No more typing reviews! Try our Samantha, our new voice AI agent.
ISSE at a outsourcing company with 10,001+ employees
Real User
Top 20
Sep 16, 2026
Centralized security data has supported investigations but data transformation still needs work
Pros and Cons
  • "Splunk Enterprise Platform has positively impacted my organization because it gives our SOC the ability to secure our organization's information technology posture."
  • "I have not seen a return on investment, and I cannot share any relevant metrics, such as fewer employees needed, money saved, time saved, or anything else."

What is our primary use case?

My main use case for Splunk Enterprise Platform is as an administrator preparing data for the SOC. My job is to validate that the SOC has the data they need.

I validate that the SOC has the data they need using SPL queries in Splunk Web.

What is most valuable?

The best features Splunk Enterprise Platform offers are the ability to store and query large amounts of data efficiently.

Splunk's ability to store and query large amounts of data has helped me in my work because we are able to store data longer than we need it, and there have been cases where a cybersecurity investigation required data older than we are required to retain from a regulatory compliance standpoint. We were able to go back two years to query data where only a year of retention is required.

Splunk Enterprise Platform has positively impacted my organization because it gives our SOC the ability to secure our organization's information technology posture.

What needs improvement?

Splunk Enterprise Platform can be improved by providing better tooling for transforming data easily between ingestion and storage.

The ingest and edge processor features are nice to have, but they seem to be a case of Splunk leaning into their weaknesses instead of leaning into their strength of ingesting, storing, and querying data. I think perhaps Splunk should reset their data transformation technology considerably to make the end-to-end visibility better for customers and less convoluted using conf files in Splunkd and Otel in the edge and ingest processors.

For how long have I used the solution?

I have been using Splunk Enterprise Platform for eight years.

Buyer's Guide
Splunk Enterprise Platform
September 2026
Learn what your peers think about Splunk Enterprise Platform. Get advice and tips from experienced pros sharing their opinions. Updated: September 2026.
914,394 professionals have used our research since 2012.

What do I think about the stability of the solution?

Splunk Enterprise Platform is stable.

What do I think about the scalability of the solution?

Splunk Enterprise Platform's scalability is great because we can scale out our search heads or our indexers, our deployment servers, or any other role horizontally as needed.

How are customer service and support?

In my experience, customer support has been such that the first level of support is often following scripts, and it can be difficult to get more complicated problems moved past level one.

Which solution did I use previously and why did I switch?

I did not previously use a different solution.

What was our ROI?

I have not seen a return on investment, and I cannot share any relevant metrics, such as fewer employees needed, money saved, time saved, or anything else.

What's my experience with pricing, setup cost, and licensing?

I did not have a decision-making role and generally was not involved in negotiations, only in assessing Splunk Enterprise Platform against alternatives regarding pricing, setup cost, and licensing.

Which other solutions did I evaluate?

Before choosing Splunk Enterprise Platform, I evaluated other options, including Cribl, CrowdStrike, and DataDog.

What other advice do I have?

My advice to others looking into using Splunk Enterprise Platform is to leave your data where it lives. Do not try to centralize it, particularly in a federal government space. That is no longer necessary according to the latest guidance. Find a product that lets you query across different products, vendors, tenants, geographical areas, and other entities, something that is product-agnostic.

For the data that we store in Splunk, it does a fine job, but we do not store all our data in Splunk. We have a federated logging and telemetry posture, and I will not go into those other vendors and products that we use, but they all do a fine job of what we need.

We do not use Splunk Federated Search.

I maintain granular control over data using the trusted control plane within Splunk Enterprise Platform through role-based access and granular capabilities and index permissions on the roles.

I find Splunk Enterprise Platform's role-based access and index permissions effective for controlling who can see or interact with specific data, but the interface for roles and the ability to report on the roles is somewhat limited, particularly where we have SAML integration and have to build reports using a combination of SPL and PowerShell queries.

As my organization considers new use cases like agentic AI, we are still figuring that out, but the MCP server's added role capabilities are probably going to be adequate, but we are figuring out exactly how it will be implemented.

Regarding Splunk Enterprise Platform's AI capabilities, I do not know much about Splunk's AI platforms other than the fact we have used Splunk's MCP server and have built our own agents. We have not actually used any Splunk-branded AI technologies other than the Machine Learning Toolkit a little bit or the AI Toolkit, and that was for development and testing.

Regarding Splunk Enterprise Platform's AI capabilities, the accuracy and reliability of output based on my limited experience with the AI Toolkit or Machine Learning Toolkit is that it has limited statistical models and does not actually have many machine learning techniques and models available, and it would be nice to see more there.

My overall rating for Splunk Enterprise Platform is seven out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Last updated: Sep 16, 2026
Flag as inappropriate
PeerSpot user
R Nandasana - PeerSpot reviewer
Senior Information Technology Security Consultant at Mideast Data Systems
Real User
Top 5Leaderboard
May 7, 2026
Centralized monitoring has unified security insights and supports flexible architecture design
Pros and Cons
  • "What I appreciate most about Splunk Enterprise Platform is that one of the best features is its ability to support customization."
  • "What I dislike about Splunk Enterprise Platform is the props and transforms functionality. For most types of data, we have custom add-ons and everything is available, but for some data we want to parse, the add-on is not available."

What is our primary use case?

In my enterprise work as a consultant, I designed most of the architecture based on customer use cases and requirements. For the use case part, we can convert data into CSV to JSON with the ingest processor, which is a good point for data reduction. We create security alerts, notifications, and many data models to monitor data for compliance purposes.

