No more typing reviews! Try our Samantha, our new voice AI agent.
Ahmed Al-Nabhani - PeerSpot reviewer
Systems Engineer at Dell Technologies
Real User
Top 20
Aug 3, 2025
Provides threat intelligence, good visibility, and detects threats faster
Pros and Cons
  • "Splunk has been recognized by Gartner as a leader in providing visibility for observability and monitoring across various platforms, including physical, virtual, and container environments, for several years."
  • "Splunk goes beyond collecting basic metrics like CPU or memory utilization; it comprehensively gathers data from various sources, including networks, applications, and virtualization, eliminating the need for siloed solutions and enhancing the capabilities of existing engineering software."
  • "I'd like a dashboard that allows me to connect elements through drag-and-drop functionality."

What is our primary use case?

Typically, the standard approach for Splunk sizing involves gathering data from the entire IT environment, regardless of whether it's hardware, virtualized, or application-based. This data is then collected and monitored through Splunk as a comprehensive security solution. We also work with Splunk-related platforms like Application Performance Monitoring to provide a holistic view of system performance. Recently, we implemented this solution for a bank in Jetar. Splunk excels at collecting high-volume data from networks, making it ideal for performance monitoring and scaling. During the sizing process, it's crucial to calculate the daily data ingestion rate, which determines the amount of data Splunk Enterprise needs to process and visualize for security purposes. Several factors need consideration when sizing Splunk: tier structure hot and cold buckets, customer use cases for free quota access, and storage choices based on data access frequency. Hot buckets typically utilize all-flash storage for optimal performance and low latency, while less frequently accessed data resides in cold or frozen buckets for archival purposes. In essence, the goal is to tailor the Splunk solution to meet the specific needs and usage patterns of each customer.

One challenge that our customers face is slow data retrieval. Customers may experience delays in retrieving call data due to complex search queries within Splunk Enterprise Security. These queries can sometimes take up to an hour and a half to execute. Our architecture incorporates optimized query strategies and customization options to significantly reduce data retrieval times. This enables faster access to both hot and cold data. 

Another challenge is scalability constraints. Traditional solutions may have limitations in scaling to accommodate increasing data volumes. This can be a significant concern for customers who anticipate future growth. Our certified architecture is designed for easy and flexible scalability. It allows customers to seamlessly scale their infrastructure based on their evolving needs, without encountering the limitations often faced with other vendors' solutions.

The final challenge is complex sizing and management. Traditional solutions often require extensive hardware configuration and sizing expertise, which can be a challenge for many organizations. This reliance on hardware expertise can hinder scalability and adaptability. Our architecture focuses on software and application administration, minimizing the dependence on specific hardware configurations. This simplifies deployment and ongoing management, making it more accessible to organizations with varying levels of technical expertise.

Our architecture leverages Splunk's native deployment features, including: 
Index and bucket configuration. Data is categorized into hot, warm, and cold buckets for efficient storage and retrieval. Active/passive or active/active clustering. This ensures high availability and redundancy for critical data. Resource allocation. Data, compute, and memory resources are distributed evenly across clusters for optimal performance.

For high-volume data ingestion exceeding 8 terabytes per day, we recommend deploying critical components on dedicated physical hardware rather than virtual machines. Virtualization can introduce overhead and latency, potentially impacting performance. Utilizing physical hardware for these components can help mitigate these bottlenecks and ensure optimal performance for large data volumes.

How has it helped my organization?

Splunk Enterprise Security provides visibility across multiple environments. IT leaders and management directors often seek a simplified monitoring tool that can handle everything. However, using a third-party tool or a monitoring tool for multiple environments comes with certain considerations. These may include software version upgrades, connector updates, or API integrations for collecting specific metrics beyond the usual ten. Therefore, the key factors for a customer choosing a monitoring solution are, how easily can the tool integrate with existing physical, virtual, microservices, or hyper-scaler environments, whether it can provide a centralized view of monitoring data across multiple environments, and whether it can integrate with existing data analytics tools like Cloudera, Starburst, or Teradata. Integrating a monitoring solution with data analytics is crucial for a complete picture. While a standalone monitoring solution can help with capacity planning, data analytics provides insights for code analysis and historical data. This allows management to plan budgets, reduce costs, and make informed decisions for the future. Combining a monitoring tool like Splunk Enterprise Security with a data analytics engine like Cloudera or Teradata maximizes the value of data and empowers better decision-making.

Our monitoring tools offer various functionalities, including detection and third-party integration. For example, we have an integration with TigerGuard, a platform for threat detection. Additionally, we provide robust auditing capabilities to track changes within the environment. This helps identify potential intrusions and suspicious activity, whether from internal or external actors. To ensure the security of our monitoring tools, we implement several prevention and protection mechanisms. This includes continuous monitoring of logs and audits, even in case of tool failure. Leading enterprise monitoring solutions often connect to dedicated audit servers via SNMP traps, providing a centralized view of all infrastructure changes. This allows administrators, like Splunk users, to easily track modifications and identify potential security risks. Furthermore, individual software products within our monitoring suite have their access control lists and security measures. These may include features like certificates, user authentication, and security manager integration. Additionally, some products offer optional plugins or add-on licenses to enhance their auditing capabilities and meet specific organizational security requirements. Security is a complex and multifaceted topic, encompassing various aspects. This includes data location, user activity monitoring, intrusion prevention, and incident recovery procedures. Addressing these concerns effectively requires a comprehensive security platform assessment that evaluates the entire system, from hardware to applications, ensuring data integrity, encryption, and overall security at every layer.

Threat intelligence management utilizes dedicated tools for both threat and incident management. These tools help organizations define their response plan in case of an event, including how to recover, what the RTO and RPO are, and how to achieve them. This ensures the organization can recover quickly and efficiently in the event of a failure, unauthorized access, or data deletion. While threat incident management strategies may vary depending on the customer, the banking sector typically undergoes rigorous threat management inspections. While I may not be a threat management expert, there are crucial security measures to consider, encompassing personnel training, hardware security, and application controls. These elements, when orchestrated harmoniously, contribute to a secure environment that minimizes the risk of breaches, facilitates successful audits, and ensures data integrity.

The effectiveness of the threat intelligence management feature depends on how the customer responds to various threats, such as ransomware or network intrusions. While the tool provides recommendations, it requires customization to align with each organization's unique categorization criteria like high, medium, low, and specific security objectives. Ultimately, the goal is to protect data, enhance security, and ensure effective incident response procedures. Deploying the threat intelligence tool necessitates customization for each customer. Default settings may not be optimal, as human intervention might be necessary to address potential software errors or inaccurate recommendations. In such cases, manual intervention might be more effective. Therefore, the tool's usefulness depends on the specific threat, its recommendations, and the organization's response approach.

