No more typing reviews! Try our Samantha, our new voice AI agent.
Kenny Corbett - PeerSpot reviewer
Associate Director of IT at Rigel Pharmaceuticals Inc
Real User
Jul 25, 2023
Provides risk scores and end-to-end visibility
Pros and Cons
  • "It provides a risk score for each object, device, or user. We can then take action if they are at a higher risk."
  • "The pricing can be better."

What is our primary use case?

Splunk Enterprise Security provides more visibility into endpoints in our environment.

How has it helped my organization?

We only monitor AWS, but we also have SaaS services that are in our own clouds. So far, it is easy to monitor our cloud environment with this solution. As long as we ingest our data correctly and tune it, it will read it. It is very easy to use.

It provides end-to-end visibility into our cloud-native environment. This is critical for us because we are always one step away from a security incident, which could impact the company and cost a lot of money. That is our main point of focus.

What is most valuable?

It provides a risk score for each object, device, or user. We can then take action if they are at a higher risk.

What needs improvement?

The pricing can be better.

Buyer's Guide
Splunk Enterprise Security
July 2026
Learn what your peers think about Splunk Enterprise Security. Get advice and tips from experienced pros sharing their opinions. Updated: July 2026.
909,647 professionals have used our research since 2012.

For how long have I used the solution?

We have been evaluating Splunk Enterprise Security for the last eight months.

What do I think about the stability of the solution?

I cannot say anything about stability, but I am assuming it would be the same as Splunk. It is an app. It is going to work.

How are customer service and support?

The technical support is above average, but they do not go into the details, so we have a contract with a third party to help us.

There might be more Splunk support tiers, but we are working with SP6. They will get their hands directly onto our Splunk environment, whereas Splunk support does not do that. Maybe there is a different tier that does that, but we do not have that. It is more of an email dialogue. They are not going to VPN into our environment. SP6 is more hands-on. I would rate SP6 a nine out of ten.

Which solution did I use previously and why did I switch?

We did not use a similar solution. We have Carbon Black for endpoints, but this is going to be a lot bigger than that.

How was the initial setup?

We are still evaluating it. We have not deployed it yet, but I was involved with the deployment of Splunk. 

It was very easy to set it up for evaluation. It is just an installer file. It is an add-on app for Splunk, and if you know how to install Splunk and add-ons, it is easy.

What's my experience with pricing, setup cost, and licensing?

I am fine with the licensing, but in terms of the cost, it is expensive for the data that we have. We have an open discussion with our account rep about this.

Which other solutions did I evaluate?

We are not evaluating any solutions because we already have Splunk, and we do not want to leave Splunk. I like it, so it is just a matter of making the commitment.

What other advice do I have?

The value that I get from attending Splunk Conferences is going to sessions and learning about what other people are doing and use cases that I have not really thought of. Also, I am able to talk directly to people about questions I have regarding our Splunk instances, and I can get some answers right away. It is very good to know what people are doing because sometimes we do something one way, but we do not know if we are doing it the right way. Here, we can get validation, or realize that we are doing it wrong and make the necessary changes. That is very valuable.

I would rate Splunk Enterprise Security a ten out of ten. Most customers at the conference have already implemented it, except for our company. It is a critical foundation app that allows you to explore other apps that Splunk is grading, and it works.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Regional Channel Manager at i2sBusiness Solutions
Reseller
Top 5
Jul 10, 2023
Drastically reduces time spent by analysts on false positives, and AI-based detection identifies real-time anomalies
Pros and Cons
  • "The dashboard and reporting are very good... It provides very good visibility in a hybrid cloud environment, and you can build custom utilization APIs using Splunk."
  • "While there aren't any major areas where the solution has to be improved, there are certain integrations that are still not available. I would specifically like to see legacy applications integrated."

What is our primary use case?

The use cases are mainly around monitoring for our clients' security operation centers and correlation of events and analytics for incidents that have been identified.

How has it helped my organization?

