I use other types of security solutions that integrate or import data into Splunk Enterprise Security, such as EDRs, firewalls, and other security products. The integration supports my security operations by providing one clear view of threat detections from firewalls and imported data.
Security Analyst at a computer software company with 51-200 employees
Out-of-the-box detections have supported threat identification while integration consolidates alerts from multiple sources
What is our primary use case?
What is most valuable?
The features of Splunk Enterprise Security that I appreciate the most are out-of-the-box detections. These features have benefited my organization because it's a product we sell, and we sell detecting threats in the organization.The features have benefited the organizations I sell to because without them a lot would have been self-programmed, and they support us in very different ways.
What needs improvement?
It's difficult to answer how Splunk Enterprise Security can be improved because I'm hearing AI mentioned frequently in the keynote. It's definitely out there and it's improving the whole process. I think that a lot of effort is going into the realization of AI, but some effort is left out because they don't always mention that the outcome has to always be verified. You just say, 'Ask AI to narrow down the threats, show me how to write an email, summarize it up,' but the additional process that comes with it is verifying it all. Maybe question it, and sometimes it's wrong and you have to start over. I think improving it would be either having different AI responses to cover more, or always having to verify the user, not relying on an answer.
The most significant challenges I face when using Splunk Enterprise Security for advanced threat detection are not in the product; they're in the human aspect. Writing the query and knowing what to search for is not a product problem.
For how long have I used the solution?
I have been using Splunk Enterprise Security for two years.
Buyer's Guide
Splunk Enterprise Security
August 2026
Learn what your peers think about Splunk Enterprise Security. Get advice and tips from experienced pros sharing their opinions. Updated: August 2026.
914,109 professionals have used our research since 2012.
How are customer service and support?
I would evaluate customer service and technical support for Splunk Enterprise Security as good on a scale of one to 10.
How was the initial setup?
My experience with pricing, setup cost, and licensing is that it's expensive.
What's my experience with pricing, setup cost, and licensing?
I think the value of Splunk Enterprise Security is there, but it is one of the most expensive solutions on the market.
What other advice do I have?
My organization uses risk-based alerting in Splunk Enterprise Security, which supports our SOC by negating through false positives. On a scale of one to 10, I would rate Splunk Enterprise Security an eight.
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
Manager at a tech vendor with 1,001-5,000 employees
Access to critical network security insights has improved and supports faster incident response
Pros and Cons
- "Based on my experience and what I have heard, the customer support for Splunk Enterprise Security is excellent."
- "I think Splunk Enterprise Security can be improved because sometimes it is difficult to make sense of the data that is provided to me. The amount of information makes the data hard to interpret, and I feel the niche content is hard to find."
What is our primary use case?
My main use case for Splunk Enterprise Security is network security.
What is most valuable?
In my opinion, the best feature that Splunk Enterprise Security offers is ease of access. When I say ease of access, I mean it is about how quickly we can get to the information we need.
What needs improvement?
I think Splunk Enterprise Security can be improved because sometimes it is difficult to make sense of the data that is provided to me. The amount of information makes the data hard to interpret, and I feel the niche content is hard to find.
For how long have I used the solution?
Our company has been using Splunk Enterprise Security for a few years.
What do I think about the stability of the solution?
Splunk Enterprise Security is stable based on my experience.
What do I think about the scalability of the solution?
From what I have seen, Splunk Enterprise Security's scalability is adequate.
How are customer service and support?
Based on my experience and what I have heard, the customer support for Splunk Enterprise Security is excellent.
What other advice do I have?
My advice to others looking into using Splunk Enterprise Security is that it is definitely built for enterprises and contains a substantial amount of information. We are an integration platform as a service, so we use Splunk Enterprise Security's APIs and have a business relationship with this vendor. The reason I chose a rating of eight out of ten is mainly due to the amount of information provided; I feel you really have to dig extensively and sometimes even use third-party systems to make sense of what you are seeing.
I rate this product eight out of ten.
