What is our primary use case?
My main use case for Splunk Enterprise Security is reviewing incidents in the Mission Control dashboard for our clients. When an incident occurs, my analyst team and I review every incident and conduct investigations to view logs and perform formal investigations.
A specific example of how I have used Splunk Enterprise Security recently is when an incident in the Analyst Queue occurs or triggers. We review every property of the incident, including the host name, the user involved, and any risk events. Meanwhile, we work in an investigation file, and for the client, we deliver this as a PDF file or a Word file. Everything that we find in the alert or in the logs, we build a timeline so that when an incident occurs, we provide the client with the scope. When we deliver an investigation, the client knows what happened, who did it, and other relevant details.
I have been using the RBA framework increasingly. When an incident is happening, we review many things in this dashboard. When a host is involved, we review the most recent incidents in the risk framework, and when we review the alert, we know what was happening with this host.
How has it helped my organization?
Splunk Enterprise Security has positively impacted my organization because as a team, we have built a framework for how we can investigate things. Before we used Splunk Enterprise Security, when an incident happened, the team did not know how to start an investigation. Now that we are using most of Splunk Enterprise Security's features, we review the alert, the properties of the alert, and with that information, we can start to build an investigation. The most important part that Splunk Enterprise Security gives us is a framework to investigate incidents.
Since we have been using Splunk Enterprise Security, the most important part for our team is that we can build investigations very quickly. While I do not have specific numbers or metrics, I have seen this improvement in the team and in our framework to work.
What is most valuable?
The best features that Splunk Enterprise Security offers are the intelligence side, which is the most important aspect for my team and our investigations. When we were searching for traffic in the network, we use a lot of features including the traffic search or the intrusion search, and most of these features give us context of what is happening.
The intelligence features help my team in daily work and investigations because when an alert is triggered in the network side, we review this dashboard. When we have a malicious IP, we search this IP in all the traffic and we know what hosts this IP may have targeted. With these dashboards, we build a story so that the client has a great scope of what is happening or the incident.
What needs improvement?
I have noticed with a lot of clients that the instances in the cloud have been really slow. When the team performs an update in the instance, some features are missing. The most recent thing we have noticed is that when a version is updated, we miss the button of the short ID, which we use to identify our investigations or reports. Since the update was applied, we did not see that button, so these types of things in the dashboard or in the metrics of the operation in the cloud instance have been impacted.
I think it would be great if Splunk Enterprise Security could add an EDR solution. If we install a sensor in the endpoint, the sensor could forward the logs of Sysmon into a SIEM in a more rapid and efficient way.
For how long have I used the solution?
I have been using Splunk Enterprise Security since the beginning of 2025. I have been using it for Mission Control and detections.
What do I think about the stability of the solution?
In my experience, Splunk Enterprise Security is stable. However, when Splunk applies an upgrade, the instance could suffer some impacts. When the team applies an upgrade, we are very careful to control what happens in the instance.
What do I think about the scalability of the solution?
When it comes to scalability, I think that is more of the license involvement. I do not know if the technical side has some part in that.
How are customer service and support?
The customer support for Splunk Enterprise Security is very good. When we open a ticket with PS or something similar, the team responds very quickly and with complete information. I would rate the customer support a 10.
What was our ROI?
Since we are using the RBA framework, I think Splunk Enterprise Security has helped improve my organization's business resilience because we can know when a host or a user is acting in a suspicious or malicious way. If we identify this behavior, we can have answers for our clients. With this framework, knowing how an endpoint or a user behaves, we can understand if something is malicious or not.
Splunk Enterprise Security has helped reduce my team's average mean time to resolve, MTTR metric. While I do not have a specific number in metrics, what I have seen is that the team can investigate findings in a more specific way by reviewing logs. When we deliver an investigation, the client knows what is happening.
What other advice do I have?
When we configure an alert in Splunk Enterprise Security, we map the attacks in every detection, and when the client or the team reviews an alert, we know what is happening and what MITRE ATT&CK it is related to.
While I do not have the exact numbers since I work more in the technical side, I think we have seen improvements in alert fatigue using RBA with Splunk Enterprise Security.
The advice I would give to others looking into using Splunk Enterprise Security is to understand what kind of information from indexes they are currently ingesting in Splunk, so when an incident occurs, the team would perfectly know what is happening and where to search for it.
Which deployment model are you using for this solution?
Public Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Microsoft Azure
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner