Splunk Enterprise Security Pros and Cons: Top 5 Advantages and Disadvantages

Quick AI Summary Based on G2 Reviews

Generated from real user reviews

Users value the ease of use of Splunk Enterprise Security, enhancing their monitoring and log management experience. (15 mentions)
Users appreciate the easy integrations of Splunk Enterprise Security, enabling seamless connection with various platforms and systems. (13 mentions)
Users highlight the impressive threat detection capabilities of Splunk Enterprise Security, enhancing security focus and reducing false alarms. (13 mentions)
Users value the effective features of Splunk Enterprise Security, enhancing security analysis with comprehensive logs and insights. (12 mentions)
Users appreciate the user-friendly interface of Splunk Enterprise Security, enabling efficient monitoring and attractive dashboards. (11 mentions)
Users note that the high cost of Splunk Enterprise Security is a major drawback for smaller organizations. (17 mentions)
Users find the initial implementation complex, needing expert resources and time to onboard Splunk Enterprise Security effectively. (8 mentions)
Users find the complex implementation of Splunk Enterprise Security challenging, requiring extensive expertise and resources. (6 mentions)
Users find the complexity and extensive setup of Splunk Enterprise Security to be time-consuming and challenging. (6 mentions)
Users find the difficult learning curve of Splunk Enterprise Security a challenge for beginners and costly to set up. (6 mentions)

5 Pros or Advantages of Splunk Enterprise Security

5 Cons or Disadvantages of Splunk Enterprise Security

Splunk Enterprise Security Reviews (10)

View 2 Video Reviews
Reviews

Splunk Enterprise Security Reviews (10)

View 2 Video Reviews
4.3
248 reviews
Search reviews
Clear Results
Filter Reviews
Clear Results
G2 reviews are authentic and verified.
Muhammad R.
MR
Muhammad R.
Technical Consultant Manager
Enterprise (> 1000 emp.)
"Unmatched Visibility and Customization for Security Operations"
5/5
What do you like best about Splunk Enterprise Security?

What I like most about Splunk Enterprise Security is its ability to give clear and comprehensive visibility across the entire environment. The correlation searches, use cases, and dashboards make it easier to identify patterns and prioritize threats. As someone who works in SOC operations and consulting, the flexibility to customize detections and build my own dashboards is a huge advantage and everything feels scalable, structured, and analyst-friendly. Review collected by and hosted on G2.com.

What do you dislike about Splunk Enterprise Security?

What I dislike about Splunk Enterprise Security is that some of its features can be quite resource intensive. The platform is powerful, but it sometimes requires significant tuning and infrastructure capacity to keep everything running smoothly. Additionally, certain configurations or customizations can take more time than expected. It’s not a major drawback, but it does require proper planning and optimization. Review collected by and hosted on G2.com.

Anugrah Pratap S.
AS
Anugrah Pratap S.
Technical Lead
Enterprise (> 1000 emp.)
"Unmatched data mining, analysis, and Security monitoring by Splunk ES"
4.5/5
What do you like best about Splunk Enterprise Security?

Splunk ES is very helpful in seamless integration and automation, Data analytics, Investigation, Log source onboarding, dashboard, SPL, ease of search, use-case modification/fine-tuning, you name it. Every task and job in Splunk ES is perfect. Its vendor support is very responsive. Splunk ES has ease of implementation and integration. Review collected by and hosted on G2.com.

What do you dislike about Splunk Enterprise Security?

Apart from cost, no one dislikes Splunk ES. Due to its costly services, most organizations use other cloud-native security solutions. Recently, one of our clients also proposed another security solution over Splunk ES. so that's cost is the main disadvantage of Splunk ES in my opinion. Review collected by and hosted on G2.com.

Manish D.
MD
Manish D.
Staff Security Engineer - SecOps
Enterprise (> 1000 emp.)
"One of the leading & innovative SIEM solution"
4.5/5
What do you like best about Splunk Enterprise Security?

The simplified UX is what makes Splunk/Splunk Enterprise Security (ES) seperate from all other competitors. The vast range of data connectors in Splunkbase, simplified architecture, granular level of customization options, out of the box data models and complete coverage of MITRE Att&ck are some of the prime features and services offered by Splunk ES. The data model acceleration, notable events, dashboards and wide range of apps & addons makes searching and data transformation tasks really easy. The customer support is great for any type of issues you might be facing. Review collected by and hosted on G2.com.

What do you dislike about Splunk Enterprise Security?

The licensing model and cost is bit difficult to understand and manage. Review collected by and hosted on G2.com.

Alexandra V.
AV
Alexandra V.
Senior Software Engineer
Mid-Market (51-1000 emp.)
"Splunk Enterprise Security is the master log data collection and threat detection"
4.5/5
What do you like best about Splunk Enterprise Security?