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Amazon Web Services (AWS)
Disclosure: My company has a business relationship with this vendor other than being a customer. Integration Platform as a Service
Last updated: Sep 16, 2026
Flag as inappropriateBuyer's Guide
Splunk Enterprise Security
August 2026
Learn what your peers think about Splunk Enterprise Security. Get advice and tips from experienced pros sharing their opinions. Updated: August 2026.
914,109 professionals have used our research since 2012.
Solutions Diretor at a computer software company with 51-200 employees
Risk-based alerting has improved detection efficiency and supports faster remediation
Pros and Cons
- "On average, my security ops team takes fairly quickly to remediate security incidents with Splunk Enterprise Security, depending on the use case, minutes versus hours, compared to my previous solution, which was ArcSight."
- "Splunk Enterprise Security could be cheaper."
What is our primary use case?
My main use cases for Splunk Enterprise Security are security, general security, and SIM.
What is most valuable?
The feature I appreciate the most in Splunk Enterprise Security is RBA. These features in Splunk Enterprise Security help my organization contextualize security alerts and put them in a framework that makes sense for our customers.
My organization uses risk-based alerting in Splunk Enterprise Security. Risk-based alerting in Splunk Enterprise Security supports my SOC by giving me a holistic view of what's happening and prioritizing alerts based on various risk factors that are important to me.
The most significant challenges I face when using Splunk Enterprise Security for advanced threat detection are zero-day events. I use disparate security solutions that integrate or import data into Splunk Enterprise Security. This integration supports my security operations by giving me a holistic view of what's happening in my environment. I find the process of customizing, developing, testing, deploying, and refining detections in Splunk Enterprise Security easier than other platforms.
On average, my security ops team takes fairly quickly to remediate security incidents with Splunk Enterprise Security, depending on the use case, minutes versus hours, compared to my previous solution, which was ArcSight.
Splunk Enterprise Security has helped improve my organization's business resilience.
My impressions of Splunk Enterprise Security's ability to predict, identify, and solve problems are good. I would say to other organizations considering Splunk Enterprise Security to solve your data challenges first and focus on data quality, and then everything else will work with your infrastructure.
What needs improvement?
Splunk Enterprise Security could be cheaper. More artificial intelligence implementation for features should be included in the next release of Splunk Enterprise Security.
For how long have I used the solution?
I have been using Splunk Enterprise Security for nine years.
What do I think about the stability of the solution?
Splunk Enterprise Security is very reliable. I have not experienced any downtime, crashes, or glitches with Splunk Enterprise Security.
What do I think about the scalability of the solution?
Splunk Enterprise Security scales efficiently with the growing needs of my organization. I have expanded usage, and the process was very smooth.
How are customer service and support?
I would evaluate customer service and technical support as pretty good. There is a good community.
On a scale of one to ten, I would rate customer service an eight.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
Prior to adopting Splunk Enterprise Security, I was using ArcSight to address similar needs.
How was the initial setup?
I would describe my experience with deploying Splunk Enterprise Security as easy. I deploy it all the time, so it's easy for me.
What was our ROI?
I have seen a return on investment with Splunk Enterprise Security.
What's my experience with pricing, setup cost, and licensing?
I don't deal with pricing, setup cost, and licensing mainly; however, everyone says it's pricey.
Which other solutions did I evaluate?
I was using ArcSight, and the factor to change was that it could not accept all the data.
What other advice do I have?
On a scale of one to ten, I would rate Splunk Enterprise Security an eight.
Which deployment model are you using for this solution?
Hybrid Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Disclosure: My company has a business relationship with this vendor other than being a customer. Partnrr
Issm at a government with 10,001+ employees
Video Review
Prioritizes critical threats and improves collaboration across teams for faster incident response
Pros and Cons
- "Splunk Enterprise Security helps my SOC team prioritize and investigate high-fidelity alerts more effectively by enabling us to quickly gather information, collaborate, and provide various teams with access to the same information, allowing them to follow the workflow to complete the task."
- "Splunk Enterprise Security can improve in terms of probably being able to talk to additional sources."
What is our primary use case?
My main use cases for Splunk Enterprise Security are insider threat, application security, incident response, and risk forecasting.
What is most valuable?
I appreciate the ability of Splunk Enterprise Security to tap into various network equipment and services on the network to pull it all into one place. That's my favorite feature.
