No more typing reviews! Try our Samantha, our new voice AI agent.
Security Architect at a tech vendor with 10,001+ employees
MSP
Top 10
Jul 1, 2026
Security monitoring has improved with faster rule creation but search and AI features still need work
Pros and Cons
  • "Splunk Enterprise Platform offers very good integration patterns and extensive support for many log sources with pre-built rule sets and pre-built integrations."
  • "One area where Splunk Enterprise Platform can be improved is that the underlying search architecture is not up to the mark compared to something Elastic."

What is our primary use case?

My main use case for Splunk Enterprise Platform is as a SIEM/SOAR.

I use Splunk Enterprise Platform as a SIEM where we send all the relevant logs including firewall logs, EDR logs, authentication logs, application logs, and database logs towards Splunk, and then we write rules based on that.

Day-to-day, it is mainly used as a SIEM solution to look at all the security events and write the rules.

What is most valuable?

Splunk Enterprise Platform offers very good integration patterns and extensive support for many log sources with pre-built rule sets and pre-built integrations. It also has a wide variety of support sources.

Those integrations and pre-built rule sets help my team in our daily work as they made the integrations much faster and easier. Using the community rules was also much faster.

Splunk Enterprise Platform has very good retention and log ingestion methods. The log querying is also pretty good.

Splunk Enterprise Platform has positively impacted my organization by providing very good insight into the different security logs.

I have seen specific outcomes or improvements with Splunk Enterprise Platform, where the time to respond is pretty good. The time to write a rule is very fast, and the time for integration to the different log sources is very good.

What needs improvement?

One area where Splunk Enterprise Platform can be improved is that the underlying search architecture is not up to the mark compared to something Elastic. This could be improved.

I wish Splunk Enterprise Platform could do more towards AI and use AI to help in SOC automation.

Regarding Splunk Enterprise Platform's AI capabilities, I think its governance and security are pretty good, but not up to the mark.

Regarding Splunk Enterprise Platform's AI capabilities, I feel that its accuracy and reliability of output are still in the nascent stages, although it is pretty good.

For how long have I used the solution?

I have been using Splunk Enterprise Platform for about to three years.

Buyer's Guide
Splunk Enterprise Platform
September 2026
Learn what your peers think about Splunk Enterprise Platform. Get advice and tips from experienced pros sharing their opinions. Updated: September 2026.
914,394 professionals have used our research since 2012.

What do I think about the stability of the solution?

Splunk Enterprise Platform is stable.

What do I think about the scalability of the solution?

Splunk Enterprise Platform's scalability is very good.

How are customer service and support?

The customer support is very good.

I would rate the customer support on a scale of one to ten as an eight. They are able to query and answer most of the questions.

Which solution did I use previously and why did I switch?

We have used many solutions before, including Sentinel and Elastic, which we use in combination.

What was our ROI?

I feel I have seen a return on investment, and my general impression is that it is a great product.

What's my experience with pricing, setup cost, and licensing?

My experience with pricing, setup cost, and licensing is that the setup costs and licensing are pretty high.

Which other solutions did I evaluate?

Before choosing Splunk Enterprise Platform, I evaluated other options including Elastic.

What other advice do I have?

My advice for others looking into using Splunk Enterprise Platform is that it is a great solution, but it is a little expensive. I would rate this review a seven out of ten.

Which deployment model are you using for this solution?

Hybrid Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Last updated: Jul 1, 2026
Flag as inappropriate
PeerSpot user
Software engineer at ProminentPixel
Real User
Top 5
Apr 24, 2026
Log monitoring has transformed operations and now supports real-time threat detection
Pros and Cons
  • "Overall, it is a great tool for security analysis and log monitoring, and it is one of the best tools we have been using."
  • "The number one area for improvement is cost; it is not cost-efficient for small organizations."

What is our primary use case?

I use Splunk Enterprise Platform and Splunk Cloud for our Splunk solutions. I work with Splunk Enterprise Platform for the Enterprise, not with Enterprise Security.

I use Splunk Enterprise Platform for monitoring systems, analyzing logs, and building dashboards that support our operations, visibility, and business insights. I perform log analysis, create dashboards, and set up alerts using SPL. We query large volumes of logs, identify patterns, and troubleshoot issues.

I definitely use Splunk Enterprise Platform's machine learning toolkit. It helps us with predictive analytics in our organization. I have set alerts for daily ingestion using the Machine Learning toolkit in Splunk Enterprise Platform directly. I use SPL commands such as fit, apply, and score for regression and classification analysis, including yes or no category alerts. I mainly use it for anomaly detection in our company.

It is very efficient for us in assessing the effectiveness of Splunk Enterprise Platform in detecting anomalies and preventing system outages. I also set alerts for daily ingestion. Overall, it is a great tool for security analysis and log monitoring, and it is one of the best tools we have been using.

I have a custom add-on for forwarder management. Instead of having different instances, I made a different app for forwarder management. Anything that happens to that forwarder, I can see using that particular app and add-on SPL. That is how it helps us. I have many different custom add-ons for Splunk Enterprise Platform, and I have directly published them in Splunkbase. Even if our new employees need to see and debug what is the problem in our forwarder, that is how Splunk Enterprise Platform custom add-ons work for us.

I definitely leverage Splunk Enterprise Platform for advanced threat detection. It integrates with our existing security tools by aggregating logs from multiple sources such as servers, applications, and network devices. It makes it easier to correlate events and identify suspicious patterns that would not be visible in isolated systems. I use real-time alerts for suspicious activities. I have also set alerts in our organization for users; if multiple failed login attempts occur, then we get an alert. I monitor security events in real-time through dashboards.

What is most valuable?

The number one valuable feature is its powerful search capabilities in Splunk Enterprise Platform. Using SPL, we can fire a query and get so much results from that. The number two is its dashboard; we have built dashboards and alerts for different use cases. We use dashboards for visualization, which is also one of the best features. It is integrated with other tools; we have our custom add-ons there. It integrates with other tools as well. Additionally, it handles large volumes of machine data well, as we ingest daily TBs of data in Splunk Enterprise Platform.

In terms of improving data interpretation, it shows only the most relevant information for a specific user or role. Instead of going through large volumes of raw logs, we can directly see key metrics and alerts that matter to us. In our use case, we have set a system health and error rate, which we can directly see on our personalized dashboard. It makes our data more actionable, improves our efficiency, and allows both our technical and non-technical users to interpret insights without deep querying knowledge.

What needs improvement?

The number one area for improvement is cost; it is not cost-efficient for small organizations. Better cost management should be the first priority. Performance optimization is also important. Large queries or poorly optimized searches can sometimes slow down our results. Better recommendations or automation for query tuning would help us. It would be better if this is added in the near future versions.

For how long have I used the solution?

I have been using Splunk Enterprise Platform for a year.

What do I think about the stability of the solution?

It is super stable, which is why we use it. It is one of the best tools.

What do I think about the scalability of the solution?

It is super scalable for us; I would rate it eight out of ten regarding scalability.

How are customer service and support?

It is superb because whenever we raise a support case, they answer us instantly. Customer service is also good.

How was the initial setup?

It was straightforward for the initial setup.

What about the implementation team?

We have Splunk dedicated employees here who have trained in Splunk Enterprise Platform. It was installed directly by our own employees.

What was our ROI?

We definitely have approximately thirty to forty percent ROI from Splunk Enterprise Platform.

Which other solutions did I evaluate?

We have directly integrated to Splunk Enterprise Platform because we have become Splunk partners.

What other advice do I have?

This is my first time, so I do not know much about this platform. We have our custom application, and we can directly use that to enhance end-user experience. My piece of advice will be if you are looking for a SIEM tool to monitor and have personalized dashboards, then Splunk Enterprise Platform is definitely for you. If your team has the budget and your company has budget, then you should definitely move to Splunk Enterprise Platform. I would rate this product a nine out of ten overall.

Which deployment model are you using for this solution?

Public Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor. The reviewer's company has a business relationship with this vendor other than being a customer: Partner
Last updated: Apr 24, 2026
Flag as inappropriate
PeerSpot user
Buyer's Guide
Splunk Enterprise Platform
September 2026
Learn what your peers think about Splunk Enterprise Platform. Get advice and tips from experienced pros sharing their opinions. Updated: September 2026.
914,394 professionals have used our research since 2012.
reviewer2899293 - PeerSpot reviewer
Administrator at a government with 201-500 employees
Real User
Top 20
Sep 16, 2026
Centralized logging has simplified daily error detection and improved problem solving
Pros and Cons
  • "Splunk Enterprise Platform has positively impacted my organization primarily for finding errors and problem-solving."
  • "I suggest removing the KV store and replacing it with MongoDB to improve Splunk Enterprise Platform."

What is our primary use case?

My main use case for Splunk Enterprise Platform is log management. I use Splunk Enterprise Platform for log management by collecting all security logs, Microsoft logs, and more. I also manage syslogs in addition to my main use case.

What is most valuable?

In my opinion, the best features Splunk Enterprise Platform offers are searchability and the ease of searching through data. The search functionality helps me day-to-day by allowing me to use searches for error finding and other tasks. We value the Tenable integrations, which I would note among the features.

Splunk Enterprise Platform has positively impacted my organization primarily for finding errors and problem-solving. It comes down to how proficient you are at searching, which has made error finding and problem-solving easier for me.

What needs improvement?

I suggest removing the KV store and replacing it with MongoDB to improve Splunk Enterprise Platform. I am uncertain about Splunk Enterprise Platform's governance and security, but we maintain strict policies on how to use AI, requiring limitations in certain ways.

For how long have I used the solution?

I have been using Splunk Enterprise Platform for two and a half years.

What do I think about the stability of the solution?

The stability of Splunk Enterprise Platform depends on which version you run.

What do I think about the scalability of the solution?

Its scalability is somewhat straightforward because you can copy configurations from one environment to another and make minor adjustments in the logs or configuration.

How are customer service and support?

I find the customer support to be acceptable.

Which solution did I use previously and why did I switch?

Before Splunk Enterprise Platform, we only had local logs, which made it necessary to check logs on each machine individually, as we did not have a centralized product.

How was the initial setup?

My experience with pricing, setup cost, and licensing for Splunk Enterprise Platform is positive and acceptable.

What about the implementation team?

We only have a third-party security company with consultants to help us, so our relationship with this vendor extends only to being a customer.

What was our ROI?

The return on investment in our case is primarily based on how it governs the logging of everything, though for us, the main value lies in error handling and identifying bugs.

What's my experience with pricing, setup cost, and licensing?

My experience with pricing, setup cost, and licensing for Splunk Enterprise Platform is positive and acceptable.

Which other solutions did I evaluate?

I evaluated other options before choosing Splunk Enterprise Platform, including Slack.

What other advice do I have?

I would advise others considering Splunk Enterprise Platform to pay attention to the KV store and MongoDB and understand how they function once you use or upgrade the product. I would rate Splunk Enterprise Platform an eight or nine overall.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Last updated: Sep 16, 2026
Flag as inappropriate
PeerSpot user
reviewer2830626 - PeerSpot reviewer
Dev Ops And Observability Admin at a tech services company with 11-50 employees
Real User
Top 5
Apr 27, 2026
Log analytics has improved monitoring and currently powers flexible dashboards and alerts
Pros and Cons
  • "Splunk Enterprise Platform is very efficient for us."
  • "The cost increases significantly as data volume grows. We ingest terabytes of data, so I can say Splunk Enterprise Platform is somewhat costly."

What is our primary use case?

I work in the data and analytics space where I deal with large data sets and system-generated logs. I use Splunk Enterprise Platform for monitoring systems. I analyze logs and create dashboards that help our technical teams.

Splunk Enterprise Platform is very efficient for us. We monitor logs and troubleshoot our issues, then create dashboards for tracking system performance. We bring in logs from different systems like Windows Event logs and AWS logs, so it is highly efficient for us. It is one of the best SIEM tools.

We use the Machine Learning Toolkit.

What is most valuable?

I love its search capabilities. It has a very strong search functionality using SPL. The dashboards are very flexible and easy to customize. One of the best features is how it can handle large-scale machine data efficiently.

What needs improvement?

The cost is definitely an area for improvement. The cost increases significantly as data volume grows. We ingest terabytes of data, so I can say Splunk Enterprise Platform is somewhat costly. Poorly written queries can impact our performance, so there should be suggestions provided to write queries in SPL.

