No more typing reviews! Try our Samantha, our new voice AI agent.
MatthewSnyder - PeerSpot reviewer
Principal Engineer at Aviatrix
Video Review
Real User
Top 5
Sep 11, 2025
Transforms threat detection by reducing investigation time and enabling consistent response workflows
Pros and Cons
  • "While it might be an initial upfront investment on data onboarding, it's going to be something that makes your life incredibly easy once you get beyond that point."
  • "Previously, it would take us days to properly analyze, triage, and respond to insider threats; now with risk-based alerting, we are able to reduce that to 10 minutes."
  • "When deploying Enterprise Security, the biggest challenge or the most amount of work that you're going to spend time on is onboarding your data and getting it into a position that allows you to search it uniformly. So applying things like the common information model is the biggest time investment that you'll have in the deployment."

How has it helped my organization?

Splunk Enterprise Security has helped reduce my team's average meantime to detect insider threats, which I discussed at a conference a few years ago. Previously, it would take us days to properly analyze, triage, and respond to insider threats. Now with risk-based alerting, we are able to reduce that to 10 minutes. 

This is a powerful metric on the amount of time saved. Not only are we saving time, we're able to apply investigations in a more uniform and consistent manner where we're able to control the output, ensuring we're delivering consistent and valuable products each time we perform investigations or responses.

What is most valuable?

If you want to use some of the out-of-the-box and more guided features, you have that, and if it meets your team's needs, that's great. If you also want to start to grow and mature beyond those out-of-the-box capabilities, it gives you this wide-open road to be able to create and develop your own applications, response capabilities, and detection capabilities, where your limitations are really only your imagination and what your team's able to accomplish. This is something powerful with Splunk that other vendors aren't replicating.

What needs improvement?

I've used it for a long time and I still feel it's the best tool out there. I love what the team is doing. They refreshed the user interface recently, they've got version control coming, and they're doing more exciting things. 

I'm really excited to see them continue to improve by making the SIEM the central point of what security teams are doing and operating instead of having multiple tools such as SOAR or UEBA. 

With Splunk Enterprise Security and Mission Control, everything is coming back into one place. We're able to operate from a single source to take an alert and get to an actionable state much quicker. I'm really excited to see how they continue to grow and evolve that.

What do I think about the stability of the solution?

I have been really impressed with the stability and reliability of Splunk Enterprise Security over the last ten years as we've had very few incidents where it was down or we had an issue. 

Typically when we've had issues, it was something more self-initiated where we had a piece of hardware that failed. It wasn't ES's fault. I've been really happy that it's delivered very consistent user performance. Performance delivery for us hasn't been a constant pain or nightmare that I've dealt with other vendors where the tool is constantly up and down. Splunk has been very reliable and very consistent.

Buyer's Guide
Splunk Enterprise Security
August 2026
Learn what your peers think about Splunk Enterprise Security. Get advice and tips from experienced pros sharing their opinions. Updated: August 2026.
914,109 professionals have used our research since 2012.

What do I think about the scalability of the solution?

I've seen Splunk Enterprise Security scale from a 300-gig license to a 30-terabyte-a-day license. The infrastructure and different options allow you to scale at the pace that makes sense for you and your organization, whether that's large scale or something smaller to midsize. There are many different options at your fingertips to create the right architecture that meets your needs.

How are customer service and support?

I find the customer service and technical support of the platform to be amazing. It's done better at Splunk than I've seen any other vendor do. 

We've had great customer success managers who have helped us navigate scaling from 600 gigs to 30 terabytes. We've always had the architecture team, security team, or other experts whenever we've needed them or wanted to consult on our growth or future. 

The Splunk community is amazing as it's not just help we have to go to Splunk for. There's a vibrant community we can reach out to for answers from other Splunk users on how they're solving problems and what challenges they're facing and solving. We've got all these sources we can rely on and not just a vendor giving us the answer they want us to hear.

Which solution did I use previously and why did I switch?

Prior to adopting Splunk Enterprise Security, I have used quite a few different SIEMs and have done many proof of values throughout the years. There are many SIEMs that have similar features and capabilities. As an industry, they all brag that they can do similar things. What it really comes down to is establishing what you want your team to be able to do and accomplish. When you are able to write that out and compare it against what the market is doing, you're going to consistently find that Splunk is doing it better, if not miles better than the nearest competition.

How was the initial setup?

When deploying Enterprise Security, the biggest challenge or the most amount of work that you're going to spend time on is onboarding your data and getting it into a position that allows you to search it uniformly. So applying things like the common information model is the biggest time investment that you'll have in the deployment. 

The actual configurations of alerts and dashboards and all of that happen rather smoothly once your data is uniform. One of the powerful aspects of this is that it allows you to search across similar languages, hit multiple data sources and indexes, and make the most of your datasets. That's something that I really like. 

While it might be an initial upfront investment on data onboarding, it's going to be something that makes your life incredibly easy once you get beyond that point.

What was our ROI?

The biggest return on investment when using Splunk Enterprise Security is that it gives you control.

What's my experience with pricing, setup cost, and licensing?

One of the things I hear a lot is that it's expensive. We've tried to move beyond just a single line item on a spreadsheet to talk more about what's valuable to us as a security organization. What are we trying to do and accomplish? What are the tools we need to accomplish all of that? What I've found over the last 20 years is it's either going to be one big line item on your budget or a bunch of smaller line items. When you break it down and individualize it, you've got other things that might initially cost less, however, your cost over the years is going to end up being more than Splunk. 

The initial license ask is typically more than what we'd see with other vendors. The value it provides and the capabilities it gives us, when we look at what other tools can do, we would end up spending more just to meet that same level of capabilities. It's important that everybody understands SIEM value isn't just a singular license cost. There are many other components that come into play that really show value and true cost.

What other advice do I have?

The biggest advice I would give to anybody considering Splunk Enterprise Security is to understand what you want your organization to look like. What kind of things do you need your SOC to do? If you're just looking at doing basic auditing and alerting and reporting, there are features you can use. 

If you're wanting to do more threat hunting and incident response and go from ordinary to extraordinary, there are many features Splunk will help you utilize. It's really important that you understand what you want your SOC's identity to look like. 

As you partner and do your proof of value with Splunk, you can focus on those features that align to your immediate needs, as those you're curious about growing into, where you might see your organization in the next one year, two year, three year, five year type of journey and how those features really align, knowing that you've got a partner that's going to allow you to happily exist where you're at, yet also support you on the growth where you're wanting to go. 

I'd rate the solution nine out of ten.

Which deployment model are you using for this solution?

On-premises

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
reviewer2898969 - PeerSpot reviewer
Security manager at a tech vendor with 10,001+ employees
Real User
Top 20
Sep 16, 2026
Daily log insights have strengthened security decisions and reduced detection time
Pros and Cons
  • "Splunk Enterprise Security has positively impacted our organization by allowing us to use it on a daily basis, improving our security front and allowing our analysts to review and inform management on any trends, deficiencies, and necessary areas of improvement."
  • "Splunk Enterprise Security can always improve its UI; we do have some less technical team members, so continual improvement and refreshes of the UI are always appreciated."

What is our primary use case?

My main use case for Splunk Enterprise Security is to review logs of our assets and interests, other data assets, and create tables for management review to make the best informed security decisions.

I use Splunk Enterprise Security to make informed security decisions by reviewing current logs of any data spillages that may happen, any deficiencies that we may see with our assets, and reviewing logs monthly to ensure we remain compliant.

How has it helped my organization?

Splunk Enterprise Security has positively impacted our organization by allowing us to use it on a daily basis, improving our security front and allowing our analysts to review and inform management on any trends, deficiencies, and necessary areas of improvement.

The impact of Splunk Enterprise Security is evident as it has reduced vulnerabilities by allowing us to visualize any trends and take corrective measures, as well as giving us a roadmap of where we can improve our security front by ingesting data sets.

Splunk Enterprise Security has helped improve my organization's business resilience by providing adaptability through using AI models to foreshadow any trends and utilizing historical data sets from our company, which we use to make further business decisions based on recommendations from the trends from the models.

Splunk Enterprise Security has reduced my team's average mean time to detect, or MTDD metric, by about ten percent.

Splunk Enterprise Security's Risk-Based Alerting, or RBA, has impacted my alert volume and analyst productivity by giving us almost an immediate response time to any of our found alerts.

The integration of threat intelligence directly into the TDIR workflow has improved my ability to preemptively block threats by providing us a security-first mindset and allowing the threat to be stopped at the door versus performing forensics and after-action review.

The consolidation of SIEM, SOAR, and UEBA into a single interface has improved my team's operational efficiency by embracing the all-in-one aspect of the tools being combined, allowing us to train our controllers to utilize the one toolkit to solve or remediate our problems.

What is most valuable?

The best features Splunk Enterprise Security offers include visualizations, which are very helpful for our non-technical team to see trends and for us to input data sets and review at our meetings.

The visualizations help my team make decisions or communicate findings by allowing us to review trends, looking at graphs and bar graphs, enabling us to compare and contrast deficiencies and make business decisions.

What needs improvement?

Splunk Enterprise Security can always improve its UI; we do have some less technical team members, so continual improvement and refreshes of the UI are always appreciated.

For how long have I used the solution?

I have been using Splunk Enterprise Security for roughly five years with the current company.

What do I think about the stability of the solution?

Splunk Enterprise Security is stable; it is fully integrated into our ecosystem, and we will continue to use it.

What do I think about the scalability of the solution?

Splunk Enterprise Security's scalability is sufficient for our needs currently, and I believe that it will continue to be.

How are customer service and support?

The customer support for Splunk Enterprise Security is very sufficient from what I am seeing.

I would rate the customer support a ten out of ten.

Which solution did I use previously and why did I switch?

I did not previously use a different solution.

How was the initial setup?

Licensing was pretty fast and efficient; the cost was handled by our finance department, but it seemed like a pretty efficient workflow from what I am seeing.

What was our ROI?

I have seen a return on investment from Splunk Enterprise Security as we do not need additional employees to perform the work that we need, and having just one stream, one account to handle all the security has been beneficial.

What other advice do I have?

My advice for others looking into using Splunk Enterprise Security is to definitely give it a try; there are definitely trials to test out, learn about the product, take advantage of reaching out to the tier three support if needed, and integrate it into your ecosystem to understand what it's doing and what it can do for you. I would rate this product a nine out of ten.

Which deployment model are you using for this solution?

Hybrid Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Amazon Web Services (AWS)
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
Last updated: Sep 16, 2026
Flag as inappropriate
PeerSpot user
Buyer's Guide
Splunk Enterprise Security
August 2026
Learn what your peers think about Splunk Enterprise Security. Get advice and tips from experienced pros sharing their opinions. Updated: August 2026.
914,109 professionals have used our research since 2012.
Clay Matt - PeerSpot reviewer
Dir Of Global Cyber Security Ops at a manufacturing company with 10,001+ employees
Real User
Top 5
Sep 13, 2025
Significantly improves visibility and strengthens internal threat detection capabilities
Pros and Cons
  • "I would assess the stability and reliability of Splunk Enterprise Security as typically very good, with minimal downtime or crashes."
  • "I find the process for customizing, developing, testing, deploying, and refining detections in Splunk Enterprise Security to be cumbersome."

