No more typing reviews! Try our Samantha, our new voice AI agent.
reviewer2500056 - PeerSpot reviewer
Cyber security analyst at a manufacturing company with 10,001+ employees
Real User
Jul 8, 2024
Provides threat intelligence correlations and reduces lead time for identifying risks and threats
Pros and Cons
  • "The solution's most valuable feature is threat intelligence correlations."
  • "I'd love to see more integrations, which is one of the primary points of the key node with Splunk Enterprise Security."

What is our primary use case?

We use Splunk Enterprise Security for insider risk and security operations centers.

How has it helped my organization?

Splunk Enterprise Security primarily reduces our lead time for identifying risks and threats. Since a lot of the work is being outsourced or we depend on those new threat intelligence feeds, we're able to identify and triage them quicker. So, it leads to a quicker incident response.

What is most valuable?

The solution's most valuable feature is threat intelligence correlations. It's too hard to stay up-to-date on all the different data feeds yourself. So, having a tool that does it for you is very beneficial.

Splunk Enterprise Security has increased our alert volume because we now have new data to work with, and we're writing more alerts. We don't use the solution a lot for observability. Usually, our primary use case for Splunk Enterprise Security is cybersecurity.

It is extremely important to our organization that Splunk Enterprise Security provides end-to-end visibility into our environment. That's the primary reason we use it. We want the ability to do everything from one tool without having to trash back and forth and take that precious time.

Splunk Enterprise Security has helped reduce our mean time to resolve. We're at least twice as efficient with Splunk Enterprise Security at identifying risk, following up, tracing it throughout the chain, and resolving it. We still have various toolings, but over time, the goal is to nest everything into Splunk Enterprise Security to make it cohesive from end to end.

What needs improvement?

I'd love to see more integrations, which is one of the primary points of the key node with Splunk Enterprise Security. I would also like to see more admin capability to enable the health of Splunk Enterprise Security because, a lot of times, it's difficult to know when and why things are failing, especially for on-premises customers.

Splunk Cloud is a little clearer because it has more integrated support. For on-premises, it feels like sometimes you have to guess and then hope for the best. Troubleshooting some things related to Splunk Enterprise Security takes a lot of time.

Buyer's Guide
Splunk Enterprise Security
August 2026
Learn what your peers think about Splunk Enterprise Security. Get advice and tips from experienced pros sharing their opinions. Updated: August 2026.
913,630 professionals have used our research since 2012.

For how long have I used the solution?

I have been using Splunk Enterprise Security for five years.

What do I think about the scalability of the solution?

The solution's clustering is great, but it could have easier containerization where it's more dynamic, and you can spin up and scale down as needed. Right now, Splunk is a very large expense for us as far as our cloud environment is concerned. Anything we can do to cut costs would be great.

Right now, we run the servers 24/7 and never change the size unless they're underpowered. We're spending a lot of money on off-hours to keep it alive, which is not ideal.

How are customer service and support?

We've got a lot of experience on our team solving Splunk, but the few times we used Splunk's technical support, we found them to be very effective and efficient. Occasionally, we'll forget to respond to them, and they'll follow up with us, which is usually the opposite of what you see. So, I've got nothing but good things to say about Splunk support.

How was the initial setup?

The solution's deployment was difficult because we were going through admin changes right as we were installing it. It took three admins over the course of five years to get it set up. I think if we had one dedicated admin from the start and kept them on the job until the job was done, we wouldn't have had nearly as much trouble.

What about the implementation team?

We used a reseller to implement the solution.

What was our ROI?

We have seen a return on investment with the solution.

What other advice do I have?

Splunk Enterprise Security is really strong, capable, and great at what it does. There are obvious areas of improvement, but it looks like Splunk has already identified them and is working on road maps to enhance SOAR integration and AI digital assistance for Splunk Enterprise Security. Once those are fully implemented, the product will further improve.

Overall, I rate the solution an eight out of ten.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
PRAKAS RAJA - PeerSpot reviewer
Associate at a computer software company with 11-50 employees
Real User
Jun 2, 2024
Improves the incident response time, but data ingestion from IoT sources can be better
Pros and Cons
  • "Splunk Enterprise Security has helped speed up our security investigations."
  • "They can improve their support teams. They can also improve their capability of ingesting data from different IoT sources."

What is our primary use case?

I implement Splunk products in customer environments. I am not an end user. I implement the product on customers' cloud stack.

I have full experience in the implementation part. I know the end-to-end configurations in Splunk. I know how to configure it, index the data, and then how to use it to get some alerts.

How has it helped my organization?

Splunk Enterprise Security has improved our incident response time quite a bit. What we usually do in the customer environment is to configure it with their ticket management tools. It creates alerts and pushes the alerts to the ticket management tool so that their analysts are able to view the tickets and then do an instant investigation. It provides a good solution for instant response.

Splunk Enterprise Security has complete information about the entities and the users in the organization. In the case of any alert, we do not have to manually verify the computer name and its owner name. In the alert itself, Splunk Enterprise Security populates the necessary data that we need. It is a great feature of Splunk Enterprise Security.

We have created dashboards related to critical alerts. For example, we have a dashboard for the inbound and outbound traffic flow of firewalls. We use a few other products or IT systems to monitor the CPU and memory utilization. We are also able to integrate web applications, Kubernetes, Linux systems, Windows systems, etc. We integrate whatever data sources are available.

We monitor most of the cloud environments with Splunk Enterprise Security. We have different cloud providers such as AWS, Azure, and GCP. We have separate add-ons and apps for them. It is quite easy to integrate those. Third-party developers are also able to develop their apps and publish them at Splunkbase. We can utilize them for visualization of the data that we are interested in from different sources.

We configure most of the frameworks available inside Splunk Enterprise Security such as threat intelligence, identity management, and risk management. Whenever alerts are triggered, these frameworks do the correlation and give us visualization over the dashboards, which improves the incident response time.

There is something that we can configure to reduce false positives. If any alert is triggered, it checks against various threat IOCs, such as IPs, URLs, domains, emails, file hashes, etc. If it matches any of the threats, we can take it forward.

What is most valuable?

Splunk Enterprise Security has helped speed up our security investigations.

What needs improvement?

They can also improve their capability of ingesting data from different IoT sources. It supports IoT data, but they can add some additional apps or add-ons to easily integrate the IoT devices.

For how long have I used the solution?

I have been using Splunk Enterprise Security for the past two years.

What do I think about the stability of the solution?

It is a stable product as compared to other premium solutions. I do work with other premium solutions. Splunk Enterprise security is a more stable product.

What do I think about the scalability of the solution?

It scales very easily. We can have as much data as we want. We have customers who are ingesting more than 400 TB of data per day, so it does not matter how much data you have.

We have customers that have the Splunk application deployed in a multi-cluster environment.

How are customer service and support?

Their support is good, but they can have a customization team to help us with any customizations. I would rate them an eight out of ten.

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

This is my first tool.

How was the initial setup?

We have deployed it on-prem and on the cloud. Its deployment is straightforward. Any Splunk engineer can do it.

It requires maintenance in terms of upgrades. Apart from that, it does not need any maintenance. There is a one-hour or two-hour maintenance window to upgrade the apps.

What other advice do I have?

I would recommend Splunk Enterprise Security. Its frameworks make it stand out among other tools. 

It is a great solution with multiple in-built frameworks. With other solutions, there can be limitations in configuring different frameworks within the same solution.

Overall, I would rate Splunk Enterprise Security a seven out of ten.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Buyer's Guide
Splunk Enterprise Security
August 2026
Learn what your peers think about Splunk Enterprise Security. Get advice and tips from experienced pros sharing their opinions. Updated: August 2026.
913,630 professionals have used our research since 2012.
reviewer2398662 - PeerSpot reviewer
CTO at a computer software company with 11-50 employees
Real User
May 21, 2024
Reduces alert volume and remediation time, but pricing and learning curve for ML should be better
Pros and Cons
  • "We can extract the metrics we want on the dashboards. We are able to react to the incidents."
  • "There is a learning curve in order to start using machine learning. We have been trying to do it for three years, and we have not managed anything. It is too complex."

