No more typing reviews! Try our Samantha, our new voice AI agent.
Isaiah Melton - PeerSpot reviewer
Issm at a government with 10,001+ employees
Video Review
Real User
Top 5
Sep 13, 2025
Prioritizes critical threats and improves collaboration across teams for faster incident response
Pros and Cons
  • "Splunk Enterprise Security helps my SOC team prioritize and investigate high-fidelity alerts more effectively by enabling us to quickly gather information, collaborate, and provide various teams with access to the same information, allowing them to follow the workflow to complete the task."
  • "Splunk Enterprise Security can improve in terms of probably being able to talk to additional sources."

What is our primary use case?

My main use cases for Splunk Enterprise Security are insider threat, application security, incident response, and risk forecasting.

What is most valuable?

I appreciate the ability of Splunk Enterprise Security to tap into various network equipment and services on the network to pull it all into one place. That's my favorite feature.

The feature I've mentioned helps us in responding to incidents and disasters and different technical situations by being able to pull data from various sources and analyze it and take action.

Splunk Enterprise Security's Risk-Based Alerting, or RBA, has enabled us to prioritize and focus on the most critical threats and issues, while blocking out some of the noise and various information that can come from all these different sources.

Splunk Enterprise Security helps my SOC team prioritize and investigate high-fidelity alerts more effectively by enabling us to quickly gather information, collaborate, and provide various teams with access to the same information, allowing them to follow the workflow to complete the task.

Splunk Enterprise Security's ability to ingest and normalize data from diverse sources has enhanced our threat detection capabilities by making us aware of what's going on in the world, relating to our use cases and our threat tolerance, as we constantly pull in that information and brief everyone who has a stake.

What needs improvement?

Splunk Enterprise Security can improve in terms of being able to add to additional sources. They're adding many different ones, but as more cloud and data lakes emerge, being able to touch all those different new technologies that emerge together would be beneficial.

What do I think about the stability of the solution?

I assess the stability and reliability of Splunk Enterprise Security as very reliable and stable so far. We haven't had any glitches with testing out the first pilot use of it.

Buyer's Guide
Splunk Enterprise Security
June 2026
Learn what your peers think about Splunk Enterprise Security. Get advice and tips from experienced pros sharing their opinions. Updated: June 2026.
904,973 professionals have used our research since 2012.

What was our ROI?

From my point of view, the biggest return on investment when using Splunk Enterprise Security is definitely being able to respond to incidents faster, adapt to future attacks by analyzing that information and doing risk-based management decisions, and also preparing for the future by looking at new technologies that can help us.

What's my experience with pricing, setup cost, and licensing?

I'm not too involved with the pricing, the setup costs, and the licensing of the platform. It is pretty straightforward.

What other advice do I have?

We just started turning on UEBA in our company, but we haven't really started utilizing it yet. There is a roadmap to try to do some of that stuff from the program side, and we just have to get access to it once the enterprise is ready to implement it and hand it over to the program office.

Even though we just started using UEBA, it's very useful, and it helps us set a bar for what normal activity is, and then it sets alerts and gives us awareness for anything that's out of the norm in terms of normal user behavior and the data that's being accessed.

My advice to other companies considering Splunk Enterprise Security is that you should definitely look into it, get your folks a proof of concept and try it out, send folks to training, and let them learn about it, and see how it can help you be better at securing your environment.

I rate Splunk Enterprise Security nine out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
reviewer2756124 - PeerSpot reviewer
Dir Security Ops at a government with 10,001+ employees
Real User
Top 20
Sep 13, 2025
Has improved incident detection and reduced SOC response times with a unified dashboard
Pros and Cons
  • "The feature I appreciate the most about Splunk Enterprise Security is the dashboard."
  • "The correlation of events is the most significant challenge I face when using Splunk Enterprise Security for advanced threat detection."

What is our primary use case?

My main use cases for Splunk Enterprise Security are threat alerts.

What is most valuable?

The feature I appreciate the most about Splunk Enterprise Security is the dashboard. It has supported my SOC by making their job easier regarding notifications. It also reduces the time they have to spend using other tools to help them out, cutting down on their workload.

When it comes to incidents, we are able to detect, monitor, and handle incidents that come in. We can take those incidents and correlate them to other tools that we use. It serves as our single pane of focus.

Our security ops team's remediation time with Splunk Enterprise Security is measured in minutes. One notable improvement has been the maturation of our SOC, which now features a single pane of glass for incident viewing.

What needs improvement?

The correlation of events is the most significant challenge I face when using Splunk Enterprise Security for advanced threat detection. I am still looking at version 8 to see how it can be improved or how we can utilize it better.

For how long have I used the solution?

I have been using Splunk Enterprise Security for three years.

What do I think about the stability of the solution?

I assess the stability and reliability of Splunk Enterprise Security as having some issues because we have problems with our SC4S. We are working through it. There are some things that we need to troubleshoot, but we are addressing those.

What do I think about the scalability of the solution?

It is easy to scale Splunk Enterprise Security, and the plan is to expand it, however, we are in the planning stages right now. My experience with scaling has been smooth.

How are customer service and support?

I evaluate customer service and technical support as good, with no issues.

On a scale of one to ten, I would rate customer service and technical support an eight.

How would you rate customer service and support?

Positive

How was the initial setup?

My experience with pricing, setup costs, and licensing is that they are expensive and growing, but that is really above my level. Our C suite handles more of the pricing aspects.

What about the implementation team?

I find the process for customizing, developing, testing, deploying, and refining detections in Splunk Enterprise Security not overly complicated because we use Splunk resources to help us with this. It is not as challenging as we would think it would be.

What was our ROI?

I have seen a return on investment with Splunk Enterprise Security.

Which other solutions did I evaluate?

I use other security solutions that integrate or import data into Splunk Enterprise Security such as CrowdStrike, Proofpoint, and a threat intel platform called ThreatConnect.

What other advice do I have?

My advice to other organizations considering Splunk Enterprise Security is to weigh their options, but I would definitely recommend it.

On a scale of one to ten, I rate Splunk Enterprise Security an eight.

Which deployment model are you using for this solution?

Public Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Buyer's Guide
Splunk Enterprise Security
June 2026
Learn what your peers think about Splunk Enterprise Security. Get advice and tips from experienced pros sharing their opinions. Updated: June 2026.
904,973 professionals have used our research since 2012.
Divya More - PeerSpot reviewer
Technical Support at Softcell Technologies Limited
Real User
Top 5
Jul 15, 2026
Ai-driven threat detection has improved investigations and now speeds up incident response
Pros and Cons
  • "The consolidation of SIEM, SOAR, and UEBA into a single interface has greatly improved my efficiency."
  • "Areas for improvement in Splunk Enterprise Security include enhancements to the dashboard and reporting features, as well as better handling of queries during peak times and improving self-monitoring dashboards."

What is our primary use case?

My use case for Splunk Enterprise Security is mainly for enterprise defense, including cyber threats and cybersecurity threat detection, as I have worked at an administrator level within the security model which utilizes multiple feeds including Elasticsearch.

What is most valuable?

The best features of Splunk Enterprise Security are the AI models and the reporting function, which is very good and faster than other solutions.

The impact of Splunk Enterprise Security on my organization is that it helps to identify bottlenecks and it is effective in large-scale environments, although my environment is medium-scale.

The AI-driven detections improve the accuracy of my investigations by enhancing infrastructure, conducting health checks, and providing insights that recommend features for Splunk Enterprise Security, especially for security-related queries.

Risk-based alerting in Splunk Enterprise Security analyzes alerts by checking logs and processes, allowing me to determine the targeting process and destination IP.

What needs improvement?

Areas for improvement in Splunk Enterprise Security include enhancements to the dashboard and reporting features, as well as better handling of queries during peak times and improving self-monitoring dashboards.

For how long have I used the solution?

I have been using Splunk Enterprise Security for the last one year.

What do I think about the stability of the solution?

Regarding stability, it is okay, with no issues.

What do I think about the scalability of the solution?

In my organization, around three thousand users utilize Splunk Enterprise Security.

How are customer service and support?

I rate the technical support a nine out of ten.

How was the initial setup?

The deployment of Splunk Enterprise Security is easier.

It takes about one or two days for deployment, depending on customer availability.

What was our ROI?

My mean time to detect and respond has become faster by about fifty percent.

What's my experience with pricing, setup cost, and licensing?

The pricing is moderate; it is neither expensive nor cheap.

Which other solutions did I evaluate?

Compared to other vendors, I find Splunk Enterprise Security to be the best.

What other advice do I have?

In the SIEM solution review, I have experience with Splunk Enterprise Security and Wazuh.

I use Wazuh as my SIEM solution.

Additionally, I use Splunk Enterprise Security.

Specifically, Splunk Enterprise Security is the threat detection product, so it is based on AI technology.

Regarding stability, it is okay, with no issues.

The integration of threat intelligence into the TDIR workflow has improved my ability to block threats by utilizing AD integration and Syslog forwarding integration, allowing logs to be effectively forwarded to EDR.

The consolidation of SIEM, SOAR, and UEBA into a single interface has greatly improved my efficiency.

I have upgraded to Splunk Enterprise Security eight point zero.

The detection version is lacking some specific functionalities.

The deployment model is on-premises.

I provide an overall review rating of nine out of ten for Splunk Enterprise Security.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer. Reseller
Last updated: Jul 15, 2026
Flag as inappropriate
PeerSpot user
Kumar Shubham - PeerSpot reviewer
Senior Consultant at a consultancy with 1,001-5,000 employees
Consultant
Top 20
Jul 6, 2026
Advanced correlation has simplified threat hunting and now delivers faster incident investigations
Pros and Cons
  • "The unique and most valuable feature in Splunk Enterprise Security is the correlation capability and the SPL query language itself."
  • "Splunk Enterprise Security is a costlier tool compared to ArcSight or IBM QRadar."

What is our primary use case?

Splunk Enterprise Security has an upper hand when compared with other products. We can correlate multiple data sources for generating alerts through SPL. Although many find it complex, we found it much easier because recursive query hunting for identifying threats is straightforward and quick. Those are the aspects which we really appreciated.

For detecting threats, we have created use cases over Splunk Enterprise Security. We have onboarded multiple third-party products with Splunk Enterprise Security. On top of that, we have created multiple use cases correlating multiple third-party vendors. For example, if event A happens where data is B, we have defined those scenarios in queries to trigger the alert.

What is most valuable?

The unique and most valuable feature in Splunk Enterprise Security is the correlation capability and the SPL query language itself. Through an SPL query, we can even identify ransomware scenarios where we can execute large queries and receive results within a few seconds. That aspect gives Splunk Enterprise Security an upper hand with their own query language.

Splunk Enterprise Security helps us reduce the time to react to alerts because the query itself executes so fast that when investigating something in big data set scenarios, it provides significant assistance. Splunk Enterprise Security has the feature of correlating multiple data sources to generate alerts. The risk factor is the second feature where it triggers to identify the severity level of the alert. While correlating multiple data sets along with the query itself, it gives us exactly what we need if we have proper understanding.

The main benefits that Splunk Enterprise Security provides for us as an end user is that it is a well-known tool. When it comes to querying or identifying any data from a big data set or data lake scenario, the query executes so fast and gives us a good outcome.

What needs improvement?

A FIM integrating model would be one improvement that Splunk Enterprise Security could add because Splunk Enterprise Security is a costlier tool compared to ArcSight or IBM QRadar. A FIM monitoring scenario would help.

Regarding pricing, this depends on company preferences. If a company wants to go with a brand, they will opt for Splunk Enterprise Security because it is well-known and a majority of familiar brands or big brands trust Splunk Enterprise Security. To increase their revenue, they could drop the price slightly because there are customers who do not care about money and have an ample amount of budget, and if they think about security, they will go for security. There are customers who are looking at the security side as well as the financial front, and they do not go for Splunk Enterprise Security. They opt for ArcSight or IBM QRadar instead. The pricing of the Enterprise version is at a higher end compared to any other well-known product.