As Splunk partners, as our data volume grows, our cost also increases significantly. From a pricing perspective, Splunk Enterprise Platform is somewhat costly for us.

For how long have I used the solution?

I have been working with this solution for the past one year.

What do I think about the stability of the solution?

We have experienced no stability issues. It is highly stable and scalable for us. We are increasing our team vertically and horizontally dedicated to Splunk Enterprise Platform.

What do I think about the scalability of the solution?

We have experienced no scalability issues. It is highly stable and scalable for us. We are increasing our team vertically and horizontally dedicated to Splunk Enterprise Platform.

How are customer service and support?

During an upgrade we were having some issues, but after some time, they resolved our issue and we were satisfied with that.

I would rate their customer service nine out of ten because our issues were solved quickly after two to three hours.

Which solution did I use previously and why did I switch?

We directly became Splunk partners. When I joined this firm, I directly used Splunk Enterprise Platform.

How was the initial setup?

We had training sessions for the onboarding process. Since I come from an observability and SIEM background, it was quite easy for me to integrate Splunk Enterprise Platform.

What about the implementation team?

We had training sessions for the onboarding process. Since I come from an observability and SIEM background, it was quite easy for me to integrate Splunk Enterprise Platform.

What's my experience with pricing, setup cost, and licensing?

The cost is a concern. The cost increases significantly as data volume grows. We ingest terabytes of data, so I can say Splunk Enterprise Platform is somewhat costly.

What other advice do I have?

We have an add-on of the Universal Forwarder that helps us check whether our forwarder server is down or not. We have our custom add-ons that are definitely helping us and easing our work.

We use alerts about licensing every day. We have set an alert that triggers if our daily license exceeds 500 GB. We came to know that our licensing limit has been reached, so we had to remove unnecessary data. That's how we use that feature.

We have just integrated Splunk Enterprise Platform with Amazon Web Services. It integrates well without any issue.

It helps with suggestions about regression and has pre-built functions and algorithms to build with. I would rate my overall experience with this solution nine out of ten.

Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
Last updated: Apr 27, 2026
Flag as inappropriate
PeerSpot user
Cyber Analyst at a university with 10,001+ employees
Real User
Top 20
Sep 16, 2026
Log aggregation has improved how I quickly find packet capture insights with dashboards
Pros and Cons
  • "The best features Splunk Enterprise Platform offers are the dashboards and the ability to aggregate all the logs that we have."

    What is our primary use case?

    I have been using Splunk Enterprise Platform for about a year. 

    My main use case for Splunk Enterprise Platform is log aggregation. I use Splunk Enterprise Platform for log aggregation in my day-to-day work to ingest all our packet captures.

    What is most valuable?

    The best features Splunk Enterprise Platform offers are the dashboards and the ability to aggregate all the logs that we have.

    What I appreciate about the dashboards is that log aggregation makes things easier and quicker to find the information I am looking for, and the dashboards again make it easier to find what I need.

    For my own use case, I have noticed that I am able to find the information I am looking for relatively quickly.

    What needs improvement?

    I do not have enough experience with Splunk Enterprise Platform to make improvements, as I am still learning.

    I have not found anything that has been challenging for me as a new user, as I am able to figure things out.

    What do I think about the stability of the solution?

    Splunk Enterprise Platform is stable in my experience.

    What do I think about the scalability of the solution?

    From what I have seen, Splunk Enterprise Platform is very scalable.

    Which solution did I use previously and why did I switch?

    I have not previously used a different solution before Splunk Enterprise Platform.

    What was our ROI?

    I have seen a return on investment in terms of efficiency, which is the only thing I can speak to regarding my use case with Splunk Enterprise Platform.

    What's my experience with pricing, setup cost, and licensing?

    I do not have any experience with pricing, setup cost, and licensing, as that is not within my responsibility.

    What other advice do I have?

    The advice I would give to others looking into using Splunk Enterprise Platform is to attend Splunk University and learn how to use it.

    Which deployment model are you using for this solution?

