Splunk Enterprise Security, now part of Cisco, is a SIEM built on Splunk's data platform for threat detection, investigation, and response. It is aimed at security operations teams that analyze large volumes of machine data, and includes SOAR capabilities for automating response. The product can be deployed both in the cloud via Splunk Cloud and self-hosted. It carries an extensive compliance posture including SOC 2, ISO 27001, FedRAMP, HIPAA, and PCI-DSS, fitting regulated environments. Pricing is workload-based with no free tier.
siemsoarenterpriseanalytics
Overview
- Founded
- 2003
- Pricing tier
- High
- Startup-friendly
- No
- Enterprise-ready
- Yes
SIEM
- Cloud-native
- Yes
- Threat detection
- Yes
- SOAR included
- Yes
- Free tier
- No
- Deployment
- Both
