Elastic Search vs Splunk Enterprise Security comparison

Cancel
You must select at least 2 products to compare!
Elastic Logo
2,215 views|742 comparisons
98% willing to recommend
Splunk Logo
24,689 views|20,244 comparisons
92% willing to recommend
Comparison Buyer's Guide
Executive Summary

We performed a comparison between Elastic Search and Splunk Enterprise Security based on real PeerSpot user reviews.

Find out what your peers are saying about Elastic, IBM, OpenText and others in Indexing and Search.
To learn more, read our detailed Indexing and Search Report (Updated: May 2024).
771,157 professionals have used our research since 2012.
Q&A Highlights
Question: What are the advantages of ELK over Splunk?
Answer: First of all, we need to understand what those two softwares are; Splunk is a finished SIEM that is mainly used to analyze data, such as logs, net flows, etc. Splunk comes in different flavors, below I will include a link of all the products they have. https://www.splunk.com/en_us/software.html Some of them can be even downloaded or you can try them in the cloud, below I will give you a link of Splunk enterprise, in the link you can see that you can download it, as a trial. https://www.splunk.com/en_us/software/splunk-enterprise/features.html ELK can be used for the requirements that you included, such as log analysis, the difference is that you will have to write the normalizers (this is a configuration file based on regex that reads the raw log and devices the log in small pieces), you will have to write the configuration file of the different widgets in the dashboard, alerts will have to be also written, etc. Elastic.co has already made an app that works as a SIEM, from all the products I think this will be the one that will make the most sense, as a log storage/analyzer, below is the link and you can try it as a cloud deployment. https://www.elastic.co/products/siem Also, this is a more complete list of all the features that are included in the enterprise version, here you can check them out and decide if this is something that will work for you. https://www.elastic.co/subscriptions Those two softwares are very good, but it will be better if you give them a try by yourself and try to compare them to see which one is the best for your network environment.
Featured Review
Quotes From Members
We asked business professionals to review the solutions they use.
Here are some excerpts of what they said:
Pros
"The most valuable feature of Elastic Enterprise Search is the opportunity to search behind and between different logs.""Gives us a more user-friendly, centralized solution (for those who just needed a quick glance, without being masters of sed and awk) as well as the ability to implement various mechanisms for machine-learning from our logs, and sending alerts for anomalies.""It is stable.""The tool's stability and performance are good.""The solution is valuable for log analytics.""The most valuable features of Elastic Enterprise Search are it's cloud-ready and we do a lot of infrastructure as code. By using ELK, we're able to deploy the solution as part of our ISC deployment.""The solution has great scalability.""Search is really powerful."

More Elastic Search Pros →

"The flexibility of the solution is quite good.""Splunk Enterprise Security helped us with faster detection of threats.""The SIEM is the most valuable feature of the product.""It has quite extensive support in terms of integration. If you want to do anything, there are tools for that.""Splunk setup is easy and straightforward. ​""Internal tracking is helpful because we do not like to deal with multiple ticketing systems, and I am not a fan of ServiceNow. We are able to keep everything internal and utilize Enterprise Security.""Splunk has significantly reduced the time in performing the task of aggregating logs, reviewing as well as time spent during investigations.""We have found all the features useful. However, the dashboarding and logging have been very helpful. Additionally, the log analysis does a great job."

More Splunk Enterprise Security Pros →

Cons
"It needs email notification, similar to what Logentries has. Because of the notification issue, we moved to Logentries, as it provides a simple way to receive notification whenever a server encounters an error or unexpected conditions (which we have defined using RegEx​).""Elastic Search needs to improve authentication. It also needs to work on the Kibana visualization dashboard.""Technical support should be faster.""It was not possible to use authentication three years back. You needed to buy the product's services for authentication.""Elastic Enterprise Search can improve by adding some kind of search that can be used out of the box without too much struggle with configuration. With every kind of search engine, there is some kind of special function that you need to do. A simple out-of-the-box search would be useful.""There is another solution I'm testing which has a 500 record limit when you do a search on Elastic Enterprise Search. That's the only area in which I'm not sure whether it's a limitation on our end in terms of knowledge or a technical limitation from Elastic Enterprise Search. There is another solution we are looking at that rides on Elastic Enterprise Search. And the limit is for any sort of records that you're doing or data analysis you're trying to do, you can only extract 500 records at a time. I know the open-source nature has a lot of limitations, Otherwise, Elastic Enterprise Search is a fantastic solution and I'd recommend it to anyone.""Better dashboards or a better configuration system would be very good.""I don't see improvements at the moment. The current setup is working well for me, and I'm satisfied with it. Integrating with different platforms is also fine, and I'm not recommending any changes or enhancements right now."

More Elastic Search Cons →

"The UI can be difficult to understand for non-technical people.""Splunk could be improved by reducing the cost. The cost is one of the biggest challenges for us in keeping to our production requirements.""It's costly.""Missing capability for audio/video and image processing.""The GUI can be improved to include some of the capabilities that other BI solutions have.""Although the technical support is adequate, there is still room for improvement.""This solution could be improved by better pricing in general and by easier installation.""I would like additional features in different programming models with the support for writing queries in SQL or other languages, such as C#, Java, or some other type of query definitions."

More Splunk Enterprise Security Cons →

Pricing and Cost Advice
  • "ELK has been considered as an alternative to Splunk to reduce licensing costs."
  • "An X-Pack license is more affordable than Splunk."
  • "​The pricing and license model are clear: node-based model."
  • "This is a free, open source software (FOSS) tool, which means no cost on the front-end. There are no free lunches in this world though. Technical skill to implement and support are costly on the back-end with ELK, whether you train/hire internally or go for premium services from Elastic."
  • "We are using the free version and intend to upgrade."
  • "It can be expensive."
  • "This product is open-source and can be used free of charge."
  • "We are using the open-sourced version."
  • More Elastic Search Pricing and Cost Advice →

  • "Pricing and licensing is quite expensive. But for the value the product provides, it seems at par in the market."
  • "Although Splunk is an expensive product, it is designed to be utilized across your organization in order to maximize your ROI and lower your TCO."
  • "It is not cheap."
  • "Splunk Enterprise becomes extremely expensive after the 20GB/month license."
  • "You will eat up whatever you purchase quickly. The level of insights that Splunk empowers is addictive."
  • "Splunk licensing model might seem expensive but with all the gain in functionalities you will have compared to traditional SIEM solutions I think it’s worth the price."
  • "Pricing is pretty fair."
  • "While licensing can be a concern, there are ