No more typing reviews! Try our Samantha, our new voice AI agent.
ROBERT-CHRISTIAN - PeerSpot reviewer
CTO at a tech vendor with 10,001+ employees
Real User
Top 5
Dec 22, 2024
Has many predefined correlation rules and is brilliant for investigation and log analysis
Pros and Cons
  • "They have approximately 50,000 predefined correlation rules, which is quite a lot, and I find that good."
  • "Overall, Splunk is among the top three SIEM tools due to its capabilities and agility in bridging business analytics with security needs."
  • "It is very complicated to write your own correlation rules without the help of Splunk support."
  • "Most importantly, Splunk can be outrageously expensive. That is the problem with both Splunk and Sentinel. Their pricing literally explodes based on the amount of data you feed in."

What is our primary use case?

We are an MSSP, and some of our customers have Splunk Enterprise Security, and we run it for them.

How has it helped my organization?

Splunk Enterprise Security is very good for helping us find any security event across multi-cloud environments.

Splunk's unified platform works very nicely to help consolidate networking, security, and IT observability tools.

It helps speed up security investigations. There is a 25% to 30% improvement. There is also a 25% reduction in the mean time to resolve, but we are also using a SOAR tool, which reduces that by 70% to 80%. 

What is most valuable?

They have approximately 50,000 predefined correlation rules, which is quite a lot, and I find that good.

What needs improvement?

It is very complicated to write your own correlation rules without the help of Splunk support.

What Splunk could do better is to create an API to the standard SIEM tools, such as Microsoft Sentinel. The idea would be to make it less painful. In ELK Stack, Kibana is the query language with which you can search log files. I believe Splunk has also a query language in which they search their log files, but once you have identified the log file that you want to use for further security correlation, you want to very quickly transport that into your SIEM tool, such as Microsoft Sentinel. That is something that Splunk could make a little bit less painful because it is a lot of effort to find that log file and forward it. An API with Microsoft Sentinel or a similar SIEM tool would be a good idea.

Buyer's Guide
Splunk Enterprise Security
September 2026
Learn what your peers think about Splunk Enterprise Security. Get advice and tips from experienced pros sharing their opinions. Updated: September 2026.
915,325 professionals have used our research since 2012.

For how long have I used the solution?

I have used the solution for about five years.

What do I think about the stability of the solution?

It is very stable. Sometimes it can be sluggish, especially in completely virtualized environments, but overall, it is good.

What do I think about the scalability of the solution?

I would rate it a nine out of ten for scalability. They struggle a bit with pure virtual environments, but in terms of how much they can handle, it is pretty good.

How are customer service and support?

Based on what customers tell me, it has been good. If you want to write your own correlation rules, it is very difficult to do, and you need Splunk's support to write new correlation rules for the SIEM tool.

Which solution did I use previously and why did I switch?

In our organization, we use our own tools such as Kyndryl Bridge and Elastic. We use Kyndryl Bridge which essentially has a similar function. It is based on Elastic. It indexes log files and flags log files. It helps you to very quickly search log files similar to the Splunk algorithm.

Our clients use Splunk Enterprise Security. If somebody already has Splunk as a business intelligence tool, then very often, it makes sense to expand the Splunk subscription they have to include Enterprise Security as well. We base our decisions on customer requirements, not on anything else. If a customer comes to us looking for a SIEM solution, we advise them based on their infrastructure and objectives. If we deliver the service for them and they want us to do that, we mostly go with Microsoft Sentinel when they already do not have Splunk. Otherwise, we go with Splunk Enterprise Security. We have about 30 customers in Germany who have Splunk, and we run it for them.

Monitoring multiple clouds with Splunk Enterprise Security is no more difficult than it is with Sentinel. I find Sentinel a bit easier. Splunk, of course, is very useful if you have AWS. Generically, because Splunk is not a cloud provider itself, it fits with anything. However, integration can be challenging at times, especially in virtualized environments. Splunk struggles a bit with speed in virtualized environments. Most importantly, Splunk can be outrageously expensive. That is the problem with both Splunk and Sentinel. Their pricing literally explodes based on the amount of data you feed in.

I like Elastic SIEM. It is a tool that allows you to determine the price. It is based on the computing power you require and not on the amount of data you put in, so it is a lot more flexible than Splunk or Sentinel. If there is a cost concern, Elastic SIEM is a good idea. Elastic is also pretty good at creating on-premises data lakes to control the amount of information you put into the same tool. That is something that neither Splunk nor Sentinel offers. 

In our operations, we use a separate threat intelligence vendor. To the SIEM tool, we added a SOAR tool for security orchestration, automation, and response, which is very critical these days. We get threat intelligence from a third-party provider because neither Splunk nor Microsoft gives the coverage that our customers need. Splunk does not have a SOAR capability, so we add that on top. We could add that on top of any tool, so it is not specific to Splunk, but Splunk helps because going through the log files is very fast. It does help when you do the incident analysis. Elastic also provides that, and Sentinel has that to some degree, but Splunk is still the Google for log files.

MITRE ATT&CK framework is integrated pretty much into any SIEM tool. It is not unique to Splunk. It is there in QRadar and other solutions. MITRE ATT&CK framework is helpful when designing incident response plans or playbooks. It is nice that they have it, but that is nothing unique to Splunk.

How was the initial setup?

It is mostly a cloud solution.

What's my experience with pricing, setup cost, and licensing?

