We have been working with Splunk Enterprise Platform for two years. Currently, we have been running Splunk in our SOC for two years, but we have not used the Machine Learning Toolkit yet. I believe it is a powerful tool, but we have not explored it.
Security Consultant at ITSEC Asia
Flexible analytics have unified our security monitoring and improved threat detection workflows
Pros and Cons
- "I consider Splunk to be one of the best solutions available compared to other options."
- "From my perspective, Splunk tends to be too expensive for smaller customers."
What is our primary use case?
What is most valuable?
I think the most valuable feature of Splunk Enterprise Platform is its capability to correlate all the logs that we ingest into our platform. Splunk offers many predefined analytic stories that we can implement for our customers, which act as playbooks for detecting suspicious activity, anomalous behavior, and other security-related events. This capability stands out as a key feature of Splunk.
We work with Splunk on-premise, especially with Splunk Enterprise and Splunk Enterprise Security. Splunk Enterprise refers to Splunk Enterprise Platform and also includes the Splunk Enterprise Security platform, known as Splunk or Splunk ES.
We implement detection rules similarly across multiple platforms, including Microsoft Sentinel, Elastic Security, and IBM QRadar, and I can say that Splunk is one of the powerful SIEM tools. It offers us the flexibility to define our correlation rules and detection rules, which is a significant strength. Compared to other platforms, Splunk is more user-friendly regarding querying, making it easier to create detection rules and correlate various log sources.
What needs improvement?
From what I have noticed across all SIEM platforms, they are beginning to incorporate AI capabilities, which is an aspect that I think Splunk could enhance. Microsoft Sentinel, for example, features a Security Copilot, but it requires an additional license for use. Other platforms such as Google SecOps and Palo Alto's Cortex XSIAM integrate agentic AI capabilities that I believe will become standard features for all SIEM solutions in the future.
For generative AI, it would be beneficial for Splunk to add features allowing users to define queries using prompts. For example, being able to ask for the top 10 malicious IPs could simplify tasks significantly. Additionally, Splunk could consider an AI response feature where triggered alerts can prompt recommendations for users on corrective actions. A noise cancellation AI might also help security analysts reduce alert clutter. There are many agentic AI improvements that can be made in Splunk Enterprise Platform.
What do I think about the scalability of the solution?
In terms of scalability, many SIEM brands, including Splunk, provide options that adapt to a growing organization. As companies expand, the ability to scale their SIEM is crucial. Splunk allows for scalability, as you can start with an all-in-one instance and, as your deployment grows, split it into distributed deployment, such as separating the search head and indexers. I believe all SIEM solutions provide reliability, and Splunk is no exception as it also offers strong scalability.
Buyer's Guide
Splunk Enterprise Platform
September 2026
Learn what your peers think about Splunk Enterprise Platform. Get advice and tips from experienced pros sharing their opinions. Updated: September 2026.
914,394 professionals have used our research since 2012.
How are customer service and support?
We sometimes communicate with Splunk's technical support, but it is not often, especially regarding technical issues. When we encounter issues, we utilize the Splunk community, which I believe showcases a big advantage of Splunk due to its strong community support. Many of our technical problems are resolved by this community.
How was the initial setup?
I usually participate in the initial setup and deployment of Splunk Enterprise Platform.
What's my experience with pricing, setup cost, and licensing?
Regarding pricing, I remember that Splunk is generally more expensive than SIEMs such as Microsoft Sentinel and Securonix, while it is also pricier than Elastic Security. From my perspective, Splunk tends to be too expensive for smaller customers. This leads us not to recommend it for small companies due to the high cost and often pushes us to suggest alternatives such as Elastic Security, which has more volume-based licensing options.
Which other solutions did I evaluate?
I have experience delivering SIEM platforms to our customers, including Elastic Security, Microsoft Sentinel, Splunk, and IBM QRadar.
What other advice do I have?
We have many use cases for using Splunk Enterprise Platform. We use Splunk to detect anomalies in our customers' IT environments, such as their network environments. We want to detect suspicious activity or anomalous activity from our customer environments. From Splunk, we utilize many applications from Splunkbase to support our deployment. Many of our services relate to the Security Operation Center, so many of our use cases are linked to SOC activities.
Since the query capability in Splunk is extremely flexible, creating dashboards is also very easy. Dashboard creation depends on the SPL queries, and in the latest version of Splunk, we have two options: classic dashboards and Studio dashboards. Both options can be tailored to our needs, enabling us to create highly customized dashboards, for instance, by adding images. This flexibility makes crafting custom dashboards simple.
