Splunk — Gartner SIEM Leader
Splunk is a leader in this Magic Quadrant. Splunk's Enterprise Security application is delivered on premises or through SaaS. Splunk offers pricing flexibility based on daily ingest or on cloud workloads, known as Splunk Virtual Compute. Most Splunk customers are larger enterprise organizations based in North America. Splunk is introducing an AI Assistant for Security integrated with Enterprise Security to provide detection and response capabilities. Cisco completed its acquisition of Splunk on 18 March 2024.
Strengths
- General observability: the Splunk platform can integrate security, IT, application, and other data sources. Together with its federated search and analysis capabilities across third-party data stores, this is a strength for customers looking to build highly enriched queries and alerts.
- Broad integration: SOAR integration improves a wide range of common SIEM use cases. Customers who want a fast path to automating common SIEM operational functions will find Splunk's playbook library a strength.
- User interface: the Splunk interface and dashboard allow significant customization. Customers who require custom animations and visualizations for specialized monitoring, such as OT or financial systems, will find the UI editor a general strength.
Market definition and description
SIEM is a configurable log-based security system that aggregates and analyzes security event data from on-premises and cloud environments. SIEM supports response actions to mitigate issues that cause damage to the organization and to meet compliance and reporting requirements. A security information and event management (SIEM) system should help with:
- Aggregating and normalizing data from various IT and operational technology (OT) environments.
- Identifying and investigating security events of interest.
- Supporting manual and automated response actions.
- Maintaining and reporting on current and historical security events.
Must-have capabilities
- Collecting infrastructure details and security-relevant data from a wide range of assets located on premises and/or in cloud infrastructure.
- The ability for end users to develop, modify, and maintain threat detection use cases using correlation, analytics, and signature-based methods.
- Providing SIEM vendor content and installation for customer-created content, in areas including analytics, data normalization, collection, and enrichment.
- Providing case management and support for incident response activities.
- Generating reports to support business, compliance, and audit needs as required.
Standard capabilities
- Storing essential security event data long term and making it available for search.
- Enabling collection of event data from disparate sources, using multiple mechanisms (log streaming, API, file processing) for threat detection, reporting, and incident investigation.
- Multiple deployment options: on premises, cloud hosted, cloud native, or SaaS.
- Normalization, enrichment, and risk scoring of data from third-party systems.
- Orchestration and automation of tasks and workflows to improve investigations and limit the impact of incidents.
- Full-featured SOAR functionality.
- Advanced analytics capabilities through user and entity behavior analytics (UEBA) and data science (supervised and unsupervised machine learning, deep learning / recurrent neural networks).
- Threat intelligence platform (TIP) capabilities to manage intelligence and provide contextual information.
