We develop use cases for Splunk Enterprise Security all the time. I mostly work with the SOAR platform to ingest those use cases.
Splunk developer at a government with 5,001-10,000 employees
The incident review functionality gives a good overview of security incidents
Pros and Cons
- "The solution's most valuable feature is the incident review, which gives a good overview of our security incidents."
- "You can run a script from an event, but it needs many clicks to run that integration, which could be made easier."
What is our primary use case?
How has it helped my organization?
Splunk Enterprise Security helps our organization because we use it daily to solve our security use cases. We have incidents every day.
What is most valuable?
The most valuable feature is the incident review, which gives a good overview of our security incidents. I also like the solution's search functionality, which makes it easy to find things.
Splunk Enterprise Security generates our alerts, and we would have to refine the searches if we want to reduce them.
It's very important to our organization that Splunk Enterprise Security provides end-to-end visibility into our environment.
Splunk Enterprise Security has helped reduce our mean time to resolve and helped improve our organization’s business resilience.
What needs improvement?
The incident review could definitely be improved in many ways. It should be easier to run integrations from it. You can run a script from an event, but it needs many clicks to run that integration, which could be made easier.
Buyer's Guide
Splunk Enterprise Security
July 2026
Learn what your peers think about Splunk Enterprise Security. Get advice and tips from experienced pros sharing their opinions. Updated: July 2026.
909,647 professionals have used our research since 2012.
For how long have I used the solution?
I have been using Splunk Enterprise Security for five years.
What do I think about the stability of the solution?
The solution’s stability is very good, and we haven’t had any stability issues with Splunk Enterprise Security.
What do I think about the scalability of the solution?
The solution’s scalability could have been better.
How are customer service and support?
The solution's technical support is very good, and I'm very happy with the support.
How was the initial setup?
The solution’s initial setup is easy.
What other advice do I have?
Overall, I rate the solution an eight out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Lead Information Security Specialist at a tech services company with 1,001-5,000 employees
Provides end-to-end visibility and reduces the investigation time tenfold
Pros and Cons
- "Correlation search, in general, is valuable because it allows us to search multiple data sources easily."
- "The main issue that I have with it is that the field transformations sometimes overlap with those in Splunk Enterprise, and then you get permissions issues that lead to troubles."
What is our primary use case?
Generally, we leverage it to correlate all of our threat intelligence data with all of our log events to make researching them simpler.
How has it helped my organization?
Splunk Enterprise Security gives us a lot more visibility into the entire enterprise and makes our analysis simpler. It streamlines the process and makes it easier to handle it.
It is very important for us that Splunk Enterprise Security provides end-to-end visibility into our environment. It saves us all the time where we used to have to go from tool to tool to tool to track down issues. Splunk Enterprise Security has tenfold reduced the amount of time it takes to investigate any one thing.
Splunk Enterprise Security simplifies being able to pivot from one data point to everything else, and it does not matter where in the pipeline that occurred because you can see it all.
It has helped improve our organization’s ability to ingest and normalize data. It has been very impressive how it is able to handle all of that for visibility and tracking things down.
Splunk Enterprise Security has not yet helped to reduce our alert volume. Our alert volume has increased at this point because we are still getting used to it, but I see how it can reduce the alert volume.
It provides us with the relevant context to help guide our investigations. The biggest part of it is that when we go through the alerts and the notable events, we are able to pivot to information from data sources that are not necessarily in Splunk, and we are able to run the automated response actions.
Splunk Enterprise Security has helped reduce our mean time to resolve. I do not have the metrics, but it is a decent amount.
Every process has been streamlined. Things for which you have to bounce between multiple tools can be done in one place, which in its nature speeds everything up and reduces the manpower.
What is most valuable?
Correlation search, in general, is valuable because it allows us to search multiple data sources easily.
What needs improvement?
The main issue that I have with it is that the field transformations sometimes overlap with those in Splunk Enterprise, and then you get permissions issues that lead to troubles.
I do not have any additional features that can be included. From what I gather, Mission Control is already included in the next release, as is a lot of the Cisco threat data.
For how long have I used the solution?
I have been using Splunk Enterprise Security for about five and a half years.
What do I think about the stability of the solution?
It is quite good.
What do I think about the scalability of the solution?
I have not experienced any issues with the scalability, but I do not handle the scaling, so I cannot speak to that.
How are customer service and support?
I do not have to deal with them, so I do not have any information. Our administrators handle that side of things.
Which solution did I use previously and why did I switch?
I did not. We acquired Splunk around about the same time I joined the cybersecurity team.
How was the initial setup?
I do not handle the administrative part. I am more of a user.
In terms of the deployment model, I believe it is technically a hybrid deployment. I am not involved in the architecture, but I know we are not exclusively cloud and we are not exclusively on-prem. We use AWS.
What about the implementation team?
I know we had Splunk Professional Services for the deployment, but I was not involved.
What was our ROI?
I do not know what the cost is, but I would imagine we have seen an ROI because we are able to run our security team with fewer people than previously.
Which other solutions did I evaluate?
I do not know what we evaluated because I came to the company at the same time we got Splunk.
What other advice do I have?
I would rate Splunk Enterprise Security an eight out of ten. It is an amazing tool that provides so much visibility and streamlines so much. The main issues I have encountered with Splunk are the difficulties in configuration and keeping everything up to date as the data sources change.
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
Buyer's Guide
Splunk Enterprise Security
July 2026
Learn what your peers think about Splunk Enterprise Security. Get advice and tips from experienced pros sharing their opinions. Updated: July 2026.
909,647 professionals have used our research since 2012.
Engineer at a tech vendor with 501-1,000 employees
Serves as our SIEM, providing security alerts and operational alerts
Pros and Cons
- "The solution's most valuable feature is the criticality of alerts."
- "The solution's automation could be improved."
What is our primary use case?
We usually use the solution for the same functionality, which includes setting up alerting and making notables. We also use it for the workflow from ingestion, alerting, and response.
How has it helped my organization?
Splunk Enterprise Security serves as our SIEM, providing security alerts, operational alerts, and even some logging that we probably need to check in on from time to time. It basically serves as an alerting platform for our enterprise.
What is most valuable?
The solution's most valuable feature is the criticality of alerts. Some alerts can be noise, and others will be more high-level and warrant a higher-level response than others.
What needs improvement?
The solution's automation could be improved. It would be better if we could automate ingesting and alerting for low-level events.
For how long have I used the solution?
I have been using Splunk Enterprise Security for seven to ten years.
What do I think about the stability of the solution?
I rate the solution’s stability a nine out of ten.
How are customer service and support?
For the times I've had to set up incidents from critical to lower ones, the technical support team has been fairly responsive. Sometimes, the support team has had a two to three-hour turnaround time for critical incidents. Usually, you would like to get to someone sooner rather than later for critical incidents.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
I've previously used other SIEM tools like ArcSight, QRadar, and Elastic Security.
What was our ROI?
We have seen a return on investment with the solution.
What other advice do I have?
The solution helps us see what's actually happening in our environment. Some things we might not expect at times, and others we do expect. The tool helps us respond based on what we see from our logs. I've seen and thoroughly liked some AI, automation, and single-pane-of-glass updates coming to the solution.
It is very important to our organization that Splunk Enterprise Security provides end-to-end visibility into our environment. You can't respond to what you can't see was ingested. So, the visibility provided by the tool into our logs and alerting environment is critical.
From an ingestion point of view, the solution alerts you to what you'd tell it to. It's pretty agnostic log-wise.
Splunk Enterprise Security has helped improve our organization’s ability to ingest and normalize data.
It has helped reduce our alert volume. You're getting the same alerts. You can see what's noise, what's actionable, and what's not as actionable.
Splunk Enterprise Security provides us with the relevant context to help guide our investigations. We see what's coming into the environment, including specific logs that we wouldn't expect as much. All of that gets filtered into alert data, potentially operational data, and sometimes even billing data, so we can adjust and move forward with that in the environment.
Splunk Enterprise Security helped reduce our mean time to resolve by somewhere between 20% to 35%.
Splunk Enterprise Security has helped improve our organization's business resilience for some ingestion purposes.
The unified platform helps consolidate networking, security, and IT observability tools. Splunk is pretty log-agnostic. All of your logs, tools, and sometimes even dashboards can get ingested into one specific tool. That way, you have a single platform where you can view all those logs and respond based on that data.
Overall, I rate the solution a nine out of ten.
Which deployment model are you using for this solution?
Public Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
Sr Security Engineer at a insurance company with 5,001-10,000 employees
Risk-based alerting significantly reduces the alert volume and speeds up the investigation
Pros and Cons
- "I am enjoying our implementation of risk-based alerting. That has helped very much with cutting out a lot of the noise that we have. It has reduced our alert volume significantly. There is about an 80% reduction."
- "I do not like the pricing model. It is expensive."
What is our primary use case?
We use it for alerting. It also helps our analysts triage.
How has it helped my organization?
It is our bread and butter and our day-to-day tool for the SOC. Besides alerting, just being able to do research and look through various logs to gather context around the alerts has been super valuable.
It is critical to us that Splunk Enterprise Security provides end-to-end visibility. The place that you cannot see is from where you are going to get attacked.
We have a hybrid cloud environment with AWS and Azure. I am pretty confident in its ability to help us find any security event across our environment. We have put in time to feed Splunk Enterprise Security the data that we want to look at.
I am pretty happy with its ability to ingest data. When it comes to normalizing, my company could improve on that a little because we need to do more tuning of some of the data that we are ingesting. That is not much of an issue with Splunk Enterprise Security. That is more of an issue with how we are using it. We need to possibly do a little bit better in terms of how we utilize this tool.
I am pretty confident in its ability to identify and solve problems in real-time. If it has the data and you implement it properly, it will tell you what is wrong.
With risk-based alerting, we are now getting the right context for investigations. It definitely helps and speeds up the investigation. With risk-based alerting, I can see the chain of events. I can see what caused this to occur. I do not have a percentage, but I know my analysts are not getting the alerts that they have not completed by the end of the shift. Previously, that was not the case, so I am pretty pleased.
Splunk Enterprise Security has helped improve our organization’s business resilience.
Splunk Enterprise Security helps to identify and solve problems in real-time, but I do not know if it can also predict the problems in real-time.
What is most valuable?
I am enjoying our implementation of risk-based alerting. That has helped very much with cutting out a lot of the noise that we have. It has reduced our alert volume significantly. There is about an 80% reduction.
What needs improvement?
I do not like the pricing model. It is expensive.
For how long have I used the solution?
I have been using Splunk Enterprise Security for about five years.
What do I think about the stability of the solution?
I have not had issues with its stability.
What do I think about the scalability of the solution?
It is pretty scalable. It also depends on what you are ingesting, but it does a good job with our data.
How are customer service and support?
I do not use the support that often. Normally, when I am looking for help, I just search on the web. If I am trying to build something and I do not remember the command, it is pretty easy to find.
Which solution did I use previously and why did I switch?
I have used logging solutions. I find Splunk easier to use than other solutions such as LogStack.
With any such tool, the alert quality that you will get is based on the data that you are feeding it. If you are parsing logs and doing a good job with that, the outcome is good.
How was the initial setup?
I did not deploy this instance, but I deployed it in my last company. It was not as bad as I thought. It was comparable to some of the other product rollouts in the environment.
What's my experience with pricing, setup cost, and licensing?
It is expensive, but it is a good tool.
It is worth the cost. I have worked with organizations that did not want to invest in a security tool. I am glad that we are taking security a little more seriously in this organization.
What other advice do I have?
I would rate Splunk Enterprise Security a ten out of ten. I enjoy it. I like it.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Makes it easier to read the index data
Pros and Cons
- "Its alerting is most valuable. We have alerts set up in our environment for certain attacks, such as an SQL injection attempt. We have a front-facing server for the website. It is out there, and anybody can access it. When those SQL injection attempts come in, we are able to detect that with the alert."
- "I do not have any pain points for Splunk Enterprise Security. I am still trying to learn it, but there can be more information on the education side for Splunk Enterprise Security. It would be nice if the certification path was more specific to what I use instead of being so broad."
What is our primary use case?
When we identify a threat in the environment, we try to track down whether it has moved from one system to another or there is any lateral movement. When we are trying to figure out how it got started and where it came from, we use Splunk to identify those logs. Palo Alto is our biggest index for the firewall, and we can look into those logs, see the relevant data, and correlate it into something that makes sense, so we can track down the problem.
How has it helped my organization?
For the most part, it makes it easier to read the index data. Instead of trying to look through an individual index, all the logs, and other aspects, it brings everything to one area. I can look at the relevant data that I need to identify the threat.