I find deploying Splunk to be very straightforward because you can choose to install it on either Linux or Microsoft operating systems. Before deployment, we conduct sizing for the instance, including storage, CPU, memory, and network considerations. Once sizing is clear, we proceed with the installation, which offers multiple options such as Debian packages or RPMs. Overall, the deployment process is quite easy.
Currently, many of our customers prefer cloud deployment for Splunk Enterprise Platform. We do not recommend specific cloud services, but we often see GCP, Google, and Microsoft Azure being used among our customers.
I consider Splunk to be one of the best solutions available compared to other options. If budget is not a concern, Splunk stands out due to its extensive integrations, flexibility in scalability, and the simplicity of its deployment. I would rate this review an overall 8.
Disclosure: My company has a business relationship with this vendor other than being a customer. partner
Last updated: Jan 1, 2026
Flag as inappropriateNetwork Engineering Operations Manager at a comms service provider with 10,001+ employees
Monitoring has reduced outages and provides live insight into video on demand success rates
Pros and Cons
- "Splunk Enterprise Platform has positively impacted my organization by helping us reduce our outages through monitoring."
What is our primary use case?
My main use case for Splunk Enterprise Platform is to monitor the video on demand success rate for our video platform.
A specific example of how I use Splunk Enterprise Platform for monitoring the video on demand success rate is that we monitor the success rate of video on demand plays on different markets where customers will order a video on demand program that will play on their set-top box. We collect a lot of log data for that and if a video on demand session fails, it logs an alarm code that will be monitored through our Splunk Enterprise Platform dashboards. It allows us to show the successful setup rate. It gives us information on the user, their MAC address, so we can see if all of the failed attempts are from the same user or different users. It also shows us different markets and allows us to narrow in on what device it might have failed in on based on what alarm ID it flags.
What is most valuable?
The best features Splunk Enterprise Platform offers include the customization because the way we have our dashboards set up helps us identify anomalies or if we have something that is happening or if an issue is cleared or not.
Regarding the customization aspect, we have it set up to graph the success rate over time, and the way the graph shows not only the success rate but failures on the same graph makes it easy to identify those anomalies. It will have a success rate line and then if there is a failure and the success rate line goes down, there is another line on the same graph that will show how many failures there were at that time.
Splunk Enterprise Platform has positively impacted my organization by helping us reduce our outages through monitoring.
Monitoring with Splunk Enterprise Platform has reduced outages for us because it is live data and that has allowed us to see trends in an area and anticipate if something is going to happen in a market that we need to get on top of.
What needs improvement?
I do not have any suggestions on how Splunk Enterprise Platform can be improved because I am happy with it.
If I had to think of one area where Splunk Enterprise Platform could be better or easier to use, helpful hints maybe could be added where you hover over something and it gives you some ideas of what you can do for that feature.
For how long have I used the solution?
I have been using Splunk Enterprise Platform for approximately five years.
What do I think about the stability of the solution?
Splunk Enterprise Platform is stable.
What do I think about the scalability of the solution?
Its scalability is easy.
How are customer service and support?
I have no complaints concerning customer support for Splunk Enterprise Platform.
Which solution did I use previously and why did I switch?
I did not previously use a different solution before Splunk Enterprise Platform in my department.
How was the initial setup?
My experience with pricing, setup cost, and licensing is great; I just log in. I was given a login and that is how I worked it. I do not think my department dealt with any of that; that is a whole other department within our organization.
What was our ROI?
I would say we probably do benefit from having Splunk Enterprise Platform because we use it every day and they have expanded our use of it and they have even decided to migrate it into the cloud versus trying to use other open platform systems. We continue to use it, which would tell me that it has been beneficial.
Which other solutions did I evaluate?
Before choosing Splunk Enterprise Platform, I did not evaluate other options.
What other advice do I have?
My advice to others looking into using Splunk Enterprise Platform is to research the product and utilize all the support that Splunk provides. I have rated this review a ten out of ten.
Which deployment model are you using for this solution?
Private Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Last updated: Sep 17, 2026
Flag as inappropriateBuyer's Guide
Splunk Enterprise Platform
September 2026
Learn what your peers think about Splunk Enterprise Platform. Get advice and tips from experienced pros sharing their opinions. Updated: September 2026.
914,394 professionals have used our research since 2012.
Senior Cyber Security Analyst at a tech vendor with 10,001+ employees
Security monitoring has become more effective and handles large log volumes with detailed analysis
Pros and Cons
- "Splunk Enterprise Platform has positively impacted our organization by improving our security posture, and our team performs good analyses since there is no need to select any log source; we just input the necessary fields and obtain the details."
What is our primary use case?
My main use case for Splunk Enterprise Platform is using it for security monitoring.
