No more typing reviews! Try our Samantha, our new voice AI agent.
PeerSpot user
Information Architect at a financial services firm with 5,001-10,000 employees
Real User
May 23, 2017
Provides visibility into business metrics and insights that deliver value.
Pros and Cons
  • "Splunk provides immediate visibility into key business metrics and new business insights that deliver immediate value."
  • "We usually have to follow up with technical support on our open cases."

How has it helped my organization?

It is deployed to investigate, detect, respond, and prevent security incidents and threats by providing valuable context and visual insights to make faster and smarter security decisions.

What is most valuable?

  • Splunk delivers a holistic view of an application (the big picture).
  • Splunk provides immediate visibility into key business metrics and new business insights that deliver immediate value.
  • Significant reduction in mean-time-to-investigate (MTTI) and mean-time-to-resolve (MTTR) production incidents from days to hours.
  • Splunk visualization capabilities help pinpoint problem areas, spikes, and anomalies easier and faster.
  • Ability to monitor and resolve integration problems before they impact the business user area.
  • Splunk is being used as part of the development life cycle, resulting in better quality and more efficient applications.
  • Provides additional insights into a 360 degree view of the customer.

What needs improvement?

We usually have to follow up with technical support on our open cases. Otherwise, Splunk listens to customers and is constantly incorporating their feedback in future releases.

What do I think about the stability of the solution?

There are no software stability issues. The issues so far have been internal.

Buyer's Guide
Splunk Enterprise Security
July 2026
Learn what your peers think about Splunk Enterprise Security. Get advice and tips from experienced pros sharing their opinions. Updated: July 2026.
908,877 professionals have used our research since 2012.

What do I think about the scalability of the solution?

There are no scalability issues. If you are planning on using Splunk for security use cases, I would recommend you go with Linux for your OS.

How are customer service and support?

We have the enterprise level of support. This is one area Splunk could improve upon, since we usually have to follow up with them on our open cases.

Which solution did I use previously and why did I switch?

We did not have a previous solution.

How was the initial setup?

There were no issues with the initial setup. We utilized Splunk’s partner zones for the initial setup. In retrospect, we should have utilized Splunk Professional Services.

What's my experience with pricing, setup cost, and licensing?

Although Splunk is an expensive product, it is designed to be utilized across your organization in order to maximize your ROI and lower your TCO.

We contacted Gartner and other business associates to determine what others are paying for Splunk.

Which other solutions did I evaluate?

We started researching ELK (Elastic, Logstash, Kibana). But management was so impressed with Splunk that we ended this research.

What other advice do I have?

Ensure you have an executive sponsors to fully deploy Splunk across your organization to maximize your ROI and lower your TCO.

Make use of Splunk Professional Services.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Alireza Ghahrood - PeerSpot reviewer
Alireza GhahroodConsultant & Instructor -Cyber Security,GovernanceRIskCompliance (CISO as a Services) at a consultancy with 51-200 employees
Top 5Real User

If there's gold in log files, Splunk will help you to find it. Splunk bridges the gap between simple log management and security information and event management products from vendors such as ArcSight, RSA, Q1 Labs and Symantec.

Splunk lets you gather log data from systems and devices, and run queries on that data to find issues and debug problems. Splunk's capabilities also include reporting and alerting, pushing it ever-so-slightly into the world of SIEM.

What separates out Splunk from the world of Syslog servers and SIEM tools is Splunk Apps, a library of nearly 200 addons that make Splunk smarter about particular types of log information, change its look-and-feel or add new types of analysis.

it_user664635 - PeerSpot reviewer
Performance Consultant at a tech services company with 10,001+ employees
Real User
May 17, 2017
Some of the valuable features include data representation options and the analytics and querying of the indices.
Pros and Cons
  • "The data representation options in the dashboards are excellent."
  • "Technical support and the online community are some of the best for any product."
  • "Security administration and user access control is pretty basic. The user access control could be much more granular, so that the admins can control r/w/x access for specific features of the product like dashboards, etc."

What is most valuable?

The analytics and querying the indices is super easy.

The data representation options in the dashboards are excellent.

Multiple datasource/filetypes are supported and each can be customized in a few clicks.

What needs improvement?

Security administration and user access control is pretty basic. This can be improved.

The user access control could be much more granular, so that the admins can control r/w/x access for specific features of the product like dashboards, etc.

If this is improved, with a mapping against LDAP roles, it would be excellent.

What do I think about the stability of the solution?

We had no stability issues.

What do I think about the scalability of the solution?

We had no scalability issues.

How are customer service and technical support?

Technical support and the online community are some of the best for any product.

Which solution did I use previously and why did I switch?

We did not have a previous solution.

How was the initial setup?

The setup was quite easy and there is lot of technical documentation for handholding you through the process.

What's my experience with pricing, setup cost, and licensing?

Pricing and licensing is quite expensive. But for the value the product provides, it seems at par in the market.

Which other solutions did I evaluate?

We looked at IBM SmartCloud Analytics and Log Analytics.

What other advice do I have?

Please watch out for the licensing agreement. There are a lot of IP specific clauses that Splunk has included in their license agreement. Per my understanding, any plugin available in the community cannot be used OOB, due to licensing restrictions. (This might be specific to our organization.)

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Buyer's Guide
Splunk Enterprise Security
July 2026
Learn what your peers think about Splunk Enterprise Security. Get advice and tips from experienced pros sharing their opinions. Updated: July 2026.
908,877 professionals have used our research since 2012.
it_user664626 - PeerSpot reviewer
Business Analyst at a retailer with 10,001+ employees
Vendor
May 16, 2017
Provides real-time and scheduled searches with alternate functionalities.
Pros and Cons
  • "I would strongly recommend this product, as it would be very beneficial for service operations and management."
  • "VMware and security device integration looks a bit complex."

What is most valuable?

  • Flexibility when creating dashboards
  • Automated cron searches
  • Real-time and scheduled searches with alternate functionalities
  • User-base integration with LDAP

How has it helped my organization?

It alerted many situations before other monitoring systems identified that there is a critical issue.

What needs improvement?

VMware and security device integration looks a bit complex.

For how long have I used the solution?

I have used Splunk for almost three years.

What do I think about the stability of the solution?

As of now, we have had no issues with stability. It is running like a charm.

What do I think about the scalability of the solution?

From a nodes perspective, there have been no scalability issues.

How are customer service and technical support?

I can say that support is good.

Which solution did I use previously and why did I switch?

We never used other solutions.

How was the initial setup?

We used the Splunk Cluster setup. It was a bit complex to set up, but management-wise and stability-wise, it was awesome.

What's my experience with pricing, setup cost, and licensing?

License costs fall under the NDA, but Splunk license costs are public, I believe.

Which other solutions did I evaluate?

We evaluated Logstash and others, but Splunk plays a pivotal role.

What other advice do I have?

I would strongly recommend this product, as it would be very beneficial for service operations and management.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
it_user594183 - PeerSpot reviewer
Security Engineer at a retailer with 10,001+ employees
Real User
May 16, 2017
They provide predefined user cases. Scalability is always a question for this product.
Pros and Cons
  • "They provide excellent predefined user cases."
  • "Scalability is always a question for this product."

What is most valuable?

They provide excellent predefined user cases.

How has it helped my organization?

This helps us in the footprinting of all the incidents.

What needs improvement?

When we deep dive into the events for the triggers, we have very little information in some instances.

For how long have I used the solution?

I have used Splunk for two years.

What do I think about the stability of the solution?

We raised support cases.

What do I think about the scalability of the solution?

Scalability is always a question for this product.

How are customer service and technical support?

Response from technical support can be improved. There was always a delay and we had to chase them.

Which solution did I use previously and why did I switch?

We didn’t have a previous solution.

How was the initial setup?

I was not present during the initial setup.

What's my experience with pricing, setup cost, and licensing?

Pricing and licensing are always high compared to other products in the market. Storage is very expensive as well.

What other advice do I have?

It is a good product, but expensive.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
MS Alam - PeerSpot reviewer
MS AlamSystem Administrator at a retailer with 5,001-10,000 employees
Real User

Splunk license and storage pricing is high. please make it cheap then most off company can use this product.

it_user396600 - PeerSpot reviewer
Vice Manager at a comms service provider with 10,001+ employees
Vendor
May 15, 2017
Collects data from many sources. Has search, analysis, and visualization capabilities.
Pros and Cons
  • "If you are an enterprise and you need the best service for critical business analysis, Splunk would be one of the best choices."

    What is most valuable?

    • Collects data from any source
    • Powerful search, analysis, and visualization
    • Easy to build system on any platform
    • API and easily integrated search
    • Action script

    How has it helped my organization?

