Our primary use cases are for detection and remediation.
Architect at a tech consulting company with 10,001+ employees
Brings all of the components necessary to identify, analyze, and respond together
Pros and Cons
- "The most valuable feature is that it brings all of the components necessary to identify, analyze, and respond together."
- "Splunk is such a large product. Allowing it to be more easily used by people who have not had a lot of training on it would be an improvement."
What is our primary use case?
How has it helped my organization?
The benefits we've seen from Splunk is that we can promote it to our customers. The second benefit is that it works. It does what it's purported to do, and the support is more than adequate.
What is most valuable?
The most valuable feature is that it brings all of the components necessary to identify, analyze, and respond together.
It's pretty important that Splunk provides end-to-end visibility into your environment. As in any product that one purchases to fulfill a function, we want to recognize where it came in, who it affected, and what the challenges are that need to be met in order to resolve something, both immediately and also to make sure that it doesn't replicate in the future. Splunk does a good job of being able to do the former half. Dealing with issues requires tier-three support and above and it takes time. You can work through it with the help of your vendor team.
I would rate them an eight out of ten. It's not so much the problem of the application itself, although there are always improvements that can be done. There are a lot of moving parts that need to be added in and if you don't have the information that you need, especially within identity and inventory, then that can be an added challenge when you have to start making imprints based on what you do know.
Splunk Enterprise Security provides us with the relevant context to help guide our investigations. There are a number of different standards that can be presented, which is beneficial. Some customers like to have the information that they receive in one format. The driving factor is that when you work with federal customers, some of them want it in one format. The response will be in one format as opposed to another.
Splunk has helped to improve my company's business resilience. It's an active component in ensuring that we are vigilant against intrusion and detecting it.
What needs improvement?
Splunk is such a large product. Allowing it to be more easily used by people who have not had a lot of training on it would be an improvement. That's something that they're accomplishing with their current version, although I haven't had an opportunity to learn much about it. With AI capabilities coming on board, a lot of that will alleviate the minutiae that people need to know in order to resolve problems as they come up.
Splunk's ability to predict, identify, and solve problems in real-time is a work in progress.
Buyer's Guide
Splunk Enterprise Security
February 2026
Learn what your peers think about Splunk Enterprise Security. Get advice and tips from experienced pros sharing their opinions. Updated: February 2026.
884,933 professionals have used our research since 2012.
For how long have I used the solution?
I have been using Splunk Enterprise Security for the past four years.
What do I think about the stability of the solution?
Aside from the fact that it can be a resource hog, I'm satisfied with the stability. I don't have too many problems except for a few occasions when we have a threat intelligence file blow up a drive because there's not enough room. It might be because a complete configuration has not been implemented.
What do I think about the scalability of the solution?
I like the fact that it can be tweaked, but a lot of the various configurations for how long data is held or how long particular components of investigation are held.
How are customer service and support?
I encourage users to use the vendor management team and cultivate a relationship with them. I have worked with companies who had support that I would rate 11 out of 10. I would rate Splunk an eight out of ten because as any large growing company, they have challenges with keeping the talent necessary, who are not only educated to evaluate a problem and pass it on or solve it themselves.
How was the initial setup?
The largest challenge with the setup is that it has so many different components. The environment that we're in is a multi-tenant. Enterprise Security with all of its components is huge. If you're using something like a deployment server you can't break it up. It makes it rather unwieldy. I'm sure that there are workarounds that have not been implemented in-house.
What was our ROI?
Splunk provides more than the people who pay for it realize. I had a few exercises in presenting ROI and benefit-cost analysis and I have been able to demonstrate where it has performed superior to other options.
What's my experience with pricing, setup cost, and licensing?
I was deeply distressed when they went away from their perpetual license.
Which other solutions did I evaluate?
We evaluated Splunk's typical competitors. We went with Splunk because Splunk has the underlying capability of not only ingesting anything and storing it using their bloom filters and whatnot in order so that you can do sparse and large searches relatively quickly. It also has a wonderful presentation layer, which can basically plug into many other systems. I find Splunk to be a veritable Swiss Grey knife of capabilities.
What other advice do I have?
I would rate Splunk Enterprise Security an eight out of ten because there's always room for improvement and because it can be difficult to learn.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
Data Analyst
Offers integration with other risk-based solutions
Pros and Cons
- "If properly built, I'm very impressed with the stability of Splunk ES."