In security monitoring, we are using Splunk Enterprise Platform for multiple log sources which come from different devices including Active Directory, VPN, Defender, and EDR. We are receiving these logs from these devices and onboarding them on Splunk Enterprise Platform. We have written many alerts, and we are getting those alerts on Splunk Enterprise Platform and performing analysis on that.
Regarding my main use case with Splunk Enterprise Platform, we have written numerous security alerts and monitoring rules according to the log source requirements. We have obtained different alerts from Azure security, cloud security, and EDR, and we perform analysis on many alerts, closing them on Splunk Enterprise Platform after the analysis. We have integrated Splunk Enterprise Platform with ServiceNow, utilizing automation, and we use SOAR Phantom with Splunk ES. All these generate alerts and send them to Phantom, where we have written many playbooks to take actions based on those playbooks.
What is most valuable?
In my experience, the best feature of Splunk Enterprise Platform is its excellent data searching capability. Whenever we want to search long data or export heavy logs, we can easily export them from Splunk Enterprise Platform. Other tools do not offer this level of functionality; they have limited capabilities.
The searching feature in Splunk Enterprise Platform stands out because, for example, if I want to export multiple GB of logs, we can easily do so. In other tools, we do not have much functionality; they impose limitations on exporting large log sources. Splunk Enterprise Platform has a very good functionality called lookup, which allows us to add many elements into the lookup and expand it significantly, unlike other tools that have restrictions affecting formatting upon updates.
I find the visualization feature in Splunk Enterprise Platform to be very good, as well as reporting and dashboards, which we can customize based on SPL queries to see more detail in visualization. Additionally, the log ingestion and exporting capabilities are much better than other tools.
Splunk Enterprise Platform has positively impacted our organization by improving our security posture, and our team performs good analyses since there is no need to select any log source; we just input the necessary fields and obtain the details.
As for specific outcomes, we also achieve a good reduction in false positives because we can create lookups and assign permissions to our analysts based on requirements. We have many custom permissions we can add.
What needs improvement?
One area for improvement in Splunk Enterprise Platform is the issue we face when writing Regex; it would be beneficial to have a tool that can automatically generate Regex.
For how long have I used the solution?
I have been using Splunk Enterprise Platform for eight years.
What do I think about the stability of the solution?
I find Splunk Enterprise Platform to be steady.
What do I think about the scalability of the solution?
The scalability of Splunk Enterprise Platform is good.
How are customer service and support?
Customer support is good. I rate customer support a 10.
Which solution did I use previously and why did I switch?
We used a different solution previously, though those decisions were made by higher management rather than by me.
What's my experience with pricing, setup cost, and licensing?
I find the pricing, setup cost, and licensing of Splunk Enterprise Platform to be fine based on our usage and integrations.
Which other solutions did I evaluate?
Before choosing Splunk Enterprise Platform, we evaluated QRadar and found that its licensing cost was higher than that of Splunk Enterprise Platform.
What other advice do I have?
I rate Splunk Enterprise Platform a 10 based on my experience with multiple tools.
I choose to rate it 10 because Splunk Enterprise Platform helps ingest many logs, and we can perform extensive searches and large data exports easily.
Regarding Splunk Enterprise Platform's AI capabilities, I find its governance and capability to be good, with many apps available that we can integrate with Splunk ES to obtain results.
We can manage data sovereignty at a petabyte scale within our environment easily.
My experience in maintaining granular control over data using the trusted control plane within Splunk Enterprise Platform is good.
As my organization considers new use cases including Agentic AI, Splunk Enterprise Platform's governance and role-based access controls help us onboard Agentic AI logs on Splunk Enterprise Platform and write rules based on requirements.
My advice for others considering Splunk Enterprise Platform is that it works very well for handling long data and very large datasets. My overall rating for Splunk Enterprise Platform is 10.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Last updated: Jul 11, 2026
Flag as inappropriateInfrastructure Analyst at a energy/utilities company with 501-1,000 employees
Centralized monitoring has improved cloud VM insights and supports proactive CPU management
Pros and Cons
- "Splunk Enterprise Platform has positively impacted our organization by providing insight into our environment in a centralized manner so that we don't have to set up alerts in a bunch of different places; we just have to look at one place to get what we need."
- "I have not seen a return on investment and think we have some internal issues; we really just got Splunk Enterprise Platform for our SOC."
What is our primary use case?
Splunk Enterprise Platform is used primarily for our SOC and ingesting all metrics and data from all the virtual machines that we're running in our cloud environment.
A specific example of how I use Splunk Enterprise Platform in my daily work is monitoring CPU usage for VMs, and if CPU credits run out on a burstable instance, we know to add more credits or reconsider how we're using that VM.
What is most valuable?
