Try our new research platform with insights from 80,000+ expert users
AKHIL Kumar Guttapalli - PeerSpot reviewer
Product Sales Specialist(Asst.Manager) at Redington India Limited
Real User
Knowledgeable support, reliable, and useful reports
Pros and Cons
  • "Splunk is stable, and this is why many customers want it."

    What is most valuable?

    The most valuable feature of Splunk is security information and event management(SIEM). Additionally, the solution is easy to use, has useful reports, and good interface.

    For how long have I used the solution?

    I have used Splunk within the past 12 months.

    What do I think about the stability of the solution?

    Splunk is stable, and this is why many customers want it.

    What do I think about the scalability of the solution?

    The scalability of Splunk is good. Customers can purchase 100 GB now and if they wanted more, they can immediately add an additional 100. The customer will have to only pay for additional licenses.

    Buyer's Guide
    Splunk Enterprise Security
    November 2024
    Learn what your peers think about Splunk Enterprise Security. Get advice and tips from experienced pros sharing their opinions. Updated: November 2024.
    823,875 professionals have used our research since 2012.

    How are customer service and support?

    I hear that customers usually have support on time from the Splunk team. Generally, they are satisfied with the response they receive from Splunk.

    How was the initial setup?

    The total time of the implementation depends upon the customer's requirement. The factors that affect the implementation time are the type of use case, the environment of deployment, one location or multiple locations, number of devices, and applications. The requirements play a large role in the time it might take for implementation. You cannot simply explain in one week or one month.

    What about the implementation team?

    There are two to three people required for the implementation of Splunk.

    What's my experience with pricing, setup cost, and licensing?

    The price of this solution is expensive. However, it has great features. If you want a great solution you need to pay a price matching the features.

    What other advice do I have?

    If this solution matches the needs of your use case then I would give it a try.

    I rate Splunk a nine out of ten.

    Which deployment model are you using for this solution?

    On-premises
    Disclosure: I am a real user, and this review is based on my own experience and opinions.
    PeerSpot user
    reviewer2170611 - PeerSpot reviewer
    Security Architect at a computer software company with 501-1,000 employees
    Reseller
    Top 5Leaderboard
    Reduces alert volumes, speeds up investigations, and handles big data well
    Pros and Cons
    • "If you want to understand how it can analyze or find out incidents, the visibility is good."
    • "We'd like to see a more seamless cloud-based integration."

    What is our primary use case?

    The solution is primarily for security incident investigation. Whenever a customer wants to monitor the environment for any security incident or events that are occurring, and they want to analyze the incident when virtual issues happen, that's when we propose Splunk. Otherwise, it's difficult to understand what kind of security event is arising in the environment.

    What is most valuable?

    The primary feature that is the most valuable is the correlation feature, which helps you analyze the data. If there's a lot of telemetry data at some point, Splunk can take advantage of it. It can handle a large volume of data. 

    Now, with big data, AI, and all those things, the amount of security data that is generated is too high. Generally, the other SIMs face trouble when handling big data. However, Splunk itself is a very strong solution for handling lots of data. It helps the SOC team analyze data very well, and it does not crash on handling a large amount. That's a key benefit.

    Our customers usually monitor multiple cloud environments. It's not very difficult. There are two ways we use Splunk. One is that they can be multiple cloud environments. The second is that it can be an on-prem and a cloud environment. We are mapping it to our one solution. 

    Splunk is very flexible and it's integratable with other solutions

    If you want to understand how it can analyze or find out incidents, the visibility is good. The best visibility would always be in the on-prem environment. Then, the cloud, since Splunk is not a native cloud solution like Microsoft's Sentinel, is used. We don't see a lot of challenges if we do a hybrid kind of setup, however.

    I'd assess Splunk's insider threat detection capabilities to help find unknown threats or anomalous user behavior at an eight out of ten. Splunk itself uses another agent or another module to do it. Splunk does the job. It's not that it will not do the job; however, it will require more refining than other solutions in the market.

