TrustRadius: an HG Insights company

Splunk Enterprise Security

Score8.1 out of 10

266 Reviews and Ratings

What is Splunk Enterprise Security?

Splunk Enterprise Security is an analytics-driven SIEM that helps to combat threats with actionable intelligence and advanced analytics at scale.

Read more details.

Videos

Top Performing Features

  • Correlation

    Correlation of logs and events to pinpoint significant threats

    Category average: 8.4

  • Event and log normalization/management

    Ability to normalize event syntax so that logs can be compared and are machine-understandable

    Category average: 8.6

  • Custom dashboards and workspaces

    dashboards that can be customized to meet the needs of specific groups

    Category average: 8.4

Areas for Improvement

  • Response orchestration and automation

    Quality of built-in response orchestration and automation in Next-Gen SIEM

    Category average: 7.6

  • Behavioral analytics and baselining

    How effectively activity and behavior baselines are established and maintained

    Category average: 7.7

  • Deployment flexibility

    Ability to tune system to maximize threat detection and minimize false positives

    Category average: 7.5

Who Buys & Uses Splunk Enterprise Security

Pros

  • Robust log management and ingestion capabilities
  • Centralization, normalization, and visualization of diverse logs
  • Strong correlation and detection functionalities

Cons

  • Difficulty with data onboarding and Common Information Model (CIM) mapping
  • High complexity and steep learning curve for users
  • Significant deployment and ongoing maintenance overhead

Review

Use Cases and Deployment Scope

In our organization, we use Splunk Enterprise Security for Large financial enterprise SOC (security operations system) leveraging ES (enterprise security) to run SecOps

Pros

  • Large telemetry logging
  • correlation

Cons

  • I think scalability has room for improvement in Splunk Enterprise Security
  • I think buit-in agentic capability has room for improvement in Splunk Enterprise Security

Return on Investment

  • Good dashboarding but flaky performance
  • expensive from a ROI perspective

Usability

Alternatives Considered

SecOps Solution and Chronicle Cloud

Splunk - The Enterprise Leader.

Use Cases and Deployment Scope

In our organization, Splunk Enterprise Security (ES) is the central Security Information and Event Management (SIEM) platform that consolidates telemetry across the enterprise, spanning network infrastructure, cloud services, endpoints, Kubernetes environments, identity systems, and critical applications. As part of the Cisco family, Splunk continues to evolve with deep integrations into Cisco threat intelligence (e.g., Talos) and network telemetry, enhancing both detection fidelity and operational efficiency.

Pros

  • Centralized Log & Event Aggregation.
  • Compliance & Reporting.
  • Threat Visibility Across the Enterprise.
  • Scalability for Global Growth.

Cons

  • Complexity and learning curve.
  • Deployment Overhead.

Return on Investment

  • Cost and licensing.

Usability

Alternatives Considered

Arcsight by OpenText

Other Software Used

Cisco Secure Network Analytics, Cisco Catalyst Center, SDWAN|Link

My Splunk review.

Use Cases and Deployment Scope

We deployed Cisco Splunk as a central SIEM to consolidate all of our logs from different vendors (Palo Alto, Fortinet, Aruba, Red Hat, Check Point...). Before Splunk, our analysts were juggling multiple disconnected tools across many dashboards and logs. Splunk fits our needs perfectly with real-time logging and alerting to prioritize incidents.

Pros

  • Risk alerting.
  • SOAR integration.
  • Threat management.
  • Ecosystem

Cons

  • Costs and license.
  • Onprem integration.
  • Out of the box detection.

Return on Investment

  • Tools consolidated.
  • False positive rate.
  • MTTD reduction.

Usability

Alternatives Considered

Kibana

Other Software Used

CheckPoint, Juniper 7000, Fortinet FortiGate

Different stack but Threats Rhyme

Use Cases and Deployment Scope

We utilize Splunk Enterprise Security more as an operational layer that ties together everything we promise our clients from a security standpoint. What that looks like in practice revolves around compiling activity logs, endpoint detections or evn custom app logs into one place where we can make sense of it- 100% of the time, it's on Splunk Enterprise Security

Pros

  • correlation searches scale across clients really well once you abstract detection logic properly
  • It has a really superior ability to ingest and normalize very different log types

Cons

  • licensing is always a constant balancing war
  • maintaining CIM consistency across different tech stacks is super resource intensive.

Return on Investment

  • reuse of correlation searches across different domains
  • Great increases in client confidence through deeper and with more context type of reporting

Usability

Alternatives Considered

Microsoft Sentinel

Other Software Used

IBM AIOps Insights, TeamViewer

Splunk Enterprise Security appropriately prices SIEM Best to use for big company

Use Cases and Deployment Scope

I'm a security analyst and my bau task is to triage and investigate incidents. To investigate the security incidents, I depends on logs and to query logs we use Splunk Enterprise Security. Almost all the device, software, services push logs into the SIEM and we query then on demand basis. Splunk Enterprise Security helped my company to store, query the logs mainly. We also use it to run a analytical query on the logs to search anamolies.

Pros

  • Splunk Enterprise Security is really good in storing logs from all the different system and services.
  • Splunk Enterprise Security provides a really good interface to query logs and analytics
  • Splunk Enterprise Security is really good in creating and managing analytical rule which is used for creating detections.

Cons

  • The search speed is slow as compared to other solutions
  • Although UI is significantly improved recently but it has a room for improvment.

Return on Investment

  • Splunk Enterprise Security query is slow when searching for very large amount of logs this can pump or SLA for resolving security alerts, As we need to query logs multiple times.

Usability

Alternatives Considered

Google Security Operations

Other Software Used

CrowdStrike Falcon, Jamf Connect, PingOne from Ping Identity