Regarding Federated Search, it is an excellent feature. We have a separate environment where we can search data from different complete stacks or different complete Splunk infra. We have one platform with a complete environment for SIEM and another environment for observability. We enabled Federated Search between both of these environments. Any observability team can get data from the SIEM, and the SIEM team can get data from observability.

What is most valuable?

What I appreciate most about Splunk Enterprise Platform is that one of the best features is its ability to support customization. You can customize anything in Splunk Enterprise Platform. We have scripted input, normal file monitor, port monitoring, and many add-ons. Splunkbase is one of the biggest app and add-on stocks available. It supports everything you need. Wherever your data is, we can retrieve it. This is one of the best things about Splunk Enterprise Platform.

What needs improvement?

What I dislike about Splunk Enterprise Platform is the props and transforms functionality. For most types of data, we have custom add-ons and everything is available, but for some data we want to parse, the add-on is not available. Then we need to write manual props and transforms. Sometimes there are many issues with the Regex. When you write Regex, it may not work properly. In the Regex101 platform, you find Regex working, but when you apply it to Splunk Enterprise Platform, it is not working. Therefore, props and transforms, such as parsing of the data, are not that reliable.

Regarding maintenance, I don't think there is a strict maintenance requirement, but we need to continuously monitor the platform. For example, when Splunk version upgrades come in, we need to upgrade. Continuous monitoring is required. Sometimes knowledge bundle size increases, sometimes an alert is not running, and sometimes we have search head cluster replication factor down. Many kinds of issues are present with Splunk Enterprise Platform because you have your own infrastructure. This could be a plus or minus at any time, which is where we need to focus on maintenance.

Regarding the feature called Trusted Control Plane, I am not familiar with it. Is it in Splunk 10x or what?

For how long have I used the solution?

I have been using Splunk Enterprise Platform for eight years.

What do I think about the stability of the solution?

The stability of Splunk Enterprise Platform is very good. There are no stability concerns.

What do I think about the scalability of the solution?

Scalability is also good. There is not much configuration required. If you want to expand anything, you can increase more indexes or add storage. There is a separate storage tier that you can expand however you want. It supports both vertical and horizontal scaling. You can grow the environment without difficulty.

How are customer service and support?

I was working directly with Splunk when I worked at Splunk.com as a Site Reliability Engineer with the data system. There we directly supported all Splunk customers by upgrading their environments, installing apps, and performing Splunk version upgrades. We handled many tasks such as changing configurations. For everything that a customer raised a support case for, we were the ones who provided support.

I have contacted Splunk support myself. I worked with two clients, including Emirates Airline, which I am currently working on. I raised support cases many times, including ODS cases. Regeneron Pharmaceuticals was another customer, and I raised many technical support cases for them.

I would rate Splunk support a nine because they are very good and very technical. They provide solutions on time, which is something I appreciate.

How was the initial setup?

The initial deployment of Splunk Enterprise Platform is simple and very easy. You need some training before you do it. For a single instance, it is very easy. You just need to unzip the package and install it. However, if you want to set up clustering, search head clustering, indexer clustering, and other configurations, you either need to read the documentation or complete the architect labs. For me, it was very easy because I was an architect and consultant at that time.

What's my experience with pricing, setup cost, and licensing?

Regarding pricing, it is costly. I don't know the exact numbers, but it is very expensive. However, it is worth it when you are using it properly. When you have a proper SIEM, proper data, and everything is in compliance, and you use Splunk Enterprise Platform to its full potential, then this investment is worth it.

Which other solutions did I evaluate?

I have used alternatives, and most of the customers are using Cribl for parsing because it has the best UI and visual elements. In Splunk Enterprise Platform, we need to write the files, but Cribl offers a visual approach, which is better.

What other advice do I have?

I was working with Emirates Airline, where we take a license from Splunk and use Splunk Enterprise Platform. We have our own on-premises infrastructure. I am a customer of Splunk Enterprise Platform. I would give this product an overall rating of nine.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Last updated: May 7, 2026
Flag as inappropriate
PeerSpot user
Buyer's Guide
Splunk Enterprise Platform
September 2026
Learn what your peers think about Splunk Enterprise Platform. Get advice and tips from experienced pros sharing their opinions. Updated: September 2026.
914,394 professionals have used our research since 2012.
Information Security Engineer at a university with 5,001-10,000 employees
Real User
Top 20
Sep 16, 2026
Centralized security analytics has accelerated incident response but dashboard creation remains complex
Pros and Cons
  • "Splunk Enterprise Platform has positively impacted my organization by allowing us to react to incidents significantly faster."
  • "I think Splunk Enterprise Platform can be improved with easier dashboards since dashboard building is incredibly complex."

What is our primary use case?

My main use case for Splunk Enterprise Platform is security analytics.

A specific example of how I use Splunk Enterprise Platform for security analytics is that when we are alerted about a threat through our IDS, I will often perform investigations through our data that we are pulling into Splunk Enterprise Platform to chase down the threat. I also occasionally use Splunk Enterprise Platform for threat hunting to see anomalies in the data set.

I have more to add about how we use Splunk Enterprise Platform, as it was built in and is maintained by our infrastructure team for infrastructure analytics and troubleshooting.

What is most valuable?

The best features Splunk Enterprise Platform offers include the ability to centralize logs across multiple data sets.

What I find most valuable about centralizing logs is speed and ease of searching, especially during a security incident, as having to swivel chair is not effective.

Splunk Enterprise Platform has positively impacted my organization by allowing us to react to incidents significantly faster.

An example of how much faster my team can respond to incidents now is that it probably cuts our investigation time down by at least thirty to forty percent.

