No more typing reviews! Try our Samantha, our new voice AI agent.
Abhishek Nayak - PeerSpot reviewer
Soc L1 Engineer at Softcell Technologies Limited
Real User
Top 5
Jun 5, 2026
Incident review has improved threat detection and AI now reduces noise for faster investigations
Pros and Cons
  • "AI in Splunk Enterprise Security improves the accuracy, and the AI feature has helped me reduce false positive alerts, which prevented me from wasting time on junk alerts and separating the noise from the actual true positive alerts."
  • "Writing SPL queries is tough at first with Splunk Enterprise Security, and the system gets a bit slow when searching through a large amount of data."

What is our primary use case?

My use cases mainly involve using Splunk Enterprise Security to monitor security threats, checking the dashboard for any alerts, looking at logs to see what is actually happening, and using the built-in searches to identify suspicious alerts regarding security or suspicious activity.

What is most valuable?

I appreciate the incident review dashboard as the best feature, as it makes it very easy to track alerts and manage them in one single interface.

AI in Splunk Enterprise Security improves the accuracy, and the AI feature has helped me reduce false positive alerts, which prevented me from wasting time on junk alerts and separating the noise from the actual true positive alerts. It makes my detection much more reliable.

Risk-based alerting in Splunk Enterprise Security is very helpful. Instead of getting overwhelmed by hundreds of small, low priority alerts, it gives me a risk score to users or machines based on their activity.

Using MITRE ATT&CK is really helpful. Splunk Enterprise Security automatically maps alerts to the MITRE ATT&CK framework, so when an alert triggers, I can see exactly which stage of an attack is happening, such as lateral movement, reconnaissance, or credential access tactics. This gives me a clear picture of what the attacker is trying to do.

What needs improvement?

Writing SPL queries is tough at first with Splunk Enterprise Security, and the system gets a bit slow when searching through a large amount of data.

For how long have I used the solution?

I have been using Splunk Enterprise Security for four months overall.

Buyer's Guide
Splunk Enterprise Security
July 2026
Learn what your peers think about Splunk Enterprise Security. Get advice and tips from experienced pros sharing their opinions. Updated: July 2026.
909,647 professionals have used our research since 2012.

What do I think about the stability of the solution?

I did see lagging with Splunk Enterprise Security. Even when I have a huge amount of data coming in, it doesn't crash or hang. I haven't faced any major downtime. Once the configurations are set, it runs quite reliably in the background without needing constant attention.

What do I think about the scalability of the solution?

Splunk Enterprise Security is pretty flexible regarding scalability. Whenever our data volume grows, I can easily add more indexers or searchers to handle extra load, and it's straightforward to expand.

How are customer service and support?

Other analysts contact the support team if there is any need to understand the latest updates from the Splunk community, but I haven't contacted them.

Which solution did I use previously and why did I switch?

I have used an open-source Wazuh SIEM tool as an alternative. I prefer Splunk Enterprise Security more.

How was the initial setup?

The initial deployment of Splunk Enterprise Security had the main challenge of connecting all our data sources like firewall and server and making sure the data was flowing correctly. It wasn't a simple click and run. It required good planning to get all the data logs showing up properly.

What's my experience with pricing, setup cost, and licensing?

The pricing for Splunk Enterprise Security is a little bit high compared to other similar tools.

What other advice do I have?

Splunk Enterprise Security helped me in many ways. It really helped me reduce noise. Since it groups similar alerts together, I don't have to look at every single small thing. It filters out unimportant information, so I can focus on real threats.

Maintaining Splunk Enterprise Security is necessary to keep things running smoothly. I regularly check if all the logs are coming in properly. I also spend time updating and tuning searches or reducing the false positives.

I have not upgraded to Splunk Enterprise Security 8 yet.

I haven't seen any reduction in my mean time to resolve or my mean time to detect. I would rate this review an eight overall.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Last updated: Jun 5, 2026
Flag as inappropriate
PeerSpot user
DevOps&Cloud Engineer Mentee at CertDirectory.io
Real User
Top 20
Jun 27, 2025
Reduces alert fatigue, and it's well-documented and well-designed
Pros and Cons
  • "Splunk Enterprise Security is fast and well-documented, and user interface and user interaction are well-designed compared to other SIEM solutions."
  • "Splunk Enterprise Security is great but can have some frustration points. It can sometimes be slower to use."

What is our primary use case?

My main use case is for log management and checking the logs. We have rules running in Splunk Enterprise Security. We are using it as a main SIEM solution for our customers.

How has it helped my organization?

Alert fatigue is a common issue with security solutions, but Splunk Enterprise Security reduces alert fatigue. When we encounter real incidents, we get to dive deeper to check out the main cause of that incident. It is useful because it reduces alert fatigue.

What is most valuable?

The best feature of Splunk Enterprise Security is the documentation. Splunk Enterprise Security's documentation is well-organized. For example, if you have a problem or if you want to read about what you're looking for, you can easily go there and read from the documentation. It also has many resources worldwide. It is a de facto standard of the SIEM solutions. For example, I have used IBM QRadar, which is another solution many companies are using.

One of the most beneficial use cases for me is that Splunk Enterprise Security is fast. I cannot speak to how the SIEMs work in the backend, but I can say it is fast to find any logs. 

Its UX and UI experience is getting better. It is much better than one year ago. Some of the buttons and other features are much easier to locate and choose. The user interactions are much better than one year ago. The advanced queries are much faster. The UI design is much better. That is one of the best changes that happened in one year.

What needs improvement?

AI is an area that has room for improvement in Splunk Enterprise Security. I would say that AI plays a significant role in many of the cybersecurity tools I've used, not just Splunk. Many AI tools offer some form of assistance. By "AI assistance," I mean that while AI may not have complete knowledge of all customer flow data, it can still help engineers who often encounter unfamiliar situations. For example, during incidents, a large volume of logs can be generated, and it can be difficult to analyze all of them in a timely manner. In such cases, AI tools can be beneficial, even if they are not universally applicable. Certain events, like denial-of-service attacks, can result in massive log flows, which complicate detection and response efforts. Additionally, there may be similar collective issues affecting multiple customers.

Many cybersecurity tools incorporate some limited AI capabilities, which can assist operators. For instance, if a specific endpoint security issue arises with a customer, AI can help identify potential causes and suggest improvements. In my experience, most cybersecurity operators and companies rely on security tools that may not offer full-fledged SIEM solutions but do provide integrated security functionalities such as Intrusion Detection Systems (IDS) and Intrusion Prevention Systems (IPS). My expectation is that even small, incremental integrations of AI will significantly enhance these tools' effectiveness.

For how long have I used the solution?

I have been using the solution for approximately one year. I used it for 12 months in the company.

What do I think about the stability of the solution?

It's stable. I would rate it a ten out of ten for stability.

What do I think about the scalability of the solution?

The scalability of Splunk Enterprise Security rates as an eight out of ten. I have not used the scalability option, but I would say the other procedures and processes are flawless. Scalability might be the same.

How are customer service and support?

I have not reached out to their technical support because whenever I have an issue, I use the documentation rather than reaching out to technicians. When there is an issue, people need swift assistance to solve it. People do not want to wait, so I mainly use the documentation.

How would you rate customer service and support?

Neutral

Which solution did I use previously and why did I switch?

I have worked with other SIEM solutions. Splunk Enterprise Security is great but can have some frustration points. It can sometimes be slower to use. On the other hand, when I use IBM QRadar, it rarely experiences slowdowns, especially when using the Incident Command Module (ICM). In the case of Splunk Enterprise Security, the speed might be affected by the number of systems in use or possibly due to how the security engineers configure it. As an operator, I find that the speed is a reason I would rate it an eight out of ten. Overall, it's very fast and accurate, and the user interface is excellent for various uses, such as querying data. However, I do notice that it can be slightly slower compared to other large enterprise solutions.

How was the initial setup?

Most of the time, it is deployed on-premises. We don’t rely heavily on cloud solutions, although we have explored them a bit. Our customers, particularly in the financial industry, tend to prefer on-premises systems due to their concerns about cloud security.

Having good documentation is helpful for deployment. If the documentation is lacking, it can be challenging. The ease of navigating the systems really depends on a person's experience. 

The duration varies depending on the company. I can't give a specific answer because it depends on several factors, such as the number of people working in the system, the number of endpoints, and how many on-premises servers are running. In my case, I haven't experienced a full deployment, as I've only deployed a few endpoints and on-premises services. This process took just a couple of days for me, but I haven't dealt with a large-scale on-premises deployment. When I joined the company, they were already using Splunk for various on-premises services, so I haven't gone through a complete zero to one hundred type of scenario.

Splunk Enterprise Security absolutely requires maintenance, but I don't deal with maintenance. It needs maintenance, but I have not encountered much of it. 

What was our ROI?

From a return on investment standpoint, Splunk Enterprise Security saves a lot of time. I have used other SIEM solutions, and they are not so great. They create lots of exhaustion and frustrating periods of checking queries, and the response times are slower. This leads to a lot of frustration because many companies don’t rely on just one SIEM tool; they often use multiple alternatives simultaneously.

The documentation for Splunk Enterprise Security is outstanding. It is well-organized and easy to access. You can simply go to the Splunk documentation website, search for what you need, and by the end of the day, you’ll have a great solution for any issue you encounter with Splunk Enterprise Security. In contrast, other SIEM tools often lack this level of documentation, which is quite disappointing. 

Splunk Enterprise Security also excels with its user interface. It is easy to navigate and integrates seamlessly with other services, which is a significant advantage. You can easily search for solutions, try out different features, and create reports.

As a security operator, one of our main responsibilities is writing reports. If an issue arises, clients will often ask, “What happened around noon? Can you explain the main issue?” Other SIEM tools can make it difficult to find the appropriate buttons or functions to navigate and analyze these incidents. However, with Splunk Enterprise Security, you just look up the documentation, write what you’re searching for, and apply the same rules in Splunk Enterprise Security. Everything is easy to follow, and the system works effectively. In summary, I would say that the well-documented guidance is one of the most valuable aspects for saving me time.

What other advice do I have?

I have not used the advanced correlation capabilities so much because mainly all of them are running. Specifically, I have not gone very deep into the use case of Splunk Enterprise Security. I have used advanced queries a couple of times. For example, there was a sort of attack, a false positive attack. We had to check out all the timelines or block queries to find out what might have happened or what the reason was for the false positive. I used that and it is quite fast.

I have not used the risk-based alerting feature. It is more for log management and checking the log flow. 

Whenever you want to apply for any exams, such as the SOC exam or Blue Team certification exams, they mainly ask for Splunk rather than other SIEM solutions. For me, it is overall the best SIEM solution to use.

I can recommend Splunk Enterprise Security to other users. It is fast and well-documented. User interface and user interaction are well-designed compared to other SIEM solutions. It is a great SIEM tool.

