No more typing reviews! Try our Samantha, our new voice AI agent.
Vikash Kushwaha - PeerSpot reviewer
Full-Stack Software Engineer at mindpathtech
Real User
Top 5Leaderboard
Jul 8, 2026
Security monitoring has improved and supports complex, high-volume environments effectively
Pros and Cons
  • "Splunk Enterprise Security is fully scalable because it provides all kinds of configuration in management servers and all cloud integrations such as AWS, Azure, Google Cloud, Kubernetes, Docker, GitHub, Jenkins, and Cisco as well, and it is quite fully scalable across all platforms."
  • "The learning curve, its implementation, and its pricing are quite heavy for learners or purchasers."

What is our primary use case?

Splunk Enterprise Security was the major use case that I had.

What is most valuable?

As a service provider and person managing the tool, the biggest advantage that stands out for me is quite significant. I am using disparate security solutions to integrate or import data into Splunk. I have worked with risk-based alerting in this aspect.

In banking, the logs generated are significant, so everyone should be aware of not facing emergencies such as service failures. Debugging and analyzing these services are really important, especially for larger organizations such as banks, where the services should be implemented with Splunk.

Splunk Enterprise Security helps to improve business resilience by being dependent on the services the company provides. If the processes are heavy such as banking, healthcare, and aviation, it is quite helpful. However, for a small and less complex system, it is not useful because it contains a very heavy architecture. It can be quite expensive to implement for them, but for larger processes and products, it is quite useful.

What needs improvement?

High infrastructure requirements are present when I integrate Splunk into my full services such as app microservices, database, CloudWatch, or the machines where I have deployed the services. I have to integrate into all the platforms I am using. It needs another machine or infrastructure to manage all the logs and generate these kinds of reports.

Regarding the learning curve, any beginner encounters trouble with it because it is complex to implement across all services due to the huge amount of applications or functionality to watch and implement. I also mentioned earlier that the pricing is a concern because it does not provide any free tier to use; therefore, I have to use the paid version, which is quite expensive, costing thousands of dollars per one gigabyte or ten gigabytes of data generated.

I believe the pricing is quite expensive. It generates a huge amount of data, so it sometimes works slowly for the generated logs. I can say around ninety-eight percent uptime because I can sometimes get into trouble finding logs across the services in the generated logs.

The learning curve, its implementation, and its pricing are quite heavy for learners or purchasers.

For how long have I used the solution?

I have used Splunk Enterprise Security for three years now.

Buyer's Guide
Splunk Enterprise Security
August 2026
Learn what your peers think about Splunk Enterprise Security. Get advice and tips from experienced pros sharing their opinions. Updated: August 2026.
914,109 professionals have used our research since 2012.

What do I think about the scalability of the solution?

Splunk Enterprise Security is fully scalable because it provides all kinds of configuration in management servers and all cloud integrations such as AWS, Azure, Google Cloud, Kubernetes, Docker, GitHub, Jenkins, and Cisco as well. It is quite fully scalable across all platforms.

How are customer service and support?

My manager discussed licensing earlier, but I did not have the need to call them later after implementing. After my organization bought it, they provided quite a good response from the support team.

Which solution did I use previously and why did I switch?

When I compare Splunk Enterprise Security to other tools, I have been using various solutions on average to allow my SecOps team to remediate security incidents with Splunk.

How was the initial setup?

Regarding the installation and deployment, I would say it is quite complex. It is complex because I have to deeply learn it due to the many things involved. As a beginner, it is quite complex to learn. If a senior developer or individual is trying to implement it, that is time-consuming because I have to do a lot of things to implement Splunk across the services and servers.

What was our ROI?

If I quantify the return on investment of Splunk in percentage, I would say it is around ten to twenty percent on average for its services provided because these bugs or hacker attempts are really rare cases, making it heavy to calculate.

What's my experience with pricing, setup cost, and licensing?

I did not purchase it because these transactions are handled at the organizational level. The higher managers process these purchases over the AWS cloud, so as a developer, I am not included in that process.

What other advice do I have?

I am using a new threat detection feature in Splunk. When I implement Splunk, it provides a dashboard or methods to implement these threat detection processes. It gives me an email trail that identifies when services and which users are trying to breach security. If any service has failed, then it also triggers an email or a notification in the dashboard. These are rare cases, but I find the average number to be acceptable.

I have used Azure for deployment. I rate Splunk Enterprise Security nine points out of ten, and my overall review rating for this product is nine out of ten.

Which deployment model are you using for this solution?

On-premises

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Microsoft Azure
Disclosure: My company has a business relationship with this vendor other than being a customer. MSP
Last updated: Jul 8, 2026
Flag as inappropriate
PeerSpot user
GuruPrasad3 - PeerSpot reviewer
Cyber Security Manager at a tech vendor with 10,001+ employees
Real User
Top 10
Sep 30, 2025
Provides strong threat visibility and MITRE coverage but lacks AI features and cost flexibility
Pros and Cons
  • "Splunk Enterprise Security would provide better capabilities and out-of-box detections."
  • "We haven't saved any money with Splunk Enterprise Security. Instead, we have spent excess of the budget on this with unexpected costs."

What is our primary use case?

We use Splunk Enterprise Security for our security monitoring and incident management. This is our global application that we are using for security monitoring and compliance.

How has it helped my organization?

We've seen some good improvements from a business perspective, particularly regarding security monitoring. However, when I consider our current challenges and future roadmap, I don't believe Splunk Enterprise Security has the capabilities we need. We previously faced challenges with QRadar, which prompted us to migrate to Splunk Enterprise Security. While Splunk Enterprise Security has addressed the past issues we encountered, it fails to meet our future requirements. Currently, it effectively addresses existing threats, but it doesn’t tackle advanced threats, which is a significant challenge we foresee with Splunk. There is still a lot of room for improvement.

What is most valuable?

With the Classic flavor we have in our company, the feature that I find good in Splunk Enterprise Security is from the MITRE coverage point of view, and then the level of information that it provides. The integration with its own SOAR platform is also one of the pros.

What needs improvement?

From the product point of view and deployment point of view, Splunk Enterprise Security is satisfactory. It is not simple; it is at a medium level when it comes to deployment and management of the tool altogether. This includes not only the enterprise platform but also other components such as deployment servers or the Splunk agents we use for collecting logs. When comparing it with different vendors in the industry, from the deployment and maintenance point of view, it is not up to the level of other vendors. 

When discussing the drawbacks, it's important to note that the flavor I’m currently using is called "Classic." Unfortunately, this platform does not offer any of the new features that Splunk introduces. As a result, we are the last ones to find out about new capabilities, and we’re also slow to implement them. Splunk tends to release new features with different flavors of their platform, and being on the Classic flavor means we are least likely to receive the latest updates. This is a significant concern I have regarding Splunk.

When comparing Splunk Enterprise Security with next-gen SIEMs, we look for AI and ML models being incorporated in such a way that it automatically should be able to detect behavioral-based detections. It should be able to detect behaviors from logs and show us the entire attack surface and blast radius of any particular incident, which is primarily missing.

The capability of AI, Artificial Intelligence, is missing, which would help to automatically detect and read data comprehensively. Splunk lacks the new native solutions for agent deployment, which is essential for a large enterprise.

Currently, there is Machine Learning in Splunk Enterprise Security, but that is resource exhaustive and complex, bringing an impact onto our overall stack performance. Technical expertise in Machine Learning is required, and continuous monitoring is needed to ensure Machine Learning learns about our data to provide results, which is resource exhaustive, time-consuming, and costly.

Artificial Intelligence is missing in the Splunk Enterprise Security platform, which would help us read the data automatically, learn from it, and provide attack surface area from a 360-degree perspective. The fixed pricing model requires upfront purchase based on assumptions and roadmap, requiring payment for the next two to three years regardless of usage.

For how long have I used the solution?

I have been using Splunk Enterprise Security for around three years.

What do I think about the stability of the solution?

On a stability scale, I would rate it an eight out of ten.

What do I think about the scalability of the solution?

Regarding scalability, I would rate it a seven out of ten. I don't have the pay as you go model. 

We have 150 users using this solution.

How are customer service and support?

Whenever we raise any support case in Splunk, even after providing the required information, if a person is working on it and it gets transferred or handed over to a different representative in a different shift, they keep asking the same questions and requesting more details. Even when we ask for a call, even for P1 or P2 incidents, they keep going around asking for details. When we request P1 or P2 support, it would be wise to get into a call, get all the details, and have a troubleshooting call to address the issue on a priority basis. The technical support representatives keep transferring the tickets during shift handover, and different representatives ask the same questions multiple times, wasting our precious time. The issue doesn't get resolved until I escalate it to their higher management.

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

We were using QRadar previously. We had legacy systems, and from the volume and log source point of view, from the costing perspective and detection point of view, we thought Splunk Enterprise Security was far better than QRadar. Splunk Enterprise Security would provide better capabilities and out-of-box detections. These were some of the things that we saw, and Splunk Enterprise Security was also one of the leaders in SIEM technology. However, once we started using Splunk Enterprise Security, we discovered it was not the right tool.

How was the initial setup?

The initial setup was of medium complexity. It took approximately 8 to 12 months to migrate from QRadar to Splunk Enterprise Security. 

The cloud platform we are using is maintained by the Splunk team itself. However, when it comes to our on-premises deployment, the maintenance is very high, cumbersome, and costly from both resource and time perspectives.

What was our ROI?

We haven't saved any money with Splunk Enterprise Security. Instead, we have spent excess of the budget on this with unexpected costs. That's one of the pain points I see with Splunk Enterprise Security. There haven't been any savings.

What's my experience with pricing, setup cost, and licensing?

Splunk Enterprise Security comes with high fixed costs. That's one of the disadvantages. When comparing with different vendors, they offer pay-as-you-use models, which is more user-friendly, but Splunk Enterprise Security comes with fixed pricing.

Which other solutions did I evaluate?

We use different security tools as well.

What other advice do I have?

For any user who wants to have a cost-efficient and next-gen SIEM solution, I wouldn't recommend Splunk Enterprise Security. However, if a user is not concerned about cost and is looking for an on-premises solution, then I would suggest Splunk Enterprise Security. For anyone who wants to go for a cloud and cost-effective solution with next-gen capability, I wouldn't recommend this.

I would rate it a seven out of ten.

Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
PeerSpot user
Buyer's Guide
Splunk Enterprise Security
August 2026
Learn what your peers think about Splunk Enterprise Security. Get advice and tips from experienced pros sharing their opinions. Updated: August 2026.
914,109 professionals have used our research since 2012.
Jeanette Pavelka - PeerSpot reviewer
Assistant VP, Data Loss Prevention at State Street
Real User
Top 10
Sep 11, 2025
Creating custom detections has accelerated threat response and improved team independence

What is our primary use case?

My main use case for Splunk Enterprise Security is web uploads.

What is most valuable?

The ability to create SPLs in Splunk Enterprise Security is my favorite feature. These features benefit my organization primarily through threat detection, which I use for, so that's a huge benefit. Splunk Enterprise Security has absolutely helped improve my organization's business resilience.

