No more typing reviews! Try our Samantha, our new voice AI agent.
CR 1 at a healthcare company with 5,001-10,000 employees
Real User
Top 20
Sep 17, 2026
Centralized alerts have reduced investigation time and provide flexible correlation with SPL
Pros and Cons
  • "Splunk Enterprise Security has positively impacted our organization because it gives us the ability to have the information in one point."

    What is our primary use case?

    I use Splunk Enterprise Security as a SIEM, and I mostly like to correlate whatever logs we see to view all the logs for the alerts.

    We have everything that involves the apps in the company within Splunk logs. We have identity logs, vishing, and phishing. We also have some remote access and a bunch of alerts. Splunk's capabilities give the opportunity to see everything and have a timeline on the alerts.

    What is most valuable?

    In my opinion, the best features Splunk Enterprise Security offers are the flexibility and the language usage.

    When I mention flexibility and language usage, I am referring to the ability to customize searches and dashboards with SPL. I customize searches and dashboards and I have been using the correlation functionality to see the detection and tuning opportunities for alerts. I also use the SPL language to extend the way I present numbers to my managers through dashboards.

    Splunk Enterprise Security has positively impacted our organization because it gives us the ability to have the information in one point. This facilitates the time we spend going through alerts and investigations. Our MTTR has been decreasing since we started using Splunk Enterprise Security.

    What needs improvement?

    I think it would be great to integrate all the capabilities that Cisco is providing to improve Splunk Enterprise Security.

    Splunk is already an expensive application, so I expect that they give enterprises the time, resources, and all the integrations that they have been providing regarding the needed improvements.

    For how long have I used the solution?

    I have been using Splunk Enterprise Security for a year and a half now.

    Buyer's Guide
    Splunk Enterprise Security
    August 2026
    Learn what your peers think about Splunk Enterprise Security. Get advice and tips from experienced pros sharing their opinions. Updated: August 2026.
    914,109 professionals have used our research since 2012.

    What do I think about the stability of the solution?

    Splunk Enterprise Security is stable.

    What do I think about the scalability of the solution?

    Splunk Enterprise Security's scalability is great and it works.

    How are customer service and support?

    The customer support for Splunk Enterprise Security is great.

    Which solution did I use previously and why did I switch?

    I had QRadar before and switched because it was in my old job.

    What other advice do I have?

    Splunk Enterprise Security's risk-based alerting (RBA) has been performing very well. It has been tuning out some of the alerts from our queues that do not indicate much malicious activity.

    I assess the threat topology and MITRE ATT&CK framework features as making the TTPs more clear and that helps me search alerts in a better way.

    The integration of threat intelligence directly into the TDIR workflow has not improved my ability to preemptively block threats yet.

    I recommend getting into the courses in Splunk University to have a better understanding of the application. I give this review a rating of nine out of ten.

    Which deployment model are you using for this solution?

    On-premises
    Disclosure: My company does not have a business relationship with this vendor other than being a customer.
    Last updated: Sep 17, 2026
    Flag as inappropriate
    PeerSpot user
    reviewer2899395 - PeerSpot reviewer
    Security Engineer at a financial services firm with 10,001+ employees
    Real User
    Top 20
    Sep 16, 2026
    Platform has improved threat intelligence dashboards and supports proactive system health monitoring
    Pros and Cons
    • "I love Splunk; it is fantastic and our account team is always willing to work with us and make sure we're getting the most for our money."

      What is our primary use case?

      My main use case for Splunk Enterprise Security is creating dashboards and general overall system health and maintenance. For system health or maintenance, I build dashboards for threat intelligence across the bank environment.

      How has it helped my organization?

      Splunk Enterprise Security has positively impacted my organization by making it easier to download and process data for findings and incidents in the environment.

      What is most valuable?

      The best features Splunk Enterprise Security offers include using Threat Intelligence Manager to organize threat intelligence data from outside sources. Threat Intelligence Manager helps me in my day-to-day work by being faster, easier, and more reliable than older options such as True Star.

      What needs improvement?

      Splunk Enterprise Security is pretty top-notch and one of the best in its class. Along with moving to the new interface, there should be more consistency across the board for all applications to improve my experience even better.

      For how long have I used the solution?

      I have been using Splunk Enterprise Security for four years.

      What do I think about the stability of the solution?

      Splunk Enterprise Security is stable.

      What do I think about the scalability of the solution?

      Splunk Enterprise Security's scalability is amazing.

      How are customer service and support?

      So far, customer support for Splunk Enterprise Security has been great.

      Which solution did I use previously and why did I switch?

      My organization has not previously used a different solution.

      How was the initial setup?

      My experience with pricing, setup cost, and licensing has been good so far, and our account team has been willing to work with us along the way.

      What about the implementation team?

      My company does not have a business relationship with this vendor other than being a customer. I was offered a gift card or incentive for this review.

      What's my experience with pricing, setup cost, and licensing?

      My experience with pricing, setup cost, and licensing has been good so far, and our account team has been willing to work with us along the way.

      Which other solutions did I evaluate?

      My organization has not evaluated other options before choosing Splunk Enterprise Security.

      What other advice do I have?

      I love Splunk; it is fantastic and our account team is always willing to work with us and make sure we're getting the most for our money. My advice to others looking into using Splunk Enterprise Security is to make sure your data is clean and to be prepared for when you actually move to Splunk. I gave this review a rating of 10.

      Which deployment model are you using for this solution?

      Public Cloud

      If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

      Other
      Disclosure: My company does not have a business relationship with this vendor other than being a customer.
      Last updated: Sep 16, 2026
      Flag as inappropriate
      PeerSpot user
      Buyer's Guide
      Splunk Enterprise Security
      August 2026
      Learn what your peers think about Splunk Enterprise Security. Get advice and tips from experienced pros sharing their opinions. Updated: August 2026.
      914,109 professionals have used our research since 2012.
      reviewer2898966 - PeerSpot reviewer
      Threat hunter at a consultancy with 51-200 employees
      Real User
      Top 20
      Sep 16, 2026
      Streamlined threat detection and alert automation has improved workflows but needs newer features
      Pros and Cons
      • "Splunk Enterprise Security offers excellent features that include constant updates with the Enterprise Security Content Update, which helps keep our detections current, and it allows for automating a lot of alerting that is important to the organization that I support."
      • "Splunk Enterprise Security has not helped improve our organization's business resilience since resilience means the ability to recover from a disaster, and we are not using it in that capacity at all."

      What is our primary use case?

      My main use case for Splunk Enterprise Security is cybersecurity for one of my government agency customers. In my role with my agency customer, we have alerts that come in, and junior analysts review them. As a senior analyst, I help develop new alerts and then triage ones that cannot be handled at the lower level or review ones that were handled to ensure they were done correctly.

      What is most valuable?

      Splunk Enterprise Security offers excellent features that include constant updates with the Enterprise Security Content Update, which helps keep our detections current, and it allows for automating a lot of alerting that is important to the organization that I support. The Enterprise Security Content Update specifically helps my team as it is a free service from Splunk's research team that provides new detections for Splunk Enterprise Security that are developed and tested by the threat research team, and they generally help support our organization in that way. From an automation perspective, we're integrating with workflow actions to other tools that are involved in our process. Splunk Enterprise Security has positively impacted our organization as it has been beneficial for us. We had been working with an internal self-developed Splunk app that was adequate, but it took a lot of effort to maintain it and to develop new analytics when necessary. Splunk Enterprise Security streamlined all of that for us.

      What needs improvement?

      Splunk Enterprise Security's improvement potential is difficult to assess since we're not currently running the latest version. There may already be features that I would want, such as the automated AI integration and other capabilities. There are pain points my team runs into, though specifying exact improvements would be challenging given my current version.

      For how long have I used the solution?

      I have been using Splunk Enterprise Security for around six to ten years.

      What do I think about the stability of the solution?

      Splunk Enterprise Security is stable in our environment.

      What do I think about the scalability of the solution?

      Splunk Enterprise Security's scalability is performing very well in our environment, and we do not have any problems with that.

      How are customer service and support?

      Splunk Enterprise Security's customer support is very good. We have excellent personnel available to help us, although we handle most of our problems in-house.

      Which solution did I use previously and why did I switch?

      We previously used an ad hoc self-built solution that roughly followed the MITRE ATT&CK framework and, prior to that, the Lockheed Martin Kill Chain. We switched because it was the next evolution and because the availability of the detections and the ease of use for our analysts to be able to respond to alerts made it the better option. We did not evaluate other options before choosing Splunk Enterprise Security.

      How was the initial setup?

      I was not involved in any of the pricing, setup cost, and licensing aspects of Splunk Enterprise Security as I am an end user analyst.

      What was our ROI?

      There is likely a return on investment, but because of my role in the organization, I would not have any metrics that would support that assessment.

      What other advice do I have?

      Splunk Enterprise Security has not helped improve our organization's business resilience since resilience means the ability to recover from a disaster, and we are not using it in that capacity at all.

      Regarding the average meantime to resolve metric, we implemented Splunk Enterprise Security a long time ago. Providing quantifiable metrics would be very difficult because it was so long ago and it was such a generational leap when we did employ it that there was really no comparison.

      We have actually chosen not to implement risk-based alerting. We are in an environment where the alerts are not so voluminous that risk-based alerting would add value to our triage and resolving.

      I would assess the threat topology and MITRE ATT&CK framework features for helping me discover the overall scope of an incident by noting that we have MITRE enabled, but in our particular environment, we do not leverage it as one would in a non-air-gapped environment. The actual use of it being able to quantify various threats through the MITRE framework does not really apply to where I am.

      Splunk Enterprise Security has helped me detect threats faster, but as I mentioned before, we implemented it so long ago, and it was such a generational leap in our ability to have quantifiable metrics on how well or how much it improved things that providing specific measurements would be inappropriate.

      I would advise others looking into using Splunk Enterprise Security to give it a try. Because of the availability of those ongoing added detections from the Enterprise Security Content Update, you will not find a better value. The time to engineer new detections is greatly reduced, especially ones that are topical and in the news. I would rate this product a seven out of ten.

      Which deployment model are you using for this solution?

      On-premises
      Disclosure: My company does not have a business relationship with this vendor other than being a customer.
      Last updated: Sep 16, 2026
      Flag as inappropriate
      PeerSpot user
      Mahmoud Younes - PeerSpot reviewer
      Cyber Security Architects at VaporVM
      Real User
      Top 5Leaderboard
      Apr 17, 2026
      Security monitoring has improved and now covers diverse attacks with rich incident management
      Pros and Cons
      • "When I compare it to different SIEM solutions, Splunk Enterprise Security has incident management and a threat intelligence component that is native and not limited the way different SIEM solutions are."
      • "The price is a significant concern. It is expensive and is designed for enterprise companies, not for small or medium-sized companies."

      What is our primary use case?

      There are a thousand use cases covered. Splunk Enterprise Security covers the MITRE ATT&CK framework for initial access, remote executions with malicious codes, and many other attack vectors. All use cases are covered by MITRE ATT&CK, including initial access, executions, discovery, and credential access.

      What is most valuable?

      When I compare it to different SIEM solutions, Splunk Enterprise Security has incident management and a threat intelligence component that is native and not limited the way different SIEM solutions are. It also has scoring features, including user scoring and correlations that the normal Splunk Enterprise doesn't have. In Enterprise, you have detection mapping to the MITRE ATT&CK framework. The GUI is very easy to use, and by using SPL, you can find or mine data easily. You can create custom dashboards. These are many benefits when compared with IBM QRadar or FortiSIEM for on-premises SIEM solutions.

      However, this solution is for enterprise companies, not for small or medium businesses. Splunk Enterprise Security has many integrations and connectors that are easy to use when compared with IBM QRadar or normal Splunk Enterprise.

      What needs improvement?

      The price is a significant concern. It is expensive and is designed for enterprise companies, not for small or medium-sized companies.

      Another area for improvement is the machine learning capabilities. There is no native AI or machine learning in Splunk when compared with different SIEM solutions. While it is there, it requires manual setup.

      For how long have I used the solution?

      I have been working with Splunk for two years.

      What do I think about the stability of the solution?

      There are no stability challenges. Even when creating a report, incident, or dashboard, or when parsing data, everything functions very smoothly. There are no challenges that I have observed.

      What do I think about the scalability of the solution?

      It is easy to scale. You can deploy it in containers or directly on-premises. It can also be used in the cloud. However, for distribution, you need some experience if you are running indexers and search heads. If you install it as an all-in-one solution, it is fine, and anyone can install it.

      How are customer service and support?

      The customer service is helpful. Even if you face something that does not have a direct solution, you can create a workaround. Issues are resolved on time.

      Which solution did I use previously and why did I switch?

      I deployed QRadar and Wazuh before.

      How was the initial setup?

      The initial setup does not take too much time. It can be completed quickly when compared with another product. The setup takes approximately 80 minutes.

      What about the implementation team?

      We are an MSSP, and we perform POCs or production implementations and recommendations for some customers. We are also a partner with Splunk. I am working with Cisco, and Cisco is a partner with Splunk.

      What was our ROI?

      For ROI measurement, I integrated Splunk with FortiSOAR. In FortiSOAR, I can calculate the ROI and the time for closing alerts. However, I have not tried this within Splunk itself.

      Which other solutions did I evaluate?

      For threat detection, I integrated Splunk with MDE and Falcon. For normal threat detection, you can enable threat feeds from MISP or SOCRadar to create rules and check if events have any malicious IOCs to trigger alerts.

      FortiSOAR and XSOAR are also alternative solutions.

      What other advice do I have?

      Even if you face something that does not have a direct solution, you can create a workaround. Issues are resolved on time. Splunk uses a very customizable SPL language. You can search easily, and for me, it is better than EQL in Sentinel or IBM QRadar. I would rate this product a 10.

      Which deployment model are you using for this solution?

