No more typing reviews! Try our Samantha, our new voice AI agent.
security engineer at a tech vendor with 501-1,000 employees
Real User
Top 20
Apr 14, 2026
Security monitoring has become proactive and real-time investigation detects threats faster
Pros and Cons
  • "Before using Splunk Enterprise Platform, I used LogRhythm, but after initiating Splunk Enterprise Platform, I noticed several positive impacts in my organization."
  • "For Splunk Enterprise Platform improvement, I think it would be beneficial to focus on particular areas such as system performance, cost management, and detection accuracy."

What is our primary use case?

I am not currently using Splunk Enterprise Platform, but in my previous company, PwC, I used Splunk for almost six months, and before that company, I had a total exposure of almost three years to Splunk Enterprise Platform. My main use case for Splunk Enterprise Platform was detection and investigation.

Ingesting massive amounts of machine-generated data and running real-time searches to identify patterns, anomalies, or threats related to specific security issues was how I used Splunk Enterprise Platform for detection and investigation. The most significant aspect, if I must prioritize, is the data ingestion capability. Splunk Enterprise Platform usually collects authentication logs from various sources such as Windows event logs and SSH, which relates to Linux logs, and some web application-based logs as well. Apart from that, I use it for detection logic. The main search I use is Search Processing Language, based upon the queries I provide related to the machines I monitor.

Mostly for brute-force detection, I use it for monitoring multiple failed login attempts from a single source or multiple IP sources followed by a successful login, which often indicates a compromised account. I also use it for lateral movement and privilege escalations. For privilege escalations, it involves detecting when a normal user is added to a high-privilege group, such as Domain Admins. Additionally, I have capabilities related to IT operations, which involve web traffic analysis, mostly identifying slow-loading web pages or sudden spikes, errors such as 404 or 403 Forbidden, or even 500 errors.

What is most valuable?

The best features in Splunk Enterprise Platform are the Search Processing Language, which includes pipe syntax, and real-time alerting and dashboards. The dashboard is an interactive tool, and I use it for visualizations such as heat maps, graphs, and glass tables. The dashboards I use depend upon the widgets that are most helpful to track and monitor. I can also set some thresholds to trigger real-time values based upon the log information available in Splunk Enterprise Platform, which can be useful for the remediation of scripts.

When a specific condition is met, such as any brute-force attack happening, it is easy to investigate the alert, particularly in Splunk Enterprise Platform. Integration is a notable aspect of the features in Splunk Enterprise Platform.

Before using Splunk Enterprise Platform, I used LogRhythm, but after initiating Splunk Enterprise Platform, I noticed several positive impacts in my organization.

What needs improvement?

For Splunk Enterprise Platform improvement, I think it would be beneficial to focus on particular areas such as system performance, cost management, and detection accuracy. Based upon system performance, I generally look into errors, status errors, or forbidden errors. I could also build some pre-indexed summaries so that Splunk Enterprise Platform can search much faster than raw logs.

For how long have I used the solution?

In my current field, I have worked for around six years, and at my current company, I have been working for the last three years.
Buyer's Guide
Splunk Enterprise Platform
July 2026
Learn what your peers think about Splunk Enterprise Platform. Get advice and tips from experienced pros sharing their opinions. Updated: July 2026.
909,647 professionals have used our research since 2012.

What do I think about the stability of the solution?

There is no proper downtime for Splunk Enterprise Platform; whatever downtime occurs, the IT team handles it. There is no significant downtime to report.

What do I think about the scalability of the solution?

It is easy to differentiate the type of logs based on Splunk Enterprise Platform. If it is a phishing email, I can easily identify what kind of phishing alert it is. If it is a brute-force attack or something such as password spraying, it is easy to identify in Splunk Enterprise Platform.

How are customer service and support?

I usually reach out to customer support for Splunk Enterprise Platform whenever I need specific data. I contact the technical support team immediately, and on a priority basis, I receive a resolution. If not, I raise a ticket so that I can get a proper solution for the issues I am facing.

How was the initial setup?

My experience with pricing, setup cost, and licensing has been notable.

What was our ROI?

I have seen a return on investment from using Splunk Enterprise Platform, illustrated by tracking how the daily data volume has been indexed, the estimated cost, the monthly actual report, and the annual report. Biquarterly and mid-year reports can be easily tracked in Splunk Enterprise Platform.

Which other solutions did I evaluate?

I do have other options such as DataDog for one, and Microsoft Sentinel, Azure Sentinel. In my current company, I am using DataDog currently as a SIEM tool.

What other advice do I have?

