TrustRadius: an HG Insights company

Splunk Enterprise Reviews & Insights

Score8.6 out of 10

560 Reviews and Ratings

Top industries

Based on 1,413 HG Insights installations.

Powered by

Community Insights for Splunk Enterprise

Synthesised from 37 verified reviews.


Synthesised from 37 reviews | Last Published June 3, 2026


Splunk Enterprise is widely adopted for robust log monitoring and analysis, a primary use case for 68% of reviewers, serving as a critical platform for collecting, analyzing, and troubleshooting machine-generated data. Organizations frequently deploy it as a Security Information and Event Management (SIEM) tool for threat detection and compliance. In TrustRadius reviews, users consistently highlight its strengths in data parsing and the creation of insightful dashboards, which are key for gaining comprehensive operational visibility and efficient searches across large datasets.

Beyond its core functions, reviewers note innovative uses like data export to cloud storage and integration with ITSM platforms. However, a significant concern is the high cost, particularly its ingest-based licensing model, cited by 22% of reviewers. Challenges with dashboard and UI usability, often described as outdated, are also noted. Despite these, Splunk Enterprise is valued for enabling faster issue identification and resolution, contributing to enhanced operational efficiency and security posture.


  • Robust log monitoring and analysis capabilities
  • Effective data parsing and aggregation from diverse sources
  • Creation of insightful dashboards and visualizations
  • Efficient searching and querying across large datasets
  • Proactive alerting and notification features for incident response
  • High cost and expensive ingest-based licensing model
  • Outdated and messy Dashboard and UI usability
  • Performance issues and high resource consumption with large datasets
  • Limited built-in AI integration compared to emerging needs
  • Steep learning curve due to proprietary Search Processing Language (SPL)
What other products like Splunk Enterprise have you used or evaluated?

From 37 reviews | Last Published June 3, 2026

Reviewers evaluating Splunk Enterprise have also considered a range of alternative solutions, primarily focusing on security information and event management (SIEM) and observability platforms. These categories represent the most frequently cited alternatives, each mentioned by 8% of reviewers. The competitive landscape includes established SIEM solutions such as IBM Security QRadar and Securonix, indicating that organizations often compare Splunk's capabilities against dedicated security analytics platforms. Similarly, observability platforms like Dynatrace and Datadog are frequently evaluated alongside Splunk, suggesting a need for comprehensive monitoring across diverse IT environments. A smaller segment of reviewers, 5%, also reported experience with messaging queue technologies like Apache Kafka, which can be used for data ingestion similar to some Splunk functionalities. Additionally, cloud-focused observability tools, including Elastic Observability and Splunk AppDynamics, were mentioned by 5% of the review base, highlighting the increasing importance of cloud-native monitoring in their evaluations. The overall sentiment regarding these alternative products is mixed, reflecting the diverse experiences and specific use cases that drive product selection.

SIEM Solutions

IBM Security QRadar SIEM, Gurucul SIEM and Securonix Next-Generation SIEM

Observability Platforms

Dynatrace, IBM Instana and Datadog

Messaging Queues

Apache Kafka and RabbitMQ

What are the 3-5 most important use cases for this product in your organization?

From 37 reviews | Last Published June 3, 2026

Reviewers primarily utilize this product for operational intelligence, with a strong focus on log management and real-time incident response. A significant portion of the feedback, cited by 14% of reviewers, highlights the product's effectiveness in log analysis and monitoring, including the collection and ingestion of logs from critical applications and servers. Closely related, an equal proportion of reviewers, 14%, emphasize its utility for alerting and notifications, particularly for creating alerts based on log data to detect cybersecurity risks and monitor application health. Beyond these core functions, the product also serves specialized security use cases, such as SOC detection and firewall rule analysis, as noted by 5% of the reviews. Additionally, 5% of reviewers find the product valuable for application troubleshooting and ensuring application availability, leveraging its data insights to diagnose and resolve performance issues.

