No more typing reviews! Try our Samantha, our new voice AI agent.
Abhilash Kondodi - PeerSpot reviewer
Assistant VP at a financial services firm with 10,001+ employees
Video Review
Real User
Top 10
Sep 13, 2025
Has supported data loss prevention investigations by centralizing access to user activity across multiple tools
Pros and Cons
  • "Splunk Enterprise Security scales well with the growing needs of our company."
  • "For instance, if a DLP operations analyst accesses the platform, it should guide them to navigate predefined content for their role. That's something I've already mentioned to them, and I'm eager to see what happens next."

What is our primary use case?

My main use cases for Splunk Enterprise Security include supporting production changes, which helps us ensure that we are not going to break the business from a DLP engineer standpoint. From an investigations and operations perspective, it allows us to look into all activities done by any individual, such as which emails they sent or what kind of data they have in their folders. We have logs coming from data at rest and data in motion channels, and all this combined is quite helpful for insider threat and data loss prevention activities.

One of the use cases I leverage Splunk Enterprise Security's dashboards and visualizations for is looking into risky applications. Since we manage the web side, we look into emerging AI applications in the market. Splunk Enterprise Security provides access to logs that show which category of websites are being accessed and what those are. We can see that in a search, yet visualizations dashboards enhance this representation. Instead of writing an SPL every time, any team member can go into a dashboard, input the application name they're interested in, and access all relevant details. These are some use cases, and you can continually build your own with Splunk Enterprise Security providing the platform for those developments while limiting access to only those who need to see the information.

How has it helped my organization?

Splunk Enterprise Security plays a role in our organization's strategy to combat insider threats and advanced persistent threats by allowing us to examine how users are affected and the various egress points they are hitting. From my perspective, this is essential as I work in a specific area within cybersecurity.

What is most valuable?

As a DLP Engineer and Assistant Vice President at a US bank with about 50,000+ employees, I manage the Data Loss Prevention tool, configurations, and deployments. We work across the globe in multiple regions and work on multiple different kinds of tools. Splunk Enterprise Security is leveraged quite heavily to support our DLP functions by creating SPLs for our DLP operations. We also create dashboards and reports that are required, where Splunk Enterprise Security is the single point of connection that allows us to send all the logs across and use the data as we need and see fit.

Due to my role, I have limitations on what I can do in Splunk Enterprise Security, yet for whatever access I have, it's been a very useful tool for detections and investigations. From a DLP standpoint, we look into enabling blocking, and we want to make sure that we are looking into what's happening there and how many people would be affected. Splunk Enterprise Security gives us access to that data, while the DLP platforms themselves provide data too, however, Splunk Enterprise Security's integrations with various inputs from identity and asset management create a single point for all information.

I appreciate the statistics feature of Splunk Enterprise Security since it helps showcase numbers to management. While we can share a long spreadsheet, that's not a good way of sharing data. Although we still share spreadsheets, having statistics, visualizations, and dashboards to showcase security benefits is much more effective.

Any new tooling we bring in and adding that data set helps create much richer data. Different integrations enhance our ability to find the right context for threat analysis and insider threat analysis.

I don't have any metrics regarding how Splunk Enterprise Security has helped reduce our team's average mean time to detect. However, I can think of the practical aspect: we have four different tools with their alerts. When we go into each of those tools, we can see what a user has done. With Splunk Enterprise Security, we can just pop in an SPL, search for the user, and find all the details from different sources in one spot, making it much easier to dive into investigations.

What needs improvement?

I have many good ideas for how Splunk Enterprise Security can be improved. Our Splunk team attended a session, and it was really good. I see that AI integration would assist analysts in seamlessly looking into data without relying on engineers to write an SPL. With AI integration, they can search different kinds of data that they have access to. The UEBA side looks good, and the Splunk Enterprise Security UI indicates that we are on the right path. I look forward to using and sharing what I've learned with my team regarding different tools in Splunk Enterprise Security that we can leverage to improve processes, provided they are not already using them.

One major return on investment for using Splunk Enterprise Security, from my perspective, is the feedback I provided to the product research team about creating a UI that helps specific team members extract value from the platform. For instance, if a DLP operations analyst accesses the platform, it should guide them to navigate predefined content for their role. That's something I've already mentioned to them, and I'm eager to see what happens next. Currently, it's a blank slate where users can explore, which is good, however, some people might need a push. Training can either be done from start to finish, or with AI integrating everywhere, users could ask questions that would return answers, from creating an SPL to providing results.

Buyer's Guide
Splunk Enterprise Security
September 2026
Learn what your peers think about Splunk Enterprise Security. Get advice and tips from experienced pros sharing their opinions. Updated: September 2026.
915,325 professionals have used our research since 2012.

For how long have I used the solution?

I have about ten plus years of experience in IT and security. The last seven years, I've been focused on data security. I've worked on probably more than seven DLP platforms, data loss prevention platforms. And from what I've seen, almost all these companies that I work with, a lot of them leverage Splunk.

What do I think about the stability of the solution?

I am happy with Splunk Enterprise Security's stability and reliability so far. I haven't seen any drawbacks, although sometimes the search takes a while to return results. That's often due to how I design the search, not the platform's fault. I have fantastic team members who assist me with specific SPLs, which makes it easier. It's just about navigating and understanding the right way to do it.

What do I think about the scalability of the solution?

Splunk Enterprise Security scales well with the growing needs of our company. We have a massive team that supports this, with an amazing team managing all the work around Splunk Enterprise Security ingestions. I keep hearing that the use cases are increasing, and we look forward to what more comes in.

Which solution did I use previously and why did I switch?

Before adopting Splunk Enterprise Security, we did not use any other solution to address similar needs in our company.

What other advice do I have?

I know that our SOC team does use Splunk Enterprise Security to prioritize and investigate high-fidelity alerts, however, I'm not sure how it helps them specifically. I can say that many different teams in the business use it very heavily.