Splunk Enterprise Security is a powerful tool for analyzing malicious activity and detecting breaches. However, its effectiveness depends heavily on proper configuration and skilled administration. They must be able to connect Splunk with the necessary parameters, collect logs daily, and analyze them effectively. They must also have the ability to query Splunk efficiently to gather relevant data, an understanding of use cases and how to integrate with other systems securely, customization of the environment to meet specific needs, including adding connectors and add-ons, and visualization of data in a way that is clear and actionable for both analysts and management. While Splunk is a valuable platform, it requires careful management and expertise to unlock its full potential. Companies deploying Splunk should invest in skilled administrators to ensure its effectiveness in securing their environment.

Splunk helps us detect threats faster. As a Splunk administrator, I can monitor for suspicious activity, such as sudden changes in behavior, high resource utilization on specific file shares, or unusual data transfers. These events can trigger questions, like, Why is the system experiencing high utilization, is data leaking and being transferred elsewhere, why is this application consuming excessive resources, why has data suddenly disappeared from the system? Splunk Enterprise Security provides valuable insights and helps identify potential security issues. However, integrating threat intelligence management with Splunk can further automate this process. When suspicious activity is detected, the system can automatically take predefined actions. However, these actions require customization and testing before implementation. This may involve, customer review and approval of the automated response, POC testing to validate the effectiveness of the response, regular monitoring of the system's behavior and response to threat intelligence, and fine-tuning or customization of Splunk Enterprise Security settings to optimize threat detection and response.

Splunk has been beneficial to our organization from a partnership perspective. Even after Dell's acquisition of Cisco, our strong collaboration and certified solutions continue. This partnership strengthens our position with customers seeking the best solutions on the right platform. For example, if a customer requires a Splunk solution and a competitor lacks certified solutions, it could hinder their trust and purchasing decision. In contrast, our close collaboration with Splunk and certified add-ons for Splunk Enterprise Security adds value. We possess expertise in various Splunk architectures. I've worked with over four banks in Saudi Arabia alone that utilize Splunk and Dell hardware. Globally, we cater to diverse Splunk architectures and platforms, ensuring customer satisfaction with our diverse technology expertise. While we acknowledge competition, the focus here is on how our partnership with Splunk enhances the integration experience, offering both tightly coupled and loosely coupled architectures.

Since implementing Splunk Enterprise Security, we've observed improvements in both stability and the accuracy of data visualization. The low latency allows us to efficiently query the extensive data it provides. Splunk goes beyond collecting basic metrics like CPU or memory utilization; it comprehensively gathers data from various sources, including networks, applications, and virtualization. This unified platform eliminates the need for siloed solutions and enhances the capabilities of existing engineering software. While Splunk is a popular choice for data analysis due to its powerful features, its pricing structure based on daily data ingestion can be expensive. This pricing model, however, allows them to accurately charge based on resource usage. It's important to consider your data collection and visualization needs to determine the appropriate licensing tier. While other monitoring tools might share similar pricing models, Splunk distinguishes itself through its data segregation across various components. This simplifies communication between indexes, forwarders, and searches, allowing for efficient data processing within a single platform. Additionally, Splunk excels in data visualization and analytics, making it a leading choice for security and observability solutions. Their recent top ranking in Gartner's observability category further emphasizes their strengths. This recognition stems from their platform's compatibility with diverse hardware vendors, exceptional data visualization capabilities, and innovative data segregation strategies. Splunk's tiered access control and efficient cold/frozen data storage further enhance its value proposition. Ultimately, Splunk empowers users to interact with their data effectively. This valuable asset, when properly understood and visualized, can provide actionable insights without impacting network or application performance. Moreover, Splunk's customization and implementation potential extend beyond data analysis, offering recommendations and threat intelligence for proactive security measures. In conclusion, while Splunk's pricing might initially appear expensive, its comprehensive features and capabilities justify its cost for organizations seeking advanced data analysis and security solutions.

Realizing the full benefits of Splunk Enterprise Security takes time. While the software itself can be deployed quickly, it requires historical data to function effectively. This means collecting data for some time before you can rely on it for accurate insights. Several factors contribute to the time it takes to see value. First, there is deployment and customization. Setting up Splunk involves hardware, software, and integration, which can be time-consuming, especially during the first year. The second is data collection. Building a historical data set takes time, and the initial period may not provide significant value. There is also customization and training. Tailoring reports and training users requires additional investment, potentially involving workshops and professional services. To expedite the process, Splunk offers various resources including, proof of concept which allows testing Splunk with a limited data set for a specific period. Splunk may offer temporary free licenses for small workloads to facilitate initial evaluation. Splunk provides educational resources to help customers understand and utilize the platform effectively. Additionally, some partners leverage their Splunk expertise to help customers. Partners can educate and guide customers through the process, streamlining their experience, and assist with customizing reports and training users, accelerating the value realization process. By understanding these factors and leveraging available resources, organizations can optimize their Splunk implementation and achieve its full potential within a reasonable timeframe.

What is most valuable?

Splunk has been recognized by Gartner as a leader in providing visibility for observability and monitoring across various platforms, including physical, virtual, and container environments, for several years. This has made it a popular choice for many organizations, including those in the banking industry. Currently, only one of our banks utilizes QRadar. This may be due to the cost associated with switching from Splunk, which can be expensive. As a result, the customer might be prioritizing financial considerations over functionality at this time. It's important to note that while Splunk is recognized as a leader in platform capabilities, the decision to use a specific solution should ultimately be based on both functionality and cost considerations. This is why we have established a joint engineering team with Splunk to develop a platform that meets the needs of our customers.

What needs improvement?

I'd like a dashboard that allows me to connect elements through drag-and-drop functionality. Additionally, I want the ability to view the automatically generated queries behind the scenes, including recommendations for optimization. This is just a preliminary idea, but I envision the possibility of using intelligent software to further customize my queries. For example, imagine I could train my queries to be more specific through an AI-powered interface. This would allow me to perform complex searches efficiently. For instance, an initial search might take an hour and a half, but by refining the parameters through drag-and-drop and AI suggestions, I could achieve the same result in just five minutes. Overall, I'm interested in exploring ways to customize queries for faster and more efficient data retrieval. Ideally, the dashboard would provide additional guidance and suggestions to further enhance my workflow through customization and optimization.

Buyer's Guide
Splunk Enterprise Security
August 2026
Learn what your peers think about Splunk Enterprise Security. Get advice and tips from experienced pros sharing their opinions. Updated: August 2026.
912,801 professionals have used our research since 2012.

For how long have I used the solution?

I have been using Splunk APM for four years.

What do I think about the stability of the solution?

The stability of Splunk Enterprise Security depends on how data is tiered. Splunk recommends different storage options based on data access frequency and volume. Hot and warm data: This data is accessed frequently and requires fast storage like SSD or NVMe. Cold and frozen data: This data is accessed less often and can be stored on cheaper options like Nearline, SaaS, NAS, or object storage.

Splunk prioritizes cost-effectiveness and recommends low-tier storage for cold and frozen data, which typically makes up the majority of customer data. This reduces costs compared to expensive SAN storage. However, the decision ultimately depends on the customer's budget and specific needs. Customers with limited budgets or small use cases might choose to store all data on a single platform initially and expand to dedicated cold and frozen storage later. This approach requires manual configuration changes e.g., modifying index.conf and forwarder configurations to redirect data to the new tier.

While Splunk recommends optimal tier configurations for hot, warm, cold, and frozen data, the final decision rests with the customer based on their budget and specific requirements.

Changes to storage tiers can be implemented later through configuration adjustments, but this process might be more complex than using dedicated storage from the beginning.

Overall, Splunk guides the best tier options for different data access patterns while acknowledging the customer's autonomy in making the final storage decision.

What do I think about the scalability of the solution?

We have ambitious expansion plans. As our customer base grows, we see significant increases in data ingestion. For example, one of our largest Splunk customers has increased its daily data ingestion from two terabytes to eight terabytes in just three years. This expansion benefits both the customer and Splunk. The customer gains valuable insights from the additional data, while Splunk increases its revenue through additional license sales. However, it's important to note that expanding data ingestion requires careful consideration of hardware limitations. Increasing data volume necessitates adding more forwarders, indexes, and searches, which can impact Splunk licensing requirements. This highlights the crucial need for comprehensive planning and resource allocation during expansion initiatives. Furthermore, we have observed instances where customers unintentionally exceed their licensed data ingestion capacity. For example, one bank was ingesting six terabytes of data per day while only holding a four-terabyte license. This underscores the importance of close monitoring and proactive license management to ensure compliance and avoid potential licensing issues.

Which solution did I use previously and why did I switch?

Our expertise extends beyond Splunk. We offer certified architectures for other SIEM solutions like IBM QRadar, catering to diverse customer requirements. However, IBM QRadar does not have as wide of a platform as Splunk Enterprise Security.

What's my experience with pricing, setup cost, and licensing?

Splunk can be expensive, as its licensing is based on the daily data ingestion volume. While we've observed numerous implementations, most are executed remotely by Splunk itself. However, if on-site assistance from a Splunk engineer is desired, it can be costly due to travel expenses from either the Dubai office or Europe. To address this, Splunk is exploring partnerships to offer implementation services at more accessible price points.

For someone evaluating SIEM solutions and prioritizing cost, traditional marketing materials may not be the most effective approach. Customers in Saudi Arabia, like many others, often appreciate tangible demonstrations of value. Therefore, consider offering a POC to showcase Splunk's capabilities in their specific environment. Investing in the customer through various strategies can demonstrate your commitment and build trust. Granting temporary access allows them to experiment with Splunk firsthand. Provide resources and support to help them learn and utilize the platform effectively. Leverage your partner network to offer additional training and expertise. Invite key decision-makers to exclusive events or meetings with Splunk leadership, fostering a deeper connection and understanding. Remember, success often hinges on addressing specific needs. While POCs and business cases are crucial, consider potential customization requirements and existing workflows. If they've used a different tool for years, transitioning may require additional support and training due to established user familiarity. Splunk's investment in the customer journey goes beyond initial acquisition. By offering POCs, temporary licenses, training, and even exclusive experiences, you demonstrate value and commitment, ultimately fostering long-term success. Demand generation, in essence, boils down to two key aspects, Identifying their specific requirements and desired outcomes, and recognizing that different customers have varying budgets, experience levels, learning curves, expectations, and decision-making processes. While some customers may be more challenging to persuade, others readily embrace the extra mile. Enterprise clients often fall into the latter category due to their greater flexibility in resource allocation, dedicated security operations teams, and ability to invest in necessary hardware. Remember, SIEM solutions often involve hardware considerations beyond just software, so understanding these additional costs is crucial for accurate solution sizing and customer budgeting.

Which other solutions did I evaluate?

Several competitors to Splunk exist in the market, including IBM QRadar, AppDynamics which is used by some customers for monitoring and security, and Micro Focus used for enterprise monitoring, incident reporting, and capacity planning. While Dynatrace is a leader in the field, its presence in the banking sector, particularly in Saudi Arabia, seems limited, perhaps due to having only one certified partner acting as its distributor. In contrast, Splunk boasts a wider network of partners who actively implement and enable customers, leading to its increased market prevalence.

What other advice do I have?

I would rate Splunk APM a nine out of ten.

Monitoring multiple hyperscalers with a single tool can be challenging. While some tools like VMware CloudHealth offer limited cross-platform capabilities, they often focus on specific aspects like virtual instances and storage. For comprehensive cloud monitoring across different hyperscalers like Azure and AWS, third-party solutions are typically necessary. Here at Dell, for example, we focus on monitoring tools for our own workloads and installed base, allowing integration with third-party solutions for cloud environments. This enables customers with workloads across multiple hyperscalers to leverage established enterprise monitoring tools like New Relic, AppDynamics (Cisco), Micro Focus (HP), and Splunk for unified visibility. Ultimately, choosing a solution often involves balancing operational and capital expenditures. By employing third-party tools, organizations can achieve comprehensive monitoring across various cloud environments while potentially reducing overall costs.

We offer various deployment options for Splunk to cater to diverse customer needs and regulations. We can deploy Splunk on various infrastructures, including hyper-converged, bare-metal, two-tier, and three-tier architectures. While cloud deployment is an option, regulations from the Saudi Central Bank restrict customer data storage outside the kingdom. Therefore, most of our customers in the financial sector opt for private or local cloud solutions. While a dedicated private cloud experience for Splunk isn't currently available, customers are seeking access to features like the SmartStore, a caching tier that is now bundled with the Enterprise Security license previously offered separately from version 7X onwards. The chosen deployment approach depends on factors like budget, customer expectations, performance requirements, and compatibility with Splunk's recommended sizing solutions. We utilize both internal sizing tools and Splunk's official tools to ensure proper resource allocation for indexers, search heads, and forwarders based on specific customer needs. We have deployed our Dell servers, storage, and data protection solutions. Additionally, we have implemented a reference architecture. From a hardware perspective, we have everything in place to support Splunk as a reference architecture. This is indisputable, as it reflects our current infrastructure.

I have one customer who uses Splunk on a single site. In contrast, other customers have deployed Splunk in an active-active cluster configuration across two sites, effectively segregating the data across the environments with two-factor authentication. For these other environments, I have observed that each customer has a unique monitoring perspective or performance requirement, reflected in their individual subscriptions.

Splunk is responsible for software maintenance, while we handle the hardware aspects.

Splunk Enterprise Security is one of the most mature security solutions available. While it is expensive, it offers good value by providing the necessary security measurements, monitoring, and auditing capabilities required for running an enterprise environment. 

