No more typing reviews! Try our Samantha, our new voice AI agent.
Raymundo Perez - PeerSpot reviewer
Splunk Admin at Sempra Infraestructura
Real User
Top 5
Sep 13, 2025
Correlation and integration capabilities have streamlined our investigation and response efforts
Pros and Cons
  • "The features of Splunk Enterprise Security that I find most valuable are the correlation and correlation data."
  • "Splunk Enterprise Security could be improved in the dashboards that provide KPIs about environmental behavior."

What is our primary use case?

My main use cases for Splunk Enterprise Security are detection, attacks, analysis, and investigation.

What is most valuable?

The features of Splunk Enterprise Security that I find most valuable are the correlation and correlation data. These features have benefited my organization through the model of investigation, correlating with correlation alerts, and integration with other tools, which is a good point.

In my experience with other tools in previous jobs, the time is reduced by around 70% compared to the previous tool.

My impressions of Splunk's ability to predict, identify, and solve problems in real time are positive. There are points to consider when enriching the data with these kinds of inputs. It is a good opportunity for companies trying to start with this environment, though it might be a challenge for those who have been using it for a long time since it requires identifying the context and use cases.

What needs improvement?

Splunk Enterprise Security could be improved in the dashboards that provide KPIs about environmental behavior.

The most significant challenges I face when using Splunk Enterprise Security for advanced threat detection include correlation when we have inputs or tools about security, such as Forescout or CrowdStrike, which presents a good challenge.

My organization uses risk-based alerting in Splunk Enterprise Security, yet not optimally, which presents another challenge. My security ops team takes longer to remediate security incidents with Splunk Enterprise Security compared to our previous solution. It is very complex.

For how long have I used the solution?

I have been using Splunk Enterprise Security for four years.

Buyer's Guide
Splunk Enterprise Security
August 2026
Learn what your peers think about Splunk Enterprise Security. Get advice and tips from experienced pros sharing their opinions. Updated: August 2026.
914,109 professionals have used our research since 2012.

What do I think about the stability of the solution?

I would assess the stability and reliability of Splunk Enterprise Security as good. However, it depends on the Splunk architects or the best practices provided by the admins and power users. They should avoid creating bad practices in correlation alerts, queries, and dashboard reports, but overall, it is a good, stable product.

What do I think about the scalability of the solution?

Scaling is smooth in certain functionalities but can be more difficult when involving different areas. When under the same scope, it progresses smoothly.

How are customer service and support?

Customer service and technical support are good. They can sometimes be expensive, but the cost is appropriate given the professionalism in providing reports, diagnostics, and analyses.

We may need more follow-up for remediation, which is sometimes noted as expensive, however, it is acceptable as part of the partnership agreement.

Which solution did I use previously and why did I switch?

Prior to adopting Splunk Enterprise Security, I was using another solution, SOAR, to address similar needs. It accomplishes that along with the implementation process, and I need to consider the different policies within the company regarding privileges, roles, and dependencies across different areas.

How was the initial setup?

The process for customizing, developing, testing, deploying, and refining detections in Splunk Enterprise Security is part of the onboarding process. We sometimes need to review it based on our needs or use cases we need to apply, and we need to correlate the data with different inputs, sometimes directly from security or IT data.

What was our ROI?

I have seen a return on investment with Splunk Enterprise Security. If the account executives for Splunk do not explain the implementation process clearly, we may face challenges, as our company's first question is usually about seeing immediate results for the amount spent. We often need to follow a process and achieve a certain maturity level, which requires a prompt response from our management.

What's my experience with pricing, setup cost, and licensing?

Regarding my experience with pricing, setup cost, and licensing, it is good. I saw around 2016 when the license was one option, however, now it is good, although sometimes it depends on the business of the company since we do not always have the budget to increase, decrease, or try to change.

Which other solutions did I evaluate?

The factors that led me to change to Enterprise include the new improvements. This is the correct path, and next year we will need to review the challenges concerning AI governance, which I plan to use in Splunk Enterprise Security.

What other advice do I have?

Splunk Enterprise Security has helped improve our organization's business resilience. It helps us respond to various needs in our different regions or plants, aiming to obtain critical information to reduce the impact of hacks in our plants.

I would absolutely recommend Splunk Enterprise Security. Every time I have the opportunity to promote or explain how it works, people say it is amazing, and I agree. It is an integrated solution that stands out against competitors, and though it may be expensive, it delivers good quality.

I would rate Splunk Enterprise Security overall a nine on a scale of one to ten, considering the current improvements.

