No more typing reviews! Try our Samantha, our new voice AI agent.
Kevin Muriithi - PeerSpot reviewer
Technical Lead at a tech services company with 11-50 employees
Real User
Top 20
Sep 16, 2026
Custom rule capabilities have delivered early threat detection and reduced analyst alert noise
Pros and Cons
  • "Splunk Enterprise Security positively impacts our organization and clients mainly through early detections in the security landscape, allowing us to detect vulnerabilities and intrusions much earlier than previously undetected issues."
  • "I believe the areas of improvement for Splunk Enterprise Security would focus on resource utilization."

What is our primary use case?

My main use case for Splunk Enterprise Security is for detections.

A specific example of how I use Splunk Enterprise Security for detections involves VPN use cases, where we deal with clients who have numerous third-party vendors supported on VPN, leading to scenarios where users might share their VPN credentials, allowing access from disparate geographical locations. Splunk Enterprise Security is particularly effective at detecting these logins from different locations over a short period and alerting on these events, indicating users who are sharing their credentials.

There are quite many use cases, and some are user-customizable; for instance, we might have someone wanting to know which users got SSH access to servers over working hours or who is accessing RDP outside of working hours. We usually cover traditional brute force attacks and network intrusions within the rules that we enable.

What is most valuable?

The best features that Splunk Enterprise Security offers include easy customization of the rules and a pool of out-of-the-box rules, where creating customizable rules is quite user-friendly and easily achievable without a lot of complexity and required technical knowledge.

The easy customization of rules has helped my team and clients significantly, such as when customers migrate from older SIEMs and request that their previous rules and shortcomings be translated into Splunk Enterprise Security. We are able to create correlation searches within a few hours to achieve the necessary thresholds and supplement what was missing in their previous deployments. Basically, whatever a user can think of, we can translate it into a detection rule, allowing the customer to gain value.

The richness of those rules significantly benefits us when dealing with customers, as it is not a one-size-fits-all model. We have different customizations for different technology layers, so if there are detections tailored to AWS, we do not enable those for customers who are not using AWS, which makes the environment quite efficient.

Splunk Enterprise Security positively impacts our organization and clients mainly through early detections in the security landscape, allowing us to detect vulnerabilities and intrusions much earlier than previously undetected issues. Clients can comply with regulations, act on the detections within their environment, and gain actionable insights. Additionally, there is a minimization of alert load through the risk-based alerting system, which significantly reduces the alert noise for analysts, enhancing their overall work efficiency.

What needs improvement?

I believe the areas of improvement for Splunk Enterprise Security would focus on resource utilization. For smaller environments lacking adequate CPU and memory resources, the system tends to be laggy, so reducing resource consumption would greatly improve experiences in most customer environments.

The usability of the solution is well built, and the interface is intuitive, so there are few improvements to suggest apart from implementing multi-tenancy, which is a frequent request we receive, especially from regional banks managing different branches under varying administrative controls.

For how long have I used the solution?

I have been using Splunk Enterprise Security for coming up to five years now.

Buyer's Guide
Splunk Enterprise Security
August 2026
Learn what your peers think about Splunk Enterprise Security. Get advice and tips from experienced pros sharing their opinions. Updated: August 2026.
914,109 professionals have used our research since 2012.

What do I think about the stability of the solution?

Splunk Enterprise Security is stable.

What do I think about the scalability of the solution?

Its scalability is impressive, especially when utilizing a multi-site search head cluster; we encounter no challenges scaling the solution.

How are customer service and support?

Customer support is excellent, with same-day responses to our opened tickets and a quick turnaround for out-of-the-box support queries.

Which solution did I use previously and why did I switch?

Previously, we used ArcSight, but we switched to Splunk Enterprise Security mainly due to the limitations of the ArcSight solution in adapting to the changing security landscape.

What was our ROI?

We have observed a return on investment in terms of turnaround time for incident investigations and a reduction in the number of engineers required to manage the system; where three agents were once necessary, tasks are now comfortably handled by two, though we typically maintain two for high availability.

What's my experience with pricing, setup cost, and licensing?

The most significant impact we see relates to license costs. While implementation and setup costs are manageable since we provide those services, the license expense is the primary cost concern.

Which other solutions did I evaluate?

Before choosing Splunk Enterprise Security, we evaluated other options, including FortiNet FortiSIEM and IBM QRadar.

What other advice do I have?

My advice for others considering Splunk Enterprise Security is to try it out, prepare definitive data sources, narrow down on the use cases they want to address, and focus on ensuring data availability to support those use cases.

I want to appreciate the effectiveness of Splunk Enterprise Security, how well it is designed, and its capability to meet customer objectives. I would rate this product a 9 out of 10.

Which deployment model are you using for this solution?

Private Cloud
Disclosure: My company has a business relationship with this vendor other than being a customer. Reseller
Last updated: Sep 16, 2026
Flag as inappropriate
PeerSpot user
Niranjan Narasaiah - PeerSpot reviewer
Security Delivery Senior Analyst at Accenture
Reseller
Top 20
Jul 1, 2026
Advanced analytics have boosted investigations and consistently improve incident response speed
Pros and Cons
  • "Splunk Enterprise Security's risk-based alerting positively impacts my alert volume and analyst productivity because we get low, medium, and high-security alerts based on the use cases driven in Splunk Enterprise Security, and we receive good feedback from clients regarding our productivity as we consistently resolve incidents meeting SLA, resulting in increased client satisfaction with our team and work over the past two to three years."
  • "In my opinion, improvements in Splunk Enterprise Security could address the issue of unnecessary alerts. Sometimes we receive many false positives, leading to difficulties in identifying real security incidents."

What is most valuable?

For search queries in Splunk Enterprise Security, we can build our deep-dive investigations as it will not be too complex. We can find L2 and L3 level investigations. In the initial stages, if we do not find any trace of an alert, malware, or any kind of malicious activity, we can dig into the investigation with the help of queries. Overall, dashboards help as well. For example, we can find O365 authentication activities and deauthentication, which lets us see different locations where the user is logged in and whether they are using a VPN or not. If they log in with a VPN IP, it shows a different location. We can monitor authentication activities for normal users and create dashboards for them. Splunk Enterprise Security also allows us to investigate suspicious emails and blacklisted IP traffic, making it an excellent feature for malware investigation and network traffic analysis.

The AI-driven detections and assistance in Splunk Enterprise Security have improved the accuracy. Recently, I have integrated a copilot with Microsoft Teams for AI investigations. I use it when I cannot find information in the basic data. For example, if I provide the use case name, it gives information about the overall picture of the alert activities. We have to check user logs for any activities that happened on a host or if a suspicious user has logged into an AD account, including any changes to paths or modifications to files. This kind of investigation can be facilitated with AI in Splunk Enterprise Security.

Regarding whether Splunk Enterprise Security has helped reduce my team's average mean time to resolve issues, I can say that it almost resolves incidents within one hour. It depends on the clients, with a mean time of approximately thirty minutes for low alerts and up to six hours for high-security alerts. We must follow our SLA for any particular alert.

I can say that the average mean time to detect specific attacks with Splunk Enterprise Security is around five to six minutes or seven minutes, and under specific conditions, it can be eight minutes. For top security incidents, we can detect within under sixty minutes using a formula: alert time minus activity start time divided by the number of incidents.

Splunk Enterprise Security's risk-based alerting positively impacts my alert volume and analyst productivity because we get low, medium, and high-security alerts based on the use cases driven in Splunk Enterprise Security. We receive good feedback from clients regarding our productivity, as we consistently resolve incidents meeting SLA, resulting in increased client satisfaction with our team and work over the past two to three years.

The MITRE ATT&CK framework features are beneficial for helping discover the overall scope of incidents because we have integrated it into our use cases within Splunk Enterprise Security. It helps to map various attacks such as persistence, brute-force attacks, and blacklisted IP activities. We follow the process of incident response and the MITRE framework to investigate alerts effectively.

Splunk Enterprise Security Essentials contributes to reducing analyst burnout or fatigue because we have mapped it with the MITRE framework and the Cyber Kill Chain. This integration leads to more detections and helps mitigate numerous malware and security alerts, thus improving productivity and creating a healthier work environment.

What needs improvement?

In my opinion, improvements in Splunk Enterprise Security could address the issue of unnecessary alerts. Sometimes we receive many false positives, leading to difficulties in identifying real security incidents. We could reduce alerts for scheduled activities to lessen our workload because, in a set of one hundred alerts, perhaps only one is a security incident, which we may miss amidst all the noise. Filtering and sorting are time-consuming but necessary, as seen in other SIEM tools like IBM QRadar and ArcSight. However, I still believe Splunk Enterprise Security is superior, considering my experience over several years.

Pricing for Splunk Enterprise Security is high, but I do not have in-depth knowledge as that is managed by higher management. I cannot provide a convincing answer since negotiations are typically handled by them.

For how long have I used the solution?

I have more than three years of experience in Splunk.

How are customer service and support?

I rate the technical support by Splunk as a perfect ten out of ten. I always receive support when needed, and while it may take time due to their workload, the results are assured and accurate based on my needs and thought processes.

How was the initial setup?

The initial setup of Splunk Enterprise Security is straightforward as it involves following the architecture of cloud deployment, with forwarders and security devices integrated by the client. We propose use cases for future attacks, but the deployment issues are managed by the client, while our role is providing SOC incident response services from India.

Which other solutions did I evaluate?

I believe Splunk Enterprise Security is one of the best options currently available in the market. While I see competitors like Sentinel emerging, Splunk Enterprise Security remains a top choice, alongside others like QRadar, ArcSight, and ELK tools such as Elastic, Logstash, and Kibana.

What other advice do I have?

Splunk Enterprise Security helps improve my organization's business resilience as I have almost two and a half years completed in Accenture. The client is most satisfied, and our team has consistently received appreciation for our work. We have not caused any security breaches and continue to see good results quarterly over the last two years.

The integration of threat intelligence directly into the TDIR workflow improves my ability to preemptively block threats because we receive weekly emails from our Threat Intelligence team with CVEs or IOCs. We add those IOCs to Splunk Enterprise Security to mitigate potential attacks. Recently, due to higher cyberattacks stemming from events in Iran and the USA, we have created use cases to monitor several IOCs every two hours, which is still ongoing.

In the future, I would like to see artificial intelligence integrated into Splunk Enterprise Security. I am uncertain about costs, but such integration could enhance functionality, much like in my previous project where alerts from Splunk Enterprise Security directly integrated into ServiceNow facilitated quicker responses. Reducing false positive alerts would also be beneficial to streamline our process, as we sometimes deal with hundreds of alerts, causing strain on resources. I would rate this product overall as a nine out of ten.

Which deployment model are you using for this solution?

Hybrid Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Other
Disclosure: My company has a business relationship with this vendor other than being a customer. Reseller
Last updated: Jul 1, 2026
Flag as inappropriate
PeerSpot user
Buyer's Guide
Splunk Enterprise Security
August 2026
Learn what your peers think about Splunk Enterprise Security. Get advice and tips from experienced pros sharing their opinions. Updated: August 2026.
914,109 professionals have used our research since 2012.
reviewer2778402 - PeerSpot reviewer
Systems Development Engineer at a tech vendor with 10,001+ employees
Real User
Top 20
Nov 30, 2025
Supports real-time detection and response through flexible data ingestion and adaptable workflows
Pros and Cons
  • "What Splunk does, and really is why it is a choice platform, is that it speaks all of those languages, no matter what IT discipline you are in."
  • "The biggest thing with Splunk is making sure that the documentation is maintained."

What is our primary use case?

Splunk Enterprise Security use cases drive the workflow from threat detection all the way through to incident response, giving an approach mirrored with technology. Depending on use cases, whether having a tool drive some approach or conducting discovery, or looking to facilitate an operational security operations role at your company, it is very much driven heavily on the scheduler, setting things up and then looking and deep diving when necessary. Splunk Enterprise Security does well by giving a good framework.

Risk-based alerting is enabled in Splunk Enterprise Security. However, because of custom applications, a lot of times it works but doesn't work. Some discovery on our own is required, conducting our own campaigns to do that.

The time it takes the SecOps team to remediate any security incidents with Splunk Enterprise Security depends on the situation. Splunk skips over the whole trying to figure out how to use the tool. That is the biggest thing. Using Elastic SIEM and using other SIEMs, there is a learning curve, whereas with Splunk Enterprise Security, even if there is no one on the team who has mastery in Splunk, there is enough support and enough tooling and things that people have done before to really deep dive right in immediately.

Splunk Enterprise Security helps tell a story and helps focus at the customer level. As a managed service provider, I can only speak from the security side of it.

As a managed service provider, consolidating networking, security, and IT observability tools with Splunk Enterprise Security can be difficult, especially when providing those tools yourself. What Splunk does, and really is why it is a choice platform, is that it speaks all of those languages, no matter what IT discipline you are in. You are able to surface and view data in a quantitative manner and also get insights into what you are looking for. That is a very strong aspect of a tool where it does consolidate.

What is most valuable?

Splunk Enterprise Security has helped mainly when it comes down to the data science part. If you have a strong data science background, it is easy to detect anomalies. Some of the toolkits that are deployed with Splunk Enterprise Security and ML Toolkit allow you to do a lot more upfront than you typically would be able to do.

Splunk Enterprise Security has helped to improve the ability to ingest and normalize data.

The impressions of Splunk Enterprise Security's ability to identify and solve problems in close to real-time are that the different ingest methods that it provides are critical to finding out and looking at the breadth of data that comes in through machine data. In some parts, some people call them logs, some people call them metrics, some people call it telemetry. Having an aggregator at the ingest level like Splunk is amazing because it does not matter what you want to send, you can send it. It does not need to be in a particular format. A lot of the data brought in is not log data, it is programmatic from APIs and customer activity and things that need to be looked at as a whole picture. So when it comes to security, to be able to look at that in real-time requires compute and less structure because you need to be able to see there are payloads coming in that are typically not in this correct format, and the tool should not miss that because fields are not necessary. Splunk's ability to do schema on search is immensely powerful and that does aid in the ability to get results faster.

Threat topology and the MITRE ATT&CK framework features for helping discover the overall scope of an incident in Splunk Enterprise Security are pretty good. In this particular discipline when it comes to security, applying knowledge and then having a tool support that knowledge and drive forward, the integration paths of those particular types of things are very helpful. The more data that you bring in across your topology, if you will — network, user activity, user behavior activity, authentication, and application errors — you get this full landscape that you can see. With that, if a type of MITRE ATT&CK comes along and you understand what it is, you can see where the attack entry point was, the activity that was performed, and then start the incident response.

What needs improvement?

The biggest thing with Splunk is making sure that the documentation is maintained. There is a gap where if you search for an issue, a lot of times it is in the community. There should be a path that moves community answers into documentation or into an FAQ that allows people to not use the community answers to drive results. For instance, when you can use Splunk this way and this solves your problem, but if there is a better solution, that should be presented as an FAQ. Just working with Splunk for an immense amount of years, it is usually necessary to try to figure something out. The docs tell you where you can figure it out, as in a configuration file, but it does not really help you get to the end result. More complete documentation would be beneficial.

What do I think about the stability of the solution?

There has never been any instability with Splunk Enterprise Security. Some core dumps appear from time to time, but it really depends on your architecture. If you are really good at architecting Splunk, you should not ever run into that. Splunk is solid, and that is almost a ten.

What do I think about the scalability of the solution?

Splunk Enterprise Security's scalability is huge. If you were to take one thing from Splunk that is probably really amazing, it is the scalability. With a handful of users now, coming from a shop where there were 5,000-plus users in Splunk and it was pretty stable, the scalability is immense. It is one of the things that separates it from other tooling, and if not, it is the most scalable solution out there.

How are customer service and support?

Technical support or customer support at Splunk has been contacted.

The quality and speed of the support at Splunk are interesting. As an expert in the field, the work is really far beyond what customer support can probably handle. They are pretty good when it comes to that, especially if you have a Sev 1 ticket. The support team overall at Splunk, the people that have been interacted with, are fine, but typically if there is a problem, someone like a specialist needs to be spoken to. This one is hard to answer because of being such a niche customer.

If Splunk support were to be put on a scale from 1 to 10, it would receive a seven. This has been discussed with them and it is fair feedback. The reason for giving seven is simply because the first contact is not necessarily able to answer most of the problems that have to be submitted.

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

Alternatives to Splunk have been used. In the past, ArcSight has been used, of course managed service provider tools that you typically get with the big cloud providers, and then Elastic.

How was the initial setup?

Splunk Enterprise Security is just an app that sits on top of Splunk. There really is not much to it. It is pretty straightforward and about as easy as production enterprise software that has ever been seen. It is super easy.

What about the implementation team?

Implementation was automation, probably a couple of minutes and a button click.

Which other solutions did I evaluate?

There is not anything that is close to Splunk Enterprise Security as of right now. Splunk has taken this weird leap ahead of everybody else. It is also the most expensive tool out there. It is kind of like buying a luxury SUV or a used entry-level SUV. There is a difference for a reason. That is not saying that any of the other tools mentioned are that. It is just that Splunk is ahead, so there is really not a fair comparison.

What other advice do I have?

Splunk Enterprise Security has not been upgraded to 8.0. Splunk Enterprise Security does require maintenance between patching and upgrades. Professional services are available and have been done on behalf of another customer, but it is done mainly personally. The overall review rating for Splunk Enterprise Security is an eight.

Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor. The reviewer's company has a business relationship with this vendor other than being a customer: Partner
PeerSpot user
Kyle Vernham - PeerSpot reviewer
Threat Analyst at a manufacturing company with 10,001+ employees
Video Review
Real User
Top 5
Sep 11, 2025
Built-in searches and unified data access streamline alert investigation and boosts analyst efficiency
Pros and Cons
  • "When it comes to leveraging Splunk Enterprise Security's dashboards and visualizations to communicate security posture to executives, it's pretty straightforward for any type of information."
  • "The two features I appreciate the most in Splunk Enterprise Security are the built-in searches, which have been very easy for us to get started with right out of the box, and the fact that it accesses all of our other systems."
  • "One main change I would suggest is related to the incident board: when an incident is resolved, it should not appear on the incident board. It's just a rare occurrence that we open up the incident."

What is our primary use case?

The main use cases for Splunk Enterprise Security are primarily threat detection and insight. We have more of a focus on the insider threat, and we have it as a requirement of this new media to address any type of alerts or malicious activity from a special endpoint. Now it's inside.

What is most valuable?

The two features I appreciate the most in Splunk Enterprise Security are the built-in searches, which have been very easy for us to get started with right out of the box, and the fact that it accesses all of our other systems. You can access it as a pane of glass rather than having to search individually. 

We also have the option to compare our analysts from our service to service. Splunk Enterprise Security helps our SOC team prioritize and investigate high-fidelity alerts more effectively by providing a more in-depth look and the ability to access a lot more of our data. Instead of jumping from several segmented systems, it allows us to have everything brought together in one place.

For example, you have to move from our purview to our build system and to Splunk Enterprise Security, and it enables us to streamline that process. The built-in features of Splunk Enterprise Security, which we recently procured, have given us a good starting point and demonstrated the value of the product, providing an easy way to sell it to our company. 

The ease of getting everything into our purview helps us, and it serves as a good start for the investigation part in one location rather than what we usually have, which is jumping from system to system to system.

