Our purpose for using Splunk Enterprise Security is SIEM.
Senior Information Technology Security Consultant at Mideast Data Systems
Saves a lot of time with powerful alerting and notification mechanism
Pros and Cons
- "I would definitely recommend Splunk Enterprise Security because if you are really concerned about security and want to follow compliance rules, this product is really helpful."
- "We can only increase the environment. For instance, with an ES server, we cannot make a cluster of ES. If you have two servers and want to make a cluster of these two servers for ES, that is not possible."
What is our primary use case?
How has it helped my organization?
Machine learning has been incredibly beneficial in our efforts to detect various threats. For example, we pull all security logs and utilize the MLTK framework, which helps us identify potential risks effectively. So, overall, it's been quite helpful.
We use the risk-based alerting feature. For instance, when it detects a failed login attempt, it assigns a risk score to it. This allows us to utilize the risk-based alerting features effectively to prioritize incidents based on their severity.
Risk-based alerting generates notifications based on the level of risk associated with a transaction. This approach effectively assists in monitoring transactions, such as payments. It allows us to track the progress of a transaction, from initiation to completion, and identify any errors that may occur during the process. If there are numerous errors, we can assess the risk and determine whether the transaction might be a false positive.
Splunk Enterprise Security has been very helpful in this regard. However, I've noticed that improvement is still needed. We need to analyze the data more thoroughly. While this can be quite complex, finding a simpler solution would be beneficial.
What is most valuable?
The best features of Splunk Enterprise Security are the correlation rules and automation over the correlation rules. We can trigger alerts and notifications. The alerting and notification mechanism is really powerful and good.
What needs improvement?
It needs more AI integration. The threat intelligence framework requires some AI functionality, which would be helpful.
Buyer's Guide
Splunk Enterprise Security
July 2026
Learn what your peers think about Splunk Enterprise Security. Get advice and tips from experienced pros sharing their opinions. Updated: July 2026.
909,647 professionals have used our research since 2012.
For how long have I used the solution?
We have been using Splunk Enterprise Security for a couple of years, and I have been on the ES team for the last year. I have also used it in my previous company.
What do I think about the stability of the solution?
The stability of Splunk Enterprise Security rates at eight out of ten.
What do I think about the scalability of the solution?
It is scalable. We can only increase the environment. For instance, with an ES server, we cannot make a cluster of ES. If you have two servers and want to make a cluster of these two servers for ES, that is not possible. There is only one server, and if you want to increase scalability, you must increase the RAM and memory for that same server. The scalability is an eight out of ten.
We simply request Splunk support to increase our storage or make other adjustments as needed. We don't have access to AWS; all of that is managed by Splunk. We just need to reach out to them and say, "Please increase our storage by one terabyte," and they can handle that for us.
How are customer service and support?
Technical support for Splunk Enterprise Security is very good. We have daily calls. They are very helpful, rating at nine out of ten.
Which solution did I use previously and why did I switch?
We tried LogScale in the past, but it has very limited functionalities and not a proper UI. It offers approximately 10% of Splunk Enterprise Security's capabilities. We haven't found any solution comparable to Splunk Enterprise Security.
How was the initial setup?
We utilize a combination of both cloud and on-premises setup. Specifically, we use Splunk Cloud for search indexes and other things. On the on-premises side, we have our heavy forwarders, standard forwarders, and user-defined forwarders. So, we effectively integrate both approaches.
The deployment for Splunk Cloud is very easy. They have predefined templates and setups on the AWS end. They utilize many AWS features. If you terminate any indexer, it will spawn up again. This type of automation exists with Splunk Cloud, making it really efficient.
It doesn't require any maintenance, but when we are doing batch upgrades, we need downtime, which is acceptable. It's four to five hours of downtime.
What about the implementation team?
Currently we have a team of seven people for Splunk Enterprise Security, with additional staff using Splunk Cloud and related services.
What was our ROI?
Splunk Enterprise Security helps to save a lot of time, which is our main purpose. Whenever something is wrong in our environment, we immediately get an alert. It saves time and costs. Compared to traditional methods, Splunk Enterprise Security saves approximately 40% to 50% of time.
What's my experience with pricing, setup cost, and licensing?
For small customers, Splunk Enterprise Security is quite expensive. For my team with a substantial budget, the cost is acceptable.
What other advice do I have?
I would definitely recommend Splunk Enterprise Security because if you are really concerned about security and want to follow compliance rules, this product is really helpful.
Splunk Enterprise Security helps save significant time and money, which most customers are looking for. It is easy to configure and manage. If you have certification or basic knowledge of Splunk Enterprise Security, it provides excellent job opportunities. The solution provides numerous helpful dashboards where you can directly check threats and other metrics.
Overall, I would rate it an eight out of ten.
Which deployment model are you using for this solution?
Public Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Amazon Web Services (AWS)
Disclosure: My company has a business relationship with this vendor other than being a customer. partner
Works at a marketing services firm with 1,001-5,000 employees
Extensive customization facilitates threat detection but integration with cloud and Git needs improvement
Pros and Cons
- "The product is generally stable and forgiving."
- "The GUI, now called Mission Control, which serves as issue management or ticket management, falls below what would be considered industry standards."
- "The AWS add-on is particularly problematic, with most inputs requiring manual writing due to lack of out-of-box functionality."
What is our primary use case?
My use cases for Splunk Enterprise Security are extensive in production. I utilize it for all available functions including observability, asset management, vulnerability management, threat detection, network security, identity management, and various other capabilities.
How has it helped my organization?
The solution does require a lot of customization for an organization.
What is most valuable?
It is highly customizable, which is a significant advantage. It requires substantial customization and tailoring to particular organization requirements, meaning that out of the box, most features would need configuration.
What needs improvement?
The risk and notables component, particularly the two-tier system of picking something from risk into the notable, is one of the most problematic features.
The GUI, now called Mission Control, which serves as issue management or ticket management, falls below what would be considered industry standards.
AI assistance for security analysts to analyze notables and risks needs improvement. Although it exists, the demonstration is not yet sufficient for the required level. We need this as soon as possible to help security analysts.
Splunk Enterprise Security is not cloud environment-friendly, especially when dealing with large cloud infrastructures. With significant AWS presence and multiple clouds, collecting asset data is challenging. The AWS add-on is particularly problematic, with most inputs requiring manual writing due to lack of out-of-box functionality.
Regarding the platform and Enterprise Security specifically, the lack of Git-friendly or Git-native integration is problematic. The recently introduced content management system is inadequate, attempting to implement an outdated concept of storing rule versions in an index while teams work with Git natively.
The storage of queries in savedsearches.conf prevents efficient work with query text. It should be structured as separate SPL files that can utilize intellectual add-ons for Visual Studio Code and work natively with GitHub. Content management is limited to applications within the Enterprise Security suite, excluding custom applications not starting with SA or DA.
For how long have I used the solution?
I have been using Splunk Enterprise Security for more than five years.
What do I think about the stability of the solution?
The product is generally stable and forgiving.
What do I think about the scalability of the solution?
When considering Enterprise Security in particular, it demonstrates good scalability.
How are customer service and support?
I contacted their technical support recently. The support provided is decent, though they often reference their knowledge base. For publicly available solutions, this can be redundant as these solutions can be found through internet searches. Support becomes valuable when dealing with issues requiring access to their closed knowledge base for faster responses.
While support provides solutions, implementation can be complex. In a recent case, the provided solution was so complex to implement that I decided not to proceed. The support staff themselves are highly knowledgeable, polite, and responsive, with some being exceptional. The support team deserves a perfect score.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
I have experience with similar solutions such as AlienVault and ArcSight, each with its advantages and disadvantages. The recommendation depends on the working environment. For cloud-native and GitHub-native organizations, the Enterprise Security solution should align with those principles.
How was the initial setup?
I was solely responsible for the implementation.
It was one of the most difficult deployments I've ever handled. After we set up a cluster with consultants, we made it usable after a year and a half.
Splunk Enterprise Security requires continuous maintenance, consuming approximately 50% of the time. The numerous data sources and constantly changing formats and source types demand ongoing work on data quality, detection rules, assets, and identities.
People are delegated for platform administration, though they currently need additional time to reach optimal performance levels.
What about the implementation team?
We did work with consultants during the deployment.
What's my experience with pricing, setup cost, and licensing?
The pricing is currently managed by procurement. Even with substantial company discounts, it remains extremely expensive. This creates internal challenges when teams independently choose open-source or less expensive solutions for log dumping. Duplicating application logs becomes costly as teams may already use DataDog, ELK stack, Elasticsearch, or S3.
With data ingestion of two terabytes or more daily, Splunk Enterprise Security costs become significant. Cloud-native solutions, particularly in AWS, make it more practical to use native security detection mechanisms such as Security Hub, GuardDuty, and Inspector, using Splunk Enterprise Security as a data aggregator.
Many users prefer pre-processing data before ingestion using the Databricks platform for large data sources such as cloud trail logs. The on-premises pricing model based on data ingestion affects Splunk Enterprise Security's market position.
What other advice do I have?
This product requires significant investment in learning as it is not easily understood. Organizations purchasing the solution should expect 6-12 months with a dedicated team before meaningful insights can be delivered.
On a scale from one to ten, Splunk Enterprise Security rates as a seven.
Which deployment model are you using for this solution?
On-premises
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Amazon Web Services (AWS)
Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
Buyer's Guide
Splunk Enterprise Security
July 2026
Learn what your peers think about Splunk Enterprise Security. Get advice and tips from experienced pros sharing their opinions. Updated: July 2026.
909,647 professionals have used our research since 2012.
Technical Lead at a tech vendor with 5,001-10,000 employees
Monitoring file transfers has become detailed and reporting now provides flexible, time-based insights
Pros and Cons
- "Splunk Enterprise Security has the capability to pull the report from anytime or any respective time, or if I need it from all the time, then it can be helpful."
- "Because we are using a licensed DataDog, which gives us more reliable results. And for file logs, we are using a BAM, a business audit and monitoring tool, which gives us a more visualized experience than Splunk Enterprise Security."
What is our primary use case?
Currently we are using Splunk Enterprise Security for monitoring the jobs and along with Splunk Enterprise Security, we are using DataDog where it will be used for monitoring the servers and our URLs.
Currently, we are using it only for monitoring because that is going to be decommissioned very soon. So we have only had it active for monitoring for the last four years.
Currently, we are using the on-premises and we are slowly going to be migrated to the cloud, and then we can use that for whatever we have existing. We can utilize it in the cloud.
Splunk Enterprise Security is only used for our MFT tool purpose, which is integrated with our MFT tool.
What is most valuable?
Splunk Enterprise Security has the capability to pull the report from anytime or any respective time, or if I need it from all the time, then it can be helpful. And we can also set the monitoring for a particular server, particular file type, or a particular user. Those are some of the good features which I really appreciate.
Threat detection is not something we use. Our TechSec team uses their own respective tools such as Qualys to pull out the reports. And apart from that, they mainly look into DataDog.
DataDog will give a more pictorial idea of what went wrong, where it lagged, and where the issue is. But Splunk Enterprise Security won't give that much pictorial detail.
Compared to other tools, Splunk Enterprise Security is kind of user-friendly.
Initially, it was helping us to give the logs and integrate with Splunk Enterprise Security and all.
What needs improvement?
The main challenge is that it runs on the Linux part. So that is a very big challenge for us where we have installed it on the Linux machine. And getting it moved out from the Linux machine is the biggest challenge for us currently. So it is not so friendly for us to do that. That is why we came up with DataDog and then Splunk Enterprise Security is going out.
Now, we currently have completed all the setups. We are currently using it on-premises, but going forward, we will be utilizing the cloud environment.
Because we are using a licensed DataDog, which gives us more reliable results. And for file logs, we are using a BAM, a business audit and monitoring tool, which gives us a more visualized experience than Splunk Enterprise Security.
For how long have I used the solution?
For five years.
What do I think about the stability of the solution?
Currently, there are no stability issues. I am not that good at providing any advice, but these are my few feedbacks.
What do I think about the scalability of the solution?
Currently, there are no scalability issues.
How are customer service and support?
Currently, customer service is limited.
Which solution did I use previously and why did I switch?
We are using a licensed DataDog, which gives us more reliable results.
How was the initial setup?
It is not a support kind of thing. It is just helpful for looking around the logs.
What about the implementation team?
Initially, it was helping us to give the logs and integrate with Splunk Enterprise Security and all.
Which other solutions did I evaluate?
Our TechSec team mostly uses DataDog.
What other advice do I have?
I am using a Globalscape, not Axway.
I am working on MFT and SSIS.
Splunk Enterprise Security is only used for our MFT tool purpose, which is integrated with our MFT tool. Otherwise, our TechSec team mostly uses DataDog.
The complete Splunk Enterprise Security itself is going out, going to be decommissioned. So we are not at all using it. So I do not think there will be any more advancement on that part.
Currently, we do not have it.
I do not have any details about that.
It has had some of it, but as we are moving out of it, we never look into it so deeply. For the time being, it will be just refixed.
It is a good product. I rate this product an overall 8 out of 10.
Which deployment model are you using for this solution?
On-premises
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Other
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Last updated: Apr 16, 2026
Flag as inappropriateManager cybersecurity at Hexion Inc.
Effectively monitors cybersecurity risks and improves IT landscape visibility
Pros and Cons
- "From a visibility perspective, the solution has significantly improved our organization by providing a single platform to visualize our entire IT landscape."
- "The best features I've experienced over the past six years with Splunk Enterprise Security are the ability to create use cases and the flexibility to customize searches and use cases based on our specific requirements."
- "Regarding room for improvement, I expect Splunk to provide information about new features on a regular basis, such as notifications about enhancements that may improve security posture."
What is our primary use case?
We use Splunk Enterprise Security for security monitoring purposes, and we have many security use cases configured to detect cybersecurity-related risks. We have 100+ use cases related to brute force attacks, ransomware, credential access attacks, et cetera.
We use it for the extra security layer since we want to be very proactive and monitor our infrastructure fully end-to-end.
How has it helped my organization?
We now have a single platform where we can visualize our entire landscape. It's improved our security posture. We can see all the logs getting ingested, and if there are any anomalies, we're able to visualize that as well. The alerts help us be very proactive. We used to miss a few things happening in our organization. Now we get alerts on time.
What is most valuable?
The best features I've experienced over the past six years with Splunk Enterprise Security are the ability to create use cases and the flexibility to customize searches and use cases based on our specific requirements.
It's user-friendly. You don't need to be an expert to create a use case. Even a basic understanding will allow you to do the work. There are lots of knowledge articles as well.
From a visibility perspective, the solution has significantly improved our organization by providing a single platform to visualize our entire IT landscape. This has also enhanced our security posture by enabling us to view all logs.
We do connect with a Splunk representative on a monthly basis. They can proactively provide us with solutions.
What needs improvement?
Regarding room for improvement, I expect Splunk to provide information about new features on a regular basis, such as notifications about enhancements that may improve security posture. I want these notifications to come to us quite regularly, as we always want to improve our security posture.
I'm interested in the notifications and alerts aspect, particularly since Splunk Enterprise Security's Mission Control feature was very proactive when it was rolled out.
For how long have I used the solution?
I have been using Splunk Enterprise Security for the last six years.
What do I think about the stability of the solution?
I would rate the stability at eight out of ten; we never had any gap in monitoring. That said, there were instances of backend issues that did not impact our monitoring.
What do I think about the scalability of the solution?
It is a scalable solution for our business, and I would rate it nine out of ten, as we have recently scaled it to monitor operational use cases.
How are customer service and support?
I would rate the technical support as nine out of ten. They are always on top of resolving issues, providing technical account manager details for further assistance.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
We had tried IBM QRadar and Azure Sentinel previously.
How was the initial setup?
If I need to set up Splunk from scratch, I don't have to do a lot of planning. It's pretty straightforward.
It took about a month to deploy Splunk Enterprise Security, as we took many days to plan how to set up the architecture.
There is some maintenance required once it is set up.
What about the implementation team?
The IT team exclusively uses Splunk Enterprise Security for assistance. The team is always there to assist.
What's my experience with pricing, setup cost, and licensing?
I don't deal with pricing. I have a fair understanding based on the market research; from what I've witnessed, the pricing is competitive.
What other advice do I have?
I rate Splunk Enterprise Security higher due to its user-friendliness. That is something on top of my list.
Splunk Enterprise Security is on top in terms of how users or administrators can manage it. Everything else looks pretty fine regarding the support we get from Splunk Enterprise Security.
I would rate Splunk Enterprise Security overall as eight out of ten.
Which deployment model are you using for this solution?
Hybrid Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
System Engineer - Security Presales at Raya Integration
Achieve comprehensive data visibility with versatile language
Pros and Cons
- "Splunk Enterprise Security's most valuable features are its stability and the robust Splunk Search Processing Language, allowing extensive customization and analysis capabilities."
- "Splunk simplifies real-time problem identification and resolution by seamlessly integrating existing customer and vendor systems."
- "Splunk could enhance its offerings by incorporating modules for network detection and response and fraud management, along with improving its threat intelligence management capabilities."
What is our primary use case?
After the acquisition by Cisco, we are focusing on our partnership with them as a Gold Partner and Tier One reseller. Following the acquisition, we also shifted our focus to Splunk. I am a system integrator implementing Splunk for customers in their environments.
How has it helped my organization?
Splunk has a vast integration with multiple vendors, which makes it easy for our customers to integrate various cloud environments.
Splunk provides complete visibility when integrated with all installed appliances and applications.
The threat intelligence management feature is a good add-on for startups, especially given its affordability.
Splunk allows organizations to ingest and normalize data effectively.
Splunk simplifies real-time problem identification and resolution by seamlessly integrating existing customer and vendor systems. Its customizable dashboards can be tailored to map and reflect specific environmental needs precisely.
The threat topology and MITRE ATT&CK framework features can help discover the full scope of a security incident, provided they are fully integrated into the customer's environment.
Splunk's comprehensive log visibility enables efficient investigation of malicious activities and breaches. By generating a dashboard that collects logs from firewalls, emails, proxy endpoints, and threat intelligence, Splunk can provide access to critical information within seconds, significantly reducing investigation time compared to other vendors or solutions. This streamlined process, facilitated by Splunk's ability to gather and analyze diverse log data, ensures swift identification and resolution of security incidents.
It helps our customers improve their organization's business resilience.
The unified platform helps consolidate networking infrastructure and security. This single-platform approach offers the advantage of combining multiple technologies and features, streamlining operations and enhancing efficiency.
Implementing Splunk with SOAR capabilities, along with machine learning and AI for alert filtering, can significantly reduce alert volume without constantly interrupting administrators. This streamlined approach ensures that only alerts requiring approval are sent to administrators, optimizing their workflow and efficiency.
The analysts using Splunk, even the free edition, are very satisfied with the information it provides for their investigations.
Splunk has helped customers accelerate their security investigations by integrating AI and machine learning into its platform. This integration automates many basic tasks and saves valuable time.
Splunk helps reduce our customer's mean time to resolve.
What is most valuable?
Splunk Enterprise Security's most valuable features are its stability and the robust Splunk Search Processing Language, allowing extensive customization and analysis capabilities.
What needs improvement?
Splunk could enhance its offerings by incorporating modules for network detection and response and fraud management, along with improving its threat intelligence management capabilities. Additionally, the pricing could be made more competitive.
For how long have I used the solution?
I have been using Splunk Enterprise Security for almost six months.
What do I think about the stability of the solution?
Splunk is a very stable platform.
What was our ROI?
My customers feel it's a good investment, but Splunk updated its price models recently.
What's my experience with pricing, setup cost, and licensing?
One of Splunk's two major disadvantages is its high cost. The platform requires significant financial investment and resources, making it expensive despite its comprehensive features.
What other advice do I have?
Splunk has disadvantages such as cost and resource requirements. However, once I invest, it's a powerful platform that ranks number one in SIEM and observability. I rate the product nine out of ten due to pricing concerns and threat intelligence management not being advanced.
I believe Splunk is the top SIEM tool. However, the term "enterprise security" is misused when applied to Splunk. While many vendors claim to offer "enterprise security," true enterprise security should cover all aspects of cybersecurity. Splunk excels in SIEM, SOAR, and UEBA, but it doesn't address other crucial areas like firewalls, PAM, or web/mail gateways. Therefore, Splunk shouldn't be categorized as an "enterprise security" solution. Although Splunk leads in SIEM with its superior visibility and observability, it lacks presence in other essential cybersecurity domains.
Which deployment model are you using for this solution?
Hybrid Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Other
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
Incident reviews and machine learning capabilities help identify and prevent incidents
Pros and Cons
- "The incident review in Splunk Enterprise Security seems to be the most helpful feature."
- "Splunk Enterprise Security is more advanced compared to other solutions, which makes it stand out as a better option."
- "It would be nice to have more advanced UEBA in Splunk Enterprise Security. Additionally, it would be beneficial if they offered more threat intel feeds for free."
- "One thing that I probably dislike the most about the Splunk product is their support."
What is our primary use case?
We use Splunk Enterprise Security for security monitoring.
How has it helped my organization?
Advanced correlation capabilities help to identify the patterns of malicious activities.
Machine learning capabilities in Splunk Enterprise Security have been effective for identifying and preventing incidents. Through machine learning, they correlate all the data and create notable events, which helps us identify malicious or suspicious traffic.
We have used the risk-based alerting a little bit. So far, it's been just fine. We haven't gone deep into it. Our other operations team hasn't utilized it to its full capacity, but it makes a pretty good filter overall.
