I need the product for SIEM, Security Identity Event Management. I also need it for security operations, automated response, as well as mapping adjusting of security components as well. It helps us with how best to look at various events, and orchestrate between various different hyper-scalers.
CTA\Owner at UCSolutions
Easy to use and simple to set up with reasonable pricing
Pros and Cons
- "The SIEM is the most valuable feature of the product."
- "The documentation is in definite need of improvement."
What is our primary use case?
How has it helped my organization?
The solution has made us more secure and has allowed for more definable mapping.
What is most valuable?
The SIEM is the most valuable feature of the product.
Having a better integration method and then ingesting and mapping the information have been somewhat easier than some of the other tools that I've used previously (other than QRadar and Rapid7).
The initial setup is pretty simple.
The solution is scalable.
Stability has been quite good.
The pricing is pretty decent.
What needs improvement?
The documentation is in definite need of improvement.
There are pieces of it that are somewhat just daunting and there should be better orchestration and automation.
I've done some automation with it, with Terraform, and also with some other sources. If it wasn't so proprietary, that would be ideal.
I'd like to have it so that Splunk integrates better with Terraform and Python.
Buyer's Guide
Splunk Enterprise Security
May 2025

Learn what your peers think about Splunk Enterprise Security. Get advice and tips from experienced pros sharing their opinions. Updated: May 2025.
852,780 professionals have used our research since 2012.
For how long have I used the solution?
I've used the solution for eight years. I've used it for quite a while.
What do I think about the stability of the solution?
Splunk is probably the best brand in terms of stability. I'd rate its reliability at a four out of five. There aren't bugs or glitches. It doesn't crash or freeze.
What do I think about the scalability of the solution?
The scalability is great. I'd give it a score of four out of five. If a company needs to expand, it can do so.
We have 450 people in our organization that use the product. We've also done this for clients that needed access for over 200,000 people.
We use the solution extensively and likely will increase usage.
How are customer service and support?
The support is okay, however, there are a couple of things that they couldn't figure out and they couldn't help me with automation or stuff like that. It could have been better from there, however, it's not that bad.
Which solution did I use previously and why did I switch?
I've previously used QRadar and it wasn't ideal.
There were certain times I integrated with other solutions too.
How was the initial setup?
The initial implementation is pretty simple and straightforward. It's not too complex. I'd rate the experience at an eight out of ten.
The initial deployment took us about two weeks or so.
The amount of personnel you need for deployment and maintenance tasks depends on the size of the deployment. Typically, it's just one or two people. That said, it needs to be proportionate to certain sizes. Usually, the staff is from procurement or provisioning.
What about the implementation team?
I handled the implementation myself. I didn't need any outside assistance from any integrators. I'm a consultant myself.
What was our ROI?
We've seen quite extensive ROI, however, it's more of a qualitative assessment and I don't have numbers to share. It works well and customers are happy. That's what counts.
What's my experience with pricing, setup cost, and licensing?
It's a little bit more expensive than some of the other tools. It's not as expensive as QRadar. That said, it's more expensive than LogRhythm or Sentinel.
There aren't really other fees beyond the standard costs of licensing.
Which other solutions did I evaluate?
I evaluated other things. I also integrated with other solutions too. I decided to go with Splunk due to the fact that it worked well.
What other advice do I have?
I'm a consultant. I'm also a customer and use it myself.
We use multiple deployment models, including public and private clouds.
We typically use the latest version of the solution.
I'd advise potential new users to get a proper plan. They should have a good partner or someone that can help them and quickly map and orchestrate.
I'd rate the solution at a ten out of ten.
Which deployment model are you using for this solution?
Public Cloud
Disclosure: I am a real user, and this review is based on my own experience and opinions.

Sr. IT Manager at a pharma/biotech company with 10,001+ employees
Good log aggregation and scales well, with good technical support that is responsive and helpful
Pros and Cons
- "The most valuable feature is that it's very good for log aggregation."
- "The implementation and the scanning of the logs can be difficult."
What is our primary use case?