It has really improved things for our clients by reducing false positives. Most of the time, analysts end up wasting their time with false incidents, and that has been drastically reduced by Splunk.

It also definitely helps speed up your security investigations.

What is most valuable?

The dashboard and reporting are very good. Our clients monitor multiple cloud environments and Splunk helps because, in general, monitoring multiple cloud environments is definitely difficult and very complex. It provides very good visibility in a hybrid cloud environment, and you can build custom utilization APIs using Splunk.

The solution is also very good in its threat-hunting capabilities and anomaly detection. It uses an AI-based detection system to identify real-time anomalies and provides complete visibility into the network.

And you can feed multiple threat sources into Splunk and the Threat Intelligence Management feature gives you information about current or potential attacks. It provides complete security support in the threat intelligence space. It helps your administrator to correlate indicators of compromise from threat intelligence databases and feeds.

Also, the Splunk Mission Control feature, which is mainly for Splunk Enterprise Security cloud users, provides a unified and simplified security operations experience for SOC analysts.

We also use the solution's Threat Topology and MITRE ATT&CK framework feature. That's something you need for cyber breaches to contain a threat. This feature comes into play when you need to mitigate an incident in your environment.

What needs improvement?

While there aren't any major areas where the solution has to be improved, there are certain integrations that are still not available. I would specifically like to see legacy applications integrated. Splunk has integrations with AWS, Azure, and other cloud providers, but when it comes to legacy applications, it is difficult to do a Splunk integration.

For how long have I used the solution?

We have been working with Splunk Enterprise Security for one and a half years.

What do I think about the stability of the solution?

It's a very stable solution. 

What do I think about the scalability of the solution?

It is very highly scalable.

How are customer service and support?

The technical support is very good.

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

I used IBM Security QRadar. The main reason for switching is that Splunk has the scalability to handle bigger enterprise logs. Log management is the biggest issue in any SIEM. Splunk is able to rapidly grow its capacity.

How was the initial setup?

Our clients' implementations are mostly on-prem and in the cloud.

What's my experience with pricing, setup cost, and licensing?

Splunk is definitely not a cheap solution. It is an expensive product.

If a customer is evaluating SIEM solutions and is considering cheaper products, it depends on the customer's budget and use cases. For a large, enterprise customer with critical infrastructure that needs to be monitored 24/7, obviously, the cheaper solutions may not have the capacity to handle the huge volume of data. Splunk has the SIEM and the scalability as well as visibility features. When you want to monitor your applications and how they are performing, that is where Splunk is very strong.

What other advice do I have?

In terms of maintenance of Splunk, you need to have an IT administrator monitoring it at all times.

When it comes to a large, enterprise customer's critical infrastructure, Splunk is one of the best solutions to use in a security operations center. It has multiple advantages, such as the dashboard that provides complete visibility, and a threat detection system with very advanced features. It is very valuable for any company that wants a good protection system.

You should definitely consider Splunk as one of your options for your SOC.

Disclosure: My company has a business relationship with this vendor other than being a customer. Reseller
PeerSpot user
Buyer's Guide
Splunk Enterprise Security
July 2026
Learn what your peers think about Splunk Enterprise Security. Get advice and tips from experienced pros sharing their opinions. Updated: July 2026.
909,647 professionals have used our research since 2012.
reviewer2088153 - PeerSpot reviewer
Security Compliance Program Manager at a educational organization with 5,001-10,000 employees
Real User
Feb 14, 2023
Incorporates a lot of elements that help to reduce security risks but the architecture isn't well-defined
Pros and Cons
  • "Splunk incorporates a lot of elements that help to reduce security risks. For it to reach certain compliance, we need to have some security insight. Splunk is a very good SIEM, it’s a top solution, but the best feature is its cost of visibility. We have all the most important features to detect vulnerabilities or risks."
  • "I have concerns about the architecture as well since I can see it is not very well defined."

What is our primary use case?

