Help the communities most affected by the California wildfires in only a few minutes. We'll donate $10 for every review you submit.

Splunk Enterprise

4.3
(252)

Splunk is a software platform for machine data that enables customers to gain real-time Operational Intelligence.

Work for Splunk Enterprise?

Learning about Splunk Enterprise?

We can help you find the solution that fits you best.

Splunk Enterprise Reviews

Chat with a G2 Advisor
Write a Review
Filter Reviews
Filter Reviews
  • Ratings
  • Company Size
  • User Role
  • For Category
  • Industry
Ratings
Company Size
User Role
For Category
Industry
Showing 268 Splunk Enterprise reviews
LinkedIn Connections
Splunk Enterprise review by Gregg W.
Gregg W.
Validated Reviewer
Verified Current User
Review Source
View Original
Business partner of the vendor or vendor's competitor, not included in G2 Crowd scores.

"Splunk: IT legos for Beginners through Master Builders!"

Sign in to G2 Crowd to see what your connections have to say about Splunk Enterprise
Splunk Enterprise review by Mark A.
Mark A.
Validated Reviewer
Verified Current User
Review Source
Business partner of the vendor or vendor's competitor, not included in G2 Crowd scores.

"Splunk is like the eyes of your Security Snipers, without it you won't be stopping the bad guys."

What do you like best?

Splunk is a great application that is super fast to install and setup. Everyone should be using this product after seeing how great of an impact it makes on your security posture.

What do you dislike?

Splunk does charge a pretty penny for the higher levels of certification. But the cost paid to value earned is totally worth the cost of certifications needed.

Recommendations to others considering the product

While Splunk is amazing, you will inevitably run into problems that need fixing. Enter "Splunk Support". Splunk's support team is awesome at solving complex problems and bugs found in the software. They are serious about fixing whatever problems you may encounter with their product. The last issue we had that we raised to Splunk's support team was fixed within a couple days. I mean come on, "a couple days" is how long it takes to get a cup of coffee folks! Aside from Splunk's support team, the Splunk community is incredibly powerful. There's all kinds of events, forums, videos, conferences and meetings that you can go to and have your questions answered. Splunk is by far the best product on the market and it will continue to be in the future. So what are you waiting for? Get on the band wagon!

What business problems are you solving with the product? What benefits have you realized?

When you have the visibility Splunk give you into your data at the speed and ease that Splunk provides it, your options are limitless. We've been using it in the SOC and it is amazing how easy it is to find problems and fix them once they are found.

What Big Data Analytics solution do you use?

Thanks for letting us know!
Splunk Enterprise review by Nathan P.
Nathan P.
Validated Reviewer
Verified Current User
Review Source

"If there's a problem, yo, Splunk'll solve it."

What do you like best?

Splunk enables me and my customers to find needles they didn't know they needed in stacks of other needles. A large portion of our solutions started in hallway conversations leading to "I wonder if Splunk could ..." and it invariably can.

In an enterprise environment of any complexity, there are hurdles with any product, but the Splunk community, as well as education and docs teams are incredibly helpful resources.

They offer trial, dev, and dev/test licenses, so I can run Splunk at home, on my laptop, as one-off testing setups, etc.

They also offer free licenses to non-profits under their Splunk4good program.

What do you dislike?

x.0.0 releases are frequently buggy, but they get patches out fairly quickly.

Splunk could really use a naming scheme makeover. (I'm looking at you, deploy*.)

Recommendations to others considering the product

Grab a trial license and start playing with it. Read the docs. Join a user group. Get some training; the first (fundamentals) course is free!

What business problems are you solving with the product? What benefits have you realized?

We largely use Splunk for fraud prevention and security monitoring/investigation. Splunk has enabled those teams to get significantly more work done in less time with the same number of analysts. Across just two small-effort projects, we discovered fraud and inefficiencies that, once eliminated, are now saving us over $100k per month. Splunk doesn't look so expensive now, does it?

Splunk Enterprise review by Mittal M.
Mittal M.
Validated Reviewer
Verified Current User
Review Source

"Analyzed you data"

What do you like best?

Splunk is a very simple and easy to use tool that Helps you and your team to analyze the information. Any data from network, servers, application. etc.

The best part I like about Splunk is that it is easy to deploy.

You can a simple utility call Splunk lite to push your data from your servers to the main Splunk engine.

The way Splunk indexes your data is very good. Which in returns good analytic results.

The report created by Splunk is very accurate. which helps my company to determine the improvement we need to do in our infrastructure.

The pricing model is very simple and reasonable.

They have very good well written online Knowledgebase articles to help use Splunk to its full use.

What do you dislike?

The trial version of Splunk is very limited it only gives 500 MB do daily data indexing. As a result, it may prevent you to get an insight of all the potential you can get through Splunk.

Recommendations to others considering the product

Definitely a good tool for your enterprise. If you would like to improve quality of your current process.

What business problems are you solving with the product? What benefits have you realized?

Splunk helps me and my team to analyze customer log data and helps us to find our pointers of the actual problem. This in return helps us to get back to our customer much quicker, thus improving overall customer satisfaction, better quality of work and improved work process.

Splunk Enterprise review by Timothy V.
Timothy V.
Validated Reviewer
Verified Current User
Review Source

"Great, but not amazing"

What do you like best?

The ability to build dashboards so we can test new notable alerts. The ability to set severity levels. We like the correlation events. Ability to ingest multiple indexes and create correlated searches, as opposed to just using a wildcard search. The dashboard layout is usefull and is very customizable. Integration via ES and other plugins allows us to spend time on one single pane of glass, do a pivot investigation and drill way down into the logs that were ingested. Metadata is easy to find, the logs are parsed neatly and are relatively easy to read once you get used to them. Training is also very good, and readily available online. Certification paths are also available

What do you dislike?

The load on our search heads, some queries take forever. Sometimes we have great difficulty with getting other products to parse logs correctly into splunk. API issues occasionally. The lag in the UI when running a search. The community could use better visibility, a central repository for splunk queries would be nice.

Recommendations to others considering the product

Carefully plan for the storage and processing power required to wield a tool such as this

What business problems are you solving with the product? What benefits have you realized?

Getting better visualization of threats in our environment via notable alerts. We are building out new automations and use cases for splunk on a weekly basis. Splunk is a primary intake for our analysts and we develop new notable alerts and use cases for our dashboards as well as continually tune and improve the information splunk is telling us.

Splunk Enterprise review by Richard G.
Richard G.
Validated Reviewer
Verified Current User
Review Source
Business partner of the vendor or vendor's competitor, not included in G2 Crowd scores.

"Love it!"

What do you like best?

It's flexible and powerful while still being easy to use. Valuable insights can come quickly with minimal effort.

The user community, both online and offline, is active, friendly, and very helpful. It's one of the best user communities I've encountered and has resulted in hundreds of apps (plug-ins) available for free use to help make Splunk even easier to use.

What do you dislike?

Larger implementations can be complex to build and maintain, often needing Professional Services assistance.

Recommendations to others considering the product

While Splunk is easy to use out of the box, you'll get more out of it if you take the free on-line training courses.

You can also install Splunk on your personal workstation for use as a test platform.

What business problems are you solving with the product? What benefits have you realized?

I've used Splunk to produce a Continuous Diagnostics and Monitoring (CDM) solution. I've also used it to consolidate 12 different monitoring tools into a single pane of glass. One of the first searches of network logs for a customer showed access from unexpected locations around the world. The customer was able to block access from those locations and prevent a possible security incident all because of Splunk.

Splunk Enterprise review by Niket N.
Niket N.
Validated Reviewer
Verified Current User
Review Source
Business partner of the vendor or vendor's competitor, not included in G2 Crowd scores.

"Platform for all Data Analytics needs"

What do you like best?

Splunk is a very powerful Data Analytics platform which can be adopted by users of all levels i.e. from tools like Data Tables for Novice to Splunk's Web Framework for Experts. What I like best is the significant improvements and capabilities they bring into the software with every major release is simply mind blowing.

What do you dislike?

We always need to wait a bit for latest release to be adopted at Enterprise level because of the unforeseen bugs. Good thing is one of Splunk Support, Professional Support, Splunk Answers Community and Slack might be able to assist with workaround or solution.

Recommendations to others considering the product

Get Splunk Enterprise for free to try out your use case, in most cases your proof of concept could easily be used as final analytics app that you need at your Enterprise.

Based on your technical experience with the product, reach out to Splunk's Sales Team for demo and Professional Services during implementation if required.

Go through numerous resources online from Use Cases and Case Studies to technical documentations, development tools, blogs and videos.

What business problems are you solving with the product? What benefits have you realized?

We have provided solutions to customers with their Operational Intelligence needs, Infrastructure Monitoring, Security and Business Intelligence.I felt turnaround time to be pretty fast and Splunk's capability to ingest almost all kinds of machine data gives it an significant edge over competitions for log aggregation and event correlation.

Splunk Enterprise review by Clara M.
Clara M.
Validated Reviewer
Verified Current User
Review Source

"Best Tool Around"

What do you like best?

It has made projects more efficient (ease of joining multiple sources together, search times are quicker, etc.) which frees up more of my time to research, explore, and work on more projects

What do you dislike?

Custom visualizations don't export to PDF

Recommendations to others considering the product

If you're looking for software the ingests streaming data, CSVs, etc., and can read warehouse data, this is a great tool. The documentation is very thorough for every topic from installation, administration, search, development, etc. The customization is incredible. It is a truly innovative company with an amazing community that is very helpful for answering questions. No other software like it on the market.

What business problems are you solving with the product? What benefits have you realized?

I use Splunk Enterprise for Business Intelligence and use it to answer questions relating to revenue, product usage, system usage and health, etc. One amazing benefit is that we don't have to grab data from five different applications and join them all together in another tool to analyze. Splunk creates a single pane of glass and allows us to access all the data we need in one place.

Splunk Enterprise review by Rich M.
Rich M.
Validated Reviewer
Verified Current User
Review Source

"We do so much more than just what's listed"

What do you like best?

The versatility. We ingest some of the worst looking logs and force them into a usable form, generating reports and dashboards that business users make decisions from. At times I use Splunk as a clearinghouse for terribly formatted data that I don't even directly use, taking data that makes my BI team cry, reformatting it, cleaning it up and shoving it into a database for them to use further down the pipe. In the more standard uses, we use it to correlate various pieces of information from across our environment to identify when weird things are happening so we can better address them. But two of its primary strengths are the quality of the documentation and the thriving and active user community (answers.splunk.com, User Groups, their Slack channel and so on) who are always willing to help out if you need it!

What do you dislike?

There's can be a significant amount of complexity, some of which is due to the domain across which it works, but some of which hasn't been smoothed over yet by Splunk. This is mostly not in the core product but in some of the Apps, which just need a little work. See comments on the community above, though - there are replacement apps and lots of help available on the Slack channel and in Answers!

Recommendations to others considering the product

Splunk Fundamentals I is a ~8 hour free online course that gives you a basic understanding of how Splunk works, I recommend signing up for that and using that as your springboard. There's a free download of Splunk Enterprise that enables all features for 30+ days, you can switch it to a free version after that which costs nothing. Then get into Answers and into Slack in the Splunk user group channels and start playing around!

What business problems are you solving with the product? What benefits have you realized?

The quick ability to make sense of new data has changed how we react to many situations, speeding up responses to complex questions we may have. The ability to correlate all the disparate events thrown out by all our devices and distill them into a small set of events that are actually unusual is one of the cornerstones of how we react to anomalies.

Splunk Enterprise review by Jaya Krishna T.
Jaya Krishna T.
Validated Reviewer
Review Source

"Sr. Database Administrator"

What do you like best?

Splunk provides a great ease in reading the logs. It helps us analyze the metrics on a regular basis to troubleshoot production issues. We have been using Splunk for quite a few years now and it has always been a great tool use to analyze the data patterns and alert us on all performance related issues and pattern matching.

What do you dislike?

There is not much of dislike on the product. It's more of how much I can help reviewing the production to help it enhance its ease of use.

It would be great to have multiple levels of automation setup within splunk where in it allows users to choose what exactly they want by looking at the earlier patterns and usage of the product. By showing this suggestions, it will be easy for the users to make sure they take into consideration the suggestions shown by splunk to make a wise decision whether to go ahead with the suggestion or implement a new one.

Recommendations to others considering the product

Its a great product

What business problems are you solving with the product? What benefits have you realized?

We are using splunk to log all our web and application logs. Using this log we are having a great ease at the time of post mortem an issue to take a look at the pattern and troubleshoot accordingly.

also for any issues which pop-up during the connection timeouts, we are able to pin point which user its creating problem and take the necessary steps.

Splunk is helping us choose and make our lives easy by ease of use.

Splunk Enterprise review by Kevin P.
Kevin P.
Validated Reviewer
Verified Current User
Review Source

"Great tool if you need log aggregation"

What do you like best?

Splunk provides an easy way to search multiple log files over a period of time. You can search by any combination of unique text. The syntax is similar to that of SQL where you can use keywords such as AND and OR. Logs are archived for time capsule viewing.

What do you dislike?

It's rich with features which can be overwhelming. The search over a long period of time can sometimes be slow and fail to pull back result altogether. If you try to view a log's source, it can take several minutes for results to return.

Recommendations to others considering the product

Splunk is a godsend for any large scale application/system that wants a solution to having to connect to individual boxes and viewing one log at a time.

What business problems are you solving with the product? What benefits have you realized?

Our system has many instances per application which each has its own log. Splunk aggregates all those instance logs into one and also archives older logs.

Splunk Enterprise review by Christopher M.
Christopher M.
Validated Reviewer
Verified Current User
Review Source

"Making Your Logs Usable"

What do you like best?

The ability to manipulate data in Splunk is unparalleled. Splunk’s powerful and flexible query language can morph difficult to understand log formats into usable data. Correlating data across different systems via one interface will allow you to know your environment or identify incident data in ways you never imagined.

What do you dislike?

There is a definite learning curve to starting out. However, there is a quite a bit of documentation out there to help you get started. In addition Splunk documentation, the community (Splunk answers/slack channel/user groups) can help get you moving along a lot faster.

What business problems are you solving with the product? What benefits have you realized?

Moving over to Splunk has enabled our organization to utilize log files that were previously being collected and not reviewed. With Splunk now these logs are constantly reviewed and used to provide insight to who is using applications and how they are using them.

Splunk Enterprise review by Cameron M.
Cameron M.
Validated Reviewer
Verified Current User
Review Source

"Splunk flavored Life Saver"

What do you like best?

Splunk allows me to quick diagnose problems and in most cases prevent them for going wide spread by pulling in logs from all of the sources in our development architecture.

What do you dislike?

The only thing I dislike is that it can be difficult to pull data in from a database, they make the DB Connect app, but it is does not work very well in our situation.

Recommendations to others considering the product

Give it a try and you will never look back. We started using Splunk just monitor a server that kept crashing, now we are fully integrating Splunk into our DevOps flow. Splunk is the glue that holds it together.

What business problems are you solving with the product? What benefits have you realized?

We are monitoring our internal application stack. Splunk has reduced on call incidents and allowed us to spend more time being proactive than reactive.

Splunk Enterprise review by Myles W.
Myles W.
Validated Reviewer
Verified Current User
Review Source

"Unrivaled Tool"

What do you like best?

The ease to scale and ingest multiple types of data sources with minimal effort. The effortless ability to begin digging through data without fully comprehending the content of the data itself.

ITSI is also a phenomenal App that really allows us to dig deep into services!

What do you dislike?

I've had a few issues with Apps and/or Add-ons working OOTB without a few customizations. Overall I don't have many dislikes about the product itself.

What business problems are you solving with the product? What benefits have you realized?

Right now I am using Splunk for 2 main purposes.

1. Troubleshooting other Enterprise applications to track down bottle necks, errors and in turn tune the application to better perform it's functionality that it was sold as. (The vendors will remain nameless)

2. Alerting for patterns or security concerns in multiple different security logs.

Splunk Enterprise review by Steven B.
Steven B.
Validated Reviewer
Verified Current User
Review Source

"It can help save lives!"

What do you like best?

The ease of splunk for using it to learn new insights into our data. With traditional log systems you can't review old logs and events using the new understanding you have about your data. However, Splunk performs extractions done at the time you search and allows you to look at old data with a new light.

What do you dislike?

The product can be very expensive for large scale. The price model per data consumed per day can grow quickly and often requires a person to evaluate if the data being logged has any business value.

What business problems are you solving with the product? What benefits have you realized?

Our splunk environment is used to help troubleshoot problems, monitor for security incidents, and has even helped our police department locate in distress person's quick enough to provide intervention.

Splunk Enterprise review by Administrator in Defense & Space
Administrator in Defense & Space
Validated Reviewer
Verified Current User
Review Source

"Splunk can do it all"

What do you like best?

It isn't really a question of whether or not you can accomplish something with Splunk. The question is more about how much time and money it would take to accomplish something using Splunk. Some things are very simple and Splunk does provide a low barrier to entry, allowing you to obtain value from your data right from the start. While it has a low barrier to entry, it is also very extensible and allows you to stack on top of Splunk to leverage the platform for whatever your specific needs are. This is why it is so beneficial across many different sectors of IT. On top of the actual product, the community is top notch and always looking to help should any issues come up.

What do you dislike?

Cost. Splunk is not the cheapest product and it can be a fight to get funding.

What business problems are you solving with the product? What benefits have you realized?

Security, Incident Response, and Root Cause Analysis. The platform allows for analysis that would never be possible sifting through data manually on a file system .Bringing everything together into a central repository and allowing for analysis of aggregate data all at once allows you to see where dependencies are and how failures in an architecture can affect everything beneath it.

