Try our new research platform with insights from 80,000+ expert users
PeerSpot user
Information Security Advisor, CISO & CIO, Docutek Services at Docutek Services
Consultant
Leaderboard
It gives us the liberty to do more in terms of use cases.
Pros and Cons
  • "It gives us the liberty to do more in terms of use cases."
  • "The Web Application Firewall will send you too much information because it's more dedicated to security than a normal firewall."

What is our primary use case?

I work in the HIPAA industry. I work at a healthcare company in Puerto Rico. HIPAA requires us to go over security risks. Our use case right now is to be compliant.

In our hierarchy, we have 1000 servers and 16,000 endpoints. We also have 100 entry points and 3000 VPN connections. It's huge.

How has it helped my organization?

Manually, it used to take us a whole day to do strong monitoring. Now, it takes a maximum of two hours because of this product.

It creates a single pane of glass. Plus, it gives us the liberty to do more in terms of use cases, especially since HIPAA wants use cases. We must monitor them. Therefore, we can also add our own correlations for all our use cases.

What is most valuable?

The dashboard centralizes the daily routine. We used to do this by hand. Now, we go through daily checklists, using the dashboard and setting up the alarms. It helps us to cut down the time on this routine. 

I am a cybersecurity director. I manage five different business lines. Every morning, we used to have to go to different tools to get our daily routines done. With Splunk, centralized as it is, we can see everything in one place. We use it not only for monitoring events, but in case we need to do a group call. We can see what's going on, viewing all of the offenses and security events which are happening in our infrastructure.

What needs improvement?

The Web Application Firewall will send you too much information because it's more dedicated to security than a normal firewall.

Buyer's Guide
Splunk Enterprise Security
December 2024
Learn what your peers think about Splunk Enterprise Security. Get advice and tips from experienced pros sharing their opinions. Updated: December 2024.
831,020 professionals have used our research since 2012.

For how long have I used the solution?

One to three years.

How was the initial setup?

It was pretty straightforward. I even did a couple of logs myself. 

What about the implementation team?

We implement through a vendor.

Which other solutions did I evaluate?

We were using QRadar as a POC. We were using for real at our cloud but also it was a POC for us because we were watching the product. But, QRadar needs a lot of fine tuning.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Spelunking Consultant at BlueVoyant
Consultant
Top 20
Provides a centralized place to consolidate everything and start investigations
Pros and Cons
  • "The solution's most valuable feature is its data modeling."
  • "It would be good if the solution had some kind of copilot to automate or help write correlation searches."

What is our primary use case?

My customers subscribe to many different tools, like CrowdStrike. They ingest all that into Splunk and use it as an aggregator to launch their investigations into any threats detected.

How has it helped my organization?

The solution has improved our organization by providing a centralized place to start investigations. It allows us to consolidate everything into one place that kicks everything off so we can map it back to at least that Splunk instance.

What is most valuable?

The solution's most valuable feature is its data modeling. Splunk has data from so many different vendors. Moving all that or normalizing that to the data models allows us to look at one place holistically across all the different inputs.

What needs improvement?

The one problem Splunk has is writing correlation searches. My analysts are intimidated to write queries to create correlation searches. It would be good if the solution had some kind of copilot to automate or help write correlation searches. Splunk Enterprise Security should include more automation, AI, and machine learning capabilities.

For how long have I used the solution?

I have been using Splunk Enterprise Security for three to four months.

What do I think about the stability of the solution?

We haven’t faced any issues with the solution’s stability.

What do I think about the scalability of the solution?

We haven’t faced any scalability issues with Splunk Enterprise Security.

What other advice do I have?

The end-to-end visibility the tool provides is not that big of a deal. They have so many tools that can do that kind of part. Splunk doesn't have to be the one place for total visibility, but at least for visibility when it consolidates on threats.

Splunk has helped improve our organization's ability to ingest and normalize data. The tool pretty much consumes everything that we have. Everything from dozens of different vendor products gets ingested into Splunk. Splunk Enterprise Security is just that one central place where everything goes.

Splunk Enterprise Security has helped speed up our security investigations. Something that requires someone to work on it at the beginning of the day would not take more than 15 minutes with Splunk Enterprise Security.

Overall, I rate the solution an eight out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Flag as inappropriate
PeerSpot user
Buyer's Guide
Splunk Enterprise Security
December 2024
Learn what your peers think about Splunk Enterprise Security. Get advice and tips from experienced pros sharing their opinions. Updated: December 2024.
831,020 professionals have used our research since 2012.
reviewer1339833 - PeerSpot reviewer
Project manager at a computer software company with 10,001+ employees
Real User
Top 20
Excels in providing advanced threat detection, real-time monitoring and comprehensive security analytics
Pros and Cons
  • "The technical support is among the best in the market."

    What is our primary use case?

    We employed Splunk Enterprise Security for one of our projects. Integrating it into our environment involved opening network ports and making necessary connections.

    How has it helped my organization?

    We had the opportunity to assess visibility in various environments, including on-premises. On-premises visibility has proven to be both satisfactory and advantageous.

    What is most valuable?

    We use the threat intelligence management feature. 

    We have been considering implementing certain frameworks, such as MITRE ATT&CK or threat topology features.

    It contributes value by enhancing resilience, crucial for adopting a Security Information and Event Management solution. Site resilience is imperative for our organization, meeting a key security requirement.

    For how long have I used the solution?

    I have been working with it for three years.

    What do I think about the scalability of the solution?

    It provides good scalability capabilities.

    How are customer service and support?

    The technical support is among the best in the market. While we didn't have extensive interactions with the support team, we are satisfied with it. It offers support services locally in my country. I would rate it ten out of ten.

    How would you rate customer service and support?

    Positive

    How was the initial setup?

    The initial setup was straightforward.

    What about the implementation team?

    The integration and initial setup of Splunk were managed with the assistance of local support.

    What other advice do I have?

    Overall, I would rate it eight out of ten.

    Disclosure: I am a real user, and this review is based on my own experience and opinions.
    PeerSpot user
    reviewer909678 - PeerSpot reviewer
    Systems Engineer at a consultancy with 201-500 employees
    Real User
    Top 5
    Fine features, good monitoring, and reduces alert volume
    Pros and Cons
    • "We are using Microsoft 365 and we're using the Exchange Mail Service. It's good for monitoring that in particular."
    • "The setup time is quite long."

    What is most valuable?

    The features are fine; they aren't exceptional in any way.

    We are using Microsoft 365 and we're using the Exchange Mail Service. It's good for monitoring that in particular. 

    The visibility we get has been good. 

    Inside threat detection capabilities are good. 

    It's helped us to reduce our alert volume a little. I haven't properly calculated it fully so it's hard to lay out a percentage. 

    What needs improvement?

    We'd like to have customer service in Hong Kong. I tend to wait a while for their response. We'd like to have more best-practice rules and instructions on how to create a dashboard.

    I've only been using Splunk for two years. I make use of it to incorporate other solutions. I need to spend more time mastering Splunk. Sometimes it's a little bit difficult to use. I'd like to get more certificates, et cetera, and have spoken to their main office about that. It's got a high learning curve.

    It hasn't helped us speed up security investigations. 

    For how long have I used the solution?

    I've been using the solution for about two years. 

    What do I think about the stability of the solution?

    I've never had any issues with Splunk's stability.

    What do I think about the scalability of the solution?

    The solution does not lack scalability. 

    How are customer service and support?

    I haven't had any communication with Splunk's technical team.

    Which solution did I use previously and why did I switch?

    I did not previously use a different solution. 

    How was the initial setup?

    The setup time is quite long. To this point, I haven't deployed it to all servers and devices. I'm still in the process of deploying. 

    Which other solutions did I evaluate?

    I have not evaluated other options. 

    What other advice do I have?

    We are Splunk customers. 

    We do not use it in multiple environments. We just use it on-premises. 

    I'm not yet using the threat intelligence features. 

    We do not use the mission control feature. 

    I have not created any customized dashboards as of now. At some point, I will create one for, for example, Windows Security.

    I'm still in the process of mastering threat detection and XDR. 

    I'd rate the solution eight out of ten. I haven't used it for such a long time, so it's hard to give comprehensive details about the solution. 

    Which deployment model are you using for this solution?

