The typical use case for Splunk Enterprise Security is to meet regulations and requirements for critical infrastructure. It is used to audit changes and authentication logs. The second purpose is for security operation center management and security management.
Splunk System Engineer at a non-tech company with 11-50 employees
Correlation engine and alert features significantly reduce alert volume
Pros and Cons
- "It's great for finding anonymous threats."
- "The stability of Splunk Enterprise Security is very impressive; it is a very stable product."
- "Splunk Enterprise Security can be improved mainly from the user interface regarding the visualizations. They are working on it, yet there are only five to ten very basic visualizations."
What is our primary use case?
What is most valuable?
The most valuable features of Splunk Enterprise Security are the main component, which is the correlation engine that can specify detailed conditions such as how many events there need to be, what notification I will get, and if I get it per event or one per batch.
There is also throttling; in basic Splunk, there is no throttling at all. In Splunk Enterprise Security, there is an additional layer of control of these alerts. I appreciate the correlations and the alerts in that product.
The asset management is particularly useful. We can enable asset lookups to show in every event. We define one, and it will translate to all events, allowing asset management to be easy.
Splunk Enterprise Security helps to reduce alert volume because the language is similar to SQL with Google-style functionality above it. We can use these terms to specify what is in the allow list. We can specify what's in lookups, what should be there, and what's not. It definitely helps to reduce the numbers of full score.
Splunk Enterprise Security helps to speed up security investigations. When the finding is created, there are many correlations. You can quickly see what asset it is, what identity is involved, and you see the historical progress of what happened. Right from the findings, you can call VirusTotal and other resources, which is definitely helping.
I assess Splunk Enterprise Security's insider threat detection capabilities for helping to find unknown threats and anomalous user behavior as great. It regularly checks new events through the correlation search and compares them with threat intelligence. The threat intelligence is refreshed regularly, downloading new threat information. Splunk has a special research team for security content and intelligence, which distributes its own threat list to Splunk Enterprise Security.
It's great for finding anonymous threats. It checks new events and also works with the latest threat intelligence. At least once a day, it develops new threat information. In Splunk, there is a special research team. They are also distributing their own threat lists. The solution is capable of very good threat detection.
In basic SPL, with the Splunk query language, we can detect brute force without threats. It scans every event, and if it finds patterns, IOCs, it can trigger notable events, which are now called findings. The new version includes an internal Git repository, so when the SOC team makes improvements to the correlation search and makes changes, it automatically keeps a history of that correlation search, what was changed, when, by whom, and you can revert if it breaks.
The value that Splunk Enterprise Security offers in resilience is vital. It helps customers distributing gas across the Slovak Republic, ensuring that critical infrastructure, such as operational pipelines, are running. If there were an outage that delayed recovery, the economic impact could be significant.
It's good for analyzing malicious activities and detecting breaches. The interface sometimes can be very essential.
Splunk has helped us reduce alert volume. We can use terms to specify what is whitelisted and we can search like we would on Google.
We've been able to speed up security investigations. We a finding is created, there are many correlations. You can quickly see the asset, the identity involved, the history, et cetera.
What needs improvement?
Splunk Enterprise Security can be improved mainly from the user interface regarding the visualizations. They are working on it, yet there are only five to ten very basic visualizations. When you have your data all set and the customer wants some new dashboards that would help them, it is pretty complicated to build them from the built-in visualizations.
This is one of the blocking points in Splunk, however, they're working on a new layer called Dashboard Studio. It is still limited. An older version of Splunk allowed implementation of JavaScript to capture events when a user clicked by mouse, which enabled great features. In the improved Dashboard Studio, this is not possible. They have improved one part and have made the other part worse, so it still lacks a premium feeling. Cisco will improve it, however, it seems they are focusing on what the big companies want. They will implement it if it's usable for these big players that pay, but for small companies, it's too pricey to use this solution.
For how long have I used the solution?
I've been working with this solution for seven years.
Buyer's Guide
Splunk Enterprise Security
August 2026
Learn what your peers think about Splunk Enterprise Security. Get advice and tips from experienced pros sharing their opinions. Updated: August 2026.
913,422 professionals have used our research since 2012.
What do I think about the stability of the solution?
The stability of Splunk Enterprise Security is very impressive; it is a very stable product. They handle these things perfectly and conduct internal testing thoroughly.
They test it very thoroughly before release, and our customers have Splunk running for months without issues.
When I observe how customers work with Splunk in the cloud, it is also very good. They manage maintenance windows and inform customers, resulting in little to no interruptions to workflow. In terms of stability, I would give it a full score.
What do I think about the scalability of the solution?
We work with medium to large organizations. Our typical environment has 500 servers. In volume, we're looking at 100GB in storage. From Splunk's view, we're doing rather small volumes. It's big in a Central European context, and small from a Splunk North American context. It can be pricey for small companies.
How are customer service and support?
I would rate technical support from Splunk Enterprise Security as a six out of ten.
It's average, considering it's a very big product, and they handle several hundred tickets a day. I have opened 20 to 30 cases, and they helped me with only three to five of them. They try to close issues as soon as possible, often just offering documentation links.
Even when I provide them with the core problem, they do not help much. The customer often has to rely on workarounds, custom scripts, and solutions which are somewhat lacking.
Which solution did I use previously and why did I switch?
Before Splunk Enterprise Security, I didn't use a different solution; this was my first job, and I started working full-time with Splunk about eight years ago.
In the beginning, when they were testing, I was shown the OP5 and Nagios operating monitoring; we used tried them out, however, they were not really security-related.
How was the initial setup?
You can quickly set up Splunk by downloading the package, unpacking it, and starting to work. It's straightforward to get a quick view of your data, and you do not have to worry about connections to databases; it will start parsing the data as soon as you hand it over. For bigger environments with several hundred servers, Splunk Enterprise Security is the best solution.
What was our ROI?
Customers see the value in investing in this solution, particularly when it helps resolve issues quickly, turning a potential 20-hour response into one hour.
