As a SOC analyst, I use Splunk Enterprise Security primarily for real-time threat monitoring and incident investigation, and my main use case involves correlating logs from various endpoints, especially integrating alerts from CrowdStrike.
Jr Soc Analyst at Wysetek Systems Technologists Pvt. Ltd
Centralized analytics and ai-driven detections have transformed my real-time threat response
Pros and Cons
- "Splunk Enterprise Security's consolidation of SIEM, SOAR, and UEBA into a single interface improves my team's operational efficiency as we monitor and detect suspicious activities from a centralized SIEM where we can manage all endpoints."
- "I would like to see improvements in user-friendliness, as it is quite challenging for a newcomer to learn SPL queries or get hands-on with Splunk Enterprise Security."
What is our primary use case?
What is most valuable?
Splunk Enterprise Security's best feature is definitely the visibility, having everything centralized, especially with how well it integrates with CrowdStrike logs, which means I don't have to jump between platforms to get the context I need.
The best functionality in Splunk Enterprise Security is search flexibility. Once I get knowledge of SPL queries, I can hunt for almost any threat pattern I need, and the incident review dashboard is a lifesaver for my workflow as it keeps my alerts organized, which makes it much easier to triage and investigate, even when things get busy.
The AI-driven detections and assistance have improved the accuracy of my investigations. The anomaly detection is great, but static rules miss a lot of weird behavior, and Splunk uses machine learning to outline threats and user logging, such as a new location or a sudden spike in data volume not caught by our standard alerts, helping me catch things that could otherwise fly under the radar. The UEBA feature helps me focus on actual risk by baselining normal behavior and analyzing highlights between normal and suspicious activity.
Splunk Enterprise Security's capabilities save real time for our team. If my team is stuck on a complex SPL query or needs a quick summary of a long investigation, I can just ask the AI assistant in plain English.
Splunk Enterprise Security has helped to reduce my team's mean time to resolve by 5 to 15 minutes for each alert.
It has reduced my team's average mean time to detect slightly by an average of two to three minutes.
Splunk Enterprise Security's risk-based alerting system is pretty good, and honestly, one of my best features because it changed how I handle alerts by aggregating suspicious events into a single risk notable incident instead of pinging for every single suspicious event.
When I am looking at one aggregated incident in Splunk Enterprise Security that shows the full story of what that user has been doing, it makes my investigation more efficient and keeps me focused on real threats rather than getting buried in noise.
Splunk Enterprise Security helps me detect threats in real time, and we also use it for threat-sending purposes proactively in our organization by feeding threat intel lists into Splunk Enterprise Security and running a surface to see if any malicious IPs, hashes, or domains have appeared in our environment recently.
Splunk Enterprise Security has reduced our manual work by half an hour for in-depth analysis.
The AI features, UEBA, and other risk-based analysis features help reduce alert fatigue, and the anomaly detection feature significantly decreases the workload of our team to investigate real threats behind the noise.
Splunk Enterprise Security improved a lot for our security team. Before we were overwhelmed by alerts without specific context. Now, using Splunk Enterprise Security in my daily routine, I triage new alerts focusing on high-severity items first, checking the logs in Splunk Enterprise Security, and pivoting to CrowdStrike if I need to see processes on endpoints.
Integrating threat intelligence directly into the TDIR workflow with Splunk Enterprise Security improves my ability to preemptively block threats. We have integrated our threat intelligence platform, such as VirusTotal, seamlessly into Splunk Enterprise Security, which is one of the biggest time-savers for me as an analyst, pulling various feeds while the platform handles the heavy lifting.
In proactive defense, Splunk Enterprise Security improves a lot in our organization. We don't just monitor alerts but carve out time to look for tactics, techniques, and procedures that might not trigger a specific rule yet, and we also use the behavioral analytics feature to flag anomalies before they become full-blown incidents.
Splunk Enterprise Security's native UEBA capability enhances my visibility into unknown, sophisticated, or insider threats, especially as it helps mitigate alert fatigue by focusing on entity risk scoring rather than single noisy events.
We have implemented UEBA use cases for abnormal login spikes, such as a VPN login spike and suspicious entity processes.
Splunk Enterprise Security's consolidation of SIEM, SOAR, and UEBA into a single interface improves my team's operational efficiency as we monitor and detect suspicious activities from a centralized SIEM where we can manage all endpoints.
Splunk Enterprise Security has improved my visibility across hybrid or multi-cloud environments as we integrated it with our AWS infrastructure, and it effectively handles cloud log injection and ingestion flows.
Using Splunk Add-on for AWS, we pull in everything we need, such as AWS CloudTrail for audit logs, VPC Flow Logs for network traffic, and GuardDuty for immediate threat alerts, significantly boosting my confidence in our overall security posture.
Splunk Enterprise Security has significantly improved our business resilience, as we provide security services to our clients, and their feedback indicates it has boosted our productivity.
What needs improvement?
I would like to see improvements in user-friendliness, as it is quite challenging for a newcomer to learn SPL queries or get hands-on with Splunk Enterprise Security.
Missing features I would like to see in Splunk Enterprise Security include improvements in AI for UEBA, as it frequently gives false alarms when historical data is not correctly parsed, and I also suggest enhancing the parser for switches.
For how long have I used the solution?
I have been using Splunk Enterprise Security for two months.
Buyer's Guide
Splunk Enterprise Security
August 2026
Learn what your peers think about Splunk Enterprise Security. Get advice and tips from experienced pros sharing their opinions. Updated: August 2026.
914,109 professionals have used our research since 2012.
What do I think about the stability of the solution?
I find Splunk Enterprise Security stable, as it has been rock-solid for us over the three months we have been using it, reliably handling massive data streams without major hiccups, although it occasionally takes time to collect logs.
What do I think about the scalability of the solution?
In terms of scalability, Splunk Enterprise Security is quite flexible. When we need to inject more data, we simply add more indexers, but it demands careful attention to compute and storage requirements for sustained performance.
How are customer service and support?
I would rate Splunk's customer service and technical support an 8 out of 10.
Which solution did I use previously and why did I switch?
We previously used the open-source Wazuh for SIEM.
Splunk Enterprise Security's key differences with Wazuh include integration capabilities. Splunk Enterprise Security allows sourcing logs from various endpoints and products, such as CrowdStrike and XDR platforms, while Wazuh has similar features but lacks the ingestion efficiency that Splunk Enterprise Security provides.
How was the initial setup?
From my experience, the initial deployment of Splunk Enterprise Security isn't easy or plug-and-play. It's a heavy-duty platform that requires careful planning, especially when integrating with various products or different types of servers.
What about the implementation team?
I wasn't there for the initial setup of Splunk Enterprise Security, but based on maintenance, it definitely requires a solid strategy and expertise for smooth operation. It's not just installing the app but entails ongoing tuning and infrastructure balancing for optimal functionality.
What was our ROI?
Splunk Enterprise Security has provided measurable benefits. It significantly reduced the mean time to detection and response, which has lessened my workload and improved our team's efficiency.
What's my experience with pricing, setup cost, and licensing?
I haven't worked with the team dealing with pricing, but the operational perspective indicates that pricing is usually tied to data injection volume and workload.
Which other solutions did I evaluate?
We decided to go with Splunk Enterprise Security because its features and customer support are the best in the market. Troubleshooting during deployment or for new features has direct access to effective Splunk customer support.
What other advice do I have?
For deployment, we use a hybrid model, incorporating both on-premises and cloud components.
We purchase Splunk Enterprise Security directly from Splunk and have an official license, contacting the sales team for our needs.
I would overall rate Splunk Enterprise Security as a product 9 out of 10.
Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
Last updated: Jun 29, 2026
Flag as inappropriateCSOC Manager at a retailer with 10,001+ employees
Security monitoring has unified alert triage and incident response for our SOC analysts
Pros and Cons
- "Splunk Enterprise Security has positively impacted our organization by helping to formalize our SOC program, enabling us to fundamentally respond to alerts as well as create detections around security events, and providing a single source of truth for our analysts to work out of instead of having multiple different platforms."
- "I think Splunk Enterprise Security is relatively scalable, but it relies on your company's capability to get the appropriate and good data inside of Splunk. Without that maturity, Splunk suffers immensely."
What is our primary use case?
My main use case for Splunk Enterprise Security is for security alerting, triage, SIEM, and incident response.
We use Splunk Enterprise Security for incident response with an MSSP that will triage findings or events, and then they will escalate them up as investigations in which our analysts will then respond to them. We then take in and start doing our investigation, adding notes, and eventually closing with disposition. If the incident comes from external to Splunk, we typically just conduct the investigation through Splunk and document it externally via our IR processes.
What is most valuable?
The best features that Splunk Enterprise Security offers include case management, which has come a long way in terms of being able to collaborate and have multiple people working inside of the case management platform at the same time without necessarily overlapping, as well as the ability to work out of one platform with integrations via SOAR and being able to search all inside of the same investigation and keep all of your notes straight.
Splunk Enterprise Security has positively impacted our organization by helping to formalize our SOC program, enabling us to fundamentally respond to alerts as well as create detections around security events, and providing a single source of truth for our analysts to work out of instead of having multiple different platforms.
What needs improvement?
One of the big things that's important in my industry currently is being able to measure your time, whether that's for implementation of AI and automation or just simply for headcount and asset allocation. I think the ability to track how much time is spent in different portions of a runbook playbook or in triage of an alert would be a beneficial addition to Splunk Enterprise Security's case management.
For how long have I used the solution?
I have been using Splunk Enterprise Security for three to four years.
What do I think about the stability of the solution?
Splunk Enterprise Security is stable.
What do I think about the scalability of the solution?
I think Splunk Enterprise Security is relatively scalable, but it relies on your company's capability to get the appropriate and good data inside of Splunk. Without that maturity, Splunk suffers immensely.
How are customer service and support?
My experience with customer support has been good.
On a scale of one to ten, I would give customer support an eight or a nine. It's been good for when I need it.
Which solution did I use previously and why did I switch?
I did not use a solution prior to Splunk Enterprise Security for SOC operations.
How was the initial setup?
I was a part of the conversations regarding pricing, setup cost, and licensing, but ultimately, I was not the only decision maker in renewing Splunk Enterprise Security. There were multiple teams consolidated for the multiple use cases in our organization.
What about the implementation team?
Splunk Enterprise Security was selected prior to my job responsibility as a SOC manager. I believe it was actually bought for site reliability engineering primarily, and then it was just a product that was available when we started SIEM and SOC operations.
What was our ROI?
I think the ROI typically has been in risk reduction and the building of the program. We're looking to start getting better ROIs on reduced analyst time and potentially fewer analysts with some of the agentic triage capabilities. But as of now, I don't have much to compare. We have recently started using the i4S add-on for insights, so I'm hoping that also proves valuable insights for ROI.
What's my experience with pricing, setup cost, and licensing?
I was a part of the conversations regarding pricing, setup cost, and licensing, but ultimately, I was not the only decision maker in renewing Splunk Enterprise Security. There were multiple teams consolidated for the multiple use cases in our organization.
Which other solutions did I evaluate?
Splunk Enterprise Security was selected prior to my job responsibility as a SOC manager. I believe it was actually bought for site reliability engineering primarily, and then it was just a product that was available when we started SIEM and SOC operations.
What other advice do I have?
I have not really gotten to use too many of the AI feature sets in the current state, so I do not believe that I can speak to the efficacy of those features.
I think the functionality is there. The implementation is probably the hardest part, which is just a lot of work on the engineering and architecture of an organization, as well as if there are deficiencies in the IT infrastructure side, bad data equals bad Splunk. We have to ensure that we continue to implement things to be able to use Splunk Enterprise Security to its full potential.
From a directional standpoint, I think Splunk Enterprise Security is on the right path of observability taking the forefront of any sort of AI implementation. The biggest concerns about agentic capabilities is how you arrive at that decision making, which are the same concerns you would have with a human in terms of triage. Ensuring that observability always maintains the forefront of the decision making in the feature sets that are provided is important.
I'm not sure if the consolidation really has much of an effect on us as of date. UEBA, I believe, will have a huge benefit, but it's not fully implemented, so I can't speak to it in a full manner. The investigation capability of being able to search while inside of an investigation and that single pane of view has been beneficial for path consolidation for us to be able to focus on the alert that we're looking at.
I would say to ensure that you're getting the right data and getting it formatted appropriately when looking into using Splunk Enterprise Security. While you don't need to ingest everything, you do need to make sure that you're ingesting everything that is important from a detection engineering perspective. If you're missing a large portion of your logs, it's going to be very difficult for you to adequately triage the situation, and the fewer places you have to go for the right information, the easier the investigation and the better Splunk Enterprise Security tools work.
I would give Splunk Enterprise Security an overall rating of eight on a scale of one to ten.
Which deployment model are you using for this solution?
Public Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Other
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Last updated: Sep 16, 2026
Flag as inappropriateBuyer's Guide
Splunk Enterprise Security
August 2026
Learn what your peers think about Splunk Enterprise Security. Get advice and tips from experienced pros sharing their opinions. Updated: August 2026.
914,109 professionals have used our research since 2012.
Soc Analyst at Softcell Technologies Global Pvt.Ltd
Centralized monitoring has improved real-time threat detection and faster incident response
Pros and Cons
- "The best advantage is that Splunk Enterprise Security helps our organization collect and analyze logs from multiple systems in one place, providing real-time monitoring, faster threat detection, and quick incident response and investigations that improve security visibility, reduce response times, and help our team make better decisions."
