My main use cases for Splunk Enterprise Security have evolved over various roles, primarily focusing on the correlation of external threat intelligence in the notables existing in Splunk Enterprise Security, where we currently emphasize making it easier for our customers to bring in external threat intelligence such as from Recorded Future and correlate that against their entire telemetry to create notables indicative of alerts that could have been missed through traditional defenses.
Senior Product Manager at Recorded Future
Video Review
Improves threat detection by correlating external intelligence with internal alerts and reduced response times through enriched visibility
Pros and Cons
- "The feature I appreciate the most about Splunk Enterprise Security is the CIM data model, which allows users to bring in data from different technologies, such as firewalls, endpoints, and perimeter DMZs, enabling every device to pump data into Splunk Enterprise Security, with the data model normalizing all the data and placing it in a common plane."
- "Splunk Enterprise Security's risk-based alerting has been a game-changer for us, adding intelligence to alerts by considering behavioral or internal asset-based criteria, effectively helping us prioritize alerts and filtering out noise that can be ignored."
- "While Splunk Enterprise Security is powerful, it presents significant complexity for users, as it's not particularly user-friendly for beginners."
What is our primary use case?
What is most valuable?
The feature I appreciate the most about Splunk Enterprise Security is the CIM data model, which allows users to bring in data from different technologies, such as firewalls, endpoints, and perimeter DMZs, enabling every device to pump data into Splunk Enterprise Security, with the data model normalizing all the data and placing it in a common plane.
The main benefit of Splunk Enterprise Security features is the increased visibility of our data itself since we can pump in all the data from every security device within our enterprise, providing comprehensive visibility in a single pane of glass without needing to check every tool for individual alerts, allowing us to identify outliers and anomalies easily and build detection rules across multiple technologies.
Splunk Enterprise Security's risk-based alerting has been a game-changer for us. Previously, we were flooded with many alerts, leading to alert fatigue; now, risk-based alerting adds intelligence to alerts by considering behavioral or internal asset-based criteria, effectively helping us prioritize alerts and filtering out noise that can be ignored.
When it comes to leveraging Splunk Enterprise Security's dashboards and visualizations, we struggle to communicate our security posture effectively to leaders such as the CISO, yet Splunk Enterprise Security provides the ability to create tailored reports from generated data using correlations, macros, and specific metrics such as MTTR or MTTD, allowing us to convert this into strategic or tactical-level reports sent directly to the CISO for situational awareness.
Splunk Enterprise Security assists our SOC team in prioritizing and investigating high-fidelity alerts effectively after we triage and identify them; there are various ways to dig deeper, either by building search queries that expand the scope to other data sources or using adaptive response actions to gather additional context, aggregating everything inside Enterprise Security for a comprehensive investigation.
What needs improvement?
While Splunk Enterprise Security is powerful, it presents significant complexity for users, as it's not particularly user-friendly for beginners. I recommend focusing on building user-driven guided workflows to help newcomers navigate and efficiently use the platform through simple guides.
I also see room for improvement in the integration of Splunk SOAR, which currently has some limitations regarding its data use in downstream playbooks.
For how long have I used the solution?
I have been using Splunk Enterprise Security for approximately seven to eight years, starting even before my current role.
Buyer's Guide
Splunk Enterprise Security
September 2026
Learn what your peers think about Splunk Enterprise Security. Get advice and tips from experienced pros sharing their opinions. Updated: September 2026.
915,287 professionals have used our research since 2012.
What do I think about the stability of the solution?
I find Splunk Enterprise Security to be generally reliable and stable, as we haven't experienced issues with downtime or crashes despite having a single-node cluster, which has been sufficient for our operational needs.
What do I think about the scalability of the solution?
One of the main reasons we moved to Splunk Enterprise Security is its ability to scale with our growing needs, as it easily accommodates additional compute and storage, and even for on-premises deployment, it simplifies the process of adding those resources as we expand our telemetry.
How are customer service and support?
I would give Splunk customer service an okay rating since they handle standard queries with clear responses; however, the experience can vary when tailored queries arise, sometimes leading to delays in communication, which highlights areas for possible improvement.
Which solution did I use previously and why did I switch?
Before adopting Splunk Enterprise Security, we relied on a couple of open-source tools, yet soon realized they weren't scaling to our needs, prompting the decision to switch to a more scalable solution backed by support.
What was our ROI?
From my point of view, the biggest return on investment when using Splunk Enterprise Security comes from its flexibility to bring any data into the platform for visibility, which is hard to achieve with other platforms; this capability, combined with features such as UEBA and risk-based alerting, reduces the need for full-time employees in my SOC while allowing easy integration with external threat intelligence to reveal hidden threat patterns, resulting in reduced MTTD, MTTR, and enhanced situational awareness.
What's my experience with pricing, setup cost, and licensing?
I don't directly handle pricing, yet my experience indicates that Splunk tends to be on the expensive side as a SIEM platform, so I suggest users consider a phased deployment starting with Splunk Cloud or Splunk ES and then expanding capabilities over time rather than embarking on a full deployment initially.
What other advice do I have?
In our strategy to combat insider threats and advanced persistent threats, Splunk Enterprise Security plays an important role with its UEBA features, helping us identify outliers from baseline behavior that assists in detecting anomalies or insider threats that may otherwise slip through traditional defenses.
I advise organizations considering Splunk Enterprise Security to proceed if you are already a big Splunk shop with an underlying platform deployed, as it seamlessly integrates with your existing data and allows easy onboarding of additional technologies within the Splunk ecosystem without additional overhead.
Considering the overall performance, I would rate Splunk Enterprise Security as an eight out of ten, recognizing it as a powerful platform within our SOC toolkit.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer. Partners
IT Orchestration Architect at Penn State University
Reduces detection and response times significantly by enabling analysts to manage end-to-end incidents through a single pane of glass
Pros and Cons
- "I evaluate customer service and technical support as excellent."
- "An example of how these features benefited my organization is that the mean time to detect compromised accounts from the time that we're able to detect that account and then launch some automation to actually disable the account and work with the end user to fix the issue has gone from taking a couple of days to literally taking two to three minutes."
- "I find the process for customizing, developing, testing, deploying, and refining detections in Splunk Enterprise Security to be challenging at times. It takes some of our more advanced engineers to be able to work through a lot of those processes."
What is our primary use case?
My primary use cases for Splunk Enterprise Security are correlation searches and the workflow that enables our SOC analysts to work through an entire incident from start to finish.
How has it helped my organization?
An example of how these features benefited my organization is that the mean time to detect compromised accounts from the time that we're able to detect that account and then launch some automation to actually disable the account and work with the end user to fix the issue has gone from taking a couple of days to literally taking two to three minutes.
What is most valuable?
The features of Splunk Enterprise Security that I value most are the correlation searches, being able to bring multiple things together and to have one result to look at in a single pane of glass.
What needs improvement?
I'm not sure how Splunk Enterprise Security can be improved, but I'm sure it will be improved; the features that they add, I constantly never even think of. One of the big things is making it a little easier for the intro analyst to be able to understand and work through without a lot of dedicated training.
For how long have I used the solution?
I've been using Splunk Enterprise Security for probably about the last two years.
What do I think about the stability of the solution?
I would assess the stability and reliability of Splunk Enterprise Security as having not experienced any issues that would be in the realm of Splunk's.
What do I think about the scalability of the solution?
Splunk Enterprise Security has scaled very well with the growing needs of my organization. We started out with a smaller deployment and now we're ingesting multiple terabytes of data a day and being able to scale as much hardware as we can throw at it.
How are customer service and support?
I evaluate customer service and technical support as excellent. Anytime that we've had an issue, we've been able to engage with Splunk support, and we also have agreements with some other folks that help us out, some private organizations that we leverage.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
Prior to adopting Splunk Enterprise Security, we were just using Splunk Enterprise and formulating our own searches and finding stuff ourselves.
How was the initial setup?
I find the process for customizing, developing, testing, deploying, and refining detections in Splunk Enterprise Security to be challenging at times. It takes some of our more advanced engineers to be able to work through a lot of those processes.
The challenges with deploying something like Splunk Enterprise Security are getting the data in, knowing what data you need, and trying just to find it and normalize it. It's such a vast area and we're such a distributed organization, trying to get all that information in one place has been a challenge.
What about the implementation team?
The process to expand usage has been smooth.
What was our ROI?
I have absolutely seen a return on investment with Splunk Enterprise Security. I can say that just because of the time that the analysts would take, and I can say that we have saved man-hours, which in the end is money. On average, my SecOps team takes probably at least a quarter of the time, if not more, to remediate security incidents with Splunk Enterprise Security compared to our previous solution.
Now that we can show that we're able to reduce that mean time to detection, we're getting a lot more buy in. So a lot more people are interested in that, and they're excited about that. So that really helps out.
What's my experience with pricing, setup cost, and licensing?
I'm not familiar with the setup costs.
What other advice do I have?
The advice I would give to other organizations considering Splunk Enterprise Security is to work with professional services. It's a large undertaking for your SOC, so work with professional services that have seen different examples and situations and lean on their expertise to help you develop the right solution.
I would rate Splunk Enterprise Security overall on a scale of one to ten as probably about an eight; there's still some work to be done, however, it's the best that we can do right now.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Buyer's Guide
Splunk Enterprise Security
September 2026
Learn what your peers think about Splunk Enterprise Security. Get advice and tips from experienced pros sharing their opinions. Updated: September 2026.
915,287 professionals have used our research since 2012.
Detection Engineer at a tech vendor with 10,001+ employees
Planning security use cases has given my team a solid overview and improves threat coverage
Pros and Cons
- "Splunk Enterprise Security has positively impacted my organization as it is a solid tool that gives us a great overview, and that overview helps my team by ensuring us that we are covered for cyber security attacks."
- "Splunk Enterprise Security has not helped reduce my team's average mean time to resolve, as they find it hard to use Splunk, and they are more used to Sentinel."
What is our primary use case?
My main use case for Splunk Enterprise Security is developing use cases. A specific use case I have developed with Splunk Enterprise Security is click fix detections.
To develop those click fix detections in Splunk, I first look up whether there are any applicable detections in Splunk Enterprise Security content updates and if there are some viable detections, I use them.
I have a big challenge with my main use case since I administrate five different instances and do not have access to detection as code, so it would be helpful to find a way where you can administrate multiple instances at once.
