We use Splunk Enterprise Security for monitoring. We've been using it for monitoring our network. We've created some rules and use cases and we get alerts based on rules.
Security Operation Centre (SOC) Analyst at Nera Philippines Inc.
Continuous visibility with good features and fast threat detection
Pros and Cons
- "Splunk Enterprise Security helped us with faster detection of threats."
- "We'd like to have the number of devices covered under the license to be increased."
What is our primary use case?
How has it helped my organization?
It’s helpful in relation to the security perspective. With it, we can monitor all log sources and it helps us to reduce risks to our enterprise from a security perspective.
We can monitor all of our digital assets and reduce threats via constant monitoring. Using Splunk, we can mitigate malicious activities on the spot.
What is most valuable?
The solution offers a variety of good features. It has a simple user interface where we can find various options easily. The search functionality is great.
Integrations can be done easily. It’s not complex like other solutions, like Radar or Azure. Everything is easy to manage, including the low sources.
The visibility is continuous. We have different web servers, databases, routers, endpoints, et cetera, and we gain visibility from a security perspective to all of them. We can generate different types of dashboards to visualize traffic from various resources.
We can see user behavior and have access to user behavior analytics. We also are able to have some custom rules that allow us to effectively continuously monitor the activities of our users. We use a third-party solution for that.
Splunk Enterprise Security is helpful for analyzing malicious activities and detecting breaches. I can take various logs from log sources and centrally manage everything via custom rules. We have been satisfied with the capability to analyze malicious activities and detect breaches.
It helped us with faster detection of threats. If we compare it with other solutions, it is much faster. For big organizations that have their logs and terabytes, working with something like QRadar takes lots of time. Splunk is much faster.
Since the time of deployment, we've been able to use all of the features and integrate rules and use cases with threat intelligence. We've reduced false positives by 90%. Between the first and sixth months, we reduced our alert volume by 50% to 60%.
Splunk Enterprise Security helped speed up our security investigations. We now have an in-depth insight into endpoint usage. We've saved about 60% of our time if you compare Splunk to how we were operating before in terms of monitoring.
What needs improvement?
We'd like to have the number of devices covered under the license to be increased.
Buyer's Guide
Splunk Enterprise Security
December 2024
Learn what your peers think about Splunk Enterprise Security. Get advice and tips from experienced pros sharing their opinions. Updated: December 2024.
831,020 professionals have used our research since 2012.
For how long have I used the solution?
I've been using the solution for seven months.
What do I think about the stability of the solution?
I'd rate the ability eight out of ten.
What do I think about the scalability of the solution?
The solution is mostly scalable. The ability to scale is related to storage. If you want to expand storage, it can be quite difficult.
At this point, we do not have plans to increase our usage.
How are customer service and support?
I'm satisfied with the level of service technical support provides.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
Previously, I have used QRadar. My current company uses Splunk.
How was the initial setup?
I was not involved in the deployment of the solution.
There is some maintenance required. Users need to do some administration around storage and monitoring.
What's my experience with pricing, setup cost, and licensing?
I'm not sure how much the solution costs, or how much my company pays for it.
If a company needs something cheaper than Splunk, there are some open-source solutions available to them.
What other advice do I have?
The resilience of the solution is good. It's quite scalable, however, it does depend on the license. If you want more sources or logs you need to increase your license.
I'd advise users to evaluate the solution to see if it meets their personal requirements.
I would rate the solution eight out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Engineer at a government with 10,001+ employees
We can create notable events and look at the data faster, but Dashboard Studio needs to mature a bit
Pros and Cons
- "From the class that I took this week, being able to create notable events from whatever you find in the data set is pretty useful."
- "We are waiting for Dashboard Studio to mature a little bit more. There are some things that we are using with Classic Dashboards which have not yet made it to Dashboard Studio. We are waiting for that."
What is our primary use case?
We use it for a lot of compliance work and incident reviews. We are also using it for remediation and tracking assets.
How has it helped my organization?
We use Splunk not just for security, but we also collect a lot of data from our operational equipment. We are using it a lot for troubleshooting and trending and even for command and control.
It has reduced our mean time to resolve some of the things. We are able to look at the data a lot faster and see what is going on. For some of our use cases, our NOC controllers or our operators are looking at the Splunk dashboard a lot. It is a part of their main job. In one specific use case, we used to take a couple of weeks to do certain maintenance. With Splunk and having the data, we were able to reduce that to just a few hours.
It has helped improve our organization's business resilience. We are able to have the data collected in one spot, see it, and get some insights from it. That has helped a lot.
It has definitely given our technical workforce tools to help with their jobs for troubleshooting and things like that.
What is most valuable?
From the class that I took this week, being able to create notable events from whatever you find in the data set is pretty useful.
What needs improvement?
We are waiting for Dashboard Studio to mature a little bit more. There are some things that we are using with Classic Dashboards which have not yet made it to Dashboard Studio. We are waiting for that.
It seems to be limited in terms of predictive features. I took up machine learning a couple of years ago. It seems to have some capabilities there, but I do not have specific things for it right now.
For how long have I used the solution?
In our organization, we have had it for over five years, but my personal experience with it is very limited.
What do I think about the stability of the solution?
It has been working for us so far.
What do I think about the scalability of the solution?
We have been able to scale as needed.
How are customer service and support?
I have not contacted their support directly because we have folks who are pretty knowledgeable. I go to them, and then they go to their support if needed. As far as I could tell, their support has been okay. I have not heard of any issues.
Which solution did I use previously and why did I switch?
We did not have a similar product. Splunk came as a security product, and we have evolved it into doing operational work.
What about the implementation team?
We have folks who do the deployment. I am more on the interface side.
What was our ROI?
We would have seen an ROI. We are using it for a lot of our operational work and other things as well that are not related to what we are doing on a daily basis. We are looking at logs and other things that our executives are looking for.
Its time to value was within a year or so. There are a lot more things that we could do with Splunk, and that is why we ended up adding some stuff to it to fit our needs.
It is hard to tell whether we had any cost efficiencies because we did not have something like this before. Of course, we have Splunk now.
What's my experience with pricing, setup cost, and licensing?
As a team, we prefer the old pricing model with a perpetual license. We are still evaluating the whole subscription-based model.
Which other solutions did I evaluate?
We did not evaluate other solutions. Splunk came in with the modernization effort that we were going through, so it just came with the system.
What other advice do I have?
We are pretty happy with it. I would rate Splunk Enterprise Security a seven out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Buyer's Guide
Splunk Enterprise Security
December 2024
Learn what your peers think about Splunk Enterprise Security. Get advice and tips from experienced pros sharing their opinions. Updated: December 2024.
831,020 professionals have used our research since 2012.
Security delivery manager at a tech vendor with 1,001-5,000 employees
Drastically reduces SOC overhead
Pros and Cons
- "The tool drastically reduces SOC overhead. Its integration with our tool suite is great and helps us correlate events. The solution is also a lot faster than our standalone instances."
- "The solution is expensive."
What is our primary use case?
We use the solution in our SOC to support SOAR. We use its alerting capabilities and integrate them with our SOAR platform. Additionally, we tie it in with cyber threat intelligence, cyber threat hunting, and adversary emulation tools to identify gaps in our environment and alert us to notable events.
What is most valuable?
The tool drastically reduces SOC overhead. Its integration with our tool suite is great and helps us correlate events. The solution is also a lot faster than our standalone instances.
Splunk Enterprise Security helps address our customers' missions. We want to ensure that our environment is secure and safe and detects anomalies and threat actors as soon as possible.
The solution helps my organization's ability to ingest and normalize data. It has also improved resilience.
What needs improvement?
Enterprise Security is expensive.
For how long have I used the solution?
I have been working with the product for three years.
What do I think about the stability of the solution?
Splunk Enterprise Security is very stable.
What do I think about the scalability of the solution?
The tool is very scalable. We can deploy agents seamlessly and get reports.
How are customer service and support?
We have had good success with customer support. We haven't had any issues contacting them and getting problems resolved.
How was the initial setup?
Splunk Enterprise Security's deployment is hit or miss. Recently, we got UBA. We were able to spin up an environment easily with Terraform. However, the recent upgrade caused many hiccups and slowdowns. We are working with support to resolve them. Some legacy code is choking the system and slowing us.
Which other solutions did I evaluate?
We do market evaluation and continuous research every year to check for alternatives to our security tools.
What other advice do I have?
It seems like the tool is improving. It incorporates AI into the platform to streamline event identification processes.
Splunk Enterprise Security does a good job. However, we need many analysts to correlate searches and populate data models, and some overheads are needed in any SOC environment.
We have a lot of data to process from different sources. However, we have only limited data analysts. It takes time to find malicious threats or what we seek.
No specific metrics are tracked, but we report this to our leadership weekly, focusing on continuous improvement. Regarding reducing the mean time to resolve, especially with our SOAR integration, we can swiftly address major issues by leveraging alerts to initiate tickets. This allows us to notify the teams and address issues immediately.
I rate the overall product a ten out of ten. I don't think there is another alternative with similar capabilities.
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
Last updated: Jul 9, 2024
Flag as inappropriateRisk Manager at Samapartners
Helps reduce alert volume, speeds up investigations, and can monitor multiple environments
Pros and Cons
- "Three features stand out for me: the SDK for writing Python, the customizable and adaptable diagnostic dashboard, and the optimizer for collecting data."
- "The threat detection system has room for improvement."
What is our primary use case?
As a software analyst, I utilize Splunk Enterprise Security for security purposes, including threat hunting on developed and customized applications for vulnerability management. I also use it to display dashboards, analyze data, and address alerts.
We implemented Splunk Enterprise Security to consolidate all our security data into a single platform. This has enhanced our visibility into our security posture and the potential threats we face.
How has it helped my organization?
Splunk Enterprise Security enables us to monitor multiple cloud environments, which is crucial for receiving real-time email alerts in the event of critical incidents. However, directing me to the source can be time-consuming compared to the verified swim methodology used by SIEMs. For my application, I have approximately ten million records. Directing me to the service code takes two minutes to instruct them to view the file using VLOOKUP. However, sending it to the capital takes about half an hour.
The ability to monitor multiple environments is excellent. We have customers who use Splunk Enterprise Security both on-premises and in the cloud. Both options have their merits, depending on the specific needs of the customer. If a customer has the required resources, the cloud is often the most suitable solution.
The robust threat detection capabilities of Splunk are essential for our project. However, it's crucial to manage user access carefully. While we need to grant access to certain users, we must not provide them with unrestricted capabilities. Splunk's granular access control feature empowers administrators to customize user permissions, ensuring that only authorized users have access to the necessary features.
Splunk's threat topology helps us identify the scope of an incident. This is crucial due to the high likelihood of unauthorized data being compromised, necessitating prompt incident detection.
Splunk Enterprise Security has facilitated the timely detection of threats, enabling us to swiftly customize it to identify a wider range of threats and potential risks. We can incorporate external scripts for enhanced threat intelligence and threat-hunting capabilities.
Before implementing Splunk Enterprise Security, we relied on a patchwork of other tools, each requiring manual implementation for data collection, rule definition, and threat identification. This approach was not optimized and occasionally resulted in delayed threat detection. Limiting our focus to device security alone proved insufficient, as it lacked the real-time threat actor intelligence and activity insights provided by Splunk Enterprise Security. Our reliance on licensed development restricted us to pre-built alerts or manually uploaded scripts for mitigation and response.
Splunk Enterprise Security has helped reduce our alert volume.
Splunk Enterprise Security has helped speed up our security investigation time.
