No more typing reviews! Try our Samantha, our new voice AI agent.
Hari Haran. - PeerSpot reviewer
Technical Associate at Positka
Reseller
Top 20
Feb 26, 2026
Security operations have become streamlined and threat investigations gain rapid, actionable insight
Pros and Cons
  • "Regarding scalability, Splunk Enterprise Security is way ahead compared to other products, and I would score it at the maximum."
  • "During my experience with Splunk Enterprise Security, I have faced some significant challenges, particularly with customers adapting from version 7 to version 8."

What is our primary use case?

I would like to discuss Enterprise Security, and I explain that the main use case for the product is to protect our customers and support various attacks.

Regarding threat detection, I explain that during investigations, most of our SOC-related customers use Splunk Enterprise Security to identify threats.

How has it helped my organization?

In terms of benefits, Splunk Enterprise Security provides numerous advantages to end users, notably in reducing personnel needs for SOC operations.

Regarding pricing for Splunk Enterprise Security, I find it relatively affordable globally, although it seems costly in India due to currency exchange.

What is most valuable?

In my opinion, the functions in Splunk Enterprise Security that I find most valuable include unique features and tools that the product offers.

What needs improvement?

For improvement points, I think Splunk has several enhancements on the table right now to enhance Splunk Enterprise Security with functionalities and threat detection improvements.

Buyer's Guide
Splunk Enterprise Security
July 2026
Learn what your peers think about Splunk Enterprise Security. Get advice and tips from experienced pros sharing their opinions. Updated: July 2026.
908,877 professionals have used our research since 2012.

For how long have I used the solution?

I have been working with Splunk Enterprise Security for seven years.

What do I think about the stability of the solution?

For stability, I would rate it a 10, as Splunk Enterprise Security is generally stable, especially now with its latest version.

What do I think about the scalability of the solution?

Regarding scalability, Splunk Enterprise Security is way ahead compared to other products, and I would score it at the maximum.

How are customer service and support?

I would rate Splunk Enterprise Security's technical support as a 10, as they provide 24/7 assistance based on priorities and are accessible for queries.

Which solution did I use previously and why did I switch?

In comparison to other products, I think previous tools such as IBM QRadar were competitors, but currently, I hear about CrowdStrike getting into the picture.

How was the initial setup?

In general, I find that the initial setup for Splunk Enterprise Security is simple, especially with clear documentation from Splunk.

It depends on the client; if they have a qualified engineer with experience in Splunk Enterprise Security, they can handle the setup themselves.

What about the implementation team?

The solution is deployed both on-premises and cloud-based, depending on the customer's domain.

What other advice do I have?

My feedback regarding some processes of customizing, developing, and testing in Splunk Enterprise Security is that I am thinking from a customer perspective, focusing on the customizations they require.

I have experience with risk-based alerting in Splunk Enterprise Security, as we configure based on the priority of the instance, servers, or the endpoints.

During my experience with Splunk Enterprise Security, I have faced some significant challenges, particularly with customers adapting from version 7 to version 8.

Which deployment model are you using for this solution?

Hybrid Cloud
Disclosure: My company has a business relationship with this vendor other than being a customer. reseller
Last updated: Feb 26, 2026
Flag as inappropriate
PeerSpot user
Ankar Aung - PeerSpot reviewer
Network Security Engineer at a consultancy with 10,001+ employees
Real User
Top 5
Jan 8, 2026
Centralized dashboards have improved log visibility and support faster security investigations
Pros and Cons
  • "Splunk Enterprise Security can retain logs for compliance purposes longer than the usual three months."
  • "Splunk Enterprise Security documentation exists, but compared to Palo Alto, Palo Alto has more knowledge base articles."

What is our primary use case?

I deal with the Palo Alto FO and then Cortex XSIAM. I work with Cortex XSIAM and Cortex EDR products. We recently adopted Cortex XSIAM from Splunk Enterprise Security as our SIEM product for log management.

I have two to three years of experience with Splunk Enterprise Security, but not continuously; this is just a tool used by me, not daily. We send logs from the firewalls to XSIAM and analyze the traffic logs to determine whether deny or allow for migration. We use both Splunk and Cortex XSIAM for log analysis. I have never dealt with Splunk support.

What is most valuable?

I have experience with Palo Alto, Cisco, and Fortinet products. Splunk Enterprise Security is more dedicated to logs, not a unified product like Palo Alto. Palo Alto Cortex has the same UI across Cortex EDR and Cortex XSIAM, so all the product family is in one UI, whereas Splunk Enterprise Security is more focused on log search.

Palo Alto has better speed and better visibility. I can see all the M-points from one UI and search the logs from this UI. I use disparate security solutions that integrate or import data into Splunk Enterprise Security, including different log sources from the endpoint, firewall, router, switches, and everything that needs logging for visibility.

Splunk Enterprise Security can retain logs for compliance purposes longer than the usual three months. The dashboard capability also allows Splunk Enterprise Security to create dashboards based on logs, which makes it really helpful for visibility.

