No more typing reviews! Try our Samantha, our new voice AI agent.
Kumar Shubham - PeerSpot reviewer
Senior Consultant at a consultancy with 1,001-5,000 employees
Consultant
Top 20
Jul 6, 2026
Advanced correlation has simplified threat hunting and now delivers faster incident investigations
Pros and Cons
  • "The unique and most valuable feature in Splunk Enterprise Security is the correlation capability and the SPL query language itself."
  • "Splunk Enterprise Security is a costlier tool compared to ArcSight or IBM QRadar."

What is our primary use case?

Splunk Enterprise Security has an upper hand when compared with other products. We can correlate multiple data sources for generating alerts through SPL. Although many find it complex, we found it much easier because recursive query hunting for identifying threats is straightforward and quick. Those are the aspects which we really appreciated.

For detecting threats, we have created use cases over Splunk Enterprise Security. We have onboarded multiple third-party products with Splunk Enterprise Security. On top of that, we have created multiple use cases correlating multiple third-party vendors. For example, if event A happens where data is B, we have defined those scenarios in queries to trigger the alert.

What is most valuable?

The unique and most valuable feature in Splunk Enterprise Security is the correlation capability and the SPL query language itself. Through an SPL query, we can even identify ransomware scenarios where we can execute large queries and receive results within a few seconds. That aspect gives Splunk Enterprise Security an upper hand with their own query language.

Splunk Enterprise Security helps us reduce the time to react to alerts because the query itself executes so fast that when investigating something in big data set scenarios, it provides significant assistance. Splunk Enterprise Security has the feature of correlating multiple data sources to generate alerts. The risk factor is the second feature where it triggers to identify the severity level of the alert. While correlating multiple data sets along with the query itself, it gives us exactly what we need if we have proper understanding.

The main benefits that Splunk Enterprise Security provides for us as an end user is that it is a well-known tool. When it comes to querying or identifying any data from a big data set or data lake scenario, the query executes so fast and gives us a good outcome.

What needs improvement?

A FIM integrating model would be one improvement that Splunk Enterprise Security could add because Splunk Enterprise Security is a costlier tool compared to ArcSight or IBM QRadar. A FIM monitoring scenario would help.

Regarding pricing, this depends on company preferences. If a company wants to go with a brand, they will opt for Splunk Enterprise Security because it is well-known and a majority of familiar brands or big brands trust Splunk Enterprise Security. To increase their revenue, they could drop the price slightly because there are customers who do not care about money and have an ample amount of budget, and if they think about security, they will go for security. There are customers who are looking at the security side as well as the financial front, and they do not go for Splunk Enterprise Security. They opt for ArcSight or IBM QRadar instead. The pricing of the Enterprise version is at a higher end compared to any other well-known product.

For how long have I used the solution?

I have been using Splunk Enterprise Security for more than five years.

Buyer's Guide
Splunk Enterprise Security
August 2026
Learn what your peers think about Splunk Enterprise Security. Get advice and tips from experienced pros sharing their opinions. Updated: August 2026.
914,109 professionals have used our research since 2012.

What do I think about the stability of the solution?

From a scale of one to ten, I rate the stability of Splunk Enterprise Security as a nine point five or a ten.

What do I think about the scalability of the solution?

In terms of scalability, the ability to scale and expand is a nine.

How are customer service and support?

My rating for Splunk Enterprise Security technical support is not very high, as I have not interacted extensively with Splunk Enterprise Security support because in our organization itself, we have five people who are Splunk certified architects.

How was the initial setup?

The initial setup for Splunk Enterprise Security is not complex, but it is not simple either. If an administrator wants to implement it, they have to do some homework at their own level before proceeding. When we compare it with Wazuh, for example, Wazuh has a one-click installation scenario. There is one script that you have to run and automatically everything is done. You are ready to go and your tool is set up.

Which other solutions did I evaluate?

In my opinion, the main competitors for Splunk Enterprise Security are IBM QRadar and ArcSight. There are many products and everyone has their own capabilities.

What other advice do I have?

Regarding the customization and development part inside Splunk Enterprise Security, we can create our own customized dashboards for whatever we need. If you understand Splunk Enterprise Security completely, you can create customization or you can request certain help on the support front, and they can assist you with that.

Splunk Enterprise Security provides better functionality when it comes to investigating data because when there is an incident, the analyst or the CISO wants to gain an upper hand as soon as an attack or breach has been detected. The SPL queries give an upper hand while fetching data compared to any other tool. That is the only difference, or the key difference.

In my opinion, Splunk Enterprise Security does not help to improve a company's or business's resilience because a majority of companies use Splunk Enterprise Security for security purposes. Rather than that, any AI or ML professionals or data science engineers would prefer Elastic, which is an open-source tool, to analyze data.

We recommend Splunk Enterprise Security to other users that if a customer has a good budget, they can go for a Splunk Enterprise Security solution. It depends on what the client is looking for and what they want to achieve. If they are going through funding, they want to showcase to the investors that they have a security team and they are using a grade-A solution in place to get additional checks. I give this review an overall rating of nine.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Last updated: Jul 6, 2026
Flag as inappropriate
PeerSpot user
Mohan Janarthanan - PeerSpot reviewer
Associate Vice President at Novac Technology Solutions
Real User
Top 5Leaderboard
Jun 3, 2026
Unified analytics and AI-driven risk-based alerting have transformed our security operations
Pros and Cons
    • "The NLP-based thing will give risk-based alerting which will reduce more than 50%, but I could see only 30%."