What's my experience with pricing, setup cost, and licensing?
It's still pretty pricey. It's an expensive solution for smaller companies.
That said, if someone evaluating SIEM solutions wants to go with the cheapest solution, Splunk Enterprise Security is a very good option. It has difficulties in administration and setup, however, in comparison with other products, it's still a great platform.
What other advice do I have?
My relationship with Splunk is that we are a partner and reseller partner. My organization does not monitor multiple cloud environments; we primarily monitor M365 and Azure environments from cloud products. We use the Microsoft Add-on for Splunk to read Exchange and Microsoft audit logs from the cloud. However, we still prefer on-premise solutions in our country.
We use the Mission Control feature. It's replaced another component. I don't use it too much myself. It's like a connector for SOAR. We're investigating its capabilities and have not implemented it fully.
Overall, I would rate Splunk Enterprise Security a nine out of ten. If you want to see your data quickly and in full view, it's very good - specifically for bigger environments.
Which deployment model are you using for this solution?
On-premises
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
Issm at a government with 10,001+ employees
Video Review
Prioritizes critical threats and improves collaboration across teams for faster incident response
Pros and Cons
- "Splunk Enterprise Security helps my SOC team prioritize and investigate high-fidelity alerts more effectively by enabling us to quickly gather information, collaborate, and provide various teams with access to the same information, allowing them to follow the workflow to complete the task."
- "Splunk Enterprise Security can improve in terms of probably being able to talk to additional sources."
What is our primary use case?
My main use cases for Splunk Enterprise Security are insider threat, application security, incident response, and risk forecasting.
What is most valuable?
I appreciate the ability of Splunk Enterprise Security to tap into various network equipment and services on the network to pull it all into one place. That's my favorite feature.
The feature I've mentioned helps us in responding to incidents and disasters and different technical situations by being able to pull data from various sources and analyze it and take action.
Splunk Enterprise Security's Risk-Based Alerting, or RBA, has enabled us to prioritize and focus on the most critical threats and issues, while blocking out some of the noise and various information that can come from all these different sources.
Splunk Enterprise Security helps my SOC team prioritize and investigate high-fidelity alerts more effectively by enabling us to quickly gather information, collaborate, and provide various teams with access to the same information, allowing them to follow the workflow to complete the task.
Splunk Enterprise Security's ability to ingest and normalize data from diverse sources has enhanced our threat detection capabilities by making us aware of what's going on in the world, relating to our use cases and our threat tolerance, as we constantly pull in that information and brief everyone who has a stake.
What needs improvement?
Splunk Enterprise Security can improve in terms of being able to add to additional sources. They're adding many different ones, but as more cloud and data lakes emerge, being able to touch all those different new technologies that emerge together would be beneficial.
What do I think about the stability of the solution?
I assess the stability and reliability of Splunk Enterprise Security as very reliable and stable so far. We haven't had any glitches with testing out the first pilot use of it.
What was our ROI?
From my point of view, the biggest return on investment when using Splunk Enterprise Security is definitely being able to respond to incidents faster, adapt to future attacks by analyzing that information and doing risk-based management decisions, and also preparing for the future by looking at new technologies that can help us.
What's my experience with pricing, setup cost, and licensing?
I'm not too involved with the pricing, the setup costs, and the licensing of the platform. It is pretty straightforward.
What other advice do I have?
We just started turning on UEBA in our company, but we haven't really started utilizing it yet. There is a roadmap to try to do some of that stuff from the program side, and we just have to get access to it once the enterprise is ready to implement it and hand it over to the program office.
Even though we just started using UEBA, it's very useful, and it helps us set a bar for what normal activity is, and then it sets alerts and gives us awareness for anything that's out of the norm in terms of normal user behavior and the data that's being accessed.
My advice to other companies considering Splunk Enterprise Security is that you should definitely look into it, get your folks a proof of concept and try it out, send folks to training, and let them learn about it, and see how it can help you be better at securing your environment.
I rate Splunk Enterprise Security nine out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Buyer's Guide
Splunk Enterprise Security
August 2026
Learn what your peers think about Splunk Enterprise Security. Get advice and tips from experienced pros sharing their opinions. Updated: August 2026.
913,422 professionals have used our research since 2012.
Technical Support at Softcell Technologies Limited
Ai-driven threat detection has improved investigations and now speeds up incident response
Pros and Cons
- "The consolidation of SIEM, SOAR, and UEBA into a single interface has greatly improved my efficiency."
- "Areas for improvement in Splunk Enterprise Security include enhancements to the dashboard and reporting features, as well as better handling of queries during peak times and improving self-monitoring dashboards."
What is our primary use case?
My use case for Splunk Enterprise Security is mainly for enterprise defense, including cyber threats and cybersecurity threat detection, as I have worked at an administrator level within the security model which utilizes multiple feeds including Elasticsearch.
What is most valuable?
The best features of Splunk Enterprise Security are the AI models and the reporting function, which is very good and faster than other solutions.
The impact of Splunk Enterprise Security on my organization is that it helps to identify bottlenecks and it is effective in large-scale environments, although my environment is medium-scale.
The AI-driven detections improve the accuracy of my investigations by enhancing infrastructure, conducting health checks, and providing insights that recommend features for Splunk Enterprise Security, especially for security-related queries.
Risk-based alerting in Splunk Enterprise Security analyzes alerts by checking logs and processes, allowing me to determine the targeting process and destination IP.
What needs improvement?
Areas for improvement in Splunk Enterprise Security include enhancements to the dashboard and reporting features, as well as better handling of queries during peak times and improving self-monitoring dashboards.
For how long have I used the solution?
I have been using Splunk Enterprise Security for the last one year.
What do I think about the stability of the solution?
Regarding stability, it is okay, with no issues.
What do I think about the scalability of the solution?
In my organization, around three thousand users utilize Splunk Enterprise Security.
How are customer service and support?
I rate the technical support a nine out of ten.
How was the initial setup?
The deployment of Splunk Enterprise Security is easier.
