Splunk — Gartner SIEM Leader

Splunk is a leader in this Magic Quadrant. Splunk's Enterprise Security application is delivered on premises or through SaaS. Splunk offers pricing flexibility based on daily ingest or on cloud workloads, known as Splunk Virtual Compute. Most Splunk customers are larger enterprise organizations based in North America. Splunk is introducing an AI Assistant for Security integrated with Enterprise Security to provide detection and response capabilities. Cisco completed its acquisition of Splunk on 18 March 2024.

Strengths

Market definition and description

SIEM is a configurable log-based security system that aggregates and analyzes security event data from on-premises and cloud environments. SIEM supports response actions to mitigate issues that cause damage to the organization and to meet compliance and reporting requirements. A security information and event management (SIEM) system should help with:

Must-have capabilities

Standard capabilities