    What is our primary use case?

    My use cases include continuous security monitoring on our log management, forensic activity, and threat detection piece and analytics of Splunk Enterprise Security. We are using Cisco and Splunk all-in-one console, where I can get the indexes, forwarders, and logs to consolidate my data center security and cloud portions. All logs will move to Splunk Enterprise Security.

    What is most valuable?

    They are good at the detection piece and the analytics piece. I do not want to create a customized rule. The rules which they have on the analytics piece cover part of my use cases. For example, if I want to create a manual use case in my other product, Splunk Enterprise Security, QRadar, or FortiSIEM, I have to create a manual use case. Here, I do not want to create anything. The analytics plays a major role. They have 2,000 analytics use cases where I can deploy based on my use case and environment.

    The only advantage I can communicate is that in threat detection, triaging, investigation, and response, I will get in a single platform. I do not want to go to multiple platforms. If I am using a SIEM product in one solution and a SOAR product in a different solution, I do not want to go to multiple management consoles. I want a unified console that I can use. That is Splunk all-in-one console.

    SecOps only the product does. Most of my unified governance will be taken care of by SentinelOne Enterprise Security. It has artificial intelligence, it has a SOAR, it has a SIEM. They have agentic artificial intelligence where we can integrate in SecOps platform.

    Triaging is part of risk-based solution. Risk-based alerting will reduce the alert volumes around 30% to 40%. They committed something, but at least I could see the risk-based alerting. From 30%, alert volumes are off now. Basically, it is reducing my manual L1 work.

    Normally on traditional SIEM, they will pull all the logs and send all the 100% volumes. All alerts will go to my SIEM console and manually we have to find the alerting. We have to create a use case and offense and see that. But they have an artificial intelligence piece. The NLP-based thing will give risk-based alerting which will reduce more than 50%, but I could see only 30%. They committed something. Probably it is only a matter of time. We can also leverage their threat intel platform. That is one of the major use cases and a decision factor while we are going with that product.

    What needs improvement?

    I have recently adopted the product. Six months ago I did the testing. Three months ago I started implementing the product.

    I have faced issues only while I was doing my UAT environment, not the production piece. While I was testing, I could see something.

    I have recently implemented the product. I do not want to give wrong commitment or wrong information. As of now, I have not come across any negative feedback or lack of services. I am not able to see anything. Because I am using it for last three months, if you are calling me after two months, probably I can explain better.

    For how long have I used the solution?

    I have been using the solution for three months only.

    What do I think about the stability of the solution?

    There has been no downtime so far, but I am using it for the last 90 days only. I have not faced any issues.

    How are customer service and support?

    The customer service has been excellent.

    Which solution did I use previously and why did I switch?

    We have not done Cloud Security Posture Management.

    It is a great solution for risk-based alerting. It is reducing my 30% workload currently.

    What was our ROI?

    For me, time is the most important factor. If you are saving time, definitely you are saving money also.

    What other advice do I have?

    Splunk Enterprise Security is what I am currently using. We discussed Distributed Services only, but not other products from F5. Regarding Zscaler Internet Access, I am not using that product. Regarding Unified Vulnerability Management, I told you no and I am not using that product. I am using Splunk Enterprise Security, which is a SIEM solution. SentinelOne is another product I have integrated. I integrated firewall logs, app gateway logs, and EDR logs. Threat detection capability is a unified threat detection, which is a basic one we are having. That is part of my SOAR platform. The artificial intelligence-powered security options gives a more fine-tuning alert mechanism where I can get the threat detections. I can do alerting and triaging. My whole incident response is based on that. Definitely it is a leading product. I would say analytics is the most valuable currently. I am comparing it with my Microsoft Sentinel. The proof of concept validations and concepts do take time while you are doing them. I have tested FortiCNAP, but I am not using it. I have tested the product but did not buy it. I am using FortiGate, which is a next-generation firewall. I am also using FortiRecon, FortiManager, FortiAnalyzer, and FortiSIM, and I am using FortiGate firewall on cloud. I am using eight to nine products from Fortinet. My review rating for this product is 9 out of 10.

    Which deployment model are you using for this solution?

    Hybrid Cloud

    If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

    Other
    Disclosure: My company does not have a business relationship with this vendor other than being a customer.
    Last updated: Jun 3, 2026
    Flag as inappropriate
    PeerSpot user
    Buyer's Guide
    Splunk Enterprise Security
    August 2026
    Learn what your peers think about Splunk Enterprise Security. Get advice and tips from experienced pros sharing their opinions. Updated: August 2026.
    914,109 professionals have used our research since 2012.
    reviewer2899494 - PeerSpot reviewer
    Especialista en ciberseguridad at a retailer with 11-50 employees
    Real User
    Top 20
    Sep 17, 2026
    Centralized alerts have improved risk visibility and support faster, more accurate investigations
    Pros and Cons
    • "We have seen a clear return on investment since we started using Splunk Enterprise Security; we get a lot of value from it for the business side."
    • "I do not consider Splunk Enterprise Security to be stable. I consider it not to be stable because the platform is very slow, the AI sometimes doesn't return results, and we have encountered that upgrades break things that were already working well."

    What is our primary use case?

    Splunk Enterprise Security's main use case in my organization is centralizing alerts and seeing the risk by asset. Centralizing alerts and visualizing risk by asset has helped us identify which assets are compromised and give them proper attention.

    How has it helped my organization?

