No more typing reviews! Try our Samantha, our new voice AI agent.
R Nandasana - PeerSpot reviewer
Senior Information Technology Security Consultant at Mideast Data Systems
Real User
Top 5Leaderboard
May 7, 2026
Centralized monitoring has unified security insights and supports flexible architecture design
Pros and Cons
  • "What I appreciate most about Splunk Enterprise Platform is that one of the best features is its ability to support customization."
  • "What I dislike about Splunk Enterprise Platform is the props and transforms functionality. For most types of data, we have custom add-ons and everything is available, but for some data we want to parse, the add-on is not available."

What is our primary use case?

In my enterprise work as a consultant, I designed most of the architecture based on customer use cases and requirements. For the use case part, we can convert data into CSV to JSON with the ingest processor, which is a good point for data reduction. We create security alerts, notifications, and many data models to monitor data for compliance purposes.

Regarding Federated Search, it is an excellent feature. We have a separate environment where we can search data from different complete stacks or different complete Splunk infra. We have one platform with a complete environment for SIEM and another environment for observability. We enabled Federated Search between both of these environments. Any observability team can get data from the SIEM, and the SIEM team can get data from observability.

What is most valuable?

What I appreciate most about Splunk Enterprise Platform is that one of the best features is its ability to support customization. You can customize anything in Splunk Enterprise Platform. We have scripted input, normal file monitor, port monitoring, and many add-ons. Splunkbase is one of the biggest app and add-on stocks available. It supports everything you need. Wherever your data is, we can retrieve it. This is one of the best things about Splunk Enterprise Platform.

What needs improvement?

What I dislike about Splunk Enterprise Platform is the props and transforms functionality. For most types of data, we have custom add-ons and everything is available, but for some data we want to parse, the add-on is not available. Then we need to write manual props and transforms. Sometimes there are many issues with the Regex. When you write Regex, it may not work properly. In the Regex101 platform, you find Regex working, but when you apply it to Splunk Enterprise Platform, it is not working. Therefore, props and transforms, such as parsing of the data, are not that reliable.

Regarding maintenance, I don't think there is a strict maintenance requirement, but we need to continuously monitor the platform. For example, when Splunk version upgrades come in, we need to upgrade. Continuous monitoring is required. Sometimes knowledge bundle size increases, sometimes an alert is not running, and sometimes we have search head cluster replication factor down. Many kinds of issues are present with Splunk Enterprise Platform because you have your own infrastructure. This could be a plus or minus at any time, which is where we need to focus on maintenance.

Regarding the feature called Trusted Control Plane, I am not familiar with it. Is it in Splunk 10x or what?

For how long have I used the solution?

I have been using Splunk Enterprise Platform for eight years.

Buyer's Guide
Splunk Enterprise Platform
July 2026
Learn what your peers think about Splunk Enterprise Platform. Get advice and tips from experienced pros sharing their opinions. Updated: July 2026.
909,647 professionals have used our research since 2012.

What do I think about the stability of the solution?

The stability of Splunk Enterprise Platform is very good. There are no stability concerns.

What do I think about the scalability of the solution?

Scalability is also good. There is not much configuration required. If you want to expand anything, you can increase more indexes or add storage. There is a separate storage tier that you can expand however you want. It supports both vertical and horizontal scaling. You can grow the environment without difficulty.

How are customer service and support?

I was working directly with Splunk when I worked at Splunk.com as a Site Reliability Engineer with the data system. There we directly supported all Splunk customers by upgrading their environments, installing apps, and performing Splunk version upgrades. We handled many tasks such as changing configurations. For everything that a customer raised a support case for, we were the ones who provided support.

I have contacted Splunk support myself. I worked with two clients, including Emirates Airline, which I am currently working on. I raised support cases many times, including ODS cases. Regeneron Pharmaceuticals was another customer, and I raised many technical support cases for them.

I would rate Splunk support a nine because they are very good and very technical. They provide solutions on time, which is something I appreciate.

How was the initial setup?

The initial deployment of Splunk Enterprise Platform is simple and very easy. You need some training before you do it. For a single instance, it is very easy. You just need to unzip the package and install it. However, if you want to set up clustering, search head clustering, indexer clustering, and other configurations, you either need to read the documentation or complete the architect labs. For me, it was very easy because I was an architect and consultant at that time.

What's my experience with pricing, setup cost, and licensing?

Regarding pricing, it is costly. I don't know the exact numbers, but it is very expensive. However, it is worth it when you are using it properly. When you have a proper SIEM, proper data, and everything is in compliance, and you use Splunk Enterprise Platform to its full potential, then this investment is worth it.

Which other solutions did I evaluate?

I have used alternatives, and most of the customers are using Cribl for parsing because it has the best UI and visual elements. In Splunk Enterprise Platform, we need to write the files, but Cribl offers a visual approach, which is better.

What other advice do I have?

I was working with Emirates Airline, where we take a license from Splunk and use Splunk Enterprise Platform. We have our own on-premises infrastructure. I am a customer of Splunk Enterprise Platform. I would give this product an overall rating of nine.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Last updated: May 7, 2026
Flag as inappropriate
PeerSpot user
Consultant at a tech vendor with 10,001+ employees
Real User
Top 20
Jul 15, 2026
Centralized monitoring has reduced incident resolution time and improves operational visibility
Pros and Cons
  • "Overall, Splunk Enterprise Platform helps me monitor system health, reduce incident resolution time, and improve operational efficiency."
  • "The licensing model is based on data ingestion volume and can become expensive as organizations grow."

What is our primary use case?

My main use case for Splunk Enterprise Platform is to monitor and troubleshoot, perform incident analysis, and search and analyze applications and system logs to identify the root cause of issues. I create dashboards to monitor key metrics, configure alerts for critical events, and generate reports for the operation systems.