We are using Splunk to look at the logs, and see what is happening.
What is most valuable?
The most valuable feature is that it's very good for log aggregation.
What needs improvement?
Splunk is very complex. The implementation and the scanning of the logs can be difficult.
For how long have I used the solution?
I have been using Splunk for approximately three years.
What do I think about the stability of the solution?
In general, Splunk is stable.
What do I think about the scalability of the solution?
It's a scalable product. it's pretty good.
How are customer service and technical support?
Technical support is usually pretty good.
They are responsive, knowledgeable, and helpful.
How was the initial setup?
The initial setup was relatively straightforward.
What's my experience with pricing, setup cost, and licensing?
The price is comparable.
What other advice do I have?
I would rate Splunk and eight out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Buyer's Guide
Splunk Enterprise Security
May 2025

Learn what your peers think about Splunk Enterprise Security. Get advice and tips from experienced pros sharing their opinions. Updated: May 2025.
852,780 professionals have used our research since 2012.
VMware Engineer at First Data Corporation
In-depth logs but downloading and uploading logs have become an issue
How has it helped my organization?
100%. VMware needs log information to troubleshoot; it's not easy finding problems.
Downloading and uploading logs have become an issue.
What is most valuable?
- In-depth logs
- Add-ons
- The ability to ingest data from other tools
- The detailed log view
- It's easy to read
What needs improvement?
- The amount of time it takes to troubleshoot not-easily-available data
- Also, hours on the phone with VMware techs.
For how long have I used the solution?
Less than one year.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Application Engineer at Expedia
The most valuable feature is its centralized log analytics
Pros and Cons
- "We have a one stop dashboard for health of some of our services where you can click in and it takes you to other dashboards that have custom near real-time metrics that show the application's health."
- "The historical data extraction needs improvement. I would like the capability of taking data and having it trend longer."
What is our primary use case?
The primary use case is for log analytics. Although, we have been using it as a hammer which hits all the nails. We have sort of overused it in some areas where it doesn't need to be used.
How has it helped my organization?
We have a one stop dashboard for health of some of our services where you can click in and it takes you to other dashboards that have custom near real-time metrics that show the application's health. From there, you can drill in to see the real deep dive example of what is happening in your environment. It has reduced our time to resolve incidents.
What is most valuable?
The most valuable feature is its centralized log analytics.
What needs improvement?
The historical data extraction needs improvement. I would like the capability of taking data and having it trend longer. Splunk is good about viewing data within the last seven or 14 days, but if you want to see a year-over-year trend, you have to do a lot of work to get to that point. If there was a better way to extract the data point and put it into a long-term viewing ability for a year-over-year analysis, then compare that to your other business metrics. That is what I am looking for, as an example, for a call center you want to see the time it takes for your customer to be handled on their need comparatively to the system performance that is happening, then overlay that data.
For how long have I used the solution?
Three to five years.
What do I think about the stability of the solution?
We put a lot of trust in it. It has been pretty rock-solid outside of a couple of changes that we made. Upgrades sometimes don't always go smoothly, but otherwise the system performs, and operates.
What do I think about the scalability of the solution?
When we were trying to implement an enterprise solution on-premise, we had scaling issues. It was very difficult to search the data retention beyond a few days. A lot of talent was given to the ability to go into AWS and scale with our need. We still had to do some administrative things to prevent consumers from trying to search all records for all time in very inefficient searches. This could sometimes bring our core system functionality to a halt, so we had to do some user administration in it.
How is customer service and technical support?
I don't engage with the support directly. Another member of my team does. Any time that we have needed support, he hasn't had an issue opening a ticket and receiving the help that he needs.
How was the initial setup?
The integration and configuration in the AWS environment was pretty good. They have a consumption method for pretty much every service. They might be able to do a little better at advertising different patterns for best practices for different service, but overall there's a method to get everything.
What was our ROI?
We have had a reduction in the time it takes to resolve issues and correlate what has failed. This has significantly helped.
Which other solutions did I evaluate?
We looked at the Elk Stack, Kibana, and Sumo Logic.
