Splunk Enterprise security is a powerful tool to explore
June 21, 2022

Splunk Enterprise security is a powerful tool to explore

Anonymous | TrustRadius Reviewer
Score 9 out of 10
Vetted Review
Verified User

Overall Satisfaction with Splunk Enterprise Security (ES)

Splunk Enterprise Security is being used in our company to quickly detect security issues and respond to internal and external attacks. The security department is currently working on exploring all use cases for ES. Splunk is widely used for all types of monitoring, detecting issues, threats, security, cybercrime, DDOS, etc.
  • Good graphical UI to learn and detect threat and perform quick recovery action.
  • ES is very useful in detecting security issues in enterprise infrastructures such as devices, systems, and applications.
  • Using AI and ML features to detect anomalies and trigger alerts to NOC.
  • Limited use cases, need to be expanded and include all the other use cases in the ES to detect security issues.
  • Definitely, ES helps in reducing MTTD and MTTR, with the help of ES overall detection method, we could save a lot of time in issue detection and correction.
Very flexible and easy to deploy ES SW on the cloud and on-premises.

Do you think Splunk Enterprise Security (ES) delivers good value for the price?

Not sure

Are you happy with Splunk Enterprise Security (ES)'s feature set?

Yes

Did Splunk Enterprise Security (ES) live up to sales and marketing promises?

Yes

Did implementation of Splunk Enterprise Security (ES) go as expected?

I wasn't involved with the implementation phase

Would you buy Splunk Enterprise Security (ES) again?

Yes

Splunk ES helps my team to detect threats and issues in real-time, drill down to detail issues helped in investigating the root cause, and solve problems quickly. Our team relies on Splunk logs analysis and Machine learning for early detection and correction. ES is one of the tools we are currently exploring all use cases and trying to build some dashboard for overall monitoring of all technologies nodes.

Splunk Enterprise Security (ES) Feature Ratings

Centralized event and log data collection
9
Correlation
9
Event and log normalization/management
9
Deployment flexibility
8
Integration with Identity and Access Management Tools
8
Custom dashboards and workspaces
9
Host and network-based intrusion detection
8
Log retention
9
Data integration/API management
9
Behavioral analytics and baselining
9
Rules-based and algorithmic detection thresholds
9
Response orchestration and automation
9
Reporting and compliance management
9
Incident indexing/searching
9