Splunk helps us to be proactive and it integrates with many devices. It offers visibility from many different levels, areas, zones, and devices rather than from a single system. We can use this intelligence to create correlations, system solutions, etc. Splunk reduces the risk factors and helps us in many ways beyond just collecting logs. Though Splunk is costly, it has many features like threat intelligence which is very useful. It helps us be proactive about reducing risks.

What is most valuable?

Splunk incorporates a lot of elements that help to reduce security risks. For it to reach certain compliance, we need to have some security insight. Splunk is a very good SIEM, it’s a top solution, but the best feature is its cost of visibility. We have all the most important features to detect vulnerabilities or risks.

What needs improvement?

Customers cannot manage or maintain the servers on the cloud since they are all deployed. Since there are platforms, they can become a little bit hectic. One of my other observations is that the applications that are available on the store are not updated as much as those available on on-prem.

Moreover, I have had issues with the Splunk store. I believe that the developers in the Splunk store are external and I can see that the level of maturity of these developers ranges between low and medium. I have never seen the maturity go up higher. The applications are not maintained regularly and it can cause issues in the visibility dashboard. I would suggest to Splunk's tech team to keep the store private, so that Splunk creates its own applications without the interference of external developers.

I have concerns about the architecture as well since I can see it is not very well defined. However, this is not the case with on-prem. We were able to manage and do whatever we wanted on the server level without opening a case or anything else. Moreover, the applications are updated every six months.

What do I think about the stability of the solution?

Splunk is a stable solution.

What do I think about the scalability of the solution?

Splunk is a scalable solution. I am also impressed with the integrity of the solution. It is very good at collecting logs.

How are customer service and support?

To resolve issues in the Splunk platform, you need to wait in a queue and then open a ticket with the support team. I find it a bit time-consuming since it takes time to call tech support and get what you need.

Which solution did I use previously and why did I switch?

I have used Wazuh. From my point of view, Wazuh is a simple and basic SIEM solution compared to Splunk in terms of features. I don’t see Wazuh as a competitor to Splunk. Wazuh relies greatly on human tactics. It is best suited for cloud environments and maybe smaller ones. I have issues with Wazuh’s stability as well because I have found scenarios where it was working for one instance and not for another. These issues might be because it is open-source.

Wazuh is not actively working on their platform. I opine that they need to integrate many components and have many aspects automated so that the solution does not depend on its users. I have found issues with the language of Wazuh as well. It requires a lot of resources and time to learn the language. These issues make me think that Splunk is better than Wazuh.

How was the initial setup?

The initial setup process for Splunk was simple. The language used in Splunk is very easy to pick up and you can rely on any person using it to be able to learn it quickly. The language and picking up logs are easier with Splunk.

What about the implementation team?

I implemented Splunk through a POC.

What's my experience with pricing, setup cost, and licensing?

Splunk is costly but it’s worth it due to the high-end features.

Which other solutions did I evaluate?

I have worked with Wazuh and ManageEngine Endpoint Central.

What other advice do I have?

I would rate Splunk Cloud a 6.5 out of 10, but plugged on time, I would give it 8.8 out of 10. The maintenance of Splunk is a bit difficult due to the time-consuming tech support.

I would recommend Splunk. I cannot compare Splunk with any other SIEM solution because I have worked with many different solutions and logarithms, like the ManageEngine Endpoint Central, and Wazuh. I have used Splunk for two years and I can see Splunk as really the best SIEM solution that can be used for work. I totally recommend it even though I gave some negative feedback, it's because I am coming from a product perspective. We have to also take into consideration the security perspective. I am not talking about only visibility in which they should take a lot of care, but the way the solution is handling and even manipulating the data. This is the most valuable thing.

Which deployment model are you using for this solution?

Private Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Raymond De Rooij - PeerSpot reviewer
Product Owner at ABN AMRO Bank N.V.
Real User
Top 5
Mar 6, 2022
Poor performance and the display options are limited, but it can parse a variety of log files
Pros and Cons
  • "Splunk works based on parsing log files."
  • "I find the graphical options really limited and you don't have enough control over how to display the data that you want to see."
  • "Overall, I don't think that this is a very good product and I don't recommend it."

