We primarily use the solution for security and operations monitoring.
Managing Director at Hayyan Horizons
Low-maintenance and stable with very useful dashboards
Pros and Cons
- "The log aggregation is great."
- "Gives full visibility on operational and security posture in our organization."
- "Technical support needs to be more responsive."
- "The TERM licensing model is still not very useful. It's not helping us."
What is our primary use case?
How has it helped my organization?
Gives full visibility on operational and security posture in our organization. Integrations is straightforward and effective.
What is most valuable?
The log aggregation is great.
The solution offers good data analytics.
The dashboards are very helpful.
The initial setup is simple and straightforward.
The solution is low-maintenance.
It's a stable product.
We have found that the solution scales well.
What needs improvement?
The TERM licensing model is still not very useful. It's not helping us. They used to have a perpetual licensing model. Now Splunk is offering annual term/subscription only. That's costly and it's more expensive and it's putting some burden on us.
Technical support needs to be more responsive.
We would like to see more AI. Through AI, artificial intelligence, not machine learning only. We want to see more AI-enabled kinds of functionalities just to reduce dependencies on manual interventions. We do that, however, automation and artificial intelligence-based kind of automation we would really like to see.
Buyer's Guide
Splunk Enterprise Security
May 2026
Learn what your peers think about Splunk Enterprise Security. Get advice and tips from experienced pros sharing their opinions. Updated: May 2026.
902,270 professionals have used our research since 2012.
For how long have I used the solution?
I've been using the solution for six years. I've used it for a while at this point.
What do I think about the stability of the solution?
It's not high maintenance. There are software or upgrade releases every now and then, however, in general, the product is very stable. There are no bugs or glitches. It doesn't crash or freeze.
What do I think about the scalability of the solution?
We have 17 people that are using the solution currently.
It's very easy to scale the product if you need to.
How are customer service and support?
We use technical support every now and then. The response times are not very good. This is the thing that I would need to see improvement on and probably in that area only. They are that good when they started handling cases, however, they take too much time to respond to customer requests.
Which solution did I use previously and why did I switch?
We did not use anything else on the production scale. Our first experience was with Splunk.
How was the initial setup?
The solution is straightforward and simple to set up. It's not complex at all.
What about the implementation team?
We handled the process internally. We did not need the assistance of any integrators or consultants.
What's my experience with pricing, setup cost, and licensing?
Filter the noise out.
Which other solutions did I evaluate?
Yes all the other competitors, Splunk by far is the best.
What other advice do I have?
We're a partner and a customer.
I'm using the latest version of the solution.
I would highly recommend the solution. It's the best product out there. It's definitely easy to set up. The use cases are multiple. It's not restrictive in terms of the efficiency of the platform. Just make sure that you have enough resources or good counsel from people who can help with the use cases. If you do the sky would be the limit. It is a good solution.
I'd rate the solution at a ten out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
Senior Network Engineer at a tech services company with 51-200 employees
Useful search function, beneficial session reports, but performance could improve
Pros and Cons
- "The most valuable features in Splunk are the search function and the ability to run selected session reports. The session reports are important because I can use them to see what is going on in our environment weekly. Additionally, we can use the graph to see how often that particular event is happening."
- "Splunk has saved our organization time by resolving problems in a quicker timeframe."
- "Over time I will have more requirements and I can foresee the solution could improve the search algorithm to run and output the data faster."
What is our primary use case?
We typically use Splunk to collect and check all the logs and events around the diverse network environment which includes, firewall, switches, and routers. For example, we have traffic that needs to go from one part of the network to another and if we think there is a firewall blocking it along the path, rather than log in to all the firewalls to see what is happening, we simply go into Splunk and the check traffic going across the parts of the network to see where it is being dropped and what is the likely reason it has been dropped.
How has it helped my organization?
Splunk has saved our organization time by resolving problems in a quicker timeframe. Before if we had networking issues we would have to log into every single device, check the firewall to see why the traffic is not going across to solve the problem. With Splunk, you only have a single pane of glass to check what is likely happening. This has enabled us to easily go to the right environment and write the necessary security policy to permit such traffic. It brings about faster resolution of problems reduced with visibility.
What is most valuable?
The most valuable features in Splunk are the search function and the ability to run selected session reports. The session reports are important because I can use them to see what is going on in our environment weekly. Additionally, we can use the graph to see how often that particular event is happening.
What needs improvement?
