Just Right
June 17, 2022
Just Right

Score 7 out of 10
Vetted Review
Verified User
Overall Satisfaction with Splunk Enterprise Security (ES)
We recently deployed Splunk Enterprise Security in testing mode and are evaluating it to replace Arcsight as the main SIEM. We are currently scoping the use cases and the painpoint is to replace the slow Arcsight. Since we use Splunk Enterprise Security for logging all our logs, it’s just natural that we will need a SIEM that lives on top of the data.
Pros
- Viewing all in one page
- Drill downs
- Correlation
Cons
- As much as you do well with correlation, I still feel there is room for improvement
- This is not a Splunk Enterprise Security-specific issue but generally Splunk, the Stability has been spotty lately. We can use some improvement on this.
- It’s still in testing can’t comment on this yet
As I have mentioned, we are still in the testing phase. Splunk Enterprise Security. However, we are hoping that by the time we implement and get it fully operational, it will have alleviated our major pain point mentioned before and hence have a significant ROI. Once we have it in production, I will be able to comment on it.
Splunk Enterprise Security is superior in the logging aspect and searching. That’s why it was easier to pick switch to Splunk Enterprise Security. Arcsight is however superior in the correlation and stability aspect. It’s very reliable and stable that we sometimes forget that it exists Splunk's Enterprise Security benefits are however big enough to ignore the downside
Do you think Splunk Enterprise Security delivers good value for the price?
Yes
Are you happy with Splunk Enterprise Security's feature set?
Yes
Did Splunk Enterprise Security live up to sales and marketing promises?
Yes
Did implementation of Splunk Enterprise Security go as expected?
I wasn't involved with the implementation phase
Would you buy Splunk Enterprise Security again?
Yes
Comments
Please log in to join the conversation