Splunk Enterprise Security gives us the foundation for collecting, indexing, and analyzing data, while Splunk Enterprise Security adds more security-specific capabilities like threat detection, correlation search, risk analysis, and investigation workflows. We use it to monitor security events from different sources such as authentication systems, endpoint, and network devices. It helps us identify suspicious behavior, prioritize notable events, and investigate incidents more efficiently. The advantage is that we can still customize detection and dashboards based on our environment instead of only depending on different tools.
Jr. Oracle Apex Developer at a tech services company with 51-200 employees
Flexible analytics have empowered custom threat detection and faster incident investigations
Pros and Cons
- "After implementing Splunk Enterprise Security, we have seen the downtime reduced approximately 30 to 40%."
- "Splunk Enterprise Security is a very mature platform, but there are a few areas where I think it can improve."
What is our primary use case?
What is most valuable?
The best feature of Splunk Enterprise Security is the flexibility it provides when working with different types of machine data. One feature I really appreciate is SPL, or Search Processing Language, because it allows us to investigate data in a very detailed way; we can start from a simple search and gradually build more advanced queries to find patterns, troubleshoot problems, or identify unusual activities. Another valuable feature is the customization capability, allowing us to create our own dashboards, alerts, and reports based on exactly what our team needs instead of depending only on predefined templates. I also appreciate the data onboarding flexibility as Splunk can handle many different log formats, and we can decide how data is indexed, retained, and analyzed based on our requirements.
Splunk Enterprise Security's security customization capability is one of the areas where I find it very strong. From a security perspective, every organization has different requirements, and Splunk Enterprise Security allows us to build detection logic based on our own environments instead of depending only on fixed rules. For example, we can create custom SPL search and correlation rules, alerts, and dashboards to monitor specific activities such as unusual login behavior, system changes, or suspicious events. I also appreciate that we can combine data from multiple sources such as servers, network devices, and security tools to create a complete investigation workflow. The flexibility of customized search and security monitoring based on real business needs is one of the biggest advantages of Splunk Enterprise Security.
What needs improvement?
Splunk Enterprise Security is a very mature platform, but there are a few areas where I think it can improve. One area is administration and configuration simplicity; since Splunk Enterprise gives a lot of control, managing components such as indexers, search heads, configuration, and upgrades can become complex, especially for new teams. More automation around administration would help. Another improvement area is resource optimization. When dealing with very large data volumes, search and storage require proper tuning, so more built-in recommendations for performance optimization would make it easier. I would also appreciate more AI-assisted capabilities, especially for creating SPL queries, tuning alerts, and suggesting improvements automatically. Overall, the flexibility is excellent, but making management and optimization easier would improve the experience.
For how long have I used the solution?
I have been using Splunk Enterprise Security for around 1.5 years, and during this time, I work mainly for log analysis, monitoring, and troubleshooting different systems.
Buyer's Guide
Splunk Enterprise Security
September 2026
Learn what your peers think about Splunk Enterprise Security. Get advice and tips from experienced pros sharing their opinions. Updated: September 2026.
915,325 professionals have used our research since 2012.
What do I think about the stability of the solution?
I would rate the stability of Splunk Enterprise Security around nine out of ten; in my experience, it is a very stable and reliable platform, especially when the architecture is designed properly. Once components such as indexers, search heads, and forwarders are configured correctly, it runs consistently without frequent issues and handles continuous data ingestion and searches very well, even with large amounts of machine data. The reason I would not give a ten is that stability also depends on proper maintenance, resource allocation, and configuration tuning. If searches are not optimized or the infrastructure is not sized correctly, performance issues can occur. But overall, for an enterprise environment, it is a very dependable solution.
What do I think about the scalability of the solution?
We have around 40 to 50 active users of Splunk Enterprise Security, and the users are mainly from different teams such as security operations, infrastructure, application support, and the engineering team. Not every user uses it in the same way; some mainly view dashboards and reports, while analysts and engineers use it more deeply for SPL search, troubleshooting, investigation, and creating alerts. We manage access based on roles, so different teams get permission and data visibility according to their needs.
How are customer service and support?
I would rate technical support around nine; overall, the support experience has been good. The support team is knowledgeable, especially when dealing with complex topics such as indexing issues, search performance, configuration problems, or distributed development troubleshooting. The documentation from the Splunk community is also very strong, allowing many common issues to be resolved quickly. The reason I would not give a full ten is that for some advanced technical issues, especially in environment-specific problems, it sometimes takes multiple decisions or escalations to reach the final solution. But the overall quality of support and technical expertise is reliable.
Which solution did I use previously and why did I switch?
I have compared Splunk Enterprise Security with other SIEM and analytics solutions such as IBM QRadar and similar platforms. From my experience, the biggest advantage for Splunk Enterprise Security is its flexibility and data analytics capability; Splunk Enterprise Security is not limited only to security events, and we can bring in almost any type of machine data and create custom searches, dashboards, and use cases. Solutions such as IBM QRadar are strong for traditional SIEM use cases because they provide many predefined security rules and workflows out of the box. However, Splunk Enterprise Security gives more freedom to customize detection logic and analyze data in different ways using SPL; while Splunk Enterprise Security may require more configuration and tuning initially, once it is properly set up, it provides a lot of control and scalability. I would say QRadar is more structured out of the box, while Splunk Enterprise Security is better for organizations that want deeper customization, flexible analytics, and broader use cases beyond security. Therefore, I suggest that Splunk Enterprise Security is the best.
How was the initial setup?
We have deployed Splunk Enterprise Security in a self-managed on-premises development with a distributed architecture. Our setup includes components such as universal forwarders for collecting data, indexers for storing and processing events, and search heads for users to perform searches, create dashboards, and run reports. This deployment approach gives us more control over things such as data retention, infrastructure sizing, security policy, and custom configuration. For some data sources, we have integrated with cloud services, so it is more of a hybrid monitoring approach, but the main Splunk Enterprise Security environment is managed by our team.
What was our ROI?
