17 års erfaring med å hjelpe bedrifter
velge bedre programvare
Om Splunk Enterprise
Søk, analyser og visualiser data fra hele systemet. Overvåk, varsle og rapporter om driften for å skape mer robuste systemer.
When you need to store, correlate, and search large amounts of data, especially System Log data, there is no tool that even comes close to Splunk. It's power and flexibility is amazing.
So, first time user it can be difficult to use it.
Filtrer anmeldelser (230)
Best SIEM in the market
Kommentarer: My overall experience has been awsome so far. I would rate it 8.5/10.Splunk has been as effective soluntion when it comes to triaging and monitoring of day to alerts.
Fordeler:
- Easy to triage and monitor alert (Very fast and gives effective results as compared to other produts)Arcsight,Devo etc- Customer Support is excellent- Threat Hunting can be done effectively with the help of Splunk(IOC based,Corellation based etc)- Log parising is very effective & intelligent.
Ulemper:
- The only think i liked least about splunk is the cost involved/pricing model in case of high data volumes.
Big data is no problem for Splunk Enterprise
Kommentarer: Splunk is a powerful and useful monitoring tool. Splunk's efficiency is enhanced by the ability to integrate third-party apps developed in-house. It's also interesting that we can incorporate a customs alert and dashboard. In most situations, it resolves the need to normalize data, allowing for the use of any and all data in business forecasting. It is analyzed for data that can be utilized to optimize spending plans and asset tracking.
Fordeler:
Without worrying too much about data type or normalization, Splunk Enterprise can efficiently manage massive amounts of data from numerous sources. Data may be accessed in a flash, and there are a number of options for tailoring and integrating data analysis workflows to create bespoke dashboards or utilizing apps from our other product partners.
Ulemper:
There isn't much I dislike about splunk, however if we have to be picky, it would be that it's more difficult to maintain as an administrator when splunk is installed on outdated architecture.
Slunk comes with a hard to learn and proprietary Query Language
Kommentarer: That monitoring tool is a really good support for our daily operations
Fordeler:
It's a really good tool for monitoring and query logs
Ulemper:
The proprietary Query language is difficult to use
I use Splunk Enterprise to analyze and visualize data for better decision-making.
Fordeler:
Splunk Enterprise has powerful search capabilities and customizable dashboards.
Ulemper:
The learning curve for setting up queries can be steep, and the pricing can be high for smaller teams.
Bettering Cybersecurity With Splunk Enterprise
Fordeler:
It has amazing firewall protection features It makes handling security monitoring and improving networks security easy log monitoring is easy
Ulemper:
No regrets as Splunk Enterprise meets needs.
Splunk is a great solution for SIEM and also for monitoring your infrastructure
Kommentarer: We needed a way to monitor our internal environment and start to be more proactive with issues, so we started sending all of our logs to Splunk and we we able to get insights we did not know we needed. It is a great solution and they are constantly innovating.
Fordeler:
Splunk makes it easy to search through various data including logs. In the past I have had to pour through logs in order to find the one lines among the 100 of thousands of lines. Splunk allows me to search through those logs in a matter of seconds vs the hours it used to take.
Ulemper:
Most of enterprise setup is done through the command line. It would be nice to have cluster configuration (index creation) as part of the UI.
Vurderte alternativer:
Splunk Enterprise, not just a SIEM
Kommentarer: We have been using Splunk Enterprise, ES, ITSI, and other Splunk parts for 6+ years in production. This has helped us reduce staff in some cases, increase response time in most cases, and allow non-IT teams to get data and metrics in a fast efficient way.
Fordeler:
The versatility is amazing. The same data in logs, such as IIS, can be used for Security, Application performance, and even error handling. This allows us to use one log to help multiple teams. This is just one example.
Ulemper:
Start up takes someone who has had some training. While searching and output is easy, its the onboarding of custom apps that takes the know how.
Vurderte alternativer:
Best log monitoring tool
Fordeler:
Powerful search language Advanced visualisation Flexibility to accept logs from any source High availability Ease of administration
Ulemper:
The cost is too high compared to other log monitoring tools.
A better business companion when integrated with RPA
Kommentarer: Overall, the experience was positive; even with a free trial license, it was much easier, and on the course and certification side, Splunk has a very good collection of videos and materials that help even a novice quickly setup the integration and indexing.
