No more typing reviews! Try our Samantha, our new voice AI agent.
reviewer2899149 - PeerSpot reviewer
Milizsoldat at a tech services company with 5,001-10,000 employees
Real User
Top 20
Sep 16, 2026
Centralized security operations have gained flexible data onboarding and powerful detections
Pros and Cons
  • "Splunk Enterprise Platform has a positive impact on my company as it forms the backbone of the CDC services offered by my company; therefore, it is essential in order to offer this service."
  • "I see room for improvement with Splunk Enterprise Platform, particularly concerning costs, as many customers are considering switching to other SIEM platforms because the costs for the data are sometimes too high."

What is our primary use case?

My main use case for Splunk Enterprise Platform is using it as a SIEM for the SOC. I use Splunk Enterprise Platform as a central data collection platform, where the detections or use cases are then written, which are used by our analysts in the SOC.

What is most valuable?

In my view, the best features that Splunk Enterprise Platform offers are absolute flexibility in onboarding data, regardless of the source, and the flexibility in how you can work with data, such as transformations of the data, for example.

This flexibility affects my daily work by helping me in my role; no matter what requests come from customers or the like, I can connect the data at the end of the day, because Splunk Enterprise Platform offers these options.

Splunk Enterprise Platform has a positive impact on my company as it forms the backbone of the CDC services offered by my company; therefore, it is essential in order to offer this service.

Offering this service has led to revenue growth because it is one more service in the employer's portfolio that is in high demand.

What needs improvement?

I see room for improvement with Splunk Enterprise Platform, particularly concerning costs, as many customers are considering switching to other SIEM platforms because the costs for the data are sometimes too high.

I would like to see improvements in user-friendliness, as depending on what needs to be done, Splunk Enterprise Platform requires relatively good knowledge of the product.

For innovations and new features, I would like to see a more concrete best-practice architecture or an updated best-practice architecture, similar to the Splunk Validated Architectures, as this would be quite helpful to find my way through the jungle of new things.

For how long have I used the solution?

I have been using Splunk Enterprise Platform for one and a half years.

Buyer's Guide
Splunk Enterprise Platform
September 2026
Learn what your peers think about Splunk Enterprise Platform. Get advice and tips from experienced pros sharing their opinions. Updated: September 2026.
914,394 professionals have used our research since 2012.

What do I think about the stability of the solution?

In my view, Splunk Enterprise Platform is stable, but it requires more experienced administrators.

What do I think about the scalability of the solution?

I rate the scalability of Splunk Enterprise Platform as very good, even though the costs become quite high beyond a certain point.

How are customer service and support?

I rate the customer support of Splunk Enterprise Platform as good, but it also depends on the complexity of the problem; sometimes it takes quite a long time before I really get to a technician who recognizes the problem as such and then comes up with a solution.

Which solution did I use previously and why did I switch?

I did not use another solution before Splunk Enterprise Platform.

How was the initial setup?

My experience with pricing, setup effort, and licensing shows that the price is quite high, specifically becoming quite high if I don't process, change, and filter the data fairly heavily, and the setup effort depends on how unusual the environment is in which or for which Splunk Enterprise Platform is used and which data sources are used.

What about the implementation team?

We, as a managed service provider, manage and set up Splunk Enterprise Platform for customers.

What was our ROI?

I have not been able to identify a return on investment since we, as a managed service provider, manage and set up Splunk Enterprise Platform for customers, at most certain features that reduce the administrative effort on our side.

What's my experience with pricing, setup cost, and licensing?

We, as a managed service provider, manage and set up Splunk Enterprise Platform for customers.

Which other solutions did I evaluate?

Before deciding on Splunk Enterprise Platform, I evaluated other solutions; CrowdStrike NGSIEM is also currently being evaluated or is now being used in parallel because of the cheaper pricing model and certain advantages in administrative effort at the expense of flexibility in data onboarding and data transformation.

What other advice do I have?

My advice to others who are considering using Splunk Enterprise Platform is to focus heavily on best practices from the beginning, using the additional features or add-ons provided by Splunk Enterprise Platform or the Splunk community in general right away and acting as consistently as possible in terms of add-ons, code, detections, or the like, and making as much as possible centrally controllable via either automation tools or similar.

In my environment, I assess Splunk Enterprise Platform's ability to manage data sovereignty at the petabyte scale in the on-premises area as Splunk Enterprise Platform certainly having a leading role, as there is otherwise no SIEM provider that can handle data that well at that data size or volume.

We don't use the federated search function of Splunk Enterprise Platform yet, but in the future, especially in view of rising costs and competition from other SIEM providers, it will become increasingly important and will be worth considering in the future.

I cannot judge the options with Splunk Enterprise Platform's Trusted Control Plane for maintaining granular control over data as I haven't used it yet.

My impression of Splunk Enterprise Platform in terms of governance within a private network environment is actually very good due to the control over the platform and the many settings and configuration options.

I provided a review rating of 8 for Splunk Enterprise Platform.

Which deployment model are you using for this solution?

On-premises

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
Last updated: Sep 16, 2026
Flag as inappropriate
PeerSpot user
reviewer2899446 - PeerSpot reviewer
Senior Cybersecurity Engineer at a tech vendor with 10,001+ employees
Real User
Top 20
Sep 16, 2026
Log analytics has simplified troubleshooting and now supports faster root cause analysis
Pros and Cons
  • "The impact of Splunk Enterprise Platform on my organization is significant as it makes it easier to search logs and troubleshoot issues within a service or a platform."
  • "I think Splunk Enterprise Platform can be improved by introducing federated search to search different data and adding in more cloud capabilities that are available into Splunk Enterprise quickly enough, because we pay for the same features that you provide in cloud."

What is our primary use case?

My main use case for Splunk Enterprise Platform is administering it for our Workday users and onboarding logs into Splunk.

I administer Splunk by checking in alerts, looking at health metrics, and leveraging Splunk TAs to onboard logs into Splunk, performing these tasks on a day-to-day basis.

What is most valuable?

The best features Splunk Enterprise Platform offers include data management, forwarding management, as well as search and dashboards.

I find myself using the search most often, but I do not particularly rely on a specific dashboard or search capability; I do everything.

The impact of Splunk Enterprise Platform on my organization is significant as it makes it easier to search logs and troubleshoot issues within a service or a platform. Finding the issues and getting RCA done quickly is the main benefit of using Splunk Enterprise Platform.

What needs improvement?

I think Splunk Enterprise Platform can be improved by introducing federated search to search different data and adding in more cloud capabilities that are available into Splunk Enterprise quickly enough, because we pay for the same features that you provide in cloud. I would appreciate having all features in cloud available in Enterprise as well.

For how long have I used the solution?

I have been using Splunk Enterprise Platform for about 10 years.

What do I think about the stability of the solution?

My impression of Splunk Enterprise Platform's ability to manage data sovereignty at a petabyte scale in my environment is that it does a good job handling large-scale data while keeping everything compliant and secure.

What do I think about the scalability of the solution?

My experiences in maintaining granular control over data using the trusted control plane within Splunk Enterprise Platform show that I find it interesting; however, I have not used it, but we manage it through roles and capabilities.

Which solution did I use previously and why did I switch?

I did not purchase Splunk Enterprise Platform through the AWS marketplace.

What's my experience with pricing, setup cost, and licensing?

I do not have any experiences with pricing, setup cost, and licensing because that is managed by another layer of management from my side.

What other advice do I have?

My advice to others looking into using Splunk Enterprise Platform is to look at your requirements, look at your data, and teach the valuable information to Splunk that your end users can leverage and act upon. Actionable data is the most important piece of information to use Splunk Enterprise Platform at its full capability. I would rate this product an 8.

Which deployment model are you using for this solution?

Hybrid Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Last updated: Sep 16, 2026
Flag as inappropriate
PeerSpot user
Buyer's Guide
Splunk Enterprise Platform
September 2026
Learn what your peers think about Splunk Enterprise Platform. Get advice and tips from experienced pros sharing their opinions. Updated: September 2026.
914,394 professionals have used our research since 2012.
reviewer2899044 - PeerSpot reviewer
Senior Security Analyst at a government with 5,001-10,000 employees
Real User
Top 20
Sep 15, 2026
Centralized security logging has simplified compliance reporting but still needs better agent control
Pros and Cons
  • "Splunk Enterprise Platform impacts my organization positively by making it easier for us to meet security compliance requirements."
  • "I have not seen a return on investment; our license costs have only gone up every year, and there has not been any return on investment."

What is our primary use case?

My main use case for Splunk Enterprise Platform is security logging. For security logging, we bring in Windows event logs and other logs from data sources and ingest them into Splunk Enterprise Platform.

How has it helped my organization?

Splunk Enterprise Platform impacts my organization positively by making it easier for us to meet security compliance requirements. We can use Splunk Enterprise Platform to set up alerts or reports that match the security controls and use that as artifacts to meet those compliance requirements.