    We have over 7000 devices in our network infrastructure for monitoring, maintenance, and performance assessment.

    We achieve this by collecting data and applying the analysis.

    For how long have I used the solution?

    I have used this solution for one year.

    What do I think about the scalability of the solution?

    We did not encounter any issues with scalability. Everything is normal with no bugs.

    How are customer service and technical support?

    It’s easy to obtain support from Splunk for technical issues. We also have enough knowledge ourselves to apply fixes.

    Which solution did I use previously and why did I switch?

    We used to deploy Elastic Stack. The search language of Splunk is easier and friendlier than Elastic Stack. It has helped me to search quickly and easily. Based on the results, it’s easy to visualize and add results to a previously built, personal dashboard.

    What's my experience with pricing, setup cost, and licensing?

    Licensing is free. Pricing is based on usage.

    Which other solutions did I evaluate?

    We evaluated Elastic Stack and Sumo Logic.

    What other advice do I have?

    If you are an enterprise and you need the best service for critical business analysis, Splunk would be one of the best choices.

    Disclosure: My company does not have a business relationship with this vendor other than being a customer.
    PeerSpot user
    it_user363165 - PeerSpot reviewer
    Products Manager at a tech services company with 5,001-10,000 employees
    MSP
    May 11, 2017
    Valuable features include rapid search, data mining, and information propagation. The GUI should be improved.
    Pros and Cons
    • "It has been helping a lot of my clients with fast data mining and information propagation."
    • "The GUI should be improved, in other words, the overall appearance."

    What is most valuable?

    Rapid search is a valuable feature. Performance and incident response were the top priorities for most MSSPs. Breaches of SLAs will have a negative impact on customer trust, which eventually leads to losing customer confidence on services to which they’re subscribing. Hence, the proactive approaches will be the main differentiator from one MSSP to the others.

    How has it helped my organization?

    It has been helping a lot of my clients with fast data mining and information propagation.

    What needs improvement?

    The GUI should be improved, in other words, the overall appearance.

    For how long have I used the solution?

    I am not the end-user. However, my job was more relevant as a consultant.

    What do I think about the stability of the solution?

    Performance upgrades are needed when more processing power is required.

    What do I think about the scalability of the solution?

    We have not had scalability issues.

    How are customer service and technical support?

    Technical support is good.

    Which solution did I use previously and why did I switch?

    The client was using an open source solution. They decided to switch to an enterprise product.

    How was the initial setup?

    The setup can be straightforward, if use cases are well defined.

    What's my experience with pricing, setup cost, and licensing?

    Overall, it the cost is reasonable and it is easy to upgrade.

    Which other solutions did I evaluate?

    Our client was considering the other solutions as well. However, due to their overall assessment, they still considered going with it.

    What other advice do I have?

    Start off with something at a comfortable level, expand gradually, and then move upwards, expanding steadily.

    Disclosure: My company has a business relationship with this vendor other than being a customer. We are a distributor.
    PeerSpot user
    PeerSpot user
    Sr. Program Manager at a consultancy with 51-200 employees
    Consultant
    May 10, 2017
    It is able to configure and integrate various solutions into one tool and provide actionable results. You need a dedicated developer.
    Pros and Cons
    • "Can ingest data from various data sources, is very useful for organizations who are attempting to meet compliance requirements, and is able to fully configure and integrate various solutions into one tool and provide actionable results."

      What is most valuable?

      • Can ingest data from various data sources.
      • Is very useful for organizations who are attempting to meet compliance requirements.
      • Is able to fully configure and integrate various solutions into one tool and provide actionable results.

      How has it helped my organization?

      My use of Splunk at my previous place of employment improved how we functioned.

      For how long have I used the solution?

      I have used Splunk for three years.

      What do I think about the stability of the solution?

      We didn’t have any stability issues.

      What do I think about the scalability of the solution?

      We didn’t have any scalability issues.

      How are customer service and technical support?

      During our use of Splunk, we had professional services assisting and not actual technical support. However, the professional services team was great.

      Which solution did I use previously and why did I switch?

      Our organization did not have an established SIEM tool.

      How was the initial setup?

      The initial setup is straightforward, depending on the level of implementation of the tool.

      What's my experience with pricing, setup cost, and licensing?

