SOC team maturation tool of choice
March 11, 2022

SOC team maturation tool of choice

Angie Mackey | TrustRadius Reviewer
Score 7 out of 10
Vetted Review
Verified User

Overall Satisfaction with Splunk Enterprise Security (ES)

As a result, Splunk Enterprise Security provides us with the ability to categorize network activity, mapping it to NIST and CIS threat types. In addition, this visibility allows for quick identification of possible threats and the capacity to do further research and analytics. A great deal of activity can be tracked after the relevant data has been collected.
  • Visual graphs and charts were used to communicate findings.
  • unique workflows can be accommodated in the interface.
  • According to the automatic reports, attacks that hadn't before been detected were made.
  • Learning curve is steep.
  • Out-of-the-box setup
  • It's all over the place.
  • Enhanced Perceptions
  • The MTTD will be faster.
  • Splunk Enterprise Security's licensing charges look to be higher than in the past.
Effortlessness. It can be used in any department because it is so configurable. Security upgrades can be made more effective if all relevant information can be gleaned from a variety of sources. It has reduced the danger of on-premise security. Storing records makes it simple to conduct investigations.
Because an effective team of consultants and Product functionality and performance

Do you think Splunk Enterprise Security (ES) delivers good value for the price?

Yes

Are you happy with Splunk Enterprise Security (ES)'s feature set?

No

Did Splunk Enterprise Security (ES) live up to sales and marketing promises?

Yes

Did implementation of Splunk Enterprise Security (ES) go as expected?

Yes

Would you buy Splunk Enterprise Security (ES) again?

Yes

Make sure your employees are adequately trained so that they don't mishandle this instrument and end up with subpar results. Keep in mind that if you don't comply with logging standards, Splunk Enterprise Security (ES) will be expensive, unreliable, and potentially slow to use.

Splunk Enterprise Security (ES) Feature Ratings

Centralized event and log data collection
8
Correlation
5
Event and log normalization/management
9
Deployment flexibility
8
Integration with Identity and Access Management Tools
5
Custom dashboards and workspaces
9
Host and network-based intrusion detection
9
Log retention
7
Data integration/API management
8
Behavioral analytics and baselining
7
Rules-based and algorithmic detection thresholds
9
Response orchestration and automation
7
Reporting and compliance management
7
Incident indexing/searching
8