No more typing reviews! Try our Samantha, our new voice AI agent.

Palantir Foundry vs Splunk Enterprise Security comparison

 

Comparison Buyer's Guide

Executive SummaryUpdated on Jan 25, 2026

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Palantir Foundry
Ranking in IT Operations Analytics
8th
Average Rating
7.8
Reviews Sentiment
7.0
Number of Reviews
18
Ranking in other categories
Data Integration (13th), Supply Chain Analytics (1st), Cloud Data Integration (10th), Data Migration Appliances (3rd), Data Management Platforms (DMP) (1st), Data and Analytics Service Providers (1st)
Splunk Enterprise Security
Ranking in IT Operations Analytics
1st
Average Rating
8.4
Reviews Sentiment
7.3
Number of Reviews
387
Ranking in other categories
Log Management (1st), Security Information and Event Management (SIEM) (1st)
 

Mindshare comparison

As of May 2026, in the IT Operations Analytics category, the mindshare of Palantir Foundry is 4.0%, up from 3.2% compared to the previous year. The mindshare of Splunk Enterprise Security is 13.4%, down from 25.4% compared to the previous year. It is calculated based on PeerSpot user engagement data.
IT Operations Analytics Mindshare Distribution
ProductMindshare (%)
Splunk Enterprise Security13.4%
Palantir Foundry4.0%
Other82.6%
IT Operations Analytics
 

Featured Reviews

BA
Associate Vice President at a insurance company with 10,001+ employees
Unified data workflows have empowered collaborative analytics and streamlined AI development
Regarding points for improvement for Palantir Foundry, I see that they are improving day by day. In the last one to two years, I have seen many improvements compared to the two years that I have worked on Palantir Foundry. There are many things that come up, but a few things are not intuitive enough. Now that we are in this AI phase, Palantir Foundry has created some wrappers around the models, allowing us to create using a no-code application, chatbots, and LLM functions. The problem is that interaction with outside applications can be difficult with the current setup that Palantir Foundry has. There are ways to do that, but it is not that intuitive, which is what I feel.
Sathis-Kumar - PeerSpot reviewer
Senior Manager at Bank of America
Helps us detect cyber threats quickly and integrate multiple feeds effectively
Overall, the product is good, but when it comes to some infrastructure issues, we have to dig into more logs. There is no straightforward indication of an issue. Health check kind of dashboards are not available. More AI would help us, and more optimization, since security products run more queries. The AI module could suggest solutions, optimizing queries or workload balancing. If the product itself advises on running queries during peak times, it would be similar to what ChatGPT currently offers. We see quite a few issues on stability. Even last week, we faced something, and identifying bottlenecks is not easy. We need more SMEs, and there is no mechanism to tell us about indexer or search head issues. Self-monitoring dashboards could be beneficial. The technical support still requires more improvement. Often, primary support takes a lot of time and forwards most solutions to the engineering side. The primary support team has very limited knowledge to provide.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"Live video sessions enhance the available documentation and allow you to ask questions directly."
"I rate Palantir Foundry a ten out of ten."
"Great features available in one tool."
"I like the data onboarding to Palantir Foundry and ETL creation."
"It is easy to map out a workflow and run trigger-based scripts without having to deploy to another server."
"The interface is really user-friendly."
"This product has all the various components for getting data, transforming it and visually creating the dashboards without the need to integrate things and no need to check the compatibility."
"The security is also excellent. It's highly granular, so the admins have a high degree of control, and there are many levels of security. That worked well. You won't have an EDC unless you put everything onto the platform because it is its own isolated thing."
"We have found all the features useful. However, the dashboarding and logging have been very helpful."
"What I appreciate about Splunk Enterprise Security is creating the newest SPL for network traffic and using the risk-based alerting feature that helps my organization by allowing me to learn more information about Splunk every day because it is a big platform."
"Splunk allows us to find insights that we were not able to with traditional BI tools using ETL​. It allows us to dig into raw events."
"Splunk Enterprise Security helped improve our organization’s ability to ingest and normalize data."
"Speeds up root cause analysis and can help identify issues that your organization never realized were occurring."
"I have noticed a return on investment with Splunk Enterprise Security, as it delivers substantial value for money."
"Before Splunk, we used Kibana and Elasticsearch; sometimes, with them, logs wouldn't even be there, so Splunk being there and working does a lot."
"The most valuable features include agility and Splunk Enterprise Security's ability to quickly search for alerted items, as well as the capacity to create custom alerts using the SQL language employed by Splunk."
 

Cons

"The solution's visualization and analysis could be improved."
"Compared to other hyperscalers, Palantir Foundry is complex and not so user-intuitive."
"Difficult to receive data from external sources."
"The one area where improvement could be made is the cost of the solution which is quite expensive."
"Cost of this solution is quite high."
"It would be helpful to build applications based on Azure functions or web apps in Palantir Foundry."
"The major hindrance with Palantir Foundry is that being a very closed product, the cost optimization and costing are not exposed to the end users."
"The problem is that interaction with outside applications can be difficult with the current setup that Palantir Foundry has."
"We would like more integrations with other cloud products, not just AWS, e.g., Azure."
"The high cost of Splunk Enterprise Security prevented us from using its full capabilities."
"I would like to see future development in terms of ML (Machine Learning)."
"We're planning to incorporate UBA and SOAR. It would be good to have everything in one place."
"The threat detection library needs to increase the frequency at which the playbooks are updated."
"Its deployment is difficult. I remember when I first started learning, I faced several challenges, especially when deploying VMware in a virtual environment."
"If you monitor too much, you can lose performance on your systems."
"The problem with Splunk Enterprise Security generally, from what I've seen in the last couple of years, is that it has a cultural, assumption design model around it, which means the company has to fit its internal processes in terms of how to use it."
 

Pricing and Cost Advice

"Palantir Foundry is an expensive solution."
"Palantir Foundry has different pricing models that can be negotiated."
"The solution’s pricing is high."
"It's expensive."
"Luckily, we come under a large federal agency, and before the pandemic, they signed a large enterprise license agreement. It worked out great and to our advantage because we are a small organization. We got a 300 gig license, and we just did not have the buying power to be able to get products cheaply. Because we all partnered together under the agency umbrella, we were able to get Splunk Enterprise Security, UBA, and ITSI for cheap. This was good considering the fact that some of these premium apps require a minimum number of users, and we do not have the number of people needed to even justify buying it."
"I assume that the pricing is reasonable, because if it was too costly, there are other alternatives."
"Price-wise, if you compare QRadar to Splunk for SIEM functionality then they are in the same range but when you integrate SOAR with these solutions, Splunk takes the lead and is more competitive."
"Splunk Enterprise Security is expensive."
"Setup cost is cheap: It is free, it is user-friendly, and it is fast."
"It is possible to use a developer's license, which is up to 10GB per day of volume traffic, which is usually enough for most use cases."
"The Splunk licensing is high."
"The cost is on the high end, which makes it difficult for some organizations to use."
report
Use our free recommendation engine to learn which IT Operations Analytics solutions are best for your needs.
893,244 professionals have used our research since 2012.
 

Comparison Review

VS
Manager, Enterprise Risk Consulting at a tech company with 1,001-5,000 employees
Feb 26, 2015
HP ArcSight vs. IBM QRadar vs. ​McAfee Nitro vs. Splunk vs. RSA Security vs. LogRhythm
We at Infosecnirvana.com have done several posts on SIEM. After the Dummies Guide on SIEM, we are following it up with a SIEM Product Comparison – 101 deck. So, here it is for your viewing pleasure. Let me know what you think by posting your comments below. The key products compared here are…
 

Top Industries

By visitors reading reviews
Manufacturing Company
13%
Financial Services Firm
9%
Government
8%
University
6%
Financial Services Firm
14%
Manufacturing Company
9%
Computer Software Company
9%
Comms Service Provider
5%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business4
Midsize Enterprise5
Large Enterprise9
By reviewers
Company SizeCount
Small Business118
Midsize Enterprise51
Large Enterprise269
 

Questions from the Community

What needs improvement with Palantir Foundry?
Regarding points for improvement for Palantir Foundry, I see that they are improving day by day. In the last one to two years, I have seen many improvements compared to the two years that I have wo...
What is your primary use case for Palantir Foundry?
There are several use cases that we are working on with Palantir Foundry. The first thing is for data model creation for all our data engineering pipelines. That is one use case. Palantir Foundry a...
What advice do you have for others considering Palantir Foundry?
The visualization part in Palantir Foundry works for me at least if I want to see how the data is structured and for an initial analysis, but I would say it is not as matured as Power BI or Tableau...
What SOC product do you recommend?
For tools I’d recommend: -SIEM- LogRhythm -SOAR- Palo Alto XSOAR Doing commercial w/o both (or at least an XDR) is asking to miss details that are critical, and ending up a statistic. Also, rememb...
What is a better choice, Splunk or Azure Sentinel?
It would really depend on (1) which logs you need to ingest and (2) what are your use cases Splunk is easy for ingestion of anything, but the charge per GB/Day Indexed and it gets expensive as log ...
How does Splunk compare with Azure Monitor?
Splunk handles a high amount of data very well. We use Splunk to capture information and as an aggregator for monitoring information from different sources. Splunk is very good at alerting us if we...
 

Overview

 

Sample Customers

Merck KGaA, Airbus, Ferrari,United States Intelligence Community, United States Department of Defense
Splunk has more than 7,000 customers spread across over 90 countries. These customers include Telenor, UniCredit, ideeli, McKenney's, Tesco, and SurveyMonkey.
Find out what your peers are saying about Palantir Foundry vs. Splunk Enterprise Security and other solutions. Updated: April 2026.
893,244 professionals have used our research since 2012.