Splunk Enterprise Security plays a role in our company's strategy to combat insider threats and advanced persistent threats by currently being in its technical test phase. We are still rolling it out, and it should help us find any insider threats based on information that our policy states should not be present in our system.

Splunk Enterprise Security's risk-based alerting (RBA) has impacted our alert volume and analyst productivity because we've got many different systems feeding into it. However, it has helped to make it easier for our analysts to go through a set of events rather than 100 alerts. RBA allows us to streamline the process and customize it for our analysts.

When it comes to leveraging Splunk Enterprise Security's dashboards and visualizations to communicate security posture to executives, it's pretty straightforward for any type of information. The visualization is easy to understand, but I haven't had any direct conversations with our executives.

What needs improvement?

It's hard for me to say how Splunk Enterprise Security can be improved because I've seen what they've done with the AI systems, which is going to help a lot once it's rolled out. 

However, one main change I would suggest is related to the incident board: when an incident is resolved, it should not appear on the incident board. It's just a rare occurrence that we open up the incident.

For how long have I used the solution?

I have been working in my current field for three years now.

What do I think about the stability of the solution?

The stability and reliability of Splunk Enterprise Security overall have been good. We haven't had it crash, and we haven't experienced any issues with the indexes shutting down.

Most of the problems we've faced have stemmed from the implementation of our systems and with forwarding information into the indexes, but we haven't encountered any issues with Splunk Enterprise Security itself.

What do I think about the scalability of the solution?

I'm not sure how Splunk Enterprise Security scales with the growing needs of our company yet. We have increased the amount of data we can ingest as the project has progressed, which has provided us with better information, however, we haven't rescaled it to a production level.

How are customer service and support?

My thoughts on the customer service and technical support are that it's good. They've been very attentive to us, and we've maintained a bi-weekly cadence call with the A team. We've also collaborated with several of their architects to address problems. 

We've worked with the Splunk community to gather resources to roll out Splunk Enterprise Security, and we've never felt left in the dark when we encountered a problem; they've always been very responsive.

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

Prior to adopting Splunk Enterprise Security, we had Purview and our own home-grown threat detection system. I don't know the exact systems we used past Purview, however, I know there were several options.

How was the initial setup?

My experience with deploying Splunk Enterprise Security so far has not been difficult. Everything works smoothly with all the other systems we have. The only issues we've faced have been with the volume of indexes, which is more about how we're finding our data. Past that, installing, updating, and modifying it has all been pretty smooth.

What about the implementation team?

We've worked with the Splunk community to gather resources to roll out Splunk Enterprise Security, and we've never felt left in the dark when we encountered a problem; they've always been very responsive.

What was our ROI?

The biggest return on investment when using Splunk Enterprise Security is its user-friendliness and how easy it is to adjust pre-built functionalities to fit our system, especially for investigation purposes. 

Additionally, I have found that some of the other programs we use for detection don't pick up as many alerts as Splunk Enterprise Security does.

What's my experience with pricing, setup cost, and licensing?

Regarding my experience with the pricing, setup cost, and licensing of the platform, ours is provided by a different agency. In our situation, the licensing is something we don't really have to handle directly. I can say one issue we've encountered pertains to how our system is set up, specifically indexing data. However, that's more about our infrastructure rather than a Splunk Enterprise Security issue since we have an entirely new Splunk system running that data, and it requires its own license.

What other advice do I have?

Regarding whether Splunk Enterprise Security's ability to ingest and normalize data from diverse sources has enhanced our threat detection capabilities, it is based on a system we have, and since we have a SIM, the data is already segmented coming in. In terms of whether Splunk Enterprise Security has helped reduce our team's average meantime to detect, it's still very early in the rollout phase. I can say that as time goes along, it's a bit quicker and has sped up, however, we haven't yet gotten any specific metrics.

We haven't used UEBA, but we've used UBA, which is what the system is based on. There's Splunk UBA and then there's Splunk UEBA, which is integrated into Splunk Enterprise Security. 

I would rate Splunk Enterprise Security an eight out of ten. 

My advice to other companies considering Splunk Enterprise Security is to avoid setting it up as a separate test system. It's crucial to integrate it into your main system because one of the main issues we've faced is managing the amount of data and understanding that you want to feed it as much data as you can.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer. Partners
PeerSpot user
reviewer2899419 - PeerSpot reviewer
DCO Manager at a aerospace/defense firm with 10,001+ employees
Real User
Top 20
Sep 17, 2026
Comprehensive security analytics have improved visibility and supported compliance reporting
Pros and Cons
  • "Splunk Enterprise Security positively impacts my organization by aiding in compliance by giving me visibility into what's happening from a workstation to a server to the network with syslog and NetFlow, and this visibility extends to the endpoints as well."

    What is our primary use case?

    Splunk Enterprise Security serves as my main SIEM with forensics and response capabilities. I use it for threat detection, vulnerability management, and incident response for observability. 

    How has it helped my organization?

    What is most valuable?

    The best features Splunk Enterprise Security offers are analytics. I appreciate the analytics features, particularly the dashboards and reporting, which are the primary highlights for me. Splunk Enterprise Security positively impacts my organization by aiding in compliance. It helps with compliance by giving me visibility into what's happening from a workstation to a server to the networking devices.

    What needs improvement?

    n/a

    For how long have I used the solution?

    I have been using Splunk Enterprise Security for 7 years.

    What do I think about the stability of the solution?

    Splunk Enterprise Security is very stable.

    What do I think about the scalability of the solution?

    Splunk Enterprise Security's scalability is not necessarily supported by Enterprise Security or Splunk. We would have to deploy another server or increase the license size. 

    How are customer service and support?

    Customer support for Splunk Enterprise Security is amazing.

    Which solution did I use previously and why did I switch?

    I have been using Splunk and Splunk Enterprise Security for the duration of my time at my current employer.

    How was the initial setup?

    Complex

    What about the implementation team?

    No

    What was our ROI?

    The return on investment has been pretty baseline for years. We have been using Enterprise Security for years, and I could not say that there was a change in my team's average mean time to resolve security incidents. I could not share any relevant metrics.

    What's my experience with pricing, setup cost, and licensing?

    A bit expensive for government customers but it meets the requirement. 

    Which other solutions did I evaluate?

    The previous person who held my position before I came into this role decided we were with Splunk, and I supported that decision when I took over.

    What other advice do I have?