What needs improvement?

Splunk Enterprise Security could be improved by incorporating AI features, as it doesn't have the AI capability that Pyramid does, where users can ask questions without having to write code.

For how long have I used the solution?

It has been more than three years.

What do I think about the stability of the solution?

I haven't experienced any downtime or performance issues with Splunk Enterprise Security. Zscaler may experience issues because Splunk grabs data from them, but other than that, I haven't had anything crash.

What do I think about the scalability of the solution?

Splunk Enterprise Security adapts to our growing needs on a yearly basis, as we're constantly growing our program and it has helped in that way. We have expanded usage from just engineering, as now our whole DLP team uses it, allowing us to not rely on other people for it. It was a smooth process when we were expanding usage.

What other advice do I have?

The most significant challenges I've faced when using Splunk include getting the code right. I find the process for customizing, developing, testing, deploying, and refining detections in Splunk Enterprise Security to be good, as changes are easy to make. On average, my security ops team takes about three days to remediate security incidents with Splunk Enterprise Security, depending on what the incident is.

My advice to other organizations considering Splunk Enterprise Security is that it depends on their needs and costs, but I think it can cover everything from a small business to a large business, so I would definitely recommend it.

On a scale of 1-10, I rate Splunk Enterprise Security an 8.

Which deployment model are you using for this solution?

Hybrid Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Other
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
reviewer2899464 - PeerSpot reviewer
IT Administrator at a government with 1,001-5,000 employees
Real User
Top 20
Sep 17, 2026
Platform has become our security hub and has improved threat detection and response speed
Pros and Cons
  • "Splunk Enterprise Security has helped reduce our team's average meantime to resolve metric by about 50 percent because we are able to tune it to lower false positives and noise."
  • "I think Splunk Enterprise Security could integrate more features, just as a SOAR should be part of the product, along with more AI detection features, and additional features available in observability. The current offering is not sufficient."

What is our primary use case?

My main use case for Splunk Enterprise Security is detection and engineering. We are looking for all different kinds of threats with Splunk Enterprise Security and then we ingest data sources from different telemetry to look at our posture, starting from MFA to everything else. That is our main use for Splunk Enterprise Security.

What is most valuable?

In my experience, the best features Splunk Enterprise Security offers are the in-depth search, dashboards, and all those features.

Our dashboards with Splunk Enterprise Security give us our metrics, and I also use it for the executive dashboard. For example, we use it for lateral movement and email security, and basically, we use it for protection and firewalls as well, ingesting all the logs.

Splunk Enterprise Security is our main MDR service and the center of our cybersecurity operation, where we have all the alerts ingested and present.

Since implementing Splunk Enterprise Security, I have seen a faster response time, and we can also suppress noise, including false positives.

What needs improvement?

I think Splunk Enterprise Security could integrate more features, just as a SOAR should be part of the product, along with more AI detection features, and additional features available in observability. The current offering is not sufficient.

For how long have I used the solution?

I have been using Splunk Enterprise Security for two years.

What do I think about the stability of the solution?

Splunk Enterprise Security is stable.

What do I think about the scalability of the solution?

In terms of scalability, Splunk Enterprise Security is pretty scalable. You just have to pay more.

How are customer service and support?

We have very good customer support with Splunk's SE, and while sometimes responses can be slow, overall it is satisfactorily defined. I would rate the customer support of Splunk Enterprise Security an eight out of ten.

Which solution did I use previously and why did I switch?

We previously used LogRhythm, and that decision was made by someone else, our former CIO. We owned Splunk before and decided to go back to Splunk again.

What was our ROI?

I have not yet seen a return on investment. It is still hard to quantify because we are still configuring and building our metrics to measure it. We started some metrics and I am hoping to get those in the next six months.

What's my experience with pricing, setup cost, and licensing?

My experience with pricing, setup cost, and licensing is that pricing is high, and it feels as though it is not very transparent. We do not know what discount rate we are going to get, and I have to buy multiple different products.

Which other solutions did I evaluate?

Before choosing Splunk Enterprise Security, we knew what we wanted to do, so I did not have to evaluate other products.

What other advice do I have?

Splunk Enterprise Security has helped reduce our team's average meantime to resolve metric by about 50 percent because we are able to tune it to lower false positives and noise.

I would say Splunk Enterprise Security helps us detect threats faster because we are able to tune the number of alerts sent out, resulting in fewer alerts we need to monitor.

We are still developing the impact of Splunk Enterprise Security's risk-based alerting on our alert volume and analyst productivity.

Having the consolidation of SIEM, SOAR, and UEBA into a single interface with Splunk Enterprise Security improves our operational efficiency and provides a single pane of glass.

The integration of threat intelligence directly into the TDIR workflow with Splunk Enterprise Security improves our ability to preemptively block threats and makes our decision-making faster since we have intel ingested in the platform instead of referencing different sources.

Regarding Splunk Enterprise Security Essentials, we have not worked much on the cloud side, so it has not improved our visibility across hybrid or multi-cloud environments.

My advice to others looking into using Splunk Enterprise Security is that if someone wants a very comprehensive solution, it is the way to go. However, they need to ensure they have a person who can handle, configure, maintain, and add rules and policies, as it is not the product they need to buy unless they have managed services. I would rate this product an eight out of ten overall.

Which deployment model are you using for this solution?