We do utilize UEBA in our company, yet not Splunk Enterprise Security UEBA from my understanding. I'm not part of those teams, so I wouldn't have an answer for how it specifically functions.

I would rate Splunk Enterprise Security a ten out of ten.

I advise other companies considering Splunk Enterprise Security to recognize that it is utilized by massive companies and is more practical. I would suggest finding what works for their environment and evaluating all related costs as those are important factors. Overall, Splunk Enterprise Security delivers, which is what truly matters.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Duy-An Dô - PeerSpot reviewer
Information Security Specialist at Ubisoft International SAS
Real User
Top 10
Sep 13, 2025
Streamlines alert triage and incident investigation while improving communication with non-technical stakeholders
Pros and Cons
  • "The features of Splunk Enterprise Security that I appreciate the most include the SPL search."
  • "Splunk Enterprise Security can be improved mainly regarding the UI, which can be daunting at first for newer employees."

What is our primary use case?

As a security analyst, my main use cases for Splunk Enterprise Security involve reviewing notables. I receive all the alerts and notables in my queue, review them, ensure they're not actual security incidents, and triage them as either true positives, false positives, and so on. I then investigate the true positives.

What is most valuable?

The features of Splunk Enterprise Security that I appreciate the most include the SPL search. It allows me to get all the data I need, make it beautiful, show it to my boss, and show it to less technical people. It's easy to display the data.

When we have a major incident, we need to move fast and answer quickly. Also, we need to inform non-technical people, so it's easier to show them.

Instead of showing them a raw log that's ugly and hard to read, we can show them a very concise point such as 'This insider threat with this IP address accesses this system,' and pivot wherever needed. It's really useful for data presentation.

Dealing with incidents depends on the type of incident; a major incident can take a few months, while a smaller incident can take from five minutes to five hours. We use Splunk SOAR, and we're starting to use that in Splunk Enterprise Security to automate our response. It's made my life easier because repetitive tasks can be automated with a playbook, and everything gets done in the background without manual triage.

Splunk Enterprise Security helps improve my business's resilience by protecting our enterprise. Every time there's something not working, it's our central log space. Every incident and everything that's not working is in Splunk. The factors that led to adding Splunk involve our relationship with the sales team and our technical contact. We have a very good relationship with them, which helps considerably.

The integration of these security solutions supports my security operations by providing us with better visibility into various types of endpoints. We have custom detections that we make on Splunk, and we also integrate Microsoft Defender alerts into Splunk. I have one place to investigate them all instead of going from product to product.

What needs improvement?

Splunk Enterprise Security can be improved mainly regarding the UI, which can be daunting at first for newer employees. It's hard to find everything, such as menu locations, dashboard access, and dashboard creation. It's still very complicated and takes a few weeks to understand. The UI could be more user-friendly.

The most significant challenges I face when using Splunk Enterprise Security for advanced threat detection include skills. I've been using it for four years and I don't know everything yet. Finding information and writing complex SPL queries can be challenging. I tried to use external AI, ChatGPT, but they're not very good with it. I know now there's SPL with AI, and we're going to test that.

For how long have I used the solution?

I have been using Splunk Enterprise Security for about four years.

What do I think about the stability of the solution?

I would assess the stability and reliability of Splunk Enterprise Security as generally good. We had a few performance issue bugs with very specific use cases, and they were handled quite fast. We reported them to our technical contact, and within a week, it was fixed.

What do I think about the scalability of the solution?

Splunk Enterprise Security scales effectively with the growing needs of our organization. We expand continuously, always adding new detection, new logs, and new systems. In Splunk Cloud, it's very scalable. We never have an issue with that, and we have terabytes of data coming in.

How are customer service and support?

I would evaluate customer service and technical support for Splunk Enterprise Security as very good. This is probably one of the reasons why we have a good relationship and we keep Splunk around.

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

Prior to adopting Splunk Enterprise Security, I always used Splunk. At the same time, we use Microsoft Defender Endpoint, however, we don't use their SIEM solution. I use MD alerting too.

Which other solutions did I evaluate?

I use disparate security solutions that integrate or import data into Splunk Enterprise Security.

What other advice do I have?

I am not directly involved in pushing new detection in Splunk Enterprise Security. However, I do tune detections; if a detection is firing too much or I feel we could edit the detection, I find it quite easy to do. My organization does not use risk-based alerting in Splunk Enterprise Security yet; we're working on it.

The advice I would give to other organizations considering Splunk Enterprise Security is to contact them, contact the sales rep, the tech rep, and ask them for a PoC trial. They're very open with this and even with new features. Before we buy anything new, such as SOAR, Splunk offers us to do a PoC. They give us a license to try it for free for a few months and give feedback if interested or not. For any enterprise thinking about it, I would contact them and get them to do a free trial for a while.

On a scale of one to ten, I rate Splunk Enterprise Security a nine.

Which deployment model are you using for this solution?

Public Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Other
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Buyer's Guide
Splunk Enterprise Security
September 2026
Learn what your peers think about Splunk Enterprise Security. Get advice and tips from experienced pros sharing their opinions. Updated: September 2026.
915,325 professionals have used our research since 2012.
Harshit Pawar - PeerSpot reviewer
Cybersecurity Engineer at a tech vendor with 201-500 employees
Real User
Top 20
Jul 27, 2026
Centralized threat data has powered faster incident response and proactive attack prevention
Pros and Cons
  • "The best features and the most important feature I want to highlight about Splunk Enterprise Security is its capability to process large amounts of data."
  • "From the point of view of deployments and making custom modifications in this particular product, it becomes really difficult because deployments of Splunk can get really tricky."

What is our primary use case?

I work for a cybersecurity-based company. We have our own products and solutions that we build and deliver to our customers, primarily revolving around Threat Intelligence solutions, TIP platforms, SOAR platforms, and incident response platforms.

