Splunk Enterprise

Machine data management and analytics

Classificação geral

4,6 /5
(166)
Relação qualidade/preço
4,3/5
Recursos
4,5/5
Praticidade
4,1/5
Suporte ao cliente
4,3/5

96%
dos usuários recomendam este app
Classificar por

166 avaliações

Mauricio
Classificação geral
  • Setor: Bancos
  • Porte da empresa: 1 001-5 000 funcionários
  • Usado Diariamente durante Mais de dois anos
  • Fonte da avaliação

Classificação geral

  • Relação qualidade/preço
  • Praticidade
  • Suporte ao cliente
  • Probabilidade de recomendação 5.0 /10

Splunk, Solução para Monitoramento e Relatórios

Avaliado em 04/10/2022

Gosto do uso simples e da facilidade na criação de Dashboards. A linguagem é muita parecida com Pl SQL

Vantagens

As Dashboards são incríveis e precisas. Podemos criar utilizando a interface do programa ou por Comandos muito parecidos com Pl SQL.

Desvantagens

Nada a declarar, o software atende a todas as necessidades.

Sachin
Classificação geral
  • Setor: Software
  • Porte da empresa: 10 000+ funcionários
  • Usado Diariamente durante 6 a 12 meses
  • Fonte da avaliação

Classificação geral

  • Relação qualidade/preço
  • Praticidade
  • Suporte ao cliente
  • Probabilidade de recomendação 9.0 /10

Splunk: A Monitoring Tool for all your needs

Avaliado em 30/04/2022

If i have put a word it would say "Fantastic". The functionalities Splunk provides eases team to manage/monitor their IT infrastructure and internal application you will be well aware about the performance of your applications. Setup alerting and take necessary actions in stipulated time to overcome all the issues which may affect your application performance.

Vantagens

Splunk offers various features whether you need to setup monitoring on your server, application logs based on logs ingestion set alerts so that teams got notified on real time and take actions accordingly. In this way, it helps to monitor application which are mission critical. You can make dashboards in Splunk where you can configure various components such indexes, data inputs and schedule reports as well. To achieve additional functionalities we can install third party apps as well such as AWS Add on for cloud watch log ingestion.

Desvantagens

From Admin perspective, I found user access management a little difficult. The roles of access management becomes complicated because some time the config files for that didn't came very handy. Other then that I think all in all Splunk provides fulfill all of the requirements.

Avaliador Verificado
Classificação geral
  • Setor: Saúde, bem-estar e condicionamento físico
  • Porte da empresa: 1 001-5 000 funcionários
  • Usado Diariamente durante Mais de dois anos
  • Fonte da avaliação

Classificação geral

  • Relação qualidade/preço
  • Praticidade
  • Suporte ao cliente
  • Probabilidade de recomendação 9.0 /10

Splunk Enterprise, not just a SIEM

Avaliado em 27/05/2022

We have been using Splunk Enterprise, ES, ITSI, and other Splunk parts for 6+ years in production. This has helped us reduce staff in some cases, increase response time in most cases, and allow non-IT teams to get data and metrics in a fast efficient way.

Vantagens

The versatility is amazing. The same data in logs, such as IIS, can be used for Security, Application performance, and even error handling. This allows us to use one log to help multiple teams. This is just one example.

Desvantagens

Start up takes someone who has had some training. While searching and output is easy, its the onboarding of custom apps that takes the know how.

Alternativas consideradas

Sumo Logic

Razões para mudar para o Splunk Enterprise

Versatility with custom applications we create in house.
Avaliador Verificado
Classificação geral
  • Setor: Serviços financeiros
  • Porte da empresa: 10 000+ funcionários
  • Usado Diariamente durante Mais de dois anos
  • Fonte da avaliação

Classificação geral

  • Relação qualidade/preço
  • Praticidade
  • Suporte ao cliente
  • Probabilidade de recomendação 10.0 /10

Best friend for debugging

Avaliado em 13/10/2022

Splunk basically makes debugging and monitoring easier and touch less. I can easily debug by starring the rolling logs from different instances in single screen.
I can monitor multiple components and multiple metrics, without running commands manually with custom plugins.