Over time I will have more requirements and I can foresee the solution could improve the search algorithm to run and output the data faster.
For how long have I used the solution?
I have been using Splunk for approximately six months.
What do I think about the stability of the solution?
We have been satisfied with the stability of the solution.
What do I think about the scalability of the solution?
Slunk scale very well.
We have approximately 50 people in our infrastructure and applications teams using this solution in my organization.
We plan to increase usage in the future.
How are customer service and technical support?
I have not needed to open a ticket up with technical support.
Which solution did I use previously and why did I switch?
Previously to using Splunk we only had some Syslog servers that we sent logs to. However, Syslog servers, do not analyze your logs, they only capturing them. Whereas, in Splunk, you can assess the logs and you can do other things with the log.
How was the initial setup?
I do not think the implementation is difficult.
What about the implementation team?
We have an internal team that does the maintenance of the solution.
Which other solutions did I evaluate?
I have evaluated DataDog.
What other advice do I have?
Splunk is easy to use and not having the need to log into every single network device for management is helpful.
I rate Splunk a seven out of ten.
Which deployment model are you using for this solution?
Public Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Buyer's Guide
Splunk Enterprise Security
May 2026
Learn what your peers think about Splunk Enterprise Security. Get advice and tips from experienced pros sharing their opinions. Updated: May 2026.
902,270 professionals have used our research since 2012.
President at a non-profit with self employed
Expensive, but easy data gathering and reliable
Pros and Cons
- "The solution allows easy gathering and ingestion of the data."
- "The solution could improve by increasing the performance. We have run into problems when large amounts of data are processed."
What is our primary use case?
We use Splunk for analyzing data.
What is most valuable?
The solution allows easy gathering and ingestion of the data.
What needs improvement?
The solution could improve by increasing the performance. We have run into problems when large amounts of data are processed.
For how long have I used the solution?
I have been using Splunk within the past 12 months.
What do I think about the stability of the solution?
The solution has been stable.
What do I think about the scalability of the solution?
Our customers are mostly enterprise-sized companies using this solution.
How are customer service and technical support?
Splunk has many partners that provide customer support that can be used.
How was the initial setup?
The initial setup is not easy. Customers have to learn the Splunk language and it is hard to operate it by themselves. They will need Splunk engineers to assist in their projects.
What about the implementation team?
You will need a Splunk implementation specialist for the deployment.
What's my experience with pricing, setup cost, and licensing?
My customers have found the price of the solution to be high.
What other advice do I have?
I rate Splunk a five out of ten.
Disclosure: My company has a business relationship with this vendor other than being a customer.
Senior Cyber Security Expert at a security firm with 11-50 employees
Great performance, easy to set up, and offers good speed
Pros and Cons
- "The level of robustness on offer is very good."
- "The performance is very good; it's something that customers are always looking for, and the product offers good stability with no bugs or glitches, and it doesn't crash or freeze, making it reliable."
- "The complexity could be worked on so that it's even easier and faster."
What is our primary use case?
Typically, we use the solution for critical infrastructure companies.
What is most valuable?
The speed is a very valuable aspect of the solution.
The way Splunk handles low data and low-rate costs are great.
The level of robustness on offer is very good.
The initial setup is very straightforward.
We have found that the solution offers good integrations with other products.
Overall, the solution works very well.
What needs improvement?
The complexity could be worked on so that it's even easier and faster. However, I understand that, if some complexity was removed, there might be slightly more limitations.
Occasionally there are data sizing and data-related issues that need to be overcome.
For how long have I used the solution?
I've been using the solution for a couple of years.
What do I think about the stability of the solution?
The performance is very good. It's something that customers are always looking for. The product offers good stability. There are no bugs or glitches and it doesn't crash or freeze. It's reliable.
What do I think about the scalability of the solution?
We have about five to ten partners that use Splunk.
Which solution did I use previously and why did I switch?
I'm a fan of QRadar. I use them as well.
How was the initial setup?
The initial setup is very straightforward. It's not overly complex or difficult. A company shouldn't have any issues with the process. The deployment process doesn't take too long. You can manage it with fewer people and smaller teams. This is especially true if it isn't the critical infrastructure that you are working with.
For deployment and maintenance, you only need two to three people. That can include one manager and two professionals. Since Splunk is easier to handle, more people can join in on the client-side.
What's my experience with pricing, setup cost, and licensing?
