a good tool for threat hunting and response
August 31, 2023

a good tool for threat hunting and response

Anonymous | TrustRadius Reviewer
Score 7 out of 10
Vetted Review
Verified User

Overall Satisfaction with Splunk Enterprise Security (ES)

we use ES to analyse the risk of the organization and do actions to mitigate them to enhance our security Level in the environment faced variety of attacks from the world wide. we take much affort to imporve our rules to reduce the false positive and flase negative

Pros

  • incident review show up all the risk case so that we can review it in a convenience way
  • security posture combine very useful information and do analysis and trend in overall
  • security intelligence give a score to judge which is true risk

Cons

  • may be join search
  • more depend on log if log not received in time
  • need professional train to use
  • reduce alert volume
  • fast risk dectection
  • SLA
it really help us, but there is a room to achieve our company objective
it could be a out-standing product to help us enhance our company security aspect.

Do you think Splunk Enterprise Security delivers good value for the price?

Not sure

Are you happy with Splunk Enterprise Security's feature set?

Yes

Did Splunk Enterprise Security live up to sales and marketing promises?

Yes

Did implementation of Splunk Enterprise Security go as expected?

Yes

Would you buy Splunk Enterprise Security again?

Yes

Trellix Insights, Imperva Web Application Firewall (WAF), Juniper Mist Edge

Splunk Enterprise Security Feature Ratings

Centralized event and log data collection
6
Correlation
6
Event and log normalization/management
7
Deployment flexibility
6
Integration with Identity and Access Management Tools
7
Custom dashboards and workspaces
6
Host and network-based intrusion detection
7
Log retention
7
Data integration/API management
5
Behavioral analytics and baselining
4
Rules-based and algorithmic detection thresholds
5
Response orchestration and automation
5
Reporting and compliance management
5
Incident indexing/searching
5

Comments

More Reviews of Splunk Enterprise Security