There is improvement needed when importing from some types of data sources. Most of the time you have to do some customization for the data because not everything is working the way it should. Additionally, in other solutions, it is easier to build use cases.
Cyber Security Consultant at a computer software company with 11-50 employees
Customizable and has average installation difficulty
Pros and Cons
- "I have found the installation can be of medium difficulty to very complex depending on the use case."
- "There is improvement needed when importing from some types of data sources."
What needs improvement?
For how long have I used the solution?
I have been using this solution for approximately three years.
Which solution did I use previously and why did I switch?
I have previously used Curator and it was much easier to use than this solution.
How was the initial setup?
I have found the installation can be of medium difficulty to very complex depending on the use case. It is not easy for new customers. You need to have the experience to be able to do it.
Buyer's Guide
Splunk Enterprise Security
April 2025

Learn what your peers think about Splunk Enterprise Security. Get advice and tips from experienced pros sharing their opinions. Updated: April 2025.
849,686 professionals have used our research since 2012.
What other advice do I have?
When using this solution for Security Information Management(SIM), I highly recommend importing data sources from the whole cycle for the service security chain. Some people only use main inputs and not all of the data sources they have. They might not have some data sources, in this case, you can purchase one or there are free open-source ones available. You will then have this data source that can enrich your life because many correlations are done with this data.
I rate Splunk an eight out of ten.
Disclosure: I am a real user, and this review is based on my own experience and opinions.

Enterprise Architect and Business with 5,001-10,000 employees
It is easy to use, and easy to implement.
Pros and Cons
- "This solution helps us increase our productivity."
- "It is easy to use, and easy to implement."
- "I would like to see ability to master management. In terms of clustering, how it manages clustering needs improvement."
What is our primary use case?
It helps increase our productivity.
How has it helped my organization?
We are saving a lot of time by being in one place instead of several servers.
What is most valuable?
The most valuable features are understanding the visualization compass on the dashboard, as well as the reports on the dashboards.
What needs improvement?
I would like to have the ability to master the management of clustering.
For how long have I used the solution?
One to three years.
How was the initial setup?
It is easy to implement.
What other advice do I have?
It is easy to use, and easy to implement.
Disclosure: I am a real user, and this review is based on my own experience and opinions.

Buyer's Guide
Download our free Splunk Enterprise Security Report and get advice and tips from experienced pros
sharing their opinions.
Updated: April 2025
Product Categories
Security Information and Event Management (SIEM) Log Management IT Operations AnalyticsPopular Comparisons
CrowdStrike Falcon
Microsoft Sentinel
IBM Security QRadar
Elastic Security
LogRhythm SIEM
Rapid7 InsightIDR
Cortex XSIAM
Fortinet FortiSIEM
AlienVault OSSIM
Sumo Logic Security
Securonix Next-Gen SIEM
Google Chronicle Suite
ManageEngine Log360
Buyer's Guide
Download our free Splunk Enterprise Security Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- Which would you recommend to your boss, IBM QRadar or Splunk?
- What are some of the best features and use-cases of Splunk?
- What SOC product do you recommend?
- Splunk as an Enterprise Class monitoring solution -- thoughts?
- What is the biggest difference between Dynatrace and Splunk?
- IBM QRadar is rated above competitors (McAfee, Splunk, LogRhythm) in Gartner's 2020 Magic Quandrant. Agree/Disagree?
- What are the advantages of ELK over Splunk?
- How does Splunk compare with Azure Monitor?
- New risk scoring framework in the Splunk App for Enterprise Security -- thoughts?
- Splunk vs. Elastic Stack