We primarily use the solution for security and operations monitoring.
Managing Director at Hayyan Horizons
Low-maintenance and stable with very useful dashboards
Pros and Cons
- "The log aggregation is great."
- "Technical support needs to be more responsive."
What is our primary use case?
How has it helped my organization?
Gives full visibility on operational and security posture in our organization. Integrations is straightforward and effective.
What is most valuable?
The log aggregation is great.
The solution offers good data analytics.
The dashboards are very helpful.
The initial setup is simple and straightforward.
The solution is low-maintenance.
It's a stable product.
We have found that the solution scales well.
What needs improvement?
The TERM licensing model is still not very useful. It's not helping us. They used to have a perpetual licensing model. Now Splunk is offering annual term/subscription only. That's costly and it's more expensive and it's putting some burden on us.
Technical support needs to be more responsive.
We would like to see more AI. Through AI, artificial intelligence, not machine learning only. We want to see more AI-enabled kinds of functionalities just to reduce dependencies on manual interventions. We do that, however, automation and artificial intelligence-based kind of automation we would really like to see.
Buyer's Guide
Splunk Enterprise Security
September 2025

Learn what your peers think about Splunk Enterprise Security. Get advice and tips from experienced pros sharing their opinions. Updated: September 2025.
868,787 professionals have used our research since 2012.
For how long have I used the solution?
I've been using the solution for six years. I've used it for a while at this point.
What do I think about the stability of the solution?
It's not high maintenance. There are software or upgrade releases every now and then, however, in general, the product is very stable. There are no bugs or glitches. It doesn't crash or freeze.
What do I think about the scalability of the solution?
We have 17 people that are using the solution currently.
It's very easy to scale the product if you need to.
How are customer service and support?
We use technical support every now and then. The response times are not very good. This is the thing that I would need to see improvement on and probably in that area only. They are that good when they started handling cases, however, they take too much time to respond to customer requests.
Which solution did I use previously and why did I switch?
We did not use anything else on the production scale. Our first experience was with Splunk.
How was the initial setup?
The solution is straightforward and simple to set up. It's not complex at all.
What about the implementation team?
We handled the process internally. We did not need the assistance of any integrators or consultants.
What's my experience with pricing, setup cost, and licensing?
Filter the noise out.
Which other solutions did I evaluate?
Yes all the other competitors, Splunk by far is the best.
What other advice do I have?
We're a partner and a customer.
I'm using the latest version of the solution.
I would highly recommend the solution. It's the best product out there. It's definitely easy to set up. The use cases are multiple. It's not restrictive in terms of the efficiency of the platform. Just make sure that you have enough resources or good counsel from people who can help with the use cases. If you do the sky would be the limit. It is a good solution.
I'd rate the solution at a ten out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner

President at a non-profit with self employed
Expensive, but easy data gathering and reliable
Pros and Cons
- "The solution allows easy gathering and ingestion of the data."
- "The solution could improve by increasing the performance. We have run into problems when large amounts of data are processed."
What is our primary use case?
We use Splunk for analyzing data.
What is most valuable?
The solution allows easy gathering and ingestion of the data.
What needs improvement?
The solution could improve by increasing the performance. We have run into problems when large amounts of data are processed.
For how long have I used the solution?
I have been using Splunk within the past 12 months.
What do I think about the stability of the solution?
The solution has been stable.
What do I think about the scalability of the solution?
Our customers are mostly enterprise-sized companies using this solution.
How are customer service and technical support?
Splunk has many partners that provide customer support that can be used.
How was the initial setup?
The initial setup is not easy. Customers have to learn the Splunk language and it is hard to operate it by themselves. They will need Splunk engineers to assist in their projects.
What about the implementation team?
You will need a Splunk implementation specialist for the deployment.
What's my experience with pricing, setup cost, and licensing?
My customers have found the price of the solution to be high.
What other advice do I have?
I rate Splunk a five out of ten.
Disclosure: My company has a business relationship with this vendor other than being a customer.
Buyer's Guide
Splunk Enterprise Security
September 2025

Learn what your peers think about Splunk Enterprise Security. Get advice and tips from experienced pros sharing their opinions. Updated: September 2025.
868,787 professionals have used our research since 2012.
