15 años ayudando a las empresas ecuatorianas
a elegir el mejor software
Sobre Splunk Enterprise
Con la confianza de 92 empresas de la lista Fortune 100, Splunk ayuda a investigar, supervisar, analizar y actuar sobre todos los datos de la organización.
When you need to store, correlate, and search large amounts of data, especially System Log data, there is no tool that even comes close to Splunk. It's power and flexibility is amazing.
So, first time user it can be difficult to use it.
Filtrar opiniones (215)
Uso
Ordenar por
Filtrar opiniones (215)
Opinión Splunk Enterprise
Comentarios: Splunk se ha alineado con nuestras expectativas. Recomendado.
Puntos a favor:
Splunk nos ha permitido fortalecer nuestras capacidades de visibilidad sobre una amplia variedad de eventos (de ciberseguridad y funcionales), dada su flexibilidad nativa para consumir, correlacionar y alertar a partir de distintas fuentes. Con ello, hemos podido detectar y reaccionar oportunamente ante aquellos eventos que representan posibles amenazas para nuestros objetivos.
Contras:
Algunas funcionalidades requieren componentes adicionales.
es buena herramienta
Puntos a favor:
es una herramienta de facin configuracion e implementacion, aparte de ser intuitiva.
Contras:
hay veces que se traba la interfas cuando se sastura el equipo.
Básica para el Big Data
Comentarios: Muy buena, lo recomendamos aunque es conveniente analizar bien el mercado y los productos parecidos que hay.
Puntos a favor:
Capas de procesar gran volumen de datos a partir de múltiples fuentes, rápido y eficaz en el análisis . Nos ha permitido mejorar y fortalecer todos nuestros procesos internos de la empresa y optimizar nuestros objetivos
Contras:
Es un software bastante caro y no para pequeñas empresas, a no ser que te dediques a ello. Puede requetir implementar algunos complementos adicionales.

Alternativas consideradas:
Best SIEM in the market
Comentarios: My overall experience has been awsome so far. I would rate it 8.5/10.Splunk has been as effective soluntion when it comes to triaging and monitoring of day to alerts.
Puntos a favor:
- Easy to triage and monitor alert (Very fast and gives effective results as compared to other produts)Arcsight,Devo etc- Customer Support is excellent- Threat Hunting can be done effectively with the help of Splunk(IOC based,Corellation based etc)- Log parising is very effective & intelligent.
Contras:
- The only think i liked least about splunk is the cost involved/pricing model in case of high data volumes.

Big data is no problem for Splunk Enterprise
Comentarios: Splunk is a powerful and useful monitoring tool. Splunk's efficiency is enhanced by the ability to integrate third-party apps developed in-house. It's also interesting that we can incorporate a customs alert and dashboard. In most situations, it resolves the need to normalize data, allowing for the use of any and all data in business forecasting. It is analyzed for data that can be utilized to optimize spending plans and asset tracking.
Puntos a favor:
Without worrying too much about data type or normalization, Splunk Enterprise can efficiently manage massive amounts of data from numerous sources. Data may be accessed in a flash, and there are a number of options for tailoring and integrating data analysis workflows to create bespoke dashboards or utilizing apps from our other product partners.
Contras:
There isn't much I dislike about splunk, however if we have to be picky, it would be that it's more difficult to maintain as an administrator when splunk is installed on outdated architecture.
Alternativas consideradas:
The only tool you need to manage production data
Comentarios: I'm very pleased with the data management capabilities Splunk Enterprise has given us. Before we implemented it, we were really struggling to make sense of some of the big data we get from our machines, but now, we can get very detailed insights into hw the machines are performing at any time. It's helped us monitor performance, issues, and opportunities much easier.
Puntos a favor:
I love how detailed you can have the dasboards and charts go. It supports tons of chart types, and custom reporting elements. But above all, with the automaetd monitoring, you can have access to continuous insights from large data you wouldn't have been able to make sense of otherwise.