Splunk Enterprise Platform is deployed on-premises in my organization. I rate this product an overall 8 out of 10.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Last updated: Apr 14, 2026
Flag as inappropriate
PeerSpot user
Bhavesh Kadachha - PeerSpot reviewer
Dev Ops Engineer at ProminentPixel
Real User
Top 5
May 18, 2026
Centralized monitoring has improved troubleshooting and alerting across diverse log sources
Pros and Cons
  • "We use Federated Search, which allows us to search data across multiple Splunk Enterprise Platform deployments without moving all the data in a single instance, so it helps us very much to access and analyze distributed data sources from one central search interface."
  • "One thing I dislike is definitely the licensing cost, especially when our ingestion volume increases, so it is a bit costly."

What is our primary use case?

Splunk Enterprise Platform is used mainly for monitoring and troubleshooting activities, and we work with SPL to query and filter logs. We identify patterns, and then we investigate issues around different systems.

Splunk Enterprise Platform is used mainly for creating dashboards, monitoring alerts, and understanding system behavior. We have a few use cases about the alerting mechanism. We ingest logs from multiple sources and multiple hosts like AWS, Kafka, and different systems, and we use Splunk Enterprise Platform as a SIEM tool. That is our main use case.

What is most valuable?

We use Federated Search, which allows us to search data across multiple Splunk Enterprise Platform deployments without moving all the data in a single instance, so it helps us very much to access and analyze distributed data sources from one central search interface.

Splunk Enterprise Platform is highly scalable for us as we are increasing our team horizontally as well as vertically, so it is scalable for us right now.

What needs improvement?

One thing I dislike is definitely the licensing cost, especially when our ingestion volume increases, so it is a bit costly. The second thing is that SPL query performance can slow down if searches are not optimized properly, so if searches are not optimized, then query performance is slower.

For how long have I used the solution?

I have been using Splunk Enterprise Platform for approximately 14 to 15 months.

What do I think about the stability of the solution?

During one upgrade of our server, there was one crash, but it was solved by the Splunk Enterprise Platform team itself. During upgrades, we have found it one or two times; otherwise it is quite stable for us.

What do I think about the scalability of the solution?

Splunk Enterprise Platform is super easy and does not take any maintenance so far; it is quite easy to use.

How are customer service and support?

We have contacted their technical support mainly during an upgrade when we raised a ticket about our system crashing during the upgrade. Our KV store was not coming up, so we contacted them and they briefly told us what the issue was, and after that, we solved that problem.

I would definitely give them an 8 out of 10 because they were always helpful for us whenever we needed them.

Which solution did I use previously and why did I switch?

We have been directly using Splunk Enterprise Platform.

How was the initial setup?

It was quite easy because we have a dedicated Splunk Enterprise Platform team with us, so it was easy for us. It took less than a week; approximately one week it took us.

What about the implementation team?

One person did the implementation for our entire team.

What other advice do I have?

I would give this solution an overall rating of 9 out of 10.

Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
Last updated: May 18, 2026
Flag as inappropriate
PeerSpot user
Buyer's Guide
Splunk Enterprise Platform
July 2026
Learn what your peers think about Splunk Enterprise Platform. Get advice and tips from experienced pros sharing their opinions. Updated: July 2026.
909,647 professionals have used our research since 2012.
Mohamed Fouad - PeerSpot reviewer
Cybersecurity Team Leader at EMAK For Computer Manufacturing (ECM)
Real User
Top 5Leaderboard
Mar 18, 2026
Comprehensive correlation and automation have improved incident detection and reduced phishing
Pros and Cons
  • "The best features I value about Splunk Enterprise Platform include a great correlation rule that allows me to edit and generate alerts based on any event in an easy and fast way."
  • "We have Splunk at a very high cost, but I can say that other vendors working with mid-size customers can compete against Splunk."

What is our primary use case?

Splunk Enterprise Platform serves as our SIEM solution from Splunk, which is a market leader. It is a SIEM solution for log management and correlations. We have multiple logs from most of our infrastructure tools and security products. We obtain these rules and logs through many protocols including syslog and API. We then normalize and correlate this data and create incidents based on the activity running on our infrastructure.

What is most valuable?

I appreciate the API, the protocols, and the workflows as it functions as a SIEM solution. The main function is correlation.

The best features I value about Splunk Enterprise Platform include a great correlation rule that allows me to edit and generate alerts based on any event in an easy and fast way. I can accomplish this in a short period of time, and afterward, I can see incidents based on the correlation rule in a very professional and effective way.

I value the incident management and the correlations.

