We are using Splunk for querying data from different sources.
Senior Manager, Analytics & Insights at a consultancy with 10,001+ employees
Effective machine learning, reliable, and responsive support
Pros and Cons
- "Splunk has machine learning which is a valuable feature."
- "The algorithms customization of Splunk could improve. They have limited algorithms for machine learning support. If they can allow the user to add more machine learning algorithms, such as the ability to choose the algorithm that a user might want. Additionally, they should provide the required libraries for those algorithms, and then analyzes the data for use."
What is our primary use case?
What is most valuable?
Splunk has machine learning which is a valuable feature.
What needs improvement?
The algorithms customization of Splunk could improve. They have limited algorithms for machine learning support. If they can allow the user to add more machine learning algorithms, such as the ability to choose the algorithm that a user might want. Additionally, they should provide the required libraries for those algorithms, and then analyzes the data for use.
For how long have I used the solution?
I have used Splunk within the past 12 months.
Buyer's Guide
Splunk Enterprise Security
June 2025

Learn what your peers think about Splunk Enterprise Security. Get advice and tips from experienced pros sharing their opinions. Updated: June 2025.
861,524 professionals have used our research since 2012.
What do I think about the stability of the solution?
Splunk is a stable solution.
How are customer service and support?
We have contacted the support and most of the reasons we have contact support has been project-related. For example, we want the APAs to work in a certain way or for certain fixes.
What other advice do I have?
I have been using Splunk for approximately
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.

Information Security Officer at a financial services firm with 501-1,000 employees
Simple to set up with good log management and responsive technical support
Pros and Cons
- "You can check up on security from the dashboards."
- "There can be a bit of complexity around some fields during the initial setup."
What is our primary use case?
We primarily use the solution for log management and security purposes.
What is most valuable?
The log management is great.
It has a very good alert tool that you can create with the logs that Splunk gets.
You can check up on security from the dashboards. We use some custom applications which we have created by ourselves. It's very helpful to have custom dashboards with knowledge of the system of what we monitor.
The initial setup is simple.
We have found the solution to be stable.
Its scalability is quite good.
What needs improvement?
Right now, everything is good. I don't really have notes for aspects of improvement.
There can be a bit of complexity around some fields during the initial setup. There are some places where you have to use regular expressions to parse logs. The part of parsing logs correctly is the most, let's say, difficult thing, and when this is done, all of the other things are easier. Anyway, the regex part is a very good feature and in my opinion, it should stay like it is, because it gives a lot of flexibility. Customers may learn to use it or use technical support.
The cost of the solution is a little bit high.
For how long have I used the solution?
I've used the solution since 2016. I've used it for around six years at this point.
What do I think about the stability of the solution?
In terms of stability, it's reliable. There aren't bugs or glitches. it works well. It doesn't crash or freeze.
What do I think about the scalability of the solution?
The solution is scalable. If a company needs to expand it, it can do so.
How are customer service and support?
We have a technical support contract.
For the most part, we can do it probably ourselves. When technical support helps us, however, everything goes pretty smoothly. We are quite satisfied with them. We typically get immediate support and assistance.
How was the initial setup?
The ease or difficulty of the initial setup depends on the infrastructure of the organization. However, when we have installed it, it was pretty simple. That said, there are some fields that are complex, and for this, we have support.
What about the implementation team?
We did get support to assist us with a few complex fields.
What's my experience with pricing, setup cost, and licensing?
We pay a yearly license. You do need to set up a contract for technical support.
While I don't have details about the exact pricing, my understanding is that it can be a bit expensive.
What other advice do I have?
We are a customer and an end-user.
I would rate the solution at a nine out of ten. We've been very happy with its capabilities in general.
The only downside is the pricing. If the price would be lower, you would have the possibility to buy more capacity for parsing logs per day. In Splunk, you have a daily limit of logs that will be parsed. If you place that limit several times, the Splunk license will be blocked and you have to talk with support to get a recovery license. With the capacity, you can include, let's say, 30 servers, but if you want to include another 20 servers, you have to buy an additional license, which is very costly.
