Our primary use case of Splunk is for log monitoring and infrastructure monitoring. If we want to diagnose any issue in our application, we just push our application logs. This is on any client server using the universal forwarder logs on the Splunk server. After indexing, we can create a base log, and create attractive dashboards that are simple to understand and use. I'm a system administrator and we are customers of Splunk.
System Administrator and DevOps Engineer at a tech services company with 10,001+ employees
Very straightforward, easy to configure, stable and scalable.
Pros and Cons
- "This is a straightforward solution, easy to configure."
- "This is a costly solution."
What is our primary use case?
What is most valuable?
This is a straightforward solution, easy to configure and difficult to mess up.
What needs improvement?
Splunk is a very costly solution and I think it's the most expensive in the market in terms of costing. Splunk provides an application for infrastructure monitoring. If we're monitoring the docker with containers, we can't see the container name, only the ID. That's a big drawback.
For how long have I used the solution?
I've been using this solution for two years.
Buyer's Guide
Splunk Enterprise Security
February 2025

Learn what your peers think about Splunk Enterprise Security. Get advice and tips from experienced pros sharing their opinions. Updated: February 2025.
838,713 professionals have used our research since 2012.
What do I think about the stability of the solution?
This is a stable solution. Deployment takes one person, it can be a system admin or an engineer.
What do I think about the scalability of the solution?
This is a scalable solution. We can do the clustering of it for large applications. We have around 15 users for this product.
How are customer service and support?
If I have any issues, I'll go to the community. I can generally get a response within a day. Although most of the documentation is good, some of it is unclear, particularly if you're new to the product.
How was the initial setup?
I think it takes around 10 minutes to install it on the server. On the client side, it takes around five minutes. I do the installation myself.
What other advice do I have?
If you're going with this solution, make sure that when implementing the ports are open. If they're not open, it creates problems with the server. Other than that, this is a very stable and very easy to configure product. We can easily deploy and easily use. Other similar solutions are difficult to configure, Splunk is the simplest. I've used three or four monitoring tools and Splunk is the easiest. If a company can afford it, this is a good product. We are planning to shift to another product because of the cost. We're searching for an open source or cheaper product.
I would rate this solution a nine out of 10. They lose one point for the price and lack of infrastructure support.
Which deployment model are you using for this solution?
On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Software Engineer at Tableau Software
It has reduced the time to resolution and time to investigate, but the search query is slow
Pros and Cons
- "It has reduced the time to resolution, time to investigate, and time to troubleshoot for debugging issues."
- "Out-of-the-box, it seems very powerful."
- "My company could benefit from doing more Splunk training with Splunk consultants teaching us how to use it."
What is our primary use case?
We use it for searching logs in a production environment.
How has it helped my organization?
It has reduced the time to resolution, time to investigate, and time to troubleshoot for debugging issues.
What is most valuable?
Being able to search across all the different production environments at the same time, then being able to do search queries to scope out specific environments, specific components, or specific logs from different languages, such as Java or C++. Thus, being able to have really fine grain control on log searching is really good.
Out-of-the-box, it seems very powerful.
What needs improvement?
The search query seems slow, but I am not sure if that is just because it is searching millions upon millions of lines of text. Also, I just started using it, so I might have no idea what I am doing. I could probably speed up the queries by improving my search skills.
My company could benefit from doing more Splunk training with Splunk consultants teaching us how to use it. It is possible that we have already done this and I haven't participate, but this type of training would be helpful.
For how long have I used the solution?
Less than one year.
What do I think about the stability of the solution?
It is always up when I need to search. I am probably not using it that much. I will maybe search a couple times a day for something specific, so I am not using it too much. I know plenty of the people who are doing a lot more for debugging, and who use it a lot all day.
What do I think about the scalability of the solution?
It seems like it scales well. We have hundreds of production and development environments, and we are searching on all of them. Therefore, it seems like the scale is good.
We have hundreds of production environments, and each production environment has ten to 20 host machines. Each production environment can manage tens of thousands of customers.
Maybe going to AWS and scaling it better would be more cost-effective for our company. However, I am not involved in those decisions.
How is customer service and technical support?
I have not used technical support.
Which other solutions did I evaluate?
We have other log searching tools, but we have standardized on Splunk.
What other advice do I have?
It is a great product. We have a lot of different tools to do this type of debugging. Yet, it is one of the first ones that I will reach for, and I think that is a good sign.
It works well and is the industry standard for log searching. It probably has other features too. Therefore, if you use it, I would recommend the training, so you know what you are doing.
I am using the on-premise version.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Buyer's Guide
Splunk Enterprise Security
February 2025

Learn what your peers think about Splunk Enterprise Security. Get advice and tips from experienced pros sharing their opinions. Updated: February 2025.
838,713 professionals have used our research since 2012.
DevOps Engineer at BigPanda
A full monitoring and alerting solution for operations and application analysis
Pros and Cons
- "It is a one stop shop as a full monitoring and alerting solution for operations and application analysis for most of our back-end systems."
- "We used it to create a custom anomaly detection data model to monitor the activity of our back-end services on an hourly basis relative to the past three months of activity."
- "It needs to improve the way to install third-party apps and enable installation without logging into splunk.com."
What is our primary use case?
We use Splunk for a few different use cases:
- We package it as part of one of our on-premise software offerings which includes our in-house customized dashboards.
- We use it for Application Monitoring of many of our back-end systems. Monitoring is done completely through Splunk by forwarding application and other logs to Splunk and many configured customized alerts and dashboards for the Ops, Dev, product, and management teams.
- We created a custom anomaly detection data model to monitor the activity of our back-end services on an hourly basis relative to the past three months of activity.
How has it helped my organization?
It has improved our organization in many ways:
- Having Splunk as part of one of our software products was our choice for giving our customers a great user experience.
- It is a one stop shop as a full monitoring and alerting solution for operations and application analysis for most of our back-end systems.
What is most valuable?
- The easy automatic field parsing of logs.
- Data model acceleration
- The ability to easily have access and install Splunk add-on plugins and custom apps. This greatly assists with using it to connect to various systems easily and use it as a centralized data sink.
What needs improvement?
It needs to improve the way to install third-party apps and enable installation without logging into splunk.com.
For how long have I used the solution?
One to three years.
What do I think about the stability of the solution?
Not at all.
What do I think about the scalability of the solution?
Not really.
How is customer service and technical support?
Their support is pretty good, but not amazing. Although we have our own in-house Splunk expert who worked for Splunk themselves for a few years, we do not really need external support that much. We basically use them for licensing stuff.
The forums are pretty thorough, so technically we have not had much need for support.
How was the initial setup?
The initial setup is easy. Although, we currently use just a single server and not multi-server clustered instances.
For our Linux instance setup, an upgrade is very easy. It is all managed by about three simple Bash scripts.
What's my experience with pricing, setup cost, and licensing?
It is possible to use a developer's license, which is up to 10GB per day of volume traffic, which is usually enough for most use cases.
Which other solutions did I evaluate?
We evaluated ELK Stack and QlikView.
What other advice do I have?
We are a Splunk Partner, since after much deliberation, we decided to choose Splunk as a component of one of our on-premise software offerings.
Disclosure: My company has a business relationship with this vendor other than being a customer: We are a Splunk Partner.
Sr. Production Support Analyst at Electric Reliability Council of Texas
Quickly searches logs, performance data, and other inputs to assist with troubleshooting
Pros and Cons
- "The ability to quickly search logs, performance data, and other inputs has helped tremendously with troubleshooting."
What is our primary use case?
Operational intelligence monitoring for several different systems. We collect logs from applications and performance data from hardware, as well as information pulled from databases.
How has it helped my organization?
The ability to quickly search logs, performance data, and other inputs has helped tremendously with troubleshooting. The visualizations are easy and well received by business and management users.
What is most valuable?
For how long have I used the solution?
Three to five years.
How is customer service and technical support?