We also use QRadar, and we make more money with QRadar than with Splunk as we can make bigger projects happen. However, we find that with Splunk, while we don't make as much money on each project, we can do more of them.
What other advice do I have?
I'd rate the solution at an eight out of ten.
Which deployment model are you using for this solution?
Public Cloud
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
Product Manager, FX Solutions at a tech services company with 10,001+ employees
Easy to use, informative documentation for data retrieval, and easy to install
Pros and Cons
- "The most valuable features of the solution are it is straightforward to use and the documentation is good for finding out how to get the data you are looking for."
- "The solution could improve by making it more business analysis oriented. The way it is now is designed more for developers."
What is our primary use case?
I use this solution for data visualization.
What is most valuable?
The most valuable features of the solution are it is straightforward to use and the documentation is good for finding out how to get the data you are looking for.
What needs improvement?
The solution could improve by making it more business analysis oriented. The way it is now is designed more for developers.
For how long have I used the solution?
I have been using Splunk for two weeks.
What do I think about the stability of the solution?
The solution is stable, I have not experienced any bugs or glitches.
What do I think about the scalability of the solution?
The solution is scalable and it is a requirement of my company to have scalable solutions.
Which solution did I use previously and why did I switch?
I have used previously Qlik Sense and Kibana.
How was the initial setup?
I did the training with Slunk and once I had the training the installation was easy.
Which other solutions did I evaluate?
I have evaluated Tableau.
What other advice do I have?
My advice to others is not to be intimidated by the solution and to give it a try. It will become easier over time.
I rate Splunk an eight out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Cyber Security Consultant at a computer software company with 11-50 employees
Customizable and has average installation difficulty
Pros and Cons
- "I have found the installation can be of medium difficulty to very complex depending on the use case."
- "When using this solution for Security Information Management (SIM), I highly recommend importing data sources from the whole cycle for the service security chain."
- "There is improvement needed when importing from some types of data sources. Most of the time you have to do some customization for the data because not everything is working the way it should."
What needs improvement?
There is improvement needed when importing from some types of data sources. Most of the time you have to do some customization for the data because not everything is working the way it should. Additionally, in other solutions, it is easier to build use cases.
For how long have I used the solution?
I have been using this solution for approximately three years.
Which solution did I use previously and why did I switch?
I have previously used Curator and it was much easier to use than this solution.
How was the initial setup?
I have found the installation can be of medium difficulty to very complex depending on the use case. It is not easy for new customers. You need to have the experience to be able to do it.
What other advice do I have?
When using this solution for Security Information Management(SIM), I highly recommend importing data sources from the whole cycle for the service security chain. Some people only use main inputs and not all of the data sources they have. They might not have some data sources, in this case, you can purchase one or there are free open-source ones available. You will then have this data source that can enrich your life because many correlations are done with this data.
I rate Splunk an eight out of ten.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Technical Account Manager at Trustaira
Straightforward to set up with great integration capabilities and a high level of maturity
Pros and Cons
- "The solution has proven to be quite stable."
- "This solution is the best security solution."
- "The product is relatively expensive."
- "The problem with the product is that the price of Splunk is very high."
What is our primary use case?
We primarily use the solution for monitoring and security.
We can use the solution to try to find some correlational data. For example, in banks, there is usually a protocol whereby users cannot withdraw more than a certain amount of money from an ATM. However, we find that, when people are on holiday, they are trying to withdraw more than the allowed amount. It's a use case we can deploy in our country. You can set certain rules and watch the data in order to gain insights.
How has it helped my organization?
I cannot speak to a specific example of how the solution has assisted our organization.
What is most valuable?
The solution's capability is its most valuable aspect.
The initial setup is very straightforward.
The solution has proven to be quite stable.
We've found the solution to be very mature.
The integration capabilities are excellent. They have apps that integrate quite well with Palo Alto and Cisco, for example.
What needs improvement?
Sometimes it becomes very difficult to find certain results from Splunk. Not all users are developers and they are not able to write code to find specific results or specific details from Splunk. From a user perspective, the solution needs to improve the search functionality.
The dashboard could be improved. If it was easier for non-developers or those working in network security, it would be ideal. It would be nice if they had a built-in dashboard for those who are less knowledgeable in coding.
The product is relatively expensive.
For how long have I used the solution?
I haven't been using the solution for very long just yet.
What do I think about the stability of the solution?
The solution is very stable. There are no bugs or glitches. It doesn't crash or freeze. It's reliable.