The pricing is based on the volume of data fed into it, which can lead to substantial costs. This pricing model is complex and unpredictable, making cost management difficult.

Many parts of the IT world price based on IP addresses, nodes, or the number of devices. Splunk, of course, prices its services based on the volume of data submitted into the Splunk system. From a security perspective, it is very hard for clients to figure out how many security events per second their SIEM tool needs to work with. With Splunk, it is not just the events per second. They also need to know how much data per event per second the Splunk SIEM tool needs to work with. That is almost impossible to indicate.

Microsoft Sentinel is just as weird as Splunk. They also base the price on the amount of data you feed, whereas Elastic has a very interesting approach. It is not the amount of data you feed in; it is the amount of processing power you want to use. If you have a very large amount of data and want to correlate that very quickly, you need a lot more processing power. They base the pricing on processing power rather than on the amount of data. That is not a bad approach because that is scalable up and down depending on the needs of the organization, so the pricing from Splunk is a bit weird. That is what most people that I speak to are unhappy about because the cost can literally explode. I saw clients spend two million dollars a year just feeding data into the Splunk solution. You might have spent two million in feeding data into the SIEM tool a year, but the next year, it could be half of that. You find yourself frequently in an unpredictable situation of how much cost you are going to generate with your SIEM tool, so Splunk or Cisco needs to come up with a better and more scalable way of pricing their SIEM tool.

What other advice do I have?

Overall, Splunk is among the top three SIEM tools due to its capabilities and agility in bridging business analytics with security needs. They very much deserve where they stand on the Gartner Magic Quadrant. I like it a lot better than ArcSight, which was owned by HP at one point or another. In comparison to that, Splunk is much more agile and quick. It comes from a business analytics perspective. It is a lot easier to build the bridge between the business and security based on that platform. As far as stability and scalability are concerned, it is a brilliant solution.

I would rate Splunk Enterprise Security a nine out of ten.

Disclosure: My company has a business relationship with this vendor other than being a customer. MSP
PeerSpot user
Evonce Barrett - PeerSpot reviewer
Security Engineer at Nightwing
Real User
Top 20
Sep 21, 2026
Long-term security monitoring has transformed investigations and sped up data-driven decisions
Pros and Cons
  • "Splunk Enterprise Security has been the best SIEM solution tool I have worked with over the past ten to fifteen years."
  • "I perceive that the overall functionality of Splunk Enterprise Security is robust, but I believe it could see improvement, particularly in enhancing its AI capabilities."

What is our primary use case?

I have been using Splunk Enterprise Security for over seven years, and many of my use cases include monitoring user behavior, tracking system processes that go up and down, and determining necessary actions when dealing with Windows admin endpoints. I examine CVEs and the vulnerabilities that require triaging and remediation. One of the main features and functions for my use cases with Splunk Enterprise Security involves alerts built on user activity.

There are numerous ways to take data and events, correlate them, or review correlation searches to populate the necessary information across any industry and environment.

Splunk Enterprise Security is a wonderful tool to have for enterprise security.

What is most valuable?

The features of Splunk Enterprise Security that I appreciate most are tied to the overall experience. I can utilize the apps based on my use cases, and I can take all the data and consolidate it into one location. I appreciate the entire experience with Splunk Enterprise Security.

Security Essentials serves as a valuable resource for specific searches and helps tune alerts. AI-driven detections and assistance have improved my investigations by reducing triage times and allowing for faster data-driven decisions.

What needs improvement?

I perceive that the overall functionality of Splunk Enterprise Security is robust, but I believe it could see improvement, particularly in enhancing its AI capabilities.

If Splunk Enterprise Security were able to build its own LLM based on the incoming data instead of relying on other AI solutions, that would be a significant improvement, streamlining my experience while maintaining the quality of feedback.

For how long have I used the solution?

I have been using Splunk Enterprise Security for over seven years.

How are customer service and support?

I rate customer service and tech support at Splunk as a nine or ten based on my great experiences working with them. When I first started with Splunk Enterprise Security, the professional service I received was phenomenal.

The general customer service at Splunk is something I view positively, with great account service management that stands out, especially one particular representative named Matthew, whom I would rate as a nine or ten for his professionalism.

Which solution did I use previously and why did I switch?

Prior to adopting Splunk Enterprise Security, I utilized another solution that was not Elastic, although I cannot recall the name.

I remember it provided slow indexing and a cumbersome search query process. The indexing capabilities of Splunk Enterprise Security have always been its standout feature, enabling faster data retrieval when queries are submitted.

What was our ROI?

I have seen significant ROI with Splunk Enterprise Security primarily through the time saved. What used to take ten minutes for a search query can now be completed in mere seconds, allowing me to focus on additional tasks such as conducting PCI compliance interviews that demand timely responses, which is incredibly beneficial during those sessions.

What other advice do I have?

Splunk Enterprise Security has been the best SIEM solution tool I have worked with over the past ten to fifteen years.

It has integrated with numerous products beyond just being a SIEM solution, including AWS and Cisco networking devices, which, alongside their security essentials and correlation searches, creates a comprehensive package.

Excellent customer service, availability for monitoring the cloud, and data lake solutions that facilitate easier data access underscore the readiness of Splunk Enterprise Security to meet various organizational needs.

I give this product a rating of ten.

Which deployment model are you using for this solution?