That said, for medium and large enterprise businesses it's really necessary to have. Even in smaller businesses, it is good to have. It's just the price that would stop small businesses from taking it on.
If a small business has less than 500 MB logs/day, they may use a splunk free license.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Buyer's Guide
Splunk Enterprise Security
June 2025

Learn what your peers think about Splunk Enterprise Security. Get advice and tips from experienced pros sharing their opinions. Updated: June 2025.
861,524 professionals have used our research since 2012.
Account Presale at a tech services company with 1,001-5,000 employees
A flexible solution
Pros and Cons
- "Splunk is quite flexible for our customers. Splunk does not filter from a specific lock, you can define it later."
- "I would like Splunk to add more integration. QRadar has many indications with more products than Splunk."
What is our primary use case?
The project we are working on with Splunk is short as the customer has given us two months to implement. My company is a Splunk partner.
What is most valuable?
Splunk is quite flexible for our customers. Splunk does not filter from a specific lock, you can define it later.
What needs improvement?
I would like Splunk to add more integration. QRadar has many indications with more products than Splunk.
For how long have I used the solution?
I have been working with Splunk for three months.
What do I think about the scalability of the solution?
Splunk is quite good if you want to scale it.
Which solution did I use previously and why did I switch?
My client has some pain points with QRadar and does not feel the kilogram function is accurate. Other features do not match with the customer behavior as well. They want to replace QRadar with Splunk because they are familiar with this solution.
How was the initial setup?
The initial setup of Splunk is complex. It requires a lot of equipment and uploads.
What about the implementation team?
My company provides the implementation and maintenance services to our customers.
What's my experience with pricing, setup cost, and licensing?
Splunk licensing requires you to purchase licenses for any feature per user. For example, if you need UEBA, it is difficult to propose in the project. QRadar has a free upcharge for UEBA. Customers cannot calculate the additional costs based on gigabytes per day because they can not forecast the future.
What other advice do I have?
Due to the cost of Splunk, I recommend it for larger companies. Splunk is powerful when sorting huge amounts of data.
Implementation of Splunk takes preparation. It requires a lot of resources and needs the infrastructure to support the project.
I would rate the solution an 8 out of 10.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
Cybersecurity Senior Manager at a tech services company with 10,001+ employees
Simple data file updates, good support, and useful dashboards
Pros and Cons
- "The connections to the database are very good and updating the data files is simple to do. The dashboards are useful and user-friendly."
- "We had some connections issues with the solution at the beginning."
What is most valuable?
The connections to the database are very good and updating the data files is simple to do. The dashboards are useful and user-friendly.
What needs improvement?
We had some connections issues with the solution at the beginning.
For how long have I used the solution?
I have used Splunk within the last 12 months.
What do I think about the stability of the solution?
Splunk is a highly stable solution.
What do I think about the scalability of the solution?
The scalability is good.
We have approximately 50 users using this solution in my organization.
How are customer service and support?
I am satisfied with the support from Splunk.
Which solution did I use previously and why did I switch?
We were previously using Excel.
What about the implementation team?
We used a consultant for the implementation of the solution. The full process took approximately one week.
We had a big problem with communication sometimes during the implementation. Some files in our network were a little difficult to receive. This was our fault because of some of our firewall configurations.
We have a five-person maintenance team that works on this solution.
What other advice do I have?
I rate Splunk an eight out of ten.
Which deployment model are you using for this solution?
Hybrid Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
CTA\Owner at UCSolutions
Easy to use and simple to set up with reasonable pricing
Pros and Cons
- "The SIEM is the most valuable feature of the product."
- "The documentation is in definite need of improvement."
What is our primary use case?
I need the product for SIEM, Security Identity Event Management. I also need it for security operations, automated response, as well as mapping adjusting of security components as well. It helps us with how best to look at various events, and orchestrate between various different hyper-scalers.
How has it helped my organization?
The solution has made us more secure and has allowed for more definable mapping.
What is most valuable?