    My team uses the Splunk Mission Control, topology, and attach framework features, which are really helpful. We've used it for multiple customers. We take their existing SOC or detection use cases and try to map them to the framework. From a security point of view, it obviously makes a solution more superior. With Splunk, you can catch more security incidents. From a best practice standpoint also, it is a good thing as we can configure the solution, and, according to that configuration, the entire performance is better in terms of security. 

    It's very useful for assessing malicious activities or detecting breaches. It's a robust solution. 

    We've been able to help customers detect threats faster. It might be 5% to 10% faster in some cases. And since we can analyze large volumes of data, we're not missing any particular data point or data set. That gives us an advantage.

    Splunk helps reduce alert volume. You can reduce your alert volume based on your configuration, and it's highly customizable, so it can help you reduce alerts by a lot. It's helped us improve the quality of incidents we receive. 

    It's helping customers speed up security investigations somewhat.

    It improves the resilience of a company thanks to its ability to quickly analyze data.  

    What needs improvement?

    While it's costlier than other solutions, it's highly stable. 

    The security orchestration response requires a bit of improvement. 

    We'd like to see a more seamless cloud-based integration.

    Their mobile features for iOS and Android could be improved in terms of quality of performance. 

    For how long have I used the solution?

    I've been using the solution for three and a half years. 

    What do I think about the stability of the solution?

    It's a highly stable product even for large customers with diverse environments. For companies that have huge amounts of data even, it does not crash. It's the preferred option when a lot of data is involved. It offers good resilience and improves performance. 

    What do I think about the scalability of the solution?

    I'd rate the scalability seven out of ten since it is not cloud-native.

    How are customer service and support?

    Technical support is good. We purchase premium support services.

    How would you rate customer service and support?

    Positive

    How was the initial setup?

    I was not involved in the initial setup of the solution. 

    The solution is deployed wherever your appliance is. You deploy it where your software team wants to monitor from. Typically, that's headquarters or a company's security center. Splunk then has agents that help devices connect across geographies. For example, while Splunk may be primarily in the UK, it can cover devices via agents across Europe, and the agents can monitor other environments.

    We have between two to five people who handle maintenance activities, depending on the client. 

    What other advice do I have?

    There is a threat intelligence management feature. However, customers don't use it in our case. Typically, customers want something superior in that nature.

    Price is a major concern for most customers, big or small. However, price should not be the determining factor when seeking a solution. Users need to think about performance and quality. They need something that will help them prevent security incidents, and they need a product that will be stable. If you can monitor your environment better, you can prevent incidents that may lead to financial loss - and when incidents happen, companies can spend far more dealing with an extended phishing attack than they would on a service like Splunk that will protect them effectively. When it comes to security, while it's not necessary to have the most expensive solution on the market, you should at least seek out a solution that's best suited to your company and its needs.

    I'd rate the solution eight out of ten. It's a great option for enterprise-level companies. However, a smaller customer with a smaller budget may not be a good match. They may not need such a powerful solution in any case. That said, if a customer is about to grow a lot, I might suggest Splunk as a primary option. I'd advise potential users to look at the environment size and complexity, consider the budget, and then decide if Splunk makes sense. 

    Which deployment model are you using for this solution?

    Hybrid Cloud

    If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

    Microsoft Azure
    Disclosure: My company has a business relationship with this vendor other than being a customer: reseller
    Flag as inappropriate
    PeerSpot user
    Buyer's Guide
    Splunk Enterprise Security
    November 2024
    Learn what your peers think about Splunk Enterprise Security. Get advice and tips from experienced pros sharing their opinions. Updated: November 2024.
    823,875 professionals have used our research since 2012.
    reviewer2398662 - PeerSpot reviewer
    CTO at a computer software company with 11-50 employees
    Real User
    Top 20
    Reduces alert volume and remediation time, but pricing and learning curve for ML should be better
    Pros and Cons
    • "We can extract the metrics we want on the dashboards. We are able to react to the incidents."
    • "There is a learning curve in order to start using machine learning. We have been trying to do it for three years, and we have not managed anything. It is too complex."

    What is our primary use case?