Contras:
It's quite difficult to set up in the beginning. It took us a lot longer than expected to map our production data onto the system. But once you have it up and running, it works like clockwork
Spunk Review
Puntos a favor:
It allows me to bring a lot of information into one friendly view. It's a great security audit tool.
Contras:
It has limited functionality. It is a very memory intensive system. It does not integrate with Lennox.
Alternativas consideradas:
Splunk is a great solution for SIEM and also for monitoring your infrastructure
Comentarios: We needed a way to monitor our internal environment and start to be more proactive with issues, so we started sending all of our logs to Splunk and we we able to get insights we did not know we needed. It is a great solution and they are constantly innovating.
Puntos a favor:
Splunk makes it easy to search through various data including logs. In the past I have had to pour through logs in order to find the one lines among the 100 of thousands of lines. Splunk allows me to search through those logs in a matter of seconds vs the hours it used to take.
Contras:
Most of enterprise setup is done through the command line. It would be nice to have cluster configuration (index creation) as part of the UI.
Alternativas consideradas:
Splunk Enterprise, not just a SIEM
Comentarios: We have been using Splunk Enterprise, ES, ITSI, and other Splunk parts for 6+ years in production. This has helped us reduce staff in some cases, increase response time in most cases, and allow non-IT teams to get data and metrics in a fast efficient way.
Puntos a favor:
The versatility is amazing. The same data in logs, such as IIS, can be used for Security, Application performance, and even error handling. This allows us to use one log to help multiple teams. This is just one example.
Contras:
Start up takes someone who has had some training. While searching and output is easy, its the onboarding of custom apps that takes the know how.

Alternativas consideradas:
A better business companion when integrated with RPA
Comentarios: Overall, the experience was positive; even with a free trial license, it was much easier, and on the course and certification side, Splunk has a very good collection of videos and materials that help even a novice quickly setup the integration and indexing.
Puntos a favor:
The most useful thing about Splunk is the ease of integration with application. With uipath on-premises it was very much helpful as the business users can monitor the actions of robots through spluink without entering into uipath orchestrator
Contras:
Expression creation for indexing was bit hard as it is not user-friendly to business users if they wanted to create any new fields, also the forwarder was not able to directly connect with uipath cloud so that the logs has to be shifted to intermediate file before uploading into splunk, but that seems not an issue with splunk but more related to uipath cloud
A valuable SIEM tool that aids Cyber defences
Comentarios: Overall a rather good experience based on the Customer Service we receive and the extent to which they make our use of the tool a good experience
Puntos a favor:
The saying "you only get out what you put in" is rather apt when utilising Splunk as a SIEM tool - i.e. the more logs / data you can feed into the solution the better the results. Ingesting multiple log files from numerous systems / applications is essential when reviewing security incidents and ensures everything is in one place.
Contras:
For all that is good with Splunk, the costs are rather high and could force Customers to other solutions unless they make themselves more competitive in the pricing market
really true nice monitoring tool if its nice implemented
Comentarios: For me it is a very good experience. It is necessary to develop a good implementation of IT INC Management
Puntos a favor:
It helped me enormously in my job as IT INC Management including detailed reports and alerting any necessary information.
Contras:
It has a somewhat complex paring curve and there are no simple tutorials or parallel design of tutorials for new managers

Perfect solution to handle big data
Puntos a favor:
I love its versatility to handle different kinds of data. While monitoring our internal data, Splunk Enterprise saved a lot of code with its real-time data monitoring and logs analysis feature.
Contras:
With the growth of the data, costs grew intensively which was out of the budget for our startup company. Initially setting up Splunk was complex as we were new to this.
A powerful log aggregation solution with immensely useful tools built-in for popular applications.