What is most valuable?
The best features Splunk Enterprise Security offers are probably the content updates where new detections are being developed that are useful. Whenever the content updates are released, I look through to see if there's anything interesting.
Splunk Enterprise Security has positively impacted my organization as it is a solid tool that gives us a great overview. That overview helps my team by ensuring us that we are covered for cyber security attacks.
What needs improvement?
Splunk Enterprise Security can be improved by finding a way to administrate multiple instances at once.
It should be easier to import custom detections in Splunk Enterprise Security, as if you have a detection in one place, you shouldn't need to copy and paste it into a new detection; it should allow an easy way to import it without detection as code.
For how long have I used the solution?
I have been using Splunk Enterprise Security for four years.
What do I think about the stability of the solution?
Splunk Enterprise Security is stable.
Which solution did I use previously and why did I switch?
I did not previously use a different solution before Splunk Enterprise Security.
Which other solutions did I evaluate?
I did not evaluate other options before choosing Splunk Enterprise Security.
What other advice do I have?
Splunk Enterprise Security has not helped reduce my team's average mean time to resolve, as they find it hard to use Splunk, and they are more used to Sentinel.
Splunk Enterprise Security's risk-based alerting has decreased the alert volume a tiny bit.
I haven't used the threat topology and MITRE ATT&CK framework features, so I cannot assess how they help discover the overall scope of an incident.
The integration of threat intelligence directly into the TDIR workflow has not improved my ability to preemptively block threats, as it is not that important.
I would advise others looking into using Splunk Enterprise Security to start planning. I rate this product a 9.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner, Reseller
Last updated: Sep 17, 2026
Flag as inappropriateinformation security architect at a energy/utilities company with 1,001-5,000 employees
Security monitoring has improved visibility and supports efficient AI-driven incident response
Pros and Cons
- "Splunk Enterprise Security has positively impacted my organization by improving efficiency and visibility by allowing us to take quicker action on the information that we're seeing that needs to be actionable."
What is our primary use case?
I have been using Splunk Enterprise Security for four years.
My main use case for Splunk Enterprise Security is for our preparation for our SOAR deployment.
I use Splunk Enterprise Security through dashboards and alerts for that.
What is most valuable?
The best features Splunk Enterprise Security offers include ease of use.
The interface makes it easy to use for me.
Splunk Enterprise Security has positively impacted my organization by improving efficiency and visibility. It has improved efficiency and visibility by allowing us to take quicker action on the information that we're seeing that needs to be actionable.
What needs improvement?
I don't have any recommendations on how Splunk Enterprise Security can be improved.
For how long have I used the solution?
I have been using Splunk Enterprise Security for four years.
What do I think about the stability of the solution?
Splunk Enterprise Security is stable.
What do I think about the scalability of the solution?
Splunk Enterprise Security's scalability works efficiently.
How are customer service and support?
Customer support for Splunk Enterprise Security is excellent.
I give the customer support a 10 on a scale of 1 to 10.
Which solution did I use previously and why did I switch?
I don't have that data on whether we previously used a different solution, as that was before my time.
What was our ROI?
I have seen a return on investment with Splunk Enterprise Security, certainly doing more with the current team size. We didn't really have the ability to bring a whole lot of SOC analysts on, and with this tool, we're really able to leverage more with the current staff that we have.
What's my experience with pricing, setup cost, and licensing?
My experience with pricing, setup cost, and licensing has been fairly smooth with our sales rep and continued support throughout the purchase and deployment of new features.
Which other solutions did I evaluate?
I did not evaluate other options before choosing Splunk Enterprise Security.
What other advice do I have?
Regarding Splunk Enterprise Security's AI capabilities, it is definitely helping our organization in building our guardrails.
Regarding Splunk Enterprise Security's AI capabilities, its accuracy and reliability of output are satisfactory.
Splunk Enterprise Security's risk-based alerting, RBA, has led to increased productivity, while alert volume remains the same.
I assess the threat topology or MITRE ATT&CK framework features of Splunk Enterprise Security as quickly giving us the ability to see where in the MITRE ATT&CK framework the information we're receiving applies.
My advice to others looking into using Splunk Enterprise Security is to ask peers and other entities that are using it. I would rate this product 9 out of 10.
Which deployment model are you using for this solution?
Hybrid Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Last updated: Sep 16, 2026
Flag as inappropriateHead Of Solution Engineer at a security firm with 201-500 employees
Unified security monitoring has improved threat detection speed and strengthened proactive defense
Pros and Cons
- "Splunk Enterprise Security is rated highly by Gartner as a top player for SOC monitoring and SIEM monitoring, playing a critical role in improving cyber resilience across multiple organizations, including at a national level deployment."
- "Scalability may become a challenge when deploying Splunk Enterprise Security due to licensing based on ingestion GBs, while cloud-based solutions such as Microsoft Sentinel offer more flexibility without requiring additional infrastructure resources."
What is our primary use case?
The main use cases for Splunk Enterprise Security are that the majority of my clients use it for getting complete visibility in their entire ecosystem, including IT, OT, and IoMT devices, by bringing telemetry from those sources, sending it to Splunk, and asking us to configure customized use cases and integration with some SOAR platforms, whether it's from Splunk or from third parties like Fortinet or Palo Alto.
How has it helped my organization?
With the unified workflow, it has impacted my ability to triage and investigate events by reducing the time needed for correlation and notification creation since previously using stand-alone solutions made correlation difficult due to multiple dashboards being involved.
Splunk has helped to reduce my clients' team's average MTTR and MTTD metrics significantly due to the unification of the different tools.
Splunk Enterprise Security is rated highly by Gartner as a top player for SOC monitoring and SIEM monitoring, playing a critical role in improving cyber resilience across multiple organizations, including at a national level deployment.
Business resilience, in terms of cybersecurity, has improved because Splunk Enterprise Security helps predict, identify, and solve problems in real-time.
What is most valuable?
What I like about Splunk Enterprise Security is the licensing model and deployment model it supports, allowing deployment on-premises or in the cloud, along with the native integration offered by Splunk Enterprise Security from a log source perspective.
The main benefits that Splunk Enterprise Security brings to my customers include the recent new features, which incorporate the SOAR platform and user behavior analytics, adding significant value to the overall offering from Splunk Enterprise Security.
The native UEBA capabilities have enhanced the visibility into unknown, sophisticated, and insider threats, as we have found lateral movement threats and identity-related threats using UEBA features.
The consolidation of SIEM, SOAR, and UEBA into a single interface has improved my team's operational efficiency because my customers are looking for a single pane of glass for complete visibility from the UEBA, SIEM monitoring, and EDR monitoring perspectives, which Splunk Enterprise Security addresses very well.
ES Essentials has improved my visibility across hybrid or multi-cloud environments.
Splunk Enterprise Security has helped to detect threats faster because when the ecosystem is fully based on Splunk Enterprise Security, with native integration across the SIEM, SOAR, and UEBA functions, it increases detection speed, although external factors such as the quality of threat intelligence also play a role.
The integration of threat intelligence directly into my workflow has improved my ability to preemptively block threats by augmenting Splunk Enterprise Security with SOAR and enhancing the overall SOC monitoring capabilities.
It has changed my approach to proactive defense significantly, providing visibility into active threats both locally and globally, and enabling me to perform threat hunting with IOCs.
Splunk Enterprise Security's Risk-Based Alerting has impacted the alert volume and analyst productivity by reducing false positives, particularly when integrating EDR solutions with Splunk Enterprise Security, which tend to produce a lot of noise.
I assess the threat topology and MITRE ATT&CK framework features as helpful in discovering the overall scope of incidents, as we create use cases mapped to the framework, usually covering around 60 to 80% depending on the customer's vertical and their attack surface.
Splunk Enterprise Security has improved the daily work experience and retention for my security team.
What needs improvement?
I would like to see improvement in the default dashboarding options, allowing for customization to avoid dependency on third-party solutions such as Microsoft Power BI.
There aren't any specific missing features I can think of at this time, but I can check with my SOC team for their feedback.
For how long have I used the solution?
I have been working with Splunk Enterprise Security for approximately 12 to 15 years.
What do I think about the stability of the solution?
My experience with Splunk Enterprise Security's stability has been fantastic, with no issues so far.
What do I think about the scalability of the solution?
Scalability may become a challenge when deploying Splunk Enterprise Security due to licensing based on ingestion GBs, while cloud-based solutions such as Microsoft Sentinel offer more flexibility without requiring additional infrastructure resources.
How was the initial setup?
I find the setup process for Splunk Enterprise Security very straightforward, and our engineering team loves deploying it.
What was our ROI?
Overall, I find Splunk Enterprise Security cost-effective, providing a good ROI compared to other cloud-based SIEM solutions such as Microsoft Sentinel, especially because you only pay for specified usage without extra costs for data movement.
What's my experience with pricing, setup cost, and licensing?
The pricing aspect, including setup cost and licensing, is satisfactory because we're happy with the level of discount we receive as part of our partnership tier.
Which other solutions did I evaluate?
In comparison to Microsoft Sentinel and other SIEM products, I don't have negative feedback about Splunk Enterprise Security, as it offers a significant number of native integrations and is a mature product with valuable new capabilities.
What other advice do I have?
ES Essentials has improved my visibility across hybrid or multi-cloud environments.
I'm not sure what the current version of Splunk Enterprise Security is, but I need to check.
I utilize AI in Splunk Enterprise Security, but I recently went through Splunk Enterprise Security's documentation and couldn't find much on AI capabilities. I need to check the official Splunk Enterprise Security documentation for updates on AI.
I haven't personally experienced a reduction in analyst burnout or fatigue, but I know our SOC analysts love working on Splunk Enterprise Security.
My advice for organizations considering Splunk Enterprise Security is to look for a licensing model that doesn't restrict data ingestion, perhaps a perpetual license that allows scalability with added infrastructure, particularly for larger enterprises. I would rate this product a 9 out of 10.
Which deployment model are you using for this solution?
On-premises
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Other
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
Last updated: Jul 15, 2026
Flag as inappropriateSoc L1 Engineer at Softcell Technologies Limited
Incident review has improved threat detection and AI now reduces noise for faster investigations
Pros and Cons
- "AI in Splunk Enterprise Security improves the accuracy, and the AI feature has helped me reduce false positive alerts, which prevented me from wasting time on junk alerts and separating the noise from the actual true positive alerts."
- "Writing SPL queries is tough at first with Splunk Enterprise Security, and the system gets a bit slow when searching through a large amount of data."
What is our primary use case?
My use cases mainly involve using Splunk Enterprise Security to monitor security threats, checking the dashboard for any alerts, looking at logs to see what is actually happening, and using the built-in searches to identify suspicious alerts regarding security or suspicious activity.
What is most valuable?
I appreciate the incident review dashboard as the best feature, as it makes it very easy to track alerts and manage them in one single interface.
AI in Splunk Enterprise Security improves the accuracy, and the AI feature has helped me reduce false positive alerts, which prevented me from wasting time on junk alerts and separating the noise from the actual true positive alerts. It makes my detection much more reliable.
Risk-based alerting in Splunk Enterprise Security is very helpful. Instead of getting overwhelmed by hundreds of small, low priority alerts, it gives me a risk score to users or machines based on their activity.
Using MITRE ATT&CK is really helpful. Splunk Enterprise Security automatically maps alerts to the MITRE ATT&CK framework, so when an alert triggers, I can see exactly which stage of an attack is happening, such as lateral movement, reconnaissance, or credential access tactics. This gives me a clear picture of what the attacker is trying to do.
What needs improvement?
Writing SPL queries is tough at first with Splunk Enterprise Security, and the system gets a bit slow when searching through a large amount of data.
For how long have I used the solution?
I have been using Splunk Enterprise Security for four months overall.
What do I think about the stability of the solution?
I did see lagging with Splunk Enterprise Security. Even when I have a huge amount of data coming in, it doesn't crash or hang. I haven't faced any major downtime. Once the configurations are set, it runs quite reliably in the background without needing constant attention.
What do I think about the scalability of the solution?
Splunk Enterprise Security is pretty flexible regarding scalability. Whenever our data volume grows, I can easily add more indexers or searchers to handle extra load, and it's straightforward to expand.
How are customer service and support?
Other analysts contact the support team if there is any need to understand the latest updates from the Splunk community, but I haven't contacted them.
Which solution did I use previously and why did I switch?
I have used an open-source Wazuh SIEM tool as an alternative. I prefer Splunk Enterprise Security more.
How was the initial setup?
The initial deployment of Splunk Enterprise Security had the main challenge of connecting all our data sources like firewall and server and making sure the data was flowing correctly. It wasn't a simple click and run. It required good planning to get all the data logs showing up properly.
What's my experience with pricing, setup cost, and licensing?
The pricing for Splunk Enterprise Security is a little bit high compared to other similar tools.
What other advice do I have?
Splunk Enterprise Security helped me in many ways. It really helped me reduce noise. Since it groups similar alerts together, I don't have to look at every single small thing. It filters out unimportant information, so I can focus on real threats.
Maintaining Splunk Enterprise Security is necessary to keep things running smoothly. I regularly check if all the logs are coming in properly. I also spend time updating and tuning searches or reducing the false positives.
I have not upgraded to Splunk Enterprise Security 8 yet.
I haven't seen any reduction in my mean time to resolve or my mean time to detect. I would rate this review an eight overall.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Last updated: Jun 5, 2026
Flag as inappropriateCyber Security Associate at SAP
Improves business resilience and reduced incident remediation time through real-time risk identification
Pros and Cons
- "The ability to identify risks as they come in is quite good."
- "Better education for users would be beneficial as they often don't know what they don't know or how to look for certain features."
What is our primary use case?
My main use cases for Splunk Enterprise Security include detection engineering tasks. I work with the SIM team handling various responsibilities, specifically ensuring uptime availability and correct log ingestion.
How has it helped my organization?
Splunk Enterprise Security has helped improve my organization's business resilience. We have definitely been able to get significant value out of it.
What is most valuable?
As an administrator, I mainly ensure other people can use the system effectively rather than using it extensively myself.
My impressions of Splunk's ability to predict, identify, and solve problems in real time are solid. I definitely notice when it makes predictions and helps with what we're trying to find in general. The ability to identify risks as they come in is quite good.
The integration of disparate security solutions supports our security operations by providing multiple methods to handle things. We have 21 lines of business with different Splunk pods, each requiring different solutions.
Personally, the integration creates some challenges, particularly when trying to standardize processes and migrate to Splunk Cloud. Managing different Splunk pods on-premises and separate stacks leads to confusion and time inefficiencies.
The process for customizing, developing, testing, deploying, and refining detections in Splunk Enterprise Security works adequately. While I don't write the detections myself, I work closely with those who do, and it doesn't seem to be an issue.
Our Security Ops team's incident remediation time has improved significantly. Previously, it took approximately 11 hours, but now it takes a few hours, though we're still working to reduce this time further through our migration to Splunk Cloud.
What needs improvement?
There are ways Splunk Enterprise Security can be improved, though I might be speaking specifically about my organization's implementation. Better education for users would be beneficial as they often don't know what they don't know or how to look for certain features.
Regarding ease of use, Splunk Enterprise Security is adequate. The challenge arises when we have multiple users trying to differentiate between the regular search head and the Enterprise Security search head. While users can accomplish their tasks, the main issue stems from education rather than the platform itself.
For how long have I used the solution?
I have been using Splunk Enterprise Security for three years, with a six-month break in between. I have been using it extensively for the last year.
What do I think about the stability of the solution?
The stability and reliability of Splunk Enterprise Security is very good. While we've experienced some downtime, crashes, and performance issues, these were caused by end users running poorly optimized queries rather than system problems.
What do I think about the scalability of the solution?
Splunk Enterprise Security scales effectively with our organization's growing needs. We haven't encountered any problems with scalability.
How are customer service and support?
I would rate customer service and technical support from Splunk at nine out of ten. I have had nothing but good experiences with Splunk support, receiving timely and helpful replies. In one instance, when I needed immediate support, I received a call within ten minutes of submitting the ticket, and we resolved the issue promptly.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
I am uncertain if my organization used another solution prior to adopting Splunk Enterprise Security. I believe we have been using Splunk the whole time, but this predates my joining the team.
How was the initial setup?
The deployment is fine. I don't really have much of a problem with that end of things.
What was our ROI?
I have seen a return on investment with Splunk Enterprise Security.
What's my experience with pricing, setup cost, and licensing?
I am not familiar with the pricing of Splunk Enterprise Security. Regarding licensing, we face some challenges. The management of different pods makes it confusing and complicated, but it gets resolved by our senior team members.
Which other solutions did I evaluate?
I use disparate security solutions that integrate or import data into Splunk Enterprise Security. We utilize many different tools.
What other advice do I have?
I would advise other organizations to consider Splunk Enterprise Security as it's an easy solution to implement and effective for its intended purpose.
On a scale of one to ten, I rate Splunk Enterprise Security an eight.
Which deployment model are you using for this solution?
On-premises
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Other
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
Security Analyst at a comms service provider with 10,001+ employees
Risk-based alerting has improved threat visibility but still needs better alert volume control
Pros and Cons
- "Splunk Enterprise Security has had a positive impact on our organization by allowing us to detect new things with RBA."
- "I have observed that the Risk-Based Alerting feature of Splunk Enterprise Security has not had a positive impact on the volume of alerts or on analyst productivity."
What is our primary use case?
My main use of Splunk Enterprise Security in my organization is to create detection rules for our clients.
Notably, the detection rule that I created with this tool is the RBA rules, Risk-Based Alerting, that we have used for many clients.
To implement an RBA rule with Splunk Enterprise Security, we took the templates provided by Splunk and adapted them to our needs, allowing us to detect things we were not able to detect before, such as pen tests.
What is most valuable?
The best features offered by Splunk Enterprise Security are the unified interface for managing content, whether it is detection rules, lookups, and so forth, and the identity part, which I think is the most important.
What I particularly appreciate about the unified interface and identity management is that it allows us to apply priorities to assets and identities and therefore respond in the best way to the alerts we receive.
Splunk Enterprise Security has had a positive impact on our organization by allowing us to detect new things with RBA.
What needs improvement?
The improvement I would like to see made to Splunk Enterprise Security is a unified interface across several Splunk tenants to manage our clients' Splunk content from a single place.
For how long have I used the solution?
I have been using Splunk Enterprise Security for five years.
What do I think about the stability of the solution?
I find Splunk Enterprise Security stable in daily operation, and there is nothing to note about that.
What do I think about the scalability of the solution?
Regarding the scalability of Splunk Enterprise Security in my different environments, I find it fairly slow, and new features take quite a long time to be developed.
How are customer service and support?
I rate the customer support for Splunk Enterprise Security depending on the context, and on certain topics, we have considerable trouble finding information.
How was the initial setup?
Splunk Enterprise Security is deployed in my organization in various ways since we are a service provider and it all depends on our clients' choices. We have on-premises, we have cloud, and we have various other configurations.
What about the implementation team?
My company has a commercial relationship with this vendor other than as a customer because we are a partner, reseller, and service provider, so we advise and give guidance to our clients.
What was our ROI?
I have not seen a return on investment with Splunk Enterprise Security, and I cannot share concrete indicators such as time savings or human resource savings.
What other advice do I have?
I do not have information on whether I have noticed a reduction in the mean time to resolve incidents (MTTR) thanks to Splunk Enterprise Security.
I have observed that the Risk-Based Alerting feature of Splunk Enterprise Security has not had a positive impact on the volume of alerts or on analyst productivity. On the contrary, it has actually generated quite a lot of alerts that are even longer to analyze, and the benefit is not necessarily immediate.
I do not really have an opinion on the Threat Topology features or the support for the MITRE ATT&CK framework in Splunk Enterprise Security in helping me discover the scope of an incident.
I have not noticed an improvement in the speed of threat detection thanks to Splunk Enterprise Security.
I would rate this review seven out of ten.
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner, Reseller, Service Provider
Last updated: Sep 17, 2026
Flag as inappropriateSIEM engineer at a tech vendor with 10,001+ employees
Security platform has unified triage and alerts and provides structured incident response
Pros and Cons
- "Splunk Enterprise Security has positively impacted my organization by giving our SOC a place to triage and respond to incidents and alerts as they come in, allowing us to respond to cyber incidents."
- "My assessment of customer support is that it is terrible."
What is our primary use case?
My main use case for Splunk Enterprise Security involves knowledge object development, detection engineering, data normalization, and alerting.
