No more typing reviews! Try our Samantha, our new voice AI agent.
Mohamed Fouad - PeerSpot reviewer
Cybersecurity Team Leader at EMAK For Computer Manufacturing (ECM)
Real User
Top 5Leaderboard
Mar 18, 2026
Comprehensive correlation and automation have improved incident detection and reduced phishing
Pros and Cons
  • "The best features I value about Splunk Enterprise Platform include a great correlation rule that allows me to edit and generate alerts based on any event in an easy and fast way."
  • "We have Splunk at a very high cost, but I can say that other vendors working with mid-size customers can compete against Splunk."

What is our primary use case?

Splunk Enterprise Platform serves as our SIEM solution from Splunk, which is a market leader. It is a SIEM solution for log management and correlations. We have multiple logs from most of our infrastructure tools and security products. We obtain these rules and logs through many protocols including syslog and API. We then normalize and correlate this data and create incidents based on the activity running on our infrastructure.

What is most valuable?

I appreciate the API, the protocols, and the workflows as it functions as a SIEM solution. The main function is correlation.

The best features I value about Splunk Enterprise Platform include a great correlation rule that allows me to edit and generate alerts based on any event in an easy and fast way. I can accomplish this in a short period of time, and afterward, I can see incidents based on the correlation rule in a very professional and effective way.

I value the incident management and the correlations.

Splunk Enterprise Platform helps in detecting anomalies and preventing outages. The main core function for any SIEM is to have correlation. For example, if you receive user activity on a VPN logging in from Egypt, then after a while you receive logs from the firewall showing the same user logging in with a VPN from Ukraine, it is not logical that the user would move from Egypt to Ukraine in just five minutes. Splunk Enterprise Platform will create an incident and detect this as a credential compromise because we have a successful login from another location. This is the magic of correlation. We receive many events, we correlate these events, and then we can create an incident. After that, we have Splunk SOAR to take actions in an automation process to stop this incident without any management or any actions from the team.

The end-user experience is enhanced by the security product, as we have a return on investment on lower security incidents. After we implemented it with the SOC and Splunk SOAR, we can stop phishing and spam. The end-user experience will not see many phishing domains; they will be reduced. Security incidents will be reduced. Network performance will be very good after we implement it because we can detect who is scanning our network and creating a bottleneck on the network. We can stop and detect this with Splunk, whether it is SIEM from Splunk or SIEM with SOAR.

What needs improvement?

I use the machine learning toolkit with Splunk Enterprise Platform. The machine learning is very good on Splunk, but it sometimes makes searching for events become slow, so we have stopped using it. I think this needs improvement on Splunk.

The machine learning has room for improvement.

I think threat management needs improvement when compared to other vendors.

I compare Splunk Enterprise Platform with other solutions and vendors and see a very good point on pricing. We have Splunk at a very high cost, but I can say that other vendors working with mid-size customers can compete against Splunk. However, compared to Splunk, it is very expensive compared to other vendors. I think after the acquisition from Cisco, we can get discounts for licensing, and I believe Cisco will reconsider the pricing for Splunk Enterprise Platform.

I would prefer to see improved pricing for Splunk Enterprise Platform.

My thoughts on the pricing are that it is not cheap.

I have thoughts on the advanced threat detection, and I see that it is integrating with threat intelligence, and I believe this needs improvement.

For how long have I used the solution?

I have been using this solution for about two years. We have deployed many services from Splunk here in Egypt. Most of it is a SIEM solution from Splunk. We also have SOAR from Splunk, and we are running it on the largest bank here in Egypt. Most of the portfolio from Splunk that I have worked with was over approximately two years.

Buyer's Guide
Splunk Enterprise Platform
March 2026
Learn what your peers think about Splunk Enterprise Platform. Get advice and tips from experienced pros sharing their opinions. Updated: March 2026.
885,311 professionals have used our research since 2012.

What do I think about the scalability of the solution?

Regarding scalability, Splunk Enterprise Platform, like any SIEM solution, provides scalability. Whenever we receive more logs, we can easily scale. I rate this aspect as a ten.

How are customer service and support?

I rate the technical support as very good.

How was the initial setup?

The deployment was not easy, nor was it complex. It requires a professional and certified engineer to deploy the product, as many SIEM solutions do. One cannot easily deploy a SIEM solution. You have to work on correlations and personalize the dashboard. There is a lot of configuration for any SIEM solution, not only Splunk Enterprise Platform.

What other advice do I have?