- "We manage alert fatigue multiple times, as false positive alerts are triggered frequently, sometimes 200 to 300 alerts."
What is our primary use case?
In our organization, we use log management tools that collect data from multiple types of devices such as system applications and network devices like firewalls. We can collect logs from these network devices, analyze them, and report findings to the client side. We primarily use this for security purposes.
For our business improvement, we manage security for multiple clients on our side. This supports greater business development and improves our security posture. We can improve system reliability and reduce downtime while providing real-time operational insights. This helps our organization make data-driven decisions to improve customer trust, ensure compliance, and reduce operational costs.
We have achieved improvements by enhancing dashboard performance, reducing search execution time, and simplifying complex queries. The queries we work with are very complex. We have also benefited from better AI-driven threat detection and improved data management. These are areas where Splunk Enterprise Security can be further improved.
What is most valuable?
The best advantage is that Splunk Enterprise Security helps our organization collect and analyze logs from multiple systems in one place. It provides real-time monitoring, faster threat detection, and quick incident response and investigations. This improves security visibility, reduces response times, and helps our team make better decisions.
We can continuously monitor logs, detect suspicious behavior in real time, correlate events from different sources, and generate alerts before threats escalate. With AI threat intelligence and automations, our security team can identify and stop attacks as early as possible. This type of proactive defense is what we need.
Regarding pricing, we have compared multiple SIEM tools, and the pricing for Splunk Enterprise Security is the best. Multiple features are included, and the pricing reflects the value it delivers. It helps reduce security risks, automate tasks, minimize downtime, and improve incident response. The long-term savings and strong return on investment often outweigh the initial licensing cost. According to my assessment, the pricing is the best compared to other SIEM tools.
What needs improvement?
The MITRE ATT&CK framework is a knowledge base of real-world cyberattack techniques used by attackers. It helps our security team understand attack behavior, map threats, and detect malicious activity. We can track what attackers are doing, understand what happened, and follow the appropriate steps to strengthen incident response.
We manage alert fatigue multiple times, as false positive alerts are triggered frequently, sometimes 200 to 300 alerts. Alert fatigue is something we observe and analyze properly. Managing this is one of the biggest tasks we handle. We analyze these alerts to determine which types of alerts are key matches and what we should focus on.
For how long have I used the solution?
I have two years and three months of experience with Splunk Enterprise Security.
What do I think about the stability of the solution?
According to my experience, there is no downtime. During updates, we occasionally observe slowness, but generally everything performs well.
What do I think about the scalability of the solution?
We have not experienced any impact on our security posture. We have integrated multiple types of devices including multiple firewalls, network devices, and IPS systems. These help our organization and clients to improve features. We have found no negative impact from scaling.
How are customer service and support?
When we have raised multiple types of alerts to the support team and cannot manage them ourselves, we escalate to the client side support. The response time is excellent, with resolution typically occurring within 10 to 15 minutes. The support team provides links to join sessions and conducts troubleshooting. The support quality is the best for our needs.
How was the initial setup?
The setup is not fully straightforward and is somewhat complex. However, installing the agents on the client side is very easy, taking between two to three minutes, or less than five minutes total. We can continue monitoring immediately after installation. According to my experience, the setup is straightforward and not very complex overall.
What was our ROI?
When comparing tools we have used, including IBM QRadar and Splunk Enterprise Security, we created and tested multiple types of alerts. Splunk Enterprise Security generates real-time alerts, while IBM QRadar is slower with only seconds of difference rather than minutes. The AI-driven features are more improved in Splunk Enterprise Security than in IBM QRadar. However, the dashboards are better in IBM QRadar compared to Splunk Enterprise Security, which is why we suggest improving dashboard features in Splunk Enterprise Security.
We can improve Splunk Enterprise Security by simplifying queries and creating automatic alert raising features with AI-driven capabilities and machine learning. These AI-driven improvements would be better than current features.
What other advice do I have?
Splunk Enterprise Security can enhance its AI capability by improving threat prediction and reducing false positive alerts through automating alert triage and providing smarter incident response. Generating natural language questions and AI-driven analysis can help our security teams detect threats faster and improve response time while reducing manual effort.
The AI capabilities provided by Splunk Enterprise Security are improving threat predictions and automating alert triage, creating and raising alerts to the client side. This is the best AI-driven feature according to my assessment.
When we have generated alerts, we can reduce resolution time from 10 to 15 minutes for our organization and client side. As an MSSP partner, we can provide this service to the client side.
Multiple features are available in Splunk Enterprise Security that help manage our client side. We can create multiple types of dashboards and rules, which helps reduce false positive alerts. Automations are available, which is why the alert raising speed is very fast compared to manual alert raising.
Threat detection is faster because of the AI-driven features. We receive alerts faster as a result. The AI and machine learning can analyze large volumes of data to detect unusual behaviors and identify potential threats while reducing false positive alerts. Automated investigations are also available, helping our security team find any critical alert faster and improve incident response and decision-making for more efficient threat reporting.
We work with multiple environments because our clients are diverse, including leaders and medium-sized organizations. Deployment types include multiple types of servers we can integrate on the client side. Deployment options include on-premises, cloud, or hybrid environments. The organization can choose the model that best fits their needs. Splunk Enterprise Security is scalable, easy to integrate with existing infrastructures, and supports businesses of all sizes while ensuring reliable data collection and monitoring.
In our organization, we are an MSSP partner portal partner with Splunk Enterprise Security. This partnership allows us to purchase directly from Splunk and then provide the tool to our clients.
We can add threat intelligence feeds on our side. When any malicious activity or known activity is found, we can create those types of alerts. When any malicious indicator of compromise or other activity is detected in our network teams, firewalls, routers, or switches, alerts are triggered.
I give Splunk Enterprise Security a rating of 9 out of 10. I would give it a 10 out of 10, but I reduced the rating by one point because some features such as dashboard capabilities could be better, which is why I give it a 9 out of 10.
Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor. The reviewer's company has a business relationship with this vendor other than being a customer: MSP
Last updated: Jun 30, 2026
Flag as inappropriateSenior Cyber Security Operations Engineer at a manufacturing company with 10,001+ employees
Improves detection and investigation workflows while streamlining alert creation for better resilience
Pros and Cons
- "I find the process for customizing, developing, testing, deploying, and refining detections in Splunk Enterprise Security effective."
- "Splunk Enterprise Security streamlines the creation of what they call notables, which takes a lot of the effort that we would have to put into creating our own solution off the table and does it for us."
- "Splunk Enterprise Security is not exactly user-friendly."
- "Regarding customer service and technical support, their support is the worst I have ever run into in any industry."
What is our primary use case?
My main use cases for Splunk Enterprise Security are detection and investigation.
How has it helped my organization?
Splunk Enterprise Security has helped improve my organization's business resilience.
What is most valuable?
I never liked Splunk Enterprise Security much until the new version, and now that they've ramped up RBA and made changes in version eight, I prefer it much better.
Splunk Enterprise Security streamlines the creation of what they call notables, which takes a lot of the effort that we would have to put into creating our own solution off the table and does it for us.
We haven't made the newspaper yet, so Splunk Enterprise Security is doing its job. That integration supports my security operations very efficiently, or we wouldn't use it. I find the process for customizing, developing, testing, deploying, and refining detections in Splunk Enterprise Security effective. That's my bread and butter.
My organization uses risk-based alerting in Splunk Enterprise Security. The SOC is still in the development and testing phase for RBA, so they're not seeing any risk-based alerting yet. Within the next week or two, they should start seeing it.
I have no idea how long on average my SecOps team takes to remediate security incidents with Splunk Enterprise Security. I am not using any new threat detection features in Splunk Enterprise Security since we write our own correlation searches from scratch.
Regarding Splunk's ability to predict, identify, and solve problems in real-time: prediction capabilities are not present at all, identification is pretty good, and resolution is effective. It's a good tool. We've got really amazing people behind it, using it, and although there are only four of us behind it, we've got really amazing people using it.
What needs improvement?
Splunk Enterprise Security is not exactly user-friendly. The most significant challenges I face when using Splunk Enterprise Security for advanced threat detection are assets and identities, which are a pain in the neck, and the documentation for RBA is horrible.
They've got it now to where it pretty much deploys itself as long as you know what you're doing, yet it does some really weird and impractical things such as putting file extensions on lookup tables that shouldn't be there, which you have to go in and clean up. It's got some quirks that aren't documented, or not all documented.
For how long have I used the solution?
I have been working in this field for ten years and using Splunk Enterprise Security for eight.
What do I think about the stability of the solution?
I have not experienced any downtime, crashes, or performance issues based on Splunk Enterprise Security.
What do I think about the scalability of the solution?
We've expanded our license dramatically since the merger, and Splunk Enterprise Security handles it just fine. It's not really affected by scale; the infrastructure it sits on is affected by scale, however, the software itself isn't.
How are customer service and support?
Regarding customer service and technical support, their support is the worst I have ever run into in any industry. On the front line, they put people who don't know what they're doing, refuse to escalate, and are not helpful.
When we go to Splunk support, we've already done everything and are really good at what we do, however they make us do it over again or won't help us, and that's enough.
How would you rate customer service and support?
Neutral
Which solution did I use previously and why did I switch?
Way back in the day, we used QRadar, however, as soon as we converted to Splunk, we bought Splunk Enterprise Security with it.
How was the initial setup?
They've got it now to where it's pretty much as long as you know what you're doing, it deploys itself. However, it does some really weird things, like putting file extensions on lookup tables that shouldn't be there, that we have to go in and clean up.
It has some quirks that aren't documented or aren't fully documented. That's Splunk. They're not good with documentation. If you conduct thorough testing in a development or testing environment, you'll find 99% of what doesn't work and be prepared for it, ensuring that it does.
What was our ROI?
We have seen return on investment with Splunk Enterprise Security, and we're getting our money's worth. It streamlines the creation of what they call notables, which eliminates a significant amount of the effort that would be required to create our own solution, allowing us to achieve a good ROI.
Which other solutions did I evaluate?
I considered the change initially due to a better product, as it was an evaluation of a better product for a better price back then.
What other advice do I have?
My advice to other organizations considering Splunk Enterprise Security is that unless you're really big, don't spend the money. On a scale of one to ten, I rate this solution an eight.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Executive Director
Teaching students real-time cyber defense has become effective but alerts and adoption need work
Pros and Cons
- "Splunk Enterprise Security has positively impacted my organization by giving students who had no knowledge of the tool cues on how to use it and pushing them deeper into topics like cybersecurity, monitoring, and troubleshooting in terms of log monitoring."
- "Splunk Enterprise Security Essentials has not contributed to a reduction in analyst burnout or fatigue."
What is our primary use case?
I have been using Splunk Enterprise Security for about seven years.
My main use case for Splunk Enterprise Security is building dashboards, monitoring our data centers that we have built, using containerization to build dashboards, looking for anomalies, and testing for cybersecurity issues in real time.
A specific example of how I have used Splunk Enterprise Security is during a recent exercise for the students where they simulate a DDoS attack in AWS, observe what they are seeing, check the problem in the logs, and then troubleshoot and fix the problem from there. I use Splunk mostly for teaching, but of course, to monitor our data center environments as well.
I do this to teach young people Splunk, and our students have grasped the concept very well, going from not knowing what Splunk was to building high-quality dashboards that I referred to earlier.
What is most valuable?
The best features Splunk Enterprise Security offers include ease of use, which is one definite benefit, and the AI agent that you have recently released, which is very helpful in terms of being proactive and finding problems before they happen in your network as opposed to after.
Regarding ease of use, I chose Splunk Enterprise Security because it is adaptable to young students and stands out compared to other monitoring tools. Regarding the AI agent, I have let it loose in our environment to look for VLANs, private subnets, and DDoS attacks.
Students build AWS and container environments, then send their application data into Splunk Enterprise Security, create dashboards, monitor infrastructure health, identify unusual behavior, and troubleshoot performance or security issues. The important part is that they are learning how cloud, networks, containers, data centers, and observability work together in a production-style environment. For AARI, Splunk Enterprise Security turns raw telemetry into something students can understand and act on, helping me train operators who can recognize a problem, investigate it, and explain what needs to happen next. My next step is extending that same model into physical inference and robotics using telemetry from power, cooling, environmental centers, and edge devices. Splunk Enterprise Security becomes the common operating view across the entire system.
Splunk Enterprise Security has positively impacted my organization by giving students who had no knowledge of the tool cues on how to use it and pushing them deeper into topics like cybersecurity, monitoring, and troubleshooting in terms of log monitoring.
I have seen a huge increase in their confidence and skills. As I mentioned prior to us teaching them, they had no idea what Splunk Enterprise Security was, and now they are building dashboards and extending the project into other areas like robotics, which has been very inspiring to watch.
What needs improvement?
I need to partner with teaching more students what Splunk Enterprise Security is and the other products so they can be aware of it early on in life as opposed to later.
For how long have I used the solution?
I have been using Splunk Enterprise Security for about seven years.
What do I think about the stability of the solution?
Splunk Enterprise Security is stable.
What do I think about the scalability of the solution?
Splunk Enterprise Security's scalability is good.
How are customer service and support?
I have not had to use customer support for Splunk Enterprise Security.
Which solution did I use previously and why did I switch?
I did not previously use a different solution.
What was our ROI?
I have seen a return on investment, and it has more than doubled my return.
What's my experience with pricing, setup cost, and licensing?
My experience with pricing, setup cost, and licensing was quite minimal since it was through the nonprofit organization.
Which other solutions did I evaluate?