A specific example of how I used Splunk Enterprise Platform to solve a problem occurred when users reported intermittent application failures in production. I used Splunk Enterprise Platform to search and correlate application and server logs using SPL. By filtering the logs based on timestamps and error codes, I identified repeated timeout exceptions that were caused by backend services. I created a dashboard to monitor these errors and configured an alert to notify the support team whenever the error count exceeded a threshold. This helped the team detect similar issues proactively and reduce troubleshooting time significantly.

In addition to troubleshooting and log analysis, I use Splunk Enterprise Platform for real-time monitoring of application and infrastructure, creating dashboards for operational visibility, configuring alerts for critical events, and generating reports for stakeholders. I use SPL to analyze trends, identify recurring issues, and support root cause analysis. Overall, Splunk Enterprise Platform helps me monitor system health, reduce incident resolution time, and improve operational efficiency.

What is most valuable?

Splunk Enterprise Platform offers numerous powerful features including powerful log search using SPL, real-time monitoring and alerting, interactive dashboards and visualizations, data indexing and fast search, centralized log management, role-based access control, scalability, and integrations with various data sources. These features help our organization monitor and troubleshoot our systems.

Out of those features, I find the combination of real-time monitoring and SPL search capabilities the most valuable in my day-to-day work. Real-time monitoring helps me identify issues as soon as they occur, while SPL allows me to quickly filter and analyze large volumes of logs to pinpoint the root cause. This significantly reduces the troubleshooting time. I also rely heavily on dashboards because they provide a clear view of application health, error trends, and system performance in one place. Centralized log management is another key advantage as it brings logs from multiple sources and servers together, eliminating the need to check each system individually. Overall, these features help me resolve incidents faster, improve system reliability, and reduce downtime.

An additional feature I truly appreciate is the flexibility of Splunk Enterprise Platform. It can ingest data from a wide variety of sources, such as application servers, operating systems, and network devices, and correlate all the information in a single platform.

What needs improvement?

In order to improve Splunk Enterprise Platform, there are a few areas that need improvement. The licensing model is based on data ingestion volume and can become expensive as organizations grow. The initial setup and configuration can also be complex for new users.

I would rate Splunk Enterprise Platform an eight because it is a powerful and reliable platform for centralized log management and real-time monitoring. It significantly improves our troubleshooting times. I did not give it a ten because the licensing costs can be high, the initial setup and administration can be complex, and there is a learning curve for SPL and advanced configurations.

For how long have I used the solution?

I have been using Splunk Enterprise Platform for about two years.

What do I think about the stability of the solution?

Splunk Enterprise Platform is stable.

What do I think about the scalability of the solution?

Splunk Enterprise Platform is highly scalable. It can handle increasing volumes of machine data by scaling horizontally, such as adding more indexes, search heads, and forwarders as an environment grows. This allows organizations to support more users, onboard additional data sources, and process large amounts of data.

I do not have direct experience managing Splunk Enterprise Platform at petabyte scale. However, based on my understanding, Splunk Enterprise Platform is designed to scale horizontally by adding indexes and search heads, which allows it to handle very large data volumes. For data sovereignty, it supports role-based access controls, encryption, and various deployment options.

How are customer service and support?

My experience with customer support was great.

Which solution did I use previously and why did I switch?

I have not previously used a different solution before Splunk Enterprise Platform; we directly adopted Splunk Enterprise Platform.

How was the initial setup?

The initial setup and administration can be complex, and there is a learning curve for SPL and advanced configurations.

What about the implementation team?

The setup was performed by our in-house team who are highly skilled in working with Splunk Enterprise Platform.

What was our ROI?

I definitely see the return on investment. Splunk Enterprise Platform improved our reliability, and the time to investment ratio has been excellent because the time we are spending solving incidents through Splunk Enterprise Platform has been great.

What's my experience with pricing, setup cost, and licensing?

My experience with pricing, setup cost, and licensing indicates that the initial setup cost, and when the organization grows, the setup cost might increase significantly. The main costs considering Splunk Enterprise Platform are licensing, infrastructure, and setup. Since licensing is based on data ingestion volume, costs can increase as the organization generates more log data.

Which other solutions did I evaluate?

We did not evaluate other options before choosing Splunk Enterprise Platform; we directly chose Splunk Enterprise Platform as our first option.

What other advice do I have?

My advice to others looking into using Splunk Enterprise Platform is that if there is an organization which is about to scale to large numbers, I would highly suggest Splunk Enterprise Platform. However, I would ask them to carefully check and ingest valuable data only for cost efficiency. I would rate this recommendation an eight out of ten.

Which deployment model are you using for this solution?

On-premises

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Other
Disclosure: My company has a business relationship with this vendor other than being a customer. Consultant
Last updated: Jul 15, 2026
Flag as inappropriate
PeerSpot user
Buyer's Guide
Splunk Enterprise Platform
July 2026
Learn what your peers think about Splunk Enterprise Platform. Get advice and tips from experienced pros sharing their opinions. Updated: July 2026.
909,647 professionals have used our research since 2012.
reviewer2879052 - PeerSpot reviewer
Operations Digital, Technology & Innovation Japac Head Of Strategic Planning at a pharma/biotech company with 10,001+ employees
Real User
Top 10
Jul 23, 2026
Centralized monitoring has unified our alerts and improves daily threat detection workflows
Pros and Cons
  • "Splunk Enterprise Platform has had a significant positive impact on our organization."
  • "Pricing for Splunk Enterprise Platform is actually very high, but at the same time, the value that it gives is highly beneficial."

What is our primary use case?

Splunk Enterprise Platform serves as our SIEM tool where we receive alerts and we primarily depend on it. As a centralized logging and monitoring system, we use Splunk based upon different data types. We receive data from our EDR solutions, our email, and cloud sources, so Splunk acts as a centralized point where we receive alerts from multiple sources. Day-to-day operations include Windows event loggings, such as when we get brute force alerts and similar kinds of alerts. Another example is with respect to Office 365, which is our messaging logs where if there is a need and any email forwarding rules are detected, we set a set of alerts. We also receive alerts from the cloud, GuardDuty logs, and CloudTrail logs.