Senior Cyber Security Expert at a security firm with 11-50 employees
Great performance, easy to set up, and offers good speed
Pros and Cons
- "The level of robustness on offer is very good."
- "The complexity could be worked on so that it's even easier and faster."
What is our primary use case?
Typically, we use the solution for critical infrastructure companies.
What is most valuable?
The speed is a very valuable aspect of the solution.
The way Splunk handles low data and low-rate costs are great.
The level of robustness on offer is very good.
The initial setup is very straightforward.
We have found that the solution offers good integrations with other products.
Overall, the solution works very well.
What needs improvement?
The complexity could be worked on so that it's even easier and faster. However, I understand that, if some complexity was removed, there might be slightly more limitations.
Occasionally there are data sizing and data-related issues that need to be overcome.
For how long have I used the solution?
I've been using the solution for a couple of years.
What do I think about the stability of the solution?
The performance is very good. It's something that customers are always looking for. The product offers good stability. There are no bugs or glitches and it doesn't crash or freeze. It's reliable.
What do I think about the scalability of the solution?
We have about five to ten partners that use Splunk.
Which solution did I use previously and why did I switch?
I'm a fan of QRadar. I use them as well.
How was the initial setup?
The initial setup is very straightforward. It's not overly complex or difficult. A company shouldn't have any issues with the process. The deployment process doesn't take too long. You can manage it with fewer people and smaller teams. This is especially true if it isn't the critical infrastructure that you are working with.
For deployment and maintenance, you only need two to three people. That can include one manager and two professionals. Since Splunk is easier to handle, more people can join in on the client-side.
What's my experience with pricing, setup cost, and licensing?
We also use QRadar, and we make more money with QRadar than with Splunk as we can make bigger projects happen. However, we find that with Splunk, while we don't make as much money on each project, we can do more of them.
What other advice do I have?
I'd rate the solution at an eight out of ten.
Which deployment model are you using for this solution?
Public Cloud
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
Founder at a marketing services firm with 11-50 employees
Easy to deploy and relatively simple learning curve; could be more user friendly
Pros and Cons
- "Easy to deploy and simple to use."
- "Could be more user friendly."
What is our primary use case?
We're using the solution to try to build a virtual network and put Splunk inside it and do some kind of transcentralization with a log server. Our aim is to track connections, network traffic and some personal databases. I'm the founder of the company and we are customers of Splunk.
What is most valuable?
Splunk can quickly be deployed and it's not difficult to learn the solution.
What needs improvement?
The solution could be more user friendly and it's difficult to know at this stage whether our requirements will be met by the solution.
For how long have I used the solution?
I've been using this solution for a couple of months.
What do I think about the stability of the solution?
The solution is stable.
What do I think about the scalability of the solution?
Scalability is good with Splunk.
How was the initial setup?
The initial setup doesn't take much time especially if there's good bandwidth. In a small company deployment might take a month or two. If you have 100 devices then a technical team of three should be sufficient. They would need to be able to deal with log analysis, forensics and have general knowledge about admin systems. In time, we would expect to have thousands of users.
What's my experience with pricing, setup cost, and licensing?
I think Splunk is expensive compared to other tools at the purchase stage. It's possible that if we can keep control of the costs involved down the track, it won't be so bad.
Which other solutions did I evaluate?
We studied four or five tools including Logrhythm and Exabeam. We went with Splunk for now and will see how that goes.
What other advice do I have?
I think this is a good solution and rate it a seven out of 10.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Product Manager, FX Solutions at a tech services company with 10,001+ employees
Easy to use, informative documentation for data retrieval, and easy to install
Pros and Cons
- "The most valuable features of the solution are it is straightforward to use and the documentation is good for finding out how to get the data you are looking for."
- "The solution could improve by making it more business analysis oriented. The way it is now is designed more for developers."
What is our primary use case?
I use this solution for data visualization.
What is most valuable?
The most valuable features of the solution are it is straightforward to use and the documentation is good for finding out how to get the data you are looking for.
What needs improvement?
The solution could improve by making it more business analysis oriented. The way it is now is designed more for developers.
For how long have I used the solution?
I have been using Splunk for two weeks.
What do I think about the stability of the solution?
The solution is stable, I have not experienced any bugs or glitches.
What do I think about the scalability of the solution?
The solution is scalable and it is a requirement of my company to have scalable solutions.
Which solution did I use previously and why did I switch?
I have used previously Qlik Sense and Kibana.
How was the initial setup?
I did the training with Slunk and once I had the training the installation was easy.
Which other solutions did I evaluate?
I have evaluated Tableau.
What other advice do I have?
My advice to others is not to be intimidated by the solution and to give it a try. It will become easier over time.
I rate Splunk an eight out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Product Manager, CyberSecurity at a tech services company with 201-500 employees
Has good security features but needs a better pricing model
Pros and Cons
- "The initial setup isn't overly complex."
- "Splunk can be an expensive solution. Technical support could be improved as well."
What is most valuable?
Because I'm security focused, I prefer the security features such as Splunk Phantom and Splunk Enterprise Security.
What needs improvement?
We need to get a Splunk Cloud instance inside South Africa's borders. At this stage, we are pushing Splunk Cloud, but it is not yet within South Africa's borders. So we've got data sovereignty issues, especially with government organizations.
Technical support could be improved as well.
Splunk can be an expensive solution. I think that they need to change their pricing model. At present, it is based on the number of gigabytes that you ingest into the Splunk system. Their competitors are now starting with a pricing model where you pay per device talking back. If Splunk could have a similar alternative, it would then allow people to choose the data model they want such as set data or a set number of devices.
For how long have I used the solution?
I have been using Splunk for three years.
How are customer service and technical support?
The technical support here in South Africa hasn't been great, but I understand why as we make up less than 3% of Splunk's total revenue in the world.
How was the initial setup?
The initial setup isn't overly complex, but it's not easy either.
What's my experience with pricing, setup cost, and licensing?
The pricing model is based on the number of gigabytes that you ingest into the Splunk system. So it can be an expensive solution.
What other advice do I have?
Plan your requirements properly from the beginning so that you can get the most value in a shorter space of time.
On a scale from one to ten, I would rate Splunk at six.
Disclosure: My company has a business relationship with this vendor other than being a customer. reseller
Information Security Analyst at a tech services company with 1,001-5,000 employees
Good integration, easy UI, and very stable and scalable
Pros and Cons
- "Its integration is most valuable. Its UI is also pretty much easy."
- "Its setup is a little bit complex for a distributed environment. Their support can also be better. If we miss the response for more than a week, they usually close the case. Sometimes, it can take us more than a week to reply."
What is most valuable?
Its integration is most valuable. Its UI is also pretty much easy.
What needs improvement?
Its setup is a little bit complex for a distributed environment.
Their support can also be better. If we raise a case with Splunk support and by any chance we missed to respond for more than a week, they usually close the case. Sometimes, it can take us more than a week to reply. In that case What they can do is they can send a followup mail before closing.
For how long have I used the solution?
I have been using this solution for a year now.
What do I think about the stability of the solution?
It is very stable haven't encounter any glitches or bugs till now.
What do I think about the scalability of the solution?
It is very much scalable. I am acting as an admin, and we have more than a hundred users of this solution in our company. We use it on a regular basis. We currently don't have any plan to increase its usage.
How are customer service and technical support?
I would rate them an eight out of ten. Their response speed is okay, but if, by any chance, we miss the response for more than a week, they usually close the case. Sometimes, it can take us more than a week to reply.
Which solution did I use previously and why did I switch?
This is the only solution that we have been using.
How was the initial setup?
Its setup is pretty much easy for standalone, but for a distributed environment, it is a little bit complex.
What other advice do I have?
I would recommend this solution to others, but it should meet their needs and architecture.
I would rate Splunk a nine out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Solutions Consultant at a tech services company with 1,001-5,000 employees
Easy to use, provides a lot of analytics, and allows you to do pretty much whatever you want
Pros and Cons
- "It provides a lot of analytics with the underlying AI engine, and it is a lot easier than other solutions. There are some products that do automated AI-based detection and drawing up charts, but for network monitoring and all of the monitoring aspects, it is quite a nice tool. It is very convenient for business users because they get more or less a lot of data readily available. If you're familiar with the Splunk query language, you can pretty much do whatever you want."
