The team I work on is a workflow team for the bank. We get a lot of traffic because of onboarding and workflow processes, which results in around a million hits per day. Whenever we have a release scheduled, Splunk Enterprise Platform is a very useful tool for me to monitor the logs.
Centralized log monitoring has enabled real-time insight into high-volume workflow activity
Pros and Cons
- "Splunk Enterprise Platform has the Search Processing Language, which is the query language for the product, and the advantage is that I can log and monitor all of the microservices in a single location."
- "Regarding the downsides of Splunk Enterprise Platform, as I mentioned, one is the Search Processing Language is somewhat complex when it comes to complex filtering and searching."
What is our primary use case?
What is most valuable?
Splunk offers an advantage where I can log and monitor all of the microservices in a single location. Search Processing Language (SPL), which is the query language for the product. SPL does take time to master as it is somewhat complex. When searches are straightforward, then it is quick, but if you need to perform complex searches with multiple pipes, sub-searches, or statistical functions, then it becomes somewhat confusing. You need time to become familiar with it.
I created some Splunk Enterprise Platform dashboards, which is the main focus of my work. I used a drag-and-drop builder, and it has real-time updates, visualization varieties, drilldowns, and token inputs. I built a dashboard for the application which answered these questions: which workflow combination has the highest hits and which users are triggering them. I wrote a query using SPL which aggregated the results from the API in the given timeframe that we can choose, and accordingly it will show a pie chart. Using the drilldowns and tokens, I built another panel where if you click a particular combination, it will list the number of users hitting that combination and how many times. This is something very useful I found in Splunk Enterprise Platform dashboards.
What needs improvement?
Regarding the downsides of Splunk Enterprise Platform, as I mentioned, one is the Search Processing Language is somewhat complex when it comes to complex filtering and searching. You need to become familiar with it to make complex searches. That is one thing.
There is not a no-code option for panels. You have to write an entire query for it. It would be better if they could introduce more drag-and-drop options so that people can add more features to their panels and pie charts and visualize the data they want.
For how long have I used the solution?
I have been using Splunk Enterprise Platform for 1.5 years.
Buyer's Guide
Splunk Enterprise Platform
September 2026
Learn what your peers think about Splunk Enterprise Platform. Get advice and tips from experienced pros sharing their opinions. Updated: September 2026.
914,394 professionals have used our research since 2012.
What do I think about the stability of the solution?
Considering the stability of Splunk Enterprise Platform, it is pretty stable. It sometimes takes time when I switch the timeframe, such as from 15 minutes to one hour. It takes some time in loading all of the logs from the application. Otherwise, it is very stable. It is a latency issue.
What do I think about the scalability of the solution?
As I mentioned, the current application I was working on already has a lot of users. So it is a pretty scalable solution. We get millions of hits for the APIs.
Which solution did I use previously and why did I switch?
When I joined the company, Splunk Enterprise Platform was already in place from the very start. Many of my friends work in several different companies, many uses DataDog, but here, I have only used Splunk Enterprise Platform.
Which other solutions did I evaluate?
I am not involved in those kinds of decisions yet. I do not know about the pricing.
What other advice do I have?
The whole bank uses the same tool to monitor their logs and analyze production data or any environment data. That is why I have not had any chance to use an alternative.
I am not familiar with the pricing because being a junior developer.
Splunk Enterprise Platform offers Federated Search, which I have not used.
My overall review rating for Splunk Enterprise Platform is 9 out of 10.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Last updated: Jun 30, 2026
Flag as inappropriateSoc Analyst at a manufacturing company with 10,001+ employees
Continuous monitoring has improved investigations and now prevents ransomware incidents
Pros and Cons
- "Splunk Enterprise Platform has drastically improved our monitoring capability in a 24/7 environment."
- "One improvement for Splunk Enterprise Platform would be to slightly lower the licensing cost, which I believe is quite high."
What is our primary use case?
As an analyst, I use Splunk Enterprise Platform for monitoring, investigating, and analyzing and responding to alerts in a 24/7 environment.
In my daily work, we receive alerts in Splunk Enterprise Mission Control where we monitor our alerts. For example, if I receive any malware-related alerts, I will use Splunk and check the logs from different log sources such as host, proxy, and DNS. I check these logs from Splunk, analyze them, and based on that analysis, I write my analysis in Splunk.
For specific use cases, such as the malware example I mentioned, if any malware-related alert is triggered in an environment, I check the logs of the host, identify who the user is, determine what happened, understand what actually occurred in that alert, and identify which file or process that alert was triggered for with the help of Splunk.
What is most valuable?
Splunk Enterprise Platform features such as risk-based alerting, which is the most important one, and advanced search, search processing language (SPL), along with the new add-on of Splunk AI that is integrated in Splunk Enterprise Platform, leverage analysis and writing Splunk queries. Additionally, the real-time alerting and scalability that Splunk Enterprise Platform provides if you want to scale it to a larger space are impressive.
Regarding risk-based alerting, it adds risk to any identity such as a host, IP address, or user, quantifying how many alerts trigger on that user, and adding a risk score to the particular entity, which I believe is a good feature. For SPL, we use it daily for analyzing logs, and Splunk Enterprise Platform's three modes—verbose, smart, and fast mode—speed up our process or provide detailed insights based on our requirements.
Splunk Enterprise Platform has drastically improved our monitoring capability in a 24/7 environment. I used other tools such as ArcSight, which is not as effective compared to Splunk Enterprise Platform, where everything is in one place, whereas ArcSight requires different tools for logging and monitoring alerts, showcasing Splunk Enterprise Platform's superior scalability.
What needs improvement?
One improvement for Splunk Enterprise Platform would be to slightly lower the licensing cost, which I believe is quite high. If possible, making SPL queries a bit easier would be beneficial, though the introduction of Splunk AI helps in writing queries automatically. Performance and scaling are also areas to consider.
For how long have I used the solution?
I have been working in this current field for 2.6 years.
What do I think about the stability of the solution?
Splunk Enterprise Platform is stable.
What do I think about the scalability of the solution?
Splunk Enterprise Platform offers excellent scalability, perfectly handling data growth and allowing us to scale from gigabytes to petabytes as our business expands.
How are customer service and support?
Customer support is very good. I had one query that was resolved within 24 hours.
Which solution did I use previously and why did I switch?
I have used ArcSight previously, but I did not switch. Rather, I transitioned to a different project where I began using Splunk Enterprise Platform, and I prefer Splunk Enterprise Platform for its comprehensive features that offer everything in one place.
What was our ROI?
We have seen a return on investment with Splunk Enterprise Platform, which is expensive but pays for itself through preventing costly downtime and security breaches.
We saved one ransomware alert in our organization.
What's my experience with pricing, setup cost, and licensing?
My experience with Splunk Enterprise Platform's pricing is that it has a high overall cost. Licensing fees require a large budget commitment, and traditional volume-based pricing can become unpredictable and expensive as data grows, alongside the costly setup for building infrastructure requiring specialized staff.
What other advice do I have?
I advise others looking into using Splunk Enterprise Platform to consider its great user interface, comprehensive features, superior scalability compared to other products, and the growing integration of AI into the platform, making it a compelling option over other products. I would rate this product a 10 out of 10.
Which deployment model are you using for this solution?
Private Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Last updated: Aug 1, 2026
Flag as inappropriateBuyer's Guide
Splunk Enterprise Platform
September 2026
Learn what your peers think about Splunk Enterprise Platform. Get advice and tips from experienced pros sharing their opinions. Updated: September 2026.
914,394 professionals have used our research since 2012.
IT systems engineer at a outsourcing company with 5,001-10,000 employees
Centralized monitoring has provided full visibility and simplified audits for our on-premise network
Pros and Cons
- "The people in the Splunk world have been awesome, the conference is awesome, Splunk Enterprise Platform is awesome, and the value is awesome."
- "Splunk Enterprise Platform has experienced stability issues."
What is our primary use case?
My main use case for Splunk Enterprise Platform is gaining insights, visibility, and maintenance for on-premise infrastructure.
For insights, visibility, or maintenance, we have a Splunk forwarder on all of our Windows servers, desktop endpoints, Linux servers, and we collect Cisco switch IOS data. For our CCRI, we are required to collect logs from all those devices. Thanks to Splunk Enterprise Platform and SPL, I was able to write queries that would prove that all of our devices were online, checking in, and reporting. I was also able to show us what is actively online at any given time.
What is most valuable?
The best features Splunk Enterprise Platform offers include a robust environment and platform for all the various devices on the network, an easy ability to update, a great support team from Splunk, which helps us stay on track and expand our functionality, and an ecosystem with so many options to improve visibility of durability and everything else.
The feature I rely on the most or find the most valuable in my day-to-day work is the ability to keep eyes and ears on our network and be able to search for any events that need attention and make sure the network and all the devices are online.
Splunk Enterprise Platform positively impacts my organization by helping us keep all of our devices online and healthy and helped us prove we meet the requirements for the CCRI audit.
What needs improvement?
When we had a consultant come on site, they installed a bunch of apps, and some of those did not work. In order to go back and clean everything up, we have to go into the back end. It would be helpful if there were a way to look into the installed apps, which ones are being used, and which ones are not being used.
For how long have I used the solution?
I have been using Splunk Enterprise Platform for two years.
What do I think about the stability of the solution?
Splunk Enterprise Platform has experienced stability issues.
What do I think about the scalability of the solution?
Splunk Enterprise Platform's scalability for my needs is very good. It scales extremely easily because of our distributed environment and our deployment server, we can expand as needed very easily.
How are customer service and support?
The customer support is second to none. It is some of the best customer support I have experienced in the IT world in 20 years.
What about the implementation team?
Because Splunk Enterprise Platform is such a solid product, we only have two admins. One of them is a Linux administrator, which manages the back end, and then there is me, which is the Splunk admin, which is responsible for searches, dashboards, and setting up alerts. We have been able to keep a small team of only two people and have complete oversight over our network and all of our devices.
What was our ROI?
Because Splunk Enterprise Platform is such a solid product, we only have two admins. One of them is a Linux administrator, which manages the back end, and then there is me, which is the Splunk admin, which is responsible for searches, dashboards, and setting up alerts. We have been able to keep a small team of only two people and have complete oversight over our network and all of our devices.
What other advice do I have?
Regarding Splunk Enterprise Platform's AI capabilities, we have not used it because it is on classified systems, which are air-gapped networks.
I have not used Federated Search.
In maintaining granular control over data using the Trusted Control Plane within Splunk Enterprise Platform, we have a few users from cybersecurity who have everything under the Power User role, and then we have admins. That is all.
