17 years helping South African businesses
choose better software
Splunk Enterprise
What Is Splunk Enterprise?
Splunk is the key to enterprise resilience. Trusted by the world’s leading organizations to keep their digital systems secure and reliable, Splunk can prevent major issues, absorb shocks, and accelerate transformation. With visibility into all your digital systems, you can respond to incidents before they have bigger business impacts. Take the next steps to make your organization more resilient with the all-in-one unified security and observability platform.
Who Uses Splunk Enterprise?
AI-powered solutions for security and observability that accelerate detection, investigation and response. Supported by an enterprise-class platform that enables shared data, context and workflows.
Not sure about Splunk Enterprise?
Compare with a popular alternative
Splunk Enterprise
Reviews of Splunk Enterprise
Big data is no problem for Splunk Enterprise
Comments: Splunk is a powerful and useful monitoring tool. Splunk's efficiency is enhanced by the ability to integrate third-party apps developed in-house. It's also interesting that we can incorporate a customs alert and dashboard. In most situations, it resolves the need to normalize data, allowing for the use of any and all data in business forecasting. It is analyzed for data that can be utilized to optimize spending plans and asset tracking.
Pros:
Without worrying too much about data type or normalization, Splunk Enterprise can efficiently manage massive amounts of data from numerous sources. Data may be accessed in a flash, and there are a number of options for tailoring and integrating data analysis workflows to create bespoke dashboards or utilizing apps from our other product partners.
Cons:
There isn't much I dislike about splunk, however if we have to be picky, it would be that it's more difficult to maintain as an administrator when splunk is installed on outdated architecture.
Alternatives Considered:
Complete Security operations with Splunk
Comments: Splunk data visualization and its analytics handling chunks of data is exceptional.
Pros:
Data visualization, Analytics skills with AI-powered and can handle data in TB/per day without any interruptions in services. Live dashboards, developing use-cases and their capabilities (correlation).
Cons:
complex architecture and efficient skills are required, financial is also not feasible for small and medium customers. no inbuilt query builders for beginners to understand the platform.
Powerful tool to perform db queries
Comments: I used Splunk to surface and review platform logs
Pros:
Possibility to export query results in a variety of formats.
Cons:
User interface is not intuitive and it requires a steep learning curve
Alternatives Considered:
Splunk is a great solution for SIEM and also for monitoring your infrastructure
Comments: We needed a way to monitor our internal environment and start to be more proactive with issues, so we started sending all of our logs to Splunk and we we able to get insights we did not know we needed. It is a great solution and they are constantly innovating.
Pros:
Splunk makes it easy to search through various data including logs. In the past I have had to pour through logs in order to find the one lines among the 100 of thousands of lines. Splunk allows me to search through those logs in a matter of seconds vs the hours it used to take.
Cons:
Most of enterprise setup is done through the command line. It would be nice to have cluster configuration (index creation) as part of the UI.
Alternatives Considered:
Splunk Enterprise, not just a SIEM
Comments: We have been using Splunk Enterprise, ES, ITSI, and other Splunk parts for 6+ years in production. This has helped us reduce staff in some cases, increase response time in most cases, and allow non-IT teams to get data and metrics in a fast efficient way.
Pros:
The versatility is amazing. The same data in logs, such as IIS, can be used for Security, Application performance, and even error handling. This allows us to use one log to help multiple teams. This is just one example.
Cons:
Start up takes someone who has had some training. While searching and output is easy, its the onboarding of custom apps that takes the know how.