Public Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Last updated: Sep 21, 2026
Flag as inappropriate
PeerSpot user
Buyer's Guide
Splunk Enterprise Security
September 2026
Learn what your peers think about Splunk Enterprise Security. Get advice and tips from experienced pros sharing their opinions. Updated: September 2026.
915,325 professionals have used our research since 2012.
Cyber Security Ops Manger at a educational organization with 1,001-5,000 employees
Real User
Top 10
Sep 13, 2025
Mission Control helps our team prioritize critical alerts and respond to incidents more efficiently
Pros and Cons
  • "It has supported our SOC by improving it."
  • "I would definitely improve the risk-based alerts in Splunk Enterprise Security, helping SOC analysts to get to the drill-down searches."

What is our primary use case?

My main use cases for Splunk Enterprise Security are security operation center and incident response.

What is most valuable?

The Mission Control feature of Splunk Enterprise Security benefits my organization by providing quick alerts, making it easy for the SOC team to navigate events and find threats quickly.

I use disparate security solutions that integrate or import data into Splunk Enterprise Security. This integration supports our security operations effectively because we work with different tools, and Splunk apps support many integrations, so we don't need to write custom ones; it's available by default.

It has supported our SOC by improving it; in looking through many alerts, we can look at only the critical alerts, and the number of alerts investigated by SOC has changed drastically. Currently, my security ops team remediates security incidents with Splunk Enterprise Security within 45 minutes compared to our previous solution.

I would be using Detection Studio, which is one of the new threat detection features in Splunk Enterprise Security that I'm interested in. Splunk Enterprise Security has definitely helped improve my organization's business resilience; it has helped us to pass our SOC 2 audit, and we have good monitoring about security alerts and threats happening.

I assess Splunk's ability to predict, identify, and solve problems in real time as very good.

What needs improvement?

I would definitely improve the risk-based alerts in Splunk Enterprise Security, helping SOC analysts to get to the drill-down searches.

The most significant challenges I face when using Splunk Enterprise Security for advanced threat detection include writing detection rules for new threats, finding out about the SPL logic, and writing correlation rules. In ES8, we are experiencing some issues with crashes, and whenever we open the correlation rule, it gives a Java error requiring a refresh. We had not seen that error before, however, we are seeing it more frequently in ES 8.1.

For how long have I used the solution?

I have been using Splunk Enterprise Security for five years.

What do I think about the stability of the solution?

Splunk Enterprise Security scales absolutely with the growing needs of my organization; it has caught up with our needs, and we use the tool without any pain.

On a scale of one to ten, I would rate Splunk Enterprise Security overall as eight.

What do I think about the scalability of the solution?

We have definitely expanded our usage over the five years; our utilization of Splunk has totally changed.

How are customer service and support?

I would evaluate customer service and technical support as good and satisfactory because it was not satisfactory a few years back, however, now I see some positive changes, which is good.

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

I used IBM QRadar.

How was the initial setup?

I would describe my experience with deploying Splunk Enterprise Security as easy thanks to the cloud.

What was our ROI?

I have seen a return on investment; though it is an expensive tool, we did see return on investment. The integration is a specific example where we see value; the basic integration with different data is easy and more adaptable. As we use more different tools, Splunk Enterprise Security is able to integrate all those things without needing to create custom integration.

What's my experience with pricing, setup cost, and licensing?

My experience with pricing, setup cost, and licensing for Splunk Enterprise Security is that it is expensive.

Which other solutions did I evaluate?

I made a change because IBM QRadar was on-premises, and we were transitioning; we had many challenges with the tool when dealing with big data, and it was not able to catch up, which is why we moved to Splunk Enterprise Security.

What other advice do I have?

I would advise other organizations considering Splunk Enterprise Security to use it and also utilize the built-in ES Content Pack, where you have many rules ready, instead of trying to figure everything out. Use that content pack to start, and once you have the basic fundamental detection rules, then you can expand on it.

On a scale of one to ten, I rate Splunk Enterprise Security an eight.

Which deployment model are you using for this solution?

Public Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
MatthewSnyder - PeerSpot reviewer
Principal Engineer at Aviatrix
Video Review
Real User
Top 5
Sep 11, 2025
Transforms threat detection by reducing investigation time and enabling consistent response workflows
Pros and Cons
  • "While it might be an initial upfront investment on data onboarding, it's going to be something that makes your life incredibly easy once you get beyond that point."
  • "Previously, it would take us days to properly analyze, triage, and respond to insider threats; now with risk-based alerting, we are able to reduce that to 10 minutes."
  • "When deploying Enterprise Security, the biggest challenge or the most amount of work that you're going to spend time on is onboarding your data and getting it into a position that allows you to search it uniformly. So applying things like the common information model is the biggest time investment that you'll have in the deployment."

How has it helped my organization?

Splunk Enterprise Security has helped reduce my team's average meantime to detect insider threats, which I discussed at a conference a few years ago. Previously, it would take us days to properly analyze, triage, and respond to insider threats. Now with risk-based alerting, we are able to reduce that to 10 minutes. 

This is a powerful metric on the amount of time saved. Not only are we saving time, we're able to apply investigations in a more uniform and consistent manner where we're able to control the output, ensuring we're delivering consistent and valuable products each time we perform investigations or responses.

What is most valuable?

If you want to use some of the out-of-the-box and more guided features, you have that, and if it meets your team's needs, that's great. If you also want to start to grow and mature beyond those out-of-the-box capabilities, it gives you this wide-open road to be able to create and develop your own applications, response capabilities, and detection capabilities, where your limitations are really only your imagination and what your team's able to accomplish. This is something powerful with Splunk that other vendors aren't replicating.

