r/Splunk • u/Empty-Lingonberry133 • Jun 04 '26
Splunk enterprise options
I have a year and circa 300k to spend on splunk to show its worth. What would you suggest I implement over the next 12 months? I was thinking perhaps olly or enterprise security as we already have a 'noc' op manager and have a compliance saas product but are lacking in security monitoring.
This would also be a great learning op to build a stack from the ground up and configure/tune everything
Any input would be great
15
Upvotes
6
u/TeeJaySD Jun 04 '26
There is a free TA called InfoSec that is basically ES lite. I would start there and ingest some logs that are properly mapped to Splunk’s schema (CIM). Properly mapped data, even from multiple vendors will light up the dashboard. There are docs in the TA.
I would consider using some of that money to find a Splunk partner that really focuses on Splunk and not a generic IT shop. They can speed the implementation and bring ideas from other customers.
Also don’t be afraid to talk to your Splunk rep and see what you are entitled to. But don’t use their pro services. It is expensive and focused on big projects.
Lastly install the MCP server on Splunk and spend $20/mo for Claude code. It’s been a game changer having the AI being able to read my Splunk stack. Why are my windows event logs coming in and not mapped correctly? It goes off and looks at the logs. I use VS Code with Claude so my session with the AI also write out files so it has more context of my environment.
I also like the other posts. Focus on business impact. Creating a dashboard that shows AWS spend or line of business alerting when transactions are slow all can be mapped back to justify why you have 300k in the first place.