Splunk Enterprise Security Pros and Cons: Top 5 Advantages and Disadvantages

Quick AI Summary Based on G2 Reviews

Generated from real user reviews

Users value the ease of use of Splunk Enterprise Security, enhancing their monitoring and log management experience. (15 mentions)
Users appreciate the easy integrations of Splunk Enterprise Security, enabling seamless connection with various platforms and systems. (13 mentions)
Users highlight the impressive threat detection capabilities of Splunk Enterprise Security, enhancing security focus and reducing false alarms. (13 mentions)
Users value the effective features of Splunk Enterprise Security, enhancing security analysis with comprehensive logs and insights. (12 mentions)
Users appreciate the user-friendly interface of Splunk Enterprise Security, enabling efficient monitoring and attractive dashboards. (11 mentions)
Users note that the high cost of Splunk Enterprise Security is a major drawback for smaller organizations. (17 mentions)
Users find the initial implementation complex, needing expert resources and time to onboard Splunk Enterprise Security effectively. (8 mentions)
Users find the complex implementation of Splunk Enterprise Security challenging, requiring extensive expertise and resources. (6 mentions)
Users find the complexity and extensive setup of Splunk Enterprise Security to be time-consuming and challenging. (6 mentions)
Users find the difficult learning curve of Splunk Enterprise Security a challenge for beginners and costly to set up. (6 mentions)

5 Pros or Advantages of Splunk Enterprise Security

5 Cons or Disadvantages of Splunk Enterprise Security

Splunk Enterprise Security Reviews (13)

View 2 Video Reviews
Reviews

Splunk Enterprise Security Reviews (13)

View 2 Video Reviews
4.3
248 reviews
Search reviews
Clear Results
Filter Reviews
Clear Results
G2 reviews are authentic and verified.
Verified User in Financial Services
AF
Verified User in Financial Services
Mid-Market (51-1000 emp.)
"Robust SIEM Solution with Strong Ecosystem Support"
4.5/5
What do you like best about Splunk Enterprise Security?

✅ Powerful Search and Correlation Capabilities

Splunk Enterprise Security excels at log aggregation, correlation, and threat detection. The Search Processing Language (SPL) allows advanced querying that lets our team pinpoint suspicious activity across multiple systems.

✅ Strong Integration with Multiple Systems

One of the key strengths is its ability to integrate with a wide range of third-party systems - firewalls, endpoint detection tools, identity providers, and cloud environments like AWS, Azure, and GCP. It pulls everything into a central platform, which is critical for visibility.

✅ Splunkbase Ecosystem

The Splunkbase app ecosystem is extensive. We’ve used certified add-ons and community-built integrations for tools like Palo Alto Networks, CrowdStrike, Okta, and Microsoft 365. This dramatically reduces the time required to normalize and enrich logs.

✅ Flexible Dashboards and Alerts

Splunk ES provides customizable dashboards and correlation rules, making it easier to tailor detection mechanisms to our organization's needs. The MITRE ATT&CK integration is also a big plus for mapping threats and to evaluate how our detection coverage maps against possible threats.

✅ Scalability

We’ve scaled Splunk ES from ingesting a few hundred GBs a day to multiple TBs without much performance degradation, though it requires careful planning and tuning. Review collected by and hosted on G2.com.

What do you dislike about Splunk Enterprise Security?

❌ Learning Curve

The flexibility of SPL is a double-edged sword. New analysts often struggle with query writing and alert customization unless they have a strong background in Splunk or scripting. However, there is now an AI solution which will convert natural language to complex SPL syntax.

❌ Expensive at Scale

Pricing is based on ingest volume, which might be expensive as data grows. Without smart data hygiene practices and archiving, costs can grow easily.

❌ Heavy Resource Requirements

On-premise deployments require significant compute and storage resources. High availability and disaster recovery setups can become complex and costly. However, Splunk Cloud takes care of much of this work if purchased.

❌ Limited Out-of-the-Box Content for Certain Use Cases

Although it comes with prebuilt dashboards and correlation rules, some use cases (like insider threat or advanced cloud threat detection) require additional tuning, enterprise specific knowledge or external tools to be truly effective. Review collected by and hosted on G2.com.

Anugrah Pratap S.
AS
Anugrah Pratap S.
Technical Lead
Enterprise (> 1000 emp.)
"Unmatched data mining, analysis, and Security monitoring by Splunk ES"
4.5/5
What do you like best about Splunk Enterprise Security?

Splunk ES is very helpful in seamless integration and automation, Data analytics, Investigation, Log source onboarding, dashboard, SPL, ease of search, use-case modification/fine-tuning, you name it. Every task and job in Splunk ES is perfect. Its vendor support is very responsive. Splunk ES has ease of implementation and integration. Review collected by and hosted on G2.com.

What do you dislike about Splunk Enterprise Security?

Apart from cost, no one dislikes Splunk ES. Due to its costly services, most organizations use other cloud-native security solutions. Recently, one of our clients also proposed another security solution over Splunk ES. so that's cost is the main disadvantage of Splunk ES in my opinion. Review collected by and hosted on G2.com.

EM
Ernesto M.
IT Security Engineer
Mid-Market (51-1000 emp.)
"Easy to integrate, understand the workflows and to manage."
5/5
What do you like best about Splunk Enterprise Security?

