There are quite a lot of things that we find useful. Splunk agents are useful and good. Its UI is quite impressive.
Senior Information Technology System Analyst at a computer software company with 5,001-10,000 employees
Impressive UI, many useful features, and very scalable, but needs alerting feature and better pricing and integration
Pros and Cons
- "There are quite a lot of things that we find useful. Splunk agents are useful and good. Its UI is quite impressive."
- "Its pricing model and integration with third-party services can be improved. We had faced an issue with integration. The alerting feature is currently not available with Splunk, but it is definitely available with Datadog and PagerDuty. They should include this feature. A few dashboards in Splunk look quite old and are not that modern. They aren't bad, but improving these dashboards will definitely make Splunk more attractive and usable. I read in a few blog posts that there were a few security incidents related to Splunk agents. So, it can be made more secure."
What is most valuable?
What needs improvement?
Its pricing model and integration with third-party services can be improved. We had faced an issue with integration.
The alerting feature is currently not available with Splunk, but it is definitely available with Datadog and PagerDuty. They should include this feature.
A few dashboards in Splunk look quite old and are not that modern. They aren't bad, but improving these dashboards will definitely make Splunk more attractive and usable.
I read in a few blog posts that there were a few security incidents related to Splunk agents. So, it can be made more secure.
For how long have I used the solution?
I have been using this solution for almost two years. I am using its latest version.
What do I think about the stability of the solution?
It is a stable product.
Buyer's Guide
Splunk Enterprise Security
December 2025
Learn what your peers think about Splunk Enterprise Security. Get advice and tips from experienced pros sharing their opinions. Updated: December 2025.
879,310 professionals have used our research since 2012.
What do I think about the scalability of the solution?
Splunk is definitely scalable.
How are customer service and support?
I have not interacted with them. Another team is taking care of raising tickets with their technical support.
How was the initial setup?
It is quite simple.
What's my experience with pricing, setup cost, and licensing?
Its pricing model can be improved.
What other advice do I have?
A few years ago, I would have definitely recommended Splunk, but nowadays, better alternatives are available. We are currently exploring a few other alternatives, so I won't recommend Splunk as of now.
I would rate Splunk a seven out of ten.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Founder at a tech services company with 1,001-5,000 employees
Seamless integration with devices and operating systems, centralized management and control, and proactive support
Pros and Cons
- "The integration is seamless with many devices and operating systems."
- "Being a SIEM solution with a centralized dashboard, we would like to have more options to customize it."
What is our primary use case?
We are a solution provider and Splunk is something that we provide as a service to our customers.
What is most valuable?
The most valuable feature is the reporting and the information that is provided by the tool.
It is very easy to implement a PoC using Splunk, which will show the value of the reporting and data that it provides.
The integration is seamless with many devices and operating systems.
It is flexible enough that you can choose what kind of deployment model you want.
They have a large solution toolkit that supports IoT, wherein businesses can get a lot of help with the centralized management functionality. There are also tools to assist from the security and SIEM perspective, and there is a centralized dashboard.
What needs improvement?
Being a SIEM solution with a centralized dashboard, we would like to have more options to customize it. It should be easy to customize dashboards.
When we are monitoring something, we would like to have a more granular outlook. Splunk has a good dashboard that is easier to use than some competing products, but better customizability would be a great help for the users.
For how long have I used the solution?
We have been working with Splunk for approximately three years.
What do I think about the stability of the solution?
This product is very stable.
What do I think about the scalability of the solution?
Splunk is a very scalable solution. Being a Japanese product, they will ensure that all of the features work in any environment. It is very heterogeneous. It can integrate with Windows, Linux, AIX, HP-UX, and Solaris. It also supports IoT devices, mobile phones, and more.
We have more than 150,000 people using our services.
How are customer service and technical support?
The Splunk team has good, proactive support. Also in terms of assisting with the installation, they are quite good.
Which solution did I use previously and why did I switch?
Splunk is similar to IBM QRadar, which we also have experience with. However, Splunk has advanced SIEM features included with it, so we often use it to satisfy this requirement. Whenever an organization is looking to implement SIEM, they have the flexibility to choose Splunk, QRadar, or the ArcSight Logger solution.
One of the major differences that I see between Splunk and QRadar is that Splunk gives the users fewer devices, so they can do things quicker.
How was the initial setup?
The installation for Splunk is easier than competing products QRadar and ArcSight.
We have Splunk deployed on the cloud so that we can provide the service, but some of our customers have it installed on-premises.
All the user has to do is download the Splunk server agent, install it on the laptop or endpoint, integrate 50 or 100 devices, then see what kind of reporting is available.
What about the implementation team?
We have an in-house team for deployment in maintenance. Splunk is a tool that does not require much staff to maintain. The users can start with a PoC, simply learn it, and deploy it for themselves. They don't require subject experts to be hired for the installation and configuration.
What's my experience with pricing, setup cost, and licensing?
Price-wise, if you compare QRadar to Splunk for SIEM functionality then they are in the same range but when you integrate SOAR with these solutions, Splunk takes the lead and is more competitive.
What other advice do I have?
This is a product that I recommend for anybody who wants and advanced SIEM solutions. Of the three that I have used including QRadar and ArcSight, Splunk is the one that I prefer.
I would rate this solution a nine out of ten.
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
Buyer's Guide
Splunk Enterprise Security
December 2025
Learn what your peers think about Splunk Enterprise Security. Get advice and tips from experienced pros sharing their opinions. Updated: December 2025.
879,310 professionals have used our research since 2012.
Assistant Manager System at a financial services firm with 10,001+ employees
Stable, with easy log connection and the capability to scale
Pros and Cons
- "Its compatibility with other SIEMS is very useful."
- "We find that the maintenance process could be a lot better."
What is our primary use case?
What is most valuable?
The ease of log connection has been great.
Its compatibility with other SIEMS is very useful.
They have many basic use cases that we like.
The cloud version of the solution is especially scalable.
The product has been quite stable so far.
The initial setup is very easy.
What needs improvement?
Technical support is lacking post-sale.
The modification of firmware could be improved.
We find that the maintenance process could be a lot better.
The solution is more expensive than other options on the market.
For how long have I used the solution?
We haven't been using the solution for too long at this point. It's been about four months or so.
What do I think about the stability of the solution?
The stability has been good. It offers good performance and doesn't seem to be buggy. There aren't glitches. It doesn't crash or freeze. It's reliable.
What do I think about the scalability of the solution?
The solution is scalable. This is especially true for the cloud deployment model. There really isn't anything holding you back if you use that version.
We have around 100 people on the solution currently. 60 to 70 of those are technical users.
We do plan to keep using Splunk.
How are customer service and technical support?
Technical support services are lacking, especially after you buy the product. They aren't as helpful or responsive as we need them to be. However, when we do reach them, they are good and they help.
Which solution did I use previously and why did I switch?
I have used McAfee Nitro in the past and IBM QRadar as well.
How was the initial setup?
The initial setup is not complex. It's very straightforward. In fact, it's far easier to install than other log tools on the market. A company shouldn't have any issues with the process.
That said, I did not work on the installation myself. Other people at the company handled that aspect of the process.
The maintenance process could be better. It's a bit difficult once the deployment is done. We need about five people for maintenance tasks.
What's my experience with pricing, setup cost, and licensing?
When you compare the services and features, the pricing is reasonable. That said, if you compare Splunk to other options on the market, it is more expensive.
What other advice do I have?
As we recently purchased the solution, we are using the latest version right now.
I would recommend the solution to other users.
I would rate the solution at an eight out of ten. If the solution offered a better price and better support services, I would likely rate it higher. However, for the most part, we have been satisfied with the product and its capabilities.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Senior Consultant at a tech services company with 1-10 employees
Powerful programming language and search capability, but it is expensive and the vendor is inflexible
Pros and Cons
- "What I really like is that even if you have already collected the data, you can extract fields and can build searches."
- "I would like to see more SIEM functionality and a better ticket tool."
What is our primary use case?
My reason for implementing it was just to learn more about the product. I wanted to learn about the Splunk programming language, how to pipe searches, add logs, verify the logs, create fields, extract data into fields, build dashboards, and to get hands-on experience with the product.
What is most valuable?
The Splunk programming language allows you to pipe searches into another searches.
What I really like is that even if you have already collected the data, you can extract data and add fields which improves building searches. This is not the case with Elasticsearch, where this needs to be done upfront.
What needs improvement?
I really dislike how Splunk sales and partner manager behaves. I have faced several sales model and partnership changes. Also, the last time I wanted to by a license ro built a SIEM solution, they had removed the ability to purchase a splunk subscription or license from their website. In the past, there was a web page calculator it was possible to by online, but now it instructs to contact sales.
The free version is limited to 500 megabytes and there is no alerting. Due to the missing feature on the Splunk webpage, I have ask Splunk Sales to purchase a license like 1Gyte a day or a license for max 2500 Euro/year to use it as a test or development instance for myself. Asking Splunk for a quote willing to pay for Splunk license to learn and to get used to the product, Splunk didn't get it managed to offer my a license neither arranging the partnership paperwork I have ask for. Sales people from Splunk where calling, each time after I left my details on ther trial download page. I explained my experience and concerns about Splunk in the past. All excuses received and promises that someone will contact me to solve the issues faced in the past, was leading in excactly nothing. Well Done Splunk.
Inflexible and expensive and I do not have much faith in the people working there because if someone is asking for a test environment and is willing to spend up to €2,500 a year, I can't understand why they are unable to provide a license. This could be a lost opportunity because they are not able to onboard a potential new partner.
They definitely need to boost their sales and partner program because it changes to often, where they are dropping partners and it is difficult to get in contact with somebody. This is something that needs to be improved.
I would like to see more SIEM functionality and embedded moduled such a ticket tool to make a end to end SIEM.
For how long have I used the solution?
I have been using Splunk for a few weeks.
What do I think about the scalability of the solution?
As I was using a test environment, I can't comment on scalability. It was just myself and a colleague who was using it as a test instance.
How are customer service and technical support?
I have not been in contact with technical support.
Which solution did I use previously and why did I switch?
I have worked a little bit with Elasticsearch. I also have an instance of SIEMonster running, and I'm trying to get used to it. I found that Splunk provided a good benefit compared to Elasticsearch.
With Elasticsearch, if you have already inserted the data then it's gone because you need to do the pre-filtering. Once you've inserted or ingested the raw data, using Logstash, for example, you are no longer able to build the fields such as IP address, hostname, username, and the other fields that you want to export. This unsorted, raw data that you have is really a drawback for Elasticsearch and some other products. This is something from Splunk that I consider to be a heavy feature, where you can just insert data and ingest it later on.
How was the initial setup?
really fast and easy to install a test instance.
What's my experience with pricing, setup cost, and licensing?
The pricing model is expensive and could lead into a budget nightmare based on the amount of data.
A better pricing plan would be an improvement.
Which other solutions did I evaluate?
I have done some research on LogRhythm, IBM QRadar, and ArcSight, but I don't have any hands-on experience yet.
I did a comparison for a customer two weeks ago and the outcome of my comparison was SIEMonster, effortable price model, even though it's a niche player, it's quite powerful. I also provided Splunk as a recommendation because it is a market leader, really powerful, and really good to use. I also recommended LogRhythm; it is also expensive but it's also really powerful, and the feedback of customers is really good.
With respect to Splunk, I would recommend it but when a customer is budget-driven then Splunk is not the solution. Money shouldn't be the question.
What other advice do I have?
This is a solution that I could recommend for somebody who wants a really powerful product. It is not an end to end orchestrated SIEM yet.
This is a product that I would generally recommend, although I would not do so if the customer is really budget-driven.
I would rate this solution a six out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
IT System Developer/Admin at a manufacturing company with 10,001+ employees
A stable, scalable solution with comprehensive dashboards and helpful technical support
Pros and Cons
- "The scalability of the solution is amazing because it can collect a lot of data and you can have your own structure to monitor this data."
- "An area of improvement would be the licensing of the solution. They need a free license, which would allow faster lead times."
What is our primary use case?
The primary use case of this solution is to monitor Cyber Mission databases.
I create the diagrams to create an architecture that is then implemented. However, creating these diagrams are for my own learnings since these implementations are usually already available in the cloud office logs.
What is most valuable?
The features I have found most valuable are the dashboards.
I monitor the complete capacity that users are using in the company.
What needs improvement?
An area of improvement would be the licensing of the solution. They need a free license, which would allow faster lead times.
They also need to update their documentation.
What do I think about the stability of the solution?
The solution is stable.
What do I think about the scalability of the solution?
The scalability of the solution is amazing because it can collect a lot of data and you can have your own structure to monitor this data.
How are customer service and technical support?
The customer service/technical support was helpful and they answered my questions as best they could.
How was the initial setup?
The setup was easy, but you have to have a VPN connection depending on the security protocols in place.
What about the implementation team?
The deployment was in-house and took about two days with the correct licenses and permissions.
What other advice do I have?
It is important to define different guidelines to integrate Splunk in development, QA, and production deployments. Additionally, define the applications that will be used and the configuration of the databases to collect the data. If this is not done, there will be a lot of issues due to, for example, master access or permissions to use the database collector and blocks.
Which deployment model are you using for this solution?
Hybrid Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Amazon Web Services (AWS)
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
General Manager at a tech vendor with 11-50 employees
A great solution for application management, security and compliance
Pros and Cons
- "The correlation capabilities are the first value that our clients say they like with Splunk."
- "The difficult part is related to integration with sources of data that are used to create the logs as this depends on the infrastructure of the client."
What is our primary use case?
We use Splunk for security and also PCI compliance.
We have installed and implemented this solution for several clients in Bolivia with our team. We have received training from Splunk directly, and we have also provided training to our clients.
We deploy two versions: one for on-premise and one for the cloud.
Most of our customers purchase Splunk because they required a tool for gathering and collecting all of the logs from the infrastructure in order to make a correlation between data and to spot patterns surrounding security incidents.
What is most valuable?