Disclosure: My company has a business relationship with this vendor other than being a customer. Accenture
PeerSpot user
Ashiq Ashraf - PeerSpot reviewer
Specialist-Infrastructure Opertions at Allianz Technology
Real User
Top 10
May 22, 2025
Effective data management and threat detection through comprehensive integration and rapid response
Pros and Cons
  • "Splunk Enterprise Security provides the foundation for unified threat detection, investigation, and response, enabling fast identification of critical issues."
  • "The pricing of Splunk Enterprise Security is not very affordable, and I have seen many companies planning to leave because of cost concerns."

What is our primary use case?

I'm an end user, admin, and consultant. We use Splunk Enterprise Security internally in our organization, and I also use it for my personal studies. My usual use cases for Splunk Enterprise Security include monitoring several kinds of exchange server logs and Office 365 logs, among others, as we have multiple monitoring use cases based on our requirements in our environment. We were trying to solve multiple things by implementing Splunk Enterprise Security, particularly for monitoring our applications based on the insurance business, so we use Splunk Enterprise Security logs for security purposes and internal infrastructure monitoring, including logs matching security purposes in our Office 365 and exchange servers.

What is most valuable?

The most valuable features of Splunk Enterprise Security are several add-ons and TAs, while the lack of a DB requirement is a significant advantage for the business, allowing easier management without needing in-depth DB knowledge. I find that Splunk Enterprise Security's ability to import data from various sources, including looking up Excel files, is quite effective, providing a good way for management.

We import data from several unique data sources into Splunk Enterprise Security, possibly more than a hundred because we have AWS and multiple servers. We have disparate security solutions that integrate data into Splunk Enterprise Security. I can still query data in Splunk Enterprise Security regardless of where it resides, and in my perspective, the query provides data quickly.

Splunk Enterprise Security has improved our organization's ability to ingest and normalize data compared to before using Splunk Enterprise Security. The unified platform helps consolidate networking, security, and IT observability tools, which is very relevant to our internal needs. Using Splunk Enterprise Security, our focus was not on reducing alert volume but on properly finding and handling alerts; we've managed to capture 100% of them effectively.

Splunk Enterprise Security provides the relevant context to help guide investigations by allowing us to share application logs and details with clients efficiently. We utilize out-of-the-box detections in Splunk Enterprise Security, and we have created dashboards that add value to our monitoring efforts. Customizing, developing, testing, deploying, and refining detections in Splunk Enterprise Security is easy; it has been a good experience without significant difficulties.

We upgraded to Splunk Enterprise Security from version 8.0.4 to 9.0.6, and also from 8.1.4 to 9.0.6; it worked well with the support we received from the team, and it has proven to be very useful. Splunk Enterprise Security provides the foundation for unified threat detection, investigation, and response, enabling fast identification of critical issues.

What needs improvement?

The solution could be improved by integrating more application monitoring features and possibly incorporating AI capabilities to enhance its functionality.

For how long have I used the solution?

I've been working with Splunk Enterprise Security for six years.

What do I think about the stability of the solution?

Splunk Enterprise Security is stable and scalable, making it a good tool that is beneficial for our needs.

What do I think about the scalability of the solution?

Splunk Enterprise Security is stable and scalable, making it a good tool that is beneficial for our needs.

What other advice do I have?

I participated in the deployment process of Splunk Enterprise Security, and we performed UAT before moving it to production. It's not the most affordable solution, as I've witnessed several companies considering leaving due to cost factors. The pricing of Splunk Enterprise Security is not very affordable, and I have seen many companies planning to leave because of cost concerns.

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Buyer's Guide
Splunk Enterprise Security
August 2026
Learn what your peers think about Splunk Enterprise Security. Get advice and tips from experienced pros sharing their opinions. Updated: August 2026.
914,109 professionals have used our research since 2012.
reviewer2898975 - PeerSpot reviewer
руководителем дирекции SOC at a financial services firm with 1,001-5,000 employees
Real User
Top 20
Sep 16, 2026
Visual security insights have transformed incident oversight and guided data-driven defense
Pros and Cons
  • "The features of Splunk Enterprise Security that I consider the best include the platform's ability to search big data, the ease of writing SPL queries and finding this data, and the quality of the dashboards that are drawn very well, allowing the creation of any dashboards you want, as far as your imagination goes."
  • "Since I am currently working with SOAR, I would like to give recommendations regarding Splunk SOAR, as there are very few ready-made apps, and we face problems with integration, which requires us to write to the vendor for help."

What is our primary use case?

My main use case for Splunk Enterprise Security involves advising on how integration should be done, what the architectural diagram should look like, what data we should see, assigning tasks for performing gap analysis according to MITRE ATT&CK and international standards, and similar responsibilities. I used to be an analyst investigating information security incident cases, and now I'm in a more managerial position.