Splunk Enterprise Security has helped reduce our mean time to resolve. I do not have the metrics, but I know it is faster compared to the old way of doing it. Previously, we had to go through Windows logs and security logs. We had to go through each log to figure out what happened. I can pull all of the information way faster with Splunk Enterprise Security. I can look at multiple systems.
Splunk's unified platform has helped consolidate networking, security, and IT observability tools.
Splunk Enterprise Security brings all the logs into one central location to look at the relevant data and filter out the things I do not use. We are able to see the logs of multiple systems, the logs of the firewall, and the logs of the DNS and the Windows servers. It is able to bring all of that together and give a nice, solid picture of what is happening. We can read those logs faster.
Splunk Enterprise Security provides end-to-end visibility into the environment. It is very important for our organization to be able to see the threats, understand the threats, and figure out how to stop those threats. That is the importance of it. We are a casino. After what happened last year with two casinos in terms of hacking, we want to be able to stop that from happening to us. We learned a lot of lessons from what happened to the other two casino properties, and we applied them to a lot of our tools. Splunk Enterprise Security gives us a heads-up a lot faster.
Splunk Enterprise Security helped improve our organization’s business resilience.
What is most valuable?
Its alerting is most valuable. We have alerts set up in our environment for certain attacks, such as an SQL injection attempt. We have a front-facing server for the website. It is out there, and anybody can access it. When those SQL injection attempts come in, we can detect that with the alert. We get the alert in our mailbox, so we can start looking at it right away. Generally, with a SQL injection attempt, there is way more to it than just the SQL injection. There could be another 15 or 20 different types of attacks attempted during the injection. They are just trying to see if there is any vulnerability, and then they can take a shot at it.
What needs improvement?
I do not have any pain points for Splunk Enterprise Security. I am still trying to learn it, but there can be more information on the education side for Splunk Enterprise Security. It would be nice if the certification path was more specific to what I use instead of being so broad.
For how long have I used the solution?
I have been using Splunk Enterprise Security for about six months.
What do I think about the stability of the solution?
Besides the forwarder, it is nice. The forwarder ran out of space, so it occasionally has to be rebooted to clear out the space that is being utilized.
What do I think about the scalability of the solution?
We have 50 gigs of data.
How are customer service and support?
I never really had to use professional services. For the most part, everybody is knowledgeable and patient, and there is a decent amount of communication back and forth.
I would rate their support an eight out of ten. My biggest issue right now has not been solved yet. Our heavy forwarder ran out of space. It is a VM. By using vCenter, we presented more space to the drive, but we could not get the VM or the Linux OS to allocate the new space. So far, nobody has been able to help us fix that. The current solution is to just upgrade it. We are not in a position to upgrade it right now because of the workload.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
I changed my career last year to InfoSec. I was in IT before that. With IT, if there is a problem with the system, we just look at the logs. With Splunk, it is nice to be able to have it all centralized in my location where I can look at the data relatively fast as opposed to a line-by-line.
How was the initial setup?
I was not involved in its setup. We have a bit of a hybrid setup. We have an on-prem data center and then we also have a cloud. We have Azure Cloud.
What was our ROI?
I would say that we have seen an ROI, but I do not know the numbers.
What other advice do I have?
I would rate Splunk Enterprise Security a ten out of ten.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Security Architect at a computer software company with 501-1,000 employees
Reduces alert volumes, speeds up investigations, and handles big data well
Pros and Cons
- "If you want to understand how it can analyze or find out incidents, the visibility is good."
- "We'd like to see a more seamless cloud-based integration."
What is our primary use case?
The solution is primarily for security incident investigation. Whenever a customer wants to monitor the environment for any security incident or events that are occurring, and they want to analyze the incident when virtual issues happen, that's when we propose Splunk. Otherwise, it's difficult to understand what kind of security event is arising in the environment.
What is most valuable?
The primary feature that is the most valuable is the correlation feature, which helps you analyze the data. If there's a lot of telemetry data at some point, Splunk can take advantage of it. It can handle a large volume of data.
Now, with big data, AI, and all those things, the amount of security data that is generated is too high. Generally, the other SIMs face trouble when handling big data. However, Splunk itself is a very strong solution for handling lots of data. It helps the SOC team analyze data very well, and it does not crash on handling a large amount. That's a key benefit.
