No more typing reviews! Try our Samantha, our new voice AI agent.
reviewer2756124 - PeerSpot reviewer
Dir Security Ops at a government with 10,001+ employees
Real User
Top 20
Sep 13, 2025
Has improved incident detection and reduced SOC response times with a unified dashboard
Pros and Cons
  • "The feature I appreciate the most about Splunk Enterprise Security is the dashboard."
  • "The correlation of events is the most significant challenge I face when using Splunk Enterprise Security for advanced threat detection."

What is our primary use case?

My main use cases for Splunk Enterprise Security are threat alerts.

What is most valuable?

The feature I appreciate the most about Splunk Enterprise Security is the dashboard. It has supported my SOC by making their job easier regarding notifications. It also reduces the time they have to spend using other tools to help them out, cutting down on their workload.

When it comes to incidents, we are able to detect, monitor, and handle incidents that come in. We can take those incidents and correlate them to other tools that we use. It serves as our single pane of focus.

Our security ops team's remediation time with Splunk Enterprise Security is measured in minutes. One notable improvement has been the maturation of our SOC, which now features a single pane of glass for incident viewing.

What needs improvement?

The correlation of events is the most significant challenge I face when using Splunk Enterprise Security for advanced threat detection. I am still looking at version 8 to see how it can be improved or how we can utilize it better.

For how long have I used the solution?

I have been using Splunk Enterprise Security for three years.

Buyer's Guide
Splunk Enterprise Security
September 2026
Learn what your peers think about Splunk Enterprise Security. Get advice and tips from experienced pros sharing their opinions. Updated: September 2026.
915,287 professionals have used our research since 2012.

What do I think about the stability of the solution?

I assess the stability and reliability of Splunk Enterprise Security as having some issues because we have problems with our SC4S. We are working through it. There are some things that we need to troubleshoot, but we are addressing those.

What do I think about the scalability of the solution?

It is easy to scale Splunk Enterprise Security, and the plan is to expand it, however, we are in the planning stages right now. My experience with scaling has been smooth.

How are customer service and support?

I evaluate customer service and technical support as good, with no issues.

On a scale of one to ten, I would rate customer service and technical support an eight.

How was the initial setup?

My experience with pricing, setup costs, and licensing is that they are expensive and growing, but that is really above my level. Our C suite handles more of the pricing aspects.

What about the implementation team?

I find the process for customizing, developing, testing, deploying, and refining detections in Splunk Enterprise Security not overly complicated because we use Splunk resources to help us with this. It is not as challenging as we would think it would be.

What was our ROI?

I have seen a return on investment with Splunk Enterprise Security.

Which other solutions did I evaluate?

I use other security solutions that integrate or import data into Splunk Enterprise Security such as CrowdStrike, Proofpoint, and a threat intel platform called ThreatConnect.

What other advice do I have?

My advice to other organizations considering Splunk Enterprise Security is to weigh their options, but I would definitely recommend it.

On a scale of one to ten, I rate Splunk Enterprise Security an eight.

Which deployment model are you using for this solution?

Public Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
R Nandasana - PeerSpot reviewer
Senior Information Technology Security Consultant at Mideast Data Systems
Real User
Top 5Leaderboard
Jun 28, 2025
Saves a lot of time with powerful alerting and notification mechanism
Pros and Cons
  • "I would definitely recommend Splunk Enterprise Security because if you are really concerned about security and want to follow compliance rules, this product is really helpful."
  • "We can only increase the environment. For instance, with an ES server, we cannot make a cluster of ES. If you have two servers and want to make a cluster of these two servers for ES, that is not possible."

What is our primary use case?

Our purpose for using Splunk Enterprise Security is SIEM.

How has it helped my organization?

Machine learning has been incredibly beneficial in our efforts to detect various threats. For example, we pull all security logs and utilize the MLTK framework, which helps us identify potential risks effectively. So, overall, it's been quite helpful.

We use the risk-based alerting feature. For instance, when it detects a failed login attempt, it assigns a risk score to it. This allows us to utilize the risk-based alerting features effectively to prioritize incidents based on their severity.

Risk-based alerting generates notifications based on the level of risk associated with a transaction. This approach effectively assists in monitoring transactions, such as payments. It allows us to track the progress of a transaction, from initiation to completion, and identify any errors that may occur during the process. If there are numerous errors, we can assess the risk and determine whether the transaction might be a false positive.

Splunk Enterprise Security has been very helpful in this regard. However, I've noticed that improvement is still needed. We need to analyze the data more thoroughly. While this can be quite complex, finding a simpler solution would be beneficial.

What is most valuable?

The best features of Splunk Enterprise Security are the correlation rules and automation over the correlation rules. We can trigger alerts and notifications. The alerting and notification mechanism is really powerful and good. 

What needs improvement?

It needs more AI integration. The threat intelligence framework requires some AI functionality, which would be helpful.

