Security: Enterprise Security Essentials and Enterprise Security Premier

Community Office Hours

Security: Enterprise Security Essentials and Enterprise Security Premier

1 Comment
Cover Images - Office Hours (27).png
Published on ‎02-23-2026 09:26 AM by Splunk Employee | Updated on ‎03-23-2026 02:27 PM

[Register Here]  This thread is for the Community Office Hours session on  Security: Enterprise Security Essentials and Enterprise Security Premier on Wednesday, March 18, 2026 at 11 am PT / 2 pm ET

 

Ask the experts at Community Office Hours! An ongoing series where technical Splunk experts answer questions and provide how-to guidance on various Splunk product and use case topics.

 

What can I ask in this AMA?

  • What is available in Splunk Enterprise Security (ES) Premier that is not available in Splunk Enterprise Security (ES) Essentials?
  • What makes ES Essentials better than ES 7.X?
  • What new or improved use cases should I expect ES Premier to help me deliver?
  • What should I consider or prepare if I’m currently using ES Essentials and planning to migrate to ES Premier?
  • What will happen to my dashboards, configurations, and investigations if I upgrade from ES Essentials to ES Premier?
  • What sort of education or professional services are available for me to build an expert practice in ES Essentials or ES Premier?
  • What does the SOAR integration look like for ES Essentials and ES Premier?
  • How does UEBA integrate with ES Premier?
  • Anything else you’d like to learn!

 

Please submit your questions at registration. You can also head to the #office-hours user Slack channel to ask questions (sign in with SSO here). 

 

Pre-submitted questions will be prioritized. After that, we will open the floor up to live Q&A with meeting participants.

 

Look forward to connecting!



Labels (3)
0 Karma
loriexi
Splunk Employee

Hi everyone! Here are a few questions from the session (get the full Q&A deck and live recording in the #office-hours Slack channel) 

 

Q1: What is the major difference between ES Essentials and ES Premier?

A:  Screenshot 2026-03-19 at 14.27.13.png

 

Q2:  At the time of installing and configuring both versions, are there any differences?

A:  This is somewhat of a nuanced answer. TL;DR: No.

That said, since ES Premier enables unlimited SOAR seats and UEBA functionality, there are configuration considerations that apply to those products and features.

  • For example, with SOAR, you'll want to link the SOAR instance to ES in the ES configuration settings.
  • For UEBA, since UEBA is an integrated feature of ES, there are no special installation considerations, beyond ensuring you've onboarded the data that UEBA feeds on, and the usual ES frameworks like Assets and Identities are populating.
  • That said, there are different considerations for Customer Managed Platform(CMP), aka on-prem deployments of UEBA. For example, you can download and install the UEBA Content App to extend the functions of UEBA and access more behavior-based detections.

 

Q3:  We just purchased ES Essentials. What should we consider when deciding whether to upgrade to Premier? How can we maximize the value of our investment?

A:  Either Edition of Splunk Enterprise Security is a phenomenal investment.

Considerations for Premier include Insider Risk Use Cases (UEBA) and the force multiplication that unlimited SOAR seats brings to your ability to automate your security, AND IT operations.

In addition, while forward-looking statements apply here, what we want is for Premier customers to have a "seat at the table" for all the amazing innovation we have planned for the future.

More news on that front will be coming shortly, maybe as soon as at RSAC. 😉