No more typing reviews! Try our Samantha, our new voice AI agent.
Andry Casares - PeerSpot reviewer
Security Engineer at a financial services firm with 5,001-10,000 employees
Real User
Top 5
Sep 11, 2025
Improves business resilience through faster incident response and effective use case customization
Pros and Cons
  • "My security ops team takes around 30 minutes to one hour to remediate security incidents with Splunk Enterprise Security compared to a previous solution."
  • "Now with Splunk Enterprise Security, we have everything in one place—the notables are created automatically, but they can also create their own notables based on the investigation, which improved and reduced about 50% of the manual work that was done before versus what we are doing now."
  • "We're planning to incorporate UBA and SOAR. It would be good to have everything in one place."
  • "I have not seen ROI with Splunk Enterprise Security."

What is our primary use case?

My main use cases for Splunk Enterprise Security are cloud-based use cases.

What is most valuable?

The features I appreciate the most are the content. I use the content, enable, and see how that works. They give me ideas on how to tune something or determine if that use case is proper for us, or I can take the idea of that use case and customize it based on our needs. 

Splunk Enterprise Security has helped improve my organization's business resilience.

I do use disparate security solutions that integrate or import data into Splunk Enterprise Security. The integration of these solutions supports our security operations. That's the part I work on with the architect. I'm not fully familiar with that, but when we talk, he mentions those integrations and that seems to be good from that perspective because we are separate. We have separation of duty between the architect, security engineer, and analyst.

I find the process for customizing, developing, testing, deploying, and refining detections in Splunk Enterprise Security to be good. My organization uses risk-based alerting in Splunk Enterprise Security for three or four use cases. We have one active for user, cloud users, with data from Microsoft 365. We elevate the risk of users based on behavior and conditional access. It gives us visibility of which users are at real risk based on the configuration we have.

My security ops team takes around 30 minutes to one hour to remediate security incidents with Splunk Enterprise Security compared to a previous solution. They previously did everything manually with the last solution, opening tickets manually and jumping between platforms, the ITSM platform, the same platform. Now with Splunk Enterprise Security, we have everything in one place. The notables are created automatically, but they can also create their own notables based on the investigation. That improved and reduced about 50% of the manual work that was done before versus what we are doing now.

What needs improvement?

In terms of how Splunk Enterprise Security can be improved, based on the last version I'm seeing here, as we are a bit behind,is the Mission Control. It is something that I have heard and tested on a couple of labs that is very good for unifying everything. There are additional features I would want to see included in the next release. We're planning to incorporate UBA and SOAR. It would be good to have everything in one place.

For how long have I used the solution?

I have been using Splunk Enterprise Security for two years.

Buyer's Guide
Splunk Enterprise Security
August 2026
Learn what your peers think about Splunk Enterprise Security. Get advice and tips from experienced pros sharing their opinions. Updated: August 2026.
914,109 professionals have used our research since 2012.

What do I think about the stability of the solution?

The stability and reliability of Splunk Enterprise Security that I would assess depend on our on-premises setup.

What do I think about the scalability of the solution?

Splunk Enterprise Security scales with the growing needs of my organization; however, that's more the architect's domain. We had licensing for 500 gigabytes, then we extended it to 1 terabyte. Now we have 1.5, and we are going to extend to 2.5.

How are customer service and support?

I would evaluate customer service and technical support as good, rating them a nine out of ten. I'm usually not the one who opens tickets. The couple of times that I have opened tickets with Splunk, they were very good. The only thing I was expecting is that they would follow up with me.

Which solution did I use previously and why did I switch?

Prior to adopting Splunk Enterprise Security, I was using Microsoft Sentinel to address similar needs.

How was the initial setup?

The initial setup process was good.

What was our ROI?

I have not seen ROI with Splunk Enterprise Security. 

What's my experience with pricing, setup cost, and licensing?

I don't work with the numbers, licensing, and related aspects. The architect handles that part.

Which other solutions did I evaluate?

I wasn't in the organization when they made the decision, however, based on what I heard, the factors that led to the change were all the detection capabilities, and at that time, they were looking for a solution that was mature enough to implement. At that time, Microsoft Sentinel was not the right solution.

What other advice do I have?

The most significant challenges I face when using Splunk Enterprise Security for advanced threat detection are related to the data. Onboarding the data, trying to get only what we want and what matters for security is a challenge every day. We're trying to onboard what matters and what is significant for security. We use Splunk solely for security purposes. Some people see Splunk as a data analytics tool, which it is, but changing people's minds that we use Splunk for security is an everyday challenge.

I am not using any new threat detection features in Splunk Enterprise Security currently. My impressions of its ability to predict, identify, and solve problems in real time are good, even though we don't use many things out of the box. We use most of the out-of-the-box features and customize them. We have just a few out-of-the-box use cases in place.

The advice I would give to other organizations considering it is to send people to training before getting Splunk Enterprise Security. You can use my real name when publishing my review.

On a scale of one to ten, I would rate Splunk Enterprise Security a nine.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Chetankumar Savalagimath - PeerSpot reviewer
Delivery Manager at a tech services company with 1,001-5,000 employees
Reseller
Top 5
Feb 20, 2026
Security operations have become faster and threat visibility improves across hybrid environments
Pros and Cons
  • "We are satisfied with Splunk Enterprise Security, and it comes with a wide number of out-of-the-box applications which do help us to fix the problems."
  • "However, for smaller organizations, the deployment and management can be expensive, leading them to choose other SIEM tools."

What is our primary use case?

The business case we use Splunk Enterprise Security for is internal security and organizational security purposes. We use it for all kinds of use cases, depending on the project.

What is most valuable?

We are satisfied with Splunk Enterprise Security, and it comes with a wide number of out-of-the-box applications which do help us to fix the problems. The out-of-the-box applications are majorly important for any log source onboarding. When you bring in log sources, you can do anything with it. It has inbuilt Security Essentials, which is the application that helps when you get a lot of log types onboarded, enhancing the use cases based on what you need. For example, after onboarding XYZ log sources, you can develop use cases based on that, such as security contents on that, then you can take it ahead. Those features are the best which we have.

After that, you can develop advanced dashboards or use the new AI feature that can translate something you say into SPL language, making it easy for us. Those features are better right now.

What needs improvement?

Splunk Enterprise Security has achieved a high level of product functionality. Improvements can focus on bringing various features together for easier use and potentially addressing human versus machine threats with AI-based detection, along with educating organizations about compliance.

For how long have I used the solution?

I have been working with Splunk Enterprise Security for almost four years now.

What do I think about the stability of the solution?

Data ingestion is crucial, and I have mentioned this feedback in previous calls. Splunk Enterprise Security is stable and provides a good infrastructure for large organizations. For a Splunk Enterprise Security product in organizations with 20,000 to 80,000 people, it is very stable. However, for smaller organizations, the deployment and management can be expensive, leading them to choose other SIEM tools. For mid-sized organizations, Splunk Enterprise Security is indeed the best option, especially when ingesting a lot of data.