For how long have I used the solution?

We have been using Splunk Enterprise Security for a couple of years, and I have been on the ES team for the last year. I have also used it in my previous company.

What do I think about the stability of the solution?

The stability of Splunk Enterprise Security rates at eight out of ten.

What do I think about the scalability of the solution?

It is scalable. We can only increase the environment. For instance, with an ES server, we cannot make a cluster of ES. If you have two servers and want to make a cluster of these two servers for ES, that is not possible. There is only one server, and if you want to increase scalability, you must increase the RAM and memory for that same server. The scalability is an eight out of ten.

We simply request Splunk support to increase our storage or make other adjustments as needed. We don't have access to AWS; all of that is managed by Splunk. We just need to reach out to them and say, "Please increase our storage by one terabyte," and they can handle that for us.

How are customer service and support?

Technical support for Splunk Enterprise Security is very good. We have daily calls. They are very helpful, rating at nine out of ten.

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

We tried LogScale in the past, but it has very limited functionalities and not a proper UI. It offers approximately 10% of Splunk Enterprise Security's capabilities. We haven't found any solution comparable to Splunk Enterprise Security.

How was the initial setup?

We utilize a combination of both cloud and on-premises setup. Specifically, we use Splunk Cloud for search indexes and other things. On the on-premises side, we have our heavy forwarders, standard forwarders, and user-defined forwarders. So, we effectively integrate both approaches.

The deployment for Splunk Cloud is very easy. They have predefined templates and setups on the AWS end. They utilize many AWS features. If you terminate any indexer, it will spawn up again. This type of automation exists with Splunk Cloud, making it really efficient.

It doesn't require any maintenance, but when we are doing batch upgrades, we need downtime, which is acceptable. It's four to five hours of downtime.

What about the implementation team?

Currently we have a team of seven people for Splunk Enterprise Security, with additional staff using Splunk Cloud and related services.

What was our ROI?

Splunk Enterprise Security helps to save a lot of time, which is our main purpose. Whenever something is wrong in our environment, we immediately get an alert. It saves time and costs. Compared to traditional methods, Splunk Enterprise Security saves approximately 40% to 50% of time.

What's my experience with pricing, setup cost, and licensing?

For small customers, Splunk Enterprise Security is quite expensive. For my team with a substantial budget, the cost is acceptable.

What other advice do I have?

I would definitely recommend Splunk Enterprise Security because if you are really concerned about security and want to follow compliance rules, this product is really helpful.

Splunk Enterprise Security helps save significant time and money, which most customers are looking for. It is easy to configure and manage. If you have certification or basic knowledge of Splunk Enterprise Security, it provides excellent job opportunities. The solution provides numerous helpful dashboards where you can directly check threats and other metrics. 

Overall, I would rate it an eight out of ten.

Which deployment model are you using for this solution?

Public Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Amazon Web Services (AWS)
Disclosure: My company has a business relationship with this vendor other than being a customer. partner
PeerSpot user
Buyer's Guide
Splunk Enterprise Security
September 2026
Learn what your peers think about Splunk Enterprise Security. Get advice and tips from experienced pros sharing their opinions. Updated: September 2026.
915,287 professionals have used our research since 2012.
reviewer2899035 - PeerSpot reviewer
IT Security Officer at a government with 10,001+ employees
Real User
Top 20
Sep 16, 2026
Security dashboards have boosted threat response and have accelerated data‑driven decisions
Pros and Cons
  • "Splunk Enterprise Security has positively impacted my organization by speeding up our ability to respond to security threats, improving my response time from a time span of months to a time span of days."

    What is our primary use case?

    I have been using Splunk Enterprise Security for five years.

    My main use case for Splunk Enterprise Security is reports and dashboards.

    I use reports and dashboards to show vulnerability information.

    It helps my day-to-day work or decision-making by speeding up decision-making and making it easier to see trends to make decisions.

    What is most valuable?

    The best features Splunk Enterprise Security offers include the ability to aggregate data from multiple sources.

    Aggregating data from multiple sources benefits my work by allowing us to compare information from different security and networking tools to verify correctness.

    Splunk Enterprise Security has positively impacted my organization by speeding up our ability to respond to security threats. My response time has improved from a time span of months to a time span of days.

    What needs improvement?

    Everything is good with Splunk Enterprise Security, and I have nothing that comes to mind regarding improvements, even small things that could make my experience better.

    For how long have I used the solution?

    I have been using Splunk Enterprise Security for five years.

    What do I think about the stability of the solution?

    Splunk Enterprise Security is stable.

    What do I think about the scalability of the solution?

    Its scalability seems very good, but licensing is expensive.

    Which solution did I use previously and why did I switch?

    I did not previously use a different solution, as there was no previous solution.

    How was the initial setup?

    Splunk Enterprise Security is deployed on-premises in my organization.

    What was our ROI?

    It has definitely saved time and improved efficiency, indicating a return on investment.