What needs improvement?

I've used it for a long time and I still feel it's the best tool out there. I love what the team is doing. They refreshed the user interface recently, they've got version control coming, and they're doing more exciting things. 

I'm really excited to see them continue to improve by making the SIEM the central point of what security teams are doing and operating instead of having multiple tools such as SOAR or UEBA. 

With Splunk Enterprise Security and Mission Control, everything is coming back into one place. We're able to operate from a single source to take an alert and get to an actionable state much quicker. I'm really excited to see how they continue to grow and evolve that.

What do I think about the stability of the solution?

I have been really impressed with the stability and reliability of Splunk Enterprise Security over the last ten years as we've had very few incidents where it was down or we had an issue. 

Typically when we've had issues, it was something more self-initiated where we had a piece of hardware that failed. It wasn't ES's fault. I've been really happy that it's delivered very consistent user performance. Performance delivery for us hasn't been a constant pain or nightmare that I've dealt with other vendors where the tool is constantly up and down. Splunk has been very reliable and very consistent.

What do I think about the scalability of the solution?

I've seen Splunk Enterprise Security scale from a 300-gig license to a 30-terabyte-a-day license. The infrastructure and different options allow you to scale at the pace that makes sense for you and your organization, whether that's large scale or something smaller to midsize. There are many different options at your fingertips to create the right architecture that meets your needs.

How are customer service and support?

I find the customer service and technical support of the platform to be amazing. It's done better at Splunk than I've seen any other vendor do. 

We've had great customer success managers who have helped us navigate scaling from 600 gigs to 30 terabytes. We've always had the architecture team, security team, or other experts whenever we've needed them or wanted to consult on our growth or future. 

The Splunk community is amazing as it's not just help we have to go to Splunk for. There's a vibrant community we can reach out to for answers from other Splunk users on how they're solving problems and what challenges they're facing and solving. We've got all these sources we can rely on and not just a vendor giving us the answer they want us to hear.

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

Prior to adopting Splunk Enterprise Security, I have used quite a few different SIEMs and have done many proof of values throughout the years. There are many SIEMs that have similar features and capabilities. As an industry, they all brag that they can do similar things. What it really comes down to is establishing what you want your team to be able to do and accomplish. When you are able to write that out and compare it against what the market is doing, you're going to consistently find that Splunk is doing it better, if not miles better than the nearest competition.

How was the initial setup?

When deploying Enterprise Security, the biggest challenge or the most amount of work that you're going to spend time on is onboarding your data and getting it into a position that allows you to search it uniformly. So applying things like the common information model is the biggest time investment that you'll have in the deployment. 

The actual configurations of alerts and dashboards and all of that happen rather smoothly once your data is uniform. One of the powerful aspects of this is that it allows you to search across similar languages, hit multiple data sources and indexes, and make the most of your datasets. That's something that I really like. 

While it might be an initial upfront investment on data onboarding, it's going to be something that makes your life incredibly easy once you get beyond that point.

What was our ROI?

The biggest return on investment when using Splunk Enterprise Security is that it gives you control.

What's my experience with pricing, setup cost, and licensing?

One of the things I hear a lot is that it's expensive. We've tried to move beyond just a single line item on a spreadsheet to talk more about what's valuable to us as a security organization. What are we trying to do and accomplish? What are the tools we need to accomplish all of that? What I've found over the last 20 years is it's either going to be one big line item on your budget or a bunch of smaller line items. When you break it down and individualize it, you've got other things that might initially cost less, however, your cost over the years is going to end up being more than Splunk. 

The initial license ask is typically more than what we'd see with other vendors. The value it provides and the capabilities it gives us, when we look at what other tools can do, we would end up spending more just to meet that same level of capabilities. It's important that everybody understands SIEM value isn't just a singular license cost. There are many other components that come into play that really show value and true cost.

What other advice do I have?

The biggest advice I would give to anybody considering Splunk Enterprise Security is to understand what you want your organization to look like. What kind of things do you need your SOC to do? If you're just looking at doing basic auditing and alerting and reporting, there are features you can use. 

If you're wanting to do more threat hunting and incident response and go from ordinary to extraordinary, there are many features Splunk will help you utilize. It's really important that you understand what you want your SOC's identity to look like. 

As you partner and do your proof of value with Splunk, you can focus on those features that align to your immediate needs, as those you're curious about growing into, where you might see your organization in the next one year, two year, three year, five year type of journey and how those features really align, knowing that you've got a partner that's going to allow you to happily exist where you're at, yet also support you on the growth where you're wanting to go. 

I'd rate the solution nine out of ten.

Which deployment model are you using for this solution?

On-premises

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
reviewer2898969 - PeerSpot reviewer
Security manager at a tech vendor with 10,001+ employees
Real User
Top 20
Sep 16, 2026
Daily log insights have strengthened security decisions and reduced detection time
Pros and Cons
  • "Splunk Enterprise Security has positively impacted our organization by allowing us to use it on a daily basis, improving our security front and allowing our analysts to review and inform management on any trends, deficiencies, and necessary areas of improvement."
  • "Splunk Enterprise Security can always improve its UI; we do have some less technical team members, so continual improvement and refreshes of the UI are always appreciated."

What is our primary use case?

My main use case for Splunk Enterprise Security is to review logs of our assets and interests, other data assets, and create tables for management review to make the best informed security decisions.