What do I think about the scalability of the solution?

Data ingestion is crucial, and I have mentioned this feedback in previous calls. Splunk Enterprise Security is stable and provides a good infrastructure for large organizations. For a Splunk Enterprise Security product in organizations with 20,000 to 80,000 people, it is very stable. However, for smaller organizations, the deployment and management can be expensive, leading them to choose other SIEM tools. For mid-sized organizations, Splunk Enterprise Security is indeed the best option, especially when ingesting a lot of data.

Which solution did I use previously and why did I switch?

We were previously using IBM QRadar and McAfee products, but right now we haven't explored that part because for a few years, I am working for an organization where we only explore Splunk Enterprise Security or Azure Sentinel or any freeware market SIEM solution. That is the kind of project I am doing right now, but I am not working with IBM QRadar.

How was the initial setup?

The setup process for Splunk Enterprise Security is simple. An experienced technician can complete a systematic installation within a few weeks. Splunk Enterprise Security offers success partner provisioning for additional support and implementation.

Which other solutions did I evaluate?

We usually use Splunk Enterprise Security and Azure Sentinel, and we are researching Wazuh EDR and solution.

Right now we are working on Tines and Scramble, and there are few SOARs which we are looking at like LogRhythm and Sumo Logic source. We are assessing the products right now. We haven't adopted any of them right away.

What other advice do I have?

There is integration between third parties with Splunk Enterprise Security. For example, we can connect a Tenable vulnerability assessment tool. It has inbuilt features to trigger automation actions. We have integrated a lot of products, and when you want to trigger SOAR or something of that nature, third-party applications are already available. For instance, when you integrate Tines, there are extensions available, making it a more powerful tool. This systematic integration is beneficial to us.

Regarding risk-based alerting in Splunk Enterprise Security, there are a lot of contents available from Splunk used as rules or searches. If we design systematic inputs and use cases, it does provide a lot of threat-based detection, showing what detection is happening right now and how advanced automation is expected to happen. Those visibilities are available with Security Essentials.

The resolution of security incidents using Splunk Enterprise Security is quite faster. However, faster remediation ultimately depends on the security operations. The detection with Splunk Enterprise Security is effective, but the story starts afterward. In the actual products, such as Splunk Enterprise Security, 20 to 30% of the time is spent on detection and investigation for incidents. The combination of Splunk Enterprise Security, ITSM tools, and SOAR on a single platform provides a value-add, allowing for a more efficient resolution process while considering costs for security teams.

For threat detection features in Splunk Enterprise Security, it is necessary to build use cases. SIEM tools are not purely threat detection tools; they are notification tools for threats detected elsewhere. We can do anomaly detection, but detecting actual threats requires specific signatures that we haven't explored yet in depth.

For threat detection features, it is vital to build use cases and compare anomalies such as a significant increase in login attempts. Anomalies can be detected in Splunk Enterprise Security, but defining signatures for threats is a task we still need to explore.

We work in both cloud and on-premises models, with our on-premises being integrated with cloud services from certain vendors. I would rate this product overall a 9 out of 10.

Which deployment model are you using for this solution?

Hybrid Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Disclosure: My company has a business relationship with this vendor other than being a customer. reseller
Last updated: Feb 20, 2026
Flag as inappropriate
PeerSpot user
Buyer's Guide
Splunk Enterprise Security
August 2026
Learn what your peers think about Splunk Enterprise Security. Get advice and tips from experienced pros sharing their opinions. Updated: August 2026.
914,109 professionals have used our research since 2012.
Abhilash Kondodi - PeerSpot reviewer
Assistant VP at a financial services firm with 10,001+ employees
Video Review
Real User
Top 10
Sep 13, 2025
Has supported data loss prevention investigations by centralizing access to user activity across multiple tools
Pros and Cons
  • "Splunk Enterprise Security scales well with the growing needs of our company."
  • "For instance, if a DLP operations analyst accesses the platform, it should guide them to navigate predefined content for their role. That's something I've already mentioned to them, and I'm eager to see what happens next."

What is our primary use case?

My main use cases for Splunk Enterprise Security include supporting production changes, which helps us ensure that we are not going to break the business from a DLP engineer standpoint. From an investigations and operations perspective, it allows us to look into all activities done by any individual, such as which emails they sent or what kind of data they have in their folders. We have logs coming from data at rest and data in motion channels, and all this combined is quite helpful for insider threat and data loss prevention activities.

One of the use cases I leverage Splunk Enterprise Security's dashboards and visualizations for is looking into risky applications. Since we manage the web side, we look into emerging AI applications in the market. Splunk Enterprise Security provides access to logs that show which category of websites are being accessed and what those are. We can see that in a search, yet visualizations dashboards enhance this representation. Instead of writing an SPL every time, any team member can go into a dashboard, input the application name they're interested in, and access all relevant details. These are some use cases, and you can continually build your own with Splunk Enterprise Security providing the platform for those developments while limiting access to only those who need to see the information.

How has it helped my organization?

Splunk Enterprise Security plays a role in our organization's strategy to combat insider threats and advanced persistent threats by allowing us to examine how users are affected and the various egress points they are hitting. From my perspective, this is essential as I work in a specific area within cybersecurity.

What is most valuable?

As a DLP Engineer and Assistant Vice President at a US bank with about 50,000+ employees, I manage the Data Loss Prevention tool, configurations, and deployments. We work across the globe in multiple regions and work on multiple different kinds of tools. Splunk Enterprise Security is leveraged quite heavily to support our DLP functions by creating SPLs for our DLP operations. We also create dashboards and reports that are required, where Splunk Enterprise Security is the single point of connection that allows us to send all the logs across and use the data as we need and see fit.

Due to my role, I have limitations on what I can do in Splunk Enterprise Security, yet for whatever access I have, it's been a very useful tool for detections and investigations. From a DLP standpoint, we look into enabling blocking, and we want to make sure that we are looking into what's happening there and how many people would be affected. Splunk Enterprise Security gives us access to that data, while the DLP platforms themselves provide data too, however, Splunk Enterprise Security's integrations with various inputs from identity and asset management create a single point for all information.

I appreciate the statistics feature of Splunk Enterprise Security since it helps showcase numbers to management. While we can share a long spreadsheet, that's not a good way of sharing data. Although we still share spreadsheets, having statistics, visualizations, and dashboards to showcase security benefits is much more effective.

Any new tooling we bring in and adding that data set helps create much richer data. Different integrations enhance our ability to find the right context for threat analysis and insider threat analysis.

I don't have any metrics regarding how Splunk Enterprise Security has helped reduce our team's average mean time to detect. However, I can think of the practical aspect: we have four different tools with their alerts. When we go into each of those tools, we can see what a user has done. With Splunk Enterprise Security, we can just pop in an SPL, search for the user, and find all the details from different sources in one spot, making it much easier to dive into investigations.

What needs improvement?

I have many good ideas for how Splunk Enterprise Security can be improved. Our Splunk team attended a session, and it was really good. I see that AI integration would assist analysts in seamlessly looking into data without relying on engineers to write an SPL. With AI integration, they can search different kinds of data that they have access to. The UEBA side looks good, and the Splunk Enterprise Security UI indicates that we are on the right path. I look forward to using and sharing what I've learned with my team regarding different tools in Splunk Enterprise Security that we can leverage to improve processes, provided they are not already using them.

One major return on investment for using Splunk Enterprise Security, from my perspective, is the feedback I provided to the product research team about creating a UI that helps specific team members extract value from the platform. For instance, if a DLP operations analyst accesses the platform, it should guide them to navigate predefined content for their role. That's something I've already mentioned to them, and I'm eager to see what happens next. Currently, it's a blank slate where users can explore, which is good, however, some people might need a push. Training can either be done from start to finish, or with AI integrating everywhere, users could ask questions that would return answers, from creating an SPL to providing results.

For how long have I used the solution?

I have about ten plus years of experience in IT and security. The last seven years, I've been focused on data security. I've worked on probably more than seven DLP platforms, data loss prevention platforms. And from what I've seen, almost all these companies that I work with, a lot of them leverage Splunk.

What do I think about the stability of the solution?

I am happy with Splunk Enterprise Security's stability and reliability so far. I haven't seen any drawbacks, although sometimes the search takes a while to return results. That's often due to how I design the search, not the platform's fault. I have fantastic team members who assist me with specific SPLs, which makes it easier. It's just about navigating and understanding the right way to do it.

What do I think about the scalability of the solution?

Splunk Enterprise Security scales well with the growing needs of our company. We have a massive team that supports this, with an amazing team managing all the work around Splunk Enterprise Security ingestions. I keep hearing that the use cases are increasing, and we look forward to what more comes in.

Which solution did I use previously and why did I switch?

Before adopting Splunk Enterprise Security, we did not use any other solution to address similar needs in our company.

What other advice do I have?

I know that our SOC team does use Splunk Enterprise Security to prioritize and investigate high-fidelity alerts, however, I'm not sure how it helps them specifically. I can say that many different teams in the business use it very heavily.

We do utilize UEBA in our company, yet not Splunk Enterprise Security UEBA from my understanding. I'm not part of those teams, so I wouldn't have an answer for how it specifically functions.

I would rate Splunk Enterprise Security a ten out of ten.

I advise other companies considering Splunk Enterprise Security to recognize that it is utilized by massive companies and is more practical. I would suggest finding what works for their environment and evaluating all related costs as those are important factors. Overall, Splunk Enterprise Security delivers, which is what truly matters.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Aliasger Husain - PeerSpot reviewer
Lead Software Engineer at Wells Fargo
Real User
Top 20
Jul 15, 2026
Risk-based alerts have transformed enterprise threat monitoring and compliance reporting
Pros and Cons
  • "By this, the risk has been minimized, and it is completely automated till the end with the back tracing workflow as well."
  • "In terms of improvement, the dashboards are not up to the mark. If you compare with Tableau and Power BI reports, they are more customized, more user-friendly, and more interactive."

What is our primary use case?

We are consuming Splunk Enterprise Security because Wells Fargo routes all alerts and logs into it. I work on the reporting side that leadership uses to see the alerts and logs. Whenever threats or alerting occurs, we have kept a couple of algorithms based on which we can assume that this is not normal behavior on the server or any other devices that we are monitoring. It will alert to our systems, then we'll capture all the logs and present them on the reporting side through a dashboard.

Security monitoring, threat detection, and risk-based alerting are the key features that we use daily. Because this is a cybersecurity project, leadership wants to get alerts about what is happening overall at the enterprise level, whether there are any threats, and how to improve cybersecurity. There are a number of applications that are customer-facing, and they are under compliance, so we monitor those applications closely for any cybersecurity threats or issues. If there is something detected, we alert the application team that there is a vulnerability in their systems and these are the measures they can implement. It is a complete cycle. When we detect a threat or potential vulnerability, we report to the application team stating which vulnerabilities exist in their application and what they have to work on. Automatically, that dashboard vulnerability points get captured into a service board and from service board to the application team's Jira board. This is also called TCI activity.

My job and responsibility involves pushing the data to the corresponding team whenever we get an alert. The alert mechanism and all the algorithms have been completely designed by the admin team and the architect teams. As an analyst, I focus more on the data side. This is my source of record for my reporting. I access the Splunk web-based application directly through an API. I verify whatever comes to my database to ensure it is correct and check all the logs. There is a particular index that we use to check. We have a dedicated index for authentication-related items or data-level encryption items. All threats get alerted in the logs, and it is completely based on the risk score, which is an algorithm created for threats with a specific score. We track mostly scores where the score is more than 20.

What is most valuable?

A score of 50 will show in red. Suspicious network activity gives around more than 40 points. We track above 20 only, as 20 is a warning for us, but above 20 is an issue that we have to work on. It gives a priority based on the points, and leadership also tracks it the same way.

I access data through the search command only. I use a correlated search command on the events on the particular index and get the output. We have two instances: one runs on-premises and one runs on cloud. On-premises runs on a Windows server, and cloud runs on AWS as of now. Soon the Windows will get decommissioned, and everything will go to the cloud.

We do real-time monitoring, so within no time, we send alerts to the respective teams and they can start working on it. By this, the risk has been minimized, and it is completely automated till the end with the back tracing workflow as well. There is a middleware team that tracks closely for all these vulnerabilities and gets them resolved on time, or it becomes an escalation to the team if the app team is not able to resolve it within the timeframe.

We capture logs that applications generate. For cybersecurity purposes, we also monitor people who have logged in using Windows logs, DHCP logs, and DNS logs. For example, if someone is based in London but has logged in from a different country or region, such as Germany, we identify it. We alert that the person has logged into Germany without informing their supervisor. These kinds of alerts we do against compliance and company policy. For these reasons, including logging or remote logging through VPN, we capture VPN data from Splunk as well. We do two types of reporting on Splunk Enterprise Security. One is log-based reporting to identify if a user is based in one location but their activity is showing from a different country altogether, then it shows as a flag and goes back to their supervisor.

What needs improvement?

In terms of improvement, the dashboards are not up to the mark. If you compare with Tableau and Power BI reports, they are more customized, more user-friendly, and more interactive. Therefore, we have to do an ETL pipeline to inject those logs into an intermediate system, which is a SQL server, and from SQL server, we do reporting for the leadership.

Actually, there is a feature that got updated, but it is not working on our board. Splunk 2 has not been updated, but we have received AI-related features that are not working as of now. Convert to SQL2 is the new feature they have added, but it is not working as of now.

For how long have I used the solution?

We have been using Splunk Enterprise Security for around 10 years.

What do I think about the stability of the solution?

Splunk Enterprise Security is very much reliable and pretty reliable. Sometimes we used to face peer issues on-premises, but when we migrated to the cloud, I do not see any issues. For one index, data has multiple peers. If any one of the peers is down for five seconds, the retrieval of logs will fail or be incomplete just due to one. When we migrated to the cloud, since then I have not seen any of those issues.