    Splunk Enterprise Security has positively impacted our organization by helping us see what risk we have in the company and which assets might be compromised so we can give them proper attention. We have slightly reduced the incident handling time, the MTTR, since we started using Splunk Enterprise Security.

    What is most valuable?

    I consider the best features that Splunk Enterprise Security offers to be the ease of seeing incidents and investigations and being able to give them proper attention.

    The investigations section helps you map very well how an asset is mapped to the incident, for example, an asset with IP, and being able to carry out more complete investigations.

    We also find the Asset and Identities feature very good, and it helps us a lot to be able to search for assets by IP or by MAC address, which also helps us with incidents. The Asset and Identities feature has helped us improve visibility in hybrid or multi-cloud environments, and it has positively impacted the confidence we have in our security posture by helping us identify our vulnerabilities or flaws that we have in the organization.

    What needs improvement?

    I think the automation part of Splunk Enterprise Security could be improved. We would like to have a chat with artificial intelligence to be able to ask it to execute playbooks and be more efficient, to request actions or remediations in natural language.

    For how long have I used the solution?

    I have been working with Splunk Enterprise Security for three years.

    What do I think about the stability of the solution?

    I do not consider Splunk Enterprise Security to be stable. I consider it not to be stable because the platform is very slow, the AI sometimes doesn't return results, and we have encountered that upgrades break things that were already working well.

    What do I think about the scalability of the solution?

    Splunk Enterprise Security's scalability is very good; the tool is very scalable, and it can be used for many things. We use it to centralize our security incidents.

    How are customer service and support?

    From one to ten, I rate Splunk Enterprise Security's customer support a six. The aspects of customer support that could be improved to provide a better experience are the level of knowledge and how long they take to respond to incidents.

    Which solution did I use previously and why did I switch?

    We have always used Splunk Enterprise Security to generate dashboards for end users so they can have these dashboards and they help with operations.

    How was the initial setup?

    In this area, I see that licensing costs, initial configuration, and the price of Splunk Enterprise Security fluctuate a lot. By it fluctuating a lot, we have had different licensing calculations, sometimes oversized, sometimes we fall short.

    What about the implementation team?

    We are partners with the vendor besides being a customer.

    What was our ROI?

    We have seen a clear return on investment since we started using Splunk Enterprise Security; we get a lot of value from it for the business side.

    Which other solutions did I evaluate?

    Before choosing Splunk Enterprise Security, we were considering Palo Alto. We ultimately decided on Splunk Enterprise Security instead of other options like Palo Alto because of the customization it has for use cases, for example, it is used for business and it can also be used for security.

    What other advice do I have?

    Splunk Enterprise Security does not help us with business resilience.

    It has helped us reduce incident handling time with SOAR automation and enrichment. It also helps us with the enrichment of events and incidents; it helps us take more precise actions. We have taken advantage of integrating threat intelligence directly into the detection and response workflow. Having threat intelligence integrated into the workflow has helped us see the information generated by the AI.

    The AI-driven capabilities have improved the accuracy of our investigations, and it has supported our team in making faster, data-driven decisions by helping us determine what is a threat and what perhaps just needs tuning for false positives.

    I would advise other companies considering implementing Splunk Enterprise Security to size the license properly and also to map out the onboarding that will be done for the data sources, and to align it with the business where they are implementing the technology since it is not the same for all. I rate this product a nine overall.

    Disclosure: My company has a business relationship with this vendor other than being a customer. Socio
    Last updated: Sep 17, 2026
    Flag as inappropriate
    PeerSpot user
    reviewer2899455 - PeerSpot reviewer
    Architecte Technique at a manufacturing company with 10,001+ employees
    Real User
    Top 20
    Sep 16, 2026
    Risk-based alerts have improved weak signal detection and support daily soc investigations
    Pros and Cons
    • "In my opinion, the best features that Splunk Enterprise Security offers are the RBA part and the fact that you can easily define and develop apps while taking ownership of the tool."
    • "In terms of efficiency, I am not sure Splunk Enterprise Security has brought much value so far, but on the other hand, it provides indicators with all the dashboards offered, which enable us to see better how we handle our incidents."

    What is our primary use case?

    My main use case for Splunk Enterprise Security is detection and SOC activities, so everything related to detection and security. Every day, I use Splunk Enterprise Security to trigger alerts and analyze the risks that are currently affecting our company.

    What is most valuable?

    In my opinion, the best features that Splunk Enterprise Security offers are the RBA part and the fact that you can easily define and develop apps while taking ownership of the tool.

    Regarding the Risk-Based Alerting feature, we are at the beginning of using it, so we are not fully operational yet, but it allows us to pick up weak signals and correlate them, which we previously had some difficulty doing. This enables us to improve the quality of detection on weaker signals compared to what we are used to with direct alerts.

    What needs improvement?

    There is still an aspect of this tool that I think could be optimized or simplified, particularly the CI/CD part to enable all the API and CI/CD aspects. This would allow us to easily deploy solutions while keeping the code in our source repository. Today, we are forced to develop many things whereas Splunk Enterprise Security could probably provide tools that make customers' lives easier.

    For how long have I used the solution?

    I have been using Splunk Enterprise Security for one year.

    What other advice do I have?

    In terms of efficiency, I am not sure Splunk Enterprise Security has brought much value so far, but on the other hand, it provides indicators with all the dashboards offered, which enable us to see better how we handle our incidents.

    These indicators allow us to see where we stand and identify the cases to be handled that are pending.

