I have been using Splunk Enterprise Security for over seven years, and many of my use cases include monitoring user behavior, tracking system processes that go up and down, and determining necessary actions when dealing with Windows admin endpoints. I examine CVEs and the vulnerabilities that require triaging and remediation. One of the main features and functions for my use cases with Splunk Enterprise Security involves alerts built on user activity. There are numerous ways to take data and events, correlate them, or review correlation searches to populate the necessary information across any industry and environment. Splunk Enterprise Security is a wonderful tool to have for enterprise security.
Senior Cyber Security Analyst at a energy/utilities company with 5,001-10,000 employees
Real User
Top 20
Sep 16, 2026
My main use case for Splunk Enterprise Security involves new detections and correlation of events. I use data points that are submitted via information-sharing communities and use those as artifacts, TTPs, and IOCs to build my own detections for behavior in my logs. Using those detections I can identify suspicious or malicious behavior.
senior technical program manager at a computer software company with 201-500 employees
Real User
Top 10
Sep 16, 2026
My main use case for Splunk Enterprise Security involves log aggregation, anomaly identification, visualization of potential issues, errors, and threat modeling. I create specific reports or dashboards to measure log patterns or events that fall outside of our specific thresholds, such as user logins multiple times a day or users attempting to hit protected routes that they don't have access control for.
Presales Engineer at a comms service provider with 10,001+ employees
Real User
Top 10
Sep 16, 2026
The main use of Splunk Enterprise Security in my organization is for threat hunting activities, digging through logs by doing statistical searches and, as a result, having the ability to get results fairly quickly so I can then chain together searches or cross-reference information. For example, I get bulletins with indicators of compromise from a vendor or an entity, a public administration in France, and then I search for the IOCs and from there, step by step, starting from that information I find, I cross it with other information to know, typically, whether the IOC that was found means that the user was compromised. Did the user go all the way, and what is the root cause of the malicious activity? I am in pre-sales, so it is mainly for demos.
Security Analyst at a comms service provider with 10,001+ employees
Real User
Top 20
Sep 16, 2026
My main use of Splunk Enterprise Security in my organization is to create detection rules for our clients. Notably, the detection rule that I created with this tool is the RBA rules, Risk-Based Alerting, that we have used for many clients. To implement an RBA rule with Splunk Enterprise Security, we took the templates provided by Splunk and adapted them to our needs, allowing us to detect things we were not able to detect before, such as pen tests.
My main use case for Splunk Enterprise Security is detection engineering and detection and response. A specific example of how I use Splunk Enterprise Security for detection engineering or response is detecting potential account compromise, DLP, and insider risk. Splunk Enterprise Security helps me detect those issues by enabling us to develop detection content based on threat intelligence research, and then we use the frameworks available to us in Splunk Enterprise Security to enrich those detections to provide analysts with contextual information to help them triage and respond to the alert.
Learn what your peers think about Splunk Enterprise Security. Get advice and tips from experienced pros sharing their opinions. Updated: September 2026.
My main use case for Splunk Enterprise Security is for security alerting, triage, SIEM, and incident response.We use Splunk Enterprise Security for incident response with an MSSP that will triage findings or events, and then they will escalate them up as investigations in which our analysts will then respond to them. We then take in and start doing our investigation, adding notes, and eventually closing with disposition. If the incident comes from external to Splunk, we typically just conduct the investigation through Splunk and document it externally via our IR processes.
Cybersecurity Analyst at a energy/utilities company with 501-1,000 employees
Real User
Top 20
Sep 16, 2026
My main use case for Splunk Enterprise Security is using the SIEM for detections. A quick specific example of what kind of detections I use Splunk Enterprise Security for includes mostly the built-in ones, with one that comes to mind being possible travel.
Cybersecurity Analyst at a tech services company with 11-50 employees
Real User
Top 20
Sep 16, 2026
My main use case for Splunk Enterprise Security is reviewing incidents in the Mission Control dashboard for our clients. When an incident occurs, my analyst team and I review every incident and conduct investigations to view logs and perform formal investigations. A specific example of how I have used Splunk Enterprise Security recently is when an incident in the Analyst Queue occurs or triggers. We review every property of the incident, including the host name, the user involved, and any risk events. Meanwhile, we work in an investigation file, and for the client, we deliver this as a PDF file or a Word file. Everything that we find in the alert or in the logs, we build a timeline so that when an incident occurs, we provide the client with the scope. When we deliver an investigation, the client knows what happened, who did it, and other relevant details. I have been using the RBA framework increasingly. When an incident is happening, we review many things in this dashboard. When a host is involved, we review the most recent incidents in the risk framework, and when we review the alert, we know what was happening with this host.
Cyber Security Consultant at a tech services company with 11-50 employees
Real User
Top 5
Sep 16, 2026
My main use case for Splunk Enterprise Security is for SOC operations. I offer the SOC service to our customers, and Splunk Enterprise Security is a very powerful tool that provides all the framework and tools to correlate events, conduct investigations, and manage issues or alerts.
Especialista en ciberseguridad at a retailer with 11-50 employees
Real User
Top 20
Sep 16, 2026
Splunk Enterprise Security's main use case in my organization is centralizing alerts and seeing the risk by asset. Centralizing alerts and visualizing risk by asset has helped us identify which assets are compromised and give them proper attention.
CR 1 at a healthcare company with 5,001-10,000 employees
Real User
Top 20
Sep 16, 2026
I use Splunk Enterprise Security as a SIEM, and I mostly like to correlate whatever logs we see to view all the logs for the alerts. We have everything that involves the apps in the company within Splunk logs. We have identity logs, vishing, and phishing. We also have some remote access and a bunch of alerts. Splunk's capabilities give the opportunity to see everything and have a timeline on the alerts.
IT Administrator at a government with 1,001-5,000 employees
Real User
Top 10
Sep 16, 2026
My main use case for Splunk Enterprise Security is detection and engineering. We are looking for all different kinds of threats with Splunk Enterprise Security and then we ingest data sources from different telemetry to look at our posture, starting from MFA to everything else. That is our main use for Splunk Enterprise Security.
Architecte Technique at a manufacturing company with 10,001+ employees
Real User
Top 20
Sep 16, 2026
My main use case for Splunk Enterprise Security is detection and SOC activities, so everything related to detection and security. Every day, I use Splunk Enterprise Security to trigger alerts and analyze the risks that are currently affecting our company.
Manager cybersecurity at a tech vendor with 10,001+ employees
Real User
Top 10
Sep 16, 2026
Splunk Enterprise Security serves as my main security solution. We raise notable events and pass them to the SOAR for security purposes. When I raise notable events and pass them to the SOAR, I track insider threats and external security incidents.
Director, Technology at a financial services firm with 5,001-10,000 employees
Real User
Top 10
Sep 16, 2026
Splunk Enterprise Security serves as our main security information and event management solution for our SOC. We have a setup to pull alerts for our SOC, and then we use it to work through each of the incidents we discover. We also use it to develop SOAR and utilize the SOAR piece to develop playbooks.
Computer Systems & Application Specialist II at a mining and metals company with 501-1,000 employees
Real User
Top 10
Sep 16, 2026
Our main use case for Splunk Enterprise Security is to gather all the information that we need and also create some dashboards that can help us understand what's going on in the network. For example, we would like to see if there are any failed logging attempts and, based on that, identify the systems or computers that were attempting to access resources, the time they were trying to access them, and obtain the raw data to further investigate. We also need to create alerts when problematic events occur. Additionally, when a device is not sending logs, we need to be aware of that situation. We also must be aware of any malware installed on the network and alert on that as well. We would like to have all of this information available in Dashboard Studio.
DCO Manager at a aerospace/defense firm with 10,001+ employees
Real User
Top 10
Sep 16, 2026
Splunk Enterprise Security serves as my main SIEM with forensics and response capabilities. I use it for threat detection, vulnerability management, and incident response for observability.
information security architect at a energy/utilities company with 1,001-5,000 employees
Real User
Top 10
Sep 16, 2026
I have been using Splunk Enterprise Security for four years. My main use case for Splunk Enterprise Security is for our preparation for our SOAR deployment. I use Splunk Enterprise Security through dashboards and alerts for that.
Security Engineer at a financial services firm with 10,001+ employees
Real User
Top 10
Sep 16, 2026
My main use case for Splunk Enterprise Security is creating dashboards and general overall system health and maintenance. For system health or maintenance, I build dashboards for threat intelligence across the bank environment.
Information Security Engineer at a financial services firm with 5,001-10,000 employees
Real User
Top 20
Sep 16, 2026
My main use case for Splunk Enterprise Security is being an engineer for the SOC and insider threat risk team, where I monitor threat detection, manage the queue for a SOC, and ensure Splunk Enterprise Security data it uses is working properly. I give a quick specific example of how I use Splunk Enterprise Security in my day-to-day work by tuning detections, creating new detections, enabling any new features that come in, assessing identity, managing that, or RBA, and addressing any issues that arise that SOC analysts see, working on those with Splunk support or with the internal team.
Threat Analytics Lead at a manufacturing company with 501-1,000 employees
Real User
Top 10
Sep 16, 2026
My main use case for Splunk Enterprise Security is threat hunting.A specific example of how I use Splunk Enterprise Security for threat hunting in my organization is identifying incidents and threats. When I'm identifying incidents and threats, I use self-created dashboards in Splunk Enterprise Security.
Sr manager cybersecurity at a transportation company with 10,001+ employees
Real User
Top 10
Sep 16, 2026
My main use case for Splunk Enterprise Security is visibility. I use Splunk Enterprise Security for visibility specifically for the IR team for cybersecurity incidents. Splunk Enterprise Security helps my incident response team detect and manage cybersecurity incidents by being the only tool they use for finding incidents.
Technical Lead at a tech services company with 11-50 employees
Real User
Top 5
Sep 15, 2026
My main use case for Splunk Enterprise Security is for detections. A specific example of how I use Splunk Enterprise Security for detections involves VPN use cases, where we deal with clients who have numerous third-party vendors supported on VPN, leading to scenarios where users might share their VPN credentials, allowing access from disparate geographical locations. Splunk Enterprise Security is particularly effective at detecting these logins from different locations over a short period and alerting on these events, indicating users who are sharing their credentials. There are quite many use cases, and some are user-customizable; for instance, we might have someone wanting to know which users got SSH access to servers over working hours or who is accessing RDP outside of working hours. We usually cover traditional brute force attacks and network intrusions within the rules that we enable.
SIEM engineer at a tech vendor with 10,001+ employees
Real User
Top 10
Sep 15, 2026
My main use case for Splunk Enterprise Security involves knowledge object development, detection engineering, data normalization, and alerting. A specific example of how I use Splunk Enterprise Security in my day-to-day work is creating Splunk TAs to map non-normalized data to the Common Information Model.
Cybersecurity operations analyst at a tech vendor with 10,001+ employees
Real User
Top 10
Sep 15, 2026
Splunk Enterprise Security is used primarily for reviewing notables and security events as a SIEM. My daily work involves reviewing notables across our environment, such as network traffic. For example, if one of the devices from our network reaches out to an IP that has suspicious or bad credibility, it gets flagged. I investigate that communication to understand why it is reaching out to that malicious IP and determine if it is something actionable or if it was blocked by the firewall. I review the logs and use Splunk Enterprise Security to conduct our incident response.
System administrator at a computer software company with 201-500 employees
Real User
Top 20
Sep 15, 2026
My main use case for Splunk Enterprise Security is log analytics. I use Splunk Enterprise Security for log analytics in my day-to-day work by checking for failed logins from specific users, whether or not they're a known user or an unknown user, and seeing if this is abnormal behavior or someone who just forgot their password. We also use Splunk Enterprise Security for tracking vulnerabilities and mitigations.
Defense Analyst at a tech vendor with 10,001+ employees
Real User
Top 20
Sep 15, 2026
My main use case for Splunk Enterprise Security is RBA for Risk-Based Analysis Scores. I am currently working through activating intermediate findings from our ESCU content as we just switched from risk-based or risk rules to intermediate findings, and we have over a thousand to go through, validate that are correct, and implement. I'm newer to that function, so my experience with handling those intermediate findings right now is limited but growing.
SOC lead at a healthcare company with 10,001+ employees
Real User
Top 10
Sep 15, 2026
My main use case for Splunk Enterprise Security is risk-based alerts. I have a lot of scenarios, custom scenarios that add risk to a user. When it hits a certain unacceptable limit, we trigger the alert. There are many of these specific risk-based alerts.
IT Security Officer at a government with 10,001+ employees
Real User
Top 10
Sep 15, 2026
I have been using Splunk Enterprise Security for five years. My main use case for Splunk Enterprise Security is reports and dashboards. I use reports and dashboards to show vulnerability information. It helps my day-to-day work or decision-making by speeding up decision-making and making it easier to see trends to make decisions.
SOC analyst at a government with 10,001+ employees
Real User
Top 20
Sep 15, 2026
My main use case for Splunk Enterprise Security is investigations. A specific example of how I use Splunk Enterprise Security for investigations is diving deeper into triage alerts.
SOC Analyst at a government with 10,001+ employees
Real User
Top 20
Sep 15, 2026
My main use case for Splunk Enterprise Security is log analysis and incident response.I use Splunk Enterprise Security to review logs and see additional information about traffic at the firewall, which users are associated with which IP addresses, and what devices they used. Additionally, I use it for hunting through the analyst dashboard to review quarantined email and conduct foreign travel analysis.
detection engineer at a real estate/law firm with 1,001-5,000 employees
Real User
Top 10
Sep 15, 2026
I have been using Splunk Enterprise Security for about five years. My main use case for Splunk Enterprise Security is building security alerting detections for our SOC. A quick, specific example of a detection I've built with Splunk Enterprise Security is that we detect users clicking on a malicious phishing link and alert the SOC for it. To build that detection, we used the email data model as well as the content and alerting framework that is built in Splunk Enterprise Security.
Splunk Architect at a tech consulting company with 11-50 employees
Real User
Top 10
Sep 15, 2026
My main use case for Splunk Enterprise Security involves security and analyzing things using Splunk Enterprise in a SOC, and also building searches and findings there for our clients. We utilized Splunk Enterprise Security for building new findings, and those findings are being analyzed right now by our clients, our bank client analysts, who are doing their best with Splunk Enterprise Security. I cannot share anything unique about my main use case because I am under NDA, but we are trying to implement new products from Splunk, such as adding Splunk SOAR to Splunk Enterprise Security environment. We came to this conference to learn the best ways to implement it and to take experiences from other people who might share it with us.
руководителем дирекции SOC at a financial services firm with 1,001-5,000 employees
Real User
Top 20
Sep 15, 2026
My main use case for Splunk Enterprise Security involves advising on how integration should be done, what the architectural diagram should look like, what data we should see, assigning tasks for performing gap analysis according to MITRE ATT&CK and international standards, and similar responsibilities. I used to be an analyst investigating information security incident cases, and now I'm in a more managerial position. I cannot describe a specific example in detail because it is confidential information, as I am under an NDA. However, I can say that integration with various systems was carried out, and there were moments when Splunk agents were failing for unclear reasons. In the end, we performed troubleshooting and realized that the problem was on the agent side, requiring us to update the agents. In terms of integration with various systems, I encountered no problems during the implementation of Splunk Enterprise Security.
Security manager at a tech vendor with 10,001+ employees
Real User
Top 20
Sep 15, 2026
My main use case for Splunk Enterprise Security is to review logs of our assets and interests, other data assets, and create tables for management review to make the best informed security decisions. I use Splunk Enterprise Security to make informed security decisions by reviewing current logs of any data spillages that may happen, any deficiencies that we may see with our assets, and reviewing logs monthly to ensure we remain compliant.
Threat hunter at a consultancy with 51-200 employees
Real User
Top 20
Sep 15, 2026
My main use case for Splunk Enterprise Security is cybersecurity for one of my government agency customers. In my role with my agency customer, we have alerts that come in, and junior analysts review them. As a senior analyst, I help develop new alerts and then triage ones that cannot be handled at the lower level or review ones that were handled to ensure they were done correctly.
Senior Security Engineer at a hospitality company with 201-500 employees
Real User
Top 10
Sep 15, 2026
Splunk Enterprise Security is primarily used by Mews for phishing protection, as the company deals with numerous phishing incidents and wants to protect customers, which requires obtaining the right log in for proprietary data. An instance of using Splunk Enterprise Security for phishing involves threat actors performing credential harvesting to create backdoor accounts. A more recent example is a detection that identifies a newly created user, identifies anomalous login behavior, and allows data extraction, which occurs in approximately 40 seconds, indicating an automated and sophisticated attack. Risk scoring and risk-based analysis are also important, as different scores from the alerting help determine true positives and false positives.
Vulnerability Management Analyst at a energy/utilities company with 1,001-5,000 employees
Real User
Top 20
Sep 15, 2026
My main use case for Splunk Enterprise Security is searching and log aggregation. I use Splunk Enterprise Security for searching and log aggregation in my daily work by investigating alerts that come across through our SIEM. I engage in manual digging through logs, searching based off of alert criteria.
I have been using Splunk Enterprise Security for about seven years. My main use case for Splunk Enterprise Security is building dashboards, monitoring our data centers that we have built, using containerization to build dashboards, looking for anomalies, and testing for cybersecurity issues in real time. A specific example of how I have used Splunk Enterprise Security is during a recent exercise for the students where they simulate a DDoS attack in AWS, observe what they are seeing, check the problem in the logs, and then troubleshoot and fix the problem from there. I use Splunk mostly for teaching, but of course, to monitor our data center environments as well. I do this to teach young people Splunk, and our students have grasped the concept very well, going from not knowing what Splunk was to building high-quality dashboards that I referred to earlier.
Detection Engineer at a tech vendor with 10,001+ employees
Real User
Top 20
Sep 13, 2026
My main use case for Splunk Enterprise Security is developing use cases. A specific use case I have developed with Splunk Enterprise Security is click fix detections. To develop those click fix detections in Splunk, I first look up whether there are any applicable detections in Splunk Enterprise Security content updates and if there are some viable detections, I use them. I have a big challenge with my main use case since I administrate five different instances and do not have access to detection as code, so it would be helpful to find a way where you can administrate multiple instances at once.
Splunk Enterprise Security serves as our security monitoring solution and logging solution. We are using it for threat detection and incident handling.
Senior Vice President Cyber Security at Mindsprint
Real User
Top 5
Jul 13, 2026
I work with Splunk as a service provider as well as a customer because we use Splunk internally. This is used to run the Security Operation Center to conduct 24/7 monitoring for any security alerts and incidents for our use cases and use cases for our clients. We do use some disparate security products that integrate or import data into Splunk. We have integrated Splunk with many threat intelligence sources, including external threat intelligence sources. We have a direct Splunk integration with CrowdStrike, and we have many other integrations with Splunk itself. We have integrated Splunk with many log sources, including firewalls and other devices. From those firewalls and log sources, we have configured alerting in our Splunk environment. This helps us in detecting and alerting any security incidents.
Similar to other tools available, we use Postman, Bruno, VS Code, STS (Spring Tool Suite), and Eclipse. We also use PostgreSQL and pgAdmin for PostgreSQL management, Jira, and DNS dashboard for health checks of services since we have services registered. We monitor the health of the services continuously. Additionally, we use Splunk Enterprise Security, Honeycomb, and AWS Console to check the containers and services that are registered. These tools are essential to our operations.
Splunk Engineer at a consultancy with 11-50 employees
Real User
Top 20
Jul 10, 2026
My use case for Splunk Enterprise Security involves onboarding data and then CIM complying and normalizing fields. We are also using the data models mapping and the add-on configuration. We also have some correlation searches which are running using the data models. Using that, we have some dashboards that give us useful information and ideas of what we can do.
I'm currently working on Splunk Enterprise Security. I have been working with Splunk for almost seven years. I work in the banking sector for American Express, where we track all event logs closely. We also track security events and monitor each and every transaction. The fundamentals for which we use Splunk Enterprise Security include tracking each and every event that a customer makes when using their credit cards or their cards.
MDR Analyst at a consultancy with 501-1,000 employees
Real User
Top 10
Jun 22, 2026
Splunk Enterprise Security has been used by my company for the past four to five years. I have been with the company for about a year, so I have approximately one year of experience with Splunk Enterprise Security. Splunk Enterprise Security has various complex use cases. In our environment, the most common use case is SIEM, which stands for security information and event management. This involves security monitoring, including various attacks monitoring and logs coming from firewalls and other devices. We monitor all the devices and networks as well, which is a very effective use case for Splunk Enterprise Security. Another important use case is threat hunting. Since SIEM has all the logs from all the devices, it makes threat hunting very easy and helps us find the source of all attacks or potential attack attempts.
Our main use cases for Splunk Enterprise Security are to find the root cause of any applications, to see the dashboards, to see the logs, and to centralize some logging systems.
