My main use case for Splunk Enterprise Security is risk-based alerts. I have a lot of scenarios, custom scenarios that add risk to a user. When it hits a certain unacceptable limit, we trigger the alert. There are many of these specific risk-based alerts.
The best features Splunk Enterprise Security offers include the ease at which changes can be made as an engineer or as a lead to deploy rules. That has been streamlined in the latest versions, and it is incredibly helpful.
The way it has improved is time. I am not spending as much time doing these things as I used to. The whole process is faster, it is easier, and it just gets done a lot quicker, generating a lot less frustration.
The best thing that Splunk Enterprise Security brings in is the risk-based alerting. The other system we use is Microsoft, which does not do risk-based alerting at all in any way. This is the main value that Splunk Enterprise Security is bringing.
We have definitely seen an increase in the amount of alerts that actually need attention. We have seen a decrease in things that could be a thing, but it really does not look like it. Instead of investigating those things now, we are assigning risk and moving on. It has really been the time-saver and the focus on what is probably more important.
The one area that I would say at one point did need help and attention would have been Mission Control. However, that seems to have been really worked on, and it appears to be stabilizing out now.
I have been using Splunk Enterprise Security for about three years.
In our environment, Splunk Enterprise Security is stable.
We have thrown quite a bit more at Splunk. We are bringing in new tools every year to help us with the gaps we have, visual knowledge gaps, and just log gaps. All of those new tools are generating logs. While we are not maybe adding a ton of workstation logs every year because we are not increasing staff by a ton, we are throwing a lot more logs at Splunk, and it seems to be handling it just fine.
We have never called Splunk, but we have put in tickets with Splunk. Generally, the support folks are receptive. Once in a great while, somebody is not, but they are the exception, not the rule.
We use Splunk on-premises and we are moving to Splunk Cloud. It is kind of the same solution.
The metric that I would say we are really looking at is time saved. That is a lot. Time saved on getting things isolated, getting things remediated, and just in general, any task that needs to be done with Splunk has been faster due to upgrades from Splunk. It is very nice.
Our sales reps were very interested in continuing with us, so they were very motivated to get us some discounts. That ultimately was one of the deciding factors, not the only one, but one of them in making sure that we stayed with Splunk. Setup cost has not been something anyone except the CISO is really aware of yet. The licensing cost seems to be a good price for what we are getting.
CrowdStrike was one of them, and Sentinel was one of them.
We are about to move to the Premier Cloud edition of Splunk Enterprise Security. I do not know what new features are going to be available there.
Regarding Splunk Enterprise Security's AI capabilities, we have not really used any of the AI functions in Splunk Enterprise Security at all. My experience with them is incredibly limited, pretty much to the level of only testing. In general, I think it has good output and good understanding of the questions. Sometimes it goes a bit off the rails, but in general, the AI will understand the question, properly research the answer, provide a good answer, and even provide recommendations. Overall, it seems to be a very good product.
We are currently on-premises. Within the next two to three months, we are moving to cloud. That has not been determined, but more than likely, it will be Azure.
Splunk does have an incredible ability to react. Alerts are thrown almost in real-time. Currently, we are not using any agents, but even so, these alerts are put in front of analysts who are sitting there waiting for alerts. Our time to start work on these things is very small, even without the AI agents. With the agents, it is going to be even faster to respond. We will probably get a lot of these false positives worked out. That is currently one of the things I should have mentioned earlier. Splunk Enterprise Security does throw some false positives. It, as anything, needs some tuning. But it is pretty accurate. An agent would be very helpful in filtering out false positives.
The MITRE material is incredibly helpful for audits, but in general, our analysts are not really using that piece of Splunk Enterprise Security very much at all. I do a bit more, but I would say it is underutilized. However, it is nice that it is there.
This has been very helpful. It has also been a pain once in a while when intelligence feeds put something silly in there, and we end up blocking Google or something. That is generally a one-off occasion. The majority of the time, it is very helpful. We see domains blocked that we did not even know were bad. We had no reason to even investigate this domain, and Splunk Enterprise Security has already stopped any connection. It is very helpful.
We do not currently have SOAR, UEBA, and Splunk Enterprise Security all in the same interface. Currently, they are different interfaces. We do not even have UEBA. Unfortunately, we have not made the move to the cloud yet, so I cannot really give you a good answer.
We have not cut any employees because we do not have employees to manage alerts. We have employees for coverage. This, despite the advantages, and even when we bring in the automatic AI agents, we will not be losing any employees, as again, they are there for coverage.
I would rate this review a 9.