What is our primary use case?

We are using Splunk Enterprise Security for collecting and analyzing logs. We are keeping up with the SLAs with Splunk Enterprise Security.

How has it helped my organization?

Splunk Enterprise Security has helped reduce our alert volume. There is about 30% reduction.

Splunk Enterprise Security improves our organization’s ability to ingest and normalize data, but it requires lots of effort from our side. Splunk Enterprise Security can do that, but we also need to put effort into it. It is good enough to achieve that.

Splunk Enterprise Security has helped reduce our mean time to resolve. We have seen a reduction because doing this manually through queries is crazy. It helps to find out the root cause and things like that. It is helpful. 

We have an on-prem environment. Our information security team is using the data security features. Its security features are satisfactory.

What is most valuable?

It is pretty good. We can extract the metrics we want on the dashboards. We are able to react to the incidents. We are also able to monitor the service. In addition to the incident response, we can also do investigations, fraud detection, and other things like that.

What needs improvement?

We have this issue of data versus pricing. Its pricing can be better. There should also be a more flexible licensing model.

There is a learning curve in order to start using machine learning. We have been trying to do it for three years, and we have not managed anything. It is too complex.

Its ability to identify and solve problems in real-time could be better. We would like to have pattern recognition. There should be some kind of pre-made model to help detect something. For example, at the time of the incident investigation, there should be an option to ask questions, such as if anything changed. It is pretty hard to find out the patterns that are occurring currently because you have to have deep knowledge about your log content. There should be an option to ask a question like, "What has changed as compared to a week ago?" We should be able to specify a time frame and compare.

For how long have I used the solution?

We have been using Splunk altogether for probably five years.

What do I think about the stability of the solution?

It has not failed over the last year. There were no failures, so it is pretty good.

What do I think about the scalability of the solution?

Its scalability is quite good if you are willing to invest in the new design and do the manual work. You have to deploy new servers and things like that. In terms of architecture, it is scalable.

How are customer service and support?

Based on the few problems that we have had, I would rate them a seven out of ten. For an issue, we did not get the answer we needed within the timeframe we were expecting. They took more time, and some IT guys were disappointed. The experience varies from case to case.

How would you rate customer service and support?

Neutral

Which solution did I use previously and why did I switch?

We were not using any similar solution previously. We were only collecting logs through open-source means. We went for Splunk Enterprise Security because we needed visibility into the logs. It was the primary requirement.

We are also using Elasticsearch. We have two parallel systems.

Splunk Enterprise Security is better in terms of query language and the capability to do great searches, whereas Elasticsearch has a little bit less functionality. It is more complicated for end-users to use. However, Elasticsearch is better in terms of pricing because they do not charge based on the daily ingestion amount. You can put whatever amount into the system. Elasticsearch also has lots of additional logging capabilities. It has file beats and metrics beats capabilities, so you can use it more widely. You can also get end-to-end visibility because you can make integrity checks with it. It helps with IT operations as well. They can include these capabilities in Splunk Enterprise Security.

How was the initial setup?

Its deployment was not very complicated. It was easy.

The hard part comes after you have deployed it. You have to educate people to start using it and understand the relevant information in your logs. The configuration itself is pretty simple, but field extractions and tagging are complex.

What was our ROI?

We are just using it and doing our queries and dashboards. We have not been calculating the ROI. It has been quite easy. We invest and create our dashboards and reports. Sometimes, when a dashboard becomes too complex or too expensive, we start to think about alternatives. Other than that, we have not thought of ROI.

What's my experience with pricing, setup cost, and licensing?

The pricing can be better. We are already considering Elastic because Splunk is too expensive. 

You have to pay based on per-day ingestion. There should be a more flexible model for the use cases where one day you have a huge amount, and on other days, it is quite less.

What other advice do I have?