Splunk ES is easy to manage and understard even if you are new with SIEMs. The workflows are easy to follow and the language the splunk uses is easy to learn. Also, it has integration with anything so you can ingest logs from pretty much everything you can think of. Review collected by and hosted on G2.com.

What do you dislike about Splunk Enterprise Security?

Might be very expensinve depend of how much data you are ingesting. Review collected by and hosted on G2.com.

RP
RUDRA P.
Security Professional
Information Technology and Services
Enterprise (> 1000 emp.)
"Splunk User Behavior Analytics Review"
5/5
What do you like best about Splunk Enterprise Security?

Splunk User Behavior Analytics establishes baseline behaviors for users, devices, and applications using unsupervised machine learning algorithms. It then looks for deviations to identify insider risks and unknown threats. This can be easily integrated with other tools and is easy to use. Has good customer support. Can be implemented on cloud and can be used from anywhere in current hybrid work environment. We have been using it since last 3 years. Review collected by and hosted on G2.com.

What do you dislike about Splunk Enterprise Security?

There is nothing which is least helpful in this tool hence i do not have any dislike for Splunk User Behavior Analytics. Review collected by and hosted on G2.com.

SS
Sanket S.
Technical Specialist
Mid-Market (51-1000 emp.)
"Navigating insider threats using Splunk"
5/5
What do you like best about Splunk Enterprise Security?

It uses machine learning to identify abnormal user and entity behaviour. It effectively identifies threat by analyzing patterns of behavior that are not matching with normal patterns.

It integrates well with broader splunk ecosystem, allowing users to leverage their existing splunk investment and data. Review collected by and hosted on G2.com.

What do you dislike about Splunk Enterprise Security?

Setting up and configuring this solution can be complex and time consuming.

It may generates false positives, especially in the early stages of deployment. Review collected by and hosted on G2.com.

Verified User in Information Technology and Services
UI
Verified User in Information Technology and Services
Enterprise (> 1000 emp.)
"My experience with splunk enterprise security"
5/5
What do you like best about Splunk Enterprise Security?

The ease of integration, visualisation and alert creation. Data handling and customisation. Minimalistic maintenance Review collected by and hosted on G2.com.

What do you dislike about Splunk Enterprise Security?

There are nothing much to dislike here. But I can say search speed will be a bit of issue for me when it is overloaded unless we are using optimal queries Review collected by and hosted on G2.com.

Alexandra V.
AV
Alexandra V.
Senior Software Engineer
Mid-Market (51-1000 emp.)
"Splunk Enterprise Security is the master log data collection and threat detection"
4.5/5
What do you like best about Splunk Enterprise Security?

It is easy to use and quick to collect multiple event and data log with best intrusion dection capability. Easy to integrate and quick to customize dashboard and the initial implementation process is also very easy. Review collected by and hosted on G2.com.

What do you dislike about Splunk Enterprise Security?

Advanced security settings not easy especially when new with the system. The support team deseves merit for being helpful and always available when in need. Review collected by and hosted on G2.com.

Alaa E.
AE
Alaa E.
Cybersecurity Consultant
Mid-Market (51-1000 emp.)
"Splunk ES : Empowering Security Operations"
4.5/5
What do you like best about Splunk Enterprise Security?

One notable aspect of Splunk ES that I find particularly commendable is its extensive array of integration options with various platforms. Furthermore, the inclusion of the adaptive response feature significantly enhances the efficiency and effectiveness of SOC analysts, streamlining their workflows and contributing to a more seamless experience. Review collected by and hosted on G2.com.

What do you dislike about Splunk Enterprise Security?

One drawback of Splunk ES lies in its implementation complexity, which appears to be comparatively higher when juxtaposed with other SIEM solutions. Additionally, the associated cost is positioned at a premium level in comparison to the majority of SIEM offerings. This may pose a challenge for organizations seeking a more straightforward deployment process and a cost-effective SIEM solution. Review collected by and hosted on G2.com.

Sayantica G.
SG
Sayantica G.
Junior Security Analyst
Mid-Market (51-1000 emp.)
"Splunk Enterprise Security"
3.5/5
What do you like best about Splunk Enterprise Security?

Splunk has every aspect of security integration like plugins and also some development software from third party . Review collected by and hosted on G2.com.

What do you dislike about Splunk Enterprise Security?

Costly and for EPS also takes charges little bit high rather than its competitite product. For 500 workstation integration its good but less than that it suggest to use thier data monitoring and analysis tool. Review collected by and hosted on G2.com.

Rajat s.
RS
Rajat s.
SOC Specialist (SIEM SME)
Small-Business (50 or fewer emp.)
"Splunk Enterprise security overview"
4.5/5
What do you like best about Splunk Enterprise Security?

It provides ability to integrate the log sources from different security devices,provides flexibility to add any of third intel tool to integrate and get the dynamic reputations through that,had great Gui to analyze the alerts and escalate it further for deep investigation.Easily can implement any of the organisation either small or big. Review collected by and hosted on G2.com.

What do you dislike about Splunk Enterprise Security?

Cost price seems high so small enterprises having problem with their cost cutting,Need proper videos and materials to understand its platform otherwise nearly everything is okay and cover approx all kind of security devices ,Customer support is also a concern need instant support on any of the subjective matter so that organizations which have less experience or technical person can understand and work on this platform without any hesitation. Review collected by and hosted on G2.com.

Product Avatar Image
Splunk
4.3/5(248)