What is most valuable?

The best features Splunk Enterprise Platform offers are the ability to search the data and having it all in one space.

Having all my data in one place and being able to search it helps me day-to-day by making my investigations easier and faster.

I do enjoy the dashboard feature and the alert feature, but I hate the new UI that was released with Splunk 10. The dashboards and alert features help me in my work by making it easier for me to set up reports and alerts for very specific things, and then I can make the important things pop out or create graphs and charts. However, I find the new UI terrible. I wish they would let us use the classic Splunk UI instead of the new Cisco UI.

What needs improvement?

It would be a lot more beneficial to have greater visibility into things that run, such as Splunk Universal Forwarder, because it is very hard to manage, and there are a lot of features that are missing that are available in some of the competitors.

Being able to parse the data at the source rather than having to send it into Splunk Enterprise Platform would be nice, and being able to deep dive into different agents without having to wait for the logs to come in would be a great improvement.

For how long have I used the solution?

I have been using Splunk Enterprise Platform for almost five years.

What do I think about the stability of the solution?

For the most part, Splunk Enterprise Platform is stable.

What do I think about the scalability of the solution?

Splunk Enterprise Platform's scalability is fine.

How are customer service and support?

I have never had a problem with customer support.

Which solution did I use previously and why did I switch?

I did not previously use a different solution before Splunk Enterprise Platform.

What was our ROI?

I have not seen a return on investment; our license costs have only gone up every year, and there has not been any return on investment.

What's my experience with pricing, setup cost, and licensing?

My experience with pricing, setup cost, and licensing is that it is expensive.

Which other solutions did I evaluate?

I did not evaluate any other options before choosing Splunk Enterprise Platform; I came in and we had Splunk Enterprise Platform, so that is what we went with.

What other advice do I have?

My advice to others looking into using Splunk Enterprise Platform is to not use it. I do have additional thoughts about Splunk Enterprise Platform. My overall review rating for Splunk Enterprise Platform is six out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Last updated: Sep 15, 2026
Flag as inappropriate
PeerSpot user
security engineer at a tech vendor with 501-1,000 employees
Real User
Top 20
Apr 14, 2026
Security monitoring has become proactive and real-time investigation detects threats faster
Pros and Cons
  • "Before using Splunk Enterprise Platform, I used LogRhythm, but after initiating Splunk Enterprise Platform, I noticed several positive impacts in my organization."
  • "For Splunk Enterprise Platform improvement, I think it would be beneficial to focus on particular areas such as system performance, cost management, and detection accuracy."

What is our primary use case?

I am not currently using Splunk Enterprise Platform, but in my previous company, PwC, I used Splunk for almost six months, and before that company, I had a total exposure of almost three years to Splunk Enterprise Platform. My main use case for Splunk Enterprise Platform was detection and investigation.

Ingesting massive amounts of machine-generated data and running real-time searches to identify patterns, anomalies, or threats related to specific security issues was how I used Splunk Enterprise Platform for detection and investigation. The most significant aspect, if I must prioritize, is the data ingestion capability. Splunk Enterprise Platform usually collects authentication logs from various sources such as Windows event logs and SSH, which relates to Linux logs, and some web application-based logs as well. Apart from that, I use it for detection logic. The main search I use is Search Processing Language, based upon the queries I provide related to the machines I monitor.

Mostly for brute-force detection, I use it for monitoring multiple failed login attempts from a single source or multiple IP sources followed by a successful login, which often indicates a compromised account. I also use it for lateral movement and privilege escalations. For privilege escalations, it involves detecting when a normal user is added to a high-privilege group, such as Domain Admins. Additionally, I have capabilities related to IT operations, which involve web traffic analysis, mostly identifying slow-loading web pages or sudden spikes, errors such as 404 or 403 Forbidden, or even 500 errors.

What is most valuable?

The best features in Splunk Enterprise Platform are the Search Processing Language, which includes pipe syntax, and real-time alerting and dashboards. The dashboard is an interactive tool, and I use it for visualizations such as heat maps, graphs, and glass tables. The dashboards I use depend upon the widgets that are most helpful to track and monitor. I can also set some thresholds to trigger real-time values based upon the log information available in Splunk Enterprise Platform, which can be useful for the remediation of scripts.

When a specific condition is met, such as any brute-force attack happening, it is easy to investigate the alert, particularly in Splunk Enterprise Platform. Integration is a notable aspect of the features in Splunk Enterprise Platform.

