Great tool for maturing SOC teams and gathering data
March 10, 2022

Great tool for maturing SOC teams and gathering data

Mamie snodgrass | TrustRadius Reviewer
Score 8 out of 10
Vetted Review
Verified User

Overall Satisfaction with Splunk Enterprise Security (ES)

Splunk Security Enterprise, which consolidates security assessments following an optimal infrastructure installation, is entrusted with responding quickly to the growth in recurrent threats and vulnerabilities. Through the use of Splunk Security Enterprise, incident investigations can be expedited and problem characteristics disclosed, enabling the resolution of failures and the avoidance of future recurrence. Additionally, the usage of third-party software optimizes security scan performance.
  • Customer consents and identities are quantified for cyber risk.
  • Compatibility with third-party tools.
  • Addons
  • manage notable events and security incidents
  • Training
  • External asset management systems and ES do not play well together.
  • Constructing a custom investigation isn't always a cakewalk.
  • Even though there is a vast user base and many issues may be fixed by asking a question in the forums, the support crew is supposed to handle any problems that arise, but that doesn't happen.
  • With the integration of third parties, the study of vulnerabilities has significantly enhanced. It is astonishing that there are no problems detecting threats.
  • All of our customers are happy with ES.
  • The speed with which information is gathered
  • which has reduced intermittency and losses by 5%
It may be prohibitively expensive to scale the product.

Do you think Splunk Enterprise Security (ES) delivers good value for the price?

Yes

Are you happy with Splunk Enterprise Security (ES)'s feature set?

No

Did Splunk Enterprise Security (ES) live up to sales and marketing promises?

Yes

Did implementation of Splunk Enterprise Security (ES) go as expected?

Yes

Would you buy Splunk Enterprise Security (ES) again?

Yes

ES is a program that all security analysts should use since it combines threat detection characteristics with notable and security incident management. I use it every day in ES implementations for our customers, and that's why I recommend it in every circumstance where cyber security protection is needed. It's a good fit for any organization that's well-structured or large, in my opinion. In small businesses, it's difficult (and expensive) to put this into practice.

Splunk Enterprise Security (ES) Feature Ratings

Centralized event and log data collection
5
Correlation
8
Event and log normalization/management
5
Deployment flexibility
8
Integration with Identity and Access Management Tools
4
Custom dashboards and workspaces
7
Host and network-based intrusion detection
8
Log retention
5
Data integration/API management
7
Behavioral analytics and baselining
8
Rules-based and algorithmic detection thresholds
5
Response orchestration and automation
8
Reporting and compliance management
5
Incident indexing/searching
8