Security Analyst at a tech vendor with 10,001+ employees
Real User
Top 20
Jun 16, 2026
During the initial two years, I was an incident response analyst who used Splunk Enterprise Security as a SIEM tool, and in the recent two years, I work as an admin who handles the integration part, content management part, and the detection response engineering. We use disparate security solutions with additional IDS, IPS, and EDR tools integrated into Splunk Enterprise Security for single-handled monitoring for the analyst's ease. We do not need to go to each tool separately; instead, we integrate all of them into the Splunk Enterprise Security interface, allowing us to monitor them via Splunk Enterprise Security. Regarding Risk-Based Alerting in Splunk Enterprise Security, we used to tag alerts while creating correlation searches in Splunk Enterprise Security. I work with both on-premise and cloud-based setups.
Senior Vice President Cyber Security at Mindsprint
Real User
Top 5
Jun 16, 2026
Splunk Enterprise Security is used for our SOC, the Security Operations Center, which provides 24/7 monitoring. I am using disparate security solutions to integrate or import data into Splunk Enterprise Security. We use Splunk Enterprise Security to ingest the logs and do the monitoring. As for alerting, especially risk-based alerting, it works well. It supports the use cases that we are looking for. Splunk Enterprise Security supports my SOC in terms of developing any new use cases. If we have any custom integration requirements or any custom use cases, we can easily develop that in Splunk Enterprise Security, and that's how we are able to leverage Splunk Enterprise Security for any custom use cases.
I have worked extensively with Splunk Enterprise Security for centralized log ingestion, security monitoring, and detection engineering. My objective is to improve enterprise visibility, reduce alert fatigue, and operationalize attack detection that is capable of identifying authentication abuse with lateral movement, PowerShell misuse, and privilege misuse in Linux environments and suspicious network activity. My recent project focused heavily on enterprise security engineering and detection engineering, IAM Governance Analysis, which is identity and access management, cloud security operation, and resilience validation. This platform aligns directly with the areas I am actively expanding deeper into. At the end of all my logs and documentation, I link them to MetaTask, ISO 27001, and SOC 2. I have a couple of frameworks I use to analyze all of these topologies. I was able to reduce unmanaged firewall exposure from over five thousand rows to eight hundred and fifty significantly. This was one of my enterprise projects I did on Zero Trust Security, all documented on my LinkedIn portfolio.
One significant deployment we executed was for an organization looking to extend and modernize their existing SIEM capabilities. Their primary objective was to strengthen their threat detection, investigation, and response posture, which had outgrown their legacy solution. As part of this engagement, they also expanded their Security Operations Center — bringing in additional skilled analysts to support the growing operational demand. The architecture we deployed centered around Splunk Enterprise Security as the core SIEM platform, which was then tightly integrated with Splunk SOAR to automate response workflows and accelerate incident handling. This combination of Splunk ES for detection and investigation, paired with Splunk SOAR for orchestration and automated response, delivered a comprehensive and cohesive end-to-end security operations capability.
The clients who are using Splunk Enterprise Security are primarily using it for security as a SIEM solution, or they are also using Splunk Observability. Generally, when you have the complete set of solutions such as EDR or DLP and then on top of it, if you have a solution such as SIEM, which is collecting logs and everything and then correlating that particular data, it takes somewhere around five to ten minutes to identify and start working on that particular issue.
I have been using Splunk Enterprise Security for the last five years, mainly building use cases for the SOC team. My role involves analyzing logs and writing vulnerability alerts based on what I observe. When security alerts are triggered, the security team receives notifications and takes appropriate action. For the initial deployment of Splunk Enterprise Security, I cannot say this is easy. It is somewhat complex because when you purchase the product, you have a lot of data. You need to align all of your data so that it fits Splunk Enterprise Security standards. Splunk Enterprise Security has custom data models and custom correlation searches that are already defined. You need to modify or set your data according to Splunk Enterprise Security standards. Once you complete this setup, the product is amazing and will do all of the work.
Observability Engineer at Data Elicit Solutions Pvt. Ltd.
Real User
Top 5
Apr 9, 2026
I primarily use it for SIEM operations including log monitoring, threat detection, and incident investigation. We collect logs from multiple sources such as firewalls, servers, and cloud platforms and use Splunk Enterprise Security to correlate events and identify suspicious activities. It acts as a centralized platform where we can monitor everything and respond to potential security incidents effectively.
At the moment, we are using Splunk ITSI (IT Service Intelligence) with Splunk Enterprise Security suite solution to create the use cases. We have criteria to create use cases in such a way that as soon as we receive a request from a customer or internally, we need to see based on the MITRE ATT&CK frameworks and techniques and tactics. Based on that, we are going to create use cases in Enterprise Security. We will consider a few things, such as what the severity is and what it is based on the group, whether it is end-user support or application support. Based on that, we will create the urgency and all.
Delivery Manager at a tech services company with 1,001-5,000 employees
Reseller
Top 5
Feb 20, 2026
The business case we use Splunk Enterprise Security for is internal security and organizational security purposes. We use it for all kinds of use cases, depending on the project.
Citius Tech at a outsourcing company with 5,001-10,000 employees
Real User
Top 5
Feb 17, 2026
Splunk Enterprise Security is primarily a security solution used for device monitoring. If there is any suspicious activity happening, Cisco will capture that and get you the alert, then your SOC team can analyze the issue and take necessary action to avoid the breach. Analysis is the first point when suggesting the best features of Splunk Enterprise Security. I think the firewall and all these network devices and security devices—routers, switches—they all need to be connected to Splunk Enterprise Security in some way, so that it can get the data from all these devices, and then SIEM can analyze that data and get us the alert. There are a few tools such as Snowflake Security Data Lake which integrates with Splunk Enterprise Security, and Splunk Enterprise Security has its own security data lake. There are multiple tools that integrate with Splunk Enterprise Security. In the context of risk-based alerting in Splunk Enterprise Security, company-wise, they have different policies, but risk-based alerting is definitely a great feature that multiple customers utilize.
Network Security Engineer at a consultancy with 10,001+ employees
Real User
Top 5
Jan 8, 2026
I deal with the Palo Alto FO and then Cortex XSIAM. I work with Cortex XSIAM and Cortex EDR products. We recently adopted Cortex XSIAM from Splunk Enterprise Security as our SIEM product for log management.I have two to three years of experience with Splunk Enterprise Security, but not continuously; this is just a tool used by me, not daily. We send logs from the firewalls to XSIAM and analyze the traffic logs to determine whether deny or allow for migration. We use both Splunk and Cortex XSIAM for log analysis. I have never dealt with Splunk support.
Risk Advisory Cyber Cloud Analyst at a consultancy with 1,001-5,000 employees
Real User
Top 10
Nov 14, 2025
I work mainly as a system integrator directly for a Splunk Enterprise Security infrastructure and log source analysis or log source integration within Splunk Enterprise Security. I also develop dashboards for monitoring purposes and use cases for alerting purposes. My focus is on SIEM, mainly in the Cloud and Cloud SIEM environments.
Splunk Enterprise Security is mainly used for enterprise defense like cybersecurity threat detection. We have SOAR and SIEM, Security Information and Event Management systems. We feed the data to them, SOAR. Enterprise security tools, that's what SIEM is. It has multiple products too, including Anvilogic, which they integrate. Definitely, it helps us to evaluate the threats, especially the risk. However, my scope is very limited to Splunk administration. I think we do use Splunk as primary. We still use the security modules, including the integration of the security modules or the multiple feeds, not only Splunk. We have Elasticsearch and other things, but Splunk is one of the major feeds for them.
Cyber Security Manager at a tech vendor with 10,001+ employees
Real User
Top 10
Sep 29, 2025
We use Splunk Enterprise Security for our security monitoring and incident management. This is our global application that we are using for security monitoring and compliance.
Assistant VP at a financial services firm with 10,001+ employees
Real User
Top 10
Sep 10, 2025
My main use cases for Splunk Enterprise Security include supporting production changes, which helps us ensure that we are not going to break the business from a DLP engineer standpoint. From an investigations and operations perspective, it allows us to look into all activities done by any individual, such as which emails they sent or what kind of data they have in their folders. We have logs coming from data at rest and data in motion channels, and all this combined is quite helpful for insider threat and data loss prevention activities. One of the use cases I leverage Splunk Enterprise Security's dashboards and visualizations for is looking into risky applications. Since we manage the web side, we look into emerging AI applications in the market. Splunk Enterprise Security provides access to logs that show which category of websites are being accessed and what those are. We can see that in a search, yet visualizations dashboards enhance this representation. Instead of writing an SPL every time, any team member can go into a dashboard, input the application name they're interested in, and access all relevant details. These are some use cases, and you can continually build your own with Splunk Enterprise Security providing the platform for those developments while limiting access to only those who need to see the information.
Incident Response Engineer at a international affairs institute with 1,001-5,000 employees
Real User
Top 20
Sep 10, 2025
My main use cases for Splunk Enterprise Security include insider threat hunting, supporting operations, and Threat Intel integration for security; I have a lot of use cases.
Information Security Analyst at a hospitality company with 5,001-10,000 employees
Real User
Top 10
Sep 10, 2025
My main use cases for Splunk Enterprise Security include finding out excessive login failures, any compromised accounts, any compromised emails using phishing tactics with Proofpoint, network anomalies, User Behavior Analysis, and detecting rogue assets.
Information Security Specialist at Ubisoft International SAS
Real User
Top 10
Sep 10, 2025
As a security analyst, my main use cases for Splunk Enterprise Security involve reviewing notables. I receive all the alerts and notables in my queue, review them, ensure they're not actual security incidents, and triage them as either true positives, false positives, and so on. I then investigate the true positives.
Principal Threat Detection Engineer at a transportation company with 10,001+ employees
Real User
Top 10
Sep 10, 2025
As a threat detection engineer, my main use case for Splunk Enterprise Security is to create content to find anomalous activity in our environment. Splunk Enterprise Security, via the content management interface, allows us to create correlation searches, take advantage of summary indexes where we can correlate multiple findings per host, per user, whatever anchor point you want to use, and get those alerts to our analysts in a timely manner, where they can be triaged based on alert severity and criticality.
IT Security Engineer at a financial services firm with 201-500 employees
Real User
Top 5
Sep 9, 2025
My main use cases for Splunk Enterprise Security are basically triage, ensuring cyber threat defence, and improving speed when defending the organization. Since I am the only one currently in the security team, we are growing this year and next, and we're expanding. Splunk Enterprise Security is improving the process to defend, basically.
IT Orchestration Architect at Penn State University
Real User
Top 5
Sep 9, 2025
My primary use cases for Splunk Enterprise Security are correlation searches and the workflow that enables our SOC analysts to work through an entire incident from start to finish.