The user community is extremely beneficial, particularly with Splunk Answers and the Slack User Groups.
What's my experience with pricing, setup cost, and licensing?
The licensing model can be expensive, but the value it provides is significant.
What other advice do I have?
The recent acquisition of Phantom makes the future seem bright with more automated responses.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Senior Manager of Network with 1,001-5,000 employees
Splunk is great for Syslog capabilites. For normal device management, you can't go wrong with SolarWinds.
I'd go with Splunk for logging. For Syslog capabilities, Splunk wins outright from my experience. It's quick, very customizable, and there are many different modules some specific for vendors and devices. (Cisco Security Suite for one).
If you are really into SolarWinds and want to use them for Syslog then I would go with Kiwi. SolarWinds NPM has a syslog collector but under heavy load (a few hundred devices) it will get bogged down real quick in my experience.
If you are looking for normal device management then NPM, NCM, NTA are the way to go. You can't go wrong with SolarWinds.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Regional Head at a tech services company with 51-200 employees
Good technical support, scalable, and very stable
Pros and Cons
- "It's basically one of the best SIEM products on the market."
- "You do need a lot of training and certification with this product."
What is our primary use case?
The solution is primarily a SIEM tool and it basically helps companies with security.
What is most valuable?
It's basically one of the best SIEM products on the market.
The scalability is great.
We have found the solution to be stable.
Technical support is helpful. They respond in a timely manner.
What needs improvement?
I'd like to see more documentation on the product.
The initial setup is not straightforward.
You do need a lot of training and certification with this product. Other than that, it's pretty good.
For how long have I used the solution?
I've been dealing with the solution for about three years. It's been a while.
What do I think about the stability of the solution?
The stability of the product is very good. The performance is reliable. There are no bugs or glitches. it doesn't crash or freeze. We've had no issues.
What do I think about the scalability of the solution?
The scalability of the solution is great. If a company needs to expand it, it can do so. It's not a problem.
We have about nine customers that are using Splunk.
How are customer service and support?
I've dealt with technical support and it's pretty good. They are helpful. I find them responsive.
How was the initial setup?
The initial setup is not straightforward. It depends upon the IT infrastructure that the customer has. If they have a lot of security solutions, such as DLP and other security solutions, then it is more complicated. The more you have the more complicated it gets.
The deployment of Splunk takes about three weeks.
We have six or seven team members within our organization that can handle deployment and maintenance tasks.
What about the implementation team?
I handled the implementation myself. It was done in-house.
What's my experience with pricing, setup cost, and licensing?
Splunk requires a paid license. There's no free option. Customers have to pay for the license, implementation, support - everything.
What other advice do I have?
The solution can be deployed both on-premises and on the cloud.
I'd rate the solution at a nine out of ten. We've been very happy with the product.
I would recommend the solution. It really is the best.
Which deployment model are you using for this solution?
Public Cloud
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
IT & Cloud Architect at AiM Services SA
We use it for reporting and monitoring of all solutions in the company
Pros and Cons
- "We can present to our management in real time the security of the batch management for the PCs, security regarding the network equipment. We're currently working in the Azure Cloud project, so we can send any logs from the cloud to Splunk. We can monitor them and we can present to the managers and customers. It's a very good solution for reporting. We use Splunk for reporting and monitoring of any solution in the company."
- "The security can be improved."
What is our primary use case?
Our primary use case is reporting from the Windows administration. We have SCCM that configures the manager to update every PC workstation and server in the company. We have a lot of PCs and servers in our environment and we use Splunk for the gathering of the PCs and Windows service. We also use it to collect information from the security tools, for example, to provide the management information about how the everyday connection is.
How has it helped my organization?
We can present to our management in real time the security of the batch management for the PCs, security regarding the network equipment. We're currently working in the Azure Cloud project, so we can send any logs from the cloud to Splunk. We can monitor them and we can present to the managers and customers. It's a very good solution for reporting. We use Splunk for reporting and monitoring of any solution in the company.
What needs improvement?
The security can be improved.
