No more typing reviews! Try our Samantha, our new voice AI agent.
Adam Santilli - PeerSpot reviewer
Cyber Security Associate at SAP
Real User
Top 5
Sep 12, 2025
Improves business resilience and reduced incident remediation time through real-time risk identification
Pros and Cons
  • "The ability to identify risks as they come in is quite good."
  • "Better education for users would be beneficial as they often don't know what they don't know or how to look for certain features."

What is our primary use case?

My main use cases for Splunk Enterprise Security include detection engineering tasks. I work with the SIM team handling various responsibilities, specifically ensuring uptime availability and correct log ingestion.

How has it helped my organization?

Splunk Enterprise Security has helped improve my organization's business resilience. We have definitely been able to get significant value out of it.

What is most valuable?

As an administrator, I mainly ensure other people can use the system effectively rather than using it extensively myself. 

My impressions of Splunk's ability to predict, identify, and solve problems in real time are solid. I definitely notice when it makes predictions and helps with what we're trying to find in general. The ability to identify risks as they come in is quite good.

The integration of disparate security solutions supports our security operations by providing multiple methods to handle things. We have 21 lines of business with different Splunk pods, each requiring different solutions.

Personally, the integration creates some challenges, particularly when trying to standardize processes and migrate to Splunk Cloud. Managing different Splunk pods on-premises and separate stacks leads to confusion and time inefficiencies.

The process for customizing, developing, testing, deploying, and refining detections in Splunk Enterprise Security works adequately. While I don't write the detections myself, I work closely with those who do, and it doesn't seem to be an issue.

Our Security Ops team's incident remediation time has improved significantly. Previously, it took approximately 11 hours, but now it takes a few hours, though we're still working to reduce this time further through our migration to Splunk Cloud.

What needs improvement?

There are ways Splunk Enterprise Security can be improved, though I might be speaking specifically about my organization's implementation. Better education for users would be beneficial as they often don't know what they don't know or how to look for certain features.

Regarding ease of use, Splunk Enterprise Security is adequate. The challenge arises when we have multiple users trying to differentiate between the regular search head and the Enterprise Security search head. While users can accomplish their tasks, the main issue stems from education rather than the platform itself.

Buyer's Guide
Splunk Enterprise Security
August 2026
Learn what your peers think about Splunk Enterprise Security. Get advice and tips from experienced pros sharing their opinions. Updated: August 2026.
914,109 professionals have used our research since 2012.

For how long have I used the solution?

I have been using Splunk Enterprise Security for three years, with a six-month break in between. I have been using it extensively for the last year.

What do I think about the stability of the solution?

The stability and reliability of Splunk Enterprise Security is very good. While we've experienced some downtime, crashes, and performance issues, these were caused by end users running poorly optimized queries rather than system problems.

What do I think about the scalability of the solution?

Splunk Enterprise Security scales effectively with our organization's growing needs. We haven't encountered any problems with scalability.

How are customer service and support?

I would rate customer service and technical support from Splunk at nine out of ten. I have had nothing but good experiences with Splunk support, receiving timely and helpful replies. In one instance, when I needed immediate support, I received a call within ten minutes of submitting the ticket, and we resolved the issue promptly.

Which solution did I use previously and why did I switch?

I am uncertain if my organization used another solution prior to adopting Splunk Enterprise Security. I believe we have been using Splunk the whole time, but this predates my joining the team.

How was the initial setup?

The deployment is fine. I don't really have much of a problem with that end of things.

What was our ROI?

I have seen a return on investment with Splunk Enterprise Security.

What's my experience with pricing, setup cost, and licensing?

I am not familiar with the pricing of Splunk Enterprise Security. Regarding licensing, we face some challenges. The management of different pods makes it confusing and complicated, but it gets resolved by our senior team members.

Which other solutions did I evaluate?

I use disparate security solutions that integrate or import data into Splunk Enterprise Security. We utilize many different tools.

What other advice do I have?

I would advise other organizations to consider Splunk Enterprise Security as it's an easy solution to implement and effective for its intended purpose.

On a scale of one to ten, I rate Splunk Enterprise Security an eight.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
PeerSpot user
Senior security analyst and engineer at a logistics company with 501-1,000 employees
Real User
Sep 22, 2026
Security platform has improved incident investigations and provides faster, correlated threat insights
Pros and Cons
  • "Splunk Enterprise Security has helped improve my organization's business resilience, and my impressions of Splunk Enterprise Security's ability to predict, identify, and solve problems in real-time are very efficient."
  • "Splunk Enterprise Security can be improved with additional features and newer features and tools."

What is our primary use case?

My main use case for Splunk Enterprise Security includes SIEM, SIEM services, network monitoring, detections and response, and data correlation.

We had an incident where we experienced command and control activity from an endpoint, which was a Citrix server that we had that is air-gapped or essentially firewalled off from our network. We used Splunk Enterprise Security to correlate the data and see the activity that was taking place with the threat actor.