Regarding Splunk Enterprise Platform's approach to managing governance within a private network environment, we use mostly business process as opposed to the technology, so we have not explored that yet, and I would be actually interested in learning about it.
The advice I would give to others looking into using Splunk Enterprise Platform is to understand that it is closer to a marathon than a sprint. If you are new to Splunk Enterprise Platform, it will take a little time to wrap your head around it and understand it. The value is there and your skills will grow over time, and you should contribute time every day or every week to learning and expanding your knowledge in Splunk Enterprise Platform. It is an excellent product.
The people in the Splunk world have been awesome. The conference is awesome. Splunk Enterprise Platform is awesome, and the value is awesome. I would rate this review a 9.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Last updated: Sep 17, 2026
Flag as inappropriateSplunk Engineer
Centralized logs have provided rapid user activity investigations and clearer security insights
Pros and Cons
- "Without knowing the actual cost, I can say with a very high level of confidence that Splunk Enterprise Platform has provided tremendous value."
What is our primary use case?
My main use case for Splunk Enterprise Platform is managing a lot of specific service data for a customer. We have multiple services, all with their own individual logs. We aggregate all that data as well as the Windows and Linux security logs and the F5 logs for when users try to access our services. This allows us to aggregate that information to gain a complete picture of when a user interacts with our services, whether they are authenticated or not. It lets us see where they route to, which different services within our platform they touch, and the actions they take at that point.
A quick specific example of how I use Splunk in a day-to-day scenario is that we had a request to see all the activity of a specific user over the course of six months. With Splunk Enterprise Platform, we were able to aggregate all the logs for all the services specifically for that user and pull that information to show our investigator. This includes when this user logged in on these days, which services they touched, and the files they opened, downloaded, or uploaded. We can provide a complete picture of all the activity for that user, which would normally take weeks, if not months, to compile. We were able to do it within 20 to 30 minutes.
What is most valuable?
The best features Splunk Enterprise Platform offers are ease of use, the ability to curate and customize data without too much difficulty, and the capability to provide visualizations for some of the information extracted from this data.
When I mention ease of use and customizing data, I find that we do not use specific out-of-the-box dashboards, but we can easily create our own dashboards with Dashboard Studio that allows us to make dashboards tailored for our specific use case without too much difficulty. The ease of creating a dashboard is very high. Therefore, we do not have to search for specific out-of-the-box dashboards; we can create the ones we need to perform the exact functions we require.
Splunk Enterprise Platform has positively impacted my organization by making it possible to extract meaningful information from a lot of logs that were normally isolated, siloed, and mostly not even viewed, as they weren't valuable on their own. Now, with this data ingested into Splunk Enterprise Platform, we are able to enrich other data or enrich that data with information from other sources we aggregate. This capability allows us to see the actual workflow of our system and the security posture with a high level of fidelity that we didn't have before.
We now use Splunk Enterprise Platform to grab user metrics across the entire platform to show how many users are logging into our system on a daily, weekly, or monthly basis. It also lets us pull information to reveal which individual services within our platform people are using, providing better insight to leadership on the kind of activity our services are generating for the general community.
What needs improvement?
I don't have anything I would say needs improvement. I believe it will have the standard improvements that any technology will have as it grows and as global technology improves, but nothing specific that Splunk Enterprise Platform itself needs to improve on.
If I had to think of one thing, it would be around the learning curve; I'm not very familiar with SPL2, and that might address this problem. However, having an easier way to translate from regular language to SPL could be an improvement, which may be facilitated by emerging AI technologies. If not, that's something that could be enhanced.
For how long have I used the solution?
I have been using Splunk Enterprise Platform for about three years.
What do I think about the stability of the solution?
Splunk Enterprise Platform has been very stable. We have not encountered stability issues with the product in the last three years I've been here.
What do I think about the scalability of the solution?
I am not sure about the scalability of Splunk Enterprise Platform. We have not had to scale up our system, so Splunk Enterprise Platform has not needed to scale much either; therefore, I can't speak confidently on that.
How are customer service and support?
Customer support has been fantastic. We have a representative who stops by routinely just to check in and is also available for any specific needs outside of routine check-ins. It has been a completely positive experience.
Which solution did I use previously and why did I switch?
I'm not sure what solution was used previously before Splunk Enterprise Platform; when I joined this organization, they already had Splunk Enterprise Platform in place.
How was the initial setup?
I have very little experience with pricing, setup cost, and licensing. I handle the engineering and administration of it, not the initial cost and licensing, which are managed by a completely different organization.
What was our ROI?
Without knowing the actual cost, I can say with a very high level of confidence that Splunk Enterprise Platform has provided tremendous value. There are fewer employees needed to perform security assessments, track security events, and manage those types of events. That alone should have been a cost-saving feature, which should have more than returned the value of the initial investment.
Which other solutions did I evaluate?
I'm not certain which options they evaluated before that; it was already in place when I arrived.
What other advice do I have?
My advice for others looking into using Splunk Enterprise Platform is to definitely find some good use cases for it. Even if you don't implement it immediately, install Splunk Enterprise Platform for the specific use case you are trying to satisfy, but also consider ways you could expand its use, as there are many more ways Splunk Enterprise Platform can assist than the initial reason for your installation. Therefore, keep an open mind on other ways to let Splunk Enterprise Platform grow within your system and take on more responsibilities.
We do not use Federated Search where we are. I have not used that feature. I have not explored that yet; however, it is something I would definitely like to investigate more. That is beyond the scope of my knowledge, and I am uncertain about it.
