Great for almost anything
Updated July 19, 2021

Great for almost anything

Anonymous | TrustRadius Reviewer
Score 9 out of 10
Vetted Review
Verified User

Overall Satisfaction with Splunk Enterprise

We use this across our different departments for security, app performance monitoring, host monitoring, data intelligence, correlation, alerting and much more. It's a Swiss Army Knife of IT products.
  • The power of it. It's a very good tool that does amazing things. Nothing comes close to it.
  • It can ingest any data and present it in a digestible, searchable format.
  • Flat file format makes it very fast and the best visualizations I've seen.
  • It can be cost prohibitive, but I still think it's worth it.
  • Training users is a little bit steeper, but once they have it, it's very powerful.
  • Like any tool, if you use it, it does need care and feeding. If you change your log structure or location, update it in Splunk or you'll have missing info.
  • Don't use it as a reactionary tool, it should be the first tool you go to.
  • We use another product for monitoring, but the data is not helpful in their product. We started bringing that data into Splunk and it's actually useful to us now.
Splunk is all inclusive, you don't need 3 products to do what Splunk did 4 previous major versions.
Overall security monitoring: It can take data in and correlate it across very different datasets. Some tools require you to ingest and format it their way, but being able to do ad-hoc searching during an incident has proven to be very valuable.

Splunk Enterprise Feature Ratings

Centralized event and log data collection
9
Correlation
9
Event and log normalization/management
8
Deployment flexibility
9
Integration with Identity and Access Management Tools
10
Custom dashboards and workspaces
10
Host and network-based intrusion detection
8