Log Analysis and Monitoring

Keeping logs

Alerting and Notifications

Creating alerts on logs

Security Use Cases

SOC detection use cases

What are some additional ways that your organization might be able to use Splunk Enterprise in the future?

From 37 reviews | Last Published June 3, 2026

Reviewers anticipate expanding the utility of Splunk Enterprise into several key areas to enhance operational efficiency and data leverage. A small number of reviewers, representing 8% of the sample, foresee significant opportunities in AI and Automation, particularly for streamlining security tasks and data management. Additionally, 5% of reviewers identified potential for advanced Data Integration with other enterprise tools to enrich analytics and reporting. A similar proportion of reviewers, 5%, also noted future applications in Observability, suggesting a desire to broaden monitoring capabilities, though some indicated current limitations in log integration.

Observability

Observability features which are quite new and not very well integration yet with logs.

AI and Automation

Advanced threat hunting automation

Data Integration

May be integration with audit tools and reports are directly integrated with internal audit tools

What are some unexpected or innovative ways that your organization has been able to use Splunk Enterprise?

From 37 reviews | Last Published June 3, 2026

Reviews indicate that organizations are extending Splunk Enterprise's capabilities beyond traditional use cases, leveraging it for innovative data management and operational insights. A notable emerging pattern, cited by 5% of reviewers, involves using Splunk as a conduit for data export to cloud storage platforms like AWS, transforming and securing log data. Similarly, 5% of reviewers highlighted its integration with other enterprise tools, such as ServiceNow and ITSM platforms, to automate incident generation and team notifications. Another unexpected application, also mentioned by 5% of reviewers, is the monitoring of non-IT related data, suggesting a broader applicability for the platform's analytical capabilities beyond its core IT operations and security functions. These instances collectively point to Splunk Enterprise being adapted for diverse organizational needs, acting as a flexible data pipeline and monitoring solution.

Data Export to AWS

use splunk as a passage to monitor (loss of data), change and transform data to then export it on AWS for storage purpose

Integration with Other Tools

Integration with service now

Monitoring Non-IT Data

Monitor the wastes, which is not IT related

What positive or negative impact (i.e. Return on Investment or ROI) has Splunk Enterprise had on your overall business objectives?

From 37 reviews | Last Published June 3, 2026

Splunk Enterprise significantly contributes to organizational objectives primarily through enhanced operational efficiency and robust security capabilities. Reviewers frequently highlight its ability to enable faster identification and resolution of issues, a benefit cited by 32% of the reviews. This capability is often linked to substantial reductions in Mean Time To Resolution (MTTR) and improved root cause analysis, saving significant operational hours. The platform also bolsters overall system oversight, with 14% of reviewers noting improved monitoring and visibility across diverse systems. Furthermore, Splunk Enterprise is recognized for providing valuable data analysis and insights, mentioned by 11% of reviewers, which aids in applying specific business logic and understanding application performance. Its role in detecting and responding to security incidents, including identifying breaches and correlating threats, is also a key positive impact, noted by 8% of the feedback. However, a notable concern affecting return on investment is the high cost associated with Splunk Enterprise, particularly its licensing model, which was raised by 14% of reviewers, indicating that while the benefits are substantial, the financial outlay can be a significant consideration.

Faster issue identification and resolution

Faster threat detection

Improved Monitoring and Visibility

improved the monitoring process

Cost and Licensing Concerns

cost associated with Splunk Enterprise Security is high, the licensing model and overall expenses.

Besides Splunk Enterprise, what other software do you regularly use? How likely would you be to recommend it to a friend or colleague?