The feature I've mentioned helps us in responding to incidents and disasters and different technical situations by being able to pull data from various sources and analyze it and take action.
Splunk Enterprise Security's Risk-Based Alerting, or RBA, has enabled us to prioritize and focus on the most critical threats and issues, while blocking out some of the noise and various information that can come from all these different sources.
Splunk Enterprise Security helps my SOC team prioritize and investigate high-fidelity alerts more effectively by enabling us to quickly gather information, collaborate, and provide various teams with access to the same information, allowing them to follow the workflow to complete the task.
Splunk Enterprise Security's ability to ingest and normalize data from diverse sources has enhanced our threat detection capabilities by making us aware of what's going on in the world, relating to our use cases and our threat tolerance, as we constantly pull in that information and brief everyone who has a stake.
What needs improvement?
Splunk Enterprise Security can improve in terms of being able to add to additional sources. They're adding many different ones, but as more cloud and data lakes emerge, being able to touch all those different new technologies that emerge together would be beneficial.
What do I think about the stability of the solution?
I assess the stability and reliability of Splunk Enterprise Security as very reliable and stable so far. We haven't had any glitches with testing out the first pilot use of it.
What was our ROI?
From my point of view, the biggest return on investment when using Splunk Enterprise Security is definitely being able to respond to incidents faster, adapt to future attacks by analyzing that information and doing risk-based management decisions, and also preparing for the future by looking at new technologies that can help us.
What's my experience with pricing, setup cost, and licensing?
I'm not too involved with the pricing, the setup costs, and the licensing of the platform. It is pretty straightforward.
What other advice do I have?
We just started turning on UEBA in our company, but we haven't really started utilizing it yet. There is a roadmap to try to do some of that stuff from the program side, and we just have to get access to it once the enterprise is ready to implement it and hand it over to the program office.
Even though we just started using UEBA, it's very useful, and it helps us set a bar for what normal activity is, and then it sets alerts and gives us awareness for anything that's out of the norm in terms of normal user behavior and the data that's being accessed.
My advice to other companies considering Splunk Enterprise Security is that you should definitely look into it, get your folks a proof of concept and try it out, send folks to training, and let them learn about it, and see how it can help you be better at securing your environment.
I rate Splunk Enterprise Security nine out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Dir Security Ops at a government with 10,001+ employees
Has improved incident detection and reduced SOC response times with a unified dashboard
Pros and Cons
- "The feature I appreciate the most about Splunk Enterprise Security is the dashboard."
- "The correlation of events is the most significant challenge I face when using Splunk Enterprise Security for advanced threat detection."
What is our primary use case?
My main use cases for Splunk Enterprise Security are threat alerts.
What is most valuable?
The feature I appreciate the most about Splunk Enterprise Security is the dashboard. It has supported my SOC by making their job easier regarding notifications. It also reduces the time they have to spend using other tools to help them out, cutting down on their workload.
When it comes to incidents, we are able to detect, monitor, and handle incidents that come in. We can take those incidents and correlate them to other tools that we use. It serves as our single pane of focus.
Our security ops team's remediation time with Splunk Enterprise Security is measured in minutes. One notable improvement has been the maturation of our SOC, which now features a single pane of glass for incident viewing.
What needs improvement?
The correlation of events is the most significant challenge I face when using Splunk Enterprise Security for advanced threat detection. I am still looking at version 8 to see how it can be improved or how we can utilize it better.
For how long have I used the solution?
I have been using Splunk Enterprise Security for three years.
What do I think about the stability of the solution?
I assess the stability and reliability of Splunk Enterprise Security as having some issues because we have problems with our SC4S. We are working through it. There are some things that we need to troubleshoot, but we are addressing those.
What do I think about the scalability of the solution?
It is easy to scale Splunk Enterprise Security, and the plan is to expand it, however, we are in the planning stages right now. My experience with scaling has been smooth.
How are customer service and support?
I evaluate customer service and technical support as good, with no issues.
On a scale of one to ten, I would rate customer service and technical support an eight.
How would you rate customer service and support?
Positive
How was the initial setup?
My experience with pricing, setup costs, and licensing is that they are expensive and growing, but that is really above my level. Our C suite handles more of the pricing aspects.
What about the implementation team?
I find the process for customizing, developing, testing, deploying, and refining detections in Splunk Enterprise Security not overly complicated because we use Splunk resources to help us with this. It is not as challenging as we would think it would be.
What was our ROI?
I have seen a return on investment with Splunk Enterprise Security.
Which other solutions did I evaluate?
I use other security solutions that integrate or import data into Splunk Enterprise Security such as CrowdStrike, Proofpoint, and a threat intel platform called ThreatConnect.
What other advice do I have?
My advice to other organizations considering Splunk Enterprise Security is to weigh their options, but I would definitely recommend it.
On a scale of one to ten, I rate Splunk Enterprise Security an eight.
Which deployment model are you using for this solution?
Public Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Senior Information Technology Security Consultant at Mideast Data Systems
Saves a lot of time with powerful alerting and notification mechanism
Pros and Cons
- "I would definitely recommend Splunk Enterprise Security because if you are really concerned about security and want to follow compliance rules, this product is really helpful."
- "We can only increase the environment. For instance, with an ES server, we cannot make a cluster of ES. If you have two servers and want to make a cluster of these two servers for ES, that is not possible."
What is our primary use case?
Our purpose for using Splunk Enterprise Security is SIEM.
How has it helped my organization?
Machine learning has been incredibly beneficial in our efforts to detect various threats. For example, we pull all security logs and utilize the MLTK framework, which helps us identify potential risks effectively. So, overall, it's been quite helpful.
We use the risk-based alerting feature. For instance, when it detects a failed login attempt, it assigns a risk score to it. This allows us to utilize the risk-based alerting features effectively to prioritize incidents based on their severity.
Risk-based alerting generates notifications based on the level of risk associated with a transaction. This approach effectively assists in monitoring transactions, such as payments. It allows us to track the progress of a transaction, from initiation to completion, and identify any errors that may occur during the process. If there are numerous errors, we can assess the risk and determine whether the transaction might be a false positive.
Splunk Enterprise Security has been very helpful in this regard. However, I've noticed that improvement is still needed. We need to analyze the data more thoroughly. While this can be quite complex, finding a simpler solution would be beneficial.
What is most valuable?
The best features of Splunk Enterprise Security are the correlation rules and automation over the correlation rules. We can trigger alerts and notifications. The alerting and notification mechanism is really powerful and good.
What needs improvement?
It needs more AI integration. The threat intelligence framework requires some AI functionality, which would be helpful.
For how long have I used the solution?
We have been using Splunk Enterprise Security for a couple of years, and I have been on the ES team for the last year. I have also used it in my previous company.
What do I think about the stability of the solution?
The stability of Splunk Enterprise Security rates at eight out of ten.
What do I think about the scalability of the solution?
It is scalable. We can only increase the environment. For instance, with an ES server, we cannot make a cluster of ES. If you have two servers and want to make a cluster of these two servers for ES, that is not possible. There is only one server, and if you want to increase scalability, you must increase the RAM and memory for that same server. The scalability is an eight out of ten.
We simply request Splunk support to increase our storage or make other adjustments as needed. We don't have access to AWS; all of that is managed by Splunk. We just need to reach out to them and say, "Please increase our storage by one terabyte," and they can handle that for us.
How are customer service and support?
Technical support for Splunk Enterprise Security is very good. We have daily calls. They are very helpful, rating at nine out of ten.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
We tried LogScale in the past, but it has very limited functionalities and not a proper UI. It offers approximately 10% of Splunk Enterprise Security's capabilities. We haven't found any solution comparable to Splunk Enterprise Security.
How was the initial setup?
We utilize a combination of both cloud and on-premises setup. Specifically, we use Splunk Cloud for search indexes and other things. On the on-premises side, we have our heavy forwarders, standard forwarders, and user-defined forwarders. So, we effectively integrate both approaches.
The deployment for Splunk Cloud is very easy. They have predefined templates and setups on the AWS end. They utilize many AWS features. If you terminate any indexer, it will spawn up again. This type of automation exists with Splunk Cloud, making it really efficient.
It doesn't require any maintenance, but when we are doing batch upgrades, we need downtime, which is acceptable. It's four to five hours of downtime.
What about the implementation team?
Currently we have a team of seven people for Splunk Enterprise Security, with additional staff using Splunk Cloud and related services.
What was our ROI?
Splunk Enterprise Security helps to save a lot of time, which is our main purpose. Whenever something is wrong in our environment, we immediately get an alert. It saves time and costs. Compared to traditional methods, Splunk Enterprise Security saves approximately 40% to 50% of time.
What's my experience with pricing, setup cost, and licensing?
For small customers, Splunk Enterprise Security is quite expensive. For my team with a substantial budget, the cost is acceptable.
What other advice do I have?
I would definitely recommend Splunk Enterprise Security because if you are really concerned about security and want to follow compliance rules, this product is really helpful.
Splunk Enterprise Security helps save significant time and money, which most customers are looking for. It is easy to configure and manage. If you have certification or basic knowledge of Splunk Enterprise Security, it provides excellent job opportunities. The solution provides numerous helpful dashboards where you can directly check threats and other metrics.
Overall, I would rate it an eight out of ten.
Which deployment model are you using for this solution?
Public Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Amazon Web Services (AWS)
Disclosure: My company has a business relationship with this vendor other than being a customer. partner
IT Security Officer at a government with 10,001+ employees
Security dashboards have boosted threat response and have accelerated data‑driven decisions
Pros and Cons
- "Splunk Enterprise Security has positively impacted my organization by speeding up our ability to respond to security threats, improving my response time from a time span of months to a time span of days."
What is our primary use case?
I have been using Splunk Enterprise Security for five years.
My main use case for Splunk Enterprise Security is reports and dashboards.
I use reports and dashboards to show vulnerability information.
It helps my day-to-day work or decision-making by speeding up decision-making and making it easier to see trends to make decisions.
What is most valuable?
The best features Splunk Enterprise Security offers include the ability to aggregate data from multiple sources.
Aggregating data from multiple sources benefits my work by allowing us to compare information from different security and networking tools to verify correctness.
Splunk Enterprise Security has positively impacted my organization by speeding up our ability to respond to security threats. My response time has improved from a time span of months to a time span of days.
What needs improvement?
Everything is good with Splunk Enterprise Security, and I have nothing that comes to mind regarding improvements, even small things that could make my experience better.
For how long have I used the solution?
I have been using Splunk Enterprise Security for five years.
What do I think about the stability of the solution?
Splunk Enterprise Security is stable.
What do I think about the scalability of the solution?
Its scalability seems very good, but licensing is expensive.
Which solution did I use previously and why did I switch?
I did not previously use a different solution, as there was no previous solution.
How was the initial setup?
Splunk Enterprise Security is deployed on-premises in my organization.
What was our ROI?
It has definitely saved time and improved efficiency, indicating a return on investment.
What's my experience with pricing, setup cost, and licensing?
My experience with pricing, setup cost, and licensing was overall reasonable but expensive.
Which other solutions did I evaluate?
I did not evaluate other options before choosing Splunk Enterprise Security, as no other options were considered.
What other advice do I have?
Splunk Enterprise Security's risk-based alerting, RBA, has improved productivity and provided more useful alerting than manual alerts.
I am unsure if the integration of threat intelligence directly into the TDIR workflow has improved my ability to preemptively block threats.
I assess the threat topology and MITRE ATT&CK framework features as very useful in helping me discover the overall scope of an incident.
I have not used the native UEBA capability to enhance my visibility into unknown, sophisticated, or insider threats.
I would recommend Splunk Enterprise Security to others looking into using it. I gave this review a rating of 10.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Last updated: Sep 16, 2026
Flag as inappropriateWorks at a marketing services firm with 1,001-5,000 employees
Extensive customization facilitates threat detection but integration with cloud and Git needs improvement
Pros and Cons
- "The product is generally stable and forgiving."
- "The GUI, now called Mission Control, which serves as issue management or ticket management, falls below what would be considered industry standards."
