The main use cases for Splunk Enterprise Security are that the majority of my clients use it for getting complete visibility in their entire ecosystem, including IT, OT, and IoMT devices, by bringing telemetry from those sources, sending it to Splunk, and asking us to configure customized use cases and integration with some SOAR platforms, whether it's from Splunk or from third parties like Fortinet or Palo Alto.
With the unified workflow, it has impacted my ability to triage and investigate events by reducing the time needed for correlation and notification creation since previously using stand-alone solutions made correlation difficult due to multiple dashboards being involved.
Splunk has helped to reduce my clients' team's average MTTR and MTTD metrics significantly due to the unification of the different tools.
Splunk Enterprise Security is rated highly by Gartner as a top player for SOC monitoring and SIEM monitoring, playing a critical role in improving cyber resilience across multiple organizations, including at a national level deployment.
Business resilience, in terms of cybersecurity, has improved because Splunk Enterprise Security helps predict, identify, and solve problems in real-time.
What I like about Splunk Enterprise Security is the licensing model and deployment model it supports, allowing deployment on-premises or in the cloud, along with the native integration offered by Splunk Enterprise Security from a log source perspective.
The main benefits that Splunk Enterprise Security brings to my customers include the recent new features, which incorporate the SOAR platform and user behavior analytics, adding significant value to the overall offering from Splunk Enterprise Security.
The native UEBA capabilities have enhanced the visibility into unknown, sophisticated, and insider threats, as we have found lateral movement threats and identity-related threats using UEBA features.
The consolidation of SIEM, SOAR, and UEBA into a single interface has improved my team's operational efficiency because my customers are looking for a single pane of glass for complete visibility from the UEBA, SIEM monitoring, and EDR monitoring perspectives, which Splunk Enterprise Security addresses very well.
ES Essentials has improved my visibility across hybrid or multi-cloud environments.
Splunk Enterprise Security has helped to detect threats faster because when the ecosystem is fully based on Splunk Enterprise Security, with native integration across the SIEM, SOAR, and UEBA functions, it increases detection speed, although external factors such as the quality of threat intelligence also play a role.
The integration of threat intelligence directly into my workflow has improved my ability to preemptively block threats by augmenting Splunk Enterprise Security with SOAR and enhancing the overall SOC monitoring capabilities.
It has changed my approach to proactive defense significantly, providing visibility into active threats both locally and globally, and enabling me to perform threat hunting with IOCs.
Splunk Enterprise Security's Risk-Based Alerting has impacted the alert volume and analyst productivity by reducing false positives, particularly when integrating EDR solutions with Splunk Enterprise Security, which tend to produce a lot of noise.
I assess the threat topology and MITRE ATT&CK framework features as helpful in discovering the overall scope of incidents, as we create use cases mapped to the framework, usually covering around 60 to 80% depending on the customer's vertical and their attack surface.
Splunk Enterprise Security has improved the daily work experience and retention for my security team.
I would like to see improvement in the default dashboarding options, allowing for customization to avoid dependency on third-party solutions such as Microsoft Power BI.
There aren't any specific missing features I can think of at this time, but I can check with my SOC team for their feedback.
I have been working with Splunk Enterprise Security for approximately 12 to 15 years.
My experience with Splunk Enterprise Security's stability has been fantastic, with no issues so far.
Scalability may become a challenge when deploying Splunk Enterprise Security due to licensing based on ingestion GBs, while cloud-based solutions such as Microsoft Sentinel offer more flexibility without requiring additional infrastructure resources.
I find the setup process for Splunk Enterprise Security very straightforward, and our engineering team loves deploying it.
Overall, I find Splunk Enterprise Security cost-effective, providing a good ROI compared to other cloud-based SIEM solutions such as Microsoft Sentinel, especially because you only pay for specified usage without extra costs for data movement.
The pricing aspect, including setup cost and licensing, is satisfactory because we're happy with the level of discount we receive as part of our partnership tier.
In comparison to Microsoft Sentinel and other SIEM products, I don't have negative feedback about Splunk Enterprise Security, as it offers a significant number of native integrations and is a mature product with valuable new capabilities.
ES Essentials has improved my visibility across hybrid or multi-cloud environments.
I'm not sure what the current version of Splunk Enterprise Security is, but I need to check.
I utilize AI in Splunk Enterprise Security, but I recently went through Splunk Enterprise Security's documentation and couldn't find much on AI capabilities. I need to check the official Splunk Enterprise Security documentation for updates on AI.
I haven't personally experienced a reduction in analyst burnout or fatigue, but I know our SOC analysts love working on Splunk Enterprise Security.
My advice for organizations considering Splunk Enterprise Security is to look for a licensing model that doesn't restrict data ingestion, perhaps a perpetual license that allows scalability with added infrastructure, particularly for larger enterprises. I would rate this product a 9 out of 10.