I would advise others looking to implement this product to totally recommend it. I recommend this both before and after the acquisition. I totally recommend acquiring Splunk Enterprise Platform portfolio, whether it is Splunk SOAR, Splunk Cloud, or Splunk Enterprise Platform. I rate this solution a ten overall.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Last updated: Mar 18, 2026
Flag as inappropriate
PeerSpot user
Manager Recruitment at tata elxsi
Real User
Top 20
Apr 24, 2025
User-friendly interface accelerates task approval but update confirmations occasionally delay
Pros and Cons
  • "Splunk Enterprise Platform saves approximately 20 to 30 percent of my time without having to perform different actions separately."
  • "The only problem I have with Splunk Enterprise Platform is that sometimes when I update a review, it takes time to receive confirmation emails."

What is our primary use case?

I normally use Splunk Enterprise Platform for review purposes. It is very easy and convenient. Its GUI is easy for me to review and approve all those things.

What is most valuable?

Splunk Enterprise Platform is very easy and convenient to use. The graphical user interface is easy for me to review and approve tasks. It saves time by allowing me to perform actions on a single platform instead of managing them separately. Additionally, its real-time processing capability is very good.

What needs improvement?

The only problem I have with Splunk Enterprise Platform is that sometimes when I update a review, it takes time to receive confirmation emails. This happens very rarely, maybe once or twice a month. I feel this can be improved in terms of performance.

For how long have I used the solution?

I have been using Splunk Enterprise Platform for three years.

What do I think about the stability of the solution?

Splunk Enterprise Platform is very stable.

What do I think about the scalability of the solution?

Splunk Enterprise Platform is scalable to some extent, which is acceptable. However, when I connect via VPN, it may take time to launch.

How are customer service and support?

I haven't got any support yet, so I can't comment on this as of now.

How would you rate customer service and support?

What was our ROI?

Splunk Enterprise Platform saves approximately 20 to 30 percent of my time without having to perform different actions separately.

What other advice do I have?

My overall experience with Splunk Enterprise Platform rates around seven out of ten points. The main issues are regarding updating reviews and scalability, which may take some time when connecting via VPN. I would rate the overall solution 7 out of 10.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Buyer's Guide
Splunk Enterprise Platform
March 2026
Learn what your peers think about Splunk Enterprise Platform. Get advice and tips from experienced pros sharing their opinions. Updated: March 2026.
885,311 professionals have used our research since 2012.
UzairKhan - PeerSpot reviewer
Business General Manager at Mutex Systems
Reseller
Top 5
May 9, 2025
Delivers financial benefits and operational efficiency with impactful data analytics capabilities
Pros and Cons
  • "Splunk Enterprise enhances data analytics with its AI capabilities."

    What is our primary use case?

    The use cases for Splunk Enterprise Platform vary depending on the specific scenario.

    Splunk Enterprise Platform has different purposes, including data visualization and other applications.

    What is most valuable?

    In Splunk Enterprise Platform, the most impactful features for data analytics allow you to get into the repository.

    There are financial benefits from using Splunk Enterprise Platform, and as a retailer, it provides better profit margins.

    Splunk Enterprise enhances data analytics with its AI capabilities.

    What needs improvement?

    For future updates of Splunk Enterprise Platform, I would like to see integration by GUI.

    The integration should be improved with the UI.

    For how long have I used the solution?

    I have been using Splunk Enterprise Platform for about two years.

    What was my experience with deployment of the solution?

    There are no significant challenges in deploying Splunk Enterprise Platform.

    The challenges or pain points others should anticipate before implementing Splunk Enterprise Platform are mostly related to the integration part.

    How was the initial setup?

    The time it takes to deploy Splunk Enterprise Platform depends on the use cases.

    It may take anywhere from a couple of hours to a couple of weeks for Splunk Enterprise Platform deployment.

    What about the implementation team?

    The same three people take part in the deployment of Splunk Enterprise Platform.

    I do not take part in the deployment; my team does.

    What other advice do I have?

    My advice for those looking to implement Splunk Enterprise Platform is to know the product well and have hands-on workshops or create a lab to gain complete knowledge before proceeding.

    Regarding maintenance, it does not require much as it is on-premises.

    Overall, I would rate Splunk Enterprise Platform an eight.

    Which deployment model are you using for this solution?

