Sobre Splunk Enterprise
Con la confianza de 92 empresas de la lista Fortune 100, Splunk ayuda a investigar, supervisar, analizar y actuar sobre todos los datos de la organización.
When you need to store, correlate, and search large amounts of data, especially System Log data, there is no tool that even comes close to Splunk. It's power and flexibility is amazing.
So, first time user it can be difficult to use it.
Filtrar opiniones (186)
Uso
Ordenar por
Filtrar opiniones (186)
Alberto M
Opinión Splunk Enterprise
Comentarios: Splunk se ha alineado con nuestras expectativas. Recomendado.
Puntos a favor:
Splunk nos ha permitido fortalecer nuestras capacidades de visibilidad sobre una amplia variedad de eventos (de ciberseguridad y funcionales), dada su flexibilidad nativa para consumir, correlacionar y alertar a partir de distintas fuentes. Con ello, hemos podido detectar y reaccionar oportunamente ante aquellos eventos que representan posibles amenazas para nuestros objetivos.
Contras:
Algunas funcionalidades requieren componentes adicionales.
Usuario verificado
Básica para el Big Data
Comentarios: Muy buena, lo recomendamos aunque es conveniente analizar bien el mercado y los productos parecidos que hay.
Puntos a favor:
Capas de procesar gran volumen de datos a partir de múltiples fuentes, rápido y eficaz en el análisis . Nos ha permitido mejorar y fortalecer todos nuestros procesos internos de la empresa y optimizar nuestros objetivos
Contras:
Es un software bastante caro y no para pequeñas empresas, a no ser que te dediques a ello. Puede requetir implementar algunos complementos adicionales.

vikram
Splunk for Log Monitoring
Comentarios: Splunk is best data monitoring and visualization tool. We can set alert for log and monitor log . It provides different modes for searching Fast, Smart and verbose. By using Splunk we are getting all system log in one place .Splunk has capability to handle large and big size data. It has best GUI , one can easily adopt and do customization and based on requirments.
Puntos a favor:
We are using Splunk for log monitoring . It is integrated with Kubernetes and pivot cloud via data bus. By Splunk we get Realtime log application. It provides best visualization of data generated by system. Splunk also provide option to filter data based on data range and time. We can configure email alert for specific issue. Splunk also provide ML model for data. Splunk use simple query to get data ,everyone can easily learn Splunk query.
Contras:
I haven't found any issue yet the only problem with Splunk I have that log in Splunk is scattered . We need to build good query or better logging mechanism at application side.
Usuario verificado
Alternativas consideradas:
Splunk Enterprise, not just a SIEM
Comentarios: We have been using Splunk Enterprise, ES, ITSI, and other Splunk parts for 6+ years in production. This has helped us reduce staff in some cases, increase response time in most cases, and allow non-IT teams to get data and metrics in a fast efficient way.
Puntos a favor:
The versatility is amazing. The same data in logs, such as IIS, can be used for Security, Application performance, and even error handling. This allows us to use one log to help multiple teams. This is just one example.
Contras:
Start up takes someone who has had some training. While searching and output is easy, its the onboarding of custom apps that takes the know how.
Idaly
Powerful SIEM system that meets our expectations.
Comentarios: We are using Splunk Enterprise for log correlation, the analytics are accurate and it catches errors right away which improves our internal capabilities, it is a special service that collects data from different data sources very accurately to catch future issues, the reports are detailed and understandable. It has features that streamline manual work, improve our security and our protection in our IT infrastructure.
Puntos a favor:
I really like the platform, the data collection is ideal and the reports are detailed, it is the most appropriate SIEM service to monitor our IT infrastructure, it is an ideal software to take preventive measures, it is easy to customize the dashboards, the monitoring is constant and it gives us security in real time, the alerts are accurate and it helps us understand what is happening and fix it before it becomes serious.
Contras:
It is a somewhat expensive service but with more powerful features than other free SIEM systems, and it is a bit complex to set up and use for inexperienced users, so a lot of help should be sought from experienced staff and support team at first.