What do I think about the scalability of the solution?
We do not plan to increase usage at this time.
How are customer service and technical support?
We've used technical support in the past. We've found them to be very helpful and responsive. We're satisfied with the level of support that we receive when we reach out for help.
Which solution did I use previously and why did I switch?
I've previously used LogRhythm, among other solutions. We sell a few different solutions.
How was the initial setup?
The initial setup is not too difficult. It's not overly complex. It's straightforward. The code is very easy.
The deployment took two or three months or so.
What about the implementation team?
We used an integrator to assist us in the initial setup.
What's my experience with pricing, setup cost, and licensing?
The problem with the product is that the price of Splunk is very high. It is an industry leader and therefore it's high in terms of price. That is the issue in our country. Sometimes people want to buy Splunk, however, due to the budget, they are not able to.
What other advice do I have?
We are resellers.
We use a variety of deployment models, including private cloud and hybrid.
This solution is the best security solution. If a company is looking for the best, they have to buy Splunk. It is a very good and very mature solution. It is very easy to integrate with some other service or security solutions. If they have specific solutions that need to be integrated for monitoring purposes, it should be a problem. For example, it integrates very well with Cisco.
I'd rate the solution at a ten out of ten. We are quite happy with its capabilities.
Which deployment model are you using for this solution?
Private Cloud
Disclosure: My company has a business relationship with this vendor other than being a customer. Reseller
Security Professional at a tech services company with 51-200 employees
Good data analysis and visualizations, absolutely stable, and scalable
Pros and Cons
- "The data analysis part is good in Splunk, which is something that I like the most, and it is also quite easy to use, with dashboards, visualizations, and analytics that are good."
- "It currently has limited default rules and customizations. If they can concentrate more on the compliance part and the security information part, it would be helpful. The platform part is good, but it requires many features from the security aspect."
What is our primary use case?
We are using it for security information and event management (SIEM). We have started to use Splunk recently, and we are in the implementation phase as of now.
What is most valuable?
The data analysis part is good in Splunk, which is something that I like the most. It is also quite easy to use. Its dashboards, visualizations, and analytics are good.
What needs improvement?
It currently has limited default rules and customizations. If they can concentrate more on the compliance part and the security information part, it would be helpful. The platform part is good, but it requires many features from the security aspect.
For how long have I used the solution?
I have been using this solution for a couple of months.
What do I think about the stability of the solution?
It is absolutely stable.
What do I think about the scalability of the solution?
It is scalable. We have approximately 25 users.
How was the initial setup?
It was easy to install. Its configuration and development are the critical parts, and there are a limited number of people in the market with such a skill set. It takes some time to find people with the right skill set and get it implemented properly. It took approximately three months.
What about the implementation team?
I have a team of a few Splunk consultants who are currently managing it for me. For a mid-sized organization, at least 15 persons are required to manage the entire Splunk instance.
What other advice do I have?
I would recommend this solution to others. I would rate Splunk an eight out of ten.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Consultant at a financial services firm with 5,001-10,000 employees
Good scalability, dashboards, and alarms, but should have a default dashboard for a firewall and better knowledge base
Pros and Cons
- "Its dashboard is valuable, and if you have a good knowledge of how to create a dashboard, you can create any dashboard related to cybersecurity, and if fine-tuned, the alarms that are triggered for instant review are also very valuable and useful."
- "Splunk is query-based, which is not the case with most cybersecurity tools. It is based on search queries and can be difficult to use. It would be good if they can make it easier to understand how to create search queries. They can improve the knowledge base for better understanding. To create your dashboard, you need to have a search query. We have multiple firewalls in our company, and we need a dashboard for them. It would be helpful if a default firewall dashboard is included in Splunk to make monitoring easier. If a dashboard is available for a security device, the operation part will be more efficient. We won't have to follow a manual process for this."
- "Splunk is query-based, which is not the case with most cybersecurity tools. It is based on search queries and can be difficult to use."
What is our primary use case?
We are using Splunk for cybersecurity operations.
What is most valuable?
Its dashboard is valuable. If you have a good knowledge of how to create a dashboard, you can create any dashboard related to cybersecurity. If fine-tuned, the alarms that are triggered for instant review are also very valuable and useful.
What needs improvement?
Splunk is query-based, which is not the case with most cybersecurity tools. It is based on search queries and can be difficult to use. It would be good if they can make it easier to understand how to create search queries. They can improve the knowledge base for better understanding.
