List of Splunk Enterprise Security Customers
San Francisco, 94107, CA,
United States
Since 2010, our global team of researchers has been studying Splunk Enterprise Security customers around the world, aggregating massive amounts of data points that form the basis of our forecast assumptions and perhaps the rise and fall of certain vendors and their products on a quarterly basis.
Each quarter our research team identifies companies that have purchased Splunk Enterprise Security for Security Information and Event Management (SIEM) from public (Press Releases, Customer References, Testimonials, Case Studies and Success Stories) and proprietary sources, including the customer size, industry, location, implementation status, partner involvement, LOB Key Stakeholders and related IT decision-makers contact details.
Companies using Splunk Enterprise Security for Security Information and Event Management (SIEM) include: Boeing, a United States based Aerospace and Defense organisation with 172000 employees and revenues of $66.52 billion, Charter Communications, a United States based Communications organisation with 91900 employees and revenues of $54.80 billion, Royal Bank of Canada, a Canada based Banking and Financial Services organisation with 96628 employees and revenues of $48.64 billion, Carnival Corporation, a United States based Leisure and Hospitality organisation with 115000 employees and revenues of $25.02 billion, Dover, a United States based Manufacturing organisation with 24000 employees and revenues of $8.09 billion and many others.
Contact us if you need a completed and verified list of companies using Splunk Enterprise Security, including the breakdown by industry (21 Verticals), Geography (Region, Country, State, City), Company Size (Revenue, Employees, Asset) and related IT Decision Makers, Key Stakeholders, business and technology executives responsible for the software purchases.
The Splunk Enterprise Security customer wins are being incorporated in our Enterprise Applications Buyer Insight and Technographics Customer Database which has over 100 data fields that detail company usage of software systems and their digital transformation initiatives. Apps Run The World wants to become your No. 1 technographic data source!
Apply Filters For Customers
| Logo | Customer | Industry | Empl. | Revenue | Country | Vendor | Application | Category | When | SI | Insight |
|---|---|---|---|---|---|---|---|---|---|---|---|
|
|
Ally Bank | Banking and Financial Services | 10000 | $3.7B | United States | Splunk | Splunk Enterprise Security | Security Information and Event Management (SIEM) | 2020 | n/a |
In 2020, Ally Bank implemented Splunk Enterprise Security to centralize security telemetry and analytics across its on-premises and AWS-cloud estates. Splunk Enterprise Security serves as the core Security Information and Event Management (SIEM) platform for Ally Bank security operations and threat detection, ingesting logs and supporting event search and lookup table workflows used by SOC analysts.
The implementation focused on log onboarding, event correlation, incident search and investigation workflows, and dashboarding for operational visibility. Splunk Enterprise Security was configured to support real time response playbooks and orchestration patterns aligned with SOAR concepts, including integration with RTR scripts and incident enrichment sources to accelerate triage and forensic analysis.
Integrations documented in the implementation include employee monitoring and forensics tools ObserveIT, Teramind, and Encase Investigator, endpoint telemetry from CrowdStrike, vulnerability data from Qualys, File Integrity Monitoring via OSSEC FIM, and Data Loss Prevention and classification tools such as Digital Guardian. The deployment also integrated certificate and key reporting from Venafi, credential vaulting workflows on Delinea, ITSM flow and onboarding via ServiceNow and Jira, and cross platform observability inputs from Nucleus and Dynatrace. AWS infrastructure components were explicitly used, including EC2 instances running monitoring services and Terraform for provisioning non production and production environments, with Splunk ingest pipelines consuming cloud-native logs and telemetry.
Operational governance emphasized enterprise change control and documentation, using Confluence and formal CR processes for production changes, monthly and annual certification workflows, and CMDB driven reporting pulled via API and PowerShell. The security engineering team managed key operational tasks inside Splunk Enterprise Security such as log onboarding, search optimization, and integration maintenance while coordinating endpoint key rotation and API management for CrowdStrike and other clients. The implementation supported disaster recovery and continuity planning, and Ally Bank reported enhanced enterprise security posture through data classification and DLP integration as part of the overall SIEM program.
|
|
|
Boeing | Aerospace and Defense | 172000 | $66.5B | United States | Splunk | Splunk Enterprise Security | Security Information and Event Management (SIEM) | 2015 | n/a |
In 2015 Boeing deployed Splunk Enterprise Security as its Security Information and Event Management (SIEM) platform to centralize event monitoring and log aggregation across a mixed infrastructure. The initial implementation placed Splunk Enterprise Security on Linux and Windows servers to ingest telemetry from enterprise endpoints and infrastructure, with the St. Louis site cited as an operational location supporting continuous monitoring and reporting.
