There are quite a lot of things that we find useful. Splunk agents are useful and good. Its UI is quite impressive.
Senior Information Technology System Analyst at YASH Technologies
Impressive UI, many useful features, and very scalable, but needs alerting feature and better pricing and integration
Pros and Cons
- "There are quite a lot of things that we find useful. Splunk agents are useful and good. Its UI is quite impressive."
- "Its pricing model and integration with third-party services can be improved. We had faced an issue with integration. The alerting feature is currently not available with Splunk, but it is definitely available with Datadog and PagerDuty. They should include this feature. A few dashboards in Splunk look quite old and are not that modern. They aren't bad, but improving these dashboards will definitely make Splunk more attractive and usable. I read in a few blog posts that there were a few security incidents related to Splunk agents. So, it can be made more secure."
What is most valuable?
What needs improvement?
Its pricing model and integration with third-party services can be improved. We had faced an issue with integration.
The alerting feature is currently not available with Splunk, but it is definitely available with Datadog and PagerDuty. They should include this feature.
A few dashboards in Splunk look quite old and are not that modern. They aren't bad, but improving these dashboards will definitely make Splunk more attractive and usable.
I read in a few blog posts that there were a few security incidents related to Splunk agents. So, it can be made more secure.
For how long have I used the solution?
I have been using this solution for almost two years. I am using its latest version.
What do I think about the stability of the solution?
It is a stable product.
Buyer's Guide
Splunk Enterprise Security
May 2025

Learn what your peers think about Splunk Enterprise Security. Get advice and tips from experienced pros sharing their opinions. Updated: May 2025.
857,028 professionals have used our research since 2012.
What do I think about the scalability of the solution?
Splunk is definitely scalable.
How are customer service and support?
I have not interacted with them. Another team is taking care of raising tickets with their technical support.
How was the initial setup?
It is quite simple.
What's my experience with pricing, setup cost, and licensing?
Its pricing model can be improved.
What other advice do I have?
A few years ago, I would have definitely recommended Splunk, but nowadays, better alternatives are available. We are currently exploring a few other alternatives, so I won't recommend Splunk as of now.
I would rate Splunk a seven out of ten.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.

Senior Solutions Architect at a manufacturing company with 51-200 employees
Seamless integration with devices and operating systems, centralized management and control, and proactive support
Pros and Cons
- "The integration is seamless with many devices and operating systems."
- "Being a SIEM solution with a centralized dashboard, we would like to have more options to customize it."
What is our primary use case?
We are a solution provider and Splunk is something that we provide as a service to our customers.
What is most valuable?
The most valuable feature is the reporting and the information that is provided by the tool.
It is very easy to implement a PoC using Splunk, which will show the value of the reporting and data that it provides.
The integration is seamless with many devices and operating systems.
It is flexible enough that you can choose what kind of deployment model you want.
They have a large solution toolkit that supports IoT, wherein businesses can get a lot of help with the centralized management functionality. There are also tools to assist from the security and SIEM perspective, and there is a centralized dashboard.
What needs improvement?
Being a SIEM solution with a centralized dashboard, we would like to have more options to customize it. It should be easy to customize dashboards.
When we are monitoring something, we would like to have a more granular outlook. Splunk has a good dashboard that is easier to use than some competing products, but better customizability would be a great help for the users.
For how long have I used the solution?
We have been working with Splunk for approximately three years.
What do I think about the stability of the solution?
This product is very stable.
What do I think about the scalability of the solution?
Splunk is a very scalable solution. Being a Japanese product, they will ensure that all of the features work in any environment. It is very heterogeneous. It can integrate with Windows, Linux, AIX, HP-UX, and Solaris. It also supports IoT devices, mobile phones, and more.
We have more than 150,000 people using our services.
How are customer service and technical support?
The Splunk team has good, proactive support. Also in terms of assisting with the installation, they are quite good.
Which solution did I use previously and why did I switch?
