AI Buyer Insights:

Moog, an UKG AutoTime customer evaluated Workday Time and Attendance

Citigroup, a VestmarkONE customer evaluated BlackRock Aladdin Wealth

Cantor Fitzgerald, a Kyriba Treasury customer evaluated GTreasury

Wayfair, a Korber HighJump WMS customer just evaluated Manhattan WMS

Westpac NZ, an Infosys Finacle customer evaluated nCino Bank OS

Swedbank, a Temenos T24 customer evaluated Oracle Flexcube

Michelin, an e2open customer evaluated Oracle Transportation Management

Moog, an UKG AutoTime customer evaluated Workday Time and Attendance

Citigroup, a VestmarkONE customer evaluated BlackRock Aladdin Wealth

Cantor Fitzgerald, a Kyriba Treasury customer evaluated GTreasury

Wayfair, a Korber HighJump WMS customer just evaluated Manhattan WMS

Westpac NZ, an Infosys Finacle customer evaluated nCino Bank OS

Swedbank, a Temenos T24 customer evaluated Oracle Flexcube

Michelin, an e2open customer evaluated Oracle Transportation Management

List of Splunk Enterprise Security Customers

loading spinner icon

Apply Filters For Customers

Logo Customer Industry Empl. Revenue Country Vendor Application Category When SI Insight
Ally Bank Banking and Financial Services 10000 $3.7B United States Splunk Splunk Enterprise Security Security Information and Event Management (SIEM) 2020 n/a
In 2020, Ally Bank implemented Splunk Enterprise Security to centralize security telemetry and analytics across its on-premises and AWS-cloud estates. Splunk Enterprise Security serves as the core Security Information and Event Management (SIEM) platform for Ally Bank security operations and threat detection, ingesting logs and supporting event search and lookup table workflows used by SOC analysts. The implementation focused on log onboarding, event correlation, incident search and investigation workflows, and dashboarding for operational visibility. Splunk Enterprise Security was configured to support real time response playbooks and orchestration patterns aligned with SOAR concepts, including integration with RTR scripts and incident enrichment sources to accelerate triage and forensic analysis. Integrations documented in the implementation include employee monitoring and forensics tools ObserveIT, Teramind, and Encase Investigator, endpoint telemetry from CrowdStrike, vulnerability data from Qualys, File Integrity Monitoring via OSSEC FIM, and Data Loss Prevention and classification tools such as Digital Guardian. The deployment also integrated certificate and key reporting from Venafi, credential vaulting workflows on Delinea, ITSM flow and onboarding via ServiceNow and Jira, and cross platform observability inputs from Nucleus and Dynatrace. AWS infrastructure components were explicitly used, including EC2 instances running monitoring services and Terraform for provisioning non production and production environments, with Splunk ingest pipelines consuming cloud-native logs and telemetry. Operational governance emphasized enterprise change control and documentation, using Confluence and formal CR processes for production changes, monthly and annual certification workflows, and CMDB driven reporting pulled via API and PowerShell. The security engineering team managed key operational tasks inside Splunk Enterprise Security such as log onboarding, search optimization, and integration maintenance while coordinating endpoint key rotation and API management for CrowdStrike and other clients. The implementation supported disaster recovery and continuity planning, and Ally Bank reported enhanced enterprise security posture through data classification and DLP integration as part of the overall SIEM program.
Boeing Aerospace and Defense 172000 $66.5B United States Splunk Splunk Enterprise Security Security Information and Event Management (SIEM) 2015 n/a
In 2015 Boeing deployed Splunk Enterprise Security as its Security Information and Event Management (SIEM) platform to centralize event monitoring and log aggregation across a mixed infrastructure. The initial implementation placed Splunk Enterprise Security on Linux and Windows servers to ingest telemetry from enterprise endpoints and infrastructure, with the St. Louis site cited as an operational location supporting continuous monitoring and reporting. The deployment included canonical SIEM capabilities such as event collection, indexed search, correlation, alerting, and dashboarding configured for aviation and defense security operations. Boeing personnel developed tooling to extend the platform, including a Python CVRF parser that automated importing Windows, Linux, and Cisco vulnerability definitions into Splunk and a GUI-based Python search utility to accelerate forensic searches, both integrated into the Splunk data pipeline and analyst workflows. Integrations and data sources were explicitly instrumented into Splunk Enterprise Security, including Windows, RHEL, HP-UX, Unix, Cisco network devices, and VMware ESXi hosts for log collection. The security stack operated alongside McAfee controls, with McAfee Data Loss Prevention, McAfee Disk Encryption, and VirusScan Enterprise managed as adjacent security capabilities, and vulnerability intelligence aligned to industry standards OWASP Top 10, CVE, CWE, and NVD for consistent categorization within the SIEM. Operational governance emphasized secure communication and pre-deployment assurance, enforcing SSL and TLS for web application stacks such as IIS, Apache, Tomcat, and WebSphere, and mandating that operating systems and applications be patched and scanned for vulnerabilities before being moved into closed government programs. Splunk Enterprise Security administration and ongoing support responsibilities were held by Boeing cybersecurity staff, who maintained log aggregation, event monitoring, and the ingest pipelines for vulnerability definitions and endpoint telemetry.
Carnival Corporation Leisure and Hospitality 115000 $25.0B United States Splunk Splunk Enterprise Security Security Information and Event Management (SIEM) 2023 n/a
