Hello Splunk Community,
I’m working on a project to implement a Security Information and Event Management (SIEM) solution for a small-to-medium-sized enterprise that provides IT support and managed services. We're exploring options within the Splunk product line for effective log collection and analysis from endpoint devices, as well as vulnerability detection. Could you recommend the most suitable Splunk product(s) for this scope, along with pricing information or guidance on how to estimate the costs? Any advice on best practices or additional tools to enhance incident response would also be greatly appreciated. Thank you!
That is something you need to work with your local Splunk Partner on.
Firstly, noone will just pull a quote out of the hat without even knowing your requirements. Secondly, a good Partner will sit with you and discuss your requirements to try and find a good solution for you because your stated "requirements" are so broadly (un)defined (and there are many aspects not covered) that the answer could actually be anything from a single-server bare Splunk Enterprise installation to a fully blown multisite cluster with ES, ITSI and some additional stuff. Or maybe a Cloud instance... That's all that needs to be discussed in depth and an online forum with volunteers is not something to base your business decisions on.