The combined forces of Splunk and Dell create significant resilience for us. Our joint architecture, strong alignment between the Dell account team and Splunk sales and presales, and collaborative efforts have been instrumental in addressing specific customer needs, such as sizing. This collaboration is mutually beneficial: Splunk focuses on selling licenses, while Dell prioritizes hardware sales. Unlike Cloudera, which optimizes licenses for its platform, Splunk bases licensing on the ingestion rate, demonstrating its alignment with our advanced architecture. This creates a win-win situation for both companies.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
reviewer2755854 - PeerSpot reviewer
Senior Cyber Architect at a tech vendor with 10,001+ employees
Real User
Top 10
Sep 11, 2025
Improves threat detection through integrations and provides valuable support for meeting compliance objectives
Pros and Cons
  • "I appreciate the integrations with the SOAR architectures and the expandability that can be used throughout the entire ecosystem of Splunk Enterprise Security."
  • "The system can be intimidating, and sometimes the concepts conveyed in the documentation require adjustment."

What is our primary use case?

My main use case for Splunk Enterprise Security is getting observability and insights in order to meet compliance objectives.

What is most valuable?

I appreciate the integrations with the SOAR architectures and the expandability that can be used throughout the entire ecosystem of Splunk Enterprise Security. They've improved my threat detection capabilities.

What needs improvement?

The system can be intimidating, and sometimes the concepts conveyed in the documentation require adjustment. The product is mature and continuing to mature. There could be a better opportunity to let larger groups outside of the community know about the ease of deploying the product.

I'm finding that newer generations, including my own, don't respond well to TL; DRs that often come from third parties and are often incorrect. If there was more of a quick answer, perhaps with Splunk AI, they could start implementing that on the documentation page to let people who have trust in that get a quicker answer.

For how long have I used the solution?

Professionally, I have been using Splunk Enterprise Security in the last one to two years. Personally, I've used it several times as a hobby product and competitively in cyber games.

What do I think about the stability of the solution?

The product is mature. 

How are customer service and support?

I don't directly deal with technical support.

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

Prior to adopting Splunk Enterprise Security, I was using another solution to address similar needs, however, I can't go into details.

How was the initial setup?

I would describe my experience with deploying Splunk Enterprise Security as one that needs some more hand-holding. Some aspects of the language and understanding can be challenging for individuals unfamiliar with Splunk. There are opportunities to improve that dissemination.

With training, I find deployment relatively easy. There's some self-service that has to be done as a user in terms of learning and understanding the product. Once you understand those workflows, it presents as a relatively easy and intuitive product to expand and grow into.

What was our ROI?

I have seen a return on investment with Splunk Enterprise Security. It's a useful system, and I would highly advocate it with any Splunk deployment.

What's my experience with pricing, setup cost, and licensing?

I'm not involved on the licensing side. 

What other advice do I have?

The features that have been demoed and debuted in Splunk Enterprise Security are of particular interest, and I'm interested to see where that journey continues. I find the process for customizing, developing, testing, deploying, and refining detections in Splunk Enterprise Security relatively easy with training.

My advice to other organizations considering Splunk Enterprise Security is to try it. I would suggest getting a demo from Splunk as that's the worthwhile approach. It's better to see all the powers that this tool can bring in terms of those capacities rather than trying to figure it out on your own journey.

I would rate Splunk Enterprise Security an eight out of ten. The only reason for this rating is, from an outside-in perspective, as someone who hasn't spent time either deploying it themselves or learning more of the nuances of how clustered designs work, it can be an intimidating experience and requires a lot of hand-holding. This creates a barrier to adoption.

Which deployment model are you using for this solution?

On-premises

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Other
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
PeerSpot user
Buyer's Guide
Splunk Enterprise Security
August 2026
Learn what your peers think about Splunk Enterprise Security. Get advice and tips from experienced pros sharing their opinions. Updated: August 2026.
912,801 professionals have used our research since 2012.
Splunk Engineer at a consultancy with 11-50 employees
Real User
Top 20
Jul 13, 2026
Automated risk-based alerts have reduced incident response time and support faster remediation
Pros and Cons
  • "The time it takes my SecOps team to remediate security incidents is very reduced compared to before."
  • "Currently, in my opinion, Splunk Enterprise Security is good. However, Splunk has an ingest processor that could be improved."

What is our primary use case?

My use case for Splunk Enterprise Security involves onboarding data and then CIM complying and normalizing fields. We are also using the data models mapping and the add-on configuration. We also have some correlation searches which are running using the data models. Using that, we have some dashboards that give us useful information and ideas of what we can do.

How has it helped my organization?

The time it takes my SecOps team to remediate security incidents is very reduced compared to before. Our security team gets notified very urgently and very fast, and we take action as per the alerts. This has reduced the time for us by a lot.

It helps our customers.

What is most valuable?

The dashboard is the feature in Splunk Enterprise Security that I find most valuable because in the dashboard we have background searches, and the background search runs in the dashboard and gives us useful information. We also have alert automation, such as if someone is logging in to our system like a firewall. If the IP is malicious, then we get the alert at that time and we can block that IP.

We are working with the risk-based alerting feature in Splunk Enterprise Security. We are using risk-based alerts called RBA. That assigns the risk to the user, the system, and the other entities instead of generating a notable event for every individual detection. Multiple low and medium confidence detections accumulate over time, and when the combined risk exceeds the defined threshold, a high-confidence alert is generated using that risk-based alert.

We are working with a new threat detection feature in Splunk Enterprise Security. That helps the security teams to identify, investigate, and respond to malicious activities across the environment. We have some correlation searches that detect suspicious behavior using predefined or custom rules. We also have some notable events that run as very high-frequency alerts created by the correlation searches or the risk thresholds.

What needs improvement?

Currently, in my opinion, Splunk Enterprise Security is good. However, Splunk has an ingest processor that could be improved.

For how long have I used the solution?

I have been using Splunk Enterprise Security for two years.

What other advice do I have?

I am working with Splunk Enterprise Security.

I use some third-party solutions for integration or to import data into Splunk. We are creating some custom add-ons. We are also using ServiceNow. When some alerts are triggered, then the incidents will automatically trigger and be assigned to the necessary team. That type of customization we are using for the data collection. If you have some API integration, then you can create your own add-ons using those APIs and the credentials, and you can directly pull the logs from the APIs into Splunk.

It is easy to customize Splunk Enterprise Security for our needs. We can customize as per our requirement. If you want to create some dynamic dashboards, then you can also create them as per your use case. It is also the same for the saved search and for the extraction. We can customize things as per our use cases and ideas.

I gave this product a rating of eight.

Which deployment model are you using for this solution?

Private Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Other
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
Last updated: Jul 13, 2026
Flag as inappropriate
PeerSpot user
reviewer2123547 - PeerSpot reviewer
Security Analyst at a tech vendor with 10,001+ employees
Real User
Top 20
Jun 16, 2026
Unified security monitoring has improved incident response and supported flexible threat detection
Pros and Cons
  • "Splunk Enterprise Security is a wide tool that we can use for different purposes, as it can be configured in many ways, not just as a SIEM, and we can leverage it in various ways."
  • "Whenever an upgrade happens from a lower version to the latest version, some things get complicated, particularly compatibility issues, which we usually see in Splunk Enterprise Security."

What is our primary use case?

During the initial two years, I was an incident response analyst who used Splunk Enterprise Security as a SIEM tool, and in the recent two years, I work as an admin who handles the integration part, content management part, and the detection response engineering.

