We use the solution for monitoring systems. We also use it with servers and CG routers from the data center, as well as for collecting the ADL from all networks which are located in our regions of the country.
Network Operations Center Engineer at a tech company with 51-200 employees
A stable and scalable solution which is easy to install and use and has good tech support
Pros and Cons
- "I am satisfied with the support."
- "The price of the solution could be cheaper."
What is our primary use case?
What is most valuable?
I like that the solution is easy to use and stable.
What needs improvement?
The price of the solution could be cheaper.
For how long have I used the solution?
I am currently working with Splunk and have a year's experience doing so.
Buyer's Guide
Splunk Enterprise Security
February 2026
Learn what your peers think about Splunk Enterprise Security. Get advice and tips from experienced pros sharing their opinions. Updated: February 2026.
884,933 professionals have used our research since 2012.
What do I think about the stability of the solution?
The solution is stable.
What do I think about the scalability of the solution?
The solution is scalable.
How are customer service and support?
Support is at a level one department and I am responsible for managing both IT support and node engineers.
I am satisfied with the support.
How was the initial setup?
The solution is easy to install.
It took half a day.
What about the implementation team?
We were able to handle the installation on our own.
There are 40 people responsible for the deployment and maintenance of the solution, four of whom are engineers. There is a computer DE who is responsible for the engineering and a candidate for graduation in 2022.
What's my experience with pricing, setup cost, and licensing?
The solution could be more cost-effective, as we charge our customers the cheapest price.
The subscription is monthly.
What other advice do I have?
The solution is cloud-based.
There are more than a thousand users making use of the solution in our organization, who are connected with us in over 530 different areas.
I recommend the solution and plan to continue using it.
I rate Splunk as a seven out of ten.
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
Senior Technical Lead at a financial services firm with 10,001+ employees
Priced reasonably, effective log analysis, but artificial intelligence features need improvement
Pros and Cons
- "We have found all the features useful. However, the dashboarding and logging have been very helpful. Additionally, the log analysis does a great job."
- "The solution could improve by giving more email details."
What is most valuable?
We have found all the features useful. However, the dashboarding and logging have been very helpful. Additionally, the log analysis does a great job.
What needs improvement?
The solution could improve by giving more email details.
In a future release, the solution could improve on the artificial intelligence features, such as if an alert comes, it could automatically do logging from the system, get the KV knowledge base, and perform other functions. This would be a benefit.
For how long have I used the solution?
I have used Splunk for approximately five years.
How are customer service and support?
The technical support is good.
How was the initial setup?
The initial setup is complex.
What's my experience with pricing, setup cost, and licensing?
The price of Splunk is reasonable.
Which other solutions did I evaluate?
We have evaluated SoapUI and Postman, and we are still evaluating others.
What other advice do I have?
I rate Splunk a seven out of ten.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Buyer's Guide
Splunk Enterprise Security
February 2026
Learn what your peers think about Splunk Enterprise Security. Get advice and tips from experienced pros sharing their opinions. Updated: February 2026.
884,933 professionals have used our research since 2012.
Telecom Tech at a university with 501-1,000 employees
Easy to configure with user-friendly alerts and good search functionality
Pros and Cons
- "We can easily configure things as required in relation to our use cases."
- "From the commercial point of view, they have to bring down their costs."
What is most valuable?
We enjoy the whole solution. It is meeting our requirements, especially the SIM solution.
The alerts are very user-friendly.
We can easily configure things as required in relation to our use cases.
The search functionality is good. It works like Google.
Onboarding is quite easy.
The scalability is good.
Product-wise, the performance is good.
What needs improvement?
From the commercial point of view, they have to bring down their costs. It's a bit pricey right now. The license is quite expensive.
Much like the SOAR platform, which has security, orchestration, and automation response, all of that should be part of the SIM solution itself. Currently, it is actually separated. We understand that we have to integrate a SIM with a SOAR platform, however, if they could combine these two products together, that would be ideal. It would make things easy to implement and make more automation possible to avoid false-positive alerts.
