My use cases are very limited. I use the product mostly to detect internal threats like data exfiltration.
Insider Thread Consultant at a manufacturing company with 10,001+ employees
A reliable and stable solution that helps detect internal threats and improves business resilience
Pros and Cons
- "The search lookups are useful."
- "The product must improve insider threat detection."
What is our primary use case?
What is most valuable?
I am a basic user. The search lookups are useful.
What needs improvement?
The product must improve insider threat detection. Almost everything is outside in, but not inside out.
For how long have I used the solution?
I have been using the solution for four years.
Buyer's Guide
Splunk Enterprise Security
August 2025

Learn what your peers think about Splunk Enterprise Security. Get advice and tips from experienced pros sharing their opinions. Updated: August 2025.
867,497 professionals have used our research since 2012.
What do I think about the stability of the solution?
The solution is very reliable. I like its stability. It always works.
What do I think about the scalability of the solution?
Sometimes, it takes time when we need additional information or something extra. However, the tool’s able to do it.
How are customer service and support?
I haven’t contacted the support team. I reach out to the internal expert. My searches and my requirements are very basic. The expert is great. He’s always able to help me and guide me.
How would you rate customer service and support?
Positive
What was our ROI?
We do see a return on investment. The product saves us time by automating reports and helping us see data.
What other advice do I have?
The solution helps reduce our mean time to resolve. It’s great to automate some tasks. I believe Splunk has helped improve our organization’s business resilience. We have become stronger in insider threats by just stopping things, being able to show what is leaving, and taking action on it. It's very useful when I try to identify events.
When I started working in my organization, they were using Splunk. Overall, I rate the product a nine out of ten.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.

Engineer at a government with 10,001+ employees
We can create notable events and look at the data faster, but Dashboard Studio needs to mature a bit
Pros and Cons
- "From the class that I took this week, being able to create notable events from whatever you find in the data set is pretty useful."
- "We are waiting for Dashboard Studio to mature a little bit more. There are some things that we are using with Classic Dashboards which have not yet made it to Dashboard Studio. We are waiting for that."
What is our primary use case?
We use it for a lot of compliance work and incident reviews. We are also using it for remediation and tracking assets.
How has it helped my organization?
We use Splunk not just for security, but we also collect a lot of data from our operational equipment. We are using it a lot for troubleshooting and trending and even for command and control.
It has reduced our mean time to resolve some of the things. We are able to look at the data a lot faster and see what is going on. For some of our use cases, our NOC controllers or our operators are looking at the Splunk dashboard a lot. It is a part of their main job. In one specific use case, we used to take a couple of weeks to do certain maintenance. With Splunk and having the data, we were able to reduce that to just a few hours.
It has helped improve our organization's business resilience. We are able to have the data collected in one spot, see it, and get some insights from it. That has helped a lot.
It has definitely given our technical workforce tools to help with their jobs for troubleshooting and things like that.
What is most valuable?
From the class that I took this week, being able to create notable events from whatever you find in the data set is pretty useful.
What needs improvement?
We are waiting for Dashboard Studio to mature a little bit more. There are some things that we are using with Classic Dashboards which have not yet made it to Dashboard Studio. We are waiting for that.
It seems to be limited in terms of predictive features. I took up machine learning a couple of years ago. It seems to have some capabilities there, but I do not have specific things for it right now.
For how long have I used the solution?
In our organization, we have had it for over five years, but my personal experience with it is very limited.
What do I think about the stability of the solution?
It has been working for us so far.
What do I think about the scalability of the solution?
We have been able to scale as needed.
How are customer service and support?
I have not contacted their support directly because we have folks who are pretty knowledgeable. I go to them, and then they go to their support if needed. As far as I could tell, their support has been okay. I have not heard of any issues.
Which solution did I use previously and why did I switch?
We did not have a similar product. Splunk came as a security product, and we have evolved it into doing operational work.
What about the implementation team?
We have folks who do the deployment. I am more on the interface side.
What was our ROI?
We would have seen an ROI. We are using it for a lot of our operational work and other things as well that are not related to what we are doing on a daily basis. We are looking at logs and other things that our executives are looking for.