What do I think about the scalability of the solution?

In terms of scalability, I think they have come up with something, but Wells Fargo has not implemented it. I attended the training as well, though it was almost a year ago and I do not recall the details. It was a two-day training. When we talk about scalability, it depends on the business requirement and the use case. It varies.

What other advice do I have?

I am not familiar with all aspects of Splunk Enterprise Security as I am more focused on the alert and reporting part. The admin and principal engineers handle most of the other work. My work involves reporting and the alert part of it.

We run special Splunk queries on two indexes. One is threat intelligence and I believe that is AI-based, though I am not sure what the mechanism is behind it. I have heard in conversations that they are working on the threat intelligence, but it has not been rolled out yet.

I believe that is an AI-based tool that they are working on. Beyond my pay grade, I just raise a request for getting access and pricing information. Because I work for Wells Fargo, which is a big enterprise with a lot of hierarchy, I am not familiar with certain decisions. The requirements come from the leadership level, and if they say this is the tool and I need to get the required data from it, then I have to go for it. I cannot ask why this or that because it is beyond my pay grade. In a huge organization, we have to work on the requirements that come from leadership, even though there are many features that I am not aware of because other team members handle them. My knowledge is based on requirement to requirement and use case to use case. I have explained the two use cases I am working on. In the future, if there is something coming up, I am happy to explore, but as of now, I have two use cases that I have already shared.

At the enterprise level, there are different use cases. Some other developers have different use cases for Splunk Enterprise Security beyond what I am working on. I rate this product a 9 out of 10.

Which deployment model are you using for this solution?

Hybrid Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Last updated: Jul 15, 2026
Flag as inappropriate
PeerSpot user
David-Alfonso - PeerSpot reviewer
IT Security Engineer at a financial services firm with 201-500 employees
Real User
Top 5
Sep 11, 2025
Has significantly improved detection speed and enabled faster response to threats through better integration and automation
Pros and Cons
  • "The features of Splunk Enterprise Security that I find most valuable include Mission Control, which I really appreciate, the way accelerated data functions, making it really fast to see, the integration with SOAR, which is something really cool and integrates with automated processes, and the way to ingest threat intelligence feeds, which is an amazing feature as well."
  • "Splunk Enterprise Security has helped improve my organization's business resilience, as we were able to detect an attack that was happening after hours and prevent it thanks to the detections."
  • "The on-premise integration with SOAR could be more simple; the cloud version integrates with SOAR very easily, but the on-premise SOAR and on-premise Splunk Enterprise Security are really not that easy, so I would appreciate if that could be improved."

What is our primary use case?

My main use cases for Splunk Enterprise Security are basically triage, ensuring cyber threat defence, and improving speed when defending the organization. Since I am the only one currently in the security team, we are growing this year and next, and we're expanding. Splunk Enterprise Security is improving the process to defend, basically.

How has it helped my organization?

The features of Splunk Enterprise Security benefit the organization. You can see threats much faster, helping detect something that the antivirus may miss. Splunk Enterprise Security can work with this, and when the antivirus has a hard position, by using proper detection rules that are well-configured, you can see what's going on in real-time, both endpoint-based and network-based.

What is most valuable?

The features of Splunk Enterprise Security that I find most valuable include Mission Control, which I really appreciate, the way accelerated data functions, making it really fast to see, the integration with SOAR, which is something really cool and integrates with automated processes, and the way to ingest threat intelligence feeds, which is an amazing feature as well.

Splunk Enterprise Security has helped improve my organization's business resilience, as we were able to detect an attack that was happening after hours and prevent it thanks to the detections. We stopped it immediately in a matter of about 30 minutes. Splunk Enterprise Security has improved my ability to predict, identify, and solve problems in real-time; it's not just proactive, but also really predictive. My organization uses Risk-Based Alerting in Splunk Enterprise Security, which speeds up our process to detect and our mean time to respond. It's very helpful, and after we improved the configurations, we have RBA working fine, something that will always be maintained; it may not be perfect, but we do our best to maintain it.

On average, my security ops team takes less than five minutes to remediate security incidents with Splunk Enterprise Security compared to our previous solution, which used to take hours because we needed to see different sites. We are using new threat detection features in Splunk Enterprise Security by ingesting a lot of threat intelligence feeds from our main vendor, which has significantly improved the indicator of compromise, the IOCs detections. We also use Sigma detections and adapt to Splunk.

What needs improvement?

The on-premise integration with SOAR could be more simple; the cloud version integrates with SOAR very easily, but the on-premise SOAR and on-premise Splunk Enterprise Security are really not that easy, so I would appreciate if that could be improved. 

Additional features that should be included in the next release of Splunk Enterprise Security are the ability to integrate with other software and tool frameworks, beyond Sysmon, to avoid ingesting Sysmon logs from the endpoint, which can be very noisy at times, resulting in more straightforward detection and less resource-intensive licensing.

For how long have I used the solution?

I have been using Splunk Enterprise Security for four years.

What do I think about the stability of the solution?

I have experienced downtime, crashes, and performance issues with Splunk Enterprise Security due to a hardware issue, which we were able to quickly fix thanks to the backup recovery. However, it took about one day, and it highlights the need to move to clustering, which I've discussed with my leadership team.

What do I think about the scalability of the solution?

I would assess the stability and reliability of Splunk Enterprise Security as needing clustering. It ensures it remains operational all the time, which means you can see cyber attacks. When it's down, you can't see anything. 

We currently rely on disaster recovery and backup recovery, which takes time to recover, during which you're basically blind, so I'm pushing my leadership team to switch over to a clustering environment for constant availability. Right now, the server we have meets the hardware requirements, and we have moved to new hardware. 

We're considering moving to cluster environments to scale in the future, probably in a couple of years.

How are customer service and support?

I would evaluate customer service and technical support for Splunk Enterprise Security as excellent; when we open tickets for troubleshooting, 99% of the time, it relates to our Linux environment. I have no personal complaints about the support.

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

Prior to adopting Splunk Enterprise Security, Splunk was already in place when I came on board at Educational Federal Credit Union.

How was the initial setup?

In the beginning, we were using disparate security solutions that integrate or import data into Splunk Enterprise Security. Now we are adapting to completely switch to the Splunk Enterprise Security side to have a single-pane-of-glass view of everything, minimizing the integrations with the vendors such as EDR, DLP, and the firewall.

What was our ROI?

I have seen a return on investment with Splunk Enterprise Security. My executive team has noticed improvements; we were able to save on other solutions, which increased budgeting for future projects thanks to Splunk Enterprise Security and the licensing optimization, allowing us to invest in other tools.

What's my experience with pricing, setup cost, and licensing?

My experience with pricing, setup costs, and licensing with Splunk Enterprise Security has been challenging in the past due to the expensive licensing model, which was driven by Sysmon delivering a lot of unnecessary noise. We don't use Splunk just for security; we also use it for other departments. 

We have shared the license between security and development departments, making sure to minimize ingestion logs from the endpoints, including workstations and servers. We are currently leveraging EDR telemetry ingested to Splunk, which saved a lot of licensing money while allowing us to see what we're looking for.

What other advice do I have?

My advice to other organizations considering Splunk Enterprise Security is that it's the leader in SIEM globally. You have a lot of customization and data normalization, meaning you can detect anything you want compared to other SIEMs. Splunk Enterprise Security is worth the investment because it provides exactly what you need if you are a true cyber defender. I also network with friends from a company, Next-Gen Systems, which is leading in detection and investing in developments and integrations with Splunk due to its scalability. 

On a scale of one to ten, I rate Splunk Enterprise Security a ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Ramnesh  Dubey - PeerSpot reviewer
Senior Cyber Security Specialist at HCLSoftware
Real User
Top 10
Jul 27, 2026
Security operations have improved with faster threat detection but automation still needs work
Pros and Cons
  • "Threat detection in Splunk Enterprise Security is more than 60 to 70% faster compared to other tools."
  • "My thoughts on the pricing of Splunk Enterprise Security is that it is not cost-efficient; Splunk Enterprise Security is very costly compared to other market tools."

What is our primary use case?

Currently, we are monitoring all logs for retention as well as real-time monitoring using Splunk Enterprise Security, and there is a log management component that utilizes the retention period. These are the things we are currently doing.

Threat detection in Splunk Enterprise Security is more than 60 to 70% faster compared to other tools. The main advantage is not only detection but also proper analysis, as other tools sometimes miss fields, while here we can search the raw logs for detection as well as evidence, which is very helpful.

Currently, Threat Topology and the MITRE ATT&CK framework in Splunk Enterprise Security are helpful, but we have not explored them in-depth.

The integration of threat intelligence directly into the TDIR workflow in Splunk Enterprise Security allows us to block more than 50% of threats, but due to our maximum customer environment, we cannot adopt it directly, so it is not fully automated right now.

What is most valuable?

The best feature I have in Splunk Enterprise Security is Mission Control, which enhances our SOC to real-time monitoring of incidents. The second notable feature is the threat feeds, which capture the IOCs very well.

The solution has improved my mean time to detect and resolve by about 20 to 30% in real-time for resolving an issue.

Risk-based alerting in Splunk Enterprise Security has impacted us because higher risk alerts are more critical and can be easily identified by our SOC team, providing a proper solution on that. The risk-based analysis is very good, but we need to apply this for all the correlation rules, which is not fully automatic and requires manual effort for risk.

What needs improvement?

From my point of view, the AI-driven detections in Splunk Enterprise Security scale at about 10 out of 6 in terms of helping improve the accuracy of my investigations, but I still miss a few correlation rules because the maximum correlation is based on the MITRE framework and other factors. There is still a need for improvement related to AI-based detection.

My thoughts on UEBA in Splunk Enterprise Security is that the user behavior analysis feature is very good, but it relies heavily on the identification of logs. We are capturing the data, and while Splunk Enterprise Security is good, proper integration with devices such as Active Directory, single sign-on devices, PingID, and multi-factor ID is essential, with configuration and data model creation being manual rather than automatic.

For how long have I used the solution?

I have been working with Splunk Enterprise Security for six years or more.

What do I think about the stability of the solution?

Regarding stability, I rate Splunk Enterprise Security at 9 out of 10. Right now, it is stable, and the other components are much better.

What do I think about the scalability of the solution?

I would rate the scalability of Splunk Enterprise Security at about 9 since the maximum component is on the cloud, so we encounter no issues with scalability.

How are customer service and support?

In comparing Splunk Enterprise Security with other solutions or vendors, the timely support is one noticeable aspect, and I rate it a 7 out of 10. Some vendors provide good support, but I have experienced some delays with RCA when integrating other solutions such as QRadar, IBM, and other SIEM tools, indicating a lack of customer support.

I would rate the customer support for Splunk Enterprise Security at 7.

What's my experience with pricing, setup cost, and licensing?

My thoughts on the pricing of Splunk Enterprise Security is that it is not cost-efficient. Splunk Enterprise Security is very costly compared to other market tools.

What other advice do I have?

I have upgraded to Splunk 8.0, and it is currently running on version 10.3.2.

In our company, there are 20 specialists working with Splunk Enterprise Security.

Our clients are not small; they are enterprise businesses.

I would rate this review 7 out of 10.

Which deployment model are you using for this solution?

Hybrid Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Other
Disclosure: My company has a business relationship with this vendor other than being a customer. partner
Last updated: Jul 27, 2026
Flag as inappropriate
PeerSpot user
Viral Shaa - PeerSpot reviewer
IT Security Analyst at Eos Energy Enterprises, Inc.
Real User
Top 5Leaderboard
Jun 5, 2026
Centralized monitoring has reduced analyst burnout and improves response to critical threats
Pros and Cons
  • "My overall experience with Splunk Enterprise Security in the energy sector has been overwhelmingly positive."
  • "While Splunk Enterprise Security is a great product, I observe a few challenges compared to other products. The first challenge is the licensing cost, which is significantly high, especially for organizations generating a large volume of logs common in the energy sector."

What is our primary use case?

We are currently in beta mode with AI-driven detections, connecting with AI while using Splunk forwarders and API connectors to ingest data from SCADA systems, historian databases, firewalls, endpoint security platforms, and cloud services. So far, the beta platform is working as expected, although we are not fully integrated with AI yet. Splunk Enterprise Security includes threat intelligence feeds, which summarize alerts in bullet points for analysts, helping them investigate incidents.

I use Splunk Enterprise Security as a SIEM management tool that gathers SIEM, log management, and operational monitoring. We are using it to integrate with different systems and centralize logging in one place, where we create rules or alerts that generate when there is a match. We are using that tool as a necessity and for compliance as well.

What is most valuable?

Risk-based alerting in Splunk Enterprise Security has positively impacted our alert volume and analyst productivity. We currently have a lot of alerts, including out-of-the-box alerts provided by Splunk. The risk-based alerts allow us to create alerts tailored to our needs, significantly impacting our organization by helping us prioritize events that truly matter and reducing false positives in our monitoring environment. For example, if one alert detects malware or a decommissioned user account, the risk-based alerting reduces noise from less severe alerts, allowing analysts to focus on more critical issues without having to investigate low-severity alerts extensively.

The integration of the threat intelligence feed and MITRE ATT&CK framework in Splunk Enterprise Security is significant for discovering the overall scope of incidents. When an alert generates, understanding the attacker's motive helps us recognize how they gain access to our environment, including the tools and techniques they use. Using MITRE tactics alongside threat intelligence feeds adds value to those alerts, allowing us to reduce response times significantly.

The correlation rules and risk-based alert models are effectively detecting threat factors early, enabling analysts to get to work immediately. The correlation rules, threat intelligence, notable event prioritization, and risk-based alerting help navigate the root causes of threats, thus reducing the threat landscape.

