No more typing reviews! Try our Samantha, our new voice AI agent.
Raymundo Perez - PeerSpot reviewer
Splunk Admin at Sempra Infraestructura
Real User
Top 5
Sep 13, 2025
Correlation and integration capabilities have streamlined our investigation and response efforts
Pros and Cons
  • "The features of Splunk Enterprise Security that I find most valuable are the correlation and correlation data."
  • "Splunk Enterprise Security could be improved in the dashboards that provide KPIs about environmental behavior."

What is our primary use case?

My main use cases for Splunk Enterprise Security are detection, attacks, analysis, and investigation.

What is most valuable?

The features of Splunk Enterprise Security that I find most valuable are the correlation and correlation data. These features have benefited my organization through the model of investigation, correlating with correlation alerts, and integration with other tools, which is a good point.

In my experience with other tools in previous jobs, the time is reduced by around 70% compared to the previous tool.

My impressions of Splunk's ability to predict, identify, and solve problems in real time are positive. There are points to consider when enriching the data with these kinds of inputs. It is a good opportunity for companies trying to start with this environment, though it might be a challenge for those who have been using it for a long time since it requires identifying the context and use cases.

What needs improvement?

Splunk Enterprise Security could be improved in the dashboards that provide KPIs about environmental behavior.

The most significant challenges I face when using Splunk Enterprise Security for advanced threat detection include correlation when we have inputs or tools about security, such as Forescout or CrowdStrike, which presents a good challenge.

My organization uses risk-based alerting in Splunk Enterprise Security, yet not optimally, which presents another challenge. My security ops team takes longer to remediate security incidents with Splunk Enterprise Security compared to our previous solution. It is very complex.

For how long have I used the solution?

I have been using Splunk Enterprise Security for four years.

Buyer's Guide
Splunk Enterprise Security
July 2026
Learn what your peers think about Splunk Enterprise Security. Get advice and tips from experienced pros sharing their opinions. Updated: July 2026.
908,877 professionals have used our research since 2012.

What do I think about the stability of the solution?

I would assess the stability and reliability of Splunk Enterprise Security as good. However, it depends on the Splunk architects or the best practices provided by the admins and power users. They should avoid creating bad practices in correlation alerts, queries, and dashboard reports, but overall, it is a good, stable product.

What do I think about the scalability of the solution?

Scaling is smooth in certain functionalities but can be more difficult when involving different areas. When under the same scope, it progresses smoothly.

How are customer service and support?

Customer service and technical support are good. They can sometimes be expensive, but the cost is appropriate given the professionalism in providing reports, diagnostics, and analyses.

We may need more follow-up for remediation, which is sometimes noted as expensive, however, it is acceptable as part of the partnership agreement.

Which solution did I use previously and why did I switch?

Prior to adopting Splunk Enterprise Security, I was using another solution, SOAR, to address similar needs. It accomplishes that along with the implementation process, and I need to consider the different policies within the company regarding privileges, roles, and dependencies across different areas.

How was the initial setup?

The process for customizing, developing, testing, deploying, and refining detections in Splunk Enterprise Security is part of the onboarding process. We sometimes need to review it based on our needs or use cases we need to apply, and we need to correlate the data with different inputs, sometimes directly from security or IT data.

What was our ROI?

I have seen a return on investment with Splunk Enterprise Security. If the account executives for Splunk do not explain the implementation process clearly, we may face challenges, as our company's first question is usually about seeing immediate results for the amount spent. We often need to follow a process and achieve a certain maturity level, which requires a prompt response from our management.

What's my experience with pricing, setup cost, and licensing?

Regarding my experience with pricing, setup cost, and licensing, it is good. I saw around 2016 when the license was one option, however, now it is good, although sometimes it depends on the business of the company since we do not always have the budget to increase, decrease, or try to change.

Which other solutions did I evaluate?

The factors that led me to change to Enterprise include the new improvements. This is the correct path, and next year we will need to review the challenges concerning AI governance, which I plan to use in Splunk Enterprise Security.

What other advice do I have?

Splunk Enterprise Security has helped improve our organization's business resilience. It helps us respond to various needs in our different regions or plants, aiming to obtain critical information to reduce the impact of hacks in our plants.

I would absolutely recommend Splunk Enterprise Security. Every time I have the opportunity to promote or explain how it works, people say it is amazing, and I agree. It is an integrated solution that stands out against competitors, and though it may be expensive, it delivers good quality.

I would rate Splunk Enterprise Security overall a nine on a scale of one to ten, considering the current improvements.

Disclosure: My company has a business relationship with this vendor other than being a customer. Accenture
PeerSpot user
Viral Shaa - PeerSpot reviewer
IT Security Analyst at Eos Energy Enterprises, Inc.
Real User
Top 5Leaderboard
Jun 5, 2026
Centralized monitoring has reduced analyst burnout and improves response to critical threats
Pros and Cons
  • "My overall experience with Splunk Enterprise Security in the energy sector has been overwhelmingly positive."
  • "While Splunk Enterprise Security is a great product, I observe a few challenges compared to other products. The first challenge is the licensing cost, which is significantly high, especially for organizations generating a large volume of logs common in the energy sector."

What is our primary use case?

We are currently in beta mode with AI-driven detections, connecting with AI while using Splunk forwarders and API connectors to ingest data from SCADA systems, historian databases, firewalls, endpoint security platforms, and cloud services. So far, the beta platform is working as expected, although we are not fully integrated with AI yet. Splunk Enterprise Security includes threat intelligence feeds, which summarize alerts in bullet points for analysts, helping them investigate incidents.

I use Splunk Enterprise Security as a SIEM management tool that gathers SIEM, log management, and operational monitoring. We are using it to integrate with different systems and centralize logging in one place, where we create rules or alerts that generate when there is a match. We are using that tool as a necessity and for compliance as well.

What is most valuable?

Risk-based alerting in Splunk Enterprise Security has positively impacted our alert volume and analyst productivity. We currently have a lot of alerts, including out-of-the-box alerts provided by Splunk. The risk-based alerts allow us to create alerts tailored to our needs, significantly impacting our organization by helping us prioritize events that truly matter and reducing false positives in our monitoring environment. For example, if one alert detects malware or a decommissioned user account, the risk-based alerting reduces noise from less severe alerts, allowing analysts to focus on more critical issues without having to investigate low-severity alerts extensively.

The integration of the threat intelligence feed and MITRE ATT&CK framework in Splunk Enterprise Security is significant for discovering the overall scope of incidents. When an alert generates, understanding the attacker's motive helps us recognize how they gain access to our environment, including the tools and techniques they use. Using MITRE tactics alongside threat intelligence feeds adds value to those alerts, allowing us to reduce response times significantly.

The correlation rules and risk-based alert models are effectively detecting threat factors early, enabling analysts to get to work immediately. The correlation rules, threat intelligence, notable event prioritization, and risk-based alerting help navigate the root causes of threats, thus reducing the threat landscape.

