Splunk Enterprise Security Normalizes Security!
June 20, 2022

Splunk Enterprise Security Normalizes Security!

Jacob Gonzales | TrustRadius Reviewer
Score 8 out of 10
Vetted Review
Verified User

Overall Satisfaction with Splunk Enterprise Security (ES)

We utilize it to generate notable events and alerts on enterprise-wide activity. It also enhances our threat intelligence posture to bolster security sharing with our partners. Splunk Enterprise Security helps our organization solve the problem of creating alerts based on a variety of sources through data normalization. I enjoy the Common Information Model and how it helps normalize data across sources. Our analysts don't need to know every single source but can search off one field to collect a variety of events.
  • Normalize data
  • Search efficiency
  • Reporting and dashboards
  • Data visualization
  • Alerting and reporting
  • Improved user interface
  • Resource requirement
  • Admin overhead
  • Consolidated dashboarding
  • Improved response time
  • Reduced hours for IOC analysis
  • Streamlined analyst workflow
  • Improved threat intelligence
Splunk Enterprise Security supports both a clustered and non-clustered environment. This has been an improvement as the first versions of Splunk Enterprise Security required a single standalone search head that was only running Splunk Enterprise Security specific apps and not a part of a cluster. Overall, we have been able to increase our ingestion rate two-fold, and Splunk Enterprise Security has been easily able to handle the increase.
Splunk Enterprise Security allows for data normalization that does not compare to other SIEMs such as QRadar or Trustwave. QRadar requires custom dsm parsers before the data can be onboarded. I appreciate that Splunk Enterprise Security can ingest any source of data and normalize it based on a simple app that is available from Splunkbase. It is a much more streamlined process.

Do you think Splunk Enterprise Security (ES) delivers good value for the price?

Yes

Are you happy with Splunk Enterprise Security (ES)'s feature set?

Yes

Did Splunk Enterprise Security (ES) live up to sales and marketing promises?

Yes

Did implementation of Splunk Enterprise Security (ES) go as expected?

Yes

Would you buy Splunk Enterprise Security (ES) again?

Yes

Splunk Enterprise Security helps normalize the data across the environment. It allows our analysts to search with simple terms across sources of data. The data visualization aspect is also a vast sea of dashboards and reporting. However, I find the number of dashboards to be inefficient for analysts. They have to know which dashboard will give them the proper data. It would be much easier to have a dashboard that can give them a single pane of glass.

Splunk Enterprise Security (ES) Feature Ratings

Centralized event and log data collection
10
Correlation
10
Event and log normalization/management
10
Deployment flexibility
7
Integration with Identity and Access Management Tools
7
Custom dashboards and workspaces
10
Host and network-based intrusion detection
10
Log retention
6
Data integration/API management
8
Behavioral analytics and baselining
7
Rules-based and algorithmic detection thresholds
6
Response orchestration and automation
Not Rated
Reporting and compliance management
10
Incident indexing/searching
8