What needs improvement?

I think Splunk Enterprise Platform can be improved with easier dashboards since dashboard building is incredibly complex.

I rate it a seven because there is a pretty steep learning curve, especially once you get into actually having to craft SPL queries.

For how long have I used the solution?

I have been using Splunk Enterprise Platform for about three years.

What do I think about the stability of the solution?

Splunk Enterprise Platform is stable.

What do I think about the scalability of the solution?

Regarding Splunk Enterprise Platform's scalability, we have seen some issues with scaling out storage; other than that, we have not had any issues.

How are customer service and support?

So far, our experience with customer support has been good.

I would rate the customer support of Splunk Enterprise Platform an eight on a scale of one to ten.

What was our ROI?

I don't believe we've seen a return on investment in terms of reduced FTEs; in fact, the opposite is true, as it has required an FTE to run. However, I think it has reduced the number of tools and other systems that we have needed to purchase because we can integrate on a single system.

What other advice do I have?

Regarding Splunk Enterprise Platform's AI capabilities, I think its governance and security seem to be on the right track from what we have seen.

As for the accuracy and reliability of output from Splunk Enterprise Platform's AI capabilities, I have been impressed so far, as we are using the MCP server, and I have been impressed with the output.

My impression of Splunk Enterprise Platform's capability to manage data sovereignty at a petabyte scale within my environment is that because we are entirely on-premises, I have no concerns about that.

My experiences in maintaining granular control over data using the trusted control plane within Splunk Enterprise Platform show that we set up incredibly granular controls over data with very little issue.

As my organization considers new use cases such as agentic AI, Splunk Enterprise Platform's governance and role-based access controls play a role in how we manage access to our operational data, as we are currently considering that and looking at how we can integrate.

We have not tracked specific metrics to evaluate the success of reducing total cost of ownership with Splunk Enterprise Platform's non-indexing analytics approach so far.

My advice for others looking into using Splunk Enterprise Platform is that it is an excellent platform, and to make sure you carefully consider cloud versus on-premises. I rate this product a seven overall.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Last updated: Sep 16, 2026
Flag as inappropriate
PeerSpot user
reviewer2901339 - PeerSpot reviewer
Application Server Administrator at a healthcare company with 10,001+ employees
Real User
Top 20
Sep 21, 2026
Centralized log analytics has improved alerting and speeds up finding issues across servers
Pros and Cons
  • "Splunk Enterprise Platform is very user-friendly, and our users love the ability to use the search interface, which helps determine issues when you know something is happening, but you do not know where it is happening in all of our various items that exist, all the systems that produce logging data."
  • "I believe that Splunk Enterprise Platform is expensive, but that is about all I know regarding pricing, setup cost, and licensing."

What is our primary use case?

The main use case for Splunk Enterprise Platform is collecting logs from across the enterprise and ingesting them so that we can use them to easily search and also for alerting if there are problems with all the different applications and pieces of software that we have installed here.

A simple example of how I use Splunk Enterprise Platform for alerting or searching is if we have a Linux server that is running out of memory. We have the Linux logs in Splunk and then we have an alert set up that if the memory gets below a certain threshold, then it creates a ticket for our team to address it. If the memory gets so low that it is a critical issue, then we get paged that it is an urgent issue we need to take care of.

What is most valuable?

Splunk Enterprise Platform is very user-friendly, and our users love the ability to use the search interface, which helps determine issues when you know something is happening, but you do not know where it is happening in all of our various items that exist, all the systems that produce logging data.

For our use case, the absolute best feature of Splunk Enterprise Platform is that you can get data into Splunk Enterprise Platform from anywhere, and that is really useful because there are just so many different sources.

We are primarily using Universal Forwarders, but we also use HEC forwarders and heavy forwarders to integrate different data sources.

Our users definitely love the ability to create their own dashboards in Splunk Enterprise Platform so that they can monitor the applications that they are involved in, making that a popular feature.

Splunk Enterprise Platform has made it a lot faster to find problems. This is very much Splunk Enterprise Platform's core functionality where instead of having to go and SSH into different servers and look at log files on each one, which can take a lot of time, you are able to search via the GUI and pull up logs across all of the applications being monitored.

What needs improvement?

I think making the user interface easier to navigate for users is important for improving Splunk Enterprise Platform. It may be that SPL2 takes care of some of this. I have not used that yet, but I know using just SPL, it takes quite a training for users to learn how to search Splunk Enterprise Platform most effectively.

I come from using Atlassian products a lot, and I found their documentation to be a lot easier to use, so I think Splunk Enterprise Platform could benefit from a lot more documentation out there. When I Google for an issue in Splunk Enterprise Platform, it is maybe 50-50 on whether I will pull back the information I need. It seems like I have to open a support request often with them.

For how long have I used the solution?

I have been using Splunk Enterprise Platform for about 10 years.

What do I think about the stability of the solution?

Splunk Enterprise Platform is stable, but it could be better.

What do I think about the scalability of the solution?

The scalability of Splunk Enterprise Platform is pretty good, as we have not had significant issues with scaling it.

How are customer service and support?

The customer support for Splunk Enterprise Platform could be better in that the support agents could be more knowledgeable. It takes a lot of communication to get them on board usually with what we are experiencing.

How was the initial setup?

It was fairly easy to do, and I appreciate the opportunity to provide feedback regarding my experience with Splunk Enterprise Platform.

What's my experience with pricing, setup cost, and licensing?

I believe that Splunk Enterprise Platform is expensive, but that is about all I know regarding pricing, setup cost, and licensing.

Which other solutions did I evaluate?

I know we evaluated options before choosing Splunk Enterprise Platform, but it has been several years ago and I was not involved in that process, so I do not know what the other options were.

What other advice do I have?

I would advise others looking into using Splunk Enterprise Platform to carefully evaluate if there is any less expensive option out there at this time that would do enough of what Splunk Enterprise Platform provides, as it is a very expensive product. I would rate my overall experience with Splunk Enterprise Platform an 8.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Last updated: Sep 21, 2026
Flag as inappropriate
PeerSpot user
reviewer2879052 - PeerSpot reviewer
Operations Digital, Technology & Innovation Japac Head Of Strategic Planning at a pharma/biotech company with 10,001+ employees
Real User
Top 10
Jul 23, 2026
Centralized monitoring has unified our alerts and improves daily threat detection workflows
Pros and Cons
  • "Splunk Enterprise Platform has had a significant positive impact on our organization."
  • "Pricing for Splunk Enterprise Platform is actually very high, but at the same time, the value that it gives is highly beneficial."

What is our primary use case?

Splunk Enterprise Platform serves as our SIEM tool where we receive alerts and we primarily depend on it. As a centralized logging and monitoring system, we use Splunk based upon different data types. We receive data from our EDR solutions, our email, and cloud sources, so Splunk acts as a centralized point where we receive alerts from multiple sources. Day-to-day operations include Windows event loggings, such as when we get brute force alerts and similar kinds of alerts. Another example is with respect to Office 365, which is our messaging logs where if there is a need and any email forwarding rules are detected, we set a set of alerts. We also receive alerts from the cloud, GuardDuty logs, and CloudTrail logs.

What is most valuable?

Splunk Enterprise Platform is a platform I truly love, whether it's the use cases, how we fine-tune them, how we parse them, or how we create dashboards exclusively in Splunk Enterprise Platform, and even the admin part. The dashboarding functionality provides a single-pane-of-glass view for us where whenever an alert comes or any part of threat hunting that we do, it stands exclusively, and we are able to monitor them at one place. Other features such as RBAC and risk-based alerting mechanisms provide a one-page view for us. With respect to the UI, we get all the details in; it is very user-friendly; we do not need to search here and there; we get it immediately.

Splunk Enterprise Platform has had a significant positive impact on our organization. We had a previous SIEM tool and migrated to Splunk Enterprise Platform. The storage logs and the storage bucketing system in Splunk Enterprise Platform is extensively large, and the amount of data that is getting parsed is substantial. Splunk Enterprise Platform is the one platform where we use it on a day-to-day basis, not only with respect to the cyber team but all the other data reporting team and data team use it as well.

What needs improvement?

With respect to the use cases, we were able to create many use cases as well as fine-tune them, so thirty percent of the alerts were fine-tuned, and we have improved our detection logic and also the outcomes. In specific to the metrics, our detection rate was high. The mean time to detect was incredibly lower than when compared to the previous SIEM.

With respect to Splunk Enterprise Platform, we can have a bunch of use cases though we already have a database where we get a list of use cases. Given the trend, we can improve them. Just with threat intelligence, if Splunk Enterprise Platform gets a new feature such as IOCs integration directly, that would be very helpful, just as the Falcon threat intelligence. It would be helpful if we get Splunk threat intelligence as well.

For how long have I used the solution?

In my current field, I have been working for about six years.

What do I think about the stability of the solution?

Splunk Enterprise Platform is stable with no doubt about that.

What do I think about the scalability of the solution?

I rate the scalability of Splunk Enterprise Platform an eight on ten.

How are customer service and support?

I rate the customer support of Splunk Enterprise Platform a nine on ten.

Which solution did I use previously and why did I switch?

We had a previous SIEM tool and migrated to Splunk Enterprise Platform. The storage logs and the storage bucketing system in Splunk Enterprise Platform is extensively large, and the amount of data that is getting parsed is substantial. Splunk Enterprise Platform is the one platform where we use it on a day-to-day basis, not only with respect to the cyber team but all the other data reporting team and data team use it as well.

What's my experience with pricing, setup cost, and licensing?

Pricing for Splunk Enterprise Platform is actually very high, but at the same time, the value that it gives is highly beneficial.

What other advice do I have?

With respect to the use cases, we were able to create many use cases as well as fine-tune them, so thirty percent of the alerts were fine-tuned, and we have improved our detection logic and also the outcomes. In specific to the metrics, our detection rate was high. The mean time to detect was incredibly lower than when compared to the previous SIEM.

With respect to Splunk Enterprise Platform, we can have a bunch of use cases though we already have a database where we get a list of use cases. Given the trend, we can improve them. Just with threat intelligence, if Splunk Enterprise Platform gets a new feature such as IOCs integration directly, that would be very helpful, just as the Falcon threat intelligence. It would be helpful if we get Splunk threat intelligence as well.

As of integrations, we are good. Splunk Enterprise Platform can be integrated with multiple SOAR solutions, so I would prefer to focus on the threat intelligence side.

Accuracy regarding Splunk Enterprise Platform's AI capabilities should be termed as a normal figure between sixty to seventy-five percent because sometimes it is not just AI capabilities; human intelligence is needed as well. So I would keep it around that range.

With respect to cybersecurity, you have the best solution available. I rate this review a nine overall.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Last updated: Jul 23, 2026
Flag as inappropriate
PeerSpot user
Cyber Security Analyst at a government with 5,001-10,000 employees
Real User
Top 20
Sep 16, 2026
Improved threat visibility and audit success has supported us while high costs still limit value
Pros and Cons
  • "Splunk Enterprise Platform has positively impacted our organization by giving us better visibility into our data, helping us identify threats, and from a compliance perspective, it helps us pass audits with flying colors."
  • "One way Splunk Enterprise Platform can be improved is that cost is always going to be a problem."