Puntos a favor:
- Free to use for small 500MB or less daily ingress, quite nice for small use cases and learning - No development work required to deploy and provide value. - Deployment flexibility: client agents are available to use, or clientless configurations for multiple OS platforms. It's also very easy to deploy, not just flexible. its a very simple affair. - Segmentation of logs: You can create separate instances of of logs to aggregate, based on organization needs. And those instances can have their own individual storage policies to optimize consumption of storage resources. - Configuration design: Thoughtful and mature documentation and design of the application regarding enterprise-class scaling on network storage. -POWERFUL tools: The user interface lends itself to learning more about your organization from the logs you collect, through metrics of trends of the logs being gathered. There are also specific modules/add-ons for popular applications to provide more value and event-based monitoring, all without having to develop in-house dashboards and intelligence of those logs. - Customization: You can create your own queries of logs, and event-based alerts. - Web-based GUI that clean is powerful - Sales/Technical Reps are top notch in fielding questions and evaluating environment for deployment. They were extremely helpful in helping our organization develop procedures and scaling our environment for expansion with our existing infrastructure.
Contras:
- Price: This product is not free for more than the minimal use. Pricing can be very expensive, relative to open source offerings. That is the trade-off you pay for not having in-house development of open source offerings. As this product is priced based on gigabytes of indexed logs, it is important to understand the scope of licensing necessary for your environment to determine if it is a good fit for your organization. - Watch your saved queries and hardware resources: Users have the ability to create and save queries. Like in database queries, some are more efficient than others. Large inefficient queries can be very resource-intensive. If you notice slowness in day-to-day queries, or navigation in the UI, or resource use in contention, keep an eye on saved queries and user practices.
Alternativas consideradas:
Great, wholistic centralized monitoring solution
Comentarios: I've been using Splunk for over 8 years. I've seen it constantly improve and change a lot. I do enjoy it. Cloud is getting better and much better parity with on-prem
Puntos a favor:
We use this as our SIEM. The ability to have the data ingest, visualization, alerting and correlation all in one product is very important to me from a security standpoint. We're cloud-first so having that ability with large cloud providers is important to me (AWS, Okta, GCP, etc)
Contras:
The cost can be a little concerning and htere is a bit of a learning curve when you first get into Splunk. User groups, their forum and pro serv all help with that.
Best friend for debugging
Comentarios:
Splunk basically makes debugging and monitoring easier and touch less. I can easily debug by starring the rolling logs from different instances in single screen.
I can monitor multiple components and multiple metrics, without running commands manually with custom plugins.
Puntos a favor:
Splunk comes with lot of in-built templates for each and every feature like log visualisation, dashboarding, traces,etc This makes the developers life lot easier. I can't think of any other logging tool that is snappy as well as accurate. I love the fact how easily I can plug it in my docker-compose to push container logs.
Contras:
Even though, it offers numerous features for different needs, each feature has its own learning curve. For instance log visualisation needs querying skills, which may be in natural language but it takes bit of time to get familiar.

Offers more than you think
Comentarios: We've used the software to detect layer 7 attacks, unearth issues we didn't realize were happening and gives us end to end insight into our stack.
Puntos a favor:
The system is highly intuitive to use. It is faster than other solutions I've used on the market and has a huge library of 3rd party plugins to get more from the system. It is easy to create scheduled searches, dashboards, reports etc. but there are a number of additional plugins (at an extra cost) to help with security, single pane of glass and metric collection.
Contras:
It offers challenges for a decentralized working model. Where Splunk is centrally managed, it is easy to ensure that best practices are maintained. Where the system is opened up for an entire department to utilize and on-board their logs, it becomes more difficult. However, with some creative thinking and good process, this issue can be overcome.
Doing setup redundant servers without Splunk
Comentarios: Saved my a$$ many times. In a multi-server environment, if you don't have Splunk or something like it, it will be a nightmare to try and coordinate the various log files involved.
Puntos a favor:
Several of our applications are distributed across multiple systems. It is the same software running on each server but doing the same job for different users. Each server would generate its own log files. When things went wrong, we used Splunk to be able to see what was going on on each server. Click a few buttons and you get two logs from two different servers listed together coordinated by time. But that leads you to discover that the issue came from a separate upstream or downstream server, then bring in those logs too . . . all coordinated by time. Don't get me wrong, the IT guys love these tools for their own enterprise reasons, but as a server stack developer, this was a resource I used OFTEN.