The deployment included canonical SIEM capabilities such as event collection, indexed search, correlation, alerting, and dashboarding configured for aviation and defense security operations. Boeing personnel developed tooling to extend the platform, including a Python CVRF parser that automated importing Windows, Linux, and Cisco vulnerability definitions into Splunk and a GUI-based Python search utility to accelerate forensic searches, both integrated into the Splunk data pipeline and analyst workflows.
Integrations and data sources were explicitly instrumented into Splunk Enterprise Security, including Windows, RHEL, HP-UX, Unix, Cisco network devices, and VMware ESXi hosts for log collection. The security stack operated alongside McAfee controls, with McAfee Data Loss Prevention, McAfee Disk Encryption, and VirusScan Enterprise managed as adjacent security capabilities, and vulnerability intelligence aligned to industry standards OWASP Top 10, CVE, CWE, and NVD for consistent categorization within the SIEM.
Operational governance emphasized secure communication and pre-deployment assurance, enforcing SSL and TLS for web application stacks such as IIS, Apache, Tomcat, and WebSphere, and mandating that operating systems and applications be patched and scanned for vulnerabilities before being moved into closed government programs. Splunk Enterprise Security administration and ongoing support responsibilities were held by Boeing cybersecurity staff, who maintained log aggregation, event monitoring, and the ingest pipelines for vulnerability definitions and endpoint telemetry.
|
|
|
Carnival Corporation | Leisure and Hospitality | 115000 | $25.0B | United States | Splunk | Splunk Enterprise Security | Security Information and Event Management (SIEM) | 2023 | n/a |
In 2023, Carnival Corporation implemented Splunk Enterprise Security, a Security Information and Event Management (SIEM) application, to secure shipboard systems and customer data across its global fleet. The deployment supports operations across 90+ ships and nine cruise line brands, protecting guest and crew digital experiences for more than 300,000 people daily.
Splunk Enterprise Security was configured to provide real-time visibility across applications, services, and security infrastructure, centralizing alerts and threat detection for maritime operations and shore-side systems. Functional capabilities in place include centralized event aggregation, prioritized alerting, and incident triage workflows that allow IT security and site reliability teams to assess severity and coordinate response.
Operational coverage extends from customer-facing channels such as Carnival.com and the HubApp to shipboard operational systems, enabling the team to rapidly detect glitches that could affect booking, online check-in, shore excursions, restaurant reservations, or onboard services. The platform is actively used by IT security, threat intelligence, and site reliability engineering teams across Carnival Corporation and Carnival Cruise Line to maintain around-the-clock monitoring for safety and guest experience continuity.
Governance and workflow restructuring focused on centralizing security event management, consolidating alerts into a single pane for escalation and remediation, and standardizing triage procedures across global teams. Rollout emphasized scale and flexibility to keep maritime operations available while addressing an evolving threat landscape.
Outcomes explicitly reported by the company include a substantial reduction in mean time to respond, cited as up to 98 percent in some cases, and faster triage and remediation of customer experience issues before they impact guests. Splunk Enterprise Security is described as a core security and observability layer supporting Carnival Corporation's operational resilience and guest experience assurance.
|
|
|
Charter Communications | Communications | 91900 | $54.8B | United States | Splunk | Splunk Enterprise Security | Security Information and Event Management (SIEM) | 2018 | n/a |
In 2018, Charter Communications implemented Splunk Enterprise Security. Splunk Enterprise Security was deployed as the Security Information and Event Management (SIEM) core to centralize log aggregation, correlation, and security analytics across Charter network segments supporting Spectrum News operations and corporate cybersecurity directives.
