Splunk ES on Splunk Cloud
June 17, 2022

Splunk ES on Splunk Cloud

Anonymous | TrustRadius Reviewer
Score 8 out of 10
Vetted Review
Verified User

Overall Satisfaction with Splunk Enterprise Security (ES)

We use Splunk Cloud as a Siem. We forward all log, event, and metric data to the cloud platform. We monitor the infrastructure and security operations. The soc team responds to events in real-time, that are alerted through Splunk.
  • Alerts on security incedents
  • Collects event data
  • Collects metric data
  • Allows for high level dashboards
  • Ease of use. The product is hard to learn for new users.
  • Old interface. Needs updating
  • Needs more integration for third party applications
  • Faster mttr
  • Faster mttd
  • Brings insight into security events
We use Splunk Cloud. The cloud engineers can scale up and down in demand
Splunk enterprise security works great in Splunk Cloud.

Do you think Splunk Enterprise Security (ES) delivers good value for the price?

Yes

Are you happy with Splunk Enterprise Security (ES)'s feature set?

Yes

Did Splunk Enterprise Security (ES) live up to sales and marketing promises?

I wasn't involved with the selection/purchase process

Did implementation of Splunk Enterprise Security (ES) go as expected?

Yes

Would you buy Splunk Enterprise Security (ES) again?

Yes

It's integrates very well with cloud and onprem applications. Many prebuilt apps in splunkbase.

Splunk Enterprise Security (ES) Feature Ratings

Centralized event and log data collection
8
Correlation
4
Event and log normalization/management
8
Deployment flexibility
4
Integration with Identity and Access Management Tools
4
Custom dashboards and workspaces
5
Host and network-based intrusion detection
5
Log retention
8
Data integration/API management
8
Behavioral analytics and baselining
6
Rules-based and algorithmic detection thresholds
6
Response orchestration and automation
6
Reporting and compliance management
7
Incident indexing/searching
8