I provided this review with a rating of 9 out of 10.
Which deployment model are you using for this solution?
Hybrid Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
Last updated: Sep 16, 2026
Flag as inappropriateSplunk architect at a consultancy with 10,001+ employees
Centralized log insights have strengthened compliance and daily security investigations
Pros and Cons
- "Splunk Enterprise Platform has positively impacted my organization by helping us become compliant with a lot of auditable data points that we need to meet in order to actually operate."
What is our primary use case?
My main use case for Splunk Enterprise Platform is log aggregation, ensuring that we are meeting all our AU controls, and everything that is required to be kept for investigations, logging retentions and things of that nature specified by the federal directives.
We are bringing in all of our Windows, Linux and networking logs that track daily users to ensure that everything is up and running properly and there is no insider threat, outsider threats. We are able to use that to research across the many different sites that we all work with at one time into a single enterprise location.
What is most valuable?
The best features Splunk Enterprise Platform offers are dashboarding, the ability to break things into different indexes and have different users with different knowledge bases interact with their data in order to provide the artifacts needed for auditing or to research potential issues that arise for our SOC.
Those dashboards and user permissions help our Security Operations Center day-to-day by giving them a quick breakdown of what is coming in with the dashboards and setting the alerts to the dashboards to be emailed so they get real-time information and can quickly start investigating potential breaches or potential issues that have been found. Permissions and user permissions allow the proper people elevated permissions in order to schedule searches or build their own dashboards as long as they are able to build the dashboards properly using proper search and Splunk Enterprise Platform best practices. The fact that people have gone over Splunk education requirements allows people to get the fastest results versus trying to manually go through everything quickly.
Splunk Enterprise Platform has positively impacted my organization by helping us become compliant with a lot of auditable data points that we need to meet in order to actually operate. Bringing in multiple different applications, products, and infrastructure into a single environment and allowing our SOC to investigate any type of data that comes in in a singular location has been extremely useful.
What needs improvement?
The potential for improvement in Splunk Enterprise Platform could include the addition of AI. Our network is air-gapped, so the ability to implement AI in an air-gapped network would be very important to us. One of the initiatives that we are undertaking in the government is to win the AI race and in order to do that, we need AI to assist us in building out our infrastructure so we can fight AI with AI and be better. However, AI usually needs some type of active connection to the open internet, which in our case is not possible. A self-contained AI platform that we can update weekly, which would not be an issue, would be beneficial to us specifically.
For how long have I used the solution?
I have been using Splunk Enterprise Platform for the last four years in my position, across multiple positions over a couple of different contracting companies with the Department of Energy.
What do I think about the stability of the solution?
Splunk Enterprise Platform is stable.
What do I think about the scalability of the solution?
In our current environment, Splunk Enterprise Platform's scalability has been impressive as we have been able to reach sites across the United States and bring in more sites daily. We have had no issues with the scalability at this time.
How are customer service and support?
Customer support for Splunk Enterprise Platform is great. I have bi-weekly phone calls with Splunk and they are always available to answer my questions and provide suggestions and a way forward for any issues that arise during my deployments. I would rate the customer support a ten.
What was our ROI?
I cannot speak to that as it is not my daily responsibility, so I am not up to date with those current metrics. I cannot speak to whether I have seen a return on investment.
What other advice do I have?
The advice I would give to others looking into using Splunk Enterprise Platform is to make sure you do your research because utilizing Splunk Enterprise Platform is one thing, but utilizing Splunk Enterprise Platform properly will give you an entirely different data set that is going to be more beneficial to your company. Using Splunk Enterprise Platform just to meet compliance is not taking advantage of all the different features that it has available. I would strongly suggest that anybody who is looking into Splunk Enterprise Platform research all the capabilities that it has to make sure that the capabilities that would be most beneficial for your company are actually deployed so you are not missing important data that could stop a bad actor from getting into your network or reduce productivity from internally. I would rate this product eight out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Last updated: Sep 16, 2026
Flag as inappropriateManager at a university with 10,001+ employees
Log aggregation has unified diverse security data and supports ongoing compliance reporting
Pros and Cons
- "Splunk Enterprise Platform has positively impacted my organization because it works and solves the problem that we have."
- "The user interface for search results is slower than it should be, and we would appreciate higher performance."
What is our primary use case?
My main use case for Splunk Enterprise Platform is log aggregation and SOC operations.
For log aggregation and SOC operations, any alerts that are generated by detection tools go into Splunk.
Once those alerts are in Splunk, analysts review them manually.
What is most valuable?
The most useful feature that Splunk Enterprise Platform offers is the integration with data sources.
Integrating with various data sources has made my work easier and more effective.
I have logs coming in from network devices, endpoints from different operating systems, RADIUS or other NAC tools that might have all kinds of different formats, and then it's all there in Splunk.
Splunk Enterprise Platform has positively impacted my organization because it works and solves the problem that we have.
It allows us to satisfy compliance audits because having the data there in Splunk allows that reporting to be generated.
We are able to satisfy compliance reporting requirements since implementing Splunk.
What needs improvement?
I would prefer to have real-time reporting as opposed to just schedule-based jobs with Splunk Enterprise Platform.
The user interface for search results is slower than it should be, and we would appreciate higher performance.
These are the top two needed improvements for Splunk Enterprise Platform.
For how long have I used the solution?
