Operations Digital, Technology & Innovation Japac Head Of Strategic Planning at a pharma/biotech company with 10,001+ employees
Real User
Top 10
Jul 23, 2026
Splunk Enterprise Platform serves as our SIEM tool where we receive alerts and we primarily depend on it. As a centralized logging and monitoring system, we use Splunk based upon different data types. We receive data from our EDR solutions, our email, and cloud sources, so Splunk acts as a centralized point where we receive alerts from multiple sources. Day-to-day operations include Windows event loggings, such as when we get brute force alerts and similar kinds of alerts. Another example is with respect to Office 365, which is our messaging logs where if there is a need and any email forwarding rules are detected, we set a set of alerts. We also receive alerts from the cloud, GuardDuty logs, and CloudTrail logs.
Principal Siem Engineer at a tech vendor with 201-500 employees
Real User
Top 10
Jul 20, 2026
I was a partner with Splunk for around six years, and later I moved to customer projects. As part of Splunk, I worked as a professional services consultant, and later I began working with multiple customers through a different company as an independent consultant. Splunk Enterprise Platform is exceptional as a SIEM platform, with the breadth and depth built over the last 20 years. The main benefit is that it serves both core operations and security through Enterprise Security. My experience maintaining granular control over the trusted control plane within Splunk involves working with numerous log types that can be ingested, whether from custom application events, OS events, access and identity information, or security or EDR events. Regarding AI usage in RBAC, I have primarily used it for use case management and taking actions once a security notable event is generated. I have used Splunk Federated Search, which I implemented for one of my customers about a year ago. In my experience with Federated Search, I will provide some context on why it was introduced. Splunk was pushing more on Splunk Cloud platform, which is one of their SaaS-based offerings.
At my company, we use Splunk Enterprise Platform mainly for monitoring, troubleshooting, and security analysis across our IT environment and systems. We normally collect logs from different sources, such as servers, our applications, and network devices. Splunk gives us a central place where we can investigate these issues instead of checking multiple systems manually. We use Splunk Enterprise Platform mostly because it has a search processing language that we call SPL, which helps us quickly search through large volumes of data and find the information we need. For example, if I am investigating a failed login attempt by a user, I can use SPL queries to filter out authentication events, identify which accounts were affected, check source IP addresses, and understand whether this activity is normal use or a potential security concern. Last year, we started using Splunk Enterprise Platform dashboards and its data visualization features after we hired a data analyst, and these dashboards help our team see important metrics such as server health, application errors, and unusual activity patterns in real-time. Instead of going through raw logs, we can view trends through charts and reports displayed on dashboards. These dashboards have given us real-time visualization to monitor our performance because in case of an error or unusual activity, they can provide us with such information in real-time. Splunk Enterprise Platform's real-time alerting capability is very useful in our operations. We configure these alerts for specific conditions such as a high number of failed login attempts or server failures, allowing us to respond quickly before the issue impacts our business operations since we receive those alerts in real-time.
Software Developer at a financial services firm with 10,001+ employees
Real User
Top 10
Jun 30, 2026
The team I work on is a workflow team for the bank. We get a lot of traffic because of onboarding and workflow processes, which results in around a million hits per day. Whenever we have a release scheduled, Splunk Enterprise Platform is a very useful tool for me to monitor the logs.
Security Architect at a tech vendor with 10,001+ employees
MSP
Top 10
Jun 25, 2026
My main use case for Splunk Enterprise Platform is as a SIEM/SOAR. I use Splunk Enterprise Platform as a SIEM where we send all the relevant logs including firewall logs, EDR logs, authentication logs, application logs, and database logs towards Splunk, and then we write rules based on that. Day-to-day, it is mainly used as a SIEM solution to look at all the security events and write the rules.
I mainly work on log management and observability for our platforms. We use Splunk Enterprise Platform for the collection of logs and primarily for the observability of dashboards related to incident management and our application performance.