    We are using Splunk Enterprise Security for collecting and analyzing logs. We are keeping up with the SLAs with Splunk Enterprise Security.

    How has it helped my organization?

    Splunk Enterprise Security has helped reduce our alert volume. There is about 30% reduction.

    Splunk Enterprise Security improves our organization’s ability to ingest and normalize data, but it requires lots of effort from our side. Splunk Enterprise Security can do that, but we also need to put effort into it. It is good enough to achieve that.

    Splunk Enterprise Security has helped reduce our mean time to resolve. We have seen a reduction because doing this manually through queries is crazy. It helps to find out the root cause and things like that. It is helpful. 

    We have an on-prem environment. Our information security team is using the data security features. Its security features are satisfactory.

    What is most valuable?

    It is pretty good. We can extract the metrics we want on the dashboards. We are able to react to the incidents. We are also able to monitor the service. In addition to the incident response, we can also do investigations, fraud detection, and other things like that.

    What needs improvement?

    We have this issue of data versus pricing. Its pricing can be better. There should also be a more flexible licensing model.

    There is a learning curve in order to start using machine learning. We have been trying to do it for three years, and we have not managed anything. It is too complex.

    Its ability to identify and solve problems in real-time could be better. We would like to have pattern recognition. There should be some kind of pre-made model to help detect something. For example, at the time of the incident investigation, there should be an option to ask questions, such as if anything changed. It is pretty hard to find out the patterns that are occurring currently because you have to have deep knowledge about your log content. There should be an option to ask a question like, "What has changed as compared to a week ago?" We should be able to specify a time frame and compare.

    For how long have I used the solution?

    We have been using Splunk altogether for probably five years.

    What do I think about the stability of the solution?

    It has not failed over the last year. There were no failures, so it is pretty good.

    What do I think about the scalability of the solution?

    Its scalability is quite good if you are willing to invest in the new design and do the manual work. You have to deploy new servers and things like that. In terms of architecture, it is scalable.

    How are customer service and support?

    Based on the few problems that we have had, I would rate them a seven out of ten. For an issue, we did not get the answer we needed within the timeframe we were expecting. They took more time, and some IT guys were disappointed. The experience varies from case to case.

    How would you rate customer service and support?

    Neutral

    Which solution did I use previously and why did I switch?

    We were not using any similar solution previously. We were only collecting logs through open-source means. We went for Splunk Enterprise Security because we needed visibility into the logs. It was the primary requirement.

    We are also using Elasticsearch. We have two parallel systems.

    Splunk Enterprise Security is better in terms of query language and the capability to do great searches, whereas Elasticsearch has a little bit less functionality. It is more complicated for end-users to use. However, Elasticsearch is better in terms of pricing because they do not charge based on the daily ingestion amount. You can put whatever amount into the system. Elasticsearch also has lots of additional logging capabilities. It has file beats and metrics beats capabilities, so you can use it more widely. You can also get end-to-end visibility because you can make integrity checks with it. It helps with IT operations as well. They can include these capabilities in Splunk Enterprise Security.

    How was the initial setup?

    Its deployment was not very complicated. It was easy.

    The hard part comes after you have deployed it. You have to educate people to start using it and understand the relevant information in your logs. The configuration itself is pretty simple, but field extractions and tagging are complex.

    What was our ROI?

    We are just using it and doing our queries and dashboards. We have not been calculating the ROI. It has been quite easy. We invest and create our dashboards and reports. Sometimes, when a dashboard becomes too complex or too expensive, we start to think about alternatives. Other than that, we have not thought of ROI.

    What's my experience with pricing, setup cost, and licensing?

    The pricing can be better. We are already considering Elastic because Splunk is too expensive. 

    You have to pay based on per-day ingestion. There should be a more flexible model for the use cases where one day you have a huge amount, and on other days, it is quite less.

    What other advice do I have?

    Splunk Enterprise Security provides end-to-end visibility into an environment, but it is not our use case currently.

    Splunk Enterprise Security does not really provide the relevant context to help guide our investigations because, in our country, Splunk is not represented, so it is pretty hard to get the relevant information.

    Overall, I would rate Splunk Enterprise Security a seven out of ten. Its pricing is not good, and the learning curve for machine learning is not good. However, the parts that are working are working very well.

    Disclosure: I am a real user, and this review is based on my own experience and opinions.
    Flag as inappropriate
    PeerSpot user
    reviewer1339833 - PeerSpot reviewer
    Project manager at a computer software company with 10,001+ employees
    Real User
    Top 20
    Excels in providing advanced threat detection, real-time monitoring and comprehensive security analytics
    Pros and Cons
    • "The technical support is among the best in the market."

      What is our primary use case?

      We employed Splunk Enterprise Security for one of our projects. Integrating it into our environment involved opening network ports and making necessary connections.

      How has it helped my organization?

      We had the opportunity to assess visibility in various environments, including on-premises. On-premises visibility has proven to be both satisfactory and advantageous.

      What is most valuable?

      We use the threat intelligence management feature. 

      We have been considering implementing certain frameworks, such as MITRE ATT&CK or threat topology features.

      It contributes value by enhancing resilience, crucial for adopting a Security Information and Event Management solution. Site resilience is imperative for our organization, meeting a key security requirement.

      For how long have I used the solution?

      I have been working with it for three years.

      What do I think about the scalability of the solution?

      It provides good scalability capabilities.

      How are customer service and support?

      The technical support is among the best in the market. While we didn't have extensive interactions with the support team, we are satisfied with it. It offers support services locally in my country. I would rate it ten out of ten.

      How would you rate customer service and support?

      Positive

      How was the initial setup?

      The initial setup was straightforward.

      What about the implementation team?

      The integration and initial setup of Splunk were managed with the assistance of local support.

      What other advice do I have?

      Overall, I would rate it eight out of ten.

      Disclosure: I am a real user, and this review is based on my own experience and opinions.
      PeerSpot user
      reviewer2239902 - PeerSpot reviewer
      Cyber Security at a financial services firm with 5,001-10,000 employees
      Real User
      Top 20
      Integrates well, provides good visibility, and helps to identify things that can lead to a larger problem
      Pros and Cons
      • "Integration with the cloud is pretty important and good for us. We found the integration with a lot of tools, not all tools yet, valuable. It does make the transfer of data, log files, and other things easier for us."
      • "Its pricing is extremely high. There are other tools out in the market that are competitive. They do not necessarily have all the functionality, but they are competitive. The professional services we have used have been high as well in comparison to the market."

      What is our primary use case?

      At a high level, its use cases are related to security monitoring, log aggregation, and a little bit of analysis related to incidents or fraud.

      How has it helped my organization?

      Splunk Enterprise Security has created better visibility for us on the cybersecurity type of events and issues. We are still maturing, but where we have seen some growth is getting better data, knowing what data to look at, and how to understand that data.

      It has end-to-end visibility into our cloud-native environment. This is extremely important for us because of the type of business we do. We have a lot of PII data and a lot of compliance data on which we have to maintain very tight controls, so it is extremely important that we are able to put that in the cloud and monitor and watch our environment very closely.

      It has reduced our mean time to resolve, but we are still maturing. We have got a lot of maturing to do. We have got a lot of growing to do. We have also been limited on the staff to be able to get the full realization of what we can get out of it yet, so that is a place where we are continuing to grow.

      It has improved our business resilience. We have been able to identify things that could have presented a larger problem for us financially or legally through various events. We have been able to leverage the data there. We have been able to maintain that data and support that data. It does the job. It meets the needs.

      Splunk has not helped to predict problems in real time because we have not yet matured to that place, but we need to. Generally, it has been helpful, but we know that we have got a lot of growing up there. We still have not got everything identified and captured in the space we want to be able to do better analysis.

      Its ability to provide business resilience by empowering our staff is really high. Empowerment is great, but we have a resource problem, so we have not quite realized where we could be. 

      We monitor multi-cloud environments. We have three of them. It is difficult to monitor them currently with Splunk. We are living in a highly regulated stack and a very little regulated stack and the ability to get a single pane of glass for all of that is very difficult.

