We use it mostly to generate notables, and then we can use other tools, such as ticketing systems or other SOAR platforms, to investigate.
SOAR Developer at a media company with 10,001+ employees
Reduces time to detect, improves uptime, and handles correlation search well
Pros and Cons
- "The correlation search functions that generate all the notables are valuable. That can get pretty complicated, and it handles that pretty well."
- "Some of the search functions can be better. There has been a lot of talk at the conference about the update of SPL before each iteration. That will be a lot of help."
What is our primary use case?
How has it helped my organization?
I was not around before we had Splunk Enterprise Security in our organization, so I do not know about the before and after, but I can tell it would be very painful to not have it.
It is pretty easy to monitor multiple cloud environments. All the logs from our cloud environments go to Splunk, and then we can search everything at once. It is pretty helpful.
Splunk Enterprise Security has end-to-end visibility into our cloud-native environments. It is pretty important. Especially if you use it as your single source of truth, it is pretty invaluable that you have everything in there.
It has reduced our mean time to detect, so inadvertently, it has also reduced our mean time to resolve. However, I do not have the metrics.
Splunk Enterprise Security has definitely improved our organization’s business resilience. There are a lot of logs that help with monitoring and alerting and keeping the business up.
It can help to predict, identify, and solve problems in real time. We do have some health alerts, and if they kick off, we might be able to fix something before it is really broken. In that sense, it is good.
Splunk Enterprise Security has been pretty good in terms of providing business resilience by empowering our staff. Most of our users are security-focused, but having everybody with the ability to write their own searches or build upon what we already have for detection of the future things is pretty helpful.
What is most valuable?
The correlation search functions that generate all the notables are valuable. That can get pretty complicated, and it handles that pretty well.
What needs improvement?
Some of the search functions can be better. There has been a lot of talk at the conference about the update of SPL before each iteration. That will be a lot of help.
Buyer's Guide
Splunk Enterprise Security
March 2026
Learn what your peers think about Splunk Enterprise Security. Get advice and tips from experienced pros sharing their opinions. Updated: March 2026.
885,264 professionals have used our research since 2012.
For how long have I used the solution?
I have been using Splunk Enterprise Security for about two years.
What do I think about the stability of the solution?
It is pretty stable. We have not had any instances where Splunk just completely died. Its stability is good.
What do I think about the scalability of the solution?
It seems pretty scalable, especially considering how much data we ingest. It is a good tool.
How are customer service and support?
I have not interacted with them recently, but they are pretty good when I do need something from Splunk. I would rate them a ten out of ten. I have not had any issues with their support.
Which solution did I use previously and why did I switch?
We were probably using Elasticsearch.
How was the initial setup?
It was already implemented when I got here.
What was our ROI?
We have probably seen an ROI. We are in the security space, and there has definitely been improvement in uptime and the mean time to detect and respond to security alerts.
Its time to value is pretty immediate. The more logs and the more standardization that we get into Splunk, the quicker that comes.
What's my experience with pricing, setup cost, and licensing?
Most people share the same thought that the ingestion rates can get pretty pricey. There is a lot of work we do to curate the data that we send to Splunk so that it is not too noisy or too expensive.
What other advice do I have?
Overall, I would rate Splunk Enterprise Security an eight out of ten. There are some cool things. A lot of the talks at this Splunk conference have touched on some of the gaps that Splunk is working to close, but it is a very solid tool.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Insider Thread Consultant at a manufacturing company with 10,001+ employees
A reliable and stable solution that helps detect internal threats and improves business resilience
Pros and Cons
- "The search lookups are useful."
- "The product must improve insider threat detection."
What is our primary use case?
My use cases are very limited. I use the product mostly to detect internal threats like data exfiltration.
What is most valuable?
I am a basic user. The search lookups are useful.
What needs improvement?
The product must improve insider threat detection. Almost everything is outside in, but not inside out.
For how long have I used the solution?
I have been using the solution for four years.
What do I think about the stability of the solution?
The solution is very reliable. I like its stability. It always works.
