Although my company uses Splunk extensively, my use case is primarily the Enterprise Security add-on.
Senior Network Security Engineer at Starz Entertainment
In the event of an incident, it has a rapid response search environment
Pros and Cons
- "It has a rapid response search environment in the event of an incident."
- "The correlation searches (properly configured) populate the Incident Management dashboard and provide me a quick birds-eye view of my most important concerns."
- "The use cases provided by Splunk are a good starting point, but could cover many additional topics to ensure that a smaller or less experienced shop might maximize the value of an ES deployment."
What is our primary use case?
How has it helped my organization?
Splunk has enabled us to utilize many different data sources and is easy-to-use. It has a rapid response search environment in the event of an incident.
What is most valuable?
The correlation searches (properly configured) populate the Incident Management dashboard and provide me a quick birds-eye view of my most important concerns.
What needs improvement?
ES is very powerful, but it requires a mature security posture at the company to take advantage of it currently. The use cases provided by Splunk are a good starting point, but could cover many additional topics to ensure that a smaller or less experienced shop might maximize the value of an ES deployment.
Buyer's Guide
Splunk Enterprise Security
April 2025

Learn what your peers think about Splunk Enterprise Security. Get advice and tips from experienced pros sharing their opinions. Updated: April 2025.
851,823 professionals have used our research since 2012.
For how long have I used the solution?
Less than one year.
Which solution did I use previously and why did I switch?
We were using a different SIEM, which was old-fashioned and very structured.
Disclosure: I am a real user, and this review is based on my own experience and opinions.

CISO at a financial services firm with 501-1,000 employees
Cloud-ready, with forums and README tutorials that cover everything you need to know
Pros and Cons
- "Splunk would be my choice for the presentation layer because it comes with inbuilt reports and a dashboard that you can customize."
- "I haven't found a way for me to create my own plugins and integrate them into Splunk, but this isn't necessarily a limitation; it could simply be a lack of knowledge on my part."
What is our primary use case?
Splunk just acts as an extra presentation layer, and we tried it because of the plugins they have to try and get more logs into the environment.
What is most valuable?
Splunk would be my choice for the presentation layer because it comes with inbuilt reports and a dashboard that you can customize.
What needs improvement?
Aside from the 5GB limit on the community version, I believe it is the same as ELK. It's a useful tool, and nothing comes to mind right now.
I haven't found a way for me to create my own plugins and integrate them into Splunk, but this isn't necessarily a limitation; it could simply be a lack of knowledge on my part.
What do I think about the stability of the solution?
Splunk is a stable solution. I am very happy with the stability of Splunk.
What do I think about the scalability of the solution?
Splunk can be scaled to any environment. The way it's designed, it's cloud-ready, and it has a lot of performance, in-built indexing, and performance tuning options. Splunk is easily scalable.
How are customer service and support?
I am happy to report that I've never needed to contact technical support. The README tutorials and the existing forums provide me with practically everything I need. So far, I haven't had to do so. This should be a testament to the solution.
Which solution did I use previously and why did I switch?
We broaden the scope of IT governance and IT security.
We look at everything from SIEM to network management to endpoint protection, server protection, database protection, and anything else that can aid in visibility, policy enforcement, and monitoring.
Our organization is using a combination of Splunk and Elasticsearch. We get most of what we need from the ELK suite. ELK Stack is usually the primary focus.
ELK has the same inbuilt reports and dashboards that you can customize, but ELK is better for central logging and log aggregation. Once they've all been aggregated, you'll be able to run any kind of queries and APIs to query the logs on ELK and then use Splunk as a presentation layer for the consumers to use.
Security tools, in my opinion, are business tools and should be used by businesses rather than security engineers. I'm experimenting with a hybrid of the two, in which ELK serves as the engine for central logging and Splunk handles the presentation layer and aggregation of additional third-party logs from tools that might be difficult to integrate into ELK.
I would rate Elasticsearch a ten out of ten.
How was the initial setup?
It's a cloud-ready package. It has the same characteristics as ELK. From a deployment standpoint, I don't have any issues with it. The material is freely accessible to anyone who wishes to use it. There is a virtual machine option. You can get a virtual machine by downloading it. The deployment options are simply numerous, and it is up to the implementer.
It wasn't that difficult for me. There are no complaints from me. The material is present, and there are numerous options for deployment. It's relatively simple to go from zero to viewing data with Splunk. ELK is the same way. It is now up to the implementers and their environment to provide you with more data about it.
What's my experience with pricing, setup cost, and licensing?
They could improve their discounts. I think it's a good solution, and it's gaining a lot of traction, maybe they are recouping their R&D costs, Further reductions would be fantastic, and I believe that more and more people would flock to it.