Its time to value was within a year or so. There are a lot more things that we could do with Splunk, and that is why we ended up adding some stuff to it to fit our needs.
It is hard to tell whether we had any cost efficiencies because we did not have something like this before. Of course, we have Splunk now.
What's my experience with pricing, setup cost, and licensing?
As a team, we prefer the old pricing model with a perpetual license. We are still evaluating the whole subscription-based model.
Which other solutions did I evaluate?
We did not evaluate other solutions. Splunk came in with the modernization effort that we were going through, so it just came with the system.
What other advice do I have?
We are pretty happy with it. I would rate Splunk Enterprise Security a seven out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Buyer's Guide
Splunk Enterprise Security
August 2025

Learn what your peers think about Splunk Enterprise Security. Get advice and tips from experienced pros sharing their opinions. Updated: August 2025.
867,497 professionals have used our research since 2012.
Associate Director of IT at Rigel Pharmaceuticals Inc
Provides risk scores and end-to-end visibility
Pros and Cons
- "It provides a risk score for each object, device, or user. We can then take action if they are at a higher risk."
- "The pricing can be better."
What is our primary use case?
Splunk Enterprise Security provides more visibility into endpoints in our environment.
How has it helped my organization?
We only monitor AWS, but we also have SaaS services that are in our own clouds. So far, it is easy to monitor our cloud environment with this solution. As long as we ingest our data correctly and tune it, it will read it. It is very easy to use.
It provides end-to-end visibility into our cloud-native environment. This is critical for us because we are always one step away from a security incident, which could impact the company and cost a lot of money. That is our main point of focus.
What is most valuable?
It provides a risk score for each object, device, or user. We can then take action if they are at a higher risk.
What needs improvement?
The pricing can be better.
For how long have I used the solution?
We have been evaluating Splunk Enterprise Security for the last eight months.
What do I think about the stability of the solution?
I cannot say anything about stability, but I am assuming it would be the same as Splunk. It is an app. It is going to work.
How are customer service and support?
The technical support is above average, but they do not go into the details, so we have a contract with a third party to help us.
There might be more Splunk support tiers, but we are working with SP6. They will get their hands directly onto our Splunk environment, whereas Splunk support does not do that. Maybe there is a different tier that does that, but we do not have that. It is more of an email dialogue. They are not going to VPN into our environment. SP6 is more hands-on. I would rate SP6 a nine out of ten.
Which solution did I use previously and why did I switch?
We did not use a similar solution. We have Carbon Black for endpoints, but this is going to be a lot bigger than that.
How was the initial setup?
We are still evaluating it. We have not deployed it yet, but I was involved with the deployment of Splunk.
It was very easy to set it up for evaluation. It is just an installer file. It is an add-on app for Splunk, and if you know how to install Splunk and add-ons, it is easy.
What's my experience with pricing, setup cost, and licensing?
I am fine with the licensing, but in terms of the cost, it is expensive for the data that we have. We have an open discussion with our account rep about this.
Which other solutions did I evaluate?
We are not evaluating any solutions because we already have Splunk, and we do not want to leave Splunk. I like it, so it is just a matter of making the commitment.
What other advice do I have?
The value that I get from attending Splunk Conferences is going to sessions and learning about what other people are doing and use cases that I have not really thought of. Also, I am able to talk directly to people about questions I have regarding our Splunk instances, and I can get some answers right away. It is very good to know what people are doing because sometimes we do something one way, but we do not know if we are doing it the right way. Here, we can get validation, or realize that we are doing it wrong and make the necessary changes. That is very valuable.
I would rate Splunk Enterprise Security a ten out of ten. Most customers at the conference have already implemented it, except for our company. It is a critical foundation app that allows you to explore other apps that Splunk is grading, and it works.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Regional Channel Manager at i2sBusiness Solutions
Drastically reduces time spent by analysts on false positives, and AI-based detection identifies real-time anomalies
Pros and Cons
- "The dashboard and reporting are very good... It provides very good visibility in a hybrid cloud environment, and you can build custom utilization APIs using Splunk."
- "While there aren't any major areas where the solution has to be improved, there are certain integrations that are still not available. I would specifically like to see legacy applications integrated."
