No more typing reviews! Try our Samantha, our new voice AI agent.
Harshal Pachpande - PeerSpot reviewer
Security Operation Consultant at SecurView
Real User
Top 5Leaderboard
Jun 12, 2026
Centralized monitoring has improved threat detection and reduced response times significantly
Pros and Cons
  • "Splunk is one of the most powerful SIEM platforms due to its flexibility, scalability, and advanced search capabilities as it uses the SPL language."
  • "Regarding Splunk Enterprise Security improvements, I think there should be licensing flexibility, including cost optimization for larger data volumes."

What is our primary use case?

I work with a couple of security solutions as well as devices. We have companies such as IBM, Splunk, QRadar, and many other SIEM solutions. I have worked with technologies such as DLP firewalls, proxies, file transfer solutions, and monitoring via security monitoring solutions. I am from a security analyst background.

Regarding Splunk Enterprise Security, we have both this product and Splunk as a SIEM solution with us.

Regarding Splunk's real-time capabilities, I have been using it from the monitoring perspective. We have been onboarding our customers over to the Splunk platform, gathering log details from the security monitoring perspective, and building alerts over the Splunk platform. It serves as a SIEM solution and SIEM provider by Splunk. Splunk is one of the most powerful SIEM platforms due to its flexibility, scalability, and advanced search capabilities as it uses the SPL language.

Splunk has interactive dashboards with cloud detection and cloud integration platform capabilities, having their own built dashboards which help to get all details with the VPC flows and AWS data, showing how much data has been thrown, what the detections and vulnerabilities are, and we can easily access that information.

What is most valuable?

From our security monitoring perspective, the most valuable features are the dashboards. Splunk has a wide variety of dashboards and widgets available so I can monitor ROI, MTTD, and MTTR, which are required to adhere to SLAs with respect to clients. Splunk Enterprise Security also has valuable features such as the Splunk Processing Language (SPL), enabling analysts to perform advanced threat hunting, incident investigation, and log analysis over massive data sets for longer durations in real time. It helps create custom detections and rapid investigation queries.

Splunk Phantom with automation setup helped us reduce MTTD and MTTR time significantly. The automation ensures that detections get automated and notified to customers quickly. We have been positively impacted with the Splunk setup regarding automation and detection.

Splunk detects threats in real-time using the Splunk Query Language and helps with reduced MTTD and provides higher efficiencies. AI facilitates generating investigation queries without manual crafting. Interactive dashboards assist with retention, allowing analysts to prioritize alerts and start investigations quickly. The SOAR helps automate alerts and manage ITSM incidents, reducing MTTD and MTTR. UBA adds visibility to abnormal behaviors of users, and we have detected impossible travel incidents in near real-time and contained unauthorized attempts.

What needs improvement?

Regarding Splunk Enterprise Security improvements, I think there should be licensing flexibility, including cost optimization for larger data volumes. Additionally, for new users, the SPL language can be difficult. Practical examples provided within the dashboards or the query sets of datasets should be presented.

Regarding the pricing aspect, more licensing flexibility is needed. Splunk provides licensing based on data volume. If data peaks are above average, extra charges can occur. This should be optimal based on averages.

For how long have I used the solution?

I have been using Splunk Enterprise Security for three years.

Buyer's Guide
Splunk Enterprise Security
August 2026
Learn what your peers think about Splunk Enterprise Security. Get advice and tips from experienced pros sharing their opinions. Updated: August 2026.
914,109 professionals have used our research since 2012.

What do I think about the stability of the solution?

Splunk Enterprise Security is stable. They have been pushing upgrades frequently, and this has remained stable as well.

How are customer service and support?

Splunk has continuously helped in terms of any issues or outages, helping us troubleshoot and having troubleshooting calls on a priority basis. They act according to their severity tags.

What was our ROI?

We have been having positive ROI. Time spent on log analysis and threat detection is less, and centralized multiple security tools have improved analyst efficiency. We have reduced our MTTD by about fifty percent with real-time detections.

What other advice do I have?

Splunk Enterprise Security has been helping us in terms of AI and detection quality. We have improved fine-tuning and reduced false positives. There have been no false positives in the environment, helping focus on true positives more.

Regarding risk-based volume, Splunk generates alerts based on risk and we focus on particular incidents. We have received positive feedback about RBAs helping with quick investigation and remediation. The Threat Topology helps with incident categorization and severity mapping. Minimal efforts bring content packs into production, requiring little fine-tuning.

I would rate this review a nine out of ten.

Which deployment model are you using for this solution?

Public Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
Last updated: Jun 12, 2026
Flag as inappropriate
PeerSpot user
reviewer2756187 - PeerSpot reviewer
Security Engineer at a financial services firm with 10,001+ employees
Real User
Top 20
Sep 15, 2025
Risk-based alerting has improved threat visibility and reduced false positives for our analysts
Pros and Cons
  • "The features of Splunk Enterprise Security that I prefer the most are risk-based alerting, the new Mission Control, and the integrations that are coming into place between Mission Control and Splunk SOAR."
  • "Splunk Enterprise Security could be improved by having better role-based access controls."

What is our primary use case?

My main use cases for Splunk Enterprise Security are detections and incident response.

How has it helped my organization?

An example of how these features have benefited my organization is that risk-based alerting has transformed our ability to reduce the number of detections that we have, streamline our observability into risks and threats in our environment, and really focus our analysts on actual real problems, helping to remove the noise and false positives to a large degree. It frees us up to do actual work.

What is most valuable?

The features of Splunk Enterprise Security that I prefer the most are risk-based alerting, the new Mission Control, and the integrations that are coming into place between Mission Control and Splunk SOAR.

What needs improvement?

Splunk Enterprise Security could be improved by having better role-based access controls. We need to be able to better control who can do what, which people can be allowed to take certain actions, run certain playbooks, or view specific items, and separate things between teams.

For how long have I used the solution?

I have been using Splunk Enterprise Security for about 8 years.

How are customer service and support?

I evaluate customer service and technical support as fantastic. Technical support is some of the best that I've worked with.

I work with a lot of different vendors, and Splunk support is very responsive and capable. They have very knowledgeable people who can deep dive into the details and understand the inner workings of the platform without having to engage developers or back-end people all the time; they can just deal with it because they know what they're doing.

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

I have also used Google Chronicle and the Google SecOps platform. The factors that led me to consider a change included the lack of maturity in the other product and the maturity of Splunk. Google SecOps doesn't have anywhere near the capabilities of the Splunk ecosystem.

The search capabilities in Splunk Enterprise Security, and Splunk in general, are far superior to the search capabilities in Google's products. Their automation platform was extraordinarily immature. It doesn't have many of the basic capabilities that you would expect in an enterprise-class platform, and Splunk does have that. The Splunk capabilities were just vastly superior.

How was the initial setup?

I would describe my experience with deploying Splunk Enterprise Security as fairly straightforward.  We have detection engineers who know what they're doing, and so learning the detection platform in Splunk Enterprise Security was quick for them to pick up. Even those who were not familiar with Splunk Enterprise Security to begin with were able to pick that up quickly.

What was our ROI?

I have seen a return on investment with Splunk Enterprise Security.

What other advice do I have?

I would rate it an eight out of ten.

Which deployment model are you using for this solution?

Hybrid Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Buyer's Guide
Splunk Enterprise Security
August 2026
Learn what your peers think about Splunk Enterprise Security. Get advice and tips from experienced pros sharing their opinions. Updated: August 2026.
914,109 professionals have used our research since 2012.
Presales Engineer at a comms service provider with 10,001+ employees
Real User
Top 20
Sep 17, 2026
Advanced threat hunting has become faster and more flexible for complex investigations
Pros and Cons
  • "Splunk Enterprise Security is a platform that justifies its status as a leader."
  • "Regarding pricing, implementation cost, and license management for Splunk Enterprise Security, I find that the licenses are expensive."

What is our primary use case?

The main use of Splunk Enterprise Security in my organization is for threat hunting activities, digging through logs by doing statistical searches and, as a result, having the ability to get results fairly quickly so I can then chain together searches or cross-reference information.

For example, I get bulletins with indicators of compromise from a vendor or an entity, a public administration in France, and then I search for the IOCs and from there, step by step, starting from that information I find, I cross it with other information to know, typically, whether the IOC that was found means that the user was compromised. Did the user go all the way, and what is the root cause of the malicious activity?

I am in pre-sales, so it is mainly for demos.

How has it helped my organization?

Splunk Enterprise Security was a leading platform and so I was able to address many clients with it. Because it is at the top right of the Gartner quadrant, it is a platform that is recognized by a lot of people, both in the technical world and among high-level decision makers.

Overall, when I move from a solution that is not a leader at all and with which clients encounter problems, I can then show that Splunk Enterprise Security addresses these issues in different ways. Splunk Enterprise Security is a platform that justifies its status as a leader.

What is most valuable?

The best features that Splunk Enterprise Security offers are the ability to search quickly and to get results quickly when I run a search. The ability to deploy on-premise, cloud, IaaS overall, and a platform that is very open, where I can do pretty much whatever I want on the dashboard side, rule creation, or really other behaviors.

Overall, when I compare with other products like IBM QRadar, when you run a search, you have to wait one hour, two hours to get results. With Splunk Enterprise Security, I get a result in less than three minutes, so that allows me to be much more efficient in my work.

There are many modules in Splunk Enterprise Security that allow me to improve operational resilience. There is AI, which allows me to anticipate attacks with the Machine Learning Toolkit module, the approach with weak signals, risk-based analysis alerting. These are features that many other solutions do not have and that allow me to be much more efficient in the operational management of alerts.

What needs improvement?

There is a lot to say regarding how Splunk Enterprise Security could be improved. Overall, it would be to have detection content that is truly effective and operationalizable and not just content that is available in Enterprise Security Content Update or in Splunk Enterprise Security, but content that is really mature for certain use cases that are difficult to manage in a production environment.

For how long have I used the solution?

I have been using Splunk Enterprise Security for seven years.

What do I think about the stability of the solution?

In my opinion, Splunk Enterprise Security is stable.

What do I think about the scalability of the solution?

Regarding the scalability of Splunk Enterprise Security, I would rate it as very good because in a cloud environment, as for on-prem environments, I do not really have an opinion; I have not been confronted with that.

Which solution did I use previously and why did I switch?

I was using IBM QRadar before Splunk Enterprise Security because there were many negative aspects to that solution and it is no longer supported today.

What was our ROI?

I am not at the stage yet of having measured everything related to ROI with Splunk Enterprise Security.

What's my experience with pricing, setup cost, and licensing?

Regarding pricing, implementation cost, and license management for Splunk Enterprise Security, I find that the licenses are expensive. Compared to other competitors who do broadly the same type of management and are cheaper, it is also harder to be more competitive when selling Splunk Enterprise Security. That is one of the negative points, even if Splunk Enterprise Security is still recognized.

Which other solutions did I evaluate?

I evaluated other options before choosing Splunk Enterprise Security, but I cannot disclose them.

What other advice do I have?

For others considering adopting Splunk Enterprise Security, I advise to build a lab, test it, play with it, and build up your skills on it; it is a very good solution. Splunk Enterprise Security is a very good solution, and I have no other thoughts or points to share about Splunk Enterprise Security before we finish. I would rate this product an eight overall.

Which deployment model are you using for this solution?

Hybrid Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Amazon Web Services (AWS)
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
Last updated: Sep 17, 2026
Flag as inappropriate
PeerSpot user
reviewer2711313 - PeerSpot reviewer
Director, Enterprise Insider Threat at a legal firm with 1,001-5,000 employees
Real User
Top 10
Sep 13, 2025
Unified event correlation and intelligence dashboards to strengthen business resilience
Pros and Cons
  • "I would assess the stability and reliability of Splunk Enterprise Security as good, as I have not had any issues with it."
  • "The most significant challenges I face when using Splunk Enterprise Security for advanced threat detection include not having enough time to be in it, the resources and people to also be in there, and trying to configure it and teach people how to use it. A lack of resources prevents us from giving it the attention it needs."

What is our primary use case?

My main use cases for Splunk Enterprise Security are event correlation and risk-based alerting.

What is most valuable?

The features I appreciate most about Splunk Enterprise Security are the different domains they have and the intelligence that comes along with each of those dashboards, being that single pane of glass for analysts to go in and look at. Splunk Enterprise Security has helped improve my organization's business resilience.

We use Cribl to pull data in and get it optimized before it hits Splunk Enterprise Security as far as collection. I have not done much customizing, developing, testing, deploying, and refining detections in Splunk Enterprise Security yet; we started off with just getting data in, and now we are at the point where we are starting to look at detections.

In Splunk Enterprise Security, I do not use risk-based alerting as much as we should. That goes back to the whole time issue, as we need to teach people what to do with it and how to tune them, and we do not have enough time in the day.

What needs improvement?

As for improvements to Splunk Enterprise Security, we will see how ES 8.2 looks. It is hard to say. We just found out about a bunch of changes, so it is difficult to make specific recommendations at this point.

The most significant challenges I face when using Splunk Enterprise Security for advanced threat detection include not having enough time to be in it, the resources and people to also be in there, and trying to configure it and teach people how to use it. A lack of resources prevents us from giving it the attention it needs.

For how long have I used the solution?

I have been using Splunk Enterprise Security for two years.

What do I think about the stability of the solution?

I would assess the stability and reliability of Splunk Enterprise Security as good, as I have not had any issues with it. I have experienced downtime, crashes, or performance issues with Splunk Enterprise Security only once or twice when we have had to restart our Splunk instance, and it has taken three minutes and come right back, so nothing major.

What do I think about the scalability of the solution?

Splunk Enterprise Security has not hit the point yet where we need to scale; we are still at the initial ingestion phase. We are in the process of expanding usage for Splunk Enterprise Security; we have not actually done it yet, as we are still planning and trying to get other teams involved while meeting their use cases, so we are probably a month away from that.

How are customer service and support?

I would evaluate customer service and technical support for Splunk Enterprise Security as far better than anything else, giving it an eight out of ten, thanks to the response times they meet. When going to our account representatives, if we need something, they are always responsive and we get whatever we need.

How would you rate customer service and support?

Positive

How was the initial setup?

The deployment was easy since we're cloud-based. We didn't really didn't have to do anything.

What was our ROI?

I have seen ROI with Splunk Enterprise Security. Just getting data in and being able to use the data and making sure it is compliant and mapping it to data models is far more efficient than any other SIM I have had experience with.

What's my experience with pricing, setup cost, and licensing?

My experience with pricing, setup costs, and licensing for Splunk Enterprise Security is straightforward and self-explanatory. We are ingest-based, so we are not compute-based, making it pretty simple to get everything in without worrying about pricing.

Which other solutions did I evaluate?

Factors that led me to consider the change include shifting to a cloud-based solution at an affordable price and moving to something that is going to help reduce time spent on alerts and maintaining the system, with maintaining the system being probably the biggest reason since shifting to the cloud.

What other advice do I have?

For the future of Splunk Enterprise Security, I would want the Edge Processor to be able to send to multiple destinations rather than just Splunk, though that is more about Observability.

The advice I would give to other organizations considering Splunk Enterprise Security is that everybody wants to drive a Ferrari, so get the Ferrari of SIMs.

I rate Splunk Enterprise Security ten out of ten.

Which deployment model are you using for this solution?

Public Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Other
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Huralain Mohamed - PeerSpot reviewer
SOC Lead at a recreational facilities/services company with 201-500 employees
Real User
Top 20
Sep 16, 2026
Correlation searches have transformed our soc triage and reduce alert fatigue every day
Pros and Cons
  • "I love using Splunk Enterprise Security; it's one of my favorite tools, and I think it's needed in every single SOC environment."

    What is our primary use case?

    My main use case for Splunk Enterprise Security is utilizing the correlation searches in the SOC environment that I work in to triage events.

    A quick specific example of how I use it to triage events is that recently it helped us in a lateral movement case where we set up the correlation searches to detect lateral movement using the different telemetry and logs that were available. We were able to determine if it was a false positive or not through that capability.

    What is most valuable?

    Splunk Enterprise Security has positively impacted my organization greatly; without it, I don't even know how we had a SOC previously.

    Since using Splunk Enterprise Security, I have seen specific outcomes and improvements such as our mean time to detection and mean time to mitigation substantially decreasing, and it has helped a lot with the team as well. The SOC analysts who used to have alert fatigue don't experience that as much anymore.

    Some of my favorite features that Splunk Enterprise Security offers are the dashboards that it has available. What I appreciate most about the dashboards is definitely both the visualizations and the way that we customize them. We are able to customize them for our environment and then for the individual customers that we support as well, and taking all that data and being able to view it on the screen and make sense of it is the best.

    We set up the custom correlation searches ourselves, which has been really helpful because previously we didn't have any correlation searches—it was just out-of-box searches that were set up, and then we were able to build it out to our environment, specific to the data that we have visibility into.

    Splunk Enterprise Security's Risk-Based Alerting has positively impacted my alert volume and analyst productivity, as the metrics that it uses for RBA have been very helpful for us in being able to prioritize alerts, resulting in a substantially smaller alert volume compared to what it used to be, allowing analysts to be very productive.

    The native integration with Splunk SOAR in Splunk Enterprise Security 8.0 has been excellent; we have set up a lot of playbooks.

    Splunk Enterprise Security's accuracy and reliability of output is very accurate; I haven't noticed any errors.

    Splunk Enterprise Security's AI capabilities are great, and a lot of the AI capabilities that are automatically built into it are excellent.

    What needs improvement?

    Splunk Enterprise Security can be improved by providing more visualizations, and if we have workflow actions that can be set up with it to help with OSINT, that would be a lot better.

    For how long have I used the solution?

    I have been using Splunk Enterprise Security for over eight years.

    What do I think about the stability of the solution?

    Splunk Enterprise Security is stable.

    What do I think about the scalability of the solution?

    The scalability of Splunk Enterprise Security is great.

    How are customer service and support?

    The customer support for Splunk Enterprise Security is excellent; they have been very helpful, and it's one of the things I love the most.

    Which solution did I use previously and why did I switch?

    We previously were using Elastic, and now we're using Splunk.

    What was our ROI?

    I have seen a return on investment in that time has been saved for the analysts and their workload has gotten a lot lighter.

    What other advice do I have?

    My advice to others looking into using Splunk Enterprise Security is to not wait; implement it as if it is necessary and you needed it yesterday.

    I love using Splunk Enterprise Security; it's one of my favorite tools, and I think it's needed in every single SOC environment. I have been using it for years, and every time that I've switched jobs, I have been an advocate to try to get them to bring it on.

    Splunk Enterprise Security has helped improve my organization's business resilience. Splunk Enterprise Security has helped reduce my team's average mean time to resolve metric, although I'm not certain by how much.

    Which deployment model are you using for this solution?

    Hybrid Cloud

    If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

    Amazon Web Services (AWS)
    Disclosure: My company does not have a business relationship with this vendor other than being a customer.
    Last updated: Sep 16, 2026
    Flag as inappropriate
    PeerSpot user
    SOC Analyst at a government with 10,001+ employees
    Real User
    Top 20
    Sep 16, 2026
    Log analysis has improved incident response and has prevented SLA breaches in our operations
    Pros and Cons
    • "Splunk Enterprise Security has definitely helped us save time; it has helped us tremendously with preventing breaches of SLA on incidents and tickets as well as with ticket volume and log analysis."

      What is our primary use case?

      My main use case for Splunk Enterprise Security is log analysis and incident response.

      I use Splunk Enterprise Security to review logs and see additional information about traffic at the firewall, which users are associated with which IP addresses, and what devices they used. Additionally, I use it for hunting through the analyst dashboard to review quarantined email and conduct foreign travel analysis.

      What is most valuable?

      The best features Splunk Enterprise Security offers include data visualization, accurate logs, and an excellent user experience.

      The dashboards and how they are set up are very useful for analysts on the watch floor because we can pull a lot of data very quickly. The Analyst Dashboard is the best in my opinion, particularly for hunting activities where I conduct analysis of quarantined email and data breaches.

      Splunk Enterprise Security impacts our organization positively because we can see traffic associated with incidents and triage alerts in real time very quickly, and everything is very organized. It is very user-friendly for our analysts to view the data instantly.

      My team has reduced the number of missed alerts, especially when using different indexes to pull logs. We are able to see if there are any outages quickly and determine where to start remediation.

      What needs improvement?

      I am not sure how Splunk Enterprise Security can be improved right now. I believe it is doing us a lot of good and is really helpful, so I am not able to speak on how it can be improved at the moment. Nothing comes to my mind about areas where Splunk Enterprise Security could be improved.

      For how long have I used the solution?

      I have been using Splunk Enterprise Security for two years.

      What do I think about the stability of the solution?

      I find Splunk Enterprise Security stable.

      What do I think about the scalability of the solution?

      Splunk Enterprise Security's scalability is probably good, and it has a lot of potential, especially with a new SOC environment.

      How are customer service and support?

      Customer support is great with no issues.

      I would rate customer support a 10.

      What was our ROI?

      Splunk Enterprise Security has definitely helped us save time. It has helped us tremendously with preventing breaches of SLA on incidents and tickets as well as with ticket volume and log analysis. The main benefit is the SLA, which I have not breached in a very long time.

      Splunk Enterprise Security has really tremendously helped with SLAs and reaching those without breaching them every month. We actually have not had any breach of SLAs in a very long time, and I believe that is due to a lot of the capabilities of the tool.

      What other advice do I have?

      I would tell others looking into using Splunk Enterprise Security to stay open-minded, continue learning, and go to trainings because even if it seems very complicated at first, it does have the potential to really help with metrics, especially in terms of SLA and analysis. I would rate this review a 9.

      Which deployment model are you using for this solution?

      On-premises
      Disclosure: My company does not have a business relationship with this vendor other than being a customer.
      Last updated: Sep 16, 2026
      Flag as inappropriate
      PeerSpot user
      reviewer2701950 - PeerSpot reviewer
      Splunk System Engineer at a non-tech company with 11-50 employees
      Real User
      Top 20
      May 10, 2025
      Correlation engine and alert features significantly reduce alert volume
      Pros and Cons
      • "It's great for finding anonymous threats."
      • "The stability of Splunk Enterprise Security is very impressive; it is a very stable product."
      • "Splunk Enterprise Security can be improved mainly from the user interface regarding the visualizations. They are working on it, yet there are only five to ten very basic visualizations."

      What is our primary use case?

      The typical use case for Splunk Enterprise Security is to meet regulations and requirements for critical infrastructure. It is used to audit changes and authentication logs. The second purpose is for security operation center management and security management.

      What is most valuable?

      The most valuable features of Splunk Enterprise Security are the main component, which is the correlation engine that can specify detailed conditions such as how many events there need to be, what notification I will get, and if I get it per event or one per batch. 

      There is also throttling; in basic Splunk, there is no throttling at all. In Splunk Enterprise Security, there is an additional layer of control of these alerts. I appreciate the correlations and the alerts in that product.

      The asset management is particularly useful. We can enable asset lookups to show in every event. We define one, and it will translate to all events, allowing asset management to be easy. 

      Splunk Enterprise Security helps to reduce alert volume because the language is similar to SQL with Google-style functionality above it. We can use these terms to specify what is in the allow list. We can specify what's in lookups, what should be there, and what's not. It definitely helps to reduce the numbers of full score.

      Splunk Enterprise Security helps to speed up security investigations. When the finding is created, there are many correlations. You can quickly see what asset it is, what identity is involved, and you see the historical progress of what happened. Right from the findings, you can call VirusTotal and other resources, which is definitely helping.

      I assess Splunk Enterprise Security's insider threat detection capabilities for helping to find unknown threats and anomalous user behavior as great. It regularly checks new events through the correlation search and compares them with threat intelligence. The threat intelligence is refreshed regularly, downloading new threat information. Splunk has a special research team for security content and intelligence, which distributes its own threat list to Splunk Enterprise Security.

      It's great for finding anonymous threats. It checks new events and also works with the latest threat intelligence. At least once a day, it develops new threat information. In Splunk, there is a special research team. They are also distributing their own threat lists. The solution is capable of very good threat detection.

      In basic SPL, with the Splunk query language, we can detect brute force without threats. It scans every event, and if it finds patterns, IOCs, it can trigger notable events, which are now called findings. The new version includes an internal Git repository, so when the SOC team makes improvements to the correlation search and makes changes, it automatically keeps a history of that correlation search, what was changed, when, by whom, and you can revert if it breaks.

      The value that Splunk Enterprise Security offers in resilience is vital. It helps customers distributing gas across the Slovak Republic, ensuring that critical infrastructure, such as operational pipelines, are running. If there were an outage that delayed recovery, the economic impact could be significant. 

      It's good for analyzing malicious activities and detecting breaches. The interface sometimes can be very essential.  

      Splunk has helped us reduce alert volume. We can use terms to specify what is whitelisted and we can search like we would on Google. 

      We've been able to speed up security investigations. We a finding is created, there are many correlations. You can quickly see the asset, the identity involved, the history, et cetera. 

      What needs improvement?

      Splunk Enterprise Security can be improved mainly from the user interface regarding the visualizations. They are working on it, yet there are only five to ten very basic visualizations. When you have your data all set and the customer wants some new dashboards that would help them, it is pretty complicated to build them from the built-in visualizations. 

      This is one of the blocking points in Splunk, however, they're working on a new layer called Dashboard Studio. It is still limited. An older version of Splunk allowed implementation of JavaScript to capture events when a user clicked by mouse, which enabled great features. In the improved Dashboard Studio, this is not possible. They have improved one part and have made the other part worse, so it still lacks a premium feeling. Cisco will improve it, however, it seems they are focusing on what the big companies want. They will implement it if it's usable for these big players that pay, but for small companies, it's too pricey to use this solution.

      For how long have I used the solution?

      I've been working with this solution for seven years.

      What do I think about the stability of the solution?

      The stability of Splunk Enterprise Security is very impressive; it is a very stable product. They handle these things perfectly and conduct internal testing thoroughly. 

      They test it very thoroughly before release, and our customers have Splunk running for months without issues. 

      When I observe how customers work with Splunk in the cloud, it is also very good. They manage maintenance windows and inform customers, resulting in little to no interruptions to workflow. In terms of stability, I would give it a full score.

      What do I think about the scalability of the solution?

      We work with medium to large organizations. Our typical environment has 500 servers. In volume, we're looking at 100GB in storage. From Splunk's view, we're doing rather small volumes. It's big in a Central European context, and small from a Splunk North American context. It can be pricey for small companies. 

      How are customer service and support?

      I would rate technical support from Splunk Enterprise Security as a six out of ten. 

      It's average, considering it's a very big product, and they handle several hundred tickets a day. I have opened 20 to 30 cases, and they helped me with only three to five of them. They try to close issues as soon as possible, often just offering documentation links. 

      Even when I provide them with the core problem, they do not help much. The customer often has to rely on workarounds, custom scripts, and solutions which are somewhat lacking.

      How would you rate customer service and support?

      Neutral

      Which solution did I use previously and why did I switch?

      Before Splunk Enterprise Security, I didn't use a different solution; this was my first job, and I started working full-time with Splunk about eight years ago. 

      In the beginning, when they were testing, I was shown the OP5 and Nagios operating monitoring; we used tried them out, however, they were not really security-related.

      How was the initial setup?

      You can quickly set up Splunk by downloading the package, unpacking it, and starting to work. It's straightforward to get a quick view of your data, and you do not have to worry about connections to databases; it will start parsing the data as soon as you hand it over. For bigger environments with several hundred servers, Splunk Enterprise Security is the best solution.

      What was our ROI?

      Customers see the value in investing in this solution, particularly when it helps resolve issues quickly, turning a potential 20-hour response into one hour.

      What's my experience with pricing, setup cost, and licensing?

      It's still pretty pricey. It's an expensive solution for smaller companies. 

      That said, if someone evaluating SIEM solutions wants to go with the cheapest solution, Splunk Enterprise Security is a very good option. It has difficulties in administration and setup, however, in comparison with other products, it's still a great platform.

      What other advice do I have?

      My relationship with Splunk is that we are a partner and reseller partner. My organization does not monitor multiple cloud environments; we primarily monitor M365 and Azure environments from cloud products. We use the Microsoft Add-on for Splunk to read Exchange and Microsoft audit logs from the cloud. However, we still prefer on-premise solutions in our country.

      We use the Mission Control feature. It's replaced another component. I don't use it too much myself. It's like a connector for SOAR. We're investigating its capabilities and have not implemented it fully.

      Overall, I would rate Splunk Enterprise Security a nine out of ten. If you want to see your data quickly and in full view, it's very good - specifically for bigger environments.

      Which deployment model are you using for this solution?

      On-premises

      If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

      Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
      PeerSpot user
      Divya More - PeerSpot reviewer
      Technical Support at Softcell Technologies Limited
      Real User
      Top 5
      Jul 15, 2026
      Ai-driven threat detection has improved investigations and now speeds up incident response
      Pros and Cons
      • "The consolidation of SIEM, SOAR, and UEBA into a single interface has greatly improved my efficiency."
      • "Areas for improvement in Splunk Enterprise Security include enhancements to the dashboard and reporting features, as well as better handling of queries during peak times and improving self-monitoring dashboards."

      What is our primary use case?

      My use case for Splunk Enterprise Security is mainly for enterprise defense, including cyber threats and cybersecurity threat detection, as I have worked at an administrator level within the security model which utilizes multiple feeds including Elasticsearch.

      What is most valuable?

      The best features of Splunk Enterprise Security are the AI models and the reporting function, which is very good and faster than other solutions.

      The impact of Splunk Enterprise Security on my organization is that it helps to identify bottlenecks and it is effective in large-scale environments, although my environment is medium-scale.

      The AI-driven detections improve the accuracy of my investigations by enhancing infrastructure, conducting health checks, and providing insights that recommend features for Splunk Enterprise Security, especially for security-related queries.

      Risk-based alerting in Splunk Enterprise Security analyzes alerts by checking logs and processes, allowing me to determine the targeting process and destination IP.

      What needs improvement?

      Areas for improvement in Splunk Enterprise Security include enhancements to the dashboard and reporting features, as well as better handling of queries during peak times and improving self-monitoring dashboards.

      For how long have I used the solution?

      I have been using Splunk Enterprise Security for the last one year.

      What do I think about the stability of the solution?

      Regarding stability, it is okay, with no issues.

      What do I think about the scalability of the solution?

      In my organization, around three thousand users utilize Splunk Enterprise Security.

      How are customer service and support?

      I rate the technical support a nine out of ten.

      How was the initial setup?

      The deployment of Splunk Enterprise Security is easier.

      It takes about one or two days for deployment, depending on customer availability.

      What was our ROI?

      My mean time to detect and respond has become faster by about fifty percent.

      What's my experience with pricing, setup cost, and licensing?

      The pricing is moderate; it is neither expensive nor cheap.

      Which other solutions did I evaluate?

      Compared to other vendors, I find Splunk Enterprise Security to be the best.

      What other advice do I have?

      In the SIEM solution review, I have experience with Splunk Enterprise Security and Wazuh.

      I use Wazuh as my SIEM solution.

      Additionally, I use Splunk Enterprise Security.

      Specifically, Splunk Enterprise Security is the threat detection product, so it is based on AI technology.

      Regarding stability, it is okay, with no issues.

      The integration of threat intelligence into the TDIR workflow has improved my ability to block threats by utilizing AD integration and Syslog forwarding integration, allowing logs to be effectively forwarded to EDR.

      The consolidation of SIEM, SOAR, and UEBA into a single interface has greatly improved my efficiency.

      I have upgraded to Splunk Enterprise Security eight point zero.

      The detection version is lacking some specific functionalities.

      The deployment model is on-premises.

      I provide an overall review rating of nine out of ten for Splunk Enterprise Security.

      Which deployment model are you using for this solution?

      On-premises
      Disclosure: My company has a business relationship with this vendor other than being a customer. Reseller
      Last updated: Jul 15, 2026
      Flag as inappropriate
      PeerSpot user
      reviewer2899440 - PeerSpot reviewer
      Director, Technology at a financial services firm with 5,001-10,000 employees
      Real User
      Top 20
      Sep 17, 2026
      Automated our soc workflows and improved incident response while correlation still needs work
      Pros and Cons
      • "Splunk Enterprise Security has positively impacted our organization by allowing us to stand up a SOC and make it automated."
      • "We have had some issues with customer support on getting answers for Splunk Enterprise Security, but we have been able to escalate it and get resolution."

      What is our primary use case?

      Splunk Enterprise Security serves as our main security information and event management solution for our SOC. We have a setup to pull alerts for our SOC, and then we use it to work through each of the incidents we discover. We also use it to develop SOAR and utilize the SOAR piece to develop playbooks.

      How has it helped my organization?

      Splunk Enterprise Security has positively impacted our organization by allowing us to stand up a SOC and make it automated. It has also allowed us to reduce our time on researching incidents. We are able to resolve incidents in a much quicker timeframe using Splunk Enterprise Security, although I don't have exact metrics to share.

      What is most valuable?

      The best features Splunk Enterprise Security offers include the ability to look at all of our data and create playbooks that we can then use for all of the different analysts. When it comes to creating playbooks for our analysts in Splunk Enterprise Security, I find that it works fine. There are also many apps that we can use, which we appreciate.

      What needs improvement?

      To improve Splunk Enterprise Security, I would recommend making it easier for events to be correlated together.

      For how long have I used the solution?

      I have been using Splunk Enterprise Security for about four years.

      What do I think about the stability of the solution?

      Splunk Enterprise Security is stable.

      What do I think about the scalability of the solution?

      We haven't had any issues with Splunk Enterprise Security's scalability, so it seems to be functioning well.

      How are customer service and support?

      We have had some issues with customer support on getting answers for Splunk Enterprise Security, but we have been able to escalate it and get resolution.

      Which solution did I use previously and why did I switch?

      We didn't previously use a different solution before Splunk Enterprise Security as we had a homegrown solution.

      How was the initial setup?

      We are currently working on the upgrade to Splunk Enterprise Security 8.0 but have not completed it and rolled it out yet.

      What was our ROI?

      Splunk Enterprise Security has helped reduce our team's average mean time to resolve, also known as MTTR metric, but I don't have the actual numbers available and don't want to guess.

      What's my experience with pricing, setup cost, and licensing?

      I don't know if we purchased Splunk Enterprise Security through the AWS Marketplace since I don't deal with the accounting and the purchases. I don't actually deal with the pricing, setup cost, and licensing, so I don't have any insight into that. I don't have any relevant metrics, such as fewer employees needed, money saved, or time saved, to share regarding the return on investment for Splunk Enterprise Security.

      Which other solutions did I evaluate?

      We didn't really evaluate any other options before choosing Splunk Enterprise Security since we already were using Splunk and it met our needs.

      What other advice do I have?

      Splunk Enterprise Security's risk-based alerting, also known as RBA, has allowed us to reduce some of the alerts and direct the analysts to work on the ones that have a higher risk, so it has been helpful. The threat topology and MITRE ATT&CK framework features are useful. Our threat detection team uses it, but I personally haven't, so I don't have a lot of insight into that. Splunk Enterprise Security has helped us detect threats faster. We do use it and believe it helps us identify threats in a more timely manner, although I can't give exact metrics on how much faster. I would tell others looking into using Splunk Enterprise Security that it meets our company's needs, and we're able to use it and resolve our use cases. I rate this product a seven out of ten.

      Which deployment model are you using for this solution?

      Hybrid Cloud

      If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

      Disclosure: My company does not have a business relationship with this vendor other than being a customer.
      Last updated: Sep 17, 2026
      Flag as inappropriate
      PeerSpot user
      reviewer2899356 - PeerSpot reviewer
      Computer Systems Application Specialist I at a mining and metals company with 501-1,000 employees
      Real User
      Top 20
      Sep 16, 2026
      Security platform has improved compliance alerting and speeds investigations for critical servers
      Pros and Cons
      • "I have seen a return on investment with Splunk Enterprise Security, particularly in terms of money saved, as it has helped save money by allowing us to avoid renewing our previous SIEM, leading us to save hundreds of thousands of dollars."

        What is our primary use case?

        What is most valuable?

        Splunk Enterprise Security offers comprehensive capabilities that provide significant value to our organization. The alerting functionality helps our team day-to-day by supporting our compliance process, as we have compliance requirements that necessitate alerts for multiple failed logins, which will notify us if it reaches a certain threshold, prompting our analysts to log into Mission Control, start the investigation, and document from the time the alert was triggered. We also have a dashboard in Splunk Enterprise Security where we monitor disk usage of our Linux servers and set specific thresholds; if it exceeds a certain percentage, it sends an alert, which serves as our starting point to investigate. Splunk Enterprise Security positively impacts our organization by giving us visibility and enabling us to monitor the health of our servers, along with helping us detect any anomalies.

        Since using Splunk Enterprise Security, we notice faster response times, particularly with metrics such as CPU, memory, or disk space usage, because we have visibility into those systems, making it easier to start an investigation when alerted.

        Splunk Enterprise Security's risk-based alerting, RBA, has shaped our alert volume and analyst productivity by allowing us to categorize specific alerts as high risk, which we focus on immediately, while allowing lower priority alerts to be acknowledged later.

        What needs improvement?

        We are exploring improving Splunk Enterprise Security by integrating AI, as I attended a session about integrating with the MCP server, which we believe will help us improve triage and speed up investigations.

        Splunk Enterprise Security could be improved by having more skills within the MCP that tie to compliance regulations such as NERC CIP, which is important for the utility industry.

        For how long have I used the solution?

        I have been using Splunk Enterprise Security for one year.

        What do I think about the stability of the solution?

        Splunk Enterprise Security is stable.

        What do I think about the scalability of the solution?

        We have not encountered scalability issues with Splunk Enterprise Security.

        How are customer service and support?

        Splunk Enterprise Security's customer support is amazing. I would rate the customer support of Splunk Enterprise Security a 10, as they are helpful.

        Which solution did I use previously and why did I switch?

        We used a different vendor before switching to Splunk Enterprise Security, and the previous service was significantly expensive for renewal.

        What was our ROI?

        I have seen a return on investment with Splunk Enterprise Security, particularly in terms of money saved. Splunk Enterprise Security has helped save money by allowing us to avoid renewing our previous SIEM, leading us to save hundreds of thousands of dollars.

        What's my experience with pricing, setup cost, and licensing?

        My experience with pricing and setup costs for Splunk Enterprise Security is reasonable, and the sales representatives are helpful in guiding us through the sizing to maximize our licensing needs.

        Which other solutions did I evaluate?

        We did not evaluate other options before choosing Splunk Enterprise Security, as we were aware that it is the go-to choice for many companies and our corporate predecessor was already using it.

        What other advice do I have?

        Splunk Enterprise Security Essentials has not significantly contributed to a reduction in analyst burnout or fatigue, as my team is small but critical, focusing on a limited number of servers. My advice to those looking into using Splunk Enterprise Security is to try it and see for themselves. I rate this review a 10.

        Which deployment model are you using for this solution?

        On-premises

        If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

        Other
        Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
        Last updated: Sep 16, 2026
        Flag as inappropriate
        PeerSpot user
        Buyer's Guide
        Download our free Splunk Enterprise Security Report and get advice and tips from experienced pros sharing their opinions.
        Updated: August 2026
        Buyer's Guide
        Download our free Splunk Enterprise Security Report and get advice and tips from experienced pros sharing their opinions.