Skip to content
Why Splunk

Why this platform, and not something else.

First, the question underneath. A platform choice has to hold up for years, so it does not start with a vendor but with whether it will still do the job in ten years. It helps when independent analysts point in the same direction as your own experience.

What those positions mean.

A Magic Quadrant scores vendors on two axes: how complete their vision is, and how well they deliver on it. Splunk sits in the top-right quadrant in both reports, and in SIEM highest of all vendors on Ability to Execute. That last part says something about what to expect in production, not just in the brochure.

Since the Cisco acquisition in 2024, Splunk sits inside a wider set of network, security and observability data. For existing customers little changes day to day; over the longer term it widens the data stream.

A sober note

An analyst report does not buy you a service. Splunk is powerful and therefore demanding: set up badly it becomes expensive and slow, set up well it answers your questions for years. The difference is in data modelling, retention, sizing and management, which is exactly where we sit.

Start with a health check →

Gartner, Magic Quadrant for Observability Platforms and Magic Quadrant for Security Information and Event Management, 2025. Gartner does not endorse any vendor, product or service. Positions cited are the most recent available at the time of publication.

What it is

The foundation, not the whole promise.

Splunk helps organisations collect, analyse and visualise machine data, logs, events and metrics centrally. What it delivers depends on how you set it up, run it and use it, and that is where our work sits.

What we do.

Implementation, management, lifecycle management, performance optimisation, data onboarding, dashboards, alerts, reporting and use case development. Where useful we connect Splunk to audit trail, compliance intelligence and managed service processes.

Applications
  • Security & compliance, investigate signals faster, make risk visible and substantiate audit questions.
  • Observability & IT operations, health, performance and availability across applications and infrastructure.
  • Business & data analytics, monitor operational processes and surface KPIs.
  • Audit trail & governance, reconstruct activity and make evidence available in a structured way.
Premium apps

The separate modules, and when you need them.

Splunk offers a number of modules on top of the platform. They are powerful, but they cost money and attention of their own. Here is what they do, and when, as far as we are concerned, you do not need them.

Splunk Enterprise SecuritySIEM

The SIEM layer on the platform: notable events, risk-based alerting, correlation rules and ready-made detection content. Where the base platform lets you search, ES brings order to what an analyst should look at, and in which sequence.

When it fits: you have a security team, or a party doing detection for you, and alerts need working every day. When it does not: what you mainly need is to demonstrate what happened. An audit trail on the base platform does that, for far less.

Splunk IT Service IntelligenceITSI

Looks at services rather than components. You define what a service consists of, ITSI calculates a health score across it and groups alerts that share a cause.

When it fits: you deliver services to others and need to say whether the service works, not whether the server is up. When it does not: you run a handful of systems. Dashboards on the base platform will take you a long way.

Splunk SOARAutomation

Turns incident handling into playbooks: enrich, weigh, block, raise a ticket. Connects to the rest of your tooling so an analyst does not have to walk through the steps by hand.

When it fits: the same kind of incident keeps returning and the handling is predictable. When it does not: your processes are not settled yet. Automating something that is not right yet just gets it wrong faster.

Splunk User Behavior AnalyticsUBA

Uses models to look for unusual behaviour by users and machines. The kind of signal no rule catches, because nobody thought of it in advance.

When it fits: your rule-based detection is solid and you are looking for what slips through it. When it does not: in most cases. UBA needs infrastructure of its own and a team able to judge the output; without that it mostly produces noise.

Premium apps are licensed separately, on top of your platform licence. We do not resell licences, so we have no interest in you buying more of them. A health check establishes what the base platform already gives you, and only then where a module genuinely adds something.

Our partner status

Splunk Elite Partner.

The highest tier in the Splunk Partnerverse. That status is not granted on revenue alone: Splunk tests for certified people, demonstrable customer outcomes and the authority to deliver, run and support in your own right.

What that gives you.

In practice: shorter lines into Splunk itself, early access to the roadmap and new releases, and escalation paths that go further than a regular support ticket. If an issue gets stuck in the product, we are not left empty-handed.

We are also licensed to supply licences, run migrations and deliver training. One party for licence, implementation, management and knowledge, and one point of contact when something does not run.

What it rests on
  • Certified specialists, architects, engineers, consultants and admins, with certification as a requirement rather than a bonus.
  • Thirteen years of Splunk, since 2013, and nothing else added in the meantime.
  • The full chain, advice, licences, implementation, migration, management, training.
  • Dutch customer base, government, healthcare, financial services, industry, logistics.

Get more out of Splunk by organising technology, data and service governance as one whole.

Start with a health check: five days, fixed price, and a report with findings and an order of priority.

Book a call