What is our primary use case?

We use Splunk to monitor our private cloud, data center, and other applications.

How has it helped my organization?

I don't like Splunk very much and find that it does not have many useful features.

What is most valuable?

Splunk works based on parsing log files.

What needs improvement?

I don't like the pipeline-organized programming interface.

I find the graphical options really limited and you don't have enough control over how to display the data that you want to see.

I find that the performance really varies. Sometimes, the platform doesn't respond in time. It takes a really long time to produce any results. For example, if you want to display a graph and put information out, it can become unresponsive. Perhaps you have a website and you want to show the data, there's a template for that, or it has a configuration to display your graphics, and sometimes it just doesn't show any data. This is because the system is unresponsive. There may be too much data that it has to look through. Sometimes, it responds with the fact that there is too much data to parse, and then it just doesn't give you anything. The basic problem is that every time you do a refresh, it tries to redo all of the queries for the full dataset.

Fixing Splunk would require a redesign. The basic way the present the graphs is pipeline-based parsing of log files, and it's more of a problem than it is helpful. Sometimes, you have to perform a lot of tricks to get the data in a format that you can parse.

You cannot really use global variables and you can't easily define a constant to use later. These things make it not as easy to use.

For how long have I used the solution?

I have been using Splunk for approximately one year.

What do I think about the stability of the solution?

I use Splunk at least a couple of times a week.

What do I think about the scalability of the solution?

I'm not sure about scalability but to my thinking, it's not very scalable. I know that it's probably expensive because it relies a lot on importing log files from all of the systems. One of the issues with respect to scalability is that there's never enough storage. Also, the more storage you have, the more systems you need to manage all the log files.

Splunk is open for all of the users in the company. We might have 1,000 IT personnel that could access it, although I'm not sure how many people actually use it. I estimate that there are perhaps 200 active users.

How are customer service and support?

I have not been in contact with technical support from Splunk.

Which solution did I use previously and why did I switch?

In this company, we did not previously use a different monitoring solution.

How was the initial setup?

I was not involved in the initial setup.

We have a DevOps team that is implementing Splunk and they are responsible for it. For example, they take care of the licensing of the product.

What about the implementation team?

We have a team at the company that completed the setup and deployment.

Which other solutions did I evaluate?

The other product that I've seen is Elastic, and I think that it would be a better choice than Splunk. This is something that I'm basing on performance, as well as the other features.

What other advice do I have?

My understanding is that as a company, we are migrating to Azure. When this happens, Splunk will be decommissioned.

Overall, I don't think that this is a very good product and I don't recommend it.

I would rate this solution a five out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Information Technology Specialist at a healthcare company with 10,001+ employees
Real User
Jan 13, 2022
Provides information about what's going on in a simplified way
Pros and Cons
  • "From my experience, the visual aid that it provides is most valuable. There are charts and other means to provide information."
  • "Splunk simplifies the information, and it gives you charts and different means of seeing that information, making it easily understandable for people."
  • "Its user interface for everything other than the charts can be improved. Some parts of it can be simplified a bit, such as when importing documents that have the network traffic. When you're going through the information about the network traffic, you have to have the expertise, but even if a program is supposed to be for IT support, it is good to make it user-friendly because it gets easier to train people. When something goes wrong, the more difficult a program is in terms of UI, the harder it is to fix the issue."
  • "Its user interface for everything other than the charts can be improved."

What is our primary use case?

I went to a cybersecurity boot camp through Penn University, and we went over this topic for a decent amount of time. It was more of a testing environment where they gave us different file formats that we had to go through. We would upload those files to Splunk, and it would give us good examples of what it would look like under different circumstances, such as when an organization is getting hacked, when there is a DDOS attack, and so on.

How has it helped my organization?