Public Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Last updated: Sep 17, 2026
Flag as inappropriate
PeerSpot user
senior technical program manager at a computer software company with 201-500 employees
Real User
Top 20
Sep 17, 2026
Centralized monitoring has standardized our logs and empowers teams with shared dashboards
Pros and Cons
  • "Splunk Enterprise Security has positively impacted my organization by providing enhanced logging capabilities in addition to standardizing log approaches and visualizations, allowing us to create and share dashboards and visualizations so that all of our various enterprise programs can implement standard and consistent dashboard methodologies."

    What is our primary use case?

    My main use case for Splunk Enterprise Security involves log aggregation, anomaly identification, visualization of potential issues, errors, and threat modeling.

    I create specific reports or dashboards to measure log patterns or events that fall outside of our specific thresholds, such as user logins multiple times a day or users attempting to hit protected routes that they don't have access control for.

    What is most valuable?

    All the features of Splunk Enterprise Security are quite great and necessary. I think being able to create and share visualizations and dashboards is really helpful for allowing my less Splunk-savvy co-workers the ability to still monitor and investigate issues or potential incidents.

    Typically, my coworkers use the dashboards I create for monitoring system health, error rates, and similar metrics, but then with visualization drill-downs, that allows them to dig deeper into what an issue might be caused by, which parleys into incident response.

    Splunk Enterprise Security has positively impacted my organization by providing enhanced logging capabilities in addition to standardizing log approaches and visualizations, allowing us to create and share dashboards and visualizations so that all of our various enterprise programs can implement standard and consistent dashboard methodologies.

    What needs improvement?

    I think the addition of the new Splunk AI Assistant into Splunk Enterprise Security would be really helpful, especially for new Splunk users to be able to rapidly learn and generate complex SPL queries.

    For how long have I used the solution?

    I believe we have been using Splunk Enterprise Security for about six years.

    What do I think about the stability of the solution?

    Splunk Enterprise Security is stable.

    What do I think about the scalability of the solution?

    I think Splunk Enterprise Security is very easily scalable both horizontally and vertically; we have had no issues expanding as needed.

    How are customer service and support?

    Customer support has been fantastic.

    Which solution did I use previously and why did I switch?

    I have used a couple of different solutions; traditionally, I looked at logs on servers through tail, cat, and vim, and I played around with other log aggregation solutions including Kibana, but I have been with Splunk for about six to eight years.

    How was the initial setup?

    I think my experience with pricing, setup cost, and licensing has been pretty positive. As far as licensing goes, it has been pretty transparent. The bulk of the expense for Splunk Enterprise Security comes from data storage and retention, so thankfully, we have been able to work with both our Splunk and cloud partners to come up with a retention policy and life cycle plan that works for us and fits within our budget.

    What about the implementation team?

    We used direct contract procurement to purchase Splunk Enterprise Security.

    What was our ROI?

    I have definitely seen a return on investment. Although I don't know that I can quantify that ROI, I have definitely seen a reduction in administrative burden, allowing us to redirect both our analyst and engineering resources to focus on actual remediation efforts or identification of incidents and response times, rather than engineers having to spend a lot of time parsing logs or incidents.

    What's my experience with pricing, setup cost, and licensing?

    I think my experience with pricing, setup cost, and licensing has been pretty positive. As far as licensing goes, it has been pretty transparent. The bulk of the expense for Splunk Enterprise Security comes from data storage and retention.

    Which other solutions did I evaluate?

    We evaluated other options before choosing Splunk Enterprise Security, including Kibana, Dynatrace, and Datadog.

    What other advice do I have?

    I would say to do a lot of homework in researching the different tools and modules within Splunk Enterprise Security. Splunk Enterprise Security is obviously very essential and is the heart of Splunk, but all of the other tools that are available, such as SOAR and RUM, are important, so identify exactly what your enterprise needs and map that to the different Splunk modules to make sure that you are getting as much as you can from Splunk. I provided this review with a rating of 9.

    Which deployment model are you using for this solution?

    Private Cloud

    If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

    Other
    Disclosure: My company does not have a business relationship with this vendor other than being a customer.
    Last updated: Sep 17, 2026
    Flag as inappropriate
    PeerSpot user
    Senior Vice President Cyber Security at Mindsprint
    Real User
    Top 5
    Jul 13, 2026
    Extensive integrations have enabled real-time threat detection and continuous security monitoring
    Pros and Cons
    • "Splunk Enterprise Security's biggest advantage is the ecosystem, as the large ecosystem can detect threats from a variety of devices, including firewalls and antivirus software, and because it has many built-in rules for detection already, I do not write many playbooks from scratch, which helps me get started on threat detection faster and enables me to predict, identify, and solve problems in real time so security incidents can be prevented."
    • "From a pricing perspective, the costs have become higher, as I understand from our procurement team."

    What is our primary use case?

    I work with Splunk as a service provider as well as a customer because we use Splunk internally.

    This is used to run the Security Operation Center to conduct 24/7 monitoring for any security alerts and incidents for our use cases and use cases for our clients.

    We do use some disparate security products that integrate or import data into Splunk. We have integrated Splunk with many threat intelligence sources, including external threat intelligence sources. We have a direct Splunk integration with CrowdStrike, and we have many other integrations with Splunk itself.

    We have integrated Splunk with many log sources, including firewalls and other devices. From those firewalls and log sources, we have configured alerting in our Splunk environment. This helps us in detecting and alerting any security incidents.

    What is most valuable?

    Splunk Enterprise Security's biggest benefit is the ecosystem itself. It has many connectors and plugins built-in, which provides all those capabilities as part of its ecosystem.

    I have a very positive impression of the process for customizing, developing, testing, deploying, and refining detections in Splunk Enterprise Security. The alerting part does support our SOC.

    Splunk Enterprise Security's biggest advantage is the ecosystem. The large ecosystem can detect threats from a variety of devices, including firewalls and antivirus software. Because Splunk Enterprise Security has many built-in rules for detection already, I do not write many playbooks from scratch. Splunk Enterprise Security has many detection rules that are already provided, which helps me get started on threat detection faster. This is due to two primary reasons: the large ecosystem, by which Splunk can integrate with many varieties of devices, and Splunk Enterprise Security, which has many built-in rules that help me detect threats.

    It helps me predict, identify, and solve problems in real-time, which helps me detect threats in real-time and then take action faster. Because of this, any security incidents can be prevented.

    What needs improvement?

    There are two parts to consider for areas of improvement. One, especially after the Cisco acquisition, is from a pricing point of view. From a pricing perspective, the costs have become higher, as I understand from our procurement team. The other area is from a support perspective. Support has declined, but it is starting to improve again, though it still could be better.

    For how long have I used the solution?

    I have used Splunk for eight years.

    How was the initial setup?

    I find the installation part quite straightforward.

    What was our ROI?

    There is no quantification of time-saving or money-saving benefits of Splunk because it is more focused around threat detection itself.

    What's my experience with pricing, setup cost, and licensing?

    It is worth buying the product, definitely, because no other vendor supports the kind of integrations that Splunk supports, even though the price is a little on the higher side.

    What other advice do I have?

    The biggest piece of advice I would say to people looking to use Splunk Enterprise Security in the future is to check the compatibility with the ecosystem of products they are using within the enterprise or within their own business, and see if it is supported by Splunk Enterprise Security. Because if they use a firewall which is not supported by Splunk Enterprise Security, then it will become a challenge in detecting any threats on the firewall because the logs cannot be ingested or consumed by Splunk Enterprise Security. The most important thing is to check their ecosystem and whether Splunk Enterprise Security supports logs from their ecosystem. I rate this product an 8 overall.

    Which deployment model are you using for this solution?

    On-premises

    If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

    Other
    Disclosure: My company has a business relationship with this vendor other than being a customer. MSP
    Last updated: Jul 13, 2026
    Flag as inappropriate
    PeerSpot user
    AmanThakkar - PeerSpot reviewer
    Software Engineer at Titanslab Inc.
    Real User
    Top 5Leaderboard
    Jun 19, 2026
    Centralized logging has simplified root-cause analysis and improves productivity across apps
    Pros and Cons
    • "Managing logs is very easy with Splunk Enterprise Security."
    • "One thing I would like to see improved in Splunk Enterprise Security is a better user manual."

    What is our primary use case?

    Our main use cases for Splunk Enterprise Security are to find the root cause of any applications, to see the dashboards, to see the logs, and to centralize some logging systems.

    What is most valuable?

    Managing logs is very easy with Splunk Enterprise Security. Earlier, we were using DataDog and before that, we were also using our own tool, 24/7, to maintain logs and everything. In that, we faced many issues maintaining logs from many applications because we are managing many applications right now. So it was very tough, and when we were introduced to Splunk Enterprise Security, we used it, and it became very easy to maintain. It is easy to have control over it.

    The main benefits I have seen from using Splunk Enterprise Security are mainly two things: the pricing and the manpower. Right now, we do not have to worry about the time if we encounter any issues. Recently, one of our customers raised an issue that the application was running very slow. Earlier, we had issues like that, but at that time we had to do so much manual checking everywhere to find the issue. Right now, if we get an issue regarding this, it is very easy to understand the root cause.

    What needs improvement?

    One thing I would like to see improved in Splunk Enterprise Security is a better user manual. Right now, it is pretty tough for any newcomer or new user to understand everything because there are no specific areas for them to learn from.

    From a features perspective, an enhancement I would like to see is a better learning aspect. The AI feature is great, but I believe enhancing the learning part for any new user would be beneficial.

    For how long have I used the solution?

    We have been using Splunk Enterprise Security products for the last eight to nine months, but I have been onboarded on this in the last six months.

    What do I think about the stability of the solution?

    The stability, reliability, and performance of Splunk Enterprise Security are pretty good. Now we are very stable with many production systems, and Splunk Enterprise Security is also scalable if we want to expand further.

    How are customer service and support?

    I would evaluate the tech support team as good.

    Which solution did I use previously and why did I switch?

    I previously used different products and solutions like in-house technologies and DataDog.

    How was the initial setup?

    The initial setup process for Splunk Enterprise Security was somewhat challenging. As I mentioned, it lacks a specific user manual, making the initial setup tough, but now we are hands-on and comfortable with it.

    What was our ROI?

    Regarding ROI, while I cannot speak specifically about the investment, I can say that the returns are good. We achieve one hundred percent productivity utilizing Splunk Enterprise Security to create multiple dashboards and find various issues.

    What's my experience with pricing, setup cost, and licensing?

    On the pricing aspect, I find the setup cost and licensing of Splunk Enterprise Security to be relatively cheaper compared to what we used earlier. I can say that what we are paying is worth it based on the value we receive.

    Which other solutions did I evaluate?

    We decided to switch to Splunk Enterprise Security because of the ecosystem. We are also using Splunk Cloud, and we have a good relationship with Splunk. The pricing compared to what we were using earlier is worth it.

    The key differences, apart from pricing, are the visibility and observability. We did not get good visibility with the previous tools, but now we have a very clear view, which is why we switched to Splunk Enterprise Security.

    What other advice do I have?

    My advice for anyone considering Splunk Enterprise Security is to understand the basics of logging systems first and determine your use cases before building specific functionalities in Splunk Enterprise Security.

