out of 10
Vetted Review
Verified User
Incentivized
  • It is very useful in creating custom rules for analyzing system logs and display relevant information. The query language is very easy to learn.
  • We can create custom UI to visualize the output of our data. The interface is very flexible. It also allows the sharing of rules among users.
  • There is an open online community to help others. Stackoverflow also has a splunk community. These resources make it more convenient to learn.
  • They can introduce a query builder for non-technical users.
  • The query error messages could be more specific.
Score 8 out of 10
Vetted Review
Verified User
Incentivized
  • Captures multiple different information about a customer and his/her session.
  • Intuitive and informative search options.
  • Option to set up precise alerts for different KPIs.
  • The speed of the tool could be improved.
  • It could store and allow to search for historical data older than 60 days (may be related to our company license).
  • Dashboard creation could be more user-friendly.
Score 8 out of 10
Vetted Review
Verified User
  • Versatile
  • Intelligent
  • Reporting
  • Searching
  • Log analysis
  • Costly
  • Needs training to work on
  • Needs hands on experience to get used to
Score 6 out of 10
Vetted Review
Verified User
Incentivized
  • Monitoring and Alerting: Creating custom actions based on log entries was the largest unexpected bonus for us. While we had other software configured to do this job Splunk was easy to implement and could be managed by a larger number of our team members.
  • Cross-Device Analysis: Seeing data from all of your devices in one location makes following event chains much easier.
  • Vendor Specific Add-ons: There is a large library of vendor-specific add-ons for the software allowing for automatic formatting and action for certain types of logs, greatly reducing the man-hours required to get started.
  • Splunk Light doesn't include the ability to create data models or tables without paying for a large upgrade. This is a rather basic feature, I wish it had been included.
  • High Availability is another basic feature that is excluded, greatly limiting Splunk Light's usefulness.
Score 9 out of 10
Vetted Review
Verified User
Incentivized
  • Tight access control via a variety of mechanisms to restrict users to specific logs.
  • Solves regulatory controls by providing access control and archival storage capabilities.
  • Provides a quick mechanism to search across multiple logs for issues between systems.
  • Splunk can be expensive since it's based on the amount of logging you do. The capabilities definitely make up for the cost, but there is a high bar to entry.
  • Splunk can be overly confusing for new users. The capabilities are quite vast and sometimes daunting.
Return to navigation