Splunk Enterprise Platform is used mainly for monitoring and troubleshooting activities, and we work with SPL to query and filter logs. We identify patterns, and then we investigate issues around different systems. Splunk Enterprise Platform is used mainly for creating dashboards, monitoring alerts, and understanding system behavior. We have a few use cases about the alerting mechanism. We ingest logs from multiple sources and multiple hosts like AWS, Kafka, and different systems, and we use Splunk Enterprise Platform as a SIEM tool. That is our main use case.
Dev Ops And Observability Admin at a tech services company with 11-50 employees
Real User
Top 5
Apr 27, 2026
I work in the data and analytics space where I deal with large data sets and system-generated logs. I use Splunk Enterprise Platform for monitoring systems. I analyze logs and create dashboards that help our technical teams. Splunk Enterprise Platform is very efficient for us. We monitor logs and troubleshoot our issues, then create dashboards for tracking system performance. We bring in logs from different systems like Windows Event logs and AWS logs, so it is highly efficient for us. It is one of the best SIEM tools. We use the Machine Learning Toolkit.
I use Splunk Enterprise Platform and Splunk Cloud for our Splunk solutions. I work with Splunk Enterprise Platform for the Enterprise, not with Enterprise Security. I use Splunk Enterprise Platform for monitoring systems, analyzing logs, and building dashboards that support our operations, visibility, and business insights. I perform log analysis, create dashboards, and set up alerts using SPL. We query large volumes of logs, identify patterns, and troubleshoot issues. I definitely use Splunk Enterprise Platform's machine learning toolkit. It helps us with predictive analytics in our organization. I have set alerts for daily ingestion using the Machine Learning toolkit in Splunk Enterprise Platform directly. I use SPL commands such as fit, apply, and score for regression and classification analysis, including yes or no category alerts. I mainly use it for anomaly detection in our company. It is very efficient for us in assessing the effectiveness of Splunk Enterprise Platform in detecting anomalies and preventing system outages. I also set alerts for daily ingestion. Overall, it is a great tool for security analysis and log monitoring, and it is one of the best tools we have been using. I have a custom add-on for forwarder management. Instead of having different instances, I made a different app for forwarder management. Anything that happens to that forwarder, I can see using that particular app and add-on SPL. That is how it helps us. I have many different custom add-ons for Splunk Enterprise Platform, and I have directly published them in Splunkbase. Even if our new employees need to see and debug what is the problem in our forwarder, that is how Splunk Enterprise Platform custom add-ons work for us. I definitely leverage Splunk Enterprise Platform for advanced threat detection. It integrates with our existing security tools by aggregating logs from multiple sources such as servers, applications, and network devices. It makes it easier to correlate events and identify suspicious patterns that would not be visible in isolated systems. I use real-time alerts for suspicious activities. I have also set alerts in our organization for users; if multiple failed login attempts occur, then we get an alert. I monitor security events in real-time through dashboards.
In terms of using Splunk Enterprise Platform, we use it for our SOC environment where we have an ES setup separately. We collect logs from various sources like AWS, EDR logs, firewall logs, WinEvent logs, Linux logs, application logs, and specific service logs. We gather that and based on that, we are providing users dashboards, searches, and alerts.
The most valuable feature I have found so far is the correlation rule. That seems to be very valuable for us. I can create any alert using the correlation rule, which seems to be interesting for me. I use Splunk Enterprise Platform for advanced threat detection with the correlation rules, nothing else. We have only very few customers, just two customers. They are not interested in those higher versions of Splunk Enterprise Platform. We rely completely on the correlation rule. We highly rely on this correlation rule.
Technical Lead at a financial services firm with 10,001+ employees
Real User
Top 10
Mar 4, 2026
I am working with Splunk Enterprise Platform, and I have worked with Enterprise and ITSI, both. Sometimes I have worked with ES also, Enterprise Security. I use Splunk Enterprise Platform mostly for log monitoring. In our company and our projects, we are monitoring for log monitoring, we are using Splunk. After that, we have created some dashboards according to our requirement and alerts and reports. Sometimes for historical data, we have created summary indexing. We are managing our Splunk Enterprise Platform infrastructure like search head, indexers, deployment server, and license master. We have 1,000, you could say 10,000+ UF. Some of them we are using with apps like Splunk DB Connect. For Kafka, we are using different add-ons for sending our data to Splunk Enterprise Platform from different log paths and log sources. That is the main use for Splunk Enterprise Platform. Mostly we are using it for log monitoring.
We have been working with Splunk Enterprise Platform for two years. Currently, we have been running Splunk in our SOC for two years, but we have not used the Machine Learning Toolkit yet. I believe it is a powerful tool, but we have not explored it.
I have implemented the complete Splunk Enterprise Platform structure in my previous organization, implementing the platform, creating use cases, dashboard queries, creating dashboards, and onboarding different devices via Syslog and API.
The use cases for Splunk Enterprise Platform ( /products/splunk-enterprise-platform-reviews ) vary depending on the specific scenario. Splunk Enterprise Platform ( /products/splunk-enterprise-platform-reviews ) has different purposes, including data visualization and other applications.
I normally use Splunk Enterprise Platform ( /products/splunk-enterprise-platform-reviews ) for review purposes. It is very easy and convenient. Its GUI is easy for me to review and approve all those things.
I focus on threat detection against stock trading systems. I am in charge of five to seven stock trading companies' B2C systems for detecting threat attacks. Our customers include several stock trading companies, banks and and large mobile careers in Japan.
We are working with AppDynamics, Splunk Enterprise Platform, and other Splunk products. However, the main use case here is with Splunk Enterprise Platform.
Our use case for Splunk Enterprise Platform involved deploying the solution for a client requirement, focusing on their data monitoring and management needs.
I use the solution in my company to capture the events to deal with threat detection, incident response, and compliance reporting. For IT operation management, it gets complex to track the health and performance of IT infrastructure, including our network devices and applications, so Splunk Enterprise Platform can be used for centralized log management.
System Engineer at a consultancy with 10,001+ employees
MSP
Jul 15, 2024
We use the solution to manage a large volume of data from our servers for the project I'm currently working on. Since we don't need all the data, we filter out and extract the specific information required for our applications. Depending on our needs, we use it to filter, investigate, and analyze log data for any errors or requirements.
We use the Splunk Enterprise Platform for logging and monitoring purposes. If users log into different databases and do something, we onboard database logs and other AWS logs to Splunk. Then, we create a dashboard alert report, and based on those dashboard alerts, we monitor users' actions. If they perform suspicious activities, we also send alerts. We use the solution to create dashboard alerts, reports, and some query language.
We monitor our airtight network traffic using the Splunk Enterprise Platform. We also use the solution for port monitoring, to monitor which ports are closed, which are open, and flapping if in any port. We use it to check our server performance to see if it gets choked because of high CPU or RAM utilization.
We have around 38 virtual machines, including the desktop. We have filled our gap network. Splunk Enterprise monitors all network layer traffic, starting with Cisco traffic port violations. We are monitoring Windows logs, CPU, RAM, and disk utilization in Windows.
We use Splunk Enterprise for data visualization. We use Splunk administration rather than Splunk development. We provide support to users so they can access our Splunk application and use it however they want. For example, if they are not able to view some of the logs that are coming from their servers in our Splunk, then we usually check all the logs here that have been missed and forward the ones that were not forwarded. Also, sometimes they use their access to install some apps. We have Splunk apps and they want us to create an app for their usage. We also need to create these apps in the Splunk application. Sometimes they aren't able to download or upload files into Splunk or other websites. They aren't able to download these reports as PDF files. We usually work on this and try to resolve it as quickly as possible.