What is our primary use case?

I do engineering for it to build out the platform, to do both compliance as well as to feed data to a SOC.

One specific example of how I use Splunk Enterprise Platform for compliance or for feeding data to the SOC is that we have lots of data sources that are deployed all across our network and have to try to get everything aggregated so that we can build alerts and have visibility into activities happening on the network. So, I deployed a Corelight sensor and architected a data feed to get all of that data back to Splunk Enterprise Platform to be used.

I interact with Splunk Enterprise Platform as a bit of a user as well as an administrator and an architect. I run the team that does everything with it.

What is most valuable?

The best features Splunk Enterprise Platform offers, in my experience, are the ability to search your data quickly and easily, especially if you use data model accelerations and index extractions; things like T-stats are extremely fast.

Those features, like T-stats and data model acceleration, impact my daily workflow and the team's efficiency by definitely increasing efficiency considerably. One thing I do is filter down what our noisiest source types are, and T-stats enable me to look back at historical data incredibly fast.

Splunk Enterprise Platform has positively impacted our organization by giving us better visibility into our data, helping us identify threats, and from a compliance perspective, it helps us pass audits with flying colors.

We have tracked specific outcomes and metrics, like audit pass rates and improved threat detection, resulting in us passing 100% of audits and receiving kudos specifically on all of our network monitoring, and being told that it has been some of the best that they have seen in our field.

What needs improvement?

One way Splunk Enterprise Platform can be improved is that cost is always going to be a problem. I think another thing is some of the apps that are made into premium apps requiring subscriptions could be made free just to be less cost-prohibitive.

Regarding the needed improvements, I feel that the UI in some of the newer versions of Splunk Enterprise Platform is not well received. We do not like it very much; there have been changes made that are unwanted changes, making it harder to find things and slowing down the usability of the product.

For how long have I used the solution?

I have been using Splunk Enterprise Platform for about three and a half years.

What do I think about the stability of the solution?

Splunk Enterprise Platform is stable.

What do I think about the scalability of the solution?

I would say Splunk Enterprise Platform is highly scalable, due to the ability to cluster both indexers and search heads; it is very scalable.

How are customer service and support?

Customer support has been good.

Which solution did I use previously and why did I switch?

I did not previously use a different solution; Splunk Enterprise Platform is the only solution we have used for this.

How was the initial setup?

Licensing is fairly expensive, especially for any of the premium products. If we choose to go that route, such as Enterprise Security, it is definitely very expensive.

Which other solutions did I evaluate?

Before choosing Splunk Enterprise Platform, I did not evaluate other options; Splunk Enterprise Platform was already selected as a vendor before I started my job.

What other advice do I have?

I rate Splunk Enterprise Platform a seven on a scale of one to ten.

I give it a seven because cost is definitely the number one thing that keeps it from being higher; I would say mostly cost.

Regarding Splunk Enterprise Platform's AI capabilities, I have not really used Splunk Enterprise Platform's AI.

I imagine Splunk Enterprise Platform would probably manage data sovereignty at a petabyte scale fine. Our scale is much smaller than that, but I think it would scale up effectively if needed.

I do not think I have used the trusted control plane within Splunk Enterprise Platform to maintain granular control over data.

As my organization considers new use cases such as agentic AI, we will definitely have to restrict access control over everything AI-related across the network, so Splunk Enterprise Platform would be just another application in that regard.

I feel that Splunk Enterprise Platform gives me the right tools and flexibility to manage things such as compliance, user permissions, and data privacy when it is running on my private network. I think it does a good job; it just requires us as administrators to determine exactly what it is going to be, but the controls are fine—they are good.

We do not use Splunk Enterprise Platform with non-indexed data for evaluating the success of reducing TCO with its non-indexing analytics approach.

The advice I would give to others looking into using Splunk Enterprise Platform is that it is a good product if you have a need for it. I would just say to consider using other third-party vendors in tandem with it, as there are other things that can work well with it and integrate with it.

I rate Splunk Enterprise Platform a seven overall.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Last updated: Sep 16, 2026
Flag as inappropriate
PeerSpot user
reviewer2899380 - PeerSpot reviewer
Senior Development Operations Engineer at a insurance company with 10,001+ employees
Real User
Top 20
Sep 16, 2026
Monitoring has become proactive and teams gain live insight into financial transaction issues
Pros and Cons
  • "Our downtime has been reduced to almost nothing for the area of Splunk that my team uses."
  • "Accuracy and reliability is mixed."

What is our primary use case?

My main use case for Splunk Enterprise Platform is to explain our monitoring practices. We use Splunk Enterprise Platform to monitor application transaction data for financial companies and create dashboards and reports and alerts based on that information.

From day-to-day, Splunk Enterprise Platform helps our development team, our product support team, our quality assurance analysts, and at times our fraud detection teams the ability to do their jobs better and to see the data directly as it comes live. The reports and alerts help us in our production environment, be notified of any issues, such as a client having low or no volume. We want to know about that because that means we are not getting their information to us.

What is most valuable?

The biggest feature for us of Splunk Enterprise Platform is out-of-box ease of use. We have people that are comfortable with the classic dashboards, and I am more comfortable with the Dashboard Studio or the classic dashboards. Some of the other features are mostly plug and play where we set up a configuration, and things just work. With some basic add-ons such as the SIM add-on, it can normalize all the different data and different formats of data into something singular that makes dashboarding so much easier. Splunk AI and the Splunk AI assistant helps our users and people that are new to our company onboard really quickly.