What is most valuable?

Splunk Enterprise Platform is a platform I truly love, whether it's the use cases, how we fine-tune them, how we parse them, or how we create dashboards exclusively in Splunk Enterprise Platform, and even the admin part. The dashboarding functionality provides a single-pane-of-glass view for us where whenever an alert comes or any part of threat hunting that we do, it stands exclusively, and we are able to monitor them at one place. Other features such as RBAC and risk-based alerting mechanisms provide a one-page view for us. With respect to the UI, we get all the details in; it is very user-friendly; we do not need to search here and there; we get it immediately.

Splunk Enterprise Platform has had a significant positive impact on our organization. We had a previous SIEM tool and migrated to Splunk Enterprise Platform. The storage logs and the storage bucketing system in Splunk Enterprise Platform is extensively large, and the amount of data that is getting parsed is substantial. Splunk Enterprise Platform is the one platform where we use it on a day-to-day basis, not only with respect to the cyber team but all the other data reporting team and data team use it as well.

What needs improvement?

With respect to the use cases, we were able to create many use cases as well as fine-tune them, so thirty percent of the alerts were fine-tuned, and we have improved our detection logic and also the outcomes. In specific to the metrics, our detection rate was high. The mean time to detect was incredibly lower than when compared to the previous SIEM.

With respect to Splunk Enterprise Platform, we can have a bunch of use cases though we already have a database where we get a list of use cases. Given the trend, we can improve them. Just with threat intelligence, if Splunk Enterprise Platform gets a new feature such as IOCs integration directly, that would be very helpful, just as the Falcon threat intelligence. It would be helpful if we get Splunk threat intelligence as well.

For how long have I used the solution?

In my current field, I have been working for about six years.

What do I think about the stability of the solution?

Splunk Enterprise Platform is stable with no doubt about that.

What do I think about the scalability of the solution?

I rate the scalability of Splunk Enterprise Platform an eight on ten.

How are customer service and support?

I rate the customer support of Splunk Enterprise Platform a nine on ten.

Which solution did I use previously and why did I switch?

We had a previous SIEM tool and migrated to Splunk Enterprise Platform. The storage logs and the storage bucketing system in Splunk Enterprise Platform is extensively large, and the amount of data that is getting parsed is substantial. Splunk Enterprise Platform is the one platform where we use it on a day-to-day basis, not only with respect to the cyber team but all the other data reporting team and data team use it as well.

What's my experience with pricing, setup cost, and licensing?

Pricing for Splunk Enterprise Platform is actually very high, but at the same time, the value that it gives is highly beneficial.

What other advice do I have?

With respect to the use cases, we were able to create many use cases as well as fine-tune them, so thirty percent of the alerts were fine-tuned, and we have improved our detection logic and also the outcomes. In specific to the metrics, our detection rate was high. The mean time to detect was incredibly lower than when compared to the previous SIEM.

With respect to Splunk Enterprise Platform, we can have a bunch of use cases though we already have a database where we get a list of use cases. Given the trend, we can improve them. Just with threat intelligence, if Splunk Enterprise Platform gets a new feature such as IOCs integration directly, that would be very helpful, just as the Falcon threat intelligence. It would be helpful if we get Splunk threat intelligence as well.

As of integrations, we are good. Splunk Enterprise Platform can be integrated with multiple SOAR solutions, so I would prefer to focus on the threat intelligence side.

Accuracy regarding Splunk Enterprise Platform's AI capabilities should be termed as a normal figure between sixty to seventy-five percent because sometimes it is not just AI capabilities; human intelligence is needed as well. So I would keep it around that range.

With respect to cybersecurity, you have the best solution available. I rate this review a nine overall.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Last updated: Jul 23, 2026
Flag as inappropriate
PeerSpot user
Chirag Singhtalwar - PeerSpot reviewer
Technical site manager at Tagbin
Real User
Top 20
Jul 10, 2026
Centralized logging has transformed security monitoring and incident response efficiency
Pros and Cons
  • "Splunk Enterprise Platform has improved visibility across the environment by centralizing logs from multiple systems, reduced the time needed to detect, investigate, and respond to security incidents, streamlined troubleshooting, and helped my team respond to issues more quickly, improving operational efficiency and reducing downtime."
  • "One area for improvement for Splunk Enterprise Platform is the learning curve."

What is our primary use case?

My main use case for Splunk Enterprise Platform is security monitoring and incident detection. I use Splunk Enterprise Platform to collect and analyze logs from servers, endpoints, firewalls, and network devices. I monitor security events, investigate alerts, troubleshoot issues, and support incident response through dashboards and log search.

One example of how I have used Splunk Enterprise Platform for security monitoring and incident detection was when Splunk Enterprise Platform generated multiple failed login alerts for a privileged account from different IP addresses in a short period. I used SPL to review the authentication logs, correlating them with firewall and Windows Event Logs. I confirmed it was a password spraying attempt rather than normal user activity. I escalated the incident, the account was secured, and the source IPs were blocked.

In addition to security monitoring, I use Splunk Enterprise Platform for operational monitoring and troubleshooting. It helps me quickly search logs from Windows and Linux servers, network devices, and security tools to identify the root cause of issues. I have also used dashboards to monitor system health and create alerts for critical events, which improves response time and reduces manual log analysis.

What is most valuable?

The best features Splunk Enterprise Platform offers are its log analysis and its powerful log search capabilities using SPL. Centralized log collection, real-time monitoring, alerting, customizable dashboards, fast troubleshooting, and the ability to correlate events from multiple data sources are all valuable. It also scales well for large environments and integrates with many security and IT tools, making incident investigation much more efficient.