Splunk Enterprise Security provides end-to-end visibility into an environment, but it is not our use case currently.

Splunk Enterprise Security does not really provide the relevant context to help guide our investigations because, in our country, Splunk is not represented, so it is pretty hard to get the relevant information.

Overall, I would rate Splunk Enterprise Security a seven out of ten. Its pricing is not good, and the learning curve for machine learning is not good. However, the parts that are working are working very well.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
CISO at a manufacturing company with 1,001-5,000 employees
Real User
May 9, 2024
Provides a clear picture of the current status of any incidents
Pros and Cons
  • "The tool helps with advanced reports and keeps the system scalable and flexible. It provides a clear picture of the current status of any incidents. As a CISO, I see a lot of potential for future innovation, which is interesting. I've noticed better performance, especially with the reports."
  • "Splunk Enterprise Security can provide more details and help CISOs resolve vulnerability situations better. The reason is that the tools we choose for data analysis and log collection cannot collect all the data and logs. Splunk Enterprise Security should help me with this, but it cannot."

What is our primary use case?

I use the solution for data analysis and log collection. 

What is most valuable?

Splunk Enterprise Security helps with advanced reports and keeps the system scalable and flexible. It provides a clear picture of the current status of any incidents. As a CISO, I see a lot of potential for future innovation, which is interesting. I've noticed better performance, especially with the reports.

What needs improvement?

Splunk Enterprise Security can provide more details and help CISOs resolve vulnerability situations better. The reason is that the tools we choose for data analysis and log collection cannot collect all the data and logs. Splunk Enterprise Security should help me with this, but it cannot.

For how long have I used the solution?

I have been working with the product for four years. 

What do I think about the stability of the solution?

Splunk Enterprise Security's stability is very good. The system consistently performs well, and we don't encounter many issues. Ticketing problems are minimal, which is significant because it handles a lot of logs and data persistently without causing frustration.

How are customer service and support?

The tool's customer support is good. 

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

We chose Splunk Enterprise Security because it was simple and had better data analysis capabilities. 

What about the implementation team?

A reseller helped us with the deployment. 

What's my experience with pricing, setup cost, and licensing?

The tool's licensing is good and we haven't received any complaints from the team handling it. 

What other advice do I have?

I haven't used it for multi-cloud environments. As for on-premise, it's meeting my current needs quite well. When it comes to identifying and solving problems in real time, sometimes it's challenging to understand the situation, and generating reports can be difficult. But overall, it's good for monitoring activities like endpoint and authentication incidents and normalizing.

The solution has helped us reduce alerts by five to ten percent. It processes data and allows us to look back at incidents to see what happened and where they occurred.

I rate the overall product a nine out of ten. 

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
reviewer1339833 - PeerSpot reviewer
Project manager at a computer software company with 10,001+ employees
Real User
Dec 31, 2023
Excels in providing advanced threat detection, real-time monitoring and comprehensive security analytics
Pros and Cons
  • "The technical support is among the best in the market."

    What is our primary use case?

    We employed Splunk Enterprise Security for one of our projects. Integrating it into our environment involved opening network ports and making necessary connections.

    How has it helped my organization?

    We had the opportunity to assess visibility in various environments, including on-premises. On-premises visibility has proven to be both satisfactory and advantageous.

    What is most valuable?

    We use the threat intelligence management feature. 

    We have been considering implementing certain frameworks, such as MITRE ATT&CK or threat topology features.

    It contributes value by enhancing resilience, crucial for adopting a Security Information and Event Management solution. Site resilience is imperative for our organization, meeting a key security requirement.

    For how long have I used the solution?

    I have been working with it for three years.

    What do I think about the scalability of the solution?

    It provides good scalability capabilities.

    How are customer service and support?

    The technical support is among the best in the market. While we didn't have extensive interactions with the support team, we are satisfied with it. It offers support services locally in my country. I would rate it ten out of ten.

    How would you rate customer service and support?

    Positive

    How was the initial setup?

    The initial setup was straightforward.

    What about the implementation team?