Vantagens

Splunk comes with lot of in-built templates for each and every feature like log visualisation, dashboarding, traces,etc This makes the developers life lot easier. I can't think of any other logging tool that is snappy as well as accurate.
I love the fact how easily I can plug it in my docker-compose to push container logs.

Desvantagens

Even though, it offers numerous features for different needs, each feature has its own learning curve. For instance log visualisation needs querying skills, which may be in natural language but it takes bit of time to get familiar.

Patrick
Classificação geral
  • Usado Diariamente durante Mais de dois anos
  • Fonte da avaliação

Classificação geral

  • Praticidade

Spunk Review

Avaliado em 17/05/2017

Vantagens

It allows me to bring a lot of information into one friendly view. It's a great security audit tool.

Desvantagens

It has limited functionality. It is a very memory intensive system. It does not integrate with Lennox.

Davis
Classificação geral
  • Setor: Software
  • Porte da empresa: 11-50 funcionários
  • Usado Diariamente durante Mais de dois anos
  • Fonte da avaliação

Classificação geral

  • Relação qualidade/preço
  • Praticidade
  • Suporte ao cliente
  • Probabilidade de recomendação 8.0 /10

The most expensive tool, requiring highly-skilled employees, capable of limitless value

Avaliado em 19/09/2022

Splunk's SPL is a flexible, straight forward query-language with aspects of SQL, R, Python, and Bash. The fact that an analyst can learn to be an engineer through using the platform provides ease of growth. It is unmatched in its automation to make data actionable, while providing reporting and visualization capabilities.

Vantagens

Splunk is provides a single tool for log aggregation, log analysis, and visualizations. Threat hunting, applying threat intelligence, and incident response are easily repeatable; pushing organizations to proactive security processes.

Desvantagens

Splunk is expensive, especially when an organizations is exploring and building new security or data use cases. It also requires a lot of engineering maintenance, making the quality of the data highly-dependent on the skill(s) of those supporting it. Many organizations do not maximize its benefit because it is poorly managed or supported by low-skilled employees.

Alternativas consideradas

Elastic Stack

Razões para mudar para o Splunk Enterprise

Splunk scales in all aspects except price. Organizations that are serious about security and SIEM tools will see the value in their investment almost immediately. The insights from the analytics and development capabilities are not available in other tools with this level of ease.
Ariev
Classificação geral
  • Setor: Software
  • Porte da empresa: 10 000+ funcionários
  • Usado Diariamente durante 6 a 12 meses
  • Fonte da avaliação

Classificação geral

  • Relação qualidade/preço
  • Praticidade
  • Suporte ao cliente
  • Probabilidade de recomendação 9.0 /10

Aneeded for the industry on the basic to the best role.

Avaliado em 21/08/2022

It's a great tool and used for many years to come.

Vantagens

Real time use. The ingestion of data and more.

Desvantagens

Nothing yet.. maybe performance at times.

Alternativas consideradas

IBM Security QRadar

Razões para mudar para o Splunk Enterprise

Better for the industry and real time use. More expensive.
Chetan
Classificação geral
  • Setor: Serviços e tecnologia da informação
  • Porte da empresa: 11-50 funcionários
  • Usado Diariamente durante Mais de um ano
  • Fonte da avaliação

Classificação geral

  • Relação qualidade/preço
  • Praticidade
  • Suporte ao cliente
  • Probabilidade de recomendação 8.0 /10

Splunk the best analytic tool

Avaliado em 05/10/2022

It gives best Return on Investment as analyzing the data and giving proper insights in form of Dashboards and notifying with help of Alerts if any kind of threat running in infrastructure and apart from that Deployment and use is very easy.

Vantagens

There are lot of features which Splunk offers -
1) We can onboard data from any server, device or system using Universal Forwarder
2) Onboarded data are later stored in Indexers and searched further in Search Head for analyzing the internal logs
3) Using the data we can create customizable Dashboards and get proper insights of data and create Alerts to identify any kind of Threat or anomalies running in environment
4) Deployment is very easy on-prem servers
5) We can also use Hybrid Deployment on Cloud as well.