- "In terms of training. I find that some things about Splunk aren't well-explained. I see features and then go to the website but don't find good explanations."
What is our primary use case?
The primary use case is computer network defense.
How has it helped my organization?
It is very important that Splunk ES provides end-to-end visibility in our environment. Part of the solution is bringing the user closer to the resolution.
The integration with other risk-based solutions, such as the risk matrix applications included with Splunk, is helpful. It helps us identify the risks without having to delve into other resources.
Splunk helped improve our company's ability to ingest and normalize data. That's the primary use of Splunk Enterprise or Core. For ingestion, we've been using Splunk Enterprise for about six or seven years before we had ES. So, that was the primary reason we got it.
In terms of the risk-based part, Splunk improved our ability to ingest and normalize data. Initially, we used Splunk Enterprise Core for aggregation and correlation. We didn't have the risk-based reporting.
I'm very impressed with Splunk's ability to identify and solve problems in real time. And I look forward to the new version improving the product.
We've been able to discover things we didn't see before. So, there's more that we discover now.
Splunk ES provides us with the relevant context to help guide our investigation. It goes back to the time to resolution. We have to do much less investigation because it's already built-in alerting.
What is most valuable?
Risk-based reporting and anomaly detection are valuable features.
The biggest advantage is the reduced time to resolution. Before, it took us up to days to resolve issues, and with Splunk, we've been able to move that down to hours or even minutes in some cases.
What needs improvement?
I was just at the conference, and they spoke about and demoed a new version of Splunk. It looked like some pain points are resolved in the new solution, such as not having to go to so many different panels. Like to streamline or improve the UI.
In terms of training. I find that some things about Splunk aren't well-explained. I see features and then go to the website but don't find good explanations. However, I can always call support and get help.
For how long have I used the solution?
We purchased ES four years ago.
What do I think about the stability of the solution?
If properly built, I'm very impressed with the stability of Splunk ES. We initially stood it up on a single server, and to make it more robust, we had to break out of that single server concept to make it more resilient.
What do I think about the scalability of the solution?
The scalability is very good. That comes from our experience of having to scale out, and Splunk's documentation on scaling up is very good.
How are customer service and support?
Every time we've used Splunk support, it's been very good. We don't have any in-house Splunk engineers, but headquarters has some they can send to assist us, so I can call on them. It's a very good support chain.
If there is some room for improvement, it is in terms of training. I find that some things about Splunk aren't well-explained. I see features and then go to the website but don't find good explanations. However, I can always call support and get help.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
My company is very impressed with Splunk. We've used several SIEMs before, and Splunk has been the most efficient one.
There was one called Intelotactic, and another was called Secureworks. I believe both of those are gone now.
Initially, with Splunk, we had a steep learning curve. It went from a fairly low ingestion point to figuring out how much data we needed to get to a certain level. Even when we got to a level we were happy with; we found that we were ingesting a lot of noise in the data. We had to figure out ways to reduce that noise.
How was the initial setup?
We bought the maintenance along with Splunk ES and used Splunk engineers to assist us in the setup. It was a very good process. It worked out very well for us.
The knowledge of the individual sent to us was impressive.
Deployment model: Ours is all on-prem currently, but we are headed towards a cloud solution.
What other advice do I have?
I would rate it a nine out of ten.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Buyer's Guide
Splunk Enterprise Security
February 2026
Learn what your peers think about Splunk Enterprise Security. Get advice and tips from experienced pros sharing their opinions. Updated: February 2026.
884,933 professionals have used our research since 2012.
SIEM engineer at a computer software company with 1,001-5,000 employees
Helped improve our organization’s ability to ingest and normalize data but should work better out of the box
Pros and Cons
- "Splunk Enterprise Security helped improve our organization’s ability to ingest and normalize data."
- "In the next release, they should include machine learning-based rules that would streamline the process of finding anomalies."
What is our primary use case?
Our primary use case is to find brute-force attempts on our systems.
How has it helped my organization?
We use it for security purposes, to find malicious activity, and to find misusage of our business platform.
The main benefits we have from Splunk Enterprise Security are the alerts with which we can manage the searches and the notables which can be good for documentation.
What is most valuable?
Identity management is the most valuable feature.
Its ability to find any security event across any environment is useful if you use the risk parameter. If it can correlate with an identity or an asset, then correlations between such events are up to the analyst.
Splunk Enterprise Security helped improve our organization’s ability to ingest and normalize data.
Splunk helped to reduce our alert volume by 53%. We work based on an on-call process. The analyst who is on call can use Enterprise Security to see what alerts they have and work from there.
If you load it correctly, Splunk will provide us with the relevant context to help guide our investigations. It made it easier.
Splunk Enterprise Security helped improve our organization's business resilience.
In terms of its ability to create, identify, and solve problems in real-time, if the problem arises, we can go and look at Splunk, but if it's happening in real time and no one reports the issue, then it doesn't work in real time.
It helps consolidate networking, security, and IT observability tools but it doesn't have such a big impact on our company.
What needs improvement?
It should work better out of the box and have better use cases that would not require my intervention. For example, if I install an antivirus and endpoint protection on my computer, I don't need to do much. But to get any value from Splunk, I need to work hard on it.
In the next release, they should include machine learning-based rules that would streamline the process of finding anomalies.
For real-time detection, I would not say that Splunk is the best. If you experience a problem and go to Splunk to look at the dashboard, then it's in real-time. Because of the way Splunk works, I wouldn't get an alert in real-time.
For how long have I used the solution?
I have been using Splunk Enterprise Security for five years.
What do I think about the stability of the solution?
On newer servers, it can be stable. On our servers, it can take a while. We need to re-enter when we press selections.
What do I think about the scalability of the solution?
It is scalable. You can add more servers and analysts.
How are customer service and support?
Support depends on the issue. Sometimes they help but most of the time, I have to solve the issue on my own.
I would rate support a six out of ten. Usually, it can take time until I get to someone who can help. The diagnostics aren't always accurate. I once had an issue where they replaced a certificate that we weren't using, so it didn't solve the problem. It can take a few iterations to solve the problem.
How would you rate customer service and support?
Neutral
How was the initial setup?
The deployment is fine for me, but it is not really straightforward. I would suggest simplifying the process. For example, the whole certificate part is not secured by default. I would recommend fixing that.
What about the implementation team?
We used EMET Computing for the integration. They are fine.
What was our ROI?
We do see ROI. We can deduce the ROI from finding the damage that misusing our business platform is causing.
What's my experience with pricing, setup cost, and licensing?
I think that the price can be too high sometimes, especially for the cloud. We get a lot of logs that are meaningless. For example, if we are using a firewall, we get a message for every session or packet. A lot of those connections are the same. We pay a lot of money on the license and on logs that are the same. If there was a way to aggregate them, the cost of the license would be reduced.
What other advice do I have?
I would rate Splunk Enterprise Security a six out of ten. It is useful but it doesn't add that much value on top of standard Splunk. Because of our use cases and environment, we don't use all of the features it has. Nevertheless, the value it provides isn't so different from Splunk Core.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Makes it easier to read the index data
Pros and Cons
- "Its alerting is most valuable. We have alerts set up in our environment for certain attacks, such as an SQL injection attempt. We have a front-facing server for the website. It is out there, and anybody can access it. When those SQL injection attempts come in, we are able to detect that with the alert."
- "I do not have any pain points for Splunk Enterprise Security. I am still trying to learn it, but there can be more information on the education side for Splunk Enterprise Security. It would be nice if the certification path was more specific to what I use instead of being so broad."
What is our primary use case?
When we identify a threat in the environment, we try to track down whether it has moved from one system to another or there is any lateral movement. When we are trying to figure out how it got started and where it came from, we use Splunk to identify those logs. Palo Alto is our biggest index for the firewall, and we can look into those logs, see the relevant data, and correlate it into something that makes sense, so we can track down the problem.
How has it helped my organization?
For the most part, it makes it easier to read the index data. Instead of trying to look through an individual index, all the logs, and other aspects, it brings everything to one area. I can look at the relevant data that I need to identify the threat.
Splunk Enterprise Security has helped reduce our mean time to resolve. I do not have the metrics, but I know it is faster compared to the old way of doing it. Previously, we had to go through Windows logs and security logs. We had to go through each log to figure out what happened. I can pull all of the information way faster with Splunk Enterprise Security. I can look at multiple systems.
Splunk's unified platform has helped consolidate networking, security, and IT observability tools.