My main use cases for Splunk Enterprise Security have evolved over various roles, primarily focusing on the correlation of external threat intelligence in the notables existing in Splunk Enterprise Security, where we currently emphasize making it easier for our customers to bring in external threat intelligence such as from Recorded Future and correlate that against their entire telemetry to create notables indicative of alerts that could have been missed through traditional defenses.
Threat Analyst at a manufacturing company with 10,001+ employees
Real User
Top 5
Sep 9, 2025
The main use cases for Splunk Enterprise Security are primarily threat detection and insight. We have more of a focus on the insider threat, and we have it as a requirement of this new media to address any type of alerts or malicious activity from a special endpoint. Now it's inside.
Security Analyst at a computer software company with 51-200 employees
Real User
Top 10
Sep 9, 2025
I use other types of security solutions that integrate or import data into Splunk Enterprise Security, such as EDRs, firewalls, and other security products. The integration supports my security operations by providing one clear view of threat detections from firewalls and imported data.
Senior Information Security Engineer at a outsourcing company with 1,001-5,000 employees
Real User
Top 10
Sep 9, 2025
My main use cases for Splunk Enterprise Security are being able to take our noisy level detections and using features such as risk-based learning that are built into Splunk Enterprise Security, and bubble them up into one larger alert, which makes it easier for us to go after and find adversaries throughout our network.
My main use cases for Splunk Enterprise Security include detection engineering tasks. I work with the SIM team handling various responsibilities, specifically ensuring uptime availability and correct log ingestion.
My main use cases for Splunk Enterprise Security are mainly building SIEM for our customers, implementing it at customer sites, and using it for our own developments.
Cybersecurity and Ethical Hacking at NUPAT TECHNOLOGIES
Real User
Top 5
Sep 5, 2025
I use Splunk Enterprise Security to analyze logs and data. When it comes to hybrid or multi-cloud, Splunk Enterprise Security has helped me find events. I use event logging and event IDs, which has helped me.
We use Splunk Enterprise Security for security monitoring purposes, and we have many security use cases configured to detect cybersecurity-related risks. We have 100+ use cases related to brute force attacks, ransomware, credential access attacks, et cetera. We use it for the extra security layer since we want to be very proactive and monitor our infrastructure fully end-to-end.
Vice President Research And Development at OSINT Ambition
Real User
Top 20
Jul 30, 2025
I work in a SOC team where I study threat hunting and threat determination. Most of my work is based on looking for malware traffic or suspicious traffic in Splunk Enterprise Security. I belong to the SOC team.
Senior Security Engineer at a comms service provider with 1,001-5,000 employees
Real User
Top 20
Jul 30, 2025
We use Splunk Enterprise Security to detect different anomalies and alerts based on our infrastructure. I work in the telecom industry. We have multiple network and security devices that collect logs. We create use cases to collect logs from all these devices.
Senior System Administrator at a tech services company with 5,001-10,000 employees
Real User
Top 20
Jul 29, 2025
I lead a team that does Splunk administration. We mainly worry about the platform itself, ensuring everything works, log sources are coming in, and assisting with searches. We have a dedicated security team that represents the user side, the consumers of that data. We try to get all the log sources in for them so they can create detections, alerts, dashboards, and their own custom app integrations. We support them as much as we can in the platform, and they do their security work based on that.
Works at a marketing services firm with 1,001-5,000 employees
Real User
Top 20
Jul 28, 2025
My use cases for Splunk Enterprise Security are extensive in production. I utilize it for all available functions including observability, asset management, vulnerability management, threat detection, network security, identity management, and various other capabilities.
When configuring our use cases and describing the overall purpose of Splunk Enterprise Security, I would focus on the main use cases that I encountered with this tool.
Cyber Security Engineer at a tech vendor with 51-200 employees
Real User
Top 10
Jul 8, 2025
I'm a technical support engineer for Cortex XDR at the moment and in my company, we are selling the Cortex XDR solution to other companies. I also have experience with Splunk Enterprise Security and CrowdStrike too; we are using those products in my company. For Splunk Enterprise Security, I am using the Enterprise Security module and base Splunk for developing rules.
Most times I use Splunk Enterprise Security for log analysis, and I also use it to create alerts for any security incidents. There are some alerts I set up on my endpoint, and once the alert is triggered, I get a notification. I also use it for visualization. I create my own dashboard to send to my managers for analysis, for reports, and all of that.
My usual use cases for Splunk Enterprise Security involve creating notables, use cases, and dashboards. We are creating the use cases as per the defense of depth in all the security layers, such as the network layer or data link layer, DLP protection, and network protection. We are using firewalls and proxy, as well as IPS, and we are using Defender as Cloud App Security of 365 and EDR. We are using Defender as a single pane of glass, collecting all the logs from all the security devices, writing the correlation rules, configuring the notables, and monitoring 360 degrees of the organization's security.
Specialist-Infrastructure Opertions at Allianz Technology
Real User
Top 10
May 20, 2025
I'm an end user, admin, and consultant. We use Splunk Enterprise Security internally in our organization, and I also use it for my personal studies. My usual use cases for Splunk Enterprise Security include monitoring several kinds of exchange server logs and Office 365 logs, among others, as we have multiple monitoring use cases based on our requirements in our environment. We were trying to solve multiple things by implementing Splunk Enterprise Security, particularly for monitoring our applications based on the insurance business, so we use Splunk Enterprise Security logs for security purposes and internal infrastructure monitoring, including logs matching security purposes in our Office 365 and exchange servers.
We have customized use cases for Splunk Enterprise Security as per our environment, due to our infrastructure related to cloud, virtualization, and a few application servers, along with Active Directory management, where we look for user interface and access management. We receive alerts related to any password breaches or unauthorized user access, or if any applications stop running. Consequently, we created multiple customized use cases, and accordingly, we receive alerts on Splunk Enterprise Security. It integrates with other tools for threat intelligence and anomaly detection. We are enjoying a good experience so far, and our admins ensure that the use cases are well-maintained. Additionally, they perform fine-tuning as needed. We have some database servers integrated for alerting us about unused services. We communicate with our database admins regarding incidents related to data management issues. We suggest actions to the database admins based on these alerts for better data management.
We use it for real-time monitoring and alerts for all instances and servers on our sub-prod instances. It helps in monitoring, getting alerts for specific errors, and identifying various logs. We also use it for log analysis, which is very beneficial. My use case is more related to production issues. Threat detection is taken care of by another team.
System Engineer - Security Presales at Raya Integration
Real User
Top 5
Dec 25, 2024
After the acquisition by Cisco, we are focusing on our partnership with them as a Gold Partner and Tier One reseller. Following the acquisition, we also shifted our focus to Splunk. I am a system integrator implementing Splunk for customers in their environments.
We primarily used Splunk Enterprise Security for data and cloud ingestion. We also leveraged it for enterprise security use case engineering, which encompassed malware analysis, threat management, detection, and the integration of threat and vulnerability intelligence, culminating in comprehensive reporting and dashboards. This was the principal use case for our SIEM platform. In recent years, we have also employed Splunk for user behaviour analytics to bolster insider threat protection. We implemented Splunk Enterprise Security to improve security monitoring, threat detection, and incident response.
Director - Application Services, DevOps(Application Support, Build/Deployment), Environment Support at a financial services firm with 10,001+ employees
Real User
Jul 1, 2024
We use Splunk Enterprise Security to track threats and errors and receive alerts and notifications. We implemented Splunk Enterprise Security to improve our troubleshooting, mean time to detect and resolve issues, and our alerting system.
IT Developer/Architect at a government with 10,001+ employees
Real User
Mar 22, 2024
We use Splunk Enterprise Security for various security use cases, including writing correlation searches. This has significantly improved both our use cases and correlation searches. We can leverage existing resources, making modifications as needed, rather than starting from scratch each time. Splunk Enterprise Security provides diverse use cases across different environments, including AWS, Azure, and multi-cloud setups, while also integrating with Microsoft Sentinel. Additionally, we can integrate Splunk's service orchestration product for further automation. Overall, this allows us to automate tasks that security analysts previously performed manually, such as reviewing incident dashboards. We can fine-tune alerts based on analyst feedback. Splunk's research team ensures that use cases are updated with the latest security content, enabling us to understand and implement necessary steps while customizing them to fit our company's needs. This is what makes Splunk Enterprise Security so popular; it streamlines processes compared to legacy security products that often rely on manual scripts. Clients, including government agencies and banks, are transitioning to Splunk Enterprise Security due to its reduced training requirements and comprehensive features. Everything is consolidated, simplifying training and certification. Additionally, integrating Splunk's service orchestration product further automates tasks and improves response times. The substantial investment in Splunk indicates its staying power; no other product on the market currently offers comparable capabilities. Cisco's acquisition of Splunk reinforces its potential for success, combining APM, data logging, and security portfolios. In one financial project involving 600,000 users, we were able to monitor all incoming traffic, identify security activities, and distinguish between legitimate and malicious traffic, including phishing attacks and potential identity-based threats. Splunk enables tracking individual identities, crucial for detecting attacks where perpetrators hide behind compromised identities, often leading to data breaches and other security incidents. We implemented Splunk Enterprise Security to assist with AWS security, which includes GuardDuty, CloudTrail, CloudWatch, and Inspector. These AWS components generate compliance and security alerts, which we correlate and use to create dashboard reports and identify security events for various use cases. We then enable the out-of-the-box use cases and send notable events to the dashboard. The implementation is currently in its early stages.
I work in the pharma industry, and I use Splunk to aggregate all my reporting logs for my firewall and Active Directory logs. We have anti-spam, web application firewalls, and other solutions to secure our perimeter. We use Splunk for log management and have a stack to transpose a log from the firewall to a VM. When we directly feed the firewall logs to Splunk, they become intermittent and freeze.
Information Security Manager at a retailer with 10,001+ employees
Real User
Top 5
May 11, 2021
Business indicators (KPIs) for specific (and limited) purpose together IT area, some tests with security build-in "use-cases" and like a correlation tool using pre-defined SPL (Search Processing Language).
We use Splunk to monitor unusual user behaviors. For example, if any user onboards from a different domain, it will trigger an alert. We also get alerts and high traffic when the ADI server is down. Splunk will monitor that behavior or when users make repeated wrong login attempts. My full-time job is managing the IAM product. Splunk is one of our security monitoring tools. Most of my work is on IAM tools like CyberArk and SailPoint, etc.
Engineer at a tech vendor with 501-1,000 employees
MSP
Jun 13, 2024
We usually use the solution for the same functionality, which includes setting up alerting and making notables. We also use it for the workflow from ingestion, alerting, and response.