We chose Splunk because their cost is better, the maintenance factor is a little higher, and the core functionality is higher than what other products provide. The core functionality is out-of-the-box. E.g., with a Toyota Scion, you can customize the parts to make it whatever you want, but it's a lot of work to get there. Where if you buy a Cadillac, you pay the Cadillac's price, but it's a Cadillac. It will work right out-of-the-box.
What other advice do I have?
It works well when searching logs. If you looked to try to do things beyond this, the problem that we ran into is that we treated it as the hammer which hits all nails. That is not really feasible, and there are other tools out there that can do more specialized things.
User administration is key. Trying to prevent users from being able search records all the time is a huge problem. You need a tight approval process on dashboards, making sure the dashboards are queried in the most efficient way possible.
The on-premise version that we had was not scalable at all. It was very difficult to use. We have EC2 instances in the cloud with Splunk installed, which is more scalable and easier to use. It now works much better.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Splunker at freelancer
Quickly search for almost anything across many log sources in seconds
Pros and Cons
- "We can do things in minutes instead of days."
- "We solve issues that we previously could not since we now have the data."
- "We can quickly search for almost anything across many log sources in seconds."
- "The GUI could be improved to include some of the capabilities that other BI solutions have. The layout is a little restrictive where you can’t resize all the panels to exactly how you would like them without tweaking some XML code."
- "AngularJS/ReactJS inclusion could be made easier in GUI."
What is our primary use case?
The primary use case is to analyse and monitor big data, creating various dashboards, alerts, etc.
How has it helped my organization?
- We can do things in minutes instead of days.
- We solve issues that we previously could not since we now have the data.
- We can quickly search for almost anything across many log sources in seconds.
- Teams have the dashboards or alerts that they need.
What is most valuable?
There are too many features to list, but here are a few:
- Schema on the fly
- Ease of onboarding data
- Machine learning
- Apps or Splunkbase.
- Great list of apps to use and build upon once you learn more about how Splunk works.
- Ease of correlation, creating correlation searches (easy), and you can combine multiple sources with little effort.
- Data Models Acceleration for super fast searches across tens of millions of events.
- Common Information Model
- Security Essentials App
- Enterprise Security
- Splunk SPL (Search Processing Language) is easy to learn and has IDE like capabilities.
- Log storage or compression is great and retention is not an issue.
- Dashboards are simple to create and has input options, like time range and text.
- Drop-downs are simple to create.
- The integration with cloud solutions is great and keeps getting better.
What needs improvement?
The GUI could be improved to include some of the capabilities that other BI solutions have. The layout is a little restrictive where you can’t resize all the panels to exactly how you would like them without tweaking some XML code. Over the years, they have really been improving in this area. I would think that will continue and this will become a non-issue.
Also, AngularJS/ReactJS inclusion could be made easier in GUI.
For how long have I used the solution?
One to three years.
What was our ROI?
Personnel costs are saved by not having to involve domain developers from multiple teams when tracing a problem that spans multiple platforms.
What other advice do I have?
We build many of our own apps by leveraging the logic in others.
Disclosure: My company has a business relationship with this vendor other than being a customer:
Splunk Administrator at Arizona State University
Provides important insights to more efficiently make decisions and take action
Pros and Cons
- "My favorite example of improving of organization is saving a $60k/mo in payroll fraud and $10k/mo in wasted API credits by using simple searches and clear reports."
- "Splunk's schema on demand is incredibly useful. I do not have to worry about what my users will need when we onboard their data."
- "While Splunkbase (the app repository) has a lot of great content, some apps are terribly old and could stand to be updated or purged."
- "Some of the terminology can be confusing, even for seasoned vets. Renaming components at this point would be a serious undertaking. However, it might be beneficial in the long run."
What is our primary use case?
We use Splunk primarily to provide our security and ops groups with important insights to more efficiently make decisions and take action.
How has it helped my organization?
My favorite example of improving of organization is saving a $60k/mo in payroll fraud and $10k/mo in wasted API credits by using simple searches and clear reports.