Splunk Enterprise Platform has improved visibility across the environment by centralizing logs from multiple systems. It has reduced the time needed to detect, investigate, and respond to security incidents, streamlined troubleshooting, and helped my team respond to issues more quickly. Overall, it has improved operational efficiency and reduced downtime.

What needs improvement?

One area for improvement for Splunk Enterprise Platform is the learning curve. Splunk Enterprise Platform and SPL can take time for new users to master. Licensing and data ingestion costs can also become expensive as log volumes grow. Additionally, simplifying the initial deployment and providing more out-of-the-box dashboards and use cases would help organizations get value more quickly.

For how long have I used the solution?

I have been working for three or more years in my current field.

What other advice do I have?

The feature I rely on the most day-to-day is SPL, Search Processing Language. It allows me to quickly search and filter large volumes of logs, investigate alerts, and troubleshoot issues instead of manually checking logs on multiple systems. I can correlate events from different sources in one place, identify root causes faster, and respond to incidents more efficiently.

One thing I particularly appreciate about the features is the flexibility of Splunk Enterprise Platform dashboards and alerts. They can be customized for different teams and prioritized, making it easier to monitor critical events without constantly searching through logs. That saves time and helps focus on the most important issues.

Although we have not measured exact KPIs, Splunk Enterprise Platform helped reduce the time required to investigate incidents. Instead of manually checking logs across multiple systems, we could quickly search centralized logs and identify the root cause much faster. For many incidents, the initial investigation time was reduced from around 30 to 45 minutes to approximately 10 to 15 minutes, which improved our overall response time.

Regarding Splunk Enterprise Platform's AI capabilities, from my experience, it provides strong governance and security through role-based access control, audit logging, encryption, and integration with enterprise identity providers. These features help ensure that access to data and AI-assisted capabilities is controlled and traceable. As AI capabilities continue to evolve, I would appreciate seeing even more transparency around AI-generated results and more granular governance controls.

From my experience, Splunk Enterprise Platform's AI-assisted capabilities are generally accurate and can help in prioritizing alerts, summarizing information, and speeding up the investigation. However, I do not treat the output as definitive. I always validate AI-generated insights against the underlying logs and other evidence before making a decision. Overall, I would describe the accuracy and reliability as good, but human verification is still important.

My advice for those looking into using Splunk Enterprise Platform is to clearly define your logging and security monitoring objectives before deployment. Start with your most critical data sources. Invest time in learning SPL and build dashboards and alerts that align with your operational needs. Additionally, plan your data ingestion carefully to manage licensing costs and get the best value from the platform. I rate this product a nine out of ten.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Last updated: Jul 10, 2026
Flag as inappropriate
PeerSpot user
Sydney D'Souza - PeerSpot reviewer
Security Consultant at SoftwareONE
MSP
Top 5Leaderboard
Mar 4, 2026
Correlation rules have strengthened threat detection while interface and pricing still need improvement
Pros and Cons
  • "The personalized dashboards in Splunk Enterprise Platform are a good feature."
  • "I think the machine learning toolkit is fine, but when I talk about threat intelligence, it is not that effective."

What is our primary use case?

The most valuable feature I have found so far is the correlation rule. That seems to be very valuable for us. I can create any alert using the correlation rule, which seems to be interesting for me.

I use Splunk Enterprise Platform for advanced threat detection with the correlation rules, nothing else. We have only very few customers, just two customers. They are not interested in those higher versions of Splunk Enterprise Platform. We rely completely on the correlation rule. We highly rely on this correlation rule.

What is most valuable?

The personalized dashboards in Splunk Enterprise Platform are a good feature. We have created multiple dashboards. It is easy and understandable, and whatever we need, we can get it. It is not only with Splunk Enterprise Platform but with all the other products. I would say we can go ahead and create a customized dashboard. Since I am working for SOC, I do have an internal dashboard that I have for myself where I have all the service metrics dashboard available. I make use of that rather than going directly into Splunk Enterprise Platform creating there.

What needs improvement?

I think the machine learning toolkit is fine, but when I talk about threat intelligence, it is not that effective. Since recently, I think Splunk Enterprise Platform has acquired Cisco, which has acquired VirusTotal if I am not wrong. I think VirusTotal. Initially, what used to happen was that the threat intelligence source I used for Splunk Enterprise Platform was not regularly updated. I faced challenges there, and then finally, when I went ahead and researched, I found that VirusTotal is readily available to be used in Splunk Enterprise Platform. So I integrated it, and as of now, I am making better use of it.

The effectiveness of Splunk Enterprise Platform in detecting anomalies and preventing system outages completely depends upon the correlation rule, but when it comes to threat intelligence, I have not explored much of the source side. I am mostly on the SIEM side. Though I have some features that I have integrated, I am mainly working on the SIEM side rather than the source side.

The application management feature, which I believe refers to the interface, is not that attractive, I would say. It is a simplified version, and I am using the cloud platform of Splunk Enterprise Platform instance. It is simple, but it is okay. It is manageable.

I definitely find it problematic, and I think they could need to have more nuances and more features when it comes to the interface. It should be more extended.

From my perspective, Splunk Enterprise Platform can be improved by first making the GUI, the interface, more attractive. The second improvement should try to include all the threat intelligence into that platform, integrating all threat intelligence. The behavior monitoring is a bit of a concern because I do not see much detection. Maybe that is because I am using only the correlation ID, but still, the behavior monitoring should automatically detect. Even if it is a SIEM solution, if I create some rule, that is what I have customized it for. I am not sure if SOAR has that capability, but in case SOAR does have that capability, if not, then they have to improve their machine learning and behavior analytics. I have been in touch with different technicians from different organizations, and they have mentioned these challenges. There are a few drawbacks when it comes to Splunk Enterprise Platform.

I find the price a bit high, I would say. A bit high.

For how long have I used the solution?

I have been working with this product for one and a half years.

How are customer service and support?