The SIEM is the most valuable feature of the product.
Having a better integration method and then ingesting and mapping the information have been somewhat easier than some of the other tools that I've used previously (other than QRadar and Rapid7).
The initial setup is pretty simple.
The solution is scalable.
Stability has been quite good.
The pricing is pretty decent.
What needs improvement?
The documentation is in definite need of improvement.
There are pieces of it that are somewhat just daunting and there should be better orchestration and automation.
I've done some automation with it, with Terraform, and also with some other sources. If it wasn't so proprietary, that would be ideal.
I'd like to have it so that Splunk integrates better with Terraform and Python.
For how long have I used the solution?
I've used the solution for eight years. I've used it for quite a while.
What do I think about the stability of the solution?
Splunk is probably the best brand in terms of stability. I'd rate its reliability at a four out of five. There aren't bugs or glitches. It doesn't crash or freeze.
What do I think about the scalability of the solution?
The scalability is great. I'd give it a score of four out of five. If a company needs to expand, it can do so.
We have 450 people in our organization that use the product. We've also done this for clients that needed access for over 200,000 people.
We use the solution extensively and likely will increase usage.
How are customer service and support?
The support is okay, however, there are a couple of things that they couldn't figure out and they couldn't help me with automation or stuff like that. It could have been better from there, however, it's not that bad.
Which solution did I use previously and why did I switch?
I've previously used QRadar and it wasn't ideal.
There were certain times I integrated with other solutions too.
How was the initial setup?
The initial implementation is pretty simple and straightforward. It's not too complex. I'd rate the experience at an eight out of ten.
The initial deployment took us about two weeks or so.
The amount of personnel you need for deployment and maintenance tasks depends on the size of the deployment. Typically, it's just one or two people. That said, it needs to be proportionate to certain sizes. Usually, the staff is from procurement or provisioning.
What about the implementation team?
I handled the implementation myself. I didn't need any outside assistance from any integrators. I'm a consultant myself.
What was our ROI?
We've seen quite extensive ROI, however, it's more of a qualitative assessment and I don't have numbers to share. It works well and customers are happy. That's what counts.
What's my experience with pricing, setup cost, and licensing?
It's a little bit more expensive than some of the other tools. It's not as expensive as QRadar. That said, it's more expensive than LogRhythm or Sentinel.
There aren't really other fees beyond the standard costs of licensing.
Which other solutions did I evaluate?
I evaluated other things. I also integrated with other solutions too. I decided to go with Splunk due to the fact that it worked well.
What other advice do I have?
I'm a consultant. I'm also a customer and use it myself.
We use multiple deployment models, including public and private clouds.
We typically use the latest version of the solution.
I'd advise potential new users to get a proper plan. They should have a good partner or someone that can help them and quickly map and orchestrate.
I'd rate the solution at a ten out of ten.
Which deployment model are you using for this solution?
Public Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Head Of Sales at Cascade Solutions Inc
Powerful lock server with sophisticated architecture
Pros and Cons
- "Great platform with user-friendly interface and GUI."
- "Splunk is more expensive than other solutions."
What is most valuable?
Splunk has a great platform. Their edge is in their lock management and being a very powerful lock server. Recently, they added some licensing and updated correlation rules to act as a SIEM Solution. They seem to be penetrating the market in a proper way.
For how long have I used the solution?
I have been using Splunk for more than five or six years.
What's my experience with pricing, setup cost, and licensing?
Splunk solutions are much more expensive than others. Especially when it comes to megaprojects or deals, there's a lot of competition when it comes to financials.
What other advice do I have?
I would rate this solution a seven out of ten. Splunk has a user-friendly interface and GUI. Its architecture is also much more sophisticated than others.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Regional Head at a tech services company with 51-200 employees
Good technical support, scalable, and very stable
Pros and Cons
- "It's basically one of the best SIEM products on the market."
- "You do need a lot of training and certification with this product."
What is our primary use case?
The solution is primarily a SIEM tool and it basically helps companies with security.
What is most valuable?
It's basically one of the best SIEM products on the market.
