No more typing reviews! Try our Samantha, our new voice AI agent.
Executive Director
Real User
Top 20
Sep 16, 2026
Teaching students real-time cyber defense has become effective but alerts and adoption need work
Pros and Cons
  • "Splunk Enterprise Security has positively impacted my organization by giving students who had no knowledge of the tool cues on how to use it and pushing them deeper into topics like cybersecurity, monitoring, and troubleshooting in terms of log monitoring."
  • "Splunk Enterprise Security Essentials has not contributed to a reduction in analyst burnout or fatigue."

What is our primary use case?

I have been using Splunk Enterprise Security for about seven years.

My main use case for Splunk Enterprise Security is building dashboards, monitoring our data centers that we have built, using containerization to build dashboards, looking for anomalies, and testing for cybersecurity issues in real time.

A specific example of how I have used Splunk Enterprise Security is during a recent exercise for the students where they simulate a DDoS attack in AWS, observe what they are seeing, check the problem in the logs, and then troubleshoot and fix the problem from there. I use Splunk mostly for teaching, but of course, to monitor our data center environments as well.

I do this to teach young people Splunk, and our students have grasped the concept very well, going from not knowing what Splunk was to building high-quality dashboards that I referred to earlier.

What is most valuable?

The best features Splunk Enterprise Security offers include ease of use, which is one definite benefit, and the AI agent that you have recently released, which is very helpful in terms of being proactive and finding problems before they happen in your network as opposed to after.

Regarding ease of use, I chose Splunk Enterprise Security because it is adaptable to young students and stands out compared to other monitoring tools. Regarding the AI agent, I have let it loose in our environment to look for VLANs, private subnets, and DDoS attacks.

Students build AWS and container environments, then send their application data into Splunk Enterprise Security, create dashboards, monitor infrastructure health, identify unusual behavior, and troubleshoot performance or security issues. The important part is that they are learning how cloud, networks, containers, data centers, and observability work together in a production-style environment. For AARI, Splunk Enterprise Security turns raw telemetry into something students can understand and act on, helping me train operators who can recognize a problem, investigate it, and explain what needs to happen next. My next step is extending that same model into physical inference and robotics using telemetry from power, cooling, environmental centers, and edge devices. Splunk Enterprise Security becomes the common operating view across the entire system.

Splunk Enterprise Security has positively impacted my organization by giving students who had no knowledge of the tool cues on how to use it and pushing them deeper into topics like cybersecurity, monitoring, and troubleshooting in terms of log monitoring.

I have seen a huge increase in their confidence and skills. As I mentioned prior to us teaching them, they had no idea what Splunk Enterprise Security was, and now they are building dashboards and extending the project into other areas like robotics, which has been very inspiring to watch.

What needs improvement?

I need to partner with teaching more students what Splunk Enterprise Security is and the other products so they can be aware of it early on in life as opposed to later.

For how long have I used the solution?

I have been using Splunk Enterprise Security for about seven years.

Buyer's Guide
Splunk Enterprise Security
September 2026
Learn what your peers think about Splunk Enterprise Security. Get advice and tips from experienced pros sharing their opinions. Updated: September 2026.
915,325 professionals have used our research since 2012.

What do I think about the stability of the solution?

Splunk Enterprise Security is stable.

What do I think about the scalability of the solution?

Splunk Enterprise Security's scalability is good.

How are customer service and support?

I have not had to use customer support for Splunk Enterprise Security.

Which solution did I use previously and why did I switch?

I did not previously use a different solution.

What was our ROI?

I have seen a return on investment, and it has more than doubled my return.

What's my experience with pricing, setup cost, and licensing?

My experience with pricing, setup cost, and licensing was quite minimal since it was through the nonprofit organization.

Which other solutions did I evaluate?

I did not evaluate other options before choosing Splunk Enterprise Security.

What other advice do I have?

I rate Splunk Enterprise Security a seven on a scale of one to ten.

I rate it a seven because it is tight, it is reliable, it will keep you gainfully employed, and nothing is perfect.

I think the governance of Splunk Enterprise Security is very needed, especially for data wrangling, as any AI project needs proper data in terms of platform and security, reliability, and more.

Its AI capabilities are quite accurate in terms of output reliability.

Splunk Enterprise Security is deployed in my organization in a hybrid cloud environment.

I use Azure and AWS as part of my hybrid deployment.

I did not purchase Splunk Enterprise Security through the AWS Marketplace.

Splunk Enterprise Security has helped improve my organization's business resilience, and I feel that it is a canary in the coal mine and a harbinger of things to come if you actually know what you are looking for in the logs.

Splunk Enterprise Security has not helped reduce my team's average mean time to resolve (MTTR) metric.

I have not upgraded to Splunk Enterprise Security 8.0.

Splunk Enterprise Security's Risk-Based Alerting (RBA) has made me more hyper-vigilant in terms of alert volume and analyst productivity.

Splunk Enterprise Security has helped me detect threats faster, very much so.

Splunk Enterprise Security Essentials has not contributed to a reduction in analyst burnout or fatigue.

The integration of threat intelligence directly into the TDIR workflow has improved my ability to preemptively block threats, making me realize that being proactive is my best offense and defense.

My advice for those looking into using Splunk Enterprise Security is to test it first, get your hands dirty, understand what it is, and then think about implementing it system-wide. I would rate Splunk Enterprise Security a seven overall.

Which deployment model are you using for this solution?

hybrid cloud environment

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Last updated: Sep 16, 2026
Flag as inappropriate
PeerSpot user
Solomon Henry - PeerSpot reviewer
Cybersecurity Consultant (Enterprise Projects & Detection Engineering) at Lighthouse Technology
Real User
Top 5Leaderboard
Jun 19, 2026
Centralized monitoring has transformed detection workflows and now improves proactive defense
Pros and Cons
  • "Splunk Enterprise Security Essentials has contributed to a reduction in analyst burnout or fatigue, improved the daily work experience and retention in my security team, and using structured workflow management, it improves my operational coordination, accountability, and the visibility into the remediation process across multiple security initiatives."
  • "Splunk Enterprise Security can improve in the UI UX interfaces, but for the rest, I am very comfortable with the reporting, dashboard, alerting, search, and reporting features."

What is our primary use case?

I have worked extensively with Splunk Enterprise Security for centralized log ingestion, security monitoring, and detection engineering. My objective is to improve enterprise visibility, reduce alert fatigue, and operationalize attack detection that is capable of identifying authentication abuse with lateral movement, PowerShell misuse, and privilege misuse in Linux environments and suspicious network activity.