Splunk is similar to IBM QRadar, which we also have experience with. However, Splunk has advanced SIEM features included with it, so we often use it to satisfy this requirement. Whenever an organization is looking to implement SIEM, they have the flexibility to choose Splunk, QRadar, or the ArcSight Logger solution.
One of the major differences that I see between Splunk and QRadar is that Splunk gives the users fewer devices, so they can do things quicker.
How was the initial setup?
The installation for Splunk is easier than competing products QRadar and ArcSight.
We have Splunk deployed on the cloud so that we can provide the service, but some of our customers have it installed on-premises.
All the user has to do is download the Splunk server agent, install it on the laptop or endpoint, integrate 50 or 100 devices, then see what kind of reporting is available.
What about the implementation team?
We have an in-house team for deployment in maintenance. Splunk is a tool that does not require much staff to maintain. The users can start with a PoC, simply learn it, and deploy it for themselves. They don't require subject experts to be hired for the installation and configuration.
What's my experience with pricing, setup cost, and licensing?
Price-wise, if you compare QRadar to Splunk for SIEM functionality then they are in the same range but when you integrate SOAR with these solutions, Splunk takes the lead and is more competitive.
What other advice do I have?
This is a product that I recommend for anybody who wants and advanced SIEM solutions. Of the three that I have used including QRadar and ArcSight, Splunk is the one that I prefer.
I would rate this solution a nine out of ten.
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
Buyer's Guide
Splunk Enterprise Security
May 2025

Learn what your peers think about Splunk Enterprise Security. Get advice and tips from experienced pros sharing their opinions. Updated: May 2025.
857,028 professionals have used our research since 2012.
Assistant Manager System at a financial services firm with 10,001+ employees
Stable, with easy log connection and the capability to scale
Pros and Cons
- "Its compatibility with other SIEMS is very useful."
- "We find that the maintenance process could be a lot better."
What is our primary use case?
What is most valuable?
The ease of log connection has been great.
Its compatibility with other SIEMS is very useful.
They have many basic use cases that we like.
The cloud version of the solution is especially scalable.
The product has been quite stable so far.
The initial setup is very easy.
What needs improvement?
Technical support is lacking post-sale.
The modification of firmware could be improved.
We find that the maintenance process could be a lot better.
The solution is more expensive than other options on the market.
For how long have I used the solution?
We haven't been using the solution for too long at this point. It's been about four months or so.
What do I think about the stability of the solution?
The stability has been good. It offers good performance and doesn't seem to be buggy. There aren't glitches. It doesn't crash or freeze. It's reliable.
What do I think about the scalability of the solution?
The solution is scalable. This is especially true for the cloud deployment model. There really isn't anything holding you back if you use that version.
We have around 100 people on the solution currently. 60 to 70 of those are technical users.
We do plan to keep using Splunk.
How are customer service and technical support?
Technical support services are lacking, especially after you buy the product. They aren't as helpful or responsive as we need them to be. However, when we do reach them, they are good and they help.
Which solution did I use previously and why did I switch?
I have used McAfee Nitro in the past and IBM QRadar as well.
How was the initial setup?
The initial setup is not complex. It's very straightforward. In fact, it's far easier to install than other log tools on the market. A company shouldn't have any issues with the process.
That said, I did not work on the installation myself. Other people at the company handled that aspect of the process.
The maintenance process could be better. It's a bit difficult once the deployment is done. We need about five people for maintenance tasks.
What's my experience with pricing, setup cost, and licensing?
When you compare the services and features, the pricing is reasonable. That said, if you compare Splunk to other options on the market, it is more expensive.
What other advice do I have?
As we recently purchased the solution, we are using the latest version right now.
I would recommend the solution to other users.
I would rate the solution at an eight out of ten. If the solution offered a better price and better support services, I would likely rate it higher. However, for the most part, we have been satisfied with the product and its capabilities.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Senior Consultant at sectecs
Powerful programming language and search capability, but it is expensive and the vendor is inflexible
Pros and Cons
- "What I really like is that even if you have already collected the data, you can extract fields and can build searches."
- "I would like to see more SIEM functionality and a better ticket tool."
What is our primary use case?
