Great tool for Maturing SOC teams
February 25, 2022

Great tool for Maturing SOC teams

Anonymous | TrustRadius Reviewer
Score 10 out of 10
Vetted Review
Verified User

Overall Satisfaction with Splunk Enterprise Security (ES)

Splunk Enterprise allows our analyst team to detect and identify threats within our environment and effectively take quick action. By leveraging these tools we can quickly identify adversarial patterns. The inline monitoring allows us to provide all the details needed to make actionable changes. The correlations searches allow us to average SPL which we know to enhance our detection.
  • Correlation searches
  • Asset identification
  • Addins
  • Training
  • Customization
  • Faster response times
  • Speed at gathering data
The product can be expensive to scale
Better searching and more options for plugins

Do you think Splunk Enterprise Security (ES) delivers good value for the price?

Yes

Are you happy with Splunk Enterprise Security (ES)'s feature set?

Yes

Did Splunk Enterprise Security (ES) live up to sales and marketing promises?

I wasn't involved with the selection/purchase process

Did implementation of Splunk Enterprise Security (ES) go as expected?

Yes

Would you buy Splunk Enterprise Security (ES) again?

Yes

Splunk Enterprise is a great tool for a maturing SOC to build its SIEM around.

Splunk Enterprise Security (ES) Feature Ratings

Centralized event and log data collection
10
Correlation
10
Event and log normalization/management
8
Deployment flexibility
6
Integration with Identity and Access Management Tools
8
Custom dashboards and workspaces
9
Log retention
10
Data integration/API management
7
Rules-based and algorithmic detection thresholds
10
Incident indexing/searching
10