What is our primary use case?
The use cases are mainly around monitoring for our clients' security operation centers and correlation of events and analytics for incidents that have been identified.
How has it helped my organization?
It has really improved things for our clients by reducing false positives. Most of the time, analysts end up wasting their time with false incidents, and that has been drastically reduced by Splunk.
It also definitely helps speed up your security investigations.
What is most valuable?
The dashboard and reporting are very good. Our clients monitor multiple cloud environments and Splunk helps because, in general, monitoring multiple cloud environments is definitely difficult and very complex. It provides very good visibility in a hybrid cloud environment, and you can build custom utilization APIs using Splunk.
The solution is also very good in its threat-hunting capabilities and anomaly detection. It uses an AI-based detection system to identify real-time anomalies and provides complete visibility into the network.
And you can feed multiple threat sources into Splunk and the Threat Intelligence Management feature gives you information about current or potential attacks. It provides complete security support in the threat intelligence space. It helps your administrator to correlate indicators of compromise from threat intelligence databases and feeds.
Also, the Splunk Mission Control feature, which is mainly for Splunk Enterprise Security cloud users, provides a unified and simplified security operations experience for SOC analysts.
We also use the solution's Threat Topology and MITRE ATT&CK framework feature. That's something you need for cyber breaches to contain a threat. This feature comes into play when you need to mitigate an incident in your environment.
What needs improvement?
While there aren't any major areas where the solution has to be improved, there are certain integrations that are still not available. I would specifically like to see legacy applications integrated. Splunk has integrations with AWS, Azure, and other cloud providers, but when it comes to legacy applications, it is difficult to do a Splunk integration.
For how long have I used the solution?
We have been working with Splunk Enterprise Security for one and a half years.
What do I think about the stability of the solution?
It's a very stable solution.
What do I think about the scalability of the solution?
It is very highly scalable.
How are customer service and support?
The technical support is very good.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
I used IBM Security QRadar. The main reason for switching is that Splunk has the scalability to handle bigger enterprise logs. Log management is the biggest issue in any SIEM. Splunk is able to rapidly grow its capacity.
How was the initial setup?
Our clients' implementations are mostly on-prem and in the cloud.
What's my experience with pricing, setup cost, and licensing?
Splunk is definitely not a cheap solution. It is an expensive product.
If a customer is evaluating SIEM solutions and is considering cheaper products, it depends on the customer's budget and use cases. For a large, enterprise customer with critical infrastructure that needs to be monitored 24/7, obviously, the cheaper solutions may not have the capacity to handle the huge volume of data. Splunk has the SIEM and the scalability as well as visibility features. When you want to monitor your applications and how they are performing, that is where Splunk is very strong.
What other advice do I have?
In terms of maintenance of Splunk, you need to have an IT administrator monitoring it at all times.
When it comes to a large, enterprise customer's critical infrastructure, Splunk is one of the best solutions to use in a security operations center. It has multiple advantages, such as the dashboard that provides complete visibility, and a threat detection system with very advanced features. It is very valuable for any company that wants a good protection system.
You should definitely consider Splunk as one of your options for your SOC.
Disclosure: My company has a business relationship with this vendor other than being a customer. Reseller
Product Owner at ABN AMRO Bank N.V.
Poor performance and the display options are limited, but it can parse a variety of log files
Pros and Cons
- "Splunk works based on parsing log files."
- "I find the graphical options really limited and you don't have enough control over how to display the data that you want to see."
What is our primary use case?
We use Splunk to monitor our private cloud, data center, and other applications.
How has it helped my organization?
I don't like Splunk very much and find that it does not have many useful features.
What is most valuable?
Splunk works based on parsing log files.
What needs improvement?
I don't like the pipeline-organized programming interface.
I find the graphical options really limited and you don't have enough control over how to display the data that you want to see.
I find that the performance really varies. Sometimes, the platform doesn't respond in time. It takes a really long time to produce any results. For example, if you want to display a graph and put information out, it can become unresponsive. Perhaps you have a website and you want to show the data, there's a template for that, or it has a configuration to display your graphics, and sometimes it just doesn't show any data. This is because the system is unresponsive. There may be too much data that it has to look through. Sometimes, it responds with the fact that there is too much data to parse, and then it just doesn't give you anything. The basic problem is that every time you do a refresh, it tries to redo all of the queries for the full dataset.