Our customers usually monitor multiple cloud environments. It's not very difficult. There are two ways we use Splunk. One is that they can be multiple cloud environments. The second is that it can be an on-prem and a cloud environment. We are mapping it to our one solution.
Splunk is very flexible and it's integratable with other solutions
If you want to understand how it can analyze or find out incidents, the visibility is good. The best visibility would always be in the on-prem environment. Then, the cloud, since Splunk is not a native cloud solution like Microsoft's Sentinel, is used. We don't see a lot of challenges if we do a hybrid kind of setup, however.
I'd assess Splunk's insider threat detection capabilities to help find unknown threats or anomalous user behavior at an eight out of ten. Splunk itself uses another agent or another module to do it. Splunk does the job. It's not that it will not do the job; however, it will require more refining than other solutions in the market.
My team uses the Splunk Mission Control, topology, and attach framework features, which are really helpful. We've used it for multiple customers. We take their existing SOC or detection use cases and try to map them to the framework. From a security point of view, it obviously makes a solution more superior. With Splunk, you can catch more security incidents. From a best practice standpoint also, it is a good thing as we can configure the solution, and, according to that configuration, the entire performance is better in terms of security.
It's very useful for assessing malicious activities or detecting breaches. It's a robust solution.
We've been able to help customers detect threats faster. It might be 5% to 10% faster in some cases. And since we can analyze large volumes of data, we're not missing any particular data point or data set. That gives us an advantage.
Splunk helps reduce alert volume. You can reduce your alert volume based on your configuration, and it's highly customizable, so it can help you reduce alerts by a lot. It's helped us improve the quality of incidents we receive.
It's helping customers speed up security investigations somewhat.
It improves the resilience of a company thanks to its ability to quickly analyze data.
What needs improvement?
While it's costlier than other solutions, it's highly stable.
The security orchestration response requires a bit of improvement.
We'd like to see a more seamless cloud-based integration.
Their mobile features for iOS and Android could be improved in terms of quality of performance.
For how long have I used the solution?
I've been using the solution for three and a half years.
What do I think about the stability of the solution?
It's a highly stable product even for large customers with diverse environments. For companies that have huge amounts of data even, it does not crash. It's the preferred option when a lot of data is involved. It offers good resilience and improves performance.
What do I think about the scalability of the solution?
I'd rate the scalability seven out of ten since it is not cloud-native.
How are customer service and support?
Technical support is good. We purchase premium support services.
How would you rate customer service and support?
Positive
How was the initial setup?
I was not involved in the initial setup of the solution.
The solution is deployed wherever your appliance is. You deploy it where your software team wants to monitor from. Typically, that's headquarters or a company's security center. Splunk then has agents that help devices connect across geographies. For example, while Splunk may be primarily in the UK, it can cover devices via agents across Europe, and the agents can monitor other environments.
We have between two to five people who handle maintenance activities, depending on the client.
What other advice do I have?
There is a threat intelligence management feature. However, customers don't use it in our case. Typically, customers want something superior in that nature.
Price is a major concern for most customers, big or small. However, price should not be the determining factor when seeking a solution. Users need to think about performance and quality. They need something that will help them prevent security incidents, and they need a product that will be stable. If you can monitor your environment better, you can prevent incidents that may lead to financial loss - and when incidents happen, companies can spend far more dealing with an extended phishing attack than they would on a service like Splunk that will protect them effectively. When it comes to security, while it's not necessary to have the most expensive solution on the market, you should at least seek out a solution that's best suited to your company and its needs.
I'd rate the solution eight out of ten. It's a great option for enterprise-level companies. However, a smaller customer with a smaller budget may not be a good match. They may not need such a powerful solution in any case. That said, if a customer is about to grow a lot, I might suggest Splunk as a primary option. I'd advise potential users to look at the environment size and complexity, consider the budget, and then decide if Splunk makes sense.
Which deployment model are you using for this solution?
Hybrid Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Disclosure: My company has a business relationship with this vendor other than being a customer. reseller
Senior Manager at Wipro Limited
Helps reduce the alert volume, speeds up investigations, and detect threats faster
Pros and Cons
- "The initial deployment was straightforward."
- "Splunk's reporting functionality would benefit from enhanced customization capabilities, allowing users to tailor reports to their specific needs for better data visualization and analysis."
What is our primary use case?
We use Splunk Enterprise Security to monitor our environment.