Contras:
I never fully grokked their SQL like language. I could do basic things daily without issue. However, I often had to hit the documentation to do anything more than a simple "find this" query.
Splunk helps us to walk in the darkness, for sure in the Prod arena
Comentarios: We are in Autodesk, use it much, as part of the monitoring tool. We like it and would like it to be improved and even more useful
Puntos a favor:
Dashboards feature is amazing, I use it much. Alerts and queries are easy to set up. Mostly it works fast so it's kind of Dev friendly so it's easy to onboard the new guys
Contras:
Alerts should have a better way to manage it. There should be a way to promote alerts to different environments - so we will be able to set the Dev/Stg/Prod Sometimes some things that we want to do take a while searching on the internet for a solution - they might think how to do it better - maybe some examples or better documentation
Best Tool for Monitoring Purposes.
Comentarios: As a user of Splunk, we generally used to monitor the log provided by the server clusters belonging to a tool called API Connect. As the logs are stored in Splunk, we tally the transaction count from API Connect tool and filter the log search in Splunk with a particular search query. We can download the logs of particular time and date of API Connect servers in case of transaction count issues. We create a dashboard for all the individual API's transaction count in terms of total transaction count of all API's. In this way, it makes our work easier to find out which API has the highest transaction count. We even use Splunk to know the state of the machine. Reports generated by the Splunk helps us to find out the API with the highest response time. In this way, Splunk makes our work a lot easier as it is very fast and highly secure.
Puntos a favor:
1) Accepts multiple data formats like CSV, JSON, XML 2) Does the hard work for us i.e converting machine data to a human-readable format. 3) Can create customized alerts to serve our business purpose. 4) Searching on the based on queries is pretty simple. 5) We can create dashboards to analyze and visualize our search results. 6) Can export the log content to our Personal computers. 7) Setting up plugins and integrating with any tool that needs monitoring is pretty easy. 8) Technical support for the Splunk is very quick as they have a dedicated staff for that.
Contras:
I did not find any flaws with this software.
Number 1 SIEM
Comentarios: I was very happy with splunk and I suggest it to everyone
Puntos a favor:
I think Splunk is first and best software in the field, easy to use, does what it had promised,
Contras:
pricing could be better, they could be more flexible, support is a bit slow
Software is fantastic once you get it fed the data. Setup can be a bear.
Comentarios: Software saves a great deal of time tracking down errors and issues in the network. Was able to spot a security issue using the software we might never have even noticed otherwise.
Puntos a favor:
Fast consolidation of disparate logs in an easy to search way for troubleshooting. I can find problems within my organization very quickly. Sales team was very responsive in getting me a trial license to estimate my needs.
Contras:
Set up takes some time and planning. The Licensing scheme can be pretty expensive and until you've got it up and running it can be hard to estimate how much license you need.
Carry out data analysis with Splunk
Comentarios:
It has been a great experience working with Splunk , we have been using it since past 3 years.
It is integrated tool with fuse component for real time data analysis of the data flow from source system to target system
Puntos a favor:
-Easy to use tool -Simple graphical interface which makes it easy for a new user to understand the features easily -Real time data analysis can be carried out
Contras:
When we try to search for data which is more than 30 days old, then sometimes we see slowness
Powerhouse in data management and analysis
Comentarios: A complex but rewarding journey of data exploration and anomaly detection.
Puntos a favor:
Powerful and versatile data mining tool with excellent integration capabilities.
Contras:
Challenging initial setup and learning curve, particularly with query language and high cost.
Excellent product
Comentarios: I have worked with dozens of companies to implement Splunk. My experiences have bee overwhelming positive.
Puntos a favor:
When you need to store, correlate, and search large amounts of data, especially System Log data, there is no tool that even comes close to Splunk. It's power and flexibility is amazing.
Contras:
Very expensive. Difficult to implement until all moving parts are understood. Steep learning curve for beginners.