Splunk Enterprise Platform helps in detecting anomalies and preventing outages. The main core function for any SIEM is to have correlation. For example, if you receive user activity on a VPN logging in from Egypt, then after a while you receive logs from the firewall showing the same user logging in with a VPN from Ukraine, it is not logical that the user would move from Egypt to Ukraine in just five minutes. Splunk Enterprise Platform will create an incident and detect this as a credential compromise because we have a successful login from another location. This is the magic of correlation. We receive many events, we correlate these events, and then we can create an incident. After that, we have Splunk SOAR to take actions in an automation process to stop this incident without any management or any actions from the team.

The end-user experience is enhanced by the security product, as we have a return on investment on lower security incidents. After we implemented it with the SOC and Splunk SOAR, we can stop phishing and spam. The end-user experience will not see many phishing domains; they will be reduced. Security incidents will be reduced. Network performance will be very good after we implement it because we can detect who is scanning our network and creating a bottleneck on the network. We can stop and detect this with Splunk, whether it is SIEM from Splunk or SIEM with SOAR.

What needs improvement?

I use the machine learning toolkit with Splunk Enterprise Platform. The machine learning is very good on Splunk, but it sometimes makes searching for events become slow, so we have stopped using it. I think this needs improvement on Splunk.

The machine learning has room for improvement.

I think threat management needs improvement when compared to other vendors.

I compare Splunk Enterprise Platform with other solutions and vendors and see a very good point on pricing. We have Splunk at a very high cost, but I can say that other vendors working with mid-size customers can compete against Splunk. However, compared to Splunk, it is very expensive compared to other vendors. I think after the acquisition from Cisco, we can get discounts for licensing, and I believe Cisco will reconsider the pricing for Splunk Enterprise Platform.

I would prefer to see improved pricing for Splunk Enterprise Platform.

My thoughts on the pricing are that it is not cheap.

I have thoughts on the advanced threat detection, and I see that it is integrating with threat intelligence, and I believe this needs improvement.

For how long have I used the solution?

I have been using this solution for about two years. We have deployed many services from Splunk here in Egypt. Most of it is a SIEM solution from Splunk. We also have SOAR from Splunk, and we are running it on the largest bank here in Egypt. Most of the portfolio from Splunk that I have worked with was over approximately two years.

What do I think about the scalability of the solution?

Regarding scalability, Splunk Enterprise Platform, like any SIEM solution, provides scalability. Whenever we receive more logs, we can easily scale. I rate this aspect as a ten.

How are customer service and support?

I rate the technical support as very good.

How would you rate customer service and support?

Positive

How was the initial setup?

The deployment was not easy, nor was it complex. It requires a professional and certified engineer to deploy the product, as many SIEM solutions do. One cannot easily deploy a SIEM solution. You have to work on correlations and personalize the dashboard. There is a lot of configuration for any SIEM solution, not only Splunk Enterprise Platform.

What other advice do I have?

I would advise others looking to implement this product to totally recommend it. I recommend this both before and after the acquisition. I totally recommend acquiring Splunk Enterprise Platform portfolio, whether it is Splunk SOAR, Splunk Cloud, or Splunk Enterprise Platform. I rate this solution a ten overall.

Which deployment model are you using for this solution?

On-premises

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Other
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Last updated: Mar 18, 2026
Flag as inappropriate
PeerSpot user
Security Architect at a tech vendor with 10,001+ employees
MSP
Top 10
Jul 1, 2026
Security monitoring has improved with faster rule creation but search and AI features still need work
Pros and Cons
  • "Splunk Enterprise Platform offers very good integration patterns and extensive support for many log sources with pre-built rule sets and pre-built integrations."
  • "One area where Splunk Enterprise Platform can be improved is that the underlying search architecture is not up to the mark compared to something Elastic."

What is our primary use case?

My main use case for Splunk Enterprise Platform is as a SIEM/SOAR.

I use Splunk Enterprise Platform as a SIEM where we send all the relevant logs including firewall logs, EDR logs, authentication logs, application logs, and database logs towards Splunk, and then we write rules based on that.

Day-to-day, it is mainly used as a SIEM solution to look at all the security events and write the rules.

What is most valuable?

Splunk Enterprise Platform offers very good integration patterns and extensive support for many log sources with pre-built rule sets and pre-built integrations. It also has a wide variety of support sources.

Those integrations and pre-built rule sets help my team in our daily work as they made the integrations much faster and easier. Using the community rules was also much faster.

Splunk Enterprise Platform has very good retention and log ingestion methods. The log querying is also pretty good.

Splunk Enterprise Platform has positively impacted my organization by providing very good insight into the different security logs.

I have seen specific outcomes or improvements with Splunk Enterprise Platform, where the time to respond is pretty good. The time to write a rule is very fast, and the time for integration to the different log sources is very good.

What needs improvement?

One area where Splunk Enterprise Platform can be improved is that the underlying search architecture is not up to the mark compared to something Elastic. This could be improved.

I wish Splunk Enterprise Platform could do more towards AI and use AI to help in SOC automation.

Regarding Splunk Enterprise Platform's AI capabilities, I think its governance and security are pretty good, but not up to the mark.

Regarding Splunk Enterprise Platform's AI capabilities, I feel that its accuracy and reliability of output are still in the nascent stages, although it is pretty good.

For how long have I used the solution?

I have been using Splunk Enterprise Platform for about to three years.

What do I think about the stability of the solution?

Splunk Enterprise Platform is stable.

What do I think about the scalability of the solution?

Splunk Enterprise Platform's scalability is very good.

How are customer service and support?

The customer support is very good.

I would rate the customer support on a scale of one to ten as an eight. They are able to query and answer most of the questions.

Which solution did I use previously and why did I switch?

We have used many solutions before, including Sentinel and Elastic, which we use in combination.

What was our ROI?

I feel I have seen a return on investment, and my general impression is that it is a great product.

What's my experience with pricing, setup cost, and licensing?

My experience with pricing, setup cost, and licensing is that the setup costs and licensing are pretty high.

Which other solutions did I evaluate?

Before choosing Splunk Enterprise Platform, I evaluated other options including Elastic.

What other advice do I have?

My advice for others looking into using Splunk Enterprise Platform is that it is a great solution, but it is a little expensive. I would rate this review a seven out of ten.

Which deployment model are you using for this solution?

Hybrid Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Other
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Last updated: Jul 1, 2026
Flag as inappropriate
PeerSpot user
Software engineer at ProminentPixel
Real User
Top 5
Apr 24, 2026
Log monitoring has transformed operations and now supports real-time threat detection
Pros and Cons
  • "Overall, it is a great tool for security analysis and log monitoring, and it is one of the best tools we have been using."
  • "The number one area for improvement is cost; it is not cost-efficient for small organizations."

What is our primary use case?

I use Splunk Enterprise Platform and Splunk Cloud for our Splunk solutions. I work with Splunk Enterprise Platform for the Enterprise, not with Enterprise Security.

I use Splunk Enterprise Platform for monitoring systems, analyzing logs, and building dashboards that support our operations, visibility, and business insights. I perform log analysis, create dashboards, and set up alerts using SPL. We query large volumes of logs, identify patterns, and troubleshoot issues.

I definitely use Splunk Enterprise Platform's machine learning toolkit. It helps us with predictive analytics in our organization. I have set alerts for daily ingestion using the Machine Learning toolkit in Splunk Enterprise Platform directly. I use SPL commands such as fit, apply, and score for regression and classification analysis, including yes or no category alerts. I mainly use it for anomaly detection in our company.

It is very efficient for us in assessing the effectiveness of Splunk Enterprise Platform in detecting anomalies and preventing system outages. I also set alerts for daily ingestion. Overall, it is a great tool for security analysis and log monitoring, and it is one of the best tools we have been using.

I have a custom add-on for forwarder management. Instead of having different instances, I made a different app for forwarder management. Anything that happens to that forwarder, I can see using that particular app and add-on SPL. That is how it helps us. I have many different custom add-ons for Splunk Enterprise Platform, and I have directly published them in Splunkbase. Even if our new employees need to see and debug what is the problem in our forwarder, that is how Splunk Enterprise Platform custom add-ons work for us.

I definitely leverage Splunk Enterprise Platform for advanced threat detection. It integrates with our existing security tools by aggregating logs from multiple sources such as servers, applications, and network devices. It makes it easier to correlate events and identify suspicious patterns that would not be visible in isolated systems. I use real-time alerts for suspicious activities. I have also set alerts in our organization for users; if multiple failed login attempts occur, then we get an alert. I monitor security events in real-time through dashboards.

What is most valuable?

The number one valuable feature is its powerful search capabilities in Splunk Enterprise Platform. Using SPL, we can fire a query and get so much results from that. The number two is its dashboard; we have built dashboards and alerts for different use cases. We use dashboards for visualization, which is also one of the best features. It is integrated with other tools; we have our custom add-ons there. It integrates with other tools as well. Additionally, it handles large volumes of machine data well, as we ingest daily TBs of data in Splunk Enterprise Platform.

In terms of improving data interpretation, it shows only the most relevant information for a specific user or role. Instead of going through large volumes of raw logs, we can directly see key metrics and alerts that matter to us. In our use case, we have set a system health and error rate, which we can directly see on our personalized dashboard. It makes our data more actionable, improves our efficiency, and allows both our technical and non-technical users to interpret insights without deep querying knowledge.

What needs improvement?

The number one area for improvement is cost; it is not cost-efficient for small organizations. Better cost management should be the first priority. Performance optimization is also important. Large queries or poorly optimized searches can sometimes slow down our results. Better recommendations or automation for query tuning would help us. It would be better if this is added in the near future versions.

For how long have I used the solution?

I have been using Splunk Enterprise Platform for a year.

What do I think about the stability of the solution?

It is super stable, which is why we use it. It is one of the best tools.

What do I think about the scalability of the solution?

It is super scalable for us; I would rate it eight out of ten regarding scalability.

How are customer service and support?

It is superb because whenever we raise a support case, they answer us instantly. Customer service is also good.

How was the initial setup?

It was straightforward for the initial setup.

What about the implementation team?

We have Splunk dedicated employees here who have trained in Splunk Enterprise Platform. It was installed directly by our own employees.

What was our ROI?

We definitely have approximately thirty to forty percent ROI from Splunk Enterprise Platform.

Which other solutions did I evaluate?

We have directly integrated to Splunk Enterprise Platform because we have become Splunk partners.

What other advice do I have?

This is my first time, so I do not know much about this platform. We have our custom application, and we can directly use that to enhance end-user experience. My piece of advice will be if you are looking for a SIEM tool to monitor and have personalized dashboards, then Splunk Enterprise Platform is definitely for you. If your team has the budget and your company has budget, then you should definitely move to Splunk Enterprise Platform. I would rate this product a nine out of ten overall.

Which deployment model are you using for this solution?

Public Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor. The reviewer's company has a business relationship with this vendor other than being a customer: Partner
Last updated: Apr 24, 2026
Flag as inappropriate
PeerSpot user
reviewer2830626 - PeerSpot reviewer
Dev Ops And Observability Admin at a tech services company with 11-50 employees
Real User
Top 5
Apr 27, 2026
Log analytics has improved monitoring and currently powers flexible dashboards and alerts
Pros and Cons
  • "Splunk Enterprise Platform is very efficient for us."
  • "The cost increases significantly as data volume grows. We ingest terabytes of data, so I can say Splunk Enterprise Platform is somewhat costly."

What is our primary use case?

I work in the data and analytics space where I deal with large data sets and system-generated logs. I use Splunk Enterprise Platform for monitoring systems. I analyze logs and create dashboards that help our technical teams.

Splunk Enterprise Platform is very efficient for us. We monitor logs and troubleshoot our issues, then create dashboards for tracking system performance. We bring in logs from different systems like Windows Event logs and AWS logs, so it is highly efficient for us. It is one of the best SIEM tools.

We use the Machine Learning Toolkit.

What is most valuable?

I love its search capabilities. It has a very strong search functionality using SPL. The dashboards are very flexible and easy to customize. One of the best features is how it can handle large-scale machine data efficiently.

What needs improvement?

The cost is definitely an area for improvement. The cost increases significantly as data volume grows. We ingest terabytes of data, so I can say Splunk Enterprise Platform is somewhat costly. Poorly written queries can impact our performance, so there should be suggestions provided to write queries in SPL.

As Splunk partners, as our data volume grows, our cost also increases significantly. From a pricing perspective, Splunk Enterprise Platform is somewhat costly for us.

For how long have I used the solution?

I have been working with this solution for the past one year.

What do I think about the stability of the solution?

We have experienced no stability issues. It is highly stable and scalable for us. We are increasing our team vertically and horizontally dedicated to Splunk Enterprise Platform.

What do I think about the scalability of the solution?

We have experienced no scalability issues. It is highly stable and scalable for us. We are increasing our team vertically and horizontally dedicated to Splunk Enterprise Platform.

How are customer service and support?

During an upgrade we were having some issues, but after some time, they resolved our issue and we were satisfied with that.

I would rate their customer service nine out of ten because our issues were solved quickly after two to three hours.

Which solution did I use previously and why did I switch?

We directly became Splunk partners. When I joined this firm, I directly used Splunk Enterprise Platform.

How was the initial setup?

We had training sessions for the onboarding process. Since I come from an observability and SIEM background, it was quite easy for me to integrate Splunk Enterprise Platform.

What about the implementation team?

We had training sessions for the onboarding process. Since I come from an observability and SIEM background, it was quite easy for me to integrate Splunk Enterprise Platform.

What's my experience with pricing, setup cost, and licensing?

The cost is a concern. The cost increases significantly as data volume grows. We ingest terabytes of data, so I can say Splunk Enterprise Platform is somewhat costly.

What other advice do I have?

We have an add-on of the Universal Forwarder that helps us check whether our forwarder server is down or not. We have our custom add-ons that are definitely helping us and easing our work.