The latest best feature Splunk Enterprise Platform offers is probably MCP server, where people in the organization don't need to have knowledge of SPL and syntax; they can just query Splunk Enterprise Platform directly.
MCP server has changed the way my team works and collaborates by democratizing the use of Splunk Enterprise Platform so we don't have to go to someone that knows how to use it; anybody can spin up the co-pilot agent and start querying.
Splunk Enterprise Platform has positively impacted our organization by providing insight into our environment in a centralized manner so that we don't have to set up alerts in a bunch of different places; we just have to look at one place to get what we need.
Splunk Enterprise Platform helped save time; we've had a few issues where VMs stopped responding and we had trouble figuring out what was going on, but we just went on Splunk Enterprise Platform and it was easy to see the data there.
What needs improvement?
Splunk Enterprise Platform can improve by taking more positive steps towards user-friendliness so that more people can access it without having to go through a bunch of training to learn how to use it.
For how long have I used the solution?
I have been using Splunk Enterprise Platform for about a year and a half.
What do I think about the stability of the solution?
Splunk Enterprise Platform is stable.
What do I think about the scalability of the solution?
Splunk Enterprise Platform's scalability is very good; we can just start plugging in indexes as we need.
How are customer service and support?
The customer support has been acceptable; we had an issue that we thought should be easily solvable or something that works out of the box, but it didn't.
Which solution did I use previously and why did I switch?
I previously used Microsoft Sentinel and switched because we had more places we needed to ingest data from.
What was our ROI?
I have not seen a return on investment and think we have some internal issues; we really just got Splunk Enterprise Platform for our SOC.
What's my experience with pricing, setup cost, and licensing?
My experience with pricing, setup cost, and licensing has been fairly straightforward; the partner we had to help us set up was pretty good.
What other advice do I have?
I cannot comment on Splunk Enterprise Platform's capability to manage data sovereignty at a petabyte scale within my environment because we're not at that level.
We haven't been using Splunk Enterprise Platform's federated search for querying data in place, so there hasn't been much evolution or primary drivers for either expanding or limiting its use.
I have no experience in maintaining granular control over data using the trusted control plane within Splunk Enterprise Platform; we don't use it much.
I learned a lot at this conference about how we can manage access to our operational data through Splunk Enterprise Platform; we're not quite at that level, but once we are, then I'll have more feedback.
I don't think we use the feature to track specific metrics to evaluate the success of reducing TCO with Splunk Enterprise Platform's non-indexing analytics approach.
My advice to others looking into using Splunk Enterprise Platform is to start small; ingest a little bit of data that you can start to see returns on right away, and then expand from there as you learn how it works. My overall review rating for Splunk Enterprise Platform is eight out of ten.
Which deployment model are you using for this solution?
Hybrid Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Last updated: Sep 16, 2026
Flag as inappropriateInformation Security Officer at a real estate/law firm with 5,001-10,000 employees
Centralized logs have transformed user behavior analysis and now speed up daily investigations
Pros and Cons
- "Splunk Enterprise Platform has positively impacted our organization by giving us insights into user behavior that we didn't have before, enabling us to track and monitor user activity that would otherwise have been missed."
- "I wasn't involved with the initial purchase, but I understand the pricing, setup cost, and licensing are quite expensive."
What is our primary use case?
My main use case for Splunk Enterprise Platform is as a log consolidation tool.
In my day-to-day work, we receive email logs, web logs, and any kind of user activity logs, and we investigate based on anomalies in user activity.
We initiated user behavior analysis, so we're looking for variations from a known baseline.
What is most valuable?
Splunk Enterprise Platform's best features include the ability to ingest data from any source without having to spend too much time getting the data into a set format.
The flexibility in data ingestion makes ingesting new data sources very easy and very quick for our team, allowing us to have new data sources online within a couple of days.
Splunk Enterprise Platform has positively impacted our organization by giving us insights into user behavior that we didn't have before, enabling us to track and monitor user activity that would otherwise have been missed.
It has led to faster investigations, as typically, we can go from query to resolution within a day.
What needs improvement?
The ability to delete data is something I would suggest for improvement, as at the moment, you can delete data from search, but you can't delete data permanently, which is an issue sometimes.
For how long have I used the solution?
I have been using Splunk Enterprise Platform for 15 years.
What do I think about the stability of the solution?
Splunk Enterprise Platform is stable.
What do I think about the scalability of the solution?
For our scale, Splunk Enterprise Platform's scalability is fine, as we have a relatively small license.
How are customer service and support?
Customer support for Splunk Enterprise Platform is good, but technical support is variable.
I would rate customer support an eight on a scale of one to ten.
Which solution did I use previously and why did I switch?
We did not use a different solution before Splunk Enterprise Platform; this was our first.
How was the initial setup?