After implementing Splunk Enterprise Security, we have seen the downtime reduced approximately 30 to 40%. The main reason is that Splunk Enterprise Security helps us identify problems much earlier instead of waiting until an issue impacts users. We can detect warning signs through logs, alerts, and system behavior patterns. For example, if an application starts generating errors or infrastructure performance changes, teams can investigate the event history quickly and understand the root cause. This can improve our mean time to resolution because engineers spend less time searching across multiple systems and more time fixing the actual problems.
What other advice do I have?
In Splunk Enterprise Security, we create custom correlation searches and alerts based on our environment requirements for risk-based alerting. For example, we set alerts for repeated failed login attempts, unusual user activity, privilege changes, or suspicious system behaviors. The useful part is that Splunk Enterprise Security does not force us to only use predefined detection; we can adjust thresholds, add conditions, and tune alerts using SPL to reduce false positives and focus on important events.
We have explored the newer Splunk detection capabilities mainly through Splunk Enterprise Security. We use features such as risk-based alerting and advanced correlation searches to improve how we detect threats instead of looking at every alert separately. Risk-based detection helps combine multiple suspicious activities and prioritize users or systems that show higher risk. Additionally, we use custom security content and detection rules based on our environment. The benefit is that we can tune detections, reduce unnecessary alerts, and focus more on meaningful security events. Overall, the newer detection approach helps move from just alert monitoring to a more context-driven investigation process.
I would rate Splunk Enterprise Security an eight; the reason is that it provides very strong capabilities for security monitoring, threat detection, and investigation. With Splunk Enterprise Security, we can combine data from different sources, create custom detections, and analyze suspicious activities to gain better context during investigations. I especially appreciate features such as correlation search, risk-based alerting, and customizable security dashboards because they help prioritize important threats instead of only generating a large number of alerts. The only reason I would not give it a perfect ten is that it requires proper tuning and skilled users to get maximum value, and initial configuration and optimization detections can take time. But once implemented properly, it is a very powerful security analytics platform. I rate Splunk Enterprise Security an eight overall.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Last updated: Jun 2, 2026
Flag as inappropriateSenior Information Technology Security Consultant at Mideast Data Systems
Advanced risk-based alerts have automated threat detection and reduced investigation time
Pros and Cons
- "Once you complete this setup, the product is amazing and will do all of the work."
- "The main dislikes about Splunk Enterprise Security are that we need more highly skilled people and the license for Splunk Enterprise Security is costly."
What is our primary use case?
I have been using Splunk Enterprise Security for the last five years, mainly building use cases for the SOC team. My role involves analyzing logs and writing vulnerability alerts based on what I observe. When security alerts are triggered, the security team receives notifications and takes appropriate action.
For the initial deployment of Splunk Enterprise Security, I cannot say this is easy. It is somewhat complex because when you purchase the product, you have a lot of data. You need to align all of your data so that it fits Splunk Enterprise Security standards. Splunk Enterprise Security has custom data models and custom correlation searches that are already defined. You need to modify or set your data according to Splunk Enterprise Security standards. Once you complete this setup, the product is amazing and will do all of the work.
What is most valuable?
The most valuable aspect of Splunk Enterprise Security is that SIEM compliance is one of the best features. I can say this not only because it is Splunk Enterprise Security specific, but also because it is Splunk specific. All data coming in needs to be placed in the SRC field. All data will be normalized with the SRC field. Whether you are collecting data from a firewall or from numerous products, all data with the same name will be automatically collected by Splunk Enterprise Security alerts. Based on that, you can get all alert triggers and perform any kind of investigations. If something goes wrong, such as someone wrongly accessing servers, you will get everything very quickly based on the authentication data model. The alert part and security investigation part are very good.
Threat intelligence is very helpful because there is a threat intelligence model in Splunk Enterprise Security. It will identify threats from around the world and bring them into Splunk Enterprise Security. AI also helps us. When a wrong IP is detected, an incident will be created in Splunk Enterprise Security. Once you click on the "get more info" button, it will bring all information about where this IP belongs, including location and coordinates. Based on that, you can trigger security incidents and alerts.
I am very familiar with risk-based alerting in Splunk Enterprise Security. Everything in Splunk Enterprise Security is on a risk-based model. When I found an unknown IP detection one time, everything is assigned with a risk score. If I found an unknown IP one time in one hour, the risk score might be five or ten. If the same thing repeats in one hour, for example if an unknown IP tries to log in twenty times in one hour, the score should be higher. Risk-based alerting will check the notables and increase the score. When you have one hit, the risk score will be two. Whenever you have more hits, the risk score increases and the alert severity and alert priority also go high, becoming a P1 or P2 incident for the analyst. Risk-based alerting is a very good feature in Splunk Enterprise Security.
MITRE ATT&CK is helpful for Splunk Enterprise Security. I take reference from this framework whenever I want to create alerts. The first thing I do is check the MITRE ATT&CK framework and read the documentation. In MITRE ATT&CK, there are tables with many rows and columns. I check these tables and review all the alerts. MITRE ATT&CK shows the security framework and the maximum possible things that can be done to secure our platform. From that MITRE ATT&CK reference, I create alerts.
What needs improvement?
The main dislikes about Splunk Enterprise Security are that we need more highly skilled people and the license for Splunk Enterprise Security is costly. Beyond this, the infrastructure cost is too high. Since we have an on-premises deployment, it is costly for us because we need a lot of storage and a big server.
From a maintenance perspective, Splunk Enterprise Security sometimes requires maintenance because it continuously monitors all alerts and continuously creates incidents. Sometimes the data volume is high and some searches will be skipped automatically. We might have 1,000 searches and sometimes experience a lot of skipped searches. Sometimes if we modify any macro, there can also be issues. We need at least one person for maintenance who can continuously ensure that Splunk Enterprise Security is running fine.
Regarding support for Splunk Enterprise Security, we reach out many times. Initially, we purchased hardware that was not capable enough. Sometimes our server became choked and Splunk was not able to run some searches on Splunk Enterprise Security. These issues were due to hardware limitations. We called a consultant from Splunk who analyzed the platform and fixed the issues. Sometimes we upgraded our platform twice by adding additional disk space and RAM.