My recent project focused heavily on enterprise security engineering and detection engineering, IAM Governance Analysis, which is identity and access management, cloud security operation, and resilience validation. This platform aligns directly with the areas I am actively expanding deeper into. At the end of all my logs and documentation, I link them to MetaTask, ISO 27001, and SOC 2. I have a couple of frameworks I use to analyze all of these topologies.

I was able to reduce unmanaged firewall exposure from over five thousand rows to eight hundred and fifty significantly. This was one of my enterprise projects I did on Zero Trust Security, all documented on my LinkedIn portfolio.

What is most valuable?

I appreciate the reporting features of Splunk Enterprise Security, where it enables me to document each of my telemetry. If I have an alert for a brute force attack, I can document a report on those logs and send it via email or any platform I want to share it on. I appreciate the reporting process and the alert features. Recently, I worked on onboarding Windows event logs and was able to correlate these logs with six months of telemetry, Linux authentication logs, firewall telemetry, and DNS activities into Splunk Enterprise Security. I developed correlation searches and behavioral detection that I used to align to MITRE attack techniques, including good fall detection, privilege collection monitoring, suspicious authentication analysis, and DNS abnormality detection. I also created detection to reduce false positives and improve operational reliability while integrating a reasonable workflow using Python automation for faster incident tracking. I was able to create those logs, and everything was displayed on my dashboard. The improvements reduced false positive investigation workloads significantly, improving security operation center visibility across my enterprise environment, and reducing the mean time to detect to ten minutes in a simulated enterprise environment scenario. Those are the results I have had so far in my enterprise environment.

I have solved issues during one of my enterprise security tasks where I identified excessive firewall rules, which are documented on my LinkedIn portfolio, and an unmanaged access pathway that created unnecessary attack surface exposure across my environment. The challenge was to identify still rules to validate legitimate traffic requirements and reduce unnecessary exposure without disrupting my operational workflow.

Splunk Enterprise Security has helped me detect threats faster. It has helped me reduce my team's average mean time to resolve metric. I estimate it has improved detection speed by eighty-five percent because ninety percent of my projects are essentially on Splunk, making it one hundred percent effective for my team. Splunk Enterprise Security Essentials has contributed to a reduction in analyst burnout or fatigue.

It has improved the daily work experience and retention in my security team. Using structured workflow management, it improves my operational coordination, accountability, and the visibility into the remediation process across multiple security initiatives. It has improved my ability to preemptively block threats in vulnerability management workflow and governance activities, including documenting investigations and findings, and how I assign remediation ownership. It has increased my risk ownership, improved tracking escalation status, and monitoring completion timelines.

It has changed my approach to proactive defense across both consulting and enterprise operational projects, affecting how I track remediation activities and investigation workflows, which are important for maintaining operational visibility and accountability. It has improved my operational understanding of TCP and IP behavior, attack traffic reconstruction, segmentation validation, and network-based detection engineering across the enterprise environments I have worked with. It has improved productivity in how I perform packet-level analysis using Wireshark and PXS telemetry to inspect XMB traffic, RDP sessions, DNS activities, authentication flows, and simulated lateral movement patterns.

What needs improvement?

Splunk Enterprise Security can improve in the UI UX interfaces, but for the rest, I am very comfortable with the reporting, dashboard, alerting, search, and reporting features. From the rating perspective, it could be enhanced.

For how long have I used the solution?

I have used Splunk Enterprise Security for two years.

What do I think about the stability of the solution?

Splunk Enterprise Security is stable; I have not troubleshot anything since it has worked for me. When I perform actions such as brute forcing my machine, it logs correctly, and queries I run return logs as fast as one minute ago.

What do I think about the scalability of the solution?

I believe Splunk Enterprise Security has all the features any organization could need. If the engineer knows what they are doing, it can adapt to scale, generating and importing logs without issues for different sizes of enterprises.

How are customer service and support?

I have not communicated with the technical support of Splunk Enterprise Security.

Which solution did I use previously and why did I switch?

I tried Google Sentinel before choosing Splunk Enterprise Security, but it did not suit my needs, so I had to try something else. When I got to Splunk Enterprise Security, I found it satisfactory enough not to switch to another option.

How was the initial setup?

I participated in the initial setup of Splunk Enterprise Security.

I had to go to the website first, create an account with my email, and then download either the enterprise version or Splunk Forwarder. In my Active Directory, I have my forwarder installed, and on my server machine, I have the enterprise installed. With one account, I was able to configure my port number and destination port, hosting it on localhost. I connected other components to the service with the appropriate configurations.

From a technical perspective, the initial setup was not difficult for me to navigate through.

What about the implementation team?

For a non-technical person, it may be challenging, but for a technical person, it is straightforward. The process is effective.

What was our ROI?

For return on investment, I think a large corporation would not have an issue with that. For small-scale enterprises, they may need to review those areas more, particularly related to user rates.

Which other solutions did I evaluate?

I used to analyze and log manually as a SOC analyst would before using Splunk Enterprise Security.

What other advice do I have?

Splunk Enterprise Security represents a fair price for what it can accomplish. I would rate this product a ten out of ten.

Which deployment model are you using for this solution?

On-premises

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Other
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Last updated: Jun 19, 2026
Flag as inappropriate
PeerSpot user
Buyer's Guide
Splunk Enterprise Security
September 2026
Learn what your peers think about Splunk Enterprise Security. Get advice and tips from experienced pros sharing their opinions. Updated: September 2026.
915,325 professionals have used our research since 2012.
Tejas Shah - PeerSpot reviewer
Splunk Certified Architect at Data Elicit Solutions Pvt. Ltd.
Real User
Top 5
Feb 25, 2026
Data insights have improved security operations and now streamline threat detection and response
Pros and Cons
  • "Summing up everything from a SIEM and security point of view, I think Splunk is by far the best product that I have been using since my work experience."
  • "One improvement I want to foresee is that the AI or agent needs to be fed with accurate data, not false data, so that whenever it performs automation on your behalf, it doesn't misconfigure anything."

What is our primary use case?

When we talk about Splunk Enterprise, I have seen clients using it for their data analysis, collecting the logs and preparing meaningful insights out of it, like having dashboards created from the data that they ingest into Splunk. Apart from that, there is a SaaS platform that Splunk provides which is called the Splunk Cloud platform; it provides similar functionality, but the end-to-end config management is handled by Splunk directly. You just have access to the Splunk search head where you log in and can search the data you ingest into Splunk Cloud. Regarding Splunk Enterprise Security, I have seen customers using it for security use cases and to ensure that the environment or organization is not impacted by any SOC threats; basically, they use it for detection and mitigation both.