What is our primary use case?

My main use cases for Splunk Enterprise Security include extensive security operations.

How has it helped my organization?

Splunk Enterprise Security has helped improve my organization's business resilience. The more I know, the more I can see, and the better my security stance becomes due to inherent visibility.

What is most valuable?

We did use risk-based alerting in Splunk Enterprise Security. We had to refine the data model based on the initial risk-based alerting model as, when we fed it raw data, the data models built, and there were many endpoints and network devices that had a high-risk score just because the data was new. Those risk scores carried over with weights, so we had to go back in and cleanse the risk score model and rebuild it once we had good data and logs going into the ES platform.

What needs improvement?

If they could implement an out-of-the-box solution, it would be almost an AI data onboarding system that automatically identifies the fields that are SIM compliant, Common Information Model compliant, and then immediately applies those to a data model, builds a data model, and starts the SIM searches against those data models. A lot of the work for Splunk Enterprise Security happens on the back end, not the front end, so that's where you can really trim down your resource need and expertise if you supplement that with automated or artificial intelligence.

The most significant challenges I face when using Splunk Enterprise Security for advanced threat protection are integration with other platforms and noise. Alerts from Splunk Enterprise Security generate many alerts, which take time to move through, assess, analyze, and determine whether they are true or false positives, and then go back and redundantly tune.

I find the process for customizing, developing, testing, deploying, and refining detections in Splunk Enterprise Security to be cumbersome. Custom use cases are also cumbersome. You need someone very skilled at Splunk and data modeling to get to a point where you create something inside SPL that allows you to detect what you want.

There is not much predictive analysis happening in Splunk, and I hope that with the new AI toolkit allowing for the deployment of custom AI models and large language models within Splunk, along with additional advanced mathematical capabilities for vector analysis, the prediction and ability for Splunk Enterprise Security to add value to detections will increase.

For how long have I used the solution?

I have a lot of experience using Splunk Enterprise Security.

What do I think about the stability of the solution?

I would assess the stability and reliability of Splunk Enterprise Security as typically very good, with minimal downtime or crashes.

What do I think about the scalability of the solution?

We haven't expanded our usage of Splunk Enterprise Security; we used it by default from the start. The expanded usage is simply adding more information and logging to gain better insights.

How are customer service and support?

I evaluate customer service and technical support as normally very good. When it's not, I reach out to my sales representative and my SE. I have a great SE, Jonathan Wilson, who jumps right in to solve issues when we need help or engagement.

Customer support has room for improvement, particularly in terms of speed and the ability to escalate issues to more senior personnel. I understand the need for a tiered approach, but I believe some issues should move more rapidly to a senior person.

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

Prior to adopting Splunk Enterprise Security, we were not using any other solution to address similar needs.

How was the initial setup?

It's the human element there. It's helpful to have the expertise and the people to really take those data models and build them, refine them, get everything into the common information model on the back end so that, on the front end, you're getting the best data possible and you don't have to rebuild those models like we had to do with the risk score.

What was our ROI?

I have seen a return on investment with Splunk Enterprise Security. We went from almost no visibility to significant visibility across the enterprise, allowing us to see threats that were previously unknown or unregistered, which increased our security stance and made us understand we needed to look beyond the perimeter for internal threats and for lateral movement, east-west versus just north-south.

What's my experience with pricing, setup cost, and licensing?

I helped negotiate the cost. Our sales rep is is really good, and we had a good understanding. The more you know about the product, the easier it is to negotiate. If you're not aware of how the product works, what the ingestion's like, especially Splunk Cloud with the SBC units and AWS, and how impactful that can be to queries and optimization and just general operations, it becomes very difficult if you're trying to maintain a certain price point for cost effectiveness. It it can be difficult to get an optimum amount of credits and SBCs in order to run what you need to run.

What other advice do I have?

My advice to other organizations considering Splunk Enterprise Security is that while not everyone needs the top breed, ensure you have the resources and time to invest in it if you decide to use it. Anything off the shelf won't be as valuable as something you invest in and put time into, so the more you put in, the more you get out.

I would rate Splunk Enterprise Security overall as probably an eight out of ten; it is industry-leading.

Which deployment model are you using for this solution?

Public Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Splunk Engineer at a consultancy with 11-50 employees
Real User
Top 20
Jul 13, 2026
Automated risk-based alerts have reduced incident response time and support faster remediation
Pros and Cons
  • "The time it takes my SecOps team to remediate security incidents is very reduced compared to before."
  • "Currently, in my opinion, Splunk Enterprise Security is good. However, Splunk has an ingest processor that could be improved."

What is our primary use case?

My use case for Splunk Enterprise Security involves onboarding data and then CIM complying and normalizing fields. We are also using the data models mapping and the add-on configuration. We also have some correlation searches which are running using the data models. Using that, we have some dashboards that give us useful information and ideas of what we can do.

How has it helped my organization?

The time it takes my SecOps team to remediate security incidents is very reduced compared to before. Our security team gets notified very urgently and very fast, and we take action as per the alerts. This has reduced the time for us by a lot.

It helps our customers.

What is most valuable?

The dashboard is the feature in Splunk Enterprise Security that I find most valuable because in the dashboard we have background searches, and the background search runs in the dashboard and gives us useful information. We also have alert automation, such as if someone is logging in to our system like a firewall. If the IP is malicious, then we get the alert at that time and we can block that IP.

