Hi,
IMHO:
SIEM isn't a product you can simply implement.
SIEM is more of a status you or your company will reach when a lot of work is done beforehand.
A SIEM is made out of a lot of different use-cases/departments like Network Access Control (NAC), Network Operation Center (NOC), Security Operation Center (SOC) or CERT to name a few.
All those use-cases/departments can use and utilize Splunk of course. But getting to that point are years and years of work.
You can ofc try to only use Splunk Enterprise for all the use-cases I named above. But ES gives you very cool dashboards, a workflow tool and a lot of logic and correalation searches for data insights
You should also read about making your data C.I.M. compliant.
... View more