No more typing reviews! Try our Samantha, our new voice AI agent.
Senior Network Engineer at a government with 5,001-10,000 employees
Real User
Feb 16, 2022
Capable and flexible; you can use it to gather syslog messages from any type of system.
Pros and Cons
  • "You can use it to gather syslog messages from anything."
  • "It's the best solution on the market."
  • "It would be nice if they had a wizard to construct searches, including more complex searches that include math or statistics."
  • "It would be nice if they had a wizard to construct searches, including more complex searches that include math or statistics."

What is our primary use case?

I work for a government agency and we use Splunk to monitor our Cisco equipment. I'm a senior network engineer and we are customers of Splunk

What is most valuable?

This is a very capable and flexible solution. It's based on Linux and even Windows installations use the Linux file structure. You can use it to gather syslog messages from anything; jet engines, fin-tech financial institutions, banking, regular enterprise, etc. You can gather the messages from network equipment, elevators, anything you can think of that generates syslog, and Splunk it. They also have a good API so you can write your own code to talk to it or interact with it. The solution has a lot of applications that people have written. It's the best solution on the market. 

What needs improvement?

It would be nice if they had a wizard to construct searches, including more complex searches that include math or statistics. 

For how long have I used the solution?

I've been using this solution for 10 years. 

Buyer's Guide
Splunk Enterprise Security
May 2026
Learn what your peers think about Splunk Enterprise Security. Get advice and tips from experienced pros sharing their opinions. Updated: May 2026.
896,387 professionals have used our research since 2012.

What do I think about the stability of the solution?

The product runs on Linux so it's very stable. It's important to have a well-run SAN environment to store the data. 

What do I think about the scalability of the solution?

The solution can be scaled up to any size of enterprise or agency. I have heard of Splunk installations of over 100 terabytes of licensing.

Which solution did I use previously and why did I switch?

We used Logrhythm previously but it was not a good fit for our environment. That is why we switched to Splunk.

How was the initial setup?

The initial setup is fairly complex. There's a certain architecture that Splunk utilizes to handle its indexing and it also depends on the size of your deployment. If you have a relatively low amount of gigabytes per day, deployment is simple. And of course it scales to terabyte, so if you have a terabytes installation, there are a lot of additional services that need to be implemented such as licensing servers and clustering. We sometimes configure syslog NG servers to front end the date before it ends up at an indexer. If it's a large terabyte installation, you definitely want to use professional services.

What about the implementation team?

This was implemented through a combination of in house and vendor developers.

What was our ROI?

n/a

What's my experience with pricing, setup cost, and licensing?

Splunk charges on the basis of gigabytes of incoming log messages per day. Also I would recommend that funds be set aside for Splunk training and certification.

What other advice do I have?

There is a large number of options for training and certification. The more training you have the more useful Splunk becomes. However, right out the gate you can do useful searches due to the search bar design.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
AKHIL Kumar Guttapalli - PeerSpot reviewer
Product Sales Specialist(Asst.Manager) at Redington India Limited
Real User
Feb 10, 2022
Knowledgeable support, reliable, and useful reports
Pros and Cons
  • "Splunk is stable, and this is why many customers want it."
  • "The most valuable feature of Splunk is security information and event management (SIEM), and the solution is easy to use, has useful reports, and a good interface."

    What is most valuable?

    The most valuable feature of Splunk is security information and event management(SIEM). Additionally, the solution is easy to use, has useful reports, and good interface.

    For how long have I used the solution?

    I have used Splunk within the past 12 months.

    What do I think about the stability of the solution?

    Splunk is stable, and this is why many customers want it.

    What do I think about the scalability of the solution?

    The scalability of Splunk is good. Customers can purchase 100 GB now and if they wanted more, they can immediately add an additional 100. The customer will have to only pay for additional licenses.

    How are customer service and support?

    I hear that customers usually have support on time from the Splunk team. Generally, they are satisfied with the response they receive from Splunk.

    How was the initial setup?

    The total time of the implementation depends upon the customer's requirement. The factors that affect the implementation time are the type of use case, the environment of deployment, one location or multiple locations, number of devices, and applications. The requirements play a large role in the time it might take for implementation. You cannot simply explain in one week or one month.

    What about the implementation team?

    There are two to three people required for the implementation of Splunk.

    What's my experience with pricing, setup cost, and licensing?

    The price of this solution is expensive. However, it has great features. If you want a great solution you need to pay a price matching the features.

    What other advice do I have?

    If this solution matches the needs of your use case then I would give it a try.

    I rate Splunk a nine out of ten.

    Which deployment model are you using for this solution?

    On-premises
    Disclosure: My company does not have a business relationship with this vendor other than being a customer.
    PeerSpot user
    Buyer's Guide
    Splunk Enterprise Security
    May 2026
    Learn what your peers think about Splunk Enterprise Security. Get advice and tips from experienced pros sharing their opinions. Updated: May 2026.
    896,387 professionals have used our research since 2012.
    Sontas Jiamsripong - PeerSpot reviewer
    Account Presale at a tech services company with 1,001-5,000 employees
    Real User
    Jan 23, 2022
    A flexible solution
    Pros and Cons
    • "Splunk is quite flexible for our customers. Splunk does not filter from a specific lock, you can define it later."
    • "Splunk is powerful when sorting huge amounts of data."
    • "I would like Splunk to add more integration. QRadar has many indications with more products than Splunk."
    • "The initial setup of Splunk is complex. It requires a lot of equipment and uploads."

    What is our primary use case?

    The project we are working on with Splunk is short as the customer has given us two months to implement. My company is a Splunk partner.

    What is most valuable?

    Splunk is quite flexible for our customers. Splunk does not filter from a specific lock, you can define it later.

    What needs improvement?

    I would like Splunk to add more integration. QRadar has many indications with more products than Splunk.

    For how long have I used the solution?

    I have been working with Splunk for three months.

    What do I think about the scalability of the solution?

    Splunk is quite good if you want to scale it.

    Which solution did I use previously and why did I switch?

    My client has some pain points with QRadar and does not feel the kilogram function is accurate. Other features do not match with the customer behavior as well. They want to replace QRadar with Splunk because they are familiar with this solution.

    How was the initial setup?

    The initial setup of Splunk is complex. It requires a lot of equipment and uploads.

    What about the implementation team?

    My company provides the implementation and maintenance services to our customers.

    What's my experience with pricing, setup cost, and licensing?

    Splunk licensing requires you to purchase licenses for any feature per user. For example, if you need UEBA, it is difficult to propose in the project. QRadar has a free upcharge for UEBA. Customers cannot calculate the additional costs based on gigabytes per day because they can not forecast the future.

    What other advice do I have?

    Due to the cost of Splunk, I recommend it for larger companies. Splunk is powerful when sorting huge amounts of data. 

    Implementation of Splunk takes preparation. It requires a lot of resources and needs the infrastructure to support the project.

    I would rate the solution an 8 out of 10.

    Which deployment model are you using for this solution?

    On-premises
    Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
    PeerSpot user
    reviewer1762323 - PeerSpot reviewer
    Cybersecurity Senior Manager at a tech services company with 10,001+ employees
    Real User
    Jan 19, 2022
    Simple data file updates, good support, and useful dashboards
    Pros and Cons
    • "The connections to the database are very good and updating the data files is simple to do. The dashboards are useful and user-friendly."
    • "The connections to the database are very good and updating the data files is simple to do, and the dashboards are useful and user-friendly."
    • "We had some connections issues with the solution at the beginning."
    • "We had some connections issues with the solution at the beginning."

    What is most valuable?

    The connections to the database are very good and updating the data files is simple to do. The dashboards are useful and user-friendly.

    What needs improvement?

    We had some connections issues with the solution at the beginning.

    For how long have I used the solution?

    I have used Splunk within the last 12 months.

    What do I think about the stability of the solution?

    Splunk is a highly stable solution.

    What do I think about the scalability of the solution?

    The scalability is good.

    We have approximately 50 users using this solution in my organization.

    How are customer service and support?

    I am satisfied with the support from Splunk.

    Which solution did I use previously and why did I switch?

    We were previously using Excel.

    What about the implementation team?

    We used a consultant for the implementation of the solution. The full process took approximately one week.

    We had a big problem with communication sometimes during the implementation. Some files in our network were a little difficult to receive. This was our fault because of some of our firewall configurations.

    We have a five-person maintenance team that works on this solution.

    What other advice do I have?

    I rate Splunk an eight out of ten.

    Which deployment model are you using for this solution?