Offensive Cyber Security Analyst at a agriculture with 10,001+ employees
Real User
Jun 13, 2024
We use the solution to build correlation searches around insider threats and exultation of data. We also use it for DLP (data loss prevention) and to get more visibility on what's happening in our environment that could increase risk.
Security Architect at a computer software company with 501-1,000 employees
Reseller
Jun 10, 2024
The solution is primarily for security incident investigation. Whenever a customer wants to monitor the environment for any security incident or events that are occurring, and they want to analyze the incident when virtual issues happen, that's when we propose Splunk. Otherwise, it's difficult to understand what kind of security event is arising in the environment.
My customers subscribe to many different tools, like CrowdStrike. They ingest all that into Splunk and use it as an aggregator to launch their investigations into any threats detected.
Cloud Architecture Associate Director, Infrastructure at a tech vendor with 10,001+ employees
Real User
May 8, 2024
We're using the solution for log analysis and our internal infrastructure. We may use it for customer offering at some point, but currently, it's completely internal.
We use Splunk daily to find the root cause of attacks and analyze users attempting to access our system. We create incidents and address 5 to 7 simultaneously. Once we analyze and record the activity, we can delete the incident. Our admin team will verify whether it originated externally or internally. We use Splunk to respond to security incidents and for data analytics. We conduct custom correlations for the customer and write reports on any attacks. We set alerts for user behavior to discover threats, like if someone is constantly attempting to access our internal domain. The admin will identify that threat and block it.
We typically suggest Splunk IT builds for customers with significant EPS requirements and large-scale data environments. While other solutions like Foundry and IBM QRadar may be popular, they often have limitations in handling big data effectively.
The primary focus of our work with Splunk is on security incident monitoring and security log monitoring. This involves utilizing it to analyze and respond to security events effectively. Additionally, compliance with regulatory requirements is another crucial aspect of your role. We also extend Splunk's functionality to custom applications by writing custom parsers and handling logs specific to those applications. This includes the development of unique dashboards tailored to the needs of each application.
Project manager at a computer software company with 10,001+ employees
Real User
Dec 28, 2023
We employed Splunk Enterprise Security for one of our projects. Integrating it into our environment involved opening network ports and making necessary connections.
Splunk Enterprise Security delivers powerful log management, rapid searches, and intuitive dashboards, enhancing real-time analytics and security measures. Its advanced machine learning and wide system compatibility streamline threat detection and incident response across diverse IT environments.Splunk Enterprise Security stands out in security operations with robust features like comprehensive threat intelligence and seamless data integration. Its real-time analytics and customizable queries...
I have been using Splunk Enterprise Security for over seven years, and many of my use cases include monitoring user behavior, tracking system processes that go up and down, and determining necessary actions when dealing with Windows admin endpoints. I examine CVEs and the vulnerabilities that require triaging and remediation. One of the main features and functions for my use cases with Splunk Enterprise Security involves alerts built on user activity. There are numerous ways to take data and events, correlate them, or review correlation searches to populate the necessary information across any industry and environment. Splunk Enterprise Security is a wonderful tool to have for enterprise security.
My main use case for Splunk Enterprise Security involves new detections and correlation of events. I use data points that are submitted via information-sharing communities and use those as artifacts, TTPs, and IOCs to build my own detections for behavior in my logs. Using those detections I can identify suspicious or malicious behavior.
My main use case for Splunk Enterprise Security involves log aggregation, anomaly identification, visualization of potential issues, errors, and threat modeling. I create specific reports or dashboards to measure log patterns or events that fall outside of our specific thresholds, such as user logins multiple times a day or users attempting to hit protected routes that they don't have access control for.
The main use of Splunk Enterprise Security in my organization is for threat hunting activities, digging through logs by doing statistical searches and, as a result, having the ability to get results fairly quickly so I can then chain together searches or cross-reference information. For example, I get bulletins with indicators of compromise from a vendor or an entity, a public administration in France, and then I search for the IOCs and from there, step by step, starting from that information I find, I cross it with other information to know, typically, whether the IOC that was found means that the user was compromised. Did the user go all the way, and what is the root cause of the malicious activity? I am in pre-sales, so it is mainly for demos.
My main use of Splunk Enterprise Security in my organization is to create detection rules for our clients. Notably, the detection rule that I created with this tool is the RBA rules, Risk-Based Alerting, that we have used for many clients. To implement an RBA rule with Splunk Enterprise Security, we took the templates provided by Splunk and adapted them to our needs, allowing us to detect things we were not able to detect before, such as pen tests.
My main use case for Splunk Enterprise Security is detection engineering and detection and response. A specific example of how I use Splunk Enterprise Security for detection engineering or response is detecting potential account compromise, DLP, and insider risk. Splunk Enterprise Security helps me detect those issues by enabling us to develop detection content based on threat intelligence research, and then we use the frameworks available to us in Splunk Enterprise Security to enrich those detections to provide analysts with contextual information to help them triage and respond to the alert.
My main use case for Splunk Enterprise Security is for security alerting, triage, SIEM, and incident response.We use Splunk Enterprise Security for incident response with an MSSP that will triage findings or events, and then they will escalate them up as investigations in which our analysts will then respond to them. We then take in and start doing our investigation, adding notes, and eventually closing with disposition. If the incident comes from external to Splunk, we typically just conduct the investigation through Splunk and document it externally via our IR processes.
My main use case for Splunk Enterprise Security is using the SIEM for detections. A quick specific example of what kind of detections I use Splunk Enterprise Security for includes mostly the built-in ones, with one that comes to mind being possible travel.
My main use case for Splunk Enterprise Security is reviewing incidents in the Mission Control dashboard for our clients. When an incident occurs, my analyst team and I review every incident and conduct investigations to view logs and perform formal investigations. A specific example of how I have used Splunk Enterprise Security recently is when an incident in the Analyst Queue occurs or triggers. We review every property of the incident, including the host name, the user involved, and any risk events. Meanwhile, we work in an investigation file, and for the client, we deliver this as a PDF file or a Word file. Everything that we find in the alert or in the logs, we build a timeline so that when an incident occurs, we provide the client with the scope. When we deliver an investigation, the client knows what happened, who did it, and other relevant details. I have been using the RBA framework increasingly. When an incident is happening, we review many things in this dashboard. When a host is involved, we review the most recent incidents in the risk framework, and when we review the alert, we know what was happening with this host.
My main use case for Splunk Enterprise Security is for SOC operations. I offer the SOC service to our customers, and Splunk Enterprise Security is a very powerful tool that provides all the framework and tools to correlate events, conduct investigations, and manage issues or alerts.
Splunk Enterprise Security's main use case in my organization is centralizing alerts and seeing the risk by asset. Centralizing alerts and visualizing risk by asset has helped us identify which assets are compromised and give them proper attention.
I verify users who have permissions to certain files, losing, or moving data. I use this for an overall view of the court system for our users.
I use Splunk Enterprise Security as a SIEM, and I mostly like to correlate whatever logs we see to view all the logs for the alerts. We have everything that involves the apps in the company within Splunk logs. We have identity logs, vishing, and phishing. We also have some remote access and a bunch of alerts. Splunk's capabilities give the opportunity to see everything and have a timeline on the alerts.
My main use case for Splunk Enterprise Security is detection and engineering. We are looking for all different kinds of threats with Splunk Enterprise Security and then we ingest data sources from different telemetry to look at our posture, starting from MFA to everything else. That is our main use for Splunk Enterprise Security.
My main use case for Splunk Enterprise Security is detection and SOC activities, so everything related to detection and security. Every day, I use Splunk Enterprise Security to trigger alerts and analyze the risks that are currently affecting our company.
Splunk Enterprise Security serves as my main security solution. We raise notable events and pass them to the SOAR for security purposes. When I raise notable events and pass them to the SOAR, I track insider threats and external security incidents.
Splunk Enterprise Security serves as our main security information and event management solution for our SOC. We have a setup to pull alerts for our SOC, and then we use it to work through each of the incidents we discover. We also use it to develop SOAR and utilize the SOAR piece to develop playbooks.
Our main use case for Splunk Enterprise Security is to gather all the information that we need and also create some dashboards that can help us understand what's going on in the network. For example, we would like to see if there are any failed logging attempts and, based on that, identify the systems or computers that were attempting to access resources, the time they were trying to access them, and obtain the raw data to further investigate. We also need to create alerts when problematic events occur. Additionally, when a device is not sending logs, we need to be aware of that situation. We also must be aware of any malware installed on the network and alert on that as well. We would like to have all of this information available in Dashboard Studio.
Splunk Enterprise Security serves as my main SIEM with forensics and response capabilities. I use it for threat detection, vulnerability management, and incident response for observability.
I have been using Splunk Enterprise Security for four years. My main use case for Splunk Enterprise Security is for our preparation for our SOAR deployment. I use Splunk Enterprise Security through dashboards and alerts for that.
My main use case for Splunk Enterprise Security is creating dashboards and general overall system health and maintenance. For system health or maintenance, I build dashboards for threat intelligence across the bank environment.
Splunk Enterprise Security serves as our SIEM.
Audit reviews, log analysis, and asset visibility.
My main use case for Splunk Enterprise Security is being an engineer for the SOC and insider threat risk team, where I monitor threat detection, manage the queue for a SOC, and ensure Splunk Enterprise Security data it uses is working properly. I give a quick specific example of how I use Splunk Enterprise Security in my day-to-day work by tuning detections, creating new detections, enabling any new features that come in, assessing identity, managing that, or RBA, and addressing any issues that arise that SOC analysts see, working on those with Splunk support or with the internal team.
My main use case for Splunk Enterprise Security is threat hunting.A specific example of how I use Splunk Enterprise Security for threat hunting in my organization is identifying incidents and threats. When I'm identifying incidents and threats, I use self-created dashboards in Splunk Enterprise Security.
My main use case for Splunk Enterprise Security is visibility. I use Splunk Enterprise Security for visibility specifically for the IR team for cybersecurity incidents. Splunk Enterprise Security helps my incident response team detect and manage cybersecurity incidents by being the only tool they use for finding incidents.
My main use case for Splunk Enterprise Security is network security.
My main use case for Splunk Enterprise Security is for detections. A specific example of how I use Splunk Enterprise Security for detections involves VPN use cases, where we deal with clients who have numerous third-party vendors supported on VPN, leading to scenarios where users might share their VPN credentials, allowing access from disparate geographical locations. Splunk Enterprise Security is particularly effective at detecting these logins from different locations over a short period and alerting on these events, indicating users who are sharing their credentials. There are quite many use cases, and some are user-customizable; for instance, we might have someone wanting to know which users got SSH access to servers over working hours or who is accessing RDP outside of working hours. We usually cover traditional brute force attacks and network intrusions within the rules that we enable.
My main use case for Splunk Enterprise Security involves knowledge object development, detection engineering, data normalization, and alerting. A specific example of how I use Splunk Enterprise Security in my day-to-day work is creating Splunk TAs to map non-normalized data to the Common Information Model.
Splunk Enterprise Security is used primarily for reviewing notables and security events as a SIEM. My daily work involves reviewing notables across our environment, such as network traffic. For example, if one of the devices from our network reaches out to an IP that has suspicious or bad credibility, it gets flagged. I investigate that communication to understand why it is reaching out to that malicious IP and determine if it is something actionable or if it was blocked by the firewall. I review the logs and use Splunk Enterprise Security to conduct our incident response.
My main use case for Splunk Enterprise Security is log analytics. I use Splunk Enterprise Security for log analytics in my day-to-day work by checking for failed logins from specific users, whether or not they're a known user or an unknown user, and seeing if this is abnormal behavior or someone who just forgot their password. We also use Splunk Enterprise Security for tracking vulnerabilities and mitigations.
My main use case for Splunk Enterprise Security is RBA for Risk-Based Analysis Scores. I am currently working through activating intermediate findings from our ESCU content as we just switched from risk-based or risk rules to intermediate findings, and we have over a thousand to go through, validate that are correct, and implement. I'm newer to that function, so my experience with handling those intermediate findings right now is limited but growing.
My main use case for Splunk Enterprise Security is risk-based alerts. I have a lot of scenarios, custom scenarios that add risk to a user. When it hits a certain unacceptable limit, we trigger the alert. There are many of these specific risk-based alerts.
I have been using Splunk Enterprise Security for five years. My main use case for Splunk Enterprise Security is reports and dashboards. I use reports and dashboards to show vulnerability information. It helps my day-to-day work or decision-making by speeding up decision-making and making it easier to see trends to make decisions.
My main use case for Splunk Enterprise Security is investigations. A specific example of how I use Splunk Enterprise Security for investigations is diving deeper into triage alerts.
My main use case for Splunk Enterprise Security is log analysis and incident response.I use Splunk Enterprise Security to review logs and see additional information about traffic at the firewall, which users are associated with which IP addresses, and what devices they used. Additionally, I use it for hunting through the analyst dashboard to review quarantined email and conduct foreign travel analysis.
I have been using Splunk Enterprise Security for about five years. My main use case for Splunk Enterprise Security is building security alerting detections for our SOC. A quick, specific example of a detection I've built with Splunk Enterprise Security is that we detect users clicking on a malicious phishing link and alert the SOC for it. To build that detection, we used the email data model as well as the content and alerting framework that is built in Splunk Enterprise Security.
My main use case for Splunk Enterprise Security involves security and analyzing things using Splunk Enterprise in a SOC, and also building searches and findings there for our clients. We utilized Splunk Enterprise Security for building new findings, and those findings are being analyzed right now by our clients, our bank client analysts, who are doing their best with Splunk Enterprise Security. I cannot share anything unique about my main use case because I am under NDA, but we are trying to implement new products from Splunk, such as adding Splunk SOAR to Splunk Enterprise Security environment. We came to this conference to learn the best ways to implement it and to take experiences from other people who might share it with us.
My main use case for Splunk Enterprise Security involves advising on how integration should be done, what the architectural diagram should look like, what data we should see, assigning tasks for performing gap analysis according to MITRE ATT&CK and international standards, and similar responsibilities. I used to be an analyst investigating information security incident cases, and now I'm in a more managerial position. I cannot describe a specific example in detail because it is confidential information, as I am under an NDA. However, I can say that integration with various systems was carried out, and there were moments when Splunk agents were failing for unclear reasons. In the end, we performed troubleshooting and realized that the problem was on the agent side, requiring us to update the agents. In terms of integration with various systems, I encountered no problems during the implementation of Splunk Enterprise Security.
My main use case for Splunk Enterprise Security is to review logs of our assets and interests, other data assets, and create tables for management review to make the best informed security decisions. I use Splunk Enterprise Security to make informed security decisions by reviewing current logs of any data spillages that may happen, any deficiencies that we may see with our assets, and reviewing logs monthly to ensure we remain compliant.
My main use case for Splunk Enterprise Security is cybersecurity for one of my government agency customers. In my role with my agency customer, we have alerts that come in, and junior analysts review them. As a senior analyst, I help develop new alerts and then triage ones that cannot be handled at the lower level or review ones that were handled to ensure they were done correctly.
Splunk Enterprise Security is primarily used by Mews for phishing protection, as the company deals with numerous phishing incidents and wants to protect customers, which requires obtaining the right log in for proprietary data. An instance of using Splunk Enterprise Security for phishing involves threat actors performing credential harvesting to create backdoor accounts. A more recent example is a detection that identifies a newly created user, identifies anomalous login behavior, and allows data extraction, which occurs in approximately 40 seconds, indicating an automated and sophisticated attack. Risk scoring and risk-based analysis are also important, as different scores from the alerting help determine true positives and false positives.
My main use case for Splunk Enterprise Security is searching and log aggregation. I use Splunk Enterprise Security for searching and log aggregation in my daily work by investigating alerts that come across through our SIEM. I engage in manual digging through logs, searching based off of alert criteria.
I have been using Splunk Enterprise Security for about seven years. My main use case for Splunk Enterprise Security is building dashboards, monitoring our data centers that we have built, using containerization to build dashboards, looking for anomalies, and testing for cybersecurity issues in real time. A specific example of how I have used Splunk Enterprise Security is during a recent exercise for the students where they simulate a DDoS attack in AWS, observe what they are seeing, check the problem in the logs, and then troubleshoot and fix the problem from there. I use Splunk mostly for teaching, but of course, to monitor our data center environments as well. I do this to teach young people Splunk, and our students have grasped the concept very well, going from not knowing what Splunk was to building high-quality dashboards that I referred to earlier.
My main use case for Splunk Enterprise Security is developing use cases. A specific use case I have developed with Splunk Enterprise Security is click fix detections. To develop those click fix detections in Splunk, I first look up whether there are any applicable detections in Splunk Enterprise Security content updates and if there are some viable detections, I use them. I have a big challenge with my main use case since I administrate five different instances and do not have access to detection as code, so it would be helpful to find a way where you can administrate multiple instances at once.
Splunk Enterprise Security serves as our security monitoring solution and logging solution. We are using it for threat detection and incident handling.
I work with Splunk as a service provider as well as a customer because we use Splunk internally. This is used to run the Security Operation Center to conduct 24/7 monitoring for any security alerts and incidents for our use cases and use cases for our clients. We do use some disparate security products that integrate or import data into Splunk. We have integrated Splunk with many threat intelligence sources, including external threat intelligence sources. We have a direct Splunk integration with CrowdStrike, and we have many other integrations with Splunk itself. We have integrated Splunk with many log sources, including firewalls and other devices. From those firewalls and log sources, we have configured alerting in our Splunk environment. This helps us in detecting and alerting any security incidents.
Similar to other tools available, we use Postman, Bruno, VS Code, STS (Spring Tool Suite), and Eclipse. We also use PostgreSQL and pgAdmin for PostgreSQL management, Jira, and DNS dashboard for health checks of services since we have services registered. We monitor the health of the services continuously. Additionally, we use Splunk Enterprise Security, Honeycomb, and AWS Console to check the containers and services that are registered. These tools are essential to our operations.
My use case for Splunk Enterprise Security involves onboarding data and then CIM complying and normalizing fields. We are also using the data models mapping and the add-on configuration. We also have some correlation searches which are running using the data models. Using that, we have some dashboards that give us useful information and ideas of what we can do.
I'm currently working on Splunk Enterprise Security. I have been working with Splunk for almost seven years. I work in the banking sector for American Express, where we track all event logs closely. We also track security events and monitor each and every transaction. The fundamentals for which we use Splunk Enterprise Security include tracking each and every event that a customer makes when using their credit cards or their cards.
Splunk Enterprise Security was the major use case that I had.
Splunk Enterprise Security has been used by my company for the past four to five years. I have been with the company for about a year, so I have approximately one year of experience with Splunk Enterprise Security. Splunk Enterprise Security has various complex use cases. In our environment, the most common use case is SIEM, which stands for security information and event management. This involves security monitoring, including various attacks monitoring and logs coming from firewalls and other devices. We monitor all the devices and networks as well, which is a very effective use case for Splunk Enterprise Security. Another important use case is threat hunting. Since SIEM has all the logs from all the devices, it makes threat hunting very easy and helps us find the source of all attacks or potential attack attempts.
Our main use cases for Splunk Enterprise Security are to find the root cause of any applications, to see the dashboards, to see the logs, and to centralize some logging systems.
During the initial two years, I was an incident response analyst who used Splunk Enterprise Security as a SIEM tool, and in the recent two years, I work as an admin who handles the integration part, content management part, and the detection response engineering. We use disparate security solutions with additional IDS, IPS, and EDR tools integrated into Splunk Enterprise Security for single-handled monitoring for the analyst's ease. We do not need to go to each tool separately; instead, we integrate all of them into the Splunk Enterprise Security interface, allowing us to monitor them via Splunk Enterprise Security. Regarding Risk-Based Alerting in Splunk Enterprise Security, we used to tag alerts while creating correlation searches in Splunk Enterprise Security. I work with both on-premise and cloud-based setups.
Splunk Enterprise Security is used for our SOC, the Security Operations Center, which provides 24/7 monitoring. I am using disparate security solutions to integrate or import data into Splunk Enterprise Security. We use Splunk Enterprise Security to ingest the logs and do the monitoring. As for alerting, especially risk-based alerting, it works well. It supports the use cases that we are looking for. Splunk Enterprise Security supports my SOC in terms of developing any new use cases. If we have any custom integration requirements or any custom use cases, we can easily develop that in Splunk Enterprise Security, and that's how we are able to leverage Splunk Enterprise Security for any custom use cases.
I have worked extensively with Splunk Enterprise Security for centralized log ingestion, security monitoring, and detection engineering. My objective is to improve enterprise visibility, reduce alert fatigue, and operationalize attack detection that is capable of identifying authentication abuse with lateral movement, PowerShell misuse, and privilege misuse in Linux environments and suspicious network activity. My recent project focused heavily on enterprise security engineering and detection engineering, IAM Governance Analysis, which is identity and access management, cloud security operation, and resilience validation. This platform aligns directly with the areas I am actively expanding deeper into. At the end of all my logs and documentation, I link them to MetaTask, ISO 27001, and SOC 2. I have a couple of frameworks I use to analyze all of these topologies. I was able to reduce unmanaged firewall exposure from over five thousand rows to eight hundred and fifty significantly. This was one of my enterprise projects I did on Zero Trust Security, all documented on my LinkedIn portfolio.
One significant deployment we executed was for an organization looking to extend and modernize their existing SIEM capabilities. Their primary objective was to strengthen their threat detection, investigation, and response posture, which had outgrown their legacy solution. As part of this engagement, they also expanded their Security Operations Center — bringing in additional skilled analysts to support the growing operational demand. The architecture we deployed centered around Splunk Enterprise Security as the core SIEM platform, which was then tightly integrated with Splunk SOAR to automate response workflows and accelerate incident handling. This combination of Splunk ES for detection and investigation, paired with Splunk SOAR for orchestration and automated response, delivered a comprehensive and cohesive end-to-end security operations capability.
The clients who are using Splunk Enterprise Security are primarily using it for security as a SIEM solution, or they are also using Splunk Observability. Generally, when you have the complete set of solutions such as EDR or DLP and then on top of it, if you have a solution such as SIEM, which is collecting logs and everything and then correlating that particular data, it takes somewhere around five to ten minutes to identify and start working on that particular issue.
I have been using Splunk Enterprise Security for the last five years, mainly building use cases for the SOC team. My role involves analyzing logs and writing vulnerability alerts based on what I observe. When security alerts are triggered, the security team receives notifications and takes appropriate action. For the initial deployment of Splunk Enterprise Security, I cannot say this is easy. It is somewhat complex because when you purchase the product, you have a lot of data. You need to align all of your data so that it fits Splunk Enterprise Security standards. Splunk Enterprise Security has custom data models and custom correlation searches that are already defined. You need to modify or set your data according to Splunk Enterprise Security standards. Once you complete this setup, the product is amazing and will do all of the work.
I primarily use it for SIEM operations including log monitoring, threat detection, and incident investigation. We collect logs from multiple sources such as firewalls, servers, and cloud platforms and use Splunk Enterprise Security to correlate events and identify suspicious activities. It acts as a centralized platform where we can monitor everything and respond to potential security incidents effectively.
At the moment, we are using Splunk ITSI (IT Service Intelligence) with Splunk Enterprise Security suite solution to create the use cases. We have criteria to create use cases in such a way that as soon as we receive a request from a customer or internally, we need to see based on the MITRE ATT&CK frameworks and techniques and tactics. Based on that, we are going to create use cases in Enterprise Security. We will consider a few things, such as what the severity is and what it is based on the group, whether it is end-user support or application support. Based on that, we will create the urgency and all.
The business case we use Splunk Enterprise Security for is internal security and organizational security purposes. We use it for all kinds of use cases, depending on the project.
Splunk Enterprise Security is primarily a security solution used for device monitoring. If there is any suspicious activity happening, Cisco will capture that and get you the alert, then your SOC team can analyze the issue and take necessary action to avoid the breach. Analysis is the first point when suggesting the best features of Splunk Enterprise Security. I think the firewall and all these network devices and security devices—routers, switches—they all need to be connected to Splunk Enterprise Security in some way, so that it can get the data from all these devices, and then SIEM can analyze that data and get us the alert. There are a few tools such as Snowflake Security Data Lake which integrates with Splunk Enterprise Security, and Splunk Enterprise Security has its own security data lake. There are multiple tools that integrate with Splunk Enterprise Security. In the context of risk-based alerting in Splunk Enterprise Security, company-wise, they have different policies, but risk-based alerting is definitely a great feature that multiple customers utilize.
My use cases for Splunk Enterprise Security involve both security as well as data analytics.
I deal with the Palo Alto FO and then Cortex XSIAM. I work with Cortex XSIAM and Cortex EDR products. We recently adopted Cortex XSIAM from Splunk Enterprise Security as our SIEM product for log management.I have two to three years of experience with Splunk Enterprise Security, but not continuously; this is just a tool used by me, not daily. We send logs from the firewalls to XSIAM and analyze the traffic logs to determine whether deny or allow for migration. We use both Splunk and Cortex XSIAM for log analysis. I have never dealt with Splunk support.
I work mainly as a system integrator directly for a Splunk Enterprise Security infrastructure and log source analysis or log source integration within Splunk Enterprise Security. I also develop dashboards for monitoring purposes and use cases for alerting purposes. My focus is on SIEM, mainly in the Cloud and Cloud SIEM environments.
Splunk Enterprise Security is mainly used for enterprise defense like cybersecurity threat detection. We have SOAR and SIEM, Security Information and Event Management systems. We feed the data to them, SOAR. Enterprise security tools, that's what SIEM is. It has multiple products too, including Anvilogic, which they integrate. Definitely, it helps us to evaluate the threats, especially the risk. However, my scope is very limited to Splunk administration. I think we do use Splunk as primary. We still use the security modules, including the integration of the security modules or the multiple feeds, not only Splunk. We have Elasticsearch and other things, but Splunk is one of the major feeds for them.
We use Splunk Enterprise Security for our security monitoring and incident management. This is our global application that we are using for security monitoring and compliance.
My use case for the project is thin.
My main use cases for Splunk Enterprise Security are detections and incident response.
My main use cases for Splunk Enterprise Security include supporting production changes, which helps us ensure that we are not going to break the business from a DLP engineer standpoint. From an investigations and operations perspective, it allows us to look into all activities done by any individual, such as which emails they sent or what kind of data they have in their folders. We have logs coming from data at rest and data in motion channels, and all this combined is quite helpful for insider threat and data loss prevention activities. One of the use cases I leverage Splunk Enterprise Security's dashboards and visualizations for is looking into risky applications. Since we manage the web side, we look into emerging AI applications in the market. Splunk Enterprise Security provides access to logs that show which category of websites are being accessed and what those are. We can see that in a search, yet visualizations dashboards enhance this representation. Instead of writing an SPL every time, any team member can go into a dashboard, input the application name they're interested in, and access all relevant details. These are some use cases, and you can continually build your own with Splunk Enterprise Security providing the platform for those developments while limiting access to only those who need to see the information.
My main use cases for Splunk Enterprise Security are security operation center and incident response.
My main use cases for Splunk Enterprise Security include insider threat hunting, supporting operations, and Threat Intel integration for security; I have a lot of use cases.
My main use cases for Splunk Enterprise Security are security, general security, and SIM.
My main use cases for Splunk Enterprise Security include finding out excessive login failures, any compromised accounts, any compromised emails using phishing tactics with Proofpoint, network anomalies, User Behavior Analysis, and detecting rogue assets.
My main use cases for Splunk Enterprise Security are detection, attacks, analysis, and investigation.
My main use cases for Splunk Enterprise Security are event correlation and risk-based alerting.
My main use cases for Splunk Enterprise Security are insider threat, application security, incident response, and risk forecasting.
As a security analyst, my main use cases for Splunk Enterprise Security involve reviewing notables. I receive all the alerts and notables in my queue, review them, ensure they're not actual security incidents, and triage them as either true positives, false positives, and so on. I then investigate the true positives.
My main use cases for Splunk Enterprise Security are threat alerts.
Our main use cases for Splunk Enterprise Security include security, detection, and incident response.
My main use case for Splunk Enterprise Security is security eventing.
My main use cases for Splunk Enterprise Security include extensive security operations.
As a threat detection engineer, my main use case for Splunk Enterprise Security is to create content to find anomalous activity in our environment. Splunk Enterprise Security, via the content management interface, allows us to create correlation searches, take advantage of summary indexes where we can correlate multiple findings per host, per user, whatever anchor point you want to use, and get those alerts to our analysts in a timely manner, where they can be triaged based on alert severity and criticality.
My main use cases for Splunk Enterprise Security are responding to alerts, looking for logs, and for investigations.
Splunk Enterprise Security by our SOC organization to aggregate and triage alerts used to identify IOCs.
Many of my use cases for Splunk Enterprise Security involve integrating with our networks and systems to troubleshoot and streamline our capabilities.
My main use cases for Splunk Enterprise Security are basically triage, ensuring cyber threat defence, and improving speed when defending the organization. Since I am the only one currently in the security team, we are growing this year and next, and we're expanding. Splunk Enterprise Security is improving the process to defend, basically.
My primary use cases for Splunk Enterprise Security are correlation searches and the workflow that enables our SOC analysts to work through an entire incident from start to finish.
My main use cases for Splunk Enterprise Security are detections and security.
My main use cases for Splunk Enterprise Security have evolved over various roles, primarily focusing on the correlation of external threat intelligence in the notables existing in Splunk Enterprise Security, where we currently emphasize making it easier for our customers to bring in external threat intelligence such as from Recorded Future and correlate that against their entire telemetry to create notables indicative of alerts that could have been missed through traditional defenses.
My main use cases for Splunk Enterprise Security are log management and enterprise security. Those are the key.
The main use cases for Splunk Enterprise Security are primarily threat detection and insight. We have more of a focus on the insider threat, and we have it as a requirement of this new media to address any type of alerts or malicious activity from a special endpoint. Now it's inside.
I use other types of security solutions that integrate or import data into Splunk Enterprise Security, such as EDRs, firewalls, and other security products. The integration supports my security operations by providing one clear view of threat detections from firewalls and imported data.
My main use case for this solution is to detect threats.
My main use cases for Splunk Enterprise Security are mostly for SOC, detection engineering, and incident response.
My main use cases for Splunk Enterprise Security are detection and investigation.
My main use cases for Splunk Enterprise Security are threat detection use cases.
My main use cases for Splunk Enterprise Security are being able to take our noisy level detections and using features such as risk-based learning that are built into Splunk Enterprise Security, and bubble them up into one larger alert, which makes it easier for us to go after and find adversaries throughout our network.
My main use case for Splunk Enterprise Security is getting observability and insights in order to meet compliance objectives.
My main use case for Splunk Enterprise Security is incident response.
My main use cases for Splunk Enterprise Security are cloud-based use cases.
My main use cases for Splunk Enterprise Security include cybersecurity threat, incident response, and security events.
My main use cases for Splunk Enterprise Security include detection engineering tasks. I work with the SIM team handling various responsibilities, specifically ensuring uptime availability and correct log ingestion.
My main use case for Splunk Enterprise Security is web uploads.
My main use cases for Splunk Enterprise Security are mainly building SIEM for our customers, implementing it at customer sites, and using it for our own developments.
I use Splunk Enterprise Security to analyze logs and data. When it comes to hybrid or multi-cloud, Splunk Enterprise Security has helped me find events. I use event logging and event IDs, which has helped me.