I have been using Splunk Enterprise Platform for ten years.
What do I think about the stability of the solution?
Splunk Enterprise Platform has been very stable in my experience with no issues of downtime or reliability.
What do I think about the scalability of the solution?
Splunk Enterprise Platform's scalability is good.
The clustering capabilities allow us to scale it as our needs have grown.
How are customer service and support?
I have not had to reach out to customer support for Splunk Enterprise Platform.
Which solution did I use previously and why did I switch?
I have not personally used a different solution before Splunk.
We have used Splunk for a long time.
How was the initial setup?
Before choosing Splunk Enterprise Platform, everything was already in Splunk.
Splunk being an open source deployment at the time was really just traditional syslog, not necessarily all the different products able to aggregate logs to a single space.
What about the implementation team?
Splunk is not doing any managing or controlling of governance within a private network environment.
Splunk is reporting on access control and compliance and policy, but it is just reporting.
What's my experience with pricing, setup cost, and licensing?
My experience with pricing, setup cost, and licensing for Splunk Enterprise Platform is that the add-ons feel very expensive.
The ingest license—I was fortunate to piggyback off of a parent organization that had an ingest license that was more than we needed—but then there are extra features that we would get that feel priced out of reach.
What other advice do I have?
The primary drivers for evolving my use of Splunk's federated search for querying data in place have been compliance and to some degree security.
Trusted control plane does not sound familiar to me regarding maintaining granular control over data using it within Splunk.
Role-based access control is going to always have to be there as my organization considers new use cases and agentic AI, and what role the AI agent needs to have is a good question.
My advice to others looking into using Splunk Enterprise Platform is that it depends on your use case.
If you are similar to our organization, then the clustering is probably the way to go.
I would rate this product an eight out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Last updated: Sep 15, 2026
Flag as inappropriateManager - SOC and CERT at a energy/utilities company with 1,001-5,000 employees
Automation and AI have transformed investigations while dashboards and search deliver rapid insights
Pros and Cons
- "The best features are good dashboarding, excellent search capabilities, and the speed of searching data."
- "With Splunk Enterprise Platform specifically, I hit a real hard wall at about 300,000 searches an hour, and I could not get above that."
What is our primary use case?
I work with Splunk Enterprise, Enterprise Security, UBA, and SOAR. We are relatively small because of the amount of automation and AI that we have implemented. Probably 20 people use it, but we are a massive enterprise and we fulfill the purpose across the entire enterprise.
What is most valuable?
The best features are good dashboarding, excellent search capabilities, and the speed of searching data. My experience in maintaining granular control over data with the trusted control plane is very good. I love federated search. The biggest thing for us with federated search is the ability to use it to do searches into other data planes.
What needs improvement?
A lot has room for improvement; Dashboard Studio needs significant enhancement. Their SPL, when I am running Agentic workloads, is not well suited to Agentic AI at all, especially when I have Agentic AI agents that are writing their own SPL. The MCD server could really do with a lot of improvement.
The bottom line is that going into the Agentic era, and this is across any data platform, no data platform at this moment in time is built to handle the Agentic AI era. With Splunk Enterprise Platform specifically, I hit a real hard wall at about 300,000 searches an hour, and I could not get above that. That is a real bottleneck.
When I am running Agentic swarms doing investigations, incident response, and other things and querying in code, SPL at its very core is not designed for agents. It is a human language. The volume of searches, even when I am running tens of indexes, does not scale horizontally as I thought it would. Adding more compute does not solve this issue at the volume of searches I am running now. It is fine for humans.
For how long have I used the solution?
I have been working with Splunk Enterprise Platform through various companies for the last eight years.
What do I think about the scalability of the solution?
Stability is a 10 and scalability, in the human world and context, is also a 10. However, in the Agentic world, it would probably be a four or a five.
Which other solutions did I evaluate?
The only real competitor is Elastic, and it is much of a muchness. There are a couple of other SIEM vendors and SOAR vendors that are also good. If I had to go to cloud, I would probably go to Google SecOps before I go to Splunk Cloud, but for on-premise, you would be hard-pressed to beat Splunk Enterprise Platform.
What other advice do I have?
We use Agentic AI for other things, but we do not use it for granular access control. I have built entire Agentic AI workloads and I have extensive experience using Agentic AI. It has been a multi-year journey and challenge. If I am running it on-prem, governance management is great. I would rate this solution an 8 overall.
Which deployment model are you using for this solution?
On-premises
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Google
Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
Last updated: Sep 11, 2026
Flag as inappropriateConsultant at a tech vendor with 10,001+ employees
Centralized monitoring has reduced incident resolution time and improves operational visibility
Pros and Cons
- "Overall, Splunk Enterprise Platform helps me monitor system health, reduce incident resolution time, and improve operational efficiency."
- "The licensing model is based on data ingestion volume and can become expensive as organizations grow."
What is our primary use case?
My main use case for Splunk Enterprise Platform is to monitor and troubleshoot, perform incident analysis, and search and analyze applications and system logs to identify the root cause of issues. I create dashboards to monitor key metrics, configure alerts for critical events, and generate reports for the operation systems.
A specific example of how I used Splunk Enterprise Platform to solve a problem occurred when users reported intermittent application failures in production. I used Splunk Enterprise Platform to search and correlate application and server logs using SPL. By filtering the logs based on timestamps and error codes, I identified repeated timeout exceptions that were caused by backend services. I created a dashboard to monitor these errors and configured an alert to notify the support team whenever the error count exceeded a threshold. This helped the team detect similar issues proactively and reduce troubleshooting time significantly.