    On-premises
    Disclosure: I am a real user, and this review is based on my own experience and opinions.
    PeerSpot user
    Senior security consultant at a comms service provider with 51-200 employees
    Consultant
    Threat hunting is a key feature for us
    Pros and Cons
    • "One of the most valuable features is threat hunting. We can do threat hunting and identify if there is any malicious activity happening within our environment, which is a key feature for us."
    • "Splunk could be improved by reducing the cost. The cost is one of the biggest challenges for us in keeping to our production requirements."

    What is our primary use case?

    Our initial use case was for security investigation, with the intention of creating some use cases. We ended up adding operational aspects, monitoring certain operational activities, such as high CPU utilization or any other applicational basis. 

    This is obviously a cloud solution, but it does have some presence on-premises as well, so it's hybrid. 

    What is most valuable?

    One of the most valuable features is threat hunting. We can do threat hunting and identify if there is any malicious activity happening within our environment, which is a key feature for us. 

    What needs improvement?

    Splunk could be improved by reducing the cost. The cost is one of the biggest challenges for us in keeping to our production requirements. 

    As for additional features, I think they need to refine their AI capability. I know that everyone is talking about artificial intelligence and threat hunting, so I guess one of the key requirements for us is for the solution to automatically provide us some kind of indication and then mitigate any risk. So automation should be a feature. 

    For how long have I used the solution?

    I have been using Splunk for two years. 

    What do I think about the stability of the solution?

    This solution is excellent from a performance and stability perspective. There's very minimal maintenance required. Basically the only aspect we need to maintain is the one we have on-prem. So patching up everything and making sure it has the required updates. 

    What do I think about the scalability of the solution?

    There are no issues at all in terms of scalability, since this is a cloud-based solution. There are around 25 to 30 users in my company accessing Splunk. 

    How are customer service and support?

    Splunk's support is good. The process was smooth and they provided sufficient support, so there was no need to escalate anything. Also, they provide training on a regular basis, which is good. 

    Which solution did I use previously and why did I switch?

    I have never worked with other similar products. I've worked for three companies, all of which use Splunk. 

    How was the initial setup?

    The initial setup was very smooth. I think we got some support from the Splunk team. Since it's a cloud-based solution, it took us probably three or four weeks to actually start working. But deploying agents, configuration, refining, fine tuning, and other ongoing activities went on for about a month. 

    What about the implementation team?

    We implemented through an in-house team with some support from the Splunk team. It was a very smooth process, from our perspective. 

    What's my experience with pricing, setup cost, and licensing?

    This solution is costly. Splunk is obviously a great product, but you should only choose this product if you need all the features provided. Otherwise, if you don't need all the features to meet your requirements, there are probably other products that will be more cost-effective. It's cost versus the functionality requirement. 

    Which other solutions did I evaluate?

    I also evaluated IBM QRadar and LogRhythm NextGen SIEM

    What other advice do I have?

    I work in security architectures, not operations, so I don't actually work with Splunk on a regular basis, but the team that does is working on threat hunting and incident management. 

    I rate Splunk an eight out of ten. 

    Which deployment model are you using for this solution?

    Hybrid Cloud

    If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

    Other
    Disclosure: I am a real user, and this review is based on my own experience and opinions.
    PeerSpot user
    John Yuko - PeerSpot reviewer
    Assistant Manager ICT - Projects at I&M Bank Ltd
    Real User
    Good visualization, reliable, scales well, and has good support
    Pros and Cons
    • "The additional vendors we've brought on board, particularly the elastic, have been quite beneficial."
    • "The configuration had a bit of a learning curve."

    What is our primary use case?

    We are currently using it with SIEM, and SOAR which is Security Orchestration, Automation, and Response.

    Splunk is primarily used for security, incident response, and security analytics.

    How has it helped my organization?

    Using Splunk, give us the visualization we need, we can easily observe things such as user behavior analytics, irregular traffic, frequency, and any spikes in unusual activity inside the network.

    What is most valuable?

    The additional vendors we've brought on board, particularly the Elastic, have been quite beneficial.

    It's a solid platform.

    What needs improvement?

    Other than the pricing modules, I have no issues with the product itself.

    The configuration had a bit of a learning curve.

    I would like to learn more about the Cloud solution, but I'm aware that it's lacking some core applications.

    If they could bring on more vendors, you would be able to monitor a larger number of applications. We could have visualization with other applications we have with the infrastructure in our organization.