Desvantagens

1) As it give large amount of features but licensing is too high
2) There are lot of other Open Source software which can be used as alternative of Splunk as Analytic tool because Splunk is paid one.

stephanie
Classificação geral
  • Setor: Serviços e tecnologia da informação
  • Porte da empresa: 10 000+ funcionários
  • Usado Semanal durante Mais de um ano
  • Fonte da avaliação

Classificação geral

  • Relação qualidade/preço
  • Praticidade
  • Suporte ao cliente
  • Probabilidade de recomendação 9.0 /10

With Splunk Enterprise , we can rapidly detect and get rid of bottlenecks.

Avaliado em 02/11/2022

Splunk Enterprise is the basis of our SIEM. We use it for log correlation and analysis. It collect events from multiple sources for analysis. I love using Splunk enterprise. It is the best platform that we have for monitoring data and identifying issues in real time.

Vantagens

The tool can collect all sorts of data from diffuse sources and preform advanced analytics on it. It has powerful monitoring capabilities useful in threat identification and maintaining the health of our IT infrastructure. Splunk enterprise helps us to foresee, trends through machine learning which has been a crucial to making informed business decisions.

Desvantagens

Training new users is tough, the learning curve is very steep and it gets overwhelming for them. The installation and configuration process is very long and needs a lot of time.

Michael
Classificação geral
  • Setor: Indústria farmacêutica
  • Porte da empresa: 10 000+ funcionários
  • Usado Semanal durante Mais de dois anos
  • Fonte da avaliação

Classificação geral

  • Praticidade
  • Probabilidade de recomendação 9.0 /10

Great tool for log collection

Avaliado em 10/11/2022

Vantagens

Consolidation! All logs are consolidated in one place, which makes searching and analytics better.

Desvantagens

The search features are complicated. I end up needing help every time I have to search through the logs. You need a dedicated support team.

shabbir
Classificação geral
  • Setor: Serviços e tecnologia da informação
  • Porte da empresa: 51-200 funcionários
  • Usado Diariamente durante Mais de um ano
  • Fonte da avaliação

Classificação geral

  • Relação qualidade/preço
  • Praticidade
  • Suporte ao cliente
  • Probabilidade de recomendação 8.0 /10

Complete Security operations with Splunk

Avaliado em 03/10/2021

Splunk data visualization and its analytics handling chunks of data is exceptional.

Vantagens

Data visualization, Analytics skills with AI-powered and can handle data in TB/per day without any interruptions in services. Live dashboards, developing use-cases and their capabilities (correlation).

Desvantagens

complex architecture and efficient skills are required, financial is also not feasible for small and medium customers. no inbuilt query builders for beginners to understand the platform.

Alternativas consideradas

AlienVault OSSIM

Razões para escolher o Splunk Enterprise

Its niche player was can handle only a few products data and not so feasible in terms of query building and customization in dashboards. Good for small businesses not for enterpraises.

Software anterior

AlienVault OSSIM

Razões para mudar para o Splunk Enterprise

Not so feasible in handling data and its simple architecture cannot handle logs from all the data sources.
THOMAS
Classificação geral
  • Setor: Telecomunicações
  • Porte da empresa: 51-200 funcionários
  • Usado Diariamente durante Mais de um ano
  • Fonte da avaliação

Classificação geral

  • Relação qualidade/preço
  • Praticidade
  • Suporte ao cliente
  • Probabilidade de recomendação 9.0 /10

Splunk an Enterprise Business intelligent user tool

Avaliado em 18/02/2021

Is a robust and intelligent management tool that enables everyone with user computer knowledge to navigate in real-time, consolidate vast data into a visualized report of dashboard features , reliable and web based, no major equipment required for setup, user need a smartphone or compute to access the platform through the web, you can navigate the system as long as you have computer knowledge without any training required(user friendly) .

Vantagens

It an intelligent business tool that provided me an opportunity to customize and build report from large volume of data from different departments within the 13 Africa countries in telecommunication sectors. The platform allows data to be consolidated accordingly to the organization need and produces visualized reports of dashboard features. I also noted that the system can analyst unstructured large volume of data speedily and is reliable and web based allowing for user flexible accessible from any part of the world if you have internet. The systems have been reliable and secured from the time (2 years) I started using it without any system intermittent, system errors and cyber-attack.