    On-premises
    Disclosure: My company does not have a business relationship with this vendor other than being a customer.
    Last updated: Sep 16, 2026
    Flag as inappropriate
    PeerSpot user
    reviewer2899437 - PeerSpot reviewer
    Architect at a tech vendor with 10,001+ employees
    Real User
    Top 10
    Sep 16, 2026
    Long-term log monitoring has strengthened security governance and streamlined audit reporting
    Pros and Cons
    • "Splunk Enterprise Platform has positively impacted my organization by helping with SOC dashboarding, maintaining the security enterprise platforms, application monitoring, and assisting in audit and governance purposes for the confidential data that has to be sent into Splunk and for governmental related audits and governance."
    • "Regarding Splunk Enterprise Platform's AI capabilities, I think its governance and security need to be figured out; I believe it is not completely matured as of now, so I need to figure out how things pan out."

    What is our primary use case?

    My main use case for Splunk Enterprise Platform focuses on log monitoring, audit governance, and other aspects related to application security, enterprise security, and monitoring.

    A specific example of how I use Splunk Enterprise Platform for application security or enterprise security monitoring includes user and audit monitoring.

    User and audit monitoring is my primary focus, but I also have other application logging where I try to understand the code that is being sent in and all of it.

    What is most valuable?

    Splunk Enterprise Platform offers bringing the data in seamlessly, easy integration with other applications and cloud platforms, and better dashboarding and reporting than other competitors.

    The dashboarding and reporting features stand out to me because most of them are plug and play, and the dashboard generation and other capabilities are easy to implement while also being robust with more features.

    Splunk Enterprise Platform has positively impacted my organization by helping with SOC dashboarding, maintaining the security enterprise platforms, application monitoring, and assisting in audit and governance purposes for the confidential data that has to be sent into Splunk and for governmental related audits and governance.

    I can share that all of the outcomes and metrics mentioned show how Splunk Enterprise Platform has helped my organization, such as saving time, reducing incidents, and improving compliance in measurable ways.

    What needs improvement?

    I think Splunk Enterprise Platform could be improved by reducing the number of components into a single component, similar to what Cisco data fabric is bringing in, while seamless integration is already in place.

    For how long have I used the solution?

    I have been using Splunk Enterprise Platform for over ten years.

    What other advice do I have?

    Regarding Splunk Enterprise Platform's AI capabilities, I think its governance and security need to be figured out; I believe it is not completely matured as of now, so I need to figure out how things pan out.

    Regarding Splunk Enterprise Platform's AI capabilities, I expect some decent outcomes; I have not tried much on my end, so I will definitely venture into that and check it out to see how it works out.

    My advice to others looking into using Splunk Enterprise Platform is to dive in and use proper setup and configurations to make sure they are getting true value out of it and not just using Splunk Enterprise Platform, but utilizing it in a wise and useful manner. I would rate this product a nine out of ten.

    Which deployment model are you using for this solution?

    Private Cloud

    If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

    Disclosure: My company does not have a business relationship with this vendor other than being a customer.
    Last updated: Sep 16, 2026
    Flag as inappropriate
    PeerSpot user
    reviewer2899146 - PeerSpot reviewer
    engineer at a tech services company with 11-50 employees
    MSP
    Top 20
    Sep 16, 2026
    Centralized log monitoring has improved alerting speed and enabled daily operational dashboards
    Pros and Cons
    • "Splunk Enterprise Platform has positively impacted our organization because it has helped us see the ones that we are alerting on, we are able to see and get alerts as quickly as possible, and we are able to act on them based on whatever the alert is saying."
    • "There is a function of the DB Connect app that needs improving—if you are collecting logs and the logs do not have anything that you can use as a rising column to tell the system to continue from where you left off, you have to bring in your logs in a batch, which can lead to duplicates."

    What is our primary use case?

    My main use case for Splunk Enterprise Platform is for collecting application logs and creating dashboards and alerting on them.

    We have database logs that we collect into Splunk, we review them, and based on the use case of the customer, whoever is requesting, we create a dashboard for them, or a report, or sometimes an alert if they want.

    I would say that is the main use. We also use it to create dashboards on operating system logs and all that. We ingest operating system logs and create dashboards for them.

    What is most valuable?

    In my experience, the best features Splunk Enterprise Platform offers are the DB Connect app that gives me the ability to collect database logs. It is the main thing because most of our logs are from the database.