Patrick
Spunk Review
Puntos a favor:
It allows me to bring a lot of information into one friendly view. It's a great security audit tool.
Contras:
It has limited functionality. It is a very memory intensive system. It does not integrate with Lennox.
Muhamed
Alternativas consideradas:
A better business companion when integrated with RPA
Comentarios: Overall, the experience was positive; even with a free trial license, it was much easier, and on the course and certification side, Splunk has a very good collection of videos and materials that help even a novice quickly setup the integration and indexing.
Puntos a favor:
The most useful thing about Splunk is the ease of integration with application. With uipath on-premises it was very much helpful as the business users can monitor the actions of robots through spluink without entering into uipath orchestrator
Contras:
Expression creation for indexing was bit hard as it is not user-friendly to business users if they wanted to create any new fields, also the forwarder was not able to directly connect with uipath cloud so that the logs has to be shifted to intermediate file before uploading into splunk, but that seems not an issue with splunk but more related to uipath cloud
kartik
Alternativas consideradas:
Best Siem solution in market.
Comentarios: Overall experience is amazing, we are happy with this software as it can ingest any form of data and generate alerts quite swiftly.
Puntos a favor:
Easy to install agents on servers, it can parse any form of data easily, Splunk can detect anomalies quite easily and the UBEA feature is amazing.
Contras:
The cost of this solution is high, and customer service is bad. Apart from that Splunk SPL language is difficult to learn.
Usuario verificado
An excellent SIEM at a low cost
Comentarios: We have many programs that measure the performance and quality of the operation, of the production in chevron, I think it is important that they give extra barriers to what we do and splunk is an optimal collaborator so that we can track all these programs and not get intrusions through the network.
Puntos a favor:
It is a very subtle program, when generating the setup it is not necessary to have a great knowledge of programming to install it, but to solve some configuration errors, when you start what I like the most is that you start from day one to organize your applications, then From that you can easily configure cybersecurity for each program, I particularly like the monitoring of data programs and that the program alerts you with notifications so that you see errors that sometimes jumps in the program.
Contras:
What I don't like and I see that it is something widespread is that it has very poor support in technical help, I think that the old technical support collaborators have left and people who are not so qualified have arrived to answer the tickets.For my part it is not a big problem since I am a researcher and with the information that is on the splunk website it is enough for me to generate the resolutions of problems.
Usuario verificado
Alternativas consideradas:
Great platform for data analysis and visualization
Comentarios: Splunk Enterprise is a great data analysis and visualization platform to show real time status with live dashboards.
Puntos a favor:
Security Information and Event management, log analytics, custom dashboards and workspaces
Contras:
Auto upgrade management and notifications for Add-ons. Leaning more towards config file based implementation instead of UI based implementation
Yann
Log management
Comentarios: I have been using Splunk Enterprise for a few years now and I am very happy with it. Splunk is a powerful tool that has allowed me to quickly analyze large amounts of data and identify patterns and insights.
Puntos a favor:
Splunk is very robust with being able to search network traffic, create dashboards and automate reports and alerts. It allows users and admins to solve many problems. Our company has created several alerts for when people on the network download any files that look like they could be a virus, or if they are using illegal software, or trying to login with wrong passwords constantly.
Contras:
I least like that Splunk is expensive and often requires a significant upfront investment. Additionally, the complexity of the product can be a challenge for new users, as it takes time to learn how to use the product effectively.
Usuario verificado
Efficiently manage and analyze data with Splunk Enterprise
Puntos a favor:
Splunk Enterprise's versatility is highly valued by its users, as it is capable of analyzing and managing data from a variety of sources, including machine data, logs, and structured and unstructured data formats. This makes it a valuable tool for organizations with diverse data management needs. In addition, users appreciate the software's efficiency in processing and analyzing large volumes of data quickly, allowing them to make faster and more informed decisions. This is particularly important for organizations that need to respond to data in real-time, as Splunk Enterprise's speed and efficiency can help them stay ahead of the curve.