I wasn't involved with the initial purchase, but I understand the pricing, setup cost, and licensing are quite expensive.
What was our ROI?
I can't share any exact figures regarding return on investment, but we've had Splunk Enterprise Platform for 15 years, so I would say they're happy with their ROI.
What's my experience with pricing, setup cost, and licensing?
I wasn't involved with the initial purchase, but I understand the pricing, setup cost, and licensing are quite expensive.
Which other solutions did I evaluate?
I evaluated other options before choosing Splunk Enterprise Platform; I can't remember them all, but I think Elasticsearch was one of them.
What other advice do I have?
My advice to others looking into using Splunk Enterprise Platform is to make sure you have a defined use case you can measure against.
Splunk Enterprise Platform is deployed on-premises in our organization.
We don't have it at that scale, but I'm sure Splunk Enterprise Platform would work very well for managing data sovereignty at a petabyte scale within our environment.
We don't use the trusted control plane, so I don't have experiences in maintaining granular control over data using it.
We won't be using Splunk Enterprise Platform with any AI because of the client data we hold, which affects how we manage access to our operational data.
My impression of Splunk Enterprise Platform's approach to managing governance within a private network environment is very good.
The cost of it keeps it from being a perfect ten for me.
For manual searches, we are very happy with the outputs of Splunk Enterprise Platform.
I would rate this product an overall nine out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Last updated: Sep 16, 2026
Flag as inappropriateCyber Security Consultant at EY
Daily security monitoring has become faster and incident response improves with accurate alerts
Pros and Cons
- "Splunk Enterprise Platform makes our job far more entertaining and easy to work on, helping us save on costs, money, and efforts."
- "I think Splunk Enterprise Platform can be improved to be more specific regarding certain cybersecurity-related incidents rather than giving all cybersecurity events; it can be far better."
What is our primary use case?
As a cybersecurity consultant, my job is to review all the alerts we are receiving on a daily basis and do root cause analysis of the alerts. I work as SOC L2, and I am using Splunk Enterprise Platform for cybersecurity purposes.
I start my day by logging into Splunk Enterprise Platform; first, I go to my dashboard where we get all the cybersecurity alerts. With the help of the dashboard, we get all the alerts, then we drill down those alerts and get all the information like user activity and the actions taken. Based on that, we respond to a cybersecurity incident.
I continuously use Splunk Enterprise Platform for multiple purposes, including reports, dashboards, cybersecurity incidents, alerts, and cybersecurity events. I do multiple things on a daily basis in Splunk Enterprise Platform.
In my current organization, we are using Splunk Enterprise Platform for multiple clients, and I think it is helping us very well because we use Splunk Enterprise Platform for mostly eighty percent of our clients, and so far so good.
As a SOC L2, I am using Splunk Enterprise Platform's Federated Search to query data, which is quite useful for managing our client requests.
What is most valuable?
I can say that Splunk Enterprise Platform is quite easy to use, and it is also smooth and clean. Based on the cybersecurity incidents and alerts we receive daily, it plays a major role in helping users understand what has happened in this activity or cybersecurity incident.
In the cybersecurity dashboard, Splunk Enterprise Platform plays a major role in getting and representing the cybersecurity alerts, which is quite easy to understand and work on. I never had any issue with Splunk Enterprise Platform getting wrong data or crashing, so I think it is quite robust.
Because of Splunk Enterprise Platform's ease of use, cybersecurity analysts can go through all the activities and incident events, helping us respond better to a cybersecurity alert. It aids various metrics including cybersecurity SLA and provides faster remediation.
The governance and security provided by Splunk Enterprise Platform, with artificial intelligence, is an important aspect because we are getting more than a hundred types of cybersecurity alerts. AI helps us bypass many false positives, allowing cybersecurity analysts to focus on real alerts.
Based on my recent experience, I find the accuracy and reliability of output quite good since it helps cybersecurity analysts focus more on high or critical alerts and reduces false positive alerts based on our previous responses and recommendations.
I think Splunk Enterprise Platform is quite efficient because it helps us manage cybersecurity incidents and alerts in a much better manner.
Splunk Enterprise Platform makes our job far more entertaining and easy to work on, helping us save on costs, money, and efforts.
What needs improvement?
I think Splunk Enterprise Platform can be improved to be more specific regarding certain cybersecurity-related incidents rather than giving all cybersecurity events; it can be far better.
I have provided all the information I have observed and experienced to improve Splunk Enterprise Platform.
For how long have I used the solution?
In the cybersecurity domain, I have been working for the last seven years.
What do I think about the stability of the solution?
Splunk Enterprise Platform is stable.
What do I think about the scalability of the solution?
Based on my observation, Splunk Enterprise Platform is highly scalable because we are onboarding multiple tenants.
How are customer service and support?
The customer support is adequate and very helpful.
What other advice do I have?
I advise others looking into using Splunk Enterprise Platform to be quite patient because getting to know how to work around it is going to help you. I would rate this product an eight out of ten.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Last updated: Jul 16, 2026
Flag as inappropriateSecurity Operations Center Analyst at a consultancy with 11-50 employees
Alert triage has become accurate and daily incident investigations are now more efficient
Pros and Cons
- "What I like the most about Splunk Enterprise Platform is that it generates alerts with true positives only."
- "What I dislike about Splunk Enterprise Platform is that there are so many logs coming in."
What is our primary use case?
First of all, I have to log in to Splunk Enterprise Platform with my login credentials provided by the company. Our company is RamnaSoft. Then I monitor the alerts coming in or analyze the logs coming in. I do the initial triage to the alerts. If I get some true positives, then I investigate further, examining IOCs and IOAs. I document it and forward it to my IR team or senior team, which is SOC 2 or SOC Level 3. Also, if I get some false positive alerts while initial triaging, then I update that in documents and also inform the IR team to monitor these false positive alerts to make changes according to their rules and procedures.
Federated Search is helpful, but it needs some basic knowledge of the log codes and query languages. I should know the queries to search on them.
What is most valuable?
What I like the most about Splunk Enterprise Platform is that it generates alerts with true positives only. There are fewer false positives, which is good for me. The alerts are good.
I use the Federated Search feature of Splunk Enterprise Platform for particular queries. I enter some queries there, and it responds accordingly.
What needs improvement?
What I dislike about Splunk Enterprise Platform is that there are so many logs coming in. Sometimes, unwanted logs are present, such as file creations. I do not prefer those logs.
To clarify, if some legitimate users create unnecessary files, it generates a log. Those logs are created, so I find that frustrating. Those logs are not useful to us.
For how long have I used the solution?
I have been using Splunk Enterprise Platform since last year, January 25th.
What do I think about the stability of the solution?
Regarding stability, I do not face any lagging, crashing, or downtime with Splunk Enterprise Platform. That is a very good thing.
What do I think about the scalability of the solution?
Splunk Enterprise Platform is scalable. I think it should also scale in the pen testing side and the vulnerability assessment side because right now, I am only focused on monitoring logs and alerts. It can scale in fields such as pen tests and vulnerability assessments by doing reports and documentation.
How are customer service and support?
I have not yet contacted the technical support or customer support of Splunk Enterprise Platform, but I only get in touch with my seniors, such as SOC 2s.
Which solution did I use previously and why did I switch?
I have used something similar to Splunk Enterprise Platform, but I cannot remember its name. It is something similar to ELK.
How was the initial setup?
The initial deployment of Splunk Enterprise Platform is somewhat time-consuming, but it is very easy. If I do it once, then it is not that hard, but it is a time-consuming process.
For the first time, I took around one hour to deploy Splunk Enterprise Platform. One hour was enough for me at that time.
What about the implementation team?
I have a team with my seniors who helped me deploy Splunk Enterprise Platform.
What's my experience with pricing, setup cost, and licensing?
I do not have any idea about the prices of Splunk Enterprise Platform. I think it is free.
Which other solutions did I evaluate?
I have used something similar to Splunk Enterprise Platform, but I cannot remember its name. It is something similar to ELK.
What other advice do I have?
To maintain granular control over data using the trusted control plane, I deploy Splunk Enterprise Platform on multiple machines and connect through it.
I am just a user of Splunk Enterprise Platform; my company provided it for me. I would rate my overall experience with this product a 9.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Last updated: Jul 26, 2026
Flag as inappropriateAssistant System Engineer at Tata Consultancy
Unified monitoring has improved alert investigations and reduced response time for security events
Pros and Cons
- "Splunk Enterprise Platform provides everything in one single platform, giving us a centralized log management system for faster threat detection and compliance purposes, which reduces the mean time to detect and respond to alerts in the environment."
- "One area for improvement is the high licensing cost that Splunk charges."
What is our primary use case?
I mostly use Splunk Enterprise Platform for monitoring and investigating alerts in the Infoblox environment.
When I receive an alert for excessive failed login attempts, I assign that alert to myself and start looking at the logs through drill-down searches where I check who the user is, what the failure reason is, and their event codes such as 4624 and 4625. I analyze those details.
Most of the time I monitor the environment and use the search capability of Splunk Enterprise Platform for log analysis.
What is most valuable?
The best features for my use case are query changes and searches, through which we can detect multiple suspicious activities in the environment. There is risk-based alerting and Threat Intelligence Frameworks that Splunk Enterprise Platform provides, as well as MITRE ATT&CK mapping.