    We have recently upgraded to Splunk Enterprise Security 8.0, and we are evolving everything now. We are evolving frameworks and many other things within it. I would rate this review an 8.5 overall.

    Which deployment model are you using for this solution?

    On-premises

    If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

    Other
    Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
    Last updated: Jun 19, 2026
    Flag as inappropriate
    PeerSpot user
    Vaibhav Mahendra Kolhe - PeerSpot reviewer
    Soc Analyst at Softcell Technologies Limited
    Real User
    Top 5
    May 24, 2026
    AI-driven threat detection has transformed investigations and reduces false positives for analysts
    Pros and Cons
    • "The AI-driven detections have improved the accuracy of my investigations significantly, reduced my mean time to detection by about 30 percent and my mean time to resolution by about 40 percent, and contributed to faster, more efficient threat detection compared to other SIEM tools I have used."
    • "I rate the technical support of Splunk Enterprise Security as a three. I find it not good because whenever I raise a ticket, they take a very long time."

    What is our primary use case?

    Splunk Enterprise Security is mainly used for detecting and monitoring log analysis, threat detection, and incident investigation. It is primarily used for failed login detection where multiple login failed attempts occur from the same source IP. Brute force attacks are another common use case. Splunk Enterprise Security use cases can be extended through visualization on data dashboards, setting incident triage, and Windows event log analysis in SOC environments. I use it from a SIEM perspective in my organization.

    What is most valuable?

    The best features of Splunk Enterprise Security are that it is the leading platform in cybersecurity right now in SOC environments. Business resilience is very useful for real-time monitoring and investigation, which improves our business resilience.

    The AI-driven detections have improved the accuracy of my investigations significantly. I have worked with two other SIEM tools: Wazuh and Azure Microsoft Sentinel. Compared to both, Splunk AI is very good. When we mark an alert as a false alert, Splunk Enterprise Security automatically detects it as a false positive. Whenever another similar alert comes through, it automatically takes action, so we will not get that alert on our dashboard again. It automatically handles false positive alerts, preventing clutter on our dashboard.

    It has reduced my mean time to detection (MTTD) by about 30 percent and my mean time to resolution (MTTR) by about 40 percent. Our SLA has reduced from fifteen minutes to ten minutes, which is very helpful because we are raising alerts within ten minutes.

    Risk-based alerting provides significant value. When we raise an alert, we provide the incident classification as either true positive or false positive in Splunk and also in the ticketing tool. If an alert is a false positive, Splunk's AI takes care of this and tells us whether we want this alert to show to the SOC team or not. The decision depends on AI analysis.

    The assessment of the threat topology and the MITRE ATT&CK framework in Splunk shows that Splunk already maps MITRE ATT&CK with incidents. Whenever an alert comes, the AI configures it to that framework. For investigation purposes, I check the process tree to see how the alert originates and where the malware is going to end. This is very good for threat investigation.

    Splunk Enterprise Security has become at least forty to fifty percent faster at detecting threats compared to Azure Sentinel. It is very fast for detecting alerts.

    It has contributed to the reduction of analyst burnout and fatigue because it reduces our alerts. If we raise an alert on Splunk, it takes care of them through AI. False positive alerts will not show up, preventing mess for our team. Our threat hunting team and forensic team handle the true positive alerts, while false positives are automatically taken care of by AI.

    When comparing Splunk with other vendors, I find that Splunk use cases have more power to detect alerts. Azure Microsoft Sentinel has inbuilt over two hundred use cases analytics for their team only, and we cannot create more customized use cases. In Splunk, we can create additional customized use cases, plus there is AI for detection. If we miss some use cases for any logs or events, AI takes care of it and creates its own use case, showing alerts for us. The dashboard is also very user-friendly compared to both.

    What needs improvement?

    Areas that have room for improvement in Splunk Enterprise Security include user access. When we give access to a new user, it becomes difficult for them to log in and understand the interface. It would be beneficial if there is a demo for L1 users. I also see improvement needed in integration. Currently, we have to manually integrate devices, but I would like AI to take care of it, similar to how SentinelOne operates. This would make the process smoother.

    For how long have I used the solution?

    My experience using the solution has been two years.

    What do I think about the stability of the solution?

    Stability-wise, Splunk Enterprise Security is very good. I have not experienced any significant performance issue or downtime.

    What do I think about the scalability of the solution?

    I rate the scalability of Splunk Enterprise Security as an eight. It depends on how stable and scalable you manage Splunk Enterprise Security for your organization.

    How are customer service and support?

    I rate the technical support of Splunk Enterprise Security as a three. I find it not good because whenever I raise a ticket, they take a very long time. Even if I call the toll-free number, tickets are pending.

    Which solution did I use previously and why did I switch?

    I have worked with two other SIEM tools: Wazuh and Azure Microsoft Sentinel. The AI-driven detections have improved the accuracy of my investigations significantly compared to these solutions.

    How was the initial setup?

    It is very easy to deploy Splunk Enterprise Security compared to both other SIEM tools. Splunk connector is very easy to set up.

    The time it takes to install depends on whether we are installing on a Windows or Linux machine or the size of the organization. For a moderate-level company, it usually takes around five days to install everywhere the connectors and endpoints.

    What about the implementation team?

    When it comes to upgrading Splunk Enterprise Security to version eight point zero, I have a team that handles the upgrade, and it is basically easy to upgrade the version.

    What was our ROI?