Before using Splunk Enterprise Platform, I used LogRhythm, but after initiating Splunk Enterprise Platform, I noticed several positive impacts in my organization.

What needs improvement?

For Splunk Enterprise Platform improvement, I think it would be beneficial to focus on particular areas such as system performance, cost management, and detection accuracy. Based upon system performance, I generally look into errors, status errors, or forbidden errors. I could also build some pre-indexed summaries so that Splunk Enterprise Platform can search much faster than raw logs.

For how long have I used the solution?

In my current field, I have worked for around six years, and at my current company, I have been working for the last three years.

What do I think about the stability of the solution?

There is no proper downtime for Splunk Enterprise Platform; whatever downtime occurs, the IT team handles it. There is no significant downtime to report.

What do I think about the scalability of the solution?

It is easy to differentiate the type of logs based on Splunk Enterprise Platform. If it is a phishing email, I can easily identify what kind of phishing alert it is. If it is a brute-force attack or something such as password spraying, it is easy to identify in Splunk Enterprise Platform.

How are customer service and support?

I usually reach out to customer support for Splunk Enterprise Platform whenever I need specific data. I contact the technical support team immediately, and on a priority basis, I receive a resolution. If not, I raise a ticket so that I can get a proper solution for the issues I am facing.

How was the initial setup?

My experience with pricing, setup cost, and licensing has been notable.

What was our ROI?

I have seen a return on investment from using Splunk Enterprise Platform, illustrated by tracking how the daily data volume has been indexed, the estimated cost, the monthly actual report, and the annual report. Biquarterly and mid-year reports can be easily tracked in Splunk Enterprise Platform.

Which other solutions did I evaluate?

I do have other options such as DataDog for one, and Microsoft Sentinel, Azure Sentinel. In my current company, I am using DataDog currently as a SIEM tool.

What other advice do I have?

Splunk Enterprise Platform is deployed on-premises in my organization. I rate this product an overall 8 out of 10.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Last updated: Apr 14, 2026
Flag as inappropriate
PeerSpot user
reviewer2899623 - PeerSpot reviewer
cloud security engineer at a tech vendor with 11-50 employees
Real User
Top 20
Sep 17, 2026
Log investigations have become faster and data now clearly supports executive decisions
Pros and Cons
  • "Having Splunk Enterprise Platform has made our lives easier because outside of being engineers, we are all still the analysts as well."

    What is our primary use case?

    I use Splunk Enterprise Platform for log aggregation, data validation, sifting through network connections, building out dashboards, using the dashboards and putting them in Excel to then present to executive people who may not understand the granular details of network connectivity or log ingestion.

    In one example, I was investigating some traffic where we were getting hit on one of our servers and we were trying to see where it was coming from and if our managed rule set was working properly as we configured it. Navigating to Splunk Enterprise Platform, I was able to query for all the traffic coming from the nefarious IPs and also grab the locations of where they were going, where they were coming from, and if they were blocked or not. From that, I exported that data into an Excel sheet and used that to build bar charts or pie charts to present to executive leadership on what was going on.

    I think it is a great additive to being in the cloud. As I mentioned, we are an AWS shop. Having Splunk Enterprise Platform has made our lives easier because outside of being engineers, we are all still the analysts as well. We still do all of the investigative work and log analysis. Splunk Enterprise Platform makes it very easy for us to parse and grab data that we would need in a given investigation. I am really happy with the product.

    What is most valuable?

    The best features for me include recently starting to mess with creating bar charts and pie charts within Splunk Enterprise Platform console versus exporting the data and then doing it in Excel. That has been very beneficial to me, having a one-stop shop for things of that nature.

    It has given us, from an engineering perspective, the ability and the scalability to move at haste when it is time to investigate different alerts that we need to triage. Things that may be false positive or true positive, we are able to delineate really fast, and also gather important data for those C-suite folks who may need the type of data to support KPIs and things of that nature.

    What needs improvement?

    Perhaps the interface could be improved. The console has been the same since I first started using it. The dashboard could be changed around and features could be upgraded, but as far as the functionality and the usability of Splunk Enterprise Platform in general, I do not have any negative things to say about it.

    For how long have I used the solution?

    I have been using it for about six years at this point.

    What other advice do I have?

    I think there are always challenges to some things that you learn to build out. It was not anything technical, it was just learning how to manipulate the dashboards and manipulate the data to perform or show how you wanted it to show. Once you figure that out, you can make it as expansive as you would want to.