I would rate Splunk Enterprise Security an eight out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Buyer's Guide
Splunk Enterprise Security
July 2026
Learn what your peers think about Splunk Enterprise Security. Get advice and tips from experienced pros sharing their opinions. Updated: July 2026.
909,647 professionals have used our research since 2012.
CEO at CygenIQ
Real User
Top 10
Dec 22, 2024
Improves threat management and has effective analytics
Pros and Cons
  • "The Splunk Enterprise Security's threat-hunting capabilities have been particularly useful in later releases."
  • "Splunk Enterprise Security enhances business resilience and assists with threat detection by centralizing security data."
  • "Splunk Enterprise Security would benefit from a more robust rule engine to reduce false positives."

What is our primary use case?

We primarily used Splunk Enterprise Security for data and cloud ingestion. We also leveraged it for enterprise security use case engineering, which encompassed malware analysis, threat management, detection, and the integration of threat and vulnerability intelligence, culminating in comprehensive reporting and dashboards. This was the principal use case for our SIEM platform. In recent years, we have also employed Splunk for user behaviour analytics to bolster insider threat protection.

We implemented Splunk Enterprise Security to improve security monitoring, threat detection, and incident response.

How has it helped my organization?

Although Splunk is not the only tool we use, it is essential that it provides end-to-end visibility into threats in our environment.

Splunk is effective for helping find security events across multiple cloud, on-premises, or hybrid environments.

Splunk helps improve our organization's ability to ingest and normalize data.

Splunk helps us identify threats in real-time.

We integrated 50 percent of the MITRE ATT&CK framework's techniques to enhance our incident detection capabilities.

Splunk Enterprise Security effectively analyzes various security events and has helped improve my organization's ability to ingest and normalize data.

Splunk helped us detect threats faster. 

Splunk Enterprise Security reduced the investigation time by consolidating datasets for quick access.

Splunk Enterprise Security enhances business resilience and assists with threat detection by centralizing security data.

I have a positive impression of Splunk's ability to predict, identify, and solve problems.

Splunk Enterprise Security helps reduce our mean time to resolve.

What is most valuable?

The Splunk Enterprise Security's threat-hunting capabilities have been particularly useful in later releases.

What needs improvement?

Splunk Enterprise Security would benefit from a more robust rule engine to reduce false positives. While its detection capabilities are efficient, there is room to improve its alert volume reduction and false positive management efficiency. Furthermore, enhancements in its integration capabilities with other security infrastructures could optimize its overall effectiveness.

For how long have I used the solution?

I have been using Splunk Enterprise Security for 13 years.

What do I think about the stability of the solution?

In terms of stability, Splunk is good. It provides a stable environment but needs to integrate with ITSM platforms to achieve better visibility.

What do I think about the scalability of the solution?

Splunk Enterprise Security is efficient and scalable, especially for large environments with substantial scalability needs.

How are customer service and support?

The technical support for Splunk met my expectations.

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

I haven't switched to Splunk from another solution, but I have used various products, such as Google Chronicle, Securonix, ExtraHop, and Sumo Logic, to meet different customer needs. Securonix is used more for behavioural analytics and insider threats, whereas Splunk is used for logging and monitoring.

How was the initial setup?

The initial setup of Splunk Enterprise Security is straightforward, but it does require skilled personnel.

What about the implementation team?

The implementation involved an architect, cloud DevOps engineer, data engineer, full-stack developers, and cybersecurity engineers. A team of five to six members, tailored to different roles, was typical.

What was our ROI?

Splunk's cost is justified for large environments with extensive assets. However, for smaller organizations, other products may provide better value for money.

What's my experience with pricing, setup cost, and licensing?

Splunk is priced higher than other solutions.

What other advice do I have?

I would rate Splunk Enterprise Security nine out of ten.

Splunk Enterprise Security requires continuous maintenance and support, which requires a dedicated team. Previously, seven to eight personnel were focused on platform maintenance. Additional resources may be required to optimize for multiple customer environments. 

For those evaluating SIEM solutions solely based on cost, Splunk might not be suitable. It is essential to consider security, context, and specific use cases rather than just choosing based on price. Critical assets need the right platform for effective protection rather than opting for a cheaper solution.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
GautamKar - PeerSpot reviewer
Staff Performance Engineer at ServiceNow
MSP
Top 5
Mar 2, 2025
Real-time monitoring and alerts enhance performance evaluation and security investigations
Pros and Cons
  • "I can create dashboards to collect and view information in a tabular, graphical format. This feature is important because it helps me understand time-series data over one or two hours."
  • "Overall, I would rate it a nine out of ten."
  • "Data retention can be better. If we want to look at the data for five months or six months, that is not available to us. We only have a history of 20 or 30 days. After that, the information gets lost. That is a drawback."

What is our primary use case?

We use it for real-time monitoring and alerts for all instances and servers on our sub-prod instances. It helps in monitoring, getting alerts for specific errors, and identifying various logs. We also use it for log analysis, which is very beneficial.

My use case is more related to production issues. Threat detection is taken care of by another team.

How has it helped my organization?

It is our go-to tool for monitoring multiple cloud environments. The difficult part initially is to understand how the logging is happening for particular applications or instances. Once you have an understanding of what you want to see and how they are getting generated, you can just write queries, and you can create exhaustive dashboards for anybody to look at and understand how things are.

Splunk Enterprise Security is good for analyzing malicious activities and detecting breaches. Its threat detection capabilities are good. We can look at the exact activity and task. We can look at a trace and understand what is happening. It gives a very granular understanding. I see emails from the security team mentioning what they have identified, so it seems to be helpful for threat detection.

Based on the org mail that we received, they were able to block almost 95% of threats in real time. That is a pretty good number.

Splunk Enterprise Security helps to reduce alert volume because you can understand patterns, such as where your requests are going and how everything is happening. There has been a 40% to 50% reduction.

Splunk Enterprise Security has helped speed up our security investigations by 40% to 50%. It has helped the security team to get a head start and understand where the issue is originating and where the problem is. We are operating in a very dynamic environment, so any time lost costs the company money.

