No more typing reviews! Try our Samantha, our new voice AI agent.
reviewer2704098 - PeerSpot reviewer
Security & Risk Analyst at a computer software company with 1,001-5,000 employees
Real User
Top 20
May 10, 2025
Exceptional user interface and integrations enhance analytical capabilities
Pros and Cons
  • "The community marketplace is useful; often, you do not need to rely on Splunk Enterprise Security support due to the wealth of online documentation available—Splunk docs are truly beneficial."
  • "Splunk Enterprise Security is amazing."
  • "One area Splunk Enterprise Security fails to improve is the pricing aspect; while the initial pricing seems fine, the licensing cost can skyrocket over time, creating trauma for organizations."
  • "The default threat intel feeds create many false positives and noise, which is counterproductive."

What is our primary use case?

My use cases for Splunk Enterprise Security involve mostly standard use case detections. Essentially, whatever log sources we ingest into the platform, we define use cases for detecting anomalous behavior, with most of our use cases tied to that. 

Additionally, we utilize threat intelligence; we always use lookup tables or MISP integrations to enrich those use cases or create reports and dashboards to monitor them periodically, depending on how noisy those alerts are. 

Other use cases include compliance-based use cases for auditing purposes, as there are compliance policy breaches we want to monitor proactively on a 24/7 basis. We do that, often within a mix of MSSP environment versus in-house.

What is most valuable?

The specific features I find the most valuable in Splunk Enterprise Security include the amazing UI and good integrations, and I can say this from a practitioner standpoint. 

It is just comfortable. Splunk Enterprise Security is easy to use for an analyst, and the whole analyst experience is great; it is pretty insane. It is honestly very addicting. 

As I told my fellow colleagues, they love using Splunk Enterprise Security. Once you go to any other platform, it is similar to going through withdrawal sometimes. You have to set up use cases, update data models, and link the right use cases to the right data models for those detections to happen. 

In terms of challenges, there are none; Splunk Enterprise Security is one of the best vendors in the security analytics space.

Splunk Enterprise Security has implemented improvements that may help reduce false positives, as it has some amazing features that go underutilized, such as the machine learning toolkit. The gap in skill set within the SOC environment is the reason for this underutilization.

Splunk has some amazing features we are not utilizing. For example, ML. I have not specifically utilized AI-driven security initiatives or machine learning within Splunk Enterprise Security; even the ML toolkit is not related to advanced AI components. It operates more an advanced SQL query based on existing data trends without offering out-of-the-box advanced ML capabilities to provide significant value.

The dashboards for some default use cases are provided. Similarly, default dashboards and reports are provided. You can pivot off of these and drill down on your investigations. The Splunk query language is definitely very easy to understand and use on a regular basis. The learning curve is also very low. So, from a practitioner standpoint, you're not going to face so much struggle in learning the Splunk query language. In fact, for other solutions, you might need AI capabilities to translate natural language. 

Additionally, Splunk Enterprise Security claims to reduce data storage to a certain extent. I'm not sure if that's the case, however, I have heard that that was the case.

Lookup tables are very useful in Splunk. 

What needs improvement?

The effectiveness of threat detection and response in Splunk Enterprise Security depends on how the team leverages it. Splunk Enterprise Security is not something that automatically picks things; you have to set up use cases, update data models, and link the right use cases to the right data models for those detections to happen. This is SIM-tool agnostic. If you do not have the right use cases, nothing will be detected at the end of the day. 

One challenge under that note is if your company goes through some kind of digital transformation or major solutions being replaced, and all these logs are being ingested into Splunk Enterprise Security, the data models do not get updated proactively. Splunk Enterprise Security does not have a mechanism to identify that certain data models have stopped sending logs. How do we update our data models accordingly? This issue reflects back to our use case detections.

In discussing areas for improvement in Splunk Enterprise Security, I assert that their default threat intel is inadequate. When ingesting threat intel from other sources, it would be beneficial to have capabilities that enrich the information within Splunk Enterprise Security with less dependence on a threat intel platform. The default threat intel feeds create many false positives and noise, which is counterproductive.

The UEBA aspect of Splunk Enterprise Security should also see enhancement, as it lacks that functionality.

Splunk search can sometimes take a long time; it can even time out. You have to make sure your query is very specific. It would be useful if Splunk used AI to help you write queries. I'm not sure if AI is used this way just yet.

For how long have I used the solution?

My experience with Splunk Enterprise Security is from within the last 18 months.

Buyer's Guide
Splunk Enterprise Security
September 2026
Learn what your peers think about Splunk Enterprise Security. Get advice and tips from experienced pros sharing their opinions. Updated: September 2026.
915,325 professionals have used our research since 2012.

What do I think about the stability of the solution?

Regarding stability with Splunk Enterprise Security, I do not recall facing performance issues at the moment. 

What do I think about the scalability of the solution?

The solution can scale. When your environment scales, the search operations can lag significantly.

One entity I worked with was a managed service company that managed companies of all sizes, up to 30,000 or 40,000 employees. We work with large firms. 

How are customer service and support?

The technical support of Splunk Enterprise Security is quite good, and I would rate it a four out of five (eight out of ten) easily. They are responsive and effectively resolve issues. 

The community marketplace is also useful; often, you do not need to rely on Splunk Enterprise Security support due to the wealth of online documentation available—Splunk docs are truly beneficial.

Which solution did I use previously and why did I switch?

I enjoy my work with Splunk Enterprise Security, and while I can say the same for Elastic, I have found other vendors such as QRadar, Exabeam, LogRhythm, and Sumologic not to be as impressive. I prefer ElasticSearch since it allows for quicker searches, making threat hunting and proactive activities easier, whereas Splunk Enterprise Security searches can take considerable time.

AlienVault's open-source solutions seemed inadequate compared to this, and QRadar was even worse. Thankfully, they are no longer relevant.

How was the initial setup?

I was somewhat involved in the initial setup of Splunk Enterprise Security. That said, it was not complex enough for a clear comparison with larger environments. 

Deploying indexers and forwarders is straightforward, though human errors can potentially occur in the process. It is challenging for me to compare the implementation of other similar tools versus Splunk Enterprise Security, however, the clarity on implementation could be enhanced. 

Maintaining Splunk Enterprise Security on-premise is not difficult at all, especially compared to other platforms I have not maintained as extensively. Many resources are available in the market to help with Splunk Enterprise Security, so finding people skilled in it is relatively easy due to the market's maturity.

What's my experience with pricing, setup cost, and licensing?

One area Splunk Enterprise Security fails to improve is the pricing aspect; while the initial pricing seems fine, the licensing cost can skyrocket over time, creating trauma for organizations.

It's really hard to justify the pricing. The only way it makes sense is if you reduce the number of nodes being ingested over time. If you can optimize that as you scale, it can stay affordable. 

What other advice do I have?

Now that Splunk Enterprise Security has been acquired by Cisco, I am uncertain whether it will retain its current traction or be dissolved in the coming years. 

I would rate Splunk Enterprise Security as a product an easy eight out of ten.

However, it is an easy eight as of now. Post-Cisco acquisition, the future remains uncertain. Would I recommend Splunk Enterprise Security to someone else? Absolutely. Splunk Enterprise Security is amazing. Despite all the issues, it simplifies the lives of everyone who uses it, and there is not a steep learning curve. 

Compared to other tools I discussed earlier, Splunk Enterprise Security is significantly better. Personally, I would choose Elastic and Splunk Enterprise Security over any other options.

Which deployment model are you using for this solution?

On-premises
Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
PeerSpot user
reviewer2898990 - PeerSpot reviewer
detection engineer at a real estate/law firm with 1,001-5,000 employees
Real User
Top 20
Sep 16, 2026
Advanced alerting has reduced false positives and now improves targeted threat detection
Pros and Cons
  • "Splunk Enterprise Security has positively impacted my organization by allowing us to alert and use its threat intel and asset modeling capabilities to accurately see what is happening, when it's happening, and who it's happening to."
  • "Regarding Splunk Enterprise Security's AI capabilities in terms of accuracy and reliability of output, I think by default, they were not that good."

What is our primary use case?

I have been using Splunk Enterprise Security for about five years.

My main use case for Splunk Enterprise Security is building security alerting detections for our SOC.

A quick, specific example of a detection I've built with Splunk Enterprise Security is that we detect users clicking on a malicious phishing link and alert the SOC for it.

To build that detection, we used the email data model as well as the content and alerting framework that is built in Splunk Enterprise Security.

What is most valuable?

The best features Splunk Enterprise Security offers are a clean way to organize and alert on detections and data modeling to categorize and sanitize data.

The data modeling and organization features of Splunk Enterprise Security help me in my daily work by allowing us to sanitize multiple different data sources, such as multiple firewalls or multiple email logs from different sources, into one similar set of logs so that we can easily switch between them without having to relearn new schema.

Splunk Enterprise Security has positively impacted my organization by allowing us to alert and use its threat intel and asset modeling capabilities to accurately see what is happening, when it's happening, and who it's happening to.

The specific outcomes or improvements I've seen with Splunk Enterprise Security include a large decrease in false positive tickets and a higher increase of relevant, targeted tickets when using the risk-based alerting framework. It has also made it faster to spin up and create new detections.

What needs improvement?

An improvement that could be made in Splunk Enterprise Security is proper version control for our content and alerts that are built in it.

For how long have I used the solution?

I have been using Splunk Enterprise Security for about five years.

What do I think about the stability of the solution?

Splunk Enterprise Security is stable.

What do I think about the scalability of the solution?

Splunk Enterprise Security's scalability is fine; you can put as many indexes and search heads as you need and they scale reasonably well.

How are customer service and support?

The customer support has been up and down. Our sales associates and team have been very good, but the support through the portal is adequate.

Which solution did I use previously and why did I switch?

I did not previously use a different solution before Splunk Enterprise Security.

How was the initial setup?

My experience with pricing, setup cost, and licensing was adequate. We purchased it, and it was set up with some professional services and licensed.

What about the implementation team?

We purchased it, and it was set up with some professional services and licensed.

What was our ROI?

I think it's hard to measure the return on investment, but I believe it has been more of an expansion of our detection and alerting capabilities than it is a matter of employees' work being saved.

What's my experience with pricing, setup cost, and licensing?

My experience with pricing, setup cost, and licensing was adequate. We purchased it, and it was set up with some professional services and licensed.

Which other solutions did I evaluate?

Before choosing Splunk Enterprise Security, I evaluated Elastic and Datadog as other options.

What other advice do I have?

Regarding Splunk Enterprise Security's AI capabilities, I think they're a good starting point, but as Splunk Enterprise Security evolves, the AI features will change a lot and I'm not sure what direction it will take right now.

Regarding Splunk Enterprise Security's AI capabilities in terms of accuracy and reliability of output, I think by default, they were not that good. When we input metadata and skills about where our content lives and how it lives, it got significantly better, but it was not good at finding these things by default.

Splunk Enterprise Security is deployed in a public cloud environment in my organization. We use AWS as our cloud provider.

Splunk Enterprise Security does identify problems, and with proper dashboards, it shows us issues and alerts and observability issues or when something is down very well.

Splunk Enterprise Security has helped reduce my team's average mean time to resolve (MTTR) metric because it allows our alerts to be targeted and efficient, delivering direct alerts about specific things as opposed to broader, wider alerts that were harder to triage.

Splunk Enterprise Security has helped reduce my team's average mean time to detect (MTTD) because it makes it easy and efficient to build alerts to detect these things and schedule them aggressively so that the detection appears very soon after the event.

Splunk Enterprise Security's risk-based alerting (RBA) has impacted my alert volume and analyst productivity by being great for reducing alert volume. By combining multiple indicators, we can have a comprehensive alert and a full picture of what happened on a system as opposed to multiple similar alerts that may or may not be noise.

I assess the threat topology and MITRE ATT&CK framework features for helping me discover the overall scope of an incident by noting they show us where holes are in our detections and what we have and don't have in terms of data sources and detection capability.

My advice for others looking into using Splunk Enterprise Security is that it is a product that rewards knowledge and time put into it. It is something that you can use and learn about and become really proficient in, and it will help you a lot.

I rate this product an 8 out of 10.

Which deployment model are you using for this solution?

Public Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Last updated: Sep 16, 2026
Flag as inappropriate
PeerSpot user
Buyer's Guide
Splunk Enterprise Security
September 2026
Learn what your peers think about Splunk Enterprise Security. Get advice and tips from experienced pros sharing their opinions. Updated: September 2026.
915,325 professionals have used our research since 2012.
Cyber security analyst at a government with 5,001-10,000 employees
Real User
Top 20
Sep 16, 2026
Compliance has improved and incident response transforms while complexity still requires simplification
Pros and Cons
  • "Splunk Enterprise Security has vastly improved the amount of time that it takes to respond to an incident, which has been truly helpful."
  • "In my personal opinion, it is too complicated. Installing forwarders and trying to get an overview of a network topology with Splunk Enterprise Security is challenging."

What is our primary use case?

Audit reviews, log analysis, and asset visibility.

What is most valuable?

Splunk Enterprise Security excels at manipulating and viewing all of your data. It has allowed us to pass three federal audits and proved invaluable for demonstrating that we are utilizing security and meeting government regulations.

What needs improvement?

In my personal opinion, it is too complicated. It is an immensely powerful tool, but it could be simplified. Installing forwarders and trying to get an overview of a network topology with Splunk Enterprise Security is challenging.

For how long have I used the solution?

Two years.

What do I think about the stability of the solution?

Yes.

What do I think about the scalability of the solution?

Splunk Enterprise Security is immensely scalable.

How are customer service and support?

It is very expensive. I would start with professional services and drastically overestimate the amount of resource usage that you will need. I would honestly recommend starting off in a clustered environment.

Which solution did I use previously and why did I switch?

No.

What was our ROI?

I would say that it has drastically helped the business unit because it allows us to meet government requirements, which means we are actually allowed to operate. I feel that if we did not have Splunk Enterprise Security or a SIEM tool, we would not be able to operate the business.

What's my experience with pricing, setup cost, and licensing?

It is very expensive.

Which other solutions did I evaluate?

We did not consider alternate solutions.

What other advice do I have?

Alerting is valuable. I do not think the integrations are comprehensive. It seems that Splunk Enterprise Security does not work well with other products that are not Splunk Enterprise Security.

Splunk Enterprise Security has vastly improved the amount of time that it takes to respond to an incident, which has been truly helpful.

It is not necessarily a percent improvement; it is an absolute transformation. We were not capable of responding correctly, and now we are, so I would say the improvement is from zero to one hundred.

Splunk Enterprise Security has immensely helped in this regard as well. It is not a percentage increase but rather an absolute shift from no to yes.

It provides many alerts, but it is almost excessive. When Splunk Enterprise Security has an error or is experiencing an issue, it will send hundreds, if not thousands, of alerts.

I find the alerts helpful to some degree. It seems that many incidents are different.

I would recommend attending Splunk conference and starting off a little faster. I would rate this review as seven out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Last updated: Sep 16, 2026
Flag as inappropriate
PeerSpot user
reviewer2899332 - PeerSpot reviewer
Information Security Engineer at a financial services firm with 5,001-10,000 employees
Real User
Top 20
Sep 16, 2026
Centralized alerts have improved soc workflows but triage and ai features still need refinement
Pros and Cons
  • "Analysts can review all the alerts in one pane of glass instead of going through multiple different security tools and managing or investigating alerts there."
  • "Customer support for Splunk Enterprise Security is good; sometimes it's not as fast as I would prefer, but it has been useful."

What is our primary use case?

My main use case for Splunk Enterprise Security is being an engineer for the SOC and insider threat risk team, where I monitor threat detection, manage the queue for a SOC, and ensure Splunk Enterprise Security data it uses is working properly.

I give a quick specific example of how I use Splunk Enterprise Security in my day-to-day work by tuning detections, creating new detections, enabling any new features that come in, assessing identity, managing that, or RBA, and addressing any issues that arise that SOC analysts see, working on those with Splunk support or with the internal team.

How has it helped my organization?

Analysts can review all the alerts in one pane of glass instead of going through multiple different security tools and managing or investigating alerts there.