I cannot describe a specific example in detail because it is confidential information, as I am under an NDA. However, I can say that integration with various systems was carried out, and there were moments when Splunk agents were failing for unclear reasons. In the end, we performed troubleshooting and realized that the problem was on the agent side, requiring us to update the agents.

In terms of integration with various systems, I encountered no problems during the implementation of Splunk Enterprise Security.

What is most valuable?

The features of Splunk Enterprise Security that I consider the best include the platform's ability to search big data, the ease of writing SPL queries and finding this data, and the quality of the dashboards that are drawn very well, allowing the creation of any dashboards you want, as far as your imagination goes.

Splunk Enterprise Security positively impacted our organization because we simply liked the solution for its convenience, and we decided to adopt it.

For different solutions, the state of the solutions, systems, and so on, we created visualizations and reports on a dashboard so that you can instantly see in real time what is happening.

What needs improvement?

In my opinion, there is always room for growth in Splunk Enterprise Security. Specifically, since I am currently working with SOAR, I would like to give recommendations regarding Splunk SOAR, as there are very few ready-made apps, and we face problems with integration, which requires us to write to the vendor for help. Since the vendor responds slowly, we completed a pilot and could not make a decision because there are very few ready-made apps. I would like the number of ready-made apps to grow and for the overall focus on SOAR to increase.

For how long have I used the solution?

I have been using Splunk Enterprise Security for almost three years.

What do I think about the stability of the solution?

I assess the stability of Splunk Enterprise Security as reliable, as the system works reliably.

What do I think about the scalability of the solution?

I find it easy to expand Splunk Enterprise Security for new tasks or to increase the volume of data.

Scaling Splunk Enterprise Security is easy if my organization needs to process more data or connect new systems, but it can be costly.

How are customer service and support?

We have contacted the support service of Splunk Enterprise Security.

I would give the support a rating of seven.

Which solution did I use previously and why did I switch?

We used another tool before implementing Splunk Enterprise Security, but I cannot specify which one.

Which other solutions did I evaluate?

We evaluated other solutions before choosing Splunk Enterprise Security. According to our process, we conduct a market analysis of which systems exist, run a pilot project for testing the functionality, and then choose the system we preferred.

What other advice do I have?

My advice to those considering implementing Splunk Enterprise Security is to conduct a full analysis, run a pilot, and only then make a decision. I would rate this review as an eight.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Last updated: Sep 16, 2026
Flag as inappropriate
PeerSpot user
Sreeni Mamidipaka - PeerSpot reviewer
IT Security Mgr at a legal firm with 1,001-5,000 employees
Real User
Top 10
Sep 11, 2025
Dashboards and reporting have streamlined our alert triaging and security investigations
Pros and Cons
  • "I would assess the stability and reliability of Splunk Enterprise Security as generally good, with very few downtime, crashes, and performance issues."
  • "Splunk Enterprise Security has helped improve my organization's business resilience by fulfilling gaps in forensics, incident management, IRP, and data management while helping us mature our security operations."
  • "Our organization has very limited resources, so we would want to expand some of those automation and AI capabilities to fill those gaps."
  • "My organization does not completely utilize risk-based alerting in Splunk Enterprise Security as it's not fully mature."

What is our primary use case?

My main use cases for Splunk Enterprise Security are log management and enterprise security. Those are the key.

How has it helped my organization?

Splunk Enterprise Security has helped improve my organization's business resilience. We load much of our data and information that we use. It's really helping us in our log management solution, and also for forensics and alert triaging purposes. Forensics is one of the big pieces, along with incident management, IRP, and data management. It's fulfilling all those gaps and helping us mature our security operations.

What is most valuable?

The features of Splunk Enterprise Security that I enjoy the most include reporting, dashboards, and RBA. These features have benefited my organization since the dashboards and reports help us review security alerts and events in a timely manner. The RBA is what we are currently working on to develop and have some early detection on security alerts and notifications.

Currently, I am using disparate security solutions that integrate or import data into Splunk Enterprise Security. This integration supports my security operations by providing some visibility into security. Yet we have many basic issues where we need to fix the log sources, integration, and quality of the content that's going into Splunk Enterprise Security.

I find the process for customizing, developing, testing, deploying, and refining detections in Splunk Enterprise Security quite basic. We don't have any sophisticated process. We have contractors and MSSP who are timely filling those gaps, going through the rule review process, going through regular security testing, and prioritizing what is more important as an organization.

What needs improvement?