We use disparate security solutions with additional IDS, IPS, and EDR tools integrated into Splunk Enterprise Security for single-handled monitoring for the analyst's ease. We do not need to go to each tool separately; instead, we integrate all of them into the Splunk Enterprise Security interface, allowing us to monitor them via Splunk Enterprise Security.

Regarding Risk-Based Alerting in Splunk Enterprise Security, we used to tag alerts while creating correlation searches in Splunk Enterprise Security.

I work with both on-premise and cloud-based setups.

How has it helped my organization?

Splunk Enterprise Security really helps improve business resiliency as we frequently capture real attacks.

What is most valuable?

In terms of customization ability and development capability inside Splunk Enterprise Security, it is very easy. Splunk Enterprise Security is a wide tool that we can use for different purposes. Splunk Enterprise Security can be configured in many ways, not just as a SIEM, but we can leverage it in various ways. The application add-on support from Splunk is very wide, making it very easy for configuration and customization.

The functions in Splunk Enterprise Security that I find most valuable are its ability to integrate any type of logs into the system. It is very user-friendly to read logs in any languages, which we can convert into a human-readable format in Splunk Enterprise Security, making log analysis and monitoring very useful compared to competitive SIEM tools.

The main benefits Splunk Enterprise Security provides to end users include a wide view, allowing us to have different kinds of views for the logs, and we can search according to the retention period we set in Splunk Enterprise Security. This capability and storage are good enough to retrieve older data for evaluation and analysis.

I find that threat detection in Splunk Enterprise Security is a wide case; we have the opportunity to create correlation searches, dashboards, and even integrate threat intel solutions in multiple ways into Splunk Enterprise Security. We can leverage these opportunities to get alerts based on these searches.

What needs improvement?

Whenever an upgrade happens from a lower version to the latest version, some things get complicated, particularly compatibility issues, which we usually see in Splunk Enterprise Security. In those cases, it sometimes definitely requires Splunk Enterprise Security's support or vendor support to resolve those issues. Compatibility issues during upgrades are a major concern.

I am generally satisfied with the functionality of Splunk Enterprise Security, and my only concern is the compatibility issue during upgrades.

For how long have I used the solution?

I have been working with the product for four years.

What do I think about the stability of the solution?

I rate Splunk Enterprise Security's stability as a nine.

What do I think about the scalability of the solution?

I consider its scalability, ability to scale, and ability to expand to be a ten.

How are customer service and support?

I would rate vendor support as a nine.

How was the initial setup?

The initial setup for Splunk Enterprise Security is simple, and guides from Splunk Enterprise Security support are available on the internet, making it very basic. We can read and understand the next steps from there.

What other advice do I have?

On average, the time a SecOps team takes to remediate security incidents with Splunk Enterprise Security depends on projects. If the team is working as a threat hunt team, they do not have a proper SLA, but for incident handling, some projects have 15 minutes, others 30 minutes, one hour, or in some cases, up to four hours. It varies according to the project and client requirement; incident handling is different from incident response, which usually requires more time for detailed analysis.

I am totally satisfied with Risk-Based Alerting because it works well; it works on intermediate findings. If multiple detections occur for the same host or IP, it looks for behavioral analysis and generates alerts for the analyst based on that risk, so it is actually working well in Splunk Enterprise Security.

I can recommend Splunk Enterprise Security to other users. My overall rating for this product is eight out of ten.

Which deployment model are you using for this solution?

Hybrid Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Other
Disclosure: My company has a business relationship with this vendor other than being a customer. partner
Last updated: Jun 16, 2026
Flag as inappropriate
PeerSpot user
Hari Haran. - PeerSpot reviewer
Technical Associate at Positka
Reseller
Top 20
Feb 26, 2026
Security operations have become streamlined and threat investigations gain rapid, actionable insight
Pros and Cons
  • "Regarding scalability, Splunk Enterprise Security is way ahead compared to other products, and I would score it at the maximum."
  • "During my experience with Splunk Enterprise Security, I have faced some significant challenges, particularly with customers adapting from version 7 to version 8."

What is our primary use case?

I would like to discuss Enterprise Security, and I explain that the main use case for the product is to protect our customers and support various attacks.

Regarding threat detection, I explain that during investigations, most of our SOC-related customers use Splunk Enterprise Security to identify threats.

How has it helped my organization?

In terms of benefits, Splunk Enterprise Security provides numerous advantages to end users, notably in reducing personnel needs for SOC operations.

Regarding pricing for Splunk Enterprise Security, I find it relatively affordable globally, although it seems costly in India due to currency exchange.

What is most valuable?

In my opinion, the functions in Splunk Enterprise Security that I find most valuable include unique features and tools that the product offers.

What needs improvement?

For improvement points, I think Splunk has several enhancements on the table right now to enhance Splunk Enterprise Security with functionalities and threat detection improvements.

For how long have I used the solution?

I have been working with Splunk Enterprise Security for seven years.

What do I think about the stability of the solution?

For stability, I would rate it a 10, as Splunk Enterprise Security is generally stable, especially now with its latest version.

What do I think about the scalability of the solution?

Regarding scalability, Splunk Enterprise Security is way ahead compared to other products, and I would score it at the maximum.

How are customer service and support?

I would rate Splunk Enterprise Security's technical support as a 10, as they provide 24/7 assistance based on priorities and are accessible for queries.

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

In comparison to other products, I think previous tools such as IBM QRadar were competitors, but currently, I hear about CrowdStrike getting into the picture.

How was the initial setup?

In general, I find that the initial setup for Splunk Enterprise Security is simple, especially with clear documentation from Splunk.

It depends on the client; if they have a qualified engineer with experience in Splunk Enterprise Security, they can handle the setup themselves.

What about the implementation team?

The solution is deployed both on-premises and cloud-based, depending on the customer's domain.

What other advice do I have?

My feedback regarding some processes of customizing, developing, and testing in Splunk Enterprise Security is that I am thinking from a customer perspective, focusing on the customizations they require.

I have experience with risk-based alerting in Splunk Enterprise Security, as we configure based on the priority of the instance, servers, or the endpoints.

During my experience with Splunk Enterprise Security, I have faced some significant challenges, particularly with customers adapting from version 7 to version 8.

Which deployment model are you using for this solution?

Hybrid Cloud
Disclosure: My company has a business relationship with this vendor other than being a customer. reseller
Last updated: Feb 26, 2026
Flag as inappropriate
PeerSpot user
Ankar Aung - PeerSpot reviewer
Network Security Engineer at a consultancy with 10,001+ employees
Real User
Top 5
Jan 8, 2026
Centralized dashboards have improved log visibility and support faster security investigations
Pros and Cons
  • "Splunk Enterprise Security can retain logs for compliance purposes longer than the usual three months."
  • "Splunk Enterprise Security documentation exists, but compared to Palo Alto, Palo Alto has more knowledge base articles."

What is our primary use case?

