My use cases for Splunk Enterprise Security involve both security as well as data analytics.
Associate I at Positka
Advanced analytics has improved resilience and real-time threat mapping across diverse data
Pros and Cons
- "Splunk Enterprise Security has helped greatly improve the organization's business resilience."
- "I think the pricing aspect of Splunk Enterprise Security is quite high compared to other products, which I hear from most of my customers."
What is our primary use case?
How has it helped my organization?
Splunk Enterprise Security has helped greatly improve the organization's business resilience.
What is most valuable?
The features of Splunk Enterprise Security that I appreciate the most include the recent AI feature and the MITRE mapping feature.
AI helps in analyzing a certain detection within Splunk Enterprise Security and assists with some tasks that I might require internet or other tabs to work on, while MITRE ATT&CK helps me to map the attacks and provides coverage for my attacks.
What needs improvement?
I would appreciate improvements in the licensing aspect, especially with the SVC-based license, as there is no proper view on top of it regarding how much CPU and usage is being done on the SVC-based license, along with updates to the SOAR version.
The experience with alerts, specifically risk-based alerts, is good, but it might need some improvement as there might be some deviation or false positives, so I think implementing AI over there might increase the feasibility or view around it.
I think the pricing aspect of Splunk Enterprise Security is quite high compared to other products, which I hear from most of my customers.
Buyer's Guide
Splunk Enterprise Security
September 2026
Learn what your peers think about Splunk Enterprise Security. Get advice and tips from experienced pros sharing their opinions. Updated: September 2026.
915,325 professionals have used our research since 2012.
For how long have I used the solution?
I have been working with Splunk Enterprise Security for approximately 3.5 years.
What do I think about the stability of the solution?
I would assess the stability and reliability of Splunk Enterprise Security as very good, with not much downtime or crashes, as it depends on the hardware used and the kind of setup done, which is primarily based on misconfiguration or not predicting something.
I have not faced any significant challenges when using Splunk Enterprise Security; there is not much that I cannot solve.
What do I think about the scalability of the solution?
Splunk Enterprise Security scales very well with the growing needs of my organization and my clients' organizations.
Expanding usage with Splunk Enterprise Security consumes time and effort, but the end result is actually good.
How are customer service and support?
I would evaluate customer service and technical support as good but not very good.
On a scale of one to ten, I would rate them somewhere around seven to eight.
How was the initial setup?
I would describe my experience with deploying Splunk Enterprise Security as good, pretty easy, straightforward, and with plenty of documentation.
I have not faced any challenges during the deployment aspect; even if I did, I figured it out using Splunk Community and Splunk documentation.
What was our ROI?
It does bring measurable benefits in terms of return on investment for clients; specifically, for banking or finance customers who wish to contain their data within their environments, they would definitely go for Splunk Enterprise Security compared to CrowdStrike, but less mature organizations might prefer other products.
Which other solutions did I evaluate?
The key differences, both pros and cons of Splunk Enterprise Security in comparison to CrowdStrike, are that I am a Splunk enthusiast and I love Splunk Enterprise Security, but CrowdStrike is good in search and detections due to its status as a threat intel partner, which offers good detections, while customization done in Splunk Enterprise Security might take too much time on CrowdStrike and there are fewer integration options with CrowdStrike.
I don't have much idea on disadvantages of Splunk Enterprise Security apart from the pricing.
What other advice do I have?
I am currently working with Splunk products.
I work with Splunk Enterprise and Splunk Enterprise Security.
The process for customizing, developing, testing, deploying, and refining detections in Splunk Enterprise Security is pretty easy for me as an expert, but I'm not sure for a new user; being a Splunk architect, I feel it's a little easy and the customization is very helpful.
We have it integrated with various disparate solutions including RSA, CrowdStrike, AWS, Google, Microsoft, Docker, firewalls, switches, and multiple other technologies.
This integration supports my security operations by fetching logs about user activity and audit logs and actions taken by the user; for normal products, this allows me to analyze, detect, and correlate two or three different datasets to build up a use case from which I can deduce some information, and with the queries I have using SPL queries, I can get some data analytics or alerts or reports based on which I can take action.
I use risk-based alerting in Splunk Enterprise Security.
My experience with risk-based alerting, while not mainly focused on the SOC part of Splunk Enterprise Security, provides support to my engineering efforts.
I am not currently using any new threat detection features in Splunk Enterprise Security; I have no idea about that part of it.
My impressions of Splunk Enterprise Security's capability to predict, identify, and solve problems in real-time depend on what kind of data is being received and the use cases being written; it is not straightforward, but because Splunk Enterprise Security is an analytics platform without AI on top of it, it feels that some data sources are less predictable, yet for jobs that are repetitive or similar, Splunk Enterprise Security works well.
I would rate this product a 9 out of 10.
Which deployment model are you using for this solution?
Hybrid Cloud
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
Last updated: Feb 17, 2026
Flag as inappropriateSoc Manager at a real estate/law firm with 1,001-5,000 employees
Investigation efforts have improved while search complexity still requires attention
Pros and Cons
- "The investigation feature helps the team seamlessly put everything together, providing a consistent view of all relevant artifacts for incidents."
