15 años ayudando a las empresas mexicanas
a elegir el mejor software
Sobre Splunk Enterprise
Con la confianza de 92 empresas de la lista Fortune 100, Splunk ayuda a investigar, supervisar, analizar y actuar sobre todos los datos de la organización.
When you need to store, correlate, and search large amounts of data, especially System Log data, there is no tool that even comes close to Splunk. It's power and flexibility is amazing.
So, first time user it can be difficult to use it.
Filtrar opiniones (201)
Uso
Ordenar por
Filtrar opiniones (201)
Opinión Splunk Enterprise
Comentarios: Splunk se ha alineado con nuestras expectativas. Recomendado.
Puntos a favor:
Splunk nos ha permitido fortalecer nuestras capacidades de visibilidad sobre una amplia variedad de eventos (de ciberseguridad y funcionales), dada su flexibilidad nativa para consumir, correlacionar y alertar a partir de distintas fuentes. Con ello, hemos podido detectar y reaccionar oportunamente ante aquellos eventos que representan posibles amenazas para nuestros objetivos.
Contras:
Algunas funcionalidades requieren componentes adicionales.
es buena herramienta
Puntos a favor:
es una herramienta de facin configuracion e implementacion, aparte de ser intuitiva.
Contras:
hay veces que se traba la interfas cuando se sastura el equipo.
Básica para el Big Data
Comentarios: Muy buena, lo recomendamos aunque es conveniente analizar bien el mercado y los productos parecidos que hay.
Puntos a favor:
Capas de procesar gran volumen de datos a partir de múltiples fuentes, rápido y eficaz en el análisis . Nos ha permitido mejorar y fortalecer todos nuestros procesos internos de la empresa y optimizar nuestros objetivos
Contras:
Es un software bastante caro y no para pequeñas empresas, a no ser que te dediques a ello. Puede requetir implementar algunos complementos adicionales.

Big data is no problem for Splunk Enterprise
Comentarios: Splunk is a powerful and useful monitoring tool. Splunk's efficiency is enhanced by the ability to integrate third-party apps developed in-house. It's also interesting that we can incorporate a customs alert and dashboard. In most situations, it resolves the need to normalize data, allowing for the use of any and all data in business forecasting. It is analyzed for data that can be utilized to optimize spending plans and asset tracking.
Puntos a favor:
Without worrying too much about data type or normalization, Splunk Enterprise can efficiently manage massive amounts of data from numerous sources. Data may be accessed in a flash, and there are a number of options for tailoring and integrating data analysis workflows to create bespoke dashboards or utilizing apps from our other product partners.
Contras:
There isn't much I dislike about splunk, however if we have to be picky, it would be that it's more difficult to maintain as an administrator when splunk is installed on outdated architecture.
Alternativas consideradas:
Best SIEM in the market
Comentarios: My overall experience has been awsome so far. I would rate it 8.5/10.Splunk has been as effective soluntion when it comes to triaging and monitoring of day to alerts.
Puntos a favor:
- Easy to triage and monitor alert (Very fast and gives effective results as compared to other produts)Arcsight,Devo etc- Customer Support is excellent- Threat Hunting can be done effectively with the help of Splunk(IOC based,Corellation based etc)- Log parising is very effective & intelligent.
Contras:
- The only think i liked least about splunk is the cost involved/pricing model in case of high data volumes.
Spunk Review
Puntos a favor:
It allows me to bring a lot of information into one friendly view. It's a great security audit tool.
Contras:
It has limited functionality. It is a very memory intensive system. It does not integrate with Lennox.
Swiss Knife for everything about logs
Puntos a favor:
The product has a ton of Features. Everything what you Need when working with logs is already implemented
Contras:
Due to the rich set of capabilities regarding, searching, transforming and vizualzing data it‘s sometimes quite tricky to find all necessary query commands
Alternativas consideradas:
Splunk is a great solution for SIEM and also for monitoring your infrastructure
Comentarios: We needed a way to monitor our internal environment and start to be more proactive with issues, so we started sending all of our logs to Splunk and we we able to get insights we did not know we needed. It is a great solution and they are constantly innovating.
Puntos a favor:
Splunk makes it easy to search through various data including logs. In the past I have had to pour through logs in order to find the one lines among the 100 of thousands of lines. Splunk allows me to search through those logs in a matter of seconds vs the hours it used to take.
Contras:
Most of enterprise setup is done through the command line. It would be nice to have cluster configuration (index creation) as part of the UI.
Alternativas consideradas:
Great Choice for an SIEM
Puntos a favor:
Provides a single location for collecting and analyzing logs. Provides ease of use for non-technical users, but powerful features for security and IT. There is an add-on/app for anything you could imagine.
Contras:
Some documentation is vague, and when certain things don't work, it can be difficult to find out a solution to the problem.