It is a good way of seeing the network traffic as a whole. With network traffic, there are a lot of things going on, especially in a big organization. It organizes the information and makes it more usable for average people. If you use Wireshark, you'll get a ton of information, and it is super easy to get lost in it. Even if you put Wireshark on for about 30 minutes, you can very easily get lost. Splunk simplifies the information, and it gives you charts and different means of seeing that information, making it easily understandable for people.

What is most valuable?

From my experience, the visual aid that it provides is most valuable. There are charts and other means to provide information.

What needs improvement?

Its user interface for everything other than the charts can be improved. Some parts of it can be simplified a bit, such as when importing documents that have the network traffic. When you're going through the information about the network traffic, you have to have the expertise, but even if a program is supposed to be for IT support, it is good to make it user-friendly because it gets easier to train people. When something goes wrong, the more difficult a program is in terms of UI, the harder it is to fix the issue.

For how long have I used the solution?

I've been using this solution for a little while. 

What do I think about the stability of the solution?

In terms of stability, I really liked it. I didn't see any issues as far as stability was concerned. Whenever I needed it, it was there. It was available, and it worked. It was pretty good.

What do I think about the scalability of the solution?

Its scalability seems pretty good. If you are working with a lot of information, it would be usable.

Its users would depend on the organization. Mostly network engineers, network analysts, and SOC analysts would be dealing with this. 

How are customer service and support?

There were instructors who knew how to fix a lot of the issues. If there was an overarching issue, they would deal with it.

Which solution did I use previously and why did I switch?

At the boot camp, we also used Kibana, which looked a little bit more friendly, but when we got into the details, I liked Splunk a little bit more. It was more intuitive, and it did a little bit more on its own rather than Kibana. With Kibana, it felt like I had to hold its hand all the way through the whole process. There were 20 people, and I know a number of people were leaning towards Kibana. It just came down to personal preference.

How was the initial setup?

We saw some of the basics for deploying it within an environment, but it was very minimal. 

It isn't complex, but there is a little bit of a learning curve. Once you get the hang of it, it is very easy to get in and do things, but there is definitely a learning curve. I am not speaking just for myself; other 20 or more students that were in that class at the time also had a difficult time getting the hang of it, but once you get the hang of it, it is smooth sailing. You can fly through the program. Making it a little bit more simplified would help.

What's my experience with pricing, setup cost, and licensing?

I remember Splunk being relatively affordable. Kibana was more reasonable, but you get more with Splunk. If I was suggesting something, I would probably suggest Splunk because it is better to pay a little bit more and get a lot more.

What other advice do I have?

I would advise making sure that your staff is very aware of how the program works. After one or two classes, I got the hang of it, and it felt like I knew everything that was there to know about it, but when we went into the next class, I realized that there is a lot more. So, if you are going to use the program, I would advise making sure that everyone is trained and everyone really understands it. You should take your time to go into the nitty-gritty. You can very easily think that you know everything, but when you make mistakes in Splunk, at least from my experience, it can get messy quickly. So, you want to make sure that everyone has a very good understanding of what they're doing so that you can keep everything organized and accurate.

I would rate it an eight out of 10. When we're getting into the nuts and bolts and looking at the data, it is an eight, but when we are just navigating through the website, it is a seven. Only its UI needs improvement. It isn't bad, but there is room for improvement. They should make it a little bit more user-friendly.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Bushra Alhetelah - PeerSpot reviewer
SOC Engineer at Cyberani Solutions
Real User
Top 20
Jul 10, 2025
Advanced correlation capabilities enable the identification of user activity patterns effectively
Pros and Cons
  • "The ease of use and building queries, specifically SQL queries, is notably beneficial as it is easy to build, and the data model itself is very simple."

    What is our primary use case?

    When configuring our use cases and describing the overall purpose of Splunk Enterprise Security, I would focus on the main use cases that I encountered with this tool.

    What is most valuable?