    For how long have I used the solution?

    I did a POC, but we have recently procured it. We did a rudimentary setup to get an understanding of how it works. We are into our sixth month of using it now.

    What do I think about the stability of the solution?

    Splunk is a very stable solution.

    What do I think about the scalability of the solution?

    This solution is quite scalable.

    In our organization, we have 10 users, who use this solution but we have plans to increase our usage.

    How are customer service and support?

    The technical support has been quite helpful.

    Which solution did I use previously and why did I switch?

    The previous solution was limited in its functionality. 

    We were looking at the additional controls that enterprise security may have, as well as visualization, to gain greater visibility.

    Splunk offered us more visibility.

    How was the initial setup?

    The initial setup was complex.

    We had some assistance with the actual deployment, but while I was doing the POC, I was working with a vendor. There were things I had to do myself, such as the configuration, which was a bit challenging for me, it was a big learning curve.

    What about the implementation team?

    For the installation, we received some assistance from the vendor.

    What was our ROI?

    It's too early to know if there will be a return on investment.

    What's my experience with pricing, setup cost, and licensing?

    The pricing modules could be improved.

    The licensing fees are paid on a yearly basis.

    There is a standard license with provisions for more. As we are still exploring the functionality, there may be other departments that want to use it.

    What other advice do I have?

    Those who are interested in implementing this solution should be prepared to dig deep into their pockets.

    I would rate Splunk a nine out of ten.

    Which deployment model are you using for this solution?

    On-premises
    Disclosure: I am a real user, and this review is based on my own experience and opinions.
    PeerSpot user
    Robert Cheruiyot - PeerSpot reviewer
    IT Security Consultant at Microlan Kenya Limited
    Real User
    Top 5
    Efficient, scalable, robust and easy to use
    Pros and Cons
    • "What is nice about the solution is that it makes it easy to build the queries, search for the events and then do analysis."
    • "Endpoint access is the only issue I can think to mention, even though the endpoint access we have with Cisco is fine."

    What is our primary use case?

    I have some experience with the solution, since I am working with customers who are interested in part time help monitoring their network and have been helping them fine-tune the rules in the solution's platform. The way the primary task works is to watch for and then respond to the threat. Should there be a need, I usually work with a team in fine-tuning the rules on this platform. We are providing the products.

    I recently started working primarily on the Playbooks of the Splunk Phantom, so I've been creating some of these to help the customer automate the process of responding to the threats.

    What is most valuable?

    What is nice about the solution is that it makes it easy to build the queries, search for the events and then do analysis. I recently have become involved in the Playbooks, since it is painful for the client to respond to the threat, be it positive or negative. As such, I currently see the Phantom component of the solution to be of great value. Otherwise, most other features seem to be similar to Netwitness, such as the monitor log, network, and endpoint capabilities. Importantly, the solution lacks endpoint options, as these are currently deployed on Cisco, which is okay, as it works fine with that bad side of the endpoint security. This translates into them building queries, rules and then Playbooks. 

    The main advantage of the solution is that it provides an easy setup platform in the new environment. When set up afresh, it is also easy to build queries. Historical queries can be used to site for a new event, which makes it easy to use, deploy and understand.

    What needs improvement?

    Endpoint access is the only issue I can think to mention, even though the endpoint access we have with Cisco is fine. 

    For how long have I used the solution?

    I have been engaged in the production environment of Splunk for around a year and have been reading up on it for a long time.

    What do I think about the stability of the solution?

    I would rate Splunk as one of the big five platforms. I would give it a high rating based on the efficiency of the platform. 

    What do I think about the scalability of the solution?

    Splunk allows one to easily scale up this platform. One can add more interfaces to that platform if he gets more data. 

    How are customer service and support?

    I usually rely on the Splunk community for information, such as discussions of incidents and other issues which others are facing. I feel the Splunk community to be an excellent source of information for me.

    How was the initial setup?

    Out of the three platforms I have been dealing with, I feel the initial setup of Splunk to be the easiest. I found it a bit difficult to set up a new environment with RSA Netwitness. Splunk, on the other hand, I have found to be very straightforward and an uncomplex platform. 

    Which other solutions did I evaluate?