In addition to troubleshooting and log analysis, I use Splunk Enterprise Platform for real-time monitoring of application and infrastructure, creating dashboards for operational visibility, configuring alerts for critical events, and generating reports for stakeholders. I use SPL to analyze trends, identify recurring issues, and support root cause analysis. Overall, Splunk Enterprise Platform helps me monitor system health, reduce incident resolution time, and improve operational efficiency.
What is most valuable?
Splunk Enterprise Platform offers numerous powerful features including powerful log search using SPL, real-time monitoring and alerting, interactive dashboards and visualizations, data indexing and fast search, centralized log management, role-based access control, scalability, and integrations with various data sources. These features help our organization monitor and troubleshoot our systems.
Out of those features, I find the combination of real-time monitoring and SPL search capabilities the most valuable in my day-to-day work. Real-time monitoring helps me identify issues as soon as they occur, while SPL allows me to quickly filter and analyze large volumes of logs to pinpoint the root cause. This significantly reduces the troubleshooting time. I also rely heavily on dashboards because they provide a clear view of application health, error trends, and system performance in one place. Centralized log management is another key advantage as it brings logs from multiple sources and servers together, eliminating the need to check each system individually. Overall, these features help me resolve incidents faster, improve system reliability, and reduce downtime.
An additional feature I truly appreciate is the flexibility of Splunk Enterprise Platform. It can ingest data from a wide variety of sources, such as application servers, operating systems, and network devices, and correlate all the information in a single platform.
What needs improvement?
In order to improve Splunk Enterprise Platform, there are a few areas that need improvement. The licensing model is based on data ingestion volume and can become expensive as organizations grow. The initial setup and configuration can also be complex for new users.
I would rate Splunk Enterprise Platform an eight because it is a powerful and reliable platform for centralized log management and real-time monitoring. It significantly improves our troubleshooting times. I did not give it a ten because the licensing costs can be high, the initial setup and administration can be complex, and there is a learning curve for SPL and advanced configurations.
For how long have I used the solution?
I have been using Splunk Enterprise Platform for about two years.
What do I think about the stability of the solution?
Splunk Enterprise Platform is stable.
What do I think about the scalability of the solution?
Splunk Enterprise Platform is highly scalable. It can handle increasing volumes of machine data by scaling horizontally, such as adding more indexes, search heads, and forwarders as an environment grows. This allows organizations to support more users, onboard additional data sources, and process large amounts of data.
I do not have direct experience managing Splunk Enterprise Platform at petabyte scale. However, based on my understanding, Splunk Enterprise Platform is designed to scale horizontally by adding indexes and search heads, which allows it to handle very large data volumes. For data sovereignty, it supports role-based access controls, encryption, and various deployment options.
How are customer service and support?
My experience with customer support was great.
Which solution did I use previously and why did I switch?
I have not previously used a different solution before Splunk Enterprise Platform; we directly adopted Splunk Enterprise Platform.
How was the initial setup?
The initial setup and administration can be complex, and there is a learning curve for SPL and advanced configurations.
What about the implementation team?
The setup was performed by our in-house team who are highly skilled in working with Splunk Enterprise Platform.
What was our ROI?
I definitely see the return on investment. Splunk Enterprise Platform improved our reliability, and the time to investment ratio has been excellent because the time we are spending solving incidents through Splunk Enterprise Platform has been great.
What's my experience with pricing, setup cost, and licensing?
My experience with pricing, setup cost, and licensing indicates that the initial setup cost, and when the organization grows, the setup cost might increase significantly. The main costs considering Splunk Enterprise Platform are licensing, infrastructure, and setup. Since licensing is based on data ingestion volume, costs can increase as the organization generates more log data.
Which other solutions did I evaluate?
We did not evaluate other options before choosing Splunk Enterprise Platform; we directly chose Splunk Enterprise Platform as our first option.
What other advice do I have?
My advice to others looking into using Splunk Enterprise Platform is that if there is an organization which is about to scale to large numbers, I would highly suggest Splunk Enterprise Platform. However, I would ask them to carefully check and ingest valuable data only for cost efficiency. I would rate this recommendation an eight out of ten.
Which deployment model are you using for this solution?
On-premises
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Other
Disclosure: My company has a business relationship with this vendor other than being a customer. Consultant
Last updated: Jul 15, 2026
Flag as inappropriateSenior Manager at Bank of America
Personalized dashboards have improved anomaly detection and help prevent system outages
Pros and Cons
- "Overall, Splunk Enterprise Platform impacts my organization positively, and I can see the benefit from using the product."
- "For improvement, I do see a lot of issues with Splunk support, particularly with response times."
What is our primary use case?
I still work with Splunk Enterprise. I want to clarify that I am only working with Splunk Enterprise, not with Splunk AppDynamics, Splunk Cloud Platform, or Splunk Enterprise Platform. I am solely focused on Splunk Enterprise for my current work.
What is most valuable?
I have been working with this platform for almost the last five years, even more than that. Overall, it has been around 17 years that I have been working in IT and with software in general, not only Splunk but other software as well. That was really good. The primary use for us was anomaly detection and system outage prevention, and Splunk was definitely helpful to us in those areas. The personalized dashboards in Splunk have helped me significantly with my overall workflow.
We are using Splunk Enterprise Platform for advanced threat detection. The Splunk feeds go through different systems for SIEM audits, and we utilize them from there. Overall, Splunk Enterprise Platform impacts my organization positively, and I can see the benefit from using the product.
What needs improvement?
For improvement, I do see a lot of issues with Splunk support, particularly with response times. When there is an issue, finding the root cause is taking too long. The system shows some error infrastructure-wise, but that error is not directly linked with the problems. There are some delays with the response time from their technical support, and I am not very satisfied with their work in this regard.
For how long have I used the solution?
I have been working with this platform for almost the last five years, even more than that.
What do I think about the stability of the solution?
There was no complexity with implementation. It was straightforward for me and my team, with no complexities involved.
What do I think about the scalability of the solution?
I do not see any challenges with scalability right now. Integration with third-party tools is quite easy, and I have not noticed any difficulties in this area.
How are customer service and support?
Regarding the technical support of Splunk, there are some delays with the response time, and I am not very satisfied with their work in this regard.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
Before Splunk, I worked with Dynatrace and AppDynamics. Splunk is the one directly used for log analytics and anomaly detection. I have not worked with any competitors such as Datadog.
We were moved from AppDynamics to Dynatrace. We used AppDynamics more for transaction tracing. From there, we were strategically moved into Dynatrace. For the entire log monitoring, we still recommend Splunk Enterprise Platform. We still use Dynatrace for the other transaction trace and other services. The reason for switching from AppDynamics to Splunk Enterprise Platform was that we needed a dedicated solution specifically for log monitoring and anomaly detection.
What was our ROI?
I cannot say directly about cost reduction, but it is returning on our platform in terms of detections. In terms of finance, I do benefit from Splunk Enterprise Platform, and it provides a return on investment.
What's my experience with pricing, setup cost, and licensing?
Right now, the Enterprise version is reasonable. When we go for Splunk Cloud or something similar, we recently had negotiations, and that is acceptable. When it comes to Enterprise, it is definitely reasonable in terms of pricing.
Which other solutions did I evaluate?
We are not using Splunk's Machine Learning Toolkit directly, but the Splunk feeds are still going back to the originating machine learning systems.
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
Last updated: Mar 15, 2026
Flag as inappropriateTechnical Lead at a financial services firm with 10,001+ employees
Comprehensive log monitoring has enabled deep customization and proactive anomaly detection
Pros and Cons
- "When I talk about Splunk Enterprise Platform, I can say that Splunk Enterprise Platform is, whatever the tool I have worked from my last eight, nine years of experience in my overall corporate journey, a very powerful tool where I can customize everything as per my requirement."
- "There is very much improvement needed from Splunk vendor support side because they need to check what people are raising in the requests."
What is our primary use case?
I am working with Splunk Enterprise Platform, and I have worked with Enterprise and ITSI, both. Sometimes I have worked with ES also, Enterprise Security.
I use Splunk Enterprise Platform mostly for log monitoring. In our company and our projects, we are monitoring for log monitoring, we are using Splunk. After that, we have created some dashboards according to our requirement and alerts and reports. Sometimes for historical data, we have created summary indexing. We are managing our Splunk Enterprise Platform infrastructure like search head, indexers, deployment server, and license master. We have 1,000, you could say 10,000+ UF. Some of them we are using with apps like Splunk DB Connect. For Kafka, we are using different add-ons for sending our data to Splunk Enterprise Platform from different log paths and log sources. That is the main use for Splunk Enterprise Platform. Mostly we are using it for log monitoring.
What is most valuable?
When I talk about Splunk Enterprise Platform, I can say that Splunk Enterprise Platform is, whatever the tool I have worked from my last eight, nine years of experience in my overall corporate journey, a very powerful tool where I can customize everything as per my requirement. There is no hesitation and there is no limitation for my customization. Whatever I want, I can do that from Splunk Enterprise Platform. If I am talking about tools other than Splunk Enterprise Platform, they are not very vast, or not good enough to customize. Here I can customize. If I need to customize from backend side, I can do whatever using Python, Java. If I want to create some things, that is a different thing. In every project, the requirements differ. If I need JavaScript in my platform, in my dashboard, where I want to customize and play with the dashboard according to my requirement, I can use JavaScript. I send the data, I can use Python script to send the data to Splunk Enterprise Platform. There are very different things. Mostly the SPL, which I am using, has already covered most of the things. But for what is not covered, I can use some different things also.
In my opinion, the effectiveness of Splunk Enterprise Platform in detecting anomalies for preventing system outages is very good. It is improving day by day.
When I talk about the personalization dashboard in Splunk Enterprise Platform, I can easily customize my dashboard.
Even if people do not know about Splunk Enterprise Platform, they want to create the dashboard, they can just drag and drop. They can add a widget and choose some visualization like a bar chart. If they do not know about the XML or the backend of their dashboards, they can still do it from the UI only.
The Application Management feature in Splunk Enterprise Platform may help enhance the end-user experience, but I need to check that.
Advanced threat detection in Splunk Enterprise Platform is very good enough to detect anomalies and detect vulnerabilities. Splunk Enterprise Platform has a different product called Splunk ES, which is a very good product in cybersecurity. I can easily detect some problems, and it automatically sends alerts. The anomaly detection is very good for live production data. Whenever an anomaly comes in an application, it automatically resolves and just gives the notification. It creates incidents or whatever is needed, where I can integrate with different tools like PagerDuty, Moogsoft, or even send my data into Slack if I am not using ServiceNow.