In 2023, Carnival Corporation implemented Splunk Enterprise Security, a Security Information and Event Management (SIEM) application, to secure shipboard systems and customer data across its global fleet. The deployment supports operations across 90+ ships and nine cruise line brands, protecting guest and crew digital experiences for more than 300,000 people daily. Splunk Enterprise Security was configured to provide real-time visibility across applications, services, and security infrastructure, centralizing alerts and threat detection for maritime operations and shore-side systems. Functional capabilities in place include centralized event aggregation, prioritized alerting, and incident triage workflows that allow IT security and site reliability teams to assess severity and coordinate response. Operational coverage extends from customer-facing channels such as Carnival.com and the HubApp to shipboard operational systems, enabling the team to rapidly detect glitches that could affect booking, online check-in, shore excursions, restaurant reservations, or onboard services. The platform is actively used by IT security, threat intelligence, and site reliability engineering teams across Carnival Corporation and Carnival Cruise Line to maintain around-the-clock monitoring for safety and guest experience continuity. Governance and workflow restructuring focused on centralizing security event management, consolidating alerts into a single pane for escalation and remediation, and standardizing triage procedures across global teams. Rollout emphasized scale and flexibility to keep maritime operations available while addressing an evolving threat landscape. Outcomes explicitly reported by the company include a substantial reduction in mean time to respond, cited as up to 98 percent in some cases, and faster triage and remediation of customer experience issues before they impact guests. Splunk Enterprise Security is described as a core security and observability layer supporting Carnival Corporation's operational resilience and guest experience assurance.
Charter Communications Communications 91900 $54.8B United States Splunk Splunk Enterprise Security Security Information and Event Management (SIEM) 2018 n/a
In 2018, Charter Communications implemented Splunk Enterprise Security. Splunk Enterprise Security was deployed as the Security Information and Event Management (SIEM) core to centralize log aggregation, correlation, and security analytics across Charter network segments supporting Spectrum News operations and corporate cybersecurity directives. The implementation focused on standard SIEM modules such as real time event ingestion, correlation searches and notable event management, security posture dashboards, threat intelligence enrichment, and incident investigation workflows. Splunk Enterprise Security was configured to normalize logs from servers, virtualization infrastructure, and network devices, and to support playbook driven alerting and analyst triage within an operational security operations center style workflow. Integrations were explicitly aligned with existing security and IT management tooling, including ingestion of vulnerability data and scoring from Kenna Security reports and Qualys scans, endpoint telemetry and inventory from Tanium, and EDR alerts from CrowdStrike. Asset context and authoritative configuration data were referenced from the Cherwell CMDB, and infrastructure telemetry from VMware hosts and Cisco network devices was included to improve incident context and forensic timelines. Governance and operational rollout emphasized compliance with Charter network standards for Spectrum News outlets, targeted training to elevate local IT staff capabilities, and alignment with corporate cybersecurity directives. Local IT leadership used Splunk Enterprise Security outputs to refine incident escalation playbooks, drive remediation workflows with vulnerability and endpoint teams, and support certification activities across multiple news outlets. Documented outcomes tied to the deployment at the Spectrum News NY1 and regional outlets included accelerated vulnerability remediation workflows and improved security posture as measured by Kenna Security vulnerability reports, alongside operational changes such as decommissioning end of support Windows servers and elevating IT staff skills to handle advanced network and server administration tasks.
CNO Financial Group Insurance 3300 $4.5B United States Splunk Splunk Enterprise Security Security Information and Event Management (SIEM) 2018 n/a
In 2018, CNO Financial Group implemented Splunk Enterprise Security to centralize detection, investigation, and controls testing for Information Systems handling personally identifiable information, protected health information, and systems regulated under FISMA. Splunk Enterprise Security was deployed as the core Security Information and Event Management (SIEM) platform to capture security logs, highlight missing telemetry, and provide an analytics layer for security operations. Configuration and operationalization work included authoring Splunk searches and analytic rules to identify applications not forwarding logs, instrumenting searches for secure HTTP headers and session management artifacts, and collecting digital certificate metadata including hashing and asymmetric key details. The team used Splunk Enterprise Security to tag and categorize assets, and complemented SIEM telemetry with custom risk meter dashboards in Kenna Security to surface vulnerability information by hostname and IP address. The scope emphasized web applications in the PII and PHI footprint, and explicitly identified applications using SiteMinder SSO as candidates to be last migrated into an F5 cloud network environment for multi factor authentication. The implementation supported IAM and role mining efforts by combining access control lists with HR files to propose starting points for role definitions, and by documenting mappings between servers and applications to improve asset mapping. Governance practices included controls testing, SME interviews, and documenting remediation items discovered through Splunk searches, with remediation proposals submitted to the legal team for approval. The engagement delivered results on schedule, producing actionable analysis, documented mappings, and prioritized SIEM remediation items for security and IAM teams to execute.
Manufacturing 24000 $8.1B United States Splunk Splunk Enterprise Security Security Information and Event Management (SIEM) 2015 n/a
Banking and Financial Services 657 $120M United States Splunk Splunk Enterprise Security Security Information and Event Management (SIEM) 2020 n/a
Construction and Real Estate 1000 $200M Malaysia Splunk Splunk Enterprise Security Security Information and Event Management (SIEM) 2022 n/a
Professional Services 16000 $2.2B United States Splunk Splunk Enterprise Security Security Information and Event Management (SIEM) 2022 n/a
Government 6407 $3.7B United States Splunk Splunk Enterprise Security Security Information and Event Management (SIEM) 2022 n/a
Showing 1 to 10 of 14 entries

Buyer Intent: Companies Evaluating Splunk Enterprise Security

ARTW Buyer Intent uncovers actionable customer signals, identifying software buyers actively evaluating Splunk Enterprise Security. Gain ongoing access to real-time prospects and uncover hidden opportunities. Companies Actively Evaluating Splunk Enterprise Security for Security Information and Event Management (SIEM) include:

  1. Core Consulting, a Malaysia based Professional Services organization with 20 Employees

Discover Software Buyers actively Evaluating Enterprise Applications

Logo Company Industry Employees Revenue Country Evaluated
Core Consulting Professional Services 20 $2M Malaysia 2026-06-30
FAQ - APPS RUN THE WORLD Splunk Enterprise Security Coverage

Splunk Enterprise Security is a Security Information and Event Management (SIEM) solution from Splunk.

Companies worldwide use Splunk Enterprise Security, from small firms to large enterprises across 21+ industries.

Organizations such as Boeing, Charter Communications, Royal Bank of Canada, Carnival Corporation and Dover are recorded users of Splunk Enterprise Security for Security Information and Event Management (SIEM).

Companies using Splunk Enterprise Security are most concentrated in Aerospace and Defense, Communications and Banking and Financial Services, with adoption spanning over 21 industries.

Companies using Splunk Enterprise Security are most concentrated in United States and Canada, with adoption tracked across 195 countries worldwide. This global distribution highlights the popularity of Splunk Enterprise Security across Americas, EMEA, and APAC.

Companies using Splunk Enterprise Security range from small businesses with 0-100 employees - 0%, to mid-sized firms with 101-1,000 employees - 21.43%, large organizations with 1,001-10,000 employees - 35.71%, and global enterprises with 10,000+ employees - 42.86%.

Customers of Splunk Enterprise Security include firms across all revenue levels — from $0-100M, to $101M-$1B, $1B-$10B, and $10B+ global corporations.

Contact APPS RUN THE WORLD to access the full verified Splunk Enterprise Security customer database with detailed Firmographics such as industry, geography, revenue, and employee breakdowns as well as key decision makers in charge of Security Information and Event Management (SIEM).