Elastic Search vs Splunk Enterprise Security comparison

Cancel
You must select at least 2 products to compare!
Elastic Logo
2,220 views|754 comparisons
98% willing to recommend
Splunk Logo
23,657 views|19,419 comparisons
92% willing to recommend
Comparison Buyer's Guide
Executive Summary

We performed a comparison between Elastic Search and Splunk Enterprise Security based on real PeerSpot user reviews.

Find out what your peers are saying about Elastic, IBM, Luigi's Box and others in Indexing and Search.
To learn more, read our detailed Indexing and Search Report (Updated: May 2024).
772,679 professionals have used our research since 2012.
Q&A Highlights
Question: What are the advantages of ELK over Splunk?
Answer: First of all, we need to understand what those two softwares are; Splunk is a finished SIEM that is mainly used to analyze data, such as logs, net flows, etc. Splunk comes in different flavors, below I will include a link of all the products they have. https://www.splunk.com/en_us/software.html Some of them can be even downloaded or you can try them in the cloud, below I will give you a link of Splunk enterprise, in the link you can see that you can download it, as a trial. https://www.splunk.com/en_us/software/splunk-enterprise/features.html ELK can be used for the requirements that you included, such as log analysis, the difference is that you will have to write the normalizers (this is a configuration file based on regex that reads the raw log and devices the log in small pieces), you will have to write the configuration file of the different widgets in the dashboard, alerts will have to be also written, etc. Elastic.co has already made an app that works as a SIEM, from all the products I think this will be the one that will make the most sense, as a log storage/analyzer, below is the link and you can try it as a cloud deployment. https://www.elastic.co/products/siem Also, this is a more complete list of all the features that are included in the enterprise version, here you can check them out and decide if this is something that will work for you. https://www.elastic.co/subscriptions Those two softwares are very good, but it will be better if you give them a try by yourself and try to compare them to see which one is the best for your network environment.
Featured Review
Quotes From Members
We asked business professionals to review the solutions they use.
Here are some excerpts of what they said:
Pros
"Elastic Enterprise Search is scalable. On a scale of one to 10, with one being not scalable and 10 being very scalable, I give Elastic Enterprise Search a 10.""The solution is quite scalable and this is one of its advantages.""Gives us a more user-friendly, centralized solution (for those who just needed a quick glance, without being masters of sed and awk) as well as the ability to implement various mechanisms for machine-learning from our logs, and sending alerts for anomalies.""It is highly valuable because of its simplicity in maintenance, where most tasks are handled for you, and it offers a plethora of built-in features.""X-Pack provides good features, like authorization and alerts.""The tool's stability and performance are good.""You have dashboards, it is visual, there are maps, you can create canvases. It's more visual than anything that I've ever used.""Dashboard is very customizable."

More Elastic Search Pros →

"It's basically one of the best SIEM products on the market.""The completeness of the solution is what we like the most.""The product provides visibility and enables us to correlate data and generate alerts.""It can log more logs than other solutions. It's a good way to troubleshoot problems.""Deployment server for deploying changes in one go.""They are a good partner for Google Cloud. It provides great visibility, threat detection, and proactive mitigation of risks for our mutual consumers.""It gives us good visibility into multiple environments, including cloud, on-premises, and hybrid; irrespective of platform.""UBA, User Behavior Analytics, is a key feature."

More Splunk Enterprise Security Pros →

Cons
"The different applications need to be individually deployed.""They're making changes in their architecture too frequently.""Elastic Enterprise Search's tech support is good but it could be improved.""We have an issue with the volume of data that we can handle.""The one area that can use improvement is the automapping of fields.""Machine learning on search needs improvement.""Enterprise scaling of what have been essentially separate, free open source software (FOSS) products has been a challenge, but the folks at Elastic have published new add-ons (X-Pack and ECE) to help large companies grow ELK to required scales.""Both the graph feature and the reporting feature are a little bit lacking. The alerting also needs to be improved."

More Elastic Search Cons →

"The only thing which can be improved is that they are too subjective on whom their Splunk4Good initiative can be applied. They market it as you only need to be a nonprofit, but there is more to it.""We had some connections issues with the solution at the beginning.""I feel the solution to be too slow.""The user experience could be improved.""It does not give us permission to implement on-premise so we implement them on the cloud.""Professional support is great, but too expensive.""It requires a significant amount of relatively complex architecture once you push past the single server instance.""The glass table feature does not perform as expected."