    At the moment, we do not yet have indicators to answer whether Splunk Enterprise Security has allowed us to reduce the mean time to resolution of incidents, the famous MTTR, within our team.

    We are on Splunk Enterprise Security version 8, and the integration with Splunk SOAR and the dedicated queues is a plus because it was something we were missing.

    I do not notice a reduction in analyst fatigue or burnout thanks to this tool.

    Consolidating SIEM, SOAR, and UEBA functionalities into a single interface has not improved our team's operational efficiency.

    Splunk Enterprise Security has helped improve our organization's resilience to incidents, and we chose to move to the AWS cloud to be resilient and not be tied to our current infrastructure as we were before on-premise.

    I give this product a rating of 8 out of 10.

    Which deployment model are you using for this solution?

    Public Cloud

    If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

    Disclosure: My company does not have a business relationship with this vendor other than being a customer.
    Last updated: Sep 16, 2026
    Flag as inappropriate
    PeerSpot user
    reviewer2898942 - PeerSpot reviewer
    Vulnerability Management Analyst at a energy/utilities company with 1,001-5,000 employees
    Real User
    Top 20
    Sep 16, 2026
    Unified log searches have streamlined daily alert investigations and reduced response times
    Pros and Cons
    • "Splunk Enterprise Security has helped improve my organization's business resilience, and Splunk Enterprise Security is really good at the ability to predict, identify, and solve problems in real time."

      What is our primary use case?

      My main use case for Splunk Enterprise Security is searching and log aggregation. I use Splunk Enterprise Security for searching and log aggregation in my daily work by investigating alerts that come across through our SIEM. I engage in manual digging through logs, searching based off of alert criteria.

      What is most valuable?

      The best feature that Splunk Enterprise Security offers is scalability. When I mention scalability, I mean it handles large volumes of data smoothly, even with increases of data because of new projects. Splunk Enterprise Security has positively impacted my organization by making our alert handling and research more efficient and smooth, and it helps us with maintaining logs for industry standard.

      I do not have any metrics showing time saved or improvements in workflow, but instead of having to search multiple tools, we are able to search Splunk Enterprise Security, which allows the process to be quicker.

      What needs improvement?

      I do not have any suggestions on how Splunk Enterprise Security can be improved.

      For how long have I used the solution?

      I have been using Splunk Enterprise Security for four years.

      What do I think about the stability of the solution?

      Splunk Enterprise Security is stable.

      What do I think about the scalability of the solution?

      The scalability of Splunk Enterprise Security is great.

      How are customer service and support?

      Customer support for Splunk Enterprise Security is great.

      Which solution did I use previously and why did I switch?

      I did not previously use a different solution.

      How was the initial setup?

      My experience with pricing, setup cost, and licensing has been fair pricing and an easy setup cost.

      What was our ROI?

      I have seen a return on investment with Splunk Enterprise Security, and it has definitely saved a lot of time more than anything.

      Which other solutions did I evaluate?

      Before choosing Splunk Enterprise Security, I did not evaluate other options.

      What other advice do I have?

      My advice for others looking into using Splunk Enterprise Security is to take advantage of Splunk's resources and training. Splunk Enterprise Security has helped improve my organization's business resilience, and Splunk Enterprise Security is really good at the ability to predict, identify, and solve problems in real time. I recommend other people use it for similar situations.

      Splunk Enterprise Security has helped reduce my team's average mean time to resolve, the MTTR metric. It allows us to search in one place for all the information we need to close an alert. Splunk Enterprise Security has helped reduce my team's average mean time to detect, MTTD metric, because it allows us to base alerts off of many different tools all in one place, and I would say by a couple of hours.

      Splunk Enterprise Security has helped me detect threats faster; it has decreased it. I have not used the threat topology and or MITRE ATT&CK framework features for discovering the overall scope of an incident. I would rate this review a 10 out of 10.

      Disclosure: My company does not have a business relationship with this vendor other than being a customer.
      Last updated: Sep 16, 2026
      Flag as inappropriate
      PeerSpot user
      Computer Systems & Application Specialist II at a mining and metals company with 501-1,000 employees
      Real User
      Top 20
      Sep 16, 2026
      Security monitoring has provided robust dashboards and alerts for network-wide visibility
      Pros and Cons
      • "The pricing, setup cost, and licensing for Splunk Enterprise Security are much better than McAfee, as it is more affordable and seems to be more robust and powerful."
      • "As I mentioned before, we came from the McAfee environment, and in that system, they had alerts visibility where we could easily acknowledge the alerts."

      What is our primary use case?

      Our main use case for Splunk Enterprise Security is to gather all the information that we need and also create some dashboards that can help us understand what's going on in the network.

      For example, we would like to see if there are any failed logging attempts and, based on that, identify the systems or computers that were attempting to access resources, the time they were trying to access them, and obtain the raw data to further investigate.

      We also need to create alerts when problematic events occur. Additionally, when a device is not sending logs, we need to be aware of that situation. We also must be aware of any malware installed on the network and alert on that as well. We would like to have all of this information available in Dashboard Studio.

      What is most valuable?

      I am very curious about Mission Control and Dashboard Studio, along with the administration part of Splunk Enterprise Security.

      With Mission Control, we can see all of the alerts that we have created. That is when we create tickets and acknowledge all alerts. I am not that familiar with it yet, but I am looking forward to learning more about it.