Splunk Enterprise Security helped us piece together what was going on in that incident by making the investigation easier. It helped us build a report much quicker and helped us trace the activity much quicker.

What is most valuable?

The best features Splunk Enterprise Security offers include the ability to normalize data and integrate with other security tools and products from other vendors.

I use data normalization and integrations in my day-to-day work because we have several Splunk Enterprise Security-based apps, which save us time in investigation and help us piece together data and normalize it.

Splunk Enterprise Security has positively impacted my organization by helping us see our attack surface more efficiently and have more visibility on our network more efficiently.

What needs improvement?

Splunk Enterprise Security can be improved with additional features and newer features and tools.

For how long have I used the solution?

I have been using Splunk Enterprise Security personally for around six to eight months.

What other advice do I have?

I do not have anything else to add about how I use Splunk Enterprise Security.

I do not have anything else to add about the needed improvements.

I do not have anything else to add about the needed improvements or specific features or tools I wish it had.

Regarding Splunk Enterprise Security's AI capabilities, I think its governance and security are sufficient.

Regarding Splunk Enterprise Security's AI capabilities, I have no complaints so far as it is very accurate.

Splunk Enterprise Security has helped improve my organization's business resilience, and my impressions of Splunk Enterprise Security's ability to predict, identify, and solve problems in real-time are very efficient. It helps increase our response time and helps incident response in a more efficient and fast manner.

Splunk Enterprise Security has helped reduce my team's average Mean Time to Resolve, MTTR metric, but I cannot say by how much because I do not have access to those metrics in my position.

We are not utilizing risk-based alerting in Splunk Enterprise Security at this time.

I would rate this review an eight out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Last updated: Sep 22, 2026
Flag as inappropriate
PeerSpot user
Buyer's Guide
Splunk Enterprise Security
August 2026
Learn what your peers think about Splunk Enterprise Security. Get advice and tips from experienced pros sharing their opinions. Updated: August 2026.
914,109 professionals have used our research since 2012.
reviewer2900025 - PeerSpot reviewer
Security Analyst at a comms service provider with 10,001+ employees
Real User
Top 20
Sep 17, 2026
Risk-based alerting has improved threat visibility but still needs better alert volume control
Pros and Cons
  • "Splunk Enterprise Security has had a positive impact on our organization by allowing us to detect new things with RBA."
  • "I have observed that the Risk-Based Alerting feature of Splunk Enterprise Security has not had a positive impact on the volume of alerts or on analyst productivity."

What is our primary use case?

My main use of Splunk Enterprise Security in my organization is to create detection rules for our clients.

Notably, the detection rule that I created with this tool is the RBA rules, Risk-Based Alerting, that we have used for many clients.

To implement an RBA rule with Splunk Enterprise Security, we took the templates provided by Splunk and adapted them to our needs, allowing us to detect things we were not able to detect before, such as pen tests.

What is most valuable?

The best features offered by Splunk Enterprise Security are the unified interface for managing content, whether it is detection rules, lookups, and so forth, and the identity part, which I think is the most important.

What I particularly appreciate about the unified interface and identity management is that it allows us to apply priorities to assets and identities and therefore respond in the best way to the alerts we receive.

Splunk Enterprise Security has had a positive impact on our organization by allowing us to detect new things with RBA.

What needs improvement?

The improvement I would like to see made to Splunk Enterprise Security is a unified interface across several Splunk tenants to manage our clients' Splunk content from a single place.

For how long have I used the solution?

I have been using Splunk Enterprise Security for five years.

What do I think about the stability of the solution?

I find Splunk Enterprise Security stable in daily operation, and there is nothing to note about that.

What do I think about the scalability of the solution?

Regarding the scalability of Splunk Enterprise Security in my different environments, I find it fairly slow, and new features take quite a long time to be developed.

How are customer service and support?

I rate the customer support for Splunk Enterprise Security depending on the context, and on certain topics, we have considerable trouble finding information.

How was the initial setup?

Splunk Enterprise Security is deployed in my organization in various ways since we are a service provider and it all depends on our clients' choices. We have on-premises, we have cloud, and we have various other configurations.

What about the implementation team?

My company has a commercial relationship with this vendor other than as a customer because we are a partner, reseller, and service provider, so we advise and give guidance to our clients.

What was our ROI?

I have not seen a return on investment with Splunk Enterprise Security, and I cannot share concrete indicators such as time savings or human resource savings.

What other advice do I have?

I do not have information on whether I have noticed a reduction in the mean time to resolve incidents (MTTR) thanks to Splunk Enterprise Security.

I have observed that the Risk-Based Alerting feature of Splunk Enterprise Security has not had a positive impact on the volume of alerts or on analyst productivity. On the contrary, it has actually generated quite a lot of alerts that are even longer to analyze, and the benefit is not necessarily immediate.

I do not really have an opinion on the Threat Topology features or the support for the MITRE ATT&CK framework in Splunk Enterprise Security in helping me discover the scope of an incident.

I have not noticed an improvement in the speed of threat detection thanks to Splunk Enterprise Security.

I would rate this review seven out of ten.

Disclosure: My company has a business relationship with this vendor other than being a customer. Partner, Reseller, Service Provider
Last updated: Sep 17, 2026
Flag as inappropriate
PeerSpot user
reviewer2899083 - PeerSpot reviewer
SIEM engineer at a tech vendor with 10,001+ employees
Real User
Top 20
Sep 16, 2026
Security platform has unified triage and alerts and provides structured incident response
Pros and Cons
  • "Splunk Enterprise Security has positively impacted my organization by giving our SOC a place to triage and respond to incidents and alerts as they come in, allowing us to respond to cyber incidents."
  • "My assessment of customer support is that it is terrible."

What is our primary use case?

My main use case for Splunk Enterprise Security involves knowledge object development, detection engineering, data normalization, and alerting.

A specific example of how I use Splunk Enterprise Security in my day-to-day work is creating Splunk TAs to map non-normalized data to the Common Information Model.

What is most valuable?

The best features Splunk Enterprise Security offers include one single pane of glass for all your data, normalization, RBA built-in, assets and identities, detections, and everything built into one area.

Out of those features, I find myself relying on normalization and data models most often because that is how we structure our alerts to fire off all of our different data sources.

Splunk Enterprise Security has positively impacted my organization by giving our SOC a place to triage and respond to incidents and alerts as they come in, allowing us to respond to cyber incidents.

What needs improvement?

I believe Splunk Enterprise Security could be improved by costing less.

Splunk Enterprise Security's risk-based alerting, RBA, has slightly raised our alert volume because we have not turned off old alerts, but the fidelity of the alerts that RBA has provided us has been advantageous for uncovering true positives.

For how long have I used the solution?

I have been using Splunk Enterprise Security for about five years.

What do I think about the stability of the solution?

Splunk Enterprise Security is stable on-premises, but in the cloud, we have had numerous outages.

What do I think about the scalability of the solution?

I would not know about Splunk Enterprise Security's scalability because it is not managed by us.

How are customer service and support?

My assessment of customer support is that it is terrible.

What was our ROI?

I would say we have seen a return on investment because Splunk Enterprise Security has been sufficient for our operational and SOC needs, which have allowed us to provide security as a service to the enterprise.

What's my experience with pricing, setup cost, and licensing?

My experience with pricing, setup cost, and licensing shows that pricing is massively high.

Which other solutions did I evaluate?

Before choosing Splunk Enterprise Security, we are continuously evaluating other options, but none seriously at the moment.

What other advice do I have?

We do not use Splunk Enterprise Security for business resilience; we mainly use ITSI and some custom workflows that have been developed by other people than me.

We annotate our detections; however, as far as helping us operationally, the threat topology and MITRE ATT&CK framework features are not very impactful.

The consolidation of SIEM, SOAR, and UEBA into a single interface is not available to us yet.

My advice to others looking into using Splunk Enterprise Security is to keep it on-premises.

Which deployment model are you using for this solution?

Public Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Amazon Web Services (AWS)
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Last updated: Sep 16, 2026
Flag as inappropriate
PeerSpot user
DevOps&Cloud Engineer Mentee at CertDirectory.io
Real User
Top 20
Jun 27, 2025
Reduces alert fatigue, and it's well-documented and well-designed
Pros and Cons
  • "Splunk Enterprise Security is fast and well-documented, and user interface and user interaction are well-designed compared to other SIEM solutions."
  • "Splunk Enterprise Security is great but can have some frustration points. It can sometimes be slower to use."

What is our primary use case?

My main use case is for log management and checking the logs. We have rules running in Splunk Enterprise Security. We are using it as a main SIEM solution for our customers.

How has it helped my organization?

Alert fatigue is a common issue with security solutions, but Splunk Enterprise Security reduces alert fatigue. When we encounter real incidents, we get to dive deeper to check out the main cause of that incident. It is useful because it reduces alert fatigue.

What is most valuable?

The best feature of Splunk Enterprise Security is the documentation. Splunk Enterprise Security's documentation is well-organized. For example, if you have a problem or if you want to read about what you're looking for, you can easily go there and read from the documentation. It also has many resources worldwide. It is a de facto standard of the SIEM solutions. For example, I have used IBM QRadar, which is another solution many companies are using.

One of the most beneficial use cases for me is that Splunk Enterprise Security is fast. I cannot speak to how the SIEMs work in the backend, but I can say it is fast to find any logs. 

Its UX and UI experience is getting better. It is much better than one year ago. Some of the buttons and other features are much easier to locate and choose. The user interactions are much better than one year ago. The advanced queries are much faster. The UI design is much better. That is one of the best changes that happened in one year.

What needs improvement?

AI is an area that has room for improvement in Splunk Enterprise Security. I would say that AI plays a significant role in many of the cybersecurity tools I've used, not just Splunk. Many AI tools offer some form of assistance. By "AI assistance," I mean that while AI may not have complete knowledge of all customer flow data, it can still help engineers who often encounter unfamiliar situations. For example, during incidents, a large volume of logs can be generated, and it can be difficult to analyze all of them in a timely manner. In such cases, AI tools can be beneficial, even if they are not universally applicable. Certain events, like denial-of-service attacks, can result in massive log flows, which complicate detection and response efforts. Additionally, there may be similar collective issues affecting multiple customers.

Many cybersecurity tools incorporate some limited AI capabilities, which can assist operators. For instance, if a specific endpoint security issue arises with a customer, AI can help identify potential causes and suggest improvements. In my experience, most cybersecurity operators and companies rely on security tools that may not offer full-fledged SIEM solutions but do provide integrated security functionalities such as Intrusion Detection Systems (IDS) and Intrusion Prevention Systems (IPS). My expectation is that even small, incremental integrations of AI will significantly enhance these tools' effectiveness.

For how long have I used the solution?

I have been using the solution for approximately one year. I used it for 12 months in the company.

What do I think about the stability of the solution?

It's stable. I would rate it a ten out of ten for stability.

What do I think about the scalability of the solution?

The scalability of Splunk Enterprise Security rates as an eight out of ten. I have not used the scalability option, but I would say the other procedures and processes are flawless. Scalability might be the same.

How are customer service and support?

I have not reached out to their technical support because whenever I have an issue, I use the documentation rather than reaching out to technicians. When there is an issue, people need swift assistance to solve it. People do not want to wait, so I mainly use the documentation.

How would you rate customer service and support?

Neutral

Which solution did I use previously and why did I switch?

I have worked with other SIEM solutions. Splunk Enterprise Security is great but can have some frustration points. It can sometimes be slower to use. On the other hand, when I use IBM QRadar, it rarely experiences slowdowns, especially when using the Incident Command Module (ICM). In the case of Splunk Enterprise Security, the speed might be affected by the number of systems in use or possibly due to how the security engineers configure it. As an operator, I find that the speed is a reason I would rate it an eight out of ten. Overall, it's very fast and accurate, and the user interface is excellent for various uses, such as querying data. However, I do notice that it can be slightly slower compared to other large enterprise solutions.

How was the initial setup?

Most of the time, it is deployed on-premises. We don’t rely heavily on cloud solutions, although we have explored them a bit. Our customers, particularly in the financial industry, tend to prefer on-premises systems due to their concerns about cloud security.

Having good documentation is helpful for deployment. If the documentation is lacking, it can be challenging. The ease of navigating the systems really depends on a person's experience. 

The duration varies depending on the company. I can't give a specific answer because it depends on several factors, such as the number of people working in the system, the number of endpoints, and how many on-premises servers are running. In my case, I haven't experienced a full deployment, as I've only deployed a few endpoints and on-premises services. This process took just a couple of days for me, but I haven't dealt with a large-scale on-premises deployment. When I joined the company, they were already using Splunk for various on-premises services, so I haven't gone through a complete zero to one hundred type of scenario.

Splunk Enterprise Security absolutely requires maintenance, but I don't deal with maintenance. It needs maintenance, but I have not encountered much of it. 

What was our ROI?

From a return on investment standpoint, Splunk Enterprise Security saves a lot of time. I have used other SIEM solutions, and they are not so great. They create lots of exhaustion and frustrating periods of checking queries, and the response times are slower. This leads to a lot of frustration because many companies don’t rely on just one SIEM tool; they often use multiple alternatives simultaneously.

The documentation for Splunk Enterprise Security is outstanding. It is well-organized and easy to access. You can simply go to the Splunk documentation website, search for what you need, and by the end of the day, you’ll have a great solution for any issue you encounter with Splunk Enterprise Security. In contrast, other SIEM tools often lack this level of documentation, which is quite disappointing. 

Splunk Enterprise Security also excels with its user interface. It is easy to navigate and integrates seamlessly with other services, which is a significant advantage. You can easily search for solutions, try out different features, and create reports.

As a security operator, one of our main responsibilities is writing reports. If an issue arises, clients will often ask, “What happened around noon? Can you explain the main issue?” Other SIEM tools can make it difficult to find the appropriate buttons or functions to navigate and analyze these incidents. However, with Splunk Enterprise Security, you just look up the documentation, write what you’re searching for, and apply the same rules in Splunk Enterprise Security. Everything is easy to follow, and the system works effectively. In summary, I would say that the well-documented guidance is one of the most valuable aspects for saving me time.

What other advice do I have?

I have not used the advanced correlation capabilities so much because mainly all of them are running. Specifically, I have not gone very deep into the use case of Splunk Enterprise Security. I have used advanced queries a couple of times. For example, there was a sort of attack, a false positive attack. We had to check out all the timelines or block queries to find out what might have happened or what the reason was for the false positive. I used that and it is quite fast.