For how long have I used the solution?

I have been using Splunk Enterprise Security for more than five years.

What do I think about the stability of the solution?

From a scale of one to ten, I rate the stability of Splunk Enterprise Security as a nine point five or a ten.

What do I think about the scalability of the solution?

In terms of scalability, the ability to scale and expand is a nine.

How are customer service and support?

My rating for Splunk Enterprise Security technical support is not very high, as I have not interacted extensively with Splunk Enterprise Security support because in our organization itself, we have five people who are Splunk certified architects.

How was the initial setup?

The initial setup for Splunk Enterprise Security is not complex, but it is not simple either. If an administrator wants to implement it, they have to do some homework at their own level before proceeding. When we compare it with Wazuh, for example, Wazuh has a one-click installation scenario. There is one script that you have to run and automatically everything is done. You are ready to go and your tool is set up.

Which other solutions did I evaluate?

In my opinion, the main competitors for Splunk Enterprise Security are IBM QRadar and ArcSight. There are many products and everyone has their own capabilities.

What other advice do I have?

Regarding the customization and development part inside Splunk Enterprise Security, we can create our own customized dashboards for whatever we need. If you understand Splunk Enterprise Security completely, you can create customization or you can request certain help on the support front, and they can assist you with that.

Splunk Enterprise Security provides better functionality when it comes to investigating data because when there is an incident, the analyst or the CISO wants to gain an upper hand as soon as an attack or breach has been detected. The SPL queries give an upper hand while fetching data compared to any other tool. That is the only difference, or the key difference.

In my opinion, Splunk Enterprise Security does not help to improve a company's or business's resilience because a majority of companies use Splunk Enterprise Security for security purposes. Rather than that, any AI or ML professionals or data science engineers would prefer Elastic, which is an open-source tool, to analyze data.

We recommend Splunk Enterprise Security to other users that if a customer has a good budget, they can go for a Splunk Enterprise Security solution. It depends on what the client is looking for and what they want to achieve. If they are going through funding, they want to showcase to the investors that they have a security team and they are using a grade-A solution in place to get additional checks. I give this review an overall rating of nine.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Last updated: Jul 6, 2026
Flag as inappropriate
PeerSpot user
Niranjan Narasaiah - PeerSpot reviewer
Security Delivery Senior Analyst at Accenture
Reseller
Top 20
Jul 1, 2026
Advanced analytics have boosted investigations and consistently improve incident response speed
Pros and Cons
  • "Splunk Enterprise Security's risk-based alerting positively impacts my alert volume and analyst productivity because we get low, medium, and high-security alerts based on the use cases driven in Splunk Enterprise Security, and we receive good feedback from clients regarding our productivity as we consistently resolve incidents meeting SLA, resulting in increased client satisfaction with our team and work over the past two to three years."
  • "In my opinion, improvements in Splunk Enterprise Security could address the issue of unnecessary alerts. Sometimes we receive many false positives, leading to difficulties in identifying real security incidents."

What is most valuable?

For search queries in Splunk Enterprise Security, we can build our deep-dive investigations as it will not be too complex. We can find L2 and L3 level investigations. In the initial stages, if we do not find any trace of an alert, malware, or any kind of malicious activity, we can dig into the investigation with the help of queries. Overall, dashboards help as well. For example, we can find O365 authentication activities and deauthentication, which lets us see different locations where the user is logged in and whether they are using a VPN or not. If they log in with a VPN IP, it shows a different location. We can monitor authentication activities for normal users and create dashboards for them. Splunk Enterprise Security also allows us to investigate suspicious emails and blacklisted IP traffic, making it an excellent feature for malware investigation and network traffic analysis.

The AI-driven detections and assistance in Splunk Enterprise Security have improved the accuracy. Recently, I have integrated a copilot with Microsoft Teams for AI investigations. I use it when I cannot find information in the basic data. For example, if I provide the use case name, it gives information about the overall picture of the alert activities. We have to check user logs for any activities that happened on a host or if a suspicious user has logged into an AD account, including any changes to paths or modifications to files. This kind of investigation can be facilitated with AI in Splunk Enterprise Security.

Regarding whether Splunk Enterprise Security has helped reduce my team's average mean time to resolve issues, I can say that it almost resolves incidents within one hour. It depends on the clients, with a mean time of approximately thirty minutes for low alerts and up to six hours for high-security alerts. We must follow our SLA for any particular alert.

I can say that the average mean time to detect specific attacks with Splunk Enterprise Security is around five to six minutes or seven minutes, and under specific conditions, it can be eight minutes. For top security incidents, we can detect within under sixty minutes using a formula: alert time minus activity start time divided by the number of incidents.

Splunk Enterprise Security's risk-based alerting positively impacts my alert volume and analyst productivity because we get low, medium, and high-security alerts based on the use cases driven in Splunk Enterprise Security. We receive good feedback from clients regarding our productivity, as we consistently resolve incidents meeting SLA, resulting in increased client satisfaction with our team and work over the past two to three years.

The MITRE ATT&CK framework features are beneficial for helping discover the overall scope of incidents because we have integrated it into our use cases within Splunk Enterprise Security. It helps to map various attacks such as persistence, brute-force attacks, and blacklisted IP activities. We follow the process of incident response and the MITRE framework to investigate alerts effectively.

Splunk Enterprise Security Essentials contributes to reducing analyst burnout or fatigue because we have mapped it with the MITRE framework and the Cyber Kill Chain. This integration leads to more detections and helps mitigate numerous malware and security alerts, thus improving productivity and creating a healthier work environment.

What needs improvement?

In my opinion, improvements in Splunk Enterprise Security could address the issue of unnecessary alerts. Sometimes we receive many false positives, leading to difficulties in identifying real security incidents. We could reduce alerts for scheduled activities to lessen our workload because, in a set of one hundred alerts, perhaps only one is a security incident, which we may miss amidst all the noise. Filtering and sorting are time-consuming but necessary, as seen in other SIEM tools like IBM QRadar and ArcSight. However, I still believe Splunk Enterprise Security is superior, considering my experience over several years.

Pricing for Splunk Enterprise Security is high, but I do not have in-depth knowledge as that is managed by higher management. I cannot provide a convincing answer since negotiations are typically handled by them.

For how long have I used the solution?

I have more than three years of experience in Splunk.

How are customer service and support?

I rate the technical support by Splunk as a perfect ten out of ten. I always receive support when needed, and while it may take time due to their workload, the results are assured and accurate based on my needs and thought processes.

How was the initial setup?

The initial setup of Splunk Enterprise Security is straightforward as it involves following the architecture of cloud deployment, with forwarders and security devices integrated by the client. We propose use cases for future attacks, but the deployment issues are managed by the client, while our role is providing SOC incident response services from India.

Which other solutions did I evaluate?

I believe Splunk Enterprise Security is one of the best options currently available in the market. While I see competitors like Sentinel emerging, Splunk Enterprise Security remains a top choice, alongside others like QRadar, ArcSight, and ELK tools such as Elastic, Logstash, and Kibana.

What other advice do I have?

Splunk Enterprise Security helps improve my organization's business resilience as I have almost two and a half years completed in Accenture. The client is most satisfied, and our team has consistently received appreciation for our work. We have not caused any security breaches and continue to see good results quarterly over the last two years.

The integration of threat intelligence directly into the TDIR workflow improves my ability to preemptively block threats because we receive weekly emails from our Threat Intelligence team with CVEs or IOCs. We add those IOCs to Splunk Enterprise Security to mitigate potential attacks. Recently, due to higher cyberattacks stemming from events in Iran and the USA, we have created use cases to monitor several IOCs every two hours, which is still ongoing.

In the future, I would like to see artificial intelligence integrated into Splunk Enterprise Security. I am uncertain about costs, but such integration could enhance functionality, much like in my previous project where alerts from Splunk Enterprise Security directly integrated into ServiceNow facilitated quicker responses. Reducing false positive alerts would also be beneficial to streamline our process, as we sometimes deal with hundreds of alerts, causing strain on resources. I would rate this product overall as a nine out of ten.

Which deployment model are you using for this solution?

Hybrid Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Other
Disclosure: My company has a business relationship with this vendor other than being a customer. Reseller
Last updated: Jul 1, 2026
Flag as inappropriate
PeerSpot user
reviewer2778402 - PeerSpot reviewer
Systems Development Engineer at a tech vendor with 10,001+ employees
Real User
Top 20
Nov 30, 2025
Supports real-time detection and response through flexible data ingestion and adaptable workflows
Pros and Cons
  • "What Splunk does, and really is why it is a choice platform, is that it speaks all of those languages, no matter what IT discipline you are in."
  • "The biggest thing with Splunk is making sure that the documentation is maintained."

What is our primary use case?

Splunk Enterprise Security use cases drive the workflow from threat detection all the way through to incident response, giving an approach mirrored with technology. Depending on use cases, whether having a tool drive some approach or conducting discovery, or looking to facilitate an operational security operations role at your company, it is very much driven heavily on the scheduler, setting things up and then looking and deep diving when necessary. Splunk Enterprise Security does well by giving a good framework.

Risk-based alerting is enabled in Splunk Enterprise Security. However, because of custom applications, a lot of times it works but doesn't work. Some discovery on our own is required, conducting our own campaigns to do that.

The time it takes the SecOps team to remediate any security incidents with Splunk Enterprise Security depends on the situation. Splunk skips over the whole trying to figure out how to use the tool. That is the biggest thing. Using Elastic SIEM and using other SIEMs, there is a learning curve, whereas with Splunk Enterprise Security, even if there is no one on the team who has mastery in Splunk, there is enough support and enough tooling and things that people have done before to really deep dive right in immediately.

Splunk Enterprise Security helps tell a story and helps focus at the customer level. As a managed service provider, I can only speak from the security side of it.

As a managed service provider, consolidating networking, security, and IT observability tools with Splunk Enterprise Security can be difficult, especially when providing those tools yourself. What Splunk does, and really is why it is a choice platform, is that it speaks all of those languages, no matter what IT discipline you are in. You are able to surface and view data in a quantitative manner and also get insights into what you are looking for. That is a very strong aspect of a tool where it does consolidate.

What is most valuable?

Splunk Enterprise Security has helped mainly when it comes down to the data science part. If you have a strong data science background, it is easy to detect anomalies. Some of the toolkits that are deployed with Splunk Enterprise Security and ML Toolkit allow you to do a lot more upfront than you typically would be able to do.

Splunk Enterprise Security has helped to improve the ability to ingest and normalize data.

The impressions of Splunk Enterprise Security's ability to identify and solve problems in close to real-time are that the different ingest methods that it provides are critical to finding out and looking at the breadth of data that comes in through machine data. In some parts, some people call them logs, some people call them metrics, some people call it telemetry. Having an aggregator at the ingest level like Splunk is amazing because it does not matter what you want to send, you can send it. It does not need to be in a particular format. A lot of the data brought in is not log data, it is programmatic from APIs and customer activity and things that need to be looked at as a whole picture. So when it comes to security, to be able to look at that in real-time requires compute and less structure because you need to be able to see there are payloads coming in that are typically not in this correct format, and the tool should not miss that because fields are not necessary. Splunk's ability to do schema on search is immensely powerful and that does aid in the ability to get results faster.

Threat topology and the MITRE ATT&CK framework features for helping discover the overall scope of an incident in Splunk Enterprise Security are pretty good. In this particular discipline when it comes to security, applying knowledge and then having a tool support that knowledge and drive forward, the integration paths of those particular types of things are very helpful. The more data that you bring in across your topology, if you will — network, user activity, user behavior activity, authentication, and application errors — you get this full landscape that you can see. With that, if a type of MITRE ATT&CK comes along and you understand what it is, you can see where the attack entry point was, the activity that was performed, and then start the incident response.

What needs improvement?

The biggest thing with Splunk is making sure that the documentation is maintained. There is a gap where if you search for an issue, a lot of times it is in the community. There should be a path that moves community answers into documentation or into an FAQ that allows people to not use the community answers to drive results. For instance, when you can use Splunk this way and this solves your problem, but if there is a better solution, that should be presented as an FAQ. Just working with Splunk for an immense amount of years, it is usually necessary to try to figure something out. The docs tell you where you can figure it out, as in a configuration file, but it does not really help you get to the end result. More complete documentation would be beneficial.

What do I think about the stability of the solution?

There has never been any instability with Splunk Enterprise Security. Some core dumps appear from time to time, but it really depends on your architecture. If you are really good at architecting Splunk, you should not ever run into that. Splunk is solid, and that is almost a ten.

What do I think about the scalability of the solution?

Splunk Enterprise Security's scalability is huge. If you were to take one thing from Splunk that is probably really amazing, it is the scalability. With a handful of users now, coming from a shop where there were 5,000-plus users in Splunk and it was pretty stable, the scalability is immense. It is one of the things that separates it from other tooling, and if not, it is the most scalable solution out there.

How are customer service and support?

Technical support or customer support at Splunk has been contacted.

The quality and speed of the support at Splunk are interesting. As an expert in the field, the work is really far beyond what customer support can probably handle. They are pretty good when it comes to that, especially if you have a Sev 1 ticket. The support team overall at Splunk, the people that have been interacted with, are fine, but typically if there is a problem, someone like a specialist needs to be spoken to. This one is hard to answer because of being such a niche customer.

If Splunk support were to be put on a scale from 1 to 10, it would receive a seven. This has been discussed with them and it is fair feedback. The reason for giving seven is simply because the first contact is not necessarily able to answer most of the problems that have to be submitted.

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

Alternatives to Splunk have been used. In the past, ArcSight has been used, of course managed service provider tools that you typically get with the big cloud providers, and then Elastic.

How was the initial setup?

Splunk Enterprise Security is just an app that sits on top of Splunk. There really is not much to it. It is pretty straightforward and about as easy as production enterprise software that has ever been seen. It is super easy.

What about the implementation team?

Implementation was automation, probably a couple of minutes and a button click.

Which other solutions did I evaluate?

There is not anything that is close to Splunk Enterprise Security as of right now. Splunk has taken this weird leap ahead of everybody else. It is also the most expensive tool out there. It is kind of like buying a luxury SUV or a used entry-level SUV. There is a difference for a reason. That is not saying that any of the other tools mentioned are that. It is just that Splunk is ahead, so there is really not a fair comparison.

What other advice do I have?

Splunk Enterprise Security has not been upgraded to 8.0. Splunk Enterprise Security does require maintenance between patching and upgrades. Professional services are available and have been done on behalf of another customer, but it is done mainly personally. The overall review rating for Splunk Enterprise Security is an eight.

Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor. The reviewer's company has a business relationship with this vendor other than being a customer: Partner
Last updated: Nov 30, 2025
Flag as inappropriate
PeerSpot user
Security Operation Consultant at a tech services company with 201-500 employees
Real User
Top 5
Jun 12, 2026
Centralized monitoring has improved threat detection and reduced response times significantly
Pros and Cons
  • "Splunk is one of the most powerful SIEM platforms due to its flexibility, scalability, and advanced search capabilities as it uses the SPL language."
  • "Regarding Splunk Enterprise Security improvements, I think there should be licensing flexibility, including cost optimization for larger data volumes."

What is our primary use case?

I work with a couple of security solutions as well as devices. We have companies such as IBM, Splunk, QRadar, and many other SIEM solutions. I have worked with technologies such as DLP firewalls, proxies, file transfer solutions, and monitoring via security monitoring solutions. I am from a security analyst background.

Regarding Splunk Enterprise Security, we have both this product and Splunk as a SIEM solution with us.

Regarding Splunk's real-time capabilities, I have been using it from the monitoring perspective. We have been onboarding our customers over to the Splunk platform, gathering log details from the security monitoring perspective, and building alerts over the Splunk platform. It serves as a SIEM solution and SIEM provider by Splunk. Splunk is one of the most powerful SIEM platforms due to its flexibility, scalability, and advanced search capabilities as it uses the SPL language.

Splunk has interactive dashboards with cloud detection and cloud integration platform capabilities, having their own built dashboards which help to get all details with the VPC flows and AWS data, showing how much data has been thrown, what the detections and vulnerabilities are, and we can easily access that information.

What is most valuable?

From our security monitoring perspective, the most valuable features are the dashboards. Splunk has a wide variety of dashboards and widgets available so I can monitor ROI, MTTD, and MTTR, which are required to adhere to SLAs with respect to clients. Splunk Enterprise Security also has valuable features such as the Splunk Processing Language (SPL), enabling analysts to perform advanced threat hunting, incident investigation, and log analysis over massive data sets for longer durations in real time. It helps create custom detections and rapid investigation queries.

Splunk Phantom with automation setup helped us reduce MTTD and MTTR time significantly. The automation ensures that detections get automated and notified to customers quickly. We have been positively impacted with the Splunk setup regarding automation and detection.

Splunk detects threats in real-time using the Splunk Query Language and helps with reduced MTTD and provides higher efficiencies. AI facilitates generating investigation queries without manual crafting. Interactive dashboards assist with retention, allowing analysts to prioritize alerts and start investigations quickly. The SOAR helps automate alerts and manage ITSM incidents, reducing MTTD and MTTR. UBA adds visibility to abnormal behaviors of users, and we have detected impossible travel incidents in near real-time and contained unauthorized attempts.

What needs improvement?

Regarding Splunk Enterprise Security improvements, I think there should be licensing flexibility, including cost optimization for larger data volumes. Additionally, for new users, the SPL language can be difficult. Practical examples provided within the dashboards or the query sets of datasets should be presented.

Regarding the pricing aspect, more licensing flexibility is needed. Splunk provides licensing based on data volume. If data peaks are above average, extra charges can occur. This should be optimal based on averages.

For how long have I used the solution?

I have been using Splunk Enterprise Security for three years.

What do I think about the stability of the solution?

Splunk Enterprise Security is stable. They have been pushing upgrades frequently, and this has remained stable as well.

How are customer service and support?

Splunk has continuously helped in terms of any issues or outages, helping us troubleshoot and having troubleshooting calls on a priority basis. They act according to their severity tags.

What was our ROI?

We have been having positive ROI. Time spent on log analysis and threat detection is less, and centralized multiple security tools have improved analyst efficiency. We have reduced our MTTD by about fifty percent with real-time detections.

What other advice do I have?

Splunk Enterprise Security has been helping us in terms of AI and detection quality. We have improved fine-tuning and reduced false positives. There have been no false positives in the environment, helping focus on true positives more.

Regarding risk-based volume, Splunk generates alerts based on risk and we focus on particular incidents. We have received positive feedback about RBAs helping with quick investigation and remediation. The Threat Topology helps with incident categorization and severity mapping. Minimal efforts bring content packs into production, requiring little fine-tuning.

I would rate this review a nine out of ten.

Which deployment model are you using for this solution?

Public Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
Last updated: Jun 12, 2026
Flag as inappropriate
PeerSpot user
Geoffrey Njogu - PeerSpot reviewer
Security & Privacy Engineer at a tech services company with 51-200 employees
Real User
Top 20
May 22, 2026
Unified monitoring has improved alert fatigue management and streamlined reporting workflows
Pros and Cons
  • "From using Splunk Enterprise Security, I have already seen benefits such as tracking alert fatigue in my team, especially with the SOC Operations dashboard and the Executive Dashboard."
  • "There is room for improvement for Splunk Enterprise Security. I moved away from Security Onion before switching to Splunk because Splunk was promising with Splunk AI, but now I am questioning if I made the right decision given that everybody is moving towards the AI aspect, especially since Splunk told me I cannot use Splunk AI on my platform and Security Onion already has the Gen-Sec SOC."

What is our primary use case?

Splunk Enterprise Security serves as my primary tool for security monitoring and log aggregation, allowing me to write correlation searches. I also use it for anti-money laundering purposes and have developed several use cases around that functionality.

What is most valuable?

The entire platform of Splunk Enterprise Security provides significant value, though breaking it down into individual features is challenging. The out-of-the-box log ingestion and integration with other platforms stands out as one of the most valuable aspects because I can pass data from different sources, making it very easy for me to work with.

From using Splunk Enterprise Security, I have already seen benefits such as tracking alert fatigue in my team, especially with the SOC Operations dashboard and the Executive Dashboard. I can track how many alerts we are closing, how fast we are closing them, and understand what my team is doing and what is taking too much of their time. That visibility is valuable. One of the best things about Splunk is the ability to create my own dashboards very quickly, which makes reporting straightforward for me.

What needs improvement?

There is room for improvement for Splunk Enterprise Security. I moved away from Security Onion before switching to Splunk because Splunk was promising with Splunk AI, but now I am questioning if I made the right decision given that everybody is moving towards the AI aspect, especially since Splunk told me I cannot use Splunk AI on my platform and Security Onion already has the Gen-Sec SOC.

Honestly, we are not fully using the functionality of risk-based alerting in Splunk.

For how long have I used the solution?

I have been working with Splunk Enterprise Security since around October 2022, so it has been almost two years.

What do I think about the stability of the solution?

So far, the product is very stable, and the support team is very accessible. If I have an issue, I can raise a ticket, and they either send an article or jump on a call, so they are very responsive.

What do I think about the scalability of the solution?

As of now, we are yet to fully track scalability because the team has not matured enough to use Splunk alone. We have alerts from our WAF, alerts from the EDR, and alerts from the firewall itself. Splunk serves more as a correlation platform with all the other alerts from the other defensive mechanisms sent to us via Slack, but we primarily want to use it for correlation.

We went through a vendor for our Splunk Enterprise Security purchase.

How are customer service and support?

I would definitely give my experience with technical support a rating of ten out of ten. I had an incident once, and the escalation started with a Tier 2 person and went all the way to staff engineers in a very short time, which was impressive.

Which solution did I use previously and why did I switch?

Comparing Splunk Enterprise Security with the open-source SIEMs I have only used, I would rate it an eight. The reason is that creating the searches had a very long learning curve for my team to understand how to create and improve correlation searches. Compared to tools such as Elastic Security or Security Onion, creating detection rules is more straightforward in those tools, and their community resources are convenient for troubleshooting. However, Splunk is very strong in terms of integration and fetching data from multiple platforms, which is a significant advantage for Splunk, making it easy to ingest logs from different sources.

How was the initial setup?

I took part in the deployment of Splunk Enterprise Security in my organization, and I am also the main administrator. I administer Splunk as well.

I had some issues here and there with most of the applications during the implementation of Splunk Enterprise Security, but I also worked with a consultant, and we eventually resolved them. The documentation was very helpful and quite thorough. Since it was my first time interacting with Splunk, getting around and understanding all the configuration files took some time, but I was comfortable running it by myself after the first three months.

What about the implementation team?

We went through a vendor for our Splunk Enterprise Security purchase.

What was our ROI?

I have seen a return on investment with Splunk Enterprise Security. It was tough to handle the reporting aspect and control alert fatigue from the team, but now with the visibility that I have, it is becoming very easy. We have also decommissioned some tools, such as Wazuh, because the Universal Forwarder can do almost everything Wazuh can do, and we have streamlined our focus to one area instead of looking into multiple dashboards.

What's my experience with pricing, setup cost, and licensing?

I find Splunk's pricing reasonable, but the fact that they do not disclose actual pricing makes it very hard to know whether we are overpriced, so it is difficult to know if they added a very large margin.

What other advice do I have?

Unfortunately, because of the pricing aspect, I could not get the SOAR feature, so I cannot speak to that functionality.

I do not have a specific number as of now, but what I can say is Splunk has given me visibility and a way to track results. If I log in to my dashboard, I can see that since we started, the findings and false positives, the notables that create our false positives, have been reducing over time, so it gives me that visibility.

No other problems were found, and I have been satisfied. I would rate this review an eight overall.

Which deployment model are you using for this solution?

On-premises

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Other
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Last updated: May 22, 2026
Flag as inappropriate
PeerSpot user
reviewer2745975 - PeerSpot reviewer
Works at a marketing services firm with 1,001-5,000 employees
Real User
Top 20
Jul 29, 2025
Extensive customization facilitates threat detection but integration with cloud and Git needs improvement
Pros and Cons
  • "The product is generally stable and forgiving."
  • "The GUI, now called Mission Control, which serves as issue management or ticket management, falls below what would be considered industry standards."
  • "The AWS add-on is particularly problematic, with most inputs requiring manual writing due to lack of out-of-box functionality."

What is our primary use case?

My use cases for Splunk Enterprise Security are extensive in production. I utilize it for all available functions including observability, asset management, vulnerability management, threat detection, network security, identity management, and various other capabilities.

How has it helped my organization?

The solution does require a lot of customization for an organization. 

What is most valuable?

It is highly customizable, which is a significant advantage. It requires substantial customization and tailoring to particular organization requirements, meaning that out of the box, most features would need configuration.

What needs improvement?

The risk and notables component, particularly the two-tier system of picking something from risk into the notable, is one of the most problematic features. 

The GUI, now called Mission Control, which serves as issue management or ticket management, falls below what would be considered industry standards.

AI assistance for security analysts to analyze notables and risks needs improvement. Although it exists, the demonstration is not yet sufficient for the required level. We need this as soon as possible to help security analysts. 

Splunk Enterprise Security is not cloud environment-friendly, especially when dealing with large cloud infrastructures. With significant AWS presence and multiple clouds, collecting asset data is challenging. The AWS add-on is particularly problematic, with most inputs requiring manual writing due to lack of out-of-box functionality.

Regarding the platform and Enterprise Security specifically, the lack of Git-friendly or Git-native integration is problematic. The recently introduced content management system is inadequate, attempting to implement an outdated concept of storing rule versions in an index while teams work with Git natively.

The storage of queries in savedsearches.conf prevents efficient work with query text. It should be structured as separate SPL files that can utilize intellectual add-ons for Visual Studio Code and work natively with GitHub. Content management is limited to applications within the Enterprise Security suite, excluding custom applications not starting with SA or DA.

For how long have I used the solution?

I have been using Splunk Enterprise Security for more than five years.

What do I think about the stability of the solution?

The product is generally stable and forgiving.

What do I think about the scalability of the solution?

When considering Enterprise Security in particular, it demonstrates good scalability.

How are customer service and support?

I contacted their technical support recently. The support provided is decent, though they often reference their knowledge base. For publicly available solutions, this can be redundant as these solutions can be found through internet searches. Support becomes valuable when dealing with issues requiring access to their closed knowledge base for faster responses.

While support provides solutions, implementation can be complex. In a recent case, the provided solution was so complex to implement that I decided not to proceed. The support staff themselves are highly knowledgeable, polite, and responsive, with some being exceptional. The support team deserves a perfect score.

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

I have experience with similar solutions such as AlienVault and ArcSight, each with its advantages and disadvantages. The recommendation depends on the working environment. For cloud-native and GitHub-native organizations, the Enterprise Security solution should align with those principles.

How was the initial setup?

I was solely responsible for the implementation.

It was one of the most difficult deployments I've ever handled. After we set up a cluster with consultants, we made it usable after a year and a half. 

Splunk Enterprise Security requires continuous maintenance, consuming approximately 50% of the time. The numerous data sources and constantly changing formats and source types demand ongoing work on data quality, detection rules, assets, and identities.

People are delegated for platform administration, though they currently need additional time to reach optimal performance levels.

What about the implementation team?

We did work with consultants during the deployment. 

What's my experience with pricing, setup cost, and licensing?

The pricing is currently managed by procurement. Even with substantial company discounts, it remains extremely expensive. This creates internal challenges when teams independently choose open-source or less expensive solutions for log dumping. Duplicating application logs becomes costly as teams may already use DataDog, ELK stack, Elasticsearch, or S3.

With data ingestion of two terabytes or more daily, Splunk Enterprise Security costs become significant. Cloud-native solutions, particularly in AWS, make it more practical to use native security detection mechanisms such as Security Hub, GuardDuty, and Inspector, using Splunk Enterprise Security as a data aggregator.

Many users prefer pre-processing data before ingestion using the Databricks platform for large data sources such as cloud trail logs. The on-premises pricing model based on data ingestion affects Splunk Enterprise Security's market position.

What other advice do I have?

This product requires significant investment in learning as it is not easily understood. Organizations purchasing the solution should expect 6-12 months with a dedicated team before meaningful insights can be delivered.

On a scale from one to ten, Splunk Enterprise Security rates as a seven.

Which deployment model are you using for this solution?

On-premises

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Amazon Web Services (AWS)
Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
PeerSpot user
reviewer2704098 - PeerSpot reviewer
Security & Risk Analyst at a computer software company with 1,001-5,000 employees
Real User
Top 20
May 10, 2025
Exceptional user interface and integrations enhance analytical capabilities
Pros and Cons
  • "The community marketplace is useful; often, you do not need to rely on Splunk Enterprise Security support due to the wealth of online documentation available—Splunk docs are truly beneficial."
  • "Splunk Enterprise Security is amazing."
  • "One area Splunk Enterprise Security fails to improve is the pricing aspect; while the initial pricing seems fine, the licensing cost can skyrocket over time, creating trauma for organizations."
  • "The default threat intel feeds create many false positives and noise, which is counterproductive."

What is our primary use case?

My use cases for Splunk Enterprise Security involve mostly standard use case detections. Essentially, whatever log sources we ingest into the platform, we define use cases for detecting anomalous behavior, with most of our use cases tied to that. 

Additionally, we utilize threat intelligence; we always use lookup tables or MISP integrations to enrich those use cases or create reports and dashboards to monitor them periodically, depending on how noisy those alerts are. 

Other use cases include compliance-based use cases for auditing purposes, as there are compliance policy breaches we want to monitor proactively on a 24/7 basis. We do that, often within a mix of MSSP environment versus in-house.

What is most valuable?

The specific features I find the most valuable in Splunk Enterprise Security include the amazing UI and good integrations, and I can say this from a practitioner standpoint. 

It is just comfortable. Splunk Enterprise Security is easy to use for an analyst, and the whole analyst experience is great; it is pretty insane. It is honestly very addicting. 

As I told my fellow colleagues, they love using Splunk Enterprise Security. Once you go to any other platform, it is similar to going through withdrawal sometimes. You have to set up use cases, update data models, and link the right use cases to the right data models for those detections to happen. 

In terms of challenges, there are none; Splunk Enterprise Security is one of the best vendors in the security analytics space.

Splunk Enterprise Security has implemented improvements that may help reduce false positives, as it has some amazing features that go underutilized, such as the machine learning toolkit. The gap in skill set within the SOC environment is the reason for this underutilization.

Splunk has some amazing features we are not utilizing. For example, ML. I have not specifically utilized AI-driven security initiatives or machine learning within Splunk Enterprise Security; even the ML toolkit is not related to advanced AI components. It operates more an advanced SQL query based on existing data trends without offering out-of-the-box advanced ML capabilities to provide significant value.

The dashboards for some default use cases are provided. Similarly, default dashboards and reports are provided. You can pivot off of these and drill down on your investigations. The Splunk query language is definitely very easy to understand and use on a regular basis. The learning curve is also very low. So, from a practitioner standpoint, you're not going to face so much struggle in learning the Splunk query language. In fact, for other solutions, you might need AI capabilities to translate natural language. 

Additionally, Splunk Enterprise Security claims to reduce data storage to a certain extent. I'm not sure if that's the case, however, I have heard that that was the case.

Lookup tables are very useful in Splunk. 

What needs improvement?

The effectiveness of threat detection and response in Splunk Enterprise Security depends on how the team leverages it. Splunk Enterprise Security is not something that automatically picks things; you have to set up use cases, update data models, and link the right use cases to the right data models for those detections to happen. This is SIM-tool agnostic. If you do not have the right use cases, nothing will be detected at the end of the day. 

One challenge under that note is if your company goes through some kind of digital transformation or major solutions being replaced, and all these logs are being ingested into Splunk Enterprise Security, the data models do not get updated proactively. Splunk Enterprise Security does not have a mechanism to identify that certain data models have stopped sending logs. How do we update our data models accordingly? This issue reflects back to our use case detections.

In discussing areas for improvement in Splunk Enterprise Security, I assert that their default threat intel is inadequate. When ingesting threat intel from other sources, it would be beneficial to have capabilities that enrich the information within Splunk Enterprise Security with less dependence on a threat intel platform. The default threat intel feeds create many false positives and noise, which is counterproductive.

The UEBA aspect of Splunk Enterprise Security should also see enhancement, as it lacks that functionality.

Splunk search can sometimes take a long time; it can even time out. You have to make sure your query is very specific. It would be useful if Splunk used AI to help you write queries. I'm not sure if AI is used this way just yet.

For how long have I used the solution?

My experience with Splunk Enterprise Security is from within the last 18 months.

What do I think about the stability of the solution?

Regarding stability with Splunk Enterprise Security, I do not recall facing performance issues at the moment. 

What do I think about the scalability of the solution?

The solution can scale. When your environment scales, the search operations can lag significantly.

One entity I worked with was a managed service company that managed companies of all sizes, up to 30,000 or 40,000 employees. We work with large firms. 

How are customer service and support?

The technical support of Splunk Enterprise Security is quite good, and I would rate it a four out of five (eight out of ten) easily. They are responsive and effectively resolve issues. 

The community marketplace is also useful; often, you do not need to rely on Splunk Enterprise Security support due to the wealth of online documentation available—Splunk docs are truly beneficial.

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

I enjoy my work with Splunk Enterprise Security, and while I can say the same for Elastic, I have found other vendors such as QRadar, Exabeam, LogRhythm, and Sumologic not to be as impressive. I prefer ElasticSearch since it allows for quicker searches, making threat hunting and proactive activities easier, whereas Splunk Enterprise Security searches can take considerable time.

AlienVault's open-source solutions seemed inadequate compared to this, and QRadar was even worse. Thankfully, they are no longer relevant.

How was the initial setup?

I was somewhat involved in the initial setup of Splunk Enterprise Security. That said, it was not complex enough for a clear comparison with larger environments. 

Deploying indexers and forwarders is straightforward, though human errors can potentially occur in the process. It is challenging for me to compare the implementation of other similar tools versus Splunk Enterprise Security, however, the clarity on implementation could be enhanced. 

Maintaining Splunk Enterprise Security on-premise is not difficult at all, especially compared to other platforms I have not maintained as extensively. Many resources are available in the market to help with Splunk Enterprise Security, so finding people skilled in it is relatively easy due to the market's maturity.

What's my experience with pricing, setup cost, and licensing?

One area Splunk Enterprise Security fails to improve is the pricing aspect; while the initial pricing seems fine, the licensing cost can skyrocket over time, creating trauma for organizations.

It's really hard to justify the pricing. The only way it makes sense is if you reduce the number of nodes being ingested over time. If you can optimize that as you scale, it can stay affordable. 

What other advice do I have?

Now that Splunk Enterprise Security has been acquired by Cisco, I am uncertain whether it will retain its current traction or be dissolved in the coming years. 

I would rate Splunk Enterprise Security as a product an easy eight out of ten.

However, it is an easy eight as of now. Post-Cisco acquisition, the future remains uncertain. Would I recommend Splunk Enterprise Security to someone else? Absolutely. Splunk Enterprise Security is amazing. Despite all the issues, it simplifies the lives of everyone who uses it, and there is not a steep learning curve. 

Compared to other tools I discussed earlier, Splunk Enterprise Security is significantly better. Personally, I would choose Elastic and Splunk Enterprise Security over any other options.

Which deployment model are you using for this solution?

On-premises

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Other
Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
PeerSpot user
Buyer's Guide
Download our free Splunk Enterprise Security Report and get advice and tips from experienced pros sharing their opinions.
Updated: June 2026
Buyer's Guide
Download our free Splunk Enterprise Security Report and get advice and tips from experienced pros sharing their opinions.