What do I think about the scalability of the solution?
It is scalable. We have five admins so far that we have in the solution. We have two as techs to develop the design on the world map of the solution, and we have the end users, so 80,000 users altogether.
How was the initial setup?
The initial setup was complex. We have two data centers in France, two in Germany, and we have 18 countries in the world. It's a big company and we have a lot of services, servers, etc. So the setup is more complex.
What other advice do I have?
I would rate this solution a perfect ten out of ten.
Disclosure: My company has a business relationship with this vendor other than being a customer: Reseller.
Security Engineer at Information Innovators Inc. (Triple-i)
Correlates logs throughout the enterprise for searching and use in investigations
Pros and Cons
- "We primarily use it to correlate logs throughout the enterprise for both searching and use in investigations."
- "It can be tough to get a hold of somebody in technical support depending on the complexity of the issue."
- "The Enterprise Security app could be improved. We have had trouble with it working from the first day."
What is our primary use case?
We primarily use it to correlate logs throughout the enterprise for both searching and use in investigations.
How has it helped my organization?
We previously did not have a good centralized solution which could ingest just about any log type, which has been a plus.
What is most valuable?
The search application has been the most useful. We have also liked the reporting features and dashboard capabilities.
What needs improvement?
The Enterprise Security app could be improved. We have had trouble with it working from the first day.
For how long have I used the solution?
More than five years.
What do I think about the stability of the solution?
Yes, there have been issues with the Enterprise Security application instance.
What do I think about the scalability of the solution?
No issues.
How are customer service and technical support?
It has been a weak point, but has improved over the years. It can be tough to get a hold of somebody depending on the complexity of the issue.
Which solution did I use previously and why did I switch?
Years ago, we did use another solution, but I am not sure it exists any longer. We have been using Splunk for many years.
How was the initial setup?
We had professional services set it up, as it was quite complex.
What about the implementation team?
Vendor implementation, and I would rate them as a seven out of 10.
What was our ROI?
Excellent overall.
What's my experience with pricing, setup cost, and licensing?
It can be expensive, especially the licensing costs. However, there is added value in what it can do, not just log aggregation.
Which other solutions did I evaluate?
We evaluated Trustwave and QRadar.
What other advice do I have?
It is a great product overall. I would like to see improvements on the Enterprise Security app/SIEM functionality.
Disclosure: I am a real user, and this review is based on my own experience and opinions.

Buyer's Guide
Download our free Splunk Enterprise Security Report and get advice and tips from experienced pros
sharing their opinions.
Updated: February 2025
Product Categories
Security Information and Event Management (SIEM) Log Management IT Operations AnalyticsPopular Comparisons
CrowdStrike Falcon
Microsoft Sentinel
IBM Security QRadar
Elastic Security
LogRhythm SIEM
Rapid7 InsightIDR
Sumo Logic Security
Fortinet FortiSIEM
Cortex XSIAM
AlienVault OSSIM
Securonix Next-Gen SIEM
Google Chronicle Suite
ManageEngine Log360
Buyer's Guide
Download our free Splunk Enterprise Security Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- Which would you recommend to your boss, IBM QRadar or Splunk?
- What are some of the best features and use-cases of Splunk?
- What SOC product do you recommend?
- Splunk as an Enterprise Class monitoring solution -- thoughts?
- What is the biggest difference between Dynatrace and Splunk?
- IBM QRadar is rated above competitors (McAfee, Splunk, LogRhythm) in Gartner's 2020 Magic Quandrant. Agree/Disagree?
- What are the advantages of ELK over Splunk?
- How does Splunk compare with Azure Monitor?
- New risk scoring framework in the Splunk App for Enterprise Security -- thoughts?
- Splunk vs. Elastic Stack
Kiwi syslog for SolarWinds must be seen as a patch for SolarWinds Orion NPM. SolarWinds will release a LOG management module for the Orion NPM platform but this product is in an early state of log collecting, searching and filtering. Splunk can be a good tactical solution to filter out and forward important events to SolarWinds Orion NPM