Home / Portfolio / Splunk / Security

Splunk Security (SIEM & SOAR)

Splunk's security portfolio for modern SOC operations: an analytics-driven SIEM, response automation and orchestration, user behavior analytics and threat analysis, all on data at scale.

Security

4 products
SIEM

Splunk Enterprise Security

Enterprise Security (ES)

Analytics-driven SIEM that centralizes detection, investigation and response with risk-based alerting (RBA) and frameworks such as MITRE ATT&CK.

  • Risk-based alerting (RBA)
  • Correlation and detection at scale
  • Mapping to MITRE ATT&CK
Automation

Splunk SOAR

SOAR

Security orchestration, automation and response with playbooks that speed up incident containment.

  • Automation playbooks
  • Hundreds of integrations (apps)
  • Case management
Behavior analytics

Splunk User Behavior Analytics

UBA

Detection of insider and compromised-account threats through machine learning on user and entity behavior.

  • Machine learning (UEBA)
  • Insider and account threats
  • Fewer false positives
Threat analysis

Splunk Attack Analyzer

Attack Analyzer

Automated analysis of active threats (phishing and malware) with detonation in a safe environment to speed up investigation.

  • Phishing and malware analysis
  • Automated detonation (sandbox)
  • Context for investigation

Need help choosing a Splunk security solution?

Let's talk about your project
Prototype v3 · Portfolio (EN)