The majority of tools that I work with are centered around threat intelligence, so we share threat intelligence for actioning on end security tools. These end security tools that consume threat intelligence are primarily Defender technology stack, which is how the entire arrangement functions.

Cyware has its own threat intelligence platform called Intel Exchange. This is a central data lake for all threat intelligence that any enterprise or organization might want to collect. An organization using threat intelligence from multiple sources collects threat intelligence from different types of open sources, RSS feeds, news articles, and blogs. They consume feeds from regulatory bodies like CERTs and ISACs, and they also purchase premium threat intelligence from threat intel feed providers like CrowdStrike, Recorded Future, and Microsoft Defender Threat Intelligence. When a customer has been consuming threat intelligence from these different sources, we consolidate everything, ingest it into a single platform, normalize it, and bring everything into a single structure. Threat intelligence is further processed, analyzed, and forwarded to end security tools for proactive blocking. If I am a financial sector company seeing other financial sector organizations like other banks getting targeted by a particular cyber attack, I use that intelligence to proactively block these threats in my environment before such an attack can happen in my organization.

I am using different tools including the entire Microsoft suite, most of the time working with Microsoft Sentinel, Microsoft Defender for Endpoint, CrowdStrike, Zscaler, and Splunk Enterprise Security.

What is most valuable?

Splunk Enterprise Security is basically a complete enterprise security solution, but it is primarily built on top of a security event and information management system; it is a SIEM solution. Splunk Enterprise Security acts as a data lake for all logs that I collect from different types of log sources within my environment. I bring logs and activity from my entire environment into a single place, and once this data is stored, I run analytics rules on top of it. These analytics rules are defined based on the different types of malicious behavior that I want to identify happening in my environment, and if any of these behaviors identify a match, it triggers alerts. These alerts could be actual malicious activities happening in my environment. Once those alerts are triggered, they are assigned to different types of analysts; these are SOC analysts who assign these alerts to themselves and then start investigating those alerts to see if the activity observed is actually malicious or not. Depending on those investigations, analysts close those incidents, and if something malicious has been identified, they take remediation actions. At that point, I integrate SOAR solutions. I integrate my own SOAR solution, which automates this entire actioning process.

For example, if a suspicious sign-in on a user account has happened and the sign-in was successful, my SOAR playbook resets the password for that particular user, notifies the user's manager, and sends out the necessary communication to that particular user whose account has been compromised. This is how Splunk Enterprise Security can be integrated with different security tools and how it works.

The best features and the most important feature I want to highlight about Splunk Enterprise Security is its capability to process large amounts of data. When I compare Splunk with all the other SIEM solutions that are out there in the market, Splunk has to be the one that can easily process huge volumes of data and scales really well. The query language that Splunk has, which is called SPL, is one of the best query languages out there that will help anybody to query large datasets and return results in a very quick and short period of time compared to the other SIEM solutions. For example, QRadar is extremely slow and sluggish when I want to query large datasets, but Splunk excels in that regard.

What needs improvement?

From the point of view of deployments and making custom modifications in this particular product, it becomes really difficult because deployments of Splunk can get really tricky. It requires a huge amount of hardware and infrastructure to run on. From that perspective, it is really compute heavy, and Splunk is one of the priciest solutions out there, so from a cost perspective as well, it is not one of the easiest to start with.

I do not think there is any particular lack of functionality with the product; the product is really good, but there are a few aspects in which Splunk Enterprise Security can become really difficult for people to get started with as beginners.

For how long have I used the solution?

I have been working with Splunk Enterprise Security for almost a year.

What do I think about the stability of the solution?

Splunk Enterprise Security definitely helps reduce the metrics that every security solution is built to reduce. If somebody was investigating these security threats and incidents manually and then manually going ahead and taking every single step, it would have taken those analysts a huge amount of time to remediate and protect their environments from these cybersecurity threats. Solutions like these are the reason why people buy them because they help reduce mean time to remediate and mean time to investigate, so that is the primary reason these solutions are primarily bought for.

What do I think about the scalability of the solution?

Splunk Enterprise Security is a very good solution when it comes to scalability, so I would rate it nine.

How are customer service and support?

I have not really interacted with the technical support of Splunk because I am not the one who is directly interacting with the product side of Splunk because somebody else does. I am not the one who really procures this product and interacts with their support team.

Which solution did I use previously and why did I switch?

I actually use Microsoft Sentinel, but that is not a native part of my toolset that I use. I integrate these solutions with the other set of tools that I work with at the moment.

I work with Defender and I work with Sentinel, so it is part of my job that I usually integrate these solutions with my solution that we sell.

I have worked with Defender for Cloud Apps, Defender for Endpoints, and I have also had a chance to work with Microsoft Defender for Identity, so I have worked on a few of these Defender solutions that Microsoft offers. We are a partner with Splunk.

How was the initial setup?

Both approaches are possible, but if I am simply looking to integrate the logs from my native technologies that I have in my infrastructure, I can simply use the out-of-the-box connectors, so I do not need to rely on third-party tools. If I have any particular third-party tool that allows me to ingest some custom data, that can also be done, so both things are possible.

What was our ROI?

Primarily, there are two things that Splunk Enterprise Security helps with: streamlining the log ingestion and normalization of all the logs in my environment into a single place; that is the first and foremost reason why anybody would want to buy Splunk Enterprise Security. Once I get all the data in a single platform, it really helps me analyze all those intelligence and data logs in a single place; these are done via the SPL query language that they provide along with the rules that can be scheduled and run on a regular basis. First, it helps streamline everything into a single place and helps act as a data lake for all logs in my environment. Second, it is really fast and quick in analyzing that large dataset that it can collect, so it provides a huge volume of better derived insights compared to other security solutions.

Which other solutions did I evaluate?

Microsoft Sentinel would be a top competitor, and recently Palo Alto has released their own SIEM solution as well, so these would be the top competitors.

In terms of technical capabilities, Splunk Enterprise Security would be the highest. In terms of ease of use and ease of adoption, Microsoft Sentinel would be the one, and for the other SIEM solution, they are definitely in the challenging category, but not really the market leaders.

What other advice do I have?

The threat detection module capability in Splunk Enterprise Security really comes in handy because that ties in my threat intelligence signals, and input from my different threat intelligence solutions can be brought into the picture when I am actually looking to prioritize the types of threats that I want to investigate and remediate in my environment, so that really becomes handy. I would rate this product an eight overall.

Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
Last updated: Jul 27, 2026
Flag as inappropriate
PeerSpot user
Raymundo Perez - PeerSpot reviewer
Splunk Admin at Sempra Infraestructura
Real User
Top 5
Sep 13, 2025
Correlation and integration capabilities have streamlined our investigation and response efforts
Pros and Cons
  • "The features of Splunk Enterprise Security that I find most valuable are the correlation and correlation data."
  • "Splunk Enterprise Security could be improved in the dashboards that provide KPIs about environmental behavior."

What is our primary use case?

My main use cases for Splunk Enterprise Security are detection, attacks, analysis, and investigation.

What is most valuable?

The features of Splunk Enterprise Security that I find most valuable are the correlation and correlation data. These features have benefited my organization through the model of investigation, correlating with correlation alerts, and integration with other tools, which is a good point.

In my experience with other tools in previous jobs, the time is reduced by around 70% compared to the previous tool.

My impressions of Splunk's ability to predict, identify, and solve problems in real time are positive. There are points to consider when enriching the data with these kinds of inputs. It is a good opportunity for companies trying to start with this environment, though it might be a challenge for those who have been using it for a long time since it requires identifying the context and use cases.

What needs improvement?

Splunk Enterprise Security could be improved in the dashboards that provide KPIs about environmental behavior.

The most significant challenges I face when using Splunk Enterprise Security for advanced threat detection include correlation when we have inputs or tools about security, such as Forescout or CrowdStrike, which presents a good challenge.

My organization uses risk-based alerting in Splunk Enterprise Security, yet not optimally, which presents another challenge. My security ops team takes longer to remediate security incidents with Splunk Enterprise Security compared to our previous solution. It is very complex.

For how long have I used the solution?

I have been using Splunk Enterprise Security for four years.

What do I think about the stability of the solution?

I would assess the stability and reliability of Splunk Enterprise Security as good. However, it depends on the Splunk architects or the best practices provided by the admins and power users. They should avoid creating bad practices in correlation alerts, queries, and dashboard reports, but overall, it is a good, stable product.

What do I think about the scalability of the solution?

Scaling is smooth in certain functionalities but can be more difficult when involving different areas. When under the same scope, it progresses smoothly.

How are customer service and support?

Customer service and technical support are good. They can sometimes be expensive, but the cost is appropriate given the professionalism in providing reports, diagnostics, and analyses.

We may need more follow-up for remediation, which is sometimes noted as expensive, however, it is acceptable as part of the partnership agreement.

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

Prior to adopting Splunk Enterprise Security, I was using another solution, SOAR, to address similar needs. It accomplishes that along with the implementation process, and I need to consider the different policies within the company regarding privileges, roles, and dependencies across different areas.

How was the initial setup?

The process for customizing, developing, testing, deploying, and refining detections in Splunk Enterprise Security is part of the onboarding process. We sometimes need to review it based on our needs or use cases we need to apply, and we need to correlate the data with different inputs, sometimes directly from security or IT data.

What was our ROI?

I have seen a return on investment with Splunk Enterprise Security. If the account executives for Splunk do not explain the implementation process clearly, we may face challenges, as our company's first question is usually about seeing immediate results for the amount spent. We often need to follow a process and achieve a certain maturity level, which requires a prompt response from our management.

What's my experience with pricing, setup cost, and licensing?

Regarding my experience with pricing, setup cost, and licensing, it is good. I saw around 2016 when the license was one option, however, now it is good, although sometimes it depends on the business of the company since we do not always have the budget to increase, decrease, or try to change.

Which other solutions did I evaluate?

The factors that led me to change to Enterprise include the new improvements. This is the correct path, and next year we will need to review the challenges concerning AI governance, which I plan to use in Splunk Enterprise Security.

What other advice do I have?

Splunk Enterprise Security has helped improve our organization's business resilience. It helps us respond to various needs in our different regions or plants, aiming to obtain critical information to reduce the impact of hacks in our plants.

I would absolutely recommend Splunk Enterprise Security. Every time I have the opportunity to promote or explain how it works, people say it is amazing, and I agree. It is an integrated solution that stands out against competitors, and though it may be expensive, it delivers good quality.

I would rate Splunk Enterprise Security overall a nine on a scale of one to ten, considering the current improvements.

Disclosure: My company has a business relationship with this vendor other than being a customer. Accenture
PeerSpot user
David-Alfonso - PeerSpot reviewer
IT Security Engineer at a financial services firm with 201-500 employees
Real User
Top 5
Sep 11, 2025
Has significantly improved detection speed and enabled faster response to threats through better integration and automation
Pros and Cons
  • "The features of Splunk Enterprise Security that I find most valuable include Mission Control, which I really appreciate, the way accelerated data functions, making it really fast to see, the integration with SOAR, which is something really cool and integrates with automated processes, and the way to ingest threat intelligence feeds, which is an amazing feature as well."
  • "Splunk Enterprise Security has helped improve my organization's business resilience, as we were able to detect an attack that was happening after hours and prevent it thanks to the detections."
  • "The on-premise integration with SOAR could be more simple; the cloud version integrates with SOAR very easily, but the on-premise SOAR and on-premise Splunk Enterprise Security are really not that easy, so I would appreciate if that could be improved."