What needs improvement?

I feel more comfortable using XSIAM now compared to Splunk Enterprise Security. Splunk Enterprise Security is already a mature product, so I do not have much to point out. It could be a little more user-friendly, which would be nice.

It could also expand the product family beyond security log search. Since it has the capability of indexing things, perhaps Splunk Enterprise Security could develop their own EDR agent like Palo Alto and create a product family with a unified dashboard. This would definitely help the enterprise.

Splunk Enterprise Security documentation exists, but compared to Palo Alto, Palo Alto has more knowledge base articles. Even though the concepts are the same and multiple engineers have written articles for cross-reference, I do not see this level of documentation in Splunk Enterprise Security.

For how long have I used the solution?

I have two to three years of experience with Splunk Enterprise Security, but not continuously; this is just a tool used by me, not daily.

Which solution did I use previously and why did I switch?

The switch to Cortex came from management, likely because the Palo Alto product family is already in our environment. We have been using Palo Alto GlobalProtect and other security products, so bringing XSIAM into the environment makes sense.

What other advice do I have?

I do not see a real difference between XSIAM and Splunk Enterprise Security; they both have a search query functionality. Splunk Enterprise Security has Splunk query language, so it is just a different language and different way of searching logs. Eventually, we get the same logs including source, destination, port, and traffic allow and deny information.

I used to be a customer with Splunk Enterprise Security. I have hands-on experience but not extensive experience with Splunk Enterprise Security products in the past. I am more focused on networking than the security team. I do not have an answer about how long on average it takes SecOps teams to remediate security incidents using Splunk Enterprise Security.

I would rate this review an 8.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Last updated: Jan 8, 2026
Flag as inappropriate
PeerSpot user
Buyer's Guide
Splunk Enterprise Security
July 2026
Learn what your peers think about Splunk Enterprise Security. Get advice and tips from experienced pros sharing their opinions. Updated: July 2026.
908,877 professionals have used our research since 2012.
Vice President Research And Development at OSINT Ambition
Real User
Top 20
Jul 30, 2025
Helps us manage logs easily and detect threats effectively
Pros and Cons
  • "Splunk Enterprise Security performs 80% of our work on its own; we just have to do the remaining 20%, which gives us the freedom to explore and detect threats more effectively."
  • "Its deployment is difficult. I remember when I first started learning, I faced several challenges, especially when deploying VMware in a virtual environment."

What is our primary use case?

I work in a SOC team where I study threat hunting and threat determination. Most of my work is based on looking for malware traffic or suspicious traffic in Splunk Enterprise Security. I belong to the SOC team.

What is most valuable?

The best feature about Splunk Enterprise Security is its clean interface and the detail it provides. It helps us manage logs with a very clean interface, which is not available in other software. 

They also provide extensive learning resources on their official site that help us while performing tasks. Its documentation and community are very strong, making it a perfect SOC tool. If we come across any problem, we can search the community or consult the documentation for solutions. 

It is very clean and detailed, helping us detect threats easily. Splunk Enterprise Security performs 80% of our work on its own; we just have to do the remaining 20%, which gives us the freedom to explore and detect threats more effectively.

What needs improvement?

The machine learning capabilities of Splunk Enterprise Security are good, but they can be improved. In a changing threat landscape, its machine learning capability can be improved in behavior-based analysis because signature-based analysis does not work very well currently.

It can improve in detecting new types of attacks or IOCs through behavior-based learning capabilities. For example, if there are malware traffics incoming, it should detect them using network logs more precisely, as most malware traffic uses the same kind of port or attack.

There should be a community program or hackathon-type events where people can develop more advanced and sophisticated machine learning models for Splunk Enterprise Security to enhance its functionality. 

Adding a chatbot similar to GitHub Copilot in Splunk Enterprise Security would be beneficial. It would help write different kinds of sophisticated queries and assist in solving problems we encounter, similar to what we have in VS Code.

There is good scope for developing Splunk Enterprise Security for low-level systems such as Raspberry Pi. However, for server deployment, a robust server is essential. Development should focus on making Splunk Enterprise Security capable of running on devices such as Raspberry Pi.

For how long have I used the solution?

I used Splunk Enterprise for a long time in previous organizations. I have also used the Community version for my personal projects, which is available for free. I have experience with both Splunk Enterprise Security and the normal Splunk Community version. I still use Splunk Enterprise Security quite frequently when working with SOC and related processes.

What do I think about the scalability of the solution?

Splunk Enterprise Security is highly scalable, which is why approximately 95% of the industry uses it without experiencing scalability problems. It performs exceptionally well when discussing scalability.

How are customer service and support?

I do not remember contacting technical or customer support. Whenever I faced any problem, I usually consulted the documentation or community, and 99% of my problems were solved that way.

Which solution did I use previously and why did I switch?

