Splunk supports IT operations analytics with the Splunk IT Service Intelligence premium offering, a software application available to subscribers to Splunk Cloud or Splunk Enterprise log analytics and SIEM platforms.
N/A
Veeam ONE
Score 8.2 out of 10
N/A
Veeam ONE is virtualization management technology from Ohio based VMware partner Veeam Software.
[Splunk IT Service Intelligence (ITSI)] is well suited when you have a system that you want to visualize, and then layer in information from many different sources. This will allows ITSI to intelligently create alerts based on the system as a whole vs the individual components. In some cases, a simple splunk dashboard would really suffice over using ITSI. Teams deploying ITSI should really understand the use cases and consider using simple dashboards where they make sense, and use ITSI for topological views.
Veeam One works great for monitoring virtual infrastructure. However, other dedicated server monitoring apps do better with monitoring the individual VMs. Where it stands out is its reporting functionality, which allows you to forecast growth and keep track of how you are using your resources. It is also great for companies without a big monitoring budget, as there is a pretty functional free version.
Proactive Alerting - the product can provide email alerts to notify one of any issues in the environment.
Capacity Planning and Forecasting - it has the ability to provide an analysis of the current environment as well as provide a report to forecast future capacity requirements.
Monitoring and Reporting - the software can monitor you environment 24x7 with the ability to provide comprehensive reporting.
The terminology takes some getting used to: Aggregation policies, notable events, correlation searches, glass tables. If you're not familiar with ITSI, these terms can be a bit overwhelming and steepens the learning curve.
We have had some technical issues with the underlying support when used in a multisite cluster. We've had to build in several points of redundancy to make sure it works as expected.
I'd like to see additional types of notable events, like informational events that come in for when an incident is created or when an alert is acknowledged so all of those action steps can be viewed on the episode timeline without affecting the count of events.
Basically the products works very well and we have been very pleased, but following are some picky details I could suggest for improvement specific to our needs.
We leave the GUI up on a TV in our Office and on our desktops to visibly see if anything is alerting. It would be nice if you could customize the view to have a smaller minimum view with just the widgets you wanted.
When the GUI starts on a multi-monitor setup it always returns to the primary and any popup windows always go to the primary instead of the monitor you have the application running in.
We have replaced our monitoring platform with Splunk & ITSI, and with the success, it's seen at our organization thus far we would be hard-pressed to pivot to another tool. Frankly, our business partners and application teams love Splunk & ITSI.
Splunk IT Service Intelligence (ITSI) is a platform with extended functionality and provides various functionalities which can be utilized to improve the efficiency and accuracy in analyzing the data and detecting the attacks.
The software is a joy to use. The user interface is good overall and you can find frequently needed things easily and quickly. Some less frequently needed things eg. settings are hidden under several menus and one might have to look for those for a while. We also haven't had any issues with the products reliability.
During POC, pre-planning, and implementation, we have had interactions with numerous folks at Splunk. Everyone from sales & engineering to markets analysts to specific IT component SMEs, and a small professional services engagement to get started. They have all been exceptionally helpful and go above and beyond the call of duty. They actively reach out to ensure success is being realized and find ways to help proactively, instead of having to simply open support cases with the vendor.
Support, as mentioned earlier, is often slow to respond for Veeam ONE requests. To Veeam's credit, they will work on an issue until they find a solution, and will even develop a specific hotfix for your environment if one is needed, but response time is just slow.
Splunk has raised itself as a platform not just as a tool unlike other products in the market. If I talk about Moogsoft it also has similar capabilities but Splunk ITSI has more visibility and its GUI is making a different impact on the users. ServiceNow and Splunk are equally capable products however Splunk seems to have more tech-savvy people tools than ServiceNow.
Veeam One is very easy to use, easy to configure and get what you want. The integration for Veeam Backup is perfect, for today i think Veeam need to make Veeam One monitor Microsoft 365 envirioment, this will give great imput and integrated with Veeam Backup for 365 will be amezing.
The most valuable reports can safe us a lot of headaches and downtime. What used to be an emergency once in a while is an afterthought as we proactively prevent those same issues in less than 5 minutes a week.
The simplicity has allowed us to offload some virtual environment monitoring to a junior associate.
Initial deployment took some time because we couldn't get licensing figured out, but it has been smooth sailing since then.