Use cases in Splunk Enterprise Security Editions

Use cases available in the different Enterprise Security Editions.

Note: In the Controlled Availability release stage, Splunk products may have limitations on customer access, features, maturity and regional availability. For additional information on Controlled Availability please contact your Splunk representative.
Use caseEnterprise Security Essentials (General Availability)Enterprise Security Premier (Controlled Availability)
Security Monitoring

Get a unified view across all environments for clearer threat visibility and faster, data-driven response

Learn more

Threat detection

Tackle unknown and known threats with a range of detections (correlations, rule-based, AI/ML, and custom)​

Learn more

Threat investigation

Leverage the unified Mission Control interface to rapidly analyze, identify and investigate threats for an effective response​

Learn more

Accelerate investigation through automated playbooks Splunk Enterprise Security

Learn more

Threat hunting

Use findings and searches to identify malicious activity and mitigate attacks before they escalate​

Learn more

Enhance threat hunting by leveraging UEBA's ML-driven behavioral insights and accelerate evidence gathering and response with 1-click automated runbooks​

Learn more

Automation

Use one time Adaptive Response actions for basic orchestration or integrate with a SOAR product for full spectrum automation​

Accelerate response time, minimize human error, and ensure consistent enforcement of security policies

Learn more

Insider threat detection

Requires manual implementation or integration with a separate product​

Mitigate insider threat using OOTB, proven, and scalable ML behavioral detections, fully integrated in investigation workflows

Learn more