      So far, we have been able to implement some of the alerts that I mentioned. We have full visibility as to what is going on, but I think we are in the early stages of the implementation, so we would like to know more.

      We used to have McAfee SIEM, and we also have full visibility as to all the logs coming into our SIEM devices. It is similar to what we had before, although Splunk Enterprise Security seems to be more robust with all the dashboards and the other capabilities that you can utilize with it.

      What needs improvement?

      As I mentioned before, we came from the McAfee environment, and in that system, they had alerts visibility where we could easily acknowledge the alerts. Based on that, it would show you the time when the incident happened and the time when you acknowledged the alert. I have not seen that specific capability in Splunk Enterprise Security yet. I know that you can acknowledge and then create the investigation, but since we were accustomed to that feature in McAfee, it is a bit different. This is probably just an adaptation issue, but we are still trying to figure it out.

      For how long have I used the solution?

      We just implemented Splunk Enterprise Security last year, so I do not have that much experience working with it, but I am looking forward to gaining more expertise.

      What do I think about the scalability of the solution?

      I think Splunk Enterprise Security can be used for scalability as well. The only thing we have observed so far is the price of the license fee. We know that if we are ingesting more data, it will increase costs, so that will probably be a decision for upper management. However, as far as the capabilities, I think it is very scalable.

      How are customer service and support?

      I have not had the chance to reach out to customer support. I have a co-worker who is the main administrator for that, so personally, I have not had the chance to contact support yet.

      Which solution did I use previously and why did I switch?

      We used to have McAfee SIEM, and we had full visibility as to all the logs coming into our SIEM devices. It is similar to what we had before, although Splunk Enterprise Security seems to be more robust with all the dashboards and the other capabilities that you can do with it.

      We previously used McAfee SIEM, and the reason we switched to Splunk Enterprise Security was because of budgeting issues. McAfee was becoming more expensive, which is why we made the switch.

      How was the initial setup?

      It was implemented on-premises because we manage an air-gapped network, so nothing has access to the cloud at all.

      What was our ROI?

      So far, we are at the same level. From a monetary perspective, it has been an improvement for us, as the implementation of Splunk Enterprise Security was more affordable. However, as far as resources, we still have the same people working on it.

      What's my experience with pricing, setup cost, and licensing?

      The pricing, setup cost, and licensing for Splunk Enterprise Security are much better than McAfee. It is more affordable and seems to be more robust and powerful.

      Which other solutions did I evaluate?

      We did not evaluate other options. Since we work closely with our corporate network team, they already had implemented Splunk Enterprise Security, so that was the first option for us.

      What other advice do I have?

      I would advise others looking into using Splunk Enterprise Security to take advantage of all the free courses and seminars that they offer and also start to learn SPL, because that is another challenge that we faced. We did not know the language, so it was a bit complicated to start building the queries for gathering the data. I would rate my overall experience with Splunk Enterprise Security as a nine out of ten.

      Which deployment model are you using for this solution?

      On-premises
      Disclosure: My company does not have a business relationship with this vendor other than being a customer.
      Last updated: Sep 16, 2026
      Flag as inappropriate
      PeerSpot user
      reviewer2755827 - PeerSpot reviewer
      Cyber Security Specialist at a financial services firm with 201-500 employees
      Real User
      Top 10
      Sep 11, 2025
      Has supported advanced security investigations and improved incident response through enriched data and valuable tools
      Pros and Cons
      • "The features I find most valuable in Splunk Enterprise Security are Incident Review, Security Essentials, Asset and Identity Management, and Machine Learning Toolkit."
      • "Splunk Enterprise Security can be improved with more AI in the commands and more help in the commands, as not all people know how to write code in SPL, and we need more help in this area."
      • "My security ops team takes 60 or 70% longer to remediate security incidents with Splunk Enterprise Security compared to our previous solution."

      What is our primary use case?

      My main use cases for Splunk Enterprise Security include cybersecurity threat, incident response, and security events.

      What is most valuable?

      The features I find most valuable in Splunk Enterprise Security are Incident Review, Security Essentials, Asset and Identity Management, and Machine Learning Toolkit. 

      We are enriching data from Asset and Identity Management, and we have more data for our incident response and investigation with Splunk Enterprise Security when we need more data to investigate.

      I use disparate security solutions that integrate or import data into Splunk Enterprise Security. The integration currently supports my security operations as it's now on a POC, however, it's not in production right now. 

      I have expanded usage, and that process was very smooth. I assess the stability and reliability of Splunk Enterprise Security as very good.

      What needs improvement?

      Splunk Enterprise Security can be improved with more AI in the commands and more help in the commands, as not all people know how to write code in SPL, and we need more help in this area. 

      That additional features such as AI command help and more flexibility in the search should be included in the next release to make it more simple.

      The most significant challenges I face when using Splunk Enterprise Security for advanced threat detection involve correlating data from multiple assets and networks simultaneously, as our network is very complex and we have not yet properly collected all the data from our various data centers within my environment.

      For how long have I used the solution?

      I have been using Splunk Enterprise Security for five years.

      What do I think about the stability of the solution?

      I have not experienced any downtime, crashes, or performance issues; it is very redundant.

      What do I think about the scalability of the solution?

      Splunk Enterprise Security scales very well with the growing needs of my organization.

      How are customer service and support?

      I evaluate customer service and technical support as very good.

      How would you rate customer service and support?

      Positive

      Which solution did I use previously and why did I switch?

      Prior to adopting Splunk Enterprise Security, I was not using another solution to address similar needs.