    On-premises

    If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

    Other
    Disclosure: My company has a business relationship with this vendor other than being a customer. Reseller
    PeerSpot user
    Raymond De Rooij - PeerSpot reviewer
    Product Owner at ABN AMRO Bank N.V.
    Real User
    Top 5Leaderboard
    May 28, 2024
    Enables us to create dashboards and do analysis but has limitations
    Pros and Cons
      • "Splunk can be used primarily to port log files, allowing for easy and quick management of large amounts of logs. However, this can also be a drawback due to the configuration, parsing, and dashboard creation limitations. Communication is stream-based, which means you need to do a lot of pre-emptive setup to get a nice export."

      What is our primary use case?

      We use Splunk to create dashboards and do analysis.

      What is most valuable?


      What needs improvement?

      Splunk can be used primarily to port log files, allowing for easy and quick management of large amounts of logs. However, this can also be a drawback due to the configuration, parsing, and dashboard creation limitations. Communication is stream-based, which means you need to do a lot of pre-emptive setup to get a nice export. Another issue with Splunk is its streamlined nature; it reruns the query whenever you refresh a dashboard. This becomes problematic if you have a large volume of log files, as it can be slow, resource-intensive, and require significant storage space.

      It is designed to process and analyze log files. You feed log files into the platform, automatically extracting different fields. This allows you to filter and manipulate the data in a stream-based manner. Essentially, you pass a log file through various filters sequentially, enhancing or reducing its size by adding or removing information. However, this stream-based approach can make it challenging to create detailed dashboards easily. The platform primarily focuses on log files and is unsuitable for real-time data analysis.

      For how long have I used the solution?

      I have been using Splunk Enterprise Platform for one or two years.

      What do I think about the stability of the solution?

      The product is stable.

      I rate the solution’s stability a six out of ten.

      What do I think about the scalability of the solution?

      It can be very slow if you have a lot of data, and scaling it up for better performance can be quite expensive.

      A thousand users use this solution. We have many systems and a lot of data.
      It is centrally deployed and used extensively across various systems. I use it daily, but sometimes I only use it once a month. It depends on the data I need or the issue I'm investigating.

      I rate the solution’s scalability a four out of ten.

      How was the initial setup?

      The initial setup is straightforward.

      What other advice do I have?

      I wouldn't recommend Splunk Enterprise Platform because it's slow and has significant limitations.

      Overall, I rate the solution a six out of ten.

      Which deployment model are you using for this solution?

      On-premises
      Disclosure: My company does not have a business relationship with this vendor other than being a customer.
      PeerSpot user
      Mohammed Hassan - PeerSpot reviewer
      Regional Director at iSecureMind
      Real User
      Top 5Leaderboard
      Mar 25, 2025
      Real-time data analysis benefits but automation in role creation needs improvement
      Pros and Cons
      • "Splunk Enterprise Platform is a good tool to have, but it is expensive."
      • "While Splunk Enterprise Platform is a good product, it is expensive. Additionally, it is complex for inexperienced cybersecurity engineers and requires experienced personnel to handle it effectively."

      What is our primary use case?

      We are working with AppDynamics, Splunk Enterprise Platform, and other Splunk products. However, the main use case here is with Splunk Enterprise Platform.

      What is most valuable?

      Splunk Enterprise Platform is a good tool to have, but it is expensive. The features that have proven most effective for real-time data analysis include parts of the platform and its automation capabilities. However, I want them to enhance their automation to cover every aspect, particularly the automation of roles creation.

      What needs improvement?

      While Splunk Enterprise Platform is a good product, it is expensive. Additionally, it is complex for inexperienced cybersecurity engineers and requires experienced personnel to handle it effectively.

      For how long have I used the solution?

      We have been providing Splunk Enterprise Platform for ten months.

      How are customer service and support?

      Splunk's technical support is at the same level for all products, although we have not opened many tickets.

      How would you rate customer service and support?

      Neutral

      What's my experience with pricing, setup cost, and licensing?

      Splunk Enterprise Platform is expensive.

      Which other solutions did I evaluate?

      The main competitor of Splunk in our region is Exabeam, which is less expensive. For small and medium companies, Fortinet is a competitor. Stellar Cyber has also recently entered the market.

      What other advice do I have?

      For smaller companies, I recommend Stellar Cyber as an alternative to Splunk Enterprise Platform. Stellar Cyber is easier to implement and integrate, and it has solid AI capabilities, especially for automation. It is also willing to adapt to customer requirements. I would rate Splunk Enterprise Platform overall somewhere between six and eight, depending on the size of the company.