What is most valuable?

I can create dashboards to collect and view information in a tabular, graphical format. This feature is important because it helps me understand time-series data over one or two hours. It creates graphs, allowing us to check spikes and examine average values and 90th and 95th percentile values. This capability is useful for performance monitoring and issue identification. I believe it has helped speed up security investigations.

What needs improvement?

Data retention can be better. If we want to look at the data for five months or six months, that is not available to us. We only have a history of 20 or 30 days. After that, the information gets lost. That is a drawback. 

Splunk's dashboards are pretty basic. In comparison to Grafana, the dashboards are not as detailed. There is room for improvement in that area.

For how long have I used the solution?

I have been using it for about one and a half years now.

What do I think about the stability of the solution?

It is stable. I have not encountered any stability issues so far.

What do I think about the scalability of the solution?

It is easy to scale. We have multiple instances, sub-instances, and prod instances running, so scalability is not a problem.

It is being used by development teams, QA teams, performance teams, and security teams. We have about 500 people using it.

How are customer service and support?

It is good. I have not had any major issues where support was lacking, so I would rate it positively.

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

In this organization, I did not use any similar solution. In my previous organization, we used APM tools like Dynatrace and AppDynamics, which helped us monitor real-time data and performance. Splunk is a similar tool but offers more capabilities and is also cost-effective.

It was an organizational decision to go with Splunk Enterprise Security. It involved financial considerations and the kind of deal Splunk provided, as we are using the enterprise version and another version. Economics, capabilities, and support were factors.

How was the initial setup?

I was not involved in its deployment. When it comes to maintenance, another team looks after it and takes care of maintenance.

What was our ROI?

I have not been involved in the finance part, so I cannot comment on ROI or costs. However, preventing incidents or solving performance issues saves money, converting time saved to money. Customers are happy. Employees are happy. There is less downtime.

What's my experience with pricing, setup cost, and licensing?

I am not aware of the costs; that is handled by a separate team. I only use it for logs and performance issues.

What other advice do I have?

Instead of going for the cheapest solution available, you should go for the one that meets your needs. It takes time for an organization to onboard a new solution, so it is important to choose the right solution from the start. I believe all available solutions are pretty good, so you should see what suits you better.

It is a great tool. If you learn to navigate it, you can access a wide range of information about any application or product. It is a very helpful tool, provided you know how to use it. 

Overall, I would rate it a nine out of ten.

Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
PeerSpot user
Mahmoud Younes - PeerSpot reviewer
Cyber Security Architects at VaporVM
Real User
Top 5Leaderboard
Apr 17, 2026
Security monitoring has improved and now covers diverse attacks with rich incident management
Pros and Cons
  • "When I compare it to different SIEM solutions, Splunk Enterprise Security has incident management and a threat intelligence component that is native and not limited the way different SIEM solutions are."
  • "The price is a significant concern. It is expensive and is designed for enterprise companies, not for small or medium-sized companies."

What is our primary use case?

There are a thousand use cases covered. Splunk Enterprise Security covers the MITRE ATT&CK framework for initial access, remote executions with malicious codes, and many other attack vectors. All use cases are covered by MITRE ATT&CK, including initial access, executions, discovery, and credential access.

What is most valuable?

When I compare it to different SIEM solutions, Splunk Enterprise Security has incident management and a threat intelligence component that is native and not limited the way different SIEM solutions are. It also has scoring features, including user scoring and correlations that the normal Splunk Enterprise doesn't have. In Enterprise, you have detection mapping to the MITRE ATT&CK framework. The GUI is very easy to use, and by using SPL, you can find or mine data easily. You can create custom dashboards. These are many benefits when compared with IBM QRadar or FortiSIEM for on-premises SIEM solutions.

However, this solution is for enterprise companies, not for small or medium businesses. Splunk Enterprise Security has many integrations and connectors that are easy to use when compared with IBM QRadar or normal Splunk Enterprise.

What needs improvement?

The price is a significant concern. It is expensive and is designed for enterprise companies, not for small or medium-sized companies.

Another area for improvement is the machine learning capabilities. There is no native AI or machine learning in Splunk when compared with different SIEM solutions. While it is there, it requires manual setup.

For how long have I used the solution?

I have been working with Splunk for two years.

What do I think about the stability of the solution?

There are no stability challenges. Even when creating a report, incident, or dashboard, or when parsing data, everything functions very smoothly. There are no challenges that I have observed.

What do I think about the scalability of the solution?

It is easy to scale. You can deploy it in containers or directly on-premises. It can also be used in the cloud. However, for distribution, you need some experience if you are running indexers and search heads. If you install it as an all-in-one solution, it is fine, and anyone can install it.

How are customer service and support?

The customer service is helpful. Even if you face something that does not have a direct solution, you can create a workaround. Issues are resolved on time.

Which solution did I use previously and why did I switch?

I deployed QRadar and Wazuh before.

How was the initial setup?

The initial setup does not take too much time. It can be completed quickly when compared with another product. The setup takes approximately 80 minutes.

What about the implementation team?

We are an MSSP, and we perform POCs or production implementations and recommendations for some customers. We are also a partner with Splunk. I am working with Cisco, and Cisco is a partner with Splunk.

What was our ROI?

For ROI measurement, I integrated Splunk with FortiSOAR. In FortiSOAR, I can calculate the ROI and the time for closing alerts. However, I have not tried this within Splunk itself.

Which other solutions did I evaluate?

For threat detection, I integrated Splunk with MDE and Falcon. For normal threat detection, you can enable threat feeds from MISP or SOCRadar to create rules and check if events have any malicious IOCs to trigger alerts.

