Splunk Enterprise
October 24, 2025

Splunk Enterprise

Anonymous | TrustRadius Reviewer
Score 8 out of 10
Vetted Review
Verified User

Software Version

Splunk Light (legacy)

Overall Satisfaction with Splunk Enterprise

Splunk Engerprise is used to collect various security logs but for our organization we usually send account login information to Splunk Enterprise to gather analytics of how many people logged in, unsuccessful logins, and also account logouts. Daily reports are generated and are presented at our daily team meetings for management.

Pros

  • Splunk Enterprise is able to store large amounts of logs
  • Splunk Enterprise able to search efficiently through it's log database
  • Splunk Enterprise is able to create reports of user lockouts

Cons

  • Splunk Enterprise does not integrate well will all vendors
  • Splunk Enterprise's virtual machine option has log limitations
  • Splunk Enterprise could offer better connectivity with the cloud
  • Splunk Enterprise can generate a user lockout report of thousands
  • Splunk Enterprise can correlate account lockouts with password spray attacks
  • Splunk Enterprise can detect compromise in an account
Splunk Enterprise has plenty of storage space for security logs and can search and correlate suspicious activities up to 30+ days back. Splunk Enterprise can integrate with a ticketing system to track threats and correlate with IoC between security events. Splunk Enterprise can provide reports of account lockouts. Splunk Enterprise can consolidate multiple security alerts into one entry with a number showing how many events occurred.
Splunk Enterprise stacks similarly to IBM's qradar and outperforms both Palo Alto's Panorama and Cisco's Secure Firewall Management Center in regards to storing large amounts of logs and the ability for quick searches. Splunk Enterprise handles queries of data effectively and quicklyand can correlate between security events and can integrate with security tools like Shodan and WhoAmI to identify threats.

Do you think Splunk Enterprise delivers good value for the price?

Yes

Are you happy with Splunk Enterprise's feature set?

Yes

Did Splunk Enterprise live up to sales and marketing promises?

Yes

Did implementation of Splunk Enterprise go as expected?

Yes

Would you buy Splunk Enterprise again?

Yes

Splunk Enterprise is well suited for large enterprise solutions for a company with many systems and endpoints to dump large amounts of security logs. Splunk Enterprise has plenty of storage to keep the logs of security events well over 30 days and has the ability to generate reports of user login and lockouts.

Splunk Enterprise Feature Ratings

Centralized event and log data collection
7
Correlation
6
Event and log normalization/management
7
Deployment flexibility
7
Integration with Identity and Access Management Tools
6
Custom dashboards and workspaces
7
Host and network-based intrusion detection
7
Log retention
6
Data integration/API management
7
Behavioral analytics and baselining
6
Rules-based and algorithmic detection thresholds
7
Response orchestration and automation
7
Reporting and compliance management
8
Incident indexing/searching
7

Comments

More Reviews of Splunk Enterprise