Splunk Enterprise Security Pros and Cons: Top 5 Advantages and Disadvantages

Quick AI Summary Based on G2 Reviews

Generated from real user reviews

Users value the ease of use of Splunk Enterprise Security, enhancing their monitoring and log management experience. (15 mentions)
Users appreciate the easy integrations of Splunk Enterprise Security, enabling seamless connection with various platforms and systems. (13 mentions)
Users highlight the impressive threat detection capabilities of Splunk Enterprise Security, enhancing security focus and reducing false alarms. (13 mentions)
Users value the effective features of Splunk Enterprise Security, enhancing security analysis with comprehensive logs and insights. (12 mentions)
Users appreciate the user-friendly interface of Splunk Enterprise Security, enabling efficient monitoring and attractive dashboards. (11 mentions)
Users note that the high cost of Splunk Enterprise Security is a major drawback for smaller organizations. (17 mentions)
Users find the initial implementation complex, needing expert resources and time to onboard Splunk Enterprise Security effectively. (8 mentions)
Users find the complex implementation of Splunk Enterprise Security challenging, requiring extensive expertise and resources. (6 mentions)
Users find the complexity and extensive setup of Splunk Enterprise Security to be time-consuming and challenging. (6 mentions)
Users find the difficult learning curve of Splunk Enterprise Security a challenge for beginners and costly to set up. (6 mentions)

5 Pros or Advantages of Splunk Enterprise Security

5 Cons or Disadvantages of Splunk Enterprise Security

Splunk Enterprise Security Reviews (247)

View 2 Video Reviews
Reviews

Splunk Enterprise Security Reviews (247)

View 2 Video Reviews
4.3
247 reviews
Search reviews
Filter Reviews
Clear Results
G2 reviews are authentic and verified.
Priyanshu S.
PS
Priyanshu S.
SOC Analyst Trainee
Small-Business (50 or fewer emp.)
"Powerful Threat Detection and Investigation with Splunk Enterprise Security"
5/5
What do you like best about Splunk Enterprise Security?

What I like best about Splunk Enterprise Security is its powerful threat detection and investigation capabilities. It provides a centralized view of security events from multiple sources, making it easier to monitor and analyze security incidents. The correlation searches, customizable dashboards, and threat intelligence integrations help reduce investigation time and improve overall security visibility. I also appreciate its scalability and flexibility, which allow it to adapt to different organizational requirements and large volumes of security data. Review collected by and hosted on G2.com.

What do you dislike about Splunk Enterprise Security?

One aspect I dislike about Splunk Enterprise Security is that it can have a steep learning curve, especially for new users who are not familiar with Splunk's search language and advanced configurations. The platform is highly capable, but setting up and tuning correlation rules can take time and expertise. Additionally, managing large data volumes can become expensive, and some dashboards or searches may require optimization to maintain performance in larger environments. However, once properly configured, the platform delivers strong security monitoring and investigation capabilities. Review collected by and hosted on G2.com.

Akil S.
AS
Akil S.
Technical Blogger
Small-Business (50 or fewer emp.)
"Powerful Visibility and Investigations with Splunk Enterprise Security"
4/5
What do you like best about Splunk Enterprise Security?

What I liked most is the visibility it gives once everything is set up. It becomes a solid central place for monitoring and investigations, and correlating logs across systems actually helps catch things faster.

The built-in detection rules and dashboards are a good starting point, and integrations are flexible enough to bring in data from pretty much anywhere. Performance is reliable too, as long as your queries are optimized.

It does take some effort to tune alerts and get real value, but once that’s done, it makes day-to-day security workflows a lot more structured and efficient. Review collected by and hosted on G2.com.

What do you dislike about Splunk Enterprise Security?

The biggest issue is the complexity. Setup and onboarding take time, and you really need someone experienced to get it running properly. It is not beginner friendly at all.

Pricing can also get expensive fast since it is based on data ingestion, so you have to constantly manage what logs you are sending in.

The UI feels a bit clunky in places, and navigating during investigations is not always smooth. On top of that, alerts need a lot of tuning. Without it, you end up with too much noise, which affects response time.

Overall, its Ai is powerful, but it takes effort, expertise, and budget to actually make it work well. Review collected by and hosted on G2.com.

NT
Naushad T.
Lead Technical Specialist - EDR
Enterprise (> 1000 emp.)
"Splunk ES- Scalable SIEM for Large Enterprise"
4.5/5
What do you like best about Splunk Enterprise Security?

The best thing about Splunk is the deep visibility it provides across the environment, along with its strong ability to correlate large volumes of security data into true positive, actionable alerts. This really helps make investigations/incident response faster and more efficient. Review collected by and hosted on G2.com.

What do you dislike about Splunk Enterprise Security?

The initial implementation is complicated and requires significant expertise, time, and resources. In our case, we had to extend the contract to a third party to onboard Splunk ES in our environment. Review collected by and hosted on G2.com.

Muhammad R.
MR
Muhammad R.
Technical Consultant Manager
Enterprise (> 1000 emp.)
"Unmatched Visibility and Customization for Security Operations"
5/5
What do you like best about Splunk Enterprise Security?

What I like most about Splunk Enterprise Security is its ability to give clear and comprehensive visibility across the entire environment. The correlation searches, use cases, and dashboards make it easier to identify patterns and prioritize threats. As someone who works in SOC operations and consulting, the flexibility to customize detections and build my own dashboards is a huge advantage and everything feels scalable, structured, and analyst-friendly. Review collected by and hosted on G2.com.

What do you dislike about Splunk Enterprise Security?