It takes about one or two days for deployment, depending on customer availability.
What was our ROI?
My mean time to detect and respond has become faster by about fifty percent.
What's my experience with pricing, setup cost, and licensing?
The pricing is moderate; it is neither expensive nor cheap.
Which other solutions did I evaluate?
Compared to other vendors, I find Splunk Enterprise Security to be the best.
What other advice do I have?
In the SIEM solution review, I have experience with Splunk Enterprise Security and Wazuh.
I use Wazuh as my SIEM solution.
Additionally, I use Splunk Enterprise Security.
Specifically, Splunk Enterprise Security is the threat detection product, so it is based on AI technology.
Regarding stability, it is okay, with no issues.
The integration of threat intelligence into the TDIR workflow has improved my ability to block threats by utilizing AD integration and Syslog forwarding integration, allowing logs to be effectively forwarded to EDR.
The consolidation of SIEM, SOAR, and UEBA into a single interface has greatly improved my efficiency.
I have upgraded to Splunk Enterprise Security eight point zero.
The detection version is lacking some specific functionalities.
The deployment model is on-premises.
I provide an overall review rating of nine out of ten for Splunk Enterprise Security.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer. Reseller
Last updated: Jul 15, 2026
Flag as inappropriateDirector, Technology at a financial services firm with 5,001-10,000 employees
Automated our soc workflows and improved incident response while correlation still needs work
Pros and Cons
- "Splunk Enterprise Security has positively impacted our organization by allowing us to stand up a SOC and make it automated."
- "We have had some issues with customer support on getting answers for Splunk Enterprise Security, but we have been able to escalate it and get resolution."
What is our primary use case?
Splunk Enterprise Security serves as our main security information and event management solution for our SOC. We have a setup to pull alerts for our SOC, and then we use it to work through each of the incidents we discover. We also use it to develop SOAR and utilize the SOAR piece to develop playbooks.
How has it helped my organization?
Splunk Enterprise Security has positively impacted our organization by allowing us to stand up a SOC and make it automated. It has also allowed us to reduce our time on researching incidents. We are able to resolve incidents in a much quicker timeframe using Splunk Enterprise Security, although I don't have exact metrics to share.
What is most valuable?
The best features Splunk Enterprise Security offers include the ability to look at all of our data and create playbooks that we can then use for all of the different analysts. When it comes to creating playbooks for our analysts in Splunk Enterprise Security, I find that it works fine. There are also many apps that we can use, which we appreciate.
What needs improvement?
To improve Splunk Enterprise Security, I would recommend making it easier for events to be correlated together.
For how long have I used the solution?
I have been using Splunk Enterprise Security for about four years.
What do I think about the stability of the solution?
Splunk Enterprise Security is stable.
What do I think about the scalability of the solution?
We haven't had any issues with Splunk Enterprise Security's scalability, so it seems to be functioning well.
How are customer service and support?
We have had some issues with customer support on getting answers for Splunk Enterprise Security, but we have been able to escalate it and get resolution.
Which solution did I use previously and why did I switch?
We didn't previously use a different solution before Splunk Enterprise Security as we had a homegrown solution.
How was the initial setup?
We are currently working on the upgrade to Splunk Enterprise Security 8.0 but have not completed it and rolled it out yet.
What was our ROI?
Splunk Enterprise Security has helped reduce our team's average mean time to resolve, also known as MTTR metric, but I don't have the actual numbers available and don't want to guess.
What's my experience with pricing, setup cost, and licensing?
I don't know if we purchased Splunk Enterprise Security through the AWS Marketplace since I don't deal with the accounting and the purchases. I don't actually deal with the pricing, setup cost, and licensing, so I don't have any insight into that. I don't have any relevant metrics, such as fewer employees needed, money saved, or time saved, to share regarding the return on investment for Splunk Enterprise Security.
Which other solutions did I evaluate?
We didn't really evaluate any other options before choosing Splunk Enterprise Security since we already were using Splunk and it met our needs.
What other advice do I have?
Splunk Enterprise Security's risk-based alerting, also known as RBA, has allowed us to reduce some of the alerts and direct the analysts to work on the ones that have a higher risk, so it has been helpful. The threat topology and MITRE ATT&CK framework features are useful. Our threat detection team uses it, but I personally haven't, so I don't have a lot of insight into that. Splunk Enterprise Security has helped us detect threats faster. We do use it and believe it helps us identify threats in a more timely manner, although I can't give exact metrics on how much faster. I would tell others looking into using Splunk Enterprise Security that it meets our company's needs, and we're able to use it and resolve our use cases. I rate this product a seven out of ten.
Which deployment model are you using for this solution?
Hybrid Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Last updated: Sep 17, 2026
Flag as inappropriateSoc Lead at a recreational facilities/services company with 201-500 employees
Correlation searches have transformed our soc triage and reduce alert fatigue every day
Pros and Cons
- "I love using Splunk Enterprise Security; it's one of my favorite tools, and I think it's needed in every single SOC environment."
What is our primary use case?
My main use case for Splunk Enterprise Security is utilizing the correlation searches in the SOC environment that I work in to triage events.
A quick specific example of how I use it to triage events is that recently it helped us in a lateral movement case where we set up the correlation searches to detect lateral movement using the different telemetry and logs that were available. We were able to determine if it was a false positive or not through that capability.
What is most valuable?
Splunk Enterprise Security has positively impacted my organization greatly; without it, I don't even know how we had a SOC previously.
Since using Splunk Enterprise Security, I have seen specific outcomes and improvements such as our mean time to detection and mean time to mitigation substantially decreasing, and it has helped a lot with the team as well. The SOC analysts who used to have alert fatigue don't experience that as much anymore.
Some of my favorite features that Splunk Enterprise Security offers are the dashboards that it has available. What I appreciate most about the dashboards is definitely both the visualizations and the way that we customize them. We are able to customize them for our environment and then for the individual customers that we support as well, and taking all that data and being able to view it on the screen and make sense of it is the best.
