We have found all the features useful. However, the dashboarding and logging have been very helpful. Additionally, the log analysis does a great job.
Senior Technical Lead at a financial services firm with 10,001+ employees
Priced reasonably, effective log analysis, but artificial intelligence features need improvement
Pros and Cons
- "We have found all the features useful. However, the dashboarding and logging have been very helpful. Additionally, the log analysis does a great job."
- "The solution could improve by giving more email details."
What is most valuable?
What needs improvement?
The solution could improve by giving more email details.
In a future release, the solution could improve on the artificial intelligence features, such as if an alert comes, it could automatically do logging from the system, get the KV knowledge base, and perform other functions. This would be a benefit.
For how long have I used the solution?
I have used Splunk for approximately five years.
How are customer service and support?
The technical support is good.
Buyer's Guide
Splunk Enterprise Security
June 2025

Learn what your peers think about Splunk Enterprise Security. Get advice and tips from experienced pros sharing their opinions. Updated: June 2025.
861,524 professionals have used our research since 2012.
How was the initial setup?
The initial setup is complex.
What's my experience with pricing, setup cost, and licensing?
The price of Splunk is reasonable.
Which other solutions did I evaluate?
We have evaluated SoapUI and Postman, and we are still evaluating others.
What other advice do I have?
I rate Splunk a seven out of ten.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.

Senior Network Engineer at a tech services company with 51-200 employees
Useful search function, beneficial session reports, but performance could improve
Pros and Cons
- "The most valuable features in Splunk are the search function and the ability to run selected session reports. The session reports are important because I can use them to see what is going on in our environment weekly. Additionally, we can use the graph to see how often that particular event is happening."
- "Over time I will have more requirements and I can foresee the solution could improve the search algorithm to run and output the data faster."
What is our primary use case?
We typically use Splunk to collect and check all the logs and events around the diverse network environment which includes, firewall, switches, and routers. For example, we have traffic that needs to go from one part of the network to another and if we think there is a firewall blocking it along the path, rather than log in to all the firewalls to see what is happening, we simply go into Splunk and the check traffic going across the parts of the network to see where it is being dropped and what is the likely reason it has been dropped.
How has it helped my organization?
Splunk has saved our organization time by resolving problems in a quicker timeframe. Before if we had networking issues we would have to log into every single device, check the firewall to see why the traffic is not going across to solve the problem. With Splunk, you only have a single pane of glass to check what is likely happening. This has enabled us to easily go to the right environment and write the necessary security policy to permit such traffic. It brings about faster resolution of problems reduced with visibility.
What is most valuable?
The most valuable features in Splunk are the search function and the ability to run selected session reports. The session reports are important because I can use them to see what is going on in our environment weekly. Additionally, we can use the graph to see how often that particular event is happening.
What needs improvement?
Over time I will have more requirements and I can foresee the solution could improve the search algorithm to run and output the data faster.
For how long have I used the solution?
I have been using Splunk for approximately six months.
What do I think about the stability of the solution?
We have been satisfied with the stability of the solution.
What do I think about the scalability of the solution?
Slunk scale very well.
We have approximately 50 people in our infrastructure and applications teams using this solution in my organization.
We plan to increase usage in the future.
How are customer service and technical support?
I have not needed to open a ticket up with technical support.
Which solution did I use previously and why did I switch?
Previously to using Splunk we only had some Syslog servers that we sent logs to. However, Syslog servers, do not analyze your logs, they only capturing them. Whereas, in Splunk, you can assess the logs and you can do other things with the log.
How was the initial setup?
I do not think the implementation is difficult.
What about the implementation team?
We have an internal team that does the maintenance of the solution.
Which other solutions did I evaluate?
I have evaluated DataDog.
What other advice do I have?
Splunk is easy to use and not having the need to log into every single network device for management is helpful.
I rate Splunk a seven out of ten.
Which deployment model are you using for this solution?
