TrustRadius: an HG Insights company

Splunk Enterprise Security Professional, Scientific, and Technical Services Reviews & Insights

Score9.8 out of 10

253 Reviews and Ratings

Community insights

TrustRadius Insights for Splunk Enterprise Security (ES) are summaries of user sentiment data from TrustRadius reviews and, when necessary, third party data sources.

Pros

Intuitive User Interface: Users have consistently found the user interface of the product intuitive and easy to use, allowing for quick completion of tasks. Many reviewers praised its simplicity and user-friendly design.

Efficient Log Correlation: The automation capabilities in XDR were highly appreciated by users as they enable efficient log correlation and turning data into meaningful insights. Several reviewers mentioned that this feature saves them time and enhances their overall productivity.

Comprehensive Security Monitoring: Users highlighted the product's ability to monitor firewall traffic, mail systems, and AWS infrastructure, providing comprehensive security monitoring. This feature was commended for its effectiveness in identifying potential threats from various sources.

Splunk Enterprise Security Reviews

34 Reviews
Professional, Scientific, and Technical ServicesAccounting1Information Technology & Services26Management Consulting1Research1Computer & Network Security5

Our Outcomes from Using Splunk ES

Rating: 8 out of 10
Incentivized

Use Cases and Deployment Scope

We use it to monitor and correlate data across more than 20 client environments, each with different infrastructures and compliance needs. The main challenge it addresses is visibility. Previously, our SOC relied on separate SIEM tools for certain customers, which meant fragmented investigations and duplicated alerts. Now Splunk ES centralizes all that.

Pros

  • Instead of reviewing thousands of low level alerts, I can prioritize risks based on the entity's risk score on the risk based alerts dashboard
  • The adaptive response framework allows me to link alerts directly to our SOAR playbooks in phantom. This way I can automate triage steps that traditionally took hours.

Cons

  • Creating complex custom correlation searches sometimes feels more complicated than it should. You need deep SPL experience to build anything beyond basic logic.

Likelihood to Recommend

Splunk is an incredibly capable platform especially for large scale multitenant environments like hours. But it does demand a lot of engineering effort to get it right.
Splunk thrives in environs that already have mature log pipelines and dedicated teams to maintain them. Its power lies in its flexibility. However, if your data sources are unstructured or inconsistent, you'll constantly write and rewrite custom regex transformations - at an unjustifiable cost effort wise.

Highly Recommended!

Rating: 7 out of 10
Incentivized

Use Cases and Deployment Scope

Splunk Enterprise Security (ES) is integral to our cybersecurity strategy. It swiftly detects and responds to threats, addressing compliance and incident response challenges. ES aggregates data from diverse sources, offering real-time monitoring and correlation. This agility minimizes security incident impact.

ES aids compliance management by providing detailed logs and reports, streamlining audits. Our use case spans the organization, integrating various data sources for a comprehensive security view. It also incorporates threat intelligence, bolstering proactive threat identification.

In summary, Splunk ES is a vital component, ensuring swift incident response and maintaining compliance with industry standards. Its scalability and adaptability make it a cornerstone of our security operations.

Pros

  • Advanced Threat Detection and Correlation: ES stands out in its ability to detect sophisticated threats by correlating data from multiple sources. For instance, it can identify unusual patterns in user behavior, cross-referencing with network logs to flag potential insider threats.
  • Real-time Monitoring and Alerting: ES offers robust real-time monitoring capabilities. It excels in promptly alerting us to critical security events, such as suspicious network traffic spikes or unauthorized access attempts, allowing for immediate response.
  • Comprehensive Log Analysis: ES ingests and analyzes an extensive range of log data. It's particularly adept at parsing and making sense of complex log formats, making it a versatile tool for understanding system activities and security events.

Cons

  • Improved User Interface Customization: While the interface is generally intuitive, providing more options for users to customize their dashboards and views would enhance the overall user experience. Tailoring the interface to specific roles or use cases could be a valuable addition.
  • Simplified Alert Management: Streamlining the process of managing alerts, such as grouping or categorizing them based on severity or type, would make it easier for security teams to prioritize and respond to incidents effectively.
  • Expanded Threat Intelligence Feeds: Increasing the variety and sources of threat intelligence feeds available within ES would provide a broader context for identifying and mitigating emerging threats, ensuring a more comprehensive defense against evolving attack vectors.

Likelihood to Recommend

Well-Suited Scenarios:

Real-Time Threat Response: ES excels in swiftly detecting and responding to security threats through data correlation.
Compliance Management: ES streamlines compliance with detailed logs and reports, ideal for regulated industries.
User Behavior Analytics: Effective in monitoring user and entity behavior, particularly for insider threat detection.
Large-Scale Environments: Valuable for organizations with diverse data sources and high volumes of data.
Incident Investigation: ES aids in post-incident analysis, reconstructing events to understand root causes.