Splunk Enterprise review by Kyle S.
Kyle S.
Validated Reviewer
Verified Current User
Review Source
Business partner of the vendor or vendor's competitor, not included in G2 Crowd scores.

"Transcendental Meditation as Software (TMaS)"

What do you like best?

Oh, to begin at the start is akin to creating pottery from clay. Forming the vase of data from the clay of disparity, one can simply design such meaning and substance from meaningless data, and share amongst peers and enemies alike.

What do you dislike?

Sometimes, the rapid evolution causes internal strife, but nary is it a problem, as support and documentation rules all.

Recommendations to others considering the product

Consult professional services and the community. http://splk.it/slack . Find a user, ask them questions, and join the revolution!

What business problems are you solving with the product? What benefits have you realized?

Verily, we beseech thee to not find a benefit. Optimization of Continuouse Integration, Notification of downtime and reporting of such, monitoring the temperature for optimal Feng shui, among other glorious and grand moments, one must have a sense of pride and accomplishment.

Splunk Enterprise review by Naomi P.
Naomi P.
Validated Reviewer
Review Source

"Easy to read dashboard"

What do you like best?

My team mostly uses it to track lockouts for users. However we also use it for VPN connection metrics, tracking active directory user accounts, and various other types of reports.

What do you dislike?

It does have a bit of a learning curve to it at first, such as accidentally connecting to the wrong dashboard can leave you feeling a little lost until you find you way back to the correct app.

Recommendations to others considering the product

Just having the correct subscription would be extremely helpful to your company, otherwise there can be too many logins causing issues with the license. Other than that, it has great dashboards for network admins, and creating a smooth transition for troubleshooting at a beginner level.

What business problems are you solving with the product? What benefits have you realized?

My team is initial helpdesk support, so we use it to find out what servers a users Active Directory account is locked out of, track the server, or track the MAC Address of a device that has locked them out of a radius server/wireless connection. It was a little inaccurate at first, but we have upgraded recently and now can fully track the mac addresses to reassure the user that yes, their phone is connecting to the wireless, and yes they need to fix that on their end.

Splunk Enterprise review by Administrator in Computer Software
Administrator in Computer Software
Validated Reviewer
Verified Current User
Review Source

"The most versatile data mining product I know of"

What do you like best?

Splunk takes in any data in almost any form (as long as it is human readable text) and allows searching, manipulation, transformation, calculation, etc. and then presents it in a multitude of ways to make the data tell a helpful story. That is superior to products that make you set up each type of data in a set format. We have data that varies greatly even among similar software products.

What do you dislike?

Bugs, though to be honest, I haven't run across many, and they seem to get fixed pretty quickly. I've run into some that usually have a workaround, which makes it easier to deal with the bug.

Recommendations to others considering the product

Learn as much as you can before implementing a large installation, or use professional services to get you started. You can keep from making lots of bad mistakes by doing so. Many people go into the implementation making simple, but critical mistakes that can be hard to rectify. These are things that are documented, but people don't take the time to find out about them, so they make those mistakes anyway.

What business problems are you solving with the product? What benefits have you realized?

We use Splunk for many purposes. Developers use it to find coding problems, operations uses it to find operational issues, managers look at reporting and forecasting.

Splunk Enterprise review by Administrator
Administrator
Validated Reviewer
Verified Current User
Review Source

"Have all of Enterprise logging in one place "

What do you like best?

The one thing i love about Splunk is all of your logs are in one place . Gone are the days where you need to login to each and every instance to get the logs . Splaunk not only helps to collect the logs through splunk forwarder but also helps to analyze them , create reporting , create alerting and you can integrate it with your service now or ticketing system to automate problem incident management . I love the dashoard and reporting feature for log analysis

What do you dislike?

Price and enterprise level of support . Not all splunk forwarders report to the splunk server when there is a version mismatch

What business problems are you solving with the product? What benefits have you realized?

We have an automated incident management system that is collborated with the help of splunk and is fully automated decreasing SLA overage and minimal downtimes .

Splunk Enterprise review by User in Education Management
User in Education Management
Validated Reviewer
Verified Current User
Review Source

"Monitoring Network Traffic with Splunk"

What do you like best?

I like Splunk's speed when querying millions of logs to find specific data points. Combined with the online support pages that help with any type of query, Splunk makes searching through data easy. Additionally, the ability to start a search and have it sent via email upon completion allows for productivity to increase due to the fact that I do not have to sit around waiting for my query to complete. Lastly, the export feature is extremely convenient for digging through large amounts of data easily in Excel.

What do you dislike?

If you click to expand a search result and then attempt to scroll while this result is still expanded, you will get yanked back up to that result repeatedly until it is closed.

Recommendations to others considering the product

Splunk Enterprise will change the way that an organization is able to look through its traffic logs. A search of millions of records takes very little time, and each query can be customized to find and show only what the user wants.

What business problems are you solving with the product? What benefits have you realized?

I have been able to verify the number of users that are using each route out to the internet, and then use that information to determine the use of one system vs. the other (i.e. proxy traffic vs. firewall traffic). This allowed me to solve the problem of bottlenecks on one by focusing more traffic through the other. The benefits of this change are increased speed for users and more safety of our information and systems.

Splunk Enterprise review by Mir Vizarath A.
Mir Vizarath A.
Validated Reviewer
Verified Current User
Review Source

"Best enterprise solution for querying data"

What do you like best?

- Ability to query data

- Dashboards

- Different modes to query data, this helps decide how much information you choose to see which at times is useful when reviewing several days worth of logs.

- Ease of use

- Flexibility for the most part,

What do you dislike?

- Unable to query data past 30 days, but this looks like a limit imposed by my employer.

Recommendations to others considering the product

- Great software for log analysis

What business problems are you solving with the product? What benefits have you realized?

- Log Analysis

- Dashboards

- Charts

- Splunk is one of many tools we use to help us capture key information with not only data but also meta data, this proves to be real helpfull when investigating client side issues.

