The connections to the database are very good and updating the data files is simple to do. The dashboards are useful and user-friendly.
Cybersecurity Senior Manager at a tech services company with 10,001+ employees
Simple data file updates, good support, and useful dashboards
Pros and Cons
- "The connections to the database are very good and updating the data files is simple to do. The dashboards are useful and user-friendly."
- "The connections to the database are very good and updating the data files is simple to do, and the dashboards are useful and user-friendly."
- "We had some connections issues with the solution at the beginning."
- "We had some connections issues with the solution at the beginning."
What is most valuable?
What needs improvement?
We had some connections issues with the solution at the beginning.
For how long have I used the solution?
I have used Splunk within the last 12 months.
What do I think about the stability of the solution?
Splunk is a highly stable solution.
Buyer's Guide
Splunk Enterprise Security
March 2026
Learn what your peers think about Splunk Enterprise Security. Get advice and tips from experienced pros sharing their opinions. Updated: March 2026.
885,264 professionals have used our research since 2012.
What do I think about the scalability of the solution?
The scalability is good.
We have approximately 50 users using this solution in my organization.
How are customer service and support?
I am satisfied with the support from Splunk.
Which solution did I use previously and why did I switch?
We were previously using Excel.
What about the implementation team?
We used a consultant for the implementation of the solution. The full process took approximately one week.
We had a big problem with communication sometimes during the implementation. Some files in our network were a little difficult to receive. This was our fault because of some of our firewall configurations.
We have a five-person maintenance team that works on this solution.
What other advice do I have?
I rate Splunk an eight out of ten.
Which deployment model are you using for this solution?
Hybrid Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Enterprise Client Executive at a tech services company with 11-50 employees
Good user community, good support, and very powerful
Pros and Cons
- "The Splunk user community and forum are most valuable."
- "It is stable, very powerful, and their support is good."
- "Its interface could be improved."
- "Its initial setup is complex. You're going to need deployment services from somebody who is an expert in the product."
What is our primary use case?
We use it for security operations and management.
What is most valuable?
The Splunk user community and forum are most valuable.
What needs improvement?
Its interface could be improved.
For how long have I used the solution?
We have been a reseller for three years.
What do I think about the stability of the solution?
It is stable. It is very powerful.
How are customer service and support?
Their support is good.
How was the initial setup?
Its initial setup is complex. You're going to need deployment services from somebody who is an expert in the product. You would need at least two users.
What other advice do I have?
It is hard to integrate because it can do so many things. A lot of people think it is a set-it-and-forget-it solution, but it is a full-time job for somebody. I would advise others to plan and prepare for ongoing management. It requires a dedicated person for management.
Compared to other SIEMs, it is a 10 out of 10.
Disclosure: My company has a business relationship with this vendor other than being a customer.
Buyer's Guide
Splunk Enterprise Security
March 2026
Learn what your peers think about Splunk Enterprise Security. Get advice and tips from experienced pros sharing their opinions. Updated: March 2026.
885,264 professionals have used our research since 2012.
Fast and easy to use, but could be faster
Pros and Cons
- "The solution is very fast and succinct."
- "The solution is very fast and succinct."
- "I feel the solution to be too slow."
- "When it comes to out of the box use cases, I feel the solution to be too slow."
What is most valuable?
The solution is very fast and succinct.
What needs improvement?
When it comes to out of the box use cases, I feel the solution to be too slow.
For how long have I used the solution?
I have not been working with Splunk for long.
How was the initial setup?
The initial setup was simple.
It took an hour.
Which other solutions did I evaluate?
Curator is more scalable than certain other solutions.
What other advice do I have?
We are partners of Splunk and provide the solution to customers.
I feel Splunk is easy to utilize.
My company has an app. on which the solution is deployed on-premises on a single server.
There is another team in my company that works with Splunk products.
I rate Splunk as a seven-point-five out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Technical manager at a tech services company with 11-50 employees
Stable and easy to use
Pros and Cons
- "The most valuable features are how stable and easy to use Splunk is."
- "The most valuable features are how stable and easy to use Splunk is."
- "This solution could be improved by better pricing in general and by easier installation."
- "This solution could be improved by better pricing in general and by easier installation."
What is our primary use case?
My primary use case is for log management. It's mostly deployed on-premises, but it can be cloud-based as well.
What is most valuable?
The most valuable features are how stable and easy to use Splunk is.
What needs improvement?
This solution could be improved by better pricing in general and by easier installation.
For how long have I used the solution?
I have been a partner of Splunk for three years.
What do I think about the stability of the solution?
This solution is stable.
How are customer service and support?
Technical support is customer-friendly.
How was the initial setup?
The initial installation is not straightforward. It needs two or three days, depending on the size of the company. But it can be done with one senior engineer.
What about the implementation team?
I implemented through an in-house team.
What's my experience with pricing, setup cost, and licensing?
Splunk has a subscription and a perpetual license.
This product could use better pricing.
What other advice do I have?
I would rate Splunk a nine out of ten. I recommend this product to others who are considering implementing it.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
CEO at a tech services company with 11-50 employees
Simple to install, with good monitoring, and correlation capabilities
Pros and Cons
- "The scalability is good."
- "Splunk is appropriate for small to medium-sized projects, and it should be calculated for large projects."
- "In the next releases, I would like to see more pricing flexibility."
- "In my opinion, it is too expensive for our projects."
What is our primary use case?
We are resellers. We provide solutions to our clients.
Splunk is primarily used for developing CM solutions that are based on the Splunk platform for future security operation center development.
We are concentrating on assisting in the development of a security monitor as well as analysis.
If I am not mistaken, it's a standard CM system for identification, security verification, and event monitoring.
What needs improvement?
In my opinion, it is too expensive for our projects.
It is very competitive for small and medium businesses. Perhaps some should be set aside for developing markets. To begin with, similar to the current market, there may be some special conditions for large transactions.
In the next releases, I would like to see more pricing flexibility. It's a subscription-based service, and they don't sell professional licenses.
In some cases, particularly with large projects, we are not competitive in terms of pricing when compared to IBM QRadar and other solutions; even if we offer the maximum discount available, our prices remain uncompetitive.
For how long have I used the solution?
We have been selling Splunk for approximately five years.
What do I think about the scalability of the solution?
The scalability is good. It can be added on-demand in increments of one gigabyte or ten gigabytes. It's a per-gigabyte license, and you can add whatever you need at the time.
Our projects are sized per our current IT infrastructure.
Splunk is used by 10 of our customers.
How are customer service and support?
Our team provides technical support.
I have not communicated with technical support.
Which solution did I use previously and why did I switch?
We no longer resell Checkmarks.
We were unable to assist in establishing their business on-premises because It could have been too expensive for our clientele.
How was the initial setup?
Installing Splunk is not difficult, but it can be complicated in some cases.
The issue is the integration with the customer's system, as well as the configuration of the rules for correlation, log collecting, and analysis.
It has good documentation and guides, but the main works should be focused on customer needs and customer resources for monitoring.
It can take three months to complete the installation.
We have a team of three certified engineers who will deploy and maintain this solution.
What's my experience with pricing, setup cost, and licensing?
The licensing fees and pricing models could be reduced.
It's a yearly subscription.
They don't sell professionally because it's a subscription service. As a result, it is only a subscription service that is dependent on the customer's IT infrastructure.
What other advice do I have?
We do not sell Compliance Control Limited solutions because our focus is on auditing and independent security assessments. We put an end to our selling program with Checkmarks.
I would recommend this solution to others. Splunk is appropriate for small to medium-sized projects, and it should be calculated for large projects.
It's one of the best CM solutions on the market for monitoring, and correlation, as well as IT monitoring security.
I would rate Splunk an eight out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer. Reseller
Network Operations Center Engineer at a tech company with 51-200 employees
A stable and scalable solution which is easy to install and use and has good tech support
Pros and Cons
- "I am satisfied with the support."
- "I recommend the solution and plan to continue using it."
- "The price of the solution could be cheaper."
- "The price of the solution could be cheaper."
What is our primary use case?
We use the solution for monitoring systems. We also use it with servers and CG routers from the data center, as well as for collecting the ADL from all networks which are located in our regions of the country.
What is most valuable?
I like that the solution is easy to use and stable.
What needs improvement?
The price of the solution could be cheaper.
For how long have I used the solution?
I am currently working with Splunk and have a year's experience doing so.
What do I think about the stability of the solution?
The solution is stable.
What do I think about the scalability of the solution?
The solution is scalable.
How are customer service and support?
Support is at a level one department and I am responsible for managing both IT support and node engineers.
I am satisfied with the support.
How was the initial setup?
The solution is easy to install.
It took half a day.
What about the implementation team?
We were able to handle the installation on our own.
There are 40 people responsible for the deployment and maintenance of the solution, four of whom are engineers. There is a computer DE who is responsible for the engineering and a candidate for graduation in 2022.
What's my experience with pricing, setup cost, and licensing?
The solution could be more cost-effective, as we charge our customers the cheapest price.
The subscription is monthly.
What other advice do I have?
The solution is cloud-based.
There are more than a thousand users making use of the solution in our organization, who are connected with us in over 530 different areas.
I recommend the solution and plan to continue using it.
I rate Splunk as a seven out of ten.
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
Senior Technical Lead at a financial services firm with 10,001+ employees
Priced reasonably, effective log analysis, but artificial intelligence features need improvement
Pros and Cons
- "We have found all the features useful. However, the dashboarding and logging have been very helpful. Additionally, the log analysis does a great job."
- "We have found all the features useful. However, the dashboarding and logging have been very helpful."
- "The solution could improve by giving more email details."
- "The solution could improve by giving more email details."
What is most valuable?
We have found all the features useful. However, the dashboarding and logging have been very helpful. Additionally, the log analysis does a great job.
What needs improvement?
The solution could improve by giving more email details.
In a future release, the solution could improve on the artificial intelligence features, such as if an alert comes, it could automatically do logging from the system, get the KV knowledge base, and perform other functions. This would be a benefit.
For how long have I used the solution?
I have used Splunk for approximately five years.
How are customer service and support?
The technical support is good.
How was the initial setup?
The initial setup is complex.
What's my experience with pricing, setup cost, and licensing?
The price of Splunk is reasonable.
Which other solutions did I evaluate?
We have evaluated SoapUI and Postman, and we are still evaluating others.
What other advice do I have?
I rate Splunk a seven out of ten.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Telecom Tech at a university with 501-1,000 employees
Easy to configure with user-friendly alerts and good search functionality
Pros and Cons
- "We can easily configure things as required in relation to our use cases."
- "We enjoy the whole solution; it is meeting our requirements, especially the SIM solution."
- "From the commercial point of view, they have to bring down their costs."
- "From the commercial point of view, they have to bring down their costs. It's a bit pricey right now."
What is most valuable?
We enjoy the whole solution. It is meeting our requirements, especially the SIM solution.
The alerts are very user-friendly.
We can easily configure things as required in relation to our use cases.
The search functionality is good. It works like Google.
Onboarding is quite easy.
The scalability is good.
Product-wise, the performance is good.
What needs improvement?
From the commercial point of view, they have to bring down their costs. It's a bit pricey right now. The license is quite expensive.
Much like the SOAR platform, which has security, orchestration, and automation response, all of that should be part of the SIM solution itself. Currently, it is actually separated. We understand that we have to integrate a SIM with a SOAR platform, however, if they could combine these two products together, that would be ideal. It would make things easy to implement and make more automation possible to avoid false-positive alerts.
For how long have I used the solution?
We've been using the solution for the last four years. It's been a while.
What do I think about the stability of the solution?
The performance is good. It's stable. There are no bugs or glitches. It doesn't crash or freeze.
What do I think about the scalability of the solution?
The scalability of the solution is very good. If a company needs to expand, it can do so. It's easy.
What's my experience with pricing, setup cost, and licensing?
The solution can be expensive. It's not cheap.
What other advice do I have?
We are customers and end-users.
I'd rate the solution at a nine out of ten.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Buyer's Guide
Download our free Splunk Enterprise Security Report and get advice and tips from experienced pros
sharing their opinions.
Updated: March 2026
Product Categories
Security Information and Event Management (SIEM) Log Management IT Operations AnalyticsPopular Comparisons
CrowdStrike Falcon
IBM Security QRadar
Microsoft Sentinel
Splunk AppDynamics
Elastic Security
Grafana Loki
Elastic Observability
Palantir Foundry
Security Onion
WhatsUp Gold
Buyer's Guide
Download our free Splunk Enterprise Security Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- Which would you recommend to your boss, IBM QRadar or Splunk?
- What are some of the best features and use-cases of Splunk?
- What SOC product do you recommend?
- Splunk as an Enterprise Class monitoring solution -- thoughts?
- What is the biggest difference between Dynatrace and Splunk?
- IBM QRadar is rated above competitors (McAfee, Splunk, LogRhythm) in Gartner's 2020 Magic Quandrant. Agree/Disagree?
- What are the advantages of ELK over Splunk?
- How does Splunk compare with Azure Monitor?
- New risk scoring framework in the Splunk App for Enterprise Security -- thoughts?
- Splunk vs. Elastic Stack