FortiSOAR and XSOAR are also alternative solutions.

What other advice do I have?

Even if you face something that does not have a direct solution, you can create a workaround. Issues are resolved on time. Splunk uses a very customizable SPL language. You can search easily, and for me, it is better than EQL in Sentinel or IBM QRadar. I would rate this product a 10.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer. MSP
Last updated: Apr 17, 2026
Flag as inappropriate
PeerSpot user
Security Consultant at Matiq
Consultant
Top 20
Jun 12, 2025
Reduces manual intervention and enables comprehensive security monitoring with risk-based insights
Pros and Cons
  • "The features of Splunk Enterprise Security that I have found most valuable include the risk-based score and UBA/UEBA, user behavior analytics, or user and entity behavior analytics."
  • "Areas of Splunk Enterprise Security that could be improved include the need for training and certifications. We are planning to do certifications, and there are many features, such as risk-based score and score detection, where the current training doesn't provide visibility to the analyst."

What is our primary use case?

My usual use cases for Splunk Enterprise Security involve creating notables, use cases, and dashboards. We are creating the use cases as per the defense of depth in all the security layers, such as the network layer or data link layer, DLP protection, and network protection. We are using firewalls and proxy, as well as IPS, and we are using Defender as Cloud App Security of 365 and EDR. We are using Defender as a single pane of glass, collecting all the logs from all the security devices, writing the correlation rules, configuring the notables, and monitoring 360 degrees of the organization's security.

How has it helped my organization?

It is a comprehensive solution with many security-related features. The data enrichment feature helps identify any anomalies from devices and users. It helps identify any malicious activity patterns, risks, or login failures. 

We have implemented conditional policies where traffic from certain countries gets blocked. We are utilizing the Splunk Machine Learning Toolkit (MLTK) app to create models for automatic actions or remediation. We are trying to catch the true positive incidents and orchestrate a response. We have created two models to identify brute force attacks and user login failures.

What is most valuable?

The features of Splunk Enterprise Security that I have found most valuable include the risk-based score and UBA/UEBA, user behavior analytics, or user and entity behavior analytics. Based on this feature, we can identify anomalies in any activity from the user or device. 

It serves as a single pane of glass for all the security-related events. It helps cross-correlate with minimal manual intervention, detect true positives, and take remediation steps in an orchestrated manner. It is very efficient. It's a top solution in Gartner Quadrants and Datamatics.

What needs improvement?

Areas of Splunk Enterprise Security that could be improved include the need for training and certifications. We are planning to do certifications, and there are many features, such as risk-based score and score detection, where the current training doesn't provide visibility to the analyst. They should offer training based on the features we use. For any future enhancements or features, such as MLTK and SOAR platform integration, we need more visibility, training, and certification for the skilled professionals who are working.

For how long have I used the solution?

I have been working with Splunk Enterprise Security for seven years.

What do I think about the stability of the solution?

This solution is stable. The platform and the applications we are dealing with are stable and maintain high availability both on-prem and cloud.

What do I think about the scalability of the solution?

Scalability-wise, we find it comfortable. It's convenient to scale up or scale down the licenses or the components in the cloud.

How are customer service and support?

When we require support from the Splunk Enterprise Security team, if we raise a request, they respond based on priority, providing recommendations or best practices as per the platform recommendations.

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

I work with multiple customers. They use different products, such as Trend Micro XDR. The customer I am working with right now is using Splunk Enterprise Security. It was chosen by the customer.

How was the initial setup?

For deploying Splunk Enterprise Security, we follow a cluster environment for high availability and high performance, maintaining an architecture with several search heads, indexers, and forwarders. Data is pushed from all forwarders to the indexers, which are heavy forwarders where indexing, parsing, and normalization are performed. Once it is done, we search the data through search heads, with a license master and deployment server present to push configurations to all components of Splunk Enterprise Security. It's a distributed and clustered environment we are maintaining.

What was our ROI?

We have seen a return on investment. We are getting more security. We are able to secure the environment from all security threats and maintain an environment that is free from threats and attacks, especially cyberattacks.

What's my experience with pricing, setup cost, and licensing?

Pricing and licensing are quite high compared to other tools or SIEM tools, but the features justify it.

What other advice do I have?

Overall, I would rate Splunk Enterprise Security a nine out of ten.

Which deployment model are you using for this solution?

Public Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Manager of Security Operations Center at Wipro Limited
Real User
Top 20
Sep 2, 2024
Helps ingest data, enhances business resilience and problem-solving capabilities
Pros and Cons
  • "The two features I appreciate most in Splunk Enterprise Security are the content management system and the inter-incident review dashboard."
  • "They could offer pre-built search queries for everyday use cases like brute force attacks, DDoS attacks, and other security threats."

What is our primary use case?

I have created various correlation searches to develop use cases for detecting security threats. For example, I have created use cases to identify brute force attacks, unauthorized access, denial of service attacks, and distributed denial of service attacks. To date, I have developed a total of 190 use cases for our environment using Splunk Enterprise Security.

How has it helped my organization?

The end-to-end visibility provided by Splunk Enterprise Security is crucial. Its user-friendly interface makes it easy to navigate and configure. The intuitive options allow for simple customization, enabling users to easily select and configure settings. This feature, combined with the excellent support from the Splunk team, makes it a valuable tool for addressing enterprise security issues and creating or modifying use cases.

Splunk's website provides a variety of simple commands for identifying security events. These commands and pre-built security fields make it easy to detect real-time attacks, monitor environments, and identify security threats. Splunk offers a more straightforward and efficient approach than other monitoring tools.

Splunk automatically ingests and normalizes data, eliminating the need for human intervention. When data is ingested, it is automatically converted into index-friendly formats within most source pipes.