A specific example of how I use Splunk Enterprise Security in my day-to-day work is creating Splunk TAs to map non-normalized data to the Common Information Model.
What is most valuable?
The best features Splunk Enterprise Security offers include one single pane of glass for all your data, normalization, RBA built-in, assets and identities, detections, and everything built into one area.
Out of those features, I find myself relying on normalization and data models most often because that is how we structure our alerts to fire off all of our different data sources.
Splunk Enterprise Security has positively impacted my organization by giving our SOC a place to triage and respond to incidents and alerts as they come in, allowing us to respond to cyber incidents.
What needs improvement?
I believe Splunk Enterprise Security could be improved by costing less.
Splunk Enterprise Security's risk-based alerting, RBA, has slightly raised our alert volume because we have not turned off old alerts, but the fidelity of the alerts that RBA has provided us has been advantageous for uncovering true positives.
For how long have I used the solution?
I have been using Splunk Enterprise Security for about five years.
What do I think about the stability of the solution?
Splunk Enterprise Security is stable on-premises, but in the cloud, we have had numerous outages.
What do I think about the scalability of the solution?
I would not know about Splunk Enterprise Security's scalability because it is not managed by us.
How are customer service and support?
My assessment of customer support is that it is terrible.
What was our ROI?
I would say we have seen a return on investment because Splunk Enterprise Security has been sufficient for our operational and SOC needs, which have allowed us to provide security as a service to the enterprise.
What's my experience with pricing, setup cost, and licensing?
My experience with pricing, setup cost, and licensing shows that pricing is massively high.
Which other solutions did I evaluate?
Before choosing Splunk Enterprise Security, we are continuously evaluating other options, but none seriously at the moment.
What other advice do I have?
We do not use Splunk Enterprise Security for business resilience; we mainly use ITSI and some custom workflows that have been developed by other people than me.
We annotate our detections; however, as far as helping us operationally, the threat topology and MITRE ATT&CK framework features are not very impactful.
The consolidation of SIEM, SOAR, and UEBA into a single interface is not available to us yet.
My advice to others looking into using Splunk Enterprise Security is to keep it on-premises.
Which deployment model are you using for this solution?
Public Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Amazon Web Services (AWS)
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Last updated: Sep 16, 2026
Flag as inappropriateDevOps&Cloud Engineer Mentee at CertDirectory.io
Reduces alert fatigue, and it's well-documented and well-designed
Pros and Cons
- "Splunk Enterprise Security is fast and well-documented, and user interface and user interaction are well-designed compared to other SIEM solutions."
- "Splunk Enterprise Security is great but can have some frustration points. It can sometimes be slower to use."
What is our primary use case?
My main use case is for log management and checking the logs. We have rules running in Splunk Enterprise Security. We are using it as a main SIEM solution for our customers.
How has it helped my organization?
Alert fatigue is a common issue with security solutions, but Splunk Enterprise Security reduces alert fatigue. When we encounter real incidents, we get to dive deeper to check out the main cause of that incident. It is useful because it reduces alert fatigue.
What is most valuable?
The best feature of Splunk Enterprise Security is the documentation. Splunk Enterprise Security's documentation is well-organized. For example, if you have a problem or if you want to read about what you're looking for, you can easily go there and read from the documentation. It also has many resources worldwide. It is a de facto standard of the SIEM solutions. For example, I have used IBM QRadar, which is another solution many companies are using.
One of the most beneficial use cases for me is that Splunk Enterprise Security is fast. I cannot speak to how the SIEMs work in the backend, but I can say it is fast to find any logs.
Its UX and UI experience is getting better. It is much better than one year ago. Some of the buttons and other features are much easier to locate and choose. The user interactions are much better than one year ago. The advanced queries are much faster. The UI design is much better. That is one of the best changes that happened in one year.
What needs improvement?
AI is an area that has room for improvement in Splunk Enterprise Security. I would say that AI plays a significant role in many of the cybersecurity tools I've used, not just Splunk. Many AI tools offer some form of assistance. By "AI assistance," I mean that while AI may not have complete knowledge of all customer flow data, it can still help engineers who often encounter unfamiliar situations. For example, during incidents, a large volume of logs can be generated, and it can be difficult to analyze all of them in a timely manner. In such cases, AI tools can be beneficial, even if they are not universally applicable. Certain events, like denial-of-service attacks, can result in massive log flows, which complicate detection and response efforts. Additionally, there may be similar collective issues affecting multiple customers.
Many cybersecurity tools incorporate some limited AI capabilities, which can assist operators. For instance, if a specific endpoint security issue arises with a customer, AI can help identify potential causes and suggest improvements. In my experience, most cybersecurity operators and companies rely on security tools that may not offer full-fledged SIEM solutions but do provide integrated security functionalities such as Intrusion Detection Systems (IDS) and Intrusion Prevention Systems (IPS). My expectation is that even small, incremental integrations of AI will significantly enhance these tools' effectiveness.
For how long have I used the solution?
I have been using the solution for approximately one year. I used it for 12 months in the company.
What do I think about the stability of the solution?
It's stable. I would rate it a ten out of ten for stability.
What do I think about the scalability of the solution?
The scalability of Splunk Enterprise Security rates as an eight out of ten. I have not used the scalability option, but I would say the other procedures and processes are flawless. Scalability might be the same.