The impact of automated responses provided by Splunk Enterprise Security has been very good on the efficiency of routine security operations.
What is most valuable?
The incident review in Splunk Enterprise Security seems to be the most helpful feature.
What needs improvement?
It would be nice to have more advanced UEBA in Splunk Enterprise Security. Additionally, it would be beneficial if they offered more threat intel feeds for free.
Furthermore, incorporating Attack Analyzer into the main product instead of having it as a separate paid purchase would be an improvement.
For how long have I used the solution?
I have been using the solution for about three years.
What do I think about the stability of the solution?
I've had an issue only once with one of their products, but overall, it's been pretty good.
What do I think about the scalability of the solution?
Its scalability is pretty good.
How are customer service and support?
For Splunk Enterprise Security, it's been pretty good. For the regular Splunk Enterprise Platform, overall, it's like a C-minus. One thing that I probably dislike the most about the Splunk product is their support.
How would you rate customer service and support?
Neutral
Which solution did I use previously and why did I switch?
I previously used LogRhythm. Splunk Enterprise Security is more advanced compared to other solutions, which makes it stand out as a better option.
How was the initial setup?
I deployed Splunk Enterprise Security using professional services, and overall, it was good. My main responsibility was handling the coordination. The full implementation took about four months.
Approximately 90% of maintenance is done by Splunk.
What about the implementation team?
The implementation was handled by myself.
We purchased Splunk Enterprise Security through a reseller called AccessIT.
What's my experience with pricing, setup cost, and licensing?
Splunk Enterprise Security is a bit expensive overall, but it provides good value.
What other advice do I have?
I would rate this solution an eight out of ten overall.
Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
Solutions Architect at a tech vendor with 1-10 employees
Unified monitoring has improved hybrid log visibility but pricing and compliance need refinement
Pros and Cons
- "The advantages of Splunk over its competitors include the unified platform which includes everything from security to logging."
- "There are sometimes issues with availability where you have to wait a bit longer."
What is our primary use case?
I have conducted research for some of our clients since I work in a consultancy firm, and customers sometimes have specific products. I made research on customer preference which usually leads them to go with Splunk.
We usually deal with Splunk for log management as a SIEM solution, where customers have logs on-premises and on the cloud and want to have a consolidated view. We recommend Splunk in these scenarios.
I am not very much aware of Splunk Enterprise Security; I research this and put it in my proposals mostly for log management.
Some of our customers are using the product.
I would generally recommend Splunk Enterprise Security for companies which are highly regulated or have to mandate certain compliances.
I would generally recommend it for bigger companies, not for smaller or mid-sized ones.
There are sometimes issues with availability where you have to wait a bit longer.
We deal with Splunk Essentials for certain customers, especially banks, who only need a SIEM solution.
What is most valuable?
The advantages of Splunk over its competitors include the unified platform which includes everything from security to logging. The real advantage is that they can deploy Splunk Cloud and have availability in the UAE region, especially because we deal with this within GCC and UAE mostly. Another advantage of Splunk Observability Stack is that you can deploy this solution on-premises completely, which is the product advantage I see.
It contributes to a reduction in analyst burnout or fatigue in our company because compliance mandates having a SIEM solution. Other than managing the logs on CloudWatch or using native tools or other tools, this platform has an edge by allowing you to query logs effectively, reducing the time to recover or find logs.
Splunk Enterprise Security has improved visibility across hybrid or multi-cloud environments, and they keep on improving their product, making it good for hybrid cloud as they have their on-premises stack and the cloud.
The consolidation of SIEM, SOAR, and UEBA into a single interface has improved our customers' operational efficiency as it allows correlation of logs, SIEM, and UEBA, thus enhancing customers' efficiency and reliance on the product while reducing the time to diagnose issues.
What needs improvement?
In terms of weaknesses and room for improvement, I do not see certain weaknesses, but it can get really tricky in terms of pricing if the log volumes are very high, as it can get costly, which is the only uncertain aspect I believe regarding this tool.
They should change the licensing model and make the pricing estimations more accurate to better account for logging and make the pricing a bit lower, especially for logs and analytics.
To make it closer to a perfect score, they could add more features related to security posture management and add certain compliances like GDPR and other regional-specific compliances to ensure that you comply with those and have that score built in. Although they have certain features, this can be further improved.
For how long have I used the solution?
I have been using this solution for six months.
How are customer service and support?
The technical support is good. If you have Enterprise support, their team understands the platform well, and I would rate them a seven, though sometimes there are issues with availability. Because of the issues of availability, sometimes you have to wait a bit longer.
What other advice do I have?
From the deployment perspective, it is not very difficult to deploy and integrate Splunk. They have good resources, and we usually deploy this on AWS without many challenges, as it deploys really well with pre-built stacks that you can use connectors with. We usually prefer the AWS Marketplace for purchasing. I would rate this product a seven overall.
Which deployment model are you using for this solution?
Hybrid Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Amazon Web Services (AWS)
Disclosure: My company has a business relationship with this vendor other than being a customer. Reseller
Last updated: Jul 15, 2026
Flag as inappropriateSection Head at Galaxy Chemicals Egypt
Improves our security posture and offers good reporting capabilities
Pros and Cons
- "The most valuable features of Splunk Enterprise Security are reporting capabilities. It is a good tool for checking systems and analyzing situations. I find it useful to check my systems and analyze situations."
- "Splunk's support is better, and its reporting is easier and better."