What do I think about the scalability of the solution?
Sometimes, it takes time when we need additional information or something extra. However, the tool’s able to do it.
How are customer service and support?
I haven’t contacted the support team. I reach out to the internal expert. My searches and my requirements are very basic. The expert is great. He’s always able to help me and guide me.
How would you rate customer service and support?
Positive
What was our ROI?
We do see a return on investment. The product saves us time by automating reports and helping us see data.
What other advice do I have?
The solution helps reduce our mean time to resolve. It’s great to automate some tasks. I believe Splunk has helped improve our organization’s business resilience. We have become stronger in insider threats by just stopping things, being able to show what is leaving, and taking action on it. It's very useful when I try to identify events.
When I started working in my organization, they were using Splunk. Overall, I rate the product a nine out of ten.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Buyer's Guide
Splunk Enterprise Security
March 2026
Learn what your peers think about Splunk Enterprise Security. Get advice and tips from experienced pros sharing their opinions. Updated: March 2026.
885,264 professionals have used our research since 2012.
Engineer at a government with 10,001+ employees
We can create notable events and look at the data faster, but Dashboard Studio needs to mature a bit
Pros and Cons
- "From the class that I took this week, being able to create notable events from whatever you find in the data set is pretty useful."
- "We are waiting for Dashboard Studio to mature a little bit more. There are some things that we are using with Classic Dashboards which have not yet made it to Dashboard Studio. We are waiting for that."
What is our primary use case?
We use it for a lot of compliance work and incident reviews. We are also using it for remediation and tracking assets.
How has it helped my organization?
We use Splunk not just for security, but we also collect a lot of data from our operational equipment. We are using it a lot for troubleshooting and trending and even for command and control.
It has reduced our mean time to resolve some of the things. We are able to look at the data a lot faster and see what is going on. For some of our use cases, our NOC controllers or our operators are looking at the Splunk dashboard a lot. It is a part of their main job. In one specific use case, we used to take a couple of weeks to do certain maintenance. With Splunk and having the data, we were able to reduce that to just a few hours.
It has helped improve our organization's business resilience. We are able to have the data collected in one spot, see it, and get some insights from it. That has helped a lot.
It has definitely given our technical workforce tools to help with their jobs for troubleshooting and things like that.
What is most valuable?
From the class that I took this week, being able to create notable events from whatever you find in the data set is pretty useful.
What needs improvement?
We are waiting for Dashboard Studio to mature a little bit more. There are some things that we are using with Classic Dashboards which have not yet made it to Dashboard Studio. We are waiting for that.
It seems to be limited in terms of predictive features. I took up machine learning a couple of years ago. It seems to have some capabilities there, but I do not have specific things for it right now.
For how long have I used the solution?
In our organization, we have had it for over five years, but my personal experience with it is very limited.
What do I think about the stability of the solution?
It has been working for us so far.
What do I think about the scalability of the solution?
We have been able to scale as needed.
How are customer service and support?
I have not contacted their support directly because we have folks who are pretty knowledgeable. I go to them, and then they go to their support if needed. As far as I could tell, their support has been okay. I have not heard of any issues.
Which solution did I use previously and why did I switch?
We did not have a similar product. Splunk came as a security product, and we have evolved it into doing operational work.
What about the implementation team?
We have folks who do the deployment. I am more on the interface side.
What was our ROI?
We would have seen an ROI. We are using it for a lot of our operational work and other things as well that are not related to what we are doing on a daily basis. We are looking at logs and other things that our executives are looking for.
Its time to value was within a year or so. There are a lot more things that we could do with Splunk, and that is why we ended up adding some stuff to it to fit our needs.
It is hard to tell whether we had any cost efficiencies because we did not have something like this before. Of course, we have Splunk now.
What's my experience with pricing, setup cost, and licensing?
As a team, we prefer the old pricing model with a perpetual license. We are still evaluating the whole subscription-based model.
Which other solutions did I evaluate?
We did not evaluate other solutions. Splunk came in with the modernization effort that we were going through, so it just came with the system.
