What is our primary use case?
I work for a cybersecurity-based company. We have our own products and solutions that we build and deliver to our customers, primarily revolving around Threat Intelligence solutions, TIP platforms, SOAR platforms, and incident response platforms.
The majority of tools that I work with are centered around threat intelligence, so we share threat intelligence for actioning on end security tools. These end security tools that consume threat intelligence are primarily Defender technology stack, which is how the entire arrangement functions.
Cyware has its own threat intelligence platform called Intel Exchange. This is a central data lake for all threat intelligence that any enterprise or organization might want to collect. An organization using threat intelligence from multiple sources collects threat intelligence from different types of open sources, RSS feeds, news articles, and blogs. They consume feeds from regulatory bodies like CERTs and ISACs, and they also purchase premium threat intelligence from threat intel feed providers like CrowdStrike, Recorded Future, and Microsoft Defender Threat Intelligence. When a customer has been consuming threat intelligence from these different sources, we consolidate everything, ingest it into a single platform, normalize it, and bring everything into a single structure. Threat intelligence is further processed, analyzed, and forwarded to end security tools for proactive blocking. If I am a financial sector company seeing other financial sector organizations like other banks getting targeted by a particular cyber attack, I use that intelligence to proactively block these threats in my environment before such an attack can happen in my organization.
I am using different tools including the entire Microsoft suite, most of the time working with Microsoft Sentinel, Microsoft Defender for Endpoint, CrowdStrike, Zscaler, and Splunk Enterprise Security.
What is most valuable?
Splunk Enterprise Security is basically a complete enterprise security solution, but it is primarily built on top of a security event and information management system; it is a SIEM solution. Splunk Enterprise Security acts as a data lake for all logs that I collect from different types of log sources within my environment. I bring logs and activity from my entire environment into a single place, and once this data is stored, I run analytics rules on top of it. These analytics rules are defined based on the different types of malicious behavior that I want to identify happening in my environment, and if any of these behaviors identify a match, it triggers alerts. These alerts could be actual malicious activities happening in my environment. Once those alerts are triggered, they are assigned to different types of analysts; these are SOC analysts who assign these alerts to themselves and then start investigating those alerts to see if the activity observed is actually malicious or not. Depending on those investigations, analysts close those incidents, and if something malicious has been identified, they take remediation actions. At that point, I integrate SOAR solutions. I integrate my own SOAR solution, which automates this entire actioning process.
For example, if a suspicious sign-in on a user account has happened and the sign-in was successful, my SOAR playbook resets the password for that particular user, notifies the user's manager, and sends out the necessary communication to that particular user whose account has been compromised. This is how Splunk Enterprise Security can be integrated with different security tools and how it works.
The best features and the most important feature I want to highlight about Splunk Enterprise Security is its capability to process large amounts of data. When I compare Splunk with all the other SIEM solutions that are out there in the market, Splunk has to be the one that can easily process huge volumes of data and scales really well. The query language that Splunk has, which is called SPL, is one of the best query languages out there that will help anybody to query large datasets and return results in a very quick and short period of time compared to the other SIEM solutions. For example, QRadar is extremely slow and sluggish when I want to query large datasets, but Splunk excels in that regard.
What needs improvement?
From the point of view of deployments and making custom modifications in this particular product, it becomes really difficult because deployments of Splunk can get really tricky. It requires a huge amount of hardware and infrastructure to run on. From that perspective, it is really compute heavy, and Splunk is one of the priciest solutions out there, so from a cost perspective as well, it is not one of the easiest to start with.
I do not think there is any particular lack of functionality with the product; the product is really good, but there are a few aspects in which Splunk Enterprise Security can become really difficult for people to get started with as beginners.
For how long have I used the solution?
I have been working with Splunk Enterprise Security for almost a year.
What do I think about the stability of the solution?
Splunk Enterprise Security definitely helps reduce the metrics that every security solution is built to reduce. If somebody was investigating these security threats and incidents manually and then manually going ahead and taking every single step, it would have taken those analysts a huge amount of time to remediate and protect their environments from these cybersecurity threats. Solutions like these are the reason why people buy them because they help reduce mean time to remediate and mean time to investigate, so that is the primary reason these solutions are primarily bought for.
What do I think about the scalability of the solution?
Splunk Enterprise Security is a very good solution when it comes to scalability, so I would rate it nine.
How are customer service and support?
I have not really interacted with the technical support of Splunk because I am not the one who is directly interacting with the product side of Splunk because somebody else does. I am not the one who really procures this product and interacts with their support team.
Which solution did I use previously and why did I switch?
I actually use Microsoft Sentinel, but that is not a native part of my toolset that I use. I integrate these solutions with the other set of tools that I work with at the moment.
I work with Defender and I work with Sentinel, so it is part of my job that I usually integrate these solutions with my solution that we sell.
I have worked with Defender for Cloud Apps, Defender for Endpoints, and I have also had a chance to work with Microsoft Defender for Identity, so I have worked on a few of these Defender solutions that Microsoft offers. We are a partner with Splunk.
How was the initial setup?
Both approaches are possible, but if I am simply looking to integrate the logs from my native technologies that I have in my infrastructure, I can simply use the out-of-the-box connectors, so I do not need to rely on third-party tools. If I have any particular third-party tool that allows me to ingest some custom data, that can also be done, so both things are possible.
What was our ROI?
Primarily, there are two things that Splunk Enterprise Security helps with: streamlining the log ingestion and normalization of all the logs in my environment into a single place; that is the first and foremost reason why anybody would want to buy Splunk Enterprise Security. Once I get all the data in a single platform, it really helps me analyze all those intelligence and data logs in a single place; these are done via the SPL query language that they provide along with the rules that can be scheduled and run on a regular basis. First, it helps streamline everything into a single place and helps act as a data lake for all logs in my environment. Second, it is really fast and quick in analyzing that large dataset that it can collect, so it provides a huge volume of better derived insights compared to other security solutions.
Which other solutions did I evaluate?
Microsoft Sentinel would be a top competitor, and recently Palo Alto has released their own SIEM solution as well, so these would be the top competitors.
In terms of technical capabilities, Splunk Enterprise Security would be the highest. In terms of ease of use and ease of adoption, Microsoft Sentinel would be the one, and for the other SIEM solution, they are definitely in the challenging category, but not really the market leaders.
What other advice do I have?
The threat detection module capability in Splunk Enterprise Security really comes in handy because that ties in my threat intelligence signals, and input from my different threat intelligence solutions can be brought into the picture when I am actually looking to prioritize the types of threats that I want to investigate and remediate in my environment, so that really becomes handy. I would rate this product an eight overall.
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner