Our Outcomes from Using Splunk ES
Use Cases and Deployment Scope
Pros
- Instead of reviewing thousands of low level alerts, I can prioritize risks based on the entity's risk score on the risk based alerts dashboard
- The adaptive response framework allows me to link alerts directly to our SOAR playbooks in phantom. This way I can automate triage steps that traditionally took hours.
Cons
- Creating complex custom correlation searches sometimes feels more complicated than it should. You need deep SPL experience to build anything beyond basic logic.
Return on Investment
- By consolidating 3 legacy SIEM tools into Splunk ES, we reduced licensing and infrastructure costs by about 30 percent annually.
- We are able to have retention rates much higher than the industry average, since Splunk is ridiculously reliable