I mostly use the Threat Intelligence Frameworks, which match known malicious IOCs including IPs, URLs, domains, and file hashes while correlating the alert.
Risk-based alerting is also a strong feature that Splunk Enterprise Platform provides because it assigns a risk score to the particular user or system instead of triggering alerts on every suspicious event, which reduces alert fatigue.
I have worked on ArcSight in the past, but ArcSight has different components such as the logger and the ESM. Splunk Enterprise Platform provides everything in one single platform. We do not have to log in to two different environments repeatedly. It also provides a centralized log management system where we can put all logs for faster threat detection. This reduces the mean time to detect and respond to alerts in the environment. Additionally, we use the log management capacity of Splunk Enterprise Platform for compliance purposes including HIPAA and PCI DSS.
We mostly use Splunk Enterprise Platform scheduled correlation rules, which we run on a scheduled basis rather than in real-time, which reduces the load on the system. It also provides a good amount of time to respond to alerts. Analysts can investigate alerts faster using the single platform.
What needs improvement?
One area for improvement is the high licensing cost that Splunk charges.
For how long have I used the solution?
I have been working in this field for 2.7 years.
What do I think about the stability of the solution?
Splunk Enterprise Platform is very stable.
What do I think about the scalability of the solution?
I give it a rating of 10 because it is really scalable and provides great capability for scaling.
How are customer service and support?
The customer service is really good. I received the solution within 24 hours.
Which solution did I use previously and why did I switch?
I did not particularly switch from another solution, but I found my previous platform complicated. I was working on a project where we were using ArcSight, but it is more complicated because it has a different ESM tool and different logger. We have to access those in different environments and log in two times when accessing them. Splunk Enterprise Platform provides everything in one place.
What's my experience with pricing, setup cost, and licensing?
Licensing relates to indexing the data that is ingested on a daily basis. The setup cost depends on the platform being acquired and the logs being ingested.
What other advice do I have?
I would advise that Splunk Enterprise Platform is really user-friendly and provides many functionalities. It is also integrating AI, which is helpful. I give this review a rating of 9 out of 10.
Which deployment model are you using for this solution?
Private Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Last updated: Jul 15, 2026
Flag as inappropriateCloud Engineer at a construction company with 1,001-5,000 employees
Logging and alerts have improved incident response and now support proactive server monitoring
Pros and Cons
- "Splunk Enterprise Platform has positively impacted my organization by allowing us to respond quickly to servers being offline or having resources consumed too heavily."
What is our primary use case?
My main use case for Splunk Enterprise Platform is logging and alerting.
A specific example of how I use Splunk Enterprise Platform for logging and alerting is monitoring server resource utilization as well as uptime and whether servers are offline.
When a server goes offline or resource utilization spikes, an alert is generated and sent via text message to me so that I can respond quickly.
What is most valuable?
The best feature Splunk Enterprise Platform offers is usability.
What specifically stands out to me about usability is the dashboards and alert setup.
Splunk Enterprise Platform has positively impacted my organization by allowing us to respond quickly to servers being offline or having resources consumed too heavily.
I have seen improvements in both response time and avoiding outages because of Splunk Enterprise Platform. Splunk Enterprise Platform is stable and seems to be pretty scalable. Customer support for Splunk Enterprise Platform is fairly good.
What needs improvement?
I think having a dashboard of SPL queries would be really helpful to improve Splunk Enterprise Platform.
For how long have I used the solution?
I have been using Splunk Enterprise Platform for three years.
What do I think about the stability of the solution?
Splunk Enterprise Platform is stable.
What do I think about the scalability of the solution?
Splunk Enterprise Platform seems to be pretty scalable.
How are customer service and support?
Customer support for Splunk Enterprise Platform is fairly good.
What was our ROI?
I cannot provide exact metrics regarding return on investment, but I know the time saved has been very significant.
What other advice do I have?
Regarding Splunk Enterprise Platform's AI capabilities, I find its governance and security intriguing; I do not know a great deal about it, but I have been intrigued by what the possibilities could be.
I am very confident in the accuracy and reliability of output from Splunk Enterprise Platform.
We are not really at the petabyte scale for managing data sovereignty with Splunk Enterprise Platform.
Our use of Splunk Enterprise Platform's Federated Search has evolved for querying data in place; we have expanded it for more visibility for more users, not just IT-based users.
We do not use the trusted control plane within Splunk Enterprise Platform for maintaining granular control over data, so I cannot comment on its effectiveness.
Splunk Enterprise Platform's governance and role-based access controls will be a big part of managing access to our operational data as we consider new use cases such as agentic AI.