    I would say around AI, everyone needs to improve their governance and security. As great as AI is, it is also scary. While I as the engineer do enjoy having an agentic friend helping me out and making things more efficient, guardrails are still needed to be implemented as we move further into this agentic space.

    I think they are pretty accurate. I have not had any issues at this point, but as we go and continue to do our research and due diligence, I am sure things will get better.

    Continue doing the homework, continue researching, continue using the tool to the best of its capabilities, and building out your data sets as you see fit. I would rate this product a nine out of ten.

    Which deployment model are you using for this solution?

    Private Cloud

    If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

    Disclosure: My company does not have a business relationship with this vendor other than being a customer.
    Last updated: Sep 17, 2026
    Flag as inappropriate
    PeerSpot user
    reviewer2899047 - PeerSpot reviewer
    developer at a government with 10,001+ employees
    Real User
    Top 20
    Sep 16, 2026
    Visualizing security data has transformed how my team develops dashboards and insights
    Pros and Cons
    • "Splunk Enterprise Platform has positively impacted my organization by giving us full observability and visibility into our log data, allowing us to take action on important events, monitor the health of the environment, and determine vulnerabilities and other IT security-related issues."

      What is our primary use case?

      My main use case for Splunk Enterprise Platform is content development. I typically build dashboards and visualizations for Cisco, Qualys, Tenable, Microsoft, Windows, Linux, and other types of security analysis tools.

      What is most valuable?

      Splunk Enterprise Platform's best features are searching, reporting, alerting, dashboards, visualizations, and ingestion.

      I rely on dashboards and visualizations the most because they allow me to visualize data, create analytics, and generate reportable information for users and stakeholders.

      Splunk Enterprise Platform has positively impacted my organization by giving us full observability and visibility into our log data, allowing us to take action on important events, monitor the health of the environment, and determine vulnerabilities and other IT security-related issues. Splunk Enterprise Platform provides overall visibility of our environment, gives customers the ability to visualize their own data, and helps them identify areas where they need assistance. In my case, it is used to increase our ticket volume rather than decrease it because my team helps solve problems for other departments.

      What needs improvement?

      Dashboard could have feature parity with common XML dashboards.

      For how long have I used the solution?

      I have been using Splunk Enterprise Platform for seven years.

      What do I think about the stability of the solution?

      Splunk Enterprise Platform is stable in my experience.

      What do I think about the scalability of the solution?

      Splunk Enterprise Platform is very scalable.

      How are customer service and support?

      Splunk Enterprise Platform's customer support is excellent.

      Which solution did I use previously and why did I switch?

      I did not previously use a different solution before Splunk Enterprise Platform.

      How was the initial setup?

      We do not use federated search and do not use the trusted control plane within Splunk Enterprise Platform for maintaining granular control over data.

      What about the implementation team?

      I do not know the specific metrics my organization has tracked to evaluate the success of reducing total cost of ownership with Splunk Enterprise Platform's non-indexing analytics approach, as that is a management issue and I am not in management.

      What was our ROI?

      I have not seen a return on investment with Splunk Enterprise Platform because that is outside my scope.

      What's my experience with pricing, setup cost, and licensing?

      I do not have information about pricing, setup cost, or licensing because I am part of the operations team, not the engineering team.

      What other advice do I have?

      My advice to others looking into using Splunk Enterprise Platform is to do it.

      Which deployment model are you using for this solution?

      On-premises

      If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

      Other
      Disclosure: My company does not have a business relationship with this vendor other than being a customer.
      Last updated: Sep 16, 2026
      Flag as inappropriate
      PeerSpot user
      Bhavesh Kadachha - PeerSpot reviewer
      Dev Ops Engineer at ProminentPixel
      Real User
      Top 5
      May 18, 2026
      Centralized monitoring has improved troubleshooting and alerting across diverse log sources
      Pros and Cons
      • "We use Federated Search, which allows us to search data across multiple Splunk Enterprise Platform deployments without moving all the data in a single instance, so it helps us very much to access and analyze distributed data sources from one central search interface."
      • "One thing I dislike is definitely the licensing cost, especially when our ingestion volume increases, so it is a bit costly."

      What is our primary use case?

      Splunk Enterprise Platform is used mainly for monitoring and troubleshooting activities, and we work with SPL to query and filter logs. We identify patterns, and then we investigate issues around different systems.

      Splunk Enterprise Platform is used mainly for creating dashboards, monitoring alerts, and understanding system behavior. We have a few use cases about the alerting mechanism. We ingest logs from multiple sources and multiple hosts like AWS, Kafka, and different systems, and we use Splunk Enterprise Platform as a SIEM tool. That is our main use case.

      What is most valuable?

      We use Federated Search, which allows us to search data across multiple Splunk Enterprise Platform deployments without moving all the data in a single instance, so it helps us very much to access and analyze distributed data sources from one central search interface.

      Splunk Enterprise Platform is highly scalable for us as we are increasing our team horizontally as well as vertically, so it is scalable for us right now.

      What needs improvement?

      One thing I dislike is definitely the licensing cost, especially when our ingestion volume increases, so it is a bit costly. The second thing is that SPL query performance can slow down if searches are not optimized properly, so if searches are not optimized, then query performance is slower.

      For how long have I used the solution?

      I have been using Splunk Enterprise Platform for approximately 14 to 15 months.

      What do I think about the stability of the solution?

      During one upgrade of our server, there was one crash, but it was solved by the Splunk Enterprise Platform team itself. During upgrades, we have found it one or two times; otherwise it is quite stable for us.

      What do I think about the scalability of the solution?

      Splunk Enterprise Platform is super easy and does not take any maintenance so far; it is quite easy to use.

      How are customer service and support?

      We have contacted their technical support mainly during an upgrade when we raised a ticket about our system crashing during the upgrade. Our KV store was not coming up, so we contacted them and they briefly told us what the issue was, and after that, we solved that problem.

      I would definitely give them an 8 out of 10 because they were always helpful for us whenever we needed them.

      Which solution did I use previously and why did I switch?

      We have been directly using Splunk Enterprise Platform.

      How was the initial setup?

      It was quite easy because we have a dedicated Splunk Enterprise Platform team with us, so it was easy for us. It took less than a week; approximately one week it took us.

      What about the implementation team?

      One person did the implementation for our entire team.

      What other advice do I have?

      I would give this solution an overall rating of 9 out of 10.

      Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
      Last updated: May 18, 2026
      Flag as inappropriate
      PeerSpot user
      Mohamed Fouad - PeerSpot reviewer
      Cybersecurity Team Leader at EMAK For Computer Manufacturing (ECM)
      Real User
      Top 5Leaderboard
      Mar 18, 2026
      Comprehensive correlation and automation have improved incident detection and reduced phishing
      Pros and Cons
      • "The best features I value about Splunk Enterprise Platform include a great correlation rule that allows me to edit and generate alerts based on any event in an easy and fast way."
      • "We have Splunk at a very high cost, but I can say that other vendors working with mid-size customers can compete against Splunk."

      What is our primary use case?

      Splunk Enterprise Platform serves as our SIEM solution from Splunk, which is a market leader. It is a SIEM solution for log management and correlations. We have multiple logs from most of our infrastructure tools and security products. We obtain these rules and logs through many protocols including syslog and API. We then normalize and correlate this data and create incidents based on the activity running on our infrastructure.

      What is most valuable?

      I appreciate the API, the protocols, and the workflows as it functions as a SIEM solution. The main function is correlation.

      The best features I value about Splunk Enterprise Platform include a great correlation rule that allows me to edit and generate alerts based on any event in an easy and fast way. I can accomplish this in a short period of time, and afterward, I can see incidents based on the correlation rule in a very professional and effective way.

      I value the incident management and the correlations.

      Splunk Enterprise Platform helps in detecting anomalies and preventing outages. The main core function for any SIEM is to have correlation. For example, if you receive user activity on a VPN logging in from Egypt, then after a while you receive logs from the firewall showing the same user logging in with a VPN from Ukraine, it is not logical that the user would move from Egypt to Ukraine in just five minutes. Splunk Enterprise Platform will create an incident and detect this as a credential compromise because we have a successful login from another location. This is the magic of correlation. We receive many events, we correlate these events, and then we can create an incident. After that, we have Splunk SOAR to take actions in an automation process to stop this incident without any management or any actions from the team.

      The end-user experience is enhanced by the security product, as we have a return on investment on lower security incidents. After we implemented it with the SOC and Splunk SOAR, we can stop phishing and spam. The end-user experience will not see many phishing domains; they will be reduced. Security incidents will be reduced. Network performance will be very good after we implement it because we can detect who is scanning our network and creating a bottleneck on the network. We can stop and detect this with Splunk, whether it is SIEM from Splunk or SIEM with SOAR.

      What needs improvement?