I have no problem with the technical support provided by Splunk Enterprise Platform at all. I do get support whenever needed. I would rank them at an eight, with ten being the highest.

How would you rate customer service and support?

Positive

How was the initial setup?

As for the initial setup and configuration for Splunk Enterprise Platform, I will not say it is easy. It is a bit complicated. But since I have support, that makes my life easier. It is a bit complicated compared to Trend Micro, compared to CrowdStrike, and compared to Microsoft Sentinel or Defender for Cloud, Defender for Endpoint. Splunk Enterprise Platform is on the complicated side.

Which other solutions did I evaluate?

As of now, I am pitching in for Microsoft Sentinel. I am also pitching in for CrowdStrike, which is also a bit expensive, but the only product that I pitch in is Microsoft's product, which is Microsoft Defender for Cloud for Servers, and Defender for Endpoint, Defender for Cloud Apps, Defender for Office, all those products. Defender is one of the cheaper ones. In case a customer is not okay with Microsoft, I pitch in CrowdStrike. First, I pitch in Trend Micro, and then I pitch in CrowdStrike, with CrowdStrike being at the higher price range.

One advantage these competitors have over Splunk Enterprise Platform besides lower pricing is that with one of my customers, they can fetch logs from all sources and bring them into Splunk Enterprise Platform. They can control the logs that are not required. My continuous monitoring allows me to ensure that in case there are certain logs that are no longer required, along with the architect, I can discuss that and bring down the overall log size to around 40 GB per day. I am talking about a log source that is more than 20 as of now for this customer.

The products that have this feature are CrowdStrike and Trend Micro, which have to be configured using the API. Even Microsoft has it, but Microsoft faces a lot of challenges when it comes to pulling a log from a log source that does not have an inbuilt connector. There is a challenge there. However, when it comes to Trend Micro and CrowdStrike, it is a bit easier there using APIs.

What other advice do I have?

I would recommend Splunk Enterprise Platform for bigger companies.

In the future, I expect additional features such as threat intelligence, behavior analytics, log searching, and machine learning capabilities.

As for any other functionalities I would like to see from them in the future, I do not have anything to add right now. I have something in my mind, and in case I remember, I will go ahead and add it.

Splunk Enterprise Platform is very popular in my region. My overall review rating for this product is seven out of ten.

Which deployment model are you using for this solution?

Public Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Other
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
Last updated: Mar 4, 2026
Flag as inappropriate
PeerSpot user
Muhammad Reza Aisyi - PeerSpot reviewer
Security Consultant at ITSEC Asia
Consultant
Top 5
Jan 1, 2026
Flexible analytics have unified our security monitoring and improved threat detection workflows
Pros and Cons
  • "I consider Splunk to be one of the best solutions available compared to other options."
  • "From my perspective, Splunk tends to be too expensive for smaller customers."

What is our primary use case?

We have been working with Splunk Enterprise Platform for two years. Currently, we have been running Splunk in our SOC for two years, but we have not used the Machine Learning Toolkit yet. I believe it is a powerful tool, but we have not explored it.

What is most valuable?

I think the most valuable feature of Splunk Enterprise Platform is its capability to correlate all the logs that we ingest into our platform. Splunk offers many predefined analytic stories that we can implement for our customers, which act as playbooks for detecting suspicious activity, anomalous behavior, and other security-related events. This capability stands out as a key feature of Splunk.

We work with Splunk on-premise, especially with Splunk Enterprise and Splunk Enterprise Security. Splunk Enterprise refers to Splunk Enterprise Platform and also includes the Splunk Enterprise Security platform, known as Splunk or Splunk ES.

We implement detection rules similarly across multiple platforms, including Microsoft Sentinel, Elastic Security, and IBM QRadar, and I can say that Splunk is one of the powerful SIEM tools. It offers us the flexibility to define our correlation rules and detection rules, which is a significant strength. Compared to other platforms, Splunk is more user-friendly regarding querying, making it easier to create detection rules and correlate various log sources.

What needs improvement?

From what I have noticed across all SIEM platforms, they are beginning to incorporate AI capabilities, which is an aspect that I think Splunk could enhance. Microsoft Sentinel, for example, features a Security Copilot, but it requires an additional license for use. Other platforms such as Google SecOps and Palo Alto's Cortex XSIAM integrate agentic AI capabilities that I believe will become standard features for all SIEM solutions in the future.

For generative AI, it would be beneficial for Splunk to add features allowing users to define queries using prompts. For example, being able to ask for the top 10 malicious IPs could simplify tasks significantly. Additionally, Splunk could consider an AI response feature where triggered alerts can prompt recommendations for users on corrective actions. A noise cancellation AI might also help security analysts reduce alert clutter. There are many agentic AI improvements that can be made in Splunk Enterprise Platform.

What do I think about the scalability of the solution?

In terms of scalability, many SIEM brands, including Splunk, provide options that adapt to a growing organization. As companies expand, the ability to scale their SIEM is crucial. Splunk allows for scalability, as you can start with an all-in-one instance and, as your deployment grows, split it into distributed deployment, such as separating the search head and indexers. I believe all SIEM solutions provide reliability, and Splunk is no exception as it also offers strong scalability.

How are customer service and support?

We sometimes communicate with Splunk's technical support, but it is not often, especially regarding technical issues. When we encounter issues, we utilize the Splunk community, which I believe showcases a big advantage of Splunk due to its strong community support. Many of our technical problems are resolved by this community.

How would you rate customer service and support?

Negative

How was the initial setup?

I usually participate in the initial setup and deployment of Splunk Enterprise Platform.

What's my experience with pricing, setup cost, and licensing?

Regarding pricing, I remember that Splunk is generally more expensive than SIEMs such as Microsoft Sentinel and Securonix, while it is also pricier than Elastic Security. From my perspective, Splunk tends to be too expensive for smaller customers. This leads us not to recommend it for small companies due to the high cost and often pushes us to suggest alternatives such as Elastic Security, which has more volume-based licensing options.