    Combining SIEM, SOAR, and UEBA into a single interface has improved my operational efficiency significantly. Before we integrated SOAR, we usually took fifteen minutes to raise SLA alerts. For analysis, L1 would take ten to twelve minutes to decide if they wanted to raise an alert or not. With SOAR, we have predefined playbooks, so if any inbound connection happens from a malicious IP, it automatically blocks on the firewall. We handle most alerts through SOAR now, which allows us to focus on the more significant incidents like malicious attacks, effectively reducing our response time.

    What's my experience with pricing, setup cost, and licensing?

    Regarding the pricing of Splunk Enterprise Security, I would say it is very expensive for our organization compared to the two others. Wazuh is open-source, and for SentinelOne, we are a partner with Microsoft, but Splunk has a high cost for setup, which is based on the EPS count and storage.

    Which other solutions did I evaluate?

    When comparing Splunk with other vendors, I find that Splunk use cases have more power to detect alerts. Azure Microsoft Sentinel has already inbuilt over two hundred use cases analytics for their team only, and we cannot create more customized use cases. In Splunk, we can create additional customized use cases, plus there is AI for detection. If we miss some use cases for any logs or events, AI takes care of it and creates its own use case, showing alerts for us. The dashboard is also very user-friendly compared to both.

    What other advice do I have?

    9

    Which deployment model are you using for this solution?

    On-premises

    If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

    Disclosure: My company has a business relationship with this vendor other than being a customer. MSSP
    Last updated: May 24, 2026
    Flag as inappropriate
    PeerSpot user
    reviewer2899158 - PeerSpot reviewer
    Sr manager cybersecurity at a transportation company with 10,001+ employees
    Real User
    Top 20
    Sep 16, 2026
    Incident response has gained visibility and speed but navigation and pricing still need improvement
    Pros and Cons
    • "Splunk Enterprise Security has positively impacted my organization by being able to respond faster and track down exactly what has happened."
    • "Customer support has been quite poor until recently, but they have been improving."

    What is our primary use case?

    My main use case for Splunk Enterprise Security is visibility. I use Splunk Enterprise Security for visibility specifically for the IR team for cybersecurity incidents. Splunk Enterprise Security helps my incident response team detect and manage cybersecurity incidents by being the only tool they use for finding incidents.

    How has it helped my organization?

    Splunk Enterprise Security has positively impacted my organization by being able to respond faster and track down exactly what has happened.

    With the correlation and the alerting in Splunk Enterprise Security, we are able to respond faster than we had before when we were unable to have dashboards that show us what was going on.

    Splunk Enterprise Security has helped improve my organization's business resilience, and it helps the IR analysts do their jobs.

    Splunk Enterprise Security has helped reduce my team's average mean time to resolve, MTTR metric, by 25%.

    What is most valuable?

    The best feature Splunk Enterprise Security offers is the correlation of logs. The correlation of logs stands out for my team because in incident triage, it is able to help us identify what had happened.

    What needs improvement?

    I cannot think of any improvements for Splunk Enterprise Security at the moment. I would like to add that I am not a fan of the new UI. I find the new UI challenging because it takes much more searching to find everything that you need; they introduced it all at once instead of gradually introducing it.

    For how long have I used the solution?

    I have been using Splunk Enterprise Security for 5 years.

    What do I think about the stability of the solution?

    Splunk Enterprise Security is stable.

    What do I think about the scalability of the solution?

    The scalability of Splunk Enterprise Security is fine.

    How are customer service and support?

    Customer support has been quite poor until recently, but they have been improving. I would rate the customer support a five on a scale of 1 to 10.

    Which solution did I use previously and why did I switch?

    We previously used a different solution; it was a managed solution and we wanted something that was ours.

    How was the initial setup?

    Splunk Enterprise Security is deployed in my organization through Splunk Cloud.

    What about the implementation team?

    I am not currently using RBA at the moment, so I cannot describe how Splunk Enterprise Security's risk-based alerting has impacted my alert volume and analyst productivity. I am not currently using the threat topology or MITRE ATT&CK framework features for helping discover the overall scope of an incident. The integration of threat intelligence directly into the TDIR workflow has not improved my ability to preemptively block threats. I am not a user of SOAR, so I cannot assess how the consolidation of SIEM, SOAR, and UEBA into a single interface has improved my team's operational efficiency.

    What was our ROI?

    I have saved time but have not seen true savings in investment.

    What's my experience with pricing, setup cost, and licensing?

    I find the licensing and pricing a bit much being a cloud client.

    Which other solutions did I evaluate?

    Before choosing Splunk Enterprise Security, I did not evaluate other options.

    What other advice do I have?

    I have no problems with Splunk Enterprise Security's AI capabilities regarding its governance and security; I think it is actually good. Regarding the accuracy and reliability of output, Splunk Enterprise Security seems to be right on. I am not using RBA at the moment, so I cannot describe how Splunk Enterprise Security's risk-based alerting has impacted my alert volume and analyst productivity. I give this review a rating of 7.

    Which deployment model are you using for this solution?

    Public Cloud

    If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

    Disclosure: My company does not have a business relationship with this vendor other than being a customer.
    Last updated: Sep 16, 2026
    Flag as inappropriate
    PeerSpot user
    Priyanshu-Singh - PeerSpot reviewer
    Soc Analyst Trainee at Softcell Technologies Limited
    Real User
    Top 5
    Jun 30, 2026
    Advanced threat detection has reduced alert fatigue and improves faster incident response
    Pros and Cons
    • "Over the course of using Splunk Enterprise Security, it has helped us grow our business and attract more clients due to its low mean time to respond and various analytic engines that help us address threats daily, resulting in positive customer feedback and satisfaction."
    • "There is not much to improve in Splunk Enterprise Security, but points such as deep learning and writing complex queries can be time-consuming, and managing multiple correlation rules can become complex over time, especially with high volumes of log data that can affect performance."