Customizing and developing new detections in Splunk Enterprise Security are quite simple since I have got experience with it for more than four years. I am quite familiar with it and enjoy working through that as well.

I do use disparate security solutions that integrate or import data into Splunk Enterprise Security.

The security operations are supported on a very great scale because let's say we have written n number of detections; we also need to ensure that we don't get alerted or notified on false positives. There is a dashboard in Splunk Enterprise Security that displays all the detections identified as a potential risk or alert to the environment. From there, you can triage the work to investigate deeper into it, and from the dashboard, you can drive it towards closure, with different drill-down options to investigate how a particular event was identified as a risk event and whether it was a false positive. If it wasn't a false positive, you can dive deeper into it using different response actions as well; all these customizations can be done and they support any third-party response actions that you want to apply to the Splunk Enterprise Security detection you have.

What is most valuable?

What I like about Splunk Enterprise Security is the way it is able to correlate or ingest any kind of data from any product or source, alert and adapt the whole data as it is, and then provide it in a single visualization format. It handles and provides you options for customizations and different options for alerting as well. Summing up everything from a SIEM and security point of view, I think Splunk is by far the best product that I have been using since my work experience.

Splunk Enterprise Security has indeed helped improve the organization's business resilience. I don't have specific numbers for sharing purposes, but on a quarterly basis, I have seen Splunk helping the resilience and assisting the business greatly in terms of avoiding SOC threats.

What needs improvement?

You need to adapt to new changes constantly and be sure of new learnings in Splunk Enterprise Security; that is the only challenge I would say. However, I don't see it as a problem because if resources are available for you to understand new changes and how detections are managed or how to incorporate advanced threat intelligence frameworks, there is no huge challenge in integrating it with Splunk Enterprise Security. You need to know what things you want to click on the UI; if you are aware of that, there is no challenge. It is just constant learning that you have to give yourself to learn and grow for your own better self.

One improvement I want to foresee is that the AI or agent needs to be fed with accurate data, not false data, so that whenever it performs automation on your behalf, it doesn't misconfigure anything. Trust in the product relies on the AI being reliable and trustworthy, ensuring 100% accuracy and avoiding false positives.

I would say Splunk's ability to predict, identify, and solve problems in real time is near accurate; I cannot confirm that it is 100% since none of the systems are. It definitely alerts you on what particular time you need to be notified. However, to achieve near 100% accuracy, how you handle the searches running in your environment and stagger them is important to avoid overwhelming server resources. Splunk provides features to adjust time zones and write custom schedules; there is no challenge with that. However, there will always be delays, so it is about how you ingest the data; if the source is behind the Splunk server's timezone, that could impact results.

For how long have I used the solution?

I have been working with Splunk for almost six years now.

What do I think about the stability of the solution?

So far, we have not faced any downtime or performance issues with Splunk; there can be outages, but we are automatically notified when they occur, and the team works on resolution. Since we are using Splunk Cloud, we receive notifications directly from them.

What do I think about the scalability of the solution?

I would say Splunk is quite scalable, and we are definitely making the most out of it. Our company was involved in delivering sessions at splunk.conf last year, showcasing how we utilize Splunk and the solutions provided, indicating that we are scaling quite effectively.

How are customer service and support?

I would rate the Splunk support team an eight or nine out of ten; this rating is based on my experience of being part of the partner team that delivered Splunk support. The support depends on the partner, and I appreciate having a dedicated account manager for our customer account, ensuring effective handling of operations and issues. No one can have 100% knowledge, and while there might be delays in response, the support team effectively isolates problems and finds solutions, adhering to an escalation policy that keeps customers updated and satisfied.

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

Since I have worked more with Splunk, I am somewhat biased but I would say understanding and writing queries to analyze your ingested data is simpler in Splunk and in other products such as Sumo Logic as well. However, no product can match the level of customization and visualization that Splunk can build; you can create reports, dashboards, and present these in a business fashion, which is unmatched.

How was the initial setup?

Deploying Splunk is a piece of cake for me; since I have got so much experience, deploying any kind of environment is not a challenge. I am still in the evolving phase as I started my professional journey with Splunk in 2019. I have made numerous deployments for different testing purposes, replicating customer challenges in our test environment to address their issues directly.

What was our ROI?

That is a bit subjective, I would say because in the Indian market, people often look for alternative solutions to avoid spending more. However, I have seen great satisfaction levels among companies that have utilized Splunk, including the one I am working for now, which has been renewing Splunk licenses over the past decade. If Splunk were not that great, people would not keep renewing it over the years; there is an option for good return on investment, but eventually, people try to find alternatives to save on expenses for R&D or other purposes.

What's my experience with pricing, setup cost, and licensing?

I am not very much aware of the licensing since we are service providers for Splunk or Cribl or DataDog, but I do know Splunk provides licensing in two different ways: SVC-based licensing and ingest-based licensing. The old model charged based on the volume of data ingested on a daily basis, while the current SVC-based model charges based on the compute utilized for searching that data, regardless of volume.

Which other solutions did I evaluate?

All over the globe, it is the AI and agent era, and Splunk is also a part of it having introduced Splunk AI as part of its cloud platform features, eventually to be released in on-prem solutions as well.

What other advice do I have?

I usually do not manage or investigate the alerts that have been triggered; I work on building and managing the use cases, optimizing them. The analyst team works on the incidents but from what I have heard, before I joined the current organization there were a lot of changes required to be made internally in the product itself and the way we were writing optimizations. But afterwards, we defined a clean process and the mean time to closure or mean time to resolve had reduced drastically by almost 60 to 70% compared to what it was previously.

It is not that we are limited to risk-based alerting in Splunk Enterprise Security; we are using threat intelligence and we have recently configured SOAR as I just mentioned. Additionally, we are using UBA for user behavioral analytics.

We have definitely seen benefits from the threat detection and threat intelligence capabilities in Splunk; we apply risk scores and threat scores to our detections and to the attributes we want to identify or flag as potentially high-risk or high-threat objects. This helps us prioritize the tasks we want to start our daily task with; it definitely helps with understanding the priority tasks to be worked upon. We also make sure to update our threat feeds regularly since we need to stay on top of all the threat findings globally, ensuring we identify all malicious IP addresses or any file hashes that have been tracked as a threat and are publicly available.

I would advise organizations considering Splunk to stick to the fundamentals; as long as you understand how Splunk operates and the functions of its different components, you won't face challenges in troubleshooting or understanding errors. I would rate this review a ten out of ten overall.

Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor. The reviewer's company has a business relationship with this vendor other than being a customer: MSP
Last updated: Feb 25, 2026
Flag as inappropriate
PeerSpot user
Senior Vice President Cyber Security at Mindsprint
Real User
Top 5
Jun 16, 2026
Risk-based monitoring has improved threat detection speed and supports custom SOC use cases
Pros and Cons
  • "Regarding the impact on threat detection capabilities, it provides a faster mean time to detect."
  • "We have seen that the pricing has gone higher and the support quality has not kept up or was not as good as it was earlier."

What is our primary use case?

Splunk Enterprise Security is used for our SOC, the Security Operations Center, which provides 24/7 monitoring. I am using disparate security solutions to integrate or import data into Splunk Enterprise Security. We use Splunk Enterprise Security to ingest the logs and do the monitoring.

As for alerting, especially risk-based alerting, it works well. It supports the use cases that we are looking for. Splunk Enterprise Security supports my SOC in terms of developing any new use cases. If we have any custom integration requirements or any custom use cases, we can easily develop that in Splunk Enterprise Security, and that's how we are able to leverage Splunk Enterprise Security for any custom use cases.

What is most valuable?

The biggest advantage for me in Splunk Enterprise Security is all the ready-made integrations and the connectors that are available. Integration is the strongest part; the connectors and the built-in connectors are the strongest part which allow the integration.

My impression of processes such as customization, developing, testing, deploying, and refining detections is that it works as designed for all the detections and all the new capabilities that we can leverage. It works very well.

Integration supports my security operations. When it comes to remediation, we are not using it for remediation with Splunk Enterprise Security; Splunk Enterprise Security is purely for detection. Remediation has to be done by the respective teams using their own tool sets.

Regarding the impact on threat detection capabilities, it provides a faster mean time to detect. The team is able to respond faster because we are using Splunk Enterprise Security and we are able to ingest all the logs from various sources. Any threats which are emerging across the world and across different types of log sources, our team is able to detect them faster. Overall dwell time of an attacker or any kind of attacks that we see, we are able to respond much faster because we are able to detect it in the first place much faster.

What needs improvement?

There is something in Splunk Enterprise Security which is not perfect. What we are seeing is more not on the technology side, but on the pricing and support point of view once Cisco has taken over. We have seen that the pricing has gone higher and the support quality has not kept up or was not as good as it was earlier. These are the two things we see as areas for improvement.

Regarding the issue with support, it takes longer for support to come back to us and then it goes through multiple layers of escalation before we get to the right person.

I would like to see some additional features, more on the AI detection and automatic detection using AI capability. Although Splunk Enterprise Security has some amount of AI capability, what we would like to see is more on the detection side, how AI can help and how Splunk Enterprise Security can introduce those features as part of the built-in platform itself.

For how long have I used the solution?

I started working with Splunk Enterprise Security about six or seven years ago.

What do I think about the stability of the solution?

Splunk Enterprise Security is very reliable and stable. Reliability is also very good.

What do I think about the scalability of the solution?

Regarding scalability for Splunk Enterprise Security, scalability is very good. We have scaled it about four times over the past six years in terms of the log size. Scalability is very good.

How are customer service and support?

As for the issue with support, it takes longer for support to come back to us and then it goes through multiple layers of escalation before we get to the right person.

What other advice do I have?

Splunk Enterprise Security is a worth buying product if you are able to leverage all the features and the capabilities or if the team is strong to leverage all of them.

The percentage of savings depends on what we are comparing. It is straightforward; if the team is experienced with Splunk Enterprise Security, it is quite straightforward and quite fast.

Regarding business resilience, Splunk Enterprise Security does improve business resilience because I am able to protect my assets and hence improve the resilience. I am able to solve problems in real time, to predict, and to identify threats. It helps my detection to be faster, which is about 40 percent faster. The overall review rating for this product is 8 out of 10.

Which deployment model are you using for this solution?

On-premises

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Other
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Last updated: Jun 16, 2026
Flag as inappropriate
PeerSpot user
Yevheniy Moyko - PeerSpot reviewer
Cyber Security Engineer at Underdefense
Real User
Top 5
Apr 14, 2026
Risk-based alerts have transformed our incident response and reporting to executives
Pros and Cons
  • "Overall, Splunk Enterprise Security has reduced our MTTR by approximately 30%."
  • "Beyond support, the pricing tier of Splunk Enterprise Security could be better, as it is an expensive solution; however, the cost reflects the value delivered."

What is our primary use case?

Splunk Enterprise Security serves as our security tool, specifically functioning as a SIEM product.

What is most valuable?

Splunk Enterprise Security's best features include scalability, reliability, and extensive integrations.

The RBA in Splunk Enterprise Security helps us considerably because there are rules that we cannot turn off, but they are spammy rules that we can whitelist. We group them as intermediate findings, making this risk score useful. It saves us time because instead of working on 1,000 alerts per day, we focus on two or three alerts and simply review their impact on our organization.

With Splunk Enterprise Security and our SOC team, we have developed custom rules that adjust the risk scores based on our observations, not merely Splunk's recommendations. It helps considerably because it groups the alerts, gives us information about related alerts, and provides excellent features such as drill-down searches and dashboards, which save our time and decrease mean time to respond and mean time to detect.

Overall, Splunk Enterprise Security has reduced our MTTR by approximately 30%. That reduction applies to both response and detection.

Our dashboards and visualizations in Splunk Enterprise Security communicate our security posture to executives effectively, as they are more interested in numbers and money saved rather than technical details. The visualizations allow us to present why they spend money on this solution, and we can create engaging visual stories for them based on the dashboards.

What needs improvement?

The area for improvement with Splunk Enterprise Security is support.

The knowledge base could also be improved.

Beyond support, the pricing tier of Splunk Enterprise Security could be better, as it is an expensive solution; however, the cost reflects the value delivered.

For how long have I used the solution?

I have been using Splunk Enterprise Security for more than eight years.

What do I think about the stability of the solution?

For stability, I give it a ten.

What do I think about the scalability of the solution?

In terms of scalability, I also rate it a ten.

How are customer service and support?

On a scale from 1 to 10, I rate support for Splunk Enterprise Security at a six.

How was the initial setup?

My experience deploying Splunk Enterprise Security is straightforward; I am a certified Splunk architect, which is the highest certification. Based on the documentation, it is easy for non-distributed deployments, but it can be challenging for others with larger infrastructures.

In terms of deployment time for Splunk Enterprise Security, it takes approximately 15 minutes.

What about the implementation team?

For my clients, there are over 200 people using Splunk Enterprise Security.

In my company, we have approximately 30 specialists.

Regarding Splunk Enterprise Security deployment, we utilize both on-premises and cloud setups.

What was our ROI?