    I have not used Splunk Enterprise Security's AI capabilities, so I cannot speak to that aspect. I have not used the AI portion of Splunk Enterprise Security, so I cannot speak to its accuracy and reliability of output. Splunk Enterprise Security is deployed on-premises in my organization. Splunk Enterprise Security's risk-based alerting has impacted my alert volume and analyst productivity. Risk-based alerting has made things more manageable for my team as it has decreased the number of alerts. I do not use Enterprise Security for assessing the threat topology or MITRE ATT&CK framework features. I have not used the integration of threat intelligence directly into the TDIR workflow. I rate this product a 10 out of 10. I advise others looking into using Splunk Enterprise Security that it is better than the alternatives, especially if you are working in a DoD environment, as we have a SIEM ingest and retention requirement for our networks and compliance and incident response and DCO strategies.

    Which deployment model are you using for this solution?

    On-premises
    Disclosure: My company does not have a business relationship with this vendor other than being a customer.
    Last updated: Sep 17, 2026
    Flag as inappropriate
    PeerSpot user
    Geoffrey Njogu - PeerSpot reviewer
    Security & Privacy Engineer at a tech services company with 51-200 employees
    Real User
    Top 20
    May 22, 2026
    Unified monitoring has improved alert fatigue management and streamlined reporting workflows
    Pros and Cons
    • "From using Splunk Enterprise Security, I have already seen benefits such as tracking alert fatigue in my team, especially with the SOC Operations dashboard and the Executive Dashboard."
    • "There is room for improvement for Splunk Enterprise Security. I moved away from Security Onion before switching to Splunk because Splunk was promising with Splunk AI, but now I am questioning if I made the right decision given that everybody is moving towards the AI aspect, especially since Splunk told me I cannot use Splunk AI on my platform and Security Onion already has the Gen-Sec SOC."

    What is our primary use case?

    Splunk Enterprise Security serves as my primary tool for security monitoring and log aggregation, allowing me to write correlation searches. I also use it for anti-money laundering purposes and have developed several use cases around that functionality.

    What is most valuable?

    The entire platform of Splunk Enterprise Security provides significant value, though breaking it down into individual features is challenging. The out-of-the-box log ingestion and integration with other platforms stands out as one of the most valuable aspects because I can pass data from different sources, making it very easy for me to work with.

    From using Splunk Enterprise Security, I have already seen benefits such as tracking alert fatigue in my team, especially with the SOC Operations dashboard and the Executive Dashboard. I can track how many alerts we are closing, how fast we are closing them, and understand what my team is doing and what is taking too much of their time. That visibility is valuable. One of the best things about Splunk is the ability to create my own dashboards very quickly, which makes reporting straightforward for me.

    What needs improvement?

    There is room for improvement for Splunk Enterprise Security. I moved away from Security Onion before switching to Splunk because Splunk was promising with Splunk AI, but now I am questioning if I made the right decision given that everybody is moving towards the AI aspect, especially since Splunk told me I cannot use Splunk AI on my platform and Security Onion already has the Gen-Sec SOC.

    Honestly, we are not fully using the functionality of risk-based alerting in Splunk.

    For how long have I used the solution?

    I have been working with Splunk Enterprise Security since around October 2022, so it has been almost two years.

    What do I think about the stability of the solution?

    So far, the product is very stable, and the support team is very accessible. If I have an issue, I can raise a ticket, and they either send an article or jump on a call, so they are very responsive.

    What do I think about the scalability of the solution?

    As of now, we are yet to fully track scalability because the team has not matured enough to use Splunk alone. We have alerts from our WAF, alerts from the EDR, and alerts from the firewall itself. Splunk serves more as a correlation platform with all the other alerts from the other defensive mechanisms sent to us via Slack, but we primarily want to use it for correlation.

    We went through a vendor for our Splunk Enterprise Security purchase.

    How are customer service and support?

    I would definitely give my experience with technical support a rating of ten out of ten. I had an incident once, and the escalation started with a Tier 2 person and went all the way to staff engineers in a very short time, which was impressive.

    Which solution did I use previously and why did I switch?

    Comparing Splunk Enterprise Security with the open-source SIEMs I have only used, I would rate it an eight. The reason is that creating the searches had a very long learning curve for my team to understand how to create and improve correlation searches. Compared to tools such as Elastic Security or Security Onion, creating detection rules is more straightforward in those tools, and their community resources are convenient for troubleshooting. However, Splunk is very strong in terms of integration and fetching data from multiple platforms, which is a significant advantage for Splunk, making it easy to ingest logs from different sources.

    How was the initial setup?

    I took part in the deployment of Splunk Enterprise Security in my organization, and I am also the main administrator. I administer Splunk as well.

    I had some issues here and there with most of the applications during the implementation of Splunk Enterprise Security, but I also worked with a consultant, and we eventually resolved them. The documentation was very helpful and quite thorough. Since it was my first time interacting with Splunk, getting around and understanding all the configuration files took some time, but I was comfortable running it by myself after the first three months.

    What about the implementation team?

    We went through a vendor for our Splunk Enterprise Security purchase.

    What was our ROI?

    I have seen a return on investment with Splunk Enterprise Security. It was tough to handle the reporting aspect and control alert fatigue from the team, but now with the visibility that I have, it is becoming very easy. We have also decommissioned some tools, such as Wazuh, because the Universal Forwarder can do almost everything Wazuh can do, and we have streamlined our focus to one area instead of looking into multiple dashboards.

    What's my experience with pricing, setup cost, and licensing?

    I find Splunk's pricing reasonable, but the fact that they do not disclose actual pricing makes it very hard to know whether we are overpriced, so it is difficult to know if they added a very large margin.

    What other advice do I have?

    Unfortunately, because of the pricing aspect, I could not get the SOAR feature, so I cannot speak to that functionality.

    I do not have a specific number as of now, but what I can say is Splunk has given me visibility and a way to track results. If I log in to my dashboard, I can see that since we started, the findings and false positives, the notables that create our false positives, have been reducing over time, so it gives me that visibility.

    No other problems were found, and I have been satisfied. I would rate this review an eight overall.

    Which deployment model are you using for this solution?

    On-premises

    If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

    Other
    Disclosure: My company does not have a business relationship with this vendor other than being a customer.
    Last updated: May 22, 2026
    Flag as inappropriate
    PeerSpot user
    reviewer2704098 - PeerSpot reviewer
    Security & Risk Analyst at a computer software company with 1,001-5,000 employees
    Real User
    Top 20
    May 10, 2025
    Exceptional user interface and integrations enhance analytical capabilities
    Pros and Cons
    • "The community marketplace is useful; often, you do not need to rely on Splunk Enterprise Security support due to the wealth of online documentation available—Splunk docs are truly beneficial."
    • "Splunk Enterprise Security is amazing."
    • "One area Splunk Enterprise Security fails to improve is the pricing aspect; while the initial pricing seems fine, the licensing cost can skyrocket over time, creating trauma for organizations."
    • "The default threat intel feeds create many false positives and noise, which is counterproductive."

    What is our primary use case?

    My use cases for Splunk Enterprise Security involve mostly standard use case detections. Essentially, whatever log sources we ingest into the platform, we define use cases for detecting anomalous behavior, with most of our use cases tied to that. 

    Additionally, we utilize threat intelligence; we always use lookup tables or MISP integrations to enrich those use cases or create reports and dashboards to monitor them periodically, depending on how noisy those alerts are. 

    Other use cases include compliance-based use cases for auditing purposes, as there are compliance policy breaches we want to monitor proactively on a 24/7 basis. We do that, often within a mix of MSSP environment versus in-house.

    What is most valuable?

    The specific features I find the most valuable in Splunk Enterprise Security include the amazing UI and good integrations, and I can say this from a practitioner standpoint. 

    It is just comfortable. Splunk Enterprise Security is easy to use for an analyst, and the whole analyst experience is great; it is pretty insane. It is honestly very addicting. 

    As I told my fellow colleagues, they love using Splunk Enterprise Security. Once you go to any other platform, it is similar to going through withdrawal sometimes. You have to set up use cases, update data models, and link the right use cases to the right data models for those detections to happen. 

    In terms of challenges, there are none; Splunk Enterprise Security is one of the best vendors in the security analytics space.

    Splunk Enterprise Security has implemented improvements that may help reduce false positives, as it has some amazing features that go underutilized, such as the machine learning toolkit. The gap in skill set within the SOC environment is the reason for this underutilization.

    Splunk has some amazing features we are not utilizing. For example, ML. I have not specifically utilized AI-driven security initiatives or machine learning within Splunk Enterprise Security; even the ML toolkit is not related to advanced AI components. It operates more an advanced SQL query based on existing data trends without offering out-of-the-box advanced ML capabilities to provide significant value.

    The dashboards for some default use cases are provided. Similarly, default dashboards and reports are provided. You can pivot off of these and drill down on your investigations. The Splunk query language is definitely very easy to understand and use on a regular basis. The learning curve is also very low. So, from a practitioner standpoint, you're not going to face so much struggle in learning the Splunk query language. In fact, for other solutions, you might need AI capabilities to translate natural language. 

    Additionally, Splunk Enterprise Security claims to reduce data storage to a certain extent. I'm not sure if that's the case, however, I have heard that that was the case.

    Lookup tables are very useful in Splunk. 

    What needs improvement?

    The effectiveness of threat detection and response in Splunk Enterprise Security depends on how the team leverages it. Splunk Enterprise Security is not something that automatically picks things; you have to set up use cases, update data models, and link the right use cases to the right data models for those detections to happen. This is SIM-tool agnostic. If you do not have the right use cases, nothing will be detected at the end of the day. 

    One challenge under that note is if your company goes through some kind of digital transformation or major solutions being replaced, and all these logs are being ingested into Splunk Enterprise Security, the data models do not get updated proactively. Splunk Enterprise Security does not have a mechanism to identify that certain data models have stopped sending logs. How do we update our data models accordingly? This issue reflects back to our use case detections.

    In discussing areas for improvement in Splunk Enterprise Security, I assert that their default threat intel is inadequate. When ingesting threat intel from other sources, it would be beneficial to have capabilities that enrich the information within Splunk Enterprise Security with less dependence on a threat intel platform. The default threat intel feeds create many false positives and noise, which is counterproductive.

    The UEBA aspect of Splunk Enterprise Security should also see enhancement, as it lacks that functionality.

    Splunk search can sometimes take a long time; it can even time out. You have to make sure your query is very specific. It would be useful if Splunk used AI to help you write queries. I'm not sure if AI is used this way just yet.

    For how long have I used the solution?

    My experience with Splunk Enterprise Security is from within the last 18 months.

    What do I think about the stability of the solution?

    Regarding stability with Splunk Enterprise Security, I do not recall facing performance issues at the moment. 

    What do I think about the scalability of the solution?

    The solution can scale. When your environment scales, the search operations can lag significantly.

    One entity I worked with was a managed service company that managed companies of all sizes, up to 30,000 or 40,000 employees. We work with large firms. 

    How are customer service and support?

    The technical support of Splunk Enterprise Security is quite good, and I would rate it a four out of five (eight out of ten) easily. They are responsive and effectively resolve issues. 

    The community marketplace is also useful; often, you do not need to rely on Splunk Enterprise Security support due to the wealth of online documentation available—Splunk docs are truly beneficial.

    How would you rate customer service and support?

    Positive

    Which solution did I use previously and why did I switch?

    I enjoy my work with Splunk Enterprise Security, and while I can say the same for Elastic, I have found other vendors such as QRadar, Exabeam, LogRhythm, and Sumologic not to be as impressive. I prefer ElasticSearch since it allows for quicker searches, making threat hunting and proactive activities easier, whereas Splunk Enterprise Security searches can take considerable time.

    AlienVault's open-source solutions seemed inadequate compared to this, and QRadar was even worse. Thankfully, they are no longer relevant.

    How was the initial setup?

    I was somewhat involved in the initial setup of Splunk Enterprise Security. That said, it was not complex enough for a clear comparison with larger environments. 

    Deploying indexers and forwarders is straightforward, though human errors can potentially occur in the process. It is challenging for me to compare the implementation of other similar tools versus Splunk Enterprise Security, however, the clarity on implementation could be enhanced. 

    Maintaining Splunk Enterprise Security on-premise is not difficult at all, especially compared to other platforms I have not maintained as extensively. Many resources are available in the market to help with Splunk Enterprise Security, so finding people skilled in it is relatively easy due to the market's maturity.

    What's my experience with pricing, setup cost, and licensing?

    One area Splunk Enterprise Security fails to improve is the pricing aspect; while the initial pricing seems fine, the licensing cost can skyrocket over time, creating trauma for organizations.

    It's really hard to justify the pricing. The only way it makes sense is if you reduce the number of nodes being ingested over time. If you can optimize that as you scale, it can stay affordable. 

    What other advice do I have?

    Now that Splunk Enterprise Security has been acquired by Cisco, I am uncertain whether it will retain its current traction or be dissolved in the coming years. 

    I would rate Splunk Enterprise Security as a product an easy eight out of ten.

