- Log collection and analysis
- Reporting for the whole enterprise environment.
Network & Telco Lead at a energy/utilities company with 501-1,000 employees
Provides log collection and analysis
What is our primary use case?
How has it helped my organization?
Improved visibility.
What is most valuable?
Log search and alerting/reporting.
What needs improvement?
Code understanding requirement is complicated for most users.
Buyer's Guide
Splunk Enterprise Security
February 2025

Learn what your peers think about Splunk Enterprise Security. Get advice and tips from experienced pros sharing their opinions. Updated: February 2025.
838,713 professionals have used our research since 2012.
For how long have I used the solution?
One to three years.
Disclosure: I am a real user, and this review is based on my own experience and opinions.

Principal Consultant at a computer software company with 51-200 employees
Positive features include replication capabilities, software development kits, and its architecture
Pros and Cons
- "Positive features include replication capabilities, software development kits, and the architecture."
- "The solution could use a different licensing model."
- "An improved user interface along with multi-tenancy support would be beneficial."
What is our primary use case?
- Cybersecurity defense
- Web app monitoring
- VMware monitoring
How has it helped my organization?
- Troubleshooting
- Cyber defense
What is most valuable?
- Drill down
- Apps
- REST API
- Software development kits
- Architecture
- Replication capabilities
What needs improvement?
- Multi-tenancy support
- Improved user interface
- Non-proprietary search language
- Different licensing model
For how long have I used the solution?
One to three years.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Buyer's Guide
Splunk Enterprise Security
February 2025

Learn what your peers think about Splunk Enterprise Security. Get advice and tips from experienced pros sharing their opinions. Updated: February 2025.
838,713 professionals have used our research since 2012.
Java Technical Lead at a insurance company
The visibility is amazing with easy dashboard creation
Pros and Cons
- "It is easy to use in any environment."
- "The visibility is amazing with easy dashboard creation."
- "Not even Splunk's support guy, who came to our firm, could help with defining proper role management."
- "Make it easier to include roles and user controls, as it is horrible now."
What is our primary use case?
- Log monitoring and alerts
- Looking up information
- Dashboards for nice, fast information about various application servers.
How has it helped my organization?
- It is easier to find problems and exceptions.
- It is used by any factor in the firm.
- Easy dashboards creation.
- The visibility is amazing.
What is most valuable?
- Regex for fields creation is great.
- High availability
- Easy to use in any environment.
What needs improvement?
Make it easier to include roles and user controls, as it is horrible now.
For how long have I used the solution?
More than five years.
How is customer service and technical support?
Not even Splunk's support guy, who came to our firm, could help with defining proper role management.
What's my experience with pricing, setup cost, and licensing?
It is a pretty high cost solution, but if your organization has the funds, it can bring many benefits.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Vice Manager at a comms service provider with 10,001+ employees
Collects data from many sources. Has search, analysis, and visualization capabilities.
What is most valuable?
- Collects data from any source
- Powerful search, analysis, and visualization
- Easy to build system on any platform
- API and easily integrated search
- Action script
How has it helped my organization?
We have over 7000 devices in our network infrastructure for monitoring, maintenance, and performance assessment.
We achieve this by collecting data and applying the analysis.
For how long have I used the solution?
I have used this solution for one year.
What do I think about the scalability of the solution?
We did not encounter any issues with scalability. Everything is normal with no bugs.
How are customer service and technical support?
It’s easy to obtain support from Splunk for technical issues. We also have enough knowledge ourselves to apply fixes.
Which solution did I use previously and why did I switch?
We used to deploy Elastic Stack. The search language of Splunk is easier and friendlier than Elastic Stack. It has helped me to search quickly and easily. Based on the results, it’s easy to visualize and add results to a previously built, personal dashboard.
What's my experience with pricing, setup cost, and licensing?
Licensing is free. Pricing is based on usage.
Which other solutions did I evaluate?
We evaluated Elastic Stack and Sumo Logic.
What other advice do I have?
If you are an enterprise and you need the best service for critical business analysis, Splunk would be one of the best choices.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Sr. Program Manager at a consultancy with 51-200 employees
It is able to configure and integrate various solutions into one tool and provide actionable results. You need a dedicated developer.
What is most valuable?
- Can ingest data from various data sources.
- Is very useful for organizations who are attempting to meet compliance requirements.
- Is able to fully configure and integrate various solutions into one tool and provide actionable results.
How has it helped my organization?
My use of Splunk at my previous place of employment improved how we functioned.
For how long have I used the solution?
I have used Splunk for three years.
What do I think about the stability of the solution?
We didn’t have any stability issues.
What do I think about the scalability of the solution?
We didn’t have any scalability issues.
How are customer service and technical support?
During our use of Splunk, we had professional services assisting and not actual technical support. However, the professional services team was great.
Which solution did I use previously and why did I switch?
Our organization did not have an established SIEM tool.
How was the initial setup?
The initial setup is straightforward, depending on the level of implementation of the tool.
What's my experience with pricing, setup cost, and licensing?
Take into consideration the labor costs for a dedicated Splunk developer who can craft the required queries needed for each organization. Organizations usually have their own form of implementation of each tool.
Which other solutions did I evaluate?
We didn’t evaluate any alternatives.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Head of Service Integrity with 1,001-5,000 employees
It can probably do anything if you tweak it enough but it's not cheap.
Splunk is really good at log parsing events over time. It is quick to drill in and analyze and it is quick to build a presentation layer and automate reporting. I love it for problem analysis and event management however it is not a capacity management tool.
It can be a cm tool but not a good tool for projections etc. There are many tools that claim to be cm tools but they are usually expensive and miss the basic day to day challenges of capacity management. Eg: excluding backups from day peaks, removing outliers, forward trending, accepting data from any source. Start by getting your key data extracted from reliable sources and other tools.
The charting and presentation layer is impressive and quick. It can probably do anything if you tweak it enough. I would call it a very handy tool but probably not the tool. It is not that cheap either. I have used it personally to analyze big data as well as creating knowledge from some ordinary logging. I then created some pretty cool dashboards but they were more operational dashboards.
I don't think we could afford it as a capacity tool but we can use the data it simplified.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Telecom Tech at a university with 501-1,000 employees
Easy to configure with user-friendly alerts and good search functionality
Pros and Cons
- "We can easily configure things as required in relation to our use cases."
- "From the commercial point of view, they have to bring down their costs."
What is most valuable?
We enjoy the whole solution. It is meeting our requirements, especially the SIM solution.
The alerts are very user-friendly.
We can easily configure things as required in relation to our use cases.
The search functionality is good. It works like Google.
Onboarding is quite easy.
The scalability is good.
Product-wise, the performance is good.
What needs improvement?
From the commercial point of view, they have to bring down their costs. It's a bit pricey right now. The license is quite expensive.
Much like the SOAR platform, which has security, orchestration, and automation response, all of that should be part of the SIM solution itself. Currently, it is actually separated. We understand that we have to integrate a SIM with a SOAR platform, however, if they could combine these two products together, that would be ideal. It would make things easy to implement and make more automation possible to avoid false-positive alerts.
For how long have I used the solution?
We've been using the solution for the last four years. It's been a while.
What do I think about the stability of the solution?
The performance is good. It's stable. There are no bugs or glitches. It doesn't crash or freeze.
What do I think about the scalability of the solution?
The scalability of the solution is very good. If a company needs to expand, it can do so. It's easy.
What's my experience with pricing, setup cost, and licensing?
The solution can be expensive. It's not cheap.
What other advice do I have?
We are customers and end-users.
I'd rate the solution at a nine out of ten.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Técnico Judiciário at a government with 1,001-5,000 employees
Has the ability to log more logs than similar solutions and is more efficient than its competitors
Pros and Cons
- "It can log more logs than other solutions. It's a good way to troubleshoot problems."
- "Cybersecurity and infrastructure monitoring have room for improvement."
What is our primary use case?
We use it to do SIEM.
How has it helped my organization?
It can log more logs than other solutions. It's a good way to troubleshoot problems.
What is most valuable?
Splunk is a good solution to collect more events than other solutions. It's a good solution, for me, for this reason.
What needs improvement?
Cybersecurity and infrastructure monitoring have room for improvement.
For how long have I used the solution?
Less than one year.
How was the initial setup?
On a scale from one to ten I would rate the initial setup a seven for its complexity.
Which other solutions did I evaluate?
We also looked at AlienVault.
What other advice do I have?
I would rate it an eight out of ten.
Splunk is more efficient than other solutions but it's also more expensive.
Disclosure: I am a real user, and this review is based on my own experience and opinions.

Buyer's Guide
Download our free Splunk Enterprise Security Report and get advice and tips from experienced pros
sharing their opinions.
Updated: February 2025
Product Categories
Security Information and Event Management (SIEM) Log Management IT Operations AnalyticsPopular Comparisons
CrowdStrike Falcon
Microsoft Sentinel
IBM Security QRadar
Elastic Security
LogRhythm SIEM
Rapid7 InsightIDR
Sumo Logic Security
Fortinet FortiSIEM
Cortex XSIAM
AlienVault OSSIM
Securonix Next-Gen SIEM
Google Chronicle Suite
ManageEngine Log360
Buyer's Guide
Download our free Splunk Enterprise Security Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- Which would you recommend to your boss, IBM QRadar or Splunk?
- What are some of the best features and use-cases of Splunk?
- What SOC product do you recommend?
- Splunk as an Enterprise Class monitoring solution -- thoughts?
- What is the biggest difference between Dynatrace and Splunk?
- IBM QRadar is rated above competitors (McAfee, Splunk, LogRhythm) in Gartner's 2020 Magic Quandrant. Agree/Disagree?
- What are the advantages of ELK over Splunk?
- How does Splunk compare with Azure Monitor?
- New risk scoring framework in the Splunk App for Enterprise Security -- thoughts?
- Splunk vs. Elastic Stack