I did not evaluate other options before choosing Splunk Enterprise Security.
What other advice do I have?
I rate Splunk Enterprise Security a seven on a scale of one to ten.
I rate it a seven because it is tight, it is reliable, it will keep you gainfully employed, and nothing is perfect.
I think the governance of Splunk Enterprise Security is very needed, especially for data wrangling, as any AI project needs proper data in terms of platform and security, reliability, and more.
Its AI capabilities are quite accurate in terms of output reliability.
Splunk Enterprise Security is deployed in my organization in a hybrid cloud environment.
I use Azure and AWS as part of my hybrid deployment.
I did not purchase Splunk Enterprise Security through the AWS Marketplace.
Splunk Enterprise Security has helped improve my organization's business resilience, and I feel that it is a canary in the coal mine and a harbinger of things to come if you actually know what you are looking for in the logs.
Splunk Enterprise Security has not helped reduce my team's average mean time to resolve (MTTR) metric.
I have not upgraded to Splunk Enterprise Security 8.0.
Splunk Enterprise Security's Risk-Based Alerting (RBA) has made me more hyper-vigilant in terms of alert volume and analyst productivity.
Splunk Enterprise Security has helped me detect threats faster, very much so.
Splunk Enterprise Security Essentials has not contributed to a reduction in analyst burnout or fatigue.
The integration of threat intelligence directly into the TDIR workflow has improved my ability to preemptively block threats, making me realize that being proactive is my best offense and defense.
My advice for those looking into using Splunk Enterprise Security is to test it first, get your hands dirty, understand what it is, and then think about implementing it system-wide. I would rate Splunk Enterprise Security a seven overall.
Which deployment model are you using for this solution?
hybrid cloud environment
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Last updated: Sep 16, 2026
Flag as inappropriateCybersecurity Consultant (Enterprise Projects & Detection Engineering) at Lighthouse Technology
Centralized monitoring has transformed detection workflows and now improves proactive defense
Pros and Cons
- "Splunk Enterprise Security Essentials has contributed to a reduction in analyst burnout or fatigue, improved the daily work experience and retention in my security team, and using structured workflow management, it improves my operational coordination, accountability, and the visibility into the remediation process across multiple security initiatives."
- "Splunk Enterprise Security can improve in the UI UX interfaces, but for the rest, I am very comfortable with the reporting, dashboard, alerting, search, and reporting features."
What is our primary use case?
I have worked extensively with Splunk Enterprise Security for centralized log ingestion, security monitoring, and detection engineering. My objective is to improve enterprise visibility, reduce alert fatigue, and operationalize attack detection that is capable of identifying authentication abuse with lateral movement, PowerShell misuse, and privilege misuse in Linux environments and suspicious network activity.
My recent project focused heavily on enterprise security engineering and detection engineering, IAM Governance Analysis, which is identity and access management, cloud security operation, and resilience validation. This platform aligns directly with the areas I am actively expanding deeper into. At the end of all my logs and documentation, I link them to MetaTask, ISO 27001, and SOC 2. I have a couple of frameworks I use to analyze all of these topologies.
I was able to reduce unmanaged firewall exposure from over five thousand rows to eight hundred and fifty significantly. This was one of my enterprise projects I did on Zero Trust Security, all documented on my LinkedIn portfolio.
What is most valuable?
I appreciate the reporting features of Splunk Enterprise Security, where it enables me to document each of my telemetry. If I have an alert for a brute force attack, I can document a report on those logs and send it via email or any platform I want to share it on. I appreciate the reporting process and the alert features. Recently, I worked on onboarding Windows event logs and was able to correlate these logs with six months of telemetry, Linux authentication logs, firewall telemetry, and DNS activities into Splunk Enterprise Security. I developed correlation searches and behavioral detection that I used to align to MITRE attack techniques, including good fall detection, privilege collection monitoring, suspicious authentication analysis, and DNS abnormality detection. I also created detection to reduce false positives and improve operational reliability while integrating a reasonable workflow using Python automation for faster incident tracking. I was able to create those logs, and everything was displayed on my dashboard. The improvements reduced false positive investigation workloads significantly, improving security operation center visibility across my enterprise environment, and reducing the mean time to detect to ten minutes in a simulated enterprise environment scenario. Those are the results I have had so far in my enterprise environment.
I have solved issues during one of my enterprise security tasks where I identified excessive firewall rules, which are documented on my LinkedIn portfolio, and an unmanaged access pathway that created unnecessary attack surface exposure across my environment. The challenge was to identify still rules to validate legitimate traffic requirements and reduce unnecessary exposure without disrupting my operational workflow.
Splunk Enterprise Security has helped me detect threats faster. It has helped me reduce my team's average mean time to resolve metric. I estimate it has improved detection speed by eighty-five percent because ninety percent of my projects are essentially on Splunk, making it one hundred percent effective for my team. Splunk Enterprise Security Essentials has contributed to a reduction in analyst burnout or fatigue.
It has improved the daily work experience and retention in my security team. Using structured workflow management, it improves my operational coordination, accountability, and the visibility into the remediation process across multiple security initiatives. It has improved my ability to preemptively block threats in vulnerability management workflow and governance activities, including documenting investigations and findings, and how I assign remediation ownership. It has increased my risk ownership, improved tracking escalation status, and monitoring completion timelines.
It has changed my approach to proactive defense across both consulting and enterprise operational projects, affecting how I track remediation activities and investigation workflows, which are important for maintaining operational visibility and accountability. It has improved my operational understanding of TCP and IP behavior, attack traffic reconstruction, segmentation validation, and network-based detection engineering across the enterprise environments I have worked with. It has improved productivity in how I perform packet-level analysis using Wireshark and PXS telemetry to inspect XMB traffic, RDP sessions, DNS activities, authentication flows, and simulated lateral movement patterns.
What needs improvement?
Splunk Enterprise Security can improve in the UI UX interfaces, but for the rest, I am very comfortable with the reporting, dashboard, alerting, search, and reporting features. From the rating perspective, it could be enhanced.
For how long have I used the solution?
I have used Splunk Enterprise Security for two years.
What do I think about the stability of the solution?
Splunk Enterprise Security is stable; I have not troubleshot anything since it has worked for me. When I perform actions such as brute forcing my machine, it logs correctly, and queries I run return logs as fast as one minute ago.
What do I think about the scalability of the solution?
I believe Splunk Enterprise Security has all the features any organization could need. If the engineer knows what they are doing, it can adapt to scale, generating and importing logs without issues for different sizes of enterprises.
How are customer service and support?
I have not communicated with the technical support of Splunk Enterprise Security.
Which solution did I use previously and why did I switch?
I tried Google Sentinel before choosing Splunk Enterprise Security, but it did not suit my needs, so I had to try something else. When I got to Splunk Enterprise Security, I found it satisfactory enough not to switch to another option.
