Recommendations to others considering Splunk Enterprise Security:
Get Splunk Enterprise for free to experiment with your use case, often your proof of concept could easily be used as the final analysis application that you need at your Enterprise. The documentation is thorough for each topic from installation, administration, search, development, etc. So, you can give it a try. It is worth the effort and investment to ensure your systems and data footprint. There are various tools available in the market that won't break your bank, however, you get what you pay for. This tool gives you a complete 360-degree view of the data footprint. However, there will be a learning curve to get and you will likely find that you are quickly overwhelmed by the amount of things you can do. Especially when you start getting information from different sources and wish to connect that information into dashboards and applications. Review collected by and hosted on G2.com.
What problems is Splunk Enterprise Security solving and how is that benefiting you?
Aggregating and performing pattern matching of events that can inform us if any malicious activity is occurring. It gives us a complete view into our overall security posture with appropriate drill downs into specific data to see what's happening in the organization. Collecting and analyzing data with Splunk is easy. However, there are other products out there - Graylog, the ELK stack - which are free and do the same thing - just with more work. However, once you build your dashboard, you are good to go - throw as much data at it as you want. Review collected by and hosted on G2.com.