I have used Wazuh, Elasticsearch, Kibana, and some basic Linux SOC management tools such as Zeek and Wireshark as alternatives to Splunk Enterprise Security. However, I find Splunk Enterprise Security to be much more advanced than those tools, as they lack automation and machine learning capabilities, requiring customization from the user. Splunk Enterprise Security is more refined and offers a better experience.

How was the initial setup?

Its deployment is difficult. I remember when I first started learning, I faced several challenges, especially when deploying VMware in a virtual environment. It was quite a difficult task. However, when deploying on a server, I would consider it to be at a medium level of difficulty. On the other hand, if you're deploying for a learning lab or something similar, it’s pretty much on the hard side.

For personal home labs, it is a one-person job, meaning a seasoned professional can handle it. For enterprise-level deployment, a person managing operations and a person handling server management is sufficient. After the initial deployment, one person is enough for a mid to low-level company, while a higher-order company requires a team to operate Splunk Enterprise Security.

Splunk Enterprise Security requires very little maintenance on my end, as it has improved significantly. If there are no frequent changes in the server, there is not much maintenance required. I have not invested much time in updates or maintenance, so once deployed, you just need a good professional to use it; maintenance is not much of a concern.

What's my experience with pricing, setup cost, and licensing?

The pricing of Splunk Enterprise Security is fair for what it provides. If someone wants everything for free, it is not a reasonable expectation. Everything comes at a price, and I find it to be affordable, which is why every industry uses it. Its pricing is fair, and the community version works well for learning purposes.

What other advice do I have?

I would rate Splunk Enterprise Security an eight out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Harshit Pawar - PeerSpot reviewer
Cybersecurity Engineer at a tech vendor with 201-500 employees
Real User
Top 20
Jul 27, 2026
Centralized threat data has powered faster incident response and proactive attack prevention
Pros and Cons
  • "The best features and the most important feature I want to highlight about Splunk Enterprise Security is its capability to process large amounts of data."
  • "From the point of view of deployments and making custom modifications in this particular product, it becomes really difficult because deployments of Splunk can get really tricky."

What is our primary use case?

I work for a cybersecurity-based company. We have our own products and solutions that we build and deliver to our customers, primarily revolving around Threat Intelligence solutions, TIP platforms, SOAR platforms, and incident response platforms.

The majority of tools that I work with are centered around threat intelligence, so we share threat intelligence for actioning on end security tools. These end security tools that consume threat intelligence are primarily Defender technology stack, which is how the entire arrangement functions.

Cyware has its own threat intelligence platform called Intel Exchange. This is a central data lake for all threat intelligence that any enterprise or organization might want to collect. An organization using threat intelligence from multiple sources collects threat intelligence from different types of open sources, RSS feeds, news articles, and blogs. They consume feeds from regulatory bodies like CERTs and ISACs, and they also purchase premium threat intelligence from threat intel feed providers like CrowdStrike, Recorded Future, and Microsoft Defender Threat Intelligence. When a customer has been consuming threat intelligence from these different sources, we consolidate everything, ingest it into a single platform, normalize it, and bring everything into a single structure. Threat intelligence is further processed, analyzed, and forwarded to end security tools for proactive blocking. If I am a financial sector company seeing other financial sector organizations like other banks getting targeted by a particular cyber attack, I use that intelligence to proactively block these threats in my environment before such an attack can happen in my organization.

I am using different tools including the entire Microsoft suite, most of the time working with Microsoft Sentinel, Microsoft Defender for Endpoint, CrowdStrike, Zscaler, and Splunk Enterprise Security.

What is most valuable?

Splunk Enterprise Security is basically a complete enterprise security solution, but it is primarily built on top of a security event and information management system; it is a SIEM solution. Splunk Enterprise Security acts as a data lake for all logs that I collect from different types of log sources within my environment. I bring logs and activity from my entire environment into a single place, and once this data is stored, I run analytics rules on top of it. These analytics rules are defined based on the different types of malicious behavior that I want to identify happening in my environment, and if any of these behaviors identify a match, it triggers alerts. These alerts could be actual malicious activities happening in my environment. Once those alerts are triggered, they are assigned to different types of analysts; these are SOC analysts who assign these alerts to themselves and then start investigating those alerts to see if the activity observed is actually malicious or not. Depending on those investigations, analysts close those incidents, and if something malicious has been identified, they take remediation actions. At that point, I integrate SOAR solutions. I integrate my own SOAR solution, which automates this entire actioning process.

For example, if a suspicious sign-in on a user account has happened and the sign-in was successful, my SOAR playbook resets the password for that particular user, notifies the user's manager, and sends out the necessary communication to that particular user whose account has been compromised. This is how Splunk Enterprise Security can be integrated with different security tools and how it works.

The best features and the most important feature I want to highlight about Splunk Enterprise Security is its capability to process large amounts of data. When I compare Splunk with all the other SIEM solutions that are out there in the market, Splunk has to be the one that can easily process huge volumes of data and scales really well. The query language that Splunk has, which is called SPL, is one of the best query languages out there that will help anybody to query large datasets and return results in a very quick and short period of time compared to the other SIEM solutions. For example, QRadar is extremely slow and sluggish when I want to query large datasets, but Splunk excels in that regard.