We have not upgraded to version 8.0 yet for Splunk Enterprise Security and are currently on version 7.0. Recently, we have a demo scheduled from the Splunk team to learn about Splunk Enterprise Security 8.0 features. However, in version 8.0 they changed everything. Initially, we had an incident review dashboard and risk management dashboard that I was very familiar with. In Splunk 10X, all the names changed and everything was restructured. Currently, I am still learning which old features correspond to the new ones. They changed many things, which is also one of the disadvantages, as the changes were extensive.
What do I think about the stability of the solution?
Splunk Enterprise Security has never crashed. However, sometimes there was lagging, but this was due to our infrastructure because we have an on-premises deployment. I used it in the cloud three or four years ago, and the cloud version is very stable with no scalability issues.
What do I think about the scalability of the solution?
Overall, I can give a rating of nine for the scalability of Splunk Enterprise Security.
How are customer service and support?
Splunk Enterprise Security support deserves a rating of nine.
Which solution did I use previously and why did I switch?
I have never used any alternative to Splunk Enterprise Security. Before Splunk Enterprise Security, we were using Splunk for monitoring purposes, writing queries and preparing alerts. However, this is not what Splunk Enterprise Security does. A normal traditional alert can be scheduled based on Cron or similar methods. Splunk Enterprise Security collects threats from around the world and includes a threat intelligence data model. It manages identity and asset information separately, which cannot be done with our traditional approach.
How was the initial setup?
For the initial deployment of Splunk Enterprise Security, I cannot say this is easy. It is somewhat complex because when you purchase the product, you have a lot of data. You need to align all of your data so that it fits Splunk Enterprise Security. Splunk Enterprise Security has custom data models and custom correlation searches that are already defined. You need to modify or set your data according to Splunk Enterprise Security standards. Once you complete this setup, the product is amazing and will do all of the work.
What other advice do I have?
The mean time to resolve in Splunk Enterprise Security will increase. On other platforms, whenever you create alerts, you only need to see what is there and then troubleshoot everything. In Splunk Enterprise Security, when you create an alert, you can add many additional things. For example, once an unknown IP is detected, it will send an email, create an incident, and create a notable inside the security system. It can do many things and you can add more information. You can check a lookup, check an IP, or follow specific steps. You can add multiple steps to follow as well. All of this will be included with the alert, which resolves a lot of mean time. People do not need to go searching to find how to do things. This significantly reduces the time needed and alerts are immediate. Whenever something goes wrong, you will be notified quickly.
With Splunk Enterprise Security, we detect threats frequently. I work with a major client in the Emirates, and we find a lot of attacks happening and many phishing emails. Sometimes we have two firewalls, one is a DC firewall and one is a Palo Alto firewall, with many compliance requirements. People attempt to access these systems and sometimes send vulnerability emails. For all of these things, we are blocking and detecting with Splunk Enterprise Security and immediately notifying the candidate to not open emails or notifying our team via email.
It reduced the analyst's workload in Splunk Enterprise Security. However, after purchasing Splunk Enterprise Security, we hired more people to analyze the data. By purchasing this product, we came to understand that we can implement additional features and security rules. Our team is continuously and actively working, checking the MITRE ATT&CK framework, finding detections, and implementing them on our platform to make it more secure.
MITRE ATT&CK helps detect patterns that have occurred before.
ES Essentials is in our environment for Splunk Enterprise Security, though I have never focused much on working with it and do not know much about what it does.
Overall, I would rate this review as a nine.
Which deployment model are you using for this solution?
On-premises
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Other
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Last updated: May 7, 2026
Flag as inappropriateBuyer's Guide
Splunk Enterprise Security
September 2026
Learn what your peers think about Splunk Enterprise Security. Get advice and tips from experienced pros sharing their opinions. Updated: September 2026.
915,325 professionals have used our research since 2012.
IT Security Officer at a government with 10,001+ employees
Daily reporting has improved security oversight and simplifies tracking sensitive user access
Pros and Cons
- "I would let potential users know that this is a great tool that has many features and capabilities."
- "I would recommend more training videos and simulations on what the tool can do."
What is our primary use case?
I verify users who have permissions to certain files, losing, or moving data. I use this for an overall view of the court system for our users.
What is most valuable?
I would say the level of detail is valuable. When I need to find something, I can find it relatively easily with the queries and also the helpful tips and guides. I use them often as they are helpful when I need to find a certain syntax or command that I may not know offhand.
Overall, I appreciate the fact that I have a lot of control and I can use that control to dig deeper into things that may stand out. It has impacted us positively because we have a better view of our security posture and we can look into more detail on notable events that may occur.
The reporting feature, using a daily report that gets emailed, helps with time management. I no longer have to go through different dashboards. I can have it set to automatically send me a report, which makes my time easier to find something specific and work on it if the report indicates something that needs attention.
What needs improvement?
I would recommend more training videos and simulations on what the tool can do. I know it is a huge tool that has many capabilities. Educating and providing guidance on those features would be beneficial, because new features seem to be added quite frequently.
I would also suggest more videos or features, such as pop-ups that help or guide a user when they are looking for something in particular. An AI chatbot that could guide you on what you are trying to accomplish would be helpful.
For how long have I used the solution?
I have been using this solution for about one year.
What do I think about the stability of the solution?
I believe Splunk Enterprise Security is stable. I have not had any issues.
What do I think about the scalability of the solution?
Splunk Enterprise Security's scalability is very good. I have not had any issues.
How are customer service and support?
Customer support is very good. I have not had any issues reaching out to customer support. I rate it a 10.
Which solution did I use previously and why did I switch?
I did not use a previous solution.
What was our ROI?
That is hard to quantify as I do not have a say in the return on investment, but I will say that the tool is very easy to use and I definitely recommend it moving forward.
Which other solutions did I evaluate?
I did not evaluate other options before choosing Splunk Enterprise Security.
What other advice do I have?