      Disclosure: My company has a business relationship with this vendor other than being a customer. Reseller
      PeerSpot user
      reviewer2511618 - PeerSpot reviewer
      Manager - Anti-Fraud Strategy & System Solution Officer at a financial services firm with 10,001+ employees
      Real User
      Top 5Leaderboard
      Nov 17, 2024
      Seamless integration streamlines fraud detection
      Pros and Cons
      • "Splunk is very flexible in handling various formats of data as long as basic rules are adhered to."
      • "The Splunk Processing Language (SPL) poses a steep learning curve for new users."

      What is our primary use case?

      The main use case is to analyze the data log coming from other systems. We use Splunk to identify anomalies in transaction patterns, which may indicate irregular activity from certain customers. Our goal is to create alerts for stakeholders when such anomalies are detected.

      How has it helped my organization?

      Splunk has made our job easier by streamlining data searching and decision-making processes. By using it for fraud detection, we have potentially saved billions of Indonesian rupiah.

      What is most valuable?

      Splunk is very flexible in handling various formats of data as long as basic rules are adhered to. Its integration with other systems is seamless and can be done overnight. This ease of integration is its best advantage. Additionally, Splunk is adequate for real-time data processing.

      What needs improvement?

      The Splunk Processing Language (SPL) poses a steep learning curve for new users. The software could benefit from additional processing power, such as GPU support, for handling large volumes of data faster. The language could also be more user-friendly, similar to platforms where actions are easier through button clicks.

      For how long have I used the solution?

      I have used the solution for approximately three years.

      What do I think about the stability of the solution?

      I rarely encounter bugs or glitches during daily use. However, there was one instance where an issue required solutions from the headquarter's next upgrade session.

      What do I think about the scalability of the solution?

      Splunk is scalable, provided the supporting infrastructure, such as CPU and GPU processing, is also scalable.

      How are customer service and support?

      I rarely communicate with the Splunk headquarters, usually interacting with the local implementer.

      How would you rate customer service and support?

      Positive

      Which solution did I use previously and why did I switch?

      We are not using anything else that functions like Splunk. However, for fraud detection, we also use GVD Instinct and FICO, along with Elasticsearch.

      What about the implementation team?

      I have not been involved in implementing it, except in integration, where I've found it easy.

      What was our ROI?

      We have been saving significant amounts through fraud detection. I cannot say precisely how much. Overall, Splunk has simplified our data management and decision-making processes.

      What's my experience with pricing, setup cost, and licensing?

      The official license operates like a subscription with an annual fee. Our local implementer offers pricing based on reserved quota, such as 80 gigabytes per day, costing under one billion Indonesian rupiah, or around $70,000 USD. It is affordable and flexible.

      Which other solutions did I evaluate?

      Elasticsearch, Kibana, Check Point, and other solutions like Microsoft Teams, OneDrive, and SharePoint are used.

      What other advice do I have?

      Keep my identity anonymous; publishing my title is sufficient. It's important to master the SPL for efficient use. Seek solutions that better support GPU for real-time processing.

      I'd rate the solution eight out of ten.

      If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

      Other
      Disclosure: My company does not have a business relationship with this vendor other than being a customer.
      PeerSpot user
      Sudheer Kumar - PeerSpot reviewer
      Lead Security Engineer at AeoLogic Technologies
      Real User
      Top 5
      Aug 26, 2024
      Helps with monitoring and incident management
      Pros and Cons
      • "From a stability perspective, the tool is good."
      • "he product's initial setup phase needs to be made easy since it looks like it is very complex compared to the other tools in the market."

      What is our primary use case?

      I use the solution in my company to capture the events to deal with threat detection, incident response, and compliance reporting. For IT operation management, it gets complex to track the health and performance of IT infrastructure, including our network devices and applications, so Splunk Enterprise Platform can be used for centralized log management.

      What is most valuable?

      The most valuable feature of the tool for DevOps and from a continuous delivery perspective is that the tool is useful in areas like deployment, monitoring, and incident management.

      What needs improvement?

      If I compare Splunk Enterprise Platform with the other tools, the dashboard and the user interface need to be built at a console level and in a user-friendly mode. Sometimes, the tool looks a bit complex, and we can't find out the exact area where we need to make the changes in the configuration and changes for the log events monitoring. The dashboard and the console-level areas need to be made friendly.

      The product's initial setup phase needs to be made easy since it looks like it is very complex compared to the other tools in the market.

      For how long have I used the solution?

      I have been using Splunk Enterprise Platform for three years.

      What do I think about the stability of the solution?

      From a stability perspective, the tool is good. If any breakdowns exist, remediation and support are provided, so it is not a problem.

      What do I think about the scalability of the solution?