How was the initial setup?
I participated in the initial setup of Splunk Enterprise Security.
I had to go to the website first, create an account with my email, and then download either the enterprise version or Splunk Forwarder. In my Active Directory, I have my forwarder installed, and on my server machine, I have the enterprise installed. With one account, I was able to configure my port number and destination port, hosting it on localhost. I connected other components to the service with the appropriate configurations.
From a technical perspective, the initial setup was not difficult for me to navigate through.
What about the implementation team?
For a non-technical person, it may be challenging, but for a technical person, it is straightforward. The process is effective.
What was our ROI?
For return on investment, I think a large corporation would not have an issue with that. For small-scale enterprises, they may need to review those areas more, particularly related to user rates.
Which other solutions did I evaluate?
I used to analyze and log manually as a SOC analyst would before using Splunk Enterprise Security.
What other advice do I have?
Splunk Enterprise Security represents a fair price for what it can accomplish. I would rate this product a ten out of ten.
Which deployment model are you using for this solution?
On-premises
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Other
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Last updated: Jun 19, 2026
Flag as inappropriateSplunk Certified Architect at Data Elicit Solutions Pvt. Ltd.
Data insights have improved security operations and now streamline threat detection and response
Pros and Cons
- "Summing up everything from a SIEM and security point of view, I think Splunk is by far the best product that I have been using since my work experience."
- "One improvement I want to foresee is that the AI or agent needs to be fed with accurate data, not false data, so that whenever it performs automation on your behalf, it doesn't misconfigure anything."
What is our primary use case?
When we talk about Splunk Enterprise, I have seen clients using it for their data analysis, collecting the logs and preparing meaningful insights out of it, like having dashboards created from the data that they ingest into Splunk. Apart from that, there is a SaaS platform that Splunk provides which is called the Splunk Cloud platform; it provides similar functionality, but the end-to-end config management is handled by Splunk directly. You just have access to the Splunk search head where you log in and can search the data you ingest into Splunk Cloud. Regarding Splunk Enterprise Security, I have seen customers using it for security use cases and to ensure that the environment or organization is not impacted by any SOC threats; basically, they use it for detection and mitigation both.
Customizing and developing new detections in Splunk Enterprise Security are quite simple since I have got experience with it for more than four years. I am quite familiar with it and enjoy working through that as well.
I do use disparate security solutions that integrate or import data into Splunk Enterprise Security.
The security operations are supported on a very great scale because let's say we have written n number of detections; we also need to ensure that we don't get alerted or notified on false positives. There is a dashboard in Splunk Enterprise Security that displays all the detections identified as a potential risk or alert to the environment. From there, you can triage the work to investigate deeper into it, and from the dashboard, you can drive it towards closure, with different drill-down options to investigate how a particular event was identified as a risk event and whether it was a false positive. If it wasn't a false positive, you can dive deeper into it using different response actions as well; all these customizations can be done and they support any third-party response actions that you want to apply to the Splunk Enterprise Security detection you have.
What is most valuable?
What I like about Splunk Enterprise Security is the way it is able to correlate or ingest any kind of data from any product or source, alert and adapt the whole data as it is, and then provide it in a single visualization format. It handles and provides you options for customizations and different options for alerting as well. Summing up everything from a SIEM and security point of view, I think Splunk is by far the best product that I have been using since my work experience.
Splunk Enterprise Security has indeed helped improve the organization's business resilience. I don't have specific numbers for sharing purposes, but on a quarterly basis, I have seen Splunk helping the resilience and assisting the business greatly in terms of avoiding SOC threats.
What needs improvement?
You need to adapt to new changes constantly and be sure of new learnings in Splunk Enterprise Security; that is the only challenge I would say. However, I don't see it as a problem because if resources are available for you to understand new changes and how detections are managed or how to incorporate advanced threat intelligence frameworks, there is no huge challenge in integrating it with Splunk Enterprise Security. You need to know what things you want to click on the UI; if you are aware of that, there is no challenge. It is just constant learning that you have to give yourself to learn and grow for your own better self.
One improvement I want to foresee is that the AI or agent needs to be fed with accurate data, not false data, so that whenever it performs automation on your behalf, it doesn't misconfigure anything. Trust in the product relies on the AI being reliable and trustworthy, ensuring 100% accuracy and avoiding false positives.
I would say Splunk's ability to predict, identify, and solve problems in real time is near accurate; I cannot confirm that it is 100% since none of the systems are. It definitely alerts you on what particular time you need to be notified. However, to achieve near 100% accuracy, how you handle the searches running in your environment and stagger them is important to avoid overwhelming server resources. Splunk provides features to adjust time zones and write custom schedules; there is no challenge with that. However, there will always be delays, so it is about how you ingest the data; if the source is behind the Splunk server's timezone, that could impact results.
For how long have I used the solution?
I have been working with Splunk for almost six years now.
What do I think about the stability of the solution?
So far, we have not faced any downtime or performance issues with Splunk; there can be outages, but we are automatically notified when they occur, and the team works on resolution. Since we are using Splunk Cloud, we receive notifications directly from them.
What do I think about the scalability of the solution?
I would say Splunk is quite scalable, and we are definitely making the most out of it. Our company was involved in delivering sessions at splunk.conf last year, showcasing how we utilize Splunk and the solutions provided, indicating that we are scaling quite effectively.
How are customer service and support?
I would rate the Splunk support team an eight or nine out of ten; this rating is based on my experience of being part of the partner team that delivered Splunk support. The support depends on the partner, and I appreciate having a dedicated account manager for our customer account, ensuring effective handling of operations and issues. No one can have 100% knowledge, and while there might be delays in response, the support team effectively isolates problems and finds solutions, adhering to an escalation policy that keeps customers updated and satisfied.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
Since I have worked more with Splunk, I am somewhat biased but I would say understanding and writing queries to analyze your ingested data is simpler in Splunk and in other products such as Sumo Logic as well. However, no product can match the level of customization and visualization that Splunk can build; you can create reports, dashboards, and present these in a business fashion, which is unmatched.
How was the initial setup?
Deploying Splunk is a piece of cake for me; since I have got so much experience, deploying any kind of environment is not a challenge. I am still in the evolving phase as I started my professional journey with Splunk in 2019. I have made numerous deployments for different testing purposes, replicating customer challenges in our test environment to address their issues directly.
What was our ROI?
That is a bit subjective, I would say because in the Indian market, people often look for alternative solutions to avoid spending more. However, I have seen great satisfaction levels among companies that have utilized Splunk, including the one I am working for now, which has been renewing Splunk licenses over the past decade. If Splunk were not that great, people would not keep renewing it over the years; there is an option for good return on investment, but eventually, people try to find alternatives to save on expenses for R&D or other purposes.
What's my experience with pricing, setup cost, and licensing?