What is most valuable?
Three features stand out for me: the SDK for writing Python, the customizable and adaptable diagnostic dashboard, and the optimizer for collecting data.
What needs improvement?
The threat detection system has room for improvement. The critical aspect for an organization is the timely detection of incidents. If the rules are not defined correctly, threats may not be detected in real-time, resulting in incidents being detected months or even years after they occur.
For how long have I used the solution?
I have been using Splunk Enterprise Security for almost seven years.
What do I think about the scalability of the solution?
I would rate the scalability of the solution eight out of ten.
I would rate the resilience an eight out of ten.
How are customer service and support?
I contacted Splunk support once for a separate product.
How would you rate customer service and support?
Positive
How was the initial setup?
The initial deployment was straightforward for me, likely due to my extensive experience using Splunk. When implementing the solution, we begin by defining customer needs and requirements to optimize Splunk. This involves identifying the systems necessary for daily use and ensuring the protection of the integrated licenses and external apps in the Splunk environment. This protection encompasses program security, cloud-based security, and data analysis for specific apps. Additionally, we configure personal authentication for private applications.
The deployment time is dependent on the specific requirements and can range from two to ten days.
What about the implementation team?
The implementation was completed in-house.
What was our ROI?
Splunk Enterprise Security has delivered a return on investment through its effective threat detection and vulnerability response capabilities. We have successfully demonstrated this positive impact on our customers through comprehensive reports.
What other advice do I have?
I would rate Splunk Enterprise Security nine out of ten.
While there may be cheaper solutions available, they lack the optimizer, dynamic dashboard, and security APIs that Splunk offers. These capabilities are not found in other solutions.
Maintenance is minimal for updates only.
When using Splunk Enterprise Security, ensure that optimization is performed correctly to minimize response times and resource consumption.
Which deployment model are you using for this solution?
On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
System Engineer at Tara
Easy to maintain, with good alerts and fast threat detection
Pros and Cons
- "The alerts are very effective."
- "We'd like Splunk to reduce false positives."
What is our primary use case?
We are using the solution for security. We can use it to track what has happened in our network. We can check via dashboards and alerts. We can use it for load balancing and high-performance tasks. We use it to analyze data and logs. It normalizes logs and we can detect attacks, such as brute-force attacks. We can receive information from our firewall, our Fortigate. Since we receive a lot of traffic, we have to investigate events using the solution. It provides updates on attacks. The solution helps us report on what happens in our network.
What is most valuable?
We use Splunk for security and tracking what happens on our network and it is effective at that.
We like the big data analyzer.
The dashboard and alerts are good. We can use them for monitoring to see what’s happening on our network. It’s centralized. It gives us good visibility into multiple environments. We can use it in Windows, Linux, et cetera.
We can use platforms and integrate everything together. We can see multiple environments on-premises.
When something happens, we get alerts via SMS or email.
We use the MTTR attack feature and it is very effective to use for detecting threats.
We can also schedule reports on a monthly or weekly basis.
It’s very useful for tracking. If you can look at the steps and see what happens, you can investigate effectively, and so on.
Splunk Enterprise Security is excellent for analyzing malicious activities and detecting breaches. We can see, step by step, what happened. We can escalate and investigate and so on.
Splunk has helped us detect threats faster. The alerts are very effective.
It helped to reduce alert volume. I’m not sure precisely how much, however, it depends on how many client devices you are tracking and analyzing.
Splunk is a suitable resource for collecting logs.
What needs improvement?
The threat intelligence management feature is something we cannot use.
We'd like Splunk to reduce false positives.
It would be helpful to be able to configure everything a bit more. If your network is very big, it's important to customize.
The dashboard could be improved so that tracking and analysis could be better visualized.
For how long have I used the solution?
I've been using the solution for two years.
What do I think about the stability of the solution?
The solution is stable. If you have suitable resources and buy and use the correct license, you'll get fine performance.
What do I think about the scalability of the solution?