My overall experience with Splunk Enterprise Security in the energy sector has been overwhelmingly positive. Splunk Enterprise Security has proven to be a powerful and reliable tool for centralizing logging, monitoring critical infrastructure, creating alerts and reports, and improving both operational and cybersecurity sides. It also provides security, giving us visibility into the OT and IT environments to ingest and correlate large volumes of data. After generating alerts, we detect anomalies and respond to incidents faster, all within a centralized platform. We have approximately fifty software solutions that we are using, and we ingest the logs into Splunk, allowing us to monitor them flexibly and scalably, which fits our organization's needs in a high-volume energy sector environment.

Using Splunk Enterprise Security improves our average mean time to resolve because we aggregate logs from endpoints, IAM logs, spam logs, EDR logs, and firewall logs into a centralized platform. It creates alerts that analysts can prioritize. P1 incidents should be resolved within two hours, demonstrating significant improvement from utilizing the product in our environment. It is a strong platform that faces some challenges, but overall, we receive positive feedback about reducing that mean time.

Before Splunk Enterprise Security was onboarded, finding alerts across multiple dashboards demanded considerable effort. After using Splunk Enterprise Security, we see significant improvement because everything is centralized on one dashboard. Analysts no longer need to look for firewall or EDR alert points individually; all data is accessible on Splunk Enterprise Security's dashboard. The AI model also helps minimize real-time metrics for security events, presenting everything in real time. Analysts can contact customers or end users and complete their analysis in approximately fifteen to twenty minutes, gaining insights about the ongoing environment, detecting anomalies and responding to incidents faster.

In the energy sector, where infrastructure and regulatory requirements are critical, the triage phase's capability allows us to detect significant ransomware attacks early. By triaging incidents right away, we strengthen our visibility and can swiftly take action, such as isolating virtual machines or user accounts, or changing passwords, which helps us assess the risks involved with alerts and how we can remediate them.

Splunk Enterprise Security significantly improves our ability to detect threats faster.

What needs improvement?

While Splunk Enterprise Security is a great product, I observe a few challenges compared to other products. The first challenge is the licensing cost, which is significantly high, especially for organizations generating a large volume of logs common in the energy sector. The learning curve can also be steep for new users, particularly when working with SPL and building advanced dashboards. Learning SPL, a query language in Splunk, is not hard, but for a newly onboarded analyst, it can be challenging. Building dashboards is easy, but when making special requests for management, it can be tricky. Additionally, Splunk can be resource intensive, requiring careful planning around storage, indexing, and hardware performance. These factors do not diminish the product's value, but they do require thoughtful management and ongoing training to ensure teams leverage their capabilities fully.

I recommend that Splunk improves its pricing model since the pricing is based on the logs ingested, which is currently quite high. Users and admins of the product must pre-plan and thoughtfully manage the logs to fully leverage its capabilities. Reducing pricing would be a great suggestion from my side.

For how long have I used the solution?

I have been working with Splunk Enterprise Security for three to five years on my current job and probably on my previous job as well.

What do I think about the stability of the solution?

Regarding reliability and stability, Splunk Enterprise Security is a significant tool. We have not experienced outages or downtime. The documentation states 99.9% availability, and it consistently operates 24/7 without any stability or reliability issues at this time.

What do I think about the scalability of the solution?

From a scalability standpoint, as we transition from a smaller mid-sized company to over one thousand employees, we have not encountered any hiccups or roadblocks using Splunk Enterprise Security. It effectively meets our needs in terms of log ingestion and performance.

How are customer service and support?

Splunk support is quite good; they reply within twenty-four hours. We have opened some support tickets, and they responded promptly to address the root cause of our issues. I would rate Splunk support as very responsive.

Which solution did I use previously and why did I switch?

We evaluated IBM QRadar, Elastic Stack, and ArcSight through POC, but so far, Splunk Enterprise Security's ecosystem, documentation, and functionalities stand out the most.

How was the initial setup?

My deployment experience with Splunk Enterprise Security was smooth and well-structured. We began by pre-planning the architecture to define indexer, search head, and storage requirements based on expected data volume. Once completed, we deployed the forwarder across various servers, firewalls, and OT gateways, followed by data forwarders from the SCADA system, historian database, and enterprise applications. Once ingestion was stable, we began building dashboards, alerts, and compliance reports tailored to our operational and security needs. Our team required training, which Splunk provided to help us understand how SPL works and how to create dashboards. With their assistance, we started ingesting data and the platform is fully operational. Overall, it was a smooth and standard deployment process.

I participated in the initial setup of Splunk Enterprise Security, serving as the admin of the console overseeing onboarding and offboarding processes.

What was our ROI?

In terms of improving business resilience, the ROI from Splunk Enterprise Security is significantly positive. Implementing Splunk Enterprise Security has improved our organization's overall resilience by providing real-time visibility in both IT and OT environments, enabling faster anomaly detection and addressing operational disruptions and security threats. With centralized logging, correlation searches, and risk-based alerting, we can identify issues earlier, prioritize events posing high risks, and respond before impacting critical infrastructure or service delivery. This approach reduces downtime, ensures compliance readiness, and enhances continuity across energy operations. By utilizing data from our SCADA systems, network devices, identity platforms, and cloud services, Splunk Enterprise Security supports a more adaptive, informed, and resilient operational posture while ensuring day-to-day reliability and long-term strategic stability.

What other advice do I have?

Compared to other products in the market, Splunk Enterprise Security's standard is much higher, though other options are cheaper.

I am an admin of Splunk Enterprise Security. Currently, we have Splunk Enterprise, and I would consider my role as a user.

We are using the enterprise version, which is best suited for us with a higher top-layer model.

I observe a significant reduction in analyst burnout due to utilizing Splunk Enterprise Security. Analysts face a high risk of burnout working for thirty minutes to several hours on a single alert to find the root cause. However, with everything centralized on a dashboard, burnout rates decline. Splunk Enterprise Security monitors our systems 24/7, allowing analysts on different shifts to evaluate the dashboards in a consistent manner. This standardization of dashboard alerts and reporting has significantly improved our operations and reduced burnout.

Currently, we are on a trial license for third-party vendors ingesting security event data while streamlining incident management. We receive real-time monitoring for threat intelligence feeds, using a SOAR platform for automated response workflows and an AI platform that helps narrow down visibility across our entire energy infrastructure.

Based on my experience with Splunk Enterprise Security in every aspect, I would rate it nine out of ten.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Last updated: Jun 5, 2026
Flag as inappropriate
PeerSpot user
Buyer's Guide
Splunk Enterprise Security
July 2026
Learn what your peers think about Splunk Enterprise Security. Get advice and tips from experienced pros sharing their opinions. Updated: July 2026.
908,877 professionals have used our research since 2012.
Paul-Zhang - PeerSpot reviewer
Manager, Information Security at a financial services firm with 10,001+ employees
Real User
Top 5
Sep 11, 2025
Delivers efficient threat detection through big data analytics but requires improvement in reducing false positives and operational noise
Pros and Cons
  • "Splunk Enterprise Security is doing its job in helping improve my organization's business resilience."
  • "The biggest advantage I can see in Splunk Enterprise Security is the big data analytics."
  • "There is another new term called benign positives. It is better to clearly identify each definition of those terms since it has not been popular in the industry, and everyone needs to be aware of those things."
  • "The most significant challenges I face when using Splunk Enterprise Security for advanced threat detection are the false positive alerts."