The implementation focused on standard SIEM modules such as real time event ingestion, correlation searches and notable event management, security posture dashboards, threat intelligence enrichment, and incident investigation workflows. Splunk Enterprise Security was configured to normalize logs from servers, virtualization infrastructure, and network devices, and to support playbook driven alerting and analyst triage within an operational security operations center style workflow.
Integrations were explicitly aligned with existing security and IT management tooling, including ingestion of vulnerability data and scoring from Kenna Security reports and Qualys scans, endpoint telemetry and inventory from Tanium, and EDR alerts from CrowdStrike. Asset context and authoritative configuration data were referenced from the Cherwell CMDB, and infrastructure telemetry from VMware hosts and Cisco network devices was included to improve incident context and forensic timelines.
Governance and operational rollout emphasized compliance with Charter network standards for Spectrum News outlets, targeted training to elevate local IT staff capabilities, and alignment with corporate cybersecurity directives. Local IT leadership used Splunk Enterprise Security outputs to refine incident escalation playbooks, drive remediation workflows with vulnerability and endpoint teams, and support certification activities across multiple news outlets.
Documented outcomes tied to the deployment at the Spectrum News NY1 and regional outlets included accelerated vulnerability remediation workflows and improved security posture as measured by Kenna Security vulnerability reports, alongside operational changes such as decommissioning end of support Windows servers and elevating IT staff skills to handle advanced network and server administration tasks.
|
|
|
CNO Financial Group | Insurance | 3300 | $4.5B | United States | Splunk | Splunk Enterprise Security | Security Information and Event Management (SIEM) | 2018 | n/a |
In 2018, CNO Financial Group implemented Splunk Enterprise Security to centralize detection, investigation, and controls testing for Information Systems handling personally identifiable information, protected health information, and systems regulated under FISMA. Splunk Enterprise Security was deployed as the core Security Information and Event Management (SIEM) platform to capture security logs, highlight missing telemetry, and provide an analytics layer for security operations.
Configuration and operationalization work included authoring Splunk searches and analytic rules to identify applications not forwarding logs, instrumenting searches for secure HTTP headers and session management artifacts, and collecting digital certificate metadata including hashing and asymmetric key details. The team used Splunk Enterprise Security to tag and categorize assets, and complemented SIEM telemetry with custom risk meter dashboards in Kenna Security to surface vulnerability information by hostname and IP address.
The scope emphasized web applications in the PII and PHI footprint, and explicitly identified applications using SiteMinder SSO as candidates to be last migrated into an F5 cloud network environment for multi factor authentication. The implementation supported IAM and role mining efforts by combining access control lists with HR files to propose starting points for role definitions, and by documenting mappings between servers and applications to improve asset mapping.
Governance practices included controls testing, SME interviews, and documenting remediation items discovered through Splunk searches, with remediation proposals submitted to the legal team for approval. The engagement delivered results on schedule, producing actionable analysis, documented mappings, and prioritized SIEM remediation items for security and IAM teams to execute.
|
|
|
|
Manufacturing | 24000 | $8.1B | United States | Splunk | Splunk Enterprise Security | Security Information and Event Management (SIEM) | 2015 | n/a |
|
|
|
|
Banking and Financial Services | 657 | $120M | United States | Splunk | Splunk Enterprise Security | Security Information and Event Management (SIEM) | 2020 | n/a |
|
|
|
|
Construction and Real Estate | 1000 | $200M | Malaysia | Splunk | Splunk Enterprise Security | Security Information and Event Management (SIEM) | 2022 | n/a |
|
|
|
|
Professional Services | 16000 | $2.2B | United States | Splunk | Splunk Enterprise Security | Security Information and Event Management (SIEM) | 2022 | n/a |
|
|
|
|
Government | 6407 | $3.7B | United States | Splunk | Splunk Enterprise Security | Security Information and Event Management (SIEM) | 2022 | n/a |
|
Buyer Intent: Companies Evaluating Splunk Enterprise Security
- Core Consulting, a Malaysia based Professional Services organization with 20 Employees
Discover Software Buyers actively Evaluating Enterprise Applications
| Logo | Company | Industry | Employees | Revenue | Country | Evaluated |
|---|---|---|---|---|---|---|
| Core Consulting | Professional Services | 20 | $2M | Malaysia | 2026-06-30 |