What needs improvement?

From the point of view of deployments and making custom modifications in this particular product, it becomes really difficult because deployments of Splunk can get really tricky. It requires a huge amount of hardware and infrastructure to run on. From that perspective, it is really compute heavy, and Splunk is one of the priciest solutions out there, so from a cost perspective as well, it is not one of the easiest to start with.

I do not think there is any particular lack of functionality with the product; the product is really good, but there are a few aspects in which Splunk Enterprise Security can become really difficult for people to get started with as beginners.

For how long have I used the solution?

I have been working with Splunk Enterprise Security for almost a year.

What do I think about the stability of the solution?

Splunk Enterprise Security definitely helps reduce the metrics that every security solution is built to reduce. If somebody was investigating these security threats and incidents manually and then manually going ahead and taking every single step, it would have taken those analysts a huge amount of time to remediate and protect their environments from these cybersecurity threats. Solutions like these are the reason why people buy them because they help reduce mean time to remediate and mean time to investigate, so that is the primary reason these solutions are primarily bought for.

What do I think about the scalability of the solution?

Splunk Enterprise Security is a very good solution when it comes to scalability, so I would rate it nine.

How are customer service and support?

I have not really interacted with the technical support of Splunk because I am not the one who is directly interacting with the product side of Splunk because somebody else does. I am not the one who really procures this product and interacts with their support team.

Which solution did I use previously and why did I switch?

I actually use Microsoft Sentinel, but that is not a native part of my toolset that I use. I integrate these solutions with the other set of tools that I work with at the moment.

I work with Defender and I work with Sentinel, so it is part of my job that I usually integrate these solutions with my solution that we sell.

I have worked with Defender for Cloud Apps, Defender for Endpoints, and I have also had a chance to work with Microsoft Defender for Identity, so I have worked on a few of these Defender solutions that Microsoft offers. We are a partner with Splunk.

How was the initial setup?

Both approaches are possible, but if I am simply looking to integrate the logs from my native technologies that I have in my infrastructure, I can simply use the out-of-the-box connectors, so I do not need to rely on third-party tools. If I have any particular third-party tool that allows me to ingest some custom data, that can also be done, so both things are possible.

What was our ROI?

Primarily, there are two things that Splunk Enterprise Security helps with: streamlining the log ingestion and normalization of all the logs in my environment into a single place; that is the first and foremost reason why anybody would want to buy Splunk Enterprise Security. Once I get all the data in a single platform, it really helps me analyze all those intelligence and data logs in a single place; these are done via the SPL query language that they provide along with the rules that can be scheduled and run on a regular basis. First, it helps streamline everything into a single place and helps act as a data lake for all logs in my environment. Second, it is really fast and quick in analyzing that large dataset that it can collect, so it provides a huge volume of better derived insights compared to other security solutions.

Which other solutions did I evaluate?

Microsoft Sentinel would be a top competitor, and recently Palo Alto has released their own SIEM solution as well, so these would be the top competitors.

In terms of technical capabilities, Splunk Enterprise Security would be the highest. In terms of ease of use and ease of adoption, Microsoft Sentinel would be the one, and for the other SIEM solution, they are definitely in the challenging category, but not really the market leaders.

What other advice do I have?

The threat detection module capability in Splunk Enterprise Security really comes in handy because that ties in my threat intelligence signals, and input from my different threat intelligence solutions can be brought into the picture when I am actually looking to prioritize the types of threats that I want to investigate and remediate in my environment, so that really becomes handy. I would rate this product an eight overall.

Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
Last updated: Jul 27, 2026
Flag as inappropriate
PeerSpot user
Ashiq Ashraf - PeerSpot reviewer
Specialist-Infrastructure Opertions at Allianz Technology
Real User
Top 10
May 22, 2025
Effective data management and threat detection through comprehensive integration and rapid response
Pros and Cons
  • "Splunk Enterprise Security provides the foundation for unified threat detection, investigation, and response, enabling fast identification of critical issues."
  • "The pricing of Splunk Enterprise Security is not very affordable, and I have seen many companies planning to leave because of cost concerns."

What is our primary use case?

I'm an end user, admin, and consultant. We use Splunk Enterprise Security internally in our organization, and I also use it for my personal studies. My usual use cases for Splunk Enterprise Security include monitoring several kinds of exchange server logs and Office 365 logs, among others, as we have multiple monitoring use cases based on our requirements in our environment. We were trying to solve multiple things by implementing Splunk Enterprise Security, particularly for monitoring our applications based on the insurance business, so we use Splunk Enterprise Security logs for security purposes and internal infrastructure monitoring, including logs matching security purposes in our Office 365 and exchange servers.

What is most valuable?

The most valuable features of Splunk Enterprise Security are several add-ons and TAs, while the lack of a DB requirement is a significant advantage for the business, allowing easier management without needing in-depth DB knowledge. I find that Splunk Enterprise Security's ability to import data from various sources, including looking up Excel files, is quite effective, providing a good way for management.