      Take into consideration the labor costs for a dedicated Splunk developer who can craft the required queries needed for each organization. Organizations usually have their own form of implementation of each tool.

      Which other solutions did I evaluate?

      We didn’t evaluate any alternatives.

      Disclosure: My company does not have a business relationship with this vendor other than being a customer.
      PeerSpot user
      PeerSpot user
      Technical Director at a consultancy with 11-50 employees
      Real User
      May 9, 2017
      It allows us to store raw data and use it repeatedly for different domains.
      Pros and Cons
      • "This is the right choice if you are looking for a platform that can combine all machine-generated data and use it for various use cases from different domains."
      • "Visualizations can improve. There are some performance and stability issues with the visualization layer."

      How has it helped my organization?

      We are using it for operational intelligence. We are using Splunk as a data lake for machine data. We gather all our machine data from the IT infrastructure and monitor its health.

      What is most valuable?

      Splunk's schema-on-read technology is one of the most valuable characteristics of this solution. It allows us to store raw data and use it repeatedly for different domains. You don't need to prepare the data upfront.

      Splunk's Search Processing Language (SPL) is another beneficial feature. It is a very powerful tool that gives you the ability to do almost anything with your data.

      What needs improvement?

      Visualizations can improve. There are some performance and stability issues with the visualization layer.

      What do I think about the stability of the solution?

      There were stability issues, but only with the visualization layer.

      What do I think about the scalability of the solution?

      There were no scalability issues.

      How are customer service and technical support?

      The technical support is quite good.

      Which solution did I use previously and why did I switch?

      Previously, we worked with different vendors and solutions.

      How was the initial setup?

      The setup was very straightforward.

      What's my experience with pricing, setup cost, and licensing?

      The price is pretty high for our region.

      Which other solutions did I evaluate?

      We did a SIEM solutions review with this and other systems for one of our customers.

      What other advice do I have?

      This is the right choice if you are looking for a platform that can combine all machine-generated data and use it for various use cases from different domains.

      Disclosure: My company does not have a business relationship with this vendor other than being a customer.
      PeerSpot user
      Alireza Ghahrood - PeerSpot reviewer
      Alireza GhahroodConsultant & Instructor -Cyber Security,GovernanceRIskCompliance (CISO as a Services) at a consultancy with 51-200 employees
      Top 5Real User

      Splunk's schema-on-read technology is one of the most valuable characteristics of this solution. It allows us to store raw data and use it repeatedly for different domains. You don't need to prepare the data upfront.

      PeerSpot user
      Integration Architect at a manufacturing company with 1,001-5,000 employees
      Vendor
      Oct 9, 2015
      Fast availability of operational data spread across several servers is nice, but the MES is a complex system.
      Pros and Cons
      • "What Splunk calls operational intelligence: fast availability of operational data spread across several servers to prevent or react faster to outages or performance decreases."
      • "I've ever used it, just studied it."

      What is most valuable?

      What Splunk calls operational intelligence: fast availability of operational data spread across several servers to prevent or react faster to outages or performance decreases.

      How has it helped my organization?

      MES is a complex and very critical distributed system here. Production WIP is directly connected to it and ICT is required to provide a continuous availability and very stable performance (line production has a costant speed, software cannot slowdown). Collect operational data from hardware, middleware and application software can potentially improve ICT proactive and reactive tasks.

      For how long have I used the solution?

      I've ever used it, just studied it.

      Which solution did I use previously and why did I switch?

      We also use a traditional monitor, and Microsoft SCOM.

      What was our ROI?

      Every stop or slowdown of the production line means lost of money, e.g. 30% reduction when compared to the current baseline.

      What's my experience with pricing, setup cost, and licensing?

      Every stop or slowdown of the production line means lost of money, e.g. 30% of reduction compare to the current baseline.

      Which other solutions did I evaluate?

      IBM QRadar

      Disclosure: My company does not have a business relationship with this vendor other than being a customer.
      PeerSpot user
      PeerSpot user
      Manager, Enterprise Risk Consulting at a tech company with 1,001-5,000 employees
      Real User
      Feb 26, 2015
      Innovative tool but it needs to be improved for day to day use.

      SIEM posts have grown in number at Infosecnirvana, but the requests to write about more products keep coming in. One of the oft asked about product is Splunk Enterprise. We have posted on HP ArcSight, IBM QRadar and McAfee Nitro SIEM. However, readers have been asking us repeatedly to write on Splunk.

      So here it is finally after being in the works for a long time.

      Introduction:

      In 2003, One of the most interesting products rolled out and vowed to simplify Log management once and for all (and it did!!!) - Splunk. Their motto was simple – Throw logs at me and I will provide a web based console to search through it intuitively. Interestingly they are one of the few companies that have not been acquired, in spite of being a very innovative product. So let’s see what makes Splunk tick.

      Architecture:

      As always, a product is as good as its architecture. It has to be solid both internally as well as externally (meaning solution deployment, integration, ease of use, compatibility etc.).

      • Internal Architecture: Under the hood Splunk has two main services – The Splunk Daemon that is written in C++ used for data collection, indexing, search etc. and the The Splunk Web Services that is a web application written using a combination of Python, AJAX, XML, XSLT etc . which provides the super intuitive graphical UI. Splunk also provides API access using REST and it can integrate with any web framework needed. Splunk is one of the few products that still use C++ and Python instead of the clunky Java and its cousins. This provides the edge to Splunk when processing large data volumes thrown at it.
      • Data Architecture: Splunk is a unique search engine like “data architecture”. In fact, some of the early development was based on the same concept of the path breaking GFS (Google file system) which provided a lot of direction and research into flat file storage, indexing and free text search capabilities with unmatched speed when compared to a relational DB. Splunk went on to master the distributed file system architecture and built their own proprietary data store which powers Splunk Enterprise today.
      • Deployment Architecture: The deployment of Splunk is based on true Big Data Architecture – Slave and Master, where the Slaves are the Search Indexers and the Master is a search head. Of course you can have both the nodes in the same Physical server, but in a true distributed architecture, you need a master and a slave. Read more at Big Data – What you need to know? to understand better on what Big Data is and how to try your hand at it.
      • Typical Setup: Lets look at a typical architecture deployment of Splunk in distributed mode.

      Splunk_img4
      As you can see, there are three distinct components of this architecture and they are as follows:

      1. Log collectors or Splunk Log Forwarders are installed closer to the source and forward all the logs to Splunk Indexers. This is similar to the Log Collectors in SIEM. They are not great, but are decent enough to get the job done.
      2. The Splunk indexers typically run only the Splunk Daemon service, that receives the data and indexes it based on a pre-defined Syntax (this is akin to parsers but lot more simpler and faster to process). This is then sent to the Splunk data store. Each data store has a set of indexes based on the amount of logs received. The data store can then be configured for retention, hot or cold or warm standby etc. etc. In big data terminology, these are the slave nodes.
      3. These indexers then use a process called as “Summarizer” or in big data terms – “Map reduce” to create a summary index of all the indexes available.
      4. Splunk Search head, which serves as the single console to search across all data stores has the “summary index” to know which Indexer (slave) node to query and what index to query. Now this is where the scalable search power of Splunk comes from. This is the master node in big data world.

      What’s good about Splunk?

      • Search, Search & Search: Splunk is arguably the best search engine for logs out there. We have started looking at ELK, Hadoop and other big data search engines but for the moment, Splunk rules the roost. The Splunk Search Processing Language (SPL) is the reason behind this power. The search can be done historically (on indexed data) or in real time (data before indexing) and this is as good as Log search can get. None of the SIEM products can come close to the search power of Splunk. In other words, Splunk is to search Log Data and SIEM is to search Event Data.
      • Fully customizable as far as searching capabilities is concerned, Splunk lets us add scripts to search queries, provides field extraction capabilities for custom logs, provides API, SDK and Web framework support to achieve all that you would need for Log management, Investigations, Reporting and alerting.
      • Web Interface: Even though UI is a subjective benefit, Splunk has one of the most pleasing interfaces we have seen for log management tools. It really is super easy and intuitive to use. It has great visualization capabilities, dashboards, app widgets and what not. It really puts the cool factor in a rather dull log analysis experience.
      • No Parsing: Basically, Splunk is an “All you can eat” for logs. Splunk follows a “store now, parse later” approach which takes care of receiving any logs thrown at it without any parsing or support issues. If it is a known log type, the indexes are added and updated appropriately. If it is not a known type, still the logs are stored and indexed to be searchable for later. You can then use Field Extractions and build custom field parsings. This is one of the killer differentiators compared to traditional SIEM products as Splunk is a lot more forgiving and agnostic in log collection and storage and does not require specialized connectors or collectors to do the job. This makes it a great log management product.
      • Splunk Apps help in building on top of the Search head to provide parsing, visualizations, reporting, metrics, saved searching and alerting and even SIEM-like capabilities. This, in my opinion is the power of Splunk compared to the other products in the market. They have an App Store for Splunk Apps. Cool isn’t it? These apps not only are written by product vendors, but also by User community.
      • Scalability: Splunk is a true big data architecture. It can scale with addition of Indexers and search heads. Ratio of Search Heads to Indexers is at a good 1:6. This means that if you have 1 search head, you can have 6 search indexers. This is very attractive when compared to other SIEM solutions in the market when it comes to scaling at the log management layer.

