Great Tool, I Really Like Working With
February 18, 2022

Great Tool, I Really Like Working With

Phótis Deligiánnis | TrustRadius Reviewer
Score 9 out of 10
Vetted Review
Verified User

Overall Satisfaction with Splunk Enterprise Security (ES)

I use it mainly for configurations, onboardings, and maintenance. Moreover, users ask for dashboards/alerts/reports creation and troubleshooting.
  • Monitoring
  • Security
  • Troubleshooting
  • Graphs/Dashboards
  • Automation in configuration
  • Faster mean time to detect
  • Faster mean time to respond
  • Increased cost
That is my personal opinion. Things are going well, but there is always room for improvement.
Difficult to choose, each one has pros and cons. Splunk has the best interface, QRadar has strong capabilities but ES is free.

Do you think Splunk Enterprise Security (ES) delivers good value for the price?

Not sure

Are you happy with Splunk Enterprise Security (ES)'s feature set?

Yes

Did Splunk Enterprise Security (ES) live up to sales and marketing promises?

I wasn't involved with the selection/purchase process

Did implementation of Splunk Enterprise Security (ES) go as expected?

Yes

Would you buy Splunk Enterprise Security (ES) again?

Yes

I really believe Splunk Enterprise Security (ES) is a great tool for security monitoring. There are nice features like SOAR Phantom which give you amazing capabilities. Moreover, I believe it provides amazing opportunities for troubleshooting within an organization that keeps logs and monitors everything that is happening.

Splunk Enterprise Security (ES) Feature Ratings

Centralized event and log data collection
9
Correlation
8
Event and log normalization/management
8
Deployment flexibility
7
Integration with Identity and Access Management Tools
9
Custom dashboards and workspaces
9
Host and network-based intrusion detection
8
Log retention
8
Data integration/API management
8
Behavioral analytics and baselining
9
Rules-based and algorithmic detection thresholds
8
Response orchestration and automation
8
Reporting and compliance management
9
Incident indexing/searching
9