    The ease of use and building queries, specifically SQL queries, is notably beneficial as it is easy to build, and the data model itself is very simple. The advanced correlation capabilities are very useful for identifying patterns or malicious activity of users.

    For how long have I used the solution?

    I have worked with Splunk Enterprise Security for two years.

    How are customer service and support?

    I have contacted the Splunk Enterprise Security support team once, but mainly the other team responsible for onboarding contacted them.

    How would you rate customer service and support?

    What other advice do I have?

    I am preparing my master's degree and conducting this review for completing it at KFUPM University, King Fahd University of Petroleum and Minerals, located in Saudi Arabia, to prepare for my defense. I have experience with blue team tools, specifically Splunk Enterprise Security and some other solutions.

    The company name is Cyberani Solutions, and my email is first name dot last name at cyberanisolutions.com. PeerSpot will create an account and email the login credentials, and my feedback will be published and possibly shared with third parties if I choose to not remain anonymous.

    I would rate Splunk Enterprise Security an eight.

    Disclosure: My company has a business relationship with this vendor other than being a customer. partner
    PeerSpot user
    Alparslan Özdemir - PeerSpot reviewer
    Cyber Security Engineer at a tech vendor with 51-200 employees
    Real User
    Top 10
    Jul 9, 2025
    Deployment and search capabilities boost practical use and efficiency
    Pros and Cons
    • "Its search is very flexible, allowing you to search anything by typing a sentence."
    • "Splunk Enterprise Security is a wonderful solution, however, the background configuration process could be better as the administration process is very complicated."

    What is our primary use case?

    I'm a technical support engineer for Cortex XDR at the moment and in my company, we are selling the Cortex XDR solution to other companies. 

    I also have experience with Splunk Enterprise Security and CrowdStrike too; we are using those products in my company. For Splunk Enterprise Security, I am using the Enterprise Security module and base Splunk for developing rules.

    What is most valuable?

    The deployment server is very good and is one of the best features of Splunk Enterprise Security for me; you can use that deployment server even for distributing any agents, upgrading automatically, and universal forwarders. Its search is very flexible, allowing you to search anything by typing a sentence.

    What needs improvement?

    Splunk Enterprise Security is a wonderful solution, however, the background configuration process could be better as the administration process is very complicated. As an analyst rather than a Splunk engineer, some background configurations might be easier.

    For how long have I used the solution?

    I'm working with Splunk Enterprise Security for six months, however, I have been using Splunk for one year.

    What do I think about the stability of the solution?

    Splunk Enterprise Security is a very stable product; I have never been in trouble with any stability problems if you set it up correctly.

    How are customer service and support?

    I would give support a seven out of ten as Splunk Enterprise Security's advanced support is very skillful, however, to reach that advanced support, first they send you some beginner-level support that mostly does not solve problems for me. That said, when they escalate it, it completely finds a solution.

    How would you rate customer service and support?

    Which solution did I use previously and why did I switch?

    Before Splunk Enterprise Security, I didn't use any other solution.

    How was the initial setup?

    I did not set up the Splunk Enterprise Security; my admin colleagues from another department set it up for me.

    I'm just using and revising the rules. I'm a Cortex admin, so I'm involved in the process for Cortex, not for Splunk Enterprise Security.

    My company is a partner with Splunk Enterprise Security. As an engineer and layer two security analyst, I'm solving problems with Splunk Enterprise Security, editing rules on customers, reviewing alerts, and developing rules.

    What's my experience with pricing, setup cost, and licensing?

    I'm not aware of the price of the tool. My company and other departments arange the licensing. 

    What other advice do I have?

    On Splunk Enterprise Security, we imported from the content library, specifically from the content management page that contains many rules; we are importing rules from there, enabling rules, and editing them. I'm not a deep down administrator of Splunk Enterprise Security, so I'm not arranging the data models. I'm mostly editing the rules.

    On a scale of one to ten, I rate Splunk Enterprise Security an eight out of ten.

    Which deployment model are you using for this solution?