For how long have I used the solution?
We've been using the solution for the last four years. It's been a while.
What do I think about the stability of the solution?
The performance is good. It's stable. There are no bugs or glitches. It doesn't crash or freeze.
What do I think about the scalability of the solution?
The scalability of the solution is very good. If a company needs to expand, it can do so. It's easy.
What's my experience with pricing, setup cost, and licensing?
The solution can be expensive. It's not cheap.
What other advice do I have?
We are customers and end-users.
I'd rate the solution at a nine out of ten.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Managing Director at Hayyan Horizons
Low-maintenance and stable with very useful dashboards
Pros and Cons
- "The log aggregation is great."
- "Technical support needs to be more responsive."
What is our primary use case?
We primarily use the solution for security and operations monitoring.
How has it helped my organization?
Gives full visibility on operational and security posture in our organization. Integrations is straightforward and effective.
What is most valuable?
The log aggregation is great.
The solution offers good data analytics.
The dashboards are very helpful.
The initial setup is simple and straightforward.
The solution is low-maintenance.
It's a stable product.
We have found that the solution scales well.
What needs improvement?
The TERM licensing model is still not very useful. It's not helping us. They used to have a perpetual licensing model. Now Splunk is offering annual term/subscription only. That's costly and it's more expensive and it's putting some burden on us.
Technical support needs to be more responsive.
We would like to see more AI. Through AI, artificial intelligence, not machine learning only. We want to see more AI-enabled kinds of functionalities just to reduce dependencies on manual interventions. We do that, however, automation and artificial intelligence-based kind of automation we would really like to see.
For how long have I used the solution?
I've been using the solution for six years. I've used it for a while at this point.
What do I think about the stability of the solution?
It's not high maintenance. There are software or upgrade releases every now and then, however, in general, the product is very stable. There are no bugs or glitches. It doesn't crash or freeze.
What do I think about the scalability of the solution?
We have 17 people that are using the solution currently.
It's very easy to scale the product if you need to.
How are customer service and technical support?
We use technical support every now and then. The response times are not very good. This is the thing that I would need to see improvement on and probably in that area only. They are that good when they started handling cases, however, they take too much time to respond to customer requests.
Which solution did I use previously and why did I switch?
We did not use anything else on the production scale. Our first experience was with Splunk.
How was the initial setup?
The solution is straightforward and simple to set up. It's not complex at all.
What about the implementation team?
We handled the process internally. We did not need the assistance of any integrators or consultants.
What's my experience with pricing, setup cost, and licensing?
Filter the noise out.
Which other solutions did I evaluate?
Yes all the other competitors, Splunk by far is the best.
What other advice do I have?
We're a partner and a customer.
I'm using the latest version of the solution.
I would highly recommend the solution. It's the best product out there. It's definitely easy to set up. The use cases are multiple. It's not restrictive in terms of the efficiency of the platform. Just make sure that you have enough resources or good counsel from people who can help with the use cases. If you do the sky would be the limit. It is a good solution.
I'd rate the solution at a ten out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
Senior Network Engineer at a tech services company with 51-200 employees
Useful search function, beneficial session reports, but performance could improve
Pros and Cons
- "The most valuable features in Splunk are the search function and the ability to run selected session reports. The session reports are important because I can use them to see what is going on in our environment weekly. Additionally, we can use the graph to see how often that particular event is happening."
- "Over time I will have more requirements and I can foresee the solution could improve the search algorithm to run and output the data faster."
What is our primary use case?
We typically use Splunk to collect and check all the logs and events around the diverse network environment which includes, firewall, switches, and routers. For example, we have traffic that needs to go from one part of the network to another and if we think there is a firewall blocking it along the path, rather than log in to all the firewalls to see what is happening, we simply go into Splunk and the check traffic going across the parts of the network to see where it is being dropped and what is the likely reason it has been dropped.
