Splunk Enterprise for hybrid environment monitoring
March 04, 2022
Splunk Enterprise for hybrid environment monitoring

Score 8 out of 10
Vetted Review
Verified User
Overall Satisfaction with Splunk Enterprise Security (ES)
We have been using Splunk Enterprise Security for identifying threats in AWS infrastructure, misconfiguration, and creating a single pane of glass for a complete picture of our infrastructure. Other than this, we are using enterprise security for auditing system logins, changes done in certain environments, monitoring communications, firewall rules changes, traffic monitoring, phishing attacking monitoring.
Pros
- Monitoring of Firewall traffic
- Monitoring for mail systems, logs
- Monitoring of AWS infrastructure
- Phishing attacks monitoring
- firewall rule changes monitoring
Cons
- monitoring of user activities
- Dashboarding for non-ES users
- Alerting realtime without performance impact
- We are able to provide reliable, secure environment for our customers
- Cost is high if we compare with other products available in the market, but ROI is explainable.
- The machine learning capabilities give it a cutting edge which most of the customers are looking for.
Our Enterprise security has several correlation searches which come out of the box with Splunk enterprise security and we just needed to modify them based on our environment's requirements. I would say about 60-70% of such searches are provided by Splunk Enterprise security itself and the remaining we need to create based on what devices, what technologies, and what tools are we using in the environment.
Above mentioned tools are environment-specific and provide insights into what is happening in the environment. We were looking for a product that is environment agnostic & able to work with many environments. Hence Splunk Enterprise security stands out for us. Also, we were looking for something which can withstand the scale which we working on.
Do you think Splunk Enterprise Security delivers good value for the price?
Yes
Are you happy with Splunk Enterprise Security's feature set?
Yes
Did Splunk Enterprise Security live up to sales and marketing promises?
Yes
Did implementation of Splunk Enterprise Security go as expected?
Yes
Would you buy Splunk Enterprise Security again?
Yes
Comments
Please log in to join the conversation