Desvantagens

The system is built and use-able with structured and unstructured organization though the price in foreign currency could hamper small and medium organization to use it especially in most Africa country where the local currency has depreciated against the major trading foreign currency.so the Forex pricing is a challenge.
The navigation of the platform will require minor training though if the user is computer proficient, they would management with minor challenge and interpretation of the data. So, first time user it can be difficult to use it
It will depend on internet for access and internet tend to be pricey in most African country and therefore could increase the business cost for small and medium enterprise. It can increase business cost if not fully used

Gabe
Classificação geral
  • Setor: Serviços e tecnologia da informação
  • Porte da empresa: 5 001-10 000 funcionários
  • Usado Diariamente durante Mais de um ano
  • Fonte da avaliação

Classificação geral

  • Relação qualidade/preço
  • Praticidade
  • Suporte ao cliente
  • Probabilidade de recomendação 9.0 /10

A powerful log aggregation solution with immensely useful tools built-in for popular applicatio...

Avaliado em 22/02/2018

Vantagens

- Free to use for small 500MB or less daily ingress, quite nice for small use cases and learning
- No development work required to deploy and provide value.
- Deployment flexibility: client agents are available to use, or clientless configurations for multiple OS platforms. It's also very easy to deploy, not just flexible. its a very simple affair.
- Segmentation of logs: You can create separate instances of of logs to aggregate, based on organization needs. And those instances can have their own individual storage policies to optimize consumption of storage resources.
- Configuration design: Thoughtful and mature documentation and design of the application regarding enterprise-class scaling on network storage.
-POWERFUL tools: The user interface lends itself to learning more about your organization from the logs you collect, through metrics of trends of the logs being gathered. There are also specific modules/add-ons for popular applications to provide more value and event-based monitoring, all without having to develop in-house dashboards and intelligence of those logs.
- Customization: You can create your own queries of logs, and event-based alerts.
- Web-based GUI that clean is powerful
- Sales/Technical Reps are top notch in fielding questions and evaluating environment for deployment. They were extremely helpful in helping our organization develop procedures and scaling our environment for expansion with our existing infrastructure.

Desvantagens

- Price: This product is not free for more than the minimal use. Pricing can be very expensive, relative to open source offerings. That is the trade-off you pay for not having in-house development of open source offerings. As this product is priced based on gigabytes of indexed logs, it is important to understand the scope of licensing necessary for your environment to determine if it is a good fit for your organization.
- Watch your saved queries and hardware resources: Users have the ability to create and save queries. Like in database queries, some are more efficient than others. Large inefficient queries can be very resource-intensive. If you notice slowness in day-to-day queries, or navigation in the UI, or resource use in contention, keep an eye on saved queries and user practices.

Avaliador Verificado
Classificação geral
  • Setor: Serviços financeiros
  • Porte da empresa: 10 000+ funcionários
  • Usado Diariamente durante Mais de dois anos
  • Fonte da avaliação

Classificação geral

  • Relação qualidade/preço
  • Praticidade
  • Suporte ao cliente
  • Probabilidade de recomendação 10.0 /10

Splunk is a great solution for SIEM and also for monitoring your infrastructure

Avaliado em 03/03/2020

We needed a way to monitor our internal environment and start to be more proactive with issues, so we started sending all of our logs to Splunk and we we able to get insights we did not know we needed. It is a great solution and they are constantly innovating.

Vantagens

Splunk makes it easy to search through various data including logs. In the past I have had to pour through logs in order to find the one lines among the 100 of thousands of lines. Splunk allows me to search through those logs in a matter of seconds vs the hours it used to take.

Desvantagens

Most of enterprise setup is done through the command line. It would be nice to have cluster configuration (index creation) as part of the UI.