Splunk Enterprise Security brings all the logs into one central location to look at the relevant data and filter out the things I do not use. We are able to see the logs of multiple systems, the logs of the firewall, and the logs of the DNS and the Windows servers. It is able to bring all of that together and give a nice, solid picture of what is happening. We can read those logs faster.
Splunk Enterprise Security provides end-to-end visibility into the environment. It is very important for our organization to be able to see the threats, understand the threats, and figure out how to stop those threats. That is the importance of it. We are a casino. After what happened last year with two casinos in terms of hacking, we want to be able to stop that from happening to us. We learned a lot of lessons from what happened to the other two casino properties, and we applied them to a lot of our tools. Splunk Enterprise Security gives us a heads-up a lot faster.
Splunk Enterprise Security helped improve our organization’s business resilience.
What is most valuable?
Its alerting is most valuable. We have alerts set up in our environment for certain attacks, such as an SQL injection attempt. We have a front-facing server for the website. It is out there, and anybody can access it. When those SQL injection attempts come in, we can detect that with the alert. We get the alert in our mailbox, so we can start looking at it right away. Generally, with a SQL injection attempt, there is way more to it than just the SQL injection. There could be another 15 or 20 different types of attacks attempted during the injection. They are just trying to see if there is any vulnerability, and then they can take a shot at it.
What needs improvement?
I do not have any pain points for Splunk Enterprise Security. I am still trying to learn it, but there can be more information on the education side for Splunk Enterprise Security. It would be nice if the certification path was more specific to what I use instead of being so broad.
For how long have I used the solution?
I have been using Splunk Enterprise Security for about six months.
What do I think about the stability of the solution?
Besides the forwarder, it is nice. The forwarder ran out of space, so it occasionally has to be rebooted to clear out the space that is being utilized.
What do I think about the scalability of the solution?
We have 50 gigs of data.
How are customer service and support?
I never really had to use professional services. For the most part, everybody is knowledgeable and patient, and there is a decent amount of communication back and forth.
I would rate their support an eight out of ten. My biggest issue right now has not been solved yet. Our heavy forwarder ran out of space. It is a VM. By using vCenter, we presented more space to the drive, but we could not get the VM or the Linux OS to allocate the new space. So far, nobody has been able to help us fix that. The current solution is to just upgrade it. We are not in a position to upgrade it right now because of the workload.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
I changed my career last year to InfoSec. I was in IT before that. With IT, if there is a problem with the system, we just look at the logs. With Splunk, it is nice to be able to have it all centralized in my location where I can look at the data relatively fast as opposed to a line-by-line.
How was the initial setup?
I was not involved in its setup. We have a bit of a hybrid setup. We have an on-prem data center and then we also have a cloud. We have Azure Cloud.
What was our ROI?
I would say that we have seen an ROI, but I do not know the numbers.
What other advice do I have?
I would rate Splunk Enterprise Security a ten out of ten.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Security Delivery Analyst at a consultancy with 10,001+ employees
Improves our incident response time, has customizable dashboards, and speeds up our security investigations
Pros and Cons
- "I like the Splunk dashboard and search engine."
- "Although the technical support is adequate, there is still room for improvement."
What is our primary use case?
We use Splunk Enterprise Security for security log investigation. It is a SIEM platform. Many cybersecurity and technical alerts generated by Splunk turn out to be false positives. We then analyze these alerts to determine if they indicate a genuine security threat.
How has it helped my organization?
We will be ingesting logs from various sources, including firewalls, databases, Windows devices, and Linux devices. These logs will be used to investigate security incidents and troubleshoot system issues. Our use cases will be brief and focused, allowing us to leverage pre-defined queries in Splunk for efficient analysis. These queries will trigger alerts based on specific security or operational criteria within the predefined use cases. We will then investigate the triggered alerts by further analyzing the corresponding logs.
Splunk Enterprise has improved our incident response time. For instance, if an end user attempts to log in to a system with an invalid password from a device using an unusual port number, we will receive an immediate alert. This could be indicative of a brute-force attack aimed at stealing credentials, making it a suspicious activity. This is just one example of how Splunk Enterprise enhances our security posture.
Splunk's threat detection capabilities are strong, and Splunk is a leading platform for SoC monitoring. To maximize effectiveness, we need to develop strong query-building skills. Additionally, we have the flexibility to fine-tune existing queries or remove them altogether once an issue is resolved.
The customizable dashboards of Splunk are good for visualization. It gives a better understanding, and the graph is highly customizable.