    The integration and initial setup of Splunk were managed with the assistance of local support.

    What other advice do I have?

    Overall, I would rate it eight out of ten.

    Disclosure: My company does not have a business relationship with this vendor other than being a customer.
    PeerSpot user
    reviewer909678 - PeerSpot reviewer
    Systems Engineer at a consultancy with 201-500 employees
    Real User
    Oct 30, 2023
    Fine features, good monitoring, and reduces alert volume
    Pros and Cons
    • "We are using Microsoft 365 and we're using the Exchange Mail Service. It's good for monitoring that in particular."
    • "The setup time is quite long."

    What is most valuable?

    The features are fine; they aren't exceptional in any way.

    We are using Microsoft 365 and we're using the Exchange Mail Service. It's good for monitoring that in particular. 

    The visibility we get has been good. 

    Inside threat detection capabilities are good. 

    It's helped us to reduce our alert volume a little. I haven't properly calculated it fully so it's hard to lay out a percentage. 

    What needs improvement?

    We'd like to have customer service in Hong Kong. I tend to wait a while for their response. We'd like to have more best-practice rules and instructions on how to create a dashboard.

    I've only been using Splunk for two years. I make use of it to incorporate other solutions. I need to spend more time mastering Splunk. Sometimes it's a little bit difficult to use. I'd like to get more certificates, et cetera, and have spoken to their main office about that. It's got a high learning curve.

    It hasn't helped us speed up security investigations. 

    For how long have I used the solution?

    I've been using the solution for about two years. 

    What do I think about the stability of the solution?

    I've never had any issues with Splunk's stability.

    What do I think about the scalability of the solution?

    The solution does not lack scalability. 

    How are customer service and support?

    I haven't had any communication with Splunk's technical team.

    Which solution did I use previously and why did I switch?

    I did not previously use a different solution. 

    How was the initial setup?

    The setup time is quite long. To this point, I haven't deployed it to all servers and devices. I'm still in the process of deploying. 

    Which other solutions did I evaluate?

    I have not evaluated other options. 

    What other advice do I have?

    We are Splunk customers. 

    We do not use it in multiple environments. We just use it on-premises. 

    I'm not yet using the threat intelligence features. 

    We do not use the mission control feature. 

    I have not created any customized dashboards as of now. At some point, I will create one for, for example, Windows Security.

    I'm still in the process of mastering threat detection and XDR

    I'd rate the solution eight out of ten. I haven't used it for such a long time, so it's hard to give comprehensive details about the solution. 

    Which deployment model are you using for this solution?

    On-premises
    Disclosure: My company does not have a business relationship with this vendor other than being a customer.
    PeerSpot user
    Security Engineer
    Real User
    Sep 18, 2023
    Provides organizations with visibility and enables users to correlate data and generate alerts
    Pros and Cons
    • "The product provides visibility and enables us to correlate data and generate alerts."
    • "The product could be cheaper."

    What is our primary use case?

    I used Splunk ES when I worked for a retail company. I worked mainly in the security operations center. I have also worked in healthcare and federal spaces.

    How has it helped my organization?

    Splunk ES provided the organization with overall visibility.

    What is most valuable?

    Incident Review and correlation search are valuable features. These features help us create correlations and have good actions afterward. The product provides visibility and enables us to correlate data and generate alerts.

    What needs improvement?

    The product could be cheaper.

    For how long have I used the solution?

    I have been using the solution since 2014.

    What do I think about the stability of the solution?

    The tool is very stable. Once we set it up properly, it's reliable.

    What do I think about the scalability of the solution?

    The solution's scalability is good. When we started, we had two servers and two indexers. By the time I left, it was up to 11 or more. It's not very hard to add additional components.

    How are customer service and support?

    The support team is usually very receptive and answers quickly.

    How would you rate customer service and support?

    Positive

    How was the initial setup?

    The initial setup was easy because I had done it many times before.

    What other advice do I have?

    I used the solution until December last year. It was not very hard to monitor multiple cloud environments using the product because getting data into Splunk is not very hard. It also provides add-ons that we can use to pull data from other places.

    Splunk was the brain of the whole process in our organization's security operations center. Without Splunk, we wouldn't have had any way of seeing what was going on. The tool helped reduce our mean time to resolve. We got alerts faster and responded to them faster.

    The biggest value of the conference is the community. The conferences help me interact with people, get insights and up-to-date information, and also get opportunities to present my work. There's always room for change.

    Overall, I rate the tool a nine out of ten.

    Disclosure: My company does not have a business relationship with this vendor other than being a customer.
    PeerSpot user
    reviewer2239902 - PeerSpot reviewer
    Cyber Security at a financial services firm with 5,001-10,000 employees
    Real User
    Aug 20, 2023
    Integrates well, provides good visibility, and helps to identify things that can lead to a larger problem
    Pros and Cons
    • "Integration with the cloud is pretty important and good for us. We found the integration with a lot of tools, not all tools yet, valuable. It does make the transfer of data, log files, and other things easier for us."
    • "Its pricing is extremely high. There are other tools out in the market that are competitive. They do not necessarily have all the functionality, but they are competitive. The professional services we have used have been high as well in comparison to the market."

    What is our primary use case?

    At a high level, its use cases are related to security monitoring, log aggregation, and a little bit of analysis related to incidents or fraud.

    How has it helped my organization?

    Splunk Enterprise Security has created better visibility for us on the cybersecurity type of events and issues. We are still maturing, but where we have seen some growth is getting better data, knowing what data to look at, and how to understand that data.

    It has end-to-end visibility into our cloud-native environment. This is extremely important for us because of the type of business we do. We have a lot of PII data and a lot of compliance data on which we have to maintain very tight controls, so it is extremely important that we are able to put that in the cloud and monitor and watch our environment very closely.

    It has reduced our mean time to resolve, but we are still maturing. We have got a lot of maturing to do. We have got a lot of growing to do. We have also been limited on the staff to be able to get the full realization of what we can get out of it yet, so that is a place where we are continuing to grow.

    It has improved our business resilience. We have been able to identify things that could have presented a larger problem for us financially or legally through various events. We have been able to leverage the data there. We have been able to maintain that data and support that data. It does the job. It meets the needs.

    Splunk has not helped to predict problems in real time because we have not yet matured to that place, but we need to. Generally, it has been helpful, but we know that we have got a lot of growing up there. We still have not got everything identified and captured in the space we want to be able to do better analysis.

    Its ability to provide business resilience by empowering our staff is really high. Empowerment is great, but we have a resource problem, so we have not quite realized where we could be. 

    We monitor multi-cloud environments. We have three of them. It is difficult to monitor them currently with Splunk. We are living in a highly regulated stack and a very little regulated stack and the ability to get a single pane of glass for all of that is very difficult.

    What is most valuable?

    Integration with the cloud is pretty important and good for us. We found the integration with a lot of tools, not all tools yet, valuable. It does make the transfer of data, log files, and other things easier for us.

    What needs improvement?

    Its pricing is extremely high. There are other tools out in the market that are competitive. They do not necessarily have all the functionality, but they are competitive. The professional services we have used have been high as well in comparison to the market.

    In terms of scalability, it is hard to forecast where you are going. There is room to improve there.

    For how long have I used the solution?

    I have been using this solution for about five or six years.

    What do I think about the stability of the solution?

    I would rate it eight out of ten in terms of stability. Where there has been ambiguity for me is that I recently had system stability issues that were beyond my control. They were part of my solution, and I was not aware that Splunk was accountable for it. It got quickly resolved, but there was a gap there that created pain for my business.

    What do I think about the scalability of the solution?

    We have not had any issues. We also have not had any detriment, but it is hard to forecast based on where you are going from a business perspective, at least with the models and the account teams that I have been working with. There is room to improve there. 

    How are customer service and support?

    It has been a rocky road. I have been through a road where I have had limited to little engagement or support. I am on the cusp of a large turnaround, meeting with my client team and dialoguing through it. Based on the history, I would probably rate their sales support a four out of ten. Going forward, I would rate their sales support an eight out of ten. They are in the right direction. I would rate their technical support a nine out of ten.

    How would you rate customer service and support?

    Positive

    Which solution did I use previously and why did I switch?

    We have been using the same solution for five or six years. It was selected before I joined, so I do not know.

    How was the initial setup?

    I joined after it was implemented. What I am working on now is the technical depth. I am spending a lot of time with the teams there for direction strategy. Splunk has done a great job there, specifically in pulling the right resources to bear. I had executive briefings directly with executives today where we had an opportunity to talk about different components of our solutions and our stacks, and it has been very good.

    What was our ROI?

    We are in a growth state right now. We have seen an ROI, but anticipating any point in the future is a little difficult, so it is a mixed response. Our scale is not quite clearly defined to be able to put it to a metric or to tie it back to consumption use. There is a little bit of autonomy in there to over-adjust and still find that we can true-up in a better space. That has been good for us, but if you let that run away from you, then you start to get in trouble. 

    We have not seen any cost-efficiency. We have seen our usage and needs grow, so we have seen Splunk go up in cost for us. We have not quite realized any efficiencies yet. It is also indicative of our maturity model.

    What's my experience with pricing, setup cost, and licensing?

    The licensing is good, but the pricing absolutely needs some work. It is very high. One thing that they put in a contract, but they do not emphasize it enough is true-ups on usage based on the quarterly consumption. They do not follow that methodology. They let a customer use, use, and use, and then at some point, a true-up occurs, and it is a large cost. There is an opportunity to do a quarterly track type of true-ups as per the agreements out there. That would put them in a position where customers are able to plan on, forecast around, and work through volume adjustments that may occur in their environment. 

    The other place where Splunk could spend time is the scale-up and scale-down model. Scale-up is easy where you get more business, and it is easy to add more capacity, whether it is storage or SVUs, but when you need to scale down because of a change in a business, it does put customers in a position where they are locked in, and there is no way to maneuver around that. 

    Which other solutions did I evaluate?

    We do an evaluation annually. It is important for us to do a market comparison and make sure we are looking at options in our work. What makes Splunk Enterprise Security competitive is the variabilities that they bring to the table for the overall solution. It has things like APIs that you can tie into. There is also the bonus functionality of being able to do analytics there. User behavior analytics is important for us.

    What other advice do I have?

    I would rate Splunk Enterprise Security an eight out of ten.

    Disclosure: My company does not have a business relationship with this vendor other than being a customer.
    PeerSpot user
    reviewer2239911 - PeerSpot reviewer
    SOAR Developer at a media company with 10,001+ employees
    Real User
    Aug 13, 2023
    Reduces time to detect, improves uptime, and handles correlation search well
    Pros and Cons
    • "The correlation search functions that generate all the notables are valuable. That can get pretty complicated, and it handles that pretty well."
    • "Some of the search functions can be better. There has been a lot of talk at the conference about the update of SPL before each iteration. That will be a lot of help."

    What is our primary use case?

    We use it mostly to generate notables, and then we can use other tools, such as ticketing systems or other SOAR platforms, to investigate.

    How has it helped my organization?

    I was not around before we had Splunk Enterprise Security in our organization, so I do not know about the before and after, but I can tell it would be very painful to not have it. 

    It is pretty easy to monitor multiple cloud environments. All the logs from our cloud environments go to Splunk, and then we can search everything at once. It is pretty helpful.

    Splunk Enterprise Security has end-to-end visibility into our cloud-native environments. It is pretty important. Especially if you use it as your single source of truth, it is pretty invaluable that you have everything in there.

    It has reduced our mean time to detect, so inadvertently, it has also reduced our mean time to resolve. However, I do not have the metrics.

    Splunk Enterprise Security has definitely improved our organization’s business resilience. There are a lot of logs that help with monitoring and alerting and keeping the business up.

    It can help to predict, identify, and solve problems in real time. We do have some health alerts, and if they kick off, we might be able to fix something before it is really broken. In that sense, it is good.

    Splunk Enterprise Security has been pretty good in terms of providing business resilience by empowering our staff. Most of our users are security-focused, but having everybody with the ability to write their own searches or build upon what we already have for detection of the future things is pretty helpful.

    What is most valuable?

    The correlation search functions that generate all the notables are valuable. That can get pretty complicated, and it handles that pretty well.

    What needs improvement?

    Some of the search functions can be better. There has been a lot of talk at the conference about the update of SPL before each iteration. That will be a lot of help. 

    For how long have I used the solution?

    I have been using Splunk Enterprise Security for about two years.

    What do I think about the stability of the solution?

    It is pretty stable. We have not had any instances where Splunk just completely died. Its stability is good.

    What do I think about the scalability of the solution?

    It seems pretty scalable, especially considering how much data we ingest. It is a good tool.

    How are customer service and support?

    I have not interacted with them recently, but they are pretty good when I do need something from Splunk. I would rate them a ten out of ten. I have not had any issues with their support.

    How would you rate customer service and support?

    Positive

    Which solution did I use previously and why did I switch?

    We were probably using Elasticsearch.

    How was the initial setup?

    It was already implemented when I got here.

    What was our ROI?

    We have probably seen an ROI. We are in the security space, and there has definitely been improvement in uptime and the mean time to detect and respond to security alerts.

    Its time to value is pretty immediate. The more logs and the more standardization that we get into Splunk, the quicker that comes.

    What's my experience with pricing, setup cost, and licensing?

    Most people share the same thought that the ingestion rates can get pretty pricey. There is a lot of work we do to curate the data that we send to Splunk so that it is not too noisy or too expensive.

    What other advice do I have?

    Overall, I would rate Splunk Enterprise Security an eight out of ten. There are some cool things. A lot of the talks at this Splunk conference have touched on some of the gaps that Splunk is working to close, but it is a very solid tool. 

    Disclosure: My company does not have a business relationship with this vendor other than being a customer.
    PeerSpot user
    reviewer2239899 - PeerSpot reviewer
    Insider Thread Consultant at a manufacturing company with 10,001+ employees
    Consultant
    Aug 13, 2023
    A reliable and stable solution that helps detect internal threats and improves business resilience
    Pros and Cons
    • "The search lookups are useful."
    • "The product must improve insider threat detection."

    What is our primary use case?

    My use cases are very limited. I use the product mostly to detect internal threats like data exfiltration.

    What is most valuable?

    I am a basic user. The search lookups are useful.

    What needs improvement?

    The product must improve insider threat detection. Almost everything is outside in, but not inside out.

    For how long have I used the solution?

    I have been using the solution for four years.

    What do I think about the stability of the solution?

    The solution is very reliable. I like its stability. It always works.

    What do I think about the scalability of the solution?

    Sometimes, it takes time when we need additional information or something extra. However, the tool’s able to do it.

    How are customer service and support?

    I haven’t contacted the support team. I reach out to the internal expert. My searches and my requirements are very basic. The expert is great. He’s always able to help me and guide me.

    How would you rate customer service and support?

    Positive

    What was our ROI?

    We do see a return on investment. The product saves us time by automating reports and helping us see data.

    What other advice do I have?

    The solution helps reduce our mean time to resolve. It’s great to automate some tasks. I believe Splunk has helped improve our organization’s business resilience. We have become stronger in insider threats by just stopping things, being able to show what is leaving, and taking action on it. It's very useful when I try to identify events.

    When I started working in my organization, they were using Splunk. Overall, I rate the product a nine out of ten.

    Disclosure: My company does not have a business relationship with this vendor other than being a customer.
    PeerSpot user
    Buyer's Guide
    Download our free Splunk Enterprise Security Report and get advice and tips from experienced pros sharing their opinions.
    Updated: August 2026
    Buyer's Guide
    Download our free Splunk Enterprise Security Report and get advice and tips from experienced pros sharing their opinions.