I deal with the Palo Alto FO and then Cortex XSIAM. I work with Cortex XSIAM and Cortex EDR products. We recently adopted Cortex XSIAM from Splunk Enterprise Security as our SIEM product for log management.

I have two to three years of experience with Splunk Enterprise Security, but not continuously; this is just a tool used by me, not daily. We send logs from the firewalls to XSIAM and analyze the traffic logs to determine whether deny or allow for migration. We use both Splunk and Cortex XSIAM for log analysis. I have never dealt with Splunk support.

What is most valuable?

I have experience with Palo Alto, Cisco, and Fortinet products. Splunk Enterprise Security is more dedicated to logs, not a unified product like Palo Alto. Palo Alto Cortex has the same UI across Cortex EDR and Cortex XSIAM, so all the product family is in one UI, whereas Splunk Enterprise Security is more focused on log search.

Palo Alto has better speed and better visibility. I can see all the M-points from one UI and search the logs from this UI. I use disparate security solutions that integrate or import data into Splunk Enterprise Security, including different log sources from the endpoint, firewall, router, switches, and everything that needs logging for visibility.

Splunk Enterprise Security can retain logs for compliance purposes longer than the usual three months. The dashboard capability also allows Splunk Enterprise Security to create dashboards based on logs, which makes it really helpful for visibility.

What needs improvement?

I feel more comfortable using XSIAM now compared to Splunk Enterprise Security. Splunk Enterprise Security is already a mature product, so I do not have much to point out. It could be a little more user-friendly, which would be nice.

It could also expand the product family beyond security log search. Since it has the capability of indexing things, perhaps Splunk Enterprise Security could develop their own EDR agent like Palo Alto and create a product family with a unified dashboard. This would definitely help the enterprise.

Splunk Enterprise Security documentation exists, but compared to Palo Alto, Palo Alto has more knowledge base articles. Even though the concepts are the same and multiple engineers have written articles for cross-reference, I do not see this level of documentation in Splunk Enterprise Security.

For how long have I used the solution?

I have two to three years of experience with Splunk Enterprise Security, but not continuously; this is just a tool used by me, not daily.

Which solution did I use previously and why did I switch?

The switch to Cortex came from management, likely because the Palo Alto product family is already in our environment. We have been using Palo Alto GlobalProtect and other security products, so bringing XSIAM into the environment makes sense.

What other advice do I have?

I do not see a real difference between XSIAM and Splunk Enterprise Security; they both have a search query functionality. Splunk Enterprise Security has Splunk query language, so it is just a different language and different way of searching logs. Eventually, we get the same logs including source, destination, port, and traffic allow and deny information.

I used to be a customer with Splunk Enterprise Security. I have hands-on experience but not extensive experience with Splunk Enterprise Security products in the past. I am more focused on networking than the security team. I do not have an answer about how long on average it takes SecOps teams to remediate security incidents using Splunk Enterprise Security.

I would rate this review an 8.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Last updated: Jan 8, 2026
Flag as inappropriate
PeerSpot user
Harshit Pawar - PeerSpot reviewer
Cybersecurity Engineer at a tech vendor with 201-500 employees
Real User
Top 20
Jul 27, 2026
Centralized threat data has powered faster incident response and proactive attack prevention
Pros and Cons
  • "The best features and the most important feature I want to highlight about Splunk Enterprise Security is its capability to process large amounts of data."
  • "From the point of view of deployments and making custom modifications in this particular product, it becomes really difficult because deployments of Splunk can get really tricky."

What is our primary use case?

I work for a cybersecurity-based company. We have our own products and solutions that we build and deliver to our customers, primarily revolving around Threat Intelligence solutions, TIP platforms, SOAR platforms, and incident response platforms.

The majority of tools that I work with are centered around threat intelligence, so we share threat intelligence for actioning on end security tools. These end security tools that consume threat intelligence are primarily Defender technology stack, which is how the entire arrangement functions.

Cyware has its own threat intelligence platform called Intel Exchange. This is a central data lake for all threat intelligence that any enterprise or organization might want to collect. An organization using threat intelligence from multiple sources collects threat intelligence from different types of open sources, RSS feeds, news articles, and blogs. They consume feeds from regulatory bodies like CERTs and ISACs, and they also purchase premium threat intelligence from threat intel feed providers like CrowdStrike, Recorded Future, and Microsoft Defender Threat Intelligence. When a customer has been consuming threat intelligence from these different sources, we consolidate everything, ingest it into a single platform, normalize it, and bring everything into a single structure. Threat intelligence is further processed, analyzed, and forwarded to end security tools for proactive blocking. If I am a financial sector company seeing other financial sector organizations like other banks getting targeted by a particular cyber attack, I use that intelligence to proactively block these threats in my environment before such an attack can happen in my organization.

I am using different tools including the entire Microsoft suite, most of the time working with Microsoft Sentinel, Microsoft Defender for Endpoint, CrowdStrike, Zscaler, and Splunk Enterprise Security.

What is most valuable?

Splunk Enterprise Security is basically a complete enterprise security solution, but it is primarily built on top of a security event and information management system; it is a SIEM solution. Splunk Enterprise Security acts as a data lake for all logs that I collect from different types of log sources within my environment. I bring logs and activity from my entire environment into a single place, and once this data is stored, I run analytics rules on top of it. These analytics rules are defined based on the different types of malicious behavior that I want to identify happening in my environment, and if any of these behaviors identify a match, it triggers alerts. These alerts could be actual malicious activities happening in my environment. Once those alerts are triggered, they are assigned to different types of analysts; these are SOC analysts who assign these alerts to themselves and then start investigating those alerts to see if the activity observed is actually malicious or not. Depending on those investigations, analysts close those incidents, and if something malicious has been identified, they take remediation actions. At that point, I integrate SOAR solutions. I integrate my own SOAR solution, which automates this entire actioning process.

For example, if a suspicious sign-in on a user account has happened and the sign-in was successful, my SOAR playbook resets the password for that particular user, notifies the user's manager, and sends out the necessary communication to that particular user whose account has been compromised. This is how Splunk Enterprise Security can be integrated with different security tools and how it works.

The best features and the most important feature I want to highlight about Splunk Enterprise Security is its capability to process large amounts of data. When I compare Splunk with all the other SIEM solutions that are out there in the market, Splunk has to be the one that can easily process huge volumes of data and scales really well. The query language that Splunk has, which is called SPL, is one of the best query languages out there that will help anybody to query large datasets and return results in a very quick and short period of time compared to the other SIEM solutions. For example, QRadar is extremely slow and sluggish when I want to query large datasets, but Splunk excels in that regard.

What needs improvement?

From the point of view of deployments and making custom modifications in this particular product, it becomes really difficult because deployments of Splunk can get really tricky. It requires a huge amount of hardware and infrastructure to run on. From that perspective, it is really compute heavy, and Splunk is one of the priciest solutions out there, so from a cost perspective as well, it is not one of the easiest to start with.

I do not think there is any particular lack of functionality with the product; the product is really good, but there are a few aspects in which Splunk Enterprise Security can become really difficult for people to get started with as beginners.