- "Splunk Enterprise Security can be improved with better triage capability and less dependency on running SPL searches, which would allow analysts who may not have much experience in writing SPL searches to still use the tool and run investigations."
What is our primary use case?
Our main use cases for Splunk Enterprise Security include security, detection, and incident response.
How has it helped my organization?
The data model benefits our organization by making it easy for the team to get data into Splunk, and field tagging is particularly helpful.
What is most valuable?
The features of Splunk Enterprise Security that I most appreciate are CIM, the data model, the search capabilities, and the investigation feature embedded into Splunk version 8.
The investigation feature helps the team seamlessly put everything together, providing a consistent view of all relevant artifacts for incidents.
Splunk's ability to predict, identify, and solve problems in real-time is exceptional due to its ease of data ingestion and comprehensive search capabilities with various options.
I find the process for customizing, developing, testing, deploying, and refining detections in Splunk Enterprise Security to be excellent, especially with the new Mission Control included in Splunk Cloud version 8. It is really easy to use.
We are sending data directly to Splunk Cloud without any broker or pipeline in between. Our organization does not use risk-based alerting in Splunk Enterprise Security yet, and our SecOps team has not measured incident remediation times compared to our previous solution.
I would advise other organizations considering Splunk Enterprise Security to check their business case, considering the number of systems and amount of data to determine if it is the right tool in terms of the licensing model. If they decide to implement Splunk Enterprise Security, getting professional support is crucial.
One of our decision drivers was the customer support, which we found to be very responsive based on feedback from other customers. Additionally, the ability to extend the license for IT-related topics provides flexibility to leverage the platform across all departments, not just security - a unique feature compared to other SIEM tools.
What needs improvement?
Splunk Enterprise Security can be improved with better triage capability and less dependency on running SPL searches, which would allow analysts who may not have much experience in writing SPL searches to still use the tool and run investigations.
For how long have I used the solution?
We are still at the beginning, just four months into using Splunk Enterprise Security.
What do I think about the stability of the solution?
I assess the stability and reliability of Splunk Enterprise Security as generally good. We had a few glitches, but nothing serious, and when we needed to raise cases with the support team, they were quickly resolved, particularly an issue on the indexer level.
What do I think about the scalability of the solution?
Splunk Enterprise Security scales effectively with our growing needs. As a global organization, we first started with three regions, and when we were about to move to include the last region, it was easy to increase the license and onboard the new region seamlessly.
How are customer service and support?
I would evaluate customer service and technical support for Splunk Enterprise Security as excellent, particularly our sales representative, who is exceptional. On a scale of one to ten, I would rate customer service and technical support as a nine.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
Prior to adopting Splunk Enterprise Security, we were using QRadar from IBM, but we wanted a modern and state-of-the-art SIEM, which led us to choose Splunk Enterprise Security.
How was the initial setup?
The deployment was the best that I have gone through so far. We had the professional support, which is something I recommend everyone do, which is like introducing Splunk and having the Splunk professional support personnel advising and supporting through the implementation phase.
What about the implementation team?
We had professional support, which I recommend to everyone introducing Splunk Enterprise Security, to have professional support advising and supporting them through the implementation phase.
What was our ROI?
The return on investment from Splunk Enterprise Security is still to come.
What's my experience with pricing, setup cost, and licensing?
My experience with pricing, setup cost, and licensing for Splunk Enterprise Security was positive. We had an excellent sales representative. The licensing model was fair and good compared to other tools we evaluated. The storage-based licensing was the best model that fit our requirements, though it may change as we evolve and ingest more data.
What other advice do I have?
I rate this product seven out of ten. Nothing is perfect, and there is still room for improvement.
Which deployment model are you using for this solution?
Public Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Buyer's Guide
Splunk Enterprise Security
September 2026
Learn what your peers think about Splunk Enterprise Security. Get advice and tips from experienced pros sharing their opinions. Updated: September 2026.
915,325 professionals have used our research since 2012.
Cyber Security Consultant at a tech services company with 11-50 employees
Comprehensive investigations have improved soc operations and reduced incidents for customers
Pros and Cons
- "Splunk Enterprise Security acts as a kind of plug-and-play tool for SOC operations, which makes it a very nice tool with a positive impact on my organization."
- "The customer support for Splunk Enterprise Security is bad, as the support never solves anything."
What is our primary use case?
My main use case for Splunk Enterprise Security is for SOC operations. I offer the SOC service to our customers, and Splunk Enterprise Security is a very powerful tool that provides all the framework and tools to correlate events, conduct investigations, and manage issues or alerts.
What is most valuable?
The best features Splunk Enterprise Security offers are the correlation and, specifically, a tool that I appreciate is the Asset and Identity Investigation Investigator. What I appreciate most about those two specific models is the ease of simply entering an IP and user, as it shows me not only the events but also information about that object, such as the owner, associated users, IPs, associated host names, business unit, and all this information. It also provides a summary of the authentications, IDS events, and any risk events or notables, which are also shown, making it a very powerful tool.