The ability to scale Splunk depends on your network. If it is big, you can add more resources easily. You can use a cluster and several servers.
How are customer service and support?
When you work on Splunk, it's very easy. However, when you need to reach out to support, it could be better. It would be helpful if they could respond faster.
How would you rate customer service and support?
Neutral
Which solution did I use previously and why did I switch?
I have experience with another solution called ELK; I find Splunk better, even though it is not free to use.
How was the initial setup?
I've done one implementation. I installed it across several servers. How long it takes depends on the project. It also depends on how many resources you have. If it's just a small setup it might take two hours.
The product is easy to maintain.
What other advice do I have?
I'm a customer. We cannot use the cloud versions as we are based in Iran.
I don’t have experience with the Spunk Mission Control feature.
I've worked with Splunk so far and while it's very easy to use it's not free. There are other solutions that are open-source that you could use, however, I find Splunk to be worth the price and I'd recommend it to others.
I'd rate the solution ten out of ten. I would recommend Splunk to others.
Which deployment model are you using for this solution?
On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
SOAR Developer at a media company with 10,001+ employees
Reduces time to detect, improves uptime, and handles correlation search well
Pros and Cons
- "The correlation search functions that generate all the notables are valuable. That can get pretty complicated, and it handles that pretty well."
- "Some of the search functions can be better. There has been a lot of talk at the conference about the update of SPL before each iteration. That will be a lot of help."
What is our primary use case?
We use it mostly to generate notables, and then we can use other tools, such as ticketing systems or other SOAR platforms, to investigate.
How has it helped my organization?
I was not around before we had Splunk Enterprise Security in our organization, so I do not know about the before and after, but I can tell it would be very painful to not have it.
It is pretty easy to monitor multiple cloud environments. All the logs from our cloud environments go to Splunk, and then we can search everything at once. It is pretty helpful.
Splunk Enterprise Security has end-to-end visibility into our cloud-native environments. It is pretty important. Especially if you use it as your single source of truth, it is pretty invaluable that you have everything in there.
It has reduced our mean time to detect, so inadvertently, it has also reduced our mean time to resolve. However, I do not have the metrics.
Splunk Enterprise Security has definitely improved our organization’s business resilience. There are a lot of logs that help with monitoring and alerting and keeping the business up.
It can help to predict, identify, and solve problems in real time. We do have some health alerts, and if they kick off, we might be able to fix something before it is really broken. In that sense, it is good.
Splunk Enterprise Security has been pretty good in terms of providing business resilience by empowering our staff. Most of our users are security-focused, but having everybody with the ability to write their own searches or build upon what we already have for detection of the future things is pretty helpful.
What is most valuable?
The correlation search functions that generate all the notables are valuable. That can get pretty complicated, and it handles that pretty well.
What needs improvement?
Some of the search functions can be better. There has been a lot of talk at the conference about the update of SPL before each iteration. That will be a lot of help.
For how long have I used the solution?
I have been using Splunk Enterprise Security for about two years.
What do I think about the stability of the solution?
It is pretty stable. We have not had any instances where Splunk just completely died. Its stability is good.
What do I think about the scalability of the solution?
It seems pretty scalable, especially considering how much data we ingest. It is a good tool.
How are customer service and support?
I have not interacted with them recently, but they are pretty good when I do need something from Splunk. I would rate them a ten out of ten. I have not had any issues with their support.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
We were probably using Elasticsearch.
How was the initial setup?
It was already implemented when I got here.
What was our ROI?
We have probably seen an ROI. We are in the security space, and there has definitely been improvement in uptime and the mean time to detect and respond to security alerts.
Its time to value is pretty immediate. The more logs and the more standardization that we get into Splunk, the quicker that comes.
What's my experience with pricing, setup cost, and licensing?
Most people share the same thought that the ingestion rates can get pretty pricey. There is a lot of work we do to curate the data that we send to Splunk so that it is not too noisy or too expensive.