For how long have I used the solution?

I have been working with Splunk Enterprise Security for almost a year.

What do I think about the stability of the solution?

Splunk Enterprise Security definitely helps reduce the metrics that every security solution is built to reduce. If somebody was investigating these security threats and incidents manually and then manually going ahead and taking every single step, it would have taken those analysts a huge amount of time to remediate and protect their environments from these cybersecurity threats. Solutions like these are the reason why people buy them because they help reduce mean time to remediate and mean time to investigate, so that is the primary reason these solutions are primarily bought for.

What do I think about the scalability of the solution?

Splunk Enterprise Security is a very good solution when it comes to scalability, so I would rate it nine.

How are customer service and support?

I have not really interacted with the technical support of Splunk because I am not the one who is directly interacting with the product side of Splunk because somebody else does. I am not the one who really procures this product and interacts with their support team.

Which solution did I use previously and why did I switch?

I actually use Microsoft Sentinel, but that is not a native part of my toolset that I use. I integrate these solutions with the other set of tools that I work with at the moment.

I work with Defender and I work with Sentinel, so it is part of my job that I usually integrate these solutions with my solution that we sell.

I have worked with Defender for Cloud Apps, Defender for Endpoints, and I have also had a chance to work with Microsoft Defender for Identity, so I have worked on a few of these Defender solutions that Microsoft offers. We are a partner with Splunk.

How was the initial setup?

Both approaches are possible, but if I am simply looking to integrate the logs from my native technologies that I have in my infrastructure, I can simply use the out-of-the-box connectors, so I do not need to rely on third-party tools. If I have any particular third-party tool that allows me to ingest some custom data, that can also be done, so both things are possible.

What was our ROI?

Primarily, there are two things that Splunk Enterprise Security helps with: streamlining the log ingestion and normalization of all the logs in my environment into a single place; that is the first and foremost reason why anybody would want to buy Splunk Enterprise Security. Once I get all the data in a single platform, it really helps me analyze all those intelligence and data logs in a single place; these are done via the SPL query language that they provide along with the rules that can be scheduled and run on a regular basis. First, it helps streamline everything into a single place and helps act as a data lake for all logs in my environment. Second, it is really fast and quick in analyzing that large dataset that it can collect, so it provides a huge volume of better derived insights compared to other security solutions.

Which other solutions did I evaluate?

Microsoft Sentinel would be a top competitor, and recently Palo Alto has released their own SIEM solution as well, so these would be the top competitors.

In terms of technical capabilities, Splunk Enterprise Security would be the highest. In terms of ease of use and ease of adoption, Microsoft Sentinel would be the one, and for the other SIEM solution, they are definitely in the challenging category, but not really the market leaders.

What other advice do I have?

The threat detection module capability in Splunk Enterprise Security really comes in handy because that ties in my threat intelligence signals, and input from my different threat intelligence solutions can be brought into the picture when I am actually looking to prioritize the types of threats that I want to investigate and remediate in my environment, so that really becomes handy. I would rate this product an eight overall.

Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
Last updated: Jul 27, 2026
Flag as inappropriate
PeerSpot user
Ashiq Ashraf - PeerSpot reviewer
Specialist-Infrastructure Opertions at Allianz Technology
Real User
Top 10
May 22, 2025
Effective data management and threat detection through comprehensive integration and rapid response
Pros and Cons
  • "Splunk Enterprise Security provides the foundation for unified threat detection, investigation, and response, enabling fast identification of critical issues."
  • "The pricing of Splunk Enterprise Security is not very affordable, and I have seen many companies planning to leave because of cost concerns."

What is our primary use case?

I'm an end user, admin, and consultant. We use Splunk Enterprise Security internally in our organization, and I also use it for my personal studies. My usual use cases for Splunk Enterprise Security include monitoring several kinds of exchange server logs and Office 365 logs, among others, as we have multiple monitoring use cases based on our requirements in our environment. We were trying to solve multiple things by implementing Splunk Enterprise Security, particularly for monitoring our applications based on the insurance business, so we use Splunk Enterprise Security logs for security purposes and internal infrastructure monitoring, including logs matching security purposes in our Office 365 and exchange servers.

What is most valuable?

The most valuable features of Splunk Enterprise Security are several add-ons and TAs, while the lack of a DB requirement is a significant advantage for the business, allowing easier management without needing in-depth DB knowledge. I find that Splunk Enterprise Security's ability to import data from various sources, including looking up Excel files, is quite effective, providing a good way for management.

We import data from several unique data sources into Splunk Enterprise Security, possibly more than a hundred because we have AWS and multiple servers. We have disparate security solutions that integrate data into Splunk Enterprise Security. I can still query data in Splunk Enterprise Security regardless of where it resides, and in my perspective, the query provides data quickly.

Splunk Enterprise Security has improved our organization's ability to ingest and normalize data compared to before using Splunk Enterprise Security. The unified platform helps consolidate networking, security, and IT observability tools, which is very relevant to our internal needs. Using Splunk Enterprise Security, our focus was not on reducing alert volume but on properly finding and handling alerts; we've managed to capture 100% of them effectively.

Splunk Enterprise Security provides the relevant context to help guide investigations by allowing us to share application logs and details with clients efficiently. We utilize out-of-the-box detections in Splunk Enterprise Security, and we have created dashboards that add value to our monitoring efforts. Customizing, developing, testing, deploying, and refining detections in Splunk Enterprise Security is easy; it has been a good experience without significant difficulties.

We upgraded to Splunk Enterprise Security from version 8.0.4 to 9.0.6, and also from 8.1.4 to 9.0.6; it worked well with the support we received from the team, and it has proven to be very useful. Splunk Enterprise Security provides the foundation for unified threat detection, investigation, and response, enabling fast identification of critical issues.

What needs improvement?

The solution could be improved by integrating more application monitoring features and possibly incorporating AI capabilities to enhance its functionality.

For how long have I used the solution?

I've been working with Splunk Enterprise Security for six years.

What do I think about the stability of the solution?

Splunk Enterprise Security is stable and scalable, making it a good tool that is beneficial for our needs.

What do I think about the scalability of the solution?

Splunk Enterprise Security is stable and scalable, making it a good tool that is beneficial for our needs.

What other advice do I have?

I participated in the deployment process of Splunk Enterprise Security, and we performed UAT before moving it to production. It's not the most affordable solution, as I've witnessed several companies considering leaving due to cost factors. The pricing of Splunk Enterprise Security is not very affordable, and I have seen many companies planning to leave because of cost concerns.

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Associate I at Positka
Real User
Top 20
Feb 17, 2026
Advanced analytics has improved resilience and real-time threat mapping across diverse data
Pros and Cons
  • "Splunk Enterprise Security has helped greatly improve the organization's business resilience."
  • "I think the pricing aspect of Splunk Enterprise Security is quite high compared to other products, which I hear from most of my customers."

What is our primary use case?

My use cases for Splunk Enterprise Security involve both security as well as data analytics.

How has it helped my organization?