I have not used the risk-based alerting feature. It is more for log management and checking the log flow. 

Whenever you want to apply for any exams, such as the SOC exam or Blue Team certification exams, they mainly ask for Splunk rather than other SIEM solutions. For me, it is overall the best SIEM solution to use.

I can recommend Splunk Enterprise Security to other users. It is fast and well-documented. User interface and user interaction are well-designed compared to other SIEM solutions. It is a great SIEM tool.

I would rate Splunk Enterprise Security an eight out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
CEO at CygenIQ
Real User
Top 10
Dec 22, 2024
Improves threat management and has effective analytics
Pros and Cons
  • "The Splunk Enterprise Security's threat-hunting capabilities have been particularly useful in later releases."
  • "Splunk Enterprise Security enhances business resilience and assists with threat detection by centralizing security data."
  • "Splunk Enterprise Security would benefit from a more robust rule engine to reduce false positives."

What is our primary use case?

We primarily used Splunk Enterprise Security for data and cloud ingestion. We also leveraged it for enterprise security use case engineering, which encompassed malware analysis, threat management, detection, and the integration of threat and vulnerability intelligence, culminating in comprehensive reporting and dashboards. This was the principal use case for our SIEM platform. In recent years, we have also employed Splunk for user behaviour analytics to bolster insider threat protection.

We implemented Splunk Enterprise Security to improve security monitoring, threat detection, and incident response.

How has it helped my organization?

Although Splunk is not the only tool we use, it is essential that it provides end-to-end visibility into threats in our environment.

Splunk is effective for helping find security events across multiple cloud, on-premises, or hybrid environments.

Splunk helps improve our organization's ability to ingest and normalize data.

Splunk helps us identify threats in real-time.

We integrated 50 percent of the MITRE ATT&CK framework's techniques to enhance our incident detection capabilities.

Splunk Enterprise Security effectively analyzes various security events and has helped improve my organization's ability to ingest and normalize data.

Splunk helped us detect threats faster. 

Splunk Enterprise Security reduced the investigation time by consolidating datasets for quick access.

Splunk Enterprise Security enhances business resilience and assists with threat detection by centralizing security data.

I have a positive impression of Splunk's ability to predict, identify, and solve problems.

Splunk Enterprise Security helps reduce our mean time to resolve.

What is most valuable?

The Splunk Enterprise Security's threat-hunting capabilities have been particularly useful in later releases.

What needs improvement?

Splunk Enterprise Security would benefit from a more robust rule engine to reduce false positives. While its detection capabilities are efficient, there is room to improve its alert volume reduction and false positive management efficiency. Furthermore, enhancements in its integration capabilities with other security infrastructures could optimize its overall effectiveness.

For how long have I used the solution?

I have been using Splunk Enterprise Security for 13 years.

What do I think about the stability of the solution?

In terms of stability, Splunk is good. It provides a stable environment but needs to integrate with ITSM platforms to achieve better visibility.

What do I think about the scalability of the solution?

Splunk Enterprise Security is efficient and scalable, especially for large environments with substantial scalability needs.

How are customer service and support?

The technical support for Splunk met my expectations.

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

I haven't switched to Splunk from another solution, but I have used various products, such as Google Chronicle, Securonix, ExtraHop, and Sumo Logic, to meet different customer needs. Securonix is used more for behavioural analytics and insider threats, whereas Splunk is used for logging and monitoring.

How was the initial setup?

The initial setup of Splunk Enterprise Security is straightforward, but it does require skilled personnel.

What about the implementation team?

The implementation involved an architect, cloud DevOps engineer, data engineer, full-stack developers, and cybersecurity engineers. A team of five to six members, tailored to different roles, was typical.

What was our ROI?

Splunk's cost is justified for large environments with extensive assets. However, for smaller organizations, other products may provide better value for money.

What's my experience with pricing, setup cost, and licensing?

Splunk is priced higher than other solutions.

What other advice do I have?

I would rate Splunk Enterprise Security nine out of ten.

Splunk Enterprise Security requires continuous maintenance and support, which requires a dedicated team. Previously, seven to eight personnel were focused on platform maintenance. Additional resources may be required to optimize for multiple customer environments. 

For those evaluating SIEM solutions solely based on cost, Splunk might not be suitable. It is essential to consider security, context, and specific use cases rather than just choosing based on price. Critical assets need the right platform for effective protection rather than opting for a cheaper solution.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
reviewer2899449 - PeerSpot reviewer
Manager cybersecurity at a tech vendor with 10,001+ employees
Real User
Top 20
Sep 17, 2026
Correlations and risk features have improved our threat detection and incident investigations
Pros and Cons
  • "Splunk Enterprise Security offers excellent correlations, enhancements, and risk features that help my team."
  • "I chose eight out of ten because of the lack of retroactive IOC hunts and potentially missing data, which prevented me from giving it a ten."