I would let potential users know that this is a great tool that has many features and capabilities. It is almost a one-stop shop for everything that you need to view your environment. Although it may be daunting at first, it is very easy to use once you get the hang of it.
I appreciate Splunk Enterprise Security. I do feel that there is a lot that this product can do, and I would like to see more guidance, documentation, videos, and simulations to see it firsthand. I rate this review an 8.
Which deployment model are you using for this solution?
Private Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Last updated: Sep 17, 2026
Flag as inappropriateSenior Cyber Security Analyst at a energy/utilities company with 5,001-10,000 employees
Automated investigations have accelerated threat detection but demand better built-in enrichment
Pros and Cons
- "Splunk Enterprise Security has saved us time and money by making it easier to investigate events."
- "Splunk Enterprise Security has helped us and has been more beneficial in the past, but our expectations have grown over time, and we feel like Splunk is not currently meeting our expectations."
What is our primary use case?
My main use case for Splunk Enterprise Security involves new detections and correlation of events. I use data points that are submitted via information-sharing communities and use those as artifacts, TTPs, and IOCs to build my own detections for behavior in my logs. Using those detections I can identify suspicious or malicious behavior.
How has it helped my organization?
Splunk Enterprise Security has saved us time and money by making it easier to investigate events. It has helped us in correlating similar events and identifying things that we might have missed if we were to search it out manually. Specific tools that we use, like Attack Analyzer, do all the work for us. After it identifies an event of interest, it will do the investigation for us so that we can reach decisions faster and have less time by the human doing things that a machine can do.
Splunk Enterprise Security has helped us and has been more beneficial in the past, but our expectations have grown over time, and we feel like Splunk is not currently meeting our expectations. A lot of the configuration is do-it-yourself rather than out-of-the-box or just a checkbox to implement. It improved things initially by cutting our MTTR in half upon implementation about 12 years ago. Since then, we had a significant reduction when we adopted Splunk Attack Analyzer, cutting it by 75 percent. Our decision-making ability is now being leveraged rather than our investigation abilities.
We have been able to leverage Splunk research or develop our own detections, cutting the time to detection from days to hours. Splunk Security Essentials allows us to focus on the artifacts and the decisions as opposed to the investigation. Decisions can be made in seconds. Investigations are performed by a machine and it saves us dozens of minutes per incident. The unified workflow has made it possible for there to be automatic investigations and for us to triage quickly by identifying the artifacts of interest. This has improved our daily work experience and has improved team morale, which has led to greater retention.
What is most valuable?
The best feature Splunk Enterprise Security offers is the correlation feature, being able to do automatic lookups and enrichment of data. Those automatic lookups allow us to convert IPs to network names that are human-readable and also convert user IDs into usernames and give us business units. We can have a lot of contextual information about a person and where they come from and where they are going without having to do that lookup manually ourselves. In addition to doing those lookups, it can also correlate data. If there is a specific ID or session ID or other relevant artifact, we can see that data from other data sources and it is very useful to have it all organized chronologically.
What needs improvement?
I think that there is a rich ecosystem around improving Splunk Enterprise Security, and the question we often ask ourselves is why Splunk Enterprise Security does not already do that and why we have to pay a third party to do that. We often question whether it is easier to pay the third party to do the enterprise security data enrichment or service, or if it is better and easier to just try to implement it ourselves. We will often buy into a third-party product only to have it available in Splunk a year or two later.
For how long have I used the solution?
I have been using Splunk Enterprise Security for 12 years.
What do I think about the stability of the solution?
Splunk Enterprise Security has experienced stability issues.
What do I think about the scalability of the solution?
Splunk Enterprise Security is a bit expensive to scale.
How are customer service and support?
Customer support was better in the past and it is hard to find really good support. I think that it has all been outsourced.
What other advice do I have?
The unified workflow has made it possible for there to be automatic investigations and for us to triage quickly by identifying the artifacts of interest. Splunk is no longer unique as SIEMs are now a commodity. Splunk still has a foothold with the unique detection logic, but I expect that to change in the next couple of years. Splunk Enterprise Security is a bit expensive to scale. Customer support was better in the past and it is hard to find really good support as it has all been outsourced. I would rate this review a 7.
Which deployment model are you using for this solution?
Hybrid Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Amazon Web Services (AWS)
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Last updated: Sep 17, 2026
Flag as inappropriateFull-Stack Software Engineer at mindpathtech
Security monitoring has improved and supports complex, high-volume environments effectively
Pros and Cons
- "Splunk Enterprise Security is fully scalable because it provides all kinds of configuration in management servers and all cloud integrations such as AWS, Azure, Google Cloud, Kubernetes, Docker, GitHub, Jenkins, and Cisco as well, and it is quite fully scalable across all platforms."
- "The learning curve, its implementation, and its pricing are quite heavy for learners or purchasers."
What is our primary use case?
Splunk Enterprise Security was the major use case that I had.
What is most valuable?
As a service provider and person managing the tool, the biggest advantage that stands out for me is quite significant. I am using disparate security solutions to integrate or import data into Splunk. I have worked with risk-based alerting in this aspect.
In banking, the logs generated are significant, so everyone should be aware of not facing emergencies such as service failures. Debugging and analyzing these services are really important, especially for larger organizations such as banks, where the services should be implemented with Splunk.
Splunk Enterprise Security helps to improve business resilience by being dependent on the services the company provides. If the processes are heavy such as banking, healthcare, and aviation, it is quite helpful. However, for a small and less complex system, it is not useful because it contains a very heavy architecture. It can be quite expensive to implement for them, but for larger processes and products, it is quite useful.
What needs improvement?
High infrastructure requirements are present when I integrate Splunk into my full services such as app microservices, database, CloudWatch, or the machines where I have deployed the services. I have to integrate into all the platforms I am using. It needs another machine or infrastructure to manage all the logs and generate these kinds of reports.
Regarding the learning curve, any beginner encounters trouble with it because it is complex to implement across all services due to the huge amount of applications or functionality to watch and implement. I also mentioned earlier that the pricing is a concern because it does not provide any free tier to use; therefore, I have to use the paid version, which is quite expensive, costing thousands of dollars per one gigabyte or ten gigabytes of data generated.