Which other solutions did I evaluate?
We provide IT consulting services. Our customers occasionally ask us to assist them in locating specific solutions.
What other advice do I have?
I would recommend this solution to others who are interested in using this solution.
I would say the forums and READMEs provide more than enough information about Splunk. Most people struggle because they move too quickly through the implementation process. As long as you follow the guidelines, particularly the specifications for environment requirements and implementation methodology, these solutions should work out of the box.
Splunk is a very good solution, I would rate it a ten out of ten.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Buyer's Guide
Splunk Enterprise Security
April 2025

Learn what your peers think about Splunk Enterprise Security. Get advice and tips from experienced pros sharing their opinions. Updated: April 2025.
851,823 professionals have used our research since 2012.
Senior Network Engineer at a tech services company with 51-200 employees
Useful search function, beneficial session reports, but performance could improve
Pros and Cons
- "The most valuable features in Splunk are the search function and the ability to run selected session reports. The session reports are important because I can use them to see what is going on in our environment weekly. Additionally, we can use the graph to see how often that particular event is happening."
- "Over time I will have more requirements and I can foresee the solution could improve the search algorithm to run and output the data faster."
What is our primary use case?
We typically use Splunk to collect and check all the logs and events around the diverse network environment which includes, firewall, switches, and routers. For example, we have traffic that needs to go from one part of the network to another and if we think there is a firewall blocking it along the path, rather than log in to all the firewalls to see what is happening, we simply go into Splunk and the check traffic going across the parts of the network to see where it is being dropped and what is the likely reason it has been dropped.
How has it helped my organization?
Splunk has saved our organization time by resolving problems in a quicker timeframe. Before if we had networking issues we would have to log into every single device, check the firewall to see why the traffic is not going across to solve the problem. With Splunk, you only have a single pane of glass to check what is likely happening. This has enabled us to easily go to the right environment and write the necessary security policy to permit such traffic. It brings about faster resolution of problems reduced with visibility.
What is most valuable?
The most valuable features in Splunk are the search function and the ability to run selected session reports. The session reports are important because I can use them to see what is going on in our environment weekly. Additionally, we can use the graph to see how often that particular event is happening.
What needs improvement?
Over time I will have more requirements and I can foresee the solution could improve the search algorithm to run and output the data faster.
For how long have I used the solution?
I have been using Splunk for approximately six months.
What do I think about the stability of the solution?
We have been satisfied with the stability of the solution.
What do I think about the scalability of the solution?
Slunk scale very well.
We have approximately 50 people in our infrastructure and applications teams using this solution in my organization.
We plan to increase usage in the future.
How are customer service and technical support?
I have not needed to open a ticket up with technical support.
Which solution did I use previously and why did I switch?
Previously to using Splunk we only had some Syslog servers that we sent logs to. However, Syslog servers, do not analyze your logs, they only capturing them. Whereas, in Splunk, you can assess the logs and you can do other things with the log.
How was the initial setup?
I do not think the implementation is difficult.
What about the implementation team?
We have an internal team that does the maintenance of the solution.
Which other solutions did I evaluate?
I have evaluated DataDog.
What other advice do I have?
Splunk is easy to use and not having the need to log into every single network device for management is helpful.
I rate Splunk a seven out of ten.
Which deployment model are you using for this solution?
Public Cloud
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Solutions Consultant at a tech services company with 1,001-5,000 employees
Easy to use, provides a lot of analytics, and allows you to do pretty much whatever you want
Pros and Cons
- "It provides a lot of analytics with the underlying AI engine, and it is a lot easier than other solutions. There are some products that do automated AI-based detection and drawing up charts, but for network monitoring and all of the monitoring aspects, it is quite a nice tool. It is very convenient for business users because they get more or less a lot of data readily available. If you're familiar with the Splunk query language, you can pretty much do whatever you want."
- "If you have to do your own stuff, such as customized charts, it is a little bit more work, but once you're familiar with the Splunk query language, you can pretty much do whatever you want. In terms of features, it should probably have the features that other competitors provide."
What is most valuable?
It provides a lot of analytics with the underlying AI engine, and it is a lot easier than other solutions. There are some products that do automated AI-based detection and drawing up charts, but for network monitoring and all of the monitoring aspects, it is quite a nice tool.
It is very convenient for business users because they get more or less a lot of data readily available. If you're familiar with the Splunk query language, you can pretty much do whatever you want.
What needs improvement?
If you have to do your own stuff, such as customized charts, it is a little bit more work, but once you're familiar with the Splunk query language, you can pretty much do whatever you want. In terms of features, it should probably have the features that other competitors provide.