The MITRE ATT&CK framework is a valuable tool for security teams, and its integration with Splunk Enterprise Security offers significant benefits. By mapping specific MITRE ATT&CK tactics to Splunk use cases, analysts can quickly identify the root cause of security incidents and access relevant information for remediation. For example, if a brute force attack occurs, an analyst reviewing the incident can quickly determine the corresponding MITRE ATT&CK tactic and access detailed information about the attack, including potential solutions, mitigation strategies, and potential future actions. This seamless integration between MITRE ATT&CK and Splunk empowers security teams to respond to threats more effectively and efficiently.

Splunk has significantly enhanced my business resilience and problem-solving capabilities. Due to the urgency of different issues, there are four types of Splunk support cases: P1, P2, P3, and P4. P1 cases are incredibly critical and require immediate attention. If a business-critical issue arises, I can open a P1 case, and the Splunk support team will respond within 15 minutes. This rapid response has enabled me to resolve critical issues promptly. For P2 cases, the support team typically connects within two to three hours. P3 cases receive a response within 24 hours. Overall, the Splunk support team consistently resolves issues efficiently.

After deploying the use case, we immediately observed the benefits of Splunk Enterprise Security. We can instantly monitor enterprise security use cases in our environment without delay. However, as a precautionary measure, we deploy use cases and monitor them for seven days. If the use case does not generate excessive noise within this period, we deploy it to the final environment. Otherwise, we refrain from deployment. Splunk's capability allows us to deploy use cases within seconds.

Splunk helps me consolidate all the data, such as networking and cyber security data. If there are other types, such as behaviour analysis, we can perform them with the help of Splunk. But I'm mainly in the cyber security field, so I am more concerned with Splunk for cyber security data only. For example, in my PhD, I created my thesis based on medical performance monitoring. I monitor the performance health condition of one million people with the help of Splunk. So, this is not a cybersecurity use case I'm creating there. I monitor the health condition with the help of a Splunk Enterprise. If a health condition is significant, the alert immediately goes to the doctor, physician, and their relative.

My alert volume has decreased significantly. Splunk is a machine that generates alerts based on specific use cases or service queries. Before implementing a new use case or alert, we must analyze how many alerts it will trigger. If it generates fewer than one alert per day, it's acceptable. However, I will only deploy it if it generates one daily alert. This approach allows me to reduce the alert volume effectively using Splunk Enterprise Security.

Splunk streamlined my security investigations by consolidating logs into a single repository. The Splunk community provided invaluable assistance, enabling me to quickly find answers to my security-related questions and address concerns promptly. By leveraging the collective knowledge of the global community, I expedited my security processes and enhanced overall security measures.

Splunk reduces the mean time to resolve because it enables L1 SOC analysts to view relevant data in the power role field directly. For example, when a brute force attack alert triggers, analysts can easily see the source IP, time of the alert, user, destination IP, and other critical fields. This immediate access to information allows for swift preventive measures, countermeasures, and efficient resolution of cybersecurity issues. Splunk's clear and intuitive interface empowers even junior analysts with only one year of experience to effectively apply their knowledge and address security challenges.

What is most valuable?

The two features I like most in Splunk Enterprise Security are the content management system and the inter-incident review dashboard. The incident review dashboard allows us to directly view significant events triggered by the use cases I've configured within the content management system.

What needs improvement?

I suggest that Splunk provide the same resources on its platform, as on other websites through Google. For instance, they could offer pre-built search queries for everyday use cases like brute force attacks, DDoS attacks, and other security threats. These queries would be generated based on my specific data, saving me the time and effort of creating them manually. This would be incredibly beneficial and align with the AI capabilities already present in Splunk Enterprise Security.

For how long have I used the solution?

I have been using Splunk Enterprise Security for eight years.

What do I think about the stability of the solution?

In the eight years I have used Splunk Enterprise Security, I have experienced no stability issues. There has been no downtime or crashing. The only problems I have encountered were temporary interruptions in some features, lasting approximately 15 minutes.

What do I think about the scalability of the solution?

Splunk Enterprise Security is highly scalable. For example, I currently have one terabyte of data to deploy, and tomorrow, I need to deploy ten terabytes. In that case, the system can easily accommodate the increased load without compromising performance. It is extremely fast and efficient, ensuring no issues even as the input data volume grows. The system adjusts quickly to meet the demands of expanding data requirements.

How are customer service and support?

I have contacted Splunk technical support three times in the past fifteen days due to various issues encountered while using Splunk. Each time I reached out, they responded promptly and assisted me in resolving the problems.

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

I have used several alternatives to Splunk, such as AppDynamics, Dynatrace, and Oracle Enterprise Manager. However, I have found Splunk Enterprise and Splunk Enterprise Security the most effective tools for my needs. These platforms are easy to use, allowing for flexible parameter customization and dynamic adjustments to meet specific requirements.

How was the initial setup?

The initial deployment of Splunk Enterprise Security was straightforward due to my prior experience learning and using various tools. I found it to be significantly easier to implement than similar software.

I set up my lab independently, being new to the environment at the time and eager to learn. I visited the Splunk website and discovered the free courses they offer. Using these courses, I successfully configured my lab. Splunk provides valuable assistance for setting up personal labs and offers a 60-day trial version. This version allows for direct log setup and hands-on practice of Splunk skills without cost.

What's my experience with pricing, setup cost, and licensing?

Splunk Enterprise Security's pricing is competitive. For instance, the cost typically increases proportionally with the daily license volume. For example, purchasing a 100 GB license per day is less expensive than buying one GB per day. A discount is offered for larger volume purchases.