I believe the pricing is quite expensive. It generates a huge amount of data, so it sometimes works slowly for the generated logs. I can say around ninety-eight percent uptime because I can sometimes get into trouble finding logs across the services in the generated logs.
The learning curve, its implementation, and its pricing are quite heavy for learners or purchasers.
For how long have I used the solution?
I have used Splunk Enterprise Security for three years now.
What do I think about the scalability of the solution?
Splunk Enterprise Security is fully scalable because it provides all kinds of configuration in management servers and all cloud integrations such as AWS, Azure, Google Cloud, Kubernetes, Docker, GitHub, Jenkins, and Cisco as well. It is quite fully scalable across all platforms.
How are customer service and support?
My manager discussed licensing earlier, but I did not have the need to call them later after implementing. After my organization bought it, they provided quite a good response from the support team.
Which solution did I use previously and why did I switch?
When I compare Splunk Enterprise Security to other tools, I have been using various solutions on average to allow my SecOps team to remediate security incidents with Splunk.
How was the initial setup?
Regarding the installation and deployment, I would say it is quite complex. It is complex because I have to deeply learn it due to the many things involved. As a beginner, it is quite complex to learn. If a senior developer or individual is trying to implement it, that is time-consuming because I have to do a lot of things to implement Splunk across the services and servers.
What was our ROI?
If I quantify the return on investment of Splunk in percentage, I would say it is around ten to twenty percent on average for its services provided because these bugs or hacker attempts are really rare cases, making it heavy to calculate.
What's my experience with pricing, setup cost, and licensing?
I did not purchase it because these transactions are handled at the organizational level. The higher managers process these purchases over the AWS cloud, so as a developer, I am not included in that process.
What other advice do I have?
I am using a new threat detection feature in Splunk. When I implement Splunk, it provides a dashboard or methods to implement these threat detection processes. It gives me an email trail that identifies when services and which users are trying to breach security. If any service has failed, then it also triggers an email or a notification in the dashboard. These are rare cases, but I find the average number to be acceptable.
I have used Azure for deployment. I rate Splunk Enterprise Security nine points out of ten, and my overall review rating for this product is nine out of ten.
Which deployment model are you using for this solution?
On-premises
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Microsoft Azure
Disclosure: My company has a business relationship with this vendor other than being a customer. MSP
Last updated: Jul 8, 2026
Flag as inappropriateCyber Security Manager at a tech vendor with 10,001+ employees
Provides strong threat visibility and MITRE coverage but lacks AI features and cost flexibility
Pros and Cons
- "Splunk Enterprise Security would provide better capabilities and out-of-box detections."
- "We haven't saved any money with Splunk Enterprise Security. Instead, we have spent excess of the budget on this with unexpected costs."
What is our primary use case?
We use Splunk Enterprise Security for our security monitoring and incident management. This is our global application that we are using for security monitoring and compliance.
How has it helped my organization?
We've seen some good improvements from a business perspective, particularly regarding security monitoring. However, when I consider our current challenges and future roadmap, I don't believe Splunk Enterprise Security has the capabilities we need. We previously faced challenges with QRadar, which prompted us to migrate to Splunk Enterprise Security. While Splunk Enterprise Security has addressed the past issues we encountered, it fails to meet our future requirements. Currently, it effectively addresses existing threats, but it doesn’t tackle advanced threats, which is a significant challenge we foresee with Splunk. There is still a lot of room for improvement.
What is most valuable?
With the Classic flavor we have in our company, the feature that I find good in Splunk Enterprise Security is from the MITRE coverage point of view, and then the level of information that it provides. The integration with its own SOAR platform is also one of the pros.
What needs improvement?
From the product point of view and deployment point of view, Splunk Enterprise Security is satisfactory. It is not simple; it is at a medium level when it comes to deployment and management of the tool altogether. This includes not only the enterprise platform but also other components such as deployment servers or the Splunk agents we use for collecting logs. When comparing it with different vendors in the industry, from the deployment and maintenance point of view, it is not up to the level of other vendors.
When discussing the drawbacks, it's important to note that the flavor I’m currently using is called "Classic." Unfortunately, this platform does not offer any of the new features that Splunk introduces. As a result, we are the last ones to find out about new capabilities, and we’re also slow to implement them. Splunk tends to release new features with different flavors of their platform, and being on the Classic flavor means we are least likely to receive the latest updates. This is a significant concern I have regarding Splunk.
When comparing Splunk Enterprise Security with next-gen SIEMs, we look for AI and ML models being incorporated in such a way that it automatically should be able to detect behavioral-based detections. It should be able to detect behaviors from logs and show us the entire attack surface and blast radius of any particular incident, which is primarily missing.
The capability of AI, Artificial Intelligence, is missing, which would help to automatically detect and read data comprehensively. Splunk lacks the new native solutions for agent deployment, which is essential for a large enterprise.
Currently, there is Machine Learning in Splunk Enterprise Security, but that is resource exhaustive and complex, bringing an impact onto our overall stack performance. Technical expertise in Machine Learning is required, and continuous monitoring is needed to ensure Machine Learning learns about our data to provide results, which is resource exhaustive, time-consuming, and costly.
Artificial Intelligence is missing in the Splunk Enterprise Security platform, which would help us read the data automatically, learn from it, and provide attack surface area from a 360-degree perspective. The fixed pricing model requires upfront purchase based on assumptions and roadmap, requiring payment for the next two to three years regardless of usage.
For how long have I used the solution?
I have been using Splunk Enterprise Security for around three years.
What do I think about the stability of the solution?
On a stability scale, I would rate it an eight out of ten.
What do I think about the scalability of the solution?
Regarding scalability, I would rate it a seven out of ten. I don't have the pay as you go model.
We have 150 users using this solution.
How are customer service and support?