    On-premises
    Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
    PeerSpot user
    Spelunking Consultant at BlueVoyant
    Real User
    May 21, 2024
    Provides a centralized place to consolidate everything and start investigations
    Pros and Cons
    • "The solution's most valuable feature is its data modeling."
    • "It would be good if the solution had some kind of copilot to automate or help write correlation searches."

    What is our primary use case?

    My customers subscribe to many different tools, like CrowdStrike. They ingest all that into Splunk and use it as an aggregator to launch their investigations into any threats detected.

    How has it helped my organization?

    The solution has improved our organization by providing a centralized place to start investigations. It allows us to consolidate everything into one place that kicks everything off so we can map it back to at least that Splunk instance.

    What is most valuable?

    The solution's most valuable feature is its data modeling. Splunk has data from so many different vendors. Moving all that or normalizing that to the data models allows us to look at one place holistically across all the different inputs.

    What needs improvement?

    The one problem Splunk has is writing correlation searches. My analysts are intimidated to write queries to create correlation searches. It would be good if the solution had some kind of copilot to automate or help write correlation searches. Splunk Enterprise Security should include more automation, AI, and machine learning capabilities.

    For how long have I used the solution?

    I have been using Splunk Enterprise Security for three to four months.

    What do I think about the stability of the solution?

    We haven’t faced any issues with the solution’s stability.

    What do I think about the scalability of the solution?

    We haven’t faced any scalability issues with Splunk Enterprise Security.

    What other advice do I have?

    The end-to-end visibility the tool provides is not that big of a deal. They have so many tools that can do that kind of part. Splunk doesn't have to be the one place for total visibility, but at least for visibility when it consolidates on threats.

    Splunk has helped improve our organization's ability to ingest and normalize data. The tool pretty much consumes everything that we have. Everything from dozens of different vendor products gets ingested into Splunk. Splunk Enterprise Security is just that one central place where everything goes.

    Splunk Enterprise Security has helped speed up our security investigations. Something that requires someone to work on it at the beginning of the day would not take more than 15 minutes with Splunk Enterprise Security.

    Overall, I rate the solution an eight out of ten.

    Which deployment model are you using for this solution?

    On-premises
    Disclosure: My company does not have a business relationship with this vendor other than being a customer.
    PeerSpot user
    reviewer2398776 - PeerSpot reviewer
    Principle Architect at a computer software company with 51-200 employees
    Real User
    May 9, 2024
    Provides insights to customers about what their users are doing and alerts them to anomalies
    Pros and Cons
    • "The metrics and trends that Splunk Enterprise Security generates using all the data points we send allow customers to understand better what their users are doing."
    • "Splunk Enterprise Security should provide a better and richer integration."

    What is our primary use case?

    We will have clients that generate events through our platform and wish to export those events as data points to Splunk.

    How has it helped my organization?

    The solution improves our customers' integrations. They really want insights into what their users are doing. They want to be alerted to anomalies, general pain points, or popular areas in the integration to understand what's working and what's not.

    What is most valuable?

    The metrics and trends that Splunk Enterprise Security generates using all the data points we send allow customers to understand better what their users are doing.

    What needs improvement?

    Splunk Enterprise Security should provide a better and richer integration. It has a regimented integration, where we had to build a Python library. It was a very tough way to integrate officially and get into the marketplace. We'd like to see more options so that we can better send data over to the Splunk platform.

    The requirements of building the integration had to be a very specific and certain way to get onto your marketplace. Once it's there, it's fine, but it took a little effort to get it exactly that way. That's not as maintainable as we like, so we'd rather that be a more robust integration.

    For how long have I used the solution?

    We've had an integration available for the better part of three or four years.

    What do I think about the stability of the solution?

    The solution provides good stability.

    What do I think about the scalability of the solution?

    We haven’t seen any issues with the solution’s scalability.

    How are customer service and support?

    We mostly interacted with the marketplace community. Although our support experience was not great, the issue was straightforward.

    What was our ROI?

