Its integration is most valuable. Its UI is also pretty much easy.
Information Security Analyst at a tech services company with 1,001-5,000 employees
Good integration, easy UI, and very stable and scalable
Pros and Cons
- "Its integration is most valuable. Its UI is also pretty much easy."
- "Its setup is a little bit complex for a distributed environment. Their support can also be better. If we miss the response for more than a week, they usually close the case. Sometimes, it can take us more than a week to reply."
What is most valuable?
What needs improvement?
Its setup is a little bit complex for a distributed environment.
Their support can also be better. If we raise a case with Splunk support and by any chance we missed to respond for more than a week, they usually close the case. Sometimes, it can take us more than a week to reply. In that case What they can do is they can send a followup mail before closing.
For how long have I used the solution?
I have been using this solution for a year now.
What do I think about the stability of the solution?
It is very stable haven't encounter any glitches or bugs till now.
Buyer's Guide
Splunk Enterprise Security
April 2025

Learn what your peers think about Splunk Enterprise Security. Get advice and tips from experienced pros sharing their opinions. Updated: April 2025.
851,823 professionals have used our research since 2012.
What do I think about the scalability of the solution?
It is very much scalable. I am acting as an admin, and we have more than a hundred users of this solution in our company. We use it on a regular basis. We currently don't have any plan to increase its usage.
How are customer service and support?
I would rate them an eight out of ten. Their response speed is okay, but if, by any chance, we miss the response for more than a week, they usually close the case. Sometimes, it can take us more than a week to reply.
Which solution did I use previously and why did I switch?
This is the only solution that we have been using.
How was the initial setup?
Its setup is pretty much easy for standalone, but for a distributed environment, it is a little bit complex.
What other advice do I have?
I would recommend this solution to others, but it should meet their needs and architecture.
I would rate Splunk a nine out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.

Técnico Judiciário at a government with 1,001-5,000 employees
Has the ability to log more logs than similar solutions and is more efficient than its competitors
Pros and Cons
- "It can log more logs than other solutions. It's a good way to troubleshoot problems."
- "Cybersecurity and infrastructure monitoring have room for improvement."
What is our primary use case?
We use it to do SIEM.
How has it helped my organization?
It can log more logs than other solutions. It's a good way to troubleshoot problems.
What is most valuable?
Splunk is a good solution to collect more events than other solutions. It's a good solution, for me, for this reason.
What needs improvement?
Cybersecurity and infrastructure monitoring have room for improvement.
For how long have I used the solution?
Less than one year.
How was the initial setup?
On a scale from one to ten I would rate the initial setup a seven for its complexity.
Which other solutions did I evaluate?
We also looked at AlienVault.
What other advice do I have?
I would rate it an eight out of ten.
Splunk is more efficient than other solutions but it's also more expensive.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Buyer's Guide
Splunk Enterprise Security
April 2025

Learn what your peers think about Splunk Enterprise Security. Get advice and tips from experienced pros sharing their opinions. Updated: April 2025.
851,823 professionals have used our research since 2012.
Director of Information Security with 201-500 employees
Extremely scalable but they need to make purpose-built modules more robust
Pros and Cons
- "It's extremely scalable. It's a very robust solution and certainly has the capability of handling far bigger data requirements than a lot of the other tools. Generally what ends up happening with me is that my clients tend, for the most part, to be mid-tier organizations where the cost of that solutions would be accompanying requirements for people just becomes way too prohibitive. Especially considering the model that they use for costing, which is based on the volume of data. Of course, they're going to put everything including the Coke machine as the ability to collect data off of it, because of course the more they can put through the tool the more money they make."
- "The tool itself is very difficult to configure. It's great for its number of inputs, for the different types of systems devices, and things that it could collect information from. To actually make good use of it, you need a fairly dedicated team of people that have some reasonably good programming or modeling skills to be able to do the things that you need to do with it. Whereas a lot of the other tools are better packaged for that, and so require a lot less training and a lot less dedication."
What is our primary use case?
- SIEM
- Security information
- Event management
What needs improvement?
The tool itself is very difficult to configure. It's great for its number of inputs, for the different types of systems devices, and things that it could collect information from. To actually make good use of it, you need a fairly dedicated team of people that have some reasonably good programming or modeling skills to be able to do the things that you need to do with it. Whereas a lot of the other tools are better packaged for that, and so require a lot less training and a lot less dedication.
What they need to do more than anything else is, they need to take a serious look at purpose-built modules like the SIEM and put a lot more effort into making them more robust. If they did that I think they would have a better chance on the market. The base tool was great, and if the organization that they're looking to sell into requires a good, solid logging solution then they would have a very good sales statement to make because you could get the logging solution you need that could give you the SIEM at the same time.
What do I think about the scalability of the solution?
It's extremely scalable. It's a very robust solution and certainly has the capability of handling far bigger data requirements than a lot of the other tools. Generally what ends up happening with me is that my clients tend, for the most part, to be mid-tier organizations where the cost of that solution would be accompanying requirements for people just becomes way too prohibitive. Especially considering the model that they use for costing, which is based on the volume of data. Of course, they're going to put everything including the Coke machine as the ability to collect data off of it, because of course the more they can put through the tool the more money they make.
Which solution did I use previously and why did I switch?
- AlienVault
- LogRhthym
- ArcSight
- QRadar
I've used a whole bunch of different solutions. For a SIEM based solution, they are more purpose-built for that function. Where Splunk is purpose-built for a general logging and data capture solution so you'd be able to capture a lot of different information.
How was the initial setup?
Anything that's not out of the box requires codding. Even up until recently when they finally released their SIEM or their security add-on. Before then there was not security stuff at all. I would actually have to go in and code that within the system to able to do the necessary searches to pull that information. Where a lot of the other tools, they already have those preconfigured which means I don't have to go and recreate the wheel. Now, we finally figured that out to a certain degree, and started putting the new tool in a place that gives you some SIEM functionality.
What other advice do I have?
As a logging solution, I would say it's probably an eight or nine. If you're talking about the SIEM I'd say it's probably about a five. For logging, I think they would have to change the costing model. The costing model is way out of line. It's built for very large organizations.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Technical Lead at Wipro Technologies
Capability to expand functionality through custom code for data inputs, commands, visualization, alerts, and machine learning
Pros and Cons
- "We can ingest and correlate data from virtually any type of system."
- "Capability to expand the functionality through custom code for data inputs, commands, visualization, alerts, and machine learning."
- "Missing capability for audio/video and image processing."
- "While scheduled reports can be embedded, Splunk dashboard can not be embedded directly without enabling cross origin."
What is our primary use case?
We use Splunk for infrastructure monitoring, application monitoring and in the security space for our organization as well as for our customers.
How has it helped my organization?
Since Splunk is a platform for data, we can ingest and correlate data from virtually any type of system.
It has a fast turnaround time for setting up monitoring/alerting and forecasting of trends as per our customers' requirements.
What is most valuable?
The following are top three features that I find quite valuable:
- Capability to expand the functionality through custom code for data inputs, commands, visualization, alerts, and machine learning.
- Quick turnaround time for setting up monitoring and alerting with built-in capabilities, plenty of enterprise grade apps available on Splunkbase, and custom coding based on Splunk development skill level.
- Free Splunk license for PoCs on personal machines and the ability to scale the PoC to an enterprise level app.
What needs improvement?
- Scheduled PDF generation does not work well for all visualizations, and it does not work for custom visualizations.
- While scheduled reports can be embedded, Splunk dashboard can not be embedded directly without enabling cross origin.
- Missing capability for audio/video and image processing.
For how long have I used the solution?
More than five years.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Manager, Enterprise Risk Consulting at a tech company with 1,001-5,000 employees
Great Log Management and Investigation tool, but Operational SIEM capability needs improvement
Valuable Features
Great Log management capabilities with flexible and comprehensive search capabilities. Scalable and Easy to use.
Room for Improvement
Operational Workflow, Use Case Framework, and ticketing systems to make it suitable for SOC environments
Use of Solution
3 years
Scalability Issues
Splunk is extremely scalable with the limit being the hardware in use.
Customer Service and Technical Support
If you get the right people engaged, support can be a bliss.
Initial Setup
Setup is simple and straight forward.
Other Advice
http://infosecnirvana.com/splunk-enterprise-need-know/
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Product Manager, CyberSecurity at a tech services company with 201-500 employees
Has good security features but needs a better pricing model
Pros and Cons
- "The initial setup isn't overly complex."
- "Splunk can be an expensive solution. Technical support could be improved as well."