      What is most valuable?

      Integration with the cloud is pretty important and good for us. We found the integration with a lot of tools, not all tools yet, valuable. It does make the transfer of data, log files, and other things easier for us.

      What needs improvement?

      Its pricing is extremely high. There are other tools out in the market that are competitive. They do not necessarily have all the functionality, but they are competitive. The professional services we have used have been high as well in comparison to the market.

      In terms of scalability, it is hard to forecast where you are going. There is room to improve there.

      For how long have I used the solution?

      I have been using this solution for about five or six years.

      What do I think about the stability of the solution?

      I would rate it eight out of ten in terms of stability. Where there has been ambiguity for me is that I recently had system stability issues that were beyond my control. They were part of my solution, and I was not aware that Splunk was accountable for it. It got quickly resolved, but there was a gap there that created pain for my business.

      What do I think about the scalability of the solution?

      We have not had any issues. We also have not had any detriment, but it is hard to forecast based on where you are going from a business perspective, at least with the models and the account teams that I have been working with. There is room to improve there. 

      How are customer service and support?

      It has been a rocky road. I have been through a road where I have had limited to little engagement or support. I am on the cusp of a large turnaround, meeting with my client team and dialoguing through it. Based on the history, I would probably rate their sales support a four out of ten. Going forward, I would rate their sales support an eight out of ten. They are in the right direction. I would rate their technical support a nine out of ten.

      How would you rate customer service and support?

      Positive

      Which solution did I use previously and why did I switch?

      We have been using the same solution for five or six years. It was selected before I joined, so I do not know.

      How was the initial setup?

      I joined after it was implemented. What I am working on now is the technical depth. I am spending a lot of time with the teams there for direction strategy. Splunk has done a great job there, specifically in pulling the right resources to bear. I had executive briefings directly with executives today where we had an opportunity to talk about different components of our solutions and our stacks, and it has been very good.

      What was our ROI?

      We are in a growth state right now. We have seen an ROI, but anticipating any point in the future is a little difficult, so it is a mixed response. Our scale is not quite clearly defined to be able to put it to a metric or to tie it back to consumption use. There is a little bit of autonomy in there to over-adjust and still find that we can true-up in a better space. That has been good for us, but if you let that run away from you, then you start to get in trouble. 

      We have not seen any cost-efficiency. We have seen our usage and needs grow, so we have seen Splunk go up in cost for us. We have not quite realized any efficiencies yet. It is also indicative of our maturity model.

      What's my experience with pricing, setup cost, and licensing?

      The licensing is good, but the pricing absolutely needs some work. It is very high. One thing that they put in a contract, but they do not emphasize it enough is true-ups on usage based on the quarterly consumption. They do not follow that methodology. They let a customer use, use, and use, and then at some point, a true-up occurs, and it is a large cost. There is an opportunity to do a quarterly track type of true-ups as per the agreements out there. That would put them in a position where customers are able to plan on, forecast around, and work through volume adjustments that may occur in their environment. 

      The other place where Splunk could spend time is the scale-up and scale-down model. Scale-up is easy where you get more business, and it is easy to add more capacity, whether it is storage or SVUs, but when you need to scale down because of a change in a business, it does put customers in a position where they are locked in, and there is no way to maneuver around that. 

      Which other solutions did I evaluate?

      We do an evaluation annually. It is important for us to do a market comparison and make sure we are looking at options in our work. What makes Splunk Enterprise Security competitive is the variabilities that they bring to the table for the overall solution. It has things like APIs that you can tie into. There is also the bonus functionality of being able to do analytics there. User behavior analytics is important for us.

      What other advice do I have?

      I would rate Splunk Enterprise Security an eight out of ten.

      Disclosure: I am a real user, and this review is based on my own experience and opinions.
      PeerSpot user
      reviewer2239911 - PeerSpot reviewer
      SOAR Developer at a media company with 10,001+ employees
      Real User
      Reduces time to detect, improves uptime, and handles correlation search well
      Pros and Cons
      • "The correlation search functions that generate all the notables are valuable. That can get pretty complicated, and it handles that pretty well."
      • "Some of the search functions can be better. There has been a lot of talk at the conference about the update of SPL before each iteration. That will be a lot of help."

      What is our primary use case?

      We use it mostly to generate notables, and then we can use other tools, such as ticketing systems or other SOAR platforms, to investigate.

      How has it helped my organization?

      I was not around before we had Splunk Enterprise Security in our organization, so I do not know about the before and after, but I can tell it would be very painful to not have it. 

      It is pretty easy to monitor multiple cloud environments. All the logs from our cloud environments go to Splunk, and then we can search everything at once. It is pretty helpful.

      Splunk Enterprise Security has end-to-end visibility into our cloud-native environments. It is pretty important. Especially if you use it as your single source of truth, it is pretty invaluable that you have everything in there.

      It has reduced our mean time to detect, so inadvertently, it has also reduced our mean time to resolve. However, I do not have the metrics.

      Splunk Enterprise Security has definitely improved our organization’s business resilience. There are a lot of logs that help with monitoring and alerting and keeping the business up.

      It can help to predict, identify, and solve problems in real time. We do have some health alerts, and if they kick off, we might be able to fix something before it is really broken. In that sense, it is good.

      Splunk Enterprise Security has been pretty good in terms of providing business resilience by empowering our staff. Most of our users are security-focused, but having everybody with the ability to write their own searches or build upon what we already have for detection of the future things is pretty helpful.

      What is most valuable?

      The correlation search functions that generate all the notables are valuable. That can get pretty complicated, and it handles that pretty well.

      What needs improvement?

      Some of the search functions can be better. There has been a lot of talk at the conference about the update of SPL before each iteration. That will be a lot of help. 

      For how long have I used the solution?

      I have been using Splunk Enterprise Security for about two years.

      What do I think about the stability of the solution?

      It is pretty stable. We have not had any instances where Splunk just completely died. Its stability is good.

      What do I think about the scalability of the solution?

      It seems pretty scalable, especially considering how much data we ingest. It is a good tool.

      How are customer service and support?

      I have not interacted with them recently, but they are pretty good when I do need something from Splunk. I would rate them a ten out of ten. I have not had any issues with their support.

      How would you rate customer service and support?

      Positive

      Which solution did I use previously and why did I switch?

      We were probably using Elasticsearch.

      How was the initial setup?

      It was already implemented when I got here.

      What was our ROI?

      We have probably seen an ROI. We are in the security space, and there has definitely been improvement in uptime and the mean time to detect and respond to security alerts.

      Its time to value is pretty immediate. The more logs and the more standardization that we get into Splunk, the quicker that comes.

      What's my experience with pricing, setup cost, and licensing?

      Most people share the same thought that the ingestion rates can get pretty pricey. There is a lot of work we do to curate the data that we send to Splunk so that it is not too noisy or too expensive.

      What other advice do I have?

      Overall, I would rate Splunk Enterprise Security an eight out of ten. There are some cool things. A lot of the talks at this Splunk conference have touched on some of the gaps that Splunk is working to close, but it is a very solid tool. 

      Disclosure: I am a real user, and this review is based on my own experience and opinions.
      PeerSpot user
      reviewer2238918 - PeerSpot reviewer
      SOC Analyst at a tech services company with 10,001+ employees
      Real User
      Top 20
      Helps us to plan, know where to look, and what to look for when we have an incident
      Pros and Cons
      • "I haven't had the chance to properly sink my teeth into Enterprise Security but so far I like that they added the MITRE ATT&CK features."
      • "The training was mostly sales-focused, like how to monitor your sales. It was hard to then come back from doing the training and try to switch it to a cybersecurity focus because all the training we did was sales oriented. The basic training didn't really touch on any kind of cybersecurity use cases or anything like that. That would have been great to see in the training."

      What is our primary use case?

      Our primary use case is for cyber security, tracking logs, and incident response.

      What is most valuable?