Which other solutions did I evaluate?

I have experience delivering SIEM platforms to our customers, including Elastic Security, Microsoft Sentinel, Splunk, and IBM QRadar.

What other advice do I have?

We have many use cases for using Splunk Enterprise Platform. We use Splunk to detect anomalies in our customers' IT environments, such as their network environments. We want to detect suspicious activity or anomalous activity from our customer environments. From Splunk, we utilize many applications from Splunkbase to support our deployment. Many of our services relate to the Security Operation Center, so many of our use cases are linked to SOC activities.

Since the query capability in Splunk is extremely flexible, creating dashboards is also very easy. Dashboard creation depends on the SPL queries, and in the latest version of Splunk, we have two options: classic dashboards and Studio dashboards. Both options can be tailored to our needs, enabling us to create highly customized dashboards, for instance, by adding images. This flexibility makes crafting custom dashboards simple.

I find deploying Splunk to be very straightforward because you can choose to install it on either Linux or Microsoft operating systems. Before deployment, we conduct sizing for the instance, including storage, CPU, memory, and network considerations. Once sizing is clear, we proceed with the installation, which offers multiple options such as Debian packages or RPMs. Overall, the deployment process is quite easy.

Currently, many of our customers prefer cloud deployment for Splunk Enterprise Platform. We do not recommend specific cloud services, but we often see GCP, Google, and Microsoft Azure being used among our customers.

I consider Splunk to be one of the best solutions available compared to other options. If budget is not a concern, Splunk stands out due to its extensive integrations, flexibility in scalability, and the simplicity of its deployment. I would rate this review an overall 8.

Disclosure: My company has a business relationship with this vendor other than being a customer. partner
Last updated: Jan 1, 2026
Flag as inappropriate
PeerSpot user
Senior Cyber Security Analyst at a tech vendor with 10,001+ employees
Real User
Top 20
Jul 11, 2026
Security monitoring has become more effective and handles large log volumes with detailed analysis
Pros and Cons
  • "Splunk Enterprise Platform has positively impacted our organization by improving our security posture, and our team performs good analyses since there is no need to select any log source; we just input the necessary fields and obtain the details."

    What is our primary use case?

    My main use case for Splunk Enterprise Platform is using it for security monitoring.

    In security monitoring, we are using Splunk Enterprise Platform for multiple log sources which come from different devices including Active Directory, VPN, Defender, and EDR. We are receiving these logs from these devices and onboarding them on Splunk Enterprise Platform. We have written many alerts, and we are getting those alerts on Splunk Enterprise Platform and performing analysis on that.

    Regarding my main use case with Splunk Enterprise Platform, we have written numerous security alerts and monitoring rules according to the log source requirements. We have obtained different alerts from Azure security, cloud security, and EDR, and we perform analysis on many alerts, closing them on Splunk Enterprise Platform after the analysis. We have integrated Splunk Enterprise Platform with ServiceNow, utilizing automation, and we use SOAR Phantom with Splunk ES. All these generate alerts and send them to Phantom, where we have written many playbooks to take actions based on those playbooks.

    What is most valuable?

    In my experience, the best feature of Splunk Enterprise Platform is its excellent data searching capability. Whenever we want to search long data or export heavy logs, we can easily export them from Splunk Enterprise Platform. Other tools do not offer this level of functionality; they have limited capabilities.

    The searching feature in Splunk Enterprise Platform stands out because, for example, if I want to export multiple GB of logs, we can easily do so. In other tools, we do not have much functionality; they impose limitations on exporting large log sources. Splunk Enterprise Platform has a very good functionality called lookup, which allows us to add many elements into the lookup and expand it significantly, unlike other tools that have restrictions affecting formatting upon updates.

    I find the visualization feature in Splunk Enterprise Platform to be very good, as well as reporting and dashboards, which we can customize based on SPL queries to see more detail in visualization. Additionally, the log ingestion and exporting capabilities are much better than other tools.

    Splunk Enterprise Platform has positively impacted our organization by improving our security posture, and our team performs good analyses since there is no need to select any log source; we just input the necessary fields and obtain the details.

    As for specific outcomes, we also achieve a good reduction in false positives because we can create lookups and assign permissions to our analysts based on requirements. We have many custom permissions we can add.

    What needs improvement?

    One area for improvement in Splunk Enterprise Platform is the issue we face when writing Regex; it would be beneficial to have a tool that can automatically generate Regex.

    For how long have I used the solution?

    I have been using Splunk Enterprise Platform for eight years.

    What do I think about the stability of the solution?

    I find Splunk Enterprise Platform to be steady.

    What do I think about the scalability of the solution?

    The scalability of Splunk Enterprise Platform is good.

    How are customer service and support?

    Customer support is good. I rate customer support a 10.

    Which solution did I use previously and why did I switch?

    We used a different solution previously, though those decisions were made by higher management rather than by me.

    What's my experience with pricing, setup cost, and licensing?

    I find the pricing, setup cost, and licensing of Splunk Enterprise Platform to be fine based on our usage and integrations.

    Which other solutions did I evaluate?

    Before choosing Splunk Enterprise Platform, we evaluated QRadar and found that its licensing cost was higher than that of Splunk Enterprise Platform.

    What other advice do I have?

    I rate Splunk Enterprise Platform a 10 based on my experience with multiple tools.

    I choose to rate it 10 because Splunk Enterprise Platform helps ingest many logs, and we can perform extensive searches and large data exports easily.

    Regarding Splunk Enterprise Platform's AI capabilities, I find its governance and capability to be good, with many apps available that we can integrate with Splunk ES to obtain results.

    We can manage data sovereignty at a petabyte scale within our environment easily.

    My experience in maintaining granular control over data using the trusted control plane within Splunk Enterprise Platform is good.

    As my organization considers new use cases including Agentic AI, Splunk Enterprise Platform's governance and role-based access controls help us onboard Agentic AI logs on Splunk Enterprise Platform and write rules based on requirements.