Whenever we raise any support case in Splunk, even after providing the required information, if a person is working on it and it gets transferred or handed over to a different representative in a different shift, they keep asking the same questions and requesting more details. Even when we ask for a call, even for P1 or P2 incidents, they keep going around asking for details. When we request P1 or P2 support, it would be wise to get into a call, get all the details, and have a troubleshooting call to address the issue on a priority basis. The technical support representatives keep transferring the tickets during shift handover, and different representatives ask the same questions multiple times, wasting our precious time. The issue doesn't get resolved until I escalate it to their higher management.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
We were using QRadar previously. We had legacy systems, and from the volume and log source point of view, from the costing perspective and detection point of view, we thought Splunk Enterprise Security was far better than QRadar. Splunk Enterprise Security would provide better capabilities and out-of-box detections. These were some of the things that we saw, and Splunk Enterprise Security was also one of the leaders in SIEM technology. However, once we started using Splunk Enterprise Security, we discovered it was not the right tool.
How was the initial setup?
The initial setup was of medium complexity. It took approximately 8 to 12 months to migrate from QRadar to Splunk Enterprise Security.
The cloud platform we are using is maintained by the Splunk team itself. However, when it comes to our on-premises deployment, the maintenance is very high, cumbersome, and costly from both resource and time perspectives.
What was our ROI?
We haven't saved any money with Splunk Enterprise Security. Instead, we have spent excess of the budget on this with unexpected costs. That's one of the pain points I see with Splunk Enterprise Security. There haven't been any savings.
What's my experience with pricing, setup cost, and licensing?
Splunk Enterprise Security comes with high fixed costs. That's one of the disadvantages. When comparing with different vendors, they offer pay-as-you-use models, which is more user-friendly, but Splunk Enterprise Security comes with fixed pricing.
Which other solutions did I evaluate?
We use different security tools as well.
What other advice do I have?
For any user who wants to have a cost-efficient and next-gen SIEM solution, I wouldn't recommend Splunk Enterprise Security. However, if a user is not concerned about cost and is looking for an on-premises solution, then I would suggest Splunk Enterprise Security. For anyone who wants to go for a cloud and cost-effective solution with next-gen capability, I wouldn't recommend this.
I would rate it a seven out of ten.
Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
IT Administrator at a government with 1,001-5,000 employees
Platform has become our security hub and has improved threat detection and response speed
Pros and Cons
- "Splunk Enterprise Security has helped reduce our team's average meantime to resolve metric by about 50 percent because we are able to tune it to lower false positives and noise."
- "I think Splunk Enterprise Security could integrate more features, just as a SOAR should be part of the product, along with more AI detection features, and additional features available in observability. The current offering is not sufficient."
What is our primary use case?
My main use case for Splunk Enterprise Security is detection and engineering. We are looking for all different kinds of threats with Splunk Enterprise Security and then we ingest data sources from different telemetry to look at our posture, starting from MFA to everything else. That is our main use for Splunk Enterprise Security.
What is most valuable?
In my experience, the best features Splunk Enterprise Security offers are the in-depth search, dashboards, and all those features.
Our dashboards with Splunk Enterprise Security give us our metrics, and I also use it for the executive dashboard. For example, we use it for lateral movement and email security, and basically, we use it for protection and firewalls as well, ingesting all the logs.
Splunk Enterprise Security is our main MDR service and the center of our cybersecurity operation, where we have all the alerts ingested and present.
Since implementing Splunk Enterprise Security, I have seen a faster response time, and we can also suppress noise, including false positives.
What needs improvement?
I think Splunk Enterprise Security could integrate more features, just as a SOAR should be part of the product, along with more AI detection features, and additional features available in observability. The current offering is not sufficient.
For how long have I used the solution?
I have been using Splunk Enterprise Security for two years.
What do I think about the stability of the solution?
Splunk Enterprise Security is stable.
What do I think about the scalability of the solution?
In terms of scalability, Splunk Enterprise Security is pretty scalable. You just have to pay more.
How are customer service and support?
We have very good customer support with Splunk's SE, and while sometimes responses can be slow, overall it is satisfactorily defined. I would rate the customer support of Splunk Enterprise Security an eight out of ten.
Which solution did I use previously and why did I switch?
We previously used LogRhythm, and that decision was made by someone else, our former CIO. We owned Splunk before and decided to go back to Splunk again.
What was our ROI?
I have not yet seen a return on investment. It is still hard to quantify because we are still configuring and building our metrics to measure it. We started some metrics and I am hoping to get those in the next six months.
What's my experience with pricing, setup cost, and licensing?
My experience with pricing, setup cost, and licensing is that pricing is high, and it feels as though it is not very transparent. We do not know what discount rate we are going to get, and I have to buy multiple different products.
Which other solutions did I evaluate?
Before choosing Splunk Enterprise Security, we knew what we wanted to do, so I did not have to evaluate other products.
What other advice do I have?
Splunk Enterprise Security has helped reduce our team's average meantime to resolve metric by about 50 percent because we are able to tune it to lower false positives and noise.
I would say Splunk Enterprise Security helps us detect threats faster because we are able to tune the number of alerts sent out, resulting in fewer alerts we need to monitor.
We are still developing the impact of Splunk Enterprise Security's risk-based alerting on our alert volume and analyst productivity.
Having the consolidation of SIEM, SOAR, and UEBA into a single interface with Splunk Enterprise Security improves our operational efficiency and provides a single pane of glass.
The integration of threat intelligence directly into the TDIR workflow with Splunk Enterprise Security improves our ability to preemptively block threats and makes our decision-making faster since we have intel ingested in the platform instead of referencing different sources.
Regarding Splunk Enterprise Security Essentials, we have not worked much on the cloud side, so it has not improved our visibility across hybrid or multi-cloud environments.
My advice to others looking into using Splunk Enterprise Security is that if someone wants a very comprehensive solution, it is the way to go. However, they need to ensure they have a person who can handle, configure, maintain, and add rules and policies, as it is not the product they need to buy unless they have managed services. I would rate this product an eight out of ten overall.
Which deployment model are you using for this solution?