- "If you have to do your own stuff, such as customized charts, it is a little bit more work, but once you're familiar with the Splunk query language, you can pretty much do whatever you want. In terms of features, it should probably have the features that other competitors provide."
What is most valuable?
It provides a lot of analytics with the underlying AI engine, and it is a lot easier than other solutions. There are some products that do automated AI-based detection and drawing up charts, but for network monitoring and all of the monitoring aspects, it is quite a nice tool.
It is very convenient for business users because they get more or less a lot of data readily available. If you're familiar with the Splunk query language, you can pretty much do whatever you want.
What needs improvement?
If you have to do your own stuff, such as customized charts, it is a little bit more work, but once you're familiar with the Splunk query language, you can pretty much do whatever you want. In terms of features, it should probably have the features that other competitors provide.
For how long have I used the solution?
I have been using this solution for about three to four months.
What do I think about the scalability of the solution?
I'm not sure. I do not really throw a lot of data in it, but it has been authenticated very nicely. It manages indexes and all of these things very nicely. I have not been privy to any production systems where you have millions of lines of log coming in every second. It works very well for the data that I have. It should be able to handle a lot of data. That's the whole purpose of it, and that's why Splunk has become so popular. It is an enterprise monitoring tool, and a lot of customers have Splunk in their ecosystem.
How are customer service and technical support?
They have pretty much good documentation and good training. Their documentation is a lot better than Qlik Sense.
Which solution did I use previously and why did I switch?
Splunk is an enterprise monitoring tool. Qlik Sense can do a little bit of log monitoring, but it is mostly used for dashboard reporting, whereas Splunk is more around monitoring and figuring out threats and all such things. They are different, but both deal with the data and allow you to create operation reports.
Power BI is another tool that a lot of our customers use, but Splunk is quite often requested. It is also a lot more popular than Qlik Sense. We have a fair number of Qlik Sense customers.
We usually sell Blue Prism to business users who are more concerned with the reporting aspect, which is why they would like to have easy tools like Qlik Sense in their ecosystem, but on the infrastructure side, it would be Splunk for enterprise monitoring.
How was the initial setup?
Simple environments are easier to install. Because there is a lot of data log monitoring, once you have a production system, there is some amount of work in setting it up, especially making it SSL Secure and exposing it on the internet. There are multiple components behind it, so you need to ensure that all these things are set up correctly. These kinds of things are not required on a cloud platform because you are just uploading data. You really don't have much access to the backend.
Splunk also has a cloud version, which I haven't looked at, but I have used Qlik Sense's cloud platforms. With on-premises, you are in control of pretty much how you set up all the data that you are sending out. A lot of our customers have the issue that if it is a cloud platform, they cannot really send out the data to any of these cloud platforms. So, there are data residence and other issues.
What's my experience with pricing, setup cost, and licensing?
It is economical than other solutions.
What other advice do I have?
I would definitely recommend Splunk. It is quite a decent tool, and it is there in a lot of enterprises.
I would rate Splunk an eight out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer. partner

Buyer's Guide
Download our free Splunk Enterprise Security Report and get advice and tips from experienced pros
sharing their opinions.
Updated: September 2025
Product Categories
Security Information and Event Management (SIEM) Log Management IT Operations AnalyticsPopular Comparisons
CrowdStrike Falcon
Microsoft Sentinel
IBM Security QRadar
Elastic Security
Grafana Loki
Splunk AppDynamics
Elastic Observability
Graylog Enterprise
Security Onion
Cortex XSIAM
Palantir Foundry
Buyer's Guide
Download our free Splunk Enterprise Security Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- Which would you recommend to your boss, IBM QRadar or Splunk?
- What are some of the best features and use-cases of Splunk?
- What SOC product do you recommend?
- Splunk as an Enterprise Class monitoring solution -- thoughts?
- What is the biggest difference between Dynatrace and Splunk?
- IBM QRadar is rated above competitors (McAfee, Splunk, LogRhythm) in Gartner's 2020 Magic Quandrant. Agree/Disagree?
- What are the advantages of ELK over Splunk?
- How does Splunk compare with Azure Monitor?
- New risk scoring framework in the Splunk App for Enterprise Security -- thoughts?
- Splunk vs. Elastic Stack