      On-premises
      Disclosure: My company has a business relationship with this vendor other than being a customer. MSP
      Last updated: Apr 17, 2026
      Flag as inappropriate
      PeerSpot user
      Jason Ogresovich - PeerSpot reviewer
      Principal Threat Detection Engineer at a transportation company with 10,001+ employees
      Video Review
      Real User
      Top 10
      Sep 13, 2025
      Has accelerated detection workflows and enabled timely alert triage across multiple data anchors
      Pros and Cons
      • "I would assess the stability and reliability of Splunk Enterprise Security as very reliable and very stable."
      • "Splunk Enterprise Security can be improved by addressing the content management interface, which is very outdated, slow, and clunky; sometimes we think things are saved and they haven't."

      What is our primary use case?

      As a threat detection engineer, my main use case for Splunk Enterprise Security is to create content to find anomalous activity in our environment. Splunk Enterprise Security, via the content management interface, allows us to create correlation searches, take advantage of summary indexes where we can correlate multiple findings per host, per user, whatever anchor point you want to use, and get those alerts to our analysts in a timely manner, where they can be triaged based on alert severity and criticality.

      What is most valuable?

      The notable feature of Splunk Enterprise Security, which in version 8 is going to be called "findings," is the ability to send notables, and all the actions that can be chained with the notable when you actually have a hit or a finding.

      The ability to quickly automate detections based on alerts or intelligence that we operationalize in the environment benefits my company, as we get that alert sent to the appropriate parties and put in front of the analysts quickly, allowing for triage and the ability to group the alerts together instead of just always looking at a single finding.

      What needs improvement?

      Splunk Enterprise Security can be improved by addressing the content management interface, which is very outdated, slow, and clunky; sometimes we think things are saved and they haven't. Being able to edit saved content and saved searches in batch, such as when you have a log source and a field changes, is a pain point right now since you have to go in and basically update all of them unless you do some kind of Eval on the ingestion side; that's probably the biggest pain point with it right now.

      What do I think about the stability of the solution?

      I would assess the stability and reliability of Splunk Enterprise Security as very reliable and very stable.

      What do I think about the scalability of the solution?

      Splunk Enterprise Security scales very well with the growing needs of our company, although there are definitely some things that are behind the times, such as some of the limitations out of the box on KV Stores, lookups, and some of the commands, the MV line of commands and some of the limitations there. Hopefully, with the advent of all the cool AI and ML capabilities coming down in the 8 series, many of those limitations will be eliminated.

      How are customer service and support?

      Regarding customer service and technical support, I don't generally submit support tickets, however, I have on a few occasions. It's usually our Splunk engineering team.

      We have bimonthly meetings with our account representatives, and we have some sort of on-call technical staff that are assigned to our company and our contract, and they've all been excellent; wonderful people to work with.

      How would you rate customer service and support?

      Positive

      Which solution did I use previously and why did I switch?

      Prior to adopting Splunk Enterprise Security, I used another solution that does similar things, and over the course of my career, I've used a couple of different solutions, peer solutions with Splunk, but Splunk Enterprise Security is the best.

      It really comes down to the versatility and how powerful it is; I have never worked with another platform where I can do as much for as many teams, not even just security, which is my primary focus, and the value that you can get out of it, I've never seen a platform that versatile.

      What was our ROI?

      From my point of view, the biggest return on investment when using Splunk Enterprise Security is keeping our company safe.

      What other advice do I have?

      The advice I would give to other companies that are considering Splunk Enterprise Security is that if you've never used Splunk, it can be a little daunting at first, learning a new language, Splunk SPL. That said, it's worth it.

      The cycle time that's going to be taken in training and upskilling, once your staff is familiar with that, and you don't even have to do a lot of training, just a couple of the basic classes from Splunk University to get proficient, it's going to open a lot of doors.

      On a scale of one out of ten, I rate Splunk Enterprise Security a nine out of ten.

      Disclosure: My company does not have a business relationship with this vendor other than being a customer.
      PeerSpot user
      reviewer2755848 - PeerSpot reviewer
      Cyber Security Engineer at a government with 1,001-5,000 employees
      Real User
      Top 10
      Sep 11, 2025
      Case management improves incident response but the user interface remains a daily challenge
      Pros and Cons
      • "I evaluate customer service and technical support as great."
      • "Splunk Enterprise Security is probably one of the first products that actually could handle all the ingest and do all the correlation without crumbling under its own weight."
      • "To improve Splunk Enterprise Security, I would suggest allowing third-party SOAR solutions to work with it."
      • "The user interface feels clunky to navigate and interact with in Splunk Enterprise Security compared to other case management solutions where it feels easier to use at a high level."

      What is our primary use case?

      My main use case for Splunk Enterprise Security is incident response.

      What is most valuable?

      The feature I appreciate the most in Splunk Enterprise Security is the case management, although I have more critiques for the case management than favorite features. Having case management in Splunk Enterprise Security is something I appreciate since we needed a way to centrally manage all of our incidents. 

      Having case management in Splunk Enterprise Security has really benefited our organization.

      What needs improvement?