My overall experience with Splunk Enterprise Security in the energy sector has been overwhelmingly positive. Splunk Enterprise Security has proven to be a powerful and reliable tool for centralizing logging, monitoring critical infrastructure, creating alerts and reports, and improving both operational and cybersecurity sides. It also provides security, giving us visibility into the OT and IT environments to ingest and correlate large volumes of data. After generating alerts, we detect anomalies and respond to incidents faster, all within a centralized platform. We have approximately fifty software solutions that we are using, and we ingest the logs into Splunk, allowing us to monitor them flexibly and scalably, which fits our organization's needs in a high-volume energy sector environment.

Using Splunk Enterprise Security improves our average mean time to resolve because we aggregate logs from endpoints, IAM logs, spam logs, EDR logs, and firewall logs into a centralized platform. It creates alerts that analysts can prioritize. P1 incidents should be resolved within two hours, demonstrating significant improvement from utilizing the product in our environment. It is a strong platform that faces some challenges, but overall, we receive positive feedback about reducing that mean time.

Before Splunk Enterprise Security was onboarded, finding alerts across multiple dashboards demanded considerable effort. After using Splunk Enterprise Security, we see significant improvement because everything is centralized on one dashboard. Analysts no longer need to look for firewall or EDR alert points individually; all data is accessible on Splunk Enterprise Security's dashboard. The AI model also helps minimize real-time metrics for security events, presenting everything in real time. Analysts can contact customers or end users and complete their analysis in approximately fifteen to twenty minutes, gaining insights about the ongoing environment, detecting anomalies and responding to incidents faster.

In the energy sector, where infrastructure and regulatory requirements are critical, the triage phase's capability allows us to detect significant ransomware attacks early. By triaging incidents right away, we strengthen our visibility and can swiftly take action, such as isolating virtual machines or user accounts, or changing passwords, which helps us assess the risks involved with alerts and how we can remediate them.

Splunk Enterprise Security significantly improves our ability to detect threats faster.

What needs improvement?

While Splunk Enterprise Security is a great product, I observe a few challenges compared to other products. The first challenge is the licensing cost, which is significantly high, especially for organizations generating a large volume of logs common in the energy sector. The learning curve can also be steep for new users, particularly when working with SPL and building advanced dashboards. Learning SPL, a query language in Splunk, is not hard, but for a newly onboarded analyst, it can be challenging. Building dashboards is easy, but when making special requests for management, it can be tricky. Additionally, Splunk can be resource intensive, requiring careful planning around storage, indexing, and hardware performance. These factors do not diminish the product's value, but they do require thoughtful management and ongoing training to ensure teams leverage their capabilities fully.

I recommend that Splunk improves its pricing model since the pricing is based on the logs ingested, which is currently quite high. Users and admins of the product must pre-plan and thoughtfully manage the logs to fully leverage its capabilities. Reducing pricing would be a great suggestion from my side.

For how long have I used the solution?

I have been working with Splunk Enterprise Security for three to five years on my current job and probably on my previous job as well.

What do I think about the stability of the solution?

Regarding reliability and stability, Splunk Enterprise Security is a significant tool. We have not experienced outages or downtime. The documentation states 99.9% availability, and it consistently operates 24/7 without any stability or reliability issues at this time.

What do I think about the scalability of the solution?

From a scalability standpoint, as we transition from a smaller mid-sized company to over one thousand employees, we have not encountered any hiccups or roadblocks using Splunk Enterprise Security. It effectively meets our needs in terms of log ingestion and performance.

How are customer service and support?

Splunk support is quite good; they reply within twenty-four hours. We have opened some support tickets, and they responded promptly to address the root cause of our issues. I would rate Splunk support as very responsive.

Which solution did I use previously and why did I switch?

We evaluated IBM QRadar, Elastic Stack, and ArcSight through POC, but so far, Splunk Enterprise Security's ecosystem, documentation, and functionalities stand out the most.

How was the initial setup?

My deployment experience with Splunk Enterprise Security was smooth and well-structured. We began by pre-planning the architecture to define indexer, search head, and storage requirements based on expected data volume. Once completed, we deployed the forwarder across various servers, firewalls, and OT gateways, followed by data forwarders from the SCADA system, historian database, and enterprise applications. Once ingestion was stable, we began building dashboards, alerts, and compliance reports tailored to our operational and security needs. Our team required training, which Splunk provided to help us understand how SPL works and how to create dashboards. With their assistance, we started ingesting data and the platform is fully operational. Overall, it was a smooth and standard deployment process.

I participated in the initial setup of Splunk Enterprise Security, serving as the admin of the console overseeing onboarding and offboarding processes.

What was our ROI?

In terms of improving business resilience, the ROI from Splunk Enterprise Security is significantly positive. Implementing Splunk Enterprise Security has improved our organization's overall resilience by providing real-time visibility in both IT and OT environments, enabling faster anomaly detection and addressing operational disruptions and security threats. With centralized logging, correlation searches, and risk-based alerting, we can identify issues earlier, prioritize events posing high risks, and respond before impacting critical infrastructure or service delivery. This approach reduces downtime, ensures compliance readiness, and enhances continuity across energy operations. By utilizing data from our SCADA systems, network devices, identity platforms, and cloud services, Splunk Enterprise Security supports a more adaptive, informed, and resilient operational posture while ensuring day-to-day reliability and long-term strategic stability.

What other advice do I have?

Compared to other products in the market, Splunk Enterprise Security's standard is much higher, though other options are cheaper.

I am an admin of Splunk Enterprise Security. Currently, we have Splunk Enterprise, and I would consider my role as a user.

We are using the enterprise version, which is best suited for us with a higher top-layer model.

I observe a significant reduction in analyst burnout due to utilizing Splunk Enterprise Security. Analysts face a high risk of burnout working for thirty minutes to several hours on a single alert to find the root cause. However, with everything centralized on a dashboard, burnout rates decline. Splunk Enterprise Security monitors our systems 24/7, allowing analysts on different shifts to evaluate the dashboards in a consistent manner. This standardization of dashboard alerts and reporting has significantly improved our operations and reduced burnout.

Currently, we are on a trial license for third-party vendors ingesting security event data while streamlining incident management. We receive real-time monitoring for threat intelligence feeds, using a SOAR platform for automated response workflows and an AI platform that helps narrow down visibility across our entire energy infrastructure.

Based on my experience with Splunk Enterprise Security in every aspect, I would rate it nine out of ten.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Last updated: Jun 5, 2026
Flag as inappropriate
PeerSpot user
Paul-Zhang - PeerSpot reviewer
Manager, Information Security at a financial services firm with 10,001+ employees
Real User
Top 5
Sep 11, 2025
Delivers efficient threat detection through big data analytics but requires improvement in reducing false positives and operational noise
Pros and Cons
  • "Splunk Enterprise Security is doing its job in helping improve my organization's business resilience."
  • "The biggest advantage I can see in Splunk Enterprise Security is the big data analytics."
  • "There is another new term called benign positives. It is better to clearly identify each definition of those terms since it has not been popular in the industry, and everyone needs to be aware of those things."
  • "The most significant challenges I face when using Splunk Enterprise Security for advanced threat detection are the false positive alerts."