Public Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Last updated: Sep 17, 2026
Flag as inappropriatesenior technical program manager at a computer software company with 201-500 employees
Centralized monitoring has standardized our logs and empowers teams with shared dashboards
Pros and Cons
- "Splunk Enterprise Security has positively impacted my organization by providing enhanced logging capabilities in addition to standardizing log approaches and visualizations, allowing us to create and share dashboards and visualizations so that all of our various enterprise programs can implement standard and consistent dashboard methodologies."
What is our primary use case?
My main use case for Splunk Enterprise Security involves log aggregation, anomaly identification, visualization of potential issues, errors, and threat modeling.
I create specific reports or dashboards to measure log patterns or events that fall outside of our specific thresholds, such as user logins multiple times a day or users attempting to hit protected routes that they don't have access control for.
What is most valuable?
All the features of Splunk Enterprise Security are quite great and necessary. I think being able to create and share visualizations and dashboards is really helpful for allowing my less Splunk-savvy co-workers the ability to still monitor and investigate issues or potential incidents.
Typically, my coworkers use the dashboards I create for monitoring system health, error rates, and similar metrics, but then with visualization drill-downs, that allows them to dig deeper into what an issue might be caused by, which parleys into incident response.
Splunk Enterprise Security has positively impacted my organization by providing enhanced logging capabilities in addition to standardizing log approaches and visualizations, allowing us to create and share dashboards and visualizations so that all of our various enterprise programs can implement standard and consistent dashboard methodologies.
What needs improvement?
I think the addition of the new Splunk AI Assistant into Splunk Enterprise Security would be really helpful, especially for new Splunk users to be able to rapidly learn and generate complex SPL queries.
For how long have I used the solution?
I believe we have been using Splunk Enterprise Security for about six years.
What do I think about the stability of the solution?
Splunk Enterprise Security is stable.
What do I think about the scalability of the solution?
I think Splunk Enterprise Security is very easily scalable both horizontally and vertically; we have had no issues expanding as needed.
How are customer service and support?
Customer support has been fantastic.
Which solution did I use previously and why did I switch?
I have used a couple of different solutions; traditionally, I looked at logs on servers through tail, cat, and vim, and I played around with other log aggregation solutions including Kibana, but I have been with Splunk for about six to eight years.
How was the initial setup?
I think my experience with pricing, setup cost, and licensing has been pretty positive. As far as licensing goes, it has been pretty transparent. The bulk of the expense for Splunk Enterprise Security comes from data storage and retention, so thankfully, we have been able to work with both our Splunk and cloud partners to come up with a retention policy and life cycle plan that works for us and fits within our budget.
What about the implementation team?
We used direct contract procurement to purchase Splunk Enterprise Security.
What was our ROI?
I have definitely seen a return on investment. Although I don't know that I can quantify that ROI, I have definitely seen a reduction in administrative burden, allowing us to redirect both our analyst and engineering resources to focus on actual remediation efforts or identification of incidents and response times, rather than engineers having to spend a lot of time parsing logs or incidents.
What's my experience with pricing, setup cost, and licensing?
I think my experience with pricing, setup cost, and licensing has been pretty positive. As far as licensing goes, it has been pretty transparent. The bulk of the expense for Splunk Enterprise Security comes from data storage and retention.
Which other solutions did I evaluate?
We evaluated other options before choosing Splunk Enterprise Security, including Kibana, Dynatrace, and Datadog.
What other advice do I have?
I would say to do a lot of homework in researching the different tools and modules within Splunk Enterprise Security. Splunk Enterprise Security is obviously very essential and is the heart of Splunk, but all of the other tools that are available, such as SOAR and RUM, are important, so identify exactly what your enterprise needs and map that to the different Splunk modules to make sure that you are getting as much as you can from Splunk. I provided this review with a rating of 9.
Which deployment model are you using for this solution?
Private Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Other
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Last updated: Sep 17, 2026
Flag as inappropriateSenior Vice President Cyber Security at Mindsprint
Extensive integrations have enabled real-time threat detection and continuous security monitoring
Pros and Cons
- "Splunk Enterprise Security's biggest advantage is the ecosystem, as the large ecosystem can detect threats from a variety of devices, including firewalls and antivirus software, and because it has many built-in rules for detection already, I do not write many playbooks from scratch, which helps me get started on threat detection faster and enables me to predict, identify, and solve problems in real time so security incidents can be prevented."
- "From a pricing perspective, the costs have become higher, as I understand from our procurement team."
What is our primary use case?
I work with Splunk as a service provider as well as a customer because we use Splunk internally.
This is used to run the Security Operation Center to conduct 24/7 monitoring for any security alerts and incidents for our use cases and use cases for our clients.
We do use some disparate security products that integrate or import data into Splunk. We have integrated Splunk with many threat intelligence sources, including external threat intelligence sources. We have a direct Splunk integration with CrowdStrike, and we have many other integrations with Splunk itself.
We have integrated Splunk with many log sources, including firewalls and other devices. From those firewalls and log sources, we have configured alerting in our Splunk environment. This helps us in detecting and alerting any security incidents.
What is most valuable?
Splunk Enterprise Security's biggest benefit is the ecosystem itself. It has many connectors and plugins built-in, which provides all those capabilities as part of its ecosystem.
I have a very positive impression of the process for customizing, developing, testing, deploying, and refining detections in Splunk Enterprise Security. The alerting part does support our SOC.
Splunk Enterprise Security's biggest advantage is the ecosystem. The large ecosystem can detect threats from a variety of devices, including firewalls and antivirus software. Because Splunk Enterprise Security has many built-in rules for detection already, I do not write many playbooks from scratch. Splunk Enterprise Security has many detection rules that are already provided, which helps me get started on threat detection faster. This is due to two primary reasons: the large ecosystem, by which Splunk can integrate with many varieties of devices, and Splunk Enterprise Security, which has many built-in rules that help me detect threats.
It helps me predict, identify, and solve problems in real-time, which helps me detect threats in real-time and then take action faster. Because of this, any security incidents can be prevented.
What needs improvement?
There are two parts to consider for areas of improvement. One, especially after the Cisco acquisition, is from a pricing point of view. From a pricing perspective, the costs have become higher, as I understand from our procurement team. The other area is from a support perspective. Support has declined, but it is starting to improve again, though it still could be better.