    The DB Connect feature has made my work easier because once you are able to connect to it, it is easier for the log collection from the database and also the ability to query directly from the database while you are in Splunk.

    Splunk Enterprise Platform has positively impacted our organization because it has helped us see the ones that we are alerting on. We are able to see and get alerts as quickly as possible, and we are able to act on them based on whatever the alert is saying. For those that want to see the dashboard, they have something to visualize every day and tell them how their systems are doing, especially on the operating systems. It has helped us a lot.

    Since using Splunk Enterprise Platform, I notice faster response time as a specific outcome.

    What needs improvement?

    I am very satisfied with Splunk Enterprise Platform because it is helping me get what my use cases are. I am able to find everything I need for right now, but there is always room for improvement.

    If I could change or add one thing to make Splunk Enterprise Platform even better for me, it would be the DB Connect app. There is a function of the DB Connect app that needs improving—if you are collecting logs and the logs do not have anything that you can use as a rising column to tell the system to continue from where you left off, you have to bring in your logs in a batch, which can lead to duplicates. I think if there is a way to help with that, it would be very helpful because it will be eating your licenses and that is not what you want.

    For how long have I used the solution?

    I have been using Splunk Enterprise Platform for four years.

    What do I think about the stability of the solution?

    Splunk Enterprise Platform is very stable.

    What do I think about the scalability of the solution?

    Splunk Enterprise Platform is very scalable, and depending on how, it is not so difficult to scale up if there is a need.

    How are customer service and support?

    I do not think I have had any issues with customer support. They respond as and when we need them. Every time we create a support case, they are always there to support us.

    I would rate the customer support a ten.

    Which solution did I use previously and why did I switch?

    I did not previously use a different solution before Splunk Enterprise Platform.

    Which other solutions did I evaluate?

    Before choosing Splunk Enterprise Platform, I did not evaluate other options because Splunk Enterprise Platform was already there before I used it.

    What other advice do I have?

    I would encourage others looking into using Splunk Enterprise Platform to try it because, depending on what they are looking for, if they can find it, it is something that I will encourage because it is stable and there is always support for it if need be.

    As our organization considers new use cases with agentic AI, I believe when we get there, we will have a proper plan, but for right now, we do not have anything going.

    I have rated this review an eight overall.

    Which deployment model are you using for this solution?

    On-premises

    If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

    Other
    Disclosure: My company does not have a business relationship with this vendor other than being a customer.
    Last updated: Sep 16, 2026
    Flag as inappropriate
    PeerSpot user
    Vsadalaga Sadalga - PeerSpot reviewer
    Soc Analyst at a manufacturing company with 10,001+ employees
    Real User
    Top 5Leaderboard
    Aug 9, 2026
    Centralized monitoring has improved incident triage and speeds up daily security investigations
    Pros and Cons
    • "While I cannot share internal metrics, I can say that Splunk Enterprise Platform has led to faster incident triage, better visibility into security events, and reduced time spent on manual investigations due to centralized log analysis and automated correlations."
    • "I would like to see more flexible licensing, easier deployment and administration, enhanced AI-driven automation, and more built-in dashboards and detection content in Splunk Enterprise Platform."

    What is our primary use case?

    Splunk Enterprise Platform serves as our primary solution for centralized log collection, real-time security monitoring, threat detection, incident investigation, and alert management. The cloud deployment simplifies platform maintenance and scaling.

    Beyond threat detection, we use Splunk Enterprise Platform daily for alert triage, incident investigation, threat hunting, dashboard monitoring, and reporting. It provides us with centralized visibility and helps us respond to incidents more efficiently.

    For example, when Splunk generates a high-risk sign-in alert, I correlate authentication and endpoint logs, review the user's activity, source IP, device, and MFA events, and then determine whether it is a true positive or false positive.

    What is most valuable?

    I would highlight centralized log management, fast search, real-time alerting, correlation searches, customizable dashboards, scalability, and strong integration as the best features of Splunk Enterprise Platform.