From 37 reviews | Last Published June 3, 2026

Reviewers frequently utilize a diverse array of software alongside Splunk Enterprise, primarily focusing on enhancing monitoring, cloud infrastructure management, development workflows, and security operations. Monitoring and observability tools are the most commonly mentioned category, cited by 19% of reviewers, indicating a strong need for comprehensive system oversight beyond Splunk's core capabilities. Cloud platforms and services also feature prominently, with 14% of reviewers noting their use of major providers like AWS and Azure for infrastructure and application deployment. Development tools and platforms, including version control and CI/CD systems, are used by 11% of the review sample to streamline software creation and deployment. An equal percentage of reviewers, 11%, integrate specialized security and threat detection software to bolster their defensive postures. While most categories reflect a mixed sentiment due to the variety of tools mentioned, a smaller segment of 5% of reviewers expressed positive experiences with specific Cisco products, highlighting their reliability and integration.

Monitoring and Observability

Datadog

Cloud Platforms and Services

Google Cloud Platform

Development Tools and Platforms

Microsoft Visual Studio Code, Notepad++, GitHub

Describe how you use Splunk Enterprise in your organization. What are the business problems the product addresses and what is the scope of your use case?

From 37 reviews | Last Published June 3, 2026

Splunk Enterprise is widely adopted by organizations primarily for its robust capabilities in log monitoring and analysis, a use case cited by 68% of reviewers. Reviewers leverage the platform to collect, analyze, and troubleshoot machine-generated data from various sources, including servers, applications, and network devices. A significant portion of users, 27%, also deploy Splunk Enterprise as a critical tool for security operations, functioning as a Security Information and Event Management (SIEM) platform for threat detection and compliance. The platform's ability to centralize data, mentioned by 14% of reviewers, underpins these applications, enabling comprehensive visibility and streamlined operations. Furthermore, 22% of reviewers highlight the utility of custom dashboards and visualizations for tracking key metrics and gaining insights, while an equal percentage value its alerting and incident response features for proactive issue detection and resolution. These functionalities collectively address business problems related to operational oversight, security posture enhancement, and efficient incident management.

Log Monitoring and Analysis

I use Splunk Enterprise to monitor logs from our servers and also application logs.

Security and Threat Detection

Splunk technology is used for business and web analytics, application management, compliance, and security.

Dashboards and Visualizations

Also, we have built many custom dashboards to display the keys metrics for applications/infrastructure.

Please provide some detailed examples of areas where Splunk Enterprise has room for improvement.

From 37 reviews | Last Published June 3, 2026

Reviewers frequently identified several areas where Splunk Enterprise could be enhanced, with cost and licensing emerging as the most significant concern, cited by 22% of reviewers. Many users find the platform's pricing model, particularly its ingest-based licensing, to be expensive and a major factor in the total cost of ownership, especially for organizations managing large data volumes. Beyond financial considerations, 19% of reviewers expressed a need for improvements in Dashboard and UI Usability, noting that the interface can feel outdated and dashboard creation can be a messy experience. Performance and Data Handling also represented a notable area for improvement, with 16% of reviewers reporting issues with resource consumption and the system's ability to manage exceptionally large datasets efficiently. Furthermore, 11% of reviewers suggested that Splunk Enterprise lags in AI Integration, advocating for more built-in AI capabilities and features. Finally, the platform's Learning Curve and its proprietary Search Processing Language (SPL) were mentioned by 8% of reviewers as challenging for new users. These points collectively suggest opportunities for Splunk Enterprise to refine its value proposition, user experience, and technological capabilities.

Cost and Licensing

Licensing and cost

Dashboard and UI Usability

The tool’s dashboards are not as reliable as other tools such as Tableau.

Performance and Data Handling

Resource consumption and performance

Splunk Enterprise Reviews

112 Reviews

Splunk Enterprise Review

Rating: 8 out of 10
Incentivized

Use Cases and Deployment Scope

A lot of it is really log forwarding so that we're ingesting the logs just for more analytics and drill-down reporting functionality. That's the primary use case.

Pros

  • The login gest. That is number one. I'm looking at some of the new features or new products, just the graphs and just the ability to really detail the granularity of basically being able to look at and/or cross-reference the different logs and query on the different logs. The querying of the logs, really. Querying logs and multiple logs.

Cons

  • I think sometimes as a new user, it's difficult to master those queries just as a beginner, just to pull your data and just moving through the menus. But looking at the newer versions, it made it a little bit easier. You're not clicking through multiple menu items just to get to simple queries and so forth. I've already made improvements and looking at some of the things that you're doing with the new product. I'm looking forward to some of the use cases as we're moving into AI and the Agentic, just AI in general, and the Agentic use. So that's pretty exciting for me right now, observability. That's got me really excited. So I want to use that.

Likelihood to Recommend

I'm liking the newer products, and I'm looking forward to how they integrate with the overall product when they come together. Just log in and be able to query a large number of systems for similar issues or a unique one. That is a great fit for Splunk Enterprise, looking for a simple case or a simple String or something of that nature across multiple machines. It's a great fit for that to identify issues or particular software, whatever your scenario is, String, to find it across any particular server or group of servers, so that you can update or do a deployment or whatever it is you're looking to do.
Vetted Review
Splunk Enterprise
7 years of experience

Splunk Enterprise - [...] Review

Rating: 10 out of 10
Incentivized

Use Cases and Deployment Scope

Security incidents, syslog, alerts monitoring

Pros

  • corelate events for incident review
  • search is easy

Cons

  • Licensing cost
  • support

Likelihood to Recommend

Best SIEM on market
Vetted Review
Splunk Enterprise
7 years of experience

Splunk Enterprise

Rating: 10 out of 10
Incentivized

Use Cases and Deployment Scope

I feel we are missing out on other things that it can do to help with our network.

Pros

  • It is able to take log and put them into a great dashboard
  • provide loads of info

Cons

  • Help us with network monitoring

Likelihood to Recommend

If asked, I think I am likely to recommend Splunk Enterprise to a colleague because, in my experience, We are able to use Splunk Enterprise on other product in our company

Splunk Enterprise Review

Rating: 10 out of 10
Incentivized

Use Cases and Deployment Scope

Im director of an ATM company, that runs Splunk Enterprise as long concentrator, Siem, and fraud prevent service, we are currently migrating to Splunk Cloud with Splunk security in it. Splunk helps a lot in the speed of anomaly review and preventing Fraud to happen or spread in case we find some.

Pros

  • Log correlation and investigation
  • monitoring dashboards
  • shortening analysis times.

Cons

  • Splunk Observability suit lack quarkus integration.
  • the "executive view" could improve.

Likelihood to Recommend

it was easy to set up, and bring a lot of new features with time. if well used, its not expensive. once you got a team set up in, and find the right people to administrate the service, you are one step close to optimize all the experience and analysis, and of course, automation over it.
Vetted Review
Splunk Enterprise
2 years of experience

Splunk Enterprise Review

Rating: 7 out of 10
Incentivized

Use Cases and Deployment Scope

We use this to monitor user log ins, user actions on workstations. if our networking services are online. We have dashboards that were created to show this. We also use it to manage device certificates and to see if they are expired. We use it to monitor network traffic. We also use it for threat detection.

Pros

  • the dashboard customizability
  • AI tools
  • insider threat detection

Cons

  • The search feature of Splunk,
  • How to turn off and turn on Splunk
  • The set up complexity of Splunk
  • Splunk language can be simplified

Likelihood to Recommend

We think Splunk is very well suited for our project and how it is utilized in an air-gapped lab environment.

Review of Splunk Enterprise

Rating: 10 out of 10
Incentivized

Use Cases and Deployment Scope

we use it to monitor real live threats and allows us to provide insight into our data and be able to analyze it in real time. it allows for requirements to be met and for certain events and people actions to be audited. The best use case is to allow for insider threat to be detected further enhancing our security posture of the network.