Alternativas consideradas:
A better business companion when integrated with RPA
Comentarios: Overall, the experience was positive; even with a free trial license, it was much easier, and on the course and certification side, Splunk has a very good collection of videos and materials that help even a novice quickly setup the integration and indexing.
Puntos a favor:
The most useful thing about Splunk is the ease of integration with application. With uipath on-premises it was very much helpful as the business users can monitor the actions of robots through spluink without entering into uipath orchestrator
Contras:
Expression creation for indexing was bit hard as it is not user-friendly to business users if they wanted to create any new fields, also the forwarder was not able to directly connect with uipath cloud so that the logs has to be shifted to intermediate file before uploading into splunk, but that seems not an issue with splunk but more related to uipath cloud
Helps you predict IT problems
Comentarios: Splunk Enterprise's real-time monitoring keeps us ahead of potential problems. A must-have tool!
Puntos a favor:
Splunk Enterprise is a great tool for security analytics, IT operations, and business intelligence. I especially like the way it can help me identify potential threats and improve our IT infrastructure.
Contras:
The pricing for Splunk Enterprise may be out of reach for some small businesses.
Good tool
Puntos a favor:
The search feature allows for quick searching of signatures for new KBs
Contras:
It feels very clunky to set up, explained by the whole certification track just for using splunk..
best security tool for Enterprise Network
Puntos a favor:
splunk is the best tool for real time analysis and monitoring tool and also it is providing the powerful threat incident response.
Contras:
from my perspective, these no downside of the splunk . but about costing is too much for single user
Splunk an Enterprise Business intelligent user tool
Comentarios: Is a robust and intelligent management tool that enables everyone with user computer knowledge to navigate in real-time, consolidate vast data into a visualized report of dashboard features , reliable and web based, no major equipment required for setup, user need a smartphone or compute to access the platform through the web, you can navigate the system as long as you have computer knowledge without any training required(user friendly) .
Puntos a favor:
It an intelligent business tool that provided me an opportunity to customize and build report from large volume of data from different departments within the 13 Africa countries in telecommunication sectors. The platform allows data to be consolidated accordingly to the organization need and produces visualized reports of dashboard features. I also noted that the system can analyst unstructured large volume of data speedily and is reliable and web based allowing for user flexible accessible from any part of the world if you have internet. The systems have been reliable and secured from the time (2 years) I started using it without any system intermittent, system errors and cyber-attack.
Contras:
The system is built and use-able with structured and unstructured organization though the price in foreign currency could hamper small and medium organization to use it especially in most Africa country where the local currency has depreciated against the major trading foreign currency.so the Forex pricing is a challenge. The navigation of the platform will require minor training though if the user is computer proficient, they would management with minor challenge and interpretation of the data. So, first time user it can be difficult to use it It will depend on internet for access and internet tend to be pricey in most African country and therefore could increase the business cost for small and medium enterprise. It can increase business cost if not fully used
An excellent SIEM at a low cost
Comentarios: We have many programs that measure the performance and quality of the operation, of the production in chevron, I think it is important that they give extra barriers to what we do and splunk is an optimal collaborator so that we can track all these programs and not get intrusions through the network.
Puntos a favor:
It is a very subtle program, when generating the setup it is not necessary to have a great knowledge of programming to install it, but to solve some configuration errors, when you start what I like the most is that you start from day one to organize your applications, then From that you can easily configure cybersecurity for each program, I particularly like the monitoring of data programs and that the program alerts you with notifications so that you see errors that sometimes jumps in the program.
Contras:
What I don't like and I see that it is something widespread is that it has very poor support in technical help, I think that the old technical support collaborators have left and people who are not so qualified have arrived to answer the tickets.For my part it is not a big problem since I am a researcher and with the information that is on the splunk website it is enough for me to generate the resolutions of problems.
Best friend for debugging
Comentarios:
Splunk basically makes debugging and monitoring easier and touch less. I can easily debug by starring the rolling logs from different instances in single screen.
I can monitor multiple components and multiple metrics, without running commands manually with custom plugins.
Puntos a favor:
Splunk comes with lot of in-built templates for each and every feature like log visualisation, dashboarding, traces,etc This makes the developers life lot easier. I can't think of any other logging tool that is snappy as well as accurate. I love the fact how easily I can plug it in my docker-compose to push container logs.
Contras:
Even though, it offers numerous features for different needs, each feature has its own learning curve. For instance log visualisation needs querying skills, which may be in natural language but it takes bit of time to get familiar.
Splunk the best analytic tool
Comentarios: It gives best Return on Investment as analyzing the data and giving proper insights in form of Dashboards and notifying with help of Alerts if any kind of threat running in infrastructure and apart from that Deployment and use is very easy.
