What is our primary use case?
I am not currently using
Splunk Enterprise Platform, but in my previous company, PwC, I used Splunk for almost six months, and before that company, I had a total exposure of almost three years to
Splunk Enterprise Platform. My main use case for Splunk Enterprise Platform was detection and investigation.
Ingesting massive amounts of machine-generated data and running real-time searches to identify patterns, anomalies, or threats related to specific security issues was how I used Splunk Enterprise Platform for detection and investigation. The most significant aspect, if I must prioritize, is the data ingestion capability. Splunk Enterprise Platform usually collects authentication logs from various sources such as Windows event logs and SSH, which relates to Linux logs, and some web application-based logs as well. Apart from that, I use it for detection logic. The main search I use is Search Processing Language, based upon the queries I provide related to the machines I monitor.
Mostly for brute-force detection, I use it for monitoring multiple failed login attempts from a single source or multiple IP sources followed by a successful login, which often indicates a compromised account. I also use it for lateral movement and privilege escalations. For privilege escalations, it involves detecting when a normal user is added to a high-privilege group, such as Domain Admins. Additionally, I have capabilities related to IT operations, which involve web traffic analysis, mostly identifying slow-loading web pages or sudden spikes, errors such as 404 or 403 Forbidden, or even 500 errors.
What is most valuable?
The best features in Splunk Enterprise Platform are the Search Processing Language, which includes pipe syntax, and real-time alerting and dashboards. The dashboard is an interactive tool, and I use it for visualizations such as heat maps, graphs, and glass tables. The dashboards I use depend upon the widgets that are most helpful to track and monitor. I can also set some thresholds to trigger real-time values based upon the log information available in Splunk Enterprise Platform, which can be useful for the remediation of scripts.
When a specific condition is met, such as any brute-force attack happening, it is easy to investigate the alert, particularly in Splunk Enterprise Platform. Integration is a notable aspect of the features in Splunk Enterprise Platform.
Before using Splunk Enterprise Platform, I used LogRhythm, but after initiating Splunk Enterprise Platform, I noticed several positive impacts in my organization.
What needs improvement?
For Splunk Enterprise Platform improvement, I think it would be beneficial to focus on particular areas such as system performance, cost management, and detection accuracy. Based upon system performance, I generally look into errors, status errors, or forbidden errors. I could also build some pre-indexed summaries so that Splunk Enterprise Platform can search much faster than raw logs.
For how long have I used the solution?
In my current field, I have worked for around six years, and at my current company, I have been working for the last three years.
Buyer's Guide
Splunk Enterprise Platform
April 2026
Learn what your peers think about Splunk Enterprise Platform. Get advice and tips from experienced pros sharing their opinions. Updated: April 2026.
894,738 professionals have used our research since 2012.
What do I think about the stability of the solution?
There is no proper downtime for Splunk Enterprise Platform; whatever downtime occurs, the IT team handles it. There is no significant downtime to report.
What do I think about the scalability of the solution?
It is easy to differentiate the type of logs based on Splunk Enterprise Platform. If it is a phishing email, I can easily identify what kind of phishing alert it is. If it is a brute-force attack or something such as password spraying, it is easy to identify in Splunk Enterprise Platform.
How are customer service and support?
I usually reach out to customer support for Splunk Enterprise Platform whenever I need specific data. I contact the technical support team immediately, and on a priority basis, I receive a resolution. If not, I raise a ticket so that I can get a proper solution for the issues I am facing.
How was the initial setup?
My experience with pricing, setup cost, and licensing has been notable.
What was our ROI?
I have seen a return on investment from using Splunk Enterprise Platform, illustrated by tracking how the daily data volume has been indexed, the estimated cost, the monthly actual report, and the annual report. Biquarterly and mid-year reports can be easily tracked in Splunk Enterprise Platform.
Which other solutions did I evaluate?
I do have other options such as DataDog for one, and
Microsoft Sentinel,
Azure Sentinel. In my current company, I am using DataDog currently as a
SIEM tool.
What other advice do I have?
Splunk Enterprise Platform is deployed on-premises in my organization. I rate this product an overall 8 out of 10.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.