What other advice do I have?
Overall, I would rate Splunk Enterprise Security an eight out of ten. There are some cool things. A lot of the talks at this Splunk conference have touched on some of the gaps that Splunk is working to close, but it is a very solid tool.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Splunk developer at a government with 5,001-10,000 employees
The incident review functionality gives a good overview of security incidents
Pros and Cons
- "The solution's most valuable feature is the incident review, which gives a good overview of our security incidents."
- "You can run a script from an event, but it needs many clicks to run that integration, which could be made easier."
What is our primary use case?
We develop use cases for Splunk Enterprise Security all the time. I mostly work with the SOAR platform to ingest those use cases.
How has it helped my organization?
Splunk Enterprise Security helps our organization because we use it daily to solve our security use cases. We have incidents every day.
What is most valuable?
The most valuable feature is the incident review, which gives a good overview of our security incidents. I also like the solution's search functionality, which makes it easy to find things.
Splunk Enterprise Security generates our alerts, and we would have to refine the searches if we want to reduce them.
It's very important to our organization that Splunk Enterprise Security provides end-to-end visibility into our environment.
Splunk Enterprise Security has helped reduce our mean time to resolve and helped improve our organization’s business resilience.
What needs improvement?
The incident review could definitely be improved in many ways. It should be easier to run integrations from it. You can run a script from an event, but it needs many clicks to run that integration, which could be made easier.
For how long have I used the solution?
I have been using Splunk Enterprise Security for five years.
What do I think about the stability of the solution?
The solution’s stability is very good, and we haven’t had any stability issues with Splunk Enterprise Security.
What do I think about the scalability of the solution?
The solution’s scalability could have been better.
How are customer service and support?
The solution's technical support is very good, and I'm very happy with the support.
How was the initial setup?
The solution’s initial setup is easy.
What other advice do I have?
Overall, I rate the solution an eight out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Last updated: Jul 8, 2024
Flag as inappropriateCTO at a computer software company with 11-50 employees
Reduces alert volume and remediation time, but pricing and learning curve for ML should be better
Pros and Cons
- "We can extract the metrics we want on the dashboards. We are able to react to the incidents."
- "There is a learning curve in order to start using machine learning. We have been trying to do it for three years, and we have not managed anything. It is too complex."
What is our primary use case?
We are using Splunk Enterprise Security for collecting and analyzing logs. We are keeping up with the SLAs with Splunk Enterprise Security.
How has it helped my organization?
Splunk Enterprise Security has helped reduce our alert volume. There is about 30% reduction.
Splunk Enterprise Security improves our organization’s ability to ingest and normalize data, but it requires lots of effort from our side. Splunk Enterprise Security can do that, but we also need to put effort into it. It is good enough to achieve that.
Splunk Enterprise Security has helped reduce our mean time to resolve. We have seen a reduction because doing this manually through queries is crazy. It helps to find out the root cause and things like that. It is helpful.
We have an on-prem environment. Our information security team is using the data security features. Its security features are satisfactory.
What is most valuable?
It is pretty good. We can extract the metrics we want on the dashboards. We are able to react to the incidents. We are also able to monitor the service. In addition to the incident response, we can also do investigations, fraud detection, and other things like that.
What needs improvement?
We have this issue of data versus pricing. Its pricing can be better. There should also be a more flexible licensing model.
There is a learning curve in order to start using machine learning. We have been trying to do it for three years, and we have not managed anything. It is too complex.
Its ability to identify and solve problems in real-time could be better. We would like to have pattern recognition. There should be some kind of pre-made model to help detect something. For example, at the time of the incident investigation, there should be an option to ask questions, such as if anything changed. It is pretty hard to find out the patterns that are occurring currently because you have to have deep knowledge about your log content. There should be an option to ask a question like, "What has changed as compared to a week ago?" We should be able to specify a time frame and compare.
For how long have I used the solution?
We have been using Splunk altogether for probably five years.