What is our primary use case?

Splunk Enterprise Security serves as my main security solution. We raise notable events and pass them to the SOAR for security purposes. When I raise notable events and pass them to the SOAR, I track insider threats and external security incidents.

What is most valuable?

Splunk Enterprise Security offers excellent correlations, enhancements, and risk features that help my team. Data scrubbing for anomalous events stands out most for me because it ensures we focus on crucial alerts.

Splunk Enterprise Security has positively impacted my organization as it is embedded in our workflows and raises notables that are investigated by CERT analysts. The embedding and investigation process has improved things for my team by yielding better detection rates.

What needs improvement?

The assets and identities framework in Splunk Enterprise Security could benefit from more integrations for improvement.

I chose eight out of ten because of the lack of retroactive IOC hunts and potentially missing data, which prevented me from giving it a ten. Splunk Enterprise Security has helped improve my organization's business resilience, though my impressions of its ability to predict, identify, and solve problems in real-time are somewhat lacking due to a delay in search windows and possible overlap in data availability.

For how long have I used the solution?

I have been using Splunk Enterprise Security for thirteen years.

What do I think about the stability of the solution?

Splunk Enterprise Security is stable.

What do I think about the scalability of the solution?

Its reliability is good as it scales well.

How are customer service and support?

The customer support for Splunk Enterprise Security is sufficient.

Which solution did I use previously and why did I switch?

We have had Splunk Enterprise Security for over ten years and did not previously use a different solution.

What was our ROI?

I have not seen a return on investment; my focus was on the quality of alerts and detections, as our detection framework was previously version controlled.

What's my experience with pricing, setup cost, and licensing?

My experience with pricing, setup cost, and licensing indicates that the licensing is prohibitively expensive.

Which other solutions did I evaluate?

Before choosing Splunk Enterprise Security, we conducted a bake-off with Google SecOps and Palo Alto's XSIAM.

What other advice do I have?

We recently upgraded to Splunk Enterprise Security version 8.4, and the terminology normalization is a good move. The Analyst Queue is very similar to previous versions incident review, and we have not yet utilized those workflows. We recently implemented the risk-based alerting (RBA) index, and I have yet to evaluate the improvements. We had the MITRE ATT&CK framework in place prior to this version, which has been useful. You should focus on data onboarding, indexing, and source typing per Splunk best practices. I gave this product a rating of eight out of ten.

Which deployment model are you using for this solution?

Hybrid Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Last updated: Sep 17, 2026
Flag as inappropriate
PeerSpot user
reviewer2899491 - PeerSpot reviewer
Cybersecurity Analyst at a tech services company with 11-50 employees
Real User
Top 20
Sep 17, 2026
Incident investigations have become structured and now provide clients clear attack timelines
Pros and Cons
  • "Splunk Enterprise Security has positively impacted my organization because as a team, we have built a framework for how we can investigate things."
  • "I have noticed with a lot of clients that the instances in the cloud have been really slow."

What is our primary use case?

My main use case for Splunk Enterprise Security is reviewing incidents in the Mission Control dashboard for our clients. When an incident occurs, my analyst team and I review every incident and conduct investigations to view logs and perform formal investigations.

A specific example of how I have used Splunk Enterprise Security recently is when an incident in the Analyst Queue occurs or triggers. We review every property of the incident, including the host name, the user involved, and any risk events. Meanwhile, we work in an investigation file, and for the client, we deliver this as a PDF file or a Word file. Everything that we find in the alert or in the logs, we build a timeline so that when an incident occurs, we provide the client with the scope. When we deliver an investigation, the client knows what happened, who did it, and other relevant details.

I have been using the RBA framework increasingly. When an incident is happening, we review many things in this dashboard. When a host is involved, we review the most recent incidents in the risk framework, and when we review the alert, we know what was happening with this host.

How has it helped my organization?

Splunk Enterprise Security has positively impacted my organization because as a team, we have built a framework for how we can investigate things. Before we used Splunk Enterprise Security, when an incident happened, the team did not know how to start an investigation. Now that we are using most of Splunk Enterprise Security's features, we review the alert, the properties of the alert, and with that information, we can start to build an investigation. The most important part that Splunk Enterprise Security gives us is a framework to investigate incidents.

Since we have been using Splunk Enterprise Security, the most important part for our team is that we can build investigations very quickly. While I do not have specific numbers or metrics, I have seen this improvement in the team and in our framework to work.

What is most valuable?

The best features that Splunk Enterprise Security offers are the intelligence side, which is the most important aspect for my team and our investigations. When we were searching for traffic in the network, we use a lot of features including the traffic search or the intrusion search, and most of these features give us context of what is happening.