    What is our primary use case?

    I am still working with Splunk Enterprise Security. We are a reseller of Splunk Enterprise Security, providing it to our customers.

    On a daily basis, we use Splunk Enterprise Security for advanced threat and ransomware detection, providing it to our customers for threat detection and ransomware detection, as well as for detecting insider threat anomalies and for continuous monitoring and log analysis.

    We provide Splunk Enterprise Security both internally as we are an MSSP, managing our customers and our internal operations.

    Splunk Enterprise Security Essentials has contributed to a reduction in analyst burnout or fatigue by addressing the issue of receiving thousands of alerts, with nearly half being false positives, which creates a psychological burden and desensitizes analysts to warnings.

    The integration of threat intelligence directly into our TDIR workflow helps us identify false IOCs based on external data, normalizing and correlating it with our internal networks, with Splunk Enterprise Security operationalizing TI feeds through highly structured workflows that manage multiple threat feeds effectively.

    Over the course of using Splunk Enterprise Security, it has helped us grow our business and attract more clients due to its low mean time to respond and various analytic engines that help us address threats daily, resulting in positive customer feedback and satisfaction.

    What is most valuable?

    The most useful features of Splunk Enterprise Security are the data handling, schema flexibility, correlation rules, threat detection engines, and log search capability, which makes it easy to find logs among lots of data, as well as customizable dashboards and risk-based alerting, among other features.

    These features are valuable because they help us daily find logs related to our customer requirements and provide reports based on that, making it easier to find data for devices such as networks and Windows.

    The most benefits from using Splunk Enterprise Security are the drastic reduction in alert fatigue, rapid incident triage, the ability to find a particular log for specific devices, unified security workflows, data flexibility, instant mapping to security frameworks, and correlation rules, along with anomaly-based rule detection and threat hunting that help us on a daily basis.

    These benefits are very important for my users, as they help us and our customers secure our infrastructure from unauthorized access and detect spoofing, phishing, and all types of attacks, allowing us to identify vulnerabilities and patch them before exploitation.

    What needs improvement?

    There is not much to improve in Splunk Enterprise Security, but points such as deep learning and writing complex queries can be time-consuming, and managing multiple correlation rules can become complex over time, especially with high volumes of log data that can affect performance.

    For how long have I used the solution?

    I have been using Splunk Enterprise Security for almost three years.

    What do I think about the stability of the solution?

    Regarding stability, we have not faced significant challenges with Splunk Enterprise Security so far, though we have had some minor issues due to service failures, which were resolved without major threats. Its reliability is strong, especially after the visual redesign that helps prevent critical signals from getting lost.

    What do I think about the scalability of the solution?

    I rate the scalability of Splunk Enterprise Security as nine out of ten based on my use cases and observations.

    How are customer service and support?

    My experience communicating with technical support has been very good, as we quickly receive resolutions from them.

    Which solution did I use previously and why did I switch?

    The AI-driven detections and assistance have improved the accuracy of my investigations.

    Splunk Enterprise Security is very helpful in triaging and raising alerts before they reach SLA times, which helps us reduce the mean time to respond.

    I estimate that we have reduced the mean time to resolve by around 40 to 70%.

    Splunk Enterprise Security has helped reduce my team's average mean time to detect by around 50 to 70%, overall for threat detection and alert detection.

    Regarding risk-based alerting, it helps us identify true positives and false positives, effectively eliminating alert fatigue; we rarely get false positive alerts, as RBA assigns a risk score to user devices and alerts analysts only when an asset accumulates enough risk score from different systems, exposing advanced persistent threats that traditional SIEM rules miss.

    The threat topology or MITRE ATT&CK framework features help us easily identify unauthorized persons and attackers' tactics and techniques used to gain unauthorized access to our data center, making it easy to analyze active correlation rules and identify blind spots.

    Splunk Enterprise Security helps us detect threats faster due to its advanced rule-based alerting and anomaly detection, allowing us to catch threats before they impact our services and servers.

    I estimate that we can detect threats about 30 to 40% faster compared to traditional SIEM services.

    How was the initial setup?

    I participated in the initial setup of Splunk Enterprise Security, working with numerous device installations in Wazuh and Splunk Enterprise Security, including network devices, servers, and cloud services.

    To set up Splunk Enterprise Security, we need to install Splunk Enterprise Security on the server, share logs with the forwarder, and then receive logs from the forwarder.

    I faced some challenges specifically with the AWS integration during the initial setup.

    Which other solutions did I evaluate?

    I did not participate in the decision-making process for Splunk Enterprise Security, but I highly suggested it for small businesses seeking a low-cost solution.

    I did not have any other options besides Splunk Enterprise Security.

    What other advice do I have?

    I consider Splunk Enterprise Security to be an affordable solution given the capabilities it offers; for organizations with predictable data environments wanting certainty in cost, it is a worthwhile investment. I rate this review as a nine out of ten overall.

    If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

    Amazon Web Services (AWS)
    Disclosure: My company has a business relationship with this vendor other than being a customer. partner
    Last updated: Jun 30, 2026
    Flag as inappropriate
    PeerSpot user
    Buyer's Guide
    Download our free Splunk Enterprise Security Report and get advice and tips from experienced pros sharing their opinions.
    Updated: August 2026
    Buyer's Guide
    Download our free Splunk Enterprise Security Report and get advice and tips from experienced pros sharing their opinions.