What is most valuable?
Because I'm security focused, I prefer the security features such as Splunk Phantom and Splunk Enterprise Security.
What needs improvement?
We need to get a Splunk Cloud instance inside South Africa's borders. At this stage, we are pushing Splunk Cloud, but it is not yet within South Africa's borders. So we've got data sovereignty issues, especially with government organizations.
Technical support could be improved as well.
Splunk can be an expensive solution. I think that they need to change their pricing model. At present, it is based on the number of gigabytes that you ingest into the Splunk system. Their competitors are now starting with a pricing model where you pay per device talking back. If Splunk could have a similar alternative, it would then allow people to choose the data model they want such as set data or a set number of devices.
For how long have I used the solution?
I have been using Splunk for three years.
How are customer service and technical support?
The technical support here in South Africa hasn't been great, but I understand why as we make up less than 3% of Splunk's total revenue in the world.
How was the initial setup?
The initial setup isn't overly complex, but it's not easy either.
What's my experience with pricing, setup cost, and licensing?
The pricing model is based on the number of gigabytes that you ingest into the Splunk system. So it can be an expensive solution.
What other advice do I have?
Plan your requirements properly from the beginning so that you can get the most value in a shorter space of time.
On a scale from one to ten, I would rate Splunk at six.
Disclosure: My company has a business relationship with this vendor other than being a customer: reseller
Network & Telco Lead at a energy/utilities company with 501-1,000 employees
Provides log collection and analysis
What is our primary use case?
- Log collection and analysis
- Reporting for the whole enterprise environment.
How has it helped my organization?
Improved visibility.
What is most valuable?
Log search and alerting/reporting.
What needs improvement?
Code understanding requirement is complicated for most users.
For how long have I used the solution?
One to three years.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Vice Manager at a comms service provider with 10,001+ employees
Collects data from many sources. Has search, analysis, and visualization capabilities.
What is most valuable?
- Collects data from any source
- Powerful search, analysis, and visualization
- Easy to build system on any platform
- API and easily integrated search
- Action script
How has it helped my organization?
We have over 7000 devices in our network infrastructure for monitoring, maintenance, and performance assessment.
We achieve this by collecting data and applying the analysis.
For how long have I used the solution?
I have used this solution for one year.
What do I think about the scalability of the solution?
We did not encounter any issues with scalability. Everything is normal with no bugs.
How are customer service and technical support?
It’s easy to obtain support from Splunk for technical issues. We also have enough knowledge ourselves to apply fixes.
Which solution did I use previously and why did I switch?
We used to deploy Elastic Stack. The search language of Splunk is easier and friendlier than Elastic Stack. It has helped me to search quickly and easily. Based on the results, it’s easy to visualize and add results to a previously built, personal dashboard.
What's my experience with pricing, setup cost, and licensing?
Licensing is free. Pricing is based on usage.
Which other solutions did I evaluate?
We evaluated Elastic Stack and Sumo Logic.
What other advice do I have?
If you are an enterprise and you need the best service for critical business analysis, Splunk would be one of the best choices.
Disclosure: I am a real user, and this review is based on my own experience and opinions.

Buyer's Guide
Download our free Splunk Enterprise Security Report and get advice and tips from experienced pros
sharing their opinions.
Updated: April 2025
Product Categories
Security Information and Event Management (SIEM) Log Management IT Operations AnalyticsPopular Comparisons
CrowdStrike Falcon
Microsoft Sentinel
IBM Security QRadar
Elastic Security
Splunk AppDynamics
Elastic Observability
Grafana Loki
Security Onion
Palantir Foundry
LogRhythm SIEM
Buyer's Guide
Download our free Splunk Enterprise Security Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- Which would you recommend to your boss, IBM QRadar or Splunk?
- What are some of the best features and use-cases of Splunk?
- What SOC product do you recommend?
- Splunk as an Enterprise Class monitoring solution -- thoughts?
- What is the biggest difference between Dynatrace and Splunk?
- IBM QRadar is rated above competitors (McAfee, Splunk, LogRhythm) in Gartner's 2020 Magic Quandrant. Agree/Disagree?
- What are the advantages of ELK over Splunk?
- How does Splunk compare with Azure Monitor?
- New risk scoring framework in the Splunk App for Enterprise Security -- thoughts?
- Splunk vs. Elastic Stack