For how long have I used the solution?
I have used Splunk for eight years.
How was the initial setup?
I find the installation part quite straightforward.
What was our ROI?
There is no quantification of time-saving or money-saving benefits of Splunk because it is more focused around threat detection itself.
What's my experience with pricing, setup cost, and licensing?
It is worth buying the product, definitely, because no other vendor supports the kind of integrations that Splunk supports, even though the price is a little on the higher side.
What other advice do I have?
The biggest piece of advice I would say to people looking to use Splunk Enterprise Security in the future is to check the compatibility with the ecosystem of products they are using within the enterprise or within their own business, and see if it is supported by Splunk Enterprise Security. Because if they use a firewall which is not supported by Splunk Enterprise Security, then it will become a challenge in detecting any threats on the firewall because the logs cannot be ingested or consumed by Splunk Enterprise Security. The most important thing is to check their ecosystem and whether Splunk Enterprise Security supports logs from their ecosystem. I rate this product an 8 overall.
Which deployment model are you using for this solution?
On-premises
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Other
Disclosure: My company has a business relationship with this vendor other than being a customer. MSP
Last updated: Jul 13, 2026
Flag as inappropriateSoftware Engineer at Titanslab Inc.
Centralized logging has simplified root-cause analysis and improves productivity across apps
Pros and Cons
- "Managing logs is very easy with Splunk Enterprise Security."
- "One thing I would like to see improved in Splunk Enterprise Security is a better user manual."
What is our primary use case?
Our main use cases for Splunk Enterprise Security are to find the root cause of any applications, to see the dashboards, to see the logs, and to centralize some logging systems.
What is most valuable?
Managing logs is very easy with Splunk Enterprise Security. Earlier, we were using DataDog and before that, we were also using our own tool, 24/7, to maintain logs and everything. In that, we faced many issues maintaining logs from many applications because we are managing many applications right now. So it was very tough, and when we were introduced to Splunk Enterprise Security, we used it, and it became very easy to maintain. It is easy to have control over it.
The main benefits I have seen from using Splunk Enterprise Security are mainly two things: the pricing and the manpower. Right now, we do not have to worry about the time if we encounter any issues. Recently, one of our customers raised an issue that the application was running very slow. Earlier, we had issues like that, but at that time we had to do so much manual checking everywhere to find the issue. Right now, if we get an issue regarding this, it is very easy to understand the root cause.
What needs improvement?
One thing I would like to see improved in Splunk Enterprise Security is a better user manual. Right now, it is pretty tough for any newcomer or new user to understand everything because there are no specific areas for them to learn from.
From a features perspective, an enhancement I would like to see is a better learning aspect. The AI feature is great, but I believe enhancing the learning part for any new user would be beneficial.
For how long have I used the solution?
We have been using Splunk Enterprise Security products for the last eight to nine months, but I have been onboarded on this in the last six months.
What do I think about the stability of the solution?
The stability, reliability, and performance of Splunk Enterprise Security are pretty good. Now we are very stable with many production systems, and Splunk Enterprise Security is also scalable if we want to expand further.
How are customer service and support?
I would evaluate the tech support team as good.
Which solution did I use previously and why did I switch?
I previously used different products and solutions like in-house technologies and DataDog.
How was the initial setup?
The initial setup process for Splunk Enterprise Security was somewhat challenging. As I mentioned, it lacks a specific user manual, making the initial setup tough, but now we are hands-on and comfortable with it.
What was our ROI?
Regarding ROI, while I cannot speak specifically about the investment, I can say that the returns are good. We achieve one hundred percent productivity utilizing Splunk Enterprise Security to create multiple dashboards and find various issues.
What's my experience with pricing, setup cost, and licensing?
On the pricing aspect, I find the setup cost and licensing of Splunk Enterprise Security to be relatively cheaper compared to what we used earlier. I can say that what we are paying is worth it based on the value we receive.
Which other solutions did I evaluate?
We decided to switch to Splunk Enterprise Security because of the ecosystem. We are also using Splunk Cloud, and we have a good relationship with Splunk. The pricing compared to what we were using earlier is worth it.
The key differences, apart from pricing, are the visibility and observability. We did not get good visibility with the previous tools, but now we have a very clear view, which is why we switched to Splunk Enterprise Security.
What other advice do I have?
My advice for anyone considering Splunk Enterprise Security is to understand the basics of logging systems first and determine your use cases before building specific functionalities in Splunk Enterprise Security.
We have recently upgraded to Splunk Enterprise Security 8.0, and we are evolving everything now. We are evolving frameworks and many other things within it. I would rate this review an 8.5 overall.
Which deployment model are you using for this solution?
On-premises
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Other
Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
Last updated: Jun 19, 2026
Flag as inappropriateBuyer's Guide
Download our free Splunk Enterprise Security Report and get advice and tips from experienced pros
sharing their opinions.
Updated: September 2026
Product Categories
Security Information and Event Management (SIEM) Log Management IT Operations AnalyticsPopular Comparisons
IBM Security QRadar
Splunk AppDynamics
Microsoft Sentinel
Elastic Security
IBM Turbonomic
Palantir Foundry
WhatsUp Gold
LogRhythm SIEM
Rapid7 InsightIDR
Buyer's Guide
Download our free Splunk Enterprise Security Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- Which would you recommend to your boss, IBM QRadar or Splunk?
- What are some of the best features and use-cases of Splunk?
- What SOC product do you recommend?
- Splunk as an Enterprise Class monitoring solution -- thoughts?
- What is the biggest difference between Dynatrace and Splunk?
- IBM QRadar is rated above competitors (McAfee, Splunk, LogRhythm) in Gartner's 2020 Magic Quandrant. Agree/Disagree?
- What are the advantages of ELK over Splunk?
- How does Splunk compare with Azure Monitor?
- New risk scoring framework in the Splunk App for Enterprise Security -- thoughts?
- Splunk vs. Elastic Stack


