We use Splunk Enterprise Security for security monitoring purposes, and we have many security use cases configured to detect cybersecurity-related risks. We have 100+ use cases related to brute force attacks, ransomware, credential access attacks, et cetera. We use it for the extra security layer since we want to be very proactive and monitor our infrastructure fully end-to-end.
I work in a SOC team where I study threat hunting and threat determination. Most of my work is based on looking for malware traffic or suspicious traffic in Splunk Enterprise Security. I belong to the SOC team.
We use Splunk Enterprise Security to detect different anomalies and alerts based on our infrastructure. I work in the telecom industry. We have multiple network and security devices that collect logs. We create use cases to collect logs from all these devices.
I lead a team that does Splunk administration. We mainly worry about the platform itself, ensuring everything works, log sources are coming in, and assisting with searches. We have a dedicated security team that represents the user side, the consumers of that data. We try to get all the log sources in for them so they can create detections, alerts, dashboards, and their own custom app integrations. We support them as much as we can in the platform, and they do their security work based on that.
My use cases for Splunk Enterprise Security are extensive in production. I utilize it for all available functions including observability, asset management, vulnerability management, threat detection, network security, identity management, and various other capabilities.
When configuring our use cases and describing the overall purpose of Splunk Enterprise Security, I would focus on the main use cases that I encountered with this tool.
I'm a technical support engineer for Cortex XDR at the moment and in my company, we are selling the Cortex XDR solution to other companies. I also have experience with Splunk Enterprise Security and CrowdStrike too; we are using those products in my company. For Splunk Enterprise Security, I am using the Enterprise Security module and base Splunk for developing rules.
Most times I use Splunk Enterprise Security for log analysis, and I also use it to create alerts for any security incidents. There are some alerts I set up on my endpoint, and once the alert is triggered, I get a notification. I also use it for visualization. I create my own dashboard to send to my managers for analysis, for reports, and all of that.
My usual use cases for Splunk Enterprise Security include normal reporting.
My usual use cases for Splunk Enterprise Security involve creating notables, use cases, and dashboards. We are creating the use cases as per the defense of depth in all the security layers, such as the network layer or data link layer, DLP protection, and network protection. We are using firewalls and proxy, as well as IPS, and we are using Defender as Cloud App Security of 365 and EDR. We are using Defender as a single pane of glass, collecting all the logs from all the security devices, writing the correlation rules, configuring the notables, and monitoring 360 degrees of the organization's security.
I'm an end user, admin, and consultant. We use Splunk Enterprise Security internally in our organization, and I also use it for my personal studies. My usual use cases for Splunk Enterprise Security include monitoring several kinds of exchange server logs and Office 365 logs, among others, as we have multiple monitoring use cases based on our requirements in our environment. We were trying to solve multiple things by implementing Splunk Enterprise Security, particularly for monitoring our applications based on the insurance business, so we use Splunk Enterprise Security logs for security purposes and internal infrastructure monitoring, including logs matching security purposes in our Office 365 and exchange servers.
We have customized use cases for Splunk Enterprise Security as per our environment, due to our infrastructure related to cloud, virtualization, and a few application servers, along with Active Directory management, where we look for user interface and access management. We receive alerts related to any password breaches or unauthorized user access, or if any applications stop running. Consequently, we created multiple customized use cases, and accordingly, we receive alerts on Splunk Enterprise Security. It integrates with other tools for threat intelligence and anomaly detection. We are enjoying a good experience so far, and our admins ensure that the use cases are well-maintained. Additionally, they perform fine-tuning as needed. We have some database servers integrated for alerting us about unused services. We communicate with our database admins regarding incidents related to data management issues. We suggest actions to the database admins based on these alerts for better data management.
We use it for real-time monitoring and alerts for all instances and servers on our sub-prod instances. It helps in monitoring, getting alerts for specific errors, and identifying various logs. We also use it for log analysis, which is very beneficial. My use case is more related to production issues. Threat detection is taken care of by another team.
After the acquisition by Cisco, we are focusing on our partnership with them as a Gold Partner and Tier One reseller. Following the acquisition, we also shifted our focus to Splunk. I am a system integrator implementing Splunk for customers in their environments.
We primarily used Splunk Enterprise Security for data and cloud ingestion. We also leveraged it for enterprise security use case engineering, which encompassed malware analysis, threat management, detection, and the integration of threat and vulnerability intelligence, culminating in comprehensive reporting and dashboards. This was the principal use case for our SIEM platform. In recent years, we have also employed Splunk for user behaviour analytics to bolster insider threat protection. We implemented Splunk Enterprise Security to improve security monitoring, threat detection, and incident response.
We are an MSSP, and some of our customers have Splunk Enterprise Security, and we run it for them.
We use Splunk Enterprise Security to track threats and errors and receive alerts and notifications. We implemented Splunk Enterprise Security to improve our troubleshooting, mean time to detect and resolve issues, and our alerting system.
We use Splunk Enterprise Security for various security use cases, including writing correlation searches. This has significantly improved both our use cases and correlation searches. We can leverage existing resources, making modifications as needed, rather than starting from scratch each time. Splunk Enterprise Security provides diverse use cases across different environments, including AWS, Azure, and multi-cloud setups, while also integrating with Microsoft Sentinel. Additionally, we can integrate Splunk's service orchestration product for further automation. Overall, this allows us to automate tasks that security analysts previously performed manually, such as reviewing incident dashboards. We can fine-tune alerts based on analyst feedback. Splunk's research team ensures that use cases are updated with the latest security content, enabling us to understand and implement necessary steps while customizing them to fit our company's needs. This is what makes Splunk Enterprise Security so popular; it streamlines processes compared to legacy security products that often rely on manual scripts. Clients, including government agencies and banks, are transitioning to Splunk Enterprise Security due to its reduced training requirements and comprehensive features. Everything is consolidated, simplifying training and certification. Additionally, integrating Splunk's service orchestration product further automates tasks and improves response times. The substantial investment in Splunk indicates its staying power; no other product on the market currently offers comparable capabilities. Cisco's acquisition of Splunk reinforces its potential for success, combining APM, data logging, and security portfolios. In one financial project involving 600,000 users, we were able to monitor all incoming traffic, identify security activities, and distinguish between legitimate and malicious traffic, including phishing attacks and potential identity-based threats. Splunk enables tracking individual identities, crucial for detecting attacks where perpetrators hide behind compromised identities, often leading to data breaches and other security incidents. We implemented Splunk Enterprise Security to assist with AWS security, which includes GuardDuty, CloudTrail, CloudWatch, and Inspector. These AWS components generate compliance and security alerts, which we correlate and use to create dashboard reports and identify security events for various use cases. We then enable the out-of-the-box use cases and send notable events to the dashboard. The implementation is currently in its early stages.
I work in the pharma industry, and I use Splunk to aggregate all my reporting logs for my firewall and Active Directory logs. We have anti-spam, web application firewalls, and other solutions to secure our perimeter. We use Splunk for log management and have a stack to transpose a log from the firewall to a VM. When we directly feed the firewall logs to Splunk, they become intermittent and freeze.
Business indicators (KPIs) for specific (and limited) purpose together IT area, some tests with security build-in "use-cases" and like a correlation tool using pre-defined SPL (Search Processing Language).
#1 is InfoSec
#2 is BI
#3 is IoT
I use Splunk Enterprise Security for threat hunting.
We use Splunk to monitor unusual user behaviors. For example, if any user onboards from a different domain, it will trigger an alert. We also get alerts and high traffic when the ADI server is down. Splunk will monitor that behavior or when users make repeated wrong login attempts. My full-time job is managing the IAM product. Splunk is one of our security monitoring tools. Most of my work is on IAM tools like CyberArk and SailPoint, etc.
We usually use the solution for the same functionality, which includes setting up alerting and making notables. We also use it for the workflow from ingestion, alerting, and response.
We use Splunk Enterprise Security for insider risk and security operations centers.
We use the solution to build correlation searches around insider threats and exultation of data. We also use it for DLP (data loss prevention) and to get more visibility on what's happening in our environment that could increase risk.
We use the solution for monitoring and detection and for threat hunting.
We wanted the solution to enhance the SOC ability. We were having trouble with some of our data being SIEM-compliant.
We develop use cases for Splunk Enterprise Security all the time. I mostly work with the SOAR platform to ingest those use cases.
Generally, we leverage it to correlate all of our threat intelligence data with all of our log events to make researching them simpler.
We use the solution to find systems acting strange or having strange services and security attacks.
The solution is primarily for security incident investigation. Whenever a customer wants to monitor the environment for any security incident or events that are occurring, and they want to analyze the incident when virtual issues happen, that's when we propose Splunk. Otherwise, it's difficult to understand what kind of security event is arising in the environment.
My customers subscribe to many different tools, like CrowdStrike. They ingest all that into Splunk and use it as an aggregator to launch their investigations into any threats detected.
We use Splunk Enterprise Security to monitor the network. We use the solution wherever there's a problem with the cell phone tower.
We're using the solution for log analysis and our internal infrastructure. We may use it for customer offering at some point, but currently, it's completely internal.
We are using Splunk Enterprise Security for collecting and analyzing logs. We are keeping up with the SLAs with Splunk Enterprise Security.
The solution is used to detect and protect against threats using a hypervisor infrastructure that works with artificial intelligence.
We use Splunk daily to find the root cause of attacks and analyze users attempting to access our system. We create incidents and address 5 to 7 simultaneously. Once we analyze and record the activity, we can delete the incident. Our admin team will verify whether it originated externally or internally. We use Splunk to respond to security incidents and for data analytics. We conduct custom correlations for the customer and write reports on any attacks. We set alerts for user behavior to discover threats, like if someone is constantly attempting to access our internal domain. The admin will identify that threat and block it.
There are many use cases. Most of the use cases are related to security, data integration, and data sources.
We use Splunk Enterprise Security to monitor our network environment for abnormal activities and threats.
We typically suggest Splunk IT builds for customers with significant EPS requirements and large-scale data environments. While other solutions like Foundry and IBM QRadar may be popular, they often have limitations in handling big data effectively.
The primary focus of our work with Splunk is on security incident monitoring and security log monitoring. This involves utilizing it to analyze and respond to security events effectively. Additionally, compliance with regulatory requirements is another crucial aspect of your role. We also extend Splunk's functionality to custom applications by writing custom parsers and handling logs specific to those applications. This includes the development of unique dashboards tailored to the needs of each application.
We employed Splunk Enterprise Security for one of our projects. Integrating it into our environment involved opening network ports and making necessary connections.