Less Appropriate Scenarios:

Smaller Organizations: For simpler setups, ES may be complex and costly.
Static Environments: In low-risk settings, ES's advanced features may be unnecessary.
Limited Resources: Tight budgets or sparse IT resources may hinder effective ES use.
Lack of In-House Expertise: Without security experts, optimizing ES can be challenging.
Budget Constraints: ES may be cost-prohibitive for budget-conscious organizations, prompting consideration of more affordable alternatives.
Vetted Review
Splunk Enterprise Security
1 year of experience

Splunk ES Review

Rating: 7 out of 10
Incentivized

Use Cases and Deployment Scope

I was evaluating Splunk for a potential client. Splunk is a great tool for anyone that needs a SIEM to monitor data, networks, users, etc. The customization of the Dashboard is ideal for anyone to setup and use for an easy display of information. The alerts are incredibly helpful for notification of any problems

Pros

  • Develop dashboards and notables to track security-relevant details
  • Data correlation
  • threat monitoring and detection

Cons

  • more efficient searches
  • Multiple ways of creating report and alert is confusing
  • Multiple ways of creating report and alert is confusing

Likelihood to Recommend

It is very easy to connect data sources and manipulate data sets of any size

Splunk ES Review

Rating: 9 out of 10
Incentivized

Use Cases and Deployment Scope

We use Splunk ES to monitor security-relevant events, create notables for our Analysts to review, and overall improve our organization's security and security hygiene. Splunk ES is a service we offer to our clients as an MSSP and SOC-as-a-service, giving potential customers another great option to use for their own organization.

Pros

  • Breakdown event logs into easy-to-search fields
  • Provide relevant trends and metrics for events
  • Develop dashboards and notables to track security-relevant details

Cons

  • Ease-of-use for new users
  • Better options to export events/notables
  • More streamlined UI

Likelihood to Recommend

It has nearly limitless potential for security uses, but the learning curve is very steep
Vetted Review
Splunk Enterprise Security
1 year of experience

Securing Your Environment with Splunk Enterprise Security.

Rating: 9 out of 10
Incentivized

Use Cases and Deployment Scope

Our scope is actually quite large as my team is responsible for the protection of tens of thousands of devices. This is accomplished with the use of Enterprise Security, which we have used for the past several years to great effect. Enterprise Security enables us to detect and respond to threats in real time, monitor our environment's overall security compliance, and provide timely and insightful reports and metrics to management.

Pros

  • Security incident investigation.
  • Insider threat detection.
  • Reporting and metrics.

Cons

  • Learning curve - requires subject matter expertise and Splunk administration knowledge.
  • Automated response limitations - requires SOAR to unlock its full potential.

Likelihood to Recommend

Splunk Enterprise Security is a great fit for an organization that also utilizes Splunk in its environment. While there is a learning curve, if users and admins are already familiar with Splunk, it should be a straightforward task to get Enterprise Security up and running. It makes even more sense if the organization is already utilized Splunk Security Essentials. This is like Enterprise Security Lite - but much of the setup and configuration carries directly over to Enterprise Security.
Vetted Review
Splunk Enterprise Security
3 years of experience

Splunk Enterprise Security tools are Avengers for your software systems.

Rating: 8 out of 10
Incentivized

Use Cases and Deployment Scope

We use Splunk Enterprise Security tools as our first line of defense in combating threats on our multicolored on-premises deployments. Splunk provides advanced threat intelligence that utilizes an efficient model to immensely cut down on false alerts. Splunk Enterprise Security delivers an efficient data exfiltration model to identify suspicious activity and isolate threats and user behaviors.

Pros

  • I perform risk searches correlation several times a day. Splunk adds annotations to enrich correlation search results.
  • Greatly reduces alert volumes.

Cons

  • Demands incorporation of several risk factors to identify unauthorized usage which is quite complex and time-consuming.

Likelihood to Recommend

Working as a security software engineer, Splunk Enterprise Security is like my suite of premium tools to accomplish my work. Everyone who has been behind a monitoring screen for software threats understands how hectic false positives are. Splunk is however able to reduce the alert volumes by triaging notables and saving you from the false alerts nightmare.
Vetted Review
Splunk Enterprise Security
3 years of experience

Scalable and Magnificient Security Apparatus for Businesses.

Rating: 10 out of 10
Incentivized

Use Cases and Deployment Scope

Splunk Enterprise Security is an intelligent and highly investigative solution, that assists the business in coordinating all the systems, and bringing a solid reporting of the attacks and possible cyber security challenges in a company system. Besides, Splunk Enterprise Security investigates all the possible threats or activities both on the cloud and on the premise/offline, and this ensures every action has the stipulated security improvements. Finally, Splunk Enterprise Security set the strategies that improve the security apparatus of a company system.

Pros

  • Detailed security or threat detectors for systems.
  • Credible cloud and on premise security check and monitoring.
  • Focused security remedies on our systems.

Cons

  • Demands a documentation that is comprehensive and sufficiently enhanced.
  • Better scenario case examples for practicability.
  • Other security remedies are efficient and engaging.

Likelihood to Recommend

Splunk Enterprise Security governs all the security needs that a firm has, it stipulates the proficiency of every threat detector, and the practical remedies to eliminate different challenges. More so, Splunk Enterprise Security has secured different systems that may have been prone to attacks, which is a fruitful security engagement. The close monitoring of both internal and external systems through proper security checks increases business productivity.

Splunk FTW... when it's the right fit

Rating: 9 out of 10
Incentivized

Use Cases and Deployment Scope

We implement ES for banks, government orgs, and enterprises globally. We have specialised in the banking domains and have customised many use cases for banking specific use cases in our projects.

Pros

  • Extending capabilities to 3rd-party integrations.
  • Customisation of use cases.
  • Bringing in custom log sources and integrating these into security use cases.
  • High performance, enterprise-grade, security analytics at high volumes.

Cons

  • ES on the cloud (SaaS) has too many limitations with platform administration.
  • Supported integrations are not always on par with enterprise support especially when dependent on 3rd-party proprietary APIs.
  • In later versions, unforeseen glitches seem to show up that have no resolution except version upgrade. This used to not be the case in prior versions which were very stable.

Likelihood to Recommend

  1. ES is best suited when the customer has matured out of the older standard SIEM requirement. It is not the most effective tool for a 1st time SIEM requirement (e.g. in organisations where any generic security use cases can be implemented just for compliance check box)
  2. In extremely complex, multi-site clustering, management of SH clustering for ES has come to light recently. Customers with mature DC-DR multi site requirements and processes need to set a good SOP for recovery. That said, this is still the best product at scale.
Vetted Review
Splunk Enterprise Security
7 years of experience

The Best SIEM Solution the market has to offer!

Rating: 9 out of 10
Incentivized

Use Cases and Deployment Scope

Splunk ES is used as the SIEM solution in my organization for centralized logging and monitoring of Threats. We create new use cases as per our environment requirement and also leverage the different Analytical stories published by Splunk and tune them to our requirements. Splunk Incident review is used for Analysts Eye on the glass monitoring on a 24*7 basis.

Splunk ES is the single platform the SOC team uses to ingest new Threat Intelligence, Manage Assets, identify and also work towards identifying new threats.

Splunk ES can also be used to develop business use cases which focus on operational metrics and the alerts once triggered are sent out as notifications to different business teams.

Pros

  • Threat Intelligence Management - Splunk ES does a great job in automating the Intelligence collection from different sources like STIX and TAXII feeds, other third-party sources as well as internally built IOC repository.
  • Incident Review - The Incident Review tab is the single most important view on the Splunk ES which provides analysts with a crisp view of all newly triggered alerts and also provides enough filtering options.
  • The Search tab - The Splunk search tab is a very powerful utility to work on custom queries in SPL and also investigate ad-hoc detections and work towards building new use cases. This is where the real deep-dive investigation truly happens.
  • Investigations - The Splunk Investigations tab provides a unified view of all details pertaining to an incident to an analyst and it helps in faster triaging and remediation of incidents.

Cons

  • Alert Suppression - There should be a more user-friendly mechanism of performing alert suppressions and also a single console to track all use cases that have suppression enabled and what are those suppressions.
  • Extracting of new fields can be made simpler with fewer items to select so that even beginner-level analysts can extract fields as per requirement.
  • There should be dedicated options to search for IOCs in Splunk. SOC on a daily basis needs to hunt for IOCs and a copy-paste style of IOC hunting would help instead of writing queries.

Likelihood to Recommend

Having used multiple SIEM solutions over the past 8 years, can confidently say that Splunk is the single most versatile Platform for all Security Monitoring as well as Data Analytics needs. The platform just has enough flexibility for new integrations for apps and also fast rolling out of new features for customers. Also Splunk Docs is one excellent resource to refer to for anything related to Splunk. The platform offers great reporting options for management as well. The dashboards are super customizable so it serves as a perfect suite for any organization that needs to collect data for security monitoring as well as Big Data analytics.

Organizations that do not have a high budget for security, may choose the cloud only instances of Splunk, but if even that is expensive, and the company is too small and doesn't need that much work with data, they are better off with any other affordable alternative to Splunk, like LogRythm or Sentinel One. Splunk is the single most expensive SIEM and well it justifies the cost.

Splunk Enterprise Security Normalizes Security!

Rating: 8 out of 10
Incentivized

Use Cases and Deployment Scope

We utilize it to generate notable events and alerts on enterprise-wide activity. It also enhances our threat intelligence posture to bolster security sharing with our partners. Splunk Enterprise Security helps our organization solve the problem of creating alerts based on a variety of sources through data normalization. I enjoy the Common Information Model and how it helps normalize data across sources. Our analysts don't need to know every single source but can search off one field to collect a variety of events.

Pros

  • Normalize data
  • Search efficiency
  • Reporting and dashboards
  • Data visualization
  • Alerting and reporting

Cons

  • Improved user interface
  • Resource requirement
  • Admin overhead
  • Consolidated dashboarding

Likelihood to Recommend

Splunk Enterprise Security helps normalize the data across the environment. It allows our analysts to search with simple terms across sources of data. The data visualization aspect is also a vast sea of dashboards and reporting. However, I find the number of dashboards to be inefficient for analysts. They have to know which dashboard will give them the proper data. It would be much easier to have a dashboard that can give them a single pane of glass.