We performed a comparison between ArcSight Logger and Splunk Cloud Platform based on real PeerSpot user reviews.
Find out in this report how the two Log Management solutions compare in terms of features, pricing, service and support, easy of deployment, and ROI."It's a brilliant log collection tool, and it can handle hundreds of thousands of servers in a single shot to ingest the data."
"The ESM use cases are the most valuable. It enables us to use the big data collection inside our company. We are able to create use cases for whatever it suits and I find that the most interesting part of any SIEM solution."
"It provides in-depth information on business activities once we log into the system."
"The most valuable feature is the search capability, which is simple to use."
"The ability to customize the solution in great detail is its most valuable features. We can customize the use cases and also have the ability to do scripting. We can personalize our dashboard as well. The scalability the solution offers is quite impressive."
"The machine learning is a good feature."
"The most valuable feature is the level of detail that you can see about certain events, even when they do not come up in the console."
"The technical support team is good...It is a scalable solution."
"It has definitely improved our organization by virtue of reducing the amount of overhead we would have had for those environments. Having to implement, maintain, or even update the existing stuff would have been extremely time-consuming. Splunk Cloud handles all of that for us. So it's definitely been helpful from that perspective. It's allowed them to maintain upgrades for far further than they are. Some of the hosts of that environment were still on version 7 so they could get upgraded feature parity."
"Splunk Cloud Platform's search modes are a powerful feature."
"As compared to other tools, it is very easy. It is very easy to learn. It also integrates well."
"For my current requirements, the tool theme seems to be meeting my requirements, from a cost and requirements perspective."
"Index manager is most valuable because we do not have to bother about internal storage. It is all managed by the Splunk team."
"he cloud performance is good."
"I like the fact that we do not have to maintain all the cloud infrastructure. That is probably the main thing about the Splunk Cloud Platform."
"The data management and instant search features are the most valuable ones for us, as they allow us to instantly retrieve information needed for reports and security compliance."
"The platform is quite expensive. They should reduce its cost."
"We have had problems with archiving."
"The solution should make it possible to integrate network analysis features."
"It's not a new product and is a bit complex. So, it requires a person dedicated to working on it and to know about it in and out. It is a huge product, and the search operation is a bit complicated for a new user or someone who has not used it for long. So for that person, it becomes a bit difficult."
"The next release should have AI capabilities."
"You have limited reporting capabilities and I wouldn't choose ArcSight Logger for this purpose."
"I would like to see better scheduling in the next release of this solution."
"The console in older versions is not user-friendly."
"The Splunk interface is on-premises, so we have limited access to Splunk Cloud. Splunk support is not so good on Splunk Cloud. The Splunk side of the Splunk Cloud should also be more customizable. Integrating Splunk UBA, Splunk Phantom, and Splunk Cloud is also a bit difficult."
"Some of the implementation is challenging. They're not very proxy-aware."
"The training models can only be accessed for 30 days, even if it is paid training."
"When one of my customers needs an app, and I am able to find that app on the Splunk base, I have to create a ticket and wait for five days for them to download the app into the cloud environment. That is probably one of the main things. It is painful because I have to wait to get that app in the cloud."
"The security connection should have a seamless integration. Other than that, the way we are using it, so far, it seems quite good."
"The search for bulk data needs to be improved. When we were looking for the flow, we had to search really hard. I wanted to request the Splunk team to add some features for better search because getting the flow of the bulk data was sometimes hard."
"The only thing I would say is an issue is the cost. It matches other products. The costs can be justified for the value that we gain. The entire threat analysis stack should come in a bundle. If the cost was matchable with other products I think Splunk would pick up in the market."
"Support could be improved."
ArcSight Logger is ranked 29th in Log Management with 30 reviews while Splunk Cloud Platform is ranked 3rd in Data Visualization with 34 reviews. ArcSight Logger is rated 7.8, while Splunk Cloud Platform is rated 8.0. The top reviewer of ArcSight Logger writes "A scalable and stable solution that enables users to see all the event logs in one place". On the other hand, the top reviewer of Splunk Cloud Platform writes "Does not require backend maintenance, is easily integrated and utilized". ArcSight Logger is most compared with Splunk Enterprise Security, IBM Security QRadar, Elastic Security, Wazuh and LogRhythm SIEM, whereas Splunk Cloud Platform is most compared with Wazuh, Splunk Enterprise Security, Check Point Security Management, AppInsights and Fortinet FortiAnalyzer. See our ArcSight Logger vs. Splunk Cloud Platform report.
We monitor all Log Management reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.