      To improve Splunk Enterprise Security, I would suggest allowing third-party SOAR solutions to work with it. The most significant challenges I face when using Splunk Enterprise Security for advanced threat detection include the user interface, which isn't terribly intuitive, and it has been a process to get people to adopt it and use it as much as they should.

      The user interface feels clunky to navigate and interact with in Splunk Enterprise Security compared to other case management solutions where it feels easier to use at a high level. In Splunk Enterprise Security, the way you click through everything, attach stuff, and interact with other analysts feels cumbersome, with a lot of digging required to get into things; not everything is just one click away—things are usually three clicks away. 

      The process of extending the usage of Splunk Enterprise Security is still bumpy; the user experience is really the challenge there, as many of our analysts complain about its difficulty for day-to-day use.

      For how long have I used the solution?

      I have been using Splunk Enterprise Security for about three years.

      What do I think about the stability of the solution?

      I have not experienced any downtime, crashes, or performance issues with Splunk Enterprise Security. Although we occasionally receive emails from Splunk about performance issues, they are typically resolved quickly, and the system appears to be running smoothly.

      What do I think about the scalability of the solution?

      Splunk Enterprise Security scales effectively with the growing needs of my organization and there are no issues.

      How are customer service and support?

      I evaluate customer service and technical support as great; our support team is fantastic, and we have regular cadence with our support teams and our representatives.

      How would you rate customer service and support?

      Positive

      Which solution did I use previously and why did I switch?

      Before adopting Splunk Enterprise Security, we were using several different SIM products to address similar needs, but I disliked them all; none of them really worked and they all crumbled under the ingest load. 

      One product required us to completely sever logs since it couldn't compute; it was pretty bad. Splunk Enterprise Security is probably one of the first products that actually could handle all the ingest and do all the correlation without crumbling under its own weight.

      How was the initial setup?

      I would describe my experience with deploying Splunk Enterprise Security as easy, mainly because we use the cloud version; since it's Splunk Cloud, we didn't have to do much to deploy it, and we don't do a deployment in the cloud—it's managed.

      What about the implementation team?

      I have a team that customizes, develops, tests, deploys, and refines detections in Splunk Enterprise Security; I don't do that personally, so I cannot talk extensively to that process, however, we go through a process to do that and I haven't heard many complaints about it.

      What was our ROI?

      I have seen a return on investment with Splunk Enterprise Security. Incident response, along with triaging and increased efficiency, has been a notable example of return on investment.

      What's my experience with pricing, setup cost, and licensing?

      It would always be great if Splunk Enterprise Security was cheaper; we definitely hit limits frequently with our ingest. I'm planning to explore the SVC model soon to see what that looks like. We're able to get what we need with what we have and can afford, so I'm satisfied.

      Which other solutions did I evaluate?

      We do not purchase this product on AWS Marketplace; instead, we get it directly from Splunk, or we go through a VAR.

      What other advice do I have?

      My advice to other organizations considering Splunk Enterprise Security is to make sure you understand all the functionality of it, not just what they show you, but also the integration points; understand the automation side of it and get a good holistic understanding before making a decision. 

      On a scale of one to ten, I rate this solution a seven out of ten.

      Which deployment model are you using for this solution?

      Public Cloud

      If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

      Disclosure: My company does not have a business relationship with this vendor other than being a customer.
      PeerSpot user
      Security Consultant at Matiq
      Consultant
      Top 20
      Jun 12, 2025
      Reduces manual intervention and enables comprehensive security monitoring with risk-based insights
      Pros and Cons
      • "The features of Splunk Enterprise Security that I have found most valuable include the risk-based score and UBA/UEBA, user behavior analytics, or user and entity behavior analytics."
      • "Areas of Splunk Enterprise Security that could be improved include the need for training and certifications. We are planning to do certifications, and there are many features, such as risk-based score and score detection, where the current training doesn't provide visibility to the analyst."

      What is our primary use case?

      My usual use cases for Splunk Enterprise Security involve creating notables, use cases, and dashboards. We are creating the use cases as per the defense of depth in all the security layers, such as the network layer or data link layer, DLP protection, and network protection. We are using firewalls and proxy, as well as IPS, and we are using Defender as Cloud App Security of 365 and EDR. We are using Defender as a single pane of glass, collecting all the logs from all the security devices, writing the correlation rules, configuring the notables, and monitoring 360 degrees of the organization's security.

      How has it helped my organization?

      It is a comprehensive solution with many security-related features. The data enrichment feature helps identify any anomalies from devices and users. It helps identify any malicious activity patterns, risks, or login failures. 

      We have implemented conditional policies where traffic from certain countries gets blocked. We are utilizing the Splunk Machine Learning Toolkit (MLTK) app to create models for automatic actions or remediation. We are trying to catch the true positive incidents and orchestrate a response. We have created two models to identify brute force attacks and user login failures.