We set up the custom correlation searches ourselves, which has been really helpful because previously we didn't have any correlation searches—it was just out-of-box searches that were set up, and then we were able to build it out to our environment, specific to the data that we have visibility into.
Splunk Enterprise Security's Risk-Based Alerting has positively impacted my alert volume and analyst productivity, as the metrics that it uses for RBA have been very helpful for us in being able to prioritize alerts, resulting in a substantially smaller alert volume compared to what it used to be, allowing analysts to be very productive.
The native integration with Splunk SOAR in Splunk Enterprise Security 8.0 has been excellent; we have set up a lot of playbooks.
Splunk Enterprise Security's accuracy and reliability of output is very accurate; I haven't noticed any errors.
Splunk Enterprise Security's AI capabilities are great, and a lot of the AI capabilities that are automatically built into it are excellent.
What needs improvement?
Splunk Enterprise Security can be improved by providing more visualizations, and if we have workflow actions that can be set up with it to help with OSINT, that would be a lot better.
For how long have I used the solution?
I have been using Splunk Enterprise Security for over eight years.
What do I think about the stability of the solution?
Splunk Enterprise Security is stable.
What do I think about the scalability of the solution?
The scalability of Splunk Enterprise Security is great.
How are customer service and support?
The customer support for Splunk Enterprise Security is excellent; they have been very helpful, and it's one of the things I love the most.
Which solution did I use previously and why did I switch?
We previously were using Elastic, and now we're using Splunk.
What was our ROI?
I have seen a return on investment in that time has been saved for the analysts and their workload has gotten a lot lighter.
What other advice do I have?
My advice to others looking into using Splunk Enterprise Security is to not wait; implement it as if it is necessary and you needed it yesterday.
I love using Splunk Enterprise Security; it's one of my favorite tools, and I think it's needed in every single SOC environment. I have been using it for years, and every time that I've switched jobs, I have been an advocate to try to get them to bring it on.
Splunk Enterprise Security has helped improve my organization's business resilience. Splunk Enterprise Security has helped reduce my team's average mean time to resolve metric, although I'm not certain by how much.
Which deployment model are you using for this solution?
Hybrid Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Amazon Web Services (AWS)
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Last updated: Sep 16, 2026
Flag as inappropriateComputer Systems Application Specialist I at a mining and metals company with 501-1,000 employees
Security platform has improved compliance alerting and speeds investigations for critical servers
Pros and Cons
- "I have seen a return on investment with Splunk Enterprise Security, particularly in terms of money saved, as it has helped save money by allowing us to avoid renewing our previous SIEM, leading us to save hundreds of thousands of dollars."
What is our primary use case?
Splunk Enterprise Security serves as our SIEM.
What is most valuable?
Splunk Enterprise Security offers comprehensive capabilities that provide significant value to our organization. The alerting functionality helps our team day-to-day by supporting our compliance process, as we have compliance requirements that necessitate alerts for multiple failed logins, which will notify us if it reaches a certain threshold, prompting our analysts to log into Mission Control, start the investigation, and document from the time the alert was triggered. We also have a dashboard in Splunk Enterprise Security where we monitor disk usage of our Linux servers and set specific thresholds; if it exceeds a certain percentage, it sends an alert, which serves as our starting point to investigate. Splunk Enterprise Security positively impacts our organization by giving us visibility and enabling us to monitor the health of our servers, along with helping us detect any anomalies.
Since using Splunk Enterprise Security, we notice faster response times, particularly with metrics such as CPU, memory, or disk space usage, because we have visibility into those systems, making it easier to start an investigation when alerted.
Splunk Enterprise Security's risk-based alerting, RBA, has shaped our alert volume and analyst productivity by allowing us to categorize specific alerts as high risk, which we focus on immediately, while allowing lower priority alerts to be acknowledged later.
What needs improvement?
We are exploring improving Splunk Enterprise Security by integrating AI, as I attended a session about integrating with the MCP server, which we believe will help us improve triage and speed up investigations.
Splunk Enterprise Security could be improved by having more skills within the MCP that tie to compliance regulations such as NERC CIP, which is important for the utility industry.
For how long have I used the solution?
I have been using Splunk Enterprise Security for one year.
What do I think about the stability of the solution?
Splunk Enterprise Security is stable.
What do I think about the scalability of the solution?
We have not encountered scalability issues with Splunk Enterprise Security.
How are customer service and support?
Splunk Enterprise Security's customer support is amazing. I would rate the customer support of Splunk Enterprise Security a 10, as they are helpful.
Which solution did I use previously and why did I switch?
We used a different vendor before switching to Splunk Enterprise Security, and the previous service was significantly expensive for renewal.
What was our ROI?
I have seen a return on investment with Splunk Enterprise Security, particularly in terms of money saved. Splunk Enterprise Security has helped save money by allowing us to avoid renewing our previous SIEM, leading us to save hundreds of thousands of dollars.
What's my experience with pricing, setup cost, and licensing?
My experience with pricing and setup costs for Splunk Enterprise Security is reasonable, and the sales representatives are helpful in guiding us through the sizing to maximize our licensing needs.
Which other solutions did I evaluate?
We did not evaluate other options before choosing Splunk Enterprise Security, as we were aware that it is the go-to choice for many companies and our corporate predecessor was already using it.
What other advice do I have?
Splunk Enterprise Security Essentials has not significantly contributed to a reduction in analyst burnout or fatigue, as my team is small but critical, focusing on a limited number of servers. My advice to those looking into using Splunk Enterprise Security is to try it and see for themselves. I rate this review a 10.
Which deployment model are you using for this solution?
On-premises
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Other
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
Last updated: Sep 16, 2026
Flag as inappropriateTechnical Lead at a tech services company with 11-50 employees
Custom rule capabilities have delivered early threat detection and reduced analyst alert noise
Pros and Cons
- "Splunk Enterprise Security positively impacts our organization and clients mainly through early detections in the security landscape, allowing us to detect vulnerabilities and intrusions much earlier than previously undetected issues."