Public Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Buyer's Guide
Splunk Enterprise Security
June 2025

Learn what your peers think about Splunk Enterprise Security. Get advice and tips from experienced pros sharing their opinions. Updated: June 2025.
861,524 professionals have used our research since 2012.
Senior Cyber Security Expert at a security firm with 11-50 employees
Great performance, easy to set up, and offers good speed
Pros and Cons
- "The level of robustness on offer is very good."
- "The complexity could be worked on so that it's even easier and faster."
What is our primary use case?
Typically, we use the solution for critical infrastructure companies.
What is most valuable?
The speed is a very valuable aspect of the solution.
The way Splunk handles low data and low-rate costs are great.
The level of robustness on offer is very good.
The initial setup is very straightforward.
We have found that the solution offers good integrations with other products.
Overall, the solution works very well.
What needs improvement?
The complexity could be worked on so that it's even easier and faster. However, I understand that, if some complexity was removed, there might be slightly more limitations.
Occasionally there are data sizing and data-related issues that need to be overcome.
For how long have I used the solution?
I've been using the solution for a couple of years.
What do I think about the stability of the solution?
The performance is very good. It's something that customers are always looking for. The product offers good stability. There are no bugs or glitches and it doesn't crash or freeze. It's reliable.
What do I think about the scalability of the solution?
We have about five to ten partners that use Splunk.
Which solution did I use previously and why did I switch?
I'm a fan of QRadar. I use them as well.
How was the initial setup?
The initial setup is very straightforward. It's not overly complex or difficult. A company shouldn't have any issues with the process. The deployment process doesn't take too long. You can manage it with fewer people and smaller teams. This is especially true if it isn't the critical infrastructure that you are working with.
For deployment and maintenance, you only need two to three people. That can include one manager and two professionals. Since Splunk is easier to handle, more people can join in on the client-side.
What's my experience with pricing, setup cost, and licensing?
We also use QRadar, and we make more money with QRadar than with Splunk as we can make bigger projects happen. However, we find that with Splunk, while we don't make as much money on each project, we can do more of them.
What other advice do I have?
I'd rate the solution at an eight out of ten.
Which deployment model are you using for this solution?
Public Cloud
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
Founder at a marketing services firm with 11-50 employees
Easy to deploy and relatively simple learning curve; could be more user friendly
Pros and Cons
- "Easy to deploy and simple to use."
- "Could be more user friendly."
What is our primary use case?
We're using the solution to try to build a virtual network and put Splunk inside it and do some kind of transcentralization with a log server. Our aim is to track connections, network traffic and some personal databases. I'm the founder of the company and we are customers of Splunk.
What is most valuable?
Splunk can quickly be deployed and it's not difficult to learn the solution.
What needs improvement?
The solution could be more user friendly and it's difficult to know at this stage whether our requirements will be met by the solution.
For how long have I used the solution?
I've been using this solution for a couple of months.
What do I think about the stability of the solution?
The solution is stable.
What do I think about the scalability of the solution?
Scalability is good with Splunk.
How was the initial setup?
The initial setup doesn't take much time especially if there's good bandwidth. In a small company deployment might take a month or two. If you have 100 devices then a technical team of three should be sufficient. They would need to be able to deal with log analysis, forensics and have general knowledge about admin systems. In time, we would expect to have thousands of users.
What's my experience with pricing, setup cost, and licensing?
I think Splunk is expensive compared to other tools at the purchase stage. It's possible that if we can keep control of the costs involved down the track, it won't be so bad.
Which other solutions did I evaluate?
We studied four or five tools including Logrhythm and Exabeam. We went with Splunk for now and will see how that goes.
What other advice do I have?
I think this is a good solution and rate it a seven out of 10.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
CHRO at a computer software company with 5,001-10,000 employees
Can be easily scaled and integrated with other solutions, but underscores in comparison with QRadar
Pros and Cons
- "The solution is stable and reliable."
- "The solution should also have more advanced capabilities in comparison with QRadar, which offers Watson."
What is our primary use case?