- "The AWS add-on is particularly problematic, with most inputs requiring manual writing due to lack of out-of-box functionality."
What is our primary use case?
My use cases for Splunk Enterprise Security are extensive in production. I utilize it for all available functions including observability, asset management, vulnerability management, threat detection, network security, identity management, and various other capabilities.
How has it helped my organization?
The solution does require a lot of customization for an organization.
What is most valuable?
It is highly customizable, which is a significant advantage. It requires substantial customization and tailoring to particular organization requirements, meaning that out of the box, most features would need configuration.
What needs improvement?
The risk and notables component, particularly the two-tier system of picking something from risk into the notable, is one of the most problematic features.
The GUI, now called Mission Control, which serves as issue management or ticket management, falls below what would be considered industry standards.
AI assistance for security analysts to analyze notables and risks needs improvement. Although it exists, the demonstration is not yet sufficient for the required level. We need this as soon as possible to help security analysts.
Splunk Enterprise Security is not cloud environment-friendly, especially when dealing with large cloud infrastructures. With significant AWS presence and multiple clouds, collecting asset data is challenging. The AWS add-on is particularly problematic, with most inputs requiring manual writing due to lack of out-of-box functionality.
Regarding the platform and Enterprise Security specifically, the lack of Git-friendly or Git-native integration is problematic. The recently introduced content management system is inadequate, attempting to implement an outdated concept of storing rule versions in an index while teams work with Git natively.
The storage of queries in savedsearches.conf prevents efficient work with query text. It should be structured as separate SPL files that can utilize intellectual add-ons for Visual Studio Code and work natively with GitHub. Content management is limited to applications within the Enterprise Security suite, excluding custom applications not starting with SA or DA.
For how long have I used the solution?
I have been using Splunk Enterprise Security for more than five years.
What do I think about the stability of the solution?
The product is generally stable and forgiving.
What do I think about the scalability of the solution?
When considering Enterprise Security in particular, it demonstrates good scalability.
How are customer service and support?
I contacted their technical support recently. The support provided is decent, though they often reference their knowledge base. For publicly available solutions, this can be redundant as these solutions can be found through internet searches. Support becomes valuable when dealing with issues requiring access to their closed knowledge base for faster responses.
While support provides solutions, implementation can be complex. In a recent case, the provided solution was so complex to implement that I decided not to proceed. The support staff themselves are highly knowledgeable, polite, and responsive, with some being exceptional. The support team deserves a perfect score.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
I have experience with similar solutions such as AlienVault and ArcSight, each with its advantages and disadvantages. The recommendation depends on the working environment. For cloud-native and GitHub-native organizations, the Enterprise Security solution should align with those principles.
How was the initial setup?
I was solely responsible for the implementation.
It was one of the most difficult deployments I've ever handled. After we set up a cluster with consultants, we made it usable after a year and a half.
Splunk Enterprise Security requires continuous maintenance, consuming approximately 50% of the time. The numerous data sources and constantly changing formats and source types demand ongoing work on data quality, detection rules, assets, and identities.
People are delegated for platform administration, though they currently need additional time to reach optimal performance levels.
What about the implementation team?
We did work with consultants during the deployment.
What's my experience with pricing, setup cost, and licensing?
The pricing is currently managed by procurement. Even with substantial company discounts, it remains extremely expensive. This creates internal challenges when teams independently choose open-source or less expensive solutions for log dumping. Duplicating application logs becomes costly as teams may already use DataDog, ELK stack, Elasticsearch, or S3.
With data ingestion of two terabytes or more daily, Splunk Enterprise Security costs become significant. Cloud-native solutions, particularly in AWS, make it more practical to use native security detection mechanisms such as Security Hub, GuardDuty, and Inspector, using Splunk Enterprise Security as a data aggregator.
Many users prefer pre-processing data before ingestion using the Databricks platform for large data sources such as cloud trail logs. The on-premises pricing model based on data ingestion affects Splunk Enterprise Security's market position.
What other advice do I have?
This product requires significant investment in learning as it is not easily understood. Organizations purchasing the solution should expect 6-12 months with a dedicated team before meaningful insights can be delivered.