I use Splunk Enterprise Security to make informed security decisions by reviewing current logs of any data spillages that may happen, any deficiencies that we may see with our assets, and reviewing logs monthly to ensure we remain compliant.

How has it helped my organization?

Splunk Enterprise Security has positively impacted our organization by allowing us to use it on a daily basis, improving our security front and allowing our analysts to review and inform management on any trends, deficiencies, and necessary areas of improvement.

The impact of Splunk Enterprise Security is evident as it has reduced vulnerabilities by allowing us to visualize any trends and take corrective measures, as well as giving us a roadmap of where we can improve our security front by ingesting data sets.

Splunk Enterprise Security has helped improve my organization's business resilience by providing adaptability through using AI models to foreshadow any trends and utilizing historical data sets from our company, which we use to make further business decisions based on recommendations from the trends from the models.

Splunk Enterprise Security has reduced my team's average mean time to detect, or MTDD metric, by about ten percent.

Splunk Enterprise Security's Risk-Based Alerting, or RBA, has impacted my alert volume and analyst productivity by giving us almost an immediate response time to any of our found alerts.

The integration of threat intelligence directly into the TDIR workflow has improved my ability to preemptively block threats by providing us a security-first mindset and allowing the threat to be stopped at the door versus performing forensics and after-action review.

The consolidation of SIEM, SOAR, and UEBA into a single interface has improved my team's operational efficiency by embracing the all-in-one aspect of the tools being combined, allowing us to train our controllers to utilize the one toolkit to solve or remediate our problems.

What is most valuable?

The best features Splunk Enterprise Security offers include visualizations, which are very helpful for our non-technical team to see trends and for us to input data sets and review at our meetings.

The visualizations help my team make decisions or communicate findings by allowing us to review trends, looking at graphs and bar graphs, enabling us to compare and contrast deficiencies and make business decisions.

What needs improvement?

Splunk Enterprise Security can always improve its UI; we do have some less technical team members, so continual improvement and refreshes of the UI are always appreciated.

For how long have I used the solution?

I have been using Splunk Enterprise Security for roughly five years with the current company.

What do I think about the stability of the solution?

Splunk Enterprise Security is stable; it is fully integrated into our ecosystem, and we will continue to use it.

What do I think about the scalability of the solution?

Splunk Enterprise Security's scalability is sufficient for our needs currently, and I believe that it will continue to be.

How are customer service and support?

The customer support for Splunk Enterprise Security is very sufficient from what I am seeing.

I would rate the customer support a ten out of ten.

Which solution did I use previously and why did I switch?

I did not previously use a different solution.

How was the initial setup?

Licensing was pretty fast and efficient; the cost was handled by our finance department, but it seemed like a pretty efficient workflow from what I am seeing.

What was our ROI?

I have seen a return on investment from Splunk Enterprise Security as we do not need additional employees to perform the work that we need, and having just one stream, one account to handle all the security has been beneficial.

What other advice do I have?

My advice for others looking into using Splunk Enterprise Security is to definitely give it a try; there are definitely trials to test out, learn about the product, take advantage of reaching out to the tier three support if needed, and integrate it into your ecosystem to understand what it's doing and what it can do for you. I would rate this product a nine out of ten.

Which deployment model are you using for this solution?

Hybrid Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Amazon Web Services (AWS)
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
Last updated: Sep 16, 2026
Flag as inappropriate
PeerSpot user
Clay Matt - PeerSpot reviewer
Dir Of Global Cyber Security Ops at a manufacturing company with 10,001+ employees
Real User
Top 5
Sep 13, 2025
Significantly improves visibility and strengthens internal threat detection capabilities
Pros and Cons
  • "I would assess the stability and reliability of Splunk Enterprise Security as typically very good, with minimal downtime or crashes."
  • "I find the process for customizing, developing, testing, deploying, and refining detections in Splunk Enterprise Security to be cumbersome."

What is our primary use case?

My main use cases for Splunk Enterprise Security include extensive security operations.

How has it helped my organization?

Splunk Enterprise Security has helped improve my organization's business resilience. The more I know, the more I can see, and the better my security stance becomes due to inherent visibility.

What is most valuable?

We did use risk-based alerting in Splunk Enterprise Security. We had to refine the data model based on the initial risk-based alerting model as, when we fed it raw data, the data models built, and there were many endpoints and network devices that had a high-risk score just because the data was new. Those risk scores carried over with weights, so we had to go back in and cleanse the risk score model and rebuild it once we had good data and logs going into the ES platform.

What needs improvement?

If they could implement an out-of-the-box solution, it would be almost an AI data onboarding system that automatically identifies the fields that are SIM compliant, Common Information Model compliant, and then immediately applies those to a data model, builds a data model, and starts the SIM searches against those data models. A lot of the work for Splunk Enterprise Security happens on the back end, not the front end, so that's where you can really trim down your resource need and expertise if you supplement that with automated or artificial intelligence.

The most significant challenges I face when using Splunk Enterprise Security for advanced threat protection are integration with other platforms and noise. Alerts from Splunk Enterprise Security generate many alerts, which take time to move through, assess, analyze, and determine whether they are true or false positives, and then go back and redundantly tune.

I find the process for customizing, developing, testing, deploying, and refining detections in Splunk Enterprise Security to be cumbersome. Custom use cases are also cumbersome. You need someone very skilled at Splunk and data modeling to get to a point where you create something inside SPL that allows you to detect what you want.

