Skip to main content


Security

Splunk Enterprise Security

Access data-driven insights, combat threats, protect your business and mitigate risk at scale with analytics you can act on.

im im

HOW IT WORKS

Data-driven insights for full-breadth visibility and rapid detection

executive-summary-pt1 executive-summary-pt1

Full visibility across your environment

Break down data silos and gain actionable intelligence by ingesting data from multicloud and on-premises deployments. Get full visibility to quickly detect malicious threats in your environment.

Fast threat detection

Defend against threats with advanced security analytics, machine learning and threat intelligence that focus detection and provide high-fidelity alerts to shorten triage times and raise true positive rates.

identity-investigator-swimlane-es identity-investigator-swimlane-es
investigative-tools-dashboard-featured investigative-tools-dashboard-featured

Efficient investigations

Gather all the context you need and initiate flexible investigations with security analytics at your fingertips. The built-in open and extensible data platform boosts productivity and drives down fatigue.

risk-analysis-es risk-analysis-es

Open and scalable

Built on an open and scalable data platform, you can stay agile in the face of evolving threats and business needs. Splunk meets you where you are on your cloud journey, and integrates across your data, tools and content.

Features

Analytics at your fingertips

Monitor, detect and investigate threats with speed and accuracy — all at scale.

Open, extensible data platform Open, extensible data platform

Open, extensible data platform

Ingest and monitor tens of terabytes of data per day from any source — structured or unstructured — for full visibility.

Risk-based alerting Risk-based alerting

Risk-based alerting

Attribute risk to users and systems, map alerts to cybersecurity frameworks, and trigger alerts when risk exceeds thresholds to conquer alert fatigue.

Advanced threat detection Advanced threat detection

Advanced threat detection

Detect advanced threats with machine learning and 700+ out-of-the-box detections for frameworks such as MITRE ATT&CK, NIST, CIS 20 and Kill Chain.

Embedded threat intelligence Embedded threat intelligence

Embedded threat intelligence

Prioritize alerts and accelerate investigations with built-in threat intelligence from Splunk Intelligence Management integration.

Rapid response security content Rapid response security content

Rapid response security content

Get automatic security content updates delivered directly from the Splunk Threat Research Team to help you stay on top of new and emerging threats.

Flexible deployment options Flexible deployment options

Flexible deployment options

Deploy Splunk Enterprise Security in the way that best meets the needs of your organization — cloud, on-premises or hybrid.

norlys background norlys background

CUSTOMER STORY

Norlys Accelerates Incident Response to Save 35 Hours Every Week

I just enter the hostname for a single machine, and I can see all of the endpoint response logs. ES lets you see everything going on in your environment to find the bad guys.

Tibor Földesi, Security Automation Analyst, Norlys
35 hrs
of work saved per week
30 sec
to complete processes that once took 30 minutes

INTEGRATIONS

Deepen security context with robust integrations

integrations integrations

Related products

Splunk SOAR Splunk SOAR

Splunk SOAR

Supercharge your security operations center with orchestration, automation and response.

Learn More
Splunk Intelligence Management Splunk Intelligence Management

Splunk Intelligence Management

Maximized performance with visibility everywhere.

Learn More
Splunk User Behavior Analytics Splunk User Behavior Analytics

Splunk User Behavior Analytics

Machine-learning driven analytics to identify threats.

Learn More
Splunk Security Essentials Splunk Security Essentials

Splunk Security Essentials

Pre-built detections and data recommendations to extend your Splunk solutions.

Learn More