    Hybrid Cloud
    Disclosure: My company does not have a business relationship with this vendor other than being a customer.
    PeerSpot user
    PeerSpot user
    CTA\Owner at UCSolutions
    Real User
    Jan 13, 2022
    Easy to use and simple to set up with reasonable pricing
    Pros and Cons
    • "The SIEM is the most valuable feature of the product."
    • "We've seen quite extensive ROI, however, it's more of a qualitative assessment and I don't have numbers to share."
    • "The documentation is in definite need of improvement."
    • "The documentation is in definite need of improvement."

    What is our primary use case?

    I need the product for SIEM, Security Identity Event Management. I also need it for security operations, automated response, as well as mapping adjusting of security components as well. It helps us with how best to look at various events, and orchestrate between various different hyper-scalers.

    How has it helped my organization?

    The solution has made us more secure and has allowed for more definable mapping.

    What is most valuable?

    The SIEM is the most valuable feature of the product.

    Having a better integration method and then ingesting and mapping the information have been somewhat easier than some of the other tools that I've used previously (other than QRadar and Rapid7).

    The initial setup is pretty simple.

    The solution is scalable.

    Stability has been quite good. 

    The pricing is pretty decent.

    What needs improvement?

    The documentation is in definite need of improvement. 

    There are pieces of it that are somewhat just daunting and there should be better orchestration and automation. 

    I've done some automation with it, with Terraform, and also with some other sources. If it wasn't so proprietary, that would be ideal.

    I'd like to have it so that Splunk integrates better with Terraform and Python.

    For how long have I used the solution?

    I've used the solution for eight years. I've used it for quite a while. 

    What do I think about the stability of the solution?

    Splunk is probably the best brand in terms of stability. I'd rate its reliability at a four out of five. There aren't bugs or glitches. It doesn't crash or freeze.

    What do I think about the scalability of the solution?

    The scalability is great. I'd give it a score of four out of five. If a company needs to expand, it can do so. 

    We have 450 people in our organization that use the product. We've also done this for clients that needed access for over 200,000 people.

    We use the solution extensively and likely will increase usage.

    How are customer service and support?

    The support is okay, however, there are a couple of things that they couldn't figure out and they couldn't help me with automation or stuff like that. It could have been better from there, however, it's not that bad. 

    Which solution did I use previously and why did I switch?

    I've previously used QRadar and it wasn't ideal.

    There were certain times I integrated with other solutions too.

    How was the initial setup?

    The initial implementation is pretty simple and straightforward. It's not too complex. I'd rate the experience at an eight out of ten.

    The initial deployment took us about two weeks or so.

    The amount of personnel you need for deployment and maintenance tasks depends on the size of the deployment. Typically, it's just one or two people. That said, it needs to be proportionate to certain sizes. Usually, the staff is from procurement or provisioning.

    What about the implementation team?

    I handled the implementation myself. I didn't need any outside assistance from any integrators. I'm a consultant myself.  

    What was our ROI?

    We've seen quite extensive ROI, however, it's more of a qualitative assessment and I don't have numbers to share. It works well and customers are happy. That's what counts. 

    What's my experience with pricing, setup cost, and licensing?

    It's a little bit more expensive than some of the other tools. It's not as expensive as QRadar. That said, it's more expensive than LogRhythm or Sentinel.

    There aren't really other fees beyond the standard costs of licensing. 

    Which other solutions did I evaluate?

    I evaluated other things. I also integrated with other solutions too. I decided to go with Splunk due to the fact that it worked well.

    What other advice do I have?

    I'm a consultant. I'm also a customer and use it myself. 

    We use multiple deployment models, including public and private clouds. 

    We typically use the latest version of the solution. 

    I'd advise potential new users to get a proper plan. They should have a good partner or someone that can help them and quickly map and orchestrate.

    I'd rate the solution at a ten out of ten.

    Which deployment model are you using for this solution?

    Public Cloud
    Disclosure: My company does not have a business relationship with this vendor other than being a customer.
    PeerSpot user
    project manager at ManTech International Corporation
    Real User
    Jan 9, 2022
    Integrates with our VMware environment for infrastructure alerting and monitoring, and ingests logs from many different products in our environment
    Pros and Cons
    • "The ability to ingest different log types from many different products in our environment is most valuable."
    • "It is definitely the best tool I've ever used, but nothing is perfect."
    • "The biggest problem is data compression. Splunk is an outstanding product, but it is a resource hog. There should be better data compression for being able to maintain our data repositories. We end up having to buy lots of additional storage just to house our Splunk data. This is my only complaint about it."
    • "The biggest problem is data compression. Splunk is an outstanding product, but it is a resource hog."