What is our primary use case?

My main use cases for Splunk Enterprise Security are basically triage, ensuring cyber threat defence, and improving speed when defending the organization. Since I am the only one currently in the security team, we are growing this year and next, and we're expanding. Splunk Enterprise Security is improving the process to defend, basically.

How has it helped my organization?

The features of Splunk Enterprise Security benefit the organization. You can see threats much faster, helping detect something that the antivirus may miss. Splunk Enterprise Security can work with this, and when the antivirus has a hard position, by using proper detection rules that are well-configured, you can see what's going on in real-time, both endpoint-based and network-based.

What is most valuable?

The features of Splunk Enterprise Security that I find most valuable include Mission Control, which I really appreciate, the way accelerated data functions, making it really fast to see, the integration with SOAR, which is something really cool and integrates with automated processes, and the way to ingest threat intelligence feeds, which is an amazing feature as well.

Splunk Enterprise Security has helped improve my organization's business resilience, as we were able to detect an attack that was happening after hours and prevent it thanks to the detections. We stopped it immediately in a matter of about 30 minutes. Splunk Enterprise Security has improved my ability to predict, identify, and solve problems in real-time; it's not just proactive, but also really predictive. My organization uses Risk-Based Alerting in Splunk Enterprise Security, which speeds up our process to detect and our mean time to respond. It's very helpful, and after we improved the configurations, we have RBA working fine, something that will always be maintained; it may not be perfect, but we do our best to maintain it.

On average, my security ops team takes less than five minutes to remediate security incidents with Splunk Enterprise Security compared to our previous solution, which used to take hours because we needed to see different sites. We are using new threat detection features in Splunk Enterprise Security by ingesting a lot of threat intelligence feeds from our main vendor, which has significantly improved the indicator of compromise, the IOCs detections. We also use Sigma detections and adapt to Splunk.

What needs improvement?

The on-premise integration with SOAR could be more simple; the cloud version integrates with SOAR very easily, but the on-premise SOAR and on-premise Splunk Enterprise Security are really not that easy, so I would appreciate if that could be improved. 

Additional features that should be included in the next release of Splunk Enterprise Security are the ability to integrate with other software and tool frameworks, beyond Sysmon, to avoid ingesting Sysmon logs from the endpoint, which can be very noisy at times, resulting in more straightforward detection and less resource-intensive licensing.

For how long have I used the solution?

I have been using Splunk Enterprise Security for four years.

What do I think about the stability of the solution?

I have experienced downtime, crashes, and performance issues with Splunk Enterprise Security due to a hardware issue, which we were able to quickly fix thanks to the backup recovery. However, it took about one day, and it highlights the need to move to clustering, which I've discussed with my leadership team.

What do I think about the scalability of the solution?

I would assess the stability and reliability of Splunk Enterprise Security as needing clustering. It ensures it remains operational all the time, which means you can see cyber attacks. When it's down, you can't see anything. 

We currently rely on disaster recovery and backup recovery, which takes time to recover, during which you're basically blind, so I'm pushing my leadership team to switch over to a clustering environment for constant availability. Right now, the server we have meets the hardware requirements, and we have moved to new hardware. 

We're considering moving to cluster environments to scale in the future, probably in a couple of years.

How are customer service and support?

I would evaluate customer service and technical support for Splunk Enterprise Security as excellent; when we open tickets for troubleshooting, 99% of the time, it relates to our Linux environment. I have no personal complaints about the support.

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

Prior to adopting Splunk Enterprise Security, Splunk was already in place when I came on board at Educational Federal Credit Union.

How was the initial setup?

In the beginning, we were using disparate security solutions that integrate or import data into Splunk Enterprise Security. Now we are adapting to completely switch to the Splunk Enterprise Security side to have a single-pane-of-glass view of everything, minimizing the integrations with the vendors such as EDR, DLP, and the firewall.

What was our ROI?

I have seen a return on investment with Splunk Enterprise Security. My executive team has noticed improvements; we were able to save on other solutions, which increased budgeting for future projects thanks to Splunk Enterprise Security and the licensing optimization, allowing us to invest in other tools.

What's my experience with pricing, setup cost, and licensing?

My experience with pricing, setup costs, and licensing with Splunk Enterprise Security has been challenging in the past due to the expensive licensing model, which was driven by Sysmon delivering a lot of unnecessary noise. We don't use Splunk just for security; we also use it for other departments. 

We have shared the license between security and development departments, making sure to minimize ingestion logs from the endpoints, including workstations and servers. We are currently leveraging EDR telemetry ingested to Splunk, which saved a lot of licensing money while allowing us to see what we're looking for.

What other advice do I have?

My advice to other organizations considering Splunk Enterprise Security is that it's the leader in SIEM globally. You have a lot of customization and data normalization, meaning you can detect anything you want compared to other SIEMs. Splunk Enterprise Security is worth the investment because it provides exactly what you need if you are a true cyber defender. I also network with friends from a company, Next-Gen Systems, which is leading in detection and investing in developments and integrations with Splunk due to its scalability. 

On a scale of one to ten, I rate Splunk Enterprise Security a ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Ashiq Ashraf - PeerSpot reviewer
Specialist-Infrastructure Opertions at Allianz Technology
Real User
Top 10
May 22, 2025
Effective data management and threat detection through comprehensive integration and rapid response
Pros and Cons
  • "Splunk Enterprise Security provides the foundation for unified threat detection, investigation, and response, enabling fast identification of critical issues."
  • "The pricing of Splunk Enterprise Security is not very affordable, and I have seen many companies planning to leave because of cost concerns."

What is our primary use case?

I'm an end user, admin, and consultant. We use Splunk Enterprise Security internally in our organization, and I also use it for my personal studies. My usual use cases for Splunk Enterprise Security include monitoring several kinds of exchange server logs and Office 365 logs, among others, as we have multiple monitoring use cases based on our requirements in our environment. We were trying to solve multiple things by implementing Splunk Enterprise Security, particularly for monitoring our applications based on the insurance business, so we use Splunk Enterprise Security logs for security purposes and internal infrastructure monitoring, including logs matching security purposes in our Office 365 and exchange servers.

What is most valuable?

The most valuable features of Splunk Enterprise Security are several add-ons and TAs, while the lack of a DB requirement is a significant advantage for the business, allowing easier management without needing in-depth DB knowledge. I find that Splunk Enterprise Security's ability to import data from various sources, including looking up Excel files, is quite effective, providing a good way for management.

We import data from several unique data sources into Splunk Enterprise Security, possibly more than a hundred because we have AWS and multiple servers. We have disparate security solutions that integrate data into Splunk Enterprise Security. I can still query data in Splunk Enterprise Security regardless of where it resides, and in my perspective, the query provides data quickly.

Splunk Enterprise Security has improved our organization's ability to ingest and normalize data compared to before using Splunk Enterprise Security. The unified platform helps consolidate networking, security, and IT observability tools, which is very relevant to our internal needs. Using Splunk Enterprise Security, our focus was not on reducing alert volume but on properly finding and handling alerts; we've managed to capture 100% of them effectively.

Splunk Enterprise Security provides the relevant context to help guide investigations by allowing us to share application logs and details with clients efficiently. We utilize out-of-the-box detections in Splunk Enterprise Security, and we have created dashboards that add value to our monitoring efforts. Customizing, developing, testing, deploying, and refining detections in Splunk Enterprise Security is easy; it has been a good experience without significant difficulties.

We upgraded to Splunk Enterprise Security from version 8.0.4 to 9.0.6, and also from 8.1.4 to 9.0.6; it worked well with the support we received from the team, and it has proven to be very useful. Splunk Enterprise Security provides the foundation for unified threat detection, investigation, and response, enabling fast identification of critical issues.

What needs improvement?

The solution could be improved by integrating more application monitoring features and possibly incorporating AI capabilities to enhance its functionality.

For how long have I used the solution?

I've been working with Splunk Enterprise Security for six years.

What do I think about the stability of the solution?

Splunk Enterprise Security is stable and scalable, making it a good tool that is beneficial for our needs.

What do I think about the scalability of the solution?

Splunk Enterprise Security is stable and scalable, making it a good tool that is beneficial for our needs.

What other advice do I have?

I participated in the deployment process of Splunk Enterprise Security, and we performed UAT before moving it to production. It's not the most affordable solution, as I've witnessed several companies considering leaving due to cost factors. The pricing of Splunk Enterprise Security is not very affordable, and I have seen many companies planning to leave because of cost concerns.

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
reviewer2898975 - PeerSpot reviewer
руководителем дирекции SOC at a financial services firm with 1,001-5,000 employees
Real User
Top 20
Sep 16, 2026
Visual security insights have transformed incident oversight and guided data-driven defense
Pros and Cons
  • "The features of Splunk Enterprise Security that I consider the best include the platform's ability to search big data, the ease of writing SPL queries and finding this data, and the quality of the dashboards that are drawn very well, allowing the creation of any dashboards you want, as far as your imagination goes."
  • "Since I am currently working with SOAR, I would like to give recommendations regarding Splunk SOAR, as there are very few ready-made apps, and we face problems with integration, which requires us to write to the vendor for help."

What is our primary use case?

My main use case for Splunk Enterprise Security involves advising on how integration should be done, what the architectural diagram should look like, what data we should see, assigning tasks for performing gap analysis according to MITRE ATT&CK and international standards, and similar responsibilities. I used to be an analyst investigating information security incident cases, and now I'm in a more managerial position.

I cannot describe a specific example in detail because it is confidential information, as I am under an NDA. However, I can say that integration with various systems was carried out, and there were moments when Splunk agents were failing for unclear reasons. In the end, we performed troubleshooting and realized that the problem was on the agent side, requiring us to update the agents.

In terms of integration with various systems, I encountered no problems during the implementation of Splunk Enterprise Security.

What is most valuable?

The features of Splunk Enterprise Security that I consider the best include the platform's ability to search big data, the ease of writing SPL queries and finding this data, and the quality of the dashboards that are drawn very well, allowing the creation of any dashboards you want, as far as your imagination goes.

Splunk Enterprise Security positively impacted our organization because we simply liked the solution for its convenience, and we decided to adopt it.

For different solutions, the state of the solutions, systems, and so on, we created visualizations and reports on a dashboard so that you can instantly see in real time what is happening.

What needs improvement?

In my opinion, there is always room for growth in Splunk Enterprise Security. Specifically, since I am currently working with SOAR, I would like to give recommendations regarding Splunk SOAR, as there are very few ready-made apps, and we face problems with integration, which requires us to write to the vendor for help. Since the vendor responds slowly, we completed a pilot and could not make a decision because there are very few ready-made apps. I would like the number of ready-made apps to grow and for the overall focus on SOAR to increase.

For how long have I used the solution?

I have been using Splunk Enterprise Security for almost three years.

What do I think about the stability of the solution?

I assess the stability of Splunk Enterprise Security as reliable, as the system works reliably.

What do I think about the scalability of the solution?

I find it easy to expand Splunk Enterprise Security for new tasks or to increase the volume of data.

Scaling Splunk Enterprise Security is easy if my organization needs to process more data or connect new systems, but it can be costly.

How are customer service and support?

We have contacted the support service of Splunk Enterprise Security.

I would give the support a rating of seven.

Which solution did I use previously and why did I switch?

We used another tool before implementing Splunk Enterprise Security, but I cannot specify which one.

Which other solutions did I evaluate?

We evaluated other solutions before choosing Splunk Enterprise Security. According to our process, we conduct a market analysis of which systems exist, run a pilot project for testing the functionality, and then choose the system we preferred.