The correlation capabilities are the first value that our clients say they like with Splunk. Another benefit is that they can connect to any device or log from any device from anywhere.
It's easy, the tool is very easy to install and set up.
What needs improvement?
They could have more dashboards done or predefined so our clients could use them directly in order to have more information ready to use.
The difficult part is related to integration with sources of data that are used to create the logs as this depends on the infrastructure of the client.
For how long have I used the solution?
We have been using this solution for more than five years.
What do I think about the stability of the solution?
Stability-wise, it's great.
What do I think about the scalability of the solution?
We do not require much scalability here because the clients are not so big; however, the hardware where we installed the products was enough to handle all the transactions of Splunk.
How are customer service and technical support?
The support is not so good, I would only give them a rating of six or seven.
They should provide support in Spanish here in Latin America. Their response time to inquires or requirement tickets is too long. It should be shorter.
How was the initial setup?
Deployment took us two weeks.
What other advice do I have?
I would recommend Splunk to any company: small, medium, and large.
Splunk is a great tool but you should get a partner who knows what they are doing, implementation-wise.
On a scale from one to ten, I would give Splunk a rating of nine.
Disclosure: My company has a business relationship with this vendor other than being a customer. Reseller
Sr. IT Manager at a pharma/biotech company with 10,001+ employees
Good log aggregation and scales well, with good technical support that is responsive and helpful
Pros and Cons
- "The most valuable feature is that it's very good for log aggregation."
- "The implementation and the scanning of the logs can be difficult."
What is our primary use case?
We are using Splunk to look at the logs, and see what is happening.
What is most valuable?
The most valuable feature is that it's very good for log aggregation.
What needs improvement?
Splunk is very complex. The implementation and the scanning of the logs can be difficult.
For how long have I used the solution?
I have been using Splunk for approximately three years.
What do I think about the stability of the solution?
In general, Splunk is stable.
What do I think about the scalability of the solution?
It's a scalable product. it's pretty good.
How are customer service and technical support?
Technical support is usually pretty good.
They are responsive, knowledgeable, and helpful.
How was the initial setup?
The initial setup was relatively straightforward.
What's my experience with pricing, setup cost, and licensing?
The price is comparable.
What other advice do I have?
I would rate Splunk and eight out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Sr. IT Manager at a pharma/biotech company with 10,001+ employees
Log aggregation helps us quickly detect widespread threats, but it can be resource-heavy
Pros and Cons
- "The most valuable feature is the log aggregation, being able to scan through all of the logs."
- "Queries are not always as easy or straightforward as they might be, so it can be difficult to figure out what you need to look for."
What is our primary use case?
We use Splunk for log analysis and security monitoring.
How has it helped my organization?
Splunk allows us to look at logs from different groups within NIH and see if there's a widespread threat or issue.
What is most valuable?
The most valuable feature is the log aggregation, being able to scan through all of the logs.
What needs improvement?
Queries are not always as easy or straightforward as they might be, so it can be difficult to figure out what you need to look for.
In the next release of this product, I would like to see it offer more recommendations as to what needs to be done.
For how long have I used the solution?
We have been using Splunk for between two and three years.
What do I think about the stability of the solution?
In terms of stability, the product seems to work just fine. We haven't had any problems with it.
What do I think about the scalability of the solution?
It can be somewhat of a resource hog; some of the scans can take a while. We do plan to increase our usage in the future.
How are customer service and technical support?
Technical support for Splunk is good.
How was the initial setup?
The initial setup is relatively straightforward.
What about the implementation team?
There were consultants involved in the deployment.
What other advice do I have?
I would rate this solution a seven out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Buyer's Guide
Download our free Splunk Enterprise Security Report and get advice and tips from experienced pros
sharing their opinions.
Updated: December 2025
Product Categories
Security Information and Event Management (SIEM) Log Management IT Operations AnalyticsPopular Comparisons
CrowdStrike Falcon
Microsoft Sentinel
IBM Security QRadar
Elastic Security
Splunk AppDynamics
Grafana Loki
Elastic Observability
Security Onion
Graylog Enterprise
Palantir Foundry
Buyer's Guide
Download our free Splunk Enterprise Security Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- Which would you recommend to your boss, IBM QRadar or Splunk?
- What are some of the best features and use-cases of Splunk?
- What SOC product do you recommend?
- Splunk as an Enterprise Class monitoring solution -- thoughts?
- What is the biggest difference between Dynatrace and Splunk?
- IBM QRadar is rated above competitors (McAfee, Splunk, LogRhythm) in Gartner's 2020 Magic Quandrant. Agree/Disagree?
- What are the advantages of ELK over Splunk?
- How does Splunk compare with Azure Monitor?
- New risk scoring framework in the Splunk App for Enterprise Security -- thoughts?
- Splunk vs. Elastic Stack
