What is our primary use case?

My main use cases for Splunk Enterprise Security are threat detection use cases.

What is most valuable?

The biggest advantage I can see in Splunk Enterprise Security is the big data analytics. The simple search query with faster responding results is also appealing. My team handles large volumes of cybersecurity data. To be able to search against such a big amount of data with efficiency is the key driver for my team to do threat detection and data analytics.

What needs improvement?

Splunk Enterprise Security can be improved in many ways. I am very happy to experience the AI-powered security platform they are going to show us in the new version. Better identification of true positives and false positives should be included in future releases.

There is another new term called benign positives. It is better to clearly identify each definition of those terms since it has not been popular in the industry, and everyone needs to be aware of those things.

The most significant challenges I face when using Splunk Enterprise Security for advanced threat detection are the false positive alerts. As mentioned in the keynote, there is a lot of noise. Reducing the noise to make sure the SOC is operating more efficiently is one of the challenges my team is having. The process for customizing, developing, testing, deploying, and refining detections in Splunk Enterprise Security is not the easiest, however, it is not the most difficult one, so I would say it is medium.

For how long have I used the solution?

I have been using Splunk Enterprise Security for seven years.

What do I think about the stability of the solution?

I have experienced downtime, crashes, and performance issues, with the most recent one being a data ingestion issue from another security platform. This key data source is not being ingested, causing some downtime.

What do I think about the scalability of the solution?

Splunk Enterprise Security does not scale efficiently with the growing needs of my organization. Since it is on-premises, we have some scalability issues, and there are other new players coming up.

We have expanded the usage of Splunk Enterprise Security several times.

How are customer service and support?

I would evaluate customer service and technical support as adequate since my team does not deal with it directly. Another team dealt with them, and I found it to be acceptable as they have 24/7 support all over the world. 

They hand over to the next team in another country, but sometimes it takes time to do the transfer, and we have to explain all the problem issues again, which can be frustrating. For that, I would rate it a five.

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

Prior to adopting Splunk Enterprise Security, I was not using another solution to address similar needs.

How was the initial setup?

My experience with deploying Splunk Enterprise Security is actually another team's job, however, they are doing adequately.

What about the implementation team?

My organization is moving towards risk-based alerting in Splunk Enterprise Security. My team actually built our own risk-based alerting before they released it; however, we are looking forward to integrating both.

What was our ROI?

Splunk Enterprise Security is doing its job in helping improve my organization's business resilience. There are other competitors in the same field, so I find it neither particularly good nor bad.

What's my experience with pricing, setup cost, and licensing?

I don't directly deal with pricing.

What other advice do I have?

I would advise other organizations considering Splunk Enterprise Security that the new version looks impressive. If organizations want the new, complete package, I would recommend ES Premier, as it combines ES with TIM, UEBA, and SOAR

On a scale of one to ten, I would rate Splunk Enterprise Security a seven. I believe ES is doing its job, but it is slightly behind its competitors. 

Other competitor platforms already have AI integrated, and they just announced it today, so it feels somewhat behind. However, I am looking forward to this new feature.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Sreeni Mamidipaka - PeerSpot reviewer
IT Security Mgr at a legal firm with 1,001-5,000 employees
Real User
Top 10
Sep 11, 2025
Dashboards and reporting have streamlined our alert triaging and security investigations
Pros and Cons
  • "I would assess the stability and reliability of Splunk Enterprise Security as generally good, with very few downtime, crashes, and performance issues."
  • "Splunk Enterprise Security has helped improve my organization's business resilience by fulfilling gaps in forensics, incident management, IRP, and data management while helping us mature our security operations."
  • "Our organization has very limited resources, so we would want to expand some of those automation and AI capabilities to fill those gaps."
  • "My organization does not completely utilize risk-based alerting in Splunk Enterprise Security as it's not fully mature."

What is our primary use case?

My main use cases for Splunk Enterprise Security are log management and enterprise security. Those are the key.

How has it helped my organization?

Splunk Enterprise Security has helped improve my organization's business resilience. We load much of our data and information that we use. It's really helping us in our log management solution, and also for forensics and alert triaging purposes. Forensics is one of the big pieces, along with incident management, IRP, and data management. It's fulfilling all those gaps and helping us mature our security operations.

What is most valuable?

The features of Splunk Enterprise Security that I enjoy the most include reporting, dashboards, and RBA. These features have benefited my organization since the dashboards and reports help us review security alerts and events in a timely manner. The RBA is what we are currently working on to develop and have some early detection on security alerts and notifications.

Currently, I am using disparate security solutions that integrate or import data into Splunk Enterprise Security. This integration supports my security operations by providing some visibility into security. Yet we have many basic issues where we need to fix the log sources, integration, and quality of the content that's going into Splunk Enterprise Security.

I find the process for customizing, developing, testing, deploying, and refining detections in Splunk Enterprise Security quite basic. We don't have any sophisticated process. We have contractors and MSSP who are timely filling those gaps, going through the rule review process, going through regular security testing, and prioritizing what is more important as an organization.

What needs improvement?

Though we have not completely explored the product functionality, Splunk Enterprise Security itself has many features. This morning I was reviewing all the AI capabilities, such as version 8.2 which has included incident triaging and process. That's probably a very good feature. Our organization has very limited resources, so we would want to expand some of those automation and AI capabilities to fill those gaps.

For how long have I used the solution?

I have been using Splunk Enterprise Security for two years.

What do I think about the stability of the solution?

I would assess the stability and reliability of Splunk Enterprise Security as generally good, with very few downtime, crashes, and performance issues. I've been with the organization for a little over a year. I have seen one or two occasions where the enterprise resources crashed. I haven't really seen any significant issues.

What do I think about the scalability of the solution?

Splunk Enterprise Security works efficiently with scaling growing needs since the distributed architecture is very well planned and easily scalable. All you need is to spin up a few additional resources and you can build your collectors, forwarders, and indexers. It's quite easy. At the same time, it comes with its own complexities since it's an on-premises solution. 

Overall, it performs well. I haven't seen any outages or resource challenges while using it.

How are customer service and support?

I would evaluate customer service and technical support as very responsible. Anytime that we have issues or challenges, I could see they were helping us behind the scenes and going through all these improvements. They were excellent.

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

In previous organizations, I have been well-versed with many other SIM tools. QRadar is one prominent tool I used. The McAfee Nitro, which isn't available anymore, was another. RSA NetWitness, RSA enVision, ArcSight were among the many tools I've used. In modern SIM tools, I am more familiar with Sentinel and Google Chronicle. I would say Splunk Enterprise Security has more capabilities, and maturity-wise and roadmap-wise, this product has become much more mature than the other two products I could compare.

