No more typing reviews! Try our Samantha, our new voice AI agent.
CEO at CygenIQ
Real User
Top 10
Dec 22, 2024
Improves threat management and has effective analytics
Pros and Cons
  • "The Splunk Enterprise Security's threat-hunting capabilities have been particularly useful in later releases."
  • "Splunk Enterprise Security enhances business resilience and assists with threat detection by centralizing security data."
  • "Splunk Enterprise Security would benefit from a more robust rule engine to reduce false positives."

What is our primary use case?

We primarily used Splunk Enterprise Security for data and cloud ingestion. We also leveraged it for enterprise security use case engineering, which encompassed malware analysis, threat management, detection, and the integration of threat and vulnerability intelligence, culminating in comprehensive reporting and dashboards. This was the principal use case for our SIEM platform. In recent years, we have also employed Splunk for user behaviour analytics to bolster insider threat protection.

We implemented Splunk Enterprise Security to improve security monitoring, threat detection, and incident response.

How has it helped my organization?

Although Splunk is not the only tool we use, it is essential that it provides end-to-end visibility into threats in our environment.

Splunk is effective for helping find security events across multiple cloud, on-premises, or hybrid environments.

Splunk helps improve our organization's ability to ingest and normalize data.

Splunk helps us identify threats in real-time.

We integrated 50 percent of the MITRE ATT&CK framework's techniques to enhance our incident detection capabilities.

Splunk Enterprise Security effectively analyzes various security events and has helped improve my organization's ability to ingest and normalize data.

Splunk helped us detect threats faster. 

Splunk Enterprise Security reduced the investigation time by consolidating datasets for quick access.

Splunk Enterprise Security enhances business resilience and assists with threat detection by centralizing security data.

I have a positive impression of Splunk's ability to predict, identify, and solve problems.

Splunk Enterprise Security helps reduce our mean time to resolve.

What is most valuable?

The Splunk Enterprise Security's threat-hunting capabilities have been particularly useful in later releases.

What needs improvement?

Splunk Enterprise Security would benefit from a more robust rule engine to reduce false positives. While its detection capabilities are efficient, there is room to improve its alert volume reduction and false positive management efficiency. Furthermore, enhancements in its integration capabilities with other security infrastructures could optimize its overall effectiveness.

Buyer's Guide
Splunk Enterprise Security
September 2026
Learn what your peers think about Splunk Enterprise Security. Get advice and tips from experienced pros sharing their opinions. Updated: September 2026.
915,287 professionals have used our research since 2012.

For how long have I used the solution?

I have been using Splunk Enterprise Security for 13 years.

What do I think about the stability of the solution?

In terms of stability, Splunk is good. It provides a stable environment but needs to integrate with ITSM platforms to achieve better visibility.

What do I think about the scalability of the solution?

Splunk Enterprise Security is efficient and scalable, especially for large environments with substantial scalability needs.

How are customer service and support?

The technical support for Splunk met my expectations.

Which solution did I use previously and why did I switch?

I haven't switched to Splunk from another solution, but I have used various products, such as Google Chronicle, Securonix, ExtraHop, and Sumo Logic, to meet different customer needs. Securonix is used more for behavioural analytics and insider threats, whereas Splunk is used for logging and monitoring.

How was the initial setup?

The initial setup of Splunk Enterprise Security is straightforward, but it does require skilled personnel.

What about the implementation team?

The implementation involved an architect, cloud DevOps engineer, data engineer, full-stack developers, and cybersecurity engineers. A team of five to six members, tailored to different roles, was typical.

What was our ROI?

Splunk's cost is justified for large environments with extensive assets. However, for smaller organizations, other products may provide better value for money.

What's my experience with pricing, setup cost, and licensing?

Splunk is priced higher than other solutions.

What other advice do I have?

I would rate Splunk Enterprise Security nine out of ten.

Splunk Enterprise Security requires continuous maintenance and support, which requires a dedicated team. Previously, seven to eight personnel were focused on platform maintenance. Additional resources may be required to optimize for multiple customer environments. 