This change has definitely led to measurable improvements, as it is faster, and the integration also helps analysts avoid jumping around too much, allowing them to do everything in one place, which also allowed us to create custom detections that were not covered by the security tools.

What is most valuable?

The best features that Splunk Enterprise Security offers are that it can get data from your SIEM, which is Splunk, and also has SOAR, along with the different tools that you can utilize and the different tools that Splunk provides that we can easily integrate into Splunk Enterprise Security.

I can tell you more about those integrations; all the logs that I collect from cloud providers can have my EDR tools' logs coming in, and then connecting to my EDR tool or enriching data via SOAR, and application data that's already in Splunk, utilizing that to create security alerts, is very valuable.

What needs improvement?

I believe Splunk Enterprise Security can be improved by getting into the authentic SOC space; right now, the triaging it does is able to handle some of it, but I think it would benefit from going further into that, and a lot of performance issues that were seen before have been improved, although some errors or performance issues still occur once in a while.

One specific issue I've noticed is not performance-related, but with Splunk and SOAR integration, if I use the entry ID with the auth extension, I get a 404 error after a certain time, as there is a time to live, and by default, it's one hour, and support has indicated this is by design, so this is one of the issues I see with Splunk and SOAR integration that could be improved.

Regarding Splunk Enterprise Security's AI capabilities, I think it can definitely be improved, especially re-running searches for metadata, such as getting index source and source types; it's session-by-session based, so if it can store and learn my environment and not have to run those searches every session, that could save a lot of resources and improve efficiency.

For how long have I used the solution?

I have been using Splunk Enterprise Security for three years.

What do I think about the stability of the solution?

Splunk Enterprise Security is stable.

What do I think about the scalability of the solution?

Splunk Enterprise Security has good scalability.

How are customer service and support?

Customer support for Splunk Enterprise Security is good; sometimes it's not as fast as I would prefer, but it has been useful.

Which solution did I use previously and why did I switch?

Previously, I used multiple different security tools, including EDR tools and cloud security tools, before switching to Splunk Enterprise Security.

How was the initial setup?

I have upgraded to Splunk Enterprise Security 8.0, and it has definitely supported my team's operations, especially with the team-based queues, making the integration with Splunk SOAR much easier, and the ability to run playbooks from Splunk Enterprise Security queue, with overall small features and errors that I was seeing before being improved in version 8.0.

Which other solutions did I evaluate?

I did not evaluate other options before choosing Splunk Enterprise Security, as we already had it in place before I moved in, so it was just work to enable this.

What other advice do I have?

My advice for others looking into using Splunk Enterprise Security is that if you are not using a tool where all security alerts are seen by your SOC in one pane of glass, this is definitely one of the good tools out there in the industry to take a look at.

Splunk Enterprise Security's risk-based alerting, RBA, is something we want to enable, and I can see it will be beneficial, as we can enable more alerts and gain more insights into users and entities if the risk score is utilized, which also provides us with a narrative if alerts or findings trigger for certain assets or identities.

I rate this solution 7.5 out of 10.

Which deployment model are you using for this solution?

Public Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Last updated: Sep 16, 2026
Flag as inappropriate
PeerSpot user
Kumar Shubham - PeerSpot reviewer
Senior Consultant at a consultancy with 1,001-5,000 employees
Consultant
Top 20
Jul 6, 2026
Advanced correlation has simplified threat hunting and now delivers faster incident investigations
Pros and Cons
  • "The unique and most valuable feature in Splunk Enterprise Security is the correlation capability and the SPL query language itself."
  • "Splunk Enterprise Security is a costlier tool compared to ArcSight or IBM QRadar."

What is our primary use case?

Splunk Enterprise Security has an upper hand when compared with other products. We can correlate multiple data sources for generating alerts through SPL. Although many find it complex, we found it much easier because recursive query hunting for identifying threats is straightforward and quick. Those are the aspects which we really appreciated.

For detecting threats, we have created use cases over Splunk Enterprise Security. We have onboarded multiple third-party products with Splunk Enterprise Security. On top of that, we have created multiple use cases correlating multiple third-party vendors. For example, if event A happens where data is B, we have defined those scenarios in queries to trigger the alert.

What is most valuable?

The unique and most valuable feature in Splunk Enterprise Security is the correlation capability and the SPL query language itself. Through an SPL query, we can even identify ransomware scenarios where we can execute large queries and receive results within a few seconds. That aspect gives Splunk Enterprise Security an upper hand with their own query language.

Splunk Enterprise Security helps us reduce the time to react to alerts because the query itself executes so fast that when investigating something in big data set scenarios, it provides significant assistance. Splunk Enterprise Security has the feature of correlating multiple data sources to generate alerts. The risk factor is the second feature where it triggers to identify the severity level of the alert. While correlating multiple data sets along with the query itself, it gives us exactly what we need if we have proper understanding.

The main benefits that Splunk Enterprise Security provides for us as an end user is that it is a well-known tool. When it comes to querying or identifying any data from a big data set or data lake scenario, the query executes so fast and gives us a good outcome.

What needs improvement?

A FIM integrating model would be one improvement that Splunk Enterprise Security could add because Splunk Enterprise Security is a costlier tool compared to ArcSight or IBM QRadar. A FIM monitoring scenario would help.

Regarding pricing, this depends on company preferences. If a company wants to go with a brand, they will opt for Splunk Enterprise Security because it is well-known and a majority of familiar brands or big brands trust Splunk Enterprise Security. To increase their revenue, they could drop the price slightly because there are customers who do not care about money and have an ample amount of budget, and if they think about security, they will go for security. There are customers who are looking at the security side as well as the financial front, and they do not go for Splunk Enterprise Security. They opt for ArcSight or IBM QRadar instead. The pricing of the Enterprise version is at a higher end compared to any other well-known product.

For how long have I used the solution?

I have been using Splunk Enterprise Security for more than five years.

What do I think about the stability of the solution?

From a scale of one to ten, I rate the stability of Splunk Enterprise Security as a nine point five or a ten.

What do I think about the scalability of the solution?

In terms of scalability, the ability to scale and expand is a nine.

How are customer service and support?

My rating for Splunk Enterprise Security technical support is not very high, as I have not interacted extensively with Splunk Enterprise Security support because in our organization itself, we have five people who are Splunk certified architects.

How was the initial setup?

The initial setup for Splunk Enterprise Security is not complex, but it is not simple either. If an administrator wants to implement it, they have to do some homework at their own level before proceeding. When we compare it with Wazuh, for example, Wazuh has a one-click installation scenario. There is one script that you have to run and automatically everything is done. You are ready to go and your tool is set up.

Which other solutions did I evaluate?

In my opinion, the main competitors for Splunk Enterprise Security are IBM QRadar and ArcSight. There are many products and everyone has their own capabilities.

What other advice do I have?

Regarding the customization and development part inside Splunk Enterprise Security, we can create our own customized dashboards for whatever we need. If you understand Splunk Enterprise Security completely, you can create customization or you can request certain help on the support front, and they can assist you with that.

Splunk Enterprise Security provides better functionality when it comes to investigating data because when there is an incident, the analyst or the CISO wants to gain an upper hand as soon as an attack or breach has been detected. The SPL queries give an upper hand while fetching data compared to any other tool. That is the only difference, or the key difference.

In my opinion, Splunk Enterprise Security does not help to improve a company's or business's resilience because a majority of companies use Splunk Enterprise Security for security purposes. Rather than that, any AI or ML professionals or data science engineers would prefer Elastic, which is an open-source tool, to analyze data.

We recommend Splunk Enterprise Security to other users that if a customer has a good budget, they can go for a Splunk Enterprise Security solution. It depends on what the client is looking for and what they want to achieve. If they are going through funding, they want to showcase to the investors that they have a security team and they are using a grade-A solution in place to get additional checks. I give this review an overall rating of nine.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Last updated: Jul 6, 2026
Flag as inappropriate
PeerSpot user
Mohan Janarthanan - PeerSpot reviewer
Associate Vice President at Novac Technology Solutions
Real User
Top 5Leaderboard
Jun 3, 2026
Unified analytics and AI-driven risk-based alerting have transformed our security operations
Pros and Cons
    • "The NLP-based thing will give risk-based alerting which will reduce more than 50%, but I could see only 30%."

    What is our primary use case?

    My use cases include continuous security monitoring on our log management, forensic activity, and threat detection piece and analytics of Splunk Enterprise Security. We are using Cisco and Splunk all-in-one console, where I can get the indexes, forwarders, and logs to consolidate my data center security and cloud portions. All logs will move to Splunk Enterprise Security.

    What is most valuable?

    They are good at the detection piece and the analytics piece. I do not want to create a customized rule. The rules which they have on the analytics piece cover part of my use cases. For example, if I want to create a manual use case in my other product, Splunk Enterprise Security, QRadar, or FortiSIEM, I have to create a manual use case. Here, I do not want to create anything. The analytics plays a major role. They have 2,000 analytics use cases where I can deploy based on my use case and environment.

    The only advantage I can communicate is that in threat detection, triaging, investigation, and response, I will get in a single platform. I do not want to go to multiple platforms. If I am using a SIEM product in one solution and a SOAR product in a different solution, I do not want to go to multiple management consoles. I want a unified console that I can use. That is Splunk all-in-one console.

    SecOps only the product does. Most of my unified governance will be taken care of by SentinelOne Enterprise Security. It has artificial intelligence, it has a SOAR, it has a SIEM. They have agentic artificial intelligence where we can integrate in SecOps platform.

    Triaging is part of risk-based solution. Risk-based alerting will reduce the alert volumes around 30% to 40%. They committed something, but at least I could see the risk-based alerting. From 30%, alert volumes are off now. Basically, it is reducing my manual L1 work.

    Normally on traditional SIEM, they will pull all the logs and send all the 100% volumes. All alerts will go to my SIEM console and manually we have to find the alerting. We have to create a use case and offense and see that. But they have an artificial intelligence piece. The NLP-based thing will give risk-based alerting which will reduce more than 50%, but I could see only 30%. They committed something. Probably it is only a matter of time. We can also leverage their threat intel platform. That is one of the major use cases and a decision factor while we are going with that product.

    What needs improvement?

    I have recently adopted the product. Six months ago I did the testing. Three months ago I started implementing the product.

    I have faced issues only while I was doing my UAT environment, not the production piece. While I was testing, I could see something.

    I have recently implemented the product. I do not want to give wrong commitment or wrong information. As of now, I have not come across any negative feedback or lack of services. I am not able to see anything. Because I am using it for last three months, if you are calling me after two months, probably I can explain better.

    For how long have I used the solution?

    I have been using the solution for three months only.

    What do I think about the stability of the solution?

    There has been no downtime so far, but I am using it for the last 90 days only. I have not faced any issues.

    How are customer service and support?

    The customer service has been excellent.

    Which solution did I use previously and why did I switch?

    We have not done Cloud Security Posture Management.

    It is a great solution for risk-based alerting. It is reducing my 30% workload currently.

