Splunk ES Alert Reduction
July 21, 2023

Splunk ES Alert Reduction

Anonymous | TrustRadius Reviewer
Score 8 out of 10
Vetted Review
Verified User

Overall Satisfaction with Splunk Enterprise Security (ES)

Our analysts use ES to gain a broad perspective on all the security events coming in from our customer devices. We have multiple internal customers with different environments, so it’s useful having a central place in each SIEM to find events. ES is vital to our business as it allows us to use risk based alerting, which decreases the amount of alerts our analysts have to review each day. We’re able to easily tune these rules to filter out false positives and noisy notables to ensure our analysts have an easy time identifying real threats in a timely manner.
  • Risk based alerting
  • Single pane of glass
  • Easy to use UI
  • Sometimes runs slowly
  • Some incident review panels have never worked in our environment
  • More dashboards
  • Mean time to detection
  • Mean time to response
  • Communication with higher management
  • Alert fatigue reduction
We have on prem splunk and it’s mostly east to setup, but we have issues keeping data separated between customer splunk deployments while at the same time only having to look at one SIEM to address events in every environment.
  • Splunk User Behavior Analytics (UBA)
Splunk enterprise is the only solution that we’ve been able to identify that provides risk based alerting, which allows our SOC to reduce analyst fatigue which would be a huge problem without it. Before RBA, there were thousands of alerts a day and it was impossible to review all of them.

Do you think Splunk Enterprise Security (ES) delivers good value for the price?

No

Are you happy with Splunk Enterprise Security (ES)'s feature set?

Yes

Did Splunk Enterprise Security (ES) live up to sales and marketing promises?

Yes

Did implementation of Splunk Enterprise Security (ES) go as expected?

Yes

Would you buy Splunk Enterprise Security (ES) again?

Yes

It is well suited for our analysts reviewing the alerts that come in each day. The risk based alerting system allows us to tune detections to eliminate noisy notables and ensure our analysts don’t get stuck dealing with alert fatigue. The information generated by ES allows us to create dashboards that easily communicate our accomplishments to higher leadership.

Splunk Enterprise Security (ES) Feature Ratings

Centralized event and log data collection
8
Correlation
8
Event and log normalization/management
8
Deployment flexibility
6
Integration with Identity and Access Management Tools
Not Rated
Custom dashboards and workspaces
7
Host and network-based intrusion detection
Not Rated
Log retention
10
Data integration/API management
10
Behavioral analytics and baselining
7
Rules-based and algorithmic detection thresholds
10
Response orchestration and automation
Not Rated
Reporting and compliance management
Not Rated
Incident indexing/searching
10