      I use the machine learning toolkit with Splunk Enterprise Platform. The machine learning is very good on Splunk, but it sometimes makes searching for events become slow, so we have stopped using it. I think this needs improvement on Splunk.

      The machine learning has room for improvement.

      I think threat management needs improvement when compared to other vendors.

      I compare Splunk Enterprise Platform with other solutions and vendors and see a very good point on pricing. We have Splunk at a very high cost, but I can say that other vendors working with mid-size customers can compete against Splunk. However, compared to Splunk, it is very expensive compared to other vendors. I think after the acquisition from Cisco, we can get discounts for licensing, and I believe Cisco will reconsider the pricing for Splunk Enterprise Platform.

      I would prefer to see improved pricing for Splunk Enterprise Platform.

      My thoughts on the pricing are that it is not cheap.

      I have thoughts on the advanced threat detection, and I see that it is integrating with threat intelligence, and I believe this needs improvement.

      For how long have I used the solution?

      I have been using this solution for about two years. We have deployed many services from Splunk here in Egypt. Most of it is a SIEM solution from Splunk. We also have SOAR from Splunk, and we are running it on the largest bank here in Egypt. Most of the portfolio from Splunk that I have worked with was over approximately two years.

      What do I think about the scalability of the solution?

      Regarding scalability, Splunk Enterprise Platform, like any SIEM solution, provides scalability. Whenever we receive more logs, we can easily scale. I rate this aspect as a ten.

      How are customer service and support?

      I rate the technical support as very good.

      How would you rate customer service and support?

      Positive

      How was the initial setup?

      The deployment was not easy, nor was it complex. It requires a professional and certified engineer to deploy the product, as many SIEM solutions do. One cannot easily deploy a SIEM solution. You have to work on correlations and personalize the dashboard. There is a lot of configuration for any SIEM solution, not only Splunk Enterprise Platform.

      What other advice do I have?

      I would advise others looking to implement this product to totally recommend it. I recommend this both before and after the acquisition. I totally recommend acquiring Splunk Enterprise Platform portfolio, whether it is Splunk SOAR, Splunk Cloud, or Splunk Enterprise Platform. I rate this solution a ten overall.

      Which deployment model are you using for this solution?

      On-premises

      If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

      Other
      Disclosure: My company does not have a business relationship with this vendor other than being a customer.
      Last updated: Mar 18, 2026
      Flag as inappropriate
      PeerSpot user
      reviewer2900259 - PeerSpot reviewer
      IT Monitoring Analyst at a insurance company with 5,001-10,000 employees
      Real User
      Top 20
      Sep 20, 2026
      Admin role has gained deeper observability and now supports teams with efficient dashboards
      Pros and Cons
      • "Splunk Enterprise Platform offers great observability into all my apps, as well as being able to use the GUI to edit different things and be able to provide the best experience for our internal teams so that way we can provide the best experience for our customers."

        What is our primary use case?

        I am an admin for Splunk Enterprise Platform, so I mostly help other teams use it and enable it. I enable other teams to use dashboards or onboarding different apps and such.

        More recently, we had an onboarding or ingestion of some extra data and as a POC for the HashiCorp app. It was a little challenging because we had to work around some of the different file types and they wanted them coming from specific locations to specific servers. That was a fun thing to do.

        What is most valuable?

        Splunk Enterprise Platform offers great observability into all my apps, as well as being able to use the GUI to edit different things and be able to provide the best experience for our internal teams so that way we can provide the best experience for our customers.

        The overall visibility of Splunk Enterprise Platform is great, but I do really appreciate being able to do specific searches for different teams if they're missing data or if they need extra data in, as well as looking at dashboards and enabling those teams to have the most efficient and productive time.

        I think it handles large data very well. It seems to regulate and maintain itself very well. It corrects itself back on course to resolve those errors.

        What needs improvement?

        I am pretty new to the product, so I haven't really found anything specific. I would really appreciate being able to see who edited certain dashboards or alerts. I think that would be really helpful in the future.

        For how long have I used the solution?

        I have been using Splunk Enterprise Platform for about eight months.

        What do I think about the stability of the solution?

        It has been reliable.

        What do I think about the scalability of the solution?

        It seems to scale very well, and we have never had issues with licensing or pushing up that license usage.

        How are customer service and support?

        I have interacted with Splunk support and we have weekly or biweekly meetings with them. It has been great to be able to talk through some of the issues that we have, along with getting some links or putting in a support ticket.

        What other advice do I have?