Fixing Splunk would require a redesign. The basic way the present the graphs is pipeline-based parsing of log files, and it's more of a problem than it is helpful. Sometimes, you have to perform a lot of tricks to get the data in a format that you can parse.
You cannot really use global variables and you can't easily define a constant to use later. These things make it not as easy to use.
For how long have I used the solution?
I have been using Splunk for approximately one year.
What do I think about the stability of the solution?
I use Splunk at least a couple of times a week.
What do I think about the scalability of the solution?
I'm not sure about scalability but to my thinking, it's not very scalable. I know that it's probably expensive because it relies a lot on importing log files from all of the systems. One of the issues with respect to scalability is that there's never enough storage. Also, the more storage you have, the more systems you need to manage all the log files.
Splunk is open for all of the users in the company. We might have 1,000 IT personnel that could access it, although I'm not sure how many people actually use it. I estimate that there are perhaps 200 active users.
How are customer service and support?
I have not been in contact with technical support from Splunk.
Which solution did I use previously and why did I switch?
In this company, we did not previously use a different monitoring solution.
How was the initial setup?
I was not involved in the initial setup.
We have a DevOps team that is implementing Splunk and they are responsible for it. For example, they take care of the licensing of the product.
What about the implementation team?
We have a team at the company that completed the setup and deployment.
Which other solutions did I evaluate?
The other product that I've seen is Elastic, and I think that it would be a better choice than Splunk. This is something that I'm basing on performance, as well as the other features.
What other advice do I have?
My understanding is that as a company, we are migrating to Azure. When this happens, Splunk will be decommissioned.
Overall, I don't think that this is a very good product and I don't recommend it.
I would rate this solution a five out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Security Engineer at a recreational facilities/services company with 10,001+ employees
Very versatile for many use cases
Pros and Cons
- "The feature that I have found most valuable with Splunk is the ability to sift through a bunch of data very quickly."
- "Their technical support sucks."
What is our primary use case?
We are using Splunk in the standard information security use case. We're also using it for various application use cases around identity management, windows active directory, and those types of use cases.
How has it helped my organization?
Splunk has provided a venue for us to determine student engagement during COVID, for which we didn't really have any other way except by looking at data that we captured off of our student systems and our authentication servers to see who's logging in, and who's logging out, and for how long they've been logged in.
What is most valuable?
The feature that I have found most valuable with Splunk is the ability to sift through a bunch of data very quickly.
We have about a 500 gig license with Splunk, so it's not like petabytes of data, but even 500 gigs is kind of hard to sift through sometimes.
What needs improvement?
Splunk has been improving consistently over the last couple of revs. I still think there are some administrative features that they could improve on and make them less kludgy, but from a user perspective, it has gotten very clean and very sexy looking over the last few builds. So the users seem to like it.
By less kludgy, I mean that in the version I'm running, I still have to go into the command line and modify files and then go into the GUI and validate that they got modified. So it's not all in the GUI, but it has been moving slowly to the GUI over the last several versions. It would be nice if they could move all of the administrative features into a GUI platform so that when you're in the Splunk distributed environment management platform, you then don't have to go into the command line to add new applications or new packages that you then want to be able to push out to your forwarders. Their forwarder management is still kind of split that way.
I don't really have any feature requests in Splunk's space. They seem to be doing a good job of keeping it contemporary from that perspective.
Splunk's mission is to move everyone to the cloud and charge us a bunch more money. Their goal is to cloud source everything, and quite honestly, the price of cloud sourcing the product, even at smaller 500 gigs a day (which isn't a lot of data by Splunk standards) in the cloud for that is ludicrous. The cost for me to buy equipment every three years and own licensing and run it local to my prem, is significantly less from a three or five year license. I'm going to spend X amount of money on hardware every X years, and I'm going to have to pay licensing costs on software of X over that same period versus that amount that I'd amortize over five years is what I would be paying every year in the cloud.
That is the point with the product. It seems like they are so focused on forcing everyone into the cloud that they seem to be not understanding that there are people that don't have those really deep pockets. It's one thing for a Fortune 50 company to spend a million dollars a year in the cloud. It's another thing when you're a nonprofit educational institute to spend that kind of money in the cloud. Even though we do get some discounts in most of the cloud space providers, it is still not on par with the big public businesses.
For how long have I used the solution?
I have been using Splunk for probably 10 years.
What do I think about the stability of the solution?
At least in our environment, it is super stable. When you think about how much time you spend working with other applications, just Windows Server requires more feeding than Splunk does, you see that Splunk is a very low maintenance care and feeding product.
We have probably 150 users in the environment and their roles vary from being application management folks to application engineering folks to the executive suite, so lots of different use cases. The executive suite tend to prefer more curated content and the application owners have a mix of curated content and dynamic search functions they can perform. Then the engineering tier basically gets some curated content and some free reign to do whatever they want for the most part. I'm the guy that supports this instance. So there's one person.
I support not only Splunk, but I am also the campus security engineer and I'm also the dude that runs or is responsible for all of our campus monitoring infrastructure. So that tells you how little maintenance is required.
We are adding new use cases on a fairly regular basis and we are adding more licensing to our indexing license. I don't see Splunk going away. There's nothing else that I think provides the ability to do this much data analytics from just the numbers of equipment that you need to run it. Also, the number of people that you need to actually make sure that it's functioning well. In higher ed., everybody always says we should do open source. And I respond that what I do in Splunk with 20 systems, I would need three racks of equipment to do on an open source platform. I have basically 70 - 75% of the racks now and I'd need three times that or more to run this as an open source product. And it wouldn't be as cute and it wouldn't be as beautiful or as flexible.
What do I think about the scalability of the solution?
I know other folks in the higher ed. space that are running petabyte size instances with Splunk. So I would have to say it scales very well just from talking to the folks in my market silo.
How are customer service and support?
Their technical support sucks.
My engagement with their technical support was for a product which they basically took over from an open source product and they just seemed to not be able to figure out why it's not doing what it's supposed to do. The number of times I've had to engage with Splunk for solutions has been for a couple of use cases. And in every one of those use cases, support was very painful. It took a very long time and it seemed like they were more interested in burning their queue volume than actually satisfying me as a customer.
I work in higher ed. Here in higher ed., it costs us a lot of money to run it. The support from the company that you spend a lot of money with is pretty poor. I get most of my support through the Splunk sales folks because they seem to know more and they're more incentivized to keep me as a customer. When I call in to open a ticket with Splunk support, they really don't know, and this is going to sound terrible, they don't really care whether I have a 50 Meg license or a 50 petabyte license. If it's not on their workflow, their pre-programmed triage, they can't do it.
Which solution did I use previously and why did I switch?
Splunk came into being at Case Western when we were looking for a better log product than Check Point was providing at that point in time. My entire investment in Splunk, in hardware and software and integration cost, was cheaper than what Check Point was going to provide, or what the Check Point solution path was for just looking at firewall data. We knew we needed to be able to do more analytics than what we were currently getting out of our firewall products and Splunk was brought in to do that. It can do this and a whole lot more.
How was the initial setup?
Splunk is a complex critter to put in and it's a more complex critter to keep running. We have 10 search heads and four indexers and universal and a heavy forwarding cluster. We have clustered indexers and clustered search heads. This is definitely not a drag and drop product.
We engaged a third party Splunk integrator to help us do our Splunk deployment and they did our initial deployment. We used a different integrator to do some of our upgrades, which we probably won't use again. Our implementation strategy was we really just wanted to look at the classic security use case when we put this in 10 years ago. Then after that came in, and everybody was happy with what it was doing, we added some other use cases and universal forwarding and so on and so forth.
What about the implementation team?
We used an integrator.
The integrator we used to do our initial deployment was excellent. The integrator we used to do our last round of upgrades was less than excellent.