Though we have not completely explored the product functionality, Splunk Enterprise Security itself has many features. This morning I was reviewing all the AI capabilities, such as version 8.2 which has included incident triaging and process. That's probably a very good feature. Our organization has very limited resources, so we would want to expand some of those automation and AI capabilities to fill those gaps.

For how long have I used the solution?

I have been using Splunk Enterprise Security for two years.

What do I think about the stability of the solution?

I would assess the stability and reliability of Splunk Enterprise Security as generally good, with very few downtime, crashes, and performance issues. I've been with the organization for a little over a year. I have seen one or two occasions where the enterprise resources crashed. I haven't really seen any significant issues.

What do I think about the scalability of the solution?

Splunk Enterprise Security works efficiently with scaling growing needs since the distributed architecture is very well planned and easily scalable. All you need is to spin up a few additional resources and you can build your collectors, forwarders, and indexers. It's quite easy. At the same time, it comes with its own complexities since it's an on-premises solution. 

Overall, it performs well. I haven't seen any outages or resource challenges while using it.

How are customer service and support?

I would evaluate customer service and technical support as very responsible. Anytime that we have issues or challenges, I could see they were helping us behind the scenes and going through all these improvements. They were excellent.

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

In previous organizations, I have been well-versed with many other SIM tools. QRadar is one prominent tool I used. The McAfee Nitro, which isn't available anymore, was another. RSA NetWitness, RSA enVision, ArcSight were among the many tools I've used. In modern SIM tools, I am more familiar with Sentinel and Google Chronicle. I would say Splunk Enterprise Security has more capabilities, and maturity-wise and roadmap-wise, this product has become much more mature than the other two products I could compare.

How was the initial setup?

I was not present for the deployment.

What was our ROI?

I have definitely seen a return on investment with Splunk Enterprise Security.

What other advice do I have?

The most significant challenges I face when using Splunk Enterprise Security for advanced threat detection relate to the RBA, which is something that we were struggling with. We are working with the SIM and our reseller to streamline that process. That's something that's not easy for every organization. We are going through the same turbulence.

My organization does not completely utilize risk-based alerting in Splunk Enterprise Security as it's not fully mature. It is supporting our SOC in a limited way. We still have a long way to go. The product is not completely mature. We are a unique organization, so it requires additional resources to get that work done.

My organization is in the process of expanding our security use cases. It's a multi-year model where we are strategizing and exploring all our security needs. I would say we are still in the early phase. Although we have the product in place, it was not yet mature due to some resource issues.

My advice to other organizations considering Splunk Enterprise Security is that it's a good product. It's definitely helpful. If somebody is looking for security and log management, investigations, incident, and IRP, then they can look into this product and explore it. It's one of the market-leading products. It definitely stays up to the mark. 

On a scale of one to ten, I rate this solution an eight.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Associate I at Positka
Real User
Top 20
Feb 17, 2026
Advanced analytics has improved resilience and real-time threat mapping across diverse data
Pros and Cons
  • "Splunk Enterprise Security has helped greatly improve the organization's business resilience."
  • "I think the pricing aspect of Splunk Enterprise Security is quite high compared to other products, which I hear from most of my customers."

What is our primary use case?

My use cases for Splunk Enterprise Security involve both security as well as data analytics.

How has it helped my organization?

Splunk Enterprise Security has helped greatly improve the organization's business resilience.

What is most valuable?

The features of Splunk Enterprise Security that I appreciate the most include the recent AI feature and the MITRE mapping feature.

AI helps in analyzing a certain detection within Splunk Enterprise Security and assists with some tasks that I might require internet or other tabs to work on, while MITRE ATT&CK helps me to map the attacks and provides coverage for my attacks.

What needs improvement?

I would appreciate improvements in the licensing aspect, especially with the SVC-based license, as there is no proper view on top of it regarding how much CPU and usage is being done on the SVC-based license, along with updates to the SOAR version.

The experience with alerts, specifically risk-based alerts, is good, but it might need some improvement as there might be some deviation or false positives, so I think implementing AI over there might increase the feasibility or view around it.

I think the pricing aspect of Splunk Enterprise Security is quite high compared to other products, which I hear from most of my customers.

For how long have I used the solution?

I have been working with Splunk Enterprise Security for approximately 3.5 years.

What do I think about the stability of the solution?

I would assess the stability and reliability of Splunk Enterprise Security as very good, with not much downtime or crashes, as it depends on the hardware used and the kind of setup done, which is primarily based on misconfiguration or not predicting something.

I have not faced any significant challenges when using Splunk Enterprise Security; there is not much that I cannot solve.

What do I think about the scalability of the solution?

Splunk Enterprise Security scales very well with the growing needs of my organization and my clients' organizations.

Expanding usage with Splunk Enterprise Security consumes time and effort, but the end result is actually good.

How are customer service and support?

I would evaluate customer service and technical support as good but not very good.

On a scale of one to ten, I would rate them somewhere around seven to eight.

How would you rate customer service and support?

Positive

How was the initial setup?

I would describe my experience with deploying Splunk Enterprise Security as good, pretty easy, straightforward, and with plenty of documentation.

I have not faced any challenges during the deployment aspect; even if I did, I figured it out using Splunk Community and Splunk documentation.

What was our ROI?

It does bring measurable benefits in terms of return on investment for clients; specifically, for banking or finance customers who wish to contain their data within their environments, they would definitely go for Splunk Enterprise Security compared to CrowdStrike, but less mature organizations might prefer other products.

Which other solutions did I evaluate?

The key differences, both pros and cons of Splunk Enterprise Security in comparison to CrowdStrike, are that I am a Splunk enthusiast and I love Splunk Enterprise Security, but CrowdStrike is good in search and detections due to its status as a threat intel partner, which offers good detections, while customization done in Splunk Enterprise Security might take too much time on CrowdStrike and there are fewer integration options with CrowdStrike.

I don't have much idea on disadvantages of Splunk Enterprise Security apart from the pricing.

What other advice do I have?

I am currently working with Splunk products.

I work with Splunk Enterprise and Splunk Enterprise Security.

The process for customizing, developing, testing, deploying, and refining detections in Splunk Enterprise Security is pretty easy for me as an expert, but I'm not sure for a new user; being a Splunk architect, I feel it's a little easy and the customization is very helpful.

We have it integrated with various disparate solutions including RSA, CrowdStrike, AWS, Google, Microsoft, Docker, firewalls, switches, and multiple other technologies.

This integration supports my security operations by fetching logs about user activity and audit logs and actions taken by the user; for normal products, this allows me to analyze, detect, and correlate two or three different datasets to build up a use case from which I can deduce some information, and with the queries I have using SPL queries, I can get some data analytics or alerts or reports based on which I can take action.

I use risk-based alerting in Splunk Enterprise Security.

My experience with risk-based alerting, while not mainly focused on the SOC part of Splunk Enterprise Security, provides support to my engineering efforts.

I am not currently using any new threat detection features in Splunk Enterprise Security; I have no idea about that part of it.

My impressions of Splunk Enterprise Security's capability to predict, identify, and solve problems in real-time depend on what kind of data is being received and the use cases being written; it is not straightforward, but because Splunk Enterprise Security is an analytics platform without AI on top of it, it feels that some data sources are less predictable, yet for jobs that are repetitive or similar, Splunk Enterprise Security works well.

I would rate this product a 9 out of 10.

Which deployment model are you using for this solution?

Hybrid Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Other
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
Last updated: Feb 17, 2026
Flag as inappropriate
PeerSpot user
Gerardo Ochoa López - PeerSpot reviewer
Cyber Security Consultant at a tech services company with 11-50 employees
Real User
Top 20
Sep 16, 2026
Comprehensive investigations have improved soc operations and reduced incidents for customers
Pros and Cons
  • "Splunk Enterprise Security acts as a kind of plug-and-play tool for SOC operations, which makes it a very nice tool with a positive impact on my organization."
  • "The customer support for Splunk Enterprise Security is bad, as the support never solves anything."

What is our primary use case?

My main use case for Splunk Enterprise Security is for SOC operations. I offer the SOC service to our customers, and Splunk Enterprise Security is a very powerful tool that provides all the framework and tools to correlate events, conduct investigations, and manage issues or alerts.

What is most valuable?

The best features Splunk Enterprise Security offers are the correlation and, specifically, a tool that I appreciate is the Asset and Identity Investigation Investigator. What I appreciate most about those two specific models is the ease of simply entering an IP and user, as it shows me not only the events but also information about that object, such as the owner, associated users, IPs, associated host names, business unit, and all this information. It also provides a summary of the authentications, IDS events, and any risk events or notables, which are also shown, making it a very powerful tool.

Splunk Enterprise Security acts as a kind of plug-and-play tool for SOC operations, which makes it a very nice tool with a positive impact on my organization. It is helping to reduce incidents and manage and review them, allowing me to discover easily when I need to notify my customer about something important.

What needs improvement?

The first improvement for Splunk Enterprise Security is making it cheaper, as I would like to introduce it to other customers, but the high price is a barrier to entry. I would also like a better integration or functionality with AI, as there is not a good implementation of it.

For how long have I used the solution?

I have been using Splunk Enterprise Security for three years.

What do I think about the stability of the solution?

Splunk Enterprise Security is not stable; when it becomes outdated, it always has some failures or bugs, such as features that were in the previous version that are not in the newest one, resulting in many support tickets.

What do I think about the scalability of the solution?

Splunk Enterprise Security's scalability is fine because it operates with the Splunk license, and if you have all the information, you can apply a one-to-one process using the data models.

How are customer service and support?

The customer support for Splunk Enterprise Security is bad, as the support never solves anything.

Which solution did I use previously and why did I switch?

I use various vendors' SIEMs because of my work to serve my customers.

How was the initial setup?

It has helped improve my organization's business resilience, but it is hard to achieve because there is not a clear path to follow for a good implementation of Splunk.

Splunk Enterprise Security has helped reduce my team's average mean time to resolve (MTTR) metric because the tools I previously mentioned provide a lot of context and correlation of all events, which is very good. It has helped me detect threats faster, but it is challenging to set up all the logs and configurations for it to work as desired.

What's my experience with pricing, setup cost, and licensing?

I am not the best person to answer questions about pricing, setup cost, and licensing since I am a technical person and not a commercial one, but I know it is an expensive tool. I believe that the commercial limitations of selling Enterprise Security are significant, and removing them could allow us to bring it to multiple customers.

Which other solutions did I evaluate?

This question and any decisions about why I chose Enterprise Security do not apply to me because I am not the decision-maker; I am only the technical person who administers it.

What other advice do I have?

I would advise others looking into using Splunk Enterprise Security that it is a pretty good tool that works very well, but you need a partner or someone to guide you through the process; otherwise, you may feel alone. I would rate this product a 9.

Which deployment model are you using for this solution?

Public Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Other
Disclosure: My company has a business relationship with this vendor other than being a customer. Reseller
Last updated: Sep 16, 2026
Flag as inappropriate
PeerSpot user
Defense Analyst at a tech vendor with 10,001+ employees
Real User
Top 20
Sep 16, 2026
Risk-based analysis has improved alert scoring and now gives clear visibility into analyst actions
Pros and Cons
  • "Splunk Enterprise Security has positively impacted my organization since everything we do in some form relates back to Splunk, and as a detection engineer, my responsibility is to make sure we're collecting the right information and filtering out the wrong."
  • "I don't really know how to answer how Splunk Enterprise Security's scalability is, but for the time being, it covers what we need, and I don't feel like we're actually utilizing everything."

What is our primary use case?

My main use case for Splunk Enterprise Security is RBA for Risk-Based Analysis Scores.

I am currently working through activating intermediate findings from our ESCU content as we just switched from risk-based or risk rules to intermediate findings, and we have over a thousand to go through, validate that are correct, and implement.

I'm newer to that function, so my experience with handling those intermediate findings right now is limited but growing.

What is most valuable?

The best features Splunk Enterprise Security offers in my opinion include the ability to score alerts, so you're not getting alerts on everything; you can threshold things, so they only show up once they've alerted and hit a certain score-wise.

Splunk Enterprise Security has positively impacted my organization since everything we do in some form relates back to Splunk, and as a detection engineer, my responsibility is to make sure we're collecting the right information and filtering out the wrong.

Since implementing Splunk Enterprise Security, I've noticed specific outcomes such as the visibility into being able to see what our analysts are doing and what's being caught and what's not, which is the major benefit I noticed.

What needs improvement?

In terms of how Splunk Enterprise Security can be improved, with the focus of transitioning everything to an agentic SOC, it would be beneficial to continue allowing us to see into what's being done, so we can validate that the agentic SOC formats and processes are doing the correct things.

For how long have I used the solution?

I have been using Splunk Enterprise Security for about two months.

What do I think about the stability of the solution?

In my experience, Splunk Enterprise Security is stable, as we have no issues with it; it runs for the most part, and sometimes we know of some issues with SOAR playbooks not functioning correctly, but outside of that, nothing more.

What do I think about the scalability of the solution?

I don't really know how to answer how Splunk Enterprise Security's scalability is, but for the time being, it covers what we need, and I don't feel like we're actually utilizing everything.

How are customer service and support?

The customer support for Splunk Enterprise Security is good, and we also have good contacts with our customer reps, so we are partners and we use them pretty well.

I would rate the customer support an eight, as I haven't had too many interactions with them, and while I haven't heard any complaints, I still don't have information.

Which solution did I use previously and why did I switch?

I'm newer, so as far as I'm aware, we did not previously use a different solution before Splunk Enterprise Security, but again, prior to me being there, maybe.