Fordeler:
The most useful thing about Splunk is the ease of integration with application. With uipath on-premises it was very much helpful as the business users can monitor the actions of robots through spluink without entering into uipath orchestrator
Ulemper:
Expression creation for indexing was bit hard as it is not user-friendly to business users if they wanted to create any new fields, also the forwarder was not able to directly connect with uipath cloud so that the logs has to be shifted to intermediate file before uploading into splunk, but that seems not an issue with splunk but more related to uipath cloud
Powerful tool to perform db queries
Kommentarer: I used Splunk to surface and review platform logs
Fordeler:
Possibility to export query results in a variety of formats.
Ulemper:
User interface is not intuitive and it requires a steep learning curve
Splunk an Enterprise Business intelligent user tool
Kommentarer: Is a robust and intelligent management tool that enables everyone with user computer knowledge to navigate in real-time, consolidate vast data into a visualized report of dashboard features , reliable and web based, no major equipment required for setup, user need a smartphone or compute to access the platform through the web, you can navigate the system as long as you have computer knowledge without any training required(user friendly) .
Fordeler:
It an intelligent business tool that provided me an opportunity to customize and build report from large volume of data from different departments within the 13 Africa countries in telecommunication sectors. The platform allows data to be consolidated accordingly to the organization need and produces visualized reports of dashboard features. I also noted that the system can analyst unstructured large volume of data speedily and is reliable and web based allowing for user flexible accessible from any part of the world if you have internet. The systems have been reliable and secured from the time (2 years) I started using it without any system intermittent, system errors and cyber-attack.
Ulemper:
The system is built and use-able with structured and unstructured organization though the price in foreign currency could hamper small and medium organization to use it especially in most Africa country where the local currency has depreciated against the major trading foreign currency.so the Forex pricing is a challenge. The navigation of the platform will require minor training though if the user is computer proficient, they would management with minor challenge and interpretation of the data. So, first time user it can be difficult to use it It will depend on internet for access and internet tend to be pricey in most African country and therefore could increase the business cost for small and medium enterprise. It can increase business cost if not fully used
Best tool for Distributed logs data analysis
Kommentarer:
We have several micro-services deployed in production which require to lookup application access as well as server logs and analyze data for their usage. We created several reports/charts for visualization. We use splunk as security logs tool to see the firewall traffic, tracing any vulnerable access, any database related crash ..etc.
It helps easily to find issue and fixed quickly by black listed in system.
Fordeler:
Splunk Enterprise is best tool to analyze the data based on different visualization. It help us to lookup distributed logs for micro-services . It enables field based lookup. For complex logging, we can use search query using expression. We can create multiple reports/charts for visualization such as a pie or bar chart for our data. Best feature what i like , We can visualize our search results and share them with others using dashboard panels. If Already have a dashboard, we can add a new panel from a report, clone from another dashboard, or add a prebuilt panel. Fully customization available. Interfaces is very flexible. We export it in different formats, or refresh it to visualize the newest data. Online Support is available through different community.
Ulemper:
Search query builder is fully based on technical. for Non technical users, its really difficult to lookup logs. Sometimes, error thrown by query builder is more difficult to understand. Deep Learning is required to use splunk for production data. For Large application installation, it need to manage more.
Splunk Enterprise is a powerful data analytics software
Kommentarer: I believe getting important data analysis in real-time saves us from threats
Fordeler:
Splunk Enterprise offers real-time data analysis tools makes it possible for my institution to see and take immediate action against security risks, performance difficulties, and other operational concerns.
Ulemper:
Splunk Enterprise is really expensive and it is a huge part in our annual budget because we require add-ons.
Great platform for data analysis and visualization
Kommentarer: Splunk Enterprise is a great data analysis and visualization platform to show real time status with live dashboards.
Fordeler:
Security Information and Event management, log analytics, custom dashboards and workspaces
Ulemper:
Auto upgrade management and notifications for Add-ons. Leaning more towards config file based implementation instead of UI based implementation
Splunk the best analytic tool
Kommentarer: It gives best Return on Investment as analyzing the data and giving proper insights in form of Dashboards and notifying with help of Alerts if any kind of threat running in infrastructure and apart from that Deployment and use is very easy.
Fordeler:
There are lot of features which Splunk offers - 1) We can onboard data from any server, device or system using Universal Forwarder 2) Onboarded data are later stored in Indexers and searched further in Search Head for analyzing the internal logs 3) Using the data we can create customizable Dashboards and get proper insights of data and create Alerts to identify any kind of Threat or anomalies running in environment 4) Deployment is very easy on-prem servers 5) We can also use Hybrid Deployment on Cloud as well.