Splunk Enterprise Security acts as a kind of plug-and-play tool for SOC operations, which makes it a very nice tool with a positive impact on my organization. It is helping to reduce incidents and manage and review them, allowing me to discover easily when I need to notify my customer about something important.
What needs improvement?
The first improvement for Splunk Enterprise Security is making it cheaper, as I would like to introduce it to other customers, but the high price is a barrier to entry. I would also like a better integration or functionality with AI, as there is not a good implementation of it.
For how long have I used the solution?
I have been using Splunk Enterprise Security for three years.
What do I think about the stability of the solution?
Splunk Enterprise Security is not stable; when it becomes outdated, it always has some failures or bugs, such as features that were in the previous version that are not in the newest one, resulting in many support tickets.
What do I think about the scalability of the solution?
Splunk Enterprise Security's scalability is fine because it operates with the Splunk license, and if you have all the information, you can apply a one-to-one process using the data models.
How are customer service and support?
The customer support for Splunk Enterprise Security is bad, as the support never solves anything.
Which solution did I use previously and why did I switch?
I use various vendors' SIEMs because of my work to serve my customers.
How was the initial setup?
It has helped improve my organization's business resilience, but it is hard to achieve because there is not a clear path to follow for a good implementation of Splunk.
Splunk Enterprise Security has helped reduce my team's average mean time to resolve (MTTR) metric because the tools I previously mentioned provide a lot of context and correlation of all events, which is very good. It has helped me detect threats faster, but it is challenging to set up all the logs and configurations for it to work as desired.
What's my experience with pricing, setup cost, and licensing?
I am not the best person to answer questions about pricing, setup cost, and licensing since I am a technical person and not a commercial one, but I know it is an expensive tool. I believe that the commercial limitations of selling Enterprise Security are significant, and removing them could allow us to bring it to multiple customers.
Which other solutions did I evaluate?
This question and any decisions about why I chose Enterprise Security do not apply to me because I am not the decision-maker; I am only the technical person who administers it.
What other advice do I have?
I would advise others looking into using Splunk Enterprise Security that it is a pretty good tool that works very well, but you need a partner or someone to guide you through the process; otherwise, you may feel alone. I would rate this product a 9.
Which deployment model are you using for this solution?
Public Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Other
Disclosure: My company has a business relationship with this vendor other than being a customer. Reseller
Last updated: Sep 16, 2026
Flag as inappropriateDefense Analyst at a tech vendor with 10,001+ employees
Risk-based analysis has improved alert scoring and now gives clear visibility into analyst actions
Pros and Cons
- "Splunk Enterprise Security has positively impacted my organization since everything we do in some form relates back to Splunk, and as a detection engineer, my responsibility is to make sure we're collecting the right information and filtering out the wrong."
- "I don't really know how to answer how Splunk Enterprise Security's scalability is, but for the time being, it covers what we need, and I don't feel like we're actually utilizing everything."
What is our primary use case?
My main use case for Splunk Enterprise Security is RBA for Risk-Based Analysis Scores.
I am currently working through activating intermediate findings from our ESCU content as we just switched from risk-based or risk rules to intermediate findings, and we have over a thousand to go through, validate that are correct, and implement.
I'm newer to that function, so my experience with handling those intermediate findings right now is limited but growing.
What is most valuable?
The best features Splunk Enterprise Security offers in my opinion include the ability to score alerts, so you're not getting alerts on everything; you can threshold things, so they only show up once they've alerted and hit a certain score-wise.
Splunk Enterprise Security has positively impacted my organization since everything we do in some form relates back to Splunk, and as a detection engineer, my responsibility is to make sure we're collecting the right information and filtering out the wrong.
Since implementing Splunk Enterprise Security, I've noticed specific outcomes such as the visibility into being able to see what our analysts are doing and what's being caught and what's not, which is the major benefit I noticed.
What needs improvement?
In terms of how Splunk Enterprise Security can be improved, with the focus of transitioning everything to an agentic SOC, it would be beneficial to continue allowing us to see into what's being done, so we can validate that the agentic SOC formats and processes are doing the correct things.
For how long have I used the solution?
I have been using Splunk Enterprise Security for about two months.
What do I think about the stability of the solution?
In my experience, Splunk Enterprise Security is stable, as we have no issues with it; it runs for the most part, and sometimes we know of some issues with SOAR playbooks not functioning correctly, but outside of that, nothing more.
What do I think about the scalability of the solution?
I don't really know how to answer how Splunk Enterprise Security's scalability is, but for the time being, it covers what we need, and I don't feel like we're actually utilizing everything.
How are customer service and support?
The customer support for Splunk Enterprise Security is good, and we also have good contacts with our customer reps, so we are partners and we use them pretty well.
I would rate the customer support an eight, as I haven't had too many interactions with them, and while I haven't heard any complaints, I still don't have information.
Which solution did I use previously and why did I switch?
I'm newer, so as far as I'm aware, we did not previously use a different solution before Splunk Enterprise Security, but again, prior to me being there, maybe.
Which other solutions did I evaluate?
Before choosing Splunk Enterprise Security, our team is constantly evaluating what we're using, for example, we have an evaluation out for Sentinel, though it's not something we use as a primary; I think it was offered for free as part of a bundle.
What other advice do I have?
For anyone looking into using Splunk Enterprise Security, I would advise really understanding the language and how to navigate; writing the correlation searches is just something that takes time, so just learn the language and you'll be good. I have provided an overall review rating of eight.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
Last updated: Sep 16, 2026
Flag as inappropriateThreat Analytics Lead at a manufacturing company with 501-1,000 employees
Threat hunting has become faster and focuses on critical incidents through custom dashboards
Pros and Cons
- "Splunk Enterprise Security has positively impacted my organization by helping us identify threats very quickly, and we are now able to identify threats 60% faster compared to before."
What is our primary use case?
My main use case for Splunk Enterprise Security is threat hunting.
A specific example of how I use Splunk Enterprise Security for threat hunting in my organization is identifying incidents and threats. When I'm identifying incidents and threats, I use self-created dashboards in Splunk Enterprise Security.
What is most valuable?
The best features Splunk Enterprise Security offers include the ability to create dashboards and really wrap the data up in a more readable view. Those readable views have helped my team by reducing the amount of traffic that we have to identify or incidents that we have to identify, which really minimizes the amount of time we have to spend searching for data and lets us focus on the things that are important. Splunk Enterprise Security has positively impacted my organization by helping us identify threats very quickly. I can share that we are now able to identify threats 60% faster compared to before.
What needs improvement?
I see no areas for improvement in Splunk Enterprise Security outside of incorporating AI and the ability for AI to act and respond on my behalf. I would like AI to handle responding to incidents for me within Splunk Enterprise Security.
For how long have I used the solution?
I have been using Splunk Enterprise Security for eight years.
What do I think about the stability of the solution?
Splunk Enterprise Security is absolutely stable.
What do I think about the scalability of the solution?
The scalability of Splunk Enterprise Security is good; it continues to evolve as long as we are able to maintain our data ingestion within our licensing.
How are customer service and support?
Customer support for Splunk Enterprise Security is fantastic.
Which solution did I use previously and why did I switch?
I previously used Kibana before Splunk Enterprise Security because my organization wanted to make the switch to Splunk due to having more people capable in Splunk versus Elastic.
Which other solutions did I evaluate?
I evaluated Elastic as another option before choosing Splunk Enterprise Security.
What other advice do I have?
My advice to others looking into using Splunk Enterprise Security is that it's phenomenal; the ease of use, support, and the continued development of the product continues to evolve as the technology grows, and they are embracing AI to make the product even more effective. I think their governance and security are good based on all that I have seen and the demos that I have seen, as there seems to be a lot of capabilities around governance and security. So far, so good regarding Splunk Enterprise Security's AI capabilities; what I have been able to see seems to be very accurate, especially because it actually provides the data based on what it's identified, so I can validate it. I give this product a rating of 10.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Last updated: Sep 16, 2026
Flag as inappropriateService Lead at a manufacturing company with 10,001+ employees
Has improved real-time threat detection and supports better contextual awareness
Pros and Cons
- "The features of Splunk Enterprise Security that I prefer most are the correlation engine and the common information model, basically the aggregation of data."
- "The problem with Splunk Enterprise Security generally, from what I've seen in the last couple of years, is that it has a cultural, assumption design model around it, which means the company has to fit its internal processes in terms of how to use it."
What is our primary use case?
Splunk Enterprise Security by our SOC organization to aggregate and triage alerts used to identify IOCs.
How has it helped my organization?
Splunk Enterprise Security has a strong feature set that helps identify, and solve problems in real time.
The benefits of those features for my organization, more specifically, are that it prevents us from being hacked.
What is most valuable?
The features of Splunk Enterprise Security that I prefer most are the correlation engine and the common information model, basically the aggregation of data. It's usually designed to take all the data, normalize it into a flat schema, so you can then see patterns more easily. That's the significant aspect.
What needs improvement?
The problem with Splunk Enterprise Security generally, is that organizations strugle to fit into their cultures and workflow. For better outcomes, companies have to fit their internal processes to how the tool has been designed. At times, this can be too complex to run, has high overhead requiring constant tuning. Newer versions e.g. 8.3, hint at greater ease of use.
For how long have I used the solution?
I have been working in my current field for around 12 years.
What do I think about the stability of the solution?
Reliability is all about the care and feeding of it. I have not experienced downtime, crashes, or performance issues with Splunk Enterprise Security.
How are customer service and support?
I would evaluate customer service and technical support as an eight on a scale of one to ten. Splunk Cloud's support is not bad. However, there's a gray area between what they do and what they don't do. What they don't do is the blind spot for most enterprise customers; they don't realize they have to handle certain responsibilities. There's a shared responsibility.
How would you rate customer service and support?
Positive
How was the initial setup?
Setup can be complex. Splunk has specific guidelines. Do your home work and read their SVA architecture and capacity manuals.
And always read their release notes.
What was our ROI?
What's my experience with pricing, setup cost, and licensing?
My experience with pricing, setup costs, and licensing for Splunk Enterprise Security is limited. The unit cost of Splunk Enterprise Security is slightly less than the core product.
Which other solutions did I evaluate?
What other advice do I have?
My advice to other organizations considering using Splunk Enterprise Security is to do your homework. Attend industry peer sessions and learn from other organizations. Splunk's partner program, RBA Community offer compelling resources for new customers.
I would rate it an eight out of ten.
Which deployment model are you using for this solution?
Public Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Business Development Manager at Axians Germany
Reduces implementation time through integrated security features and streamlined threat detection
Pros and Cons
- "It actually helps us by not having to develop all the use cases ourselves, providing an integrated product that has everything in one place."
- "I really appreciate the all-integrated SIEM feature of Splunk Enterprise Security, which serves as a one-stop shop to get all security tasks done."
- "Splunk Enterprise Security can be improved with more ease of configuration."
- "Splunk Enterprise Security can be improved with more ease of configuration. It is pretty straightforward to get it started, however, to really check if my data is all available and how to activate the right use case and the right correlations is still sometimes a hassle."
What is our primary use case?
My main use cases for Splunk Enterprise Security are mainly building SIEM for our customers, implementing it at customer sites, and using it for our own developments.
What is most valuable?
I really appreciate the all-integrated SIEM feature of Splunk Enterprise Security, which serves as a one-stop shop to get all security tasks done. It actually helps us by not having to develop all the use cases ourselves, providing an integrated product that has everything in one place.
It has integrated threat intelligence and an integrated use case library, so it requires only one installation and configuration. This specifically benefits my organization by reducing the implementation time at our customers, getting faster time to value with a better turnover rate for our customers.
We are using disparate security solutions that integrate or import data into Splunk Enterprise Security. We are implementing all data sources that are somehow possible, so there's no limitation to that.
The process for customizing, developing, testing, deploying, and refining detections in Splunk Enterprise Security is pretty straightforward. Developing our own solutions is pretty good, and even though we are using the Security Essentials and the Enterprise Security content libraries, that's a very good way to progress.
What needs improvement?
Splunk Enterprise Security can be improved with more ease of configuration. It is pretty straightforward to get it started, however, to really check if my data is all available and how to activate the right use case and the right correlations is still sometimes a hassle. A guided mode to help us understand how to get started, improve data quality, and prepare data more efficiently for use cases would be highly beneficial for us.
For how long have I used the solution?
I have been using Splunk Enterprise Security for the best of seven or eight years now.
What do I think about the stability of the solution?
I have experienced downtime, however, it's very little. The downtimes are mostly hardware issues such as network downtimes, which is nothing that Splunk has a say in. If you deploy a multi-site architecture and make it fail-safe, downtime isn't an issue.
What do I think about the scalability of the solution?
I have expanded usage a lot. This expansion has improved the process as scalability and scaling volume-wise and usage-wise with Splunk Enterprise Security was never a problem for me nor our customers.
How are customer service and support?
I evaluate customer service and technical support from Splunk as perfect. I'm very confident in what the partner SEs and the Splunk Professional Service team can do. If I need to reach out to them, I get instant replies, and the Splunk community itself is very helpful as well. On a scale of one to ten, I would give it a ten.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
Prior to adopting Splunk Enterprise Security, I was using another solution to address similar needs. We were using Splunk Core with our own developments and helped several customers migrate away from products QRadar and FortiSIEM, however, our main go-to platform is still Splunk Enterprise Security.
How was the initial setup?
My experience deploying Splunk Enterprise Security is all in all pretty straightforward. If you are used to how to set it up, it's very good.
What was our ROI?
I have seen ROI with Splunk Enterprise Security.
One example is a situation with a customer where we started installing it and actually found active breaches that were short of being used and leveraged for maybe blackmailing or compromising the customer. We couldn't calculate what would have been the cost if they had actually gotten compromised; however, they were in the process, so every investment was returned immediately. It was definitely significant.
What's my experience with pricing, setup cost, and licensing?
My experience with pricing, setup costs, and licensing is a bit difficult. There are competitors that are more cost-effective. That said, for the feature set that Splunk offers, it's okay. It is on a solid foundation, so there could be more rebates and opportunities for us as a partner to offer it to our customers. Still, it's competitive.
The most significant challenges I face when using Splunk Enterprise Security for advanced threat detection are primarily related to customer pricing concerns. I find it's okay for a premium product on top of the Splunk base, however, the pricing is one thing, and I don't know if it's the same for all regions. We specifically sometimes have difficulties getting a smaller license than the Splunk Core one if we don't want to ingest all the data into Splunk Enterprise Security.
What other advice do I have?
My advice to other organizations considering Splunk Enterprise Security is to try it if you don't know about it yet.
On a scale of one to ten, I would rate Splunk Enterprise Security overall as an eight. Sometimes it is a bit hard to get the searches and the data done, but all in all, it's a great product.
Which deployment model are you using for this solution?
On-premises
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
Senior Information Security Engineer at a outsourcing company with 1,001-5,000 employees
Video Review
Risk-based alerting has reduced false positives and helped us detect threats faster
Pros and Cons
- "Splunk Enterprise Security is so easy as it scales with us as we grow."
- "Splunk RBA or risk-based alerting definitely made our lives a lot easier; we went from hundreds of alerts having to be triaged a day, that generally could be false positives or just noise, and bubble them into one overall alert that we can look at on a per-day basis and see what's rising to the top and respond faster, have a higher rate of true positives and find evil a lot quicker."
- "The way Splunk Enterprise Security could improve is by pulling in and mapping my DHCP data and tracking users' IP addresses as it changes throughout sessions, and being able to keep track of who is actually assigned to what IP address more natively."
What is our primary use case?
My main use cases for Splunk Enterprise Security are being able to take our noisy level detections and using features such as risk-based learning that are built into Splunk Enterprise Security, and bubble them up into one larger alert, which makes it easier for us to go after and find adversaries throughout our network.
How has it helped my organization?
Splunk Enterprise Security has reduced our meantime to detect. Especially when we switched to RBA. We've seen our noticeable RBA mean to detect a decrease. I don't have the exact number. That said, it definitely has that potential and it's definitely worked in our implementation.
What is most valuable?
I really love the identity and asset lookups, being able to pull that identity data in and be able to enrich our alerts that are going through. Finding next-level managers, locations, and being able to build out a bigger story for our analyst as they receive these alerts is a huge functionality that I personally love the most.
The identity lookups have definitely benefited our company because it takes that guesswork of looking in other utilities and brings that live data of who our employees are, what their job titles are, and be able to build out the story of what's going on. If we have someone who works as a data analyst accessing sales data, sales information, that's a huge red flag for us so we're able to make an intelligent decision and respond faster by having that data available.
Splunk RBA or risk-based alerting definitely made our lives a lot easier. We went from hundreds of alerts having to be triaged a day, that generally could be false positives or just noise, and bubble them into one overall alert that we can look at on a per-day basis and see what's rising to the top and respond faster, have a higher rate of true positives and find evil a lot quicker.
Splunk Enterprise Security helps us look at high-fidelity alerts a lot quicker because we're using RBA. It's taking the sum of those small alerts that would be generally noise, combining them into a larger picture, boiling them up to the top and letting our analysts then focus on those, which generally have been the true positives of those malicious actors who are impersonating users or accessing through our network and be able to respond a lot quicker.
What needs improvement?
The way Splunk Enterprise Security could improve is by pulling in and mapping my DHCP data and tracking users' IP addresses as it changes throughout sessions, and being able to keep track of who is actually assigned to what IP address more natively.
For how long have I used the solution?
I have used Splunk Enterprise Security for about 14 years.
What do I think about the scalability of the solution?
Splunk Enterprise Security is so easy as it scales with us as we grow. As we throw more data sets at it, we can increase our indexers in order to accommodate that, and we know that the data is going to be searchable, ready and available in an instant.
How are customer service and support?
When I talk about Splunk customer support, I'm talking about world-class support.
They are so easy to get a hold of, they're so knowledgeable and they don't accept 'I don't know.' They'll say 'Hold on, I will go get the next person who does know this' and you'll get the answer very fast.
That, plus the community members who are writing answers to your questions, there's really not a time when you are going to say 'I don't know,' or you don't walk away with the answer on that day.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
Prior to using Splunk Enterprise Security, I had previously used other SIMs that weren't nearly as advanced or up to the task to be able to input that data in our needs at the time. Splunk really answers the question of the do everything platform.
How was the initial setup?
Deploying Splunk Enterprise Security is actually a really easy task. The onboarding steps that they provide throughout the GUI have become super simple.
The documentation through Lantern has been invaluable and can really answer any questions that we had. It really made the setup go from what seemed like it was going to be a tedious job to something that was really easily done in an afternoon. And then it gave us steps going forward on what to do in order to get the full value of it.
What was our ROI?
For me, the biggest return on investment when using Splunk Enterprise Security is being able to feed any data I need, knowing that data's going to be readily accessible, usable multiple times throughout my organization and I can even bring in non-security individuals to be able to access their data since our back controls that are in Splunk Enterprise Security.
What other advice do I have?
The advice I would give to other organizations who are considering Splunk Enterprise Security is to just do it. It's honestly one of the best investments you'll make.
You'll start noticing the return on investment really quick. You'll start to notice answers that you did not know you had to questions that didn't exist. You'll start to notice your meantime to detect goes down as you start implementing RBA and embracing the Splunk base itself.