I would rate Splunk Enterprise Security a nine out of ten for analyzing malicious activities.
Splunk Enterprise Security helped the organization control suspicious and malicious activities.
Splunk Enterprise Security has helped speed up our security investigations.
Splunk Enterprise Security's customization capabilities enable integration with other tools like EDRs, providing real-time event insights.
What is most valuable?
I like the Splunk dashboard and search engine.
What needs improvement?
Although the technical support is adequate, there is still room for improvement.
For how long have I used the solution?
I have been using Splunk Enterprise Security for 2 years.
What do I think about the stability of the solution?
I would rate the stability of Splunk Enterprise Security 9 out of 10.
What do I think about the scalability of the solution?
I would rate the scalability of Splunk Enterprise Security 9 out of 10.
How are customer service and support?
The technical support is adequate.
How would you rate customer service and support?
Positive
What other advice do I have?
I would rate Splunk Enterprise Security nine out of ten.
While I understand the desire for a cost-effective SIEM solution, prioritizing security over budget is crucial. In cybersecurity, even a seemingly minor breach can have significant consequences. Therefore, choosing the best SIEM for your needs, even if it has a higher upfront cost, can ultimately save money and protect your organization.
We have Splunk Enterprise Security deployed in four locations in one country.
Splunk takes care of the maintenance of the solution.
I recommend Splunk Enterprise Security to others.
Which deployment model are you using for this solution?
Private Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Other
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Service Management Lead at a consultancy with 10,001+ employees
Offers great visibility and good connectors to users
Pros and Cons
- "I have not seen any outages in the product in the past two years that it has been running in our company, so I think it is good when it comes to the stability part."
- "The product's price may be an area of concern where improvements are required."
What is our primary use case?
We use it in our company to log everything. We use tools like XSOAR to take appropriate actions to mitigate threats.
How has it helped my organization?
Splunk Enterprise Security has aided our organization in the way it provides great visibility and helps with what our company's users do with it.
What is most valuable?
I like how easy it is to integrate the logging of all of the various nodes. The product also offers nice connectors. Other features include the product's ability to allow users to customize their dashboards, signatures, metrics, and other elements, making it a very valuable and reliable tool for my organization.
What needs improvement?
I don't know if there is a need for any improvements in the product since it is one of my peers and not me who is directly responsible for Splunk Enterprise Security in our company, so I will have to ask him if there are any requirements associated with the product.
The price may be an area of concern where improvements are required. Splunk Enterprise Security doesn't indulge in whitewashing, but Cisco does it too much.
For how long have I used the solution?
I have been using Splunk Enterprise Security for two years.
What do I think about the stability of the solution?
I have not seen any outages in the product in the past two years that it has been running in our company, so I think it is good when it comes to the stability part. I have had an experience with the vendor during which there were two products, one from the vendor and the other from Splunk Enterprise Security, and we saw that one of them was not able to capture all the logs appropriately, after which our company had to figure out whether it was Splunk API or the vendor's tool.
How are customer service and support?
I have never used the product's customer support. My peer has contacted the product's technical support team, and it has worked very well for him.
Which solution did I use previously and why did I switch?
My company used to use one of the spin-offs from IBM. My organization has used IBM QRadar.
How was the initial setup?
Though I am not sure about the deployment model, I feel that since it may not be on Azure, the product must be deployed with the help of AWS.
What was our ROI?
I have experienced an ROI revolving around the product's dashboards, metrics, and other such related stuff, but I don't know how to quantify them. My peer would be the best person to speak about the product's ROI.
What's my experience with pricing, setup cost, and licensing?
My peer would be aware of the product's pricing part.
Which other solutions did I evaluate?
There was a pre-vendor selection approach my company followed, but I don't remember the names of the products involved.
What other advice do I have?
It is pretty important how the solution provides end-to-end visibility in our company's environment because it provides opportunities for shadow IT and for people to do things that they should be doing. If one is appropriately logging in, the product gives us a view and helps our company discover things that we didn't know about.
In terms of Splunk Enterprise Security's ability to help our company find any security events across multi-cloud, on-prem, or hybrid environments, I will have to say that since we are still using it, it has to be effective. If it wasn't effective in the aforementioned area, my peer would have found something else in the product. I don't have enough personal insight into Splunk Enterprise Security's ability to help our company find any security events across multi-cloud, on-prem, or hybrid environments.