What do I think about the stability of the solution?
It has not failed over the last year. There were no failures, so it is pretty good.
What do I think about the scalability of the solution?
Its scalability is quite good if you are willing to invest in the new design and do the manual work. You have to deploy new servers and things like that. In terms of architecture, it is scalable.
How are customer service and support?
Based on the few problems that we have had, I would rate them a seven out of ten. For an issue, we did not get the answer we needed within the timeframe we were expecting. They took more time, and some IT guys were disappointed. The experience varies from case to case.
How would you rate customer service and support?
Neutral
Which solution did I use previously and why did I switch?
We were not using any similar solution previously. We were only collecting logs through open-source means. We went for Splunk Enterprise Security because we needed visibility into the logs. It was the primary requirement.
We are also using Elasticsearch. We have two parallel systems.
Splunk Enterprise Security is better in terms of query language and the capability to do great searches, whereas Elasticsearch has a little bit less functionality. It is more complicated for end-users to use. However, Elasticsearch is better in terms of pricing because they do not charge based on the daily ingestion amount. You can put whatever amount into the system. Elasticsearch also has lots of additional logging capabilities. It has file beats and metrics beats capabilities, so you can use it more widely. You can also get end-to-end visibility because you can make integrity checks with it. It helps with IT operations as well. They can include these capabilities in Splunk Enterprise Security.
How was the initial setup?
Its deployment was not very complicated. It was easy.
The hard part comes after you have deployed it. You have to educate people to start using it and understand the relevant information in your logs. The configuration itself is pretty simple, but field extractions and tagging are complex.
What was our ROI?
We are just using it and doing our queries and dashboards. We have not been calculating the ROI. It has been quite easy. We invest and create our dashboards and reports. Sometimes, when a dashboard becomes too complex or too expensive, we start to think about alternatives. Other than that, we have not thought of ROI.
What's my experience with pricing, setup cost, and licensing?
The pricing can be better. We are already considering Elastic because Splunk is too expensive.
You have to pay based on per-day ingestion. There should be a more flexible model for the use cases where one day you have a huge amount, and on other days, it is quite less.
What other advice do I have?
Splunk Enterprise Security provides end-to-end visibility into an environment, but it is not our use case currently.
Splunk Enterprise Security does not really provide the relevant context to help guide our investigations because, in our country, Splunk is not represented, so it is pretty hard to get the relevant information.
Overall, I would rate Splunk Enterprise Security a seven out of ten. Its pricing is not good, and the learning curve for machine learning is not good. However, the parts that are working are working very well.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Last updated: May 21, 2024
Flag as inappropriateBuyer's Guide
Download our free Splunk Enterprise Security Report and get advice and tips from experienced pros
sharing their opinions.
Updated: December 2024
Product Categories
Security Information and Event Management (SIEM) Log Management IT Operations AnalyticsPopular Comparisons
CrowdStrike Falcon
Microsoft Sentinel
IBM Security QRadar
Elastic Security
LogRhythm SIEM
Sumo Logic Security
Rapid7 InsightIDR
Fortinet FortiSIEM
AlienVault OSSIM
Cortex XSIAM
Securonix Next-Gen SIEM
USM Anywhere
ManageEngine Log360
Buyer's Guide
Download our free Splunk Enterprise Security Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- Which would you recommend to your boss, IBM QRadar or Splunk?
- What are some of the best features and use-cases of Splunk?
- What SOC product do you recommend?
- Splunk as an Enterprise Class monitoring solution -- thoughts?
- What is the biggest difference between Dynatrace and Splunk?
- IBM QRadar is rated above competitors (McAfee, Splunk, LogRhythm) in Gartner's 2020 Magic Quandrant. Agree/Disagree?
- What are the advantages of ELK over Splunk?
- How does Splunk compare with Azure Monitor?
- New risk scoring framework in the Splunk App for Enterprise Security -- thoughts?
- Splunk vs. Elastic Stack