    However, it is an easy eight as of now. Post-Cisco acquisition, the future remains uncertain. Would I recommend Splunk Enterprise Security to someone else? Absolutely. Splunk Enterprise Security is amazing. Despite all the issues, it simplifies the lives of everyone who uses it, and there is not a steep learning curve. 

    Compared to other tools I discussed earlier, Splunk Enterprise Security is significantly better. Personally, I would choose Elastic and Splunk Enterprise Security over any other options.

    Which deployment model are you using for this solution?

    On-premises

    If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

    Other
    Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
    PeerSpot user
    reviewer2898990 - PeerSpot reviewer
    detection engineer at a real estate/law firm with 1,001-5,000 employees
    Real User
    Top 20
    Sep 16, 2026
    Advanced alerting has reduced false positives and now improves targeted threat detection
    Pros and Cons
    • "Splunk Enterprise Security has positively impacted my organization by allowing us to alert and use its threat intel and asset modeling capabilities to accurately see what is happening, when it's happening, and who it's happening to."
    • "Regarding Splunk Enterprise Security's AI capabilities in terms of accuracy and reliability of output, I think by default, they were not that good."

    What is our primary use case?

    I have been using Splunk Enterprise Security for about five years.

    My main use case for Splunk Enterprise Security is building security alerting detections for our SOC.

    A quick, specific example of a detection I've built with Splunk Enterprise Security is that we detect users clicking on a malicious phishing link and alert the SOC for it.

    To build that detection, we used the email data model as well as the content and alerting framework that is built in Splunk Enterprise Security.

    What is most valuable?

    The best features Splunk Enterprise Security offers are a clean way to organize and alert on detections and data modeling to categorize and sanitize data.

    The data modeling and organization features of Splunk Enterprise Security help me in my daily work by allowing us to sanitize multiple different data sources, such as multiple firewalls or multiple email logs from different sources, into one similar set of logs so that we can easily switch between them without having to relearn new schema.

    Splunk Enterprise Security has positively impacted my organization by allowing us to alert and use its threat intel and asset modeling capabilities to accurately see what is happening, when it's happening, and who it's happening to.

    The specific outcomes or improvements I've seen with Splunk Enterprise Security include a large decrease in false positive tickets and a higher increase of relevant, targeted tickets when using the risk-based alerting framework. It has also made it faster to spin up and create new detections.

    What needs improvement?

    An improvement that could be made in Splunk Enterprise Security is proper version control for our content and alerts that are built in it.

    For how long have I used the solution?

    I have been using Splunk Enterprise Security for about five years.

    What do I think about the stability of the solution?

    Splunk Enterprise Security is stable.

    What do I think about the scalability of the solution?

    Splunk Enterprise Security's scalability is fine; you can put as many indexes and search heads as you need and they scale reasonably well.

    How are customer service and support?

    The customer support has been up and down. Our sales associates and team have been very good, but the support through the portal is adequate.

    Which solution did I use previously and why did I switch?

    I did not previously use a different solution before Splunk Enterprise Security.

    How was the initial setup?

    My experience with pricing, setup cost, and licensing was adequate. We purchased it, and it was set up with some professional services and licensed.

    What about the implementation team?

    We purchased it, and it was set up with some professional services and licensed.

    What was our ROI?

    I think it's hard to measure the return on investment, but I believe it has been more of an expansion of our detection and alerting capabilities than it is a matter of employees' work being saved.

    What's my experience with pricing, setup cost, and licensing?

    My experience with pricing, setup cost, and licensing was adequate. We purchased it, and it was set up with some professional services and licensed.

    Which other solutions did I evaluate?

    Before choosing Splunk Enterprise Security, I evaluated Elastic and Datadog as other options.

    What other advice do I have?

    Regarding Splunk Enterprise Security's AI capabilities, I think they're a good starting point, but as Splunk Enterprise Security evolves, the AI features will change a lot and I'm not sure what direction it will take right now.

    Regarding Splunk Enterprise Security's AI capabilities in terms of accuracy and reliability of output, I think by default, they were not that good. When we input metadata and skills about where our content lives and how it lives, it got significantly better, but it was not good at finding these things by default.

    Splunk Enterprise Security is deployed in a public cloud environment in my organization. We use AWS as our cloud provider.

    Splunk Enterprise Security does identify problems, and with proper dashboards, it shows us issues and alerts and observability issues or when something is down very well.

    Splunk Enterprise Security has helped reduce my team's average mean time to resolve (MTTR) metric because it allows our alerts to be targeted and efficient, delivering direct alerts about specific things as opposed to broader, wider alerts that were harder to triage.

    Splunk Enterprise Security has helped reduce my team's average mean time to detect (MTTD) because it makes it easy and efficient to build alerts to detect these things and schedule them aggressively so that the detection appears very soon after the event.

    Splunk Enterprise Security's risk-based alerting (RBA) has impacted my alert volume and analyst productivity by being great for reducing alert volume. By combining multiple indicators, we can have a comprehensive alert and a full picture of what happened on a system as opposed to multiple similar alerts that may or may not be noise.

    I assess the threat topology and MITRE ATT&CK framework features for helping me discover the overall scope of an incident by noting they show us where holes are in our detections and what we have and don't have in terms of data sources and detection capability.

    My advice for others looking into using Splunk Enterprise Security is that it is a product that rewards knowledge and time put into it. It is something that you can use and learn about and become really proficient in, and it will help you a lot.

    I rate this product an 8 out of 10.

    Which deployment model are you using for this solution?

    Public Cloud

    If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

    Disclosure: My company does not have a business relationship with this vendor other than being a customer.
    Last updated: Sep 16, 2026
    Flag as inappropriate
    PeerSpot user
    Cyber security analyst at a government with 5,001-10,000 employees
    Real User
    Top 20
    Sep 16, 2026
    Compliance has improved and incident response transforms while complexity still requires simplification
    Pros and Cons
    • "Splunk Enterprise Security has vastly improved the amount of time that it takes to respond to an incident, which has been truly helpful."
    • "In my personal opinion, it is too complicated. Installing forwarders and trying to get an overview of a network topology with Splunk Enterprise Security is challenging."

    What is our primary use case?

    Audit reviews, log analysis, and asset visibility.

    What is most valuable?

    Splunk Enterprise Security excels at manipulating and viewing all of your data. It has allowed us to pass three federal audits and proved invaluable for demonstrating that we are utilizing security and meeting government regulations.

    What needs improvement?

    In my personal opinion, it is too complicated. It is an immensely powerful tool, but it could be simplified. Installing forwarders and trying to get an overview of a network topology with Splunk Enterprise Security is challenging.

    For how long have I used the solution?

    Two years.

