We are using Splunk as a SIEM tool. We're using it for monitoring.
Assistant Manager System at a financial services firm with 10,001+ employees
Stable, with easy log connection and the capability to scale
Pros and Cons
- "Its compatibility with other SIEMS is very useful."
- "We find that the maintenance process could be a lot better."
What is our primary use case?
What is most valuable?
The ease of log connection has been great.
Its compatibility with other SIEMS is very useful.
They have many basic use cases that we like.
The cloud version of the solution is especially scalable.
The product has been quite stable so far.
The initial setup is very easy.
What needs improvement?
Technical support is lacking post-sale.
The modification of firmware could be improved.
We find that the maintenance process could be a lot better.
The solution is more expensive than other options on the market.
For how long have I used the solution?
We haven't been using the solution for too long at this point. It's been about four months or so.
Buyer's Guide
Splunk Enterprise Security
June 2025

Learn what your peers think about Splunk Enterprise Security. Get advice and tips from experienced pros sharing their opinions. Updated: June 2025.
861,524 professionals have used our research since 2012.
What do I think about the stability of the solution?
The stability has been good. It offers good performance and doesn't seem to be buggy. There aren't glitches. It doesn't crash or freeze. It's reliable.
What do I think about the scalability of the solution?
The solution is scalable. This is especially true for the cloud deployment model. There really isn't anything holding you back if you use that version.
We have around 100 people on the solution currently. 60 to 70 of those are technical users.
We do plan to keep using Splunk.
How are customer service and support?
Technical support services are lacking, especially after you buy the product. They aren't as helpful or responsive as we need them to be. However, when we do reach them, they are good and they help.
Which solution did I use previously and why did I switch?
I have used McAfee Nitro in the past and IBM QRadar as well.
How was the initial setup?
The initial setup is not complex. It's very straightforward. In fact, it's far easier to install than other log tools on the market. A company shouldn't have any issues with the process.
That said, I did not work on the installation myself. Other people at the company handled that aspect of the process.
The maintenance process could be better. It's a bit difficult once the deployment is done. We need about five people for maintenance tasks.
What's my experience with pricing, setup cost, and licensing?
When you compare the services and features, the pricing is reasonable. That said, if you compare Splunk to other options on the market, it is more expensive.
What other advice do I have?
As we recently purchased the solution, we are using the latest version right now.
I would recommend the solution to other users.
I would rate the solution at an eight out of ten. If the solution offered a better price and better support services, I would likely rate it higher. However, for the most part, we have been satisfied with the product and its capabilities.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.

Senior Consultant at sectecs
Powerful programming language and search capability, but it is expensive and the vendor is inflexible
Pros and Cons
- "What I really like is that even if you have already collected the data, you can extract fields and can build searches."
- "I would like to see more SIEM functionality and a better ticket tool."
What is our primary use case?
My reason for implementing it was just to learn more about the product. I wanted to learn about the Splunk programming language, how to pipe searches, add logs, verify the logs, create fields, extract data into fields, build dashboards, and to get hands-on experience with the product.
What is most valuable?
The Splunk programming language allows you to pipe searches into another searches.
What I really like is that even if you have already collected the data, you can extract data and add fields which improves building searches. This is not the case with Elasticsearch, where this needs to be done upfront.
What needs improvement?
I really dislike how Splunk sales and partner manager behaves. I have faced several sales model and partnership changes. Also, the last time I wanted to by a license ro built a SIEM solution, they had removed the ability to purchase a splunk subscription or license from their website. In the past, there was a web page calculator it was possible to by online, but now it instructs to contact sales.
The free version is limited to 500 megabytes and there is no alerting. Due to the missing feature on the Splunk webpage, I have ask Splunk Sales to purchase a license like 1Gyte a day or a license for max 2500 Euro/year to use it as a test or development instance for myself. Asking Splunk for a quote willing to pay for Splunk license to learn and to get used to the product, Splunk didn't get it managed to offer my a license neither arranging the partnership paperwork I have ask for. Sales people from Splunk where calling, each time after I left my details on ther trial download page. I explained my experience and concerns about Splunk in the past. All excuses received and promises that someone will contact me to solve the issues faced in the past, was leading in excactly nothing. Well Done Splunk.
Inflexible and expensive and I do not have much faith in the people working there because if someone is asking for a test environment and is willing to spend up to €2,500 a year, I can't understand why they are unable to provide a license. This could be a lost opportunity because they are not able to onboard a potential new partner.
They definitely need to boost their sales and partner program because it changes to often, where they are dropping partners and it is difficult to get in contact with somebody. This is something that needs to be improved.
I would like to see more SIEM functionality and embedded moduled such a ticket tool to make a end to end SIEM.
For how long have I used the solution?
I have been using Splunk for a few weeks.
What do I think about the scalability of the solution?