What other advice do I have?

My advice to those considering implementing Splunk Enterprise Security is to conduct a full analysis, run a pilot, and only then make a decision. I would rate this review as an eight.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Last updated: Sep 16, 2026
Flag as inappropriate
PeerSpot user
Paul-Zhang - PeerSpot reviewer
Manager, Information Security at a financial services firm with 10,001+ employees
Real User
Top 5
Sep 11, 2025
Delivers efficient threat detection through big data analytics but requires improvement in reducing false positives and operational noise
Pros and Cons
  • "Splunk Enterprise Security is doing its job in helping improve my organization's business resilience."
  • "The biggest advantage I can see in Splunk Enterprise Security is the big data analytics."
  • "There is another new term called benign positives. It is better to clearly identify each definition of those terms since it has not been popular in the industry, and everyone needs to be aware of those things."
  • "The most significant challenges I face when using Splunk Enterprise Security for advanced threat detection are the false positive alerts."

What is our primary use case?

My main use cases for Splunk Enterprise Security are threat detection use cases.

What is most valuable?

The biggest advantage I can see in Splunk Enterprise Security is the big data analytics. The simple search query with faster responding results is also appealing. My team handles large volumes of cybersecurity data. To be able to search against such a big amount of data with efficiency is the key driver for my team to do threat detection and data analytics.

What needs improvement?

Splunk Enterprise Security can be improved in many ways. I am very happy to experience the AI-powered security platform they are going to show us in the new version. Better identification of true positives and false positives should be included in future releases.

There is another new term called benign positives. It is better to clearly identify each definition of those terms since it has not been popular in the industry, and everyone needs to be aware of those things.

The most significant challenges I face when using Splunk Enterprise Security for advanced threat detection are the false positive alerts. As mentioned in the keynote, there is a lot of noise. Reducing the noise to make sure the SOC is operating more efficiently is one of the challenges my team is having. The process for customizing, developing, testing, deploying, and refining detections in Splunk Enterprise Security is not the easiest, however, it is not the most difficult one, so I would say it is medium.

For how long have I used the solution?

I have been using Splunk Enterprise Security for seven years.

What do I think about the stability of the solution?

I have experienced downtime, crashes, and performance issues, with the most recent one being a data ingestion issue from another security platform. This key data source is not being ingested, causing some downtime.

What do I think about the scalability of the solution?

Splunk Enterprise Security does not scale efficiently with the growing needs of my organization. Since it is on-premises, we have some scalability issues, and there are other new players coming up.

We have expanded the usage of Splunk Enterprise Security several times.

How are customer service and support?

I would evaluate customer service and technical support as adequate since my team does not deal with it directly. Another team dealt with them, and I found it to be acceptable as they have 24/7 support all over the world. 

They hand over to the next team in another country, but sometimes it takes time to do the transfer, and we have to explain all the problem issues again, which can be frustrating. For that, I would rate it a five.

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

Prior to adopting Splunk Enterprise Security, I was not using another solution to address similar needs.

How was the initial setup?

My experience with deploying Splunk Enterprise Security is actually another team's job, however, they are doing adequately.

What about the implementation team?

My organization is moving towards risk-based alerting in Splunk Enterprise Security. My team actually built our own risk-based alerting before they released it; however, we are looking forward to integrating both.

What was our ROI?

Splunk Enterprise Security is doing its job in helping improve my organization's business resilience. There are other competitors in the same field, so I find it neither particularly good nor bad.

What's my experience with pricing, setup cost, and licensing?

I don't directly deal with pricing.

What other advice do I have?

I would advise other organizations considering Splunk Enterprise Security that the new version looks impressive. If organizations want the new, complete package, I would recommend ES Premier, as it combines ES with TIM, UEBA, and SOAR. 

On a scale of one to ten, I would rate Splunk Enterprise Security a seven. I believe ES is doing its job, but it is slightly behind its competitors. 

Other competitor platforms already have AI integrated, and they just announced it today, so it feels somewhat behind. However, I am looking forward to this new feature.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Sreeni Mamidipaka - PeerSpot reviewer
IT Security Mgr at a legal firm with 1,001-5,000 employees
Real User
Top 10
Sep 11, 2025
Dashboards and reporting have streamlined our alert triaging and security investigations
Pros and Cons
  • "I would assess the stability and reliability of Splunk Enterprise Security as generally good, with very few downtime, crashes, and performance issues."
  • "Splunk Enterprise Security has helped improve my organization's business resilience by fulfilling gaps in forensics, incident management, IRP, and data management while helping us mature our security operations."
  • "Our organization has very limited resources, so we would want to expand some of those automation and AI capabilities to fill those gaps."
  • "My organization does not completely utilize risk-based alerting in Splunk Enterprise Security as it's not fully mature."

What is our primary use case?

My main use cases for Splunk Enterprise Security are log management and enterprise security. Those are the key.

How has it helped my organization?

Splunk Enterprise Security has helped improve my organization's business resilience. We load much of our data and information that we use. It's really helping us in our log management solution, and also for forensics and alert triaging purposes. Forensics is one of the big pieces, along with incident management, IRP, and data management. It's fulfilling all those gaps and helping us mature our security operations.

What is most valuable?

The features of Splunk Enterprise Security that I enjoy the most include reporting, dashboards, and RBA. These features have benefited my organization since the dashboards and reports help us review security alerts and events in a timely manner. The RBA is what we are currently working on to develop and have some early detection on security alerts and notifications.

Currently, I am using disparate security solutions that integrate or import data into Splunk Enterprise Security. This integration supports my security operations by providing some visibility into security. Yet we have many basic issues where we need to fix the log sources, integration, and quality of the content that's going into Splunk Enterprise Security.