Splunk Enterprise Platform has given us visibility where before we had none. We have gone from a reactive organization or posture for issues to a more proactive approach. We can see issues before our customers do and we stay ahead of the problem.

Our customers are our main concern because we have SLA agreements with them and we have to meet those agreements. Them being happy is our biggest thing, and them giving us positive feedback is key to the success of our business. When their positive feedback says that we are catching problems faster than they can even identify them, that is a significant positive for our company because they really give us recognition when we are that far ahead of the problem. Then they open an incident ticket, and we immediately close it and then fill in the information where we have already taken actions against that. Internally, our teams can quickly get to an issue or a potential issue and stay ahead of the problems. Our downtime has been reduced to almost nothing for the area of Splunk that my team uses.

What needs improvement?

Splunk Enterprise Platform improvements could come with a bit more robustness in the SPL query syntax. There are certain things that we cannot do together, and there are certain queries that are limited in what they can do or there are certain combinations that will not work together. That would be the biggest improvement overall because that is the foundation of all of Splunk, which is just being able to build from that.

For how long have I used the solution?

I have been using Splunk Enterprise Platform for ten years.

What other advice do I have?

From what I have seen with the AI capabilities of Splunk Enterprise Platform, its governance is very good. The capabilities are right exactly where we need them to be as just an assistant to assist our user base with things that they might not know or with new users.

Accuracy and reliability is mixed. With AI, nothing is perfect yet. Sometimes it takes the wrong context or the information incorrectly, so it takes a bit of working with the AI assistant to get the correct or desired result.

Splunk Enterprise Platform's governance and role-based access controls have a very large and significant role because we have to remain PCI and PII compliant. Splunk's governance of that information, especially when it comes to agentic AI, even with read-only permission, can expose a customer's personally identifiable information or their credit card information, and that needs to be tightened down quite a bit for the financial sector.

I would advise others looking into using Splunk Enterprise Platform to be patient with it and take their time to develop it correctly. I give this review a rating of nine out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Last updated: Sep 16, 2026
Flag as inappropriate
PeerSpot user
Chirag Singhtalwar - PeerSpot reviewer
Technical site manager at Tagbin
Real User
Top 20
Jul 10, 2026
Centralized logging has transformed security monitoring and incident response efficiency
Pros and Cons
  • "Splunk Enterprise Platform has improved visibility across the environment by centralizing logs from multiple systems, reduced the time needed to detect, investigate, and respond to security incidents, streamlined troubleshooting, and helped my team respond to issues more quickly, improving operational efficiency and reducing downtime."
  • "One area for improvement for Splunk Enterprise Platform is the learning curve."

What is our primary use case?

My main use case for Splunk Enterprise Platform is security monitoring and incident detection. I use Splunk Enterprise Platform to collect and analyze logs from servers, endpoints, firewalls, and network devices. I monitor security events, investigate alerts, troubleshoot issues, and support incident response through dashboards and log search.

One example of how I have used Splunk Enterprise Platform for security monitoring and incident detection was when Splunk Enterprise Platform generated multiple failed login alerts for a privileged account from different IP addresses in a short period. I used SPL to review the authentication logs, correlating them with firewall and Windows Event Logs. I confirmed it was a password spraying attempt rather than normal user activity. I escalated the incident, the account was secured, and the source IPs were blocked.

In addition to security monitoring, I use Splunk Enterprise Platform for operational monitoring and troubleshooting. It helps me quickly search logs from Windows and Linux servers, network devices, and security tools to identify the root cause of issues. I have also used dashboards to monitor system health and create alerts for critical events, which improves response time and reduces manual log analysis.

What is most valuable?

The best features Splunk Enterprise Platform offers are its log analysis and its powerful log search capabilities using SPL. Centralized log collection, real-time monitoring, alerting, customizable dashboards, fast troubleshooting, and the ability to correlate events from multiple data sources are all valuable. It also scales well for large environments and integrates with many security and IT tools, making incident investigation much more efficient.

Splunk Enterprise Platform has improved visibility across the environment by centralizing logs from multiple systems. It has reduced the time needed to detect, investigate, and respond to security incidents, streamlined troubleshooting, and helped my team respond to issues more quickly. Overall, it has improved operational efficiency and reduced downtime.

What needs improvement?

One area for improvement for Splunk Enterprise Platform is the learning curve. Splunk Enterprise Platform and SPL can take time for new users to master. Licensing and data ingestion costs can also become expensive as log volumes grow. Additionally, simplifying the initial deployment and providing more out-of-the-box dashboards and use cases would help organizations get value more quickly.

For how long have I used the solution?

I have been working for three or more years in my current field.

What other advice do I have?

The feature I rely on the most day-to-day is SPL, Search Processing Language. It allows me to quickly search and filter large volumes of logs, investigate alerts, and troubleshoot issues instead of manually checking logs on multiple systems. I can correlate events from different sources in one place, identify root causes faster, and respond to incidents more efficiently.

One thing I particularly appreciate about the features is the flexibility of Splunk Enterprise Platform dashboards and alerts. They can be customized for different teams and prioritized, making it easier to monitor critical events without constantly searching through logs. That saves time and helps focus on the most important issues.

Although we have not measured exact KPIs, Splunk Enterprise Platform helped reduce the time required to investigate incidents. Instead of manually checking logs across multiple systems, we could quickly search centralized logs and identify the root cause much faster. For many incidents, the initial investigation time was reduced from around 30 to 45 minutes to approximately 10 to 15 minutes, which improved our overall response time.