We use alerts about licensing every day. We have set an alert that triggers if our daily license exceeds 500 GB. We came to know that our licensing limit has been reached, so we had to remove unnecessary data. That's how we use that feature.

We have just integrated Splunk Enterprise Platform with Amazon Web Services. It integrates well without any issue.

It helps with suggestions about regression and has pre-built functions and algorithms to build with. I would rate my overall experience with this solution nine out of ten.

Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
Last updated: Apr 27, 2026
Flag as inappropriate
PeerSpot user
Vsadalaga Sadalga - PeerSpot reviewer
Soc Analyst at a manufacturing company with 10,001+ employees
Real User
Top 5
Aug 9, 2026
Centralized monitoring has improved incident triage and speeds up daily security investigations
Pros and Cons
  • "While I cannot share internal metrics, I can say that Splunk Enterprise Platform has led to faster incident triage, better visibility into security events, and reduced time spent on manual investigations due to centralized log analysis and automated correlations."
  • "I would like to see more flexible licensing, easier deployment and administration, enhanced AI-driven automation, and more built-in dashboards and detection content in Splunk Enterprise Platform."

What is our primary use case?

Splunk Enterprise Platform serves as our primary solution for centralized log collection, real-time security monitoring, threat detection, incident investigation, and alert management. The cloud deployment simplifies platform maintenance and scaling.

Beyond threat detection, we use Splunk Enterprise Platform daily for alert triage, incident investigation, threat hunting, dashboard monitoring, and reporting. It provides us with centralized visibility and helps us respond to incidents more efficiently.

For example, when Splunk generates a high-risk sign-in alert, I correlate authentication and endpoint logs, review the user's activity, source IP, device, and MFA events, and then determine whether it is a true positive or false positive.

What is most valuable?

I would highlight centralized log management, fast search, real-time alerting, correlation searches, customizable dashboards, scalability, and strong integration as the best features of Splunk Enterprise Platform.

Customizable dashboards in Splunk Enterprise Platform give our SOC team a real-time view of key security metrics, including critical alerts, authentication activity, endpoint detections, and incident status. This helps us quickly identify high-priority issues and monitor the overall security posture from a single screen. Correlation searches automatically combine events from multiple data sources to detect attack patterns that individual alerts might miss. For example, a phishing email click followed by a suspicious sign-in and unusual endpoint activity can be correlated into one high-confidence alert, which reduces false positives and speeds up investigation.

I would also highlight strong integration, scalability, powerful search language, reporting, and the app ecosystem within Splunk Enterprise Platform. These features make it easy to centralize data and adapt the platform to different security and operational needs.

While I cannot share internal metrics, I can say that Splunk Enterprise Platform has led to faster incident triage, better visibility into security events, and reduced time spent on manual investigations due to centralized log analysis and automated correlations.

While I do not have official figures, I estimate that investigation and triage time has improved by around twenty percent to thirty percent for many common security incidents due to centralized log visibility and automated correlation with Splunk Enterprise Platform.

What needs improvement?

I would like to see more flexible licensing, easier deployment and administration, enhanced AI-driven automation, and more built-in dashboards and detection content in Splunk Enterprise Platform.

I chose nine out of ten for my rating because of the licensing cost and complexity of deployment and administration.

For how long have I used the solution?

I have been working in my current field for two years.

What do I think about the stability of the solution?

I would consider Splunk Enterprise Platform to be very stable. It has been reliable for log collection, search, and security monitoring with consistent performance in our daily operations.

What do I think about the scalability of the solution?

I do not have direct experience with petabyte-scale deployments using Splunk Enterprise Platform, but it appears to provide strong scalability, flexible data residency options, and governance controls that support data sovereignty requirements in large enterprise environments.

I would rate Splunk Enterprise Platform's scalability as very high. It scales adequately with growing data volumes and users while maintaining strong performance for search, analytics, and security monitoring.

How are customer service and support?

The customer support for Splunk Enterprise Platform is good.

Which solution did I use previously and why did I switch?

In my previous project, we used another solution before Splunk Enterprise Platform, but in the project that I am working on currently, we have been using Splunk Enterprise Platform from day one.

How was the initial setup?

The pricing for Splunk Enterprise Platform is on the higher side, especially as log volumes grow. Setup requires planning and expertise, but the platform's capability, scalability, and reliability justify the investment for enterprise environments.

What other advice do I have?

My advice for others looking into using Splunk Enterprise Platform is to start with clear use cases, onboard the right data, train your team on Splunk Enterprise Platform, optimize the searches and dashboards, and keep an eye on data ingestion to control licensing costs. Proper planning will help you get the most value from the platform. I would rate this product nine out of ten.

Which deployment model are you using for this solution?

Private Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Last updated: Aug 9, 2026
Flag as inappropriate
PeerSpot user
Consultant at Artifield
Real User
Top 5
Apr 22, 2025
Citizen programming facilitates efficient threat detection and enhances business logic
Pros and Cons
  • "Overall, I rate Splunk Enterprise Platform ten out of ten."
  • "Splunk could improve by enhancing its graphical view functionality. Compared to other BI tools, Splunk's graphic features are limited; customers desire detailed, rich visual effects, like world maps showing threat attacks as animations."

What is our primary use case?

I focus on threat detection against stock trading systems. I am in charge of five to seven stock trading companies' B2C systems for detecting threat attacks. Our customers include several stock trading companies, banks and and large mobile careers in Japan.

How has it helped my organization?

We built a threat detection system for our client company, one of the biggest security company in Japan, using Splunk Enterprise Platform. We started a new business on this platform to provide threat detection systems to stock trading system companies and banks, expanding our customer base.

What is most valuable?

One valuable feature of Splunk Enterprise Platform is citizen programming, which allows users to manage and compute huge stream-based datasets easily using SPL language. The second feature is its ability to perform matrix-like stream calculations concurrently, improving upon traditional SIEM tools. Finally, Splunk's Machine Learning Toolkit is offered without charge, allowing users to incorporate machine learning in their business logic, aiding in procedures like threat hunting.

What needs improvement?

Splunk could improve by enhancing its graphical view functionality. Compared to other BI tools, Splunk's graphic features are limited; part of customers desire detailed, rich visual effects, like world maps showing threat attacks as animations. Additionally, the deep learning capabilities need enhancing, especially on Splunk Cloud, where customers find it challenging to use deep learning tools without setting up backend computing resources.

For how long have I used the solution?

I have over 14 years of experience with Splunk Enterprise Platform, beginning my first evaluation in 2011.

What do I think about the stability of the solution?

I would rate the stability of Splunk Enterprise Platform as a seven. While it requires managing configuration files and processing scale-out operations manually, limiting its auto-scaling capabilities, it still performs adequately.

What do I think about the scalability of the solution?

I rate the scalability of Splunk Enterprise Platform as an eight. Some products can automatically scale, but Splunk Enterprise requires manual configuration changes to achieve scale, which is slightly outdated compared to modern technologies.

How are customer service and support?

I rate Splunk Japan's customer service as an eight. Although I generally provide support myself and do not often rely on Splunk support, this rating reflects general consultant feedback.

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

I previously used Elastic Search and Kibana, but switched to Splunk for ease of use and to define business entities such as branches, channels, and stock accounts.

How was the initial setup?

Standalone Installation was very easy. Designing and capacity planning for a distributed cluster environment was not easy.

What about the implementation team?

I am a Splunk consultant and implement customer solutions myself.

What's my experience with pricing, setup cost, and licensing?

I rate the pricing of Splunk as nine out of ten. The pricing model is based on ingesting data sizes, not user count, and includes a free tier for up to 500 MB of daily data, differentiating it from user-based pricing BI-tools.

Which other solutions did I evaluate?

I evaluated ArcSight and Manage Engine and made our selection.

# After using Splunk for several years, I conducted further evaluations, but our selection remained unchanged.

# Datadog was ideal for bug traceback during APM operations.

# Exabeam was ideal for use case-centric threat detection.

What other advice do I have?

Overall, I rate Splunk Enterprise Platform ten out of ten. I am dissatisfied with Splunk’s graphics view and deep learning capabilities; they could be better, especially on Splunk Cloud. While I was able to enhance the platform using technologies like JavaScript, most of my clients struggle.However, it will be sufficient for the next few years with it's strong Machine Learning capability.

 Also, it would be preferable for Splunk SOAR to include sequential Splunk task execution and MCP/A2A support features.

Which deployment model are you using for this solution?

Hybrid Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Disclosure: My company has a business relationship with this vendor other than being a customer. Implementer
PeerSpot user
reviewer2875314 - PeerSpot reviewer
Principal Siem Engineer at a tech vendor with 201-500 employees
Real User
Top 10
Jul 22, 2026
Platform has unified security and operations data and delivers strong value across enterprises
Pros and Cons
  • "Splunk Enterprise Platform is exceptional as a SIEM platform, with the breadth and depth built over the last 20 years."
  • "Regarding pricing, I find that Splunk is quite expensive, and I have seen customers getting migrated since the last two years."

What is our primary use case?

I was a partner with Splunk for around six years, and later I moved to customer projects. As part of Splunk, I worked as a professional services consultant, and later I began working with multiple customers through a different company as an independent consultant.

Splunk Enterprise Platform is exceptional as a SIEM platform, with the breadth and depth built over the last 20 years. The main benefit is that it serves both core operations and security through Enterprise Security.