When I hire an integrator to do an upgrade in an environment, I expect them to come back and say "all of your application layer apps are upgradeable, but your OS's need to be upgraded. Do you want me to do that? Or should you do that?" I now have different versions of OS's under Splunk running in my Linux world and it would've been nice to upgrade the system OS and then upgrade Splunk, even if it was more disruptive. I guess I have to read the statement of work more closely in the future.
What was our ROI?
The TCO and ROI are really great if you're in the private, non-public sector and you're in a more standard business sector. The return on investment in total cost of ownership on Splunk is from somebody who doesn't fit into that neat silo. Do we calculate that stuff? So our return on investment is by being able to solve problems that we never knew we could solve. My answer to it is the flexibility to be able to figure out student engagement when COVID hit. This was the only platform we could do it on.
What's my experience with pricing, setup cost, and licensing?
I can comment on price in this way - in education in Ohio, we're part of the Ohio supercomputer consortium, and they act as a collective bargaining agent. So we get our licensing as a piece of the State of Ohio's Splunk license. So my pricing is very much not list or even reduced list because of the volume that the state buys.
We generally spend about $20,000 a year in third party integrator costs to get us past some of the rough edges that we get with Splunk support.
Which other solutions did I evaluate?
We briefly looked at the open source product and we obviously looked at a Check Point product. When we looked at Splunk it seemed like they had a smaller cost to procure it, and a much smaller cost to maintain it than all of those other solutions. So it was kind of why we went with Splunk. This is very non-intuitive since everybody says they love Splunk but it costs too much.
What other advice do I have?
My advice to anyone considering Splunk is to understand exactly how much data you want to look at and you want to bring in on a daily basis. Then create a rational strategy to bring the data in, in reasonably sized chunks, that fulfill a use case at a time.
On a scale of one to ten, I would rate Splunk a really good nine.
I'd rate it a really good nine because it's really versatile. You can do a lot of things with it. It allows you to do a lot of analytics in the platform without needing a bunch of other third partyware to help you figure it out.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Cyber Security Engineer at a tech vendor with 51-200 employees
Deployment and search capabilities boost practical use and efficiency
Pros and Cons
- "Its search is very flexible, allowing you to search anything by typing a sentence."
- "Splunk Enterprise Security is a wonderful solution, however, the background configuration process could be better as the administration process is very complicated."
What is our primary use case?
I'm a technical support engineer for Cortex XDR at the moment and in my company, we are selling the Cortex XDR solution to other companies.
I also have experience with Splunk Enterprise Security and CrowdStrike too; we are using those products in my company. For Splunk Enterprise Security, I am using the Enterprise Security module and base Splunk for developing rules.
What is most valuable?
The deployment server is very good and is one of the best features of Splunk Enterprise Security for me; you can use that deployment server even for distributing any agents, upgrading automatically, and universal forwarders. Its search is very flexible, allowing you to search anything by typing a sentence.
What needs improvement?
Splunk Enterprise Security is a wonderful solution, however, the background configuration process could be better as the administration process is very complicated. As an analyst rather than a Splunk engineer, some background configurations might be easier.
For how long have I used the solution?
I'm working with Splunk Enterprise Security for six months, however, I have been using Splunk for one year.
What do I think about the stability of the solution?
Splunk Enterprise Security is a very stable product; I have never been in trouble with any stability problems if you set it up correctly.
How are customer service and support?
I would give support a seven out of ten as Splunk Enterprise Security's advanced support is very skillful, however, to reach that advanced support, first they send you some beginner-level support that mostly does not solve problems for me. That said, when they escalate it, it completely finds a solution.
How would you rate customer service and support?
Which solution did I use previously and why did I switch?
Before Splunk Enterprise Security, I didn't use any other solution.
How was the initial setup?
I did not set up the Splunk Enterprise Security; my admin colleagues from another department set it up for me.
I'm just using and revising the rules. I'm a Cortex admin, so I'm involved in the process for Cortex, not for Splunk Enterprise Security.
My company is a partner with Splunk Enterprise Security. As an engineer and layer two security analyst, I'm solving problems with Splunk Enterprise Security, editing rules on customers, reviewing alerts, and developing rules.
What's my experience with pricing, setup cost, and licensing?
I'm not aware of the price of the tool. My company and other departments arange the licensing.