Contras:
Splunk Enterprise to be complex and difficult to use, particularly for those who are not familiar with data analysis and management tools. The software has a range of features and capabilities, which can be overwhelming.
Gabe
A powerful log aggregation solution with immensely useful tools built-in for popular applications.
Puntos a favor:
- Free to use for small 500MB or less daily ingress, quite nice for small use cases and learning - No development work required to deploy and provide value. - Deployment flexibility: client agents are available to use, or clientless configurations for multiple OS platforms. It's also very easy to deploy, not just flexible. its a very simple affair. - Segmentation of logs: You can create separate instances of of logs to aggregate, based on organization needs. And those instances can have their own individual storage policies to optimize consumption of storage resources. - Configuration design: Thoughtful and mature documentation and design of the application regarding enterprise-class scaling on network storage. -POWERFUL tools: The user interface lends itself to learning more about your organization from the logs you collect, through metrics of trends of the logs being gathered. There are also specific modules/add-ons for popular applications to provide more value and event-based monitoring, all without having to develop in-house dashboards and intelligence of those logs. - Customization: You can create your own queries of logs, and event-based alerts. - Web-based GUI that clean is powerful - Sales/Technical Reps are top notch in fielding questions and evaluating environment for deployment. They were extremely helpful in helping our organization develop procedures and scaling our environment for expansion with our existing infrastructure.
Contras:
- Price: This product is not free for more than the minimal use. Pricing can be very expensive, relative to open source offerings. That is the trade-off you pay for not having in-house development of open source offerings. As this product is priced based on gigabytes of indexed logs, it is important to understand the scope of licensing necessary for your environment to determine if it is a good fit for your organization. - Watch your saved queries and hardware resources: Users have the ability to create and save queries. Like in database queries, some are more efficient than others. Large inefficient queries can be very resource-intensive. If you notice slowness in day-to-day queries, or navigation in the UI, or resource use in contention, keep an eye on saved queries and user practices.
Usuario verificado
Alternativas consideradas:
Great, wholistic centralized monitoring solution
Comentarios: I've been using Splunk for over 8 years. I've seen it constantly improve and change a lot. I do enjoy it. Cloud is getting better and much better parity with on-prem
Puntos a favor:
We use this as our SIEM. The ability to have the data ingest, visualization, alerting and correlation all in one product is very important to me from a security standpoint. We're cloud-first so having that ability with large cloud providers is important to me (AWS, Okta, GCP, etc)
Contras:
The cost can be a little concerning and htere is a bit of a learning curve when you first get into Splunk. User groups, their forum and pro serv all help with that.
Chetan
Splunk the best analytic tool
Comentarios: It gives best Return on Investment as analyzing the data and giving proper insights in form of Dashboards and notifying with help of Alerts if any kind of threat running in infrastructure and apart from that Deployment and use is very easy.
Puntos a favor:
There are lot of features which Splunk offers - 1) We can onboard data from any server, device or system using Universal Forwarder 2) Onboarded data are later stored in Indexers and searched further in Search Head for analyzing the internal logs 3) Using the data we can create customizable Dashboards and get proper insights of data and create Alerts to identify any kind of Threat or anomalies running in environment 4) Deployment is very easy on-prem servers 5) We can also use Hybrid Deployment on Cloud as well.
Contras:
1) As it give large amount of features but licensing is too high 2) There are lot of other Open Source software which can be used as alternative of Splunk as Analytic tool because Splunk is paid one.
Usuario verificado
Get useful insights into your logs with Splunk Enterprise.
Comentarios: We majorly use Splunk enterprise for IT security and log analysis. It is a powerful log analytics solution. We use it to collect data from several sources, analyze and transform it into meaningful metrics.
Puntos a favor:
Its been a while since I started using Splunk Enterprise. I love its ability to cumulate data and logs from multiple sources and correlate them to help find incidents and their root cause. It consolidates logs and manages them form a central place. It is a great tool for log analysis as it segregates data and provides in depth profiling. Splunk enterprise also automates alerts and indexes on logs received.
Contras:
It has a complex architecture making the learning curve quite steep
Alex
Excellent product
Puntos a favor:
It is an easy to use solution, the implementation is a bit more difficult.
Contras:
So far, this is a good solution that I use every day.
Usuario verificado
Number 1 SIEM
Comentarios: I was very happy with splunk and I suggest it to everyone
Puntos a favor:
I think Splunk is first and best software in the field, easy to use, does what it had promised,
Contras:
pricing could be better, they could be more flexible, support is a bit slow
Rob
Splunk vs Humio and Devo
Comentarios: The APIs and plugin are great. the parsers are just fantastic. It can log anything and everything.
Puntos a favor:
We have been using splunk for over 5 years now. nothing beats splunk in the market place. The only concern we have the pricing and the resource to support it. it's just too expensive
Contras:
Too expensive and it's too hard to manage. You have to find a very qualified and very expensive resource to support it.

Mark
Excellent logging and troubleshooting tool
Comentarios: As a software quality assurance engineer, I love that I can setup a single dashboard where I can then view the same data from any lane I select from a dropdown. If I see a problem in the Test lane, I can quickly check all of the other lanes for the same issue by simply changing the dropdown value.
Puntos a favor:
Splunk can give you extreme insights into how your systems and software are functioning. Not only is the search very flexible and powerful, the customizable dashboards give a status report at a glance into trends, problems and performance. You can also set up email alerts when errors occur limiting the need to have Splunk opened on your machine all the time.
Contras:
Splunk has a learning curve. They have extensive documentation but it isn't intuitive and some features are buried pretty deep. We have an onsite expert who holds bimonthly meetings to answer questions in a group forum.

André
Very reliable and powerful resource
Comentarios: On business side we have a lot of logs, informations provided for a very different resources, the most beautiful thing about Splunk is to consolidate everything on just one place, and the ease to extract this information make Splunk the most powerful resource to gather and extract data from every resource that you have logs, even if you are using Windows or Linux, Splunk covers both.
Puntos a favor:
Ease of use, you can extract any kind of information using commands provided by the software vendor. The other good thing about this software is the easy implentation on the servers, and the configuration is basic.
Contras:
For people that are not used to use command lines, it might be a liitle bit difficult on the beggining.
Parth
Monitoring Tool Splunk
Comentarios: With Splunk anything identified with the application backend logs and observing, it's extremely suitable to utilize, in light of which we can make different dashboards. For server Monitoring, Splunk logs are not exceptionally accommodating. It totally depends on log explanations, assuming articulation isn't organized in standard organization, and it gives mistaken outcomes.
Puntos a favor:
Splunk Light is ideal for independent on-premise organization. Augment endpoint logging. Can find and store logs from a wide range of resources. Customization of dashboards. Making applications dependent on your requirements.
Contras:
Complex generally design. Long execution time. The instrument needs to incorporate AI to comprehend the framework logs and alarming ought to be founded on the auto learning.

shaik
One of the best place to check large amount of the logs information.Every companies best tool.
Comentarios: make our business life easy
Puntos a favor:
The best thing about this software is i love its UI part and its dashboard where it provides the logs of all the enterprise application every business which has large amount of the transactions being held are required to maintain this tool and its logging and search frequency are very much loved and dash board has very colourful UI and easily understandable
Contras:
There is no least about this software but we are looking for some more enhanced featured like optimisation and all
Joevanne
Very cool but pricey
Puntos a favor:
Splunk integrates with many different solutions. They also have pre written apps that contain pre written dashboards and other features. It can inherit logs from many products with just several clicks.
Contras:
Pricing model is outdated and can get really pricey really fast. It's very simple to over your daily license.
Christian
Great Log Manager To Have Fireproof Applications!
Comentarios: With Splunk your platform should be safe and easy to maintain, specially if your are constantly adding features into it thanks to its error alerts.
Puntos a favor:
User friendly and an awesome dashboard to manage your logs and analyze your apps.
Contras:
It can be a little expensive but it's worth.