      What is most valuable?

      The features of Splunk Enterprise Security that I have found most valuable include the risk-based score and UBA/UEBA, user behavior analytics, or user and entity behavior analytics. Based on this feature, we can identify anomalies in any activity from the user or device. 

      It serves as a single pane of glass for all the security-related events. It helps cross-correlate with minimal manual intervention, detect true positives, and take remediation steps in an orchestrated manner. It is very efficient. It's a top solution in Gartner Quadrants and Datamatics.

      What needs improvement?

      Areas of Splunk Enterprise Security that could be improved include the need for training and certifications. We are planning to do certifications, and there are many features, such as risk-based score and score detection, where the current training doesn't provide visibility to the analyst. They should offer training based on the features we use. For any future enhancements or features, such as MLTK and SOAR platform integration, we need more visibility, training, and certification for the skilled professionals who are working.

      For how long have I used the solution?

      I have been working with Splunk Enterprise Security for seven years.

      What do I think about the stability of the solution?

      This solution is stable. The platform and the applications we are dealing with are stable and maintain high availability both on-prem and cloud.

      What do I think about the scalability of the solution?

      Scalability-wise, we find it comfortable. It's convenient to scale up or scale down the licenses or the components in the cloud.

      How are customer service and support?

      When we require support from the Splunk Enterprise Security team, if we raise a request, they respond based on priority, providing recommendations or best practices as per the platform recommendations.

      How would you rate customer service and support?

      Positive

      Which solution did I use previously and why did I switch?

      I work with multiple customers. They use different products, such as Trend Micro XDR. The customer I am working with right now is using Splunk Enterprise Security. It was chosen by the customer.

      How was the initial setup?

      For deploying Splunk Enterprise Security, we follow a cluster environment for high availability and high performance, maintaining an architecture with several search heads, indexers, and forwarders. Data is pushed from all forwarders to the indexers, which are heavy forwarders where indexing, parsing, and normalization are performed. Once it is done, we search the data through search heads, with a license master and deployment server present to push configurations to all components of Splunk Enterprise Security. It's a distributed and clustered environment we are maintaining.

      What was our ROI?

      We have seen a return on investment. We are getting more security. We are able to secure the environment from all security threats and maintain an environment that is free from threats and attacks, especially cyberattacks.

      What's my experience with pricing, setup cost, and licensing?

      Pricing and licensing are quite high compared to other tools or SIEM tools, but the features justify it.

      What other advice do I have?

      Overall, I would rate Splunk Enterprise Security a nine out of ten.

      Which deployment model are you using for this solution?

      Public Cloud

      If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

      Disclosure: My company does not have a business relationship with this vendor other than being a customer.
      PeerSpot user
      RajKumar27 - PeerSpot reviewer
      Information Security Analyst at a hospitality company with 5,001-10,000 employees
      Video Review
      Real User
      Top 10
      Sep 13, 2025
      Enables our team to automate threat detection and prioritize incidents through risk-based alerting
      Pros and Cons
      • "I appreciate the Identity and Assets framework the most, as well as the threat analysis framework."
      • "To improve Splunk Enterprise Security, I suggest incorporating more AI features for faster remediation and enhanced responses, allowing users to build more correlation searches quickly."

      What is our primary use case?

      My main use cases for Splunk Enterprise Security include finding out excessive login failures, any compromised accounts, any compromised emails using phishing tactics with Proofpoint, network anomalies, User Behavior Analysis, and detecting rogue assets.

      What is most valuable?

      I appreciate the Identity and Assets framework the most, as well as the threat analysis framework. Those are my two favorites in Splunk Enterprise Security, along with correlation searches and the entire incident response workflow.

      The Risk-Based Alerting in Splunk Enterprise Security is a great addition to our team, as it correlates data from different sources and adds scores to users or systems, allowing us to make decisions based on risk scores assigned to assets or identities.

      Splunk Enterprise Security dashboards communicate our security posture and risk score to executives, including major contributing risk factors, key performance indicators (KPIs), and key risk indicators, which help us make informed decisions about future focus areas.

      Splunk Enterprise Security helps our team save time by performing correlation searches automatically, eliminating the need for manual searches. We also utilize SOAR for taking automated remediation responses.

      What needs improvement?

      To improve Splunk Enterprise Security, I suggest incorporating more AI features for faster remediation and enhanced responses, allowing users to build more correlation searches quickly. Regarding improvements in Enterprise Security, I believe the incorporation of AI would enable Splunk users to spend less time on building correlation searches while still gaining productive ideas.

      For how long have I used the solution?

      I have over eight-plus years of experience working in the IT sector, with six-plus years of experience collectively working on security and Splunk-related tasks.

      What do I think about the stability of the solution?

      I would assess the stability and reliability of Splunk Enterprise Security at 90%.