For how long have I used the solution?
I have been using this solution for about three to four months.
What do I think about the scalability of the solution?
I'm not sure. I do not really throw a lot of data in it, but it has been authenticated very nicely. It manages indexes and all of these things very nicely. I have not been privy to any production systems where you have millions of lines of log coming in every second. It works very well for the data that I have. It should be able to handle a lot of data. That's the whole purpose of it, and that's why Splunk has become so popular. It is an enterprise monitoring tool, and a lot of customers have Splunk in their ecosystem.
How are customer service and technical support?
They have pretty much good documentation and good training. Their documentation is a lot better than Qlik Sense.
Which solution did I use previously and why did I switch?
Splunk is an enterprise monitoring tool. Qlik Sense can do a little bit of log monitoring, but it is mostly used for dashboard reporting, whereas Splunk is more around monitoring and figuring out threats and all such things. They are different, but both deal with the data and allow you to create operation reports.
Power BI is another tool that a lot of our customers use, but Splunk is quite often requested. It is also a lot more popular than Qlik Sense. We have a fair number of Qlik Sense customers.
We usually sell Blue Prism to business users who are more concerned with the reporting aspect, which is why they would like to have easy tools like Qlik Sense in their ecosystem, but on the infrastructure side, it would be Splunk for enterprise monitoring.
How was the initial setup?
Simple environments are easier to install. Because there is a lot of data log monitoring, once you have a production system, there is some amount of work in setting it up, especially making it SSL Secure and exposing it on the internet. There are multiple components behind it, so you need to ensure that all these things are set up correctly. These kinds of things are not required on a cloud platform because you are just uploading data. You really don't have much access to the backend.
Splunk also has a cloud version, which I haven't looked at, but I have used Qlik Sense's cloud platforms. With on-premises, you are in control of pretty much how you set up all the data that you are sending out. A lot of our customers have the issue that if it is a cloud platform, they cannot really send out the data to any of these cloud platforms. So, there are data residence and other issues.
What's my experience with pricing, setup cost, and licensing?
It is economical than other solutions.
What other advice do I have?
I would definitely recommend Splunk. It is quite a decent tool, and it is there in a lot of enterprises.
I would rate Splunk an eight out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer: partner
Business Intelligence Engineer at SONIFI Solutions, Inc.
Allows us to dig into raw events
Pros and Cons
- "Splunk allows us to find insights that we were not able to with traditional BI tools using ETL. It allows us to dig into raw events."
- "Splunk is extremely flexible, which allows us to create custom visualizations along with other customizations."
- "The product was designed for security and IT with business intelligence needs, such as PDF exporting, but this has not been the highest priority. While the functionality is there, it could be developed more."
What is our primary use case?
Primary use is business intelligence.
How has it helped my organization?
Splunk allows us to find insights that we were not able to with traditional BI tools using ETL. It allows us to dig into raw events.
What is most valuable?
Splunk is extremely flexible, which allows us to create custom visualizations along with other customizations. The flexibility of Splunk as well as the resources available for learning and support are the best in the business.
What needs improvement?
The product was designed for security and IT with business intelligence needs, such as PDF exporting, but this has not been the highest priority. While the functionality is there, it could be developed more.
For how long have I used the solution?
More than five years.
What do I think about the scalability of the solution?
We ingest roughly 30GB/day. We have a small environment, but it provides big insights.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Systems Administrator at a energy/utilities company with 10,001+ employees
Splunk vs LogLogic: Splunk stands out for its ability to consume almost any log type and it's ease of searching
Valuable Features:
Splunk – ease of searching large amounts of data.
Improvements to My Organization:
Splunk – real time alerts on critical indicators, compliance reports, troubleshooting and predictive abilities using trends.
Use of Solution:
Splunk – 3 years
Deployment Issues:
Splunk – Had one issue requiring a support call regarding the configuration of the automated configuration deployment package. Quickly resolved.
Stability Issues:
Splunk – None.
Scalability Issues:
Splunk – Not needed yet.
Customer Service:
Splunk – Splunk has a very knowledgeable support staff and the Splunk support website is outstanding. The message boards are very active and often using them will often prevent having to call support.
Initial Setup:
Splunk – Easy, but can get very complex depending on the type of logs to ingest. While Splunk, out of the box, handles most common types. The extraction of data from custom logs can be problematic. Although Splunk does provide tools for accomplishing this.
