Just migrated our AWS security logging over to Splunk ES from a more generic SIEM. The out-of-the-box correlation searches for things like CloudTrail, GuardDuty, and VPC flow logs are a solid starting point. It definitely got us to meaningful alerts faster than building everything from scratch.
However, the cost can sneak up on you, especially when ingesting all those verbose cloud logs. We had to be pretty aggressive with event filtering and use a lot of summary indexing to keep things manageable. The other hiccup is that for some newer AWS services, the built-in data models and detections lag a bit. You end up writing custom correlation searches or using add-ons, which is fine if you're comfortable with SPL.
Overall, it's powerful if you're already invested in the Splunk ecosystem and need that tight integration between IT ops and security data. For a purely cloud-native team, the native tools combined with something like SOAR might be more cost-effective. Curious if others have hit similar scaling issues or found clever ways to optimize.