We are working with the risk-based alerting feature in Splunk Enterprise Security. We are using risk-based alerts called RBA. That assigns the risk to the user, the system, and the other entities instead of generating a notable event for every individual detection. Multiple low and medium confidence detections accumulate over time, and when the combined risk exceeds the defined threshold, a high-confidence alert is generated using that risk-based alert.

We are working with a new threat detection feature in Splunk Enterprise Security. That helps the security teams to identify, investigate, and respond to malicious activities across the environment. We have some correlation searches that detect suspicious behavior using predefined or custom rules. We also have some notable events that run as very high-frequency alerts created by the correlation searches or the risk thresholds.

What needs improvement?

Currently, in my opinion, Splunk Enterprise Security is good. However, Splunk has an ingest processor that could be improved.

For how long have I used the solution?

I have been using Splunk Enterprise Security for two years.

What other advice do I have?

I am working with Splunk Enterprise Security.

I use some third-party solutions for integration or to import data into Splunk. We are creating some custom add-ons. We are also using ServiceNow. When some alerts are triggered, then the incidents will automatically trigger and be assigned to the necessary team. That type of customization we are using for the data collection. If you have some API integration, then you can create your own add-ons using those APIs and the credentials, and you can directly pull the logs from the APIs into Splunk.

It is easy to customize Splunk Enterprise Security for our needs. We can customize as per our requirement. If you want to create some dynamic dashboards, then you can also create them as per your use case. It is also the same for the saved search and for the extraction. We can customize things as per our use cases and ideas.

I gave this product a rating of eight.

Which deployment model are you using for this solution?

Private Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Other
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
Last updated: Jul 13, 2026
Flag as inappropriate
PeerSpot user
reviewer2123547 - PeerSpot reviewer
Security Analyst at a tech vendor with 10,001+ employees
Real User
Top 20
Jun 16, 2026
Unified security monitoring has improved incident response and supported flexible threat detection
Pros and Cons
  • "Splunk Enterprise Security is a wide tool that we can use for different purposes, as it can be configured in many ways, not just as a SIEM, and we can leverage it in various ways."
  • "Whenever an upgrade happens from a lower version to the latest version, some things get complicated, particularly compatibility issues, which we usually see in Splunk Enterprise Security."

What is our primary use case?

During the initial two years, I was an incident response analyst who used Splunk Enterprise Security as a SIEM tool, and in the recent two years, I work as an admin who handles the integration part, content management part, and the detection response engineering.

We use disparate security solutions with additional IDS, IPS, and EDR tools integrated into Splunk Enterprise Security for single-handled monitoring for the analyst's ease. We do not need to go to each tool separately; instead, we integrate all of them into the Splunk Enterprise Security interface, allowing us to monitor them via Splunk Enterprise Security.

Regarding Risk-Based Alerting in Splunk Enterprise Security, we used to tag alerts while creating correlation searches in Splunk Enterprise Security.

I work with both on-premise and cloud-based setups.

How has it helped my organization?

Splunk Enterprise Security really helps improve business resiliency as we frequently capture real attacks.

What is most valuable?

In terms of customization ability and development capability inside Splunk Enterprise Security, it is very easy. Splunk Enterprise Security is a wide tool that we can use for different purposes. Splunk Enterprise Security can be configured in many ways, not just as a SIEM, but we can leverage it in various ways. The application add-on support from Splunk is very wide, making it very easy for configuration and customization.

The functions in Splunk Enterprise Security that I find most valuable are its ability to integrate any type of logs into the system. It is very user-friendly to read logs in any languages, which we can convert into a human-readable format in Splunk Enterprise Security, making log analysis and monitoring very useful compared to competitive SIEM tools.

The main benefits Splunk Enterprise Security provides to end users include a wide view, allowing us to have different kinds of views for the logs, and we can search according to the retention period we set in Splunk Enterprise Security. This capability and storage are good enough to retrieve older data for evaluation and analysis.

I find that threat detection in Splunk Enterprise Security is a wide case; we have the opportunity to create correlation searches, dashboards, and even integrate threat intel solutions in multiple ways into Splunk Enterprise Security. We can leverage these opportunities to get alerts based on these searches.

What needs improvement?

Whenever an upgrade happens from a lower version to the latest version, some things get complicated, particularly compatibility issues, which we usually see in Splunk Enterprise Security. In those cases, it sometimes definitely requires Splunk Enterprise Security's support or vendor support to resolve those issues. Compatibility issues during upgrades are a major concern.

I am generally satisfied with the functionality of Splunk Enterprise Security, and my only concern is the compatibility issue during upgrades.

For how long have I used the solution?

I have been working with the product for four years.

What do I think about the stability of the solution?

I rate Splunk Enterprise Security's stability as a nine.

What do I think about the scalability of the solution?

I consider its scalability, ability to scale, and ability to expand to be a ten.

How are customer service and support?

I would rate vendor support as a nine.

How was the initial setup?

The initial setup for Splunk Enterprise Security is simple, and guides from Splunk Enterprise Security support are available on the internet, making it very basic. We can read and understand the next steps from there.

What other advice do I have?

On average, the time a SecOps team takes to remediate security incidents with Splunk Enterprise Security depends on projects. If the team is working as a threat hunt team, they do not have a proper SLA, but for incident handling, some projects have 15 minutes, others 30 minutes, one hour, or in some cases, up to four hours. It varies according to the project and client requirement; incident handling is different from incident response, which usually requires more time for detailed analysis.

I am totally satisfied with Risk-Based Alerting because it works well; it works on intermediate findings. If multiple detections occur for the same host or IP, it looks for behavioral analysis and generates alerts for the analyst based on that risk, so it is actually working well in Splunk Enterprise Security.

I can recommend Splunk Enterprise Security to other users. My overall rating for this product is eight out of ten.

Which deployment model are you using for this solution?

Hybrid Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Other
Disclosure: My company has a business relationship with this vendor other than being a customer. partner
Last updated: Jun 16, 2026
Flag as inappropriate
PeerSpot user
Hari Haran. - PeerSpot reviewer
Technical Associate at Positka
Reseller
Top 20
Feb 26, 2026
Security operations have become streamlined and threat investigations gain rapid, actionable insight
Pros and Cons
  • "Regarding scalability, Splunk Enterprise Security is way ahead compared to other products, and I would score it at the maximum."
  • "During my experience with Splunk Enterprise Security, I have faced some significant challenges, particularly with customers adapting from version 7 to version 8."

What is our primary use case?

I would like to discuss Enterprise Security, and I explain that the main use case for the product is to protect our customers and support various attacks.

Regarding threat detection, I explain that during investigations, most of our SOC-related customers use Splunk Enterprise Security to identify threats.

How has it helped my organization?

In terms of benefits, Splunk Enterprise Security provides numerous advantages to end users, notably in reducing personnel needs for SOC operations.

Regarding pricing for Splunk Enterprise Security, I find it relatively affordable globally, although it seems costly in India due to currency exchange.

What is most valuable?

In my opinion, the functions in Splunk Enterprise Security that I find most valuable include unique features and tools that the product offers.

What needs improvement?

For improvement points, I think Splunk has several enhancements on the table right now to enhance Splunk Enterprise Security with functionalities and threat detection improvements.

For how long have I used the solution?

I have been working with Splunk Enterprise Security for seven years.

What do I think about the stability of the solution?

For stability, I would rate it a 10, as Splunk Enterprise Security is generally stable, especially now with its latest version.

What do I think about the scalability of the solution?

Regarding scalability, Splunk Enterprise Security is way ahead compared to other products, and I would score it at the maximum.

How are customer service and support?

I would rate Splunk Enterprise Security's technical support as a 10, as they provide 24/7 assistance based on priorities and are accessible for queries.

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

In comparison to other products, I think previous tools such as IBM QRadar were competitors, but currently, I hear about CrowdStrike getting into the picture.

How was the initial setup?

In general, I find that the initial setup for Splunk Enterprise Security is simple, especially with clear documentation from Splunk.

It depends on the client; if they have a qualified engineer with experience in Splunk Enterprise Security, they can handle the setup themselves.

What about the implementation team?

The solution is deployed both on-premises and cloud-based, depending on the customer's domain.

What other advice do I have?

My feedback regarding some processes of customizing, developing, and testing in Splunk Enterprise Security is that I am thinking from a customer perspective, focusing on the customizations they require.

I have experience with risk-based alerting in Splunk Enterprise Security, as we configure based on the priority of the instance, servers, or the endpoints.

During my experience with Splunk Enterprise Security, I have faced some significant challenges, particularly with customers adapting from version 7 to version 8.

Which deployment model are you using for this solution?

Hybrid Cloud
Disclosure: My company has a business relationship with this vendor other than being a customer. reseller
Last updated: Feb 26, 2026
Flag as inappropriate
PeerSpot user
Ankar Aung - PeerSpot reviewer
Network Security Engineer at a consultancy with 10,001+ employees
Real User
Top 5
Jan 8, 2026
Centralized dashboards have improved log visibility and support faster security investigations
Pros and Cons
  • "Splunk Enterprise Security can retain logs for compliance purposes longer than the usual three months."
  • "Splunk Enterprise Security documentation exists, but compared to Palo Alto, Palo Alto has more knowledge base articles."

What is our primary use case?

I deal with the Palo Alto FO and then Cortex XSIAM. I work with Cortex XSIAM and Cortex EDR products. We recently adopted Cortex XSIAM from Splunk Enterprise Security as our SIEM product for log management.

I have two to three years of experience with Splunk Enterprise Security, but not continuously; this is just a tool used by me, not daily. We send logs from the firewalls to XSIAM and analyze the traffic logs to determine whether deny or allow for migration. We use both Splunk and Cortex XSIAM for log analysis. I have never dealt with Splunk support.

What is most valuable?

I have experience with Palo Alto, Cisco, and Fortinet products. Splunk Enterprise Security is more dedicated to logs, not a unified product like Palo Alto. Palo Alto Cortex has the same UI across Cortex EDR and Cortex XSIAM, so all the product family is in one UI, whereas Splunk Enterprise Security is more focused on log search.

Palo Alto has better speed and better visibility. I can see all the M-points from one UI and search the logs from this UI. I use disparate security solutions that integrate or import data into Splunk Enterprise Security, including different log sources from the endpoint, firewall, router, switches, and everything that needs logging for visibility.

Splunk Enterprise Security can retain logs for compliance purposes longer than the usual three months. The dashboard capability also allows Splunk Enterprise Security to create dashboards based on logs, which makes it really helpful for visibility.

What needs improvement?

I feel more comfortable using XSIAM now compared to Splunk Enterprise Security. Splunk Enterprise Security is already a mature product, so I do not have much to point out. It could be a little more user-friendly, which would be nice.

It could also expand the product family beyond security log search. Since it has the capability of indexing things, perhaps Splunk Enterprise Security could develop their own EDR agent like Palo Alto and create a product family with a unified dashboard. This would definitely help the enterprise.

Splunk Enterprise Security documentation exists, but compared to Palo Alto, Palo Alto has more knowledge base articles. Even though the concepts are the same and multiple engineers have written articles for cross-reference, I do not see this level of documentation in Splunk Enterprise Security.

For how long have I used the solution?

I have two to three years of experience with Splunk Enterprise Security, but not continuously; this is just a tool used by me, not daily.

Which solution did I use previously and why did I switch?

The switch to Cortex came from management, likely because the Palo Alto product family is already in our environment. We have been using Palo Alto GlobalProtect and other security products, so bringing XSIAM into the environment makes sense.

What other advice do I have?

I do not see a real difference between XSIAM and Splunk Enterprise Security; they both have a search query functionality. Splunk Enterprise Security has Splunk query language, so it is just a different language and different way of searching logs. Eventually, we get the same logs including source, destination, port, and traffic allow and deny information.

I used to be a customer with Splunk Enterprise Security. I have hands-on experience but not extensive experience with Splunk Enterprise Security products in the past. I am more focused on networking than the security team. I do not have an answer about how long on average it takes SecOps teams to remediate security incidents using Splunk Enterprise Security.

I would rate this review an 8.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Last updated: Jan 8, 2026
Flag as inappropriate
PeerSpot user
Duy-An Dô - PeerSpot reviewer
Information Security Specialist at Ubisoft International SAS
Real User
Top 10
Sep 13, 2025
Streamlines alert triage and incident investigation while improving communication with non-technical stakeholders
Pros and Cons
  • "The features of Splunk Enterprise Security that I appreciate the most include the SPL search."
  • "Splunk Enterprise Security can be improved mainly regarding the UI, which can be daunting at first for newer employees."

What is our primary use case?

As a security analyst, my main use cases for Splunk Enterprise Security involve reviewing notables. I receive all the alerts and notables in my queue, review them, ensure they're not actual security incidents, and triage them as either true positives, false positives, and so on. I then investigate the true positives.

What is most valuable?

The features of Splunk Enterprise Security that I appreciate the most include the SPL search. It allows me to get all the data I need, make it beautiful, show it to my boss, and show it to less technical people. It's easy to display the data.

When we have a major incident, we need to move fast and answer quickly. Also, we need to inform non-technical people, so it's easier to show them.

Instead of showing them a raw log that's ugly and hard to read, we can show them a very concise point such as 'This insider threat with this IP address accesses this system,' and pivot wherever needed. It's really useful for data presentation.

Dealing with incidents depends on the type of incident; a major incident can take a few months, while a smaller incident can take from five minutes to five hours. We use Splunk SOAR, and we're starting to use that in Splunk Enterprise Security to automate our response. It's made my life easier because repetitive tasks can be automated with a playbook, and everything gets done in the background without manual triage.

Splunk Enterprise Security helps improve my business's resilience by protecting our enterprise. Every time there's something not working, it's our central log space. Every incident and everything that's not working is in Splunk. The factors that led to adding Splunk involve our relationship with the sales team and our technical contact. We have a very good relationship with them, which helps considerably.

The integration of these security solutions supports my security operations by providing us with better visibility into various types of endpoints. We have custom detections that we make on Splunk, and we also integrate Microsoft Defender alerts into Splunk. I have one place to investigate them all instead of going from product to product.

What needs improvement?

Splunk Enterprise Security can be improved mainly regarding the UI, which can be daunting at first for newer employees. It's hard to find everything, such as menu locations, dashboard access, and dashboard creation. It's still very complicated and takes a few weeks to understand. The UI could be more user-friendly.

The most significant challenges I face when using Splunk Enterprise Security for advanced threat detection include skills. I've been using it for four years and I don't know everything yet. Finding information and writing complex SPL queries can be challenging. I tried to use external AI, ChatGPT, but they're not very good with it. I know now there's SPL with AI, and we're going to test that.

For how long have I used the solution?

I have been using Splunk Enterprise Security for about four years.

What do I think about the stability of the solution?

I would assess the stability and reliability of Splunk Enterprise Security as generally good. We had a few performance issue bugs with very specific use cases, and they were handled quite fast. We reported them to our technical contact, and within a week, it was fixed.

What do I think about the scalability of the solution?

Splunk Enterprise Security scales effectively with the growing needs of our organization. We expand continuously, always adding new detection, new logs, and new systems. In Splunk Cloud, it's very scalable. We never have an issue with that, and we have terabytes of data coming in.

How are customer service and support?

I would evaluate customer service and technical support for Splunk Enterprise Security as very good. This is probably one of the reasons why we have a good relationship and we keep Splunk around.

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

Prior to adopting Splunk Enterprise Security, I always used Splunk. At the same time, we use Microsoft Defender Endpoint, however, we don't use their SIEM solution. I use MD alerting too.

Which other solutions did I evaluate?

I use disparate security solutions that integrate or import data into Splunk Enterprise Security.

What other advice do I have?

I am not directly involved in pushing new detection in Splunk Enterprise Security. However, I do tune detections; if a detection is firing too much or I feel we could edit the detection, I find it quite easy to do. My organization does not use risk-based alerting in Splunk Enterprise Security yet; we're working on it.

The advice I would give to other organizations considering Splunk Enterprise Security is to contact them, contact the sales rep, the tech rep, and ask them for a PoC trial. They're very open with this and even with new features. Before we buy anything new, such as SOAR, Splunk offers us to do a PoC. They give us a license to try it for free for a few months and give feedback if interested or not. For any enterprise thinking about it, I would contact them and get them to do a free trial for a while.