How has it helped my organization?
Splunk has saved our organization time by resolving problems in a quicker timeframe. Before if we had networking issues we would have to log into every single device, check the firewall to see why the traffic is not going across to solve the problem. With Splunk, you only have a single pane of glass to check what is likely happening. This has enabled us to easily go to the right environment and write the necessary security policy to permit such traffic. It brings about faster resolution of problems reduced with visibility.
What is most valuable?
The most valuable features in Splunk are the search function and the ability to run selected session reports. The session reports are important because I can use them to see what is going on in our environment weekly. Additionally, we can use the graph to see how often that particular event is happening.
What needs improvement?
Over time I will have more requirements and I can foresee the solution could improve the search algorithm to run and output the data faster.
For how long have I used the solution?
I have been using Splunk for approximately six months.
What do I think about the stability of the solution?
We have been satisfied with the stability of the solution.
What do I think about the scalability of the solution?
Slunk scale very well.
We have approximately 50 people in our infrastructure and applications teams using this solution in my organization.
We plan to increase usage in the future.
How are customer service and technical support?
I have not needed to open a ticket up with technical support.
Which solution did I use previously and why did I switch?
Previously to using Splunk we only had some Syslog servers that we sent logs to. However, Syslog servers, do not analyze your logs, they only capturing them. Whereas, in Splunk, you can assess the logs and you can do other things with the log.
How was the initial setup?
I do not think the implementation is difficult.
What about the implementation team?
We have an internal team that does the maintenance of the solution.
Which other solutions did I evaluate?
I have evaluated DataDog.
What other advice do I have?
Splunk is easy to use and not having the need to log into every single network device for management is helpful.
I rate Splunk a seven out of ten.
Which deployment model are you using for this solution?
Public Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
President at a non-profit with self employed
Expensive, but easy data gathering and reliable
Pros and Cons
- "The solution allows easy gathering and ingestion of the data."
- "The solution could improve by increasing the performance. We have run into problems when large amounts of data are processed."
What is our primary use case?
We use Splunk for analyzing data.
What is most valuable?
The solution allows easy gathering and ingestion of the data.
What needs improvement?
The solution could improve by increasing the performance. We have run into problems when large amounts of data are processed.
For how long have I used the solution?
I have been using Splunk within the past 12 months.
What do I think about the stability of the solution?
The solution has been stable.
What do I think about the scalability of the solution?
Our customers are mostly enterprise-sized companies using this solution.
How are customer service and technical support?
Splunk has many partners that provide customer support that can be used.
How was the initial setup?
The initial setup is not easy. Customers have to learn the Splunk language and it is hard to operate it by themselves. They will need Splunk engineers to assist in their projects.
What about the implementation team?
You will need a Splunk implementation specialist for the deployment.
What's my experience with pricing, setup cost, and licensing?
My customers have found the price of the solution to be high.
What other advice do I have?
I rate Splunk a five out of ten.
Disclosure: My company has a business relationship with this vendor other than being a customer.
Senior Cyber Security Expert at a security firm with 11-50 employees
Great performance, easy to set up, and offers good speed
Pros and Cons
- "The level of robustness on offer is very good."
- "The complexity could be worked on so that it's even easier and faster."
What is our primary use case?
Typically, we use the solution for critical infrastructure companies.
What is most valuable?
The speed is a very valuable aspect of the solution.
The way Splunk handles low data and low-rate costs are great.
The level of robustness on offer is very good.
The initial setup is very straightforward.
We have found that the solution offers good integrations with other products.
Overall, the solution works very well.
What needs improvement?
The complexity could be worked on so that it's even easier and faster. However, I understand that, if some complexity was removed, there might be slightly more limitations.
Occasionally there are data sizing and data-related issues that need to be overcome.
For how long have I used the solution?
I've been using the solution for a couple of years.