There is not much predictive analysis happening in Splunk, and I hope that with the new AI toolkit allowing for the deployment of custom AI models and large language models within Splunk, along with additional advanced mathematical capabilities for vector analysis, the prediction and ability for Splunk Enterprise Security to add value to detections will increase.

For how long have I used the solution?

I have a lot of experience using Splunk Enterprise Security.

What do I think about the stability of the solution?

I would assess the stability and reliability of Splunk Enterprise Security as typically very good, with minimal downtime or crashes.

What do I think about the scalability of the solution?

We haven't expanded our usage of Splunk Enterprise Security; we used it by default from the start. The expanded usage is simply adding more information and logging to gain better insights.

How are customer service and support?

I evaluate customer service and technical support as normally very good. When it's not, I reach out to my sales representative and my SE. I have a great SE, Jonathan Wilson, who jumps right in to solve issues when we need help or engagement.

Customer support has room for improvement, particularly in terms of speed and the ability to escalate issues to more senior personnel. I understand the need for a tiered approach, but I believe some issues should move more rapidly to a senior person.

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

Prior to adopting Splunk Enterprise Security, we were not using any other solution to address similar needs.

How was the initial setup?

It's the human element there. It's helpful to have the expertise and the people to really take those data models and build them, refine them, get everything into the common information model on the back end so that, on the front end, you're getting the best data possible and you don't have to rebuild those models like we had to do with the risk score.

What was our ROI?

I have seen a return on investment with Splunk Enterprise Security. We went from almost no visibility to significant visibility across the enterprise, allowing us to see threats that were previously unknown or unregistered, which increased our security stance and made us understand we needed to look beyond the perimeter for internal threats and for lateral movement, east-west versus just north-south.

What's my experience with pricing, setup cost, and licensing?

I helped negotiate the cost. Our sales rep is is really good, and we had a good understanding. The more you know about the product, the easier it is to negotiate. If you're not aware of how the product works, what the ingestion's like, especially Splunk Cloud with the SBC units and AWS, and how impactful that can be to queries and optimization and just general operations, it becomes very difficult if you're trying to maintain a certain price point for cost effectiveness. It it can be difficult to get an optimum amount of credits and SBCs in order to run what you need to run.

What other advice do I have?

My advice to other organizations considering Splunk Enterprise Security is that while not everyone needs the top breed, ensure you have the resources and time to invest in it if you decide to use it. Anything off the shelf won't be as valuable as something you invest in and put time into, so the more you put in, the more you get out.

I would rate Splunk Enterprise Security overall as probably an eight out of ten; it is industry-leading.

Which deployment model are you using for this solution?

Public Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Splunk Engineer at a consultancy with 11-50 employees
Real User
Top 20
Jul 13, 2026
Automated risk-based alerts have reduced incident response time and support faster remediation
Pros and Cons
  • "The time it takes my SecOps team to remediate security incidents is very reduced compared to before."
  • "Currently, in my opinion, Splunk Enterprise Security is good. However, Splunk has an ingest processor that could be improved."

What is our primary use case?

My use case for Splunk Enterprise Security involves onboarding data and then CIM complying and normalizing fields. We are also using the data models mapping and the add-on configuration. We also have some correlation searches which are running using the data models. Using that, we have some dashboards that give us useful information and ideas of what we can do.

How has it helped my organization?

The time it takes my SecOps team to remediate security incidents is very reduced compared to before. Our security team gets notified very urgently and very fast, and we take action as per the alerts. This has reduced the time for us by a lot.

It helps our customers.

What is most valuable?

The dashboard is the feature in Splunk Enterprise Security that I find most valuable because in the dashboard we have background searches, and the background search runs in the dashboard and gives us useful information. We also have alert automation, such as if someone is logging in to our system like a firewall. If the IP is malicious, then we get the alert at that time and we can block that IP.

We are working with the risk-based alerting feature in Splunk Enterprise Security. We are using risk-based alerts called RBA. That assigns the risk to the user, the system, and the other entities instead of generating a notable event for every individual detection. Multiple low and medium confidence detections accumulate over time, and when the combined risk exceeds the defined threshold, a high-confidence alert is generated using that risk-based alert.

We are working with a new threat detection feature in Splunk Enterprise Security. That helps the security teams to identify, investigate, and respond to malicious activities across the environment. We have some correlation searches that detect suspicious behavior using predefined or custom rules. We also have some notable events that run as very high-frequency alerts created by the correlation searches or the risk thresholds.

What needs improvement?

Currently, in my opinion, Splunk Enterprise Security is good. However, Splunk has an ingest processor that could be improved.

For how long have I used the solution?

I have been using Splunk Enterprise Security for two years.

What other advice do I have?

I am working with Splunk Enterprise Security.

I use some third-party solutions for integration or to import data into Splunk. We are creating some custom add-ons. We are also using ServiceNow. When some alerts are triggered, then the incidents will automatically trigger and be assigned to the necessary team. That type of customization we are using for the data collection. If you have some API integration, then you can create your own add-ons using those APIs and the credentials, and you can directly pull the logs from the APIs into Splunk.

It is easy to customize Splunk Enterprise Security for our needs. We can customize as per our requirement. If you want to create some dynamic dashboards, then you can also create them as per your use case. It is also the same for the saved search and for the extraction. We can customize things as per our use cases and ideas.

I gave this product a rating of eight.

Which deployment model are you using for this solution?

