I use this solution for data visualization.
Product Manager, FX Solutions at a tech services company with 10,001+ employees
Easy to use, informative documentation for data retrieval, and easy to install
Pros and Cons
- "The most valuable features of the solution are it is straightforward to use and the documentation is good for finding out how to get the data you are looking for."
- "The most valuable features of the solution are it is straightforward to use and the documentation is good for finding out how to get the data you are looking for."
- "The solution could improve by making it more business analysis oriented. The way it is now is designed more for developers."
- "The solution could improve by making it more business analysis oriented. The way it is now is designed more for developers."
What is our primary use case?
What is most valuable?
The most valuable features of the solution are it is straightforward to use and the documentation is good for finding out how to get the data you are looking for.
What needs improvement?
The solution could improve by making it more business analysis oriented. The way it is now is designed more for developers.
For how long have I used the solution?
I have been using Splunk for two weeks.
Buyer's Guide
Splunk Enterprise Security
April 2026
Learn what your peers think about Splunk Enterprise Security. Get advice and tips from experienced pros sharing their opinions. Updated: April 2026.
894,668 professionals have used our research since 2012.
What do I think about the stability of the solution?
The solution is stable, I have not experienced any bugs or glitches.
What do I think about the scalability of the solution?
The solution is scalable and it is a requirement of my company to have scalable solutions.
Which solution did I use previously and why did I switch?
I have used previously Qlik Sense and Kibana.
How was the initial setup?
I did the training with Slunk and once I had the training the installation was easy.
Which other solutions did I evaluate?
I have evaluated Tableau.
What other advice do I have?
My advice to others is not to be intimidated by the solution and to give it a try. It will become easier over time.
I rate Splunk an eight out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Technical Account Manager at Trustaira
Straightforward to set up with great integration capabilities and a high level of maturity
Pros and Cons
- "The solution has proven to be quite stable."
- "This solution is the best security solution."
- "The product is relatively expensive."
- "The problem with the product is that the price of Splunk is very high."
What is our primary use case?
We primarily use the solution for monitoring and security.
We can use the solution to try to find some correlational data. For example, in banks, there is usually a protocol whereby users cannot withdraw more than a certain amount of money from an ATM. However, we find that, when people are on holiday, they are trying to withdraw more than the allowed amount. It's a use case we can deploy in our country. You can set certain rules and watch the data in order to gain insights.
How has it helped my organization?
I cannot speak to a specific example of how the solution has assisted our organization.
What is most valuable?
The solution's capability is its most valuable aspect.
The initial setup is very straightforward.
The solution has proven to be quite stable.
We've found the solution to be very mature.
The integration capabilities are excellent. They have apps that integrate quite well with Palo Alto and Cisco, for example.
What needs improvement?
Sometimes it becomes very difficult to find certain results from Splunk. Not all users are developers and they are not able to write code to find specific results or specific details from Splunk. From a user perspective, the solution needs to improve the search functionality.
The dashboard could be improved. If it was easier for non-developers or those working in network security, it would be ideal. It would be nice if they had a built-in dashboard for those who are less knowledgeable in coding.
The product is relatively expensive.
For how long have I used the solution?
I haven't been using the solution for very long just yet.
What do I think about the stability of the solution?
The solution is very stable. There are no bugs or glitches. It doesn't crash or freeze. It's reliable.
What do I think about the scalability of the solution?
We do not plan to increase usage at this time.
How are customer service and technical support?
We've used technical support in the past. We've found them to be very helpful and responsive. We're satisfied with the level of support that we receive when we reach out for help.
Which solution did I use previously and why did I switch?
I've previously used LogRhythm, among other solutions. We sell a few different solutions.
How was the initial setup?
The initial setup is not too difficult. It's not overly complex. It's straightforward. The code is very easy.
The deployment took two or three months or so.
What about the implementation team?
We used an integrator to assist us in the initial setup.
What's my experience with pricing, setup cost, and licensing?
The problem with the product is that the price of Splunk is very high. It is an industry leader and therefore it's high in terms of price. That is the issue in our country. Sometimes people want to buy Splunk, however, due to the budget, they are not able to.
What other advice do I have?
We are resellers.
We use a variety of deployment models, including private cloud and hybrid.
This solution is the best security solution. If a company is looking for the best, they have to buy Splunk. It is a very good and very mature solution. It is very easy to integrate with some other service or security solutions. If they have specific solutions that need to be integrated for monitoring purposes, it should be a problem. For example, it integrates very well with Cisco.
I'd rate the solution at a ten out of ten. We are quite happy with its capabilities.
Which deployment model are you using for this solution?
Private Cloud
Disclosure: My company has a business relationship with this vendor other than being a customer. Reseller
Buyer's Guide
Splunk Enterprise Security
April 2026
Learn what your peers think about Splunk Enterprise Security. Get advice and tips from experienced pros sharing their opinions. Updated: April 2026.
894,668 professionals have used our research since 2012.
Security Professional at a tech services company with 51-200 employees
Good data analysis and visualizations, absolutely stable, and scalable
Pros and Cons
- "The data analysis part is good in Splunk, which is something that I like the most. It is also quite easy to use. Its dashboards, visualizations, and analytics are good."
- "The data analysis part is good in Splunk, which is something that I like the most, and it is also quite easy to use, with dashboards, visualizations, and analytics that are good."
- "It currently has limited default rules and customizations. If they can concentrate more on the compliance part and the security information part, it would be helpful. The platform part is good, but it requires many features from the security aspect."
- "It currently has limited default rules and customizations. If they can concentrate more on the compliance part and the security information part, it would be helpful."
What is our primary use case?
We are using it for security information and event management (SIEM). We have started to use Splunk recently, and we are in the implementation phase as of now.
What is most valuable?
The data analysis part is good in Splunk, which is something that I like the most. It is also quite easy to use. Its dashboards, visualizations, and analytics are good.
What needs improvement?
It currently has limited default rules and customizations. If they can concentrate more on the compliance part and the security information part, it would be helpful. The platform part is good, but it requires many features from the security aspect.
For how long have I used the solution?
I have been using this solution for a couple of months.
What do I think about the stability of the solution?
It is absolutely stable.
What do I think about the scalability of the solution?
It is scalable. We have approximately 25 users.
How was the initial setup?
It was easy to install. Its configuration and development are the critical parts, and there are a limited number of people in the market with such a skill set. It takes some time to find people with the right skill set and get it implemented properly. It took approximately three months.
What about the implementation team?
I have a team of a few Splunk consultants who are currently managing it for me. For a mid-sized organization, at least 15 persons are required to manage the entire Splunk instance.
What other advice do I have?
I would recommend this solution to others. I would rate Splunk an eight out of ten.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Consultant at a financial services firm with 5,001-10,000 employees
Good scalability, dashboards, and alarms, but should have a default dashboard for a firewall and better knowledge base
Pros and Cons
- "Its dashboard is valuable. If you have a good knowledge of how to create a dashboard, you can create any dashboard related to cybersecurity. If fine-tuned, the alarms that are triggered for instant review are also very valuable and useful."
- "Its dashboard is valuable, and if you have a good knowledge of how to create a dashboard, you can create any dashboard related to cybersecurity, and if fine-tuned, the alarms that are triggered for instant review are also very valuable and useful."
- "Splunk is query-based, which is not the case with most cybersecurity tools. It is based on search queries and can be difficult to use. It would be good if they can make it easier to understand how to create search queries. They can improve the knowledge base for better understanding. To create your dashboard, you need to have a search query. We have multiple firewalls in our company, and we need a dashboard for them. It would be helpful if a default firewall dashboard is included in Splunk to make monitoring easier. If a dashboard is available for a security device, the operation part will be more efficient. We won't have to follow a manual process for this."
- "Splunk is query-based, which is not the case with most cybersecurity tools. It is based on search queries and can be difficult to use."
What is our primary use case?
We are using Splunk for cybersecurity operations.
What is most valuable?
Its dashboard is valuable. If you have a good knowledge of how to create a dashboard, you can create any dashboard related to cybersecurity. If fine-tuned, the alarms that are triggered for instant review are also very valuable and useful.
What needs improvement?
Splunk is query-based, which is not the case with most cybersecurity tools. It is based on search queries and can be difficult to use. It would be good if they can make it easier to understand how to create search queries. They can improve the knowledge base for better understanding.
To create your dashboard, you need to have a search query. We have multiple firewalls in our company, and we need a dashboard for them. It would be helpful if a default firewall dashboard is included in Splunk to make monitoring easier. If a dashboard is available for a security device, the operation part will be more efficient. We won't have to follow a manual process for this.
For how long have I used the solution?
I have been using this solution for eight months.
What do I think about the stability of the solution?
In terms of operations, it is stable, but if you don't have a proper configuration and sizing, there could be many issues. It could be more efficient on the storage part. We are still in the deployment stage to be able to say that for sure.
What do I think about the scalability of the solution?
It is very scalable. Currently, we have around 50 users. We will increase its usage if more people need access.
How are customer service and technical support?
We have raised multiple tickets. Some of them are good, and some of them can be better. Overall, their technical support is okay.
Which solution did I use previously and why did I switch?
We didn't use any other solution.
How was the initial setup?
I didn't do the initial configuration. I take care of the operations part. One of our clients did it, and it is somehow complex, and it takes time. It also depends on your knowledge. If you don't have knowledge of Splunk, it is complex.
Which other solutions did I evaluate?
We are a partner of Splunk. So, we did not evaluate other solutions.
What other advice do I have?
I would rate Splunk a seven out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
Product Manager, CyberSecurity at a tech services company with 201-500 employees
Has good security features but needs a better pricing model
Pros and Cons
- "The initial setup isn't overly complex."
- "Because I'm security focused, I prefer the security features such as Splunk Phantom and Splunk Enterprise Security."
- "Splunk can be an expensive solution. Technical support could be improved as well."
- "The technical support here in South Africa hasn't been great, but I understand why as we make up less than 3% of Splunk's total revenue in the world."
What is most valuable?
Because I'm security focused, I prefer the security features such as Splunk Phantom and Splunk Enterprise Security.
What needs improvement?
We need to get a Splunk Cloud instance inside South Africa's borders. At this stage, we are pushing Splunk Cloud, but it is not yet within South Africa's borders. So we've got data sovereignty issues, especially with government organizations.
Technical support could be improved as well.
Splunk can be an expensive solution. I think that they need to change their pricing model. At present, it is based on the number of gigabytes that you ingest into the Splunk system. Their competitors are now starting with a pricing model where you pay per device talking back. If Splunk could have a similar alternative, it would then allow people to choose the data model they want such as set data or a set number of devices.
For how long have I used the solution?
I have been using Splunk for three years.
How are customer service and technical support?
The technical support here in South Africa hasn't been great, but I understand why as we make up less than 3% of Splunk's total revenue in the world.
How was the initial setup?
The initial setup isn't overly complex, but it's not easy either.
What's my experience with pricing, setup cost, and licensing?
The pricing model is based on the number of gigabytes that you ingest into the Splunk system. So it can be an expensive solution.
What other advice do I have?
Plan your requirements properly from the beginning so that you can get the most value in a shorter space of time.
On a scale from one to ten, I would rate Splunk at six.
Disclosure: My company has a business relationship with this vendor other than being a customer. reseller
Senior Information Technology System Analyst at YASH Technologies
Impressive UI, many useful features, and very scalable, but needs alerting feature and better pricing and integration
Pros and Cons
- "There are quite a lot of things that we find useful. Splunk agents are useful and good. Its UI is quite impressive."
- "There are quite a lot of things that we find useful; Splunk agents are useful and good, and its UI is quite impressive."
- "Its pricing model and integration with third-party services can be improved. We had faced an issue with integration. The alerting feature is currently not available with Splunk, but it is definitely available with Datadog and PagerDuty. They should include this feature. A few dashboards in Splunk look quite old and are not that modern. They aren't bad, but improving these dashboards will definitely make Splunk more attractive and usable. I read in a few blog posts that there were a few security incidents related to Splunk agents. So, it can be made more secure."
- "A few years ago, I would have definitely recommended Splunk, but nowadays, better alternatives are available."
What is most valuable?
There are quite a lot of things that we find useful. Splunk agents are useful and good. Its UI is quite impressive.
What needs improvement?
Its pricing model and integration with third-party services can be improved. We had faced an issue with integration.
The alerting feature is currently not available with Splunk, but it is definitely available with Datadog and PagerDuty. They should include this feature.
A few dashboards in Splunk look quite old and are not that modern. They aren't bad, but improving these dashboards will definitely make Splunk more attractive and usable.
I read in a few blog posts that there were a few security incidents related to Splunk agents. So, it can be made more secure.
For how long have I used the solution?
I have been using this solution for almost two years. I am using its latest version.
What do I think about the stability of the solution?
It is a stable product.
What do I think about the scalability of the solution?
Splunk is definitely scalable.
How are customer service and technical support?
I have not interacted with them. Another team is taking care of raising tickets with their technical support.
How was the initial setup?
It is quite simple.
What's my experience with pricing, setup cost, and licensing?
Its pricing model can be improved.
What other advice do I have?
A few years ago, I would have definitely recommended Splunk, but nowadays, better alternatives are available. We are currently exploring a few other alternatives, so I won't recommend Splunk as of now.
I would rate Splunk a seven out of ten.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Information Security Analyst at a tech services company with 1,001-5,000 employees
Good integration, easy UI, and very stable and scalable
Pros and Cons
- "Its integration is most valuable. Its UI is also pretty much easy."
- "Its integration is most valuable, and its UI is also pretty much easy."
- "Its setup is a little bit complex for a distributed environment. Their support can also be better. If we miss the response for more than a week, they usually close the case. Sometimes, it can take us more than a week to reply."
- "Its setup is a little bit complex for a distributed environment."
What is most valuable?
Its integration is most valuable. Its UI is also pretty much easy.
What needs improvement?
Its setup is a little bit complex for a distributed environment.
Their support can also be better. If we raise a case with Splunk support and by any chance we missed to respond for more than a week, they usually close the case. Sometimes, it can take us more than a week to reply. In that case What they can do is they can send a followup mail before closing.
For how long have I used the solution?
I have been using this solution for a year now.
What do I think about the stability of the solution?
It is very stable haven't encounter any glitches or bugs till now.
What do I think about the scalability of the solution?
It is very much scalable. I am acting as an admin, and we have more than a hundred users of this solution in our company. We use it on a regular basis. We currently don't have any plan to increase its usage.
How are customer service and technical support?
I would rate them an eight out of ten. Their response speed is okay, but if, by any chance, we miss the response for more than a week, they usually close the case. Sometimes, it can take us more than a week to reply.
Which solution did I use previously and why did I switch?
This is the only solution that we have been using.
How was the initial setup?
Its setup is pretty much easy for standalone, but for a distributed environment, it is a little bit complex.
What other advice do I have?
I would recommend this solution to others, but it should meet their needs and architecture.
I would rate Splunk a nine out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Solutions Consultant at a tech services company with 1,001-5,000 employees
Easy to use, provides a lot of analytics, and allows you to do pretty much whatever you want
Pros and Cons
- "It provides a lot of analytics with the underlying AI engine, and it is a lot easier than other solutions. There are some products that do automated AI-based detection and drawing up charts, but for network monitoring and all of the monitoring aspects, it is quite a nice tool. It is very convenient for business users because they get more or less a lot of data readily available. If you're familiar with the Splunk query language, you can pretty much do whatever you want."
- "It provides a lot of analytics with the underlying AI engine, and it is a lot easier than other solutions."
- "If you have to do your own stuff, such as customized charts, it is a little bit more work, but once you're familiar with the Splunk query language, you can pretty much do whatever you want. In terms of features, it should probably have the features that other competitors provide."
- "If you have to do your own stuff, such as customized charts, it is a little bit more work, but once you're familiar with the Splunk query language, you can pretty much do whatever you want."
What is most valuable?
It provides a lot of analytics with the underlying AI engine, and it is a lot easier than other solutions. There are some products that do automated AI-based detection and drawing up charts, but for network monitoring and all of the monitoring aspects, it is quite a nice tool.
It is very convenient for business users because they get more or less a lot of data readily available. If you're familiar with the Splunk query language, you can pretty much do whatever you want.
What needs improvement?
If you have to do your own stuff, such as customized charts, it is a little bit more work, but once you're familiar with the Splunk query language, you can pretty much do whatever you want. In terms of features, it should probably have the features that other competitors provide.
For how long have I used the solution?
I have been using this solution for about three to four months.
What do I think about the scalability of the solution?
I'm not sure. I do not really throw a lot of data in it, but it has been authenticated very nicely. It manages indexes and all of these things very nicely. I have not been privy to any production systems where you have millions of lines of log coming in every second. It works very well for the data that I have. It should be able to handle a lot of data. That's the whole purpose of it, and that's why Splunk has become so popular. It is an enterprise monitoring tool, and a lot of customers have Splunk in their ecosystem.
How are customer service and technical support?
They have pretty much good documentation and good training. Their documentation is a lot better than Qlik Sense.
Which solution did I use previously and why did I switch?
Splunk is an enterprise monitoring tool. Qlik Sense can do a little bit of log monitoring, but it is mostly used for dashboard reporting, whereas Splunk is more around monitoring and figuring out threats and all such things. They are different, but both deal with the data and allow you to create operation reports.
Power BI is another tool that a lot of our customers use, but Splunk is quite often requested. It is also a lot more popular than Qlik Sense. We have a fair number of Qlik Sense customers.
We usually sell Blue Prism to business users who are more concerned with the reporting aspect, which is why they would like to have easy tools like Qlik Sense in their ecosystem, but on the infrastructure side, it would be Splunk for enterprise monitoring.
How was the initial setup?
Simple environments are easier to install. Because there is a lot of data log monitoring, once you have a production system, there is some amount of work in setting it up, especially making it SSL Secure and exposing it on the internet. There are multiple components behind it, so you need to ensure that all these things are set up correctly. These kinds of things are not required on a cloud platform because you are just uploading data. You really don't have much access to the backend.
Splunk also has a cloud version, which I haven't looked at, but I have used Qlik Sense's cloud platforms. With on-premises, you are in control of pretty much how you set up all the data that you are sending out. A lot of our customers have the issue that if it is a cloud platform, they cannot really send out the data to any of these cloud platforms. So, there are data residence and other issues.
What's my experience with pricing, setup cost, and licensing?
It is economical than other solutions.
What other advice do I have?
I would definitely recommend Splunk. It is quite a decent tool, and it is there in a lot of enterprises.
I would rate Splunk an eight out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer. partner
Buyer's Guide
Download our free Splunk Enterprise Security Report and get advice and tips from experienced pros
sharing their opinions.
Updated: April 2026
Product Categories
Security Information and Event Management (SIEM) Log Management IT Operations AnalyticsPopular Comparisons
CrowdStrike Falcon
IBM Security QRadar
Microsoft Sentinel
Splunk AppDynamics
Elastic Security
IBM Turbonomic
Palantir Foundry
WhatsUp Gold
Grafana Loki
Elastic Observability
Buyer's Guide
Download our free Splunk Enterprise Security Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- Which would you recommend to your boss, IBM QRadar or Splunk?
- What are some of the best features and use-cases of Splunk?
- What SOC product do you recommend?
- Splunk as an Enterprise Class monitoring solution -- thoughts?
- What is the biggest difference between Dynatrace and Splunk?
- IBM QRadar is rated above competitors (McAfee, Splunk, LogRhythm) in Gartner's 2020 Magic Quandrant. Agree/Disagree?
- What are the advantages of ELK over Splunk?
- How does Splunk compare with Azure Monitor?
- New risk scoring framework in the Splunk App for Enterprise Security -- thoughts?
- Splunk vs. Elastic Stack