Puntos a favor:
There are lot of features which Splunk offers - 1) We can onboard data from any server, device or system using Universal Forwarder 2) Onboarded data are later stored in Indexers and searched further in Search Head for analyzing the internal logs 3) Using the data we can create customizable Dashboards and get proper insights of data and create Alerts to identify any kind of Threat or anomalies running in environment 4) Deployment is very easy on-prem servers 5) We can also use Hybrid Deployment on Cloud as well.
Contras:
1) As it give large amount of features but licensing is too high 2) There are lot of other Open Source software which can be used as alternative of Splunk as Analytic tool because Splunk is paid one.
Alternativas consideradas:
Best SIEM
Comentarios: Great SIEM that beats the competition, we utilized it for various functions
Puntos a favor:
Splunk appsStrength and capabilitiesIntegration with most solutions
Contras:
Resource utilizationLimited local partner support
Excellent product
Puntos a favor:
It is an easy to use solution, the implementation is a bit more difficult.
Contras:
So far, this is a good solution that I use every day.
Best Tool for Monitoring Purposes.
Comentarios: As a user of Splunk, we generally used to monitor the log provided by the server clusters belonging to a tool called API Connect. As the logs are stored in Splunk, we tally the transaction count from API Connect tool and filter the log search in Splunk with a particular search query. We can download the logs of particular time and date of API Connect servers in case of transaction count issues. We create a dashboard for all the individual API's transaction count in terms of total transaction count of all API's. In this way, it makes our work easier to find out which API has the highest transaction count. We even use Splunk to know the state of the machine. Reports generated by the Splunk helps us to find out the API with the highest response time. In this way, Splunk makes our work a lot easier as it is very fast and highly secure.
Puntos a favor:
1) Accepts multiple data formats like CSV, JSON, XML 2) Does the hard work for us i.e converting machine data to a human-readable format. 3) Can create customized alerts to serve our business purpose. 4) Searching on the based on queries is pretty simple. 5) We can create dashboards to analyze and visualize our search results. 6) Can export the log content to our Personal computers. 7) Setting up plugins and integrating with any tool that needs monitoring is pretty easy. 8) Technical support for the Splunk is very quick as they have a dedicated staff for that.
Contras:
I did not find any flaws with this software.
Great log analysis software
Puntos a favor:
Integrates with almost all the software seamlessly..where there is a software application that produces log, splunk can be easily integrated. Gives very powerful insights into the logs Alerts can be setup on the logs, and notifications sent out which is great again for managing the health of your application
Contras:
The query language, though powerful, has a learning curve. Particularly as one goes towards complex queries. If it could be made closer to natural language, it would be so much smoother to learn. Hope that will happen sometime in future.
Splunk vs Humio and Devo
Comentarios: The APIs and plugin are great. the parsers are just fantastic. It can log anything and everything.
Puntos a favor:
We have been using splunk for over 5 years now. nothing beats splunk in the market place. The only concern we have the pricing and the resource to support it. it's just too expensive
Contras:
Too expensive and it's too hard to manage. You have to find a very qualified and very expensive resource to support it.
Splunk is a lifesaver!
Comentarios: It’s been wonderful. I was able to take most of my forwarded lambdas and charts them to watch duration and throughput. Notifications and alerts let me know if things are out of whack. Such a relief to know Splunk is watching my back!
Puntos a favor:
If you need real-time grokking into your infrastructure, look no further than Splunk. I love love love the dashboards. It’s easy to tell a story with your data, and the live search is so FAST!
Contras:
SPL is a little hard to get used to, but once you get the hang of it, it’s not so bad. I recommend downloading their community edition for some great examples of queries and dashboards.
Splunk Enterprise Reivew
Comentarios: My overall experience with splunk is too good. It helps our organization to set a real time monitoring system which keeps checking our server health and alert us if anything goes wrong. So, team can quickly resolve the issue and minimize the business impact.
Puntos a favor:
Real Time monitoring is the best feature which we like most about this software. It helps to send the notification or alerts if they are something wrong is going on in the server. So, team member can quickly resolve the issue.
Contras:
As of now, i don't have anything which i don't like about this software.
Premium but pricey log management and analytics tool
Comentarios: Having a enterprise-ready centralized logging tool is critical for production success.
Puntos a favor:
Splunk integrates with almost all popular enterprise software products including VMware, AWS, Azure, etc. Most customers use it primarily to do log analysis but it can also perform data analytics for business reporting. The UI is very straightforward and enables you to quickly search through large datasets using SPL. We were able to quickly locate the source of the issues by using Splunk to triangulate logs from several different components. There is a Splunk Cloud version with a free trial if you are aiming to do some integration work and testing. Finally, like all monitoring tools, Splunk offers AI and machine learning for even better predictive analytics.
Contras:
Splunk is expensive and probably not for smaller startup companies. The pricing is tiered and is subscription-based so if you start to ingest a lot of data, look out. It can eat into most of your IT budget and Splunk by itself doesn't handle all the Day 2 operations that are needed.