My reason for implementing it was just to learn more about the product. I wanted to learn about the Splunk programming language, how to pipe searches, add logs, verify the logs, create fields, extract data into fields, build dashboards, and to get hands-on experience with the product.
What is most valuable?
The Splunk programming language allows you to pipe searches into another searches.
What I really like is that even if you have already collected the data, you can extract data and add fields which improves building searches. This is not the case with Elasticsearch, where this needs to be done upfront.
What needs improvement?
I really dislike how Splunk sales and partner manager behaves. I have faced several sales model and partnership changes. Also, the last time I wanted to by a license ro built a SIEM solution, they had removed the ability to purchase a splunk subscription or license from their website. In the past, there was a web page calculator it was possible to by online, but now it instructs to contact sales.
The free version is limited to 500 megabytes and there is no alerting. Due to the missing feature on the Splunk webpage, I have ask Splunk Sales to purchase a license like 1Gyte a day or a license for max 2500 Euro/year to use it as a test or development instance for myself. Asking Splunk for a quote willing to pay for Splunk license to learn and to get used to the product, Splunk didn't get it managed to offer my a license neither arranging the partnership paperwork I have ask for. Sales people from Splunk where calling, each time after I left my details on ther trial download page. I explained my experience and concerns about Splunk in the past. All excuses received and promises that someone will contact me to solve the issues faced in the past, was leading in excactly nothing. Well Done Splunk.
Inflexible and expensive and I do not have much faith in the people working there because if someone is asking for a test environment and is willing to spend up to €2,500 a year, I can't understand why they are unable to provide a license. This could be a lost opportunity because they are not able to onboard a potential new partner.
They definitely need to boost their sales and partner program because it changes to often, where they are dropping partners and it is difficult to get in contact with somebody. This is something that needs to be improved.
I would like to see more SIEM functionality and embedded moduled such a ticket tool to make a end to end SIEM.
For how long have I used the solution?
I have been using Splunk for a few weeks.
What do I think about the scalability of the solution?
As I was using a test environment, I can't comment on scalability. It was just myself and a colleague who was using it as a test instance.
How are customer service and technical support?
I have not been in contact with technical support.
Which solution did I use previously and why did I switch?
I have worked a little bit with Elasticsearch. I also have an instance of SIEMonster running, and I'm trying to get used to it. I found that Splunk provided a good benefit compared to Elasticsearch.
With Elasticsearch, if you have already inserted the data then it's gone because you need to do the pre-filtering. Once you've inserted or ingested the raw data, using Logstash, for example, you are no longer able to build the fields such as IP address, hostname, username, and the other fields that you want to export. This unsorted, raw data that you have is really a drawback for Elasticsearch and some other products. This is something from Splunk that I consider to be a heavy feature, where you can just insert data and ingest it later on.
How was the initial setup?
really fast and easy to install a test instance.
What's my experience with pricing, setup cost, and licensing?
The pricing model is expensive and could lead into a budget nightmare based on the amount of data.
A better pricing plan would be an improvement.
Which other solutions did I evaluate?
I have done some research on LogRhythm, IBM QRadar, and ArcSight, but I don't have any hands-on experience yet.
I did a comparison for a customer two weeks ago and the outcome of my comparison was SIEMonster, effortable price model, even though it's a niche player, it's quite powerful. I also provided Splunk as a recommendation because it is a market leader, really powerful, and really good to use. I also recommended LogRhythm; it is also expensive but it's also really powerful, and the feedback of customers is really good.
With respect to Splunk, I would recommend it but when a customer is budget-driven then Splunk is not the solution. Money shouldn't be the question.
What other advice do I have?
This is a solution that I could recommend for somebody who wants a really powerful product. It is not an end to end orchestrated SIEM yet.
This is a product that I would generally recommend, although I would not do so if the customer is really budget-driven.
I would rate this solution a six out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
IT System Developer/Admin at a manufacturing company with 10,001+ employees
A stable, scalable solution with comprehensive dashboards and helpful technical support
Pros and Cons
- "The scalability of the solution is amazing because it can collect a lot of data and you can have your own structure to monitor this data."