The return on investment we see from Splunk Enterprise Security is not straightforward, as it depends on the company; some may not have alerts or impacts, while others, when detecting critical alerts or threats, may realize it has saved them a million dollars. Overall, I estimate the ROI to be approximately 20% to 30%.

Which other solutions did I evaluate?

When comparing Splunk Enterprise Security with other security solutions, I find it to be the best as it consolidates everything in one place. They have updated it with endpoint security and admission control capabilities, allowing you to see every comment and action during an incident, which I have not seen in other solutions such as Elastic, Sumo Logic, or LogRhythm.

What other advice do I have?

Since we do not work with UEBA in Splunk Enterprise Security, I cannot comment on any improvements in threat hunting and investigations. I have seen demos of it, and while it is a remarkable solution, I cannot personally answer that question. I provide this review with an overall rating of 10.

Which deployment model are you using for this solution?

Hybrid Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Disclosure: My company has a business relationship with this vendor other than being a customer. MSP
Last updated: Apr 14, 2026
Flag as inappropriate
PeerSpot user
reviewer2899053 - PeerSpot reviewer
SOC lead at a healthcare company with 10,001+ employees
Real User
Top 20
Sep 16, 2026
Risk-based alerts have sharpened analyst focus and save significant investigation time
Pros and Cons
  • "The best features Splunk Enterprise Security offers include the ease at which changes can be made as an engineer or as a lead to deploy rules, and the whole process is faster, it is easier, and it just gets done a lot quicker, generating a lot less frustration."
  • "Splunk Enterprise Security does throw some false positives. It, as anything, needs some tuning."

What is our primary use case?

My main use case for Splunk Enterprise Security is risk-based alerts. I have a lot of scenarios, custom scenarios that add risk to a user. When it hits a certain unacceptable limit, we trigger the alert. There are many of these specific risk-based alerts.

What is most valuable?

The best features Splunk Enterprise Security offers include the ease at which changes can be made as an engineer or as a lead to deploy rules. That has been streamlined in the latest versions, and it is incredibly helpful.

The way it has improved is time. I am not spending as much time doing these things as I used to. The whole process is faster, it is easier, and it just gets done a lot quicker, generating a lot less frustration.

The best thing that Splunk Enterprise Security brings in is the risk-based alerting. The other system we use is Microsoft, which does not do risk-based alerting at all in any way. This is the main value that Splunk Enterprise Security is bringing.

We have definitely seen an increase in the amount of alerts that actually need attention. We have seen a decrease in things that could be a thing, but it really does not look like it. Instead of investigating those things now, we are assigning risk and moving on. It has really been the time-saver and the focus on what is probably more important.

What needs improvement?

The one area that I would say at one point did need help and attention would have been Mission Control. However, that seems to have been really worked on, and it appears to be stabilizing out now.

For how long have I used the solution?

I have been using Splunk Enterprise Security for about three years.

What do I think about the stability of the solution?

In our environment, Splunk Enterprise Security is stable.

What do I think about the scalability of the solution?

We have thrown quite a bit more at Splunk. We are bringing in new tools every year to help us with the gaps we have, visual knowledge gaps, and just log gaps. All of those new tools are generating logs. While we are not maybe adding a ton of workstation logs every year because we are not increasing staff by a ton, we are throwing a lot more logs at Splunk, and it seems to be handling it just fine.

How are customer service and support?

We have never called Splunk, but we have put in tickets with Splunk. Generally, the support folks are receptive. Once in a great while, somebody is not, but they are the exception, not the rule.

Which solution did I use previously and why did I switch?

We use Splunk on-premises and we are moving to Splunk Cloud. It is kind of the same solution.

What was our ROI?

The metric that I would say we are really looking at is time saved. That is a lot. Time saved on getting things isolated, getting things remediated, and just in general, any task that needs to be done with Splunk has been faster due to upgrades from Splunk. It is very nice.

What's my experience with pricing, setup cost, and licensing?

Our sales reps were very interested in continuing with us, so they were very motivated to get us some discounts. That ultimately was one of the deciding factors, not the only one, but one of them in making sure that we stayed with Splunk. Setup cost has not been something anyone except the CISO is really aware of yet. The licensing cost seems to be a good price for what we are getting.

Which other solutions did I evaluate?

CrowdStrike was one of them, and Sentinel was one of them.

What other advice do I have?

We are about to move to the Premier Cloud edition of Splunk Enterprise Security. I do not know what new features are going to be available there.

Regarding Splunk Enterprise Security's AI capabilities, we have not really used any of the AI functions in Splunk Enterprise Security at all. My experience with them is incredibly limited, pretty much to the level of only testing. In general, I think it has good output and good understanding of the questions. Sometimes it goes a bit off the rails, but in general, the AI will understand the question, properly research the answer, provide a good answer, and even provide recommendations. Overall, it seems to be a very good product.

We are currently on-premises. Within the next two to three months, we are moving to cloud. That has not been determined, but more than likely, it will be Azure.

Splunk does have an incredible ability to react. Alerts are thrown almost in real-time. Currently, we are not using any agents, but even so, these alerts are put in front of analysts who are sitting there waiting for alerts. Our time to start work on these things is very small, even without the AI agents. With the agents, it is going to be even faster to respond. We will probably get a lot of these false positives worked out. That is currently one of the things I should have mentioned earlier. Splunk Enterprise Security does throw some false positives. It, as anything, needs some tuning. But it is pretty accurate. An agent would be very helpful in filtering out false positives.

The MITRE material is incredibly helpful for audits, but in general, our analysts are not really using that piece of Splunk Enterprise Security very much at all. I do a bit more, but I would say it is underutilized. However, it is nice that it is there.

This has been very helpful. It has also been a pain once in a while when intelligence feeds put something silly in there, and we end up blocking Google or something. That is generally a one-off occasion. The majority of the time, it is very helpful. We see domains blocked that we did not even know were bad. We had no reason to even investigate this domain, and Splunk Enterprise Security has already stopped any connection. It is very helpful.

We do not currently have SOAR, UEBA, and Splunk Enterprise Security all in the same interface. Currently, they are different interfaces. We do not even have UEBA. Unfortunately, we have not made the move to the cloud yet, so I cannot really give you a good answer.

We have not cut any employees because we do not have employees to manage alerts. We have employees for coverage. This, despite the advantages, and even when we bring in the automatic AI agents, we will not be losing any employees, as again, they are there for coverage.

I would rate this review a 9.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Last updated: Sep 16, 2026
Flag as inappropriate
PeerSpot user
Manish Arora - PeerSpot reviewer
Senior Client Partner at KyndleIT Consulting
Real User
Top 5
May 26, 2026
Security operations have unified threat detection and response across diverse data sources
Pros and Cons
  • "Splunk collects much more data as compared to traditional SNMP related tools, and log traces will eventually provide you much better and true information on which you can take actionable actions on top of it."
  • "Cost is something which is a major factor."