We import data from several unique data sources into Splunk Enterprise Security, possibly more than a hundred because we have AWS and multiple servers. We have disparate security solutions that integrate data into Splunk Enterprise Security. I can still query data in Splunk Enterprise Security regardless of where it resides, and in my perspective, the query provides data quickly.

Splunk Enterprise Security has improved our organization's ability to ingest and normalize data compared to before using Splunk Enterprise Security. The unified platform helps consolidate networking, security, and IT observability tools, which is very relevant to our internal needs. Using Splunk Enterprise Security, our focus was not on reducing alert volume but on properly finding and handling alerts; we've managed to capture 100% of them effectively.

Splunk Enterprise Security provides the relevant context to help guide investigations by allowing us to share application logs and details with clients efficiently. We utilize out-of-the-box detections in Splunk Enterprise Security, and we have created dashboards that add value to our monitoring efforts. Customizing, developing, testing, deploying, and refining detections in Splunk Enterprise Security is easy; it has been a good experience without significant difficulties.

We upgraded to Splunk Enterprise Security from version 8.0.4 to 9.0.6, and also from 8.1.4 to 9.0.6; it worked well with the support we received from the team, and it has proven to be very useful. Splunk Enterprise Security provides the foundation for unified threat detection, investigation, and response, enabling fast identification of critical issues.

What needs improvement?

The solution could be improved by integrating more application monitoring features and possibly incorporating AI capabilities to enhance its functionality.

For how long have I used the solution?

I've been working with Splunk Enterprise Security for six years.

What do I think about the stability of the solution?

Splunk Enterprise Security is stable and scalable, making it a good tool that is beneficial for our needs.

What do I think about the scalability of the solution?

Splunk Enterprise Security is stable and scalable, making it a good tool that is beneficial for our needs.

What other advice do I have?

I participated in the deployment process of Splunk Enterprise Security, and we performed UAT before moving it to production. It's not the most affordable solution, as I've witnessed several companies considering leaving due to cost factors. The pricing of Splunk Enterprise Security is not very affordable, and I have seen many companies planning to leave because of cost concerns.

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Associate I at Positka
Real User
Top 20
Feb 17, 2026
Advanced analytics has improved resilience and real-time threat mapping across diverse data
Pros and Cons
  • "Splunk Enterprise Security has helped greatly improve the organization's business resilience."
  • "I think the pricing aspect of Splunk Enterprise Security is quite high compared to other products, which I hear from most of my customers."

What is our primary use case?

My use cases for Splunk Enterprise Security involve both security as well as data analytics.

How has it helped my organization?

Splunk Enterprise Security has helped greatly improve the organization's business resilience.

What is most valuable?

The features of Splunk Enterprise Security that I appreciate the most include the recent AI feature and the MITRE mapping feature.

AI helps in analyzing a certain detection within Splunk Enterprise Security and assists with some tasks that I might require internet or other tabs to work on, while MITRE ATT&CK helps me to map the attacks and provides coverage for my attacks.

What needs improvement?

I would appreciate improvements in the licensing aspect, especially with the SVC-based license, as there is no proper view on top of it regarding how much CPU and usage is being done on the SVC-based license, along with updates to the SOAR version.

The experience with alerts, specifically risk-based alerts, is good, but it might need some improvement as there might be some deviation or false positives, so I think implementing AI over there might increase the feasibility or view around it.

I think the pricing aspect of Splunk Enterprise Security is quite high compared to other products, which I hear from most of my customers.

For how long have I used the solution?

I have been working with Splunk Enterprise Security for approximately 3.5 years.

What do I think about the stability of the solution?

I would assess the stability and reliability of Splunk Enterprise Security as very good, with not much downtime or crashes, as it depends on the hardware used and the kind of setup done, which is primarily based on misconfiguration or not predicting something.

I have not faced any significant challenges when using Splunk Enterprise Security; there is not much that I cannot solve.

What do I think about the scalability of the solution?

Splunk Enterprise Security scales very well with the growing needs of my organization and my clients' organizations.

Expanding usage with Splunk Enterprise Security consumes time and effort, but the end result is actually good.

How are customer service and support?

I would evaluate customer service and technical support as good but not very good.

On a scale of one to ten, I would rate them somewhere around seven to eight.

How would you rate customer service and support?

Positive

How was the initial setup?

I would describe my experience with deploying Splunk Enterprise Security as good, pretty easy, straightforward, and with plenty of documentation.

I have not faced any challenges during the deployment aspect; even if I did, I figured it out using Splunk Community and Splunk documentation.

What was our ROI?

It does bring measurable benefits in terms of return on investment for clients; specifically, for banking or finance customers who wish to contain their data within their environments, they would definitely go for Splunk Enterprise Security compared to CrowdStrike, but less mature organizations might prefer other products.

Which other solutions did I evaluate?