The intelligence features help my team in daily work and investigations because when an alert is triggered in the network side, we review this dashboard. When we have a malicious IP, we search this IP in all the traffic and we know what hosts this IP may have targeted. With these dashboards, we build a story so that the client has a great scope of what is happening or the incident.

What needs improvement?

I have noticed with a lot of clients that the instances in the cloud have been really slow. When the team performs an update in the instance, some features are missing. The most recent thing we have noticed is that when a version is updated, we miss the button of the short ID, which we use to identify our investigations or reports. Since the update was applied, we did not see that button, so these types of things in the dashboard or in the metrics of the operation in the cloud instance have been impacted.

I think it would be great if Splunk Enterprise Security could add an EDR solution. If we install a sensor in the endpoint, the sensor could forward the logs of Sysmon into a SIEM in a more rapid and efficient way.

For how long have I used the solution?

I have been using Splunk Enterprise Security since the beginning of 2025. I have been using it for Mission Control and detections.

What do I think about the stability of the solution?

In my experience, Splunk Enterprise Security is stable. However, when Splunk applies an upgrade, the instance could suffer some impacts. When the team applies an upgrade, we are very careful to control what happens in the instance.

What do I think about the scalability of the solution?

When it comes to scalability, I think that is more of the license involvement. I do not know if the technical side has some part in that.

How are customer service and support?

The customer support for Splunk Enterprise Security is very good. When we open a ticket with PS or something similar, the team responds very quickly and with complete information. I would rate the customer support a 10.

What was our ROI?

Since we are using the RBA framework, I think Splunk Enterprise Security has helped improve my organization's business resilience because we can know when a host or a user is acting in a suspicious or malicious way. If we identify this behavior, we can have answers for our clients. With this framework, knowing how an endpoint or a user behaves, we can understand if something is malicious or not.

Splunk Enterprise Security has helped reduce my team's average mean time to resolve, MTTR metric. While I do not have a specific number in metrics, what I have seen is that the team can investigate findings in a more specific way by reviewing logs. When we deliver an investigation, the client knows what is happening.

What other advice do I have?

When we configure an alert in Splunk Enterprise Security, we map the attacks in every detection, and when the client or the team reviews an alert, we know what is happening and what MITRE ATT&CK it is related to.

While I do not have the exact numbers since I work more in the technical side, I think we have seen improvements in alert fatigue using RBA with Splunk Enterprise Security.

The advice I would give to others looking into using Splunk Enterprise Security is to understand what kind of information from indexes they are currently ingesting in Splunk, so when an incident occurs, the team would perfectly know what is happening and where to search for it.

Which deployment model are you using for this solution?

Public Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Microsoft Azure
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
Last updated: Sep 17, 2026
Flag as inappropriate
PeerSpot user
reviewer2899014 - PeerSpot reviewer
SOC analyst at a government with 10,001+ employees
Real User
Top 20
Sep 16, 2026
Investigations have become faster as I quickly correlate alerts, reduce fatigue, and classify threats
Pros and Cons
  • "The ability to search for data and correlate with Jira alerts helps my daily work by enabling me to identify false positives, find traffic that can be tuned, and quickly identify malicious IP addresses."
  • "As far as reliability goes, I think that the AI capabilities will still need some human interaction, and I do not feel comfortable yet truly trusting everything that AI does."

What is our primary use case?

My main use case for Splunk Enterprise Security is investigations. A specific example of how I use Splunk Enterprise Security for investigations is diving deeper into triage alerts.

What is most valuable?

The best features Splunk Enterprise Security offers include searching for data to correlate with Jira alerts.

The ability to search for data and correlate with Jira alerts helps my daily work by enabling me to identify false positives, find traffic that can be tuned, and quickly identify malicious IP addresses. Splunk Enterprise Security has positively impacted my organization by providing SOC as a service and allowing us to find information quickly and escalate in a timely manner.

What needs improvement?

Regarding Splunk Enterprise Security's AI capabilities, we are currently not using the AI capabilities; however, I am excited about the AI capabilities that are being developed and hope that the government is more open to using the AI capabilities of Splunk.

As far as reliability goes, I think that the AI capabilities will still need some human interaction, and I do not feel comfortable yet truly trusting everything that AI does.

For how long have I used the solution?

I have been using Splunk Enterprise Security for two years.

What do I think about the stability of the solution?

Splunk Enterprise Security is stable.

What do I think about the scalability of the solution?

I think the scalability of Splunk Enterprise Security is good.

How are customer service and support?

I believe that the customer support for Splunk Enterprise Security is excellent; as we are government, we have our own reps that we can reach directly out to, and they are always very responsive. I would rate the customer support on a scale of one to ten as ten.

What other advice do I have?

I think Splunk Enterprise Security helps identify what part of the MITRE ATT&CK framework that the incident falls under.

I believe that Splunk Enterprise Security Essentials has contributed to a reduction in analyst burnout or fatigue; it removes having to go to multiple tools to pull data and find what I am looking for and puts the story together for me.