Regarding Splunk Enterprise Platform's AI capabilities, from my experience, it provides strong governance and security through role-based access control, audit logging, encryption, and integration with enterprise identity providers. These features help ensure that access to data and AI-assisted capabilities is controlled and traceable. As AI capabilities continue to evolve, I would appreciate seeing even more transparency around AI-generated results and more granular governance controls.

From my experience, Splunk Enterprise Platform's AI-assisted capabilities are generally accurate and can help in prioritizing alerts, summarizing information, and speeding up the investigation. However, I do not treat the output as definitive. I always validate AI-generated insights against the underlying logs and other evidence before making a decision. Overall, I would describe the accuracy and reliability as good, but human verification is still important.

My advice for those looking into using Splunk Enterprise Platform is to clearly define your logging and security monitoring objectives before deployment. Start with your most critical data sources. Invest time in learning SPL and build dashboards and alerts that align with your operational needs. Additionally, plan your data ingestion carefully to manage licensing costs and get the best value from the platform. I rate this product a nine out of ten.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Last updated: Jul 10, 2026
Flag as inappropriate
PeerSpot user
Sydney D'Souza - PeerSpot reviewer
Security Consultant at SoftwareONE
MSP
Top 5Leaderboard
Mar 4, 2026
Correlation rules have strengthened threat detection while interface and pricing still need improvement
Pros and Cons
  • "The personalized dashboards in Splunk Enterprise Platform are a good feature."
  • "I think the machine learning toolkit is fine, but when I talk about threat intelligence, it is not that effective."

What is our primary use case?

The most valuable feature I have found so far is the correlation rule. That seems to be very valuable for us. I can create any alert using the correlation rule, which seems to be interesting for me.

I use Splunk Enterprise Platform for advanced threat detection with the correlation rules, nothing else. We have only very few customers, just two customers. They are not interested in those higher versions of Splunk Enterprise Platform. We rely completely on the correlation rule. We highly rely on this correlation rule.

What is most valuable?

The personalized dashboards in Splunk Enterprise Platform are a good feature. We have created multiple dashboards. It is easy and understandable, and whatever we need, we can get it. It is not only with Splunk Enterprise Platform but with all the other products. I would say we can go ahead and create a customized dashboard. Since I am working for SOC, I do have an internal dashboard that I have for myself where I have all the service metrics dashboard available. I make use of that rather than going directly into Splunk Enterprise Platform creating there.

What needs improvement?

I think the machine learning toolkit is fine, but when I talk about threat intelligence, it is not that effective. Since recently, I think Splunk Enterprise Platform has acquired Cisco, which has acquired VirusTotal if I am not wrong. I think VirusTotal. Initially, what used to happen was that the threat intelligence source I used for Splunk Enterprise Platform was not regularly updated. I faced challenges there, and then finally, when I went ahead and researched, I found that VirusTotal is readily available to be used in Splunk Enterprise Platform. So I integrated it, and as of now, I am making better use of it.

The effectiveness of Splunk Enterprise Platform in detecting anomalies and preventing system outages completely depends upon the correlation rule, but when it comes to threat intelligence, I have not explored much of the source side. I am mostly on the SIEM side. Though I have some features that I have integrated, I am mainly working on the SIEM side rather than the source side.

The application management feature, which I believe refers to the interface, is not that attractive, I would say. It is a simplified version, and I am using the cloud platform of Splunk Enterprise Platform instance. It is simple, but it is okay. It is manageable.

I definitely find it problematic, and I think they could need to have more nuances and more features when it comes to the interface. It should be more extended.

From my perspective, Splunk Enterprise Platform can be improved by first making the GUI, the interface, more attractive. The second improvement should try to include all the threat intelligence into that platform, integrating all threat intelligence. The behavior monitoring is a bit of a concern because I do not see much detection. Maybe that is because I am using only the correlation ID, but still, the behavior monitoring should automatically detect. Even if it is a SIEM solution, if I create some rule, that is what I have customized it for. I am not sure if SOAR has that capability, but in case SOAR does have that capability, if not, then they have to improve their machine learning and behavior analytics. I have been in touch with different technicians from different organizations, and they have mentioned these challenges. There are a few drawbacks when it comes to Splunk Enterprise Platform.

I find the price a bit high, I would say. A bit high.

For how long have I used the solution?

I have been working with this product for one and a half years.

How are customer service and support?

I have no problem with the technical support provided by Splunk Enterprise Platform at all. I do get support whenever needed. I would rank them at an eight, with ten being the highest.

How would you rate customer service and support?

Positive

How was the initial setup?

As for the initial setup and configuration for Splunk Enterprise Platform, I will not say it is easy. It is a bit complicated. But since I have support, that makes my life easier. It is a bit complicated compared to Trend Micro, compared to CrowdStrike, and compared to Microsoft Sentinel or Defender for Cloud, Defender for Endpoint. Splunk Enterprise Platform is on the complicated side.

Which other solutions did I evaluate?

As of now, I am pitching in for Microsoft Sentinel. I am also pitching in for CrowdStrike, which is also a bit expensive, but the only product that I pitch in is Microsoft's product, which is Microsoft Defender for Cloud for Servers, and Defender for Endpoint, Defender for Cloud Apps, Defender for Office, all those products. Defender is one of the cheaper ones. In case a customer is not okay with Microsoft, I pitch in CrowdStrike. First, I pitch in Trend Micro, and then I pitch in CrowdStrike, with CrowdStrike being at the higher price range.