What needs improvement?
For a potential area of improvement in Splunk Enterprise Platform, I can say to try to make it easy for the user and user-friendly.
Simplifying the UI would help, because not everybody has it in their knowledge. If you want to sell your product, you will go with the company CIO, Chief Information Technology Officer. I do not think he will be working on that project; he will be working on your tool. Their resources, their employees will be working on Splunk Enterprise Platform. If you will show them the UI where they can understand, even if they do not know about any coding, they can just play, drop, and drag. If you satisfy them, then anyone will work on their tool in their company. I just want to give you the business perspective, because if you talk to any CIO, they are looking first at the UI part. They will not look into the coding part; they will just check the UI. If the UI is user-friendly, it will attract every person.
There is very much improvement needed from Splunk vendor support side because they need to check what people are raising in the requests. They do not understand the concerns people are raising. I do not think Splunk is working on their application support, I believe they hire third-party people who do not know as much about Splunk Enterprise Platform.
Regarding deep knowledge of the product, I am talking about the technical aspects. If anyone says something is not working, it seems many cases I have raised where they do not reply to my request adequately. That is why I say there is a requirement for improvement.
For how long have I used the solution?
I have been working with Splunk Enterprise Platform for the last six years.
What do I think about the stability of the solution?
From one to ten, I would rate the stability for Splunk Enterprise Platform as a nine.
What do I think about the scalability of the solution?
I would rate the scalability as an eight.
How are customer service and support?
For technical support from Splunk, I can say it is a two only.
How would you rate customer service and support?
Neutral
How was the initial setup?
The setup process for Splunk Enterprise Platform is very simple.
Which other solutions did I evaluate?
In my opinion, the main competitors for Splunk Enterprise Platform in the Enterprise Platform market are Dynatrace and DataDog. Recently, at a Dynatrace conference, they mentioned their goal to beat Splunk Enterprise Platform in the future.
DataDog is also relevant. For open-source options, ELK is available for those who need a more budget-friendly solution since Splunk Enterprise Platform is not open source and is quite costly.
What other advice do I have?
I am working with Splunk Enterprise Platform and Dynatrace, and my feedback was really valuable for us.
I am using Splunk Enterprise Platform, and I am combining it with a Cloud platform, AppDynamics, and SOAR.
I worked with Splunk Machine Learning Toolkit, but that is a different thing. I have not worked so much on the MLTK side, so I cannot say anything, I cannot give more of an idea or feedback on that.
The ability to manage applications through Splunk Enterprise Platform is something I need to check.
I am talking about Splunk Enterprise Platform, and there is a lot it provides to the end user. The first thing for Splunk Enterprise Platform is that I can organize my data, like the Common Information Model, CIM, where there are different departments in my company and different application owners. Accordingly, they can set their data, which they do not want, they can just skip that. Whenever they need, they just use the simple one, and that data will be present. In one umbrella, they can see different locations and different data. In any organization, I have to organize my data. If I do not organize my data, then it would be very difficult to find it.
Directly, if I just check my application, I can enter my application, like in Linux. I just enter index equal to Linux, and it gives me all the details. Even in the dashboard, I select Linux, and it shows all the data, including vulnerabilities, CPU usage, and memory usage.
This is a really good point. Because people are not working on their tool. If I tell any technical problem in Splunk Enterprise Platform to the CIO, I do not think he will understand. He has not worked on it; he does not know what I am talking about. But if you present to him that our UI is very helpful to everyone in your organization, no matter if they are on the leadership team, application team, development team, testing team, or application support team, they can all use our tool easily without any hesitation. Even if they need help, Splunk Enterprise Platform has introduced AI, which helps answer any questions regarding SPL.
I purchased Splunk Enterprise Platform directly from the vendor.
I rate the price for Splunk Enterprise Platform as a five because it is very high. If the price were lower, there would be no tools in the market capable of competing with Splunk Enterprise Platform. The only reason people think about moving from Splunk Enterprise Platform to another tool is the price. I would rate this Splunk Enterprise Platform solution with an overall rating of eight.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Last updated: Mar 5, 2026
Flag as inappropriateBuyer's Guide
Download our free Splunk Enterprise Platform Report and get advice and tips from experienced pros
sharing their opinions.
Updated: September 2026
Popular Comparisons
Tableau Enterprise
Informatica PowerCenter
SAP BusinessObjects Business Intelligence
ThoughtSpot
Splunk ITSI (IT Service Intelligence)
SAS Visual Analytics
Splunk Cloud Platform
Apache Superset
Splunk On-Call
RStudio Connect
Splunk Security Essentials
Buyer's Guide
Download our free Splunk Enterprise Platform Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- What's your experience or opinion about Spotfire vs. Tableau vs. Qlik?
- A journalist is writing a story about which Data Visualization software product to choose. Can you help him?
- What enterprise data analytics platform has the most powerful data visualization capabilities?
- When evaluating Data Visualization, what aspect do you think is the most important to look for?
- What are the best self-service and Excel-like filtering / display tools?
- What data visualization tool/s do you find to be the best?
- Why is Data Visualization important for companies?
- Which Data Visualization tools are good at collaboration and support the tracking of insight actions?
- How many users on average are licensed users of Data Visualization software in a company?
