    What was our ROI?

    For me, time is the most important factor. If you are saving time, definitely you are saving money also.

    What other advice do I have?

    Splunk Enterprise Security is what I am currently using. We discussed Distributed Services only, but not other products from F5. Regarding Zscaler Internet Access, I am not using that product. Regarding Unified Vulnerability Management, I told you no and I am not using that product. I am using Splunk Enterprise Security, which is a SIEM solution. SentinelOne is another product I have integrated. I integrated firewall logs, app gateway logs, and EDR logs. Threat detection capability is a unified threat detection, which is a basic one we are having. That is part of my SOAR platform. The artificial intelligence-powered security options gives a more fine-tuning alert mechanism where I can get the threat detections. I can do alerting and triaging. My whole incident response is based on that. Definitely it is a leading product. I would say analytics is the most valuable currently. I am comparing it with my Microsoft Sentinel. The proof of concept validations and concepts do take time while you are doing them. I have tested FortiCNAP, but I am not using it. I have tested the product but did not buy it. I am using FortiGate, which is a next-generation firewall. I am also using FortiRecon, FortiManager, FortiAnalyzer, and FortiSIM, and I am using FortiGate firewall on cloud. I am using eight to nine products from Fortinet. My review rating for this product is 9 out of 10.

    Which deployment model are you using for this solution?

    Hybrid Cloud

    If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

    Other
    Disclosure: My company does not have a business relationship with this vendor other than being a customer.
    Last updated: Jun 3, 2026
    Flag as inappropriate
    PeerSpot user
    reviewer2899494 - PeerSpot reviewer
    Especialista en ciberseguridad at a retailer with 11-50 employees
    Real User
    Top 20
    Sep 17, 2026
    Centralized alerts have improved risk visibility and support faster, more accurate investigations
    Pros and Cons
    • "We have seen a clear return on investment since we started using Splunk Enterprise Security; we get a lot of value from it for the business side."
    • "I do not consider Splunk Enterprise Security to be stable. I consider it not to be stable because the platform is very slow, the AI sometimes doesn't return results, and we have encountered that upgrades break things that were already working well."

    What is our primary use case?

    Splunk Enterprise Security's main use case in my organization is centralizing alerts and seeing the risk by asset. Centralizing alerts and visualizing risk by asset has helped us identify which assets are compromised and give them proper attention.

    How has it helped my organization?

    Splunk Enterprise Security has positively impacted our organization by helping us see what risk we have in the company and which assets might be compromised so we can give them proper attention. We have slightly reduced the incident handling time, the MTTR, since we started using Splunk Enterprise Security.

    What is most valuable?

    I consider the best features that Splunk Enterprise Security offers to be the ease of seeing incidents and investigations and being able to give them proper attention.

    The investigations section helps you map very well how an asset is mapped to the incident, for example, an asset with IP, and being able to carry out more complete investigations.

    We also find the Asset and Identities feature very good, and it helps us a lot to be able to search for assets by IP or by MAC address, which also helps us with incidents. The Asset and Identities feature has helped us improve visibility in hybrid or multi-cloud environments, and it has positively impacted the confidence we have in our security posture by helping us identify our vulnerabilities or flaws that we have in the organization.

    What needs improvement?

    I think the automation part of Splunk Enterprise Security could be improved. We would like to have a chat with artificial intelligence to be able to ask it to execute playbooks and be more efficient, to request actions or remediations in natural language.

    For how long have I used the solution?

    I have been working with Splunk Enterprise Security for three years.

    What do I think about the stability of the solution?

    I do not consider Splunk Enterprise Security to be stable. I consider it not to be stable because the platform is very slow, the AI sometimes doesn't return results, and we have encountered that upgrades break things that were already working well.

    What do I think about the scalability of the solution?

    Splunk Enterprise Security's scalability is very good; the tool is very scalable, and it can be used for many things. We use it to centralize our security incidents.

    How are customer service and support?

    From one to ten, I rate Splunk Enterprise Security's customer support a six. The aspects of customer support that could be improved to provide a better experience are the level of knowledge and how long they take to respond to incidents.

    Which solution did I use previously and why did I switch?

    We have always used Splunk Enterprise Security to generate dashboards for end users so they can have these dashboards and they help with operations.

    How was the initial setup?

    In this area, I see that licensing costs, initial configuration, and the price of Splunk Enterprise Security fluctuate a lot. By it fluctuating a lot, we have had different licensing calculations, sometimes oversized, sometimes we fall short.

    What about the implementation team?

    We are partners with the vendor besides being a customer.

    What was our ROI?

    We have seen a clear return on investment since we started using Splunk Enterprise Security; we get a lot of value from it for the business side.

    Which other solutions did I evaluate?

    Before choosing Splunk Enterprise Security, we were considering Palo Alto. We ultimately decided on Splunk Enterprise Security instead of other options like Palo Alto because of the customization it has for use cases, for example, it is used for business and it can also be used for security.

    What other advice do I have?

    Splunk Enterprise Security does not help us with business resilience.

    It has helped us reduce incident handling time with SOAR automation and enrichment. It also helps us with the enrichment of events and incidents; it helps us take more precise actions. We have taken advantage of integrating threat intelligence directly into the detection and response workflow. Having threat intelligence integrated into the workflow has helped us see the information generated by the AI.

    The AI-driven capabilities have improved the accuracy of our investigations, and it has supported our team in making faster, data-driven decisions by helping us determine what is a threat and what perhaps just needs tuning for false positives.