    My advice for others considering Splunk Enterprise Platform is that it works very well for handling long data and very large datasets. My overall rating for Splunk Enterprise Platform is 10.

    Which deployment model are you using for this solution?

    On-premises
    Disclosure: My company does not have a business relationship with this vendor other than being a customer.
    Last updated: Jul 11, 2026
    Flag as inappropriate
    PeerSpot user
    Vishal Awasthi - PeerSpot reviewer
    Cyber Security Consultant at EY
    Real User
    Top 20
    Jul 16, 2026
    Daily security monitoring has become faster and incident response improves with accurate alerts
    Pros and Cons
    • "Splunk Enterprise Platform makes our job far more entertaining and easy to work on, helping us save on costs, money, and efforts."
    • "I think Splunk Enterprise Platform can be improved to be more specific regarding certain cybersecurity-related incidents rather than giving all cybersecurity events; it can be far better."

    What is our primary use case?

    As a cybersecurity consultant, my job is to review all the alerts we are receiving on a daily basis and do root cause analysis of the alerts. I work as SOC L2, and I am using Splunk Enterprise Platform for cybersecurity purposes.

    I start my day by logging into Splunk Enterprise Platform; first, I go to my dashboard where we get all the cybersecurity alerts. With the help of the dashboard, we get all the alerts, then we drill down those alerts and get all the information like user activity and the actions taken. Based on that, we respond to a cybersecurity incident.

    I continuously use Splunk Enterprise Platform for multiple purposes, including reports, dashboards, cybersecurity incidents, alerts, and cybersecurity events. I do multiple things on a daily basis in Splunk Enterprise Platform.

    In my current organization, we are using Splunk Enterprise Platform for multiple clients, and I think it is helping us very well because we use Splunk Enterprise Platform for mostly eighty percent of our clients, and so far so good.

    As a SOC L2, I am using Splunk Enterprise Platform's Federated Search to query data, which is quite useful for managing our client requests.

    What is most valuable?

    I can say that Splunk Enterprise Platform is quite easy to use, and it is also smooth and clean. Based on the cybersecurity incidents and alerts we receive daily, it plays a major role in helping users understand what has happened in this activity or cybersecurity incident.

    In the cybersecurity dashboard, Splunk Enterprise Platform plays a major role in getting and representing the cybersecurity alerts, which is quite easy to understand and work on. I never had any issue with Splunk Enterprise Platform getting wrong data or crashing, so I think it is quite robust.

    Because of Splunk Enterprise Platform's ease of use, cybersecurity analysts can go through all the activities and incident events, helping us respond better to a cybersecurity alert. It aids various metrics including cybersecurity SLA and provides faster remediation.

    The governance and security provided by Splunk Enterprise Platform, with artificial intelligence, is an important aspect because we are getting more than a hundred types of cybersecurity alerts. AI helps us bypass many false positives, allowing cybersecurity analysts to focus on real alerts.

    Based on my recent experience, I find the accuracy and reliability of output quite good since it helps cybersecurity analysts focus more on high or critical alerts and reduces false positive alerts based on our previous responses and recommendations.

    I think Splunk Enterprise Platform is quite efficient because it helps us manage cybersecurity incidents and alerts in a much better manner.

    Splunk Enterprise Platform makes our job far more entertaining and easy to work on, helping us save on costs, money, and efforts.

    What needs improvement?

    I think Splunk Enterprise Platform can be improved to be more specific regarding certain cybersecurity-related incidents rather than giving all cybersecurity events; it can be far better.

    I have provided all the information I have observed and experienced to improve Splunk Enterprise Platform.

    For how long have I used the solution?

    In the cybersecurity domain, I have been working for the last seven years.

    What do I think about the stability of the solution?

    Splunk Enterprise Platform is stable.

    What do I think about the scalability of the solution?

    Based on my observation, Splunk Enterprise Platform is highly scalable because we are onboarding multiple tenants.

    How are customer service and support?

    The customer support is adequate and very helpful.

    What other advice do I have?

    I advise others looking into using Splunk Enterprise Platform to be quite patient because getting to know how to work around it is going to help you. I would rate this product an eight out of ten.

    Disclosure: My company does not have a business relationship with this vendor other than being a customer.
    Last updated: Jul 16, 2026
    Flag as inappropriate
    PeerSpot user
    Security Operations Center Analyst at a consultancy with 11-50 employees
    Real User
    Top 20
    Jul 26, 2026
    Alert triage has become accurate and daily incident investigations are now more efficient
    Pros and Cons
    • "What I like the most about Splunk Enterprise Platform is that it generates alerts with true positives only."
    • "What I dislike about Splunk Enterprise Platform is that there are so many logs coming in."

    What is our primary use case?

    First of all, I have to log in to Splunk Enterprise Platform with my login credentials provided by the company. Our company is RamnaSoft. Then I monitor the alerts coming in or analyze the logs coming in. I do the initial triage to the alerts. If I get some true positives, then I investigate further, examining IOCs and IOAs. I document it and forward it to my IR team or senior team, which is SOC 2 or SOC Level 3. Also, if I get some false positive alerts while initial triaging, then I update that in documents and also inform the IR team to monitor these false positive alerts to make changes according to their rules and procedures.

    Federated Search is helpful, but it needs some basic knowledge of the log codes and query languages. I should know the queries to search on them.

    What is most valuable?

    What I like the most about Splunk Enterprise Platform is that it generates alerts with true positives only. There are fewer false positives, which is good for me. The alerts are good.

    I use the Federated Search feature of Splunk Enterprise Platform for particular queries. I enter some queries there, and it responds accordingly.

    What needs improvement?

    What I dislike about Splunk Enterprise Platform is that there are so many logs coming in. Sometimes, unwanted logs are present, such as file creations. I do not prefer those logs.