    What's my experience with pricing, setup cost, and licensing?

    My experience with pricing, setup cost, and licensing was overall reasonable but expensive.

    Which other solutions did I evaluate?

    I did not evaluate other options before choosing Splunk Enterprise Security, as no other options were considered.

    What other advice do I have?

    Splunk Enterprise Security's risk-based alerting, RBA, has improved productivity and provided more useful alerting than manual alerts.

    I am unsure if the integration of threat intelligence directly into the TDIR workflow has improved my ability to preemptively block threats.

    I assess the threat topology and MITRE ATT&CK framework features as very useful in helping me discover the overall scope of an incident.

    I have not used the native UEBA capability to enhance my visibility into unknown, sophisticated, or insider threats.

    I would recommend Splunk Enterprise Security to others looking into using it. I gave this review a rating of 10.

    Which deployment model are you using for this solution?

    On-premises
    Disclosure: My company does not have a business relationship with this vendor other than being a customer.
    Last updated: Sep 16, 2026
    Flag as inappropriate
    PeerSpot user
    reviewer2745975 - PeerSpot reviewer
    Works at a marketing services firm with 1,001-5,000 employees
    Real User
    Top 20
    Jul 29, 2025
    Extensive customization facilitates threat detection but integration with cloud and Git needs improvement
    Pros and Cons
    • "The product is generally stable and forgiving."
    • "The GUI, now called Mission Control, which serves as issue management or ticket management, falls below what would be considered industry standards."
    • "The AWS add-on is particularly problematic, with most inputs requiring manual writing due to lack of out-of-box functionality."

    What is our primary use case?

    My use cases for Splunk Enterprise Security are extensive in production. I utilize it for all available functions including observability, asset management, vulnerability management, threat detection, network security, identity management, and various other capabilities.

    How has it helped my organization?

    The solution does require a lot of customization for an organization. 

    What is most valuable?

    It is highly customizable, which is a significant advantage. It requires substantial customization and tailoring to particular organization requirements, meaning that out of the box, most features would need configuration.

    What needs improvement?

    The risk and notables component, particularly the two-tier system of picking something from risk into the notable, is one of the most problematic features. 

    The GUI, now called Mission Control, which serves as issue management or ticket management, falls below what would be considered industry standards.

    AI assistance for security analysts to analyze notables and risks needs improvement. Although it exists, the demonstration is not yet sufficient for the required level. We need this as soon as possible to help security analysts. 

    Splunk Enterprise Security is not cloud environment-friendly, especially when dealing with large cloud infrastructures. With significant AWS presence and multiple clouds, collecting asset data is challenging. The AWS add-on is particularly problematic, with most inputs requiring manual writing due to lack of out-of-box functionality.

    Regarding the platform and Enterprise Security specifically, the lack of Git-friendly or Git-native integration is problematic. The recently introduced content management system is inadequate, attempting to implement an outdated concept of storing rule versions in an index while teams work with Git natively.

    The storage of queries in savedsearches.conf prevents efficient work with query text. It should be structured as separate SPL files that can utilize intellectual add-ons for Visual Studio Code and work natively with GitHub. Content management is limited to applications within the Enterprise Security suite, excluding custom applications not starting with SA or DA.

    For how long have I used the solution?

    I have been using Splunk Enterprise Security for more than five years.

    What do I think about the stability of the solution?

    The product is generally stable and forgiving.

    What do I think about the scalability of the solution?

    When considering Enterprise Security in particular, it demonstrates good scalability.

    How are customer service and support?

    I contacted their technical support recently. The support provided is decent, though they often reference their knowledge base. For publicly available solutions, this can be redundant as these solutions can be found through internet searches. Support becomes valuable when dealing with issues requiring access to their closed knowledge base for faster responses.

    While support provides solutions, implementation can be complex. In a recent case, the provided solution was so complex to implement that I decided not to proceed. The support staff themselves are highly knowledgeable, polite, and responsive, with some being exceptional. The support team deserves a perfect score.

    How would you rate customer service and support?

    Positive

    Which solution did I use previously and why did I switch?

    I have experience with similar solutions such as AlienVault and ArcSight, each with its advantages and disadvantages. The recommendation depends on the working environment. For cloud-native and GitHub-native organizations, the Enterprise Security solution should align with those principles.

    How was the initial setup?

    I was solely responsible for the implementation.

    It was one of the most difficult deployments I've ever handled. After we set up a cluster with consultants, we made it usable after a year and a half. 

    Splunk Enterprise Security requires continuous maintenance, consuming approximately 50% of the time. The numerous data sources and constantly changing formats and source types demand ongoing work on data quality, detection rules, assets, and identities.

    People are delegated for platform administration, though they currently need additional time to reach optimal performance levels.

    What about the implementation team?

    We did work with consultants during the deployment. 

    What's my experience with pricing, setup cost, and licensing?

    The pricing is currently managed by procurement. Even with substantial company discounts, it remains extremely expensive. This creates internal challenges when teams independently choose open-source or less expensive solutions for log dumping. Duplicating application logs becomes costly as teams may already use DataDog, ELK stack, Elasticsearch, or S3.

    With data ingestion of two terabytes or more daily, Splunk Enterprise Security costs become significant. Cloud-native solutions, particularly in AWS, make it more practical to use native security detection mechanisms such as Security Hub, GuardDuty, and Inspector, using Splunk Enterprise Security as a data aggregator.

    Many users prefer pre-processing data before ingestion using the Databricks platform for large data sources such as cloud trail logs. The on-premises pricing model based on data ingestion affects Splunk Enterprise Security's market position.

    What other advice do I have?

    This product requires significant investment in learning as it is not easily understood. Organizations purchasing the solution should expect 6-12 months with a dedicated team before meaningful insights can be delivered.

    On a scale from one to ten, Splunk Enterprise Security rates as a seven.

    Which deployment model are you using for this solution?

    On-premises

    If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

    Amazon Web Services (AWS)
    Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
    PeerSpot user
    reviewer2899080 - PeerSpot reviewer
    System administrator at a computer software company with 201-500 employees
    Real User
    Top 20
    Sep 16, 2026
    Log analytics has improved root cause analysis and now reduces false positives faster
    Pros and Cons
    • "Splunk Enterprise Security has helped improve my organization's business resilience, and I found it to be very effective for helping identify when a system goes down or is operating at an improper level before an actual issue occurs."

      What is our primary use case?

      My main use case for Splunk Enterprise Security is log analytics. I use Splunk Enterprise Security for log analytics in my day-to-day work by checking for failed logins from specific users, whether or not they're a known user or an unknown user, and seeing if this is abnormal behavior or someone who just forgot their password.

      We also use Splunk Enterprise Security for tracking vulnerabilities and mitigations.

      What is most valuable?

      The best features Splunk Enterprise Security offers include an easy user interface. What makes the user interface of Splunk Enterprise Security stand out for me is that as an administrator, I can type in SPL commands to get what I want, but I can also make pivots to allow non-technical users to gain information through dashboards.

      Splunk Enterprise Security's risk-based alerting has improved analyst productivity as it gets rid of some of the low-level taskings. I find Splunk Enterprise Security's threat topology and MITRE ATT&CK framework features quite effective as they help us identify how the risk is going to be executed, if it will, and how likely the risk or threat is to become a vulnerability.

      What needs improvement?

      I am quite happy with the feature set of Splunk Enterprise Security, and I think it can be improved. Nothing comes to mind regarding areas for improvement, even a small one, that could make my day-to-day work even smoother.

      For how long have I used the solution?

      I have been using Splunk Enterprise Security for one year.

      What do I think about the stability of the solution?

      Splunk Enterprise Security is stable.

      What do I think about the scalability of the solution?

      Splunk Enterprise Security's scalability is very good.

      How are customer service and support?

      The customer support for Splunk Enterprise Security is very good.

      Which solution did I use previously and why did I switch?

      I did not previously use a different solution.

      How was the initial setup?

      I was not involved in the pricing, setup cost, and licensing experience.

      Which other solutions did I evaluate?

      I was not part of the process of evaluating other options before choosing Splunk Enterprise Security.

      What other advice do I have?

      Splunk Enterprise Security has positively impacted my organization by making it significantly easier for us to do root cause analysis. A specific example of a situation where Splunk Enterprise Security helped with root cause analysis is that we have seen a significant reduction in the amount of time to identify false positives in certain situations.

      Splunk Enterprise Security has helped improve my organization's business resilience, and I found it to be very effective for helping identify when a system goes down or is operating at an improper level before an actual issue occurs. Splunk Enterprise Security has helped reduce my team's average mean time to resolve, MTTR metric, and while I don't have an exact percentage, it has helped us do root cause analysis.

      Splunk Enterprise Security has helped me detect threats faster, and while I don't know how much faster, it has seen an improvement as we use Tenable security, and it ingests that data to help us identify threats. My advice to others looking into using Splunk Enterprise Security is to optimize your data inputs so you can best use Splunk Enterprise Security to help you. I would rate this product an 8 out of 10.

      Which deployment model are you using for this solution?

      On-premises
      Disclosure: My company does not have a business relationship with this vendor other than being a customer.
      Last updated: Sep 16, 2026
      Flag as inappropriate
      PeerSpot user
      reviewer2750622 - PeerSpot reviewer
      Technical Lead at a tech vendor with 5,001-10,000 employees
      Real User
      Top 10
      Apr 16, 2026
      Monitoring file transfers has become detailed and reporting now provides flexible, time-based insights
      Pros and Cons
      • "Splunk Enterprise Security has the capability to pull the report from anytime or any respective time, or if I need it from all the time, then it can be helpful."
      • "Because we are using a licensed DataDog, which gives us more reliable results. And for file logs, we are using a BAM, a business audit and monitoring tool, which gives us a more visualized experience than Splunk Enterprise Security."

