No more typing reviews! Try our Samantha, our new voice AI agent.
PeerSpot user
Systems Analyst Staff - SW Eng Compute Analytics Lead at Qualcomm
Real User
Apr 24, 2018
Allows for transparency into IT metrics for insightful business analytics
Pros and Cons
  • "It allows for transparency into IT metrics for insightful business analytics."
  • "It has the ability to correlate data, analyze and review it."
  • "It brings together all sorts of data and has the ability to correlate data, analyze and review it, making weekly ops reviews and monthly executive management reporting much easier by saving hours of collecting data, with report automation being a life saver."
  • "It needs more formatting control without having to be an admin."
  • "Free-floating panels in the dashboards are like a glass table. It needs more formatting control without having to be an admin."

What is our primary use case?

IT service analytics: 

  • Server machine data
  • Monitoring data
  • Alerting data
  • ITSI KPIs
  • Real-time reporting
  • Month-over-month reporting.

How has it helped my organization?

It allows for transparency into IT metrics for insightful business analytics.

What is most valuable?

It brings together all sorts of data. It has the ability to correlate data, analyze and review it. This makes weekly ops reviews and monthly executive management reporting much easier by saving hours of collecting data. Report automation has been a life saver.

What needs improvement?

  • Free-floating panels in the dashboards are like a glass table. 
  • It needs more formatting control without having to be an admin.
Buyer's Guide
Splunk Enterprise Security
July 2026
Learn what your peers think about Splunk Enterprise Security. Get advice and tips from experienced pros sharing their opinions. Updated: July 2026.
909,647 professionals have used our research since 2012.

For how long have I used the solution?

Three to five years.

Which solution did I use previously and why did I switch?

Previously, only the service owner could see the data and he might have gone to several places to obtain it. Now, it is all in one place and easy to access. 

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Mick - PeerSpot reviewer
Sr. Production Support Analyst at Electric Reliability Council of Texas
User
Apr 24, 2018
Quickly searches logs, performance data, and other inputs to assist with troubleshooting
Pros and Cons
  • "The ability to quickly search logs, performance data, and other inputs has helped tremendously with troubleshooting."

    What is our primary use case?

    Operational intelligence monitoring for several different systems. We collect logs from applications and performance data from hardware, as well as information pulled from databases.

    How has it helped my organization?

    The ability to quickly search logs, performance data, and other inputs has helped tremendously with troubleshooting. The visualizations are easy and well received by business and management users. 

    What is most valuable?

    It is ease to integrate with other solutions, like Slack, JIRA, Remedy, etc. 

    For how long have I used the solution?

    Three to five years.

    How is customer service and technical support?

    The user community is extremely beneficial, particularly with Splunk Answers and the Slack User Groups.

    What's my experience with pricing, setup cost, and licensing?

    The licensing model can be expensive, but the value it provides is significant.

    What other advice do I have?

    The recent acquisition of Phantom makes the future seem bright with more automated responses.

    Disclosure: My company does not have a business relationship with this vendor other than being a customer.
    PeerSpot user
    Buyer's Guide
    Splunk Enterprise Security
    July 2026
    Learn what your peers think about Splunk Enterprise Security. Get advice and tips from experienced pros sharing their opinions. Updated: July 2026.
    909,647 professionals have used our research since 2012.
    PeerSpot user
    Business Intelligence Engineer at SONIFI Solutions, Inc.
    Real User
    Apr 24, 2018
    Allows us to dig into raw events
    Pros and Cons
    • "Splunk allows us to find insights that we were not able to with traditional BI tools using ETL​. It allows us to dig into raw events."
    • "Splunk is extremely flexible, which allows us to create custom visualizations along with other customizations."
    • "The flexibility of Splunk as well as the resources available for learning and support are the best in the business."
    • "The product was designed for security and IT with business intelligence needs, such as PDF exporting, but this has not been the highest priority. While the functionality is there, it could be developed more."

    What is our primary use case?

    Primary use is business intelligence. 

    How has it helped my organization?

    Splunk allows us to find insights that we were not able to with traditional BI tools using ETL. It allows us to dig into raw events. 

    What is most valuable?

    Splunk is extremely flexible, which allows us to create custom visualizations along with other customizations. The flexibility of Splunk as well as the resources available for learning and support are the best in the business. 

    What needs improvement?

    The product was designed for security and IT with business intelligence needs, such as PDF exporting, but this has not been the highest priority. While the functionality is there, it could be developed more. 

    For how long have I used the solution?

    More than five years.

    What do I think about the scalability of the solution?

    We ingest roughly 30GB/day. We have a small environment, but it provides big insights. 

    Disclosure: My company does not have a business relationship with this vendor other than being a customer.
    PeerSpot user
    PeerSpot user
    Director of IT at BLUE LAKE RANCHERIA
    Real User
    Apr 24, 2018
    Aggregation searches have reduced time and difficulty of identifying trends and conditions which need to reviewed
    Pros and Cons
    • "Splunk has significantly reduced the time in performing the task of aggregating logs, reviewing as well as time spent during investigations."
    • "Aggregation searches have reduced time and difficulty of identifying trends and conditions which need to reviewed."
    • "The case management area of the ES could be improved. The ability to move cases through various stages and states, and the ability to close a case, would be a key improvement."

    What is our primary use case?

    We primary use Splunk for log aggregation and search across multiple systems with Splunk Enterprise Security layered on top. 

    How has it helped my organization?

    Splunk has significantly reduced the time in performing the task of aggregating logs, reviewing as well as time spent during investigations. This has not only
    increased our speed of response, but our efficiency dealing with the issue(s)
    raised.

    What is most valuable?

    Aggregation searches, allowing for conditions to be automatically found in the data, have reduced time and difficulty of identifying trends and conditions which need to reviewed.

    What needs improvement?

    The case management area of the ES could be improved. The ability to move cases through various stages and states. The ability to close a case would be key improvement.

    For how long have I used the solution?

    One to three years.
    Disclosure: My company does not have a business relationship with this vendor other than being a customer.
    PeerSpot user
    PeerSpot user
    Information Security Engineer/Architect at The Church of Jesus Christ of Latter-day Saints
    Real User
    Apr 24, 2018
    Helped us consolidate all our solutions into an easy tool to use for various employees
    Pros and Cons
    • "It helped us consolidate all our solutions into an easy tool to use for various employees."
    • "Splunk is one of the top SIEM solutions to work with."
    • "More control with Splunk Cloud as it seems a bit limited. I used to manage an on-premise instance of Splunk Enterprise and really liked having more control over it."

    What is our primary use case?

    We use Splunk for operations, application monitoring, and security. We are both cloud and on-premise based, so it has been very versatile for us. 

    How has it helped my organization?

    It helped us consolidate all our solutions into an easy tool to use for various employees.

    What is most valuable?

    • Unstructured data
    • Linking things together
    • Building out stuff which is actionable.

    Once you learn SPL and what data you need to obtain and merge together, it is really useful. 

    What needs improvement?

    More control with Splunk Cloud as it seems a bit limited. I used to manage an on-premise instance of Splunk Enterprise and really liked having more control over it. 

    For how long have I used the solution?

    More than five years.

    What do I think about the stability of the solution?

    No stability issues.

    What do I think about the scalability of the solution?

    No scalability issues.

    Which solution did I use previously and why did I switch?

    While we did not have a previous solution, we took what little of Splunk that we have been using and have increased it greatly.

    What was our ROI?

    We are a nonprofit, so it is hard to quantify. 

    What's my experience with pricing, setup cost, and licensing?

    Be upfront about your needs and expectations. Splunk is one of the top SIEM solutions to work with. 

    Which other solutions did I evaluate?

    No.

    Disclosure: My company does not have a business relationship with this vendor other than being a customer.
    PeerSpot user
    it_user859770 - PeerSpot reviewer
    consultant at a non-profit with 1,001-5,000 employees
    User
    Apr 24, 2018
    Easily tracks problems and their status
    Pros and Cons
    • "I like the ease with which dashboards can be created."
    • "Splunk has give us the capability to easily track problems and their status."
    • "The only thing which can be improved is that they are too subjective on whom their Splunk4Good initiative can be applied. They market it as you only need to be a nonprofit, but there is more to it."

    What is our primary use case?

    We use Splunk for both monitoring and SIEM. Our security operations group uses Splunk to track user accounts which may have been compromised as well as follow those accounts through the organization.

    How has it helped my organization?

    Splunk has give us the capability to easily track problems and their status. Our security operations team has been able to use it to track where people login and what they do on those machines.

    What is most valuable?

    Personally, I like the capability of removing sensitive data before it goes into Splunk. I also like the ease with which dashboards can be created.

    What needs improvement?

    I like Splunk. The only thing which can be improved is that they are too subjective on whom their Splunk4Good initiative can be applied. They market it as you only need to be a nonprofit, but there is more to it.

    For how long have I used the solution?

    More than five years.
    Disclosure: My company does not have a business relationship with this vendor other than being a customer.
    PeerSpot user
    PeerSpot user
    Splunk Architect at The Johns Hopkins University Applied Physics Laboratory
    Real User
    Apr 24, 2018
    Speeds up root cause analysis and can help identify issues
    Pros and Cons
    • "Speeds up root cause analysis and can help identify issues that your organization never realized were occurring."
    • "It helps streamline troubleshooting and log analysis."
    • "It has a low barrier to entry, but it is extremely extensible, allowing it to be tailored to highly specific use cases."
    • "​On the technical side, it would be nice to see aspects of the recent acquisition of Phantom make it into the core Splunk Enterprise, not just become a part of the premium Enterprise Security.​"
    • "It can be tough to determine if you are getting all of the value out of your investment at times."

    What is our primary use case?

    Central repository for log collection and analysis in a complex environment. We have used it for a variety of use cases involving SIEM and operational support.

    How has it helped my organization?

    Speeds up root cause analysis and can help identify issues that your organization never realized were occurring. It helps streamline troubleshooting and log analysis.

    What is most valuable?

    It has a low barrier to entry, but it is extremely extensible, allowing it to be tailored to highly specific use cases. It makes searching through a wider variety of logs much quicker and enables you to correlate events from one log to another.

    What needs improvement?

    It can be tough to determine if you are getting all of the value out of your investment at times. However, our sales seems to be flexible and will work on an organization to organization basis to negotiate license terms. 

    For how long have I used the solution?

    One to three years.

    How is customer service and technical support?

    On the technical side, it would be nice to see aspects of the recent acquisition of Phantom make it into the core Splunk Enterprise, not just become a part of the premium Enterprise Security.

    What's my experience with pricing, setup cost, and licensing?

    Pricing can be a limiting factor. You have to continuously tune what you are bringing in and make sure what you bring in is of value. 

    Disclosure: My company does not have a business relationship with this vendor other than being a customer.
    PeerSpot user
    PeerSpot user
    BS Systems Engineer at a tech services company with 501-1,000 employees
    Real User
    Apr 16, 2018
    Makes use of all logs and takes proactive actions
    Pros and Cons
    • "Integrity with many vendors: This simplifies the implementation and integration with different devices"
    • "It helps the IT staff to monitor the full structure and makes use of all logs to take proactive actions."
    • "Enterprise security: Splunk must work on clarifying the solution to customers and explain how to gain more from it."

    What is our primary use case?

    We used it to create a full security operations center (SOC) for our IT department by adding all network and security devices, the AD, and mail servers to it. Then Splunk started to receive their logs, it analyzed them, and provided useful reports.  

    How has it helped my organization?

    It helps the IT staff to monitor the full structure. It also makes use of all logs and takes proactive actions.

    What is most valuable?

    Integrity with many vendors: This simplifies the implementation and integration with different devices. 

    What needs improvement?

    Enterprise security: Splunk must work on clarifying the solution to customers and explain how to gain more from it.

    For how long have I used the solution?

    One to three years.
    Disclosure: My company has a business relationship with this vendor other than being a customer. We are a partner with Splunk.
    PeerSpot user
    PeerSpot user
    System Administrator at Abdullah Al-Othaim Markets
    Real User
    Apr 15, 2018
    Searches logs from all devices and gives valuable information to the organisation
    Pros and Cons
    • "Alerts when a server is malfunctioning, monitors external attacks, and takes action to stop spreading viruses."
    • "Searches logs from all devices and gives valuable information to the organisation, so it can drill down on all reports and security threats."
    • "Make it easy to use and the cost cheaper. This will help all organisations to implement Splunk."

    What is our primary use case?

    • Searches the logs for all network devices and server. 
    • Monitors clients' hardware, networking, and security operations. 
    • It is good for the administrator to use it when maintaining the whole IT Infrastructure.

    How has it helped my organization?

    Alerts when a server is malfunctioning, monitors external attacks, and takes action to stop spreading viruses.

    What is most valuable?

    Searches logs from all devices and gives valuable information to the organisation, so it can drill down on all reports and security threats. 

    What needs improvement?

    Make it easy to use and the cost cheaper. This will help all organisations to implement Splunk

    Network Breach

    No, we have not suffered a network breach.

    Efficiency of Security Team

    Yes, the solution has improved the efficiency of our security team.

    For how long have I used the solution?

    Trial/evaluations only.

    What do I think about the stability of the solution?

    No stability issues.

    What do I think about the scalability of the solution?

    No scalability issues.

    How are customer service and technical support?

    I have received a very good response from support that I have not seen in more than 10 years of my experience. 

    Which solution did I use previously and why did I switch?

    We are using OpManager to monitor server logs. 

    What about the implementation team?

    I implemented it myself.

    What was our ROI?

    It made our organization better through integration.

    What's my experience with pricing, setup cost, and licensing?

    Make it cheaper to help small organisations implement it easier. 

    Which other solutions did I evaluate?

    We evaluated QRadar.

    What other advice do I have?

    I have been using Splunk to increase my security experience. 

    Disclosure: My company does not have a business relationship with this vendor other than being a customer.
    PeerSpot user
    MS Alam - PeerSpot reviewer
    MS AlamSystem Administrator at a retailer with 5,001-10,000 employees
    Real User

    splunk is google for all logs in organisation.

    PeerSpot user
    Infrastructure Engineer at Zirous, Inc.
    Real User
    Top 10
    Jan 17, 2018
    Monitors all machine logins and actions taken on those machines under each user
    Pros and Cons
    • "The ability to view all of these different logs, then drilling down into specific times or into specific data sources, has proved to be the greatest aspect in decreasing our troubleshooting overhead time."
    • "We did not encounter any issues with scalability. It is almost seamless to add new index (storage) or search (used to analyze the data) nodes to the cluster."
    • "Immensely, I cannot stress enough the positive impact this has had on our security team."
    • "I feel as though a major focus of upcoming releases should be set on Machine Learning, Predictive Analytics, and I would enjoy to see more security focused add-ons and apps developed by the vendor."

    What is our primary use case?

    Our primary use case of Splunk has been on the implementation side for clients. Splunk has proven, on multiple occasions, to be extremely useful in the proactive monitoring of clients' hardware, networking, and security operations. Some use cases that we have implemented include, but are not limited to, proactive account lockouts based on machine learning of a typical person's average number of failed login attempts, aggregation of a servers logs in order to predict downtime/maintenance/hardware failures quite accurately, as well as helping administrators of all sorts to gain a full picture of their environments under a single screen.

    How has it helped my organization?