On a scale from one to ten, Splunk Enterprise Security rates as a seven.
Which deployment model are you using for this solution?
On-premises
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Amazon Web Services (AWS)
Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
System administrator at a computer software company with 201-500 employees
Log analytics has improved root cause analysis and now reduces false positives faster
Pros and Cons
- "Splunk Enterprise Security has helped improve my organization's business resilience, and I found it to be very effective for helping identify when a system goes down or is operating at an improper level before an actual issue occurs."
What is our primary use case?
My main use case for Splunk Enterprise Security is log analytics. I use Splunk Enterprise Security for log analytics in my day-to-day work by checking for failed logins from specific users, whether or not they're a known user or an unknown user, and seeing if this is abnormal behavior or someone who just forgot their password.
We also use Splunk Enterprise Security for tracking vulnerabilities and mitigations.
What is most valuable?
The best features Splunk Enterprise Security offers include an easy user interface. What makes the user interface of Splunk Enterprise Security stand out for me is that as an administrator, I can type in SPL commands to get what I want, but I can also make pivots to allow non-technical users to gain information through dashboards.
Splunk Enterprise Security's risk-based alerting has improved analyst productivity as it gets rid of some of the low-level taskings. I find Splunk Enterprise Security's threat topology and MITRE ATT&CK framework features quite effective as they help us identify how the risk is going to be executed, if it will, and how likely the risk or threat is to become a vulnerability.
What needs improvement?
I am quite happy with the feature set of Splunk Enterprise Security, and I think it can be improved. Nothing comes to mind regarding areas for improvement, even a small one, that could make my day-to-day work even smoother.
For how long have I used the solution?
I have been using Splunk Enterprise Security for one year.
What do I think about the stability of the solution?
Splunk Enterprise Security is stable.
What do I think about the scalability of the solution?
Splunk Enterprise Security's scalability is very good.
How are customer service and support?
The customer support for Splunk Enterprise Security is very good.
Which solution did I use previously and why did I switch?
I did not previously use a different solution.
How was the initial setup?
I was not involved in the pricing, setup cost, and licensing experience.
Which other solutions did I evaluate?
I was not part of the process of evaluating other options before choosing Splunk Enterprise Security.
What other advice do I have?
Splunk Enterprise Security has positively impacted my organization by making it significantly easier for us to do root cause analysis. A specific example of a situation where Splunk Enterprise Security helped with root cause analysis is that we have seen a significant reduction in the amount of time to identify false positives in certain situations.
Splunk Enterprise Security has helped improve my organization's business resilience, and I found it to be very effective for helping identify when a system goes down or is operating at an improper level before an actual issue occurs. Splunk Enterprise Security has helped reduce my team's average mean time to resolve, MTTR metric, and while I don't have an exact percentage, it has helped us do root cause analysis.
Splunk Enterprise Security has helped me detect threats faster, and while I don't know how much faster, it has seen an improvement as we use Tenable security, and it ingests that data to help us identify threats. My advice to others looking into using Splunk Enterprise Security is to optimize your data inputs so you can best use Splunk Enterprise Security to help you. I would rate this product an 8 out of 10.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Last updated: Sep 16, 2026
Flag as inappropriateTechnical Lead at a tech vendor with 5,001-10,000 employees
Monitoring file transfers has become detailed and reporting now provides flexible, time-based insights
Pros and Cons
- "Splunk Enterprise Security has the capability to pull the report from anytime or any respective time, or if I need it from all the time, then it can be helpful."
- "Because we are using a licensed DataDog, which gives us more reliable results. And for file logs, we are using a BAM, a business audit and monitoring tool, which gives us a more visualized experience than Splunk Enterprise Security."
What is our primary use case?
Currently we are using Splunk Enterprise Security for monitoring the jobs and along with Splunk Enterprise Security, we are using DataDog where it will be used for monitoring the servers and our URLs.
Currently, we are using it only for monitoring because that is going to be decommissioned very soon. So we have only had it active for monitoring for the last four years.
Currently, we are using the on-premises and we are slowly going to be migrated to the cloud, and then we can use that for whatever we have existing. We can utilize it in the cloud.