      I haven't had the chance to properly sink my teeth into Enterprise Security but so far I like that they added the MITRE ATT&CK features. 

      This feature helps us know how to plan when we have an incident, know where to look, what to look for, and aspects like that. 

      The MITRE ATT&CK planning is valuable. When we see those incidents and those logs, having the information right there speeds up the process a bit.

      We did not have a SIEM at the time, so we added Enterprise Security as our SIEM. We're hoping to learn more about it and grow as we progress.

      What needs improvement?

      They wanted us to do basic training, which was offered to our organization for free. That was great. However, ours is a cybersecurity focus. The training was mostly sales-focused, like how to monitor your sales. It was hard to then come back from doing the training and try to switch it to a cybersecurity focus because all the training we did was sales oriented. The basic training didn't really touch on any kind of cybersecurity use cases or anything like that. That would have been great to see in the training.

      For how long have I used the solution?

      We upgraded to Enterprise Security a year ago but have been using general Splunk for longer. 

      What do I think about the stability of the solution?

      Stability-wise, despite these issues, it's been solid. I haven't had any issues with access to it or anything like that. The only issue we did have was with the engineer. After informing him of those issues, he went back and tweaked them, and then everything worked fine. 

      What do I think about the scalability of the solution?

      It seems pretty scalable. Our network isn't extremely large, so I don't think scalability will be an issue in our case, but I definitely see the opportunity to scale if needed.

      We have around 8,000 devices, so it's a fairly small network. It's across several different networks.

      How are customer service and support?

      I have not used support yet mainly because I haven't delved into it as much because of the issues with our initial integration with our engineer not being so trained. 

      Which solution did I use previously and why did I switch?

      We have different contractors and they have other solutions. Some of those solutions included Elastic. We want to use Splunk and our contractors want to use Elastic. We're hoping .conf23 will broaden our imagination, so we'll have more to bring back and push towards just using Splunk only.

      I have not used Elastic myself. It does sound like it does a lot. There's a lot that Splunk offers that we haven't actually used. I want to play with Mission Control. We only use Enterprise Security but I do want Mission Control where everything is in one centralized application where you don't have to jump to different applications. 

      I would love to get Mission Control.

      How was the initial setup?

      My engineer had a little bit of an issue with it but it was because of his own lack of training. We were pushed to hurry up and get a SIEM. He did the best he could. I let him know what wasn't working, and then he would try to fix what he could on the backend so it could work. He was in talks with Splunk to fix those issues. The results are coming back a bit better, but I think that there is still room for improvement.

      I was not involved with the setup. I came in afterward. One of our guys here was the one that was in the initial integration of Splunk. We ended up with Splunk as our main SIEM. I've never had any issues with it and I enjoyed it. 

      What was our ROI?

      We will see cost efficiencies mainly just from saving time and the shortened time and response to those incidents that we see. The fact that everything's organized in one application, we should see a bit of an increase in efficiency.

      What other advice do I have?

      I do see the possibility and the opportunity to increase the meantime to resolution by a lot. We use several different applications to monitor logs. We have the vision. 

      I've seen some of the updates and changes like Splunk AI and Splunk Vision Control that look nice. I didn't manage to get on some of the hands-on, which would have been lovely. I would like to get more ideas on how we can integrate Splunk into our networks. 

      I would rate Splunk Enterprise Security a nine out of ten. I see the opportunity and I'm hoping with our engineer that we can get to where we can make the best use of Splunk. It really seems great. A lot of our staff here were all ready to use it. We're just hoping our engineer can get to the place where we can actually make use of it. 

      The biggest value I get from attending a Splunk conference is being able to see the updates, changes, the features they're adding, the Splunk AI, and Splunk Vision Control. That's been nice. I am looking forward to some of the sessions. I want to get more ideas on how we can integrate Splunk into our networks and things like that, especially focusing on cybersecurity. I would also like to see some of the stock sessions because it's a brand new stock. We're trying to stand it up. Seeing how they're using it for stocks would be great.

      Which deployment model are you using for this solution?