I am not very much aware of the licensing since we are service providers for Splunk or Cribl or DataDog, but I do know Splunk provides licensing in two different ways: SVC-based licensing and ingest-based licensing. The old model charged based on the volume of data ingested on a daily basis, while the current SVC-based model charges based on the compute utilized for searching that data, regardless of volume.
Which other solutions did I evaluate?
All over the globe, it is the AI and agent era, and Splunk is also a part of it having introduced Splunk AI as part of its cloud platform features, eventually to be released in on-prem solutions as well.
What other advice do I have?
I usually do not manage or investigate the alerts that have been triggered; I work on building and managing the use cases, optimizing them. The analyst team works on the incidents but from what I have heard, before I joined the current organization there were a lot of changes required to be made internally in the product itself and the way we were writing optimizations. But afterwards, we defined a clean process and the mean time to closure or mean time to resolve had reduced drastically by almost 60 to 70% compared to what it was previously.
It is not that we are limited to risk-based alerting in Splunk Enterprise Security; we are using threat intelligence and we have recently configured SOAR as I just mentioned. Additionally, we are using UBA for user behavioral analytics.
We have definitely seen benefits from the threat detection and threat intelligence capabilities in Splunk; we apply risk scores and threat scores to our detections and to the attributes we want to identify or flag as potentially high-risk or high-threat objects. This helps us prioritize the tasks we want to start our daily task with; it definitely helps with understanding the priority tasks to be worked upon. We also make sure to update our threat feeds regularly since we need to stay on top of all the threat findings globally, ensuring we identify all malicious IP addresses or any file hashes that have been tracked as a threat and are publicly available.
I would advise organizations considering Splunk to stick to the fundamentals; as long as you understand how Splunk operates and the functions of its different components, you won't face challenges in troubleshooting or understanding errors. I would rate this review a ten out of ten overall.
Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor. The reviewer's company has a business relationship with this vendor other than being a customer: MSP
Last updated: Feb 25, 2026
Flag as inappropriateSr Manager Global Security Operations at a financial services firm with 10,001+ employees
Standardized investigations and fraud detection have improved team efficiency significantly
Pros and Cons
- "It's standardized and easy to use, so you don't have to have a lot of top-tier analysts to do the same job."
- "Splunk Enterprise Security can be improved by bringing back some of the operational use cases."
What is our primary use case?
My main use case for Splunk Enterprise Security is security eventing.
What is most valuable?
The features of Splunk Enterprise Security provide a standardized platform for investigating.
The content libraries are helpful. In our organization, we don't use them a lot. We will use them as ideas and rebuild them into what our needs are.
It's standardized and easy to use, so you don't have to have a lot of top-tier analysts to do the same job.
The investigations plane and use case library have been beneficial.
We utilize Splunk Enterprise Security for our fraud team using pure ES. We use all the fraud features, and that's been incredibly helpful.
The detection rate and prevention rate has gone up 30 times compared to when they were working on a spreadsheet. The fraud team loves it.
Once we move over to 8.2, we're going to utilize more of the built-in features.
I appreciate the visual control and the investigations plane, though that will be a major migration for us.
What needs improvement?
Splunk Enterprise Security can be improved by bringing back some of the operational use cases. When Splunk developed ITSI, they took a lot of information or use cases out of ES, where operational use cases can also be security use cases. Those two products need to be more migrated to each other. In the next release of Splunk Enterprise Security, there should be more reporting options.
For how long have I used the solution?
I have been using Splunk Enterprise Security for nine years.
What do I think about the stability of the solution?
I would assess the stability and reliability of Splunk Enterprise Security as excellent. I've had no problems with downtime, crashes, or performance issues.
What do I think about the scalability of the solution?
Splunk Enterprise Security scales with the growing needs of my organization just fine. The licensing for ingest is a different story.
How are customer service and support?
I would evaluate customer service and technical support for Splunk Enterprise Security as lacking. The service engineers that we've been getting as part of our weekly or bi-weekly calls with our salesperson, where they've assigned an engineer, have decreased tremendously in quality and expertise over the last few years. People on the team that really know Splunk know a lot more than they do, and it's evident because they don't try anymore. We can still get expert help when we need it.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
Prior to adopting Splunk Enterprise Security, I was not using another solution to address similar needs.
How was the initial setup?
I would describe my experience with deploying Splunk Enterprise Security as easy. The KV store setup was straightforward.
What was our ROI?
I have seen ROI with Splunk Enterprise Security.
What's my experience with pricing, setup cost, and licensing?
My experience with pricing, setup cost, and licensing for Splunk Enterprise Security has been fine. We've renewed since Cisco took over.
What other advice do I have?
My advice to other organizations considering Splunk Enterprise Security is to follow the documentation and not build your own stuff.
On a scale of one to ten, I rate this solution a nine.
Which deployment model are you using for this solution?
Hybrid Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Senior Vice President Cyber Security at Mindsprint
Risk-based monitoring has improved threat detection speed and supports custom SOC use cases
Pros and Cons
- "Regarding the impact on threat detection capabilities, it provides a faster mean time to detect."
- "We have seen that the pricing has gone higher and the support quality has not kept up or was not as good as it was earlier."
What is our primary use case?
Splunk Enterprise Security is used for our SOC, the Security Operations Center, which provides 24/7 monitoring. I am using disparate security solutions to integrate or import data into Splunk Enterprise Security. We use Splunk Enterprise Security to ingest the logs and do the monitoring.
As for alerting, especially risk-based alerting, it works well. It supports the use cases that we are looking for. Splunk Enterprise Security supports my SOC in terms of developing any new use cases. If we have any custom integration requirements or any custom use cases, we can easily develop that in Splunk Enterprise Security, and that's how we are able to leverage Splunk Enterprise Security for any custom use cases.
What is most valuable?
The biggest advantage for me in Splunk Enterprise Security is all the ready-made integrations and the connectors that are available. Integration is the strongest part; the connectors and the built-in connectors are the strongest part which allow the integration.
My impression of processes such as customization, developing, testing, deploying, and refining detections is that it works as designed for all the detections and all the new capabilities that we can leverage. It works very well.
Integration supports my security operations. When it comes to remediation, we are not using it for remediation with Splunk Enterprise Security; Splunk Enterprise Security is purely for detection. Remediation has to be done by the respective teams using their own tool sets.
Regarding the impact on threat detection capabilities, it provides a faster mean time to detect. The team is able to respond faster because we are using Splunk Enterprise Security and we are able to ingest all the logs from various sources. Any threats which are emerging across the world and across different types of log sources, our team is able to detect them faster. Overall dwell time of an attacker or any kind of attacks that we see, we are able to respond much faster because we are able to detect it in the first place much faster.
What needs improvement?
There is something in Splunk Enterprise Security which is not perfect. What we are seeing is more not on the technology side, but on the pricing and support point of view once Cisco has taken over. We have seen that the pricing has gone higher and the support quality has not kept up or was not as good as it was earlier. These are the two things we see as areas for improvement.