      What do I think about the scalability of the solution?

      The scalability of Splunk Enterprise Security is impressive, as you can scale it to any size and make various types of data readable, although event types and tagging are necessary for optimal performance.

      How are customer service and support?

      Customer service and technical support for Splunk Enterprise Security are great; they respond quickly and handle our cases efficiently whenever we require assistance.

      How would you rate customer service and support?

      Positive

      Which solution did I use previously and why did I switch?

      I used Splunk Enterprise Security at my previous company yet have not used any different products since then, although I have some knowledge about platforms such as Elastic Search and QRadar.

      How was the initial setup?

      The challenges with deployment are the fine-tuning and some of the correlations, such as where the data is not normalized. And that's why the CIM module has been great so far.

      What was our ROI?

      The biggest return on investment with Splunk Enterprise Security lies in the time and effort it saves due to its built-in features, datasets, and pre-built dashboards, providing us with visibility across different data sources.

      What other advice do I have?

      My advice for other companies considering Splunk Enterprise Security is that if they're looking to enhance their security visibility or establish a security operation center, this tool is an excellent starting point, and they can scale and automate processes using SOAR effectively.

      On a scale of one to ten, I rate this solution an eight.

      Which deployment model are you using for this solution?

      Public Cloud
      Disclosure: My company does not have a business relationship with this vendor other than being a customer.
      PeerSpot user
      Sheenam Singla - PeerSpot reviewer
      SAP Roles and Authorization Consultant at a tech vendor with 10,001+ employees
      Real User
      Top 5
      Sep 11, 2025
      Supports faster incident response and improved threat detection through flexible customization options
      Pros and Cons
      • "The features of Splunk Enterprise Security that I appreciate the most are its flexibility and scalability."
      • "The features of Splunk Enterprise Security that I appreciate the most are its flexibility and scalability, as it integrates disparate security solutions, offers many out-of-the-box apps through Splunkbase, enables straightforward customization, and supports efficient detection and alerting processes that improve overall business resilience."
      • "Splunk Enterprise Security can be improved by having more focus on the data health monitoring aspect, which will definitely be helpful."

      What is our primary use case?

      My main use cases for Splunk Enterprise Security are mostly for SOC, detection engineering, and incident response.

      How has it helped my organization?

      Splunk features benefit my organization as we can use it for any custom needs. That's the biggest benefit of getting it. It doesn't matter what team has what kind of requirements. There's a possibility through Splunk's back-end that we can customize it and make it work.

      What is most valuable?

      The features of Splunk Enterprise Security that I appreciate the most are its flexibility and scalability. 

      I use disparate security solutions that integrate or import data into Splunk Enterprise Security. This integration supports my security operations, as one of the biggest advantages is that Splunk Enterprise Security comes with many apps and applications out of the box through Splunkbase, and there's essentially a connector available for any log source imaginable.

      I find the process of customizing, developing, testing, deploying, and refining detections in Splunk Enterprise Security pretty straightforward overall. There's a lot of out-of-box content that can be leveraged and many features available to ensure all configurations are working as expected.

      My organization uses risk-based alerting in Splunk Enterprise Security. It supports our SOC by significantly reducing the alert count and allowing analysts to focus on what matters most.

      My SecOp team's remediation time for security incidents with Splunk Enterprise Security is definitely faster than other solutions.

      I am utilizing new threat detection features in Splunk Enterprise Security, specifically the Assets and Identity Framework and risk-based alerting. These features have improved efficiency and helped reduce false positive counts.

      Splunk Enterprise Security has helped improve my organization's business resilience. The flexible pricing models allow us to pick and choose, and I can easily see how different business units are consuming Splunk Enterprise Security, thereby distributing the cost within the organization.

      I have recently expanded my usage, and the process was smooth.

      What needs improvement?

      Splunk Enterprise Security can be improved by having more focus on the data health monitoring aspect, which will definitely be helpful. A good out-of-box application that can help monitor if the data feeds are feeding in properly or if there is any drop will really help make life easier.

      For how long have I used the solution?

      I have been using Splunk Enterprise Security for six years now.

      What do I think about the stability of the solution?

      I would assess the stability and reliability of Splunk Enterprise Security in terms of downtime, crashes, and performance issues, as there are no issues with the availability of the platform since it's cloud-based.

      What do I think about the scalability of the solution?

      Splunk Enterprise Security scales with the growing needs of my organization as it's highly scalable. As the organization grows, Splunk Enterprise Security can also grow.

      How are customer service and support?

      I would evaluate customer service and technical support as good.

      How would you rate customer service and support?

      Positive

      Which solution did I use previously and why did I switch?

      I was mostly using Splunk Enterprise Security.

      How was the initial setup?

      I would describe my experience with deploying Splunk Enterprise Security as time-consuming. It definitely needs some planning and time to ensure that everything is set up and configured properly.