The key differences, both pros and cons of Splunk Enterprise Security in comparison to CrowdStrike, are that I am a Splunk enthusiast and I love Splunk Enterprise Security, but CrowdStrike is good in search and detections due to its status as a threat intel partner, which offers good detections, while customization done in Splunk Enterprise Security might take too much time on CrowdStrike and there are fewer integration options with CrowdStrike.

I don't have much idea on disadvantages of Splunk Enterprise Security apart from the pricing.

What other advice do I have?

I am currently working with Splunk products.

I work with Splunk Enterprise and Splunk Enterprise Security.

The process for customizing, developing, testing, deploying, and refining detections in Splunk Enterprise Security is pretty easy for me as an expert, but I'm not sure for a new user; being a Splunk architect, I feel it's a little easy and the customization is very helpful.

We have it integrated with various disparate solutions including RSA, CrowdStrike, AWS, Google, Microsoft, Docker, firewalls, switches, and multiple other technologies.

This integration supports my security operations by fetching logs about user activity and audit logs and actions taken by the user; for normal products, this allows me to analyze, detect, and correlate two or three different datasets to build up a use case from which I can deduce some information, and with the queries I have using SPL queries, I can get some data analytics or alerts or reports based on which I can take action.

I use risk-based alerting in Splunk Enterprise Security.

My experience with risk-based alerting, while not mainly focused on the SOC part of Splunk Enterprise Security, provides support to my engineering efforts.

I am not currently using any new threat detection features in Splunk Enterprise Security; I have no idea about that part of it.

My impressions of Splunk Enterprise Security's capability to predict, identify, and solve problems in real-time depend on what kind of data is being received and the use cases being written; it is not straightforward, but because Splunk Enterprise Security is an analytics platform without AI on top of it, it feels that some data sources are less predictable, yet for jobs that are repetitive or similar, Splunk Enterprise Security works well.

I would rate this product a 9 out of 10.

Which deployment model are you using for this solution?

Hybrid Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Other
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
Last updated: Feb 17, 2026
Flag as inappropriate
PeerSpot user
IT Admin at EuroSerwis
Real User
Top 20
Sep 30, 2025
Faced challenges with cost and support but have gained insights into traffic monitoring and threat detection
Pros and Cons
  • "What I appreciate about Splunk Enterprise Security is creating the newest SPL for network traffic and using the risk-based alerting feature that helps my organization by allowing me to learn more information about Splunk every day because it is a big platform."
  • "I encounter issues such as downtime, bugs, glitches, and unbox errors."

What is our primary use case?

My use case for the project is thin.

What is most valuable?

What I appreciate about Splunk Enterprise Security is creating the newest SPL for network traffic. I use the risk-based alerting feature. The risk-based alerting helps my organization by allowing me to learn more information about Splunk every day because it is a big platform.

What needs improvement?

I think that Splunk Enterprise Security is a very good platform, but the price is very high. I don't know how to explain what else can be improved in Splunk Enterprise Security aside from pricing. Support is important for improvements. My thoughts on better support include better knowledge base and better response time; it encompasses both aspects.

For how long have I used the solution?

I moved to Splunk Enterprise Security and learned it for two to three years, but in the last year, I worked with my friends on one project.

What do I think about the stability of the solution?

I rate the stability as a five. I encounter issues such as downtime, bugs, glitches, and unbox errors.

What do I think about the scalability of the solution?

Only two users use Splunk Enterprise Security.

How are customer service and support?

Support is important for improvements. My thoughts on better support include better knowledge base and better response time; it encompasses both aspects. I rate support as a five.

How would you rate customer service and support?

Positive

How was the initial setup?

I think it was easy to install, but this platform has many components I must learn. It took me months to deploy.

What other advice do I have?

I am reviewing Splunk Enterprise Security today, and I am working on one simple product and creating simple SPL. My thoughts on customizing, developing, testing, deploying, and refining detections are focused on detection. The testing is just the last component. My thoughts on the testing feature in Splunk Enterprise Security involve the network traffic to Cisco traffic, Uniper, or low car infrastructure. I am using new threat detection features in Splunk Enterprise Security and would work on big projects in the future. I do not use disparate security solutions that integrate or import data into Splunk Enterprise Security. I am wanting to learn more because I create simple SPL, and my friends are not Splunk Enterprise Security expert admins. I would recommend Splunk Enterprise Security to other users because it is a platform for monitoring all traffic, network infrastructure, hardware, software, and everything.

I rate the solution overall as a five out of ten.

Which deployment model are you using for this solution?

Public Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Sage Martinez - PeerSpot reviewer
IT Security Analyst I at a comms service provider with 1,001-5,000 employees
Real User
Top 10
Sep 11, 2025
Has improved investigation speed with effective search features and real-time analysis
Pros and Cons
  • "Everything I'm seeing now in Splunk Enterprise Security is effective, especially the AI and the Attack Analyzer, which I found particularly impressive."
  • "I would say we haven't seen any return on investment with Splunk Enterprise Security because we are still maturing and trying to get everything situated, and we're experiencing roadblocks with other teams not wanting to give us what we need."