It is easy to use and quick to collect multiple event and data log with best intrusion dection capability. Easy to integrate and quick to customize dashboard and the initial implementation process is also very easy. Review collected by and hosted on G2.com.

What do you dislike about Splunk Enterprise Security?

Advanced security settings not easy especially when new with the system. The support team deseves merit for being helpful and always available when in need. Review collected by and hosted on G2.com.

Santosh V.
SV
Santosh V.
Senior Engineer
Construction
Mid-Market (51-1000 emp.)
"A Game-Changing Security Platform Revolutionizing Cybersecurity."
5/5
What do you like best about Splunk Enterprise Security?

One thing I really love about Splunk ES is a very robust and intuitive security platform that has been a game-changer platform when it comes to revolutionizing Cybersecurity. I like it offers advanced threat detection with ability to detect sophisticated threats by correlating data from multiple sources.

Real-time monitoring and alerting which alerts us during critical security events such as suspicious network traffic or any issues occurring without us knowing.

It also offers real-time threat response which helps us to swiftly detecting and responding to security threats on time before they affect our business processes or systems or apps.

Monitoring log activity for potential security incidents.

Amazing and proactive customer support team.

Intuitive UI for investigation which is pretty easy to use. Review collected by and hosted on G2.com.

What do you dislike about Splunk Enterprise Security?

I have experienced that sometimes the events tab doesn't show logs.

Slow interface incase of high data volume. Review collected by and hosted on G2.com.

Sabih K.
SK
Sabih K.
Data Analyst
Small-Business (50 or fewer emp.)
"Best SIEM tool"
5/5
What do you like best about Splunk Enterprise Security?

Spluck Intelligence Management tool is a great, It's provide security and daily logs which makes security analyst or engineer which make's easier to analyse . I love it's query search and report generate feature, which provides a great in the form of statistics report. Review collected by and hosted on G2.com.

What do you dislike about Splunk Enterprise Security?

I can't se anay bad features in this tools but sometimes we gets confused that there are so many logs, and lot to see more. Review collected by and hosted on G2.com.

Verified User in Telecommunications
UT
Verified User in Telecommunications
Enterprise (> 1000 emp.)
"Splunk user behavior"
3/5
What do you like best about Splunk Enterprise Security?

It's great because it uses smart technology to spot unusual behavior from users that might signal security issues. It helps find potential threats early and reduce false alarms, making it easier for security teams to focus on real problems. Review collected by and hosted on G2.com.

What do you dislike about Splunk Enterprise Security?

it can be complex and require a lot of setup. Review collected by and hosted on G2.com.

Vishal G.
VG
Vishal G.
Senior System Engineer
Enterprise (> 1000 emp.)
"Its better for capturing realtime incidents"
4.5/5
What do you like best about Splunk Enterprise Security?

In Splunk Enterprise Security, we save some searches and creating attractive dashboard which give impulsive graphical view of realtime events Review collected by and hosted on G2.com.

What do you dislike about Splunk Enterprise Security?

In incident secirity tab if we change status of any notable then whole page was refresh. Review collected by and hosted on G2.com.

Rajat s.
RS
Rajat s.
SOC Specialist (SIEM SME)
Small-Business (50 or fewer emp.)
"Splunk Enterprise security overview"
4.5/5
What do you like best about Splunk Enterprise Security?

It provides ability to integrate the log sources from different security devices,provides flexibility to add any of third intel tool to integrate and get the dynamic reputations through that,had great Gui to analyze the alerts and escalate it further for deep investigation.Easily can implement any of the organisation either small or big. Review collected by and hosted on G2.com.

What do you dislike about Splunk Enterprise Security?

Cost price seems high so small enterprises having problem with their cost cutting,Need proper videos and materials to understand its platform otherwise nearly everything is okay and cover approx all kind of security devices ,Customer support is also a concern need instant support on any of the subjective matter so that organizations which have less experience or technical person can understand and work on this platform without any hesitation. Review collected by and hosted on G2.com.

Tejas B.
TB
Tejas B.
Senior Cloud Information Security Engineer
Mid-Market (51-1000 emp.)
"Best platform for threat analysis"
5/5
What do you like best about Splunk Enterprise Security?

Threat intel feeds, all threat related dashboards to investigate security incident. Asset and identity dashboard helps to prioritise the incident from incident review dashboard. Review collected by and hosted on G2.com.

What do you dislike about Splunk Enterprise Security?

Threat intel feed should be divided in different category. For example, bad IPs, bad domains, bad URLs instead of clubbing them together. Review collected by and hosted on G2.com.

Product Avatar Image
Splunk
4.3/5(248)