Ulemper:
1) As it give large amount of features but licensing is too high 2) There are lot of other Open Source software which can be used as alternative of Splunk as Analytic tool because Splunk is paid one.
Best SIEM
Kommentarer: Great SIEM that beats the competition, we utilized it for various functions
Fordeler:
Splunk appsStrength and capabilitiesIntegration with most solutions
Ulemper:
Resource utilizationLimited local partner support
Splunk helps us to walk in the darkness, for sure in the Prod arena
Kommentarer: We are in Autodesk, use it much, as part of the monitoring tool. We like it and would like it to be improved and even more useful
Fordeler:
Dashboards feature is amazing, I use it much. Alerts and queries are easy to set up. Mostly it works fast so it's kind of Dev friendly so it's easy to onboard the new guys
Ulemper:
Alerts should have a better way to manage it. There should be a way to promote alerts to different environments - so we will be able to set the Dev/Stg/Prod Sometimes some things that we want to do take a while searching on the internet for a solution - they might think how to do it better - maybe some examples or better documentation
Great for log analysis
Kommentarer: Splunk has been key in sever major issue root causes by analyzing logs and from that being able to build reports and determine causes of issues. In addition being able to trend and look for the data in the many logs is very helpful.
Fordeler:
We use this tool primarily as a repository for syslog messages for infrastructure. It allows us to quickly analyze the logs and patterns to determine issues based on patterns. In addition it alerts very well from text based trigger alerts. These features are very easy to use and dependable.
Ulemper:
I do not have any cons for this software. Mainly as a user it does exactly what I need it to do with no overhead and confusing interfaces.
Great log analysis software
Fordeler:
Integrates with almost all the software seamlessly..where there is a software application that produces log, splunk can be easily integrated. Gives very powerful insights into the logs Alerts can be setup on the logs, and notifications sent out which is great again for managing the health of your application
Ulemper:
The query language, though powerful, has a learning curve. Particularly as one goes towards complex queries. If it could be made closer to natural language, it would be so much smoother to learn. Hope that will happen sometime in future.
A tool that every sys admin needs to have
Fordeler:
I'm not sure from where to start in this case. We use splunk for many things but mostly to analyze the traffic on the network / firewalls. It provides us with a nice overview of what's going on. It makes it very easy to spot spikes on the network and it will provide you also with deep analyzes. For us it's an indispensable tool, probably the best tool we have.
Ulemper:
To search for something is not always easy, however there are a lot of forums online, so finding help is not that difficult.
Splunk is a lifesaver!
Kommentarer: It’s been wonderful. I was able to take most of my forwarded lambdas and charts them to watch duration and throughput. Notifications and alerts let me know if things are out of whack. Such a relief to know Splunk is watching my back!
Fordeler:
If you need real-time grokking into your infrastructure, look no further than Splunk. I love love love the dashboards. It’s easy to tell a story with your data, and the live search is so FAST!
Ulemper:
SPL is a little hard to get used to, but once you get the hang of it, it’s not so bad. I recommend downloading their community edition for some great examples of queries and dashboards.
This is the tool every devops should have expertise on!
Kommentarer: Made life easier for all SRE/DevOps oncall.
Fordeler:
First of all you don't need to login to your servers. Just configure splunk forwarder on all of your server and have peace of mind. During outages you dont have to panic and just rely on Splunk and be sure that you will have your root cause visible in splunk.
Ulemper:
Kernel huge page issues, Search head clustering, Index clusetering. These features are as good as costly too. For SHC and IC it does need all same config hosts.
really true nice monitoring tool if its nice implemented
Kommentarer: For me it is a very good experience. It is necessary to develop a good implementation of IT INC Management
Fordeler:
It helped me enormously in my job as IT INC Management including detailed reports and alerting any necessary information.
Ulemper:
It has a somewhat complex paring curve and there are no simple tutorials or parallel design of tutorials for new managers
splunk review
Fordeler:
great monitoring tool. We have been using it for monitoring puposes, creating visualizations and dashboards which helps us to keep track of how our service is behaving. easy UI and excellent search analysis
Ulemper:
UI can be a bit more intuitive and dashboards support can be made btr and easy
Splunk Enterprise software review
Kommentarer: It is great at working with big data coming from different data sets and sources
Fordeler:
I am able to quickly act on pending issues as and when they arise and data is well protected because of their authorization features
Ulemper:
We had to purchase additional computers with higher specs than what we previously had to be able to use Splunk effectively