What is our primary use case?

My main use cases for Splunk Enterprise Security are responding to alerts, looking for logs, and for investigations.

What is most valuable?

The features I appreciate the most about Splunk Enterprise Security are the basic search capabilities, seeing what I input into the search and what results I receive, such as the charts and their visibility. These features benefit my organization by helping with our investigations; when we receive something, we're able to quickly find its source and nature. Everything I'm seeing now in Splunk Enterprise Security is effective, especially the AI and the Attack Analyzer, which I found particularly impressive.

What needs improvement?

The most significant challenge I face when using Splunk Enterprise Security for advanced threat detection is not with Splunk itself, but with our own asset management and knowing what our assets are, particularly regarding visibility.

For how long have I used the solution?

I have been using Splunk Enterprise Security for about a year.

What do I think about the stability of the solution?

I have experienced maybe one downtime, crash, or performance issue.

I would describe the stability and reliability of Splunk Enterprise Security as good, with only a couple of issues that were within our own team.

What do I think about the scalability of the solution?

Splunk Enterprise Security has been good so far in scaling with the growing needs of my organization; we haven't been growing too much to where it's a problem, but it's been performing well.

What was our ROI?

I would say we haven't seen any return on investment with Splunk Enterprise Security because we are still maturing and trying to get everything situated, and we're experiencing roadblocks with other teams not wanting to give us what we need.

Which other solutions did I evaluate?


What other advice do I have?

Splunk Enterprise Security handles problems in real-time. 

When rating Splunk Enterprise Security overall, I'd give it a nine out of ten. I appreciate that it has a good UI that looks good and works well. I would recommend Splunk Enterprise Security.

Which deployment model are you using for this solution?

Public Cloud
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
PeerSpot user
Security Engineer at a consultancy with 11-50 employees
Real User
Top 20
Sep 10, 2025
Search features have improved our threat detection and streamlined data analysis
Pros and Cons
  • "The feature I appreciate the most about Splunk Enterprise Security is Search Processing Language, which has benefited my organization by making searching data a lot easier than other tools I've used."
  • "Sometimes talking through email isn't the most effective method, as they go through troubleshooting steps we've already taken, which requires additional back-and-forth communication."

What is our primary use case?

My main use cases for Splunk Enterprise Security are detections and security.

What is most valuable?

The feature I appreciate the most about Splunk Enterprise Security is Search Processing Language. These features have benefited my organization by making searching data a lot easier than other tools I've used.

What needs improvement?

Improvement for Splunk Enterprise Security is hard to address because I'm not on version 8 yet. The main thing was integrating all the different pages we have into one, which they have accomplished in version 8.1.2. I'm looking forward to using it.

For how long have I used the solution?

I have been using Splunk Enterprise Security for two years.

What do I think about the stability of the solution?

I would assess the stability and reliability of Splunk Enterprise Security as having no issues so far.

What do I think about the scalability of the solution?

Splunk Enterprise Security appears to scale with the growing needs of my organization. We haven't expanded usage at all yet.

How are customer service and support?

I would evaluate customer service and technical support as seven or eight out of ten. They're normally great. Sometimes talking through email isn't the most effective method, as they go through troubleshooting steps we've already taken, which requires additional back-and-forth communication.

How would you rate customer service and support?

Positive

What was our ROI?

I would imagine we have seen return on investment with Splunk Enterprise Security.

What other advice do I have?

My advice to other organizations considering Splunk Enterprise Security is that it is definitely worth implementing, but it must be done properly. Make sure you have all preparations complete before getting the implementation package. I rate Splunk Enterprise Security eight out of ten.

Which deployment model are you using for this solution?

Public Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
PeerSpot user
reviewer2869212 - PeerSpot reviewer
Head Of Solution Engineer at a security firm with 201-500 employees
Real User
Top 20
Jul 15, 2026
Unified security monitoring has improved threat detection speed and strengthened proactive defense
Pros and Cons
  • "Splunk Enterprise Security is rated highly by Gartner as a top player for SOC monitoring and SIEM monitoring, playing a critical role in improving cyber resilience across multiple organizations, including at a national level deployment."
  • "Scalability may become a challenge when deploying Splunk Enterprise Security due to licensing based on ingestion GBs, while cloud-based solutions such as Microsoft Sentinel offer more flexibility without requiring additional infrastructure resources."

What is our primary use case?

The main use cases for Splunk Enterprise Security are that the majority of my clients use it for getting complete visibility in their entire ecosystem, including IT, OT, and IoMT devices, by bringing telemetry from those sources, sending it to Splunk, and asking us to configure customized use cases and integration with some SOAR platforms, whether it's from Splunk or from third parties like Fortinet or Palo Alto.

How has it helped my organization?

With the unified workflow, it has impacted my ability to triage and investigate events by reducing the time needed for correlation and notification creation since previously using stand-alone solutions made correlation difficult due to multiple dashboards being involved.