One advantage these competitors have over Splunk Enterprise Platform besides lower pricing is that with one of my customers, they can fetch logs from all sources and bring them into Splunk Enterprise Platform. They can control the logs that are not required. My continuous monitoring allows me to ensure that in case there are certain logs that are no longer required, along with the architect, I can discuss that and bring down the overall log size to around 40 GB per day. I am talking about a log source that is more than 20 as of now for this customer.

The products that have this feature are CrowdStrike and Trend Micro, which have to be configured using the API. Even Microsoft has it, but Microsoft faces a lot of challenges when it comes to pulling a log from a log source that does not have an inbuilt connector. There is a challenge there. However, when it comes to Trend Micro and CrowdStrike, it is a bit easier there using APIs.

What other advice do I have?

I would recommend Splunk Enterprise Platform for bigger companies.

In the future, I expect additional features such as threat intelligence, behavior analytics, log searching, and machine learning capabilities.

As for any other functionalities I would like to see from them in the future, I do not have anything to add right now. I have something in my mind, and in case I remember, I will go ahead and add it.

Splunk Enterprise Platform is very popular in my region. My overall review rating for this product is seven out of ten.

Which deployment model are you using for this solution?

Public Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Other
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
Last updated: Mar 4, 2026
Flag as inappropriate
PeerSpot user
reviewer2898948 - PeerSpot reviewer
Computer System Application Specialist at a mining and metals company with 501-1,000 employees
Real User
Top 20
Sep 15, 2026
Improved security monitoring has saved significant investigation time each month
Pros and Cons
  • "Splunk Enterprise Platform has reduced time in our workflow; we are able to find or correlate events much quicker, making my team's work easier so they can focus on other priorities."
  • "We have had some frustrations with the amount of data we are sending to Splunk Enterprise Platform, as sometimes it contains information that is not needed, but that is more about my team needing to understand how to parse through that data before it gets sent to Splunk."

What is our primary use case?

Our main use case for Splunk Enterprise Platform is collecting syslog information from our servers and network equipment, and then generating alerts based on some security events.

I recognize that we are underutilizing Splunk Enterprise Platform.

What is most valuable?

I do not use Splunk Enterprise Platform much myself, but I took a class on the search application, and the ability to go through all the logs and perform searches and analyze the incoming data is very helpful.

I appreciate the fact that you can create searches and then create custom fields that you can later query for additional insights in Splunk Enterprise Platform, which was very helpful compared to the previous tool we used.

Splunk Enterprise Platform has reduced time in our workflow; we are able to find or correlate events much quicker, making my team's work easier so they can focus on other priorities.

What needs improvement?

I believe I am too new to provide feedback about how Splunk Enterprise Platform can be improved, but so far, what I see looks very good.

We have had some frustrations with the amount of data we are sending to Splunk Enterprise Platform, as sometimes it contains information that is not needed, but that is more about my team needing to understand how to parse through that data before it gets sent to Splunk. What we need more is additional training.

For how long have I used the solution?

My team has been using Splunk Enterprise Platform for a little over a year.

What do I think about the stability of the solution?

Splunk Enterprise Platform is stable.

What do I think about the scalability of the solution?

We have not tested Splunk Enterprise Platform's scalability yet; our deployment is stable and not changing.

How are customer service and support?

Customer support for Splunk Enterprise Platform is very good; whenever we have questions or are trying to do something, we can call support and get the help we need, and there is a ton of information available on the web that we can rely on.

Which solution did I use previously and why did I switch?

We used a different solution before using Splunk, but I cannot disclose which one it was; the support for that solution was very poor, combing through the data was clunky, and the price was very high.

How was the initial setup?

I chose a 10 for my rating because, from the feedback I have received, it was easy to implement, and it was as easy to ingest data into Splunk as it was from our previous solution, making data ingestion great and easy to use for my team.

What about the implementation team?

I would rate Splunk Enterprise Platform a 10; so far, no negative things have come out.

What was our ROI?

I would say our return on investment with Splunk Enterprise Platform was in time saved, as we have saved about 30 hours a month.

What's my experience with pricing, setup cost, and licensing?

We were able to track some metrics that indicated success in reducing TCO with Splunk's non-indexing analytics approach; while we were able to save some money by deploying Splunk, after adding a few extra devices, our ingestion went up significantly, which could have increased costs, but we managed that.

Which other solutions did I evaluate?

Before choosing Splunk Enterprise Platform, I did not evaluate other options.

What other advice do I have?

Splunk Enterprise Platform's AI capabilities sound very good; I do not fully trust them yet as I would want to see them in a dev environment in my data center first, with just non-production systems, so I would need to see them to really trust them.

I have not tested Splunk Enterprise Platform's AI capabilities, so I cannot speak much about its accuracy and reliability of output, but from what I have seen in the keynotes and presentations, it appears very promising.

I do not have a clear answer regarding Splunk Enterprise Platform's capability to manage data sovereignty at a petabyte scale within my environment.

I do not believe we utilize Splunk's Federated Search.

I am not experienced in maintaining granular control over data using the Trusted Control Plane within Splunk.

As my organization considers new use cases such as agentic AI, I believe Splunk Enterprise Platform's governance and role-based access controls would play a key role by controlling and applying security to our agents.

My advice to others looking into using Splunk Enterprise Platform is to work with a partner to help deploy it and deploy it the right way the first time. I gave this review an overall rating of 10.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Last updated: Sep 15, 2026
Flag as inappropriate
PeerSpot user
Buyer's Guide
Download our free Splunk Enterprise Platform Report and get advice and tips from experienced pros sharing their opinions.
Updated: September 2026
Buyer's Guide
Download our free Splunk Enterprise Platform Report and get advice and tips from experienced pros sharing their opinions.