      How was the initial setup?

      I find the process for customizing, developing, testing, deploying, and refining detections in Splunk Enterprise Security very simple and straightforward.

      What was our ROI?

      I have yet to see an ROI.

      What's my experience with pricing, setup cost, and licensing?

      I'm not famiiar with the pricing. 

      What other advice do I have?

      My organization does not use risk-based alerting yet. My security ops team takes 60 or 70% longer to remediate security incidents with Splunk Enterprise Security compared to our previous solution.

      The advice I would give to other organizations considering Splunk Enterprise Security is to design, design, design, and design. Expanding on what that means, you need to be very organized with what you want and what you want to achieve from the product because the deployment is very crucial; once you install it, it's very hard to change the topology and to add more tenants or search heads, which is very complex. The vendor can contact me with any questions or comments about my review. 

      On a scale of one to ten, I would rate Splunk Enterprise Security overall an eight.

      Which deployment model are you using for this solution?

      On-premises
      Disclosure: My company does not have a business relationship with this vendor other than being a customer.
      PeerSpot user
      ROBERT-CHRISTIAN - PeerSpot reviewer
      CTO at a tech vendor with 10,001+ employees
      Real User
      Top 5
      Dec 22, 2024
      Has many predefined correlation rules and is brilliant for investigation and log analysis
      Pros and Cons
      • "They have approximately 50,000 predefined correlation rules, which is quite a lot, and I find that good."
      • "Overall, Splunk is among the top three SIEM tools due to its capabilities and agility in bridging business analytics with security needs."
      • "It is very complicated to write your own correlation rules without the help of Splunk support."
      • "Most importantly, Splunk can be outrageously expensive. That is the problem with both Splunk and Sentinel. Their pricing literally explodes based on the amount of data you feed in."

      What is our primary use case?

      We are an MSSP, and some of our customers have Splunk Enterprise Security, and we run it for them.

      How has it helped my organization?

      Splunk Enterprise Security is very good for helping us find any security event across multi-cloud environments.

      Splunk's unified platform works very nicely to help consolidate networking, security, and IT observability tools.

      It helps speed up security investigations. There is a 25% to 30% improvement. There is also a 25% reduction in the mean time to resolve, but we are also using a SOAR tool, which reduces that by 70% to 80%. 

      What is most valuable?

      They have approximately 50,000 predefined correlation rules, which is quite a lot, and I find that good.

      What needs improvement?

      It is very complicated to write your own correlation rules without the help of Splunk support.

      What Splunk could do better is to create an API to the standard SIEM tools, such as Microsoft Sentinel. The idea would be to make it less painful. In ELK Stack, Kibana is the query language with which you can search log files. I believe Splunk has also a query language in which they search their log files, but once you have identified the log file that you want to use for further security correlation, you want to very quickly transport that into your SIEM tool, such as Microsoft Sentinel. That is something that Splunk could make a little bit less painful because it is a lot of effort to find that log file and forward it. An API with Microsoft Sentinel or a similar SIEM tool would be a good idea.

      For how long have I used the solution?

      I have used the solution for about five years.

      What do I think about the stability of the solution?

      It is very stable. Sometimes it can be sluggish, especially in completely virtualized environments, but overall, it is good.

      What do I think about the scalability of the solution?

      I would rate it a nine out of ten for scalability. They struggle a bit with pure virtual environments, but in terms of how much they can handle, it is pretty good.

      How are customer service and support?

      Based on what customers tell me, it has been good. If you want to write your own correlation rules, it is very difficult to do, and you need Splunk's support to write new correlation rules for the SIEM tool.

      How would you rate customer service and support?

      Positive

      Which solution did I use previously and why did I switch?

      In our organization, we use our own tools such as Kyndryl Bridge and Elastic. We use Kyndryl Bridge which essentially has a similar function. It is based on Elastic. It indexes log files and flags log files. It helps you to very quickly search log files similar to the Splunk algorithm.

      Our clients use Splunk Enterprise Security. If somebody already has Splunk as a business intelligence tool, then very often, it makes sense to expand the Splunk subscription they have to include Enterprise Security as well. We base our decisions on customer requirements, not on anything else. If a customer comes to us looking for a SIEM solution, we advise them based on their infrastructure and objectives. If we deliver the service for them and they want us to do that, we mostly go with Microsoft Sentinel when they already do not have Splunk. Otherwise, we go with Splunk Enterprise Security. We have about 30 customers in Germany who have Splunk, and we run it for them.

      Monitoring multiple clouds with Splunk Enterprise Security is no more difficult than it is with Sentinel. I find Sentinel a bit easier. Splunk, of course, is very useful if you have AWS. Generically, because Splunk is not a cloud provider itself, it fits with anything. However, integration can be challenging at times, especially in virtualized environments. Splunk struggles a bit with speed in virtualized environments. Most importantly, Splunk can be outrageously expensive. That is the problem with both Splunk and Sentinel. Their pricing literally explodes based on the amount of data you feed in.

      I like Elastic SIEM. It is a tool that allows you to determine the price. It is based on the computing power you require and not on the amount of data you put in, so it is a lot more flexible than Splunk or Sentinel. If there is a cost concern, Elastic SIEM is a good idea. Elastic is also pretty good at creating on-premises data lakes to control the amount of information you put into the same tool. That is something that neither Splunk nor Sentinel offers. 