    I have been proposing to management to take the solution to be a primary product in our dealings with it. We do not encounter many issues involving the solution. One of the problems I have with the RSA Netwitness platform is its complexity. Splunk is straightforward for us when it comes to views and it provides us the network security posture.

    The ability for the solution to work with Cisco shows that the solution can work with other products. The only thing is that when the solution is compared with other vendors, one sees that there is only a single other vendor that has endpoint security like this one, Netwitness platform having its component for the endpoint. This is why an integrated endpoint would be a nice feature, even though the solution works on Cisco. 

    The main advantage of the solution is that it provides an easy setup platform in the new environment. When set up afresh, it is also easy to build queries. Historical queries can be used to site for a new event, which makes it easy to use, deploy and understand. 

    When it comes to a data platform, there is RSA NetWitness, which may also be a good platform. I have not done much training of my own on Splunk, but have gained much experience through learning and working with clients that I support. This is because the platform is understandable. 

    I would rate Splunk as one of the big five platforms. I would give it a high rating based on the efficiency of the platform. Clearly, I cannot include Wazuh in the top five categories, as its rating is not up there with Splunk, Qradar and LogRythm.

    What other advice do I have?

    I cannot think of anything disadvantageous about Splunk, as we are talking about a product that I like. I feel the solution has beautiful features. 

    The decision to go with Splunk would depend on the business needs of the individual. I know that Splunk has both a cloud and an on-premises option. Sometimes, such as when it comes to conferences, there is no need to move some of the data to the cloud for the purpose of complying with regional requirements. There may be a need to retain some of it and a person might wish for a mixture of on-cloud and on-premises capabilities.

    I rate Splunk as an eight out of ten. It is a robust platform and easy to use. 

    Which deployment model are you using for this solution?

    On-premises
    Disclosure: I am a real user, and this review is based on my own experience and opinions.
    PeerSpot user
    Principal Systems Engineer at Aricent
    Real User
    A reliable and complete solution, but the pricing model is complex and it's expensive
    Pros and Cons
    • "The completeness of the solution is what we like the most."
    • "It's difficult to set up initially, and their billing model is also a bit complicated."

    What is our primary use case?

    We are using the mobile SDK to check the stability of mobile applications.

    What is most valuable?

    The completeness of the solution is what we like the most.

    What needs improvement?

    It's difficult to set up initially, and their billing model is also a bit complicated. 

    We have to predict in advance how much data we will have and what the storage would be that we don't have. This makes the licensing complicated because when you start you don't have these numbers.

    In order to know how much it will cost, you need those numbers.

    I really wish that it was an application that was easier to use.

    For how long have I used the solution?

    I have been working with Splunk for more than five years.

    What do I think about the stability of the solution?

    We have not experienced any issues.

    What do I think about the scalability of the solution?

    For our use cases, we have not required any scaling.

    How are customer service and technical support?

    The technical support is fine. At times, they take time to respond back but it may have been the support contract that our client had.

    I would assume that they are not as responsive as we want them to be.

    How was the initial setup?

    We have a team of approximately 100 people who are responsible for the development of mobile applications, DevOps, and application development.

    What's my experience with pricing, setup cost, and licensing?

    The licensing cost model is complicated.

    I think that most of the monitoring solutions are expensive. I wish they were less expensive, for all types of products for monitoring.

    Which other solutions did I evaluate?

    We work with Splunk, but we are looking for some LOG Kinetics solutions for our clients.

    What other advice do I have?

    I would definitely suggest sending people to analyze or evaluate Splunk.

    Because the licensing model is very complicated to understand, it would be better to start with another product that provides a better licensing model. Later, if the product is not working well, they can consider using Splunk and may have a better understanding of the cost.

    For me, I would not recommend Splunk as their first solution unless they have all of the data that is required.

    I would rate Splunk a seven out of ten.

    Which deployment model are you using for this solution?

    Public Cloud
    Disclosure: I am a real user, and this review is based on my own experience and opinions.
    PeerSpot user
    Buyer's Guide
    Download our free Splunk Enterprise Security Report and get advice and tips from experienced pros sharing their opinions.
    Updated: December 2024
    Buyer's Guide
    Download our free Splunk Enterprise Security Report and get advice and tips from experienced pros sharing their opinions.