Splunk Enterprise Security is a great product overall.
Overall Satisfaction with Splunk Enterprise Security (ES)
in addition to providing log management, Splunk Enterprise Security is also being utilized to build correlations and establish use cases. The primary goal of the solution is to offer the Incident Response Team a single pane of glass through which they can monitor associated events from many sources and respond to threat occurrences more quickly!
Pros
- Correlation searches
- Security-related applications
- Notable events
Cons
- Machine learning functionality
- price
- To be honest, a premium solution like Splunk doesn't give premium help, thus I've submitted tickets to Splunk Support for these kinds of problems.
- Deployment flexibility
- Log retention in a 4% more
- Reporting and compliance management
I think so, too! Enterprise Security, in my opinion, can only be as good as the data it is fed. A fully functional and reliable SIEM product requires a lot of preparatory effort. A business of any size can benefit from Enterprise Security's ability to adapt to its needs. Your security demands will be met as long as the organization you're working with can give the required resources and data
- Splunk Application Performance Monitoring (APM)
In addition to providing log management, Splunk Enterprise Security is also being utilized to build correlations and establish use cases. The primary goal of the solution is to offer the Incident Response Team a single pane of glass through which they can monitor associated events from many sources and respond to threat occurrences more quickly!
Do you think Splunk Enterprise Security delivers good value for the price?
No
Are you happy with Splunk Enterprise Security's feature set?
No
Did Splunk Enterprise Security live up to sales and marketing promises?
Yes
Did implementation of Splunk Enterprise Security go as expected?
Yes
Would you buy Splunk Enterprise Security again?
Yes

Comments
Please log in to join the conversation