Splunk Enterprise Security has helped to reduce my company's alert volume. Our organization does get alerts, and we are trained for them. I will have to ask my peer to give me the exact number associated with the alerts my company receives.
The solution provides the relevant context that helps guide our company's investigations. The context information has impacted our company's investigation process as it definitely speeds it up because we have only a single source from which we can get that, and it helps us understand what may have taken place in a particular incident that we are looking at in our organization. In our company, if we look at any of the other services, we can see whether a particular or specific user touched just a single system or ten different systems.
The solution has helped reduce my company's mean time to resolve, but I don't have numbers to explain it.
The reason why I rate the tool a nine is because of the flexibility it provides to go back to the dashboards. The flexibility to be able to customize standard dashboards and other standard things that I want to be able to grab and have them pop out and then be able to create some sort of an action against those kinds of things that I want, of which the first is the standard reporting part, which is very valuable.
To those planning to use the solution, I would suggest that they need to get Splunk to work hard on the pricing part. People also need to encourage Splunk to stay true to its roots because I have seen what has happened to some of the other tools in the market. Splunk has been acquired by Cisco. You want Splunk because of its capabilities, not because of what Cisco wants to give you.
If I consider my company's needs, I rate the overall product a nine out of ten.
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Amazon Web Services (AWS)
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Cyber Security Analyst at Clarusway
Is user-friendly, can easily monitor multiple environments, and reduces alerts
Pros and Cons
- "The most valuable feature of Splunk Enterprise Security is website activity monitoring."
- "While Splunk Enterprise Security offers valuable features, its cost is high and could be more competitive."
What is our primary use case?
We use Splunk Enterprise Security to monitor our network environment for abnormal activities and threats.
How has it helped my organization?
We easily monitor multiple cloud environments with Splunk Enterprise Security.
Insider threat detection helps our security posture.
I use the threat intelligence management feature whenever I do a threat analysis.
When Splunk detects breaches and malicious activities it notifies our IT team so they can analyze the notifications and respond accordingly.
Splunk has helped our organization by allowing us to gain valuable insight through the analysis of large datasets.
The customizable dashboards are user-friendly and visually appealing.
It has helped reduce our alert volume.
It has helped speed up our security investigations.
What is most valuable?
The most valuable feature of Splunk Enterprise Security is website activity monitoring.
What needs improvement?
While Splunk Enterprise Security offers valuable features, its cost is high and could be more competitive.
For how long have I used the solution?
I have been using Splunk Enterprise Security for around five months.
What do I think about the stability of the solution?
Splunk Enterprise Security is stable.
How are customer service and support?
We frequently connect with the support team to review our options. They resolve our issues quickly.
How would you rate customer service and support?
Neutral
Which solution did I use previously and why did I switch?
We also use IBM QRadar but Splunk Enterprise Security is more functional and user-friendly.
What's my experience with pricing, setup cost, and licensing?
Splunk Enterprise Security is expensive.
What other advice do I have?
I would rate Splunk Enterprise Security eight out of ten.
For someone who wants to use the cheapest solution, I would tell them that this is the best solution and worth the cost.
I recommend Splunk Enterprise Security to others.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Owner at Infrasec
Offers advanced threat detection, robust log management and powerful analytics to enhance organization's cybersecurity posture
Pros and Cons
- "The most valuable features for us include its robust log management capabilities, which allow us to efficiently handle and retain logs for extended periods as needed."
- "I find that the learning curve for Splunk is relatively lengthy."
What is our primary use case?
The primary focus of our work with Splunk is on security incident monitoring and security log monitoring. This involves utilizing it to analyze and respond to security events effectively. Additionally, compliance with regulatory requirements is another crucial aspect of your role. We also extend Splunk's functionality to custom applications by writing custom parsers and handling logs specific to those applications. This includes the development of unique dashboards tailored to the needs of each application.
How has it helped my organization?
Splunk's capabilities in insider threat detection are highly effective in assisting organizations in identifying unknown threats and anonymous user behavior. The sophistication of these features is notable, making them suitable and beneficial across a range of organizational sizes, from small businesses to large enterprises.
The threat topology and MITRE ATT&CK features are seamlessly integrated as complementary components within Azure.
It significantly accelerated security investigations, and I believe the improvement falls within the range of twenty to thirty percent.