Private Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Other
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
Last updated: Jul 13, 2026
Flag as inappropriate
PeerSpot user
reviewer2123547 - PeerSpot reviewer
Security Analyst at a tech vendor with 10,001+ employees
Real User
Top 20
Jun 16, 2026
Unified security monitoring has improved incident response and supported flexible threat detection
Pros and Cons
  • "Splunk Enterprise Security is a wide tool that we can use for different purposes, as it can be configured in many ways, not just as a SIEM, and we can leverage it in various ways."
  • "Whenever an upgrade happens from a lower version to the latest version, some things get complicated, particularly compatibility issues, which we usually see in Splunk Enterprise Security."

What is our primary use case?

During the initial two years, I was an incident response analyst who used Splunk Enterprise Security as a SIEM tool, and in the recent two years, I work as an admin who handles the integration part, content management part, and the detection response engineering.

We use disparate security solutions with additional IDS, IPS, and EDR tools integrated into Splunk Enterprise Security for single-handled monitoring for the analyst's ease. We do not need to go to each tool separately; instead, we integrate all of them into the Splunk Enterprise Security interface, allowing us to monitor them via Splunk Enterprise Security.

Regarding Risk-Based Alerting in Splunk Enterprise Security, we used to tag alerts while creating correlation searches in Splunk Enterprise Security.

I work with both on-premise and cloud-based setups.

How has it helped my organization?

Splunk Enterprise Security really helps improve business resiliency as we frequently capture real attacks.

What is most valuable?

In terms of customization ability and development capability inside Splunk Enterprise Security, it is very easy. Splunk Enterprise Security is a wide tool that we can use for different purposes. Splunk Enterprise Security can be configured in many ways, not just as a SIEM, but we can leverage it in various ways. The application add-on support from Splunk is very wide, making it very easy for configuration and customization.

The functions in Splunk Enterprise Security that I find most valuable are its ability to integrate any type of logs into the system. It is very user-friendly to read logs in any languages, which we can convert into a human-readable format in Splunk Enterprise Security, making log analysis and monitoring very useful compared to competitive SIEM tools.

The main benefits Splunk Enterprise Security provides to end users include a wide view, allowing us to have different kinds of views for the logs, and we can search according to the retention period we set in Splunk Enterprise Security. This capability and storage are good enough to retrieve older data for evaluation and analysis.

I find that threat detection in Splunk Enterprise Security is a wide case; we have the opportunity to create correlation searches, dashboards, and even integrate threat intel solutions in multiple ways into Splunk Enterprise Security. We can leverage these opportunities to get alerts based on these searches.

What needs improvement?

Whenever an upgrade happens from a lower version to the latest version, some things get complicated, particularly compatibility issues, which we usually see in Splunk Enterprise Security. In those cases, it sometimes definitely requires Splunk Enterprise Security's support or vendor support to resolve those issues. Compatibility issues during upgrades are a major concern.

I am generally satisfied with the functionality of Splunk Enterprise Security, and my only concern is the compatibility issue during upgrades.

For how long have I used the solution?

I have been working with the product for four years.

What do I think about the stability of the solution?

I rate Splunk Enterprise Security's stability as a nine.

What do I think about the scalability of the solution?

I consider its scalability, ability to scale, and ability to expand to be a ten.

How are customer service and support?

I would rate vendor support as a nine.

How was the initial setup?

The initial setup for Splunk Enterprise Security is simple, and guides from Splunk Enterprise Security support are available on the internet, making it very basic. We can read and understand the next steps from there.

What other advice do I have?

On average, the time a SecOps team takes to remediate security incidents with Splunk Enterprise Security depends on projects. If the team is working as a threat hunt team, they do not have a proper SLA, but for incident handling, some projects have 15 minutes, others 30 minutes, one hour, or in some cases, up to four hours. It varies according to the project and client requirement; incident handling is different from incident response, which usually requires more time for detailed analysis.

I am totally satisfied with Risk-Based Alerting because it works well; it works on intermediate findings. If multiple detections occur for the same host or IP, it looks for behavioral analysis and generates alerts for the analyst based on that risk, so it is actually working well in Splunk Enterprise Security.

I can recommend Splunk Enterprise Security to other users. My overall rating for this product is eight out of ten.

Which deployment model are you using for this solution?

Hybrid Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Other
Disclosure: My company has a business relationship with this vendor other than being a customer. partner
Last updated: Jun 16, 2026
Flag as inappropriate
PeerSpot user
Hari Haran. - PeerSpot reviewer
Technical Associate at Positka
Reseller
Top 20
Feb 26, 2026
Security operations have become streamlined and threat investigations gain rapid, actionable insight
Pros and Cons
  • "Regarding scalability, Splunk Enterprise Security is way ahead compared to other products, and I would score it at the maximum."
  • "During my experience with Splunk Enterprise Security, I have faced some significant challenges, particularly with customers adapting from version 7 to version 8."

What is our primary use case?

I would like to discuss Enterprise Security, and I explain that the main use case for the product is to protect our customers and support various attacks.

Regarding threat detection, I explain that during investigations, most of our SOC-related customers use Splunk Enterprise Security to identify threats.

How has it helped my organization?

In terms of benefits, Splunk Enterprise Security provides numerous advantages to end users, notably in reducing personnel needs for SOC operations.

Regarding pricing for Splunk Enterprise Security, I find it relatively affordable globally, although it seems costly in India due to currency exchange.

What is most valuable?

In my opinion, the functions in Splunk Enterprise Security that I find most valuable include unique features and tools that the product offers.

What needs improvement?