What is our primary use case?

The clients who are using Splunk Enterprise Security are primarily using it for security as a SIEM solution, or they are also using Splunk Observability.

Generally, when you have the complete set of solutions such as EDR or DLP and then on top of it, if you have a solution such as SIEM, which is collecting logs and everything and then correlating that particular data, it takes somewhere around five to ten minutes to identify and start working on that particular issue.

What is most valuable?

The biggest advantage, if I talk about for observability, is ease of use. The customers use OTEL collectors, and since this is an open OTEL collector, it is not bound to Splunk itself. That is something which is good.

Customization requires good effort, but it is doable. We being into professional services, we do this particular part. Splunk Enterprise Security provides flexibility to write those rules and regular expressions and other tools, wherein you can filter the traffic based on different kinds of policies.

It definitely helps because when you use different sets of solutions which work on SNMP, they will only poll that data and then they will collect and provide you some information on top of it. Splunk collects much more data as compared to traditional SNMP related tools. Log traces will eventually provide you much better and true information on which you can take actionable actions on top of it. With respect to unified security operations, it helps to consolidate both SIEM and SOAR so that you can quickly detect, investigate and neutralize cyber threats. They can integrate with third-party SOAR solution as well as they have internal capabilities for SOAR.

What needs improvement?

Cost is one major factor. The reason is because they primarily work on the ingestion of data, wherein it becomes a choice for large customers who have deep pockets to spend money on Splunk Enterprise Security. If the customer does not have that much budget, then obviously they will not go for Splunk Enterprise Security. They will go for a similar set of solution such as Elastic in that case. Cost is something which is a major factor.

In integrations, a good amount of integrations are already available, but integration with newer AI components or tools and upcoming tools such as Claude or ChatGPT will obviously take some more time to evolve perfectly so that these tools become more easy to use and align to an organization's environment.

For how long have I used the solution?

I have been using the solution for somewhere around four years.

What do I think about the stability of the solution?

Splunk Enterprise Security is a stable product.

What do I think about the scalability of the solution?

Splunk Enterprise Security is scalable. You can horizontally expand it with forwarders and universal forwarders. It's scalable.

Which solution did I use previously and why did I switch?

We have been in business for the last eight years. Before partnership with Splunk, we have been working with Broadcom. Now we are also working with Elastic.

How was the initial setup?

The initial setup is straightforward and not that complex. Initially, you will struggle, but once you are done with one or two installations, then it is pretty straightforward.

What about the implementation team?

I am an implementation partner and not a direct customer of Splunk. I do implementation work.

What was our ROI?

With respect to Splunk Enterprise Security ROI, it is a costly solution. It is not something which can be adopted by every organization. Splunk Enterprise Security needs to come up with something different. When we speak to Splunk representatives, they boast about being a costly solution, but that does not make any sense because if you are not able to fit yourself with the customer and Datadog or Elastic is competing with you, then that is one part which they need to address. Rather than positioning themselves as a costly solution, they should work on something which can actually fit the customers as well as provide implementation partners like us with opportunities to work on certain projects. With respect to ROI, it takes a good amount of time because by the time you get the product installed in your environment, you start using it and you realize how much data needs to be ingested and then you fine-tune them. I think it takes a good amount of time because by that time, Splunk will take a good amount of licensing cost from the customer.

Which other solutions did I evaluate?

We are using other security tools. We are using API security, Symantec products for different customers, or CrowdStrike EDR. We generally ingest logs from all these different solutions, logs, metrics and traces from these solutions into Splunk Enterprise Security.

We are also using Elastic. The main part is for smaller customers or a limited set of customers, Elastic provides the community version. You can go and install the community version and seventy to eighty percent of the features are available, and the customer can start using it. They don't intend to use Splunk Enterprise Security in that case because that's free, and only a nominal services fee will be charged from these kinds of customers. Elastic also has the observability as well as the ELK stack, Kibana, dashboards and other tools. That part does not make too much of a difference. The major difference between both of the products is obviously pricing.

What other advice do I have?

Splunk Enterprise Security is the most significant challenge. I rate this product at nine out of ten.

Disclosure: My company has a business relationship with this vendor other than being a customer. Integrator
Last updated: May 26, 2026
Flag as inappropriate
PeerSpot user
PraveenSande - PeerSpot reviewer
Senior Splunk Engineer (L3) at Wipro Limited
Real User
Top 10
Mar 16, 2026
Risk-based monitoring has improved incident prioritization and simplifies cross-team collaboration
Pros and Cons
  • "Splunk ITSI (IT Service Intelligence) has very good capability of storing, analyzing, and searching compared to other tools."
  • "Splunk ITSI (IT Service Intelligence) correlation what we are trying to do has missed a few features from the earlier versions."

What is our primary use case?

At the moment, we are using Splunk ITSI (IT Service Intelligence) with Splunk Enterprise Security suite solution to create the use cases. We have criteria to create use cases in such a way that as soon as we receive a request from a customer or internally, we need to see based on the MITRE ATT&CK frameworks and techniques and tactics. Based on that, we are going to create use cases in Enterprise Security. We will consider a few things, such as what the severity is and what it is based on the group, whether it is end-user support or application support. Based on that, we will create the urgency and all.

What is most valuable?

The favorite features of Splunk ITSI (IT Service Intelligence) include the ability to define the risk score and understand how much priority we can assign. We can also define priority as critical, low, medium, or high. We can also give some filtering options during the execution time, such as filters, throttling, and mapping the fields by grouping the name and grouping the fields. Additionally, we have the feasibility to give a direct ticket to ServiceNow integration. It will create a ticket and assign it to somebody who is responsible to work on it. We are having some very good things with this solution.

What needs improvement?

Splunk ITSI (IT Service Intelligence) correlation what we are trying to do has missed a few features from the earlier versions. We previously had a chance to give complete descriptions of a particular thing and whether it is mandatory or not. However, in the new version, we are seeing something like a risk score that needs to be defined for any use case we are creating. I think that is not mandatory, but also in some areas we cannot define the risk score. At those times, in those cases, we are keeping the risk score as nominal, like one to ten. Because of that mandatory field, we are giving some wrong information to the end list.

For how long have I used the solution?

I am using it in my career for six years.

What do I think about the stability of the solution?

