Splunk: The Good The Bad and The SPL
October 20, 2025

Splunk: The Good The Bad and The SPL

Anonymous | TrustRadius Reviewer
Score 9 out of 10
Vetted Review
Verified User

Software Version

Splunk Light (legacy)

Overall Satisfaction with Splunk Enterprise

Splunk Enterprise is our main tool for data analytics, observability and monitoring. Our company produces petabytes of data, so splunk provides an awesome tool to not only monitor the logs that are produced by our services bit also to create dashboards for monitoring and alerting. We regularly create alerts using splunk queries and use them to find out of there is something wrong with our products. It addresses the following business problems:Loss of revenue, by means of making sure we are not giving customers degraded experience. Data driven decision making: Allows business analysts to analyze splunk dashboards and make sure that they can do appropriate analysis and take appropriate decisions for revenue growth.

Pros

  • Configurable and sophisticated way of alerting on certain conditions observed via logs
  • Ability to create amazing dashboards to showcase current performance and allows us to monitor system health.
  • ability to do anomaly detection using AIOps and Machine learning to find out proactively if there is anything wrong with the system

Cons

  • Difficult to learn SPL (Search processing language) for newcomers to splunk. Should have made it easy to understand
  • Splunk is mainly log-centric, so to add stuff like distributed tracing we need to purchase premium applications (like Splunk APM)
  • Dashboard creation can be a bit messy experience for people that dont know how to do it fast. The drag-and-drop model seems outdated and UI can certainly do better in terms of usability.
  • IT and Business Ops : Increased revenue by providing smart trends and leads to understand issues or opportunities for growth.
  • Improves time taken by DevOps and Engineers to diagnose and debug problems and bugs
  • Manual effort for auditing and compliance reporting reduced for security engineers by providing relavent alerts and dashboards.
I think this is a 5/10 because the query language SPL is having a bit of a learning curve. Hence people adept in this can easily and rapidly use this to come up with queries fast. But for newcomers or junior engineers this has a steep learning curve and can cause newcomers or juniors to take time while executing queries and without a senior engineer or Splunk admin/expert created dashboards they may feel lost.
Splunk was better in terms of analyzing unstructured data. Also Splunk has had a very good and strong community and is also has a more tried and tested performance. I personally found the dash boarding capability of Splunk better than Datadog.

We also analyzed using Kibana. Although the UI of Kibana was a bit better I found that the SPL (Search processing language) was way too powerful and allowed us to perform investigation on unstructured data in a way better manner.

Do you think Splunk Enterprise delivers good value for the price?

Yes

Are you happy with Splunk Enterprise's feature set?

No

Did Splunk Enterprise live up to sales and marketing promises?

Yes

Did implementation of Splunk Enterprise go as expected?

Yes

Would you buy Splunk Enterprise again?

Yes

I will give it 9. And its best suited for large organizations with high stakes and lot of data. Which precisely need near complex, real-time monitoring, and alerting. Especially in places where some errors, if left unattended can cause customer and revenue loss. It is useful where cost is secondary to having the capability of this sort of monitoring.

It may be less suitable for startups which dont have a lot of data, and are cost sensitive. It is also not very suitable if we dont have requirement for precision dashboarding and monitoring.

Splunk Enterprise Feature Ratings

Centralized event and log data collection
10
Correlation
10
Event and log normalization/management
10
Deployment flexibility
10
Integration with Identity and Access Management Tools
10
Custom dashboards and workspaces
10
Host and network-based intrusion detection
7
Log retention
6
Data integration/API management
6
Behavioral analytics and baselining
6
Rules-based and algorithmic detection thresholds
5
Response orchestration and automation
8
Reporting and compliance management
9
Incident indexing/searching
9

Comments

More Reviews of Splunk Enterprise