- "I believe the areas of improvement for Splunk Enterprise Security would focus on resource utilization."
What is our primary use case?
My main use case for Splunk Enterprise Security is for detections.
A specific example of how I use Splunk Enterprise Security for detections involves VPN use cases, where we deal with clients who have numerous third-party vendors supported on VPN, leading to scenarios where users might share their VPN credentials, allowing access from disparate geographical locations. Splunk Enterprise Security is particularly effective at detecting these logins from different locations over a short period and alerting on these events, indicating users who are sharing their credentials.
There are quite many use cases, and some are user-customizable; for instance, we might have someone wanting to know which users got SSH access to servers over working hours or who is accessing RDP outside of working hours. We usually cover traditional brute force attacks and network intrusions within the rules that we enable.
What is most valuable?
The best features that Splunk Enterprise Security offers include easy customization of the rules and a pool of out-of-the-box rules, where creating customizable rules is quite user-friendly and easily achievable without a lot of complexity and required technical knowledge.
The easy customization of rules has helped my team and clients significantly, such as when customers migrate from older SIEMs and request that their previous rules and shortcomings be translated into Splunk Enterprise Security. We are able to create correlation searches within a few hours to achieve the necessary thresholds and supplement what was missing in their previous deployments. Basically, whatever a user can think of, we can translate it into a detection rule, allowing the customer to gain value.
The richness of those rules significantly benefits us when dealing with customers, as it is not a one-size-fits-all model. We have different customizations for different technology layers, so if there are detections tailored to AWS, we do not enable those for customers who are not using AWS, which makes the environment quite efficient.
Splunk Enterprise Security positively impacts our organization and clients mainly through early detections in the security landscape, allowing us to detect vulnerabilities and intrusions much earlier than previously undetected issues. Clients can comply with regulations, act on the detections within their environment, and gain actionable insights. Additionally, there is a minimization of alert load through the risk-based alerting system, which significantly reduces the alert noise for analysts, enhancing their overall work efficiency.
What needs improvement?
I believe the areas of improvement for Splunk Enterprise Security would focus on resource utilization. For smaller environments lacking adequate CPU and memory resources, the system tends to be laggy, so reducing resource consumption would greatly improve experiences in most customer environments.
The usability of the solution is well built, and the interface is intuitive, so there are few improvements to suggest apart from implementing multi-tenancy, which is a frequent request we receive, especially from regional banks managing different branches under varying administrative controls.
For how long have I used the solution?
I have been using Splunk Enterprise Security for coming up to five years now.
What do I think about the stability of the solution?
Splunk Enterprise Security is stable.
What do I think about the scalability of the solution?
Its scalability is impressive, especially when utilizing a multi-site search head cluster; we encounter no challenges scaling the solution.
How are customer service and support?
Customer support is excellent, with same-day responses to our opened tickets and a quick turnaround for out-of-the-box support queries.
Which solution did I use previously and why did I switch?
Previously, we used ArcSight, but we switched to Splunk Enterprise Security mainly due to the limitations of the ArcSight solution in adapting to the changing security landscape.
What was our ROI?
We have observed a return on investment in terms of turnaround time for incident investigations and a reduction in the number of engineers required to manage the system; where three agents were once necessary, tasks are now comfortably handled by two, though we typically maintain two for high availability.
What's my experience with pricing, setup cost, and licensing?
The most significant impact we see relates to license costs. While implementation and setup costs are manageable since we provide those services, the license expense is the primary cost concern.
Which other solutions did I evaluate?
Before choosing Splunk Enterprise Security, we evaluated other options, including FortiNet FortiSIEM and IBM QRadar.
What other advice do I have?
My advice for others considering Splunk Enterprise Security is to try it out, prepare definitive data sources, narrow down on the use cases they want to address, and focus on ensuring data availability to support those use cases.
I want to appreciate the effectiveness of Splunk Enterprise Security, how well it is designed, and its capability to meet customer objectives. I would rate this product a 9 out of 10.
Which deployment model are you using for this solution?
Private Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Other
Disclosure: My company has a business relationship with this vendor other than being a customer. Reseller
Last updated: Sep 16, 2026
Flag as inappropriateSecurity Delivery Senior Analyst at Accenture
Advanced analytics have boosted investigations and consistently improve incident response speed
Pros and Cons
- "Splunk Enterprise Security's risk-based alerting positively impacts my alert volume and analyst productivity because we get low, medium, and high-security alerts based on the use cases driven in Splunk Enterprise Security, and we receive good feedback from clients regarding our productivity as we consistently resolve incidents meeting SLA, resulting in increased client satisfaction with our team and work over the past two to three years."
- "In my opinion, improvements in Splunk Enterprise Security could address the issue of unnecessary alerts. Sometimes we receive many false positives, leading to difficulties in identifying real security incidents."
What is most valuable?
For search queries in Splunk Enterprise Security, we can build our deep-dive investigations as it will not be too complex. We can find L2 and L3 level investigations. In the initial stages, if we do not find any trace of an alert, malware, or any kind of malicious activity, we can dig into the investigation with the help of queries. Overall, dashboards help as well. For example, we can find O365 authentication activities and deauthentication, which lets us see different locations where the user is logged in and whether they are using a VPN or not. If they log in with a VPN IP, it shows a different location. We can monitor authentication activities for normal users and create dashboards for them. Splunk Enterprise Security also allows us to investigate suspicious emails and blacklisted IP traffic, making it an excellent feature for malware investigation and network traffic analysis.
The AI-driven detections and assistance in Splunk Enterprise Security have improved the accuracy. Recently, I have integrated a copilot with Microsoft Teams for AI investigations. I use it when I cannot find information in the basic data. For example, if I provide the use case name, it gives information about the overall picture of the alert activities. We have to check user logs for any activities that happened on a host or if a suspicious user has logged into an AD account, including any changes to paths or modifications to files. This kind of investigation can be facilitated with AI in Splunk Enterprise Security.