    Splunk has helped our organization mainly on our increased use of the security side. We use Splunk to monitor all machine logins (both successful and unsuccessful) and actions taken on those machines under each user. We have set up some predictive and proactive models, which are programmed to take action on anything outside of the normal usage. These actions range from alerts being sent to the Splunk page, administrators being notified, and if escalated enough, automatic account locks.

    What is most valuable?

    The ability to view all of these different logs, then drilling down into specific times or into specific data sources, has proved to be the greatest aspect in decreasing our troubleshooting overhead time. The added security has proven effective as well, but given that we have not yet created the perfect model, we still find ourselves striving to develop a more efficient and predictive security analysis and action plan within Splunk.

    What needs improvement?

    Splunk has continually been increasing its features and also expanding and perfecting its core functionality. I would like to see it to continue to improve its predictive analytics and machine learning tools. It is not to be said that they are currently lacking, I don't believe it is, but given the current state and direction of the Information Technology world, I feel as though a major focus of upcoming releases should be set on Machine Learning, Predictive Analytics, and I would enjoy to see more security focused add-ons and apps developed by the vendor.

    Network Breach

    We did about a year and a half ago. The implementation was able to notify me 34 seconds after the initial breach had happened, but our implementation was already configured to auto-logout any "suspicious" users (our internal networking team had set this detection code up) which alleviated the problem, before it really became a problem for us.

    Efficiency of Security Team

    Immensely, I cannot stress enough the positive impact this has had on our security team.

    Events per Day

    Our personal implementation brings in only around 48GB to 48.5GB of events per day. Depending on the amount of remote workers in the office, it averages around 50 million events daily.

    For how long have I used the solution?

    One to three years.

    What do I think about the stability of the solution?

    We did not encounter any issues with stability.

    What do I think about the scalability of the solution?

    We did not encounter any issues with scalability. It is almost seamless to add new index (storage) or search (used to analyze the data) nodes to the cluster.

    How are customer service and technical support?

    I have not personally dealt with customer service/technical support.

    Which solution did I use previously and why did I switch?

    We did not use a different solution before. The closest thing that we would have done to this would have been personally scraping logs reactively, which cost us roughly two to three hours per issue that arose purely through log searching and remediation.

    How was the initial setup?

    The initial setup is very straightforward, unzipping a tar, creating a service, starting the service.

    What about the implementation team?

    My team was the team who had set up this implementation. I would be remiss if I didn't say that our level of expertise is quite high with an average of 4 Splunk certifications per person on my team.

    What was our ROI?

    ROI is estimated at saving my team roughly 10 to 12 man hours per week in troubleshooting for our company as well as what our profits had been from our services of installing, configuring, and supporting other clients with the product.

    What's my experience with pricing, setup cost, and licensing?

    Setup cost is cheap: It is free, it is user-friendly, and it is fast. 

    I would highly recommend anyone evaluating this option to download the free trial which allows for the ingestion of 500MB of data per day in order to get a feel for what Splunk does at its core. It will get pricey once your ingestion rates start to sky rocket, but I would consider it expensive given the amount of information that it allows you to analyze and react on straight out-of-the-box.

    Which other solutions did I evaluate?

    We evaluated the ELK Stack, of which recently we have implemented with a customer who was looking for a more lightweight, cheaper alternative that would work "Good Enough". They felt they did not need all of the bells and whistles that came with Splunk.

    What other advice do I have?

    If you have an R&D department within your company that is looking for something new to increase the efficiencies and effectiveness of your company's operations, I would highly recommend having them get the free trial to test out.

    Disclosure: My company does not have a business relationship with this vendor other than being a customer.
    PeerSpot user
    Buyer's Guide
    Download our free Splunk Enterprise Security Report and get advice and tips from experienced pros sharing their opinions.
    Updated: July 2026
    Buyer's Guide
    Download our free Splunk Enterprise Security Report and get advice and tips from experienced pros sharing their opinions.