My advice to others looking into using Splunk Enterprise Security is to make sure that you are aware of all of the capabilities and ask for demos so that you ensure that you are using everything possible to make the best of your environment. I rate this review overall as a ten.

Which deployment model are you using for this solution?

On-premises

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Other
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
Last updated: Sep 16, 2026
Flag as inappropriate
PeerSpot user
GautamKar - PeerSpot reviewer
Staff Performance Engineer at ServiceNow
MSP
Top 5
Mar 2, 2025
Real-time monitoring and alerts enhance performance evaluation and security investigations
Pros and Cons
  • "I can create dashboards to collect and view information in a tabular, graphical format. This feature is important because it helps me understand time-series data over one or two hours."
  • "Overall, I would rate it a nine out of ten."
  • "Data retention can be better. If we want to look at the data for five months or six months, that is not available to us. We only have a history of 20 or 30 days. After that, the information gets lost. That is a drawback."

What is our primary use case?

We use it for real-time monitoring and alerts for all instances and servers on our sub-prod instances. It helps in monitoring, getting alerts for specific errors, and identifying various logs. We also use it for log analysis, which is very beneficial.

My use case is more related to production issues. Threat detection is taken care of by another team.

How has it helped my organization?

It is our go-to tool for monitoring multiple cloud environments. The difficult part initially is to understand how the logging is happening for particular applications or instances. Once you have an understanding of what you want to see and how they are getting generated, you can just write queries, and you can create exhaustive dashboards for anybody to look at and understand how things are.

Splunk Enterprise Security is good for analyzing malicious activities and detecting breaches. Its threat detection capabilities are good. We can look at the exact activity and task. We can look at a trace and understand what is happening. It gives a very granular understanding. I see emails from the security team mentioning what they have identified, so it seems to be helpful for threat detection.

Based on the org mail that we received, they were able to block almost 95% of threats in real time. That is a pretty good number.

Splunk Enterprise Security helps to reduce alert volume because you can understand patterns, such as where your requests are going and how everything is happening. There has been a 40% to 50% reduction.

Splunk Enterprise Security has helped speed up our security investigations by 40% to 50%. It has helped the security team to get a head start and understand where the issue is originating and where the problem is. We are operating in a very dynamic environment, so any time lost costs the company money.

What is most valuable?

I can create dashboards to collect and view information in a tabular, graphical format. This feature is important because it helps me understand time-series data over one or two hours. It creates graphs, allowing us to check spikes and examine average values and 90th and 95th percentile values. This capability is useful for performance monitoring and issue identification. I believe it has helped speed up security investigations.

What needs improvement?

Data retention can be better. If we want to look at the data for five months or six months, that is not available to us. We only have a history of 20 or 30 days. After that, the information gets lost. That is a drawback. 

Splunk's dashboards are pretty basic. In comparison to Grafana, the dashboards are not as detailed. There is room for improvement in that area.

For how long have I used the solution?

I have been using it for about one and a half years now.

What do I think about the stability of the solution?

It is stable. I have not encountered any stability issues so far.

What do I think about the scalability of the solution?

It is easy to scale. We have multiple instances, sub-instances, and prod instances running, so scalability is not a problem.

It is being used by development teams, QA teams, performance teams, and security teams. We have about 500 people using it.

How are customer service and support?

It is good. I have not had any major issues where support was lacking, so I would rate it positively.

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

In this organization, I did not use any similar solution. In my previous organization, we used APM tools like Dynatrace and AppDynamics, which helped us monitor real-time data and performance. Splunk is a similar tool but offers more capabilities and is also cost-effective.

It was an organizational decision to go with Splunk Enterprise Security. It involved financial considerations and the kind of deal Splunk provided, as we are using the enterprise version and another version. Economics, capabilities, and support were factors.

How was the initial setup?

I was not involved in its deployment. When it comes to maintenance, another team looks after it and takes care of maintenance.

What was our ROI?

I have not been involved in the finance part, so I cannot comment on ROI or costs. However, preventing incidents or solving performance issues saves money, converting time saved to money. Customers are happy. Employees are happy. There is less downtime.

What's my experience with pricing, setup cost, and licensing?

I am not aware of the costs; that is handled by a separate team. I only use it for logs and performance issues.

What other advice do I have?

Instead of going for the cheapest solution available, you should go for the one that meets your needs. It takes time for an organization to onboard a new solution, so it is important to choose the right solution from the start. I believe all available solutions are pretty good, so you should see what suits you better.

It is a great tool. If you learn to navigate it, you can access a wide range of information about any application or product. It is a very helpful tool, provided you know how to use it. 

Overall, I would rate it a nine out of ten.

Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
PeerSpot user
Buyer's Guide
Download our free Splunk Enterprise Security Report and get advice and tips from experienced pros sharing their opinions.
Updated: August 2026
Buyer's Guide
Download our free Splunk Enterprise Security Report and get advice and tips from experienced pros sharing their opinions.