How was the initial setup?

I was not present for the deployment.

What was our ROI?

I have definitely seen a return on investment with Splunk Enterprise Security.

What other advice do I have?

The most significant challenges I face when using Splunk Enterprise Security for advanced threat detection relate to the RBA, which is something that we were struggling with. We are working with the SIM and our reseller to streamline that process. That's something that's not easy for every organization. We are going through the same turbulence.

My organization does not completely utilize risk-based alerting in Splunk Enterprise Security as it's not fully mature. It is supporting our SOC in a limited way. We still have a long way to go. The product is not completely mature. We are a unique organization, so it requires additional resources to get that work done.

My organization is in the process of expanding our security use cases. It's a multi-year model where we are strategizing and exploring all our security needs. I would say we are still in the early phase. Although we have the product in place, it was not yet mature due to some resource issues.

My advice to other organizations considering Splunk Enterprise Security is that it's a good product. It's definitely helpful. If somebody is looking for security and log management, investigations, incident, and IRP, then they can look into this product and explore it. It's one of the market-leading products. It definitely stays up to the mark. 

On a scale of one to ten, I rate this solution an eight.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Sunny-Kumar - PeerSpot reviewer
Cyber Security Analyst at airtel
Real User
Top 5
Apr 23, 2026
Real-time threat monitoring has strengthened resilience but support and automation still need work
Pros and Cons
  • "Splunk Enterprise Security helps improve our organization's business resilience because it is very useful for real-time monitoring and investigation."
  • "The technical support can be improved because sometimes when we call them, the issues are not resolved immediately and tickets take time to be addressed."

What is our primary use case?

In my organization, there are many use cases for Splunk Enterprise Security, including potential risk, brute force attack, malware attack, ransomware attacks, and firewall-related use cases. We also have switch-related, inbound traffic, outbound traffic, login failure, and successful login use cases. I estimate there are more than 150 use cases in our organization.

What is most valuable?

What I appreciate about Splunk Enterprise Security is that it is very intuitive and basic to use.

The best features of Splunk Enterprise Security that I value include its ease of use, the SPL query language, and its straightforward handling. It provides real-time monitoring and investigation, which are the main features in SPL.

Splunk Enterprise Security helps improve our organization's business resilience because it is very useful for real-time monitoring and investigation. When any incidents occur, we can check and detect them in real-time.

What needs improvement?

I would like to see improvements in Splunk Enterprise Security regarding the integration of device automation and more automatic use cases in the licensing model, as well as reducing the incident time period and incident remediation time.

The technical support can be improved because sometimes when we call them, the issues are not resolved immediately and tickets take time to be addressed.

For how long have I used the solution?

I have been working with Splunk Enterprise Security for more than three years.

What do I think about the stability of the solution?

Splunk Enterprise Security is stable and I have not experienced any downtime or significant performance issues. I rate the stability of Splunk Enterprise Security as good.

What do I think about the scalability of the solution?

Splunk Enterprise Security scales well with the growing needs of my organization, though urgent support is required for projects deployed at customer premises.

How are customer service and support?

I evaluate customer service and technical support from Splunk as requiring the raising of a ticket or calling a toll-free number for any technical issues, which they resolve with assistance.

Which solution did I use previously and why did I switch?

Before Splunk Enterprise Security, we used RSA NetWitness and also Sentinel.

What about the implementation team?

I am not directly involved in the deployment of Splunk Enterprise Security, but during the integration of devices, we have a team working on the onboarding process.

What was our ROI?

I have seen a return on investment with Splunk Enterprise Security. It is cost-effective since not many companies are using it right now compared to other SIEM tools.

What's my experience with pricing, setup cost, and licensing?

My experience with pricing, setup cost, and licensing is that Splunk Enterprise Security is very costly compared to other SIEM tools, but the advanced features justify the cost due to its real-time capabilities and user-friendly SPL features as a key differentiator. The licensing is also costly and based on events per second.

What other advice do I have?

I am currently working with Splunk Enterprise Security products and solutions. I work as a Splunk Admin with Splunk Cloud platform and Splunk Enterprise Security.

I do work with Splunk Enterprise Security but not with the Cloud. I find the process for customizing, developing, testing, deploying, and refining detections in Splunk Enterprise Security manageable.

There are many tasks we have to perform in the detection of Splunk Enterprise Security, but if we categorize them, we use the SPL commands. We have to use a query language of the SPL command and optimize and sort out the issue in a limited, minimum time period. These are the command lines we use to reduce the time and prioritize the issues.

We use disparate security solutions that integrate or import data into Splunk Enterprise Security, including Windows devices, Linux devices, and firewall devices. Many other devices are integrated, including the three main components of Splunk Enterprise Security: the forwarder, indexer, and search head. The forwarder collects data from different sources such as switches, firewalls, databases, or routers. These are the data sources integrated with our Splunk devices. The log source then collects the forwarder and sends it to the indexer. The indexer parses the logs, licenses the logs, and minimizes the logs in different formats including JSON format and TXT.IDS format. These are the two formats in which we have the logs stored in the indexer. The third component is the search head, where we perform searches in the dashboard and search console by redirecting to the indexer and extracting the necessary data.

My overall impressions of Splunk Enterprise Security's ability to predict, identify, and solve problems in real-time are positive. These include real-time investigation, incident identification, and minimizing the time required for response. The main components include the SPL command as a useful search processing language. We check the logs of the last three to four days and utilize the indexing box, including hot and cold buckets for storing logs. There are five types of buckets in Splunk Enterprise Security for this purpose.

I am using new threat detection features in Splunk Enterprise Security, including malware analysis, phishing email detection, and detection of malicious IPs, malicious tools, and URLs.

We have not faced any challenges in using Splunk Enterprise Security for advanced threat detection.

My organization uses risk-based alerting in Splunk Enterprise Security. We have a threshold in the search console for incidents. When any incident occurs, it can be categorized based on the number of occurrences as minor, moderate, major, or critical alerts depending on the threshold values.

I am not aware of specific enhancements or new features that should be included in future releases of Splunk Enterprise Security.

I decided to switch to Splunk Enterprise Security because my organization uses it and I have received training on it. The integration of devices with Splunk Enterprise Security is a significant factor, as it is a new technology with advanced real-time monitoring features.

The deployment model for Splunk Enterprise Security that I am using is on-premises.

I would advise other organizations considering Splunk Enterprise Security that it is a new product and new technology. It is easy to handle and has a straightforward deployment model. Use cases are also easy to create, and it provides real-time monitoring and incident detection, which is a valuable feature. My overall review rating for Splunk Enterprise Security is seven out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Last updated: Apr 23, 2026
Flag as inappropriate
PeerSpot user
reviewer2499171 - PeerSpot reviewer
Security Engineer at a retailer with 10,001+ employees
Real User
Top 20
Nov 19, 2025
Investigations have started faster with strong alerting and improved visibility
Pros and Cons
  • "Generally speaking, their support is pretty good and their response time is pretty good."
  • "The huge price increases that have been experienced over the last couple of years do not appear to be justified by new features or items in general."