Other Advice:
Both Splunk and LogLogic excel at their intended purpose. If you are looking for an appliance that you can stick in the rack, minimally configure and then forget about, you will like the LogLogic solution. If you need to regularly search different logs for different data you will like Splunk better.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
IT & Cloud Architect at AiM Services SA
We use it for reporting and monitoring of all solutions in the company
Pros and Cons
- "We can present to our management in real time the security of the batch management for the PCs, security regarding the network equipment. We're currently working in the Azure Cloud project, so we can send any logs from the cloud to Splunk. We can monitor them and we can present to the managers and customers. It's a very good solution for reporting. We use Splunk for reporting and monitoring of any solution in the company."
- "The security can be improved."
What is our primary use case?
Our primary use case is reporting from the Windows administration. We have SCCM that configures the manager to update every PC workstation and server in the company. We have a lot of PCs and servers in our environment and we use Splunk for the gathering of the PCs and Windows service. We also use it to collect information from the security tools, for example, to provide the management information about how the everyday connection is.
How has it helped my organization?
We can present to our management in real time the security of the batch management for the PCs, security regarding the network equipment. We're currently working in the Azure Cloud project, so we can send any logs from the cloud to Splunk. We can monitor them and we can present to the managers and customers. It's a very good solution for reporting. We use Splunk for reporting and monitoring of any solution in the company.
What needs improvement?
The security can be improved.
What do I think about the scalability of the solution?
It is scalable. We have five admins so far that we have in the solution. We have two as techs to develop the design on the world map of the solution, and we have the end users, so 80,000 users altogether.
How was the initial setup?
The initial setup was complex. We have two data centers in France, two in Germany, and we have 18 countries in the world. It's a big company and we have a lot of services, servers, etc. So the setup is more complex.
What other advice do I have?
I would rate this solution a perfect ten out of ten.
Disclosure: My company has a business relationship with this vendor other than being a customer: Reseller.
QA Lead at a financial services firm with 501-1,000 employees
It has helped with troubleshooting, making it easier
Pros and Cons
- "It provides logs in one place, so they are easy to find. It collects the logs from multiple places, then you have just one place where you see the whole flow from the front-end to the back-end."
- "The search could be improved. Now, it is a bit difficult to write search queries because they become quite long, then maintaining those long search queries is a quite challenging."
What is our primary use case?
We use it mostly for log monitoring, and also for trying to raise alarms.
How has it helped my organization?
It has helped with troubleshooting, making it easier. Now, we have one place where we can find logs and errors. There is no need to go to the actual server to search for the log file.
What is most valuable?
It provides logs in one place, so they are easy to find. It collects the logs from multiple places, then you have just one place where you see the whole flow from the front-end to the back-end. This is the best thing.
What needs improvement?
The search could be improved. Now, it is a bit difficult to write search queries because they become quite long, then maintaining those long search queries is a quite challenging.
For how long have I used the solution?
Three to five years.
What do I think about the stability of the solution?
I have not had any issues with it, and we have the whole banking infrastructure running on it.
What do I think about the scalability of the solution?
The scalability is okay as far as I have seen and used it. We have dozens of different environment environments using the same Splunk instruments, and it has been able to scale.
How is customer service and technical support?
I have not used technical support.
What other advice do I have?
Splunk's website is quite useful. You can find a lot of information on it. I would recommend to use it and try to figure out the product's features and what you can actually do with Splunk. You can do a lot of things with Splunk, but you need to know what to do first.
I have used both the AWS and on-premise versions, but in two different environment, so I am unable to compare the versions.
Disclosure: I am a real user, and this review is based on my own experience and opinions.

Buyer's Guide
Download our free Splunk Enterprise Security Report and get advice and tips from experienced pros
sharing their opinions.
Updated: April 2025
Product Categories
Security Information and Event Management (SIEM) Log Management IT Operations AnalyticsPopular Comparisons
CrowdStrike Falcon
Microsoft Sentinel
IBM Security QRadar
Elastic Security
Splunk AppDynamics
Elastic Observability
Grafana Loki
Security Onion
Palantir Foundry
LogRhythm SIEM
Buyer's Guide
Download our free Splunk Enterprise Security Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- Which would you recommend to your boss, IBM QRadar or Splunk?
- What are some of the best features and use-cases of Splunk?
- What SOC product do you recommend?
- Splunk as an Enterprise Class monitoring solution -- thoughts?
- What is the biggest difference between Dynatrace and Splunk?
- IBM QRadar is rated above competitors (McAfee, Splunk, LogRhythm) in Gartner's 2020 Magic Quandrant. Agree/Disagree?
- What are the advantages of ELK over Splunk?
- How does Splunk compare with Azure Monitor?
- New risk scoring framework in the Splunk App for Enterprise Security -- thoughts?
- Splunk vs. Elastic Stack