More Splunk Enterprise Security Cons →

Pricing and Cost Advice
  • "ELK has been considered as an alternative to Splunk to reduce licensing costs."
  • "An X-Pack license is more affordable than Splunk."
  • "​The pricing and license model are clear: node-based model."
  • "This is a free, open source software (FOSS) tool, which means no cost on the front-end. There are no free lunches in this world though. Technical skill to implement and support are costly on the back-end with ELK, whether you train/hire internally or go for premium services from Elastic."
  • "We are using the free version and intend to upgrade."
  • "It can be expensive."
  • "This product is open-source and can be used free of charge."
  • "We are using the open-sourced version."
  • More Elastic Search Pricing and Cost Advice →

  • "Pricing and licensing is quite expensive. But for the value the product provides, it seems at par in the market."
  • "Although Splunk is an expensive product, it is designed to be utilized across your organization in order to maximize your ROI and lower your TCO."
  • "It is not cheap."
  • "Splunk Enterprise becomes extremely expensive after the 20GB/month license."
  • "You will eat up whatever you purchase quickly. The level of insights that Splunk empowers is addictive."
  • "Splunk licensing model might seem expensive but with all the gain in functionalities you will have compared to traditional SIEM solutions I think it’s worth the price."
  • "Pricing is pretty fair."
  • "While licensing can be a concern, there are ways to reduce the licensing costs including filtering some events."
  • More Splunk Enterprise Security Pricing and Cost Advice →

    report
    Use our free recommendation engine to learn which Indexing and Search solutions are best for your needs.
    772,679 professionals have used our research since 2012.
    Comparison Review
    Vinod Shankar
    Answers from the Community
    Vivek Vijayan
    reviewer1182204 - PeerSpot reviewerreviewer1182204 (Director of Marketing, US)
    Vendor

    Generally Elastic is very strong in datasearch, and Splunk has a strong security solution. However Elastic has partnered with SIEM provider empow and together this integration provides a very strong platform both in datasearch and next generation SIEM.

    Here's a thorough article on ELK vs. Splunk and here's a description from Elastic on what's included in the different versions.

    Alex Boz - PeerSpot reviewerAlex Boz (Logrhythm)
    Vendor

    Splunk: hard to use, expensive with predatory pricing, few OOTB rules, SOAR is a premium, good luck training analyst on their platform in under six months. SPLUNK SEARCH.

    ELK Stack: easy to use, open-source, no predatory pricing, more robust use cases OOTB, loved and used by millions all over the globe, open ecosystem that can integrate with almost any major IT stack out of the box. LUCENE.

    Norman Freitag - PeerSpot reviewerNorman Freitag
    Real User

    We use ELK or other freeware stacks in isolated small scenarios.

    Think of a small or medium company with a „midsized“ webshop. You can easily do your Log management with an ELK-Stack, let's say size 5 up to 10 GB, no Problem. Please keep in mind to order Hardware. The best thing on ELK is that you can start immediately you don't have to wait for licensing and it's easy to build the first small things.

    Another Example:
    Your Marketing Dep. wants to do some singular evaluations and very specialized marketing stuff. It is temporary and they don't have the budget for licensing. The results are not for permanent use. Just use ELK.

    In my opinion, ELK is only cost-effective if you don't need to buy their professional service. You must leave the cases small.

    If you are looking for bigger scenarios or you want to build-up a SIEM, SOC or even doing elevated things like SOAR it is a very different kind of thing.
    There can be account issues that a developer usually won't mind at the first glance but a Controller will.
    You have to look at the Total Cost of Ownership, Scalability, Time to Market, Secureness of future development, maintenance e.g.

    If you want to build up a complex scenario with the secureness of scalability you should go with SPLUNK. If tomorrow there is a better tool with lower costs and less need for input of manpower I will refer to this.

    Questions from the Community
    Top Answer:Logsign provides us with the capability to execute multiple queries according to our requirements. The indexing is very high, making it effective for storing and retrieving logs. The real-time… more »
    Top Answer:I don't see improvements at the moment. The current setup is working well for me, and I'm satisfied with it. Integrating with different platforms is also fine, and I'm not recommending any changes or… more »
    Top Answer:For tools I’d recommend:  -SIEM- LogRhythm -SOAR- Palo Alto XSOAR Doing commercial w/o both (or at least an XDR) is asking to miss details that are critical, and ending up a statistic. Also,… more »
    Top Answer:It would really depend on (1) which logs you need to ingest and (2) what are your use cases Splunk is easy for ingestion of anything, but the charge per GB/Day Indexed and it gets expensive as log… more »
    Top Answer:Splunk handles a high amount of data very well. We use Splunk to capture information and as an aggregator for monitoring information from different sources. Splunk is very good at alerting us if we… more »
    Ranking
    1st
    out of 25 in Indexing and Search
    Views
    2,220
    Comparisons
    754
    Reviews
    27
    Average Words per Review
    507
    Rating
    8.3
    Views
    23,657
    Comparisons
    19,419
    Reviews
    85
    Average Words per Review
    894
    Rating
    8.4
    Comparisons
    Also Known As
    Elastic Enterprise Search, Swiftype, Elastic Cloud
    Learn More
    Overview

    Elasticsearch is a prominent open-source search and analytics engine known for its scalability, reliability, and straightforward management. It's a favored choice among enterprises for real-time data search, analysis, and visualization. Open-source Elasticsearch is free, offering a comprehensive feature set and scalability. It allows full control over deployments but requires managing and maintaining the infrastructure. On the other hand, Elastic Cloud provides a managed service with features like automated provisioning, high availability, security, and global reach.

    Elasticsearch excels in handling time-sensitive data and complex search requirements across large datasets. Its scalability allows it to handle growing data volumes efficiently, maintaining high performance and fast response times. Integrated with Kibana, Elasticsearch enables powerful data visualization, providing real-time insights crucial for data-driven decision-making.