Splunk Enterprise review by Patrick O.
Patrick O.
Validated Reviewer
Verified Current User
Review Source

"Amazingly broad tool with some complex management issues"

What do you like best?

The tooling included in base Splunk, plus the broad community supplying pre-built extensions to common data needs, greatly reduce time to detection on problems and make tracing root cause issues much easier than any other tool I've used.

What do you dislike?

Management of the software can be complex, as it is a complex tool. Buying professional services for initial configuration and any major changes (e.g. moving to a clustered environment) is frankly necessary unless you have someone on staff who has already managed a deployment previously.

What business problems are you solving with the product? What benefits have you realized?

Dramatic speedups of incident response, both security and business related. Replaced several other toolings, and automated a number of processes that had previously required dozens of full-time staff.

Splunk Enterprise review by Michael K.
Michael K.
Validated Reviewer
Review Source

"Great tool to maximize log analysis"

What do you like best?

Low barrier to start analysis, one need not know much to start understanding one's environment. One can simply treat everything as searchable text to start and work up to a model of the environment as complex as is suitable.

Flexible concepts for data normalization: I can extract new fields, transform existing fields, alias fields, or create entirely new datamodels within the data that I have.

Scales to handle any volume of logs, so all of my logs really can go to one place. Also can send system metrics to Splunk for analysis.

What do you dislike?

Different types of commands are formatted differently. This can be quite frustrating.

No concept of production migration: the user is simply working in production.

Recommendations to others considering the product

Worthwhile. I recommend trying it.

From a log management perspective, you could compare it against other elastic search tools, like ELK.

What business problems are you solving with the product? What benefits have you realized?

I started with Application troubleshooting. In this context Splunk allowed me to normalize data across multiple systems that I supported and to correlate that data across time and load balanced systems.

Security analysis: I have been able to build new visualizations of events on my endpoints and network based on specific events, and statistical models that I have been able to create.

Splunk Enterprise review by Erik A.
Erik A.
Validated Reviewer
Verified Current User
Review Source

"Splunk has been a great platform to learn, support, and use at my company."

What do you like best?

From the users sides, it is a single platform that can provide everything a company needs without needing to go between different platforms that host different bits and pieces of the data needed to support a customer facing service. From the support side, my day job, it is very easy to built out new environments, set them up as we need, and support their ongoing usage.

What do you dislike?

I wish I could get more people at my company onboard with the concept of a single platform is better than multiple platforms.

What business problems are you solving with the product? What benefits have you realized?

All kinds including base event log index, along with schedule reports and alerting into Email, HipChat, Slack, and EMF, dashboards, and workflow auto-remediations.

Splunk Enterprise review by Mick H.
Mick H.
Validated Reviewer
Verified Current User
Review Source

"Easy to Use and Value Added Quickly"

What do you like best?

After the initial set up, getting new users to get value out of it is easy with a the free online tutorials and support bases (answers.splunk.com, slack groups etc...). We don't have a dedicated Splunk team--so finding time to really get the most value out of it can be difficult. That said, we have been able to take interns and point them to an online tutorial and have them running and doing actual valuable work after a week.

What do you dislike?

The licensing model can be expensive for non-profits and others on a tight budget.

What business problems are you solving with the product? What benefits have you realized?

We use Splunk for transaction monitoring, alerting, volume trends and several other use cases include troubleshooting after incidents and determining root cause.

Splunk Enterprise review by Bhagat B.
Bhagat B.
Validated Reviewer
Review Source

"Powerful tool to pull logs"

What do you like best?

The best thing about spunk log is pull logs based on the time period. The logs are easy to read. Same system can pull the data from many environment. you can run your queries to pull the data. You can download all the logs in different file format. You can search your logs based on certain time period with any text. It can also pull the data based on the different system swell.

What do you dislike?

Coping of logs is not simple. It should have a link or button to copy a particular logs. I seen lots of issue with internet

explorer browser. Its very slow with IE but works well with Chrome.

Recommendations to others considering the product

Its best tools to pull the logs. It helped us debugging lots of issues related to integration. It made our life lot more easier.

What business problems are you solving with the product? What benefits have you realized?

We have connected Salesforce system and SAP through Datapower and cast iron. Splunk tool pulls the logs from MW in case we need to debug any issue.

Splunk Enterprise review by Matthew C.
Matthew C.
Validated Reviewer
Verified Current User
Review Source

"Fully featured and performant"

What do you like best?

Splunk provides a convenient mechanism for gathering numerous system and software logs. The ability to search historical and real-time logs is a key capability for our monitoring. The custom field extraction and reporting are also a great feature for analysis.

What do you dislike?

Splunk relies on a Perl-based regular expression structure. I can regex just about anything I want in a python regex and routinely am frustrated by Splunk's support of only Perl regex. This translates into a lot of lost time trying to figure out how to get my custom field extract to extract only what I want extracted.

Recommendations to others considering the product

Splunk is an excellent solution for simple to complex systems for log retention and analysis.

What business problems are you solving with the product? What benefits have you realized?

We see benefits in two key areas.

First, automatic detection and notification of errors in our volumes of logs. With a distributed system churning out logs from numerous components, it is impossible for a human to review those logs, detect anomalies, and correlate errors across them. With the use of Splunk Enterprise, we are able to set up intelligent searches that detect error custom error conditions and generate alerts to our operators for triage.

Second, a significant reduction in effort to perform analysis of software performance and usage. Through adding custom log messages in our software and custom field extraction in Splunk, we are able to generate detailed performance information that can be viewed in real-time or over custom historical periods. Similarly we are able to analyze our logs to determine how our system is being used. These features are critical to our operations and are a huge cost savings in time and effort.

Splunk Enterprise review by Administrator in Government Relations
Administrator in Government Relations
Validated Reviewer
Verified Current User
Review Source

"Great Monitor Tool, Take it Slow"

What do you like best?

I am using Splunk now to monitor the logs from my backup server. The fact that it can import in logs from another host is great. The love the reporting for the logs as it provide an easy to use ad-hoc query which output a readable format for you to understand. You can actually go beyond logs and into monitor your network for spikes in processes and resources. What makes this unique is knowing which host and users are associated with the processes.