    Customizable dashboards in Splunk Enterprise Platform give our SOC team a real-time view of key security metrics, including critical alerts, authentication activity, endpoint detections, and incident status. This helps us quickly identify high-priority issues and monitor the overall security posture from a single screen. Correlation searches automatically combine events from multiple data sources to detect attack patterns that individual alerts might miss. For example, a phishing email click followed by a suspicious sign-in and unusual endpoint activity can be correlated into one high-confidence alert, which reduces false positives and speeds up investigation.

    I would also highlight strong integration, scalability, powerful search language, reporting, and the app ecosystem within Splunk Enterprise Platform. These features make it easy to centralize data and adapt the platform to different security and operational needs.

    While I cannot share internal metrics, I can say that Splunk Enterprise Platform has led to faster incident triage, better visibility into security events, and reduced time spent on manual investigations due to centralized log analysis and automated correlations.

    While I do not have official figures, I estimate that investigation and triage time has improved by around twenty percent to thirty percent for many common security incidents due to centralized log visibility and automated correlation with Splunk Enterprise Platform.

    What needs improvement?

    I would like to see more flexible licensing, easier deployment and administration, enhanced AI-driven automation, and more built-in dashboards and detection content in Splunk Enterprise Platform.

    I chose nine out of ten for my rating because of the licensing cost and complexity of deployment and administration.

    For how long have I used the solution?

    I have been working in my current field for two years.

    What do I think about the stability of the solution?

    I would consider Splunk Enterprise Platform to be very stable. It has been reliable for log collection, search, and security monitoring with consistent performance in our daily operations.

    What do I think about the scalability of the solution?

    I do not have direct experience with petabyte-scale deployments using Splunk Enterprise Platform, but it appears to provide strong scalability, flexible data residency options, and governance controls that support data sovereignty requirements in large enterprise environments.

    I would rate Splunk Enterprise Platform's scalability as very high. It scales adequately with growing data volumes and users while maintaining strong performance for search, analytics, and security monitoring.

    How are customer service and support?

    The customer support for Splunk Enterprise Platform is good.

    Which solution did I use previously and why did I switch?

    In my previous project, we used another solution before Splunk Enterprise Platform, but in the project that I am working on currently, we have been using Splunk Enterprise Platform from day one.

    How was the initial setup?

    The pricing for Splunk Enterprise Platform is on the higher side, especially as log volumes grow. Setup requires planning and expertise, but the platform's capability, scalability, and reliability justify the investment for enterprise environments.

    What other advice do I have?

    My advice for others looking into using Splunk Enterprise Platform is to start with clear use cases, onboard the right data, train your team on Splunk Enterprise Platform, optimize the searches and dashboards, and keep an eye on data ingestion to control licensing costs. Proper planning will help you get the most value from the platform. I would rate this product nine out of ten.

    Which deployment model are you using for this solution?

    Private Cloud

    If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

    Disclosure: My company does not have a business relationship with this vendor other than being a customer.
    Last updated: Aug 9, 2026
    Flag as inappropriate
    PeerSpot user
    reviewer2899458 - PeerSpot reviewer
    Splunk engineer at a outsourcing company with 501-1,000 employees
    Real User
    Top 20
    Sep 16, 2026
    Centralized monitoring has boosted daily threat detection and streamlined compliance audits
    Pros and Cons
    • "Splunk Enterprise Platform has positively impacted my organization by allowing us to gain a centralized monitoring platform where I can centralize all of my logs."

      What is our primary use case?

      Splunk Enterprise Platform is my main tool for security use cases.

      I use Splunk Enterprise Platform for monitoring and detecting threats.

      In addition to monitoring, I use it for threat detection and incident response within my security framework.

      What is most valuable?

      Continuous monitoring is the best feature that Splunk Enterprise Platform offers.

      Continuous monitoring helps my team day to day by allowing us to stay compliant with our regulations and ensuring that no threats or serious incidents are taking place.

      Splunk Enterprise Platform has positively impacted my organization by allowing us to gain a centralized monitoring platform where I can centralize all of my logs.

      Since centralizing my logs with Splunk Enterprise Platform, it has improved compliance audits.

      For how long have I used the solution?

      I have been using Splunk Enterprise Platform for one year.

      What do I think about the stability of the solution?

      Splunk Enterprise Platform is stable.

      What do I think about the scalability of the solution?

      Splunk Enterprise Platform's scalability is really good. It is not too hard to add indexers or increase ingestion capacity or search capabilities by adding more search heads, so I would rate it pretty well.

      How are customer service and support?

      Customer support is very good.

      Which solution did I use previously and why did I switch?

      I did not previously use a different solution before Splunk Enterprise Platform.

      What was our ROI?

      I have seen a return on investment with Splunk Enterprise Platform as it has saved us time, since I don't have to go and fetch logs from specific tools, as they all come in through Splunk Enterprise Platform.

      What other advice do I have?

      Regarding Splunk Enterprise Platform's AI capabilities, I think it is important that it has the capability to use local models or in-house built models that conform to the environment that Splunk Enterprise Platform's architecture is in or Splunk Enterprise Platform's stack is in.

      I cannot say much about its accuracy and reliability of output as I have not used it too often.

      Overall, my experience with maintaining Splunk Enterprise Platform in an on-premises environment is pretty good, although there are some things that would be better in the cloud, reducing overhead for engineers or administrators, such as compliance.

      I track daily ingestion rates to see metrics related to my usage.

      My advice to others looking into using Splunk Enterprise Platform is to go through Splunk training courses, as they offer a lot of hands-on, valuable training to get you set up and ready to run your environment.

      I give this product an overall rating of 10.

      Which deployment model are you using for this solution?

      On-premises
      Disclosure: My company does not have a business relationship with this vendor other than being a customer.
      Last updated: Sep 16, 2026
      Flag as inappropriate
      PeerSpot user
      reviewer2899329 - PeerSpot reviewer
      software engineer at a government with 51-200 employees
      Real User
      Top 20
      Sep 17, 2026
      Alerting has kept issues ahead of the curve but upgrades and licensing still need work
      Pros and Cons
      • "Splunk Enterprise Platform has positively impacted my organization, as we are ahead of the curve in terms of when we discover issues."
      • "Splunk Enterprise Platform can be improved by addressing bugs and upgrades, as every time there is an upgrade, there is a bug that needs fixing."

      What is our primary use case?

      Splunk Enterprise Platform is primarily used for SOAR in my daily work to ensure everything is making its way there and everything is making its way out.

      I verify and track that everything is working smoothly with Splunk Enterprise Platform through alerting.

      What is most valuable?

      The best features Splunk Enterprise Platform offers include alerting.

      What I appreciate most about Splunk Enterprise Platform's alerting features is that it notifies me of something bad that is about to happen before it happens.

      Alerting is the main highlight for me regarding features.

      Splunk Enterprise Platform has positively impacted my organization, as we are ahead of the curve in terms of when we discover issues.

      Being ahead of the curve has helped by saving time.

      What needs improvement?

      Splunk Enterprise Platform can be improved by addressing bugs and upgrades, as every time there is an upgrade, there is a bug that needs fixing.

      For how long have I used the solution?

      I have been using Splunk Enterprise Platform for a year and a half.

      What do I think about the stability of the solution?

      Splunk Enterprise Platform is stable.

      What do I think about the scalability of the solution?

      The scalability of Splunk Enterprise Platform is pretty good.

      How are customer service and support?

      The customer support is okay.

      Which solution did I use previously and why did I switch?

      I have not previously used a different solution.

      What's my experience with pricing, setup cost, and licensing?

      My experience with pricing, setup cost, and licensing shows that licensing is a pain.

      Which other solutions did I evaluate?

      I did not evaluate other options before choosing Splunk Enterprise Platform.

      What other advice do I have?

      The advice I would give to others looking into using Splunk Enterprise Platform is to consider the cost. I would rate this product a 7.

      Which deployment model are you using for this solution?

      Private Cloud

      If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

      Other
      Disclosure: My company does not have a business relationship with this vendor other than being a customer.
      Last updated: Sep 17, 2026
      Flag as inappropriate
      PeerSpot user
      Buyer's Guide
      Download our free Splunk Enterprise Platform Report and get advice and tips from experienced pros sharing their opinions.
      Updated: September 2026
      Buyer's Guide
      Download our free Splunk Enterprise Platform Report and get advice and tips from experienced pros sharing their opinions.