Regarding whether Splunk Enterprise Security has helped reduce my team's average mean time to resolve issues, I can say that it almost resolves incidents within one hour. It depends on the clients, with a mean time of approximately thirty minutes for low alerts and up to six hours for high-security alerts. We must follow our SLA for any particular alert.
I can say that the average mean time to detect specific attacks with Splunk Enterprise Security is around five to six minutes or seven minutes, and under specific conditions, it can be eight minutes. For top security incidents, we can detect within under sixty minutes using a formula: alert time minus activity start time divided by the number of incidents.
Splunk Enterprise Security's risk-based alerting positively impacts my alert volume and analyst productivity because we get low, medium, and high-security alerts based on the use cases driven in Splunk Enterprise Security. We receive good feedback from clients regarding our productivity, as we consistently resolve incidents meeting SLA, resulting in increased client satisfaction with our team and work over the past two to three years.
The MITRE ATT&CK framework features are beneficial for helping discover the overall scope of incidents because we have integrated it into our use cases within Splunk Enterprise Security. It helps to map various attacks such as persistence, brute-force attacks, and blacklisted IP activities. We follow the process of incident response and the MITRE framework to investigate alerts effectively.
Splunk Enterprise Security Essentials contributes to reducing analyst burnout or fatigue because we have mapped it with the MITRE framework and the Cyber Kill Chain. This integration leads to more detections and helps mitigate numerous malware and security alerts, thus improving productivity and creating a healthier work environment.
What needs improvement?
In my opinion, improvements in Splunk Enterprise Security could address the issue of unnecessary alerts. Sometimes we receive many false positives, leading to difficulties in identifying real security incidents. We could reduce alerts for scheduled activities to lessen our workload because, in a set of one hundred alerts, perhaps only one is a security incident, which we may miss amidst all the noise. Filtering and sorting are time-consuming but necessary, as seen in other SIEM tools like IBM QRadar and ArcSight. However, I still believe Splunk Enterprise Security is superior, considering my experience over several years.
Pricing for Splunk Enterprise Security is high, but I do not have in-depth knowledge as that is managed by higher management. I cannot provide a convincing answer since negotiations are typically handled by them.
For how long have I used the solution?
I have more than three years of experience in Splunk.
How are customer service and support?
I rate the technical support by Splunk as a perfect ten out of ten. I always receive support when needed, and while it may take time due to their workload, the results are assured and accurate based on my needs and thought processes.
How was the initial setup?
The initial setup of Splunk Enterprise Security is straightforward as it involves following the architecture of cloud deployment, with forwarders and security devices integrated by the client. We propose use cases for future attacks, but the deployment issues are managed by the client, while our role is providing SOC incident response services from India.
Which other solutions did I evaluate?
I believe Splunk Enterprise Security is one of the best options currently available in the market. While I see competitors like Sentinel emerging, Splunk Enterprise Security remains a top choice, alongside others like QRadar, ArcSight, and ELK tools such as Elastic, Logstash, and Kibana.
What other advice do I have?
Splunk Enterprise Security helps improve my organization's business resilience as I have almost two and a half years completed in Accenture. The client is most satisfied, and our team has consistently received appreciation for our work. We have not caused any security breaches and continue to see good results quarterly over the last two years.
The integration of threat intelligence directly into the TDIR workflow improves my ability to preemptively block threats because we receive weekly emails from our Threat Intelligence team with CVEs or IOCs. We add those IOCs to Splunk Enterprise Security to mitigate potential attacks. Recently, due to higher cyberattacks stemming from events in Iran and the USA, we have created use cases to monitor several IOCs every two hours, which is still ongoing.
In the future, I would like to see artificial intelligence integrated into Splunk Enterprise Security. I am uncertain about costs, but such integration could enhance functionality, much like in my previous project where alerts from Splunk Enterprise Security directly integrated into ServiceNow facilitated quicker responses. Reducing false positive alerts would also be beneficial to streamline our process, as we sometimes deal with hundreds of alerts, causing strain on resources. I would rate this product overall as a nine out of ten.
Which deployment model are you using for this solution?
Hybrid Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Other
Disclosure: My company has a business relationship with this vendor other than being a customer. Reseller
Last updated: Jul 1, 2026
Flag as inappropriateSystems Development Engineer at a tech vendor with 10,001+ employees
Supports real-time detection and response through flexible data ingestion and adaptable workflows
Pros and Cons
- "What Splunk does, and really is why it is a choice platform, is that it speaks all of those languages, no matter what IT discipline you are in."
- "The biggest thing with Splunk is making sure that the documentation is maintained."
What is our primary use case?
Splunk Enterprise Security use cases drive the workflow from threat detection all the way through to incident response, giving an approach mirrored with technology. Depending on use cases, whether having a tool drive some approach or conducting discovery, or looking to facilitate an operational security operations role at your company, it is very much driven heavily on the scheduler, setting things up and then looking and deep diving when necessary. Splunk Enterprise Security does well by giving a good framework.
Risk-based alerting is enabled in Splunk Enterprise Security. However, because of custom applications, a lot of times it works but doesn't work. Some discovery on our own is required, conducting our own campaigns to do that.
The time it takes the SecOps team to remediate any security incidents with Splunk Enterprise Security depends on the situation. Splunk skips over the whole trying to figure out how to use the tool. That is the biggest thing. Using Elastic SIEM and using other SIEMs, there is a learning curve, whereas with Splunk Enterprise Security, even if there is no one on the team who has mastery in Splunk, there is enough support and enough tooling and things that people have done before to really deep dive right in immediately.
Splunk Enterprise Security helps tell a story and helps focus at the customer level. As a managed service provider, I can only speak from the security side of it.
As a managed service provider, consolidating networking, security, and IT observability tools with Splunk Enterprise Security can be difficult, especially when providing those tools yourself. What Splunk does, and really is why it is a choice platform, is that it speaks all of those languages, no matter what IT discipline you are in. You are able to surface and view data in a quantitative manner and also get insights into what you are looking for. That is a very strong aspect of a tool where it does consolidate.