What is our primary use case?

My main use cases for Splunk Enterprise Security are threat detection use cases.

What is most valuable?

The biggest advantage I can see in Splunk Enterprise Security is the big data analytics. The simple search query with faster responding results is also appealing. My team handles large volumes of cybersecurity data. To be able to search against such a big amount of data with efficiency is the key driver for my team to do threat detection and data analytics.

What needs improvement?

Splunk Enterprise Security can be improved in many ways. I am very happy to experience the AI-powered security platform they are going to show us in the new version. Better identification of true positives and false positives should be included in future releases.

There is another new term called benign positives. It is better to clearly identify each definition of those terms since it has not been popular in the industry, and everyone needs to be aware of those things.

The most significant challenges I face when using Splunk Enterprise Security for advanced threat detection are the false positive alerts. As mentioned in the keynote, there is a lot of noise. Reducing the noise to make sure the SOC is operating more efficiently is one of the challenges my team is having. The process for customizing, developing, testing, deploying, and refining detections in Splunk Enterprise Security is not the easiest, however, it is not the most difficult one, so I would say it is medium.

For how long have I used the solution?

I have been using Splunk Enterprise Security for seven years.

What do I think about the stability of the solution?

I have experienced downtime, crashes, and performance issues, with the most recent one being a data ingestion issue from another security platform. This key data source is not being ingested, causing some downtime.

What do I think about the scalability of the solution?

Splunk Enterprise Security does not scale efficiently with the growing needs of my organization. Since it is on-premises, we have some scalability issues, and there are other new players coming up.

We have expanded the usage of Splunk Enterprise Security several times.

How are customer service and support?

I would evaluate customer service and technical support as adequate since my team does not deal with it directly. Another team dealt with them, and I found it to be acceptable as they have 24/7 support all over the world. 

They hand over to the next team in another country, but sometimes it takes time to do the transfer, and we have to explain all the problem issues again, which can be frustrating. For that, I would rate it a five.

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

Prior to adopting Splunk Enterprise Security, I was not using another solution to address similar needs.

How was the initial setup?

My experience with deploying Splunk Enterprise Security is actually another team's job, however, they are doing adequately.

What about the implementation team?

My organization is moving towards risk-based alerting in Splunk Enterprise Security. My team actually built our own risk-based alerting before they released it; however, we are looking forward to integrating both.

What was our ROI?

Splunk Enterprise Security is doing its job in helping improve my organization's business resilience. There are other competitors in the same field, so I find it neither particularly good nor bad.

What's my experience with pricing, setup cost, and licensing?

I don't directly deal with pricing.

What other advice do I have?

I would advise other organizations considering Splunk Enterprise Security that the new version looks impressive. If organizations want the new, complete package, I would recommend ES Premier, as it combines ES with TIM, UEBA, and SOAR. 

On a scale of one to ten, I would rate Splunk Enterprise Security a seven. I believe ES is doing its job, but it is slightly behind its competitors. 

Other competitor platforms already have AI integrated, and they just announced it today, so it feels somewhat behind. However, I am looking forward to this new feature.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Sunny-Kumar - PeerSpot reviewer
Cyber Security Analyst at airtel
Real User
Top 5
Apr 23, 2026
Real-time threat monitoring has strengthened resilience but support and automation still need work
Pros and Cons
  • "Splunk Enterprise Security helps improve our organization's business resilience because it is very useful for real-time monitoring and investigation."
  • "The technical support can be improved because sometimes when we call them, the issues are not resolved immediately and tickets take time to be addressed."

What is our primary use case?

In my organization, there are many use cases for Splunk Enterprise Security, including potential risk, brute force attack, malware attack, ransomware attacks, and firewall-related use cases. We also have switch-related, inbound traffic, outbound traffic, login failure, and successful login use cases. I estimate there are more than 150 use cases in our organization.

What is most valuable?

What I appreciate about Splunk Enterprise Security is that it is very intuitive and basic to use.

The best features of Splunk Enterprise Security that I value include its ease of use, the SPL query language, and its straightforward handling. It provides real-time monitoring and investigation, which are the main features in SPL.

Splunk Enterprise Security helps improve our organization's business resilience because it is very useful for real-time monitoring and investigation. When any incidents occur, we can check and detect them in real-time.

What needs improvement?

I would like to see improvements in Splunk Enterprise Security regarding the integration of device automation and more automatic use cases in the licensing model, as well as reducing the incident time period and incident remediation time.

The technical support can be improved because sometimes when we call them, the issues are not resolved immediately and tickets take time to be addressed.

For how long have I used the solution?

I have been working with Splunk Enterprise Security for more than three years.

What do I think about the stability of the solution?

Splunk Enterprise Security is stable and I have not experienced any downtime or significant performance issues. I rate the stability of Splunk Enterprise Security as good.

What do I think about the scalability of the solution?

Splunk Enterprise Security scales well with the growing needs of my organization, though urgent support is required for projects deployed at customer premises.

How are customer service and support?

I evaluate customer service and technical support from Splunk as requiring the raising of a ticket or calling a toll-free number for any technical issues, which they resolve with assistance.

Which solution did I use previously and why did I switch?

Before Splunk Enterprise Security, we used RSA NetWitness and also Sentinel.

What about the implementation team?

I am not directly involved in the deployment of Splunk Enterprise Security, but during the integration of devices, we have a team working on the onboarding process.

What was our ROI?

I have seen a return on investment with Splunk Enterprise Security. It is cost-effective since not many companies are using it right now compared to other SIEM tools.

What's my experience with pricing, setup cost, and licensing?

My experience with pricing, setup cost, and licensing is that Splunk Enterprise Security is very costly compared to other SIEM tools, but the advanced features justify the cost due to its real-time capabilities and user-friendly SPL features as a key differentiator. The licensing is also costly and based on events per second.

What other advice do I have?

I am currently working with Splunk Enterprise Security products and solutions. I work as a Splunk Admin with Splunk Cloud platform and Splunk Enterprise Security.

I do work with Splunk Enterprise Security but not with the Cloud. I find the process for customizing, developing, testing, deploying, and refining detections in Splunk Enterprise Security manageable.

There are many tasks we have to perform in the detection of Splunk Enterprise Security, but if we categorize them, we use the SPL commands. We have to use a query language of the SPL command and optimize and sort out the issue in a limited, minimum time period. These are the command lines we use to reduce the time and prioritize the issues.