As I was using a test environment, I can't comment on scalability. It was just myself and a colleague who was using it as a test instance.
How are customer service and technical support?
I have not been in contact with technical support.
Which solution did I use previously and why did I switch?
I have worked a little bit with Elasticsearch. I also have an instance of SIEMonster running, and I'm trying to get used to it. I found that Splunk provided a good benefit compared to Elasticsearch.
With Elasticsearch, if you have already inserted the data then it's gone because you need to do the pre-filtering. Once you've inserted or ingested the raw data, using Logstash, for example, you are no longer able to build the fields such as IP address, hostname, username, and the other fields that you want to export. This unsorted, raw data that you have is really a drawback for Elasticsearch and some other products. This is something from Splunk that I consider to be a heavy feature, where you can just insert data and ingest it later on.
How was the initial setup?
really fast and easy to install a test instance.
What's my experience with pricing, setup cost, and licensing?
The pricing model is expensive and could lead into a budget nightmare based on the amount of data.
A better pricing plan would be an improvement.
Which other solutions did I evaluate?
I have done some research on LogRhythm, IBM QRadar, and ArcSight, but I don't have any hands-on experience yet.
I did a comparison for a customer two weeks ago and the outcome of my comparison was SIEMonster, effortable price model, even though it's a niche player, it's quite powerful. I also provided Splunk as a recommendation because it is a market leader, really powerful, and really good to use. I also recommended LogRhythm; it is also expensive but it's also really powerful, and the feedback of customers is really good.
With respect to Splunk, I would recommend it but when a customer is budget-driven then Splunk is not the solution. Money shouldn't be the question.
What other advice do I have?
This is a solution that I could recommend for somebody who wants a really powerful product. It is not an end to end orchestrated SIEM yet.
This is a product that I would generally recommend, although I would not do so if the customer is really budget-driven.
I would rate this solution a six out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Buyer's Guide
Splunk Enterprise Security
June 2025

Learn what your peers think about Splunk Enterprise Security. Get advice and tips from experienced pros sharing their opinions. Updated: June 2025.
861,524 professionals have used our research since 2012.
IT System Developer/Admin at a manufacturing company with 10,001+ employees
A stable, scalable solution with comprehensive dashboards and helpful technical support
Pros and Cons
- "The scalability of the solution is amazing because it can collect a lot of data and you can have your own structure to monitor this data."
- "An area of improvement would be the licensing of the solution. They need a free license, which would allow faster lead times."
What is our primary use case?
The primary use case of this solution is to monitor Cyber Mission databases.
I create the diagrams to create an architecture that is then implemented. However, creating these diagrams are for my own learnings since these implementations are usually already available in the cloud office logs.
What is most valuable?
The features I have found most valuable are the dashboards.
I monitor the complete capacity that users are using in the company.
What needs improvement?
An area of improvement would be the licensing of the solution. They need a free license, which would allow faster lead times.
They also need to update their documentation.
What do I think about the stability of the solution?
The solution is stable.
What do I think about the scalability of the solution?
The scalability of the solution is amazing because it can collect a lot of data and you can have your own structure to monitor this data.
How are customer service and technical support?
The customer service/technical support was helpful and they answered my questions as best they could.
How was the initial setup?
The setup was easy, but you have to have a VPN connection depending on the security protocols in place.
What about the implementation team?
The deployment was in-house and took about two days with the correct licenses and permissions.
What other advice do I have?
It is important to define different guidelines to integrate Splunk in development, QA, and production deployments. Additionally, define the applications that will be used and the configuration of the databases to collect the data. If this is not done, there will be a lot of issues due to, for example, master access or permissions to use the database collector and blocks.
Which deployment model are you using for this solution?
Hybrid Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Amazon Web Services (AWS)
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Assistant Vice President at Synchrony
Easy to use with a simple setup and great integration capabilities
Pros and Cons
- "The initial setup is pretty straightforward."
- "On-premises scaling of the solution is a bit more limited than it is on the cloud."
What is our primary use case?
We primarily use the solution for monitoring our infrastructure.
What is most valuable?
The models that we use are pretty mature at this point, which means we can be assured we are given the best use cases right out of the box.
We can just plug into the applications and everything is set up. There's very little configuration necessary.
The integrations that are offered with different tools are all very good. They offer integrations for all levels of security and have offerings from some of the other major solutions in the space.
The initial setup is pretty straightforward.
What needs improvement?
Over the years, I know they've been doing what they can to continue to add integration capabilities to their solution. If they continue to do that, that would be ideal. However, beyond that, there really aren't any features that I find to be lacking in any part of the solution.
On-premises scaling of the solution is a bit more limited than it is on the cloud.
The pricing of the solution needs to be a bit lower.
It would be ideal if the hardware could meet more universal global regulatory requirements. It would be great it the solution better aligned with global standards.