As there is no SIEM solution here at present, we are building it up through the assistance of a vendor. In the past I worked in the Splunk Cloud, which was seven-point something. With QRadar I worked on version 7.3.
We use Splunk Cloud as a SIEM solution and to monitor traffic and the network for detection purposes. We can create use cases so that if the solution picks up on anything entering our organization, the malicious IP can be blocked.
In respect of ones which are suspicious, based on the logs we pull from the data source, we can build the use cases accordingly and have our analysts work on these.
What needs improvement?
In the several years I have worked with the solution, I have felt there to be a need for practice of queries and understanding. As with other areas needing practice, the more one learns and practices, the easier things become.
While this is not terribly difficult, it is so when compared with QRadar. This holds true when we don't know the queries at all. Other than this, it is a great tool.
The solution should also have more advanced capabilities in comparison with QRadar, which offers Watson. The product should have add-ons.
What do I think about the stability of the solution?
The solution is stable and reliable.
What do I think about the scalability of the solution?
The solution is easy to scale, to add on and to integrate with other solutions. I am familiar with app integrations. Many solutions can be integrated with Splunk Cloud, such as CrowdStrike or Symantec.
How are customer service and technical support?
The solution's response time is not that fast. The experience of some of my peers is that the vendors have actively offered help. By contrast, when I tried Splunk Cloud's technical support I did not receive a response.
How was the initial setup?
We have not yet undertaken deployment. For the moment, we are on the EPS and discussing the proposed structure with the vendors. Our team is conducting talks with the vendors of QRadar.
We are exploring multiple avenues in search of a one-SIEM solution.
What's my experience with pricing, setup cost, and licensing?
I am not in a position to comment on the pricing.
Which other solutions did I evaluate?
By comparison, I feel QRadar to be better than Splunk Cloud, since it comes with Watson.
Another advantage is that QRadar works like a threat intelligence tool. It, also, does not require queries, which Splunk Cloud does. It is important that we have an understanding of the queries for the purpose of pulling the logs which we seek. I feel QRadar to be better than Splunk Cloud, as it does not require us to work on the queries.
I have worked on Splunk Cloud in the past, as well as on QRadar. As there is no SIEM solution in my current organization, we have plans to build it up. This is an ongoing process. I have suggested QRadar to my team and others are considering Sentinel.
What other advice do I have?
The solution is deployed on-cloud.
I would recommend the solution to others since there are a couple of companies with many clients that are looking for Splunk Cloud, with which they are familiar. We must consider client demands when it comes to attracting projects.
Even in India, most of the companies employ Splunk Cloud as the most prevalently used SIEM solution. Then comes QRadar, which is easier. So too, Splunk is less cost-effective than QRadar, although it is more in demand. There are a couple of companies with call centers that request Splunk Cloud.
I rate Splunk Cloud as a seven out of ten.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Technical Account Manager at Trustaira
Straightforward to set up with great integration capabilities and a high level of maturity
Pros and Cons
- "The solution has proven to be quite stable."
- "The product is relatively expensive."
What is our primary use case?
We primarily use the solution for monitoring and security.
We can use the solution to try to find some correlational data. For example, in banks, there is usually a protocol whereby users cannot withdraw more than a certain amount of money from an ATM. However, we find that, when people are on holiday, they are trying to withdraw more than the allowed amount. It's a use case we can deploy in our country. You can set certain rules and watch the data in order to gain insights.
How has it helped my organization?
I cannot speak to a specific example of how the solution has assisted our organization.
What is most valuable?
The solution's capability is its most valuable aspect.
The initial setup is very straightforward.
The solution has proven to be quite stable.
We've found the solution to be very mature.
The integration capabilities are excellent. They have apps that integrate quite well with Palo Alto and Cisco, for example.
What needs improvement?
Sometimes it becomes very difficult to find certain results from Splunk. Not all users are developers and they are not able to write code to find specific results or specific details from Splunk. From a user perspective, the solution needs to improve the search functionality.
The dashboard could be improved. If it was easier for non-developers or those working in network security, it would be ideal. It would be nice if they had a built-in dashboard for those who are less knowledgeable in coding.
