IBM X-Force Incident Response and Intelligence Services (IRIS)
Splunk Enterprise Security
Likelihood to Recommend
Well suited to the following:1. Data-Driven Analytics. I cannot stress that enough. It has been transformational in the way we are able to accomplish tasks and analyze large amounts of information. 2. Connect-The-Dots methodology. I have found it incredibly adept in allowing new information to be used in tandem with already-known info.3. This is the icing on the cake and what I had originally set out to accomplish - IRIS has made it possible - Generative AI that uses verified data science to provide insights and expedite our advancement by performing experiments yielding real-world positive results. This has significantly reduced the time it takes for technology to be ready and marketable, reduces the workload, and saves a tremendous amount of money in the long run by allowing our discoveries to be 3 weeks away instead of 30 years. In contrast, scenarios where it is less appropriate are in nearly identical company when it comes to my third point (A double-edged sword, if you will.) We have a responsibility to ensure that this technology is used for a positive outcome and "Future:Forward" approach. This is the mark of true Evolution. It's up to us to keep it so.
Immediate recognition of possible conflicting interests within a field of view.
Ability to assist users with Research and Development at an extraordinary rate.
Real-Time feedback via neural pathways to analyze data and implement independent solutions that are tailored to the specific applications on-site.
This entire review was written with the assistance of IRIS technology as a demonstrative of it's very real practical application. This took less than 2 minutes to write using my own hands.
Its best feature is its user interface, which is easy to navigate and understand. All you need is a little tutorial on how to use the Splunk query language and you're done.
Logs can be easily uploaded or shared across multiple platforms and display a highly insightful graphical representations of data using graphs, tables, and many other formats.
You definitely need to learn how to use Splunk to get the most of the tool. There are many courses available for free to get up to speed on the usability of the tool but it's not that simple. It will take time to digest all the data and to understand how to query for what you are looking for.
ES requires a very performant infrastructure: if it has it's performant, otherwise not. I had situation with a very performant infrastructure and I didn't notized that it was a distributed architecture, it seemed that there ware few data on my PC, othewise I experienced less performant infrastructures with less performaces.
It's good when it's responsive, but I've had times where I had to wait quite a while for a response. But these are typically the exceptions rather than the rule. When you do get a response it is always well-informed and appropriate. I would say they've been trending better over time with this.
I experienced only on-line training, but the trainers were very professional and competent. Maybe it could be more useful if they also have an experience in projects because sometimes they didn't have a real project experience to communicate to the students. Anyway, it was very interesting and I learned many thing that's very difficoult (or maybe impossible!) to have by myself, aven if I have more than 10 years of Splunk activity experience.
It was very interesting and I learned many thing that's very difficoult (or maybe impossible!) to have by myself. The only problem was that, when I worked with the Splunk Professional Services, I found some difference between the training contents and the information from PS. In addition is required a long experience on Splunk Enterprise for the data ingestion part, in other words I'm able to work with ES because I'm worling on Splunk since 11 years, otherwise I'd some problem.
Secure work environment with this platform has enhanced effective workflow infrastructure. The cost of deployment and configuration capabilities with other security applications lead to main decision of acquiring this tool. The security control dashboards gives reliable performance reports that leads to quick decision-making when there are malware attacks. It gives lifecycle report for most work processes and threat intelligence information that enables my team to track workloads effectively.
LogRhythm is good for a team comprising mostly non-technical IT users. Unlike Splunk, it has a GUI log search and a good ticketing system. Splunk is better than Logrhythm for me as it provides me with the ultimate flexibility to write custom queries. Scalyr is a good tool and quite frankly lot faster than Splunk. However, I prefer Splunk because of its better Dashboards and panel customization abilities. Elastic is another amazing tool. It is hard to choose between the two especially because both have different sets of logs on them. I use both. Elastic for internal server logs, Splunk for everything else.
We have on prem splunk and it’s mostly east to setup, but we have issues keeping data separated between customer splunk deployments while at the same time only having to look at one SIEM to address events in every environment
We have a 100% success rate on all our ES implementations due to the amazing documentation and Splunk enablement on the subject.
Our Splunk ES business has grown 100% YoY for the last 3 years.
In terms of long term management and maintenance, ES has been highly stable and predictable, reducing our overhead on costly services team for ad hoc maintenance work.