We performed a comparison between Elastic Search and Splunk Enterprise Security based on real PeerSpot user reviews.
Find out what your peers are saying about Elastic, IBM, Luigi's Box and others in Indexing and Search."Elastic Enterprise Search is scalable. On a scale of one to 10, with one being not scalable and 10 being very scalable, I give Elastic Enterprise Search a 10."
"The solution is quite scalable and this is one of its advantages."
"Gives us a more user-friendly, centralized solution (for those who just needed a quick glance, without being masters of sed and awk) as well as the ability to implement various mechanisms for machine-learning from our logs, and sending alerts for anomalies."
"It is highly valuable because of its simplicity in maintenance, where most tasks are handled for you, and it offers a plethora of built-in features."
"X-Pack provides good features, like authorization and alerts."
"The tool's stability and performance are good."
"You have dashboards, it is visual, there are maps, you can create canvases. It's more visual than anything that I've ever used."
"Dashboard is very customizable."
"It's basically one of the best SIEM products on the market."
"The completeness of the solution is what we like the most."
"The product provides visibility and enables us to correlate data and generate alerts."
"It can log more logs than other solutions. It's a good way to troubleshoot problems."
"Deployment server for deploying changes in one go."
"They are a good partner for Google Cloud. It provides great visibility, threat detection, and proactive mitigation of risks for our mutual consumers."
"It gives us good visibility into multiple environments, including cloud, on-premises, and hybrid; irrespective of platform."
"UBA, User Behavior Analytics, is a key feature."
"The different applications need to be individually deployed."
"They're making changes in their architecture too frequently."
"Elastic Enterprise Search's tech support is good but it could be improved."
"We have an issue with the volume of data that we can handle."
"The one area that can use improvement is the automapping of fields."
"Machine learning on search needs improvement."
"Enterprise scaling of what have been essentially separate, free open source software (FOSS) products has been a challenge, but the folks at Elastic have published new add-ons (X-Pack and ECE) to help large companies grow ELK to required scales."
"Both the graph feature and the reporting feature are a little bit lacking. The alerting also needs to be improved."
"The only thing which can be improved is that they are too subjective on whom their Splunk4Good initiative can be applied. They market it as you only need to be a nonprofit, but there is more to it."
"We had some connections issues with the solution at the beginning."
"I feel the solution to be too slow."
"The user experience could be improved."
"It does not give us permission to implement on-premise so we implement them on the cloud."
"Professional support is great, but too expensive."
"It requires a significant amount of relatively complex architecture once you push past the single server instance."
"The glass table feature does not perform as expected."
Elastic Search is ranked 1st in Indexing and Search with 59 reviews while Splunk Enterprise Security is ranked 1st in Security Information and Event Management (SIEM) with 251 reviews. Elastic Search is rated 8.2, while Splunk Enterprise Security is rated 8.4. The top reviewer of Elastic Search writes "Played a crucial role in enhancing our cybersecurity efforts ". On the other hand, the top reviewer of Splunk Enterprise Security writes "It has a drag-and-drop interface, so you don't need to know SQL or Java to construct a query ". Elastic Search is most compared with Faiss, Milvus, Pinecone, Azure Search and Amazon Kendra, whereas Splunk Enterprise Security is most compared with Wazuh, IBM Security QRadar, Dynatrace, Elastic Security and Microsoft Sentinel.
We monitor all Indexing and Search reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.
Generally Elastic is very strong in datasearch, and Splunk has a strong security solution. However Elastic has partnered with SIEM provider empow and together this integration provides a very strong platform both in datasearch and next generation SIEM.
Here's a thorough article on ELK vs. Splunk and here's a description from Elastic on what's included in the different versions.
Splunk: hard to use, expensive with predatory pricing, few OOTB rules, SOAR is a premium, good luck training analyst on their platform in under six months. SPLUNK SEARCH.
ELK Stack: easy to use, open-source, no predatory pricing, more robust use cases OOTB, loved and used by millions all over the globe, open ecosystem that can integrate with almost any major IT stack out of the box. LUCENE.
We use ELK or other freeware stacks in isolated small scenarios.
Think of a small or medium company with a „midsized“ webshop. You can easily do your Log management with an ELK-Stack, let's say size 5 up to 10 GB, no Problem. Please keep in mind to order Hardware. The best thing on ELK is that you can start immediately you don't have to wait for licensing and it's easy to build the first small things.
Another Example:
Your Marketing Dep. wants to do some singular evaluations and very specialized marketing stuff. It is temporary and they don't have the budget for licensing. The results are not for permanent use. Just use ELK.
In my opinion, ELK is only cost-effective if you don't need to buy their professional service. You must leave the cases small.
If you are looking for bigger scenarios or you want to build-up a SIEM, SOC or even doing elevated things like SOAR it is a very different kind of thing.
There can be account issues that a developer usually won't mind at the first glance but a Controller will.
You have to look at the Total Cost of Ownership, Scalability, Time to Market, Secureness of future development, maintenance e.g.
If you want to build up a complex scenario with the secureness of scalability you should go with SPLUNK. If tomorrow there is a better tool with lower costs and less need for input of manpower I will refer to this.