Splunk has helped to reduce my clients' team's average MTTR and MTTD metrics significantly due to the unification of the different tools.

Splunk Enterprise Security is rated highly by Gartner as a top player for SOC monitoring and SIEM monitoring, playing a critical role in improving cyber resilience across multiple organizations, including at a national level deployment.

Business resilience, in terms of cybersecurity, has improved because Splunk Enterprise Security helps predict, identify, and solve problems in real-time.

What is most valuable?

What I like about Splunk Enterprise Security is the licensing model and deployment model it supports, allowing deployment on-premises or in the cloud, along with the native integration offered by Splunk Enterprise Security from a log source perspective.

The main benefits that Splunk Enterprise Security brings to my customers include the recent new features, which incorporate the SOAR platform and user behavior analytics, adding significant value to the overall offering from Splunk Enterprise Security.

The native UEBA capabilities have enhanced the visibility into unknown, sophisticated, and insider threats, as we have found lateral movement threats and identity-related threats using UEBA features.

The consolidation of SIEM, SOAR, and UEBA into a single interface has improved my team's operational efficiency because my customers are looking for a single pane of glass for complete visibility from the UEBA, SIEM monitoring, and EDR monitoring perspectives, which Splunk Enterprise Security addresses very well.

ES Essentials has improved my visibility across hybrid or multi-cloud environments.

Splunk Enterprise Security has helped to detect threats faster because when the ecosystem is fully based on Splunk Enterprise Security, with native integration across the SIEM, SOAR, and UEBA functions, it increases detection speed, although external factors such as the quality of threat intelligence also play a role.

The integration of threat intelligence directly into my workflow has improved my ability to preemptively block threats by augmenting Splunk Enterprise Security with SOAR and enhancing the overall SOC monitoring capabilities.

It has changed my approach to proactive defense significantly, providing visibility into active threats both locally and globally, and enabling me to perform threat hunting with IOCs.

Splunk Enterprise Security's Risk-Based Alerting has impacted the alert volume and analyst productivity by reducing false positives, particularly when integrating EDR solutions with Splunk Enterprise Security, which tend to produce a lot of noise.

I assess the threat topology and MITRE ATT&CK framework features as helpful in discovering the overall scope of incidents, as we create use cases mapped to the framework, usually covering around 60 to 80% depending on the customer's vertical and their attack surface.

Splunk Enterprise Security has improved the daily work experience and retention for my security team.

What needs improvement?

I would like to see improvement in the default dashboarding options, allowing for customization to avoid dependency on third-party solutions such as Microsoft Power BI.

There aren't any specific missing features I can think of at this time, but I can check with my SOC team for their feedback.

For how long have I used the solution?

I have been working with Splunk Enterprise Security for approximately 12 to 15 years.

What do I think about the stability of the solution?

My experience with Splunk Enterprise Security's stability has been fantastic, with no issues so far.

What do I think about the scalability of the solution?

Scalability may become a challenge when deploying Splunk Enterprise Security due to licensing based on ingestion GBs, while cloud-based solutions such as Microsoft Sentinel offer more flexibility without requiring additional infrastructure resources.

How was the initial setup?

I find the setup process for Splunk Enterprise Security very straightforward, and our engineering team loves deploying it.

What was our ROI?

Overall, I find Splunk Enterprise Security cost-effective, providing a good ROI compared to other cloud-based SIEM solutions such as Microsoft Sentinel, especially because you only pay for specified usage without extra costs for data movement.

What's my experience with pricing, setup cost, and licensing?

The pricing aspect, including setup cost and licensing, is satisfactory because we're happy with the level of discount we receive as part of our partnership tier.

Which other solutions did I evaluate?

In comparison to Microsoft Sentinel and other SIEM products, I don't have negative feedback about Splunk Enterprise Security, as it offers a significant number of native integrations and is a mature product with valuable new capabilities.

What other advice do I have?

ES Essentials has improved my visibility across hybrid or multi-cloud environments.

I'm not sure what the current version of Splunk Enterprise Security is, but I need to check.

I utilize AI in Splunk Enterprise Security, but I recently went through Splunk Enterprise Security's documentation and couldn't find much on AI capabilities. I need to check the official Splunk Enterprise Security documentation for updates on AI.

I haven't personally experienced a reduction in analyst burnout or fatigue, but I know our SOC analysts love working on Splunk Enterprise Security.

My advice for organizations considering Splunk Enterprise Security is to look for a licensing model that doesn't restrict data ingestion, perhaps a perpetual license that allows scalability with added infrastructure, particularly for larger enterprises. I would rate this product a 9 out of 10.

Which deployment model are you using for this solution?

On-premises

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Other
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
Last updated: Jul 15, 2026
Flag as inappropriate
PeerSpot user
Buyer's Guide
Download our free Splunk Enterprise Security Report and get advice and tips from experienced pros sharing their opinions.
Updated: July 2026
Buyer's Guide
Download our free Splunk Enterprise Security Report and get advice and tips from experienced pros sharing their opinions.