My experience maintaining granular control over the trusted control plane within Splunk involves working with numerous log types that can be ingested, whether from custom application events, OS events, access and identity information, or security or EDR events.

Regarding AI usage in RBAC, I have primarily used it for use case management and taking actions once a security notable event is generated.

I have used Splunk Federated Search, which I implemented for one of my customers about a year ago.

In my experience with Federated Search, I will provide some context on why it was introduced. Splunk was pushing more on Splunk Cloud platform, which is one of their SaaS-based offerings.

What is most valuable?

In terms of scalability, I would rate Splunk Enterprise Platform between nine and ten because all you have to do is add one indexer to the platform. Splunk architects and consultants are involved in that process, but it is quite fast.

What needs improvement?

One area that has room for improvement is the log onboarding problem with all the AI aspects, which has not yet been solved.

For how long have I used the solution?

I have been using this solution for around eight years.

How are customer service and support?

My experience with technical support leads me to rate it between six and seven, leaning toward seven, as they have outsourced most of the support, and support in some regions is not excellent.

How was the initial setup?

The deployment model of my clients is a mix, as I have a few customers who ingest between 40 to 50 terabytes a day who are on enterprise, and there are a few clients with around four to five terabytes a day on cloud.

I would say the deployment planning and architecting is medium to hard, but once that is planned, the deployment itself is easy.

What was our ROI?

In terms of Total Cost of Ownership (TCO), I would say it is consistently net-net positive because Splunk Enterprise Platform is one of the platforms where all the logs of the entire organization are ingested.

What's my experience with pricing, setup cost, and licensing?

Regarding pricing, I find that Splunk is quite expensive, and I have seen customers getting migrated since the last two years.

Which other solutions did I evaluate?

In comparison with major vendors on the market, I see Splunk Enterprise Platform as still being the market leader, at least in terms of SIEM.

What other advice do I have?

I have a team reporting to me, as I work for a company, serving a bunch of Splunk customers and other SIEM customers.

In my organization, there are around four to five specialists who work with Splunk.

My clients are enterprise and medium to large businesses.

Splunk Enterprise Platform requires regular maintenance, and I find it easy to maintain.

My impression of Splunk's approach to managing governance within private network environments is that it is straightforward.

I suggest conducting a POC first and having one real customer who uses Splunk, because it will not work if you are just installing it locally.

I would rate this solution a nine overall.

Disclosure: My company has a business relationship with this vendor other than being a customer. partner
Last updated: Jul 22, 2026
Flag as inappropriate
PeerSpot user
Manager Recruitment at tata elxsi
Real User
Top 20
Apr 24, 2025
User-friendly interface accelerates task approval but update confirmations occasionally delay
Pros and Cons
  • "Splunk Enterprise Platform saves approximately 20 to 30 percent of my time without having to perform different actions separately."
  • "The only problem I have with Splunk Enterprise Platform is that sometimes when I update a review, it takes time to receive confirmation emails."

What is our primary use case?

I normally use Splunk Enterprise Platform for review purposes. It is very easy and convenient. Its GUI is easy for me to review and approve all those things.

What is most valuable?

Splunk Enterprise Platform is very easy and convenient to use. The graphical user interface is easy for me to review and approve tasks. It saves time by allowing me to perform actions on a single platform instead of managing them separately. Additionally, its real-time processing capability is very good.

What needs improvement?

The only problem I have with Splunk Enterprise Platform is that sometimes when I update a review, it takes time to receive confirmation emails. This happens very rarely, maybe once or twice a month. I feel this can be improved in terms of performance.

For how long have I used the solution?

I have been using Splunk Enterprise Platform for three years.

What do I think about the stability of the solution?

Splunk Enterprise Platform is very stable.

What do I think about the scalability of the solution?

Splunk Enterprise Platform is scalable to some extent, which is acceptable. However, when I connect via VPN, it may take time to launch.

How are customer service and support?

I haven't got any support yet, so I can't comment on this as of now.

How would you rate customer service and support?

What was our ROI?

Splunk Enterprise Platform saves approximately 20 to 30 percent of my time without having to perform different actions separately.

What other advice do I have?

My overall experience with Splunk Enterprise Platform rates around seven out of ten points. The main issues are regarding updating reviews and scalability, which may take some time when connecting via VPN. I would rate the overall solution 7 out of 10.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Buyer's Guide
Download our free Splunk Enterprise Platform Report and get advice and tips from experienced pros sharing their opinions.
Updated: July 2026
Buyer's Guide
Download our free Splunk Enterprise Platform Report and get advice and tips from experienced pros sharing their opinions.