The product is relatively expensive.
For how long have I used the solution?
I haven't been using the solution for very long just yet.
What do I think about the stability of the solution?
The solution is very stable. There are no bugs or glitches. It doesn't crash or freeze. It's reliable.
What do I think about the scalability of the solution?
We do not plan to increase usage at this time.
How are customer service and technical support?
We've used technical support in the past. We've found them to be very helpful and responsive. We're satisfied with the level of support that we receive when we reach out for help.
Which solution did I use previously and why did I switch?
I've previously used LogRhythm, among other solutions. We sell a few different solutions.
How was the initial setup?
The initial setup is not too difficult. It's not overly complex. It's straightforward. The code is very easy.
The deployment took two or three months or so.
What about the implementation team?
We used an integrator to assist us in the initial setup.
What's my experience with pricing, setup cost, and licensing?
The problem with the product is that the price of Splunk is very high. It is an industry leader and therefore it's high in terms of price. That is the issue in our country. Sometimes people want to buy Splunk, however, due to the budget, they are not able to.
What other advice do I have?
We are resellers.
We use a variety of deployment models, including private cloud and hybrid.
This solution is the best security solution. If a company is looking for the best, they have to buy Splunk. It is a very good and very mature solution. It is very easy to integrate with some other service or security solutions. If they have specific solutions that need to be integrated for monitoring purposes, it should be a problem. For example, it integrates very well with Cisco.
I'd rate the solution at a ten out of ten. We are quite happy with its capabilities.
Which deployment model are you using for this solution?
Private Cloud
Disclosure: My company has a business relationship with this vendor other than being a customer. Reseller
Senior Information Technology System Analyst at YASH Technologies
Impressive UI, many useful features, and very scalable, but needs alerting feature and better pricing and integration
Pros and Cons
- "There are quite a lot of things that we find useful. Splunk agents are useful and good. Its UI is quite impressive."
- "Its pricing model and integration with third-party services can be improved. We had faced an issue with integration. The alerting feature is currently not available with Splunk, but it is definitely available with Datadog and PagerDuty. They should include this feature. A few dashboards in Splunk look quite old and are not that modern. They aren't bad, but improving these dashboards will definitely make Splunk more attractive and usable. I read in a few blog posts that there were a few security incidents related to Splunk agents. So, it can be made more secure."
What is most valuable?
There are quite a lot of things that we find useful. Splunk agents are useful and good. Its UI is quite impressive.
What needs improvement?
Its pricing model and integration with third-party services can be improved. We had faced an issue with integration.
The alerting feature is currently not available with Splunk, but it is definitely available with Datadog and PagerDuty. They should include this feature.
A few dashboards in Splunk look quite old and are not that modern. They aren't bad, but improving these dashboards will definitely make Splunk more attractive and usable.
I read in a few blog posts that there were a few security incidents related to Splunk agents. So, it can be made more secure.
For how long have I used the solution?
I have been using this solution for almost two years. I am using its latest version.
What do I think about the stability of the solution?
It is a stable product.
What do I think about the scalability of the solution?
Splunk is definitely scalable.
How are customer service and technical support?
I have not interacted with them. Another team is taking care of raising tickets with their technical support.
How was the initial setup?
It is quite simple.
What's my experience with pricing, setup cost, and licensing?
Its pricing model can be improved.
What other advice do I have?
A few years ago, I would have definitely recommended Splunk, but nowadays, better alternatives are available. We are currently exploring a few other alternatives, so I won't recommend Splunk as of now.
I would rate Splunk a seven out of ten.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Senior Solutions Architect at a manufacturing company with 51-200 employees
Seamless integration with devices and operating systems, centralized management and control, and proactive support
Pros and Cons
- "The integration is seamless with many devices and operating systems."
- "Being a SIEM solution with a centralized dashboard, we would like to have more options to customize it."
What is our primary use case?
We are a solution provider and Splunk is something that we provide as a service to our customers.