Which other solutions did I evaluate?

Before choosing Splunk Enterprise Security, our team is constantly evaluating what we're using, for example, we have an evaluation out for Sentinel, though it's not something we use as a primary; I think it was offered for free as part of a bundle.

What other advice do I have?

For anyone looking into using Splunk Enterprise Security, I would advise really understanding the language and how to navigate; writing the correlation searches is just something that takes time, so just learn the language and you'll be good. I have provided an overall review rating of eight.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
Last updated: Sep 16, 2026
Flag as inappropriate
PeerSpot user
Ram Benavides - PeerSpot reviewer
Threat Analytics Lead at a manufacturing company with 501-1,000 employees
Real User
Top 20
Sep 16, 2026
Threat hunting has become faster and focuses on critical incidents through custom dashboards
Pros and Cons
  • "Splunk Enterprise Security has positively impacted my organization by helping us identify threats very quickly, and we are now able to identify threats 60% faster compared to before."

    What is our primary use case?

    My main use case for Splunk Enterprise Security is threat hunting.

    A specific example of how I use Splunk Enterprise Security for threat hunting in my organization is identifying incidents and threats. When I'm identifying incidents and threats, I use self-created dashboards in Splunk Enterprise Security.

    What is most valuable?

    The best features Splunk Enterprise Security offers include the ability to create dashboards and really wrap the data up in a more readable view. Those readable views have helped my team by reducing the amount of traffic that we have to identify or incidents that we have to identify, which really minimizes the amount of time we have to spend searching for data and lets us focus on the things that are important. Splunk Enterprise Security has positively impacted my organization by helping us identify threats very quickly. I can share that we are now able to identify threats 60% faster compared to before.

    What needs improvement?

    I see no areas for improvement in Splunk Enterprise Security outside of incorporating AI and the ability for AI to act and respond on my behalf. I would like AI to handle responding to incidents for me within Splunk Enterprise Security.

    For how long have I used the solution?

    I have been using Splunk Enterprise Security for eight years.

    What do I think about the stability of the solution?

    Splunk Enterprise Security is absolutely stable.

    What do I think about the scalability of the solution?

    The scalability of Splunk Enterprise Security is good; it continues to evolve as long as we are able to maintain our data ingestion within our licensing.

    How are customer service and support?

    Customer support for Splunk Enterprise Security is fantastic.

    Which solution did I use previously and why did I switch?

    I previously used Kibana before Splunk Enterprise Security because my organization wanted to make the switch to Splunk due to having more people capable in Splunk versus Elastic.

    Which other solutions did I evaluate?

    I evaluated Elastic as another option before choosing Splunk Enterprise Security.

    What other advice do I have?

    My advice to others looking into using Splunk Enterprise Security is that it's phenomenal; the ease of use, support, and the continued development of the product continues to evolve as the technology grows, and they are embracing AI to make the product even more effective. I think their governance and security are good based on all that I have seen and the demos that I have seen, as there seems to be a lot of capabilities around governance and security. So far, so good regarding Splunk Enterprise Security's AI capabilities; what I have been able to see seems to be very accurate, especially because it actually provides the data based on what it's identified, so I can validate it. I give this product a rating of 10.

    Which deployment model are you using for this solution?

    On-premises
    Disclosure: My company does not have a business relationship with this vendor other than being a customer.
    Last updated: Sep 16, 2026
    Flag as inappropriate
    PeerSpot user
    IT Admin at EuroSerwis
    Real User
    Top 20
    Sep 30, 2025
    Faced challenges with cost and support but have gained insights into traffic monitoring and threat detection
    Pros and Cons
    • "What I appreciate about Splunk Enterprise Security is creating the newest SPL for network traffic and using the risk-based alerting feature that helps my organization by allowing me to learn more information about Splunk every day because it is a big platform."
    • "I encounter issues such as downtime, bugs, glitches, and unbox errors."

    What is our primary use case?

    My use case for the project is thin.

    What is most valuable?

    What I appreciate about Splunk Enterprise Security is creating the newest SPL for network traffic. I use the risk-based alerting feature. The risk-based alerting helps my organization by allowing me to learn more information about Splunk every day because it is a big platform.

    What needs improvement?

    I think that Splunk Enterprise Security is a very good platform, but the price is very high. I don't know how to explain what else can be improved in Splunk Enterprise Security aside from pricing. Support is important for improvements. My thoughts on better support include better knowledge base and better response time; it encompasses both aspects.

    For how long have I used the solution?

    I moved to Splunk Enterprise Security and learned it for two to three years, but in the last year, I worked with my friends on one project.

    What do I think about the stability of the solution?

