I confirm that I am a customer of this solution, like an end user, and I usually use Splunk Enterprise Security for various use cases.
My favorite features of Splunk Enterprise Security include creating dashboards according to our understanding, having a very user-friendly query language that allows us to query the data and get the output we need, and creating alerts while integrating different types of services in Splunk so that we directly receive all error reports and production log reports in our email IDs. This is a very helpful feature for us because I recently integrated different types of mail services into Splunk. Our alerts and reports run based on a cron scheduler, which allows us to decide when to trigger alerts and reports.
Splunk Enterprise Security has positively impacted our organization by helping us monitor our services effectively. It allows us to easily identify consumer issues, especially when a consumer reports an error, as we have around 50,000 consumers in our organization, all of whom use Splunk. With Splunk Enterprise Security, we can search logs on different bases using trace IDs and span IDs, making security very effective, and integrating it into our services is easy, managing distributed transactions with ease.
I have seen that AI-driven detections and assistance have improved the accuracy of my investigations with Splunk Enterprise Security. It integrates AI features that provide quick summaries for all our traces.
The capabilities of Splunk Enterprise Security support my team in making faster, data-driven decisions because its query language is very easy to understand, resembling simple English. We write a query, specify our index and source, and get output in a very straightforward manner.
Splunk Enterprise Security has significantly reduced my team's average mean time to resolve issues. Unlike platforms such as Honeycomb, which only provide traces, Splunk Enterprise Security gives us end-to-end flow data, allowing us to see the entire data flow from start to finish when a process is created.
We have managed to reduce our average time to resolve issues by approximately 80%. Previously, debugging took around four to five hours locally, but using Splunk Enterprise Security, we can resolve the same issues in only an hour or less than an hour.
Splunk Enterprise Security has helped reduce my team's average mean time to detect issues. Approximately, we have managed to reduce that time by around 70 to 80%.
The risk-based alerting features of Splunk Enterprise Security have significantly impacted my alert volume and analyst productivity. The powerful, optimized searching language is easy to understand, allowing us to monitor our services in real-time and customize dashboards and data. We can create small components in our Splunk Enterprise Security dashboard for proper end-to-end communication flow, and the strong alerting system, along with enterprise support, makes Splunk Enterprise Security very efficient.
I evaluate the threat topology and MITRE ATT&CK framework features in Splunk Enterprise Security as very effective for discovering the overall scope of incidents. With distributed services, Splunk Enterprise Security allows easy integration and provides a single point of monitoring for all our services.
Splunk Enterprise Security has helped me detect threats faster. Tracing is very easy, which reduces debugging time and gives direct results with end-to-end traces across all services. This reduces our time by around 70 to 80%, allowing us to develop solutions for consumers quickly, especially when they raise incidents.
Splunk Enterprise Security Essentials has contributed to a reduction in analyst burnout or fatigue. My experience with Splunk Enterprise Security has been very good, although I encounter a minor issue with time limit exit errors when filtering data over longer durations. This occurs about five to ten percent of the time. If I limit the data to 15 to 20 days instead of one or two months, the experience improves significantly. However, sometimes running multiple queries in background tabs leads to session errors.
Splunk Enterprise Security Essentials has improved my team's daily work experience and retention as our team has been using Splunk Enterprise Security for the last two years and has not shifted to any other platform because all team members find it very user-friendly and the overall experience is excellent.
The integration of threat intelligence directly into the TDIR workflow has indeed improved our ability to preemptively block threats. Splunk Enterprise Security automatically finds telemetry logs and performance data from our infrastructure, enabling data pipeline automation, built-in AI and predictive monitoring, and continuous network visibility.
I find the pricing and licensing of Splunk Enterprise Security to be decent, though it can sometimes seem expensive. However, the scalability and capabilities it provides justify the price, particularly for larger organizations. I would definitely suggest that people use Splunk Enterprise Security, as it significantly improves productivity by allowing tasks that previously required two people to be completed by one due to reduced debugging time.
I have been working with Splunk Enterprise Security for two years, and I am still working with it.
The reliability and stability of Splunk Enterprise Security are commendable because integration is straightforward, user experience is excellent, and the query language is very user-friendly. Anyone with basic programming knowledge can easily understand how to query data effectively. Additionally, its most helpful feature allows searching any log using specific keywords, which provides accurate output even for those unfamiliar with query language.
The scalability level of Splunk Enterprise Security is very optimized and excellent, as it can handle millions of transactions and logs are processed in fractions of seconds. We can easily scale our Splunk Enterprise Security infrastructure.
I do not often communicate with the technical support of Splunk Enterprise Security because I have not faced any issues in my last two years of using the platform.
When I encounter issues, I rely on the official documentation provided by Splunk Enterprise Security, which is very helpful. The product documentation is the best source for finding information regarding the product, and I always go to the documentation when I am uncertain about something.
I have not used different technologies for these use cases before Splunk Enterprise Security; since I joined my organization, we have only been using Splunk Enterprise Security. In my previous organization, they may have used another platform such as Sentry.
Regarding the native UEBA capability of Splunk Enterprise Security, we have created an internal platform for data exports to Splunk Enterprise Security. However, I am not fully grasping the specifics of how it enhances visibility into unknown, sophisticated, or insider threats. I would rate this review at 9.8 out of 10.