What is our primary use case?

Splunk Enterprise Security is used for many different things. Primarily, it is used to create alerts for different use cases that need to be monitored, and then investigations can be created. At a high level, that is where many investigations start from.

What is most valuable?

Business resilience is valuable, though I am not completely certain about Splunk Enterprise Security in that regard. Visibility would be considered a valuable feature. The more I think about it, business resilience is probably valuable as well.

What needs improvement?

The pricing of Splunk Enterprise Security is probably one of the main pain point areas. It is probably the only area that has us looking elsewhere for other options, just to see what is available even just because of the price. While it is a good product, the huge price increases that have been experienced over the last couple of years do not appear to be justified by new features or items in general. Pricing is the area that has everyone looking elsewhere to see what other options exist. The prices definitely make your eyes water when you see them.

Splunk Enterprise Security could improve its pricing. This seems to have been a theme across the board at the Splunk conference this year. The general consensus is that pricing continues to increase significantly every year, not just by a couple of dollars.

For how long have I used the solution?

Splunk Enterprise Security has been used in my career overall for about six years.

What do I think about the stability of the solution?

The only instability that has been experienced with Splunk Enterprise Security is from inefficient searches and things configured incorrectly. Stability is ranked pretty high for the product.

What do I think about the scalability of the solution?

Scalability for Splunk Enterprise Security is ranked pretty high.

How are customer service and support?

I have tried contacting Splunk Enterprise Security support, and I am currently dealing with some technical support items. Technical support is relied upon pretty regularly. Generally speaking, their support is pretty good and their response time is pretty good. The caveat to that is that recently, there are some pretty interesting issues that seem to take a long time and a lot of back and forth just to get to the right people for some advanced challenging issues. When you open up a support case, you are assigned somebody at tier one support. There is no way to bypass that or indicate that this is a more advanced issue. Everything goes through the same process, and there is no way to really get advanced technical support from the beginning. You have to start at level one, and they set up a meeting and a call to explain the issue and show what is being experienced. There is a lot of back and forth, and then maybe if you are fortunate, you get assigned a more senior person after a week or two. For some cases, it takes maybe three or four weeks before you are actually in touch with people who can actually help with the issue. There is a lot of back and forth, a lot of emails, and a lot of troubleshooting and screenshots and communication for three to four weeks later before you can finally get a hold of somebody who is actually able to point you in the right direction.

Splunk Enterprise Security would be given a score of eight or nine overall for support. It is just the amount of time that it takes to get support for some advanced issues. You have to start at the bottom and keep communicating and working your way up that chain. Overall, it is a solid eight or nine, but sometimes it takes a decent amount of effort and time to get there.

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

Nothing has been used before Splunk Enterprise Security.

How was the initial setup?

When first starting to use Splunk Enterprise Security, the initial deployment was already stood up, so much of it was personal learning. I cannot really speak on behalf of other people who have stood Splunk Enterprise Security up.

What about the implementation team?

Splunk Enterprise Security is a pretty complex tool, and it is always changing. There are always new things, even with 8.0 to 8.2. There are always things that are being renamed and moved around and called different things and the UI is changing. That has definitely added to the learning curve. It is a pretty complex tool, so there is a pretty steep learning curve personally just because there are so many things that it does and controls and a lot of things to consider.

What was our ROI?

Splunk Enterprise Security has not helped to reduce the team's mean time to detect, the MTDD metric. A service provider, managed service provider, is utilized for items like that.

What's my experience with pricing, setup cost, and licensing?

Splunk Enterprise Security is not being used with the observability platform at this point.

Which other solutions did I evaluate?

Splunk Enterprise Security has not been upgraded to 8.0. The upgrade to 8.2 is in the works, probably in the next two months or less.

What other advice do I have?

Risk-based Alerting, as Splunk Enterprise Security calls it, is being used. There are some pros and cons associated with it. The organization is not mature enough for Risk-based Alerting to speak on any pros or cons too much because of how Risk-based Alerting works. Many of the underlying fundamental pieces have not been built or are not mature enough to really calculate the risk scores correctly. While Risk-based Alerting is enabled and turned on and some risk-based alerts have been created, generally speaking, the organization is not mature enough in some of the other areas to really use a lot of the granular details of what Risk-based Alerting is for. However, it is on the path for progression. The overall review rating for Splunk Enterprise Security is nine.

Which deployment model are you using for this solution?

On-premises

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Other
Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
Last updated: Nov 19, 2025
Flag as inappropriate
PeerSpot user
Fanindra Doifode - PeerSpot reviewer
Jr Soc Analyst at Wysetek Systems Technologists Pvt. Ltd
Real User
Top 20
Jun 29, 2026
Centralized analytics and ai-driven detections have transformed my real-time threat response
Pros and Cons
  • "Splunk Enterprise Security's consolidation of SIEM, SOAR, and UEBA into a single interface improves my team's operational efficiency as we monitor and detect suspicious activities from a centralized SIEM where we can manage all endpoints."
  • "I would like to see improvements in user-friendliness, as it is quite challenging for a newcomer to learn SPL queries or get hands-on with Splunk Enterprise Security."

What is our primary use case?

As a SOC analyst, I use Splunk Enterprise Security primarily for real-time threat monitoring and incident investigation, and my main use case involves correlating logs from various endpoints, especially integrating alerts from CrowdStrike.

What is most valuable?

Splunk Enterprise Security's best feature is definitely the visibility, having everything centralized, especially with how well it integrates with CrowdStrike logs, which means I don't have to jump between platforms to get the context I need.

The best functionality in Splunk Enterprise Security is search flexibility. Once I get knowledge of SPL queries, I can hunt for almost any threat pattern I need, and the incident review dashboard is a lifesaver for my workflow as it keeps my alerts organized, which makes it much easier to triage and investigate, even when things get busy.

The AI-driven detections and assistance have improved the accuracy of my investigations. The anomaly detection is great, but static rules miss a lot of weird behavior, and Splunk uses machine learning to outline threats and user logging, such as a new location or a sudden spike in data volume not caught by our standard alerts, helping me catch things that could otherwise fly under the radar. The UEBA feature helps me focus on actual risk by baselining normal behavior and analyzing highlights between normal and suspicious activity.

Splunk Enterprise Security's capabilities save real time for our team. If my team is stuck on a complex SPL query or needs a quick summary of a long investigation, I can just ask the AI assistant in plain English.

Splunk Enterprise Security has helped to reduce my team's mean time to resolve by 5 to 15 minutes for each alert.

It has reduced my team's average mean time to detect slightly by an average of two to three minutes.

Splunk Enterprise Security's risk-based alerting system is pretty good, and honestly, one of my best features because it changed how I handle alerts by aggregating suspicious events into a single risk notable incident instead of pinging for every single suspicious event.

When I am looking at one aggregated incident in Splunk Enterprise Security that shows the full story of what that user has been doing, it makes my investigation more efficient and keeps me focused on real threats rather than getting buried in noise.