    To clarify, if some legitimate users create unnecessary files, it generates a log. Those logs are created, so I find that frustrating. Those logs are not useful to us.

    For how long have I used the solution?

    I have been using Splunk Enterprise Platform since last year, January 25th.

    What do I think about the stability of the solution?

    Regarding stability, I do not face any lagging, crashing, or downtime with Splunk Enterprise Platform. That is a very good thing.

    What do I think about the scalability of the solution?

    Splunk Enterprise Platform is scalable. I think it should also scale in the pen testing side and the vulnerability assessment side because right now, I am only focused on monitoring logs and alerts. It can scale in fields such as pen tests and vulnerability assessments by doing reports and documentation.

    How are customer service and support?

    I have not yet contacted the technical support or customer support of Splunk Enterprise Platform, but I only get in touch with my seniors, such as SOC 2s.

    Which solution did I use previously and why did I switch?

    I have used something similar to Splunk Enterprise Platform, but I cannot remember its name. It is something similar to ELK.

    How was the initial setup?

    The initial deployment of Splunk Enterprise Platform is somewhat time-consuming, but it is very easy. If I do it once, then it is not that hard, but it is a time-consuming process.

    For the first time, I took around one hour to deploy Splunk Enterprise Platform. One hour was enough for me at that time.

    What about the implementation team?

    I have a team with my seniors who helped me deploy Splunk Enterprise Platform.

    What's my experience with pricing, setup cost, and licensing?

    I do not have any idea about the prices of Splunk Enterprise Platform. I think it is free.

    Which other solutions did I evaluate?

    I have used something similar to Splunk Enterprise Platform, but I cannot remember its name. It is something similar to ELK.

    What other advice do I have?

    To maintain granular control over data using the trusted control plane, I deploy Splunk Enterprise Platform on multiple machines and connect through it.

    I am just a user of Splunk Enterprise Platform; my company provided it for me. I would rate my overall experience with this product a 9.

    Disclosure: My company does not have a business relationship with this vendor other than being a customer.
    Last updated: Jul 26, 2026
    Flag as inappropriate
    PeerSpot user
    Yashwant Shinde - PeerSpot reviewer
    Assistant System Engineer at Tata Consultancy
    Real User
    Top 20
    Jul 15, 2026
    Unified monitoring has improved alert investigations and reduced response time for security events
    Pros and Cons
    • "Splunk Enterprise Platform provides everything in one single platform, giving us a centralized log management system for faster threat detection and compliance purposes, which reduces the mean time to detect and respond to alerts in the environment."
    • "One area for improvement is the high licensing cost that Splunk charges."

    What is our primary use case?

    I mostly use Splunk Enterprise Platform for monitoring and investigating alerts in the Infoblox environment.

    When I receive an alert for excessive failed login attempts, I assign that alert to myself and start looking at the logs through drill-down searches where I check who the user is, what the failure reason is, and their event codes such as 4624 and 4625. I analyze those details.

    Most of the time I monitor the environment and use the search capability of Splunk Enterprise Platform for log analysis.

    What is most valuable?

    The best features for my use case are query changes and searches, through which we can detect multiple suspicious activities in the environment. There is risk-based alerting and Threat Intelligence Frameworks that Splunk Enterprise Platform provides, as well as MITRE ATT&CK mapping.

    I mostly use the Threat Intelligence Frameworks, which match known malicious IOCs including IPs, URLs, domains, and file hashes while correlating the alert.

    Risk-based alerting is also a strong feature that Splunk Enterprise Platform provides because it assigns a risk score to the particular user or system instead of triggering alerts on every suspicious event, which reduces alert fatigue.

    I have worked on ArcSight in the past, but ArcSight has different components such as the logger and the ESM. Splunk Enterprise Platform provides everything in one single platform. We do not have to log in to two different environments repeatedly. It also provides a centralized log management system where we can put all logs for faster threat detection. This reduces the mean time to detect and respond to alerts in the environment. Additionally, we use the log management capacity of Splunk Enterprise Platform for compliance purposes including HIPAA and PCI DSS.

    We mostly use Splunk Enterprise Platform scheduled correlation rules, which we run on a scheduled basis rather than in real-time, which reduces the load on the system. It also provides a good amount of time to respond to alerts. Analysts can investigate alerts faster using the single platform.

    What needs improvement?

    One area for improvement is the high licensing cost that Splunk charges.

    For how long have I used the solution?

    I have been working in this field for 2.7 years.

    What do I think about the stability of the solution?

    Splunk Enterprise Platform is very stable.

    What do I think about the scalability of the solution?

    I give it a rating of 10 because it is really scalable and provides great capability for scaling.

    How are customer service and support?

    The customer service is really good. I received the solution within 24 hours.

    Which solution did I use previously and why did I switch?

    I did not particularly switch from another solution, but I found my previous platform complicated. I was working on a project where we were using ArcSight, but it is more complicated because it has a different ESM tool and different logger. We have to access those in different environments and log in two times when accessing them. Splunk Enterprise Platform provides everything in one place.

    What's my experience with pricing, setup cost, and licensing?

    Licensing relates to indexing the data that is ingested on a daily basis. The setup cost depends on the platform being acquired and the logs being ingested.

    What other advice do I have?

    I would advise that Splunk Enterprise Platform is really user-friendly and provides many functionalities. It is also integrating AI, which is helpful. I give this review a rating of 9 out of 10.

    Which deployment model are you using for this solution?

    Private Cloud

    If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

    Disclosure: My company does not have a business relationship with this vendor other than being a customer.
    Last updated: Jul 15, 2026
    Flag as inappropriate
    PeerSpot user
    Buyer's Guide
    Download our free Splunk Enterprise Platform Report and get advice and tips from experienced pros sharing their opinions.
    Updated: July 2026
    Buyer's Guide
    Download our free Splunk Enterprise Platform Report and get advice and tips from experienced pros sharing their opinions.