    Our customers have seen a return on investment with the solution. We have seen customer satisfaction as it was a highly sought-after integration, and they're happy now that it exists.

    What other advice do I have?

    The end-to-end visibility that the solution provides into our environment is incredibly important to our organization. We like to see it as the total answer. Any data point can be picked up, and you can really build anything you need from the integration. It's incredibly valuable with the data that it's generating. What the tool provides once integrated is highly valuable and sufficient for us.

    Finding any security event across multi-cloud, on-premises, or hybrid environments with Splunk Enterprise Security has been incredibly easy. Using the rest of the Splunk platform, you can trigger whatever you need off the data coming in through the integration.

    The solution has helped improve our organization's ability to ingest and normalize data. It also generates more customer activities so that there's a stickier relationship.

    The Splunk integration triggers the necessary events so that downstream alerting isn't necessary.

    Splunk Enterprise Security has helped speed up our security investigations. It's a great direct integration so that our customers can react quickly when necessary.

    In principle, the solution has helped reduce our mean time to resolve, but not necessarily data points that we see as the integrator.

    Overall, I rate the solution an eight out of ten.

    Disclosure: My company has a business relationship with this vendor other than being a customer. Integrator
    PeerSpot user
    reviewer2238963 - PeerSpot reviewer
    Splunk Developer at a tech vendor with 11-50 employees
    Real User
    Jul 26, 2023
    Helps us with both auditing and as well as regular monitoring
    Pros and Cons
    • "It definitely does help with both auditing and as well as regular monitoring. SOC does more monitoring, but ES also gives you other features that are auditing-related. The dashboards are also beneficial."
    • "Sometimes the communication with support happens with multiple staff. They should reduce the time to resolution."

    What is our primary use case?

    Our primary use case is for security but we also use it as a soft tool. It gives us an advantage over traditional SOC or security tools. We get to use the existing data in Splunk to make use of the security. 

    How has it helped my organization?

    It definitely does help with both auditing and as well as regular monitoring. SOC does more monitoring, but ES also gives you other features that are auditing-related. The dashboards are also beneficial. 

    Our auditing team gets benefits from Splunk, not just ES but also from general Splunk Enterprise. It's cross-functional. 

    Enterprise Security has helped us reduce our mean time to resolution by 50%. Without it, there are many manual steps. You have to go to different products to see specific things. With Splunk, you have the benefit of seeing them together in one place.

    What is most valuable?

    The notable events and the incident review features are the most valuable. It gives you an overall idea of what's going on in terms of security in the environment. 

    I also like the automation. We write custom scripts and automate certain tasks. That's also interesting. This feature saves us time.

    Splunk is capable of doing a lot in real-time with data coming in that is a terabyte in size, you can still do searches in real-time. We have correlation searches that do similar functions.

    It has a lot of the features we're looking for. 

    For how long have I used the solution?

    I have been using Splunk Enterprise Security for a year and a half.

    What do I think about the stability of the solution?

    It's quite stable. It's a mature product. 

    What do I think about the scalability of the solution?

    We can make it as scalable as we want. We can scale it horizontally as much as we want on our cluster.

    How are customer service and support?

    We get support when we need it. I would rate support an eight or nine out of ten. There's always learning and improvement to do. Sometimes the communication with support happens with multiple staff. They should reduce the time to resolution.

    How would you rate customer service and support?

    Positive

    What other advice do I have?

    I would rate Enterprise Security a nine out of ten. Not a ten because everything has room for improvement. 

    The biggest value of the Splunk conference is meeting people.

    Which deployment model are you using for this solution?

    On-premises
    Disclosure: My company has a business relationship with this vendor other than being a customer.
    PeerSpot user
    Buyer's Guide
    Download our free Splunk Enterprise Security Report and get advice and tips from experienced pros sharing their opinions.
    Updated: July 2026
    Buyer's Guide
    Download our free Splunk Enterprise Security Report and get advice and tips from experienced pros sharing their opinions.