- "The documentation and training resources available for knowledge and training can be expanded. We need to learn more about Splunk Enterprise Security and new security attacks."
What is our primary use case?
My usual use cases for Splunk Enterprise Security include normal reporting.
How has it helped my organization?
Splunk Enterprise Security has positively impacted my organization by increasing security defense. It provides a good environment for defense.
What is most valuable?
The most valuable features of Splunk Enterprise Security are reporting capabilities. It is a good tool for checking systems and analyzing situations. I find it useful to check my systems and analyze situations.
What needs improvement?
The documentation and training resources available for knowledge and training can be expanded. We need to learn more about Splunk Enterprise Security and new security attacks.
For how long have I used the solution?
I have been working with Splunk Enterprise Security during the last year.
What do I think about the stability of the solution?
I would rate Splunk Enterprise Security an eight out of ten for stability. In security, nothing is 100%.
What do I think about the scalability of the solution?
I would rate the scalability of Splunk Enterprise Security an eight out of ten. I have not tried anything to scale up or scale out as it is a new setup, but I believe it will be easy for that.
How are customer service and support?
I would rate the technical support of Splunk a seven out of ten. Sometimes there are delays. It is related to their giving a response after some time.
How would you rate customer service and support?
Neutral
Which solution did I use previously and why did I switch?
I used QRadar. The switch from QRadar to Splunk Enterprise Security was a management decision. We moved to Splunk Enterprise Security because of its benefits. Splunk's support is better, and its reporting is easier and better. There are also pricing advantages.
How was the initial setup?
It is a normal process. It isn't complex, but it is a new setup with new interfaces and a new way of thinking. It is always a challenge to use new software, and it takes some time to get familiar with it.
What about the implementation team?
I can install Splunk Enterprise Security myself, though some things require dealing with external assistance.
What was our ROI?
We have not calculated ROI in our environment. I have not received any assignment or recommendation to calculate ROI.
What's my experience with pricing, setup cost, and licensing?
The pricing of Splunk Enterprise Security is somewhat high, but comparing it with its benefits, it's acceptable. It depends on the type of business.
What other advice do I have?
Overall, I would rate Splunk Enterprise Security an eight out of ten.
Which deployment model are you using for this solution?
Public Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
IT Developer/Architect at a government with 10,001+ employees
It integrates well, reduces alert volume, and we can customize the dashboards
Pros and Cons
- "Splunk Enterprise Security allows us to create custom dashboards by changing fonts and modifying widgets."
- "I've noticed that onboarding data from various multi-cloud sources and diverse products, such as security network devices, can be challenging."
What is our primary use case?
We use Splunk Enterprise Security for various security use cases, including writing correlation searches. This has significantly improved both our use cases and correlation searches. We can leverage existing resources, making modifications as needed, rather than starting from scratch each time. Splunk Enterprise Security provides diverse use cases across different environments, including AWS, Azure, and multi-cloud setups, while also integrating with Microsoft Sentinel. Additionally, we can integrate Splunk's service orchestration product for further automation. Overall, this allows us to automate tasks that security analysts previously performed manually, such as reviewing incident dashboards. We can fine-tune alerts based on analyst feedback. Splunk's research team ensures that use cases are updated with the latest security content, enabling us to understand and implement necessary steps while customizing them to fit our company's needs. This is what makes Splunk Enterprise Security so popular; it streamlines processes compared to legacy security products that often rely on manual scripts. Clients, including government agencies and banks, are transitioning to Splunk Enterprise Security due to its reduced training requirements and comprehensive features. Everything is consolidated, simplifying training and certification. Additionally, integrating Splunk's service orchestration product further automates tasks and improves response times. The substantial investment in Splunk indicates its staying power; no other product on the market currently offers comparable capabilities. Cisco's acquisition of Splunk reinforces its potential for success, combining APM, data logging, and security portfolios. In one financial project involving 600,000 users, we were able to monitor all incoming traffic, identify security activities, and distinguish between legitimate and malicious traffic, including phishing attacks and potential identity-based threats. Splunk enables tracking individual identities, crucial for detecting attacks where perpetrators hide behind compromised identities, often leading to data breaches and other security incidents.
We implemented Splunk Enterprise Security to assist with AWS security, which includes GuardDuty, CloudTrail, CloudWatch, and Inspector. These AWS components generate compliance and security alerts, which we correlate and use to create dashboard reports and identify security events for various use cases. We then enable the out-of-the-box use cases and send notable events to the dashboard. The implementation is currently in its early stages.
How has it helped my organization?
Splunk Enterprise Security operates based on incoming data, making monitoring multiple cloud environments relatively simple due to data availability and integration capabilities. Data from cCloudRail, CloudWatch, Azure, and other diverse environments can be incorporated. While occasional patching might be necessary, most integrations are readily available, offering extensive coverage without customization. Specific customizations might still be required, but most functionalities are pre-built, leveraging code developed by Splunk. This efficient approach involves analyzing data from vendors like Palo Alto and applying add-ons to apply code and automate parsing.
Our visibility into various environments depends on how much data we incorporate; therefore, the more we scan, the better our visibility.
Splunk Enterprise Security's insider threat detection capabilities act as a secondary approval and vetting process, helping our organization ensure there are no unauthorized users.
The MITRE ATT&CK framework allows us to identify criticality levels, helping us respond to incidents. We might integrate incident response with a REST API, where a notable event triggers the creation of a ServiceNow ticket. Information flows from ServiceNow back to Splunk, which then feeds other systems, enabling bidirectional incident management. These processes are largely out-of-the-box, as Splunk integrates well with ServiceNow, except for any customizations. We understand the data integration requirements and leverage Splunk's extensive integration capabilities.
