Softwr
Splunk Enterprise Security logo

Splunk Enterprise Security

The platform for operational intelligence

Overview

What Splunk Enterprise Security does

Splunk Enterprise Security is a SIEM solution that provides insight into machine data generated by security technologies. It enables security teams to detect, investigate, and respond to threats quickly.

What people use it for

  • Running a security operations centre on Splunk indexed log data
  • Correlation searches, risk based alerting and incident investigation
  • Compliance reporting from pooled security telemetry

The honest half

Where it falls short

Concrete and checkable, so you can decide whether any of them matter to you. This is the half of a review a vendor will not write about Splunk Enterprise Security.

  • Splunk Enterprise Security is licensed separately from the Splunk platform, so a SIEM deployment needs both
  • Splunk publishes no rate for Enterprise Security and directs buyers to contact a pricing expert
  • UEBA, SOAR and automated threat analysis require the Premier edition rather than Essentials
  • The platform underneath can be billed by ingest volume, workload or activity, so the total cost depends on a pricing model chosen at contract time rather than a list price

Pricing

What Splunk Enterprise Security costs

Taken from the vendor's own pricing page. Prices move, so check before you buy.

Workload Pricing

Free

  • Pay per compute
  • Flexible scaling
  • All features
  • Contact sales

Ingest Pricing

Free

  • Pay per GB ingested
  • Predictable costs
  • All features
  • Contact sales

Entity Pricing

Free

  • Pay per monitored entity
  • Security focused
  • All features
  • Contact sales

Capabilities

Features

  • Security monitoring

    Security monitoring capability

  • Incident review

    Incident review capability

  • Risk-based alerting

    Risk-based alerting capability

  • Threat intelligence

    Threat intelligence capability

  • Investigation workbench

    Investigation workbench capability

  • MITRE ATT&CK mapping

    MITRE ATT&CK mapping capability

  • Automated response

    Automated response capability

  • Compliance reporting

    Compliance reporting capability

  • AWS

    Integration with AWS

  • Azure

    Integration with Azure

  • Google Cloud

    Integration with Google Cloud

  • Palo Alto

    Integration with Palo Alto

Behind it

Who makes Splunk Enterprise Security

Company
Splunk Inc (Cisco)
Based in
San Francisco, California, USA

Keep looking

Where to go from Splunk Enterprise Security

Other Security Cybersecurity software

Softwr does not host reviews and shows no star rating for Splunk Enterprise Security, because a rating we did not collect is not ours to publish. What is here is the pricing and platform detail from the vendor’s own pages, limitations we could state concretely, and alternatives a reviewer confirmed people weigh against it. Tell us if any of it is wrong.

More on Splunk Enterprise Security