We performed a comparison between ArcSight Logger and Splunk Enterprise Security based on real PeerSpot user reviews.
Find out in this report how the two Log Management solutions compare in terms of features, pricing, service and support, easy of deployment, and ROI."The ESM use cases are the most valuable. It enables us to use the big data collection inside our company. We are able to create use cases for whatever it suits and I find that the most interesting part of any SIEM solution."
"ArcSight provides the basic information that we want."
"The log digestion features from threat intelligence platforms like Recorded Future or Talos are valuable."
"Some of the most valuable features I really appreciate are the performance, how quick the solution is, and how easy it is to create a query."
"It's a robust, mature product and you can do some really complex operations and analytics."
"I am impressed with the product's ability to pick up logs. It also has UEBA which has reduced the time to take charge of the events."
"The most valuable feature is the level of detail that you can see about certain events, even when they do not come up in the console."
"The solution provides information about the risk factors."
"The correlation searches (properly configured) populate the Incident Management dashboard and provide me a quick birds-eye view of my most important concerns."
"The most valuable features are how stable and easy to use Splunk is."
"Exporting is a good feature. It helps me out when I have to do reports. I do a lot of exporting and crunching of the numbers. Dashboards are okay for showing to the leadership, but for doing statistics and updating tickets, the export feature is very beneficial for me."
"Splunk has give us the capability to easily track problems and their status."
"Search language is easy to understand and teach to new users."
"The indexing and data collection are valuable."
"The dashboard and reporting are very good... It provides very good visibility in a hybrid cloud environment, and you can build custom utilization APIs using Splunk."
"Its huge, versatile AppBase helped me to configure and bring data from different sources to a unified platform."
"The next release should have AI capabilities."
"I had some latency issues for two months. I had to increase our storage capacity significantly to reduce the latency."
"Using the ArcSight Logger dashboard is not particularly intuitive or efficient, so it is important to be trained in its use."
"The solution should make it possible to integrate network analysis features."
"It would be better if the product is cheaper."
"The integration with other systems could be improved."
"The speed of Logger indexing and searching for certain bugs for some queries that we provide could be improved. It can handle a huge number of logs but it can be improved."
"ArcSight has been sold two or three times, and the quality has decreased."
"It does not give us permission to implement on-premise so we implement them on the cloud."
"Splunk is very expensive. The license is based on the volume of the logs ingested. I was responsible for managing the contract with our service integrator. I don't know the precise details of the competing solution, but I have heard that Splunk is more expensive than others. I don't know what the going rate is on the market, but I think there are at least two competitors that are less expensive. We have experienced a few issues with our service providers in terms of log filtering and ingestion, so we continue to pay a bit more per day for our logs."
"In terms of the interface, it could include some improvements for the look and feel."
"Being a SIEM solution with a centralized dashboard, we would like to have more options to customize it."
"The upgrading process could be smoother."
"An area of improvement would be the licensing of the solution. They need a free license, which would allow faster lead times."
"Features related to content management must be improved."
"The glass table feature does not perform as expected."
ArcSight Logger is ranked 28th in Log Management with 31 reviews while Splunk Enterprise Security is ranked 1st in Log Management with 240 reviews. ArcSight Logger is rated 7.8, while Splunk Enterprise Security is rated 8.4. The top reviewer of ArcSight Logger writes "A scalable and stable solution that enables users to see all the event logs in one place". On the other hand, the top reviewer of Splunk Enterprise Security writes "It has a drag-and-drop interface, so you don't need to know SQL or Java to construct a query ". ArcSight Logger is most compared with IBM Security QRadar, Elastic Security, Wazuh, LogRhythm SIEM and VMware Aria Operations for Logs, whereas Splunk Enterprise Security is most compared with Wazuh, Dynatrace, IBM Security QRadar, Elastic Security and Fortinet FortiAnalyzer. See our ArcSight Logger vs. Splunk Enterprise Security report.
See our list of best Log Management vendors.
We monitor all Log Management reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.