Splunk Enterprise Security does a good job of analyzing malicious activities and detecting breaches. The amount of information the research and threat detection teams receive from Splunk enables faster threat detection of up to 60 percent, eliminating the need to consult numerous sources. This efficiency is a key benefit of Splunk, as its significant investment in security allows for expedited processes.
I have seen the older legacy product where they have this manual process to identify issues, run scripts, try to identify the output, and then go through ten systems to collect data. This could take days. Now, with Splunk, we have everything correlated with multiple use cases, and we have a correlation search between multiple systems, along with application data. Splunk Enterprise Security can stitch all this information together and show it in a single pane of glass, which makes decision-making faster and allows us to focus on the relevant issues instead of wasting time on non-relevant ones. They have done this well.
Splunk Enterprise Security significantly reduced our alert volume. The initial challenge was dealing with a legacy IBM system that generated a massive amount of unfiltered noise, making it difficult to identify relevant events to send to the incident dashboard. This process was time-consuming and inefficient, and the value of the system wasn't apparent. To address this, we fine-tuned both the SOAR system and Splunk by applying filters and conditions to focus on relevant data. Ultimately, Splunk reduced the alert noise from 1,000 events in two hours down to ten, which were then grouped into a single notable event. Despite potentially having hundreds of background events, Splunk condensed this information into a single, actionable item, allowing us to focus on investigating the most relevant issues.
Splunk Enterprise Security accelerates our security investigations by reducing noise, allowing us to focus on relevant use cases. Everything is categorized as high, medium, or low priority, and people immediately start investigating high-priority issues connected to PagerDuty. Sometimes, this leads to on-call situations, sometimes immediate action. Service orchestration and playbook scenarios enable automated responses, like instantly blocking unauthorized access to a system. The possibilities for security use cases with playbooks and service orchestration are vast, and I'm excited to explore them further in the coming days.
The dashboards and reporting capabilities help to aid our security analysis.
We have integrated Splunk Enterprise Security with various services to streamline our security operations. This integration allows us to leverage diverse data sources for creating lookups, data models, knowledge objects, and regular expressions. By automating the development of use cases and regular expressions, we can apply them to data more efficiently, enabling faster implementation and analysis. This approach enhances our ability to detect and respond to security threats effectively.
Splunk Enterprise Security has enhanced our organization's security posture by providing comprehensive security compliance dashboard reports.
What is most valuable?
I appreciate how Splunk Enterprise Security connects users to the research team and threat documentation, providing access to current events impacting other clients, security vulnerabilities, and relevant use cases. The platform's daily updates offer valuable insights for enhancing our security posture.
Splunk Enterprise Security allows us to create custom dashboards by changing fonts and modifying widgets. Those familiar with XML coding can further personalize dashboards to align with frameworks such as MITRE. Alternatively, we have the option to use the pre-built dashboards.
What needs improvement?
I've noticed that onboarding data from various multi-cloud sources and diverse products, such as security network devices, can be challenging. Although Splunk has simplified data onboarding with features like data managers, they need to improve their out-of-the-box parsing capabilities. While they've made significant progress, covering about 70 percent of common products, there's still a 30 percent gap where manual configuration is required. This forces us to spend time understanding and writing custom parsing rules instead of focusing on data analysis. With Splunk's recent acquisition by Cisco, I'm hopeful they will prioritize enhancing this functionality and increasing their coverage to 90 percent or more.
I want to see Splunk Enterprise Security dashboards incorporate more features, such as out-of-the-box AI and user behaviour analytics, which are accessible within a single dashboard.
The technical support response time has room for improvement.
For how long have I used the solution?
I have been using Splunk Enterprise Security for three years.
What do I think about the stability of the solution?
Splunk Enterprise Security has stability issues, especially with large data volumes, increased data intake, complex dashboards, custom models, and processing that significantly impact performance. Many customers experience this; even with demos using small datasets, performance degrades with millions of data points. This necessitates capacity planning, dedicated teams, and enforced best practices. These practices include restricting complex searches, blocking problematic users, and providing training to prevent performance degradation. Constant vigilance and proactive measures are crucial to maintaining a stable Splunk Enterprise Security environment. I would rate the stability of Splunk Enterprise Security five out of ten.
What do I think about the scalability of the solution?
I would rate Splunk Enterprise Security's scalability six out of ten. We need to add more shared CPU memory and increase the capacity, and scaling requires a lot of planning and effort.
How are customer service and support?
Splunk's support quality has declined in the past five years. Response times are now slower, and resolving an issue can take weeks. Submitting a ticket and connecting with the appropriate support agent often requires numerous emails and calls.
How would you rate customer service and support?
Neutral
Which solution did I use previously and why did I switch?
To improve security coverage and user experience, we replaced our outdated legacy solution with Splunk Enterprise Security.
How was the initial setup?
Our Splunk Enterprise Security cloud deployment utilizes a DevOps approach with a fully automated CI/CD pipeline. This automation has significantly improved our deployment speed, reducing the process from a week to a few minutes. Changes are made in the development environment and then automatically pushed to production after a click-through approval process. This streamlined workflow eliminates the previous manual process and associated delays, resulting in a faster and more efficient deployment cycle.
What's my experience with pricing, setup cost, and licensing?
Splunk Enterprise Security's pricing is based on data volume, which generally suits large enterprises.