- "An area of improvement would be the licensing of the solution. They need a free license, which would allow faster lead times."
What is our primary use case?
The primary use case of this solution is to monitor Cyber Mission databases.
I create the diagrams to create an architecture that is then implemented. However, creating these diagrams are for my own learnings since these implementations are usually already available in the cloud office logs.
What is most valuable?
The features I have found most valuable are the dashboards.
I monitor the complete capacity that users are using in the company.
What needs improvement?
An area of improvement would be the licensing of the solution. They need a free license, which would allow faster lead times.
They also need to update their documentation.
What do I think about the stability of the solution?
The solution is stable.
What do I think about the scalability of the solution?
The scalability of the solution is amazing because it can collect a lot of data and you can have your own structure to monitor this data.
How are customer service and technical support?
The customer service/technical support was helpful and they answered my questions as best they could.
How was the initial setup?
The setup was easy, but you have to have a VPN connection depending on the security protocols in place.
What about the implementation team?
The deployment was in-house and took about two days with the correct licenses and permissions.
What other advice do I have?
It is important to define different guidelines to integrate Splunk in development, QA, and production deployments. Additionally, define the applications that will be used and the configuration of the databases to collect the data. If this is not done, there will be a lot of issues due to, for example, master access or permissions to use the database collector and blocks.
Which deployment model are you using for this solution?
Hybrid Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Amazon Web Services (AWS)
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Assistant Vice President at Synchrony
Easy to use with a simple setup and great integration capabilities
Pros and Cons
- "The initial setup is pretty straightforward."
- "On-premises scaling of the solution is a bit more limited than it is on the cloud."
What is our primary use case?
We primarily use the solution for monitoring our infrastructure.
What is most valuable?
The models that we use are pretty mature at this point, which means we can be assured we are given the best use cases right out of the box.
We can just plug into the applications and everything is set up. There's very little configuration necessary.
The integrations that are offered with different tools are all very good. They offer integrations for all levels of security and have offerings from some of the other major solutions in the space.
The initial setup is pretty straightforward.
What needs improvement?
Over the years, I know they've been doing what they can to continue to add integration capabilities to their solution. If they continue to do that, that would be ideal. However, beyond that, there really aren't any features that I find to be lacking in any part of the solution.
On-premises scaling of the solution is a bit more limited than it is on the cloud.
The pricing of the solution needs to be a bit lower.
It would be ideal if the hardware could meet more universal global regulatory requirements. It would be great it the solution better aligned with global standards.
For how long have I used the solution?
I've been working with the solution for three to four years at this point.
What do I think about the scalability of the solution?
In terms of the cloud, scalability is very straightforward. It's just about as expansive as we want to go. When it comes to an on-premise deployment, there might be some scalability limitations. We've found we just have to cut hard on the resources as it does a lot of processing. Whereas the cloud is easy and has very little limitation, I'd advise others that on-premise may have some difficulties.
On-premises, it's definitely on the customer to ensure they have the right plates. If they're concerned and they need 100% scalability, it's best to be on the cloud.
How are customer service and technical support?
Technical support is very good. They know their product and they are responsive to requests. We're satisfied with the level of service provided to us.
How was the initial setup?
We didn't have any issues with the initial setup. It's not too complex. We found the process to be very straightforward and very simple.
What's my experience with pricing, setup cost, and licensing?
While I do understand that it is a premium tool, they could work to make it a bit less in terms of cost. It's a bit expensive.
What other advice do I have?
We use a mixture of public and private cloud deployments.
I would definitely recommend the solution, having seen it work for others so well. Its ease of usage and its man integrations make it a great product. The way you can access whatever you need on the solution is very similar to a Google bar where you can search for anything you need. It's just a super quick responsive, product.
Overall, I would rate it a perfect ten out of ten. We have no complaints.
Which deployment model are you using for this solution?
Public Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
General Manager at Intersoft S.A.
A great solution for application management, security and compliance
Pros and Cons
- "The correlation capabilities are the first value that our clients say they like with Splunk."
