We are using Splunk for querying data from different sources.
Senior Manager, Analytics & Insights at a consultancy with 10,001+ employees
Effective machine learning, reliable, and responsive support
Pros and Cons
- "Splunk has machine learning which is a valuable feature."
- "The algorithms customization of Splunk could improve. They have limited algorithms for machine learning support. If they can allow the user to add more machine learning algorithms, such as the ability to choose the algorithm that a user might want. Additionally, they should provide the required libraries for those algorithms, and then analyzes the data for use."
What is our primary use case?
What is most valuable?
Splunk has machine learning which is a valuable feature.
What needs improvement?
The algorithms customization of Splunk could improve. They have limited algorithms for machine learning support. If they can allow the user to add more machine learning algorithms, such as the ability to choose the algorithm that a user might want. Additionally, they should provide the required libraries for those algorithms, and then analyzes the data for use.
For how long have I used the solution?
I have used Splunk within the past 12 months.
Buyer's Guide
Splunk Enterprise Security
December 2025
Learn what your peers think about Splunk Enterprise Security. Get advice and tips from experienced pros sharing their opinions. Updated: December 2025.
879,310 professionals have used our research since 2012.
What do I think about the stability of the solution?
Splunk is a stable solution.
How are customer service and support?
We have contacted the support and most of the reasons we have contact support has been project-related. For example, we want the APAs to work in a certain way or for certain fixes.
What other advice do I have?
I have been using Splunk for approximately
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Director General de España at a cloud solution provider with 51-200 employees
Integrates with every technology, easy to use, and good for analytics and cybersecurity
Pros and Cons
- "It is very easy to use and integrate. There are connectors for every technology."
- "The UI can be improved. Dashboards and reports can be better in terms of graphics."
What is our primary use case?
We work with Splunk. We use it for our own services, and we also integrate and resell Splunk. It is used for cyber security.
Different clients have different versions. They have Splunk Cloud and Splunk on-premises with different versions.
What is most valuable?
It is very easy to use and integrate. There are connectors for every technology.
What needs improvement?
The UI can be improved. Dashboards and reports can be better in terms of graphics.
For how long have I used the solution?
We have been using this solution for a few years. In 2016, we became a Splunk partner.
What do I think about the stability of the solution?
It is very stable.
What do I think about the scalability of the solution?
Its scalability is very good. We work with this platform for our own services. We use Splunk extensively, and we also offer it to our clients. We plan to increase its usage.
Our company has three offices. We have offices in Spain, Columbia, and Mexico. We have around 100 people, and about 50 people are working with Splunk. They all are focused on cyber security. They are security engineers or security specialists.
How are customer service and support?
I don't know about their support. I don't work with it much. On an activity level, I'm not so close to the platform. I'm the country manager, so I am a bit far from the operation.
Which solution did I use previously and why did I switch?
We tried to work with Exabeam for user behavior analytics, but we stopped it.
How was the initial setup?
Its setup is very easy, but we have been working with Splunk for a lot of years. We have all the certifications in Splunk, and we are a specialist in Splunk. So, for us, it is very easy to set it up and integrate it, but it might not be easy for other companies.
What other advice do I have?
Splunk is a very good platform for analytics and cybersecurity. We use it very extensively. It is very easy to use, and it is very stable and scalable.
I would rate it a nine out of 10.
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner.
Buyer's Guide
Splunk Enterprise Security
December 2025
Learn what your peers think about Splunk Enterprise Security. Get advice and tips from experienced pros sharing their opinions. Updated: December 2025.
879,310 professionals have used our research since 2012.
Splunk BDM in UA at a manufacturing company with 51-200 employees
Optimizes network security, straightforward to deploy, and can handle a large volume of data
Pros and Cons
- "The fact that Splunk is a platform and not just a SIEM solution is a key benefit."
- "The support that is included with the standard licensing fee is very bad."
What is our primary use case?
We are a solution provider and Splunk is one of the products that we distribute.
The primary use case is for SIEM and we have approximately 35 customers.
What is most valuable?
The fact that Splunk is a platform and not just a SIEM solution is a key benefit.
Our customers like that they can use Splunk to optimize their security.
What needs improvement?
The Splunk licensing model should be more flexible.
The support that is included with the standard licensing fee is very bad.
For how long have I used the solution?
We have been working with Splunk since 2017.
What do I think about the stability of the solution?
Stability-wise, it's perfect. We haven't had any problem with Splunk. It's good software.
What do I think about the scalability of the solution?
One of the key benefits and differences with this software is that the customer can scale up as much as they need to. Our largest Splunk customer is using between three and four petabytes of data per day.
How are customer service and support?
If you don't pay extra for technical support then it is very bad. If you pay extra for it, then the technical support is normal.
Which solution did I use previously and why did I switch?
I am familiar with other products and Splunk can handle much more data than IBM QRadar or any other competing product.
Direct competitors are more flexible when it comes to licensing.
How was the initial setup?
We have not had any problems installing Splunk.
For a standard case, it takes between one and two weeks to install correctly and deploy. This is for situations where the client has less than 50 gigabytes of data per day.
Problems during the implementation are typically due to something on the customer's side. For example, if the client does not have somebody that is responsible for the deployment, helping to speed up the various procedures, then this is a key problem for us.
What about the implementation team?
It takes two people to deploy and maintain.
What's my experience with pricing, setup cost, and licensing?
Splunk is not a cheap solution and the license is billed annually. The licensing model should be improved and the price should be lower, in general.
You can purchase additional technical support, which is much better than the support that is included.
What other advice do I have?
I would rate this solution an eight out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer.
System Engineer at a tech vendor with 1,001-5,000 employees
Highly stable, built-in workflows, and good support
Pros and Cons
- "The most valuable feature of Splunk is the management and built-in workflows."
- "The analytics of Splunk could be improved."
What is our primary use case?
There are many use cases for Splunk, we commonly use it for log management and analytics.
What is most valuable?
The most valuable feature of Splunk is the management and built-in workflows.
What needs improvement?
The analytics of Splunk could be improved.
For how long have I used the solution?
I have been using Splunk for approximately four years.
What do I think about the stability of the solution?
Splunk is a highly stable solution.
What do I think about the scalability of the solution?
I have found Splunk to be scalable.
We have 15 members of our organization that use this solution.
How are customer service and support?
We used to support a few times and our experience was good.
I would rate the support from Splunk a four out of five.
Which solution did I use previously and why did I switch?
I have previously used RSA and I prefer Splunk.
How was the initial setup?
The implementation of slunk is not straightforward. It is of a moderate difficulty level.
What about the implementation team?
We used an integrator to do the implementation.
What's my experience with pricing, setup cost, and licensing?
There is an annual license required to use this solution.
Which other solutions did I evaluate?
I have evaluated other solutions, such as IBM QRadar.
What other advice do I have?
This solution has good technology.
I rate Splunk an eight out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Presales IT at a tech services company with 201-500 employees
Good product that satisfies our customers
Pros and Cons
- "The product is good, it satisfies our customers."
- "The prices are complicated as we operate in a small third-world country."
What is our primary use case?
Our company is an IT service provider. We are resellers of Splunk. One of our clients that we monitor is a laboratory that uses this solution.
Splunk is a change management solution. We use the solution as a log collector, and to analyze and provide alerts from the IT instructor.
What is most valuable?
The product is good, it satisfies our customers.
What needs improvement?
The price of Splunk is too high for our market.
For how long have I used the solution?
Our company has been a reseller of Splunk for less than six months.
What do I think about the stability of the solution?
Splunk is stable.
What do I think about the scalability of the solution?
This is a scalable solution.
How are customer service and support?
We have had no concerns with customer service.
How was the initial setup?
The initial setup of Splunk is somewhat difficult because it was our first time implementing the solution. It was a similar situation to implementing other CM tools like FortiSIEM.
What about the implementation team?
Splunk required two engineers to implement, and we will add another one to maintain the solution.
What's my experience with pricing, setup cost, and licensing?
The prices are complicated as we operate in a small third-world country.
Which other solutions did I evaluate?
We give support for VMware and other technologies. We purchased Splunk because our customers were asking for our services to take control of the implementation from another company.
What other advice do I have?
If you are considering Splunk and you like what you are seeing; my advice would be to go for it.
I would rate Splunk an 8 out of 10.
Disclosure: My company has a business relationship with this vendor other than being a customer.
Fast and easy to use, but could be faster
Pros and Cons
- "The solution is very fast and succinct."
- "I feel the solution to be too slow."
What is most valuable?
The solution is very fast and succinct.
What needs improvement?
When it comes to out of the box use cases, I feel the solution to be too slow.
For how long have I used the solution?
I have not been working with Splunk for long.
How was the initial setup?
The initial setup was simple.
It took an hour.
Which other solutions did I evaluate?
Curator is more scalable than certain other solutions.
What other advice do I have?
We are partners of Splunk and provide the solution to customers.
I feel Splunk is easy to utilize.
My company has an app. on which the solution is deployed on-premises on a single server.
There is another team in my company that works with Splunk products.
I rate Splunk as a seven-point-five out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Technical manager at a tech services company with 11-50 employees
Stable and easy to use
Pros and Cons
- "The most valuable features are how stable and easy to use Splunk is."
- "This solution could be improved by better pricing in general and by easier installation."
What is our primary use case?
My primary use case is for log management. It's mostly deployed on-premises, but it can be cloud-based as well.
What is most valuable?
The most valuable features are how stable and easy to use Splunk is.
What needs improvement?
This solution could be improved by better pricing in general and by easier installation.
For how long have I used the solution?
I have been a partner of Splunk for three years.
What do I think about the stability of the solution?
This solution is stable.
How are customer service and support?
Technical support is customer-friendly.
How was the initial setup?
The initial installation is not straightforward. It needs two or three days, depending on the size of the company. But it can be done with one senior engineer.
What about the implementation team?
I implemented through an in-house team.
What's my experience with pricing, setup cost, and licensing?
Splunk has a subscription and a perpetual license.
This product could use better pricing.
What other advice do I have?
I would rate Splunk a nine out of ten. I recommend this product to others who are considering implementing it.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
CEO at a tech services company with 11-50 employees
Simple to install, with good monitoring, and correlation capabilities
Pros and Cons
- "The scalability is good."
- "In the next releases, I would like to see more pricing flexibility."
What is our primary use case?
We are resellers. We provide solutions to our clients.
Splunk is primarily used for developing CM solutions that are based on the Splunk platform for future security operation center development.
We are concentrating on assisting in the development of a security monitor as well as analysis.
If I am not mistaken, it's a standard CM system for identification, security verification, and event monitoring.
What needs improvement?
In my opinion, it is too expensive for our projects.
It is very competitive for small and medium businesses. Perhaps some should be set aside for developing markets. To begin with, similar to the current market, there may be some special conditions for large transactions.
In the next releases, I would like to see more pricing flexibility. It's a subscription-based service, and they don't sell professional licenses.
In some cases, particularly with large projects, we are not competitive in terms of pricing when compared to IBM QRadar and other solutions; even if we offer the maximum discount available, our prices remain uncompetitive.
For how long have I used the solution?
We have been selling Splunk for approximately five years.
What do I think about the scalability of the solution?
The scalability is good. It can be added on-demand in increments of one gigabyte or ten gigabytes. It's a per-gigabyte license, and you can add whatever you need at the time.
Our projects are sized per our current IT infrastructure.
Splunk is used by 10 of our customers.
How are customer service and support?
Our team provides technical support.
I have not communicated with technical support.
Which solution did I use previously and why did I switch?
We no longer resell Checkmarks.
We were unable to assist in establishing their business on-premises because It could have been too expensive for our clientele.
How was the initial setup?
Installing Splunk is not difficult, but it can be complicated in some cases.
The issue is the integration with the customer's system, as well as the configuration of the rules for correlation, log collecting, and analysis.
It has good documentation and guides, but the main works should be focused on customer needs and customer resources for monitoring.
It can take three months to complete the installation.
We have a team of three certified engineers who will deploy and maintain this solution.
What's my experience with pricing, setup cost, and licensing?
The licensing fees and pricing models could be reduced.
It's a yearly subscription.
They don't sell professionally because it's a subscription service. As a result, it is only a subscription service that is dependent on the customer's IT infrastructure.
What other advice do I have?
We do not sell Compliance Control Limited solutions because our focus is on auditing and independent security assessments. We put an end to our selling program with Checkmarks.
I would recommend this solution to others. Splunk is appropriate for small to medium-sized projects, and it should be calculated for large projects.
It's one of the best CM solutions on the market for monitoring, and correlation, as well as IT monitoring security.
I would rate Splunk an eight out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer. Reseller
Buyer's Guide
Download our free Splunk Enterprise Security Report and get advice and tips from experienced pros
sharing their opinions.
Updated: December 2025
Product Categories
Security Information and Event Management (SIEM) Log Management IT Operations AnalyticsPopular Comparisons
CrowdStrike Falcon
Microsoft Sentinel
IBM Security QRadar
Elastic Security
Splunk AppDynamics
Grafana Loki
Elastic Observability
Security Onion
Graylog Enterprise
Palantir Foundry
Buyer's Guide
Download our free Splunk Enterprise Security Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- Which would you recommend to your boss, IBM QRadar or Splunk?
- What are some of the best features and use-cases of Splunk?
- What SOC product do you recommend?
- Splunk as an Enterprise Class monitoring solution -- thoughts?
- What is the biggest difference between Dynatrace and Splunk?
- IBM QRadar is rated above competitors (McAfee, Splunk, LogRhythm) in Gartner's 2020 Magic Quandrant. Agree/Disagree?
- What are the advantages of ELK over Splunk?
- How does Splunk compare with Azure Monitor?
- New risk scoring framework in the Splunk App for Enterprise Security -- thoughts?
- Splunk vs. Elastic Stack