      What is our primary use case?

      Currently we are using Splunk Enterprise Security for monitoring the jobs and along with Splunk Enterprise Security, we are using DataDog where it will be used for monitoring the servers and our URLs.

      Currently, we are using it only for monitoring because that is going to be decommissioned very soon. So we have only had it active for monitoring for the last four years.

      Currently, we are using the on-premises and we are slowly going to be migrated to the cloud, and then we can use that for whatever we have existing. We can utilize it in the cloud.

      Splunk Enterprise Security is only used for our MFT tool purpose, which is integrated with our MFT tool.

      What is most valuable?

      Splunk Enterprise Security has the capability to pull the report from anytime or any respective time, or if I need it from all the time, then it can be helpful. And we can also set the monitoring for a particular server, particular file type, or a particular user. Those are some of the good features which I really appreciate.

      Threat detection is not something we use. Our TechSec team uses their own respective tools such as Qualys to pull out the reports. And apart from that, they mainly look into DataDog.

      DataDog will give a more pictorial idea of what went wrong, where it lagged, and where the issue is. But Splunk Enterprise Security won't give that much pictorial detail.

      Compared to other tools, Splunk Enterprise Security is kind of user-friendly.

      Initially, it was helping us to give the logs and integrate with Splunk Enterprise Security and all.

      What needs improvement?

      The main challenge is that it runs on the Linux part. So that is a very big challenge for us where we have installed it on the Linux machine. And getting it moved out from the Linux machine is the biggest challenge for us currently. So it is not so friendly for us to do that. That is why we came up with DataDog and then Splunk Enterprise Security is going out.

      Now, we currently have completed all the setups. We are currently using it on-premises, but going forward, we will be utilizing the cloud environment.

      Because we are using a licensed DataDog, which gives us more reliable results. And for file logs, we are using a BAM, a business audit and monitoring tool, which gives us a more visualized experience than Splunk Enterprise Security.

      For how long have I used the solution?

      For five years.

      What do I think about the stability of the solution?

      Currently, there are no stability issues. I am not that good at providing any advice, but these are my few feedbacks.

      What do I think about the scalability of the solution?

      Currently, there are no scalability issues.

      How are customer service and support?

      Currently, customer service is limited.

      Which solution did I use previously and why did I switch?

      We are using a licensed DataDog, which gives us more reliable results.

      How was the initial setup?

      It is not a support kind of thing. It is just helpful for looking around the logs.

      What about the implementation team?

      Initially, it was helping us to give the logs and integrate with Splunk Enterprise Security and all.

      Which other solutions did I evaluate?

      Our TechSec team mostly uses DataDog.

      What other advice do I have?

      I am using a Globalscape, not Axway.

      I am working on MFT and SSIS.

      Splunk Enterprise Security is only used for our MFT tool purpose, which is integrated with our MFT tool. Otherwise, our TechSec team mostly uses DataDog.

      The complete Splunk Enterprise Security itself is going out, going to be decommissioned. So we are not at all using it. So I do not think there will be any more advancement on that part.

      Currently, we do not have it.

      I do not have any details about that.

      It has had some of it, but as we are moving out of it, we never look into it so deeply. For the time being, it will be just refixed.

      It is a good product. I rate this product an overall 8 out of 10.

      Which deployment model are you using for this solution?

      On-premises

      If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

      Other
      Disclosure: My company does not have a business relationship with this vendor other than being a customer.
      Last updated: Apr 16, 2026
      Flag as inappropriate
      PeerSpot user
      Manager cybersecurity at Hexion Inc.
      Real User
      Top 5
      Aug 4, 2025
      Effectively monitors cybersecurity risks and improves IT landscape visibility
      Pros and Cons
      • "From a visibility perspective, the solution has significantly improved our organization by providing a single platform to visualize our entire IT landscape."
      • "The best features I've experienced over the past six years with Splunk Enterprise Security are the ability to create use cases and the flexibility to customize searches and use cases based on our specific requirements."
      • "Regarding room for improvement, I expect Splunk to provide information about new features on a regular basis, such as notifications about enhancements that may improve security posture."

      What is our primary use case?

      We use Splunk Enterprise Security for security monitoring purposes, and we have many security use cases configured to detect cybersecurity-related risks. We have 100+ use cases related to brute force attacks, ransomware, credential access attacks, et cetera.

      We use it for the extra security layer since we want to be very proactive and monitor our infrastructure fully end-to-end.

      How has it helped my organization?

      We now have a single platform where we can visualize our entire landscape. It's improved our security posture. We can see all the logs getting ingested, and if there are any anomalies, we're able to visualize that as well. The alerts help us be very proactive. We used to miss a few things happening in our organization. Now we get alerts on time. 

      What is most valuable?

      The best features I've experienced over the past six years with Splunk Enterprise Security are the ability to create use cases and the flexibility to customize searches and use cases based on our specific requirements. 

      It's user-friendly. You don't need to be an expert to create a use case. Even a basic understanding will allow you to do the work. There are lots of knowledge articles as well. 

      From a visibility perspective, the solution has significantly improved our organization by providing a single platform to visualize our entire IT landscape. This has also enhanced our security posture by enabling us to view all logs.

      We do connect with a Splunk representative on a monthly basis. They can proactively provide us with solutions. 

      What needs improvement?

      Regarding room for improvement, I expect Splunk to provide information about new features on a regular basis, such as notifications about enhancements that may improve security posture. I want these notifications to come to us quite regularly, as we always want to improve our security posture. 

      I'm interested in the notifications and alerts aspect, particularly since Splunk Enterprise Security's Mission Control feature was very proactive when it was rolled out.

      For how long have I used the solution?

      I have been using Splunk Enterprise Security for the last six years.

      What do I think about the stability of the solution?

      I would rate the stability at eight out of ten; we never had any gap in monitoring. That said, there were instances of backend issues that did not impact our monitoring.

      What do I think about the scalability of the solution?

      It is a scalable solution for our business, and I would rate it nine out of ten, as we have recently scaled it to monitor operational use cases.

      How are customer service and support?

      I would rate the technical support as nine out of ten. They are always on top of resolving issues, providing technical account manager details for further assistance. 

      How would you rate customer service and support?

      Positive

      Which solution did I use previously and why did I switch?

      We had tried IBM QRadar and Azure Sentinel previously.

      How was the initial setup?

      If I need to set up Splunk from scratch, I don't have to do a lot of planning. It's pretty straightforward. 

      It took about a month to deploy Splunk Enterprise Security, as we took many days to plan how to set up the architecture.

      There is some maintenance required once it is set up.

      What about the implementation team?

      The IT team exclusively uses Splunk Enterprise Security for assistance. The team is always there to assist.

      What's my experience with pricing, setup cost, and licensing?

      I don't deal with pricing. I have a fair understanding based on the market research; from what I've witnessed, the pricing is competitive.

      What other advice do I have?

      I rate Splunk Enterprise Security higher due to its user-friendliness. That is something on top of my list. 

      Splunk Enterprise Security is on top in terms of how users or administrators can manage it. Everything else looks pretty fine regarding the support we get from Splunk Enterprise Security. 

      I would rate Splunk Enterprise Security overall as eight out of ten.

      Which deployment model are you using for this solution?

      Hybrid Cloud

      If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

      Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
      PeerSpot user
      Hamada Elewa - PeerSpot reviewer
      System Engineer - Security Presales at Raya Integration
      Real User
      Top 5
      Feb 10, 2025
      Achieve comprehensive data visibility with versatile language
      Pros and Cons
      • "Splunk Enterprise Security's most valuable features are its stability and the robust Splunk Search Processing Language, allowing extensive customization and analysis capabilities."
      • "Splunk simplifies real-time problem identification and resolution by seamlessly integrating existing customer and vendor systems."
      • "Splunk could enhance its offerings by incorporating modules for network detection and response and fraud management, along with improving its threat intelligence management capabilities."

      What is our primary use case?

      After the acquisition by Cisco, we are focusing on our partnership with them as a Gold Partner and Tier One reseller. Following the acquisition, we also shifted our focus to Splunk. I am a system integrator implementing Splunk for customers in their environments.

      How has it helped my organization?

      Splunk has a vast integration with multiple vendors, which makes it easy for our customers to integrate various cloud environments. 

      Splunk provides complete visibility when integrated with all installed appliances and applications.

      The threat intelligence management feature is a good add-on for startups, especially given its affordability.

      Splunk allows organizations to ingest and normalize data effectively.

      Splunk simplifies real-time problem identification and resolution by seamlessly integrating existing customer and vendor systems. Its customizable dashboards can be tailored to map and reflect specific environmental needs precisely.

      The threat topology and MITRE ATT&CK framework features can help discover the full scope of a security incident, provided they are fully integrated into the customer's environment.

      Splunk's comprehensive log visibility enables efficient investigation of malicious activities and breaches. By generating a dashboard that collects logs from firewalls, emails, proxy endpoints, and threat intelligence, Splunk can provide access to critical information within seconds, significantly reducing investigation time compared to other vendors or solutions. This streamlined process, facilitated by Splunk's ability to gather and analyze diverse log data, ensures swift identification and resolution of security incidents.

      It helps our customers improve their organization's business resilience.

      The unified platform helps consolidate networking infrastructure and security. This single-platform approach offers the advantage of combining multiple technologies and features, streamlining operations and enhancing efficiency.