I have never seen instability, lagging, crashing, or downtime throughout my experience with Splunk ITSI (IT Service Intelligence). We work on all production servers and production environment. We have scheduled operations, maintenance operations, and maintenance windows. During that time only, we will see if they are trying to do any activity or if they want to perform any shutdown. They plan accordingly and guide us before they are planning for it.

What do I think about the scalability of the solution?

Splunk ITSI (IT Service Intelligence) has a good feature for scalability. We can scale it very quickly, and it is very helpful for an organization to scale up. It is having that feature and it is a very good feature.

How are customer service and support?

I contacted technical support for Splunk ITSI (IT Service Intelligence). I have worked on both areas, on-premises and the cloud environment. For on-premises, based on the priority of the case, they address the issue. For the cloud environment, they will prioritize the case and give quick service.

How would you rate customer service and support?

Positive

How was the initial setup?

During the initial setup a few days and a few months when I first started using Splunk ITSI (IT Service Intelligence), it was overall understandable. If somebody does not know about it, they can learn it very quickly and they can adapt to the technology.

What about the implementation team?

For deployment of Splunk ITSI (IT Service Intelligence), we require two to three people based on the environment and the size of the environment. It is preferred to have two persons.

What was our ROI?

From a pricing point of view, Splunk ITSI (IT Service Intelligence) is a bit high. I was seeing one of my customers, an old customer, who are moving from Splunk ITSI (IT Service Intelligence) to other tools. The tool is Cortex XDR SIM. It is all because of the pricing. Other than the big organizations, if somebody in a small company or small to medium company wants to use Splunk ITSI (IT Service Intelligence) facilities, they are very much afraid of it because of the pricing. Also, the people who are already using Splunk ITSI (IT Service Intelligence) as a solution are checking for alternatives. For example, one of the other clients moved to another SIEM solution because of the pricing itself. It is comparatively more, and they need to think about this pricing.

Which other solutions did I evaluate?

I have familiarity with QRadar and SIM Nitro as alternatives to Splunk ITSI (IT Service Intelligence). I can compare QRadar with Splunk ITSI (IT Service Intelligence). My opinion is that Splunk ITSI (IT Service Intelligence) is the better one. Comparatively, I have used three SIEM tools, but Splunk has more visibility. As a Splunk engineer, we have the feasibility to integrate a lot of logs from different log sources and we can parse them. We can create custom rules. All of this provides very good visibility on Splunk ITSI (IT Service Intelligence). Log availability is also a very good thing. Splunk ITSI (IT Service Intelligence) has very good capability of storing, analyzing, and searching compared to other tools. We can create knowledge objects, such as dashboards, which is very much useful to review what we have in the system and also we can present it to somebody who is not much aware of the system. In QRadar, we do not have much scope to work on. In Splunk ITSI (IT Service Intelligence), we have a lot of things during the integration time. We have a lot of scope and also parsing, and also then utilizing the logs by creating use cases and alerts, reports, and dashboards.

What other advice do I have?

My overall experience is eight years, and relevant to this field is six years. Whenever any new add-ons and integrations we are doing, we actually need to upgrade ourselves. We recently had an upgrade of utilizing Python scripting for scripting. For on-premises Splunk ITSI (IT Service Intelligence), I would give six out of ten. For the cloud solution, I would give nine out of ten. For the overall score for the support of Splunk ITSI (IT Service Intelligence), I will give seven out of ten. I am a customer of Splunk ITSI (IT Service Intelligence). I am continuing to learn on Splunk things based on different platforms, Linux, Windows, and also on cloud. So far it has been so good. It is a good journey and I am feeling positive about it. Splunk ITSI (IT Service Intelligence) is very understandable. Everybody says Splunk is a complex environment, but it is not much complex. We can adapt and we can quickly learn if anybody is starting a new journey on Splunk ITSI (IT Service Intelligence). I have thoughts on legal statements and the process of creating an account. My overall review rating for Splunk ITSI (IT Service Intelligence) is nine out of ten.

Which deployment model are you using for this solution?

On-premises

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Other
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Last updated: Mar 16, 2026
Flag as inappropriate
PeerSpot user
Vikas_Tiwari - PeerSpot reviewer
Citius Tech at a outsourcing company with 5,001-10,000 employees
Real User
Top 5
Feb 19, 2026
Advanced analytics and flexible dashboards have improved risk-based monitoring and faster incident response
Pros and Cons
  • "We have majorly utilized Splunk Enterprise Security in SIEM and SOAR use cases, and the product is top-notch, with no problems."
  • "I think the licensing costs for Splunk Enterprise Security are on the higher side, but I am not certain."

What is our primary use case?

Splunk Enterprise Security is primarily a security solution used for device monitoring. If there is any suspicious activity happening, Cisco will capture that and get you the alert, then your SOC team can analyze the issue and take necessary action to avoid the breach.

Analysis is the first point when suggesting the best features of Splunk Enterprise Security.

I think the firewall and all these network devices and security devices—routers, switches—they all need to be connected to Splunk Enterprise Security in some way, so that it can get the data from all these devices, and then SIEM can analyze that data and get us the alert. There are a few tools such as Snowflake Security Data Lake which integrates with Splunk Enterprise Security, and Splunk Enterprise Security has its own security data lake. There are multiple tools that integrate with Splunk Enterprise Security.

In the context of risk-based alerting in Splunk Enterprise Security, company-wise, they have different policies, but risk-based alerting is definitely a great feature that multiple customers utilize.

What is most valuable?

I think the product is very good. It is a leader in its category. We have majorly utilized Splunk Enterprise Security in SIEM and SOAR use cases, and the product is top-notch, with no problems. The only challenge I was getting to know earlier was the resource crunch. The training and enablement was very limited, but post-Cisco acquisition, it is now quite easy because Cisco has a different outlook for partner enablement and partner management. They provide a plethora of free-of-cost training and enablement, and their solution engineers are available over the call for any kind of consultation, which was not very convenient before the acquisition. This is a clear call-out for me.

I am talking about the learning curve of the product. Your product adoption improves once you have the trained resources in the market, but if you don't have trained resources, then they will make mistakes in the implementation and deployment, and then people see that. If there are limited resources in the market, they will be very costly. Whoever is on that particular technology will not be affordable, and that also decreases the chance of the company to grow.

I am overall satisfied with how the dashboard is arranged. There is a lot of flexibility in the dashboard, the number of integrations that it provides, the level of accuracy, and the sensitivity level. I think these are the important things.

The workflow is good, and I think they keep improvising it. There is not a specific comment on that regarding how important this feature is and how it supports the overall workflow.

On average, the time my SecOps team takes to remediate security incidents with Splunk Enterprise Security is certainly less compared to previous solutions. In that case, I would rate Splunk Enterprise Security as the highest SIEM solution. Their SOAR solution is also quite competent.

As for currently using any new threat detection features in Splunk Enterprise Security, I mention Mandiant and VirusTotal, and then Cyber, which are a couple of tools that multiple customers, different customers, use.

What needs improvement?

It is tough to say which features would be included in future updates of Splunk Enterprise Security. I think it will keep growing. Maybe if they incorporate generative AI, I think AI is already there, but if they incorporate generative AI in terms of tracking the issues, automatic resolutions, and some root cause analysis, and I think threat intelligence, something using GenAI providing information on threat intelligence, that would also add value.

The workflow is good, and I think they keep improvising it. There is not a specific comment on that regarding how important this feature is and how it supports the overall workflow.

For how long have I used the solution?

I have 12-plus years in software and IT.

How are customer service and support?

My thoughts about the technical support of Splunk Enterprise Security is that they are good, but I think there are complaints about support sometimes. However, it is the same with every other player. I would say it is not so bad, but there could be improvements.

How would you rate customer service and support?

Negative

How was the initial setup?

It depends on the volume of deployment for Splunk Enterprise Security. A bigger organization needs a month of time for different things: running some POCs in the beginning, understanding the environment complexities, the number of integrations, and if that integration requires some kind of development, how many legacy applications need to be integrated. The time varies depending on the scope of work. A couple of months for a large enterprise can take almost a month. Organizations have to migrate data also. If they are using some existing solution, that data needs to be migrated, and all those checks and balances will take time.

What about the implementation team?

That depends on the size of the project, but I think maybe five to six resources, at least, are usually involved in deployment from my side.

What was our ROI?

I believe it is beneficial in terms of finance to use Splunk Enterprise Security, as enterprises are realizing the value, and the ROI is also good.

What's my experience with pricing, setup cost, and licensing?

I think the licensing costs for Splunk Enterprise Security are on the higher side, but I am not certain. I have not done a thorough analysis—six months back I left this Splunk partnership. I think they are still affordable to some of the very demanding enterprises. However, the mid-market and startups may struggle, because it is a very premium, enterprise-based solution. The price is also very premium. Comparing it with Microsoft Defender and the Microsoft SIEM solution, I think in terms of pricing, they are very neck-and-neck. The pricing is also good. If they can offer a slight level of discount, that can enhance their ability to reach price-sensitive customers.

What other advice do I have?

Product adoption improves once you have the trained resources in the market, but if you do not have trained resources, then they will make mistakes in the implementation and deployment, and then people see that. If there are limited resources in the market, they will be very costly. Whoever is on that particular technology will not be affordable, and that also decreases the chance of the company to grow.

Disclosure: My company has a business relationship with this vendor other than being a customer. Integrator
Last updated: Feb 19, 2026
Flag as inappropriate
PeerSpot user
Cybersecurity operations analyst at a tech vendor with 10,001+ employees
Real User
Top 20
Sep 15, 2026
Integrated security workflows have reduced response times and improved incident investigations
Pros and Cons
  • "One of the best features Splunk Enterprise Security offers is integrating everything into one platform."

    What is our primary use case?

    Splunk Enterprise Security is used primarily for reviewing notables and security events as a SIEM. My daily work involves reviewing notables across our environment, such as network traffic. For example, if one of the devices from our network reaches out to an IP that has suspicious or bad credibility, it gets flagged. I investigate that communication to understand why it is reaching out to that malicious IP and determine if it is something actionable or if it was blocked by the firewall. I review the logs and use Splunk Enterprise Security to conduct our incident response.

    What is most valuable?

    One of the best features Splunk Enterprise Security offers is integrating everything into one platform. Having the ability to investigate events without leaving Splunk Enterprise Security allows me to stay in the same environment and access all information from other platforms and network traffic logs. I can complete my entire investigation through Splunk Enterprise Security without needing to go somewhere else.

    Splunk Enterprise Security helps my day-to-day work by making it easier compared to other tools. It allows me to stay in the same tab and start running queries, find my investigation, and run everything without stepping away or taking time to log into another application to find information.

    Splunk Enterprise Security has positively impacted my organization by enabling us to take action on notables. It streamlines everything, and all the other analysts know that we need to address those notables with urgency. It allows us to maintain that level of security within the company and investigate those security events, bringing everything under control and having visibility if something bad is happening within the environment.

    Splunk Enterprise Security has helped our team by showing faster incident response times with the MTTR, or Mean Time to Respond. By tracking it, we can see how our analysts are able to target those incidents and resolve them with urgency and do them faster.

    What needs improvement?

    The improvement for Splunk Enterprise Security is happening now as they are implementing the agentic SOC, with agents helping with the mundane work for the analyst. If an agent is already looking through investigations and reaching the point where it is an actionable event, having the analyst look into it to ensure it is something we want to do is one of the biggest improvements I am seeing.

    For how long have I used the solution?

    I have been using Splunk Enterprise Security for about five years.

    What do I think about the stability of the solution?

    Splunk Enterprise Security is stable.

    What do I think about the scalability of the solution?

    The scalability of Splunk Enterprise Security is great. It is always improving, and we can use it and implement anything new that comes up.

    How are customer service and support?

    The customer support for Splunk Enterprise Security is great. I have not had any issues with it, as they have always been there to support us, especially regarding any problems or if we wanted new training or resources. The Splunk representatives have been amazing. I would rate the customer support a 10.

    Which solution did I use previously and why did I switch?

    When I came into the company, we already had Splunk, so I have not used a different solution.

    How was the initial setup?

    I am not sure which options were evaluated before choosing Splunk Enterprise Security. The company already made its decision, so when I started working in security, I was already on Splunk and learning it.

    What was our ROI?

    I am not sure if we have seen a return on investment since we still have the same number of employees. However, Splunk Enterprise Security definitely allows us to be more efficient in what we do.

    What's my experience with pricing, setup cost, and licensing?

    I am not sure about pricing, setup cost, and licensing since I am not the one making purchases for Splunk Enterprise Security. I am just using it.

    What other advice do I have?

    My advice for others looking into using Splunk Enterprise Security is to go for it. You always get what you pay for, and I believe this product has everything you need to ensure it is a good investment for your company. I would rate this product a 10.

    Which deployment model are you using for this solution?

    Private Cloud

    If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

    Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
    Last updated: Sep 15, 2026
    Flag as inappropriate
    PeerSpot user
    Buyer's Guide
    Download our free Splunk Enterprise Security Report and get advice and tips from experienced pros sharing their opinions.
    Updated: September 2026
    Buyer's Guide
    Download our free Splunk Enterprise Security Report and get advice and tips from experienced pros sharing their opinions.