Splunk Enterprise Security is only used for our MFT tool purpose, which is integrated with our MFT tool.
What is most valuable?
Splunk Enterprise Security has the capability to pull the report from anytime or any respective time, or if I need it from all the time, then it can be helpful. And we can also set the monitoring for a particular server, particular file type, or a particular user. Those are some of the good features which I really appreciate.
Threat detection is not something we use. Our TechSec team uses their own respective tools such as Qualys to pull out the reports. And apart from that, they mainly look into DataDog.
DataDog will give a more pictorial idea of what went wrong, where it lagged, and where the issue is. But Splunk Enterprise Security won't give that much pictorial detail.
Compared to other tools, Splunk Enterprise Security is kind of user-friendly.
Initially, it was helping us to give the logs and integrate with Splunk Enterprise Security and all.
What needs improvement?
The main challenge is that it runs on the Linux part. So that is a very big challenge for us where we have installed it on the Linux machine. And getting it moved out from the Linux machine is the biggest challenge for us currently. So it is not so friendly for us to do that. That is why we came up with DataDog and then Splunk Enterprise Security is going out.
Now, we currently have completed all the setups. We are currently using it on-premises, but going forward, we will be utilizing the cloud environment.
Because we are using a licensed DataDog, which gives us more reliable results. And for file logs, we are using a BAM, a business audit and monitoring tool, which gives us a more visualized experience than Splunk Enterprise Security.
For how long have I used the solution?
For five years.
What do I think about the stability of the solution?
Currently, there are no stability issues. I am not that good at providing any advice, but these are my few feedbacks.
What do I think about the scalability of the solution?
Currently, there are no scalability issues.
How are customer service and support?
Currently, customer service is limited.
Which solution did I use previously and why did I switch?
We are using a licensed DataDog, which gives us more reliable results.
How was the initial setup?
It is not a support kind of thing. It is just helpful for looking around the logs.
What about the implementation team?
Initially, it was helping us to give the logs and integrate with Splunk Enterprise Security and all.
Which other solutions did I evaluate?
Our TechSec team mostly uses DataDog.
What other advice do I have?
I am using a Globalscape, not Axway.
I am working on MFT and SSIS.
Splunk Enterprise Security is only used for our MFT tool purpose, which is integrated with our MFT tool. Otherwise, our TechSec team mostly uses DataDog.
The complete Splunk Enterprise Security itself is going out, going to be decommissioned. So we are not at all using it. So I do not think there will be any more advancement on that part.
Currently, we do not have it.
I do not have any details about that.
It has had some of it, but as we are moving out of it, we never look into it so deeply. For the time being, it will be just refixed.
It is a good product. I rate this product an overall 8 out of 10.
Which deployment model are you using for this solution?
On-premises
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Other
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Last updated: Apr 16, 2026
Flag as inappropriateBuyer's Guide
Download our free Splunk Enterprise Security Report and get advice and tips from experienced pros
sharing their opinions.
Updated: August 2026
Product Categories
Security Information and Event Management (SIEM) Log Management IT Operations AnalyticsPopular Comparisons
IBM Security QRadar
Splunk AppDynamics
Microsoft Sentinel
Elastic Security
IBM Turbonomic
Palantir Foundry
WhatsUp Gold
LogRhythm SIEM
Rapid7 InsightIDR
Elastic Observability
Buyer's Guide
Download our free Splunk Enterprise Security Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- Which would you recommend to your boss, IBM QRadar or Splunk?
- What are some of the best features and use-cases of Splunk?
- What SOC product do you recommend?
- Splunk as an Enterprise Class monitoring solution -- thoughts?
- What is the biggest difference between Dynatrace and Splunk?
- IBM QRadar is rated above competitors (McAfee, Splunk, LogRhythm) in Gartner's 2020 Magic Quandrant. Agree/Disagree?
- What are the advantages of ELK over Splunk?
- How does Splunk compare with Azure Monitor?
- New risk scoring framework in the Splunk App for Enterprise Security -- thoughts?
- Splunk vs. Elastic Stack
