What do you dislike?

It's very confusing at first because there's so many tools and links. It's not simple so do read up before you tackle this product. This product costs a lot of money for what it delivers.

Recommendations to others considering the product

There is a free version, but it's limited. You can decide to invest in this product. It's very expensive so keep that in mind.

What business problems are you solving with the product? What benefits have you realized?

We are looking for a platform to monitor our network usages from users and hosts. In addition, being able to import logs for a readable format. The application saves us time in research and allows me to focus on other tasks.

Splunk Enterprise review by User in Information Technology and Services
User in Information Technology and Services
Validated Reviewer
Verified Current User
Review Source

"Very good for basic data querying, but not so easy for complex querying"

What do you like best?

Splunk very nicely provides query/search access to huge volumes of data (for example log-file data). If you're interested in finding specific occurrences of something/anything within your data, Splunk is a nice tool to have. For basic querying, it cannot be beat.

What do you dislike?

If you need to find an "area" within your huge volume of data (for example, either what happened immediately before or after a specific occurrence) then you end up fighting with Splunk to let you see that "area". Personally, I've ended up having to write extremely complex regular expressions within Splunk just to be able to see these "areas", and they work, but it needs to be easier.

Recommendations to others considering the product

For simple querying it's very easy to pickup and use, but for complex querying, you'll need a strong background in regular expressions.

What business problems are you solving with the product? What benefits have you realized?

I use Splunk to diagnose problems within a web-application by querying the application log file data.

Splunk Enterprise review by Vikas R.
Vikas R.
Validated Reviewer
Review Source

"Powerful Product With An Intuitive User Interface"

What do you like best?

Great for visualizing any application data that is required and the custom dashboard feature makes it easy to have related reports and queries all in one place.It's easy to understand the interface, graphs are good and can be easily exported. The keywords on the left side are very helpful.

What do you dislike?

I would say query building which might be a steep for non technical user. Also licensing the Splunk software would be little expensive so the best thing would be to start with a small amount of data and see it if works for you or not.

Recommendations to others considering the product

Test it out in an enterprise environment, that's where all the bells and whistles shine out.

What business problems are you solving with the product? What benefits have you realized?

I have used Splunk for the capacity planning which covered setting up the forwarder in the source system and creating multiple dashboards as per the requirements. Also try Splunk dashboards & perform automation through a script using the Splunk API.

Splunk Enterprise review by Alexandru O.
Alexandru O.
Validated Reviewer
Review Source

"A user whose company switch to Splunk Enterprise a couple of months ago"

What do you like best?

The documentation is really well done and easy to use.

The UI is slick and fast.

The ability to easily create dashboards.

The auto-completion with suggestion while writing the search query

The left hand menu on the search page containing all the fields detected by the search.

Ability to add/exclude from search the fields extracted from the search results by hovering any text.

What do you dislike?

The time range search could be improved by allowing the following type of input:

"last 3h" or "3d ago" which is easier to use than applying several clicks to achieve the same results.

Recommendations to others considering the product

Splunk is a great tool which is suitable for any kind of company, from a small startup to a big enterprise company. It has a large number of features, great documentation and support.

What business problems are you solving with the product? What benefits have you realized?

Mostly analysis of various issues reported by customers. It helps to easily understand the customer journey and spot various issues or anomalies. It helps as well to create nice dashboard for non-technical staff who are interested in the business metrics.

Splunk Enterprise review by Industry Analyst / Tech Writer
Industry Analyst / Tech Writer
Validated Reviewer
Verified Current User
Review Source

"Splunk is one of the recommended software when it comes to data analysis."

What do you like best?

The best thing that I like about splunk is Its search are analysis engine for all of our log data, data analytical tool, comprehensive data analytics that is been provided by splunk.

What do you dislike?

Till now I haven't faced any problem with this software which will incline me towards not liking this software. It automatically collects data in real time from multiple systems is one of the best feature of this software.

What business problems are you solving with the product? What benefits have you realized?

The benefits of using this software is that you can save whatever you are doing into the dashboard and from there you can then pick up next time and start working or upload another data set or log file and do different types of analysis which is required to perform.

Splunk Enterprise review by Christopher H.
Christopher H.
Validated Reviewer
Verified Current User
Review Source

"Working with Splunk Enterprise"

What do you like best?

Splunk language is fairly easy to learn and built-in hinting system comes in handy for beginners. Splunk can be a powerful tool providing much needed insight into servers, applications, and other business data. Building dashboards are fairly easy and can provide a quick and easy to understand view of what your data looks like.

What do you dislike?

The web GUI SPL code editor isn't very customizable as far as picking a different font.

Recommendations to others considering the product

Be sure to take advantage of the training courses offered by Splunk.

What business problems are you solving with the product? What benefits have you realized?

CA Agile metrics, customer impact via outages and underperforming hardware,

Splunk Enterprise review by User in Financial Services
User in Financial Services
Validated Reviewer
Verified Current User
Review Source

"Highly powerful, steep learning curve"

What do you like best?

If the data is in your logs, you can find it with Splunk. Sometimes I'm just searching for a key phrase in the last 30 days and I can get the answer back within seconds. At other times, I'm using a regex to extract a fraction of complex line and then graph that result to find anomalies and, again, the answer comes back within seconds. Splunk is incredibly powerful and I am constantly learning new things and new ways to use it.

What do you dislike?

The learning curve is incredibly steep. You essentially have an empty search box and you have to know what commands to use (and how to use them) to really get anything useful out of it. It has an alerting feature but it's a little...quirky. There doesn't seem to be a decent way to create live alerts--instead you can have a query run every minute but don't allow it look back more than 1 minute because otherwise you'll get duplicate results.

What business problems are you solving with the product? What benefits have you realized?

We wanted a way to access all of our logs and notice trends. This limits the number of people who need access to production instances and we can also store many terabytes of logs and access the results with ease.