    What is our primary use case?

    We are using it for information assurance, system alerting, and compliance. We are using its latest version.

    How has it helped my organization?

    It integrates into our VMware environment and provides infrastructure alerting and monitoring.

    What is most valuable?

    The ability to ingest different log types from many different products in our environment is most valuable.

    It seems to have everything in terms of features. Every time I think of something, I go out to their site, and I can pretty much find it.

    What needs improvement?

    The biggest problem is data compression. Splunk is an outstanding product, but it is a resource hog. There should be better data compression for being able to maintain our data repositories. We end up having to buy lots of additional storage just to house our Splunk data. This is my only complaint about it.

    For how long have I used the solution?

    I have been using this solution for about five years.

    What do I think about the stability of the solution?

    It is excellent in terms of performance and reliability.

    What do I think about the scalability of the solution?

    Its scalability is excellent. Its users are mostly on the backside. I know there are a lot of opportunities to allow developers and engineers to access Splunk for doing different things, but we use it purely for information assurance and system monitoring. So, our engineers and IA professionals are the only ones who access Splunk. We have a couple of them, but it supports thousands of users.

    We started with Splunk Light, and now, we're using Splunk Enterprise across most of our projects. It is being used extensively. It is our primary SIEM product. I'm sure its usage will increase, but that's managed at a much higher level. The company has an agreement with Splunk on how our licensing model is established.

    How are customer service and support?

    Their support is great. I've talked to them many times.

    Which solution did I use previously and why did I switch?

    We used InTrust. We switched to Splunk because of its flexibility and capability.

    How was the initial setup?

    Its initial configuration is pretty straightforward. Their repository for information and help is really good, which makes it pretty straightforward. You can just go out to their site and do a search for any question. Usually, someone else would have experienced the same issue.

    It took us hours. We obviously expanded it as we were building the environment because we did it from scratch, but it only took hours to get it up and running and configured to do ingestion. We then deployed more forwarders and tweaked it as we went along.

    What about the implementation team?

    It was implemented in-house. Its maintenance is pretty lightweight, and I take care of it. I have a couple of other team members to help make changes. We have engineers who are available for adding capacity. We have a team of six or seven people to support our Splunk Enterprise.

    What's my experience with pricing, setup cost, and licensing?

    It is expensive. I used to buy it early on, but then they combined it into a higher-up organization. They buy it for multiple systems now. Last time, I paid around 60K for it.

    There is just the licensing fee. That's all.

    What other advice do I have?

    I would advise making sure that you incorporate enough storage and processing in order to properly support the environment.

    I would rate it an eight out of 10. It is definitely the best tool I've ever used, but nothing is perfect. They could do a little bit better on data compression and system resource management, but outside of that, it is an excellent product.

    Which deployment model are you using for this solution?

    On-premises
    Disclosure: My company does not have a business relationship with this vendor other than being a customer.
    PeerSpot user
    Regional Head at a tech services company with 51-200 employees
    Real User
    Dec 1, 2021
    Good technical support, scalable, and very stable
    Pros and Cons
    • "It's basically one of the best SIEM products on the market."
    • "It's basically one of the best SIEM products on the market."
    • "You do need a lot of training and certification with this product."
    • "You do need a lot of training and certification with this product."

    What is our primary use case?

    The solution is primarily a SIEM tool and it basically helps companies with security.

    What is most valuable?

    It's basically one of the best SIEM products on the market.

    The scalability is great.

    We have found the solution to be stable. 

    Technical support is helpful. They respond in a timely manner. 

    What needs improvement?

    I'd like to see more documentation on the product.

    The initial setup is not straightforward.

    You do need a lot of training and certification with this product. Other than that, it's pretty good.

    For how long have I used the solution?

    I've been dealing with the solution for about three years. It's been a while. 

    What do I think about the stability of the solution?

    The stability of the product is very good. The performance is reliable. There are no bugs or glitches. it doesn't crash or freeze. We've had no issues. 

    What do I think about the scalability of the solution?

    The scalability of the solution is great. If a company needs to expand it, it can do so. It's not a problem.

    We have about nine customers that are using Splunk.

    How are customer service and support?

    I've dealt with technical support and it's pretty good. They are helpful. I find them responsive. 

    How was the initial setup?

    The initial setup is not straightforward. It depends upon the IT infrastructure that the customer has. If they have a lot of security solutions, such as DLP and other security solutions, then it is more complicated. The more you have the more complicated it gets.

    The deployment of Splunk takes about three weeks.

    We have six or seven team members within our organization that can handle deployment and maintenance tasks. 

    What about the implementation team?

    I handled the implementation myself. It was done in-house. 

    What's my experience with pricing, setup cost, and licensing?

    Splunk requires a paid license. There's no free option. Customers have to pay for the license, implementation, support - everything.

    What other advice do I have?

    The solution can be deployed both on-premises and on the cloud. 

    I'd rate the solution at a nine out of ten. We've been very happy with the product.

    I would recommend the solution. It really is the best.

    Which deployment model are you using for this solution?

    Public Cloud
    Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
    PeerSpot user
    it_user1729647 - PeerSpot reviewer
    Senior security consultant at a comms service provider with 51-200 employees
    Consultant
    Nov 29, 2021
    Threat hunting is a key feature for us
    Pros and Cons
    • "One of the most valuable features is threat hunting. We can do threat hunting and identify if there is any malicious activity happening within our environment, which is a key feature for us."
    • "This solution is excellent from a performance and stability perspective."
    • "Splunk could be improved by reducing the cost. The cost is one of the biggest challenges for us in keeping to our production requirements."
    • "Splunk could be improved by reducing the cost. The cost is one of the biggest challenges for us in keeping to our production requirements."

    What is our primary use case?

    Our initial use case was for security investigation, with the intention of creating some use cases. We ended up adding operational aspects, monitoring certain operational activities, such as high CPU utilization or any other applicational basis. 

    This is obviously a cloud solution, but it does have some presence on-premises as well, so it's hybrid. 

    What is most valuable?

    One of the most valuable features is threat hunting. We can do threat hunting and identify if there is any malicious activity happening within our environment, which is a key feature for us. 

    What needs improvement?

    Splunk could be improved by reducing the cost. The cost is one of the biggest challenges for us in keeping to our production requirements. 

    As for additional features, I think they need to refine their AI capability. I know that everyone is talking about artificial intelligence and threat hunting, so I guess one of the key requirements for us is for the solution to automatically provide us some kind of indication and then mitigate any risk. So automation should be a feature. 

    For how long have I used the solution?

    I have been using Splunk for two years. 

    What do I think about the stability of the solution?

    This solution is excellent from a performance and stability perspective. There's very minimal maintenance required. Basically the only aspect we need to maintain is the one we have on-prem. So patching up everything and making sure it has the required updates. 

    What do I think about the scalability of the solution?

    There are no issues at all in terms of scalability, since this is a cloud-based solution. There are around 25 to 30 users in my company accessing Splunk. 

    How are customer service and support?

    Splunk's support is good. The process was smooth and they provided sufficient support, so there was no need to escalate anything. Also, they provide training on a regular basis, which is good. 

    Which solution did I use previously and why did I switch?

    I have never worked with other similar products. I've worked for three companies, all of which use Splunk. 

    How was the initial setup?

    The initial setup was very smooth. I think we got some support from the Splunk team. Since it's a cloud-based solution, it took us probably three or four weeks to actually start working. But deploying agents, configuration, refining, fine tuning, and other ongoing activities went on for about a month. 

    What about the implementation team?

    We implemented through an in-house team with some support from the Splunk team. It was a very smooth process, from our perspective. 

    What's my experience with pricing, setup cost, and licensing?

    This solution is costly. Splunk is obviously a great product, but you should only choose this product if you need all the features provided. Otherwise, if you don't need all the features to meet your requirements, there are probably other products that will be more cost-effective. It's cost versus the functionality requirement. 

    Which other solutions did I evaluate?

    I also evaluated IBM QRadar and LogRhythm NextGen SIEM

    What other advice do I have?

    I work in security architectures, not operations, so I don't actually work with Splunk on a regular basis, but the team that does is working on threat hunting and incident management. 

    I rate Splunk an eight out of ten. 

    Which deployment model are you using for this solution?

    Hybrid Cloud

    If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

    Other
    Disclosure: My company does not have a business relationship with this vendor other than being a customer.
    PeerSpot user
    Buyer's Guide
    Download our free Splunk Enterprise Security Report and get advice and tips from experienced pros sharing their opinions.
    Updated: May 2026
    Buyer's Guide
    Download our free Splunk Enterprise Security Report and get advice and tips from experienced pros sharing their opinions.