What other advice do I have?

I would rate Splunk Enterprise Security eight out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
PeerSpot user
reviewer2755902 - PeerSpot reviewer
Security Analyst at a computer software company with 51-200 employees
Real User
Top 10
Sep 15, 2025
Out-of-the-box detections have supported threat identification while integration consolidates alerts from multiple sources

What is our primary use case?

I use other types of security solutions that integrate or import data into Splunk Enterprise Security, such as EDRs, firewalls, and other security products. The integration supports my security operations by providing one clear view of threat detections from firewalls and imported data.

What is most valuable?

The features of Splunk Enterprise Security that I appreciate the most are out-of-the-box detections. These features have benefited my organization because it's a product we sell, and we sell detecting threats in the organization.The features have benefited the organizations I sell to because without them a lot would have been self-programmed, and they support us in very different ways.

What needs improvement?

It's difficult to answer how Splunk Enterprise Security can be improved because I'm hearing AI mentioned frequently in the keynote. It's definitely out there and it's improving the whole process. I think that a lot of effort is going into the realization of AI, but some effort is left out because they don't always mention that the outcome has to always be verified. You just say, 'Ask AI to narrow down the threats, show me how to write an email, summarize it up,' but the additional process that comes with it is verifying it all. Maybe question it, and sometimes it's wrong and you have to start over. I think improving it would be either having different AI responses to cover more, or always having to verify the user, not relying on an answer.

The most significant challenges I face when using Splunk Enterprise Security for advanced threat detection are not in the product; they're in the human aspect. Writing the query and knowing what to search for is not a product problem.

For how long have I used the solution?

I have been using Splunk Enterprise Security for two years.

How are customer service and support?

I would evaluate customer service and technical support for Splunk Enterprise Security as good on a scale of one to 10.

How would you rate customer service and support?

Positive

How was the initial setup?

My experience with pricing, setup cost, and licensing is that it's expensive.

What's my experience with pricing, setup cost, and licensing?

I think the value of Splunk Enterprise Security is there, but it is one of the most expensive solutions on the market.

What other advice do I have?

My organization uses risk-based alerting in Splunk Enterprise Security, which supports our SOC by negating through false positives. On a scale of one to 10, I would rate Splunk Enterprise Security an eight.

Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
PeerSpot user
Laurentiu Popescu - PeerSpot reviewer
Chief Product Officer at ClusterPower
Real User
Top 5
Aug 16, 2025
Customizable dashboards improve decision-making and efficient threat intelligence integration
Pros and Cons
    • "The ticketing platform could be improved."

    What is our primary use case?

    We are using the SIEM platform in our security operations center. We use it both for internal purposes, for monitoring the alerts coming from our network, as well as we have built security operation center services for our B2B customers. We are using QRadar, Splunk Enterprise Security, and more recently, we have added Elastic on top of it.

    What is most valuable?

    The features of Splunk Enterprise Security that I find the most useful include the event collector and the tool for analyzing the incidents. The dashboard that we use summarizes the alerts within a certain period of time. The customizable dashboard feature helps to improve the team's decision-making skills because it provides us with a clear image of the types of events that we have within a month, and we are able to classify them based on severity.

    What needs improvement?

    I do not really have any additional features that I would want to see in Splunk Enterprise Security. The ticketing platform could be improved. We are using our own ticketing platform right now, but we have integrated it into Splunk Enterprise Security to communicate and report back to our customers on the events to have constant interaction.

    For how long have I used the solution?

    I have been working with Splunk Enterprise Security for more than five years.

    What do I think about the stability of the solution?

    I have not faced any issues with stability or upgrades so far.

    What do I think about the scalability of the solution?

    Splunk Enterprise Security is easy to scale for scalability. We onboard more and more endpoints from our customer infrastructure without any issues scaling it up.

    How are customer service and support?

    We provide the Splunk Enterprise Security Threat Intelligence framework as a level three service for hunting and deeper inspection. We aggregate everything into a threat intelligence platform and provide feedback to our customers on their events.

    How would you rate customer service and support?

    Positive

    How was the initial setup?

    Splunk Enterprise Security is quite easy to set up, especially the on-premises solution.

    What about the implementation team?

    I have contacted Splunk Enterprise Security support for issues through a local partner that we work with. They provide the first level of support and in case there is a problem with the platform, they escalate it to the vendor.

    What was our ROI?

    Since implementing Splunk Enterprise Security, I have seen a return on investment. It is primarily a safety tool, so we do not expect a return on investment, but since we use the platform as an MSSP partner for Splunk Enterprise Security, we incur revenues for the services that we provide to our customers. We had a business case and the TCO looks quite acceptable.

    What's my experience with pricing, setup cost, and licensing?

    Splunk Enterprise Security is reasonably priced compared to other platforms, and the licensing model is quite flexible. Based on the gigabyte of data that we ingest on a daily basis, it is quite well positioned in the market.

    What other advice do I have?

    The event collector has been useful for us to gather logs from our customer's infrastructure. We have VPN connections with our customers, and we use the event collector to gather data from their network devices and incorporate it into the SIEM platform for further analysis.

    The integration of Splunk Enterprise Security with our existing security infrastructure has influenced our threat detection capabilities as we use it as an independent tool. We have other security tools in place, such as firewalls from FortiGate, from Fortinet. We have some endpoint protection solutions, but we have integrated everything into the Splunk Enterprise Security platform. We use it as an XDR platform to collect logs from different sources, from clouds, from active directory, from endpoints, from routers, from firewalls, from all the points in our customer's infrastructure.

    For the time being, we are quite satisfied with Splunk Enterprise Security. We are waiting for the AI engine to get more mature and to use it more extensively.

    I would rate Splunk Enterprise Security a nine out of ten.

    Which deployment model are you using for this solution?

    On-premises

    If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

    Other
    Disclosure: My company does not have a business relationship with this vendor other than being a customer.
    PeerSpot user
    Eko Kurniawan - PeerSpot reviewer
    IT Operations & Security at veris
    Real User
    Top 5
    Aug 25, 2024
    We can manage all the logs from every device on a single dashboard
    Pros and Cons
    • "Splunk can deliver more information by going deeper. By creating a dashboard, we can identify the root cause of the threat. Let's say I have a firewall from Check Point. Splunk will find the dashboard for Check Point, implement it in our environment, and connect it to the Check Point firewall logs, which are shown on the dashboard. If we request a custom dashboard, the engineer will take longer to complete the task."
    • "Splunk should align its security principles with those of other vendors like SentinelOne. Splunk has mature APIs that can communicate with various security applications and devices. Splunk can process more to produce an understandable dashboard."

    What is our primary use case?

    I work in the pharma industry, and I use Splunk to aggregate all my reporting logs for my firewall and Active Directory logs. We have anti-spam, web application firewalls, and other solutions to secure our perimeter. We use Splunk for log management and have a stack to transpose a log from the firewall to a VM. When we directly feed the firewall logs to Splunk, they become intermittent and freeze. 

    How has it helped my organization?

    The biggest benefit is that we can manage all the logs from every device on a single dashboard. I can put the log from the core system into Splunk to analyze for abnormal behavior and show that to the developer to improve it. Splunk can also analyze our security devices for security posture for CRM and ISO requirements, helping the organization obtain its ISO certificates.

    We started to see the benefits of Splunk when we created our first dashboard. Based on the dashboard information, we can get deep insights from the log, where we define a security incident or event and assign a score to repetitive events. For example, we receive brute force attacks, where the hacker attempts to try a thousand or a million passwords. This will trigger alerts on the dashboard or email. We are not monitoring 24/7, so we can get alerts from Splunk. We can detect threats faster from firewalls and antivirus. 

    The consolidation helps us identify the source of the threat faster. They can analyze the forensics to dig into information from the log and correlate the devices. A unified log from various devices can simplify the IT team's response and reduce the alert volume by 35 percent. 

    What is most valuable?

    Splunk can deliver more information by going deeper. By creating a dashboard, we can identify the root cause of the threat. Let's say I have a firewall from Check Point. Splunk will find the dashboard for Check Point, implement it in our environment, and connect it to the Check Point firewall logs, which are shown on the dashboard. If we request a custom dashboard, the engineer will take longer to complete the task. 

    I can create a custom dashboard for the firewall, antivirus, or endpoint protection. This will take time to complete because they need to understand the log type and mitigation of the process from the system or API.

    Splunk helps us manage our hybrid environment, including our email system. The main email system is Microsoft Exchange, which is deployed on-premise, and the second is Office 365. There isn't much security for the hybrid environment. We get logs from the web application firewall, the firewall, and the anti-spam solution. 

    What needs improvement?

    Splunk should align its security principles with those of other vendors like SentinelOne. Splunk has mature APIs that can communicate with various security applications and devices. Splunk can process more to produce an understandable dashboard.

    Splunk's latest version is much better than before. It's more resilient and powered by AI. It can ingest more complex logs. It will be better because we're using the legacy one.

    For how long have I used the solution?

    I have used Splunk for around six years.

    What do I think about the stability of the solution?

    I rate Splunk 10 out of 10 for stability. We've had no problems as long as we ensure we have capacity planning for the log system, which is growing every second. 

    What do I think about the scalability of the solution?

    I rate Splunk nine out of 10 for scalability. 

    How are customer service and support?

    I rate Splunk support eight out of 10. Support was great, and they responded quickly. 

    How would you rate customer service and support?

    Positive

    Which solution did I use previously and why did I switch?

    Splunk is our first SIEM, but we'd like to explore Wazuh more.

    How was the initial setup?

    It's hard to say whether deploying Splunk was straightforward or complex because sometimes the consultant did the work for us. I handled the operations side, and the consultant did the project itself. It was completed in two days. 

    What's my experience with pricing, setup cost, and licensing?

    Splunk is expensive. It's based on the data inside the log. If you produce bigger logs, the cost goes up. We pay a license up to a set size, let's say 100 gigabytes, and if we have 101, they charge us for the overage. We pay about a billion Indonesian rupiah. 

    There are many cheaper solutions. Microsoft Sentinel is also a little expensive, but there are cheaper ones like Wazuh, Graylog, and Rapid7.

    What other advice do I have?

    I rate Splunk Enterprise Security nine out of 10. If you want to use Splunk, you can try the free version, which goes up to half a gig. You can feed a log from the Active Directory. If you take that information directly from Active Directory, it will be hard to read. Splunk provides a good dashboard. 

    Splunk is an excellent choice for an organization that needs a fully scalable and highly customizable solution. We can customize the dashboard to combine all the device logs. Unfortunately, others still need to learn how to do that. It depends on an organization's needs and resources because it's not cheap.

    It's on the higher end of pricing, which can be a significant factor for small organizations with budget constraints. It's more appropriate for the enterprise level and companies with over 500 employees. 

    Which deployment model are you using for this solution?

    Public Cloud
    Disclosure: My company does not have a business relationship with this vendor other than being a customer.
    PeerSpot user
    Buyer's Guide
    Download our free Splunk Enterprise Security Report and get advice and tips from experienced pros sharing their opinions.
    Updated: July 2026
    Buyer's Guide
    Download our free Splunk Enterprise Security Report and get advice and tips from experienced pros sharing their opinions.