My advice for others looking into using Splunk Enterprise Platform is to take your time and learn what you are doing.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Last updated: Sep 17, 2026
Flag as inappropriateTechnical Solutions Engineer at a tech vendor with 10,001+ employees
Data exploration has become faster and deeper and now supports effective presales workshops
Pros and Cons
- "In my opinion, the best features Splunk Enterprise Platform offers are the ability to dive deep into all the data you have stored, especially how quickly it performs and how flexible it is, along with how fast you can work with your data."
- "Customer support is adequate, but presales support could be better."
What is our primary use case?
My main use case for Splunk Enterprise Platform is to demonstrate how it works as part of presales work with our partners and customers.
I use prepared workshops from Splunk Show, such as Splunk for Rookies, Splunk for Rookies Observability, Splunk for Rookies Security, and Machine Data 101, as specific examples of how I use Splunk Enterprise Platform for my partners and customers.
The most challenging aspect of my use case was adding new data from outside sources, but this was in my own lab at home, where I wanted to integrate smart devices' data into Splunk Enterprise Platform.
What is most valuable?
In my opinion, the best features Splunk Enterprise Platform offers are the ability to dive deep into all the data you have stored, especially how quickly it performs and how flexible it is, along with how fast you can work with your data.
When I say it is quick and flexible, I find that more prepared charts are very easy to build with pre-built searches.
We are not using Splunk Enterprise Platform in our organization because we are a distributor, so I cannot give you an explanation of the real impact on our organization. However, based on information from my partners, they believe Splunk Enterprise Platform is beneficial for saving costs and shortening the time to resolve problems.
One of our partners and customers, which was a bank company, had an example of how they minimized noise alerts by using Splunk Enterprise Platform and Splunk Security Essentials, which helped them avoid a lot of false positives.
What needs improvement?
I think Splunk Enterprise Platform could be improved with a slight change to the user interface. Minimizing the number of tabs, similar to what was done with Enterprise Security, would be helpful.
Regarding needed improvements, integrations are a great idea as I cannot find easy guides on how to integrate some technology. It would be better if you had one area where I could find comprehensive information about integrations.
For how long have I used the solution?
I have been using Splunk Enterprise Platform for four years.
What do I think about the stability of the solution?
Splunk Enterprise Platform is very stable.
What do I think about the scalability of the solution?
Splunk Enterprise Platform's scalability is great. For me, it is totally infinite. The only limit is your hardware.
How are customer service and support?
Customer support is adequate, but presales support could be better.
Which solution did I use previously and why did I switch?
I did not use any different solution before Splunk Enterprise Platform; I started with it.
What was our ROI?
I have seen a return on investment with Splunk Enterprise Platform, as one of my customers saved a lot of money while shortening the time of MTTR.
What's my experience with pricing, setup cost, and licensing?
I sometimes help our product manager with pricing, but usually to anticipate the needed license, size of logs, or VCPU.
Which other solutions did I evaluate?
Before choosing Splunk Enterprise Platform, many end customers evaluated other options such as QRadar, Palo Alto SIEM, or FortiSIEM, but it depends on needs and usually on their budget.
What other advice do I have?
My advice to others looking into using Splunk Enterprise Platform is to attend open, free workshops to determine if Splunk Enterprise Platform is suitable for you and your data. I would encourage continued improvements to Splunk Show for presales purposes. I would rate this product a ten out of ten.
Which deployment model are you using for this solution?
On-premises
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Disclosure: My company has a business relationship with this vendor other than being a customer. Reseller
Last updated: Sep 16, 2026
Flag as inappropriateBuyer's Guide
Download our free Splunk Enterprise Platform Report and get advice and tips from experienced pros
sharing their opinions.
Updated: September 2026
Popular Comparisons
Tableau Enterprise
Informatica PowerCenter
SAP BusinessObjects Business Intelligence
ThoughtSpot
Splunk ITSI (IT Service Intelligence)
SAS Visual Analytics
Splunk Cloud Platform
Apache Superset
Splunk On-Call
RStudio Connect
Splunk Security Essentials
Buyer's Guide
Download our free Splunk Enterprise Platform Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- What's your experience or opinion about Spotfire vs. Tableau vs. Qlik?
- A journalist is writing a story about which Data Visualization software product to choose. Can you help him?
- What enterprise data analytics platform has the most powerful data visualization capabilities?
- When evaluating Data Visualization, what aspect do you think is the most important to look for?
- What are the best self-service and Excel-like filtering / display tools?
- What data visualization tool/s do you find to be the best?
- Why is Data Visualization important for companies?
- Which Data Visualization tools are good at collaboration and support the tracking of insight actions?
- How many users on average are licensed users of Data Visualization software in a company?
