For how long have I used the solution?
I've been working with the solution for three to four years at this point.
What do I think about the scalability of the solution?
In terms of the cloud, scalability is very straightforward. It's just about as expansive as we want to go. When it comes to an on-premise deployment, there might be some scalability limitations. We've found we just have to cut hard on the resources as it does a lot of processing. Whereas the cloud is easy and has very little limitation, I'd advise others that on-premise may have some difficulties.
On-premises, it's definitely on the customer to ensure they have the right plates. If they're concerned and they need 100% scalability, it's best to be on the cloud.
How are customer service and technical support?
Technical support is very good. They know their product and they are responsive to requests. We're satisfied with the level of service provided to us.
How was the initial setup?
We didn't have any issues with the initial setup. It's not too complex. We found the process to be very straightforward and very simple.
What's my experience with pricing, setup cost, and licensing?
While I do understand that it is a premium tool, they could work to make it a bit less in terms of cost. It's a bit expensive.
What other advice do I have?
We use a mixture of public and private cloud deployments.
I would definitely recommend the solution, having seen it work for others so well. Its ease of usage and its man integrations make it a great product. The way you can access whatever you need on the solution is very similar to a Google bar where you can search for anything you need. It's just a super quick responsive, product.
Overall, I would rate it a perfect ten out of ten. We have no complaints.
Which deployment model are you using for this solution?
Public Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
General Manager at Intersoft S.A.
A great solution for application management, security and compliance
Pros and Cons
- "The correlation capabilities are the first value that our clients say they like with Splunk."
- "The difficult part is related to integration with sources of data that are used to create the logs as this depends on the infrastructure of the client."
What is our primary use case?
We use Splunk for security and also PCI compliance.
We have installed and implemented this solution for several clients in Bolivia with our team. We have received training from Splunk directly, and we have also provided training to our clients.
We deploy two versions: one for on-premise and one for the cloud.
Most of our customers purchase Splunk because they required a tool for gathering and collecting all of the logs from the infrastructure in order to make a correlation between data and to spot patterns surrounding security incidents.
What is most valuable?
The correlation capabilities are the first value that our clients say they like with Splunk. Another benefit is that they can connect to any device or log from any device from anywhere.
It's easy, the tool is very easy to install and set up.
What needs improvement?
They could have more dashboards done or predefined so our clients could use them directly in order to have more information ready to use.
The difficult part is related to integration with sources of data that are used to create the logs as this depends on the infrastructure of the client.
For how long have I used the solution?
We have been using this solution for more than five years.
What do I think about the stability of the solution?
Stability-wise, it's great.
What do I think about the scalability of the solution?
We do not require much scalability here because the clients are not so big; however, the hardware where we installed the products was enough to handle all the transactions of Splunk.
How are customer service and technical support?
The support is not so good, I would only give them a rating of six or seven.
They should provide support in Spanish here in Latin America. Their response time to inquires or requirement tickets is too long. It should be shorter.
How was the initial setup?
Deployment took us two weeks.
What other advice do I have?
I would recommend Splunk to any company: small, medium, and large.
Splunk is a great tool but you should get a partner who knows what they are doing, implementation-wise.
On a scale from one to ten, I would give Splunk a rating of nine.
Disclosure: My company has a business relationship with this vendor other than being a customer. Reseller
Sr. IT Manager at a pharma/biotech company with 10,001+ employees
Good log aggregation and scales well, with good technical support that is responsive and helpful
Pros and Cons
- "The most valuable feature is that it's very good for log aggregation."
- "The implementation and the scanning of the logs can be difficult."
What is our primary use case?
We are using Splunk to look at the logs, and see what is happening.
What is most valuable?
The most valuable feature is that it's very good for log aggregation.
What needs improvement?
Splunk is very complex. The implementation and the scanning of the logs can be difficult.
For how long have I used the solution?
I have been using Splunk for approximately three years.
What do I think about the stability of the solution?
In general, Splunk is stable.
What do I think about the scalability of the solution?
It's a scalable product. it's pretty good.
How are customer service and technical support?
Technical support is usually pretty good.
They are responsive, knowledgeable, and helpful.
How was the initial setup?
The initial setup was relatively straightforward.
What's my experience with pricing, setup cost, and licensing?
The price is comparable.
What other advice do I have?
I would rate Splunk and eight out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Sr. IT Manager at a pharma/biotech company with 10,001+ employees
Log aggregation helps us quickly detect widespread threats, but it can be resource-heavy
Pros and Cons
- "The most valuable feature is the log aggregation, being able to scan through all of the logs."
- "Queries are not always as easy or straightforward as they might be, so it can be difficult to figure out what you need to look for."
What is our primary use case?
We use Splunk for log analysis and security monitoring.
How has it helped my organization?
Splunk allows us to look at logs from different groups within NIH and see if there's a widespread threat or issue.
What is most valuable?
The most valuable feature is the log aggregation, being able to scan through all of the logs.
What needs improvement?
Queries are not always as easy or straightforward as they might be, so it can be difficult to figure out what you need to look for.
In the next release of this product, I would like to see it offer more recommendations as to what needs to be done.
For how long have I used the solution?
We have been using Splunk for between two and three years.
What do I think about the stability of the solution?
In terms of stability, the product seems to work just fine. We haven't had any problems with it.
What do I think about the scalability of the solution?
It can be somewhat of a resource hog; some of the scans can take a while. We do plan to increase our usage in the future.
How are customer service and technical support?
Technical support for Splunk is good.
How was the initial setup?
The initial setup is relatively straightforward.
What about the implementation team?
There were consultants involved in the deployment.
What other advice do I have?
I would rate this solution a seven out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Senior Informatica Administrator at a computer software company with 10,001+ employees
The logging features are useful as are the dashboards and alerts
Pros and Cons
- "Splunk is a user-friendly solution."
- "In terms of the interface, it could include some improvements for the look and feel."
What is our primary use case?
We use Splunk on-premise. We mostly use it for log analysis and fraud detection. We are also testing using it in machine learning and other solutions. We have 10 people managing Splunk and we have approximately 150 people using the product in total.
How has it helped my organization?
With Splunk, we got more insights out of our data as it includes machine and secure data. It also has a logging attendance system and this helps to protect our resources from any attackers hacking system information at a granular level
What is most valuable?
The logging features are useful as are the dashboards and alerts in addition to the organization of data. It has options for creating dashboards and alerts. You can also create queries in the SQL language. Splunk is a user-friendly solution.
What needs improvement?
Index performance is a bit slow but this is partly due to the huge volumes of data for our industry within our environment This makes the index very large and inefficient in terms of performance. Performance could be improved to cater to this, however. We have also had problems with the compatibility between Splunk and other systems. We have previously been on 5.3 and migrated to 5.5. We are now planning to migrate to version 7.7. It has been difficult to find documentation about the compatibility with Linux. In terms of the interface, it could include some improvements for the look and feel.
For how long have I used the solution?
We have been using Splunk for one year in our infrastructure environment.
What do I think about the stability of the solution?
The users access the native cloud solution. So we are taking advantage of the native cloud solution provided, and by using the gentle scaling approach this has helped stability.
What do I think about the scalability of the solution?
We scaled up gradually from three processes up to five, and the performance is okay. So we used gentle scaling but this also helped stability.
How are customer service and technical support?
We have used Splunk tech support often. If we have a critical issue such as server down or frequently occurring issues they are always reliable and provide us with solutions to our problems. Technical support for Splunk is good.
How was the initial setup?
Setup is complex. We tried to cluster five indexes. This helped us migrate our data into the Splunk environment. We are using 20 applications which make use of this indexed data. The actual deployment took us about two to three weeks because of some problems getting the data into the system.
What about the implementation team?
We worked with a Splunk consultant who shadowed us to help ensure we performed the process correctly.
What's my experience with pricing, setup cost, and licensing?
Licencing occurs yearly. We now have a three-yearly support contract as of now. Licensing is a yearly, one-time cost.
Which other solutions did I evaluate?
We considered a few alternative products because the logging was faster. In the end, we decided to go to Splunk.
What other advice do I have?
I would definitely recommend Splunk. We will review performance within two years of our three-year contract and then decide at that point what other aspects we need to consider. I would rate Splunk 8 out of 10.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.

Buyer's Guide
Download our free Splunk Enterprise Security Report and get advice and tips from experienced pros
sharing their opinions.
Updated: June 2025
Product Categories
Security Information and Event Management (SIEM) Log Management IT Operations AnalyticsPopular Comparisons
CrowdStrike Falcon
Microsoft Sentinel
IBM Security QRadar
Elastic Security
Splunk AppDynamics
Elastic Observability
Grafana Loki
Security Onion
Palantir Foundry
Cortex XSIAM
Buyer's Guide
Download our free Splunk Enterprise Security Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- Which would you recommend to your boss, IBM QRadar or Splunk?
- What are some of the best features and use-cases of Splunk?
- What SOC product do you recommend?
- Splunk as an Enterprise Class monitoring solution -- thoughts?
- What is the biggest difference between Dynatrace and Splunk?
- IBM QRadar is rated above competitors (McAfee, Splunk, LogRhythm) in Gartner's 2020 Magic Quandrant. Agree/Disagree?
- What are the advantages of ELK over Splunk?
- How does Splunk compare with Azure Monitor?
- New risk scoring framework in the Splunk App for Enterprise Security -- thoughts?
- Splunk vs. Elastic Stack