On a scale of one to ten, I would rate Splunk Enterprise Security a solid ten. It answers questions you didn't even know you had, and as you drill through the dashboards and go through the different features that are available, you start to realize all this available information that's there that you didn't even know your data had those answers to. It really starts bringing that value within your first 30 days of using it.
Which deployment model are you using for this solution?
Hybrid Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Senior Cyber Security Operations Engineer at a manufacturing company with 10,001+ employees
Improves detection and investigation workflows while streamlining alert creation for better resilience
Pros and Cons
- "I find the process for customizing, developing, testing, deploying, and refining detections in Splunk Enterprise Security effective."
- "Splunk Enterprise Security streamlines the creation of what they call notables, which takes a lot of the effort that we would have to put into creating our own solution off the table and does it for us."
- "Splunk Enterprise Security is not exactly user-friendly."
- "Regarding customer service and technical support, their support is the worst I have ever run into in any industry."
What is our primary use case?
My main use cases for Splunk Enterprise Security are detection and investigation.
How has it helped my organization?
Splunk Enterprise Security has helped improve my organization's business resilience.
What is most valuable?
I never liked Splunk Enterprise Security much until the new version, and now that they've ramped up RBA and made changes in version eight, I prefer it much better.
Splunk Enterprise Security streamlines the creation of what they call notables, which takes a lot of the effort that we would have to put into creating our own solution off the table and does it for us.
We haven't made the newspaper yet, so Splunk Enterprise Security is doing its job. That integration supports my security operations very efficiently, or we wouldn't use it. I find the process for customizing, developing, testing, deploying, and refining detections in Splunk Enterprise Security effective. That's my bread and butter.
My organization uses risk-based alerting in Splunk Enterprise Security. The SOC is still in the development and testing phase for RBA, so they're not seeing any risk-based alerting yet. Within the next week or two, they should start seeing it.
I have no idea how long on average my SecOps team takes to remediate security incidents with Splunk Enterprise Security. I am not using any new threat detection features in Splunk Enterprise Security since we write our own correlation searches from scratch.
Regarding Splunk's ability to predict, identify, and solve problems in real-time: prediction capabilities are not present at all, identification is pretty good, and resolution is effective. It's a good tool. We've got really amazing people behind it, using it, and although there are only four of us behind it, we've got really amazing people using it.
What needs improvement?
Splunk Enterprise Security is not exactly user-friendly. The most significant challenges I face when using Splunk Enterprise Security for advanced threat detection are assets and identities, which are a pain in the neck, and the documentation for RBA is horrible.
They've got it now to where it pretty much deploys itself as long as you know what you're doing, yet it does some really weird and impractical things such as putting file extensions on lookup tables that shouldn't be there, which you have to go in and clean up. It's got some quirks that aren't documented, or not all documented.
For how long have I used the solution?
I have been working in this field for ten years and using Splunk Enterprise Security for eight.
What do I think about the stability of the solution?
I have not experienced any downtime, crashes, or performance issues based on Splunk Enterprise Security.
What do I think about the scalability of the solution?
We've expanded our license dramatically since the merger, and Splunk Enterprise Security handles it just fine. It's not really affected by scale; the infrastructure it sits on is affected by scale, however, the software itself isn't.
How are customer service and support?
Regarding customer service and technical support, their support is the worst I have ever run into in any industry. On the front line, they put people who don't know what they're doing, refuse to escalate, and are not helpful.
When we go to Splunk support, we've already done everything and are really good at what we do, however they make us do it over again or won't help us, and that's enough.
How would you rate customer service and support?
Neutral
Which solution did I use previously and why did I switch?
Way back in the day, we used QRadar, however, as soon as we converted to Splunk, we bought Splunk Enterprise Security with it.
How was the initial setup?
They've got it now to where it's pretty much as long as you know what you're doing, it deploys itself. However, it does some really weird things, like putting file extensions on lookup tables that shouldn't be there, that we have to go in and clean up.
It has some quirks that aren't documented or aren't fully documented. That's Splunk. They're not good with documentation. If you conduct thorough testing in a development or testing environment, you'll find 99% of what doesn't work and be prepared for it, ensuring that it does.
What was our ROI?
We have seen return on investment with Splunk Enterprise Security, and we're getting our money's worth. It streamlines the creation of what they call notables, which eliminates a significant amount of the effort that would be required to create our own solution, allowing us to achieve a good ROI.
Which other solutions did I evaluate?
I considered the change initially due to a better product, as it was an evaluation of a better product for a better price back then.
What other advice do I have?
My advice to other organizations considering Splunk Enterprise Security is that unless you're really big, don't spend the money. On a scale of one to ten, I rate this solution an eight.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Information Security Officer at Freeport LNG Development, L.P.
Analysts detect threats efficiently through scheduled alerts and customizable searches
Pros and Cons
- "It's similar to having a car. It's a necessity. I don't have to prove to the business executives that it provides return on investment. It's a necessary function and a must-have."
- "The features I appreciate the most in Splunk Enterprise Security are the scheduled alerts and the search function."
- "I would evaluate customer service and technical support as frustrating at times."