To create your dashboard, you need to have a search query. We have multiple firewalls in our company, and we need a dashboard for them. It would be helpful if a default firewall dashboard is included in Splunk to make monitoring easier. If a dashboard is available for a security device, the operation part will be more efficient. We won't have to follow a manual process for this.
For how long have I used the solution?
I have been using this solution for eight months.
What do I think about the stability of the solution?
In terms of operations, it is stable, but if you don't have a proper configuration and sizing, there could be many issues. It could be more efficient on the storage part. We are still in the deployment stage to be able to say that for sure.
What do I think about the scalability of the solution?
It is very scalable. Currently, we have around 50 users. We will increase its usage if more people need access.
How are customer service and technical support?
We have raised multiple tickets. Some of them are good, and some of them can be better. Overall, their technical support is okay.
Which solution did I use previously and why did I switch?
We didn't use any other solution.
How was the initial setup?
I didn't do the initial configuration. I take care of the operations part. One of our clients did it, and it is somehow complex, and it takes time. It also depends on your knowledge. If you don't have knowledge of Splunk, it is complex.
Which other solutions did I evaluate?
We are a partner of Splunk. So, we did not evaluate other solutions.
What other advice do I have?
I would rate Splunk a seven out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
Product Manager, CyberSecurity at a tech services company with 201-500 employees
Has good security features but needs a better pricing model
Pros and Cons
- "The initial setup isn't overly complex."
- "Because I'm security focused, I prefer the security features such as Splunk Phantom and Splunk Enterprise Security."
- "Splunk can be an expensive solution. Technical support could be improved as well."
- "The technical support here in South Africa hasn't been great, but I understand why as we make up less than 3% of Splunk's total revenue in the world."
What is most valuable?
Because I'm security focused, I prefer the security features such as Splunk Phantom and Splunk Enterprise Security.
What needs improvement?
We need to get a Splunk Cloud instance inside South Africa's borders. At this stage, we are pushing Splunk Cloud, but it is not yet within South Africa's borders. So we've got data sovereignty issues, especially with government organizations.
Technical support could be improved as well.
Splunk can be an expensive solution. I think that they need to change their pricing model. At present, it is based on the number of gigabytes that you ingest into the Splunk system. Their competitors are now starting with a pricing model where you pay per device talking back. If Splunk could have a similar alternative, it would then allow people to choose the data model they want such as set data or a set number of devices.
For how long have I used the solution?
I have been using Splunk for three years.
How are customer service and technical support?
The technical support here in South Africa hasn't been great, but I understand why as we make up less than 3% of Splunk's total revenue in the world.
How was the initial setup?
The initial setup isn't overly complex, but it's not easy either.
What's my experience with pricing, setup cost, and licensing?
The pricing model is based on the number of gigabytes that you ingest into the Splunk system. So it can be an expensive solution.
What other advice do I have?
Plan your requirements properly from the beginning so that you can get the most value in a shorter space of time.
On a scale from one to ten, I would rate Splunk at six.
Disclosure: My company has a business relationship with this vendor other than being a customer. reseller
Buyer's Guide
Download our free Splunk Enterprise Security Report and get advice and tips from experienced pros
sharing their opinions.
Updated: May 2026
Product Categories
Security Information and Event Management (SIEM) Log Management IT Operations AnalyticsPopular Comparisons
CrowdStrike Falcon
IBM Security QRadar
Splunk AppDynamics
Microsoft Sentinel
Elastic Security
IBM Turbonomic
Palantir Foundry
WhatsUp Gold
Elastic Observability
LogRhythm SIEM
Buyer's Guide
Download our free Splunk Enterprise Security Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- Which would you recommend to your boss, IBM QRadar or Splunk?
- What are some of the best features and use-cases of Splunk?
- What SOC product do you recommend?
- Splunk as an Enterprise Class monitoring solution -- thoughts?
- What is the biggest difference between Dynatrace and Splunk?
- IBM QRadar is rated above competitors (McAfee, Splunk, LogRhythm) in Gartner's 2020 Magic Quandrant. Agree/Disagree?
- What are the advantages of ELK over Splunk?
- How does Splunk compare with Azure Monitor?
- New risk scoring framework in the Splunk App for Enterprise Security -- thoughts?
- Splunk vs. Elastic Stack