On a scale of one to ten, I rate Splunk Enterprise Security a nine.

Which deployment model are you using for this solution?

Public Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Other
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Evonce Barrett - PeerSpot reviewer
Security Engineer at Nightwing
Real User
Sep 21, 2026
Long-term security monitoring has transformed investigations and sped up data-driven decisions
Pros and Cons
  • "Splunk Enterprise Security has been the best SIEM solution tool I have worked with over the past ten to fifteen years."
  • "I perceive that the overall functionality of Splunk Enterprise Security is robust, but I believe it could see improvement, particularly in enhancing its AI capabilities."

What is our primary use case?

I have been using Splunk Enterprise Security for over seven years, and many of my use cases include monitoring user behavior, tracking system processes that go up and down, and determining necessary actions when dealing with Windows admin endpoints. I examine CVEs and the vulnerabilities that require triaging and remediation. One of the main features and functions for my use cases with Splunk Enterprise Security involves alerts built on user activity.

There are numerous ways to take data and events, correlate them, or review correlation searches to populate the necessary information across any industry and environment.

Splunk Enterprise Security is a wonderful tool to have for enterprise security.

What is most valuable?

The features of Splunk Enterprise Security that I appreciate most are tied to the overall experience. I can utilize the apps based on my use cases, and I can take all the data and consolidate it into one location. I appreciate the entire experience with Splunk Enterprise Security.

Security Essentials serves as a valuable resource for specific searches and helps tune alerts. AI-driven detections and assistance have improved my investigations by reducing triage times and allowing for faster data-driven decisions.

What needs improvement?

I perceive that the overall functionality of Splunk Enterprise Security is robust, but I believe it could see improvement, particularly in enhancing its AI capabilities.

If Splunk Enterprise Security were able to build its own LLM based on the incoming data instead of relying on other AI solutions, that would be a significant improvement, streamlining my experience while maintaining the quality of feedback.

For how long have I used the solution?

I have been using Splunk Enterprise Security for over seven years.

How are customer service and support?

I rate customer service and tech support at Splunk as a nine or ten based on my great experiences working with them. When I first started with Splunk Enterprise Security, the professional service I received was phenomenal.

The general customer service at Splunk is something I view positively, with great account service management that stands out, especially one particular representative named Matthew, whom I would rate as a nine or ten for his professionalism.

Which solution did I use previously and why did I switch?

Prior to adopting Splunk Enterprise Security, I utilized another solution that was not Elastic, although I cannot recall the name.

I remember it provided slow indexing and a cumbersome search query process. The indexing capabilities of Splunk Enterprise Security have always been its standout feature, enabling faster data retrieval when queries are submitted.

What was our ROI?

I have seen significant ROI with Splunk Enterprise Security primarily through the time saved. What used to take ten minutes for a search query can now be completed in mere seconds, allowing me to focus on additional tasks such as conducting PCI compliance interviews that demand timely responses, which is incredibly beneficial during those sessions.

What other advice do I have?

Splunk Enterprise Security has been the best SIEM solution tool I have worked with over the past ten to fifteen years.

It has integrated with numerous products beyond just being a SIEM solution, including AWS and Cisco networking devices, which, alongside their security essentials and correlation searches, creates a comprehensive package.

Excellent customer service, availability for monitoring the cloud, and data lake solutions that facilitate easier data access underscore the readiness of Splunk Enterprise Security to meet various organizational needs.

I give this product a rating of ten.

Which deployment model are you using for this solution?

Public Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Last updated: Sep 21, 2026
Flag as inappropriate
PeerSpot user
Harshit Pawar - PeerSpot reviewer
Cybersecurity Engineer at a tech vendor with 201-500 employees
Real User
Top 20
Jul 27, 2026
Centralized threat data has powered faster incident response and proactive attack prevention
Pros and Cons
  • "The best features and the most important feature I want to highlight about Splunk Enterprise Security is its capability to process large amounts of data."
  • "From the point of view of deployments and making custom modifications in this particular product, it becomes really difficult because deployments of Splunk can get really tricky."

What is our primary use case?

I work for a cybersecurity-based company. We have our own products and solutions that we build and deliver to our customers, primarily revolving around Threat Intelligence solutions, TIP platforms, SOAR platforms, and incident response platforms.

The majority of tools that I work with are centered around threat intelligence, so we share threat intelligence for actioning on end security tools. These end security tools that consume threat intelligence are primarily Defender technology stack, which is how the entire arrangement functions.

Cyware has its own threat intelligence platform called Intel Exchange. This is a central data lake for all threat intelligence that any enterprise or organization might want to collect. An organization using threat intelligence from multiple sources collects threat intelligence from different types of open sources, RSS feeds, news articles, and blogs. They consume feeds from regulatory bodies like CERTs and ISACs, and they also purchase premium threat intelligence from threat intel feed providers like CrowdStrike, Recorded Future, and Microsoft Defender Threat Intelligence. When a customer has been consuming threat intelligence from these different sources, we consolidate everything, ingest it into a single platform, normalize it, and bring everything into a single structure. Threat intelligence is further processed, analyzed, and forwarded to end security tools for proactive blocking. If I am a financial sector company seeing other financial sector organizations like other banks getting targeted by a particular cyber attack, I use that intelligence to proactively block these threats in my environment before such an attack can happen in my organization.

I am using different tools including the entire Microsoft suite, most of the time working with Microsoft Sentinel, Microsoft Defender for Endpoint, CrowdStrike, Zscaler, and Splunk Enterprise Security.