      Implementing Splunk with SOAR capabilities, along with machine learning and AI for alert filtering, can significantly reduce alert volume without constantly interrupting administrators. This streamlined approach ensures that only alerts requiring approval are sent to administrators, optimizing their workflow and efficiency.

      The analysts using Splunk, even the free edition, are very satisfied with the information it provides for their investigations.

      Splunk has helped customers accelerate their security investigations by integrating AI and machine learning into its platform. This integration automates many basic tasks and saves valuable time.

      Splunk helps reduce our customer's mean time to resolve. 

      What is most valuable?

      Splunk Enterprise Security's most valuable features are its stability and the robust Splunk Search Processing Language, allowing extensive customization and analysis capabilities.

      What needs improvement?

      Splunk could enhance its offerings by incorporating modules for network detection and response and fraud management, along with improving its threat intelligence management capabilities. Additionally, the pricing could be made more competitive.

      For how long have I used the solution?

      I have been using Splunk Enterprise Security for almost six months.

      What do I think about the stability of the solution?

      Splunk is a very stable platform.

      What was our ROI?

      My customers feel it's a good investment, but Splunk updated its price models recently.

      What's my experience with pricing, setup cost, and licensing?

      One of Splunk's two major disadvantages is its high cost. The platform requires significant financial investment and resources, making it expensive despite its comprehensive features.

      What other advice do I have?

      Splunk has disadvantages such as cost and resource requirements. However, once I invest, it's a powerful platform that ranks number one in SIEM and observability. I rate the product nine out of ten due to pricing concerns and threat intelligence management not being advanced.

      I believe Splunk is the top SIEM tool. However, the term "enterprise security" is misused when applied to Splunk. While many vendors claim to offer "enterprise security," true enterprise security should cover all aspects of cybersecurity. Splunk excels in SIEM, SOAR, and UEBA, but it doesn't address other crucial areas like firewalls, PAM, or web/mail gateways. Therefore, Splunk shouldn't be categorized as an "enterprise security" solution. Although Splunk leads in SIEM with its superior visibility and observability, it lacks presence in other essential cybersecurity domains.

      Which deployment model are you using for this solution?

      Hybrid Cloud

      If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

      Other
      Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
      PeerSpot user
      reviewer2898978 - PeerSpot reviewer
      Splunk Architect at a tech consulting company with 11-50 employees
      Real User
      Top 20
      Sep 15, 2026
      Analyst workflows have improved and investigations gain speed with integrated automation
      Pros and Cons
      • "Analyst productivity has risen because they started using Splunk instead of the other product, the third-party SIEMs, and the detection has really improved because they are doing everything by SLA and fitting into these tight schedules, and our clients really love Splunk Enterprise Security."

        What is our primary use case?

        My main use case for Splunk Enterprise Security involves security and analyzing things using Splunk Enterprise in a SOC, and also building searches and findings there for our clients.

        We utilized Splunk Enterprise Security for building new findings, and those findings are being analyzed right now by our clients, our bank client analysts, who are doing their best with Splunk Enterprise Security.

        I cannot share anything unique about my main use case because I am under NDA, but we are trying to implement new products from Splunk, such as adding Splunk SOAR to Splunk Enterprise Security environment. We came to this conference to learn the best ways to implement it and to take experiences from other people who might share it with us.

        What is most valuable?

        The best features Splunk Enterprise Security offers are findings, investigations, and the actions inside of Splunk Enterprise Security, as well as the audit for upper management to see how the analysts are working. Additionally, there is a very convenient way of integrating Splunk with SOAR, not just Splunk SOAR but even other SOARs, and that is why we think Splunk Enterprise Security is the best in its field.

        The convenient way of integrating Splunk SOAR with Splunk Enterprise Security is that our analysts and our L2s can run playbooks easily just from Splunk Enterprise Security without entering Splunk SOAR. They can do everything from one window without jumping from Splunk Enterprise Security to Splunk SOAR, and everything can be run from the investigation tab. That is what is great about that feature.

        Concerning the audit capabilities of Splunk Enterprise Security, clients sometimes ask for compliance or audit of their whole SOC team, and that is how the audit feature of Splunk Enterprise Security is usually used.

        Because we are a Splunk partner and also resellers of Splunk, it has impacted us in many ways, but mostly we are getting many clients because Splunk is great at presenting it to someone. We are also getting really good deals when selling it to our clients from Splunk itself, which means the good deals come from Splunk.

        Analyst productivity has risen because they started using Splunk instead of the other product, the third-party SIEMs. The detection has really improved because they are doing everything by SLA and fitting into these tight schedules. Our clients really love Splunk Enterprise Security.

        Splunk Enterprise Security has helped our clients detect threats faster, and I estimate by approximately fifty percent.

        What needs improvement?

        To improve Splunk Enterprise Security, I suggest starting to add SOAR inside of Splunk Enterprise Security without having two separate servers for that. I believe it might be accomplished in the future.

        For how long have I used the solution?