What other advice do I have?
I would rate Splunk Enterprise Security eight out of ten.
Splunk is widely used across larger organizations. While large organizations often have extensive teams dedicated to Splunk projects and upgrades, smaller organizations can also use Splunk, taking advantage of more affordable pricing options like the free tier for limited data. Cost isn't a significant concern for larger organizations, who prioritize Splunk's security features and are willing to invest in its capabilities.
Splunk Enterprise Security is deployed across all departments, processing millions of data points. Over 500 people manage this data: building dashboards and reports, working with Enterprise Security, discussing use cases, and creating custom data models. This represents a massive effort for any large organization where every department utilizes Splunk.
Government departments are transitioning to Splunk, with daily onboarding increasing the current user base of 5,000.
Because the deployment is cloud-based, the Splunk DevOps team handles maintenance.
Splunk offers a resilient SIEM solution with comprehensive capabilities for research and a wide range of use cases. It is constantly updated, ensuring it remains a valuable and comprehensive SIEM package.
I recommend Splunk Enterprise Security. It is an excellent tool widely used by many organizations, making it a valuable choice for security information and event management.
Which deployment model are you using for this solution?
Public Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Amazon Web Services (AWS)
Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
Cybersecurity and Ethical Hacking at NUPAT TECHNOLOGIES
Detecting threats faster with end-to-end visibility and simple data import processes
Pros and Cons
- "Splunk Enterprise Security helps me detect threats faster depending on the type of log I'm using. If I have a current company's log, I can easily detect it faster."
- "The main improvement needed in Splunk Enterprise Security is its system visibility after installation."
What is our primary use case?
I use Splunk Enterprise Security to analyze logs and data. When it comes to hybrid or multi-cloud, Splunk Enterprise Security has helped me find events. I use event logging and event IDs, which has helped me.
What is most valuable?
Splunk Enterprise Security helps me detect threats faster depending on the type of log I'm using. If I have a current company's log, I can easily detect it faster.
The ability of Splunk Enterprise Security to import data is simple. It is not hard; it is just an easy task that gives me what I want.
The command line in Splunk Enterprise Security helps to search for specific queries, such as analyzing a security log to find login attempts and distinguish between failed and accepted passwords.
End-to-end visibility in Splunk Enterprise Security is something that is appreciated. Splunk Enterprise Security is easy to use.
The Threat Intelligence Management feature in Splunk Enterprise Security is applied and helps me to normalize the data.
Splunk Enterprise Security is part of the SIEM tool, so it helps me tremendously to do my work.
What needs improvement?
The main improvement needed in Splunk Enterprise Security is its system visibility after installation. When you install Splunk, you cannot see it on the system as an application. If you are unfamiliar with Splunk and download and install it, you will not see it as an application on your system. You have to go back to your browsing history to get the link and start using it again. Additionally, Splunk Enterprise Security does not always provide an immediate response to alerts on threats.
For how long have I used the solution?
I have been using Splunk Enterprise Security for three years now.
What do I think about the stability of the solution?
Scalability in Splunk Enterprise Security is satisfactory.
How are customer service and support?
I have not needed any help from the support team at Splunk before, so I have not required any assistance from them.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
Splunk Enterprise Security was the first solution I learned, and it remains the only one I am using now.
I use a whole lot of tools at the moment aside from Slunk. I use Wireshark, I use Kali, I use Splunk Enterprise Security, and I use Metasploit.
What other advice do I have?
Splunk Enterprise Security can make mistakes, so we do not solely rely on the out-of-the-box detections. It can also be part of a hybrid or multi-cloud environment. Everything depends on who teaches you Splunk Enterprise Security. Someone can teach you, and it becomes simple, or it can become complex. To me, it is not complex as I am experienced in using Splunk Enterprise Security.
I utilize Splunk Enterprise Security to analyze and conduct investigations as part of my job. There is minimal intrusion, so I receive few alerts regarding malicious threats. We do not have a partnership with them; we use it as a normal user through the internet.
Regarding sustainability, manufacturers must continually update their products, add new features, and optimize them. They need to optimize extensively because with threats and vulnerabilities, we always have to update to the latest features.
Overall, when it comes to performance and reliability, I rate Splunk Enterprise Security an eight out of ten.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Buyer's Guide
Download our free Splunk Enterprise Security Report and get advice and tips from experienced pros
sharing their opinions.
Updated: July 2026
Product Categories
Security Information and Event Management (SIEM) Log Management IT Operations AnalyticsPopular Comparisons
IBM Security QRadar
Splunk AppDynamics
Microsoft Sentinel
Elastic Security
IBM Turbonomic
Palantir Foundry
WhatsUp Gold
LogRhythm SIEM
Rapid7 InsightIDR
Elastic Observability
Buyer's Guide
Download our free Splunk Enterprise Security Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- Which would you recommend to your boss, IBM QRadar or Splunk?
- What are some of the best features and use-cases of Splunk?
- What SOC product do you recommend?
- Splunk as an Enterprise Class monitoring solution -- thoughts?
- What is the biggest difference between Dynatrace and Splunk?
- IBM QRadar is rated above competitors (McAfee, Splunk, LogRhythm) in Gartner's 2020 Magic Quandrant. Agree/Disagree?
- What are the advantages of ELK over Splunk?
- How does Splunk compare with Azure Monitor?
- New risk scoring framework in the Splunk App for Enterprise Security -- thoughts?
- Splunk vs. Elastic Stack

