How has it helped my organization?
The threat intelligence and monitoring of Splunk are good.
We have integrated Splunk Enterprise Security with ServiceNow so whenever there is a detection it will automatically raise a ticket and send it to the appropriate team for analysis. The integration was seamless.
Splunk has helped reduce our alert volume by 20 percent and sped up our security investigations.
It does a good job detecting threats fast.
What needs improvement?
Splunk's reporting functionality would benefit from enhanced customization capabilities, allowing users to tailor reports to their specific needs for better data visualization and analysis.
For how long have I used the solution?
I have been using Splunk Enterprise Security for one and a half years.
What do I think about the stability of the solution?
Splunk Enterprise Security is stable.
What do I think about the scalability of the solution?
Splunk Enterprise Security is scalable.
How was the initial setup?
The initial deployment was straightforward.
What's my experience with pricing, setup cost, and licensing?
Splunk Enterprise Security is expensive.
What other advice do I have?
I would rate Splunk Enterprise Security ten out of ten.
For reporting we don't use the Splunk dashboard, we use Tableau and Power BI.
I would recommend Splunk to others.
While Splunk Enterprise Security offers robust features for large organizations, its cost might be prohibitive for smaller businesses. To address this, I recommend exploring open-source SIEM solutions for small and medium organizations and Splunk for larger organizations.
Which deployment model are you using for this solution?
Hybrid Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Security Delivery Analyst at a consultancy with 10,001+ employees
Improves our incident response time, has customizable dashboards, and speeds up our security investigations
Pros and Cons
- "I like the Splunk dashboard and search engine."
- "Although the technical support is adequate, there is still room for improvement."
What is our primary use case?
We use Splunk Enterprise Security for security log investigation. It is a SIEM platform. Many cybersecurity and technical alerts generated by Splunk turn out to be false positives. We then analyze these alerts to determine if they indicate a genuine security threat.
How has it helped my organization?
We will be ingesting logs from various sources, including firewalls, databases, Windows devices, and Linux devices. These logs will be used to investigate security incidents and troubleshoot system issues. Our use cases will be brief and focused, allowing us to leverage pre-defined queries in Splunk for efficient analysis. These queries will trigger alerts based on specific security or operational criteria within the predefined use cases. We will then investigate the triggered alerts by further analyzing the corresponding logs.
Splunk Enterprise has improved our incident response time. For instance, if an end user attempts to log in to a system with an invalid password from a device using an unusual port number, we will receive an immediate alert. This could be indicative of a brute-force attack aimed at stealing credentials, making it a suspicious activity. This is just one example of how Splunk Enterprise enhances our security posture.
Splunk's threat detection capabilities are strong, and Splunk is a leading platform for SoC monitoring. To maximize effectiveness, we need to develop strong query-building skills. Additionally, we have the flexibility to fine-tune existing queries or remove them altogether once an issue is resolved.
The customizable dashboards of Splunk are good for visualization. It gives a better understanding, and the graph is highly customizable.
I would rate Splunk Enterprise Security a nine out of ten for analyzing malicious activities.
Splunk Enterprise Security helped the organization control suspicious and malicious activities.
Splunk Enterprise Security has helped speed up our security investigations.
Splunk Enterprise Security's customization capabilities enable integration with other tools like EDRs, providing real-time event insights.
What is most valuable?
I like the Splunk dashboard and search engine.
What needs improvement?
Although the technical support is adequate, there is still room for improvement.
For how long have I used the solution?
I have been using Splunk Enterprise Security for 2 years.
What do I think about the stability of the solution?
I would rate the stability of Splunk Enterprise Security 9 out of 10.
What do I think about the scalability of the solution?
I would rate the scalability of Splunk Enterprise Security 9 out of 10.
How are customer service and support?
The technical support is adequate.
How would you rate customer service and support?
Positive
What other advice do I have?
I would rate Splunk Enterprise Security nine out of ten.
While I understand the desire for a cost-effective SIEM solution, prioritizing security over budget is crucial. In cybersecurity, even a seemingly minor breach can have significant consequences. Therefore, choosing the best SIEM for your needs, even if it has a higher upfront cost, can ultimately save money and protect your organization.
We have Splunk Enterprise Security deployed in four locations in one country.
Splunk takes care of the maintenance of the solution.
I recommend Splunk Enterprise Security to others.
Which deployment model are you using for this solution?
Private Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Other
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Service Management Lead at a consultancy with 10,001+ employees
Offers great visibility and good connectors to users
Pros and Cons
- "I have not seen any outages in the product in the past two years that it has been running in our company, so I think it is good when it comes to the stability part."
- "The product's price may be an area of concern where improvements are required."
What is our primary use case?
We use it in our company to log everything. We use tools like XSOAR to take appropriate actions to mitigate threats.
How has it helped my organization?
Splunk Enterprise Security has aided our organization in the way it provides great visibility and helps with what our company's users do with it.
What is most valuable?
I like how easy it is to integrate the logging of all of the various nodes. The product also offers nice connectors. Other features include the product's ability to allow users to customize their dashboards, signatures, metrics, and other elements, making it a very valuable and reliable tool for my organization.
What needs improvement?
I don't know if there is a need for any improvements in the product since it is one of my peers and not me who is directly responsible for Splunk Enterprise Security in our company, so I will have to ask him if there are any requirements associated with the product.
The price may be an area of concern where improvements are required. Splunk Enterprise Security doesn't indulge in whitewashing, but Cisco does it too much.
For how long have I used the solution?
I have been using Splunk Enterprise Security for two years.
What do I think about the stability of the solution?
I have not seen any outages in the product in the past two years that it has been running in our company, so I think it is good when it comes to the stability part. I have had an experience with the vendor during which there were two products, one from the vendor and the other from Splunk Enterprise Security, and we saw that one of them was not able to capture all the logs appropriately, after which our company had to figure out whether it was Splunk API or the vendor's tool.
How are customer service and support?
I have never used the product's customer support. My peer has contacted the product's technical support team, and it has worked very well for him.
Which solution did I use previously and why did I switch?
My company used to use one of the spin-offs from IBM. My organization has used IBM QRadar.
How was the initial setup?
Though I am not sure about the deployment model, I feel that since it may not be on Azure, the product must be deployed with the help of AWS.
What was our ROI?
I have experienced an ROI revolving around the product's dashboards, metrics, and other such related stuff, but I don't know how to quantify them. My peer would be the best person to speak about the product's ROI.
What's my experience with pricing, setup cost, and licensing?
My peer would be aware of the product's pricing part.
Which other solutions did I evaluate?
There was a pre-vendor selection approach my company followed, but I don't remember the names of the products involved.
What other advice do I have?
It is pretty important how the solution provides end-to-end visibility in our company's environment because it provides opportunities for shadow IT and for people to do things that they should be doing. If one is appropriately logging in, the product gives us a view and helps our company discover things that we didn't know about.
In terms of Splunk Enterprise Security's ability to help our company find any security events across multi-cloud, on-prem, or hybrid environments, I will have to say that since we are still using it, it has to be effective. If it wasn't effective in the aforementioned area, my peer would have found something else in the product. I don't have enough personal insight into Splunk Enterprise Security's ability to help our company find any security events across multi-cloud, on-prem, or hybrid environments.
Splunk Enterprise Security has helped to reduce my company's alert volume. Our organization does get alerts, and we are trained for them. I will have to ask my peer to give me the exact number associated with the alerts my company receives.
The solution provides the relevant context that helps guide our company's investigations. The context information has impacted our company's investigation process as it definitely speeds it up because we have only a single source from which we can get that, and it helps us understand what may have taken place in a particular incident that we are looking at in our organization. In our company, if we look at any of the other services, we can see whether a particular or specific user touched just a single system or ten different systems.
The solution has helped reduce my company's mean time to resolve, but I don't have numbers to explain it.
The reason why I rate the tool a nine is because of the flexibility it provides to go back to the dashboards. The flexibility to be able to customize standard dashboards and other standard things that I want to be able to grab and have them pop out and then be able to create some sort of an action against those kinds of things that I want, of which the first is the standard reporting part, which is very valuable.
To those planning to use the solution, I would suggest that they need to get Splunk to work hard on the pricing part. People also need to encourage Splunk to stay true to its roots because I have seen what has happened to some of the other tools in the market. Splunk has been acquired by Cisco. You want Splunk because of its capabilities, not because of what Cisco wants to give you.
If I consider my company's needs, I rate the overall product a nine out of ten.
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Amazon Web Services (AWS)
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Head of Cybersecurity at a computer software company with 51-200 employees
A market leader with good standard features and helps speed up security investigations
Pros and Cons
- "The solution is the market leader."
- "The integration could be a bit better. They charge for certain integrations."
What is our primary use case?
We mainly use the solution as a reseller. We give our users the latest version of the product.
What is most valuable?
The solution is the market leader.
Our customers are always looking to partner with market leaders as you can't go wrong with them.
Customers can monitor cloud environments.
The threat detection capabilities are quite fast and efficient based on my customer's feedback.
We've used the MITRE ATT&CK feature and it's good. It's pretty standard and comparable to IBM. Most products offer this as well.
It's good for analyzing malicious activities. It's good as an overall platform. It's good at detecting threats. It's a basic feature that is quite effective.
Splunk can help to reduce alert volume if you configure it properly.
They are a market leader in a lot of areas in terms of features and functions.
It helped us speed up security investigations. I'm not sure of the exact percentage it helped us speed up by, however.
It has a lot of basic and standard features.
It is a full-fledged solution that provides everything a company needs.
What needs improvement?
When it comes to malicious activities, however, it's rather overpriced. There are cheaper ways to detect.
There are quite a lot of security platforms on the market that do the same thing in a similar way at a cheaper rate.
The pricing could be a lot lower. I'm from Asia, and they need to provide Asian pricing. They should price better for the region they are in. Once companies see the price, it puts them off.
The integration could be a bit better. They charge for certain integrations.
For how long have I used the solution?
I've used the solution for about a year or more.
What do I think about the stability of the solution?
It is a stable product.
What do I think about the scalability of the solution?
The solution is used across multiple departments, not locations. That said, it would support multiple locations.
We've had no issues with scalability. We usually have a solution that lasts three to five years and have had no issues scaling in that time.
How are customer service and support?
I do not directly deal with technical support.
Which solution did I use previously and why did I switch?
We previously used many solutions, such as IBM. The implementation times are about the same. There are some ways that IBM is faster and other ways Splunk is faster. However, Splunk offers a more modern look.
How was the initial setup?
The initial setup is very easy. It's quite straightforward. The process is similar to IBM. The deployment takes less than one day. It is done by a different team. I don't handle the initial implementation process.
The maintenance needed is very minimal. We have at least ten people that can handle deployment and maintenance.
What's my experience with pricing, setup cost, and licensing?
The solution is quite expensive compared to the competition. It's considered a premiere security option.
Which other solutions did I evaluate?
We also looked at Dynatrace before choosing Splunk.
What other advice do I have?
I'm a registered partner of Splunk.
We are using the latest version of the solution.
We haven't used the threat intelligence management feature. We usually use another product.
The mission control feature hasn't been used. I'm not familiar with it.
For those looking for a cheaper product, I'd suggest, if they had a limited budget, to go cheaper. Likely a cheaper option that can do the same work as Splunk. At the end of the day, whether you choose a Toyota or a Rolls Royce, you get from A to B the same. The price is the differentiation.
I'd rate the solution eight out of ten. It's a good product overall.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer.
Buyer's Guide
Download our free Splunk Enterprise Security Report and get advice and tips from experienced pros
sharing their opinions.
Updated: July 2026
Product Categories
Security Information and Event Management (SIEM) Log Management IT Operations AnalyticsPopular Comparisons
IBM Security QRadar
Splunk AppDynamics
Microsoft Sentinel
Elastic Security
IBM Turbonomic
Palantir Foundry
WhatsUp Gold
LogRhythm SIEM
Rapid7 InsightIDR
Elastic Observability
Buyer's Guide
Download our free Splunk Enterprise Security Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- Which would you recommend to your boss, IBM QRadar or Splunk?
- What are some of the best features and use-cases of Splunk?
- What SOC product do you recommend?
- Splunk as an Enterprise Class monitoring solution -- thoughts?
- What is the biggest difference between Dynatrace and Splunk?
- IBM QRadar is rated above competitors (McAfee, Splunk, LogRhythm) in Gartner's 2020 Magic Quandrant. Agree/Disagree?
- What are the advantages of ELK over Splunk?
- How does Splunk compare with Azure Monitor?
- New risk scoring framework in the Splunk App for Enterprise Security -- thoughts?
- Splunk vs. Elastic Stack















