Splunk Enterprise Security (ES) - Clear Market Leader
Updated December 09, 2025

Splunk Enterprise Security (ES) - Clear Market Leader

Anonymous | TrustRadius Reviewer
Score 10 out of 10
Vetted Review
Verified User

Overall Satisfaction with Splunk Enterprise Security

Use it as the Security Information and Event Management (SIEM) platform to collect, analyze and correlate all data across the enterprise to detect, investigate, remediate and respond to threats and vulnerabilities. Other uses include auditing and compliance, security posture visibility and vulnerability management. It is a great tool with centralize dashboards for real-time monitoring and historical analysis of the entire security landscape.

Pros

  • Notable event detection
  • search correlation
  • threat monitoring and detection
  • data aggregation and normalization

Cons

  • more efficient searches
  • less app dependencies
  • app/TA consolidation
  • major improvement from previous version of the SIEM
  • reduced time for data searching and investigation
Easy integration with a wide range of data sources. Out of the box searches and dashboards are easy to use and easily customizable too. Role based controls are easily implemented as well making it easy to offer varying levels of access to many levels of users. Easy audit and tracking of all user and system activities.
  • Splunk IT Service Intelligence (ITSI)
I believe it is definitely a leader in the security space

Do you think Splunk Enterprise Security delivers good value for the price?

Yes

Are you happy with Splunk Enterprise Security's feature set?

Yes

Did Splunk Enterprise Security live up to sales and marketing promises?

Yes

Did implementation of Splunk Enterprise Security go as expected?

Yes

Would you buy Splunk Enterprise Security again?

Yes

Easy integration with multiple/disparate data sources. Prioritized alerts for investigation and response.

Splunk Enterprise Security Feature Ratings

Centralized event and log data collection
10
Correlation
10
Event and log normalization/management
8
Deployment flexibility
8
Integration with Identity and Access Management Tools
8
Custom dashboards and workspaces
9
Host and network-based intrusion detection
9
Log retention
9
Data integration/API management
8
Behavioral analytics and baselining
8
Rules-based and algorithmic detection thresholds
8
Response orchestration and automation
8
Reporting and compliance management
8
Incident indexing/searching
9

Using Splunk Enterprise Security

50 - Information Security, Network Security, Risk Management, CyberSecurity, etc.
3 - Splunk Architects and Splunk Admins
  • Threat monitoring
  • Security Posture
  • Incident Response
  • User Behavior Monitoring
  • Impossible Travel Scenarios
  • RTO functions
  • Prefer not to disclose

Evaluating Splunk Enterprise Security and Competitors

Yes - Old product was slow and hard to correlate data. It required everything, to be manually created.
  • Scalability
  • Integration with Other Systems
  • Ease of Use
Drill down more on the out of the box use cases and avail of as many if it as possible right from the start.

Splunk Enterprise Security Support

Splunk's support model for its products is quite good. It is a tier based support model with response times varying based on the severity of the issue that is being reported. Splunk support staff always responds within the stated service level agreements and continuously work on the issue until it is resolved.
ProsCons
Quick Resolution
Good followup
Knowledgeable team
Problems get solved
Kept well informed
No escalation required
Immediate help available
Support understands my problem
Support cares about my success
Quick Initial Response
None
Yes. It was part of our overall package with Splunk.
There are not many major issues with the product and support is always consistent.

Using Splunk Enterprise Security

ProsCons
Like to use
Relatively simple
Easy to use
Technical support not required
Well integrated
Consistent
Quick to learn
Convenient
Feel confident using
Familiar
None
  • Data modeling
  • Notable events

Splunk Enterprise Security Reliability

easy to deploy and use.
Issues are typically with data flow or data modeling but once the data gets in, the Splunk Enterprise Security app works as advertised.
The product performance is quite reliable. Issues like slow response times or delayed searches are due to poorly written searches or data models. It has more to do with user actions rather than the product itself.

Comments

More Reviews of Splunk Enterprise Security