
Splunk provides a very simple user interface, and it’s easy to use for daily BAU activities. I used a different solution before where we had to log in to ESM and the logger separately, but Splunk brings everything together in one place. Review collected by and hosted on G2.com.
The main thing I dislike about Splunk Enterprise Security is how complex it can be to configure and manage, especially for new users. Creating and tuning correlation searches often requires a solid understanding of SPL and the underlying data. It also takes ongoing effort to reduce false positives and to keep dashboards and detections properly maintained as the environment changes. Review collected by and hosted on G2.com.