- "If we want to filter alerts, currently it's a very manual process. We identify IP addresses and usernames and must manually filter them."
What is our primary use case?
My main use case for this solution is to detect threats.
What is most valuable?
The features I appreciate the most in Splunk Enterprise Security are the scheduled alerts and the search function.
The other SIEMs were more menu-driven, similar to Yahoo in the past. With Yahoo, you would navigate to find restaurants in San Francisco. Splunk Enterprise Security operates more with a 'tell us what you want and we'll find it' approach versus directing users to look in specific directions. It is very hunt-friendly.
We are able to prevent breaches with Splunk Enterprise Security.
Integration supports our security operations since our analysts operate within Splunk.
What needs improvement?
Additional features could be included in the next release. The specific functionality I'm looking for relates to alerts and false positives. If we want to filter alerts, currently it's a very manual process. We identify IP addresses and usernames and must manually filter them. It would be beneficial if we could simply click a checkbox to filter and automatically add it to the search, then save it immediately, instead of the time-consuming process of cutting and pasting, which isn't efficient.
The most significant challenge I face when using Splunk Enterprise Security for advanced threat detection is maintaining balance in search parameters. Creating searches that aren't too narrow to miss threats, yet not too wide to generate excessive false positives is crucial. When determining recurring false positives for filtering, junior analysts who aren't coders must edit code-like elements. This introduces unnecessary risk when they could simply check a box to filter.
For how long have I used the solution?
I have been working in my current field for 33 years.
What do I think about the stability of the solution?
I would assess the stability and reliability of Splunk Enterprise Security to be generally acceptable. Some performance issues occur with historical, long-distance searches spanning three to six months, however, these are very rare searches that we perform.
What do I think about the scalability of the solution?
Splunk Enterprise Security scales effectively with the growing needs of my organization because we've never had an issue with it. I don't know if the technology team expands usage significantly, but we've used Splunk Enterprise Security for a long time. The expansion process is so smooth it's barely even a process.
How are customer service and support?
I would evaluate customer service and technical support as frustrating at times. It was similar to experiences with other companies, where they would explain why issues occurred instead of solving them. It took time to reach the right individual who would solve the problem, however, these instances were infrequent.
How would you rate customer service and support?
Neutral
Which solution did I use previously and why did I switch?
Prior to adopting Splunk Enterprise Security, I worked at a previous job where they had a different SIEM that was inadequate, so we implemented Splunk Enterprise Security. At my next job, they already had it installed. If they didn't have it, I would have brought it in during the first month. I cannot name the previous solution as it was approximately 15 years ago and was a second-tier provider, not QRadar or other well-known solutions from that time.
How was the initial setup?
My SecOps team has never had a previous solution to compare how long it takes to remediate security incidents in Splunk Enterprise Security. When I arrived, they had a developer license and decided to use it going forward for all security purposes. My team has no experience with other solutions.
What was our ROI?
I have not seen a return on investment with Splunk Enterprise Security. It's similar to having a car. It's a necessity. I don't have to prove to the business executives that it provides return on investment. It's a necessary function and a must-have.
What's my experience with pricing, setup cost, and licensing?
I am aware of the pricing, setup cost, and licensing for it. I don't handle pricing because the primary user is the cyber team. The owners of all technology are the technology team. I inform them we need this solution, and they handle acquisition and management.
What other advice do I have?
We use multiple best-of-breed products to provide data to Splunk Enterprise Security for correlation and malicious activity determination.
My organization does not use risk-based alerting in Splunk Enterprise Security. We use third parties for threat detection features.
Splunk Enterprise Security's impact on business resilience is unclear as we use it exclusively for cyber purposes.
My advice to other organizations considering Splunk Enterprise Security is to use it.
On a scale of one to ten, I rate this solution a nine.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Buyer's Guide
Download our free Splunk Enterprise Security Report and get advice and tips from experienced pros
sharing their opinions.
Updated: September 2026
Product Categories
Security Information and Event Management (SIEM) Log Management IT Operations AnalyticsPopular Comparisons
IBM Security QRadar
Splunk AppDynamics
Microsoft Sentinel
Elastic Security
IBM Turbonomic
Palantir Foundry
WhatsUp Gold
LogRhythm SIEM
Rapid7 InsightIDR
Buyer's Guide
Download our free Splunk Enterprise Security Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- Which would you recommend to your boss, IBM QRadar or Splunk?
- What are some of the best features and use-cases of Splunk?
- What SOC product do you recommend?
- Splunk as an Enterprise Class monitoring solution -- thoughts?
- What is the biggest difference between Dynatrace and Splunk?
- IBM QRadar is rated above competitors (McAfee, Splunk, LogRhythm) in Gartner's 2020 Magic Quandrant. Agree/Disagree?
- What are the advantages of ELK over Splunk?
- How does Splunk compare with Azure Monitor?
- New risk scoring framework in the Splunk App for Enterprise Security -- thoughts?
- Splunk vs. Elastic Stack




