      In our operations, we use a separate threat intelligence vendor. To the SIEM tool, we added a SOAR tool for security orchestration, automation, and response, which is very critical these days. We get threat intelligence from a third-party provider because neither Splunk nor Microsoft gives the coverage that our customers need. Splunk does not have a SOAR capability, so we add that on top. We could add that on top of any tool, so it is not specific to Splunk, but Splunk helps because going through the log files is very fast. It does help when you do the incident analysis. Elastic also provides that, and Sentinel has that to some degree, but Splunk is still the Google for log files.

      MITRE ATT&CK framework is integrated pretty much into any SIEM tool. It is not unique to Splunk. It is there in QRadar and other solutions. MITRE ATT&CK framework is helpful when designing incident response plans or playbooks. It is nice that they have it, but that is nothing unique to Splunk.

      How was the initial setup?

      It is mostly a cloud solution.

      What's my experience with pricing, setup cost, and licensing?

      The pricing is based on the volume of data fed into it, which can lead to substantial costs. This pricing model is complex and unpredictable, making cost management difficult.

      Many parts of the IT world price based on IP addresses, nodes, or the number of devices. Splunk, of course, prices its services based on the volume of data submitted into the Splunk system. From a security perspective, it is very hard for clients to figure out how many security events per second their SIEM tool needs to work with. With Splunk, it is not just the events per second. They also need to know how much data per event per second the Splunk SIEM tool needs to work with. That is almost impossible to indicate.

      Microsoft Sentinel is just as weird as Splunk. They also base the price on the amount of data you feed, whereas Elastic has a very interesting approach. It is not the amount of data you feed in; it is the amount of processing power you want to use. If you have a very large amount of data and want to correlate that very quickly, you need a lot more processing power. They base the pricing on processing power rather than on the amount of data. That is not a bad approach because that is scalable up and down depending on the needs of the organization, so the pricing from Splunk is a bit weird. That is what most people that I speak to are unhappy about because the cost can literally explode. I saw clients spend two million dollars a year just feeding data into the Splunk solution. You might have spent two million in feeding data into the SIEM tool a year, but the next year, it could be half of that. You find yourself frequently in an unpredictable situation of how much cost you are going to generate with your SIEM tool, so Splunk or Cisco needs to come up with a better and more scalable way of pricing their SIEM tool.

      What other advice do I have?

      Overall, Splunk is among the top three SIEM tools due to its capabilities and agility in bridging business analytics with security needs. They very much deserve where they stand on the Gartner Magic Quadrant. I like it a lot better than ArcSight, which was owned by HP at one point or another. In comparison to that, Splunk is much more agile and quick. It comes from a business analytics perspective. It is a lot easier to build the bridge between the business and security based on that platform. As far as stability and scalability are concerned, it is a brilliant solution.

      I would rate Splunk Enterprise Security a nine out of ten.

      Disclosure: My company has a business relationship with this vendor other than being a customer. MSP
      PeerSpot user
      Cyber Security Ops Manger at a educational organization with 1,001-5,000 employees
      Real User
      Top 10
      Sep 13, 2025
      Mission Control helps our team prioritize critical alerts and respond to incidents more efficiently
      Pros and Cons
      • "It has supported our SOC by improving it."
      • "I would definitely improve the risk-based alerts in Splunk Enterprise Security, helping SOC analysts to get to the drill-down searches."

      What is our primary use case?

      My main use cases for Splunk Enterprise Security are security operation center and incident response.

      What is most valuable?

      The Mission Control feature of Splunk Enterprise Security benefits my organization by providing quick alerts, making it easy for the SOC team to navigate events and find threats quickly.

      I use disparate security solutions that integrate or import data into Splunk Enterprise Security. This integration supports our security operations effectively because we work with different tools, and Splunk apps support many integrations, so we don't need to write custom ones; it's available by default.

      It has supported our SOC by improving it; in looking through many alerts, we can look at only the critical alerts, and the number of alerts investigated by SOC has changed drastically. Currently, my security ops team remediates security incidents with Splunk Enterprise Security within 45 minutes compared to our previous solution.

      I would be using Detection Studio, which is one of the new threat detection features in Splunk Enterprise Security that I'm interested in. Splunk Enterprise Security has definitely helped improve my organization's business resilience; it has helped us to pass our SOC 2 audit, and we have good monitoring about security alerts and threats happening.

      I assess Splunk's ability to predict, identify, and solve problems in real time as very good.

      What needs improvement?

      I would definitely improve the risk-based alerts in Splunk Enterprise Security, helping SOC analysts to get to the drill-down searches.

      The most significant challenges I face when using Splunk Enterprise Security for advanced threat detection include writing detection rules for new threats, finding out about the SPL logic, and writing correlation rules. In ES8, we are experiencing some issues with crashes, and whenever we open the correlation rule, it gives a Java error requiring a refresh. We had not seen that error before, however, we are seeing it more frequently in ES 8.1.

      For how long have I used the solution?

      I have been using Splunk Enterprise Security for five years.

      What do I think about the stability of the solution?

      Splunk Enterprise Security scales absolutely with the growing needs of my organization; it has caught up with our needs, and we use the tool without any pain.

      On a scale of one to ten, I would rate Splunk Enterprise Security overall as eight.

      What do I think about the scalability of the solution?

      We have definitely expanded our usage over the five years; our utilization of Splunk has totally changed.

      How are customer service and support?

      I would evaluate customer service and technical support as good and satisfactory because it was not satisfactory a few years back, however, now I see some positive changes, which is good.