What I dislike about Splunk Enterprise Security is that some of its features can be quite resource intensive. The platform is powerful, but it sometimes requires significant tuning and infrastructure capacity to keep everything running smoothly. Additionally, certain configurations or customizations can take more time than expected. It’s not a major drawback, but it does require proper planning and optimization. Review collected by and hosted on G2.com.

Chris S.
CS
Chris S.
Recruiting Consultant
Enterprise (> 1000 emp.)
"Strong Correlation Analytics That Spot Threats Fast"
4.5/5
What do you like best about Splunk Enterprise Security?

Strong correlation searches and analytics help spot threats quickly, not hours later. Review collected by and hosted on G2.com.

What do you dislike about Splunk Enterprise Security?

It’s expensive, especially since pricing is based on data ingestion. Costs can climb quickly as your environment grows. Review collected by and hosted on G2.com.

Luis S.
LS
Luis S.
Presales
Small-Business (50 or fewer emp.)
"the best SIEM"
3.5/5
What do you like best about Splunk Enterprise Security?

Easy-to-use platform that integrates with different devices Review collected by and hosted on G2.com.

What do you dislike about Splunk Enterprise Security?

The licensing model based on event consumption and the new owner Review collected by and hosted on G2.com.

Verified User in Financial Services
AF
Verified User in Financial Services
Mid-Market (51-1000 emp.)
"Robust SIEM Solution with Strong Ecosystem Support"
4.5/5
What do you like best about Splunk Enterprise Security?

✅ Powerful Search and Correlation Capabilities

Splunk Enterprise Security excels at log aggregation, correlation, and threat detection. The Search Processing Language (SPL) allows advanced querying that lets our team pinpoint suspicious activity across multiple systems.

✅ Strong Integration with Multiple Systems

One of the key strengths is its ability to integrate with a wide range of third-party systems - firewalls, endpoint detection tools, identity providers, and cloud environments like AWS, Azure, and GCP. It pulls everything into a central platform, which is critical for visibility.

✅ Splunkbase Ecosystem

The Splunkbase app ecosystem is extensive. We’ve used certified add-ons and community-built integrations for tools like Palo Alto Networks, CrowdStrike, Okta, and Microsoft 365. This dramatically reduces the time required to normalize and enrich logs.

✅ Flexible Dashboards and Alerts

Splunk ES provides customizable dashboards and correlation rules, making it easier to tailor detection mechanisms to our organization's needs. The MITRE ATT&CK integration is also a big plus for mapping threats and to evaluate how our detection coverage maps against possible threats.

✅ Scalability

We’ve scaled Splunk ES from ingesting a few hundred GBs a day to multiple TBs without much performance degradation, though it requires careful planning and tuning. Review collected by and hosted on G2.com.

What do you dislike about Splunk Enterprise Security?

❌ Learning Curve

The flexibility of SPL is a double-edged sword. New analysts often struggle with query writing and alert customization unless they have a strong background in Splunk or scripting. However, there is now an AI solution which will convert natural language to complex SPL syntax.

❌ Expensive at Scale

Pricing is based on ingest volume, which might be expensive as data grows. Without smart data hygiene practices and archiving, costs can grow easily.

❌ Heavy Resource Requirements

On-premise deployments require significant compute and storage resources. High availability and disaster recovery setups can become complex and costly. However, Splunk Cloud takes care of much of this work if purchased.

❌ Limited Out-of-the-Box Content for Certain Use Cases

Although it comes with prebuilt dashboards and correlation rules, some use cases (like insider threat or advanced cloud threat detection) require additional tuning, enterprise specific knowledge or external tools to be truly effective. Review collected by and hosted on G2.com.

JM
Jordan M.
security engineer
Enterprise (> 1000 emp.)
"Splunk in a security environment"
4/5
What do you like best about Splunk Enterprise Security?

Splunk is easy to use/configure and to find what i need. plus, the splunk employees with whom we work are very talented and skilled Review collected by and hosted on G2.com.

What do you dislike about Splunk Enterprise Security?

they got bought by cisco and we are waiting for integrations to get better Review collected by and hosted on G2.com.

Anugrah Pratap S.
AS
Anugrah Pratap S.
Technical Lead
Enterprise (> 1000 emp.)
"Unmatched data mining, analysis, and Security monitoring by Splunk ES"
4.5/5
What do you like best about Splunk Enterprise Security?

Splunk ES is very helpful in seamless integration and automation, Data analytics, Investigation, Log source onboarding, dashboard, SPL, ease of search, use-case modification/fine-tuning, you name it. Every task and job in Splunk ES is perfect. Its vendor support is very responsive. Splunk ES has ease of implementation and integration. Review collected by and hosted on G2.com.

What do you dislike about Splunk Enterprise Security?

Apart from cost, no one dislikes Splunk ES. Due to its costly services, most organizations use other cloud-native security solutions. Recently, one of our clients also proposed another security solution over Splunk ES. so that's cost is the main disadvantage of Splunk ES in my opinion. Review collected by and hosted on G2.com.

EM
Ernesto M.
IT Security Engineer
Mid-Market (51-1000 emp.)
"Easy to integrate, understand the workflows and to manage."
5/5
What do you like best about Splunk Enterprise Security?

Splunk ES is easy to manage and understard even if you are new with SIEMs. The workflows are easy to follow and the language the splunk uses is easy to learn. Also, it has integration with anything so you can ingest logs from pretty much everything you can think of. Review collected by and hosted on G2.com.

What do you dislike about Splunk Enterprise Security?

Might be very expensinve depend of how much data you are ingesting. Review collected by and hosted on G2.com.

Product Avatar Image
Splunk
4.3/5(247)