Splunk Enterprise review by User in Internet
User in Internet
Validated Reviewer
Verified Current User
Review Source

"My experience with using Splunk Enterprise."

What do you like best?

Dashboards is very helpful. It gives us a lot of insight into what is happening. Also the alerting feature is also helpful. It helps to send out an email if there is an increase in threshold etc. Setting up file based forwarders is easy. Field extraction is also really great. It helps to analyze the search results.

What do you dislike?

It will take a while to learn the SPL (Splunk search processing language) but after it is learnt, it helps to get a lot of helpful searches. Event correlation is not very easy to grasp. Also the search UI is not very intuitive. Sometimes Splunk is not very fast. And also sometimes events timeline doesn't respond well. Patterns can be improved to have more intuitiveness. More formats can be supported to export the results.

Recommendations to others considering the product

It's definitely worth considering. But there are also other new vendors who recently entered the market and are worth checking out.

What business problems are you solving with the product? What benefits have you realized?

We are using Splunk to analyse our system and software logs. We also setup dashboards and custom alerts. We forward our application logs to splunk to analyse and find root cause of the problem. Monitoring the applications using Splunk alerts gives us peace of mind.

Splunk Enterprise review by matt j.
matt j.
Validated Reviewer
Verified Current User
Review Source

"Splunk is great for mining data and reporting on that data"

What do you like best?

Its easy to define the search parameters and to change them on the fly, you can also build graphs to view the progression of the trend. If you use the data often, build a dashboard and consume the data when you need it.

What do you dislike?

you have to remember all the names of the field in the database for a successful query

Recommendations to others considering the product

If you have server logs to be consumed by anyone this program is a must.

What business problems are you solving with the product? What benefits have you realized?

We are improving on view server logs and the resulting errors. This allows us to fix issues that we have now and spot trends that may come later.

Splunk Enterprise review by Aleksandr N.
Aleksandr N.
Validated Reviewer
Verified Current User
Review Source

"Splunk, security done right"

What do you like best?

Spunk is easy to navigate, relatively fast given the data size it handles, and the UI is not snazzier than ever.

What do you dislike?

Sometimes, it's very very slow! It also takes forever to refresh and the UI can be very unfriendly every now and than, especially for pattern searching.

Recommendations to others considering the product

Make sure it works with your system. Train your staff well.

What business problems are you solving with the product? What benefits have you realized?

Security and Account maintenance, Splunk is excellent for searching the logs.

Splunk Enterprise review by Giuseppe A.
Giuseppe A.
Validated Reviewer
Verified Current User
Review Source

"Powerfull product with enormous capability"

What do you like best?

It's an unique container of etherogeneus log, and permit to identify production problem and in case also to prevent, when it happens a performance degradation.

What do you dislike?

The price: it's quite expensive, and it's hard to persuade my company to upgrade to a bigger license.

Recommendations to others considering the product

the budget spent will be repaied. be confident

What business problems are you solving with the product? What benefits have you realized?

It helps me in production in order to identify and solve occurred problems. It also permits to monitor the health of our softwares. Last but not least It helps ti improve the overall qualità is software and architectures.

Splunk Enterprise review by Administrator in Information Technology and Services
Administrator in Information Technology and Services
Validated Reviewer
Verified Current User
Review Source

"Splunk Enterprise For the Win"

What do you like best?

Splunk is so easy to use that you will find yourself using it as the first step in every project or problem solving venture. The speed in which answers are realized is amazing and invaluable to fast paced teams or companies.

What do you dislike?

There is never enough time to implement all of the ideas we have for using Splunk! (this is an 'us' problem, not a Splunk problem)

Recommendations to others considering the product

Take the leap! At least download the free version and get an idea of just how much Splunk can help you.

What business problems are you solving with the product? What benefits have you realized?

We are using Splunk to identify , predict, and resolve issues across multiple products. We are also using Splunk to track items across multiple products, databases, external sites, and files in a easy to understand format for every level of user.

Splunk Enterprise review by User in Insurance
User in Insurance
Validated Reviewer
Verified Current User
Review Source

"Splunk for monitoring"

What do you like best?

Splunk allows you to capture logs from numerous different types of applications, and search or filter through them very easily. You can also create very helpful dashboards, apply plugins for applications, and more.

What do you dislike?

Not much to complain about really. We did hit a bug or two early on, but Splunk has since patched those, and things are operating well.

Recommendations to others considering the product

This is a great product overall. Searching for log entries is very simple, and you can refine the searches easily too. Definitely a great tool.

What business problems are you solving with the product? What benefits have you realized?

We are pushing Azure activity and diagnostic logs to splunk. From there we can filter on specific logs, and even cut tickets to Remedy. It's a very flexible, powerful tool for monitoring and helps with alerting.

Splunk Enterprise review by Prem Kumar S.
Prem Kumar S.
Validated Reviewer
Verified Current User
Review Source
Business partner of the vendor or vendor's competitor, not included in G2 Crowd scores.

"Splunk your Junk"

What do you like best?

Best about splunk is the ease of use of he product and its rich inbuilt functionalities to parse and clean unstructured data to give business insights in real quick time, for me splunk is a magic band that I hold everyday :)

What do you dislike?

MLTK could be more advanced and improved with lot more usecases and examples.

Recommendations to others considering the product

I strongly recommend Splunk for customers looking for any sort of machine data analysis clubbed together with great visualization package

What business problems are you solving with the product? What benefits have you realized?

Unstructured data analysis, Security & Compliance usecases

Splunk Enterprise review by NAZEER P.
NAZEER P.
Validated Reviewer
Review Source

"Splunk Review"

What do you like best?

The alerting system is best part of this. By using Transaction flow analysis we can identify where exactly the issue is. Building query is simple and easy. We have been using Splunk for 3 years now and it has always been a great tool use to analyze the data patterns and alert us on all performance related issues and pattern matching.

What do you dislike?

We run query for long time frame splunk performance will be effected. Ideally it creates one ticket for one type of exception but some times it creates more than one.