Splunk Enterprise Security helps me detect threats in real time, and we also use it for threat-sending purposes proactively in our organization by feeding threat intel lists into Splunk Enterprise Security and running a surface to see if any malicious IPs, hashes, or domains have appeared in our environment recently.

Splunk Enterprise Security has reduced our manual work by half an hour for in-depth analysis.

The AI features, UEBA, and other risk-based analysis features help reduce alert fatigue, and the anomaly detection feature significantly decreases the workload of our team to investigate real threats behind the noise.

Splunk Enterprise Security improved a lot for our security team. Before we were overwhelmed by alerts without specific context. Now, using Splunk Enterprise Security in my daily routine, I triage new alerts focusing on high-severity items first, checking the logs in Splunk Enterprise Security, and pivoting to CrowdStrike if I need to see processes on endpoints.

Integrating threat intelligence directly into the TDIR workflow with Splunk Enterprise Security improves my ability to preemptively block threats. We have integrated our threat intelligence platform, such as VirusTotal, seamlessly into Splunk Enterprise Security, which is one of the biggest time-savers for me as an analyst, pulling various feeds while the platform handles the heavy lifting.

In proactive defense, Splunk Enterprise Security improves a lot in our organization. We don't just monitor alerts but carve out time to look for tactics, techniques, and procedures that might not trigger a specific rule yet, and we also use the behavioral analytics feature to flag anomalies before they become full-blown incidents.

Splunk Enterprise Security's native UEBA capability enhances my visibility into unknown, sophisticated, or insider threats, especially as it helps mitigate alert fatigue by focusing on entity risk scoring rather than single noisy events.

We have implemented UEBA use cases for abnormal login spikes, such as a VPN login spike and suspicious entity processes.

Splunk Enterprise Security's consolidation of SIEM, SOAR, and UEBA into a single interface improves my team's operational efficiency as we monitor and detect suspicious activities from a centralized SIEM where we can manage all endpoints.

Splunk Enterprise Security has improved my visibility across hybrid or multi-cloud environments as we integrated it with our AWS infrastructure, and it effectively handles cloud log injection and ingestion flows.

Using Splunk Add-on for AWS, we pull in everything we need, such as AWS CloudTrail for audit logs, VPC Flow Logs for network traffic, and GuardDuty for immediate threat alerts, significantly boosting my confidence in our overall security posture.

Splunk Enterprise Security has significantly improved our business resilience, as we provide security services to our clients, and their feedback indicates it has boosted our productivity.

What needs improvement?

I would like to see improvements in user-friendliness, as it is quite challenging for a newcomer to learn SPL queries or get hands-on with Splunk Enterprise Security.

Missing features I would like to see in Splunk Enterprise Security include improvements in AI for UEBA, as it frequently gives false alarms when historical data is not correctly parsed, and I also suggest enhancing the parser for switches.

For how long have I used the solution?

I have been using Splunk Enterprise Security for two months.

What do I think about the stability of the solution?

I find Splunk Enterprise Security stable, as it has been rock-solid for us over the three months we have been using it, reliably handling massive data streams without major hiccups, although it occasionally takes time to collect logs.

What do I think about the scalability of the solution?

In terms of scalability, Splunk Enterprise Security is quite flexible. When we need to inject more data, we simply add more indexers, but it demands careful attention to compute and storage requirements for sustained performance.

How are customer service and support?

I would rate Splunk's customer service and technical support an 8 out of 10.

Which solution did I use previously and why did I switch?

We previously used the open-source Wazuh for SIEM.

Splunk Enterprise Security's key differences with Wazuh include integration capabilities. Splunk Enterprise Security allows sourcing logs from various endpoints and products, such as CrowdStrike and XDR platforms, while Wazuh has similar features but lacks the ingestion efficiency that Splunk Enterprise Security provides.

How was the initial setup?

From my experience, the initial deployment of Splunk Enterprise Security isn't easy or plug-and-play. It's a heavy-duty platform that requires careful planning, especially when integrating with various products or different types of servers.

What about the implementation team?

I wasn't there for the initial setup of Splunk Enterprise Security, but based on maintenance, it definitely requires a solid strategy and expertise for smooth operation. It's not just installing the app but entails ongoing tuning and infrastructure balancing for optimal functionality.

What was our ROI?

Splunk Enterprise Security has provided measurable benefits. It significantly reduced the mean time to detection and response, which has lessened my workload and improved our team's efficiency.

What's my experience with pricing, setup cost, and licensing?

I haven't worked with the team dealing with pricing, but the operational perspective indicates that pricing is usually tied to data injection volume and workload.

Which other solutions did I evaluate?

We decided to go with Splunk Enterprise Security because its features and customer support are the best in the market. Troubleshooting during deployment or for new features has direct access to effective Splunk customer support.

What other advice do I have?

For deployment, we use a hybrid model, incorporating both on-premises and cloud components.

We purchase Splunk Enterprise Security directly from Splunk and have an official license, contacting the sales team for our needs.

I would overall rate Splunk Enterprise Security as a product 9 out of 10.

Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
Last updated: Jun 29, 2026
Flag as inappropriate
PeerSpot user
Soc Analyst at Softcell Technologies Global Pvt.Ltd
Real User
Top 10
Jun 30, 2026
Centralized monitoring has improved real-time threat detection and faster incident response
Pros and Cons
  • "The best advantage is that Splunk Enterprise Security helps our organization collect and analyze logs from multiple systems in one place, providing real-time monitoring, faster threat detection, and quick incident response and investigations that improve security visibility, reduce response times, and help our team make better decisions."
  • "We manage alert fatigue multiple times, as false positive alerts are triggered frequently, sometimes 200 to 300 alerts."

What is our primary use case?

In our organization, we use log management tools that collect data from multiple types of devices such as system applications and network devices like firewalls. We can collect logs from these network devices, analyze them, and report findings to the client side. We primarily use this for security purposes.

For our business improvement, we manage security for multiple clients on our side. This supports greater business development and improves our security posture. We can improve system reliability and reduce downtime while providing real-time operational insights. This helps our organization make data-driven decisions to improve customer trust, ensure compliance, and reduce operational costs.

We have achieved improvements by enhancing dashboard performance, reducing search execution time, and simplifying complex queries. The queries we work with are very complex. We have also benefited from better AI-driven threat detection and improved data management. These are areas where Splunk Enterprise Security can be further improved.

What is most valuable?

The best advantage is that Splunk Enterprise Security helps our organization collect and analyze logs from multiple systems in one place. It provides real-time monitoring, faster threat detection, and quick incident response and investigations. This improves security visibility, reduces response times, and helps our team make better decisions.

We can continuously monitor logs, detect suspicious behavior in real time, correlate events from different sources, and generate alerts before threats escalate. With AI threat intelligence and automations, our security team can identify and stop attacks as early as possible. This type of proactive defense is what we need.

Regarding pricing, we have compared multiple SIEM tools, and the pricing for Splunk Enterprise Security is the best. Multiple features are included, and the pricing reflects the value it delivers. It helps reduce security risks, automate tasks, minimize downtime, and improve incident response. The long-term savings and strong return on investment often outweigh the initial licensing cost. According to my assessment, the pricing is the best compared to other SIEM tools.

What needs improvement?

The MITRE ATT&CK framework is a knowledge base of real-world cyberattack techniques used by attackers. It helps our security team understand attack behavior, map threats, and detect malicious activity. We can track what attackers are doing, understand what happened, and follow the appropriate steps to strengthen incident response.

We manage alert fatigue multiple times, as false positive alerts are triggered frequently, sometimes 200 to 300 alerts. Alert fatigue is something we observe and analyze properly. Managing this is one of the biggest tasks we handle. We analyze these alerts to determine which types of alerts are key matches and what we should focus on.

For how long have I used the solution?

I have two years and three months of experience with Splunk Enterprise Security.

What do I think about the stability of the solution?

According to my experience, there is no downtime. During updates, we occasionally observe slowness, but generally everything performs well.

What do I think about the scalability of the solution?

We have not experienced any impact on our security posture. We have integrated multiple types of devices including multiple firewalls, network devices, and IPS systems. These help our organization and clients to improve features. We have found no negative impact from scaling.

How are customer service and support?

When we have raised multiple types of alerts to the support team and cannot manage them ourselves, we escalate to the client side support. The response time is excellent, with resolution typically occurring within 10 to 15 minutes. The support team provides links to join sessions and conducts troubleshooting. The support quality is the best for our needs.

How was the initial setup?

The setup is not fully straightforward and is somewhat complex. However, installing the agents on the client side is very easy, taking between two to three minutes, or less than five minutes total. We can continue monitoring immediately after installation. According to my experience, the setup is straightforward and not very complex overall.

What was our ROI?

When comparing tools we have used, including IBM QRadar and Splunk Enterprise Security, we created and tested multiple types of alerts. Splunk Enterprise Security generates real-time alerts, while IBM QRadar is slower with only seconds of difference rather than minutes. The AI-driven features are more improved in Splunk Enterprise Security than in IBM QRadar. However, the dashboards are better in IBM QRadar compared to Splunk Enterprise Security, which is why we suggest improving dashboard features in Splunk Enterprise Security.

We can improve Splunk Enterprise Security by simplifying queries and creating automatic alert raising features with AI-driven capabilities and machine learning. These AI-driven improvements would be better than current features.

What other advice do I have?

Splunk Enterprise Security can enhance its AI capability by improving threat prediction and reducing false positive alerts through automating alert triage and providing smarter incident response. Generating natural language questions and AI-driven analysis can help our security teams detect threats faster and improve response time while reducing manual effort.

The AI capabilities provided by Splunk Enterprise Security are improving threat predictions and automating alert triage, creating and raising alerts to the client side. This is the best AI-driven feature according to my assessment.

When we have generated alerts, we can reduce resolution time from 10 to 15 minutes for our organization and client side. As an MSSP partner, we can provide this service to the client side.

Multiple features are available in Splunk Enterprise Security that help manage our client side. We can create multiple types of dashboards and rules, which helps reduce false positive alerts. Automations are available, which is why the alert raising speed is very fast compared to manual alert raising.

Threat detection is faster because of the AI-driven features. We receive alerts faster as a result. The AI and machine learning can analyze large volumes of data to detect unusual behaviors and identify potential threats while reducing false positive alerts. Automated investigations are also available, helping our security team find any critical alert faster and improve incident response and decision-making for more efficient threat reporting.

We work with multiple environments because our clients are diverse, including leaders and medium-sized organizations. Deployment types include multiple types of servers we can integrate on the client side. Deployment options include on-premises, cloud, or hybrid environments. The organization can choose the model that best fits their needs. Splunk Enterprise Security is scalable, easy to integrate with existing infrastructures, and supports businesses of all sizes while ensuring reliable data collection and monitoring.

In our organization, we are an MSSP partner portal partner with Splunk Enterprise Security. This partnership allows us to purchase directly from Splunk and then provide the tool to our clients.

We can add threat intelligence feeds on our side. When any malicious activity or known activity is found, we can create those types of alerts. When any malicious indicator of compromise or other activity is detected in our network teams, firewalls, routers, or switches, alerts are triggered.

I give Splunk Enterprise Security a rating of 9 out of 10. I would give it a 10 out of 10, but I reduced the rating by one point because some features such as dashboard capabilities could be better, which is why I give it a 9 out of 10.

Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor. The reviewer's company has a business relationship with this vendor other than being a customer: MSP
Last updated: Jun 30, 2026
Flag as inappropriate
PeerSpot user
Dennis Mohn - PeerSpot reviewer
Business Development Manager at Axians Germany
Real User
Top 5
Sep 11, 2025
Reduces implementation time through integrated security features and streamlined threat detection
Pros and Cons
  • "It actually helps us by not having to develop all the use cases ourselves, providing an integrated product that has everything in one place."
  • "I really appreciate the all-integrated SIEM feature of Splunk Enterprise Security, which serves as a one-stop shop to get all security tasks done."
  • "Splunk Enterprise Security can be improved with more ease of configuration."
  • "Splunk Enterprise Security can be improved with more ease of configuration. It is pretty straightforward to get it started, however, to really check if my data is all available and how to activate the right use case and the right correlations is still sometimes a hassle."

What is our primary use case?

My main use cases for Splunk Enterprise Security are mainly building SIEM for our customers, implementing it at customer sites, and using it for our own developments.

What is most valuable?

I really appreciate the all-integrated SIEM feature of Splunk Enterprise Security, which serves as a one-stop shop to get all security tasks done. It actually helps us by not having to develop all the use cases ourselves, providing an integrated product that has everything in one place. 

It has integrated threat intelligence and an integrated use case library, so it requires only one installation and configuration. This specifically benefits my organization by reducing the implementation time at our customers, getting faster time to value with a better turnover rate for our customers.

We are using disparate security solutions that integrate or import data into Splunk Enterprise Security. We are implementing all data sources that are somehow possible, so there's no limitation to that.

The process for customizing, developing, testing, deploying, and refining detections in Splunk Enterprise Security is pretty straightforward. Developing our own solutions is pretty good, and even though we are using the Security Essentials and the Enterprise Security content libraries, that's a very good way to progress.

What needs improvement?

Splunk Enterprise Security can be improved with more ease of configuration. It is pretty straightforward to get it started, however, to really check if my data is all available and how to activate the right use case and the right correlations is still sometimes a hassle. A guided mode to help us understand how to get started, improve data quality, and prepare data more efficiently for use cases would be highly beneficial for us.

For how long have I used the solution?

I have been using Splunk Enterprise Security for the best of seven or eight years now.

What do I think about the stability of the solution?

I have experienced downtime, however, it's very little. The downtimes are mostly hardware issues such as network downtimes, which is nothing that Splunk has a say in. If you deploy a multi-site architecture and make it fail-safe, downtime isn't an issue.