The scalability is great.
We have found the solution to be stable.
Technical support is helpful. They respond in a timely manner.
What needs improvement?
I'd like to see more documentation on the product.
The initial setup is not straightforward.
You do need a lot of training and certification with this product. Other than that, it's pretty good.
For how long have I used the solution?
I've been dealing with the solution for about three years. It's been a while.
What do I think about the stability of the solution?
The stability of the product is very good. The performance is reliable. There are no bugs or glitches. it doesn't crash or freeze. We've had no issues.
What do I think about the scalability of the solution?
The scalability of the solution is great. If a company needs to expand it, it can do so. It's not a problem.
We have about nine customers that are using Splunk.
How are customer service and support?
I've dealt with technical support and it's pretty good. They are helpful. I find them responsive.
How was the initial setup?
The initial setup is not straightforward. It depends upon the IT infrastructure that the customer has. If they have a lot of security solutions, such as DLP and other security solutions, then it is more complicated. The more you have the more complicated it gets.
The deployment of Splunk takes about three weeks.
We have six or seven team members within our organization that can handle deployment and maintenance tasks.
What about the implementation team?
I handled the implementation myself. It was done in-house.
What's my experience with pricing, setup cost, and licensing?
Splunk requires a paid license. There's no free option. Customers have to pay for the license, implementation, support - everything.
What other advice do I have?
The solution can be deployed both on-premises and on the cloud.
I'd rate the solution at a nine out of ten. We've been very happy with the product.
I would recommend the solution. It really is the best.
Which deployment model are you using for this solution?
Public Cloud
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
Principal Enterprise Architect at Aurenav Sweden AB
Handles a high volume of data, collects information from multiple sources, and is very stable
Pros and Cons
- "The reporting aspect is good and it does what I need it to do."
- "If you monitor too much, you can lose performance on your systems."
What is our primary use case?
In our organization, Splunk is used in our data centers.
We have integration services and other types of systems in our new IoT architecture. We're using it to capture information.
We use Splunk as an aggregator for monitoring information from different sources, however, for our protection suite, we're using Comodo.
It's designed to collect data from different points. It has a lot of integrations built into it and that's why we're using it.
We use it for our enterprise more - such as for messaging. There's a lot of stuff we do on our integration services layer that we use Splunk for. For security purposes, we're using Comodo. Therefore we're not using Splunk for security purposes. We're using it for monitoring what's happening at our integration services layer.
How has it helped my organization?
Splunk indicates when we've got problems popping up somewhere or we're not getting the flow we expected. If there's a problem, we have those flagged and we use it for logging.
What is most valuable?
Splunk handles a high volume of data that we have, and it does it really well.
For what we're using it for, we're happy with its functionality.
The reporting aspect is good and it does what I need it to do.
From an operational standpoint, it helps us on the operations side and it also shows where we're having issues.
It connects to a lot of stuff. We can collect information from a lot of sources.
What needs improvement?
The interface or maybe some settings need to be improved a bit. It cannot be perfect, however, the issues may be related to the configuration or setup.
If you monitor too much, you can lose performance on your systems. You have to be careful what you're monitoring. If you monitor everything, everything stops working. You can go overboard in monitoring. You have to plan your monitoring pretty carefully.
It could be easier for beginners. As it is, right now, You have to have a good understanding of the solution in order to use it properly.
That said, as the user, I'm at a higher level of management on the architecture side in dealing with resilience. My concerns are different from other user concerns. Also, most of our clients are using it way more than we're using it.
For how long have I used the solution?
We've used the solution for more than a decade. It's been a long time.
What do I think about the stability of the solution?
We haven't had any problems with stability. There are no bugs or glitches. It doesn't crash or freeze. It's reliable.
What do I think about the scalability of the solution?
We've never had an issue with scalability. If a company needs to scale, it can.
The danger of Splunk is that it can get too big too quickly and you have to be very careful with what you want to be monitoring due to the fact that if you monitor too much, you can slow down things and you can hurt your performance on your system. We have to be very careful of what we're logging.