Alternativas consideradas

Elastic Stack

Razões para mudar para o Splunk Enterprise

Spelunking was simple to setup and the customer service is great. It performed very well and proved to be a valuable assets to run in Production.
Amit
Classificação geral
  • Setor: Telecomunicações
  • Porte da empresa: 10 000+ funcionários
  • Usado Diariamente durante 6 a 12 meses
  • Fonte da avaliação

Classificação geral

  • Relação qualidade/preço
  • Praticidade
  • Suporte ao cliente
  • Probabilidade de recomendação 9.0 /10

Best tool for Distributed logs data analysis

Avaliado em 15/04/2020

We have several micro-services deployed in production which require to lookup application access as well as server logs and analyze data for their usage. We created several reports/charts for visualization. We use splunk as security logs tool to see the firewall traffic, tracing any vulnerable access, any database related crash ..etc.
It helps easily to find issue and fixed quickly by black listed in system.

Vantagens

Splunk Enterprise is best tool to analyze the data based on different visualization. It help us to lookup distributed logs for micro-services . It enables field based lookup. For complex logging, we can use search query using expression. We can create multiple reports/charts for visualization such as a pie or bar chart for our data. Best feature what i like , We can visualize our search results and share them with others using dashboard panels. If Already have a dashboard, we can add a new panel from a report, clone from another dashboard, or add a prebuilt panel. Fully customization available. Interfaces is very flexible. We export it in different formats, or refresh it to visualize the newest data. Online Support is available through different community.

Desvantagens

Search query builder is fully based on technical. for Non technical users, its really difficult to lookup logs. Sometimes, error thrown by query builder is more difficult to understand. Deep Learning is required to use splunk for production data. For Large application installation, it need to manage more.

Avinash
Classificação geral
  • Setor: Segurança de rede e informática
  • Porte da empresa: 10 000+ funcionários
  • Usado Diariamente durante Mais de dois anos
  • Fonte da avaliação

Classificação geral

  • Relação qualidade/preço
  • Praticidade
  • Suporte ao cliente
  • Probabilidade de recomendação 8.0 /10

Splunk - Onestop Log Management & Forensics

Avaliado em 17/04/2021

Overall i like the product but as the user base grows the logs grows too. This busts the limits of the licensing.
We need to keep on doing housekeeping to ensure that our license limits is not crossed.

Vantagens

The ablitity to configure and tweak the use cases. Building Intelligence into forensics. The AI feature is gud but needs more enhancements.

Desvantagens

The log management needs to be efficient , If the auditing logs is enabled then a huge influx of logs are pumed into splunk but no meaningful meaning can be derived.

Alternativas consideradas

FortiClient e Trellix Endpoint Security

Razões para mudar para o Splunk Enterprise

Splunk is a one whole package with features like AI & Forensics and also keeps you updated with the latest and newest threats..
Avaliador Verificado
Classificação geral
  • Setor: Software
  • Porte da empresa: 1 001-5 000 funcionários
  • Usado Diariamente durante Mais de dois anos
  • Fonte da avaliação

Classificação geral

  • Relação qualidade/preço
  • Praticidade
  • Suporte ao cliente
  • Probabilidade de recomendação 8.0 /10

Great, wholistic centralized monitoring solution

Avaliado em 11/05/2021

I've been using Splunk for over 8 years. I've seen it constantly improve and change a lot. I do enjoy it. Cloud is getting better and much better parity with on-prem

Vantagens

We use this as our SIEM. The ability to have the data ingest, visualization, alerting and correlation all in one product is very important to me from a security standpoint. We're cloud-first so having that ability with large cloud providers is important to me (AWS, Okta, GCP, etc)

Desvantagens

The cost can be a little concerning and htere is a bit of a learning curve when you first get into Splunk. User groups, their forum and pro serv all help with that.

Alternativas consideradas

Datadog e Elastic Stack

Razões para mudar para o Splunk Enterprise

Better product.
devaun
Classificação geral
  • Usado Diariamente durante Mais de dois anos
  • Fonte da avaliação

Classificação geral

  • Praticidade
  • Probabilidade de recomendação 7.0 /10

Query your log statements for your production apps in REAL TIME to triage and monitor...