        I would say look into how you would use Splunk Enterprise Platform and maybe compare other options as well. Also, I have always had a really good experience with Splunk and onboarding has been pretty easy, as well as it being super scalable, allowing you to have great observability. It is really good at self-regulating. Any issues or errors, for example a slowed queue or suddenly ingesting a lot of data, it is really good at regulating itself. I think that is great. I would rate this product a 9 out of 10.

        Which deployment model are you using for this solution?

        On-premises
        Disclosure: My company does not have a business relationship with this vendor other than being a customer.
        Last updated: Sep 20, 2026
        Flag as inappropriate
        PeerSpot user
        reviewer2899350 - PeerSpot reviewer
        Splunk product manager at a tech vendor with 10,001+ employees
        Real User
        Top 20
        Sep 16, 2026
        Data insights have boosted profit-focused demos and are building strong customer confidence
        Pros and Cons
        • "Splunk Enterprise Platform offers the best features in that it is easy and very fast, allowing end users to see the value and true benefit of implementing Splunk Enterprise Platform software."
        • "I have not seen a return on investment because I cannot share relevant metrics such as fewer employees needed, money saved, or time saved."

        What is our primary use case?

        My main use case for Splunk Enterprise Platform is to demonstrate the opportunity to increase profit for companies. This is a demo for our partners who are selling this software to end users, so I am part of the transaction presentation.

        What is most valuable?

        Splunk Enterprise Platform offers the best features in that it is easy and very fast, allowing end users to see the value and true benefit of implementing Splunk Enterprise Platform software. End users can see within minutes how they can earn money or how they can lose money when something is not working properly.

        Splunk Enterprise Platform has positively impacted my organization because everybody believes that this is a really good and fully worthwhile software. Everyone believes in the strength of Splunk Enterprise Platform.

        I notice specific outcomes or changes, mainly in terms of sales and customer satisfaction. The key to success is close cooperation with our local Splunk team. This means we are elastic. When a customer needs a special price, we try to achieve a special price.

        What needs improvement?

        It is not a question for me how Splunk Enterprise Platform can be improved, as I am a salesman. From my point of view, it is perfect. I do not want to change the prices because this is a truly valuable product.

        For how long have I used the solution?

        I have been using Splunk Enterprise Platform for five years.

        What do I think about the stability of the solution?

        I find Splunk Enterprise Platform truly stable.

        What do I think about the scalability of the solution?

        Splunk Enterprise Platform's scalability is that it can grow as a partner grows. It is elastic and adequate.

        How are customer service and support?

        Customer support is at an excellent level.

        Which solution did I use previously and why did I switch?

        I did not previously use a different solution before Splunk Enterprise Platform.

        How was the initial setup?

        The specific metrics my organization has tracked to evaluate the success of reducing total cost of ownership with Splunk Enterprise Platform's non-indexing analytics approach mostly show time saved.

        What about the implementation team?

        Regarding whether I was offered a gift card or incentive for this review, the gift card is acceptable.

        What was our ROI?

        I have not seen a return on investment because I cannot share relevant metrics such as fewer employees needed, money saved, or time saved.

        What's my experience with pricing, setup cost, and licensing?

        My experience with pricing, setup cost, and licensing indicates that Splunk Enterprise Platform is a luxury product. From my point of view, the price is truly acceptable. In some huge installations, we calculate offers by SV rather than by ingesting gigabytes. There are many different ways to achieve a perfect price for the end user.

        Which other solutions did I evaluate?

        Before choosing Splunk Enterprise Platform, I did not evaluate other options because I heard that Splunk Enterprise Platform is the best option and I believe this recommendation from my friends.

        What other advice do I have?

        My main use case for Splunk Enterprise Platform is to demonstrate the opportunity to increase profit for companies. This is a demo for our partners who are selling this software to end users, so I am part of the transaction presentation.

        I love this software.

        The advice I would give to others looking into using Splunk Enterprise Platform is that you can use this software for several different scenarios through different models by working on the same data. I have given this review a rating of ten.

        Which deployment model are you using for this solution?

        On-premises
        Disclosure: My company has a business relationship with this vendor other than being a customer. Distributor
        Last updated: Sep 16, 2026
        Flag as inappropriate
        PeerSpot user
        Buyer's Guide
        Download our free Splunk Enterprise Platform Report and get advice and tips from experienced pros sharing their opinions.
        Updated: September 2026
        Buyer's Guide
        Download our free Splunk Enterprise Platform Report and get advice and tips from experienced pros sharing their opinions.