What is most valuable?
Splunk Enterprise Security has helped mainly when it comes down to the data science part. If you have a strong data science background, it is easy to detect anomalies. Some of the toolkits that are deployed with Splunk Enterprise Security and ML Toolkit allow you to do a lot more upfront than you typically would be able to do.
Splunk Enterprise Security has helped to improve the ability to ingest and normalize data.
The impressions of Splunk Enterprise Security's ability to identify and solve problems in close to real-time are that the different ingest methods that it provides are critical to finding out and looking at the breadth of data that comes in through machine data. In some parts, some people call them logs, some people call them metrics, some people call it telemetry. Having an aggregator at the ingest level like Splunk is amazing because it does not matter what you want to send, you can send it. It does not need to be in a particular format. A lot of the data brought in is not log data, it is programmatic from APIs and customer activity and things that need to be looked at as a whole picture. So when it comes to security, to be able to look at that in real-time requires compute and less structure because you need to be able to see there are payloads coming in that are typically not in this correct format, and the tool should not miss that because fields are not necessary. Splunk's ability to do schema on search is immensely powerful and that does aid in the ability to get results faster.
Threat topology and the MITRE ATT&CK framework features for helping discover the overall scope of an incident in Splunk Enterprise Security are pretty good. In this particular discipline when it comes to security, applying knowledge and then having a tool support that knowledge and drive forward, the integration paths of those particular types of things are very helpful. The more data that you bring in across your topology, if you will — network, user activity, user behavior activity, authentication, and application errors — you get this full landscape that you can see. With that, if a type of MITRE ATT&CK comes along and you understand what it is, you can see where the attack entry point was, the activity that was performed, and then start the incident response.
What needs improvement?
The biggest thing with Splunk is making sure that the documentation is maintained. There is a gap where if you search for an issue, a lot of times it is in the community. There should be a path that moves community answers into documentation or into an FAQ that allows people to not use the community answers to drive results. For instance, when you can use Splunk this way and this solves your problem, but if there is a better solution, that should be presented as an FAQ. Just working with Splunk for an immense amount of years, it is usually necessary to try to figure something out. The docs tell you where you can figure it out, as in a configuration file, but it does not really help you get to the end result. More complete documentation would be beneficial.
What do I think about the stability of the solution?
There has never been any instability with Splunk Enterprise Security. Some core dumps appear from time to time, but it really depends on your architecture. If you are really good at architecting Splunk, you should not ever run into that. Splunk is solid, and that is almost a ten.
What do I think about the scalability of the solution?
Splunk Enterprise Security's scalability is huge. If you were to take one thing from Splunk that is probably really amazing, it is the scalability. With a handful of users now, coming from a shop where there were 5,000-plus users in Splunk and it was pretty stable, the scalability is immense. It is one of the things that separates it from other tooling, and if not, it is the most scalable solution out there.
How are customer service and support?
Technical support or customer support at Splunk has been contacted.
The quality and speed of the support at Splunk are interesting. As an expert in the field, the work is really far beyond what customer support can probably handle. They are pretty good when it comes to that, especially if you have a Sev 1 ticket. The support team overall at Splunk, the people that have been interacted with, are fine, but typically if there is a problem, someone like a specialist needs to be spoken to. This one is hard to answer because of being such a niche customer.
If Splunk support were to be put on a scale from 1 to 10, it would receive a seven. This has been discussed with them and it is fair feedback. The reason for giving seven is simply because the first contact is not necessarily able to answer most of the problems that have to be submitted.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
Alternatives to Splunk have been used. In the past, ArcSight has been used, of course managed service provider tools that you typically get with the big cloud providers, and then Elastic.
How was the initial setup?
Splunk Enterprise Security is just an app that sits on top of Splunk. There really is not much to it. It is pretty straightforward and about as easy as production enterprise software that has ever been seen. It is super easy.
What about the implementation team?
Implementation was automation, probably a couple of minutes and a button click.
Which other solutions did I evaluate?
There is not anything that is close to Splunk Enterprise Security as of right now. Splunk has taken this weird leap ahead of everybody else. It is also the most expensive tool out there. It is kind of like buying a luxury SUV or a used entry-level SUV. There is a difference for a reason. That is not saying that any of the other tools mentioned are that. It is just that Splunk is ahead, so there is really not a fair comparison.
What other advice do I have?
Splunk Enterprise Security has not been upgraded to 8.0. Splunk Enterprise Security does require maintenance between patching and upgrades. Professional services are available and have been done on behalf of another customer, but it is done mainly personally. The overall review rating for Splunk Enterprise Security is an eight.
Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor. The reviewer's company has a business relationship with this vendor other than being a customer: Partner
Threat Analyst at a manufacturing company with 10,001+ employees
Video Review
Built-in searches and unified data access streamline alert investigation and boosts analyst efficiency
Pros and Cons
- "When it comes to leveraging Splunk Enterprise Security's dashboards and visualizations to communicate security posture to executives, it's pretty straightforward for any type of information."
- "The two features I appreciate the most in Splunk Enterprise Security are the built-in searches, which have been very easy for us to get started with right out of the box, and the fact that it accesses all of our other systems."
- "One main change I would suggest is related to the incident board: when an incident is resolved, it should not appear on the incident board. It's just a rare occurrence that we open up the incident."
What is our primary use case?
The main use cases for Splunk Enterprise Security are primarily threat detection and insight. We have more of a focus on the insider threat, and we have it as a requirement of this new media to address any type of alerts or malicious activity from a special endpoint. Now it's inside.
What is most valuable?
The two features I appreciate the most in Splunk Enterprise Security are the built-in searches, which have been very easy for us to get started with right out of the box, and the fact that it accesses all of our other systems. You can access it as a pane of glass rather than having to search individually.
We also have the option to compare our analysts from our service to service. Splunk Enterprise Security helps our SOC team prioritize and investigate high-fidelity alerts more effectively by providing a more in-depth look and the ability to access a lot more of our data. Instead of jumping from several segmented systems, it allows us to have everything brought together in one place.
For example, you have to move from our purview to our build system and to Splunk Enterprise Security, and it enables us to streamline that process. The built-in features of Splunk Enterprise Security, which we recently procured, have given us a good starting point and demonstrated the value of the product, providing an easy way to sell it to our company.
The ease of getting everything into our purview helps us, and it serves as a good start for the investigation part in one location rather than what we usually have, which is jumping from system to system to system.
Splunk Enterprise Security plays a role in our company's strategy to combat insider threats and advanced persistent threats by currently being in its technical test phase. We are still rolling it out, and it should help us find any insider threats based on information that our policy states should not be present in our system.
Splunk Enterprise Security's risk-based alerting (RBA) has impacted our alert volume and analyst productivity because we've got many different systems feeding into it. However, it has helped to make it easier for our analysts to go through a set of events rather than 100 alerts. RBA allows us to streamline the process and customize it for our analysts.
When it comes to leveraging Splunk Enterprise Security's dashboards and visualizations to communicate security posture to executives, it's pretty straightforward for any type of information. The visualization is easy to understand, but I haven't had any direct conversations with our executives.
What needs improvement?
It's hard for me to say how Splunk Enterprise Security can be improved because I've seen what they've done with the AI systems, which is going to help a lot once it's rolled out.
However, one main change I would suggest is related to the incident board: when an incident is resolved, it should not appear on the incident board. It's just a rare occurrence that we open up the incident.
For how long have I used the solution?
I have been working in my current field for three years now.
What do I think about the stability of the solution?
The stability and reliability of Splunk Enterprise Security overall have been good. We haven't had it crash, and we haven't experienced any issues with the indexes shutting down.
Most of the problems we've faced have stemmed from the implementation of our systems and with forwarding information into the indexes, but we haven't encountered any issues with Splunk Enterprise Security itself.
What do I think about the scalability of the solution?
I'm not sure how Splunk Enterprise Security scales with the growing needs of our company yet. We have increased the amount of data we can ingest as the project has progressed, which has provided us with better information, however, we haven't rescaled it to a production level.
How are customer service and support?
My thoughts on the customer service and technical support are that it's good. They've been very attentive to us, and we've maintained a bi-weekly cadence call with the A team. We've also collaborated with several of their architects to address problems.
We've worked with the Splunk community to gather resources to roll out Splunk Enterprise Security, and we've never felt left in the dark when we encountered a problem; they've always been very responsive.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
Prior to adopting Splunk Enterprise Security, we had Purview and our own home-grown threat detection system. I don't know the exact systems we used past Purview, however, I know there were several options.
How was the initial setup?
My experience with deploying Splunk Enterprise Security so far has not been difficult. Everything works smoothly with all the other systems we have. The only issues we've faced have been with the volume of indexes, which is more about how we're finding our data. Past that, installing, updating, and modifying it has all been pretty smooth.
What about the implementation team?
We've worked with the Splunk community to gather resources to roll out Splunk Enterprise Security, and we've never felt left in the dark when we encountered a problem; they've always been very responsive.
What was our ROI?
The biggest return on investment when using Splunk Enterprise Security is its user-friendliness and how easy it is to adjust pre-built functionalities to fit our system, especially for investigation purposes.
Additionally, I have found that some of the other programs we use for detection don't pick up as many alerts as Splunk Enterprise Security does.
What's my experience with pricing, setup cost, and licensing?
Regarding my experience with the pricing, setup cost, and licensing of the platform, ours is provided by a different agency. In our situation, the licensing is something we don't really have to handle directly. I can say one issue we've encountered pertains to how our system is set up, specifically indexing data. However, that's more about our infrastructure rather than a Splunk Enterprise Security issue since we have an entirely new Splunk system running that data, and it requires its own license.
What other advice do I have?
Regarding whether Splunk Enterprise Security's ability to ingest and normalize data from diverse sources has enhanced our threat detection capabilities, it is based on a system we have, and since we have a SIM, the data is already segmented coming in. In terms of whether Splunk Enterprise Security has helped reduce our team's average meantime to detect, it's still very early in the rollout phase. I can say that as time goes along, it's a bit quicker and has sped up, however, we haven't yet gotten any specific metrics.
We haven't used UEBA, but we've used UBA, which is what the system is based on. There's Splunk UBA and then there's Splunk UEBA, which is integrated into Splunk Enterprise Security.
I would rate Splunk Enterprise Security an eight out of ten.
My advice to other companies considering Splunk Enterprise Security is to avoid setting it up as a separate test system. It's crucial to integrate it into your main system because one of the main issues we've faced is managing the amount of data and understanding that you want to feed it as much data as you can.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer. Partners
Buyer's Guide
Download our free Splunk Enterprise Security Report and get advice and tips from experienced pros
sharing their opinions.
Updated: August 2026
Product Categories
Security Information and Event Management (SIEM) Log Management IT Operations AnalyticsPopular Comparisons
IBM Security QRadar
Splunk AppDynamics
Microsoft Sentinel
Elastic Security
IBM Turbonomic
Palantir Foundry
WhatsUp Gold
LogRhythm SIEM
Rapid7 InsightIDR
Elastic Observability
Buyer's Guide
Download our free Splunk Enterprise Security Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- Which would you recommend to your boss, IBM QRadar or Splunk?
- What are some of the best features and use-cases of Splunk?
- What SOC product do you recommend?
- Splunk as an Enterprise Class monitoring solution -- thoughts?
- What is the biggest difference between Dynatrace and Splunk?
- IBM QRadar is rated above competitors (McAfee, Splunk, LogRhythm) in Gartner's 2020 Magic Quandrant. Agree/Disagree?
- What are the advantages of ELK over Splunk?
- How does Splunk compare with Azure Monitor?
- New risk scoring framework in the Splunk App for Enterprise Security -- thoughts?
- Splunk vs. Elastic Stack



