Avaliado em 02/02/2018

XRAY vision on your production instances. Every day we code our applications so that we will be splunk friendly with our app log statements. For example "featureX=value" allows you to query for every customer that engaged with featureX.

Vantagens

Splunk allows us to see exactly what is going on in production! I work on commerce for a fortune 100 company, and we use Splunk to monitor our apps in real time. Splunk gives you the ability to perform queries like you would with SQL against your log statements in real time. You will learn that you can place strategic log statements in your code that allows you to identify situations in production and be proactive at solving them. For example, you can log your customer's session cookie ID, and track any given customer's activity on your website via your app logs. It gives you dials and charting capabilities to monitor even the slightest drops in customer activities due to flaws in code or slowing network calls.

Desvantagens

PRICE. The software is so powerful, and they seem to leverage this in the pricing of the licenses.

Avaliador Verificado
Classificação geral
  • Setor: Administração pública
  • Porte da empresa: 51-200 funcionários
  • Usado Diariamente durante Mais de dois anos
  • Fonte da avaliação

Classificação geral

  • Relação qualidade/preço
  • Praticidade
  • Suporte ao cliente
  • Probabilidade de recomendação 9.0 /10

Great Choice for an SIEM

Avaliado em 02/12/2021

Vantagens

Provides a single location for collecting and analyzing logs. Provides ease of use for non-technical users, but powerful features for security and IT. There is an add-on/app for anything you could imagine.

Desvantagens

Some documentation is vague, and when certain things don't work, it can be difficult to find out a solution to the problem.

Alternativas consideradas

Sumo Logic

Razões para mudar para o Splunk Enterprise

We needed a product that we could host ourselves.
David
Classificação geral
  • Setor: Entretenimento
  • Usado Diariamente durante Mais de dois anos
  • Fonte da avaliação

Classificação geral

  • Relação qualidade/preço
  • Praticidade
  • Suporte ao cliente
  • Probabilidade de recomendação 9.0 /10

Offers more than you think

Avaliado em 07/02/2018

We've used the software to detect layer 7 attacks, unearth issues we didn't realize were happening and gives us end to end insight into our stack.

Vantagens

The system is highly intuitive to use. It is faster than other solutions I've used on the market and has a huge library of 3rd party plugins to get more from the system. It is easy to create scheduled searches, dashboards, reports etc. but there are a number of additional plugins (at an extra cost) to help with security, single pane of glass and metric collection.

Desvantagens

It offers challenges for a decentralized working model. Where Splunk is centrally managed, it is easy to ensure that best practices are maintained. Where the system is opened up for an entire department to utilize and on-board their logs, it becomes more difficult. However, with some creative thinking and good process, this issue can be overcome.

kalaiselvan
Classificação geral
  • Setor: Serviços e tecnologia da informação
  • Porte da empresa: 501-1 000 funcionários
  • Usado Diariamente durante Mais de um ano
  • Fonte da avaliação

Classificação geral

  • Relação qualidade/preço
  • Praticidade
  • Suporte ao cliente
  • Probabilidade de recomendação 9.0 /10

Splunk review

Avaliado em 12/07/2019

Overall, it is a very good monitoring tool for an support team and developers for doing root cause analysis.

Vantagens

Splunk Visually represents the logs mainly from production servers in the web UI .

People who Usually has no access to logs in production servers, will access the logs through splunk UI with very simplified and friendly search query.

It has lot of features like you can query for particular date and time range with specific characters. The search engine is very fast which will bring the query response effectively.

we can access all types of logs including XML and JSON.

we can create a custom dashboard with custom query for each projects and can relatively trigger the email to the support team in case of any issues.

This tool is boon for production support team in any enterprise company.

Desvantagens

Licensing cost is quite higher for enterprise usage.

Query response time will be slow when you are searching for relatively longer history(Eg. 3 months old data)

Divyang
Classificação geral
  • Setor: Serviços e tecnologia da informação
  • Porte da empresa: 201-500 funcionários
  • Usado Diariamente durante Mais de um ano
  • Fonte da avaliação

Classificação geral

  • Relação qualidade/preço
  • Praticidade
  • Suporte ao cliente
  • Probabilidade de recomendação 8.0 /10

Manipulate You Data

Avaliado em 28/09/2020

Splunk is widely used for manipulation of data and we encounter the use of this tool almostl twice a week. Even though it costs much more but still we have not found any alternative that is able to offer all these functionalities.