    What do I think about the stability of the solution?

    Yes.

    What do I think about the scalability of the solution?

    Splunk Enterprise Security is immensely scalable.

    How are customer service and support?

    It is very expensive. I would start with professional services and drastically overestimate the amount of resource usage that you will need. I would honestly recommend starting off in a clustered environment.

    Which solution did I use previously and why did I switch?

    No.

    What was our ROI?

    I would say that it has drastically helped the business unit because it allows us to meet government requirements, which means we are actually allowed to operate. I feel that if we did not have Splunk Enterprise Security or a SIEM tool, we would not be able to operate the business.

    What's my experience with pricing, setup cost, and licensing?

    It is very expensive.

    Which other solutions did I evaluate?

    We did not consider alternate solutions.

    What other advice do I have?

    Alerting is valuable. I do not think the integrations are comprehensive. It seems that Splunk Enterprise Security does not work well with other products that are not Splunk Enterprise Security.

    Splunk Enterprise Security has vastly improved the amount of time that it takes to respond to an incident, which has been truly helpful.

    It is not necessarily a percent improvement; it is an absolute transformation. We were not capable of responding correctly, and now we are, so I would say the improvement is from zero to one hundred.

    Splunk Enterprise Security has immensely helped in this regard as well. It is not a percentage increase but rather an absolute shift from no to yes.

    It provides many alerts, but it is almost excessive. When Splunk Enterprise Security has an error or is experiencing an issue, it will send hundreds, if not thousands, of alerts.

    I find the alerts helpful to some degree. It seems that many incidents are different.

    I would recommend attending Splunk conference and starting off a little faster. I would rate this review as seven out of ten.

    Which deployment model are you using for this solution?

    On-premises
    Disclosure: My company does not have a business relationship with this vendor other than being a customer.
    Last updated: Sep 16, 2026
    Flag as inappropriate
    PeerSpot user
    reviewer2899332 - PeerSpot reviewer
    Information Security Engineer at a financial services firm with 5,001-10,000 employees
    Real User
    Top 20
    Sep 16, 2026
    Centralized alerts have improved soc workflows but triage and ai features still need refinement
    Pros and Cons
    • "Analysts can review all the alerts in one pane of glass instead of going through multiple different security tools and managing or investigating alerts there."
    • "Customer support for Splunk Enterprise Security is good; sometimes it's not as fast as I would prefer, but it has been useful."

    What is our primary use case?

    My main use case for Splunk Enterprise Security is being an engineer for the SOC and insider threat risk team, where I monitor threat detection, manage the queue for a SOC, and ensure Splunk Enterprise Security data it uses is working properly.

    I give a quick specific example of how I use Splunk Enterprise Security in my day-to-day work by tuning detections, creating new detections, enabling any new features that come in, assessing identity, managing that, or RBA, and addressing any issues that arise that SOC analysts see, working on those with Splunk support or with the internal team.

    How has it helped my organization?

    Analysts can review all the alerts in one pane of glass instead of going through multiple different security tools and managing or investigating alerts there.

    This change has definitely led to measurable improvements, as it is faster, and the integration also helps analysts avoid jumping around too much, allowing them to do everything in one place, which also allowed us to create custom detections that were not covered by the security tools.

    What is most valuable?

    The best features that Splunk Enterprise Security offers are that it can get data from your SIEM, which is Splunk, and also has SOAR, along with the different tools that you can utilize and the different tools that Splunk provides that we can easily integrate into Splunk Enterprise Security.

    I can tell you more about those integrations; all the logs that I collect from cloud providers can have my EDR tools' logs coming in, and then connecting to my EDR tool or enriching data via SOAR, and application data that's already in Splunk, utilizing that to create security alerts, is very valuable.

    What needs improvement?

    I believe Splunk Enterprise Security can be improved by getting into the authentic SOC space; right now, the triaging it does is able to handle some of it, but I think it would benefit from going further into that, and a lot of performance issues that were seen before have been improved, although some errors or performance issues still occur once in a while.

    One specific issue I've noticed is not performance-related, but with Splunk and SOAR integration, if I use the entry ID with the auth extension, I get a 404 error after a certain time, as there is a time to live, and by default, it's one hour, and support has indicated this is by design, so this is one of the issues I see with Splunk and SOAR integration that could be improved.

    Regarding Splunk Enterprise Security's AI capabilities, I think it can definitely be improved, especially re-running searches for metadata, such as getting index source and source types; it's session-by-session based, so if it can store and learn my environment and not have to run those searches every session, that could save a lot of resources and improve efficiency.

    For how long have I used the solution?

    I have been using Splunk Enterprise Security for three years.

    What do I think about the stability of the solution?

    Splunk Enterprise Security is stable.

    What do I think about the scalability of the solution?

    Splunk Enterprise Security has good scalability.

    How are customer service and support?

    Customer support for Splunk Enterprise Security is good; sometimes it's not as fast as I would prefer, but it has been useful.

    Which solution did I use previously and why did I switch?

    Previously, I used multiple different security tools, including EDR tools and cloud security tools, before switching to Splunk Enterprise Security.

    How was the initial setup?

    I have upgraded to Splunk Enterprise Security 8.0, and it has definitely supported my team's operations, especially with the team-based queues, making the integration with Splunk SOAR much easier, and the ability to run playbooks from Splunk Enterprise Security queue, with overall small features and errors that I was seeing before being improved in version 8.0.

    Which other solutions did I evaluate?

    I did not evaluate other options before choosing Splunk Enterprise Security, as we already had it in place before I moved in, so it was just work to enable this.

    What other advice do I have?

    My advice for others looking into using Splunk Enterprise Security is that if you are not using a tool where all security alerts are seen by your SOC in one pane of glass, this is definitely one of the good tools out there in the industry to take a look at.

    Splunk Enterprise Security's risk-based alerting, RBA, is something we want to enable, and I can see it will be beneficial, as we can enable more alerts and gain more insights into users and entities if the risk score is utilized, which also provides us with a narrative if alerts or findings trigger for certain assets or identities.

    I rate this solution 7.5 out of 10.

    Which deployment model are you using for this solution?

    Public Cloud

    If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

    Disclosure: My company does not have a business relationship with this vendor other than being a customer.
    Last updated: Sep 16, 2026
    Flag as inappropriate
    PeerSpot user
    Buyer's Guide
    Download our free Splunk Enterprise Security Report and get advice and tips from experienced pros sharing their opinions.
    Updated: August 2026
    Buyer's Guide
    Download our free Splunk Enterprise Security Report and get advice and tips from experienced pros sharing their opinions.