For improvement points, I think Splunk has several enhancements on the table right now to enhance Splunk Enterprise Security with functionalities and threat detection improvements.

For how long have I used the solution?

I have been working with Splunk Enterprise Security for seven years.

What do I think about the stability of the solution?

For stability, I would rate it a 10, as Splunk Enterprise Security is generally stable, especially now with its latest version.

What do I think about the scalability of the solution?

Regarding scalability, Splunk Enterprise Security is way ahead compared to other products, and I would score it at the maximum.

How are customer service and support?

I would rate Splunk Enterprise Security's technical support as a 10, as they provide 24/7 assistance based on priorities and are accessible for queries.

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

In comparison to other products, I think previous tools such as IBM QRadar were competitors, but currently, I hear about CrowdStrike getting into the picture.

How was the initial setup?

In general, I find that the initial setup for Splunk Enterprise Security is simple, especially with clear documentation from Splunk.

It depends on the client; if they have a qualified engineer with experience in Splunk Enterprise Security, they can handle the setup themselves.

What about the implementation team?

The solution is deployed both on-premises and cloud-based, depending on the customer's domain.

What other advice do I have?

My feedback regarding some processes of customizing, developing, and testing in Splunk Enterprise Security is that I am thinking from a customer perspective, focusing on the customizations they require.

I have experience with risk-based alerting in Splunk Enterprise Security, as we configure based on the priority of the instance, servers, or the endpoints.

During my experience with Splunk Enterprise Security, I have faced some significant challenges, particularly with customers adapting from version 7 to version 8.

Which deployment model are you using for this solution?

Hybrid Cloud
Disclosure: My company has a business relationship with this vendor other than being a customer. reseller
Last updated: Feb 26, 2026
Flag as inappropriate
PeerSpot user
Ankar Aung - PeerSpot reviewer
Network Security Engineer at a consultancy with 10,001+ employees
Real User
Top 5
Jan 8, 2026
Centralized dashboards have improved log visibility and support faster security investigations
Pros and Cons
  • "Splunk Enterprise Security can retain logs for compliance purposes longer than the usual three months."
  • "Splunk Enterprise Security documentation exists, but compared to Palo Alto, Palo Alto has more knowledge base articles."

What is our primary use case?

I deal with the Palo Alto FO and then Cortex XSIAM. I work with Cortex XSIAM and Cortex EDR products. We recently adopted Cortex XSIAM from Splunk Enterprise Security as our SIEM product for log management.

I have two to three years of experience with Splunk Enterprise Security, but not continuously; this is just a tool used by me, not daily. We send logs from the firewalls to XSIAM and analyze the traffic logs to determine whether deny or allow for migration. We use both Splunk and Cortex XSIAM for log analysis. I have never dealt with Splunk support.

What is most valuable?

I have experience with Palo Alto, Cisco, and Fortinet products. Splunk Enterprise Security is more dedicated to logs, not a unified product like Palo Alto. Palo Alto Cortex has the same UI across Cortex EDR and Cortex XSIAM, so all the product family is in one UI, whereas Splunk Enterprise Security is more focused on log search.

Palo Alto has better speed and better visibility. I can see all the M-points from one UI and search the logs from this UI. I use disparate security solutions that integrate or import data into Splunk Enterprise Security, including different log sources from the endpoint, firewall, router, switches, and everything that needs logging for visibility.

Splunk Enterprise Security can retain logs for compliance purposes longer than the usual three months. The dashboard capability also allows Splunk Enterprise Security to create dashboards based on logs, which makes it really helpful for visibility.

What needs improvement?

I feel more comfortable using XSIAM now compared to Splunk Enterprise Security. Splunk Enterprise Security is already a mature product, so I do not have much to point out. It could be a little more user-friendly, which would be nice.

It could also expand the product family beyond security log search. Since it has the capability of indexing things, perhaps Splunk Enterprise Security could develop their own EDR agent like Palo Alto and create a product family with a unified dashboard. This would definitely help the enterprise.

Splunk Enterprise Security documentation exists, but compared to Palo Alto, Palo Alto has more knowledge base articles. Even though the concepts are the same and multiple engineers have written articles for cross-reference, I do not see this level of documentation in Splunk Enterprise Security.

For how long have I used the solution?

I have two to three years of experience with Splunk Enterprise Security, but not continuously; this is just a tool used by me, not daily.

Which solution did I use previously and why did I switch?

The switch to Cortex came from management, likely because the Palo Alto product family is already in our environment. We have been using Palo Alto GlobalProtect and other security products, so bringing XSIAM into the environment makes sense.

What other advice do I have?

I do not see a real difference between XSIAM and Splunk Enterprise Security; they both have a search query functionality. Splunk Enterprise Security has Splunk query language, so it is just a different language and different way of searching logs. Eventually, we get the same logs including source, destination, port, and traffic allow and deny information.

I used to be a customer with Splunk Enterprise Security. I have hands-on experience but not extensive experience with Splunk Enterprise Security products in the past. I am more focused on networking than the security team. I do not have an answer about how long on average it takes SecOps teams to remediate security incidents using Splunk Enterprise Security.

I would rate this review an 8.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Last updated: Jan 8, 2026
Flag as inappropriate
PeerSpot user
Buyer's Guide
Download our free Splunk Enterprise Security Report and get advice and tips from experienced pros sharing their opinions.
Updated: September 2026
Buyer's Guide
Download our free Splunk Enterprise Security Report and get advice and tips from experienced pros sharing their opinions.