      The tool is used by around 5,000 employees and servers in my company.

      How are customer service and support?

      I have interacted with the solution's technical support. I rate the technical support a seven and a half out of ten.

      How would you rate customer service and support?

      Neutral

      How was the initial setup?

      The solution is deployed in an on-premises version.

      What's my experience with pricing, setup cost, and licensing?

      The tool is expensive.

      What other advice do I have?

      To first-time users, I can say that proper analysis and bandwidth utilization, cloud resource monitoring, and cost optimization are the things I would ask one to check in the tool.

      It is not easy for beginners to use, and for freshers, it will take time to understand the tool.

      From a security perspective, I rate the tool a nine out of ten. From a user and the console perspective, I rate the tool a seven out of ten.

      In general, I rate the tool an eight out of ten.

      Which deployment model are you using for this solution?

      On-premises
      Disclosure: My company does not have a business relationship with this vendor other than being a customer.
      PeerSpot user
      Praveen Sande - PeerSpot reviewer
      Senior Splunk Engineer at Wipro Limited
      Real User
      Top 20
      May 11, 2024
      Offers extensive visibility into events with flexible scalability

      How has it helped my organization?

      Splunk Enterprise Platform is a powerful application that offers extensive visibility into events, notable occurrences, and correlations, providing robust capabilities.

      What is most valuable?

      The valuable feature is the onboarding of various logs using different methods. Additionally, it excels in content development and use case creation. I want to learn about upcoming technologies like Splunk Cloud and Azure integration. These platforms offer extensive capabilities for visualizing and manipulating data according to our requirements. Splunk's proficiency in field extractions and onboarding logs from diverse sources makes it highly capable. Its logging addition and parsing capabilities are particularly noteworthy.

      What needs improvement?

      In Splunk Enterprise Platform, while the dashboard feature is powerful, it does have limitations in terms of the number of parameters that can be included in one dashboard. However, it's important to note that these limitations can be addressed through effective dashboard design and optimization techniques. Despite these constraints, Splunk offers extensive capabilities for creating insightful dashboards that can visualize relevant data effectively.

      Splunk excels in providing accurate and valuable alerts and reports. These features are crucial in reducing manual efforts, minimizing human errors, and expediting incident resolution processes. With Splunk's alerting and reporting functionalities, users can fine-tune alerts, apply filters, and include necessary information for thorough investigation and analysis. These capabilities contribute significantly to enhancing operational efficiency and decision-making within organizations.

      For how long have I used the solution?

      I have been using Splunk Enterprise Platform for five years.

      What do I think about the stability of the solution?

      I rate the solution’s stability an eight out of ten.

      What do I think about the scalability of the solution?

      Scalability is very flexible. Without the Splunk support, we can deploy and scale up.

      How are customer service and support?

      The responsiveness of the support is very good. They will ask you if you are raising any P2, P1, or major incidents so they'll help us with immediate and accurate results.

      How was the initial setup?

      The initial setup is straightforward , with detailed deployment steps outlined in their documentation. Additionally, the Splunk community is a valuable resource where users can ask questions and receive expert solutions. 

      What other advice do I have?

      Splunk Enterprise Platform does not have a few application add-ons. Therefore, when we aim to integrate log sources from new or important ones that Splunk lacks add-ons for, we resort to developing custom add-ons. While this approach allows us to proceed with our work, it requires significant human effort and increases the likelihood of errors. Moreover, troubleshooting becomes time-consuming under these circumstances. Ideally, Splunk would offer add-ons for every possible application, significantly improving our efficiency and effectiveness.

      The Splunk Enterprise Platform offers excellent visibility through real-time monitoring. Whenever any data matches our client's SQL code, it triggers an immediate alert, allowing us to respond to incidents swiftly. This capability is highly beneficial during any incident, making Splunk an invaluable tool.

      There are various components, such as Universal Forwarder, Indexer, and Search Head. These components are relatively straightforward to set up. However, when implementing a distributed environment or setting up clustering, Splunk offers robust capabilities. Additionally, managing data storage sizing is also seamless.

      Overall, I rate the solution an eight out of ten.

      Which deployment model are you using for this solution?

      On-premises
      Disclosure: My company does not have a business relationship with this vendor other than being a customer.
      PeerSpot user
      Buyer's Guide
      Download our free Splunk Enterprise Platform Report and get advice and tips from experienced pros sharing their opinions.
      Updated: March 2026
      Buyer's Guide
      Download our free Splunk Enterprise Platform Report and get advice and tips from experienced pros sharing their opinions.