The resilience provided by SIEM adds significant value; it is highly effective.
What is most valuable?
The most valuable features for us include its robust log management capabilities, which allow us to efficiently handle and retain logs for extended periods as needed. The flexibility to customize log retention periods is particularly beneficial. Additionally, we find the dashboard functionality and the advanced query language options to be highly valuable. These features, especially the powerful query language, are extensively utilized in our day-to-day operations.
What needs improvement?
I find that the learning curve for Splunk is relatively lengthy. To utilize it effectively, one needs a substantial amount of time for learning. I might appreciate a learning curve that comes with more out-of-the-box functionality, such as easily installable Splunk apps or user-friendly features.
For how long have I used the solution?
I have been working with it for three years.
What do I think about the stability of the solution?
I find it to be highly stable, and I would rate it a solid ten out of ten.
What do I think about the scalability of the solution?
I would rate its scalability capabilities ten out of ten.
Which solution did I use previously and why did I switch?
Before using Splunk, I relied on the built-in tools of Linux operating systems, such as Syslog NG, but specifically the open-source versions. I haven't had experience with the commercial version of Syslog NG, which is a more advanced tool. In this category, Splunk is essentially my first exposure to such advanced features.
How was the initial setup?
Setting up Splunk is quite straightforward, especially for basic configurations. The process is not overly complicated. While a cluster implementation may require more advanced steps, the basic setup is generally easy to handle.
What about the implementation team?
I handled the deployment independently, but the required personnel depends on the organization's size and the expected outcomes. For larger organizations, especially when the new tool integrates with various departments like operations, development, and security, it becomes a collaborative effort. In such cases, it's not a one-person job and involvement from multiple departments is essential. However, for smaller companies, the process is less complicated. It involves coordinating with support and developer teams to communicate the implementation, and the focus is on providing the necessary outputs from the tool to support their ongoing work effectively.
I utilized it in a single, non-geographically dispersed location. My experience is limited to a single site, and I haven't worked on a multi-site installation.
While it can run stably for a certain period, eventually, there is a need to manage or archive logs, especially if your background storage is not unlimited, as is often the case in these scenarios.
What was our ROI?
The return on investment is quite favorable with Splunk, particularly for large enterprises that have made the initial purchase and possess the requisite expertise and technical support.
What's my experience with pricing, setup cost, and licensing?
In terms of pricing, I believe Splunk is unreasonably costly for the majority of mid and small-sized companies. Its real advantages, or what sets it apart, seem to be more suitable for large enterprises.
What other advice do I have?
For the market I focus on, which includes small to medium-sized companies, I would recommend Wazuh. It's an open-source security information and event management solution. The main consideration is that, in terms of both functionality and cost, Wazuh is sufficient for the requirements of smaller enterprises. Utilizing an open-source tool like Wazuh can effectively cover the necessary areas without the need for the higher costs associated with Splunk.
I would recommend that anyone considering implementing Splunk should first thoroughly assess their environment. It's crucial to determine whether Splunk is genuinely needed for your specific usage scenario or if a smaller software solution might suffice. Overall, I would rate it nine out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Buyer's Guide
Download our free Splunk Enterprise Security Report and get advice and tips from experienced pros
sharing their opinions.
Updated: February 2026
Product Categories
Security Information and Event Management (SIEM) Log Management IT Operations AnalyticsPopular Comparisons
CrowdStrike Falcon
Microsoft Sentinel
IBM Security QRadar
Splunk AppDynamics
Elastic Security
Grafana Loki
Elastic Observability
Palantir Foundry
Graylog Enterprise
Security Onion
Buyer's Guide
Download our free Splunk Enterprise Security Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- Which would you recommend to your boss, IBM QRadar or Splunk?
- What are some of the best features and use-cases of Splunk?
- What SOC product do you recommend?
- Splunk as an Enterprise Class monitoring solution -- thoughts?
- What is the biggest difference between Dynatrace and Splunk?
- IBM QRadar is rated above competitors (McAfee, Splunk, LogRhythm) in Gartner's 2020 Magic Quandrant. Agree/Disagree?
- What are the advantages of ELK over Splunk?
- How does Splunk compare with Azure Monitor?
- New risk scoring framework in the Splunk App for Enterprise Security -- thoughts?
- Splunk vs. Elastic Stack
