What other advice do I have?
We are pretty happy with it. I would rate Splunk Enterprise Security a seven out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Associate Director of IT at Rigel Pharmaceuticals Inc
Provides risk scores and end-to-end visibility
Pros and Cons
- "It provides a risk score for each object, device, or user. We can then take action if they are at a higher risk."
- "The pricing can be better."
What is our primary use case?
Splunk Enterprise Security provides more visibility into endpoints in our environment.
How has it helped my organization?
We only monitor AWS, but we also have SaaS services that are in our own clouds. So far, it is easy to monitor our cloud environment with this solution. As long as we ingest our data correctly and tune it, it will read it. It is very easy to use.
It provides end-to-end visibility into our cloud-native environment. This is critical for us because we are always one step away from a security incident, which could impact the company and cost a lot of money. That is our main point of focus.
What is most valuable?
It provides a risk score for each object, device, or user. We can then take action if they are at a higher risk.
What needs improvement?
The pricing can be better.
For how long have I used the solution?
We have been evaluating Splunk Enterprise Security for the last eight months.
What do I think about the stability of the solution?
I cannot say anything about stability, but I am assuming it would be the same as Splunk. It is an app. It is going to work.
How are customer service and support?
The technical support is above average, but they do not go into the details, so we have a contract with a third party to help us.
There might be more Splunk support tiers, but we are working with SP6. They will get their hands directly onto our Splunk environment, whereas Splunk support does not do that. Maybe there is a different tier that does that, but we do not have that. It is more of an email dialogue. They are not going to VPN into our environment. SP6 is more hands-on. I would rate SP6 a nine out of ten.
Which solution did I use previously and why did I switch?
We did not use a similar solution. We have Carbon Black for endpoints, but this is going to be a lot bigger than that.
How was the initial setup?
We are still evaluating it. We have not deployed it yet, but I was involved with the deployment of Splunk.
It was very easy to set it up for evaluation. It is just an installer file. It is an add-on app for Splunk, and if you know how to install Splunk and add-ons, it is easy.
What's my experience with pricing, setup cost, and licensing?
I am fine with the licensing, but in terms of the cost, it is expensive for the data that we have. We have an open discussion with our account rep about this.
Which other solutions did I evaluate?
We are not evaluating any solutions because we already have Splunk, and we do not want to leave Splunk. I like it, so it is just a matter of making the commitment.
What other advice do I have?
The value that I get from attending Splunk Conferences is going to sessions and learning about what other people are doing and use cases that I have not really thought of. Also, I am able to talk directly to people about questions I have regarding our Splunk instances, and I can get some answers right away. It is very good to know what people are doing because sometimes we do something one way, but we do not know if we are doing it the right way. Here, we can get validation, or realize that we are doing it wrong and make the necessary changes. That is very valuable.
I would rate Splunk Enterprise Security a ten out of ten. Most customers at the conference have already implemented it, except for our company. It is a critical foundation app that allows you to explore other apps that Splunk is grading, and it works.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Regional Channel Manager at i2sBusiness Solutions
Drastically reduces time spent by analysts on false positives, and AI-based detection identifies real-time anomalies
Pros and Cons
- "The dashboard and reporting are very good... It provides very good visibility in a hybrid cloud environment, and you can build custom utilization APIs using Splunk."
- "While there aren't any major areas where the solution has to be improved, there are certain integrations that are still not available. I would specifically like to see legacy applications integrated."
What is our primary use case?
The use cases are mainly around monitoring for our clients' security operation centers and correlation of events and analytics for incidents that have been identified.
How has it helped my organization?
It has really improved things for our clients by reducing false positives. Most of the time, analysts end up wasting their time with false incidents, and that has been drastically reduced by Splunk.
It also definitely helps speed up your security investigations.
What is most valuable?
The dashboard and reporting are very good. Our clients monitor multiple cloud environments and Splunk helps because, in general, monitoring multiple cloud environments is definitely difficult and very complex. It provides very good visibility in a hybrid cloud environment, and you can build custom utilization APIs using Splunk.