Splunk Enterprise Platform provides high flexibility and integration, featuring strong analytics, data ingestion, and real-time monitoring, catering to diverse industry needs and enhancing threat detection and data analysis.Splunk Enterprise Platform is renowned for its powerful capabilities in log management, threat detection, and data visualization. It supports infrastructure monitoring and anomaly detection, crucial for Security Incident and Event Management operations. With its scalable...
Splunk Enterprise Platform serves as our SIEM tool where we receive alerts and we primarily depend on it. As a centralized logging and monitoring system, we use Splunk based upon different data types. We receive data from our EDR solutions, our email, and cloud sources, so Splunk acts as a centralized point where we receive alerts from multiple sources. Day-to-day operations include Windows event loggings, such as when we get brute force alerts and similar kinds of alerts. Another example is with respect to Office 365, which is our messaging logs where if there is a need and any email forwarding rules are detected, we set a set of alerts. We also receive alerts from the cloud, GuardDuty logs, and CloudTrail logs.
I was a partner with Splunk for around six years, and later I moved to customer projects. As part of Splunk, I worked as a professional services consultant, and later I began working with multiple customers through a different company as an independent consultant. Splunk Enterprise Platform is exceptional as a SIEM platform, with the breadth and depth built over the last 20 years. The main benefit is that it serves both core operations and security through Enterprise Security. My experience maintaining granular control over the trusted control plane within Splunk involves working with numerous log types that can be ingested, whether from custom application events, OS events, access and identity information, or security or EDR events. Regarding AI usage in RBAC, I have primarily used it for use case management and taking actions once a security notable event is generated. I have used Splunk Federated Search, which I implemented for one of my customers about a year ago. In my experience with Federated Search, I will provide some context on why it was introduced. Splunk was pushing more on Splunk Cloud platform, which is one of their SaaS-based offerings.
At my company, we use Splunk Enterprise Platform mainly for monitoring, troubleshooting, and security analysis across our IT environment and systems. We normally collect logs from different sources, such as servers, our applications, and network devices. Splunk gives us a central place where we can investigate these issues instead of checking multiple systems manually. We use Splunk Enterprise Platform mostly because it has a search processing language that we call SPL, which helps us quickly search through large volumes of data and find the information we need. For example, if I am investigating a failed login attempt by a user, I can use SPL queries to filter out authentication events, identify which accounts were affected, check source IP addresses, and understand whether this activity is normal use or a potential security concern. Last year, we started using Splunk Enterprise Platform dashboards and its data visualization features after we hired a data analyst, and these dashboards help our team see important metrics such as server health, application errors, and unusual activity patterns in real-time. Instead of going through raw logs, we can view trends through charts and reports displayed on dashboards. These dashboards have given us real-time visualization to monitor our performance because in case of an error or unusual activity, they can provide us with such information in real-time. Splunk Enterprise Platform's real-time alerting capability is very useful in our operations. We configure these alerts for specific conditions such as a high number of failed login attempts or server failures, allowing us to respond quickly before the issue impacts our business operations since we receive those alerts in real-time.
The team I work on is a workflow team for the bank. We get a lot of traffic because of onboarding and workflow processes, which results in around a million hits per day. Whenever we have a release scheduled, Splunk Enterprise Platform is a very useful tool for me to monitor the logs.
My main use case for Splunk Enterprise Platform is as a SIEM/SOAR. I use Splunk Enterprise Platform as a SIEM where we send all the relevant logs including firewall logs, EDR logs, authentication logs, application logs, and database logs towards Splunk, and then we write rules based on that. Day-to-day, it is mainly used as a SIEM solution to look at all the security events and write the rules.
I mainly work on log management and observability for our platforms. We use Splunk Enterprise Platform for the collection of logs and primarily for the observability of dashboards related to incident management and our application performance.
Splunk Enterprise Platform is used mainly for monitoring and troubleshooting activities, and we work with SPL to query and filter logs. We identify patterns, and then we investigate issues around different systems. Splunk Enterprise Platform is used mainly for creating dashboards, monitoring alerts, and understanding system behavior. We have a few use cases about the alerting mechanism. We ingest logs from multiple sources and multiple hosts like AWS, Kafka, and different systems, and we use Splunk Enterprise Platform as a SIEM tool. That is our main use case.
I work in the data and analytics space where I deal with large data sets and system-generated logs. I use Splunk Enterprise Platform for monitoring systems. I analyze logs and create dashboards that help our technical teams. Splunk Enterprise Platform is very efficient for us. We monitor logs and troubleshoot our issues, then create dashboards for tracking system performance. We bring in logs from different systems like Windows Event logs and AWS logs, so it is highly efficient for us. It is one of the best SIEM tools. We use the Machine Learning Toolkit.
I use Splunk Enterprise Platform and Splunk Cloud for our Splunk solutions. I work with Splunk Enterprise Platform for the Enterprise, not with Enterprise Security. I use Splunk Enterprise Platform for monitoring systems, analyzing logs, and building dashboards that support our operations, visibility, and business insights. I perform log analysis, create dashboards, and set up alerts using SPL. We query large volumes of logs, identify patterns, and troubleshoot issues. I definitely use Splunk Enterprise Platform's machine learning toolkit. It helps us with predictive analytics in our organization. I have set alerts for daily ingestion using the Machine Learning toolkit in Splunk Enterprise Platform directly. I use SPL commands such as fit, apply, and score for regression and classification analysis, including yes or no category alerts. I mainly use it for anomaly detection in our company. It is very efficient for us in assessing the effectiveness of Splunk Enterprise Platform in detecting anomalies and preventing system outages. I also set alerts for daily ingestion. Overall, it is a great tool for security analysis and log monitoring, and it is one of the best tools we have been using. I have a custom add-on for forwarder management. Instead of having different instances, I made a different app for forwarder management. Anything that happens to that forwarder, I can see using that particular app and add-on SPL. That is how it helps us. I have many different custom add-ons for Splunk Enterprise Platform, and I have directly published them in Splunkbase. Even if our new employees need to see and debug what is the problem in our forwarder, that is how Splunk Enterprise Platform custom add-ons work for us. I definitely leverage Splunk Enterprise Platform for advanced threat detection. It integrates with our existing security tools by aggregating logs from multiple sources such as servers, applications, and network devices. It makes it easier to correlate events and identify suspicious patterns that would not be visible in isolated systems. I use real-time alerts for suspicious activities. I have also set alerts in our organization for users; if multiple failed login attempts occur, then we get an alert. I monitor security events in real-time through dashboards.
In terms of using Splunk Enterprise Platform, we use it for our SOC environment where we have an ES setup separately. We collect logs from various sources like AWS, EDR logs, firewall logs, WinEvent logs, Linux logs, application logs, and specific service logs. We gather that and based on that, we are providing users dashboards, searches, and alerts.
The most valuable feature I have found so far is the correlation rule. That seems to be very valuable for us. I can create any alert using the correlation rule, which seems to be interesting for me. I use Splunk Enterprise Platform for advanced threat detection with the correlation rules, nothing else. We have only very few customers, just two customers. They are not interested in those higher versions of Splunk Enterprise Platform. We rely completely on the correlation rule. We highly rely on this correlation rule.
I am working with Splunk Enterprise Platform, and I have worked with Enterprise and ITSI, both. Sometimes I have worked with ES also, Enterprise Security. I use Splunk Enterprise Platform mostly for log monitoring. In our company and our projects, we are monitoring for log monitoring, we are using Splunk. After that, we have created some dashboards according to our requirement and alerts and reports. Sometimes for historical data, we have created summary indexing. We are managing our Splunk Enterprise Platform infrastructure like search head, indexers, deployment server, and license master. We have 1,000, you could say 10,000+ UF. Some of them we are using with apps like Splunk DB Connect. For Kafka, we are using different add-ons for sending our data to Splunk Enterprise Platform from different log paths and log sources. That is the main use for Splunk Enterprise Platform. Mostly we are using it for log monitoring.
We have been working with Splunk Enterprise Platform for two years. Currently, we have been running Splunk in our SOC for two years, but we have not used the Machine Learning Toolkit yet. I believe it is a powerful tool, but we have not explored it.
I have implemented the complete Splunk Enterprise Platform structure in my previous organization, implementing the platform, creating use cases, dashboard queries, creating dashboards, and onboarding different devices via Syslog and API.
The use cases for Splunk Enterprise Platform ( /products/splunk-enterprise-platform-reviews ) vary depending on the specific scenario. Splunk Enterprise Platform ( /products/splunk-enterprise-platform-reviews ) has different purposes, including data visualization and other applications.
I normally use Splunk Enterprise Platform ( /products/splunk-enterprise-platform-reviews ) for review purposes. It is very easy and convenient. Its GUI is easy for me to review and approve all those things.
I focus on threat detection against stock trading systems. I am in charge of five to seven stock trading companies' B2C systems for detecting threat attacks. Our customers include several stock trading companies, banks and and large mobile careers in Japan.
We are working with AppDynamics, Splunk Enterprise Platform, and other Splunk products. However, the main use case here is with Splunk Enterprise Platform.
Our use case for Splunk Enterprise Platform involved deploying the solution for a client requirement, focusing on their data monitoring and management needs.
I use the solution in my company to capture the events to deal with threat detection, incident response, and compliance reporting. For IT operation management, it gets complex to track the health and performance of IT infrastructure, including our network devices and applications, so Splunk Enterprise Platform can be used for centralized log management.
We use the solution to manage a large volume of data from our servers for the project I'm currently working on. Since we don't need all the data, we filter out and extract the specific information required for our applications. Depending on our needs, we use it to filter, investigate, and analyze log data for any errors or requirements.
We use the solution for patching.
We use the solution to monitor, alert, report, and analyze.
We use Splunk for onboarding updates, dashboards, application monitoring, and insights.
We use the Splunk Enterprise Platform for logging and monitoring purposes. If users log into different databases and do something, we onboard database logs and other AWS logs to Splunk. Then, we create a dashboard alert report, and based on those dashboard alerts, we monitor users' actions. If they perform suspicious activities, we also send alerts. We use the solution to create dashboard alerts, reports, and some query language.
I use the Enterprise platform mainly to monitor infrastructure, applications, and some security logs.
We used the product for cloud-based monitoring or systems monitoring.
We use the solution mainly for security operations. We receive logs from different log sources.
Splunk Enterprise Platform is useful as a tool for its SIEM and SOAR functionalities.
We monitor our airtight network traffic using the Splunk Enterprise Platform. We also use the solution for port monitoring, to monitor which ports are closed, which are open, and flapping if in any port. We use it to check our server performance to see if it gets choked because of high CPU or RAM utilization.
My company uses Splunk Enterprise Platform for monitoring and user base filtering.
We have around 38 virtual machines, including the desktop. We have filled our gap network. Splunk Enterprise monitors all network layer traffic, starting with Cisco traffic port violations. We are monitoring Windows logs, CPU, RAM, and disk utilization in Windows.
We use Splunk Enterprise for data visualization. We use Splunk administration rather than Splunk development. We provide support to users so they can access our Splunk application and use it however they want. For example, if they are not able to view some of the logs that are coming from their servers in our Splunk, then we usually check all the logs here that have been missed and forward the ones that were not forwarded. Also, sometimes they use their access to install some apps. We have Splunk apps and they want us to create an app for their usage. We also need to create these apps in the Splunk application. Sometimes they aren't able to download or upload files into Splunk or other websites. They aren't able to download these reports as PDF files. We usually work on this and try to resolve it as quickly as possible.