What other advice do I have?
On Splunk Enterprise Security, we imported from the content library, specifically from the content management page that contains many rules; we are importing rules from there, enabling rules, and editing them. I'm not a deep down administrator of Splunk Enterprise Security, so I'm not arranging the data models. I'm mostly editing the rules.
On a scale of one to ten, I rate Splunk Enterprise Security an eight out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
Last updated: Jul 9, 2025
Flag as inappropriateSecurity delivery manager at a tech vendor with 1,001-5,000 employees
Drastically reduces SOC overhead
Pros and Cons
- "The tool drastically reduces SOC overhead. Its integration with our tool suite is great and helps us correlate events. The solution is also a lot faster than our standalone instances."
- "The solution is expensive."
What is our primary use case?
We use the solution in our SOC to support SOAR. We use its alerting capabilities and integrate them with our SOAR platform. Additionally, we tie it in with cyber threat intelligence, cyber threat hunting, and adversary emulation tools to identify gaps in our environment and alert us to notable events.
What is most valuable?
The tool drastically reduces SOC overhead. Its integration with our tool suite is great and helps us correlate events. The solution is also a lot faster than our standalone instances.
Splunk Enterprise Security helps address our customers' missions. We want to ensure that our environment is secure and safe and detects anomalies and threat actors as soon as possible.
The solution helps my organization's ability to ingest and normalize data. It has also improved resilience.
What needs improvement?
Enterprise Security is expensive.
For how long have I used the solution?
I have been working with the product for three years.
What do I think about the stability of the solution?
Splunk Enterprise Security is very stable.
What do I think about the scalability of the solution?
The tool is very scalable. We can deploy agents seamlessly and get reports.
How are customer service and support?
We have had good success with customer support. We haven't had any issues contacting them and getting problems resolved.
How was the initial setup?
Splunk Enterprise Security's deployment is hit or miss. Recently, we got UBA. We were able to spin up an environment easily with Terraform. However, the recent upgrade caused many hiccups and slowdowns. We are working with support to resolve them. Some legacy code is choking the system and slowing us.
Which other solutions did I evaluate?
We do market evaluation and continuous research every year to check for alternatives to our security tools.
What other advice do I have?
It seems like the tool is improving. It incorporates AI into the platform to streamline event identification processes.
Splunk Enterprise Security does a good job. However, we need many analysts to correlate searches and populate data models, and some overheads are needed in any SOC environment.
We have a lot of data to process from different sources. However, we have only limited data analysts. It takes time to find malicious threats or what we seek.
No specific metrics are tracked, but we report this to our leadership weekly, focusing on continuous improvement. Regarding reducing the mean time to resolve, especially with our SOAR integration, we can swiftly address major issues by leveraging alerts to initiate tickets. This allows us to notify the teams and address issues immediately.
I rate the overall product a ten out of ten. I don't think there is another alternative with similar capabilities.
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner

Buyer's Guide
Download our free Splunk Enterprise Security Report and get advice and tips from experienced pros
sharing their opinions.
Updated: August 2025
Product Categories
Security Information and Event Management (SIEM) Log Management IT Operations AnalyticsPopular Comparisons
CrowdStrike Falcon
Microsoft Sentinel
IBM Security QRadar
Elastic Security
Splunk AppDynamics
Grafana Loki
Elastic Observability
Graylog Enterprise
Security Onion
Cortex XSIAM
Palantir Foundry
Buyer's Guide
Download our free Splunk Enterprise Security Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- Which would you recommend to your boss, IBM QRadar or Splunk?
- What are some of the best features and use-cases of Splunk?
- What SOC product do you recommend?
- Splunk as an Enterprise Class monitoring solution -- thoughts?
- What is the biggest difference between Dynatrace and Splunk?
- IBM QRadar is rated above competitors (McAfee, Splunk, LogRhythm) in Gartner's 2020 Magic Quandrant. Agree/Disagree?
- What are the advantages of ELK over Splunk?
- How does Splunk compare with Azure Monitor?
- New risk scoring framework in the Splunk App for Enterprise Security -- thoughts?
- Splunk vs. Elastic Stack