The solution is also very good in its threat-hunting capabilities and anomaly detection. It uses an AI-based detection system to identify real-time anomalies and provides complete visibility into the network.
And you can feed multiple threat sources into Splunk and the Threat Intelligence Management feature gives you information about current or potential attacks. It provides complete security support in the threat intelligence space. It helps your administrator to correlate indicators of compromise from threat intelligence databases and feeds.
Also, the Splunk Mission Control feature, which is mainly for Splunk Enterprise Security cloud users, provides a unified and simplified security operations experience for SOC analysts.
We also use the solution's Threat Topology and MITRE ATT&CK framework feature. That's something you need for cyber breaches to contain a threat. This feature comes into play when you need to mitigate an incident in your environment.
What needs improvement?
While there aren't any major areas where the solution has to be improved, there are certain integrations that are still not available. I would specifically like to see legacy applications integrated. Splunk has integrations with AWS, Azure, and other cloud providers, but when it comes to legacy applications, it is difficult to do a Splunk integration.
For how long have I used the solution?
We have been working with Splunk Enterprise Security for one and a half years.
What do I think about the stability of the solution?
It's a very stable solution.
What do I think about the scalability of the solution?
It is very highly scalable.
How are customer service and support?
The technical support is very good.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
I used IBM Security QRadar. The main reason for switching is that Splunk has the scalability to handle bigger enterprise logs. Log management is the biggest issue in any SIEM. Splunk is able to rapidly grow its capacity.
How was the initial setup?
Our clients' implementations are mostly on-prem and in the cloud.
What's my experience with pricing, setup cost, and licensing?
Splunk is definitely not a cheap solution. It is an expensive product.
If a customer is evaluating SIEM solutions and is considering cheaper products, it depends on the customer's budget and use cases. For a large, enterprise customer with critical infrastructure that needs to be monitored 24/7, obviously, the cheaper solutions may not have the capacity to handle the huge volume of data. Splunk has the SIEM and the scalability as well as visibility features. When you want to monitor your applications and how they are performing, that is where Splunk is very strong.
What other advice do I have?
In terms of maintenance of Splunk, you need to have an IT administrator monitoring it at all times.
When it comes to a large, enterprise customer's critical infrastructure, Splunk is one of the best solutions to use in a security operations center. It has multiple advantages, such as the dashboard that provides complete visibility, and a threat detection system with very advanced features. It is very valuable for any company that wants a good protection system.
You should definitely consider Splunk as one of your options for your SOC.
Disclosure: My company has a business relationship with this vendor other than being a customer. Reseller
Cyber Security Engineer at a tech vendor with 51-200 employees
Deployment and search capabilities boost practical use and efficiency
Pros and Cons
- "Its search is very flexible, allowing you to search anything by typing a sentence."
- "Splunk Enterprise Security is a wonderful solution, however, the background configuration process could be better as the administration process is very complicated."
What is our primary use case?
I'm a technical support engineer for Cortex XDR at the moment and in my company, we are selling the Cortex XDR solution to other companies.
I also have experience with Splunk Enterprise Security and CrowdStrike too; we are using those products in my company. For Splunk Enterprise Security, I am using the Enterprise Security module and base Splunk for developing rules.
What is most valuable?
The deployment server is very good and is one of the best features of Splunk Enterprise Security for me; you can use that deployment server even for distributing any agents, upgrading automatically, and universal forwarders. Its search is very flexible, allowing you to search anything by typing a sentence.
What needs improvement?
Splunk Enterprise Security is a wonderful solution, however, the background configuration process could be better as the administration process is very complicated. As an analyst rather than a Splunk engineer, some background configurations might be easier.
For how long have I used the solution?
I'm working with Splunk Enterprise Security for six months, however, I have been using Splunk for one year.
What do I think about the stability of the solution?
Splunk Enterprise Security is a very stable product; I have never been in trouble with any stability problems if you set it up correctly.
How are customer service and support?
I would give support a seven out of ten as Splunk Enterprise Security's advanced support is very skillful, however, to reach that advanced support, first they send you some beginner-level support that mostly does not solve problems for me. That said, when they escalate it, it completely finds a solution.
How would you rate customer service and support?
Which solution did I use previously and why did I switch?
Before Splunk Enterprise Security, I didn't use any other solution.
How was the initial setup?
I did not set up the Splunk Enterprise Security; my admin colleagues from another department set it up for me.
I'm just using and revising the rules. I'm a Cortex admin, so I'm involved in the process for Cortex, not for Splunk Enterprise Security.
My company is a partner with Splunk Enterprise Security. As an engineer and layer two security analyst, I'm solving problems with Splunk Enterprise Security, editing rules on customers, reviewing alerts, and developing rules.
What's my experience with pricing, setup cost, and licensing?
I'm not aware of the price of the tool. My company and other departments arange the licensing.
What other advice do I have?
On Splunk Enterprise Security, we imported from the content library, specifically from the content management page that contains many rules; we are importing rules from there, enabling rules, and editing them. I'm not a deep down administrator of Splunk Enterprise Security, so I'm not arranging the data models. I'm mostly editing the rules.
On a scale of one to ten, I rate Splunk Enterprise Security an eight out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
Last updated: Jul 9, 2025
Flag as inappropriateSecurity delivery manager at a tech vendor with 1,001-5,000 employees
Drastically reduces SOC overhead
Pros and Cons
- "The tool drastically reduces SOC overhead. Its integration with our tool suite is great and helps us correlate events. The solution is also a lot faster than our standalone instances."
- "The solution is expensive."
What is our primary use case?
We use the solution in our SOC to support SOAR. We use its alerting capabilities and integrate them with our SOAR platform. Additionally, we tie it in with cyber threat intelligence, cyber threat hunting, and adversary emulation tools to identify gaps in our environment and alert us to notable events.
What is most valuable?
The tool drastically reduces SOC overhead. Its integration with our tool suite is great and helps us correlate events. The solution is also a lot faster than our standalone instances.
Splunk Enterprise Security helps address our customers' missions. We want to ensure that our environment is secure and safe and detects anomalies and threat actors as soon as possible.
The solution helps my organization's ability to ingest and normalize data. It has also improved resilience.
What needs improvement?
Enterprise Security is expensive.
For how long have I used the solution?
I have been working with the product for three years.
What do I think about the stability of the solution?
Splunk Enterprise Security is very stable.
What do I think about the scalability of the solution?
The tool is very scalable. We can deploy agents seamlessly and get reports.
How are customer service and support?
We have had good success with customer support. We haven't had any issues contacting them and getting problems resolved.
How was the initial setup?
Splunk Enterprise Security's deployment is hit or miss. Recently, we got UBA. We were able to spin up an environment easily with Terraform. However, the recent upgrade caused many hiccups and slowdowns. We are working with support to resolve them. Some legacy code is choking the system and slowing us.
Which other solutions did I evaluate?
We do market evaluation and continuous research every year to check for alternatives to our security tools.
What other advice do I have?
It seems like the tool is improving. It incorporates AI into the platform to streamline event identification processes.
Splunk Enterprise Security does a good job. However, we need many analysts to correlate searches and populate data models, and some overheads are needed in any SOC environment.
We have a lot of data to process from different sources. However, we have only limited data analysts. It takes time to find malicious threats or what we seek.
No specific metrics are tracked, but we report this to our leadership weekly, focusing on continuous improvement. Regarding reducing the mean time to resolve, especially with our SOAR integration, we can swiftly address major issues by leveraging alerts to initiate tickets. This allows us to notify the teams and address issues immediately.
I rate the overall product a ten out of ten. I don't think there is another alternative with similar capabilities.
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
Head of Cybersecurity at a computer software company with 51-200 employees
A market leader with good standard features and helps speed up security investigations
Pros and Cons
- "The solution is the market leader."
- "The integration could be a bit better. They charge for certain integrations."
What is our primary use case?
We mainly use the solution as a reseller. We give our users the latest version of the product.
What is most valuable?
The solution is the market leader.
Our customers are always looking to partner with market leaders as you can't go wrong with them.
Customers can monitor cloud environments.
The threat detection capabilities are quite fast and efficient based on my customer's feedback.
We've used the MITRE ATT&CK feature and it's good. It's pretty standard and comparable to IBM. Most products offer this as well.
It's good for analyzing malicious activities. It's good as an overall platform. It's good at detecting threats. It's a basic feature that is quite effective.
Splunk can help to reduce alert volume if you configure it properly.
They are a market leader in a lot of areas in terms of features and functions.
It helped us speed up security investigations. I'm not sure of the exact percentage it helped us speed up by, however.
It has a lot of basic and standard features.
It is a full-fledged solution that provides everything a company needs.
What needs improvement?
When it comes to malicious activities, however, it's rather overpriced. There are cheaper ways to detect.
There are quite a lot of security platforms on the market that do the same thing in a similar way at a cheaper rate.
The pricing could be a lot lower. I'm from Asia, and they need to provide Asian pricing. They should price better for the region they are in. Once companies see the price, it puts them off.
The integration could be a bit better. They charge for certain integrations.
For how long have I used the solution?
I've used the solution for about a year or more.
What do I think about the stability of the solution?
It is a stable product.
What do I think about the scalability of the solution?
The solution is used across multiple departments, not locations. That said, it would support multiple locations.
We've had no issues with scalability. We usually have a solution that lasts three to five years and have had no issues scaling in that time.
How are customer service and support?
I do not directly deal with technical support.
Which solution did I use previously and why did I switch?
We previously used many solutions, such as IBM. The implementation times are about the same. There are some ways that IBM is faster and other ways Splunk is faster. However, Splunk offers a more modern look.
How was the initial setup?
The initial setup is very easy. It's quite straightforward. The process is similar to IBM. The deployment takes less than one day. It is done by a different team. I don't handle the initial implementation process.
The maintenance needed is very minimal. We have at least ten people that can handle deployment and maintenance.
What's my experience with pricing, setup cost, and licensing?
The solution is quite expensive compared to the competition. It's considered a premiere security option.
Which other solutions did I evaluate?
We also looked at Dynatrace before choosing Splunk.
What other advice do I have?
I'm a registered partner of Splunk.
We are using the latest version of the solution.
We haven't used the threat intelligence management feature. We usually use another product.
The mission control feature hasn't been used. I'm not familiar with it.
For those looking for a cheaper product, I'd suggest, if they had a limited budget, to go cheaper. Likely a cheaper option that can do the same work as Splunk. At the end of the day, whether you choose a Toyota or a Rolls Royce, you get from A to B the same. The price is the differentiation.
I'd rate the solution eight out of ten. It's a good product overall.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer.
Buyer's Guide
Download our free Splunk Enterprise Security Report and get advice and tips from experienced pros
sharing their opinions.
Updated: March 2026
Product Categories
Security Information and Event Management (SIEM) Log Management IT Operations AnalyticsPopular Comparisons
CrowdStrike Falcon
Microsoft Sentinel
IBM Security QRadar
Splunk AppDynamics
Elastic Security
Grafana Loki
Elastic Observability
Palantir Foundry
Security Onion
Graylog Enterprise
Buyer's Guide
Download our free Splunk Enterprise Security Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- Which would you recommend to your boss, IBM QRadar or Splunk?
- What are some of the best features and use-cases of Splunk?
- What SOC product do you recommend?
- Splunk as an Enterprise Class monitoring solution -- thoughts?
- What is the biggest difference between Dynatrace and Splunk?
- IBM QRadar is rated above competitors (McAfee, Splunk, LogRhythm) in Gartner's 2020 Magic Quandrant. Agree/Disagree?
- What are the advantages of ELK over Splunk?
- How does Splunk compare with Azure Monitor?
- New risk scoring framework in the Splunk App for Enterprise Security -- thoughts?
- Splunk vs. Elastic Stack


















