Overall Satisfaction with Splunk Cloud
Here at CCMSI, we use Splunk Cloud to monitor Active Directory Events. It is primarily used by the IT Systems Team. It has proven to be invaluable to find misconfiguration, excessive usage, improper procedures, and security events. The tool allows me to give Management the information they ask for in a graphical way that shows trends, spikes, and overall usage.
- Splunk Cloud allows me to search the volumes of information help in Windows Server Logs quickly and accurately.
- Splunk Cloud allows me to create Dashboards for everyday monitoring of multiple parameters.
- Splunk Cloud allows me to create and schedule reports for Management on network usage and statistics.
- The SPL programming language that the queries are built in is not very intuitive.
- There should be a better repository of pre-built queries for what I would think of as common Active Directory usage monitoring.
- I would like to see more free training/familiarization information made available.
- Splunk Cloud has had a positive ROI in helping more efficiently track the cause of Help Desk Tickets.
- The billing model which is based on the amount of data from logs uploaded doesn't alert if a threshold is approaching. This can have a negative ROI.
- The training that I have taken while in-depth and focused is pretty expensive.
I have used several Solar Winds tools in the past to monitor and track similar things. Both tools are comparable in their performance. Each one has it's own set of challenges when getting set up for the first time as well as a learning curve to get comfortable with usage.