      On-premises
      Disclosure: I am a real user, and this review is based on my own experience and opinions.
      PeerSpot user
      reviewer2238942 - PeerSpot reviewer
      Cloud Cybersecurity Engineer at a tech services company with 10,001+ employees
      Consultant
      Top 20
      Predicts, identifies, and solves problems in real time
      Pros and Cons
      • "The most valuable feature is the incident dashboard, and the extensive use of correlation searches, which isn't available with a standard Splunk search package. This feature is important to me because it enables SOC analysts to do their job more efficiently and be able to investigate or mediate incidents at a faster pace."
      • "A lot of people are averse to using new tools so if they make it even more user-friendly than it already is, I think that could go a long way."

      How has it helped my organization?

      Enterprise Security has reduced our mean time to detection to results. It used to take 25 to 30 minutes and now it's down to less than ten minutes. 

      Our customer has been far more satisfied with our incident response and remediation since we adopted Splunk several years ago.

      Our time to value was within a few weeks to a month.

      What is most valuable?

      The most valuable feature is the incident dashboard, and the extensive use of correlation searches, which isn't available with a standard Splunk search package. This feature is important to me because it enables SOC analysts to do their job more efficiently and be able to investigate or mediate incidents at a faster pace.

      Another benefit is the expansion of the use of ITSI, SOAR, and now Mission Control being able to holistically monitor an environment with one tool. Also with Mission Control, we have the ability to have one interface.

      It's very easy to monitor a single cloud with ES solutions. I've worked with several other SIEM tools before and Splunk does it better.

      Splunk's ability to predict, identify, and solve problems in real time is good. They do it better than other tools.

      What needs improvement?

      I am looking forward to their expansion of the use of AI. Using AI in the user interface will go a long way because one of the challenges in my organization is getting other people to use Splunk. A lot of people are averse to using new tools so if they make it even more user-friendly than it already is, I think that could go a long way.

      For how long have I used the solution?

      I have been using Splunk Enterprise Security Enterprise for three and a half years. 

      What do I think about the stability of the solution?

      Stability is excellent. It is the most stable SIEM solution I've worked with.

      What do I think about the scalability of the solution?

      Scalability is excellent. If you need to add more capacity, you can add more indexes, and more search heads as you need. The environment stays stable as you're doing it if you do it the right way. 

      My environment is about nine indexes, four search heads, and about 800 GBs a day.

      How are customer service and support?

      Their support is excellent. Every case I ever had to put in has been handled and resolved in a matter that I would hope for many support tickets.

      I would rate them a ten out of ten because they are much more responsive than a lot of other vendors I've worked with.

      How would you rate customer service and support?

      Positive

      Which solution did I use previously and why did I switch?

      There are mostly pros when comparing Splunk to its competitors because it collects data and analyzes it. It analyzes data better and in a more detailed, documented, and organized fashion than any other SIEM that I've worked with.

      I have worked with Microsoft Sentinel and ArcSight.

      How was the initial setup?

      I was involved in the initial setup with the help of their professional services. It was complex at first because my colleagues and I did not know the application that well. There was definitely a learning curve but once we started to understand how to design it the proper way and how to manage it the proper way which made things a lot easier.

      What's my experience with pricing, setup cost, and licensing?

      It's more expensive than the other tools but it's worth it. Every penny is worth it. They do analytics better. They do security investigations better. They do everything better.

      What other advice do I have?

      I would rate Splunk Enterprise Security a ten out of ten. I have worked with other SIEM solutions before and Splunk is the best one.

      The biggest value I get out of attending a Splunk conference is getting to network with other people within my same account under my same account manager. I appreciate the ability to go to sessions about different support products that my organization doesn't use and try to help myself understand how some of these tools are used and how I could encourage my organization to use them.

      Disclosure: I am a real user, and this review is based on my own experience and opinions.
      PeerSpot user
      Buyer's Guide
      Download our free Splunk Enterprise Security Report and get advice and tips from experienced pros sharing their opinions.
      Updated: November 2024
      Buyer's Guide
      Download our free Splunk Enterprise Security Report and get advice and tips from experienced pros sharing their opinions.