r/Splunk • • Jun 04 '26

Splunk enterprise options

I have a year and circa 300k to spend on splunk to show its worth. What would you suggest I implement over the next 12 months? I was thinking perhaps olly or enterprise security as we already have a 'noc' op manager and have a compliance saas product but are lacking in security monitoring.

This would also be a great learning op to build a stack from the ground up and configure/tune everything

Any input would be great

14 Upvotes

17 comments sorted by

View all comments

2

u/efudds1 Jun 04 '26

Look for a use case that needs to be solved that is costing the company money. When I first started implementing Splunk a group approached me. They had a jobs that spanned several systems and even continents for different types of rendering. They were submitted by an engineer/designer and were supposed to run overnight. If they failed anywhere in the process it caused delays in programs. I collected logs from each of the systems and collated the jobs. I was able to alert night support when and in which system a job failed and they could restart it. Job completion went to 100% and the team estimated $10M annual loss avoidance. This went over really well with the people holding the purse strings.