    Elastic Cloud reduces operational overhead and improves scalability and performance, though it comes with associated costs. It is available on your preferred cloud provider — AWS, Azure, or Google Cloud. Customers who want to manage the software themselves, whether on public, private, or hybrid cloud, can download the Elastic Stack.

    At its core, Elasticsearch is renowned for its full-text search capabilities, capable of performing complex queries and supporting features like fuzzy matching and auto-complete.

    Peer reviews from various professionals highlight its strengths and weaknesses. Pros include its detection and correlation features, flexibility, cloud-readiness, extensibility, and efficient search capabilities. However, users have noted challenges like steep learning curves, data analysis limitations, and integration complexities. The platform is generally viewed as stable and scalable, with varying degrees of satisfaction regarding its usability and feature set.

    In summary, Elasticsearch stands out for its high-speed search, scalability, and versatile analytics, making it a go-to solution for organizations managing large datasets. Its adaptability to different enterprise needs, robust community support, and continuous development keep it at the forefront of enterprise search and analytics solutions. However, potential users should be aware of its learning curve and the need for skilled personnel for optimization.

    Splunk Enterprise Security is a SIEM, log management, and IT operations analytics tool. The solution provides users with the ability to secure their information and manage their data in the cloud, data centers, or other applications. Splunk Enterprise Security also offers visibility from different areas, levels, and devices, rather than from a single system, thus, providing its users with flexibility. Splunk Enterprise Security can monitor data and analyze, detect, and prevent intrusions. This benefits users as it provides alerts to possible intrusions, helps users to be proactive, and reduces risk factors. 

    Full visibility across your environment

    Break down data silos and gain actionable intelligence by ingesting data from multicloud and on-premises deployments. Get full visibility to quickly detect malicious threats in your environment.

    Fast threat detection

    Defend against threats with advanced security analytics, machine learning and threat intelligence that focus detection and provide high-fidelity alerts to shorten triage times and raise true positive rates.

    Efficient investigations

    Gather all the context you need and initiate flexible investigations with security analytics at your fingertips. The built-in open and extensible data platform boosts productivity and drives down fatigue.

    Open and scalable

    Built on an open and scalable data platform, you can stay agile in the face of evolving threats and business needs. Splunk meets you where you are on your cloud journey, and integrates across your data, tools and content.

    Sample Customers
    T-Mobile, Adobe, Booking.com, BMW, Telegraph Media Group, Cisco, Karbon, Deezer, NORBr, Labelbox, Fingerprint, Relativity, NHS Hospital, Met Office, Proximus, Go1, Mentat, Bluestone Analytics, Humanz, Hutch, Auchan, Sitecore, Linklaters, Socren, Infotrack, Pfizer, Engadget, Airbus, Grab, Vimeo, Ticketmaster, Asana, Twilio, Blizzard, Comcast, RWE and many others.
    Splunk has more than 7,000 customers spread across over 90 countries. These customers include Telenor, UniCredit, ideeli, McKenney's, Tesco, and SurveyMonkey.
    Top Industries
    REVIEWERS
    Financial Services Firm33%
    Computer Software Company27%
    Manufacturing Company10%
    Insurance Company7%
    VISITORS READING REVIEWS
    Computer Software Company18%
    Financial Services Firm15%
    Manufacturing Company8%
    Government8%
    REVIEWERS
    Computer Software Company19%
    Financial Services Firm14%
    Government9%
    Energy/Utilities Company8%
    VISITORS READING REVIEWS
    Financial Services Firm15%
    Computer Software Company14%
    Government9%
    Manufacturing Company8%
    Company Size
    REVIEWERS
    Small Business41%
    Midsize Enterprise11%
    Large Enterprise48%
    VISITORS READING REVIEWS
    Small Business24%
    Midsize Enterprise14%
    Large Enterprise62%
    REVIEWERS
    Small Business31%
    Midsize Enterprise12%
    Large Enterprise58%
    VISITORS READING REVIEWS
    Small Business19%
    Midsize Enterprise13%
    Large Enterprise68%
    Buyer's Guide
    Indexing and Search
    May 2024
    Find out what your peers are saying about Elastic, IBM, Luigi's Box and others in Indexing and Search. Updated: May 2024.
    772,679 professionals have used our research since 2012.

    Elastic Search is ranked 1st in Indexing and Search with 59 reviews while Splunk Enterprise Security is ranked 1st in Security Information and Event Management (SIEM) with 251 reviews. Elastic Search is rated 8.2, while Splunk Enterprise Security is rated 8.4. The top reviewer of Elastic Search writes "Played a crucial role in enhancing our cybersecurity efforts ". On the other hand, the top reviewer of Splunk Enterprise Security writes "It has a drag-and-drop interface, so you don't need to know SQL or Java to construct a query ". Elastic Search is most compared with Faiss, Milvus, Pinecone, Azure Search and Amazon Kendra, whereas Splunk Enterprise Security is most compared with Wazuh, IBM Security QRadar, Dynatrace, Elastic Security and Microsoft Sentinel.

    We monitor all Indexing and Search reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.