I find the process for customizing, developing, testing, deploying, and refining detections in Splunk Enterprise Security quite basic. We don't have any sophisticated process. We have contractors and MSSP who are timely filling those gaps, going through the rule review process, going through regular security testing, and prioritizing what is more important as an organization.

What needs improvement?

Though we have not completely explored the product functionality, Splunk Enterprise Security itself has many features. This morning I was reviewing all the AI capabilities, such as version 8.2 which has included incident triaging and process. That's probably a very good feature. Our organization has very limited resources, so we would want to expand some of those automation and AI capabilities to fill those gaps.

For how long have I used the solution?

I have been using Splunk Enterprise Security for two years.

What do I think about the stability of the solution?

I would assess the stability and reliability of Splunk Enterprise Security as generally good, with very few downtime, crashes, and performance issues. I've been with the organization for a little over a year. I have seen one or two occasions where the enterprise resources crashed. I haven't really seen any significant issues.

What do I think about the scalability of the solution?

Splunk Enterprise Security works efficiently with scaling growing needs since the distributed architecture is very well planned and easily scalable. All you need is to spin up a few additional resources and you can build your collectors, forwarders, and indexers. It's quite easy. At the same time, it comes with its own complexities since it's an on-premises solution. 

Overall, it performs well. I haven't seen any outages or resource challenges while using it.

How are customer service and support?

I would evaluate customer service and technical support as very responsible. Anytime that we have issues or challenges, I could see they were helping us behind the scenes and going through all these improvements. They were excellent.

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

In previous organizations, I have been well-versed with many other SIM tools. QRadar is one prominent tool I used. The McAfee Nitro, which isn't available anymore, was another. RSA NetWitness, RSA enVision, ArcSight were among the many tools I've used. In modern SIM tools, I am more familiar with Sentinel and Google Chronicle. I would say Splunk Enterprise Security has more capabilities, and maturity-wise and roadmap-wise, this product has become much more mature than the other two products I could compare.

How was the initial setup?

I was not present for the deployment.

What was our ROI?

I have definitely seen a return on investment with Splunk Enterprise Security.

What other advice do I have?

The most significant challenges I face when using Splunk Enterprise Security for advanced threat detection relate to the RBA, which is something that we were struggling with. We are working with the SIM and our reseller to streamline that process. That's something that's not easy for every organization. We are going through the same turbulence.

My organization does not completely utilize risk-based alerting in Splunk Enterprise Security as it's not fully mature. It is supporting our SOC in a limited way. We still have a long way to go. The product is not completely mature. We are a unique organization, so it requires additional resources to get that work done.

My organization is in the process of expanding our security use cases. It's a multi-year model where we are strategizing and exploring all our security needs. I would say we are still in the early phase. Although we have the product in place, it was not yet mature due to some resource issues.

My advice to other organizations considering Splunk Enterprise Security is that it's a good product. It's definitely helpful. If somebody is looking for security and log management, investigations, incident, and IRP, then they can look into this product and explore it. It's one of the market-leading products. It definitely stays up to the mark. 

On a scale of one to ten, I rate this solution an eight.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Jhoneycutt Honeycutt - PeerSpot reviewer
Senior security analyst and engineer at a logistics company with 501-1,000 employees
Real User
Top 20
Sep 22, 2026
Security platform has improved incident investigations and provides faster, correlated threat insights
Pros and Cons
  • "Splunk Enterprise Security has helped improve my organization's business resilience, and my impressions of Splunk Enterprise Security's ability to predict, identify, and solve problems in real-time are very efficient."
  • "Splunk Enterprise Security can be improved with additional features and newer features and tools."

What is our primary use case?

My main use case for Splunk Enterprise Security includes SIEM, SIEM services, network monitoring, detections and response, and data correlation.

We had an incident where we experienced command and control activity from an endpoint, which was a Citrix server that we had that is air-gapped or essentially firewalled off from our network. We used Splunk Enterprise Security to correlate the data and see the activity that was taking place with the threat actor.

Splunk Enterprise Security helped us piece together what was going on in that incident by making the investigation easier. It helped us build a report much quicker and helped us trace the activity much quicker.

What is most valuable?

The best features Splunk Enterprise Security offers include the ability to normalize data and integrate with other security tools and products from other vendors.

I use data normalization and integrations in my day-to-day work because we have several Splunk Enterprise Security-based apps, which save us time in investigation and help us piece together data and normalize it.

Splunk Enterprise Security has positively impacted my organization by helping us see our attack surface more efficiently and have more visibility on our network more efficiently.

What needs improvement?

Splunk Enterprise Security can be improved with additional features and newer features and tools.

For how long have I used the solution?

I have been using Splunk Enterprise Security personally for around six to eight months.

What other advice do I have?

I do not have anything else to add about how I use Splunk Enterprise Security.

I do not have anything else to add about the needed improvements.

I do not have anything else to add about the needed improvements or specific features or tools I wish it had.

Regarding Splunk Enterprise Security's AI capabilities, I think its governance and security are sufficient.

Regarding Splunk Enterprise Security's AI capabilities, I have no complaints so far as it is very accurate.

Splunk Enterprise Security has helped improve my organization's business resilience, and my impressions of Splunk Enterprise Security's ability to predict, identify, and solve problems in real-time are very efficient. It helps increase our response time and helps incident response in a more efficient and fast manner.

Splunk Enterprise Security has helped reduce my team's average Mean Time to Resolve, MTTR metric, but I cannot say by how much because I do not have access to those metrics in my position.

We are not utilizing risk-based alerting in Splunk Enterprise Security at this time.

I would rate this review an eight out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Last updated: Sep 22, 2026
Flag as inappropriate
PeerSpot user
Buyer's Guide
Download our free Splunk Enterprise Security Report and get advice and tips from experienced pros sharing their opinions.
Updated: September 2026
Buyer's Guide
Download our free Splunk Enterprise Security Report and get advice and tips from experienced pros sharing their opinions.