What is most valuable?
The most valuable feature is the reporting and the information that is provided by the tool.
It is very easy to implement a PoC using Splunk, which will show the value of the reporting and data that it provides.
The integration is seamless with many devices and operating systems.
It is flexible enough that you can choose what kind of deployment model you want.
They have a large solution toolkit that supports IoT, wherein businesses can get a lot of help with the centralized management functionality. There are also tools to assist from the security and SIEM perspective, and there is a centralized dashboard.
What needs improvement?
Being a SIEM solution with a centralized dashboard, we would like to have more options to customize it. It should be easy to customize dashboards.
When we are monitoring something, we would like to have a more granular outlook. Splunk has a good dashboard that is easier to use than some competing products, but better customizability would be a great help for the users.
For how long have I used the solution?
We have been working with Splunk for approximately three years.
What do I think about the stability of the solution?
This product is very stable.
What do I think about the scalability of the solution?
Splunk is a very scalable solution. Being a Japanese product, they will ensure that all of the features work in any environment. It is very heterogeneous. It can integrate with Windows, Linux, AIX, HP-UX, and Solaris. It also supports IoT devices, mobile phones, and more.
We have more than 150,000 people using our services.
How are customer service and technical support?
The Splunk team has good, proactive support. Also in terms of assisting with the installation, they are quite good.
Which solution did I use previously and why did I switch?
Splunk is similar to IBM QRadar, which we also have experience with. However, Splunk has advanced SIEM features included with it, so we often use it to satisfy this requirement. Whenever an organization is looking to implement SIEM, they have the flexibility to choose Splunk, QRadar, or the ArcSight Logger solution.
One of the major differences that I see between Splunk and QRadar is that Splunk gives the users fewer devices, so they can do things quicker.
How was the initial setup?
The installation for Splunk is easier than competing products QRadar and ArcSight.
We have Splunk deployed on the cloud so that we can provide the service, but some of our customers have it installed on-premises.
All the user has to do is download the Splunk server agent, install it on the laptop or endpoint, integrate 50 or 100 devices, then see what kind of reporting is available.
What about the implementation team?
We have an in-house team for deployment in maintenance. Splunk is a tool that does not require much staff to maintain. The users can start with a PoC, simply learn it, and deploy it for themselves. They don't require subject experts to be hired for the installation and configuration.
What's my experience with pricing, setup cost, and licensing?
Price-wise, if you compare QRadar to Splunk for SIEM functionality then they are in the same range but when you integrate SOAR with these solutions, Splunk takes the lead and is more competitive.
What other advice do I have?
This is a product that I recommend for anybody who wants and advanced SIEM solutions. Of the three that I have used including QRadar and ArcSight, Splunk is the one that I prefer.
I would rate this solution a nine out of ten.
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner

Buyer's Guide
Download our free Splunk Enterprise Security Report and get advice and tips from experienced pros
sharing their opinions.
Updated: June 2025
Product Categories
Security Information and Event Management (SIEM) Log Management IT Operations AnalyticsPopular Comparisons
CrowdStrike Falcon
Microsoft Sentinel
IBM Security QRadar
Elastic Security
Splunk AppDynamics
Elastic Observability
Grafana Loki
Security Onion
Palantir Foundry
Cortex XSIAM
Buyer's Guide
Download our free Splunk Enterprise Security Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- Which would you recommend to your boss, IBM QRadar or Splunk?
- What are some of the best features and use-cases of Splunk?
- What SOC product do you recommend?
- Splunk as an Enterprise Class monitoring solution -- thoughts?
- What is the biggest difference between Dynatrace and Splunk?
- IBM QRadar is rated above competitors (McAfee, Splunk, LogRhythm) in Gartner's 2020 Magic Quandrant. Agree/Disagree?
- What are the advantages of ELK over Splunk?
- How does Splunk compare with Azure Monitor?
- New risk scoring framework in the Splunk App for Enterprise Security -- thoughts?
- Splunk vs. Elastic Stack