    I rate the stability as a five. I encounter issues such as downtime, bugs, glitches, and unbox errors.

    What do I think about the scalability of the solution?

    Only two users use Splunk Enterprise Security.

    How are customer service and support?

    Support is important for improvements. My thoughts on better support include better knowledge base and better response time; it encompasses both aspects. I rate support as a five.

    How would you rate customer service and support?

    Positive

    How was the initial setup?

    I think it was easy to install, but this platform has many components I must learn. It took me months to deploy.

    What other advice do I have?

    I am reviewing Splunk Enterprise Security today, and I am working on one simple product and creating simple SPL. My thoughts on customizing, developing, testing, deploying, and refining detections are focused on detection. The testing is just the last component. My thoughts on the testing feature in Splunk Enterprise Security involve the network traffic to Cisco traffic, Uniper, or low car infrastructure. I am using new threat detection features in Splunk Enterprise Security and would work on big projects in the future. I do not use disparate security solutions that integrate or import data into Splunk Enterprise Security. I am wanting to learn more because I create simple SPL, and my friends are not Splunk Enterprise Security expert admins. I would recommend Splunk Enterprise Security to other users because it is a platform for monitoring all traffic, network infrastructure, hardware, software, and everything.

    I rate the solution overall as a five out of ten.

    Which deployment model are you using for this solution?

    Public Cloud

    If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

    Disclosure: My company does not have a business relationship with this vendor other than being a customer.
    PeerSpot user
    reviewer2756070 - PeerSpot reviewer
    Service Lead at a manufacturing company with 10,001+ employees
    Real User
    Top 10
    Sep 12, 2025
    Has improved real-time threat detection and supports better contextual awareness
    Pros and Cons
    • "The features of Splunk Enterprise Security that I prefer most are the correlation engine and the common information model, basically the aggregation of data."
    • "The problem with Splunk Enterprise Security generally, from what I've seen in the last couple of years, is that it has a cultural, assumption design model around it, which means the company has to fit its internal processes in terms of how to use it."

    What is our primary use case?

    Splunk Enterprise Security by our SOC organization to aggregate and triage alerts used to identify IOCs.

    How has it helped my organization?

    Splunk Enterprise Security has a strong feature set that helps identify, and solve problems in real time.

    The benefits of those features for my organization, more specifically, are that it prevents us from being hacked. 

    What is most valuable?

    The features of Splunk Enterprise Security that I prefer most are the correlation engine and the common information model, basically the aggregation of data. It's usually designed to take all the data, normalize it into a flat schema, so you can then see patterns more easily. That's the significant aspect.

    What needs improvement?

    The problem with Splunk Enterprise Security generally, is that organizations strugle to fit into their cultures and workflow. For better outcomes, companies have to fit their internal processes to how the tool has been designed. At times, this can be too complex to run, has high overhead requiring constant tuning. Newer versions e.g. 8.3, hint at greater ease of use.

    For how long have I used the solution?

    I have been working in my current field for around 12 years.

    What do I think about the stability of the solution?

    Reliability is all about the care and feeding of it. I have not experienced downtime, crashes, or performance issues with Splunk Enterprise Security.

    How are customer service and support?

    I would evaluate customer service and technical support as an eight on a scale of one to ten. Splunk Cloud's support is not bad. However, there's a gray area between what they do and what they don't do. What they don't do is the blind spot for most enterprise customers; they don't realize they have to handle certain responsibilities. There's a shared responsibility.

    How would you rate customer service and support?

    Positive

    How was the initial setup?

    Setup can be complex. Splunk has specific guidelines. Do your home work and read their SVA architecture and capacity manuals. 

    And always read their release notes.

    What was our ROI?


    What's my experience with pricing, setup cost, and licensing?

    My experience with pricing, setup costs, and licensing for Splunk Enterprise Security is limited. The unit cost of Splunk Enterprise Security is slightly less than the core product. 

    Which other solutions did I evaluate?


    What other advice do I have?

    My advice to other organizations considering using Splunk Enterprise Security is to do your homework. Attend industry peer sessions and learn from other organizations. Splunk's partner program, RBA Community offer compelling resources for new customers.

    I would rate it an eight out of ten.

    Which deployment model are you using for this solution?

    Public Cloud

    If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

    Disclosure: My company does not have a business relationship with this vendor other than being a customer.
    PeerSpot user
    Buyer's Guide
    Download our free Splunk Enterprise Security Report and get advice and tips from experienced pros sharing their opinions.
    Updated: August 2026
    Buyer's Guide
    Download our free Splunk Enterprise Security Report and get advice and tips from experienced pros sharing their opinions.