We use disparate security solutions that integrate or import data into Splunk Enterprise Security, including Windows devices, Linux devices, and firewall devices. Many other devices are integrated, including the three main components of Splunk Enterprise Security: the forwarder, indexer, and search head. The forwarder collects data from different sources such as switches, firewalls, databases, or routers. These are the data sources integrated with our Splunk devices. The log source then collects the forwarder and sends it to the indexer. The indexer parses the logs, licenses the logs, and minimizes the logs in different formats including JSON format and TXT.IDS format. These are the two formats in which we have the logs stored in the indexer. The third component is the search head, where we perform searches in the dashboard and search console by redirecting to the indexer and extracting the necessary data.

My overall impressions of Splunk Enterprise Security's ability to predict, identify, and solve problems in real-time are positive. These include real-time investigation, incident identification, and minimizing the time required for response. The main components include the SPL command as a useful search processing language. We check the logs of the last three to four days and utilize the indexing box, including hot and cold buckets for storing logs. There are five types of buckets in Splunk Enterprise Security for this purpose.

I am using new threat detection features in Splunk Enterprise Security, including malware analysis, phishing email detection, and detection of malicious IPs, malicious tools, and URLs.

We have not faced any challenges in using Splunk Enterprise Security for advanced threat detection.

My organization uses risk-based alerting in Splunk Enterprise Security. We have a threshold in the search console for incidents. When any incident occurs, it can be categorized based on the number of occurrences as minor, moderate, major, or critical alerts depending on the threshold values.

I am not aware of specific enhancements or new features that should be included in future releases of Splunk Enterprise Security.

I decided to switch to Splunk Enterprise Security because my organization uses it and I have received training on it. The integration of devices with Splunk Enterprise Security is a significant factor, as it is a new technology with advanced real-time monitoring features.

The deployment model for Splunk Enterprise Security that I am using is on-premises.

I would advise other organizations considering Splunk Enterprise Security that it is a new product and new technology. It is easy to handle and has a straightforward deployment model. Use cases are also easy to create, and it provides real-time monitoring and incident detection, which is a valuable feature. My overall review rating for Splunk Enterprise Security is seven out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Last updated: Apr 23, 2026
Flag as inappropriate
PeerSpot user
reviewer2499171 - PeerSpot reviewer
Security Engineer at a retailer with 10,001+ employees
Real User
Top 20
Nov 19, 2025
Investigations have started faster with strong alerting and improved visibility
Pros and Cons
  • "Generally speaking, their support is pretty good and their response time is pretty good."
  • "The huge price increases that have been experienced over the last couple of years do not appear to be justified by new features or items in general."

What is our primary use case?

Splunk Enterprise Security is used for many different things. Primarily, it is used to create alerts for different use cases that need to be monitored, and then investigations can be created. At a high level, that is where many investigations start from.

What is most valuable?

Business resilience is valuable, though I am not completely certain about Splunk Enterprise Security in that regard. Visibility would be considered a valuable feature. The more I think about it, business resilience is probably valuable as well.

What needs improvement?

The pricing of Splunk Enterprise Security is probably one of the main pain point areas. It is probably the only area that has us looking elsewhere for other options, just to see what is available even just because of the price. While it is a good product, the huge price increases that have been experienced over the last couple of years do not appear to be justified by new features or items in general. Pricing is the area that has everyone looking elsewhere to see what other options exist. The prices definitely make your eyes water when you see them.

Splunk Enterprise Security could improve its pricing. This seems to have been a theme across the board at the Splunk conference this year. The general consensus is that pricing continues to increase significantly every year, not just by a couple of dollars.

For how long have I used the solution?

Splunk Enterprise Security has been used in my career overall for about six years.

What do I think about the stability of the solution?

The only instability that has been experienced with Splunk Enterprise Security is from inefficient searches and things configured incorrectly. Stability is ranked pretty high for the product.

What do I think about the scalability of the solution?

Scalability for Splunk Enterprise Security is ranked pretty high.

How are customer service and support?

I have tried contacting Splunk Enterprise Security support, and I am currently dealing with some technical support items. Technical support is relied upon pretty regularly. Generally speaking, their support is pretty good and their response time is pretty good. The caveat to that is that recently, there are some pretty interesting issues that seem to take a long time and a lot of back and forth just to get to the right people for some advanced challenging issues. When you open up a support case, you are assigned somebody at tier one support. There is no way to bypass that or indicate that this is a more advanced issue. Everything goes through the same process, and there is no way to really get advanced technical support from the beginning. You have to start at level one, and they set up a meeting and a call to explain the issue and show what is being experienced. There is a lot of back and forth, and then maybe if you are fortunate, you get assigned a more senior person after a week or two. For some cases, it takes maybe three or four weeks before you are actually in touch with people who can actually help with the issue. There is a lot of back and forth, a lot of emails, and a lot of troubleshooting and screenshots and communication for three to four weeks later before you can finally get a hold of somebody who is actually able to point you in the right direction.

Splunk Enterprise Security would be given a score of eight or nine overall for support. It is just the amount of time that it takes to get support for some advanced issues. You have to start at the bottom and keep communicating and working your way up that chain. Overall, it is a solid eight or nine, but sometimes it takes a decent amount of effort and time to get there.

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

Nothing has been used before Splunk Enterprise Security.

How was the initial setup?

When first starting to use Splunk Enterprise Security, the initial deployment was already stood up, so much of it was personal learning. I cannot really speak on behalf of other people who have stood Splunk Enterprise Security up.

What about the implementation team?

Splunk Enterprise Security is a pretty complex tool, and it is always changing. There are always new things, even with 8.0 to 8.2. There are always things that are being renamed and moved around and called different things and the UI is changing. That has definitely added to the learning curve. It is a pretty complex tool, so there is a pretty steep learning curve personally just because there are so many things that it does and controls and a lot of things to consider.

What was our ROI?

Splunk Enterprise Security has not helped to reduce the team's mean time to detect, the MTDD metric. A service provider, managed service provider, is utilized for items like that.

What's my experience with pricing, setup cost, and licensing?

Splunk Enterprise Security is not being used with the observability platform at this point.

Which other solutions did I evaluate?

Splunk Enterprise Security has not been upgraded to 8.0. The upgrade to 8.2 is in the works, probably in the next two months or less.

What other advice do I have?

Risk-based Alerting, as Splunk Enterprise Security calls it, is being used. There are some pros and cons associated with it. The organization is not mature enough for Risk-based Alerting to speak on any pros or cons too much because of how Risk-based Alerting works. Many of the underlying fundamental pieces have not been built or are not mature enough to really calculate the risk scores correctly. While Risk-based Alerting is enabled and turned on and some risk-based alerts have been created, generally speaking, the organization is not mature enough in some of the other areas to really use a lot of the granular details of what Risk-based Alerting is for. However, it is on the path for progression. The overall review rating for Splunk Enterprise Security is nine.

Which deployment model are you using for this solution?

On-premises

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Other
Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
PeerSpot user
Buyer's Guide
Download our free Splunk Enterprise Security Report and get advice and tips from experienced pros sharing their opinions.
Updated: August 2026
Buyer's Guide
Download our free Splunk Enterprise Security Report and get advice and tips from experienced pros sharing their opinions.