        I have been using Splunk Enterprise Security for five years.

        What do I think about the scalability of the solution?

        Splunk Enterprise Security's scalability is great.

        How are customer service and support?

        The customer support for Splunk Enterprise Security is good.

        Which solution did I use previously and why did I switch?

        We did not previously use a different solution.

        What's my experience with pricing, setup cost, and licensing?

        My experience with pricing, setup cost, and licensing is that it was light work and light price.

        What other advice do I have?

        My advice for others looking into using Splunk Enterprise Security is to just buy it. I would rate this review a ten out of ten.

        Which deployment model are you using for this solution?

        On-premises
        Disclosure: My company has a business relationship with this vendor other than being a customer. Partner, Reseller
        Last updated: Sep 15, 2026
        Flag as inappropriate
        PeerSpot user
        reviewer2756172 - PeerSpot reviewer
        Incident Response Engineer at a international affairs institute with 1,001-5,000 employees
        Real User
        Top 20
        Sep 13, 2025
        Improves threat detection and streamlines investigations with integrated threat intelligence
        Pros and Cons
        • "I have not experienced any downtime, crashes, or performance issues with Splunk Enterprise Security."
        • "Some additional features that should be included in the next release of Splunk Enterprise Security are an integrated Attack Range, not as a separate solution, providing a way to test the rules in the production environment."

        What is our primary use case?

        My main use cases for Splunk Enterprise Security include insider threat hunting, supporting operations, and Threat Intel integration for security; I have a lot of use cases.

        How has it helped my organization?

        The features of Splunk Enterprise Security benefit my organization by providing a faster response and making it easier for the analyst to investigate.

        What is most valuable?

        The features I appreciate the most about Splunk Enterprise Security are the Enterprise Security features, the threat intelligence of Enterprise Security, the onboarded ones, and the versioning of the rules introduced on Enterprise Security; these are the top ones.

        My organization uses risk-based alerting in Splunk Enterprise Security. Splunk Enterprise Security has supported my SOC a lot, however, we have some challenges due to the architecture of our network, so there is some custom work to be done by Splunk engineers to help us maximize the benefits.

        I am using new threat detection features in Splunk Enterprise Security, including the onboard ones and Mandiant. These new features have highly improved our threat detection capabilities.

        Splunk Enterprise Security has helped improve my organization's business resilience.

        I'm not dealing with pricing, setup costs, or licensing for Splunk Enterprise Security; I'm focused on the technical part. What works with Splunk Enterprise Security is that it does work in general; I haven't faced any challenges; it's great.

        What needs improvement?

        Improving Splunk Enterprise Security is a challenging task; I have already reported several technical issues to the relevant teams and received solutions from them.

        One favor I ask for them is just to keep maintaining the on-prem version of Enterprise Security and not move everything to the cloud since we operate mostly in an air-gapped environment, so we only use some of the features of it.

        Some additional features that should be included in the next release of Splunk Enterprise Security are an integrated Attack Range, not as a separate solution, and providing a way to test the rules in the production environment.

        For how long have I used the solution?

        I've been using the solution for 11 years.

        What do I think about the stability of the solution?

        I have not experienced any downtime, crashes, or performance issues with Splunk Enterprise Security.

        What do I think about the scalability of the solution?

        Splunk Enterprise Security scales pretty well with the growing needs of my organization; we don't have issues. I have expanded the usage of Splunk Enterprise Security a lot. The process of expanding usage has been smooth; I have no problems so far, and it scales very easily.

        How are customer service and support?

        I would evaluate customer service and technical support for Splunk Enterprise Security as fast.

        How would you rate customer service and support?

        Positive

        How was the initial setup?

        I would describe my experience with deploying Splunk Enterprise Security as straightforward.

        What was our ROI?

        I have seen a return on investment with Splunk Enterprise Security, definitely, however, I don't have the specific metrics to back that up.

        What other advice do I have?

        The most significant challenge I face when using Splunk Enterprise Security for advanced threat detection is alert fatigue. Although there are ways to mitigate it, it remains a persistent issue, as evidenced by complaints from analysts. While alert fatigue is alleviated to some extent, it still persists.

        My advice to other organizations considering Splunk Enterprise Security is to at least give it a try; I know there are other solutions in the market, some of which may even be better than Enterprise Security, however, you have everything on a single pane of glass, so I think it's definitely something that enterprises should test.

        On a scale of one to ten, I rate Splunk Enterprise Security an eight out of ten.

        Which deployment model are you using for this solution?

        On-premises
        Disclosure: My company does not have a business relationship with this vendor other than being a customer.
        PeerSpot user
        Buyer's Guide
        Download our free Splunk Enterprise Security Report and get advice and tips from experienced pros sharing their opinions.
        Updated: September 2026
        Buyer's Guide
        Download our free Splunk Enterprise Security Report and get advice and tips from experienced pros sharing their opinions.