Splunk Enterprise Security has helped greatly improve the organization's business resilience.

What is most valuable?

The features of Splunk Enterprise Security that I appreciate the most include the recent AI feature and the MITRE mapping feature.

AI helps in analyzing a certain detection within Splunk Enterprise Security and assists with some tasks that I might require internet or other tabs to work on, while MITRE ATT&CK helps me to map the attacks and provides coverage for my attacks.

What needs improvement?

I would appreciate improvements in the licensing aspect, especially with the SVC-based license, as there is no proper view on top of it regarding how much CPU and usage is being done on the SVC-based license, along with updates to the SOAR version.

The experience with alerts, specifically risk-based alerts, is good, but it might need some improvement as there might be some deviation or false positives, so I think implementing AI over there might increase the feasibility or view around it.

I think the pricing aspect of Splunk Enterprise Security is quite high compared to other products, which I hear from most of my customers.

For how long have I used the solution?

I have been working with Splunk Enterprise Security for approximately 3.5 years.

What do I think about the stability of the solution?

I would assess the stability and reliability of Splunk Enterprise Security as very good, with not much downtime or crashes, as it depends on the hardware used and the kind of setup done, which is primarily based on misconfiguration or not predicting something.

I have not faced any significant challenges when using Splunk Enterprise Security; there is not much that I cannot solve.

What do I think about the scalability of the solution?

Splunk Enterprise Security scales very well with the growing needs of my organization and my clients' organizations.

Expanding usage with Splunk Enterprise Security consumes time and effort, but the end result is actually good.

How are customer service and support?

I would evaluate customer service and technical support as good but not very good.

On a scale of one to ten, I would rate them somewhere around seven to eight.

How would you rate customer service and support?

Positive

How was the initial setup?

I would describe my experience with deploying Splunk Enterprise Security as good, pretty easy, straightforward, and with plenty of documentation.

I have not faced any challenges during the deployment aspect; even if I did, I figured it out using Splunk Community and Splunk documentation.

What was our ROI?

It does bring measurable benefits in terms of return on investment for clients; specifically, for banking or finance customers who wish to contain their data within their environments, they would definitely go for Splunk Enterprise Security compared to CrowdStrike, but less mature organizations might prefer other products.

Which other solutions did I evaluate?

The key differences, both pros and cons of Splunk Enterprise Security in comparison to CrowdStrike, are that I am a Splunk enthusiast and I love Splunk Enterprise Security, but CrowdStrike is good in search and detections due to its status as a threat intel partner, which offers good detections, while customization done in Splunk Enterprise Security might take too much time on CrowdStrike and there are fewer integration options with CrowdStrike.

I don't have much idea on disadvantages of Splunk Enterprise Security apart from the pricing.

What other advice do I have?

I am currently working with Splunk products.

I work with Splunk Enterprise and Splunk Enterprise Security.

The process for customizing, developing, testing, deploying, and refining detections in Splunk Enterprise Security is pretty easy for me as an expert, but I'm not sure for a new user; being a Splunk architect, I feel it's a little easy and the customization is very helpful.

We have it integrated with various disparate solutions including RSA, CrowdStrike, AWS, Google, Microsoft, Docker, firewalls, switches, and multiple other technologies.

This integration supports my security operations by fetching logs about user activity and audit logs and actions taken by the user; for normal products, this allows me to analyze, detect, and correlate two or three different datasets to build up a use case from which I can deduce some information, and with the queries I have using SPL queries, I can get some data analytics or alerts or reports based on which I can take action.

I use risk-based alerting in Splunk Enterprise Security.

My experience with risk-based alerting, while not mainly focused on the SOC part of Splunk Enterprise Security, provides support to my engineering efforts.

I am not currently using any new threat detection features in Splunk Enterprise Security; I have no idea about that part of it.

My impressions of Splunk Enterprise Security's capability to predict, identify, and solve problems in real-time depend on what kind of data is being received and the use cases being written; it is not straightforward, but because Splunk Enterprise Security is an analytics platform without AI on top of it, it feels that some data sources are less predictable, yet for jobs that are repetitive or similar, Splunk Enterprise Security works well.

I would rate this product a 9 out of 10.

Which deployment model are you using for this solution?

Hybrid Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Other
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
Last updated: Feb 17, 2026
Flag as inappropriate
PeerSpot user
IT Admin at EuroSerwis
Real User
Top 20
Sep 30, 2025
Faced challenges with cost and support but have gained insights into traffic monitoring and threat detection
Pros and Cons
  • "What I appreciate about Splunk Enterprise Security is creating the newest SPL for network traffic and using the risk-based alerting feature that helps my organization by allowing me to learn more information about Splunk every day because it is a big platform."
  • "I encounter issues such as downtime, bugs, glitches, and unbox errors."

What is our primary use case?

My use case for the project is thin.

What is most valuable?

What I appreciate about Splunk Enterprise Security is creating the newest SPL for network traffic. I use the risk-based alerting feature. The risk-based alerting helps my organization by allowing me to learn more information about Splunk every day because it is a big platform.

What needs improvement?

I think that Splunk Enterprise Security is a very good platform, but the price is very high. I don't know how to explain what else can be improved in Splunk Enterprise Security aside from pricing. Support is important for improvements. My thoughts on better support include better knowledge base and better response time; it encompasses both aspects.

For how long have I used the solution?

I moved to Splunk Enterprise Security and learned it for two to three years, but in the last year, I worked with my friends on one project.

What do I think about the stability of the solution?

I rate the stability as a five. I encounter issues such as downtime, bugs, glitches, and unbox errors.

What do I think about the scalability of the solution?

Only two users use Splunk Enterprise Security.

How are customer service and support?

Support is important for improvements. My thoughts on better support include better knowledge base and better response time; it encompasses both aspects. I rate support as a five.

How would you rate customer service and support?

Positive

How was the initial setup?

I think it was easy to install, but this platform has many components I must learn. It took me months to deploy.

What other advice do I have?

I am reviewing Splunk Enterprise Security today, and I am working on one simple product and creating simple SPL. My thoughts on customizing, developing, testing, deploying, and refining detections are focused on detection. The testing is just the last component. My thoughts on the testing feature in Splunk Enterprise Security involve the network traffic to Cisco traffic, Uniper, or low car infrastructure. I am using new threat detection features in Splunk Enterprise Security and would work on big projects in the future. I do not use disparate security solutions that integrate or import data into Splunk Enterprise Security. I am wanting to learn more because I create simple SPL, and my friends are not Splunk Enterprise Security expert admins. I would recommend Splunk Enterprise Security to other users because it is a platform for monitoring all traffic, network infrastructure, hardware, software, and everything.

I rate the solution overall as a five out of ten.

Which deployment model are you using for this solution?

Public Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Buyer's Guide
Download our free Splunk Enterprise Security Report and get advice and tips from experienced pros sharing their opinions.
Updated: August 2026
Buyer's Guide
Download our free Splunk Enterprise Security Report and get advice and tips from experienced pros sharing their opinions.