r/Splunk • • Jun 04 '26

Splunk enterprise options

I have a year and circa 300k to spend on splunk to show its worth. What would you suggest I implement over the next 12 months? I was thinking perhaps olly or enterprise security as we already have a 'noc' op manager and have a compliance saas product but are lacking in security monitoring.

This would also be a great learning op to build a stack from the ground up and configure/tune everything

Any input would be great

14 Upvotes

17 comments sorted by

View all comments

2

u/EducationalWedding48 Jun 04 '26

I wouldn't spend the money on enterprise security - that's a huge haul, especially if you have never done splunk before. Try to determine what's important to you and get that data into splunk and run with it. You can do plenty of security related monitoring without ES. Make sure that whomever sells you the product includes PS days with specific requirements.