How are customer service and support?
I have not reached out to their technical support because whenever I have an issue, I use the documentation rather than reaching out to technicians. When there is an issue, people need swift assistance to solve it. People do not want to wait, so I mainly use the documentation.
How would you rate customer service and support?
Neutral
Which solution did I use previously and why did I switch?
I have worked with other SIEM solutions. Splunk Enterprise Security is great but can have some frustration points. It can sometimes be slower to use. On the other hand, when I use IBM QRadar, it rarely experiences slowdowns, especially when using the Incident Command Module (ICM). In the case of Splunk Enterprise Security, the speed might be affected by the number of systems in use or possibly due to how the security engineers configure it. As an operator, I find that the speed is a reason I would rate it an eight out of ten. Overall, it's very fast and accurate, and the user interface is excellent for various uses, such as querying data. However, I do notice that it can be slightly slower compared to other large enterprise solutions.
How was the initial setup?
Most of the time, it is deployed on-premises. We don’t rely heavily on cloud solutions, although we have explored them a bit. Our customers, particularly in the financial industry, tend to prefer on-premises systems due to their concerns about cloud security.
Having good documentation is helpful for deployment. If the documentation is lacking, it can be challenging. The ease of navigating the systems really depends on a person's experience.
The duration varies depending on the company. I can't give a specific answer because it depends on several factors, such as the number of people working in the system, the number of endpoints, and how many on-premises servers are running. In my case, I haven't experienced a full deployment, as I've only deployed a few endpoints and on-premises services. This process took just a couple of days for me, but I haven't dealt with a large-scale on-premises deployment. When I joined the company, they were already using Splunk for various on-premises services, so I haven't gone through a complete zero to one hundred type of scenario.
Splunk Enterprise Security absolutely requires maintenance, but I don't deal with maintenance. It needs maintenance, but I have not encountered much of it.
What was our ROI?
From a return on investment standpoint, Splunk Enterprise Security saves a lot of time. I have used other SIEM solutions, and they are not so great. They create lots of exhaustion and frustrating periods of checking queries, and the response times are slower. This leads to a lot of frustration because many companies don’t rely on just one SIEM tool; they often use multiple alternatives simultaneously.
The documentation for Splunk Enterprise Security is outstanding. It is well-organized and easy to access. You can simply go to the Splunk documentation website, search for what you need, and by the end of the day, you’ll have a great solution for any issue you encounter with Splunk Enterprise Security. In contrast, other SIEM tools often lack this level of documentation, which is quite disappointing.
Splunk Enterprise Security also excels with its user interface. It is easy to navigate and integrates seamlessly with other services, which is a significant advantage. You can easily search for solutions, try out different features, and create reports.
As a security operator, one of our main responsibilities is writing reports. If an issue arises, clients will often ask, “What happened around noon? Can you explain the main issue?” Other SIEM tools can make it difficult to find the appropriate buttons or functions to navigate and analyze these incidents. However, with Splunk Enterprise Security, you just look up the documentation, write what you’re searching for, and apply the same rules in Splunk Enterprise Security. Everything is easy to follow, and the system works effectively. In summary, I would say that the well-documented guidance is one of the most valuable aspects for saving me time.
What other advice do I have?
I have not used the advanced correlation capabilities so much because mainly all of them are running. Specifically, I have not gone very deep into the use case of Splunk Enterprise Security. I have used advanced queries a couple of times. For example, there was a sort of attack, a false positive attack. We had to check out all the timelines or block queries to find out what might have happened or what the reason was for the false positive. I used that and it is quite fast.
I have not used the risk-based alerting feature. It is more for log management and checking the log flow.
Whenever you want to apply for any exams, such as the SOC exam or Blue Team certification exams, they mainly ask for Splunk rather than other SIEM solutions. For me, it is overall the best SIEM solution to use.
I can recommend Splunk Enterprise Security to other users. It is fast and well-documented. User interface and user interaction are well-designed compared to other SIEM solutions. It is a great SIEM tool.
I would rate Splunk Enterprise Security an eight out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Buyer's Guide
Download our free Splunk Enterprise Security Report and get advice and tips from experienced pros
sharing their opinions.
Updated: September 2026
Product Categories
Security Information and Event Management (SIEM) Log Management IT Operations AnalyticsPopular Comparisons
IBM Security QRadar
Splunk AppDynamics
Microsoft Sentinel
Elastic Security
IBM Turbonomic
Palantir Foundry
WhatsUp Gold
LogRhythm SIEM
Rapid7 InsightIDR
Buyer's Guide
Download our free Splunk Enterprise Security Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- Which would you recommend to your boss, IBM QRadar or Splunk?
- What are some of the best features and use-cases of Splunk?
- What SOC product do you recommend?
- Splunk as an Enterprise Class monitoring solution -- thoughts?
- What is the biggest difference between Dynatrace and Splunk?
- IBM QRadar is rated above competitors (McAfee, Splunk, LogRhythm) in Gartner's 2020 Magic Quandrant. Agree/Disagree?
- What are the advantages of ELK over Splunk?
- How does Splunk compare with Azure Monitor?
- New risk scoring framework in the Splunk App for Enterprise Security -- thoughts?
- Splunk vs. Elastic Stack



