      How would you rate customer service and support?

      Positive

      Which solution did I use previously and why did I switch?

      I used IBM QRadar.

      How was the initial setup?

      I would describe my experience with deploying Splunk Enterprise Security as easy thanks to the cloud.

      What was our ROI?

      I have seen a return on investment; though it is an expensive tool, we did see return on investment. The integration is a specific example where we see value; the basic integration with different data is easy and more adaptable. As we use more different tools, Splunk Enterprise Security is able to integrate all those things without needing to create custom integration.

      What's my experience with pricing, setup cost, and licensing?

      My experience with pricing, setup cost, and licensing for Splunk Enterprise Security is that it is expensive.

      Which other solutions did I evaluate?

      I made a change because IBM QRadar was on-premises, and we were transitioning; we had many challenges with the tool when dealing with big data, and it was not able to catch up, which is why we moved to Splunk Enterprise Security.

      What other advice do I have?

      I would advise other organizations considering Splunk Enterprise Security to use it and also utilize the built-in ES Content Pack, where you have many rules ready, instead of trying to figure everything out. Use that content pack to start, and once you have the basic fundamental detection rules, then you can expand on it.

      On a scale of one to ten, I rate Splunk Enterprise Security an eight.

      Which deployment model are you using for this solution?

      Public Cloud

      If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

      Disclosure: My company does not have a business relationship with this vendor other than being a customer.
      PeerSpot user
      reviewer2756172 - PeerSpot reviewer
      Incident Response Engineer at a international affairs institute with 1,001-5,000 employees
      Real User
      Top 20
      Sep 13, 2025
      Improves threat detection and streamlines investigations with integrated threat intelligence
      Pros and Cons
      • "I have not experienced any downtime, crashes, or performance issues with Splunk Enterprise Security."
      • "Some additional features that should be included in the next release of Splunk Enterprise Security are an integrated Attack Range, not as a separate solution, providing a way to test the rules in the production environment."

      What is our primary use case?

      My main use cases for Splunk Enterprise Security include insider threat hunting, supporting operations, and Threat Intel integration for security; I have a lot of use cases.

      How has it helped my organization?

      The features of Splunk Enterprise Security benefit my organization by providing a faster response and making it easier for the analyst to investigate.

      What is most valuable?

      The features I appreciate the most about Splunk Enterprise Security are the Enterprise Security features, the threat intelligence of Enterprise Security, the onboarded ones, and the versioning of the rules introduced on Enterprise Security; these are the top ones.

      My organization uses risk-based alerting in Splunk Enterprise Security. Splunk Enterprise Security has supported my SOC a lot, however, we have some challenges due to the architecture of our network, so there is some custom work to be done by Splunk engineers to help us maximize the benefits.

      I am using new threat detection features in Splunk Enterprise Security, including the onboard ones and Mandiant. These new features have highly improved our threat detection capabilities.

      Splunk Enterprise Security has helped improve my organization's business resilience.

      I'm not dealing with pricing, setup costs, or licensing for Splunk Enterprise Security; I'm focused on the technical part. What works with Splunk Enterprise Security is that it does work in general; I haven't faced any challenges; it's great.

      What needs improvement?

      Improving Splunk Enterprise Security is a challenging task; I have already reported several technical issues to the relevant teams and received solutions from them.

      One favor I ask for them is just to keep maintaining the on-prem version of Enterprise Security and not move everything to the cloud since we operate mostly in an air-gapped environment, so we only use some of the features of it.

      Some additional features that should be included in the next release of Splunk Enterprise Security are an integrated Attack Range, not as a separate solution, and providing a way to test the rules in the production environment.

      For how long have I used the solution?

      I've been using the solution for 11 years.

      What do I think about the stability of the solution?

      I have not experienced any downtime, crashes, or performance issues with Splunk Enterprise Security.

      What do I think about the scalability of the solution?

      Splunk Enterprise Security scales pretty well with the growing needs of my organization; we don't have issues. I have expanded the usage of Splunk Enterprise Security a lot. The process of expanding usage has been smooth; I have no problems so far, and it scales very easily.

      How are customer service and support?

      I would evaluate customer service and technical support for Splunk Enterprise Security as fast.

      How would you rate customer service and support?

      Positive

      How was the initial setup?

      I would describe my experience with deploying Splunk Enterprise Security as straightforward.

      What was our ROI?

      I have seen a return on investment with Splunk Enterprise Security, definitely, however, I don't have the specific metrics to back that up.

      What other advice do I have?

      The most significant challenge I face when using Splunk Enterprise Security for advanced threat detection is alert fatigue. Although there are ways to mitigate it, it remains a persistent issue, as evidenced by complaints from analysts. While alert fatigue is alleviated to some extent, it still persists.

      My advice to other organizations considering Splunk Enterprise Security is to at least give it a try; I know there are other solutions in the market, some of which may even be better than Enterprise Security, however, you have everything on a single pane of glass, so I think it's definitely something that enterprises should test.

      On a scale of one to ten, I rate Splunk Enterprise Security an eight out of ten.

      Which deployment model are you using for this solution?

      On-premises
      Disclosure: My company does not have a business relationship with this vendor other than being a customer.
      PeerSpot user
      Buyer's Guide
      Download our free Splunk Enterprise Security Report and get advice and tips from experienced pros sharing their opinions.
      Updated: August 2026
      Buyer's Guide
      Download our free Splunk Enterprise Security Report and get advice and tips from experienced pros sharing their opinions.