What is most valuable?
Splunk's schema on demand is incredibly useful. I do not have to worry about what my users will need when we onboard their data. They can make connections that we could not have foreseen. They dig deeper when they are searching.
What needs improvement?
Some of the terminology can be confusing, even for seasoned vets. Renaming components at this point would be a serious undertaking. However, it might be beneficial in the long run.
While Splunkbase (the app repository) has a lot of great content, some apps are terribly old and could stand to be updated or purged.
For how long have I used the solution?
One to three years.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Principal Engineer at Publix Super Markets
A more secure, robust environment, which keeps out harmful software
Pros and Cons
- "Visualizations are the best way to understand deviation techniques from the norm."
- "We have a more secure, robust environment, which keeps the harmful software out of the zone required."
- "More training on PetaData using artificial intelligence techniques to identify the events which are not normal and exceptions that would help the organization identify threats and malware on the go with results."
What is our primary use case?
Security and incident management, which is helpful when organizing the data from different systems and running analysis on all the data together.
How has it helped my organization?
We have a more secure, robust environment, which keeps the harmful software out of the zone required.
What is most valuable?
The most valuable features are:
- Risk analysis
- Machine Learning Toolkit
- dbConnect
- Cisco products
- eStreamer
- SIEM.
Visualizations are the best way to understand deviation techniques from the norm.
What needs improvement?
More training on PetaData using artificial intelligence techniques to identify the events which are not normal and exceptions that would help the organization identify threats and malware on the go with results.
For how long have I used the solution?
Three to five years.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Business Intelligence Developer at Arizona State University
Search language is easy to understand and teach to new users
Pros and Cons
- "Support is quick and competent."
- "Search language is easy to understand and teach to new users."
- "Certain sections of the developer documentation could use some updating and clarification."
- "Search head clustering is often temperamental in its current state and should be improved, replaced by something better, or be reverted to search head pooling."
What is our primary use case?
- Monitoring IT and other processes for a large university.
- Leveraging alerts and dashboards to detect and predict security breaches and other events.
How has it helped my organization?
Splunk has enabled us to detect, even predict potential security issues, before they become severe. It has enabled our operations and development teams to more efficiently monitor and troubleshoot their systems.
What is most valuable?
The search language is easy to understand and teach to new users. The SDK is comprehensive and has incredible levels of integration with the platform and data.
What needs improvement?
- Certain sections of the developer documentation could use some updating and clarification.
- Search head clustering is often temperamental in its current state and should be improved, replaced by something better, or be reverted to search head pooling.
- Some terminology is vague and confusing (examples: deployer versus deployment server or search head versus search peer).
For how long have I used the solution?
Three to five years.
How is customer service and technical support?
Support is quick and competent.
Disclosure: I am a real user, and this review is based on my own experience and opinions.

Buyer's Guide
Download our free Splunk Enterprise Security Report and get advice and tips from experienced pros
sharing their opinions.
Updated: May 2025
Product Categories
Security Information and Event Management (SIEM) Log Management IT Operations AnalyticsPopular Comparisons
CrowdStrike Falcon
Microsoft Sentinel
IBM Security QRadar
Elastic Security
Splunk AppDynamics
Elastic Observability
Grafana Loki
Security Onion
Palantir Foundry
LogRhythm SIEM
Buyer's Guide
Download our free Splunk Enterprise Security Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- Which would you recommend to your boss, IBM QRadar or Splunk?
- What are some of the best features and use-cases of Splunk?
- What SOC product do you recommend?
- Splunk as an Enterprise Class monitoring solution -- thoughts?
- What is the biggest difference between Dynatrace and Splunk?
- IBM QRadar is rated above competitors (McAfee, Splunk, LogRhythm) in Gartner's 2020 Magic Quandrant. Agree/Disagree?
- What are the advantages of ELK over Splunk?
- How does Splunk compare with Azure Monitor?
- New risk scoring framework in the Splunk App for Enterprise Security -- thoughts?
- Splunk vs. Elastic Stack