    I would advise other companies considering implementing Splunk Enterprise Security to size the license properly and also to map out the onboarding that will be done for the data sources, and to align it with the business where they are implementing the technology since it is not the same for all. I rate this product a nine overall.

    Disclosure: My company has a business relationship with this vendor other than being a customer. Socio
    Last updated: Sep 17, 2026
    Flag as inappropriate
    PeerSpot user
    reviewer2899455 - PeerSpot reviewer
    Architecte Technique at a manufacturing company with 10,001+ employees
    Real User
    Top 20
    Sep 16, 2026
    Risk-based alerts have improved weak signal detection and support daily soc investigations
    Pros and Cons
    • "In my opinion, the best features that Splunk Enterprise Security offers are the RBA part and the fact that you can easily define and develop apps while taking ownership of the tool."
    • "In terms of efficiency, I am not sure Splunk Enterprise Security has brought much value so far, but on the other hand, it provides indicators with all the dashboards offered, which enable us to see better how we handle our incidents."

    What is our primary use case?

    My main use case for Splunk Enterprise Security is detection and SOC activities, so everything related to detection and security. Every day, I use Splunk Enterprise Security to trigger alerts and analyze the risks that are currently affecting our company.

    What is most valuable?

    In my opinion, the best features that Splunk Enterprise Security offers are the RBA part and the fact that you can easily define and develop apps while taking ownership of the tool.

    Regarding the Risk-Based Alerting feature, we are at the beginning of using it, so we are not fully operational yet, but it allows us to pick up weak signals and correlate them, which we previously had some difficulty doing. This enables us to improve the quality of detection on weaker signals compared to what we are used to with direct alerts.

    What needs improvement?

    There is still an aspect of this tool that I think could be optimized or simplified, particularly the CI/CD part to enable all the API and CI/CD aspects. This would allow us to easily deploy solutions while keeping the code in our source repository. Today, we are forced to develop many things whereas Splunk Enterprise Security could probably provide tools that make customers' lives easier.

    For how long have I used the solution?

    I have been using Splunk Enterprise Security for one year.

    What other advice do I have?

    In terms of efficiency, I am not sure Splunk Enterprise Security has brought much value so far, but on the other hand, it provides indicators with all the dashboards offered, which enable us to see better how we handle our incidents.

    These indicators allow us to see where we stand and identify the cases to be handled that are pending.

    At the moment, we do not yet have indicators to answer whether Splunk Enterprise Security has allowed us to reduce the mean time to resolution of incidents, the famous MTTR, within our team.

    We are on Splunk Enterprise Security version 8, and the integration with Splunk SOAR and the dedicated queues is a plus because it was something we were missing.

    I do not notice a reduction in analyst fatigue or burnout thanks to this tool.

    Consolidating SIEM, SOAR, and UEBA functionalities into a single interface has not improved our team's operational efficiency.

    Splunk Enterprise Security has helped improve our organization's resilience to incidents, and we chose to move to the AWS cloud to be resilient and not be tied to our current infrastructure as we were before on-premise.

    I give this product a rating of 8 out of 10.

    Which deployment model are you using for this solution?

    Public Cloud

    If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

    Disclosure: My company does not have a business relationship with this vendor other than being a customer.
    Last updated: Sep 16, 2026
    Flag as inappropriate
    PeerSpot user
    reviewer2898942 - PeerSpot reviewer
    Vulnerability Management Analyst at a energy/utilities company with 1,001-5,000 employees
    Real User
    Top 20
    Sep 16, 2026
    Unified log searches have streamlined daily alert investigations and reduced response times
    Pros and Cons
    • "Splunk Enterprise Security has helped improve my organization's business resilience, and Splunk Enterprise Security is really good at the ability to predict, identify, and solve problems in real time."

      What is our primary use case?

      My main use case for Splunk Enterprise Security is searching and log aggregation. I use Splunk Enterprise Security for searching and log aggregation in my daily work by investigating alerts that come across through our SIEM. I engage in manual digging through logs, searching based off of alert criteria.

      What is most valuable?

      The best feature that Splunk Enterprise Security offers is scalability. When I mention scalability, I mean it handles large volumes of data smoothly, even with increases of data because of new projects. Splunk Enterprise Security has positively impacted my organization by making our alert handling and research more efficient and smooth, and it helps us with maintaining logs for industry standard.

      I do not have any metrics showing time saved or improvements in workflow, but instead of having to search multiple tools, we are able to search Splunk Enterprise Security, which allows the process to be quicker.

      What needs improvement?

      I do not have any suggestions on how Splunk Enterprise Security can be improved.

      For how long have I used the solution?

      I have been using Splunk Enterprise Security for four years.

      What do I think about the stability of the solution?

      Splunk Enterprise Security is stable.

      What do I think about the scalability of the solution?

      The scalability of Splunk Enterprise Security is great.

      How are customer service and support?

      Customer support for Splunk Enterprise Security is great.

      Which solution did I use previously and why did I switch?

      I did not previously use a different solution.

      How was the initial setup?

      My experience with pricing, setup cost, and licensing has been fair pricing and an easy setup cost.

      What was our ROI?

      I have seen a return on investment with Splunk Enterprise Security, and it has definitely saved a lot of time more than anything.

      Which other solutions did I evaluate?

      Before choosing Splunk Enterprise Security, I did not evaluate other options.

      What other advice do I have?

      My advice for others looking into using Splunk Enterprise Security is to take advantage of Splunk's resources and training. Splunk Enterprise Security has helped improve my organization's business resilience, and Splunk Enterprise Security is really good at the ability to predict, identify, and solve problems in real time. I recommend other people use it for similar situations.

      Splunk Enterprise Security has helped reduce my team's average mean time to resolve, the MTTR metric. It allows us to search in one place for all the information we need to close an alert. Splunk Enterprise Security has helped reduce my team's average mean time to detect, MTTD metric, because it allows us to base alerts off of many different tools all in one place, and I would say by a couple of hours.

      Splunk Enterprise Security has helped me detect threats faster; it has decreased it. I have not used the threat topology and or MITRE ATT&CK framework features for discovering the overall scope of an incident. I would rate this review a 10 out of 10.

      Disclosure: My company does not have a business relationship with this vendor other than being a customer.
      Last updated: Sep 16, 2026
      Flag as inappropriate
      PeerSpot user
      Computer Systems & Application Specialist II at a mining and metals company with 501-1,000 employees
      Real User
      Top 20
      Sep 16, 2026
      Security monitoring has provided robust dashboards and alerts for network-wide visibility
      Pros and Cons
      • "The pricing, setup cost, and licensing for Splunk Enterprise Security are much better than McAfee, as it is more affordable and seems to be more robust and powerful."
      • "As I mentioned before, we came from the McAfee environment, and in that system, they had alerts visibility where we could easily acknowledge the alerts."

      What is our primary use case?

      Our main use case for Splunk Enterprise Security is to gather all the information that we need and also create some dashboards that can help us understand what's going on in the network.

      For example, we would like to see if there are any failed logging attempts and, based on that, identify the systems or computers that were attempting to access resources, the time they were trying to access them, and obtain the raw data to further investigate.

      We also need to create alerts when problematic events occur. Additionally, when a device is not sending logs, we need to be aware of that situation. We also must be aware of any malware installed on the network and alert on that as well. We would like to have all of this information available in Dashboard Studio.

      What is most valuable?

      I am very curious about Mission Control and Dashboard Studio, along with the administration part of Splunk Enterprise Security.

      With Mission Control, we can see all of the alerts that we have created. That is when we create tickets and acknowledge all alerts. I am not that familiar with it yet, but I am looking forward to learning more about it.

      So far, we have been able to implement some of the alerts that I mentioned. We have full visibility as to what is going on, but I think we are in the early stages of the implementation, so we would like to know more.

      We used to have McAfee SIEM, and we also have full visibility as to all the logs coming into our SIEM devices. It is similar to what we had before, although Splunk Enterprise Security seems to be more robust with all the dashboards and the other capabilities that you can utilize with it.

      What needs improvement?

      As I mentioned before, we came from the McAfee environment, and in that system, they had alerts visibility where we could easily acknowledge the alerts. Based on that, it would show you the time when the incident happened and the time when you acknowledged the alert. I have not seen that specific capability in Splunk Enterprise Security yet. I know that you can acknowledge and then create the investigation, but since we were accustomed to that feature in McAfee, it is a bit different. This is probably just an adaptation issue, but we are still trying to figure it out.

      For how long have I used the solution?

      We just implemented Splunk Enterprise Security last year, so I do not have that much experience working with it, but I am looking forward to gaining more expertise.

      What do I think about the scalability of the solution?

      I think Splunk Enterprise Security can be used for scalability as well. The only thing we have observed so far is the price of the license fee. We know that if we are ingesting more data, it will increase costs, so that will probably be a decision for upper management. However, as far as the capabilities, I think it is very scalable.

      How are customer service and support?

      I have not had the chance to reach out to customer support. I have a co-worker who is the main administrator for that, so personally, I have not had the chance to contact support yet.

      Which solution did I use previously and why did I switch?

      We used to have McAfee SIEM, and we had full visibility as to all the logs coming into our SIEM devices. It is similar to what we had before, although Splunk Enterprise Security seems to be more robust with all the dashboards and the other capabilities that you can do with it.

      We previously used McAfee SIEM, and the reason we switched to Splunk Enterprise Security was because of budgeting issues. McAfee was becoming more expensive, which is why we made the switch.

      How was the initial setup?

      It was implemented on-premises because we manage an air-gapped network, so nothing has access to the cloud at all.

      What was our ROI?

      So far, we are at the same level. From a monetary perspective, it has been an improvement for us, as the implementation of Splunk Enterprise Security was more affordable. However, as far as resources, we still have the same people working on it.

      What's my experience with pricing, setup cost, and licensing?

      The pricing, setup cost, and licensing for Splunk Enterprise Security are much better than McAfee. It is more affordable and seems to be more robust and powerful.

      Which other solutions did I evaluate?

      We did not evaluate other options. Since we work closely with our corporate network team, they already had implemented Splunk Enterprise Security, so that was the first option for us.

      What other advice do I have?

      I would advise others looking into using Splunk Enterprise Security to take advantage of all the free courses and seminars that they offer and also start to learn SPL, because that is another challenge that we faced. We did not know the language, so it was a bit complicated to start building the queries for gathering the data. I would rate my overall experience with Splunk Enterprise Security as a nine out of ten.

      Which deployment model are you using for this solution?

      On-premises
      Disclosure: My company does not have a business relationship with this vendor other than being a customer.
      Last updated: Sep 16, 2026
      Flag as inappropriate
      PeerSpot user
      Buyer's Guide
      Download our free Splunk Enterprise Security Report and get advice and tips from experienced pros sharing their opinions.
      Updated: September 2026
      Buyer's Guide
      Download our free Splunk Enterprise Security Report and get advice and tips from experienced pros sharing their opinions.