Regarding the issue with support, it takes longer for support to come back to us and then it goes through multiple layers of escalation before we get to the right person.
I would like to see some additional features, more on the AI detection and automatic detection using AI capability. Although Splunk Enterprise Security has some amount of AI capability, what we would like to see is more on the detection side, how AI can help and how Splunk Enterprise Security can introduce those features as part of the built-in platform itself.
For how long have I used the solution?
I started working with Splunk Enterprise Security about six or seven years ago.
What do I think about the stability of the solution?
Splunk Enterprise Security is very reliable and stable. Reliability is also very good.
What do I think about the scalability of the solution?
Regarding scalability for Splunk Enterprise Security, scalability is very good. We have scaled it about four times over the past six years in terms of the log size. Scalability is very good.
How are customer service and support?
As for the issue with support, it takes longer for support to come back to us and then it goes through multiple layers of escalation before we get to the right person.
What other advice do I have?
Splunk Enterprise Security is a worth buying product if you are able to leverage all the features and the capabilities or if the team is strong to leverage all of them.
The percentage of savings depends on what we are comparing. It is straightforward; if the team is experienced with Splunk Enterprise Security, it is quite straightforward and quite fast.
Regarding business resilience, Splunk Enterprise Security does improve business resilience because I am able to protect my assets and hence improve the resilience. I am able to solve problems in real time, to predict, and to identify threats. It helps my detection to be faster, which is about 40 percent faster. The overall review rating for this product is 8 out of 10.
Which deployment model are you using for this solution?
On-premises
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Other
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Last updated: Jun 16, 2026
Flag as inappropriateSoc Manager at a real estate/law firm with 1,001-5,000 employees
Investigation efforts have improved while search complexity still requires attention
Pros and Cons
- "The investigation feature helps the team seamlessly put everything together, providing a consistent view of all relevant artifacts for incidents."
- "Splunk Enterprise Security can be improved with better triage capability and less dependency on running SPL searches, which would allow analysts who may not have much experience in writing SPL searches to still use the tool and run investigations."
What is our primary use case?
Our main use cases for Splunk Enterprise Security include security, detection, and incident response.
How has it helped my organization?
The data model benefits our organization by making it easy for the team to get data into Splunk, and field tagging is particularly helpful.
What is most valuable?
The features of Splunk Enterprise Security that I most appreciate are CIM, the data model, the search capabilities, and the investigation feature embedded into Splunk version 8.
The investigation feature helps the team seamlessly put everything together, providing a consistent view of all relevant artifacts for incidents.
Splunk's ability to predict, identify, and solve problems in real-time is exceptional due to its ease of data ingestion and comprehensive search capabilities with various options.
I find the process for customizing, developing, testing, deploying, and refining detections in Splunk Enterprise Security to be excellent, especially with the new Mission Control included in Splunk Cloud version 8. It is really easy to use.
We are sending data directly to Splunk Cloud without any broker or pipeline in between. Our organization does not use risk-based alerting in Splunk Enterprise Security yet, and our SecOps team has not measured incident remediation times compared to our previous solution.
I would advise other organizations considering Splunk Enterprise Security to check their business case, considering the number of systems and amount of data to determine if it is the right tool in terms of the licensing model. If they decide to implement Splunk Enterprise Security, getting professional support is crucial.
One of our decision drivers was the customer support, which we found to be very responsive based on feedback from other customers. Additionally, the ability to extend the license for IT-related topics provides flexibility to leverage the platform across all departments, not just security - a unique feature compared to other SIEM tools.
What needs improvement?
Splunk Enterprise Security can be improved with better triage capability and less dependency on running SPL searches, which would allow analysts who may not have much experience in writing SPL searches to still use the tool and run investigations.
For how long have I used the solution?
We are still at the beginning, just four months into using Splunk Enterprise Security.
What do I think about the stability of the solution?
I assess the stability and reliability of Splunk Enterprise Security as generally good. We had a few glitches, but nothing serious, and when we needed to raise cases with the support team, they were quickly resolved, particularly an issue on the indexer level.
What do I think about the scalability of the solution?
Splunk Enterprise Security scales effectively with our growing needs. As a global organization, we first started with three regions, and when we were about to move to include the last region, it was easy to increase the license and onboard the new region seamlessly.
How are customer service and support?
I would evaluate customer service and technical support for Splunk Enterprise Security as excellent, particularly our sales representative, who is exceptional. On a scale of one to ten, I would rate customer service and technical support as a nine.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
Prior to adopting Splunk Enterprise Security, we were using QRadar from IBM, but we wanted a modern and state-of-the-art SIEM, which led us to choose Splunk Enterprise Security.
How was the initial setup?
The deployment was the best that I have gone through so far. We had the professional support, which is something I recommend everyone do, which is like introducing Splunk and having the Splunk professional support personnel advising and supporting through the implementation phase.
What about the implementation team?
We had professional support, which I recommend to everyone introducing Splunk Enterprise Security, to have professional support advising and supporting them through the implementation phase.
What was our ROI?
The return on investment from Splunk Enterprise Security is still to come.
What's my experience with pricing, setup cost, and licensing?
My experience with pricing, setup cost, and licensing for Splunk Enterprise Security was positive. We had an excellent sales representative. The licensing model was fair and good compared to other tools we evaluated. The storage-based licensing was the best model that fit our requirements, though it may change as we evolve and ingest more data.
What other advice do I have?
I rate this product seven out of ten. Nothing is perfect, and there is still room for improvement.
Which deployment model are you using for this solution?
Public Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Buyer's Guide
Download our free Splunk Enterprise Security Report and get advice and tips from experienced pros
sharing their opinions.
Updated: August 2026
Product Categories
Security Information and Event Management (SIEM) Log Management IT Operations AnalyticsPopular Comparisons
IBM Security QRadar
Splunk AppDynamics
Microsoft Sentinel
Elastic Security
IBM Turbonomic
Palantir Foundry
WhatsUp Gold
LogRhythm SIEM
Rapid7 InsightIDR
Elastic Observability
Buyer's Guide
Download our free Splunk Enterprise Security Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- Which would you recommend to your boss, IBM QRadar or Splunk?
- What are some of the best features and use-cases of Splunk?
- What SOC product do you recommend?
- Splunk as an Enterprise Class monitoring solution -- thoughts?
- What is the biggest difference between Dynatrace and Splunk?
- IBM QRadar is rated above competitors (McAfee, Splunk, LogRhythm) in Gartner's 2020 Magic Quandrant. Agree/Disagree?
- What are the advantages of ELK over Splunk?
- How does Splunk compare with Azure Monitor?
- New risk scoring framework in the Splunk App for Enterprise Security -- thoughts?
- Splunk vs. Elastic Stack



















