TrustRadius: an HG Insights company

Splunk Cloud Platform

Score8 out of 10

137 Reviews and Ratings

What is Splunk Cloud Platform?

Splunk Cloud Platform is a data platform service thats help users search, analyze, visualize and act on data. The service can go live in as little as two days, and with an IT backend managed by Splunk experts.

Top Performing Features

  • Correlation

    Correlation of logs and events to pinpoint significant threats

    Category average: 8.4

  • Event and log normalization/management

    Ability to normalize event syntax so that logs can be compared and are machine-understandable

    Category average: 8.5

  • Custom dashboards and workspaces

    dashboards that can be customized to meet the needs of specific groups

    Category average: 7.9

Areas for Improvement

  • Data integration/API management

    Ease and quality of data integrations between SIEM and other systems

    Category average: 8.1

  • Rules-based and algorithmic detection thresholds

    Effectiveness of manually-established rules and algorithmically-determined detection thresholds

    Category average: 8.2

  • Response orchestration and automation

    Quality of built-in response orchestration and automation in Next-Gen SIEM

    Category average: 7.1

Splunk Cloud Platform assessment

Use Cases and Deployment Scope

The current use case is using Splunk Cloud Platform to look for cyber security threats. While there are other tools being used to look for cybersecurity threats. Splunk Cloud Platform has proven to be a reliable and trusted source.

It's also used monitor login attempts and watch traffic patterns and trends. Dashboards have long been used in this product and will continue.

Pros

  • Monitoring
  • Dashboards
  • Searching

Cons

  • Cost
  • Configuration
  • Maintenance

Return on Investment

  • Reduced MTTR by 25%
  • Preventing breaches justifies investment
  • High licensing costs
  • Need for skilled senior personnel to operate

Usability

Alternatives Considered

Datadog, Elastic Security and Microsoft Sentinel

Other Software Used

PagerDuty, Splunk SOAR, DataSet by SentinelOne, Zeek Network Security Monitor

Perfect fit for our needs in analyzing data

Use Cases and Deployment Scope

We are using Splunk Cloud Platform mainly for data quality management, especially for monitoring important interfaces and data insufficiencies.

Additionally, we use it to monitor automation performance of our Automation Suite, including 250 productice automations from various providers. Splunk Cloud Platform is great at identifying patterns where automations are failing, summarizing that information and enhancing it with context and sending it out to another tool carrying out the orchestration for us. With Splunk Cloud Platform, we also make sure to minimize maintenance pings by summarizing likewise events in one protocol.

Pros

  • Statistics
  • Pre built functions
  • Orchestration/Queue mgmt

Cons

  • Debugging
  • Third party integrations
  • Logon speed

Return on Investment

  • Increased time for value deriving tasks
  • More efficient maintenance and debugging processes
  • Overall increase in transparency on maintenance issues
  • Improved data quality and consistency

Usability

Alternatives Considered

Microsoft Power BI

Other Software Used

UiPath Automation Platform, Microsoft Power Automate, Celonis

One-size-fits-all indexed monitoring solution with stromg search capabilities

Use Cases and Deployment Scope

Splunk Cloud Platform is our near-real-time monitoring machine for observation of more than 200 automated systems. It indicates faulted processes, inefficiencies in operations and sends out webhook pings to our developers to fix these. Without Splunk Cloud Platform‘s search pricessing capabilities, we would never be able to cover all systems executions, screen logs for systematic errors and give direct advise on the fix.

Pros

  • Search processing
  • Indexing of fields (automatic and custom)
  • Performance

Cons

  • Debugging tools
  • Implementation of AI components
  • Third-party integrations

Return on Investment

  • Saved a lot of time on maintenance / observation
  • Professionalization of automation services
  • Improved reliance and time to fix

Usability

Alternatives Considered

Celonis and Microsoft Power Automate

Other Software Used

UiPath Automation Platform, Bizagi Digital Business Platform, Celonis

Best logging and Future SIEM tool

Use Cases and Deployment Scope

We use to be Splunk Enterprise customer but local storage for logs was challenging. Moving to cloud indirectly we have now unlimited storage and scale up easy when our requirements change.

Pros

  • Storage

Cons

  • Access over private links

Return on Investment

  • Meets our dynamic / constant expanding needs

Usability

Alternatives Considered

FortiAnalyzer

Other Software Used

IBM Security QRadar SIEM

Security Excellence and IT Ops Insights at your fingertips in a single place

Use Cases and Deployment Scope

We use Splunk Cloud to aggregate logs from various Cloud and on-premise applications and services into a single place for Security and IT Operations monitoring. This allows us to focus on a single platform and remove duplication of costs, training, data onboarding etc. We have alerts that are sent directly to operations teams and dashboards available for wallboards and aggregate data.

Pros

  • Easy to get data in
  • Rich user experience
  • Wide range of Splunk & Community add-ons

Cons

  • Unable to download configuration changes easily

Return on Investment

  • Splunk Cloud has reduced the need for in-house Infrastructure Engineers due to the service being maintained by Splunk instead of ourselves.
  • We no longer need to pivot between multiple cloud provider tools to monitor multiple services.

Alternatives Considered

Amazon CloudWatch, Datadog, Elasticsearch, New Relic, Cribl Edge, Cribl Stream and Cribl.Cloud

Other Software Used

Amazon CloudWatch, Amazon Elastic Compute Cloud (EC2), AWS Lambda, Docker, Cribl Stream, Cribl Search