      What was our ROI?

      I have seen return on investment with Splunk Enterprise Security.

      What's my experience with pricing, setup cost, and licensing?

      Im not on the licensing side. 

      What other advice do I have?

      The most significant challenges I face when using Splunk Enterprise Security for advanced threat detection are that it takes some time to get the hang of the platform, and it has a slight learning curve associated with it. Other than that, I have no complaints.

      The advice I would give to other organizations considering Splunk Enterprise Security is to try it out and see if it fits their requirements. It's highly flexible, highly customizable, and can scale according to needs.

      On our rating scale, I give Splunk Enterprise Security an eight out of ten.

      Which deployment model are you using for this solution?

      Public Cloud

      If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

      Other
      Disclosure: My company does not have a business relationship with this vendor other than being a customer.
      PeerSpot user
      Derek Scott - PeerSpot reviewer
      Information System Security Officer at SAIC
      Video Review
      Real User
      Top 5
      Sep 11, 2025
      Risk-based alerting and custom dashboards transform communications and detect threats
      Pros and Cons
      • "The stability and reliability of Splunk Enterprise Security is outstanding. It's a software and product that anybody can really pick up and use."
      • "Combating insider threats and advanced persistent threats is an amazing feature of Splunk Enterprise Security, and it gives us the visibility that we need for those detections that other software doesn't have."
      • "I'm not as familiar as I should be to answer how Splunk Enterprise Security can be improved, however, one of the improvement points that Enterprise Security could offer is on-prem training."
      • "One of the improvement points that Enterprise Security could offer is on-prem training, the availability to have a Splunk representative come out to different sites and actually sit down with the organizations and help them understand."

      What is our primary use case?

      Many of my use cases for Splunk Enterprise Security involve integrating with our networks and systems to troubleshoot and streamline our capabilities.

      What is most valuable?

      One of the features of Splunk Enterprise Security that I really enjoy is the ability to have the scalability of the product and the moldability that's really customized to meet our specific needs. 

      The flexibility of Splunk Enterprise Security is beneficial, and that feature, while a broad statement, is crucial in itself, as it allows us to design our own environments with the flexibility and malleability needed to function effectively.

      Splunk Enterprise Security's Risk-Based Alerting or RBA has been really amazing. We're still new at it, however, it's definitely nice to be able to have those results at your fingertips instead of having to search what you need to.

      Using Splunk Enterprise Security's dashboards to communicate security posture to executives is probably one of the nicest things that Splunk offers. Not everyone is as skilled with the inner workings of the system as we are in my industry, so being able to put a visualization on there is critical.

      The ability of Splunk Enterprise Security to ingest data has been amazing for our threat detection. Combating insider threats and advanced persistent threats is an amazing feature of Splunk Enterprise Security, and it gives us the visibility that we need for those detections that other software doesn't have.

      The stability and reliability of Splunk Enterprise Security is outstanding. It's a software and product that anybody can really pick up and use.

      What needs improvement?

      I'm not as familiar as I should be to answer how Splunk Enterprise Security can be improved, however, one of the improvement points that Enterprise Security could offer is on-prem training, the availability to have a Splunk representative come out to different sites and actually sit down with the organizations and help them understand.

      For how long have I used the solution?

      I've been using Splunk Enterprise Security for about a year to a year and a half now.

      How are customer service and support?

      I handle most things in-house, however, I evaluate Splunk Enterprise Security's technical support and service as outstanding based on the few times we've had to contact them.

      How would you rate customer service and support?

      Positive

      How was the initial setup?

      My experience with deploying Splunk Enterprise Security is that the deployment process is pretty straightforward, especially once you have the certifications and you understand how the process works. I'd say it goes back to the training opportunities; some people are unfamiliar with it, so a little bit of support would be appreciated sometimes.

      What was our ROI?

      Splunk Enterprise Security has definitely reduced the amount of time that it takes us to detect and respond. I would say the percentage lowered by using Splunk Enterprise Security is around 25 to 30%.

      What's my experience with pricing, setup cost, and licensing?

      I understand how the pricing, the setup costs, and the licensing of Splunk Enterprise Security work, however, I personally don't have knowledge of the numerical values.

      What other advice do I have?

      I'd give Splunk Enterprise Security a rating of ten out of ten. 

      My advice to other companies considering Splunk Enterprise Security is to just do it. Don't look at any of the competitors; Splunk, hands down, is the product that I would recommend to other companies.

      Disclosure: My company does not have a business relationship with this vendor other than being a customer.
      PeerSpot user
      Buyer's Guide
      Download our free Splunk Enterprise Security Report and get advice and tips from experienced pros sharing their opinions.
      Updated: August 2026
      Buyer's Guide
      Download our free Splunk Enterprise Security Report and get advice and tips from experienced pros sharing their opinions.