We have about 12 users on the solution right now.
We do not plan to increase usage in the future.
How are customer service and support?
We don't use technical support very much. We've been using it for so long, we generally understand it and do not require assistance.
Which solution did I use previously and why did I switch?
We used to use Splunk a lot more, however, we've moved more to Comodo right now. I'd say we've moved to Comodo from Splunk in a lot of areas.
On the security side, we use Comodo. Not all of our clients even have Comodo. A lot of them are using Splunk, however, a lot of them are using Splunk for enterprise operations and network operations items. Some of them are using security and a lot of them aren't. Splunk is offered as a security option now, however, originally, when you used it, it was to collect enterprise operations information and know-how your systems are running.
How was the initial setup?
We've been using it for a long time, therefore, I don't even remember when we set it up or how it went. We do keep it updated and use the latest versions.
I only have one or two people doing maintenance on it.
What was our ROI?
ROI's a hard thing to pin down. We've had it for so long, it's part of our core operating infrastructure.
What's my experience with pricing, setup cost, and licensing?
Everything we do is either yearly or multi-year. I don't know if there is any additional cost to standard license fees.
What other advice do I have?
We use Splunk and we also sell and support it for our clients.
Normally our policy is to keep software updated to the latest version.
The main issue is that we do enterprise architecture and network and security operations. We recommend certain platforms to clients. We don't always sell Splunk directly to them due to the fact that, since we're being hired to help them make choices, we need to be neutral. In the cases where it doesn't make sense, we don't sell it. We just help clients make decisions.
I don't know which version of the solution we're using. I'm an architect; I'm not on the operations level. I'm not the one who actually uses it. Our operations use it. I get dashboard results and I do reports that are based on it, however, I'm not the one actually running it. We have a NOC and a SOC and others use it a lot more individually. They have a lot more interaction than I do. I'm getting reports out of it. Others are actually connecting to it, using it as a tool. I'm not a tool user. I'm an information user.
All Splunk is, is data collection and it can sort things out on a dashboard. However, a lot of what Splunk does is collect data and you have to decide what kind of information you're going to let it collect. When we're doing design operations we have to really pay attention to what we're doing, so we don't actually slow things down or impede things. The reason we use Splunk is we put a lot of data into it.
With Splunk, you need to really be careful about what you're monitoring and how you use it, to get keep the results working. It's a good tool if you know what you're doing and what you need to be logging. You need to be aware of what you're logging to ensure it isn't going to cause problems with your performance.
I wouldn't recommend it for somebody who's coming in new. Of the clients we have using it, I don't know if any of them don't have professional IT running it. It's important to really understand what's going on.
I'd rate the solution at an eight out of ten. In certain environments, it could be a bit complex. It's not something you could just drop into an organization, you need to be trained to use it. You need the experience to use it properly.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.

Buyer's Guide
Download our free Splunk Enterprise Security Report and get advice and tips from experienced pros
sharing their opinions.
Updated: June 2025
Product Categories
Security Information and Event Management (SIEM) Log Management IT Operations AnalyticsPopular Comparisons
CrowdStrike Falcon
Microsoft Sentinel
IBM Security QRadar
Elastic Security
Splunk AppDynamics
Elastic Observability
Grafana Loki
Security Onion
Palantir Foundry
Cortex XSIAM
Buyer's Guide
Download our free Splunk Enterprise Security Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- Which would you recommend to your boss, IBM QRadar or Splunk?
- What are some of the best features and use-cases of Splunk?
- What SOC product do you recommend?
- Splunk as an Enterprise Class monitoring solution -- thoughts?
- What is the biggest difference between Dynatrace and Splunk?
- IBM QRadar is rated above competitors (McAfee, Splunk, LogRhythm) in Gartner's 2020 Magic Quandrant. Agree/Disagree?
- What are the advantages of ELK over Splunk?
- How does Splunk compare with Azure Monitor?
- New risk scoring framework in the Splunk App for Enterprise Security -- thoughts?
- Splunk vs. Elastic Stack