      What’s bad?

      • Not a SIEM: Splunk is not your traditional SIEM. Let me clarify further. SIEM has several things in it that assists in performing security event management, monitoring, operations and workflow. In short the keyword for SIEM is “Operational Security Management”. Now the question is – Can Splunk be an SIEM? The simple answer is YES, however the real answer lies in how much customisation and how much product expertise you have in store to make it a SIEM product.
      • Poor Correlation: Splunk does not do any correlation as it is not designed to do that. However, it can be used to correlate events using the Splunk search language. You can do manual correlation using piped searches, lookup tables, scripted searches etc. but again you need to be familiar with the language. You can also automate it by scheduled and real time search triggers. However, nothing is out of the box. Anton blogs about Splunk Correlation being far superior to ArcSight (which btw is the best correlation engine we have worked with) but honestly, we don’t have real life implementation experience to justify that.
      • SIEM App: Splunk has an enterprise SIEM app that aids in SIEM-like functions. But it is definitely not a replacement killer for SIEM product. It is very basic and and does not do much out of the box.
      • No Aggregation: The logs being sent to Splunk are received as is and sent to the data store. It is not aggregated. This while is a good thing for log collection and search performance, it is not good for underlying storage sizing. SIEM solutions have this capability but Splunk does not. This in turn affects the scalability aspect.
      • Poor Compression: Many SIEM products have a compression ratio of 10:1. However for Splunk, we have consistently seen the ratio to be around 4:1. This while good for smaller log volumes, is very poor for larger volumes. The main reason for this is that the Indexes take a lot of storage compared to the raw logs. While they aid in greater search capabilities, they increase underlying storage and maintenance cost.
      • Scalability: Even though, Scalability is one of the benefits of using Splunk for Log management, there is a downside to it too. Add to it the lack of aggregation, compression etc. and you can see how it impacts Scale. For example, Every indexer can handle only 100 – 150 GB/day on a good server hardware. In spite of what people might say about Splunk sizing and performance tuning, from years of personal use and experience, we can safely say that for standard enterprise hardware, this limit is as good as it gets. So assume you are looking at 1 TB/day. You would need 8 indexer servers and 2 search head servers for Splunk. However, if you were to take ArcSight or QRadar, you could do the same on two appliances with compression enabled (10:1 ratio of compression). This from a management perspective leads to larger foot print for Splunk than other SIEM products.
      • Price: Contrary to popular belief, Splunk can get very expensive very fast. For all the reasons mentioned above, Splunk can get very expensive compared to other SIEM vendors to do large data collection as well as SIEM functionality. In a word – Be Cautious!!!

      Conclusion: In our opinion, Splunk is one of the most innovative log management tools out there. But as a SIEM, to use in day to day security management, monitoring, ticketing etc. it has a lot of catching up to do. The ideal scenario will be to use Splunk in the log management layer and use any market leading SIEM in the correlation, workflow and operational management layer. We have seen several successful implementations where Splunk serves as the log management tool and ArcSight or QRadar serves as the Correlation engine. Best of both worlds!!!

      Disclosure: My company does not have a business relationship with this vendor other than being a customer.
      PeerSpot user
      Alireza Ghahrood - PeerSpot reviewer
      Alireza GhahroodConsultant & Instructor -Cyber Security,GovernanceRIskCompliance (CISO as a Services) at a consultancy with 51-200 employees
      Top 5Real User

      thank you for a good review.

      See all 7 comments
      Buyer's Guide
      Download our free Splunk Enterprise Security Report and get advice and tips from experienced pros sharing their opinions.
      Updated: July 2026
      Buyer's Guide
      Download our free Splunk Enterprise Security Report and get advice and tips from experienced pros sharing their opinions.