What do I think about the stability of the solution?
The performance is very good. It's something that customers are always looking for. The product offers good stability. There are no bugs or glitches and it doesn't crash or freeze. It's reliable.
What do I think about the scalability of the solution?
We have about five to ten partners that use Splunk.
Which solution did I use previously and why did I switch?
I'm a fan of QRadar. I use them as well.
How was the initial setup?
The initial setup is very straightforward. It's not overly complex or difficult. A company shouldn't have any issues with the process. The deployment process doesn't take too long. You can manage it with fewer people and smaller teams. This is especially true if it isn't the critical infrastructure that you are working with.
For deployment and maintenance, you only need two to three people. That can include one manager and two professionals. Since Splunk is easier to handle, more people can join in on the client-side.
What's my experience with pricing, setup cost, and licensing?
We also use QRadar, and we make more money with QRadar than with Splunk as we can make bigger projects happen. However, we find that with Splunk, while we don't make as much money on each project, we can do more of them.
What other advice do I have?
I'd rate the solution at an eight out of ten.
Which deployment model are you using for this solution?
Public Cloud
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
Founder at a marketing services firm with 11-50 employees
Easy to deploy and relatively simple learning curve; could be more user friendly
Pros and Cons
- "Easy to deploy and simple to use."
- "Could be more user friendly."
What is our primary use case?
We're using the solution to try to build a virtual network and put Splunk inside it and do some kind of transcentralization with a log server. Our aim is to track connections, network traffic and some personal databases. I'm the founder of the company and we are customers of Splunk.
What is most valuable?
Splunk can quickly be deployed and it's not difficult to learn the solution.
What needs improvement?
The solution could be more user friendly and it's difficult to know at this stage whether our requirements will be met by the solution.
For how long have I used the solution?
I've been using this solution for a couple of months.
What do I think about the stability of the solution?
The solution is stable.
What do I think about the scalability of the solution?
Scalability is good with Splunk.
How was the initial setup?
The initial setup doesn't take much time especially if there's good bandwidth. In a small company deployment might take a month or two. If you have 100 devices then a technical team of three should be sufficient. They would need to be able to deal with log analysis, forensics and have general knowledge about admin systems. In time, we would expect to have thousands of users.
What's my experience with pricing, setup cost, and licensing?
I think Splunk is expensive compared to other tools at the purchase stage. It's possible that if we can keep control of the costs involved down the track, it won't be so bad.
Which other solutions did I evaluate?
We studied four or five tools including Logrhythm and Exabeam. We went with Splunk for now and will see how that goes.
What other advice do I have?
I think this is a good solution and rate it a seven out of 10.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Buyer's Guide
Download our free Splunk Enterprise Security Report and get advice and tips from experienced pros
sharing their opinions.
Updated: February 2026
Product Categories
Security Information and Event Management (SIEM) Log Management IT Operations AnalyticsPopular Comparisons
CrowdStrike Falcon
Microsoft Sentinel
IBM Security QRadar
Splunk AppDynamics
Elastic Security
Grafana Loki
Elastic Observability
Palantir Foundry
Graylog Enterprise
Security Onion
Buyer's Guide
Download our free Splunk Enterprise Security Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- Which would you recommend to your boss, IBM QRadar or Splunk?
- What are some of the best features and use-cases of Splunk?
- What SOC product do you recommend?
- Splunk as an Enterprise Class monitoring solution -- thoughts?
- What is the biggest difference between Dynatrace and Splunk?
- IBM QRadar is rated above competitors (McAfee, Splunk, LogRhythm) in Gartner's 2020 Magic Quandrant. Agree/Disagree?
- What are the advantages of ELK over Splunk?
- How does Splunk compare with Azure Monitor?
- New risk scoring framework in the Splunk App for Enterprise Security -- thoughts?
- Splunk vs. Elastic Stack