What is most valuable?

Splunk Enterprise Security is basically a complete enterprise security solution, but it is primarily built on top of a security event and information management system; it is a SIEM solution. Splunk Enterprise Security acts as a data lake for all logs that I collect from different types of log sources within my environment. I bring logs and activity from my entire environment into a single place, and once this data is stored, I run analytics rules on top of it. These analytics rules are defined based on the different types of malicious behavior that I want to identify happening in my environment, and if any of these behaviors identify a match, it triggers alerts. These alerts could be actual malicious activities happening in my environment. Once those alerts are triggered, they are assigned to different types of analysts; these are SOC analysts who assign these alerts to themselves and then start investigating those alerts to see if the activity observed is actually malicious or not. Depending on those investigations, analysts close those incidents, and if something malicious has been identified, they take remediation actions. At that point, I integrate SOAR solutions. I integrate my own SOAR solution, which automates this entire actioning process.

For example, if a suspicious sign-in on a user account has happened and the sign-in was successful, my SOAR playbook resets the password for that particular user, notifies the user's manager, and sends out the necessary communication to that particular user whose account has been compromised. This is how Splunk Enterprise Security can be integrated with different security tools and how it works.

The best features and the most important feature I want to highlight about Splunk Enterprise Security is its capability to process large amounts of data. When I compare Splunk with all the other SIEM solutions that are out there in the market, Splunk has to be the one that can easily process huge volumes of data and scales really well. The query language that Splunk has, which is called SPL, is one of the best query languages out there that will help anybody to query large datasets and return results in a very quick and short period of time compared to the other SIEM solutions. For example, QRadar is extremely slow and sluggish when I want to query large datasets, but Splunk excels in that regard.

What needs improvement?

From the point of view of deployments and making custom modifications in this particular product, it becomes really difficult because deployments of Splunk can get really tricky. It requires a huge amount of hardware and infrastructure to run on. From that perspective, it is really compute heavy, and Splunk is one of the priciest solutions out there, so from a cost perspective as well, it is not one of the easiest to start with.

I do not think there is any particular lack of functionality with the product; the product is really good, but there are a few aspects in which Splunk Enterprise Security can become really difficult for people to get started with as beginners.

For how long have I used the solution?

I have been working with Splunk Enterprise Security for almost a year.

What do I think about the stability of the solution?

Splunk Enterprise Security definitely helps reduce the metrics that every security solution is built to reduce. If somebody was investigating these security threats and incidents manually and then manually going ahead and taking every single step, it would have taken those analysts a huge amount of time to remediate and protect their environments from these cybersecurity threats. Solutions like these are the reason why people buy them because they help reduce mean time to remediate and mean time to investigate, so that is the primary reason these solutions are primarily bought for.

What do I think about the scalability of the solution?

Splunk Enterprise Security is a very good solution when it comes to scalability, so I would rate it nine.

How are customer service and support?

I have not really interacted with the technical support of Splunk because I am not the one who is directly interacting with the product side of Splunk because somebody else does. I am not the one who really procures this product and interacts with their support team.

Which solution did I use previously and why did I switch?

I actually use Microsoft Sentinel, but that is not a native part of my toolset that I use. I integrate these solutions with the other set of tools that I work with at the moment.

I work with Defender and I work with Sentinel, so it is part of my job that I usually integrate these solutions with my solution that we sell.

I have worked with Defender for Cloud Apps, Defender for Endpoints, and I have also had a chance to work with Microsoft Defender for Identity, so I have worked on a few of these Defender solutions that Microsoft offers. We are a partner with Splunk.

How was the initial setup?

Both approaches are possible, but if I am simply looking to integrate the logs from my native technologies that I have in my infrastructure, I can simply use the out-of-the-box connectors, so I do not need to rely on third-party tools. If I have any particular third-party tool that allows me to ingest some custom data, that can also be done, so both things are possible.

What was our ROI?

Primarily, there are two things that Splunk Enterprise Security helps with: streamlining the log ingestion and normalization of all the logs in my environment into a single place; that is the first and foremost reason why anybody would want to buy Splunk Enterprise Security. Once I get all the data in a single platform, it really helps me analyze all those intelligence and data logs in a single place; these are done via the SPL query language that they provide along with the rules that can be scheduled and run on a regular basis. First, it helps streamline everything into a single place and helps act as a data lake for all logs in my environment. Second, it is really fast and quick in analyzing that large dataset that it can collect, so it provides a huge volume of better derived insights compared to other security solutions.

Which other solutions did I evaluate?

Microsoft Sentinel would be a top competitor, and recently Palo Alto has released their own SIEM solution as well, so these would be the top competitors.

In terms of technical capabilities, Splunk Enterprise Security would be the highest. In terms of ease of use and ease of adoption, Microsoft Sentinel would be the one, and for the other SIEM solution, they are definitely in the challenging category, but not really the market leaders.

What other advice do I have?

The threat detection module capability in Splunk Enterprise Security really comes in handy because that ties in my threat intelligence signals, and input from my different threat intelligence solutions can be brought into the picture when I am actually looking to prioritize the types of threats that I want to investigate and remediate in my environment, so that really becomes handy. I would rate this product an eight overall.

Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
Last updated: Jul 27, 2026
Flag as inappropriate
PeerSpot user
Buyer's Guide
Download our free Splunk Enterprise Security Report and get advice and tips from experienced pros sharing their opinions.
Updated: August 2026
Buyer's Guide
Download our free Splunk Enterprise Security Report and get advice and tips from experienced pros sharing their opinions.