For those evaluating SIEM solutions solely based on cost, Splunk might not be suitable. It is essential to consider security, context, and specific use cases rather than just choosing based on price. Critical assets need the right platform for effective protection rather than opting for a cheaper solution.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
reviewer2899449 - PeerSpot reviewer
Manager cybersecurity at a tech vendor with 10,001+ employees
Real User
Top 20
Sep 17, 2026
Correlations and risk features have improved our threat detection and incident investigations
Pros and Cons
  • "Splunk Enterprise Security offers excellent correlations, enhancements, and risk features that help my team."
  • "I chose eight out of ten because of the lack of retroactive IOC hunts and potentially missing data, which prevented me from giving it a ten."

What is our primary use case?

Splunk Enterprise Security serves as my main security solution. We raise notable events and pass them to the SOAR for security purposes. When I raise notable events and pass them to the SOAR, I track insider threats and external security incidents.

What is most valuable?

Splunk Enterprise Security offers excellent correlations, enhancements, and risk features that help my team. Data scrubbing for anomalous events stands out most for me because it ensures we focus on crucial alerts.

Splunk Enterprise Security has positively impacted my organization as it is embedded in our workflows and raises notables that are investigated by CERT analysts. The embedding and investigation process has improved things for my team by yielding better detection rates.

What needs improvement?

The assets and identities framework in Splunk Enterprise Security could benefit from more integrations for improvement.

I chose eight out of ten because of the lack of retroactive IOC hunts and potentially missing data, which prevented me from giving it a ten. Splunk Enterprise Security has helped improve my organization's business resilience, though my impressions of its ability to predict, identify, and solve problems in real-time are somewhat lacking due to a delay in search windows and possible overlap in data availability.

For how long have I used the solution?

I have been using Splunk Enterprise Security for thirteen years.

What do I think about the stability of the solution?

Splunk Enterprise Security is stable.

What do I think about the scalability of the solution?

Its reliability is good as it scales well.

How are customer service and support?

The customer support for Splunk Enterprise Security is sufficient.

Which solution did I use previously and why did I switch?

We have had Splunk Enterprise Security for over ten years and did not previously use a different solution.

What was our ROI?

I have not seen a return on investment; my focus was on the quality of alerts and detections, as our detection framework was previously version controlled.

What's my experience with pricing, setup cost, and licensing?

My experience with pricing, setup cost, and licensing indicates that the licensing is prohibitively expensive.

Which other solutions did I evaluate?

Before choosing Splunk Enterprise Security, we conducted a bake-off with Google SecOps and Palo Alto's XSIAM.

What other advice do I have?

We recently upgraded to Splunk Enterprise Security version 8.4, and the terminology normalization is a good move. The Analyst Queue is very similar to previous versions incident review, and we have not yet utilized those workflows. We recently implemented the risk-based alerting (RBA) index, and I have yet to evaluate the improvements. We had the MITRE ATT&CK framework in place prior to this version, which has been useful. You should focus on data onboarding, indexing, and source typing per Splunk best practices. I gave this product a rating of eight out of ten.

Which deployment model are you using for this solution?

Hybrid Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Last updated: Sep 17, 2026
Flag as inappropriate
PeerSpot user
Buyer's Guide
Splunk Enterprise Security
September 2026
Learn what your peers think about Splunk Enterprise Security. Get advice and tips from experienced pros sharing their opinions. Updated: September 2026.
915,287 professionals have used our research since 2012.
reviewer2899491 - PeerSpot reviewer
Cybersecurity Analyst at a tech services company with 11-50 employees
Real User
Top 20
Sep 17, 2026
Incident investigations have become structured and now provide clients clear attack timelines
Pros and Cons
  • "Splunk Enterprise Security has positively impacted my organization because as a team, we have built a framework for how we can investigate things."
  • "I have noticed with a lot of clients that the instances in the cloud have been really slow."

What is our primary use case?

My main use case for Splunk Enterprise Security is reviewing incidents in the Mission Control dashboard for our clients. When an incident occurs, my analyst team and I review every incident and conduct investigations to view logs and perform formal investigations.

A specific example of how I have used Splunk Enterprise Security recently is when an incident in the Analyst Queue occurs or triggers. We review every property of the incident, including the host name, the user involved, and any risk events. Meanwhile, we work in an investigation file, and for the client, we deliver this as a PDF file or a Word file. Everything that we find in the alert or in the logs, we build a timeline so that when an incident occurs, we provide the client with the scope. When we deliver an investigation, the client knows what happened, who did it, and other relevant details.

I have been using the RBA framework increasingly. When an incident is happening, we review many things in this dashboard. When a host is involved, we review the most recent incidents in the risk framework, and when we review the alert, we know what was happening with this host.

How has it helped my organization?

Splunk Enterprise Security has positively impacted my organization because as a team, we have built a framework for how we can investigate things. Before we used Splunk Enterprise Security, when an incident happened, the team did not know how to start an investigation. Now that we are using most of Splunk Enterprise Security's features, we review the alert, the properties of the alert, and with that information, we can start to build an investigation. The most important part that Splunk Enterprise Security gives us is a framework to investigate incidents.

Since we have been using Splunk Enterprise Security, the most important part for our team is that we can build investigations very quickly. While I do not have specific numbers or metrics, I have seen this improvement in the team and in our framework to work.

What is most valuable?

The best features that Splunk Enterprise Security offers are the intelligence side, which is the most important aspect for my team and our investigations. When we were searching for traffic in the network, we use a lot of features including the traffic search or the intrusion search, and most of these features give us context of what is happening.

The intelligence features help my team in daily work and investigations because when an alert is triggered in the network side, we review this dashboard. When we have a malicious IP, we search this IP in all the traffic and we know what hosts this IP may have targeted. With these dashboards, we build a story so that the client has a great scope of what is happening or the incident.

What needs improvement?

I have noticed with a lot of clients that the instances in the cloud have been really slow. When the team performs an update in the instance, some features are missing. The most recent thing we have noticed is that when a version is updated, we miss the button of the short ID, which we use to identify our investigations or reports. Since the update was applied, we did not see that button, so these types of things in the dashboard or in the metrics of the operation in the cloud instance have been impacted.

I think it would be great if Splunk Enterprise Security could add an EDR solution. If we install a sensor in the endpoint, the sensor could forward the logs of Sysmon into a SIEM in a more rapid and efficient way.

For how long have I used the solution?

I have been using Splunk Enterprise Security since the beginning of 2025. I have been using it for Mission Control and detections.

What do I think about the stability of the solution?

In my experience, Splunk Enterprise Security is stable. However, when Splunk applies an upgrade, the instance could suffer some impacts. When the team applies an upgrade, we are very careful to control what happens in the instance.

What do I think about the scalability of the solution?

When it comes to scalability, I think that is more of the license involvement. I do not know if the technical side has some part in that.

How are customer service and support?

The customer support for Splunk Enterprise Security is very good. When we open a ticket with PS or something similar, the team responds very quickly and with complete information. I would rate the customer support a 10.

What was our ROI?

Since we are using the RBA framework, I think Splunk Enterprise Security has helped improve my organization's business resilience because we can know when a host or a user is acting in a suspicious or malicious way. If we identify this behavior, we can have answers for our clients. With this framework, knowing how an endpoint or a user behaves, we can understand if something is malicious or not.

Splunk Enterprise Security has helped reduce my team's average mean time to resolve, MTTR metric. While I do not have a specific number in metrics, what I have seen is that the team can investigate findings in a more specific way by reviewing logs. When we deliver an investigation, the client knows what is happening.

What other advice do I have?

When we configure an alert in Splunk Enterprise Security, we map the attacks in every detection, and when the client or the team reviews an alert, we know what is happening and what MITRE ATT&CK it is related to.

While I do not have the exact numbers since I work more in the technical side, I think we have seen improvements in alert fatigue using RBA with Splunk Enterprise Security.

The advice I would give to others looking into using Splunk Enterprise Security is to understand what kind of information from indexes they are currently ingesting in Splunk, so when an incident occurs, the team would perfectly know what is happening and where to search for it.

Which deployment model are you using for this solution?

Public Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Microsoft Azure
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
Last updated: Sep 17, 2026
Flag as inappropriate
PeerSpot user
reviewer2899014 - PeerSpot reviewer
SOC analyst at a government with 10,001+ employees
Real User
Top 20
Sep 16, 2026
Investigations have become faster as I quickly correlate alerts, reduce fatigue, and classify threats
Pros and Cons
  • "The ability to search for data and correlate with Jira alerts helps my daily work by enabling me to identify false positives, find traffic that can be tuned, and quickly identify malicious IP addresses."
  • "As far as reliability goes, I think that the AI capabilities will still need some human interaction, and I do not feel comfortable yet truly trusting everything that AI does."

What is our primary use case?

My main use case for Splunk Enterprise Security is investigations. A specific example of how I use Splunk Enterprise Security for investigations is diving deeper into triage alerts.

What is most valuable?

The best features Splunk Enterprise Security offers include searching for data to correlate with Jira alerts.

The ability to search for data and correlate with Jira alerts helps my daily work by enabling me to identify false positives, find traffic that can be tuned, and quickly identify malicious IP addresses. Splunk Enterprise Security has positively impacted my organization by providing SOC as a service and allowing us to find information quickly and escalate in a timely manner.

What needs improvement?

Regarding Splunk Enterprise Security's AI capabilities, we are currently not using the AI capabilities; however, I am excited about the AI capabilities that are being developed and hope that the government is more open to using the AI capabilities of Splunk.

As far as reliability goes, I think that the AI capabilities will still need some human interaction, and I do not feel comfortable yet truly trusting everything that AI does.

For how long have I used the solution?

I have been using Splunk Enterprise Security for two years.

What do I think about the stability of the solution?

Splunk Enterprise Security is stable.

What do I think about the scalability of the solution?

I think the scalability of Splunk Enterprise Security is good.

How are customer service and support?

I believe that the customer support for Splunk Enterprise Security is excellent; as we are government, we have our own reps that we can reach directly out to, and they are always very responsive. I would rate the customer support on a scale of one to ten as ten.

What other advice do I have?

I think Splunk Enterprise Security helps identify what part of the MITRE ATT&CK framework that the incident falls under.

I believe that Splunk Enterprise Security Essentials has contributed to a reduction in analyst burnout or fatigue; it removes having to go to multiple tools to pull data and find what I am looking for and puts the story together for me.

My advice to others looking into using Splunk Enterprise Security is to make sure that you are aware of all of the capabilities and ask for demos so that you ensure that you are using everything possible to make the best of your environment. I rate this review overall as a ten.

Which deployment model are you using for this solution?

On-premises

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Other
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
Last updated: Sep 16, 2026
Flag as inappropriate
PeerSpot user
GautamKar - PeerSpot reviewer
Staff Performance Engineer at ServiceNow
MSP
Top 5
Mar 2, 2025
Real-time monitoring and alerts enhance performance evaluation and security investigations
Pros and Cons
  • "I can create dashboards to collect and view information in a tabular, graphical format. This feature is important because it helps me understand time-series data over one or two hours."
  • "Overall, I would rate it a nine out of ten."
  • "Data retention can be better. If we want to look at the data for five months or six months, that is not available to us. We only have a history of 20 or 30 days. After that, the information gets lost. That is a drawback."

What is our primary use case?

We use it for real-time monitoring and alerts for all instances and servers on our sub-prod instances. It helps in monitoring, getting alerts for specific errors, and identifying various logs. We also use it for log analysis, which is very beneficial.

My use case is more related to production issues. Threat detection is taken care of by another team.

How has it helped my organization?

It is our go-to tool for monitoring multiple cloud environments. The difficult part initially is to understand how the logging is happening for particular applications or instances. Once you have an understanding of what you want to see and how they are getting generated, you can just write queries, and you can create exhaustive dashboards for anybody to look at and understand how things are.

Splunk Enterprise Security is good for analyzing malicious activities and detecting breaches. Its threat detection capabilities are good. We can look at the exact activity and task. We can look at a trace and understand what is happening. It gives a very granular understanding. I see emails from the security team mentioning what they have identified, so it seems to be helpful for threat detection.

Based on the org mail that we received, they were able to block almost 95% of threats in real time. That is a pretty good number.

Splunk Enterprise Security helps to reduce alert volume because you can understand patterns, such as where your requests are going and how everything is happening. There has been a 40% to 50% reduction.

Splunk Enterprise Security has helped speed up our security investigations by 40% to 50%. It has helped the security team to get a head start and understand where the issue is originating and where the problem is. We are operating in a very dynamic environment, so any time lost costs the company money.

What is most valuable?

I can create dashboards to collect and view information in a tabular, graphical format. This feature is important because it helps me understand time-series data over one or two hours. It creates graphs, allowing us to check spikes and examine average values and 90th and 95th percentile values. This capability is useful for performance monitoring and issue identification. I believe it has helped speed up security investigations.

What needs improvement?

Data retention can be better. If we want to look at the data for five months or six months, that is not available to us. We only have a history of 20 or 30 days. After that, the information gets lost. That is a drawback. 

Splunk's dashboards are pretty basic. In comparison to Grafana, the dashboards are not as detailed. There is room for improvement in that area.

For how long have I used the solution?

I have been using it for about one and a half years now.

What do I think about the stability of the solution?

It is stable. I have not encountered any stability issues so far.

What do I think about the scalability of the solution?

It is easy to scale. We have multiple instances, sub-instances, and prod instances running, so scalability is not a problem.

It is being used by development teams, QA teams, performance teams, and security teams. We have about 500 people using it.

How are customer service and support?

It is good. I have not had any major issues where support was lacking, so I would rate it positively.

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

In this organization, I did not use any similar solution. In my previous organization, we used APM tools like Dynatrace and AppDynamics, which helped us monitor real-time data and performance. Splunk is a similar tool but offers more capabilities and is also cost-effective.

It was an organizational decision to go with Splunk Enterprise Security. It involved financial considerations and the kind of deal Splunk provided, as we are using the enterprise version and another version. Economics, capabilities, and support were factors.

How was the initial setup?

I was not involved in its deployment. When it comes to maintenance, another team looks after it and takes care of maintenance.

What was our ROI?

I have not been involved in the finance part, so I cannot comment on ROI or costs. However, preventing incidents or solving performance issues saves money, converting time saved to money. Customers are happy. Employees are happy. There is less downtime.

What's my experience with pricing, setup cost, and licensing?

I am not aware of the costs; that is handled by a separate team. I only use it for logs and performance issues.

What other advice do I have?

Instead of going for the cheapest solution available, you should go for the one that meets your needs. It takes time for an organization to onboard a new solution, so it is important to choose the right solution from the start. I believe all available solutions are pretty good, so you should see what suits you better.

It is a great tool. If you learn to navigate it, you can access a wide range of information about any application or product. It is a very helpful tool, provided you know how to use it. 

Overall, I would rate it a nine out of ten.

Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
PeerSpot user
CR 1 at a healthcare company with 5,001-10,000 employees
Real User
Top 20
Sep 17, 2026
Centralized alerts have reduced investigation time and provide flexible correlation with SPL
Pros and Cons
  • "Splunk Enterprise Security has positively impacted our organization because it gives us the ability to have the information in one point."

    What is our primary use case?

    I use Splunk Enterprise Security as a SIEM, and I mostly like to correlate whatever logs we see to view all the logs for the alerts.

    We have everything that involves the apps in the company within Splunk logs. We have identity logs, vishing, and phishing. We also have some remote access and a bunch of alerts. Splunk's capabilities give the opportunity to see everything and have a timeline on the alerts.

    What is most valuable?

    In my opinion, the best features Splunk Enterprise Security offers are the flexibility and the language usage.

    When I mention flexibility and language usage, I am referring to the ability to customize searches and dashboards with SPL. I customize searches and dashboards and I have been using the correlation functionality to see the detection and tuning opportunities for alerts. I also use the SPL language to extend the way I present numbers to my managers through dashboards.

    Splunk Enterprise Security has positively impacted our organization because it gives us the ability to have the information in one point. This facilitates the time we spend going through alerts and investigations. Our MTTR has been decreasing since we started using Splunk Enterprise Security.

    What needs improvement?

    I think it would be great to integrate all the capabilities that Cisco is providing to improve Splunk Enterprise Security.

    Splunk is already an expensive application, so I expect that they give enterprises the time, resources, and all the integrations that they have been providing regarding the needed improvements.

    For how long have I used the solution?

    I have been using Splunk Enterprise Security for a year and a half now.

    What do I think about the stability of the solution?

    Splunk Enterprise Security is stable.

    What do I think about the scalability of the solution?

    Splunk Enterprise Security's scalability is great and it works.

    How are customer service and support?

    The customer support for Splunk Enterprise Security is great.

    Which solution did I use previously and why did I switch?

    I had QRadar before and switched because it was in my old job.

    What other advice do I have?

    Splunk Enterprise Security's risk-based alerting (RBA) has been performing very well. It has been tuning out some of the alerts from our queues that do not indicate much malicious activity.

    I assess the threat topology and MITRE ATT&CK framework features as making the TTPs more clear and that helps me search alerts in a better way.

    The integration of threat intelligence directly into the TDIR workflow has not improved my ability to preemptively block threats yet.

    I recommend getting into the courses in Splunk University to have a better understanding of the application. I give this review a rating of nine out of ten.

    Which deployment model are you using for this solution?

    On-premises
    Disclosure: My company does not have a business relationship with this vendor other than being a customer.
    Last updated: Sep 17, 2026
    Flag as inappropriate
    PeerSpot user
    reviewer2899395 - PeerSpot reviewer
    Security Engineer at a financial services firm with 10,001+ employees
    Real User
    Top 20
    Sep 16, 2026
    Platform has improved threat intelligence dashboards and supports proactive system health monitoring
    Pros and Cons
    • "I love Splunk; it is fantastic and our account team is always willing to work with us and make sure we're getting the most for our money."

      What is our primary use case?

      My main use case for Splunk Enterprise Security is creating dashboards and general overall system health and maintenance. For system health or maintenance, I build dashboards for threat intelligence across the bank environment.

      How has it helped my organization?

      Splunk Enterprise Security has positively impacted my organization by making it easier to download and process data for findings and incidents in the environment.

      What is most valuable?

      The best features Splunk Enterprise Security offers include using Threat Intelligence Manager to organize threat intelligence data from outside sources. Threat Intelligence Manager helps me in my day-to-day work by being faster, easier, and more reliable than older options such as True Star.

      What needs improvement?

      Splunk Enterprise Security is pretty top-notch and one of the best in its class. Along with moving to the new interface, there should be more consistency across the board for all applications to improve my experience even better.

      For how long have I used the solution?

      I have been using Splunk Enterprise Security for four years.

      What do I think about the stability of the solution?

      Splunk Enterprise Security is stable.

      What do I think about the scalability of the solution?

      Splunk Enterprise Security's scalability is amazing.

      How are customer service and support?

      So far, customer support for Splunk Enterprise Security has been great.

      Which solution did I use previously and why did I switch?

      My organization has not previously used a different solution.

      How was the initial setup?

      My experience with pricing, setup cost, and licensing has been good so far, and our account team has been willing to work with us along the way.

      What about the implementation team?

      My company does not have a business relationship with this vendor other than being a customer. I was offered a gift card or incentive for this review.

      What's my experience with pricing, setup cost, and licensing?

      My experience with pricing, setup cost, and licensing has been good so far, and our account team has been willing to work with us along the way.

      Which other solutions did I evaluate?

      My organization has not evaluated other options before choosing Splunk Enterprise Security.

      What other advice do I have?

      I love Splunk; it is fantastic and our account team is always willing to work with us and make sure we're getting the most for our money. My advice to others looking into using Splunk Enterprise Security is to make sure your data is clean and to be prepared for when you actually move to Splunk. I gave this review a rating of 10.

      Which deployment model are you using for this solution?

      Public Cloud

      If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

      Other
      Disclosure: My company does not have a business relationship with this vendor other than being a customer.
      Last updated: Sep 16, 2026
      Flag as inappropriate
      PeerSpot user
      Jeffrey Bain - PeerSpot reviewer
      Sr Manager Global Security Operations at a financial services firm with 10,001+ employees
      Real User
      Top 5
      Sep 13, 2025
      Standardized investigations and fraud detection have improved team efficiency significantly
      Pros and Cons
      • "It's standardized and easy to use, so you don't have to have a lot of top-tier analysts to do the same job."
      • "Splunk Enterprise Security can be improved by bringing back some of the operational use cases."

      What is our primary use case?

      My main use case for Splunk Enterprise Security is security eventing.

      What is most valuable?

      The features of Splunk Enterprise Security provide a standardized platform for investigating.

      The content libraries are helpful. In our organization, we don't use them a lot. We will use them as ideas and rebuild them into what our needs are.

      It's standardized and easy to use, so you don't have to have a lot of top-tier analysts to do the same job.

      The investigations plane and use case library have been beneficial.

      We utilize Splunk Enterprise Security for our fraud team using pure ES. We use all the fraud features, and that's been incredibly helpful.

      The detection rate and prevention rate has gone up 30 times compared to when they were working on a spreadsheet. The fraud team loves it.

      Once we move over to 8.2, we're going to utilize more of the built-in features.

      I appreciate the visual control and the investigations plane, though that will be a major migration for us.

      What needs improvement?

      Splunk Enterprise Security can be improved by bringing back some of the operational use cases. When Splunk developed ITSI, they took a lot of information or use cases out of ES, where operational use cases can also be security use cases. Those two products need to be more migrated to each other. In the next release of Splunk Enterprise Security, there should be more reporting options.

      For how long have I used the solution?

      I have been using Splunk Enterprise Security for nine years.

      What do I think about the stability of the solution?

      I would assess the stability and reliability of Splunk Enterprise Security as excellent. I've had no problems with downtime, crashes, or performance issues.

      What do I think about the scalability of the solution?

      Splunk Enterprise Security scales with the growing needs of my organization just fine. The licensing for ingest is a different story.

      How are customer service and support?

      I would evaluate customer service and technical support for Splunk Enterprise Security as lacking. The service engineers that we've been getting as part of our weekly or bi-weekly calls with our salesperson, where they've assigned an engineer, have decreased tremendously in quality and expertise over the last few years. People on the team that really know Splunk know a lot more than they do, and it's evident because they don't try anymore. We can still get expert help when we need it.

      How would you rate customer service and support?

      Positive

      Which solution did I use previously and why did I switch?

      Prior to adopting Splunk Enterprise Security, I was not using another solution to address similar needs.

      How was the initial setup?

      I would describe my experience with deploying Splunk Enterprise Security as easy. The KV store setup was straightforward.

      What was our ROI?

      I have seen ROI with Splunk Enterprise Security.

      What's my experience with pricing, setup cost, and licensing?

      My experience with pricing, setup cost, and licensing for Splunk Enterprise Security has been fine. We've renewed since Cisco took over.

      What other advice do I have?

      My advice to other organizations considering Splunk Enterprise Security is to follow the documentation and not build your own stuff.

      On a scale of one to ten, I rate this solution a nine.

      Which deployment model are you using for this solution?

      Hybrid Cloud

      If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

      Disclosure: My company does not have a business relationship with this vendor other than being a customer.
      PeerSpot user
      Jeanette Pavelka - PeerSpot reviewer
      Assistant VP, Data Loss Prevention at State Street
      Real User
      Top 10
      Sep 11, 2025
      Creating custom detections has accelerated threat response and improved team independence

      What is our primary use case?

      My main use case for Splunk Enterprise Security is web uploads.

      What is most valuable?

      The ability to create SPLs in Splunk Enterprise Security is my favorite feature. These features benefit my organization primarily through threat detection, which I use for, so that's a huge benefit. Splunk Enterprise Security has absolutely helped improve my organization's business resilience.

      What needs improvement?

      Splunk Enterprise Security could be improved by incorporating AI features, as it doesn't have the AI capability that Pyramid does, where users can ask questions without having to write code.

      For how long have I used the solution?

      It has been more than three years.

      What do I think about the stability of the solution?

      I haven't experienced any downtime or performance issues with Splunk Enterprise Security. Zscaler may experience issues because Splunk grabs data from them, but other than that, I haven't had anything crash.

      What do I think about the scalability of the solution?

      Splunk Enterprise Security adapts to our growing needs on a yearly basis, as we're constantly growing our program and it has helped in that way. We have expanded usage from just engineering, as now our whole DLP team uses it, allowing us to not rely on other people for it. It was a smooth process when we were expanding usage.

      What other advice do I have?

      The most significant challenges I've faced when using Splunk include getting the code right. I find the process for customizing, developing, testing, deploying, and refining detections in Splunk Enterprise Security to be good, as changes are easy to make. On average, my security ops team takes about three days to remediate security incidents with Splunk Enterprise Security, depending on what the incident is.

      My advice to other organizations considering Splunk Enterprise Security is that it depends on their needs and costs, but I think it can cover everything from a small business to a large business, so I would definitely recommend it.

      On a scale of 1-10, I rate Splunk Enterprise Security an 8.

      Which deployment model are you using for this solution?

      Hybrid Cloud

      If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

      Other
      Disclosure: My company does not have a business relationship with this vendor other than being a customer.
      PeerSpot user
      reviewer2898966 - PeerSpot reviewer
      Threat hunter at a consultancy with 51-200 employees
      Real User
      Top 20
      Sep 16, 2026
      Streamlined threat detection and alert automation has improved workflows but needs newer features
      Pros and Cons
      • "Splunk Enterprise Security offers excellent features that include constant updates with the Enterprise Security Content Update, which helps keep our detections current, and it allows for automating a lot of alerting that is important to the organization that I support."
      • "Splunk Enterprise Security has not helped improve our organization's business resilience since resilience means the ability to recover from a disaster, and we are not using it in that capacity at all."

      What is our primary use case?

      My main use case for Splunk Enterprise Security is cybersecurity for one of my government agency customers. In my role with my agency customer, we have alerts that come in, and junior analysts review them. As a senior analyst, I help develop new alerts and then triage ones that cannot be handled at the lower level or review ones that were handled to ensure they were done correctly.

      What is most valuable?

      Splunk Enterprise Security offers excellent features that include constant updates with the Enterprise Security Content Update, which helps keep our detections current, and it allows for automating a lot of alerting that is important to the organization that I support. The Enterprise Security Content Update specifically helps my team as it is a free service from Splunk's research team that provides new detections for Splunk Enterprise Security that are developed and tested by the threat research team, and they generally help support our organization in that way. From an automation perspective, we're integrating with workflow actions to other tools that are involved in our process. Splunk Enterprise Security has positively impacted our organization as it has been beneficial for us. We had been working with an internal self-developed Splunk app that was adequate, but it took a lot of effort to maintain it and to develop new analytics when necessary. Splunk Enterprise Security streamlined all of that for us.

      What needs improvement?

      Splunk Enterprise Security's improvement potential is difficult to assess since we're not currently running the latest version. There may already be features that I would want, such as the automated AI integration and other capabilities. There are pain points my team runs into, though specifying exact improvements would be challenging given my current version.

      For how long have I used the solution?

      I have been using Splunk Enterprise Security for around six to ten years.

      What do I think about the stability of the solution?

      Splunk Enterprise Security is stable in our environment.

      What do I think about the scalability of the solution?

      Splunk Enterprise Security's scalability is performing very well in our environment, and we do not have any problems with that.

      How are customer service and support?

      Splunk Enterprise Security's customer support is very good. We have excellent personnel available to help us, although we handle most of our problems in-house.

      Which solution did I use previously and why did I switch?

      We previously used an ad hoc self-built solution that roughly followed the MITRE ATT&CK framework and, prior to that, the Lockheed Martin Kill Chain. We switched because it was the next evolution and because the availability of the detections and the ease of use for our analysts to be able to respond to alerts made it the better option. We did not evaluate other options before choosing Splunk Enterprise Security.

      How was the initial setup?

      I was not involved in any of the pricing, setup cost, and licensing aspects of Splunk Enterprise Security as I am an end user analyst.

      What was our ROI?

      There is likely a return on investment, but because of my role in the organization, I would not have any metrics that would support that assessment.

      What other advice do I have?

      Splunk Enterprise Security has not helped improve our organization's business resilience since resilience means the ability to recover from a disaster, and we are not using it in that capacity at all.

      Regarding the average meantime to resolve metric, we implemented Splunk Enterprise Security a long time ago. Providing quantifiable metrics would be very difficult because it was so long ago and it was such a generational leap when we did employ it that there was really no comparison.

      We have actually chosen not to implement risk-based alerting. We are in an environment where the alerts are not so voluminous that risk-based alerting would add value to our triage and resolving.

      I would assess the threat topology and MITRE ATT&CK framework features for helping me discover the overall scope of an incident by noting that we have MITRE enabled, but in our particular environment, we do not leverage it as one would in a non-air-gapped environment. The actual use of it being able to quantify various threats through the MITRE framework does not really apply to where I am.

      Splunk Enterprise Security has helped me detect threats faster, but as I mentioned before, we implemented it so long ago, and it was such a generational leap in our ability to have quantifiable metrics on how well or how much it improved things that providing specific measurements would be inappropriate.

      I would advise others looking into using Splunk Enterprise Security to give it a try. Because of the availability of those ongoing added detections from the Enterprise Security Content Update, you will not find a better value. The time to engineer new detections is greatly reduced, especially ones that are topical and in the news. I would rate this product a seven out of ten.

      Which deployment model are you using for this solution?

      On-premises
      Disclosure: My company does not have a business relationship with this vendor other than being a customer.
      Last updated: Sep 16, 2026
      Flag as inappropriate
      PeerSpot user
      Buyer's Guide
      Download our free Splunk Enterprise Security Report and get advice and tips from experienced pros sharing their opinions.
      Updated: September 2026
      Buyer's Guide
      Download our free Splunk Enterprise Security Report and get advice and tips from experienced pros sharing their opinions.