- "The difficult part is related to integration with sources of data that are used to create the logs as this depends on the infrastructure of the client."
What is our primary use case?
We use Splunk for security and also PCI compliance.
We have installed and implemented this solution for several clients in Bolivia with our team. We have received training from Splunk directly, and we have also provided training to our clients.
We deploy two versions: one for on-premise and one for the cloud.
Most of our customers purchase Splunk because they required a tool for gathering and collecting all of the logs from the infrastructure in order to make a correlation between data and to spot patterns surrounding security incidents.
What is most valuable?
The correlation capabilities are the first value that our clients say they like with Splunk. Another benefit is that they can connect to any device or log from any device from anywhere.
It's easy, the tool is very easy to install and set up.
What needs improvement?
They could have more dashboards done or predefined so our clients could use them directly in order to have more information ready to use.
The difficult part is related to integration with sources of data that are used to create the logs as this depends on the infrastructure of the client.
For how long have I used the solution?
We have been using this solution for more than five years.
What do I think about the stability of the solution?
Stability-wise, it's great.
What do I think about the scalability of the solution?
We do not require much scalability here because the clients are not so big; however, the hardware where we installed the products was enough to handle all the transactions of Splunk.
How are customer service and technical support?
The support is not so good, I would only give them a rating of six or seven.
They should provide support in Spanish here in Latin America. Their response time to inquires or requirement tickets is too long. It should be shorter.
How was the initial setup?
Deployment took us two weeks.
What other advice do I have?
I would recommend Splunk to any company: small, medium, and large.
Splunk is a great tool but you should get a partner who knows what they are doing, implementation-wise.
On a scale from one to ten, I would give Splunk a rating of nine.
Disclosure: My company has a business relationship with this vendor other than being a customer: Reseller
Sr. IT Manager at a pharma/biotech company with 10,001+ employees
Good log aggregation and scales well, with good technical support that is responsive and helpful
Pros and Cons
- "The most valuable feature is that it's very good for log aggregation."
- "The implementation and the scanning of the logs can be difficult."
What is our primary use case?
We are using Splunk to look at the logs, and see what is happening.
What is most valuable?
The most valuable feature is that it's very good for log aggregation.
What needs improvement?
Splunk is very complex. The implementation and the scanning of the logs can be difficult.
For how long have I used the solution?
I have been using Splunk for approximately three years.
What do I think about the stability of the solution?
In general, Splunk is stable.
What do I think about the scalability of the solution?
It's a scalable product. it's pretty good.
How are customer service and technical support?
Technical support is usually pretty good.
They are responsive, knowledgeable, and helpful.
How was the initial setup?
The initial setup was relatively straightforward.
What's my experience with pricing, setup cost, and licensing?
The price is comparable.
What other advice do I have?
I would rate Splunk and eight out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.

Buyer's Guide
Download our free Splunk Enterprise Security Report and get advice and tips from experienced pros
sharing their opinions.
Updated: May 2025
Product Categories
Security Information and Event Management (SIEM) Log Management IT Operations AnalyticsPopular Comparisons
CrowdStrike Falcon
Microsoft Sentinel
IBM Security QRadar
Elastic Security
Splunk AppDynamics
Elastic Observability
Grafana Loki
Security Onion
Palantir Foundry
LogRhythm SIEM
Buyer's Guide
Download our free Splunk Enterprise Security Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- Which would you recommend to your boss, IBM QRadar or Splunk?
- What are some of the best features and use-cases of Splunk?
- What SOC product do you recommend?
- Splunk as an Enterprise Class monitoring solution -- thoughts?
- What is the biggest difference between Dynatrace and Splunk?
- IBM QRadar is rated above competitors (McAfee, Splunk, LogRhythm) in Gartner's 2020 Magic Quandrant. Agree/Disagree?
- What are the advantages of ELK over Splunk?
- How does Splunk compare with Azure Monitor?
- New risk scoring framework in the Splunk App for Enterprise Security -- thoughts?
- Splunk vs. Elastic Stack