What do I think about the scalability of the solution?

I have expanded usage a lot. This expansion has improved the process as scalability and scaling volume-wise and usage-wise with Splunk Enterprise Security was never a problem for me nor our customers.

How are customer service and support?

I evaluate customer service and technical support from Splunk as perfect. I'm very confident in what the partner SEs and the Splunk Professional Service team can do. If I need to reach out to them, I get instant replies, and the Splunk community itself is very helpful as well. On a scale of one to ten, I would give it a ten.

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

Prior to adopting Splunk Enterprise Security, I was using another solution to address similar needs. We were using Splunk Core with our own developments and helped several customers migrate away from products QRadar and FortiSIEM, however, our main go-to platform is still Splunk Enterprise Security.

How was the initial setup?

My experience deploying Splunk Enterprise Security is all in all pretty straightforward. If you are used to how to set it up, it's very good.

What was our ROI?

I have seen ROI with Splunk Enterprise Security. 

One example is a situation with a customer where we started installing it and actually found active breaches that were short of being used and leveraged for maybe blackmailing or compromising the customer. We couldn't calculate what would have been the cost if they had actually gotten compromised; however, they were in the process, so every investment was returned immediately. It was definitely significant.

What's my experience with pricing, setup cost, and licensing?

My experience with pricing, setup costs, and licensing is a bit difficult. There are competitors that are more cost-effective. That said, for the feature set that Splunk offers, it's okay. It is on a solid foundation, so there could be more rebates and opportunities for us as a partner to offer it to our customers. Still, it's competitive.

The most significant challenges I face when using Splunk Enterprise Security for advanced threat detection are primarily related to customer pricing concerns. I find it's okay for a premium product on top of the Splunk base, however, the pricing is one thing, and I don't know if it's the same for all regions. We specifically sometimes have difficulties getting a smaller license than the Splunk Core one if we don't want to ingest all the data into Splunk Enterprise Security.

What other advice do I have?

My advice to other organizations considering Splunk Enterprise Security is to try it if you don't know about it yet.

On a scale of one to ten, I would rate Splunk Enterprise Security overall as an eight. Sometimes it is a bit hard to get the searches and the data done, but all in all, it's a great product.

Which deployment model are you using for this solution?

On-premises

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
PeerSpot user
reviewer2755887 - PeerSpot reviewer
Senior Cyber Security Operations Engineer at a manufacturing company with 10,001+ employees
Real User
Top 20
Sep 11, 2025
Improves detection and investigation workflows while streamlining alert creation for better resilience
Pros and Cons
  • "I find the process for customizing, developing, testing, deploying, and refining detections in Splunk Enterprise Security effective."
  • "Splunk Enterprise Security streamlines the creation of what they call notables, which takes a lot of the effort that we would have to put into creating our own solution off the table and does it for us."
  • "Splunk Enterprise Security is not exactly user-friendly."
  • "Regarding customer service and technical support, their support is the worst I have ever run into in any industry."

What is our primary use case?

My main use cases for Splunk Enterprise Security are detection and investigation.

How has it helped my organization?

Splunk Enterprise Security has helped improve my organization's business resilience.

What is most valuable?

I never liked Splunk Enterprise Security much until the new version, and now that they've ramped up RBA and made changes in version eight, I prefer it much better. 

Splunk Enterprise Security streamlines the creation of what they call notables, which takes a lot of the effort that we would have to put into creating our own solution off the table and does it for us.

We haven't made the newspaper yet, so Splunk Enterprise Security is doing its job. That integration supports my security operations very efficiently, or we wouldn't use it. I find the process for customizing, developing, testing, deploying, and refining detections in Splunk Enterprise Security effective. That's my bread and butter.

My organization uses risk-based alerting in Splunk Enterprise Security. The SOC is still in the development and testing phase for RBA, so they're not seeing any risk-based alerting yet. Within the next week or two, they should start seeing it.

I have no idea how long on average my SecOps team takes to remediate security incidents with Splunk Enterprise Security. I am not using any new threat detection features in Splunk Enterprise Security since we write our own correlation searches from scratch.

Regarding Splunk's ability to predict, identify, and solve problems in real-time: prediction capabilities are not present at all, identification is pretty good, and resolution is effective. It's a good tool. We've got really amazing people behind it, using it, and although there are only four of us behind it, we've got really amazing people using it.

What needs improvement?

Splunk Enterprise Security is not exactly user-friendly. The most significant challenges I face when using Splunk Enterprise Security for advanced threat detection are assets and identities, which are a pain in the neck, and the documentation for RBA is horrible. 

They've got it now to where it pretty much deploys itself as long as you know what you're doing, yet it does some really weird and impractical things such as putting file extensions on lookup tables that shouldn't be there, which you have to go in and clean up. It's got some quirks that aren't documented, or not all documented.

For how long have I used the solution?

I have been working in this field for ten years and using Splunk Enterprise Security for eight.

What do I think about the stability of the solution?

I have not experienced any downtime, crashes, or performance issues based on Splunk Enterprise Security.

What do I think about the scalability of the solution?

We've expanded our license dramatically since the merger, and Splunk Enterprise Security handles it just fine. It's not really affected by scale; the infrastructure it sits on is affected by scale, however, the software itself isn't.

How are customer service and support?

Regarding customer service and technical support, their support is the worst I have ever run into in any industry. On the front line, they put people who don't know what they're doing, refuse to escalate, and are not helpful. 

When we go to Splunk support, we've already done everything and are really good at what we do, however they make us do it over again or won't help us, and that's enough.

How would you rate customer service and support?

Neutral

Which solution did I use previously and why did I switch?

Way back in the day, we used QRadar, however, as soon as we converted to Splunk, we bought Splunk Enterprise Security with it.

How was the initial setup?

They've got it now to where it's pretty much as long as you know what you're doing, it deploys itself. However, it does some really weird things, like putting file extensions on lookup tables that shouldn't be there, that we have to go in and clean up. 

It has some quirks that aren't documented or aren't fully documented. That's Splunk. They're not good with documentation. If you conduct thorough testing in a development or testing environment, you'll find 99% of what doesn't work and be prepared for it, ensuring that it does. 

What was our ROI?

We have seen return on investment with Splunk Enterprise Security, and we're getting our money's worth. It streamlines the creation of what they call notables, which eliminates a significant amount of the effort that would be required to create our own solution, allowing us to achieve a good ROI.

Which other solutions did I evaluate?

I considered the change initially due to a better product, as it was an evaluation of a better product for a better price back then.

What other advice do I have?

My advice to other organizations considering Splunk Enterprise Security is that unless you're really big, don't spend the money. On a scale of one to ten, I rate this solution an eight.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Buyer's Guide
Download our free Splunk Enterprise Security Report and get advice and tips from experienced pros sharing their opinions.
Updated: July 2026
Buyer's Guide
Download our free Splunk Enterprise Security Report and get advice and tips from experienced pros sharing their opinions.