Pros

  • analyze traffic
  • Insider Threat Detection
  • Real time traffic and parse information to a readable format

Cons

  • Splunk language is a little hard to learn maybe make it more usable friendly
  • include an AI tool that helps with creating dashboard and actually helping enhance and use Splunk better and to assist with writing search strings
  • assist with the peo

Likelihood to Recommend

I would recommend Splunk for many instances and use cases that people could have. for many things it would be for analyzing traffic in real time, setting alert for certain events that need to be audited, fulfilling logging and audit requirements especially in the dod space, helps with integrating many products with Splunk and allows or a full picture view of your traffic.

[...] Review

Rating: 10 out of 10
Incentivized

Use Cases and Deployment Scope

In our organization, we use Splunk Enterprise as our SIEM (security information and event management), Splunk Enterprise puts all of the security information and events under one roof and makes managing security events easier

Pros

  • Organize alerts
  • visablity
  • quick

Cons

  • can be faster
  • can be better documentation for use cases
  • can allow for more in-depth invesigation

Likelihood to Recommend

If asked, I think I am likely to tell a colleague that I gave Splunk Enterprise a 10 because Splunk Enterprise has helped my company tremendously and I believe other companies can get the same benefits as well

Good product not able to keep up with AI needs

Rating: 7 out of 10
Incentivized

Use Cases and Deployment Scope

Manage/maintain a large scale Splunk platform to provide analytical and security needs of the organization. Currently it provides a single pane of window for our security teams to build their threat/risk modeling at the same time integrating with other software to triage security incidents. Besides our developers leverage it for triaging purposes, along with leadership to make decisions based on data points available.

Pros

  • Easy to write SPL queries; people can learn it very quick
  • Run searches against large data set
  • Role based access to limit the data

Cons

  • Lags way behind in AI integration
  • Doesn't handle large dataset properly
  • System guard rails have been dream for admins forever

Likelihood to Recommend

Quick analysis along with visual interpretation
Vetted Review
Splunk Enterprise
9 years of experience

Splunk Enterprise for you

Rating: 10 out of 10
Incentivized

Use Cases and Deployment Scope

We use Splunk Enterprise for everything!It retrieves logs from everything, and although this creates storage issues, it gives us complete visibility over everything!As a result, we were able to create dashboards for better visibility.Whether it's for the network firewall or Active Directory!We can see everything that's happening in real time, as well as view a history over time and see how things have evolved.Plus, we get several alerts!Admittedly, we don't use SOAP yet, but we have been able to set up several alerts based on logs to warn us and protect us from a lot of things.It feels like being in a control tower and seeing everything that is being managed.I highly recomme

Pros

  • dashboard
  • alerting

Cons

  • cisco log !
  • Splunk base with other solution +++

Likelihood to Recommend

Price sadly but it's worth the effort!In fact, there have been so many cases where it has enabled us to solve problems quickly.Log management is so much simpler, as are visibility and reading.It helps at every level: at the start of integration, implementation, production at any time, upgrades, and bugs.In the end, we connect directly to Splunk Enterprise to find out what's going on because we have the entire chain, which allows us to find out directly instead of going through each element one by one to identify the problem.
Vetted Review
Splunk Enterprise
3 years of experience

Splunk Enterprise review

Rating: 9 out of 10
Incentivized

Use Cases and Deployment Scope

I use Splunk Enterprise in my organization and company to gather logs and data and analyze them. This tool allow us to monitor multiple apps, server and working station on multiple operating system, windows or linux or redhat.Thanks to Splunk Enterprise we can also detect any issue in our architecture or raise an alert, this allow us to be reactive when creating incident to solve any issue detected.

Pros

  • parsing
  • indexing
  • dashboarding

Cons

  • dashboard studio
  • performance
  • price

Likelihood to Recommend

Splunk Enterprise can be user friendly even for people not used to this kind of application thanks to an easy dashboard creation and alerting. It can also be used to create more complex dahsboard for specific needs. Splunk Enterprise also provide a wide range of data collector allowing us to retreive data from multiple sources and operating system.
Vetted Review
Splunk Enterprise
10 years of experience

Video reviews