This is a review from a consultant not from a final user
- Ingestion and analysis of data for security issues
- possibility to perform automaticincident response actions
- itpermits to SOC analysts to investigate and intervene on systems
Cons
- The interface isn't immediate in comprehension, I had to follow a training to understand how it works
- it's expensive: not all the customers can buy it!
- It needs PostgreSQL as DB, I'd like to have all inside Splunk also data.
- Satisfy customers
- Have an integrated solution for our proposal
- Avoid the presence (as much as possible) of external products in security management
- Support SIEM in data analysis
- intervenes on systems after a security incident
- Automate as many as possibile activities
- Complete Splunk ES offering
- Complete Splunk ES offerings
- Product Features
- Product Reputation
Im satisfied by this product, We'd propose much more it with a lower price.
- Implemented in-house
Design,
Installation,
Configuration
Tuning
- No relevant issues
- Online training
- Playbooks at first
- External Systems access
- Atomated activies configuration
- All without training, non with training
- Maybe installation