Vantagens

Splunk is very easy to use due to high community support and many video tutorials available online for new users to learn.
Functionalities are robust and simple to use. Data retrieval and visualisation is nice and easy if you know the right querying process.
Machine Learning supports enhances performance for the cloud, especially. It collect wide variety of data and still it amaze you the way it retrievs it.

Desvantagens

There are many tools available in market which are potential competitors of this tool and that too at reasonable pricing. Splunk offers more functionalities but costs you too much if you look at the work it does.
Complex queries may require large CPU usage and may even freeze or atleast slow down the system for a while. Need to be specific while querying the data.

Avaliador Verificado
Classificação geral
  • Setor: Varejistas
  • Porte da empresa: 10 000+ funcionários
  • Usado Diariamente durante 6 a 12 meses
  • Fonte da avaliação

Classificação geral

  • Relação qualidade/preço
  • Praticidade
  • Suporte ao cliente
  • Probabilidade de recomendação 10.0 /10

A tool which is one for all

Avaliado em 16/10/2020

Splunk has made me realize the ability to correlate different data from different realms altogether and generate valuable insights.

Vantagens

The ability to use this software for security operations, data analysis, creating dashboards, generating tickets and everything else

Desvantagens

Splunk uses its own SPL, which is not very easy to learn. However, there are lots of documentation that Splunk provides to its customers. There is paid training available which is useful for beginners to learn.

Alternativas consideradas

IBM Security QRadar

Razões para mudar para o Splunk Enterprise

Splunk has much more capabilities than IBM QRadar. The ability to automate things using Splunk is extraordinary which makes Splunk the market leader.
Robert
Classificação geral
  • Setor: Consultoria de gestão
  • Fonte da avaliação

Classificação geral

  • Praticidade
  • Suporte ao cliente
  • Probabilidade de recomendação 10.0 /10

Finding Splunk Before Splunk Finds You

Avaliado em 30/06/2015

Vantagens

Splunk is more than a tool or a product, it is a big data platform. Splunk can be used as a simple log aggregator all the way to a Big Data engine to find efficiency in operations of the Internet of Things. Splunk is less about its abilities, and more about your imagination about what you can do with Splunk. That is the beauty of the platform. Splunk shines in providing operational intelligence about systems and processes. Finding out how your systems are operating, how your processes are functioning leads to quick resolution of problems and points to where budgets are best spent.

Desvantagens

Splunk is deceptively easy to set up and use. But like learning to play chess, you can learn the moves in half an hour, but take a lifetime to master. Splunk quickly provides value, but requires imagination and creativity as well as wide ranging knowledge of systems and processes to move to the next level. Not every organization needs that kind of talent to get a great return from Splunk, but the companies who compete and win will.

Frank
Classificação geral
  • Setor: Software
  • Porte da empresa: 5 001-10 000 funcionários
  • Usado Semanal durante Mais de dois anos
  • Fonte da avaliação

Classificação geral

  • Praticidade
  • Probabilidade de recomendação 10.0 /10

Doing setup redundant servers without Splunk

Avaliado em 20/12/2020

Saved my a$$ many times. In a multi-server environment, if you don't have Splunk or something like it, it will be a nightmare to try and coordinate the various log files involved.

Vantagens

Several of our applications are distributed across multiple systems. It is the same software running on each server but doing the same job for different users. Each server would generate its own log files. When things went wrong, we used Splunk to be able to see what was going on on each server. Click a few buttons and you get two logs from two different servers listed together coordinated by time. But that leads you to discover that the issue came from a separate upstream or downstream server, then bring in those logs too . . . all coordinated by time. Don't get me wrong, the IT guys love these tools for their own enterprise reasons, but as a server stack developer, this was a resource I used OFTEN.

Desvantagens

I never fully grokked their SQL like language. I could do basic things daily without issue. However, I often had to hit the documentation to do anything more than a simple "find this" query.