Recommendations to others considering the product

Best tool of Monitoring logs and tickets will be logged automatically

What business problems are you solving with the product? What benefits have you realized?

As a Support analyst we use this for viewing logs and analyzing transaction logs. We use the logs for root cause analysis.

Splunk Enterprise review by stephane p.
stephane p.
Validated Reviewer
Verified Current User
Review Source

"A great roduct"

What do you like best?

I like the posibility to ingest a large number of logs/data format and to play with it. In a very short time, beginners are able to have a clear view of things that were hidden in the mount of data to be processed.

What do you dislike?

I miss the possibility :

1. to add pdf export to custom visualisation,

2. to configure drilldown fields in custom visualisation

What business problems are you solving with the product? What benefits have you realized?

I use it for log analysis, both for IT and non-IT systems. Everywhere you can find logs, in fact.

Splunk Enterprise review by Administrator in E-Learning
Administrator in E-Learning
Validated Reviewer
Verified Current User
Review Source

"Splunk is like a Marvel Superhero movie: worth every dime."

What do you like best?

Support teams can see everything in one place without chasing down log files on all their servers.

You can create alerts that are exactly what you need and not what a vendor thinks is a good alert.

Splunk is the most useful IT tool I've had in 30 years. I wish it had been around way back in my DBA days!

What do you dislike?

The minimum hardware requirements for Windows are still heavy.

Recommendations to others considering the product

Go with Linux as your platform.

Do not underestimate your ingestion rate, because once users/management see Splunk they will want to ingest more and more data.

What business problems are you solving with the product? What benefits have you realized?

Application performance, security monitoring, inventory tracking are all easier with Splunk in the house. Teams are able to move more quickly, because they get meaningful information quickly.

Splunk Enterprise review by Eric W.
Eric W.
Validated Reviewer
Verified Current User
Review Source

"Great Data Analytics With a Bit of a Learning Curve"

What do you like best?

The add-ons are the best. Some of the information and feedback that the add-ons are able to compile based on all the data that gets injected into Splunk is beyond awesome and very helpful

What do you dislike?

To start there is a pretty big learning curve in my opinion. The breakdowns in the left hand nav bar definitely helps. But slow to learning the search language.

What business problems are you solving with the product? What benefits have you realized?

Being able to correlate errors and find out what and where they are coming from has allowed us to solve alot of issues lightning fast

Splunk Enterprise review by User in Information Technology and Services
User in Information Technology and Services
Validated Reviewer
Review Source

"Great tool, steep learning curve"

What do you like best?

Powerful log analytics tool and solid user interface. Seems to be an industry standard. Widely accepted by the IT and IT security community. Great presence in their market and industry. Knowledgeable sales people that understand the technical and business applications of their product instead of handing it off to their developers / product managers / business analysts to answer more complicated questions.

What do you dislike?

The learning curve for the Spunk querying syntax is somewhat steep. I'm not sure how much the support is really geared towards beginners or those that are not familiar with logging tools. The support that is out there for learning the tool is great but the support that is out there for learning the actual querying syntax is, in my humble opinion, lacking. It might be great for those familiar with querying tools, etc. but for those new to IT tools, management, administration, etc it is not the easiest to pick up. I would recommend looking at the tutorials and youtube videos then finding somebody who is already familiar with the tool and having them walk you through it just for the basic features. That alone would help a bit

Recommendations to others considering the product

Understand the admin and user requirements, technical understanding, and tangible application. It is a great tool and is used by many but ensure that it actually tailors to your business needs. Specifically, where does Splunk provide value where open source or other free tools cannot provide. Furthermore, if it provides the right support then adopt-ability increases greatly. There are many other free / open source tools, so do you due diligence to understand what you really need and what tools can meet that need. A lot of vendors have value added features or just outright great features, but make sure you answer the following questions: 1) can your users learn and apply this in the needed environments? 2) How long will it take to realize it's value? and 3) can you do without the particular feature, etc.

What business problems are you solving with the product? What benefits have you realized?

Capturing logs, analytics, indexing, and correlating in real time.

Splunk Enterprise review by Corey W.
Corey W.
Validated Reviewer
Verified Current User
Review Source

"Great application when it works well"

What do you like best?

Easy to find information, easy to view and understand, easy to locate information located in different locations. For queries with a long result, it minimizes the result in an expandable box for ease of viewing.

What do you dislike?

Has a tendency to run extremely slow and sometimes simple changes in terminology can cause a difference in results.

What business problems are you solving with the product? What benefits have you realized?

My business uses this software to locate important data easily. I also use splunk to categorize information in an easy to interpret structure.

Splunk Enterprise review by Artur I.
Artur I.
Validated Reviewer
Verified Current User
Review Source

"Centralized logging management service"

What do you like best?

Very nice user experience with a lot of graph options.

"One click" report creator tool.

In contrast to ElasticSearch+Kibana, you get all services together.

What do you dislike?

I can think only about high price of this product. Need to pay per GB/Month.

Recommendations to others considering the product

if you have enough money, this tool is the best! This is only logging management system that gets you all services together.

What business problems are you solving with the product? What benefits have you realized?

We had a 10 GB of logs each day and needed to do some statistics and reports.

Splunk Enterprise review by Dunstan V.
Dunstan V.
Validated Reviewer
Verified Current User
Review Source
Business partner of the vendor or vendor's competitor, not included in G2 Crowd scores.

"Data Swiss Army Knife"

What do you like best?

The ability to ingest any sort of data. If you can work out where something you want lies in a stream of data, it can become a field. So literally anything you can get a response from becomes a data source.

What do you dislike?

While you can get results really quickly in a new environment, it can take some practice until the penny drops and you can just write off a search without looking things up.

What business problems are you solving with the product? What benefits have you realized?

All sorts, but chiefly operations.

Kate from G2 Crowd

Learning about Splunk Enterprise?

I can help.
* We monitor all Splunk Enterprise reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. Validated reviews require the user to submit a screenshot of the product containing their user ID, in order to verify a user is an actual user of the product.