Splunk Cloud Platform - a nice SIEM
Use Cases and Deployment Scope
We used it for logging all data and then feed all that data into some security models and used it as a SIEM.
Pros
- Incredibly powerful and customizable.
- Easy to ingest logs.
- Built in dashboards are good.
Cons
- Tedious to use at first.
- Slightly outdated UI.
- Sometimes slow.
Return on Investment
- Hard to use, training takes a while.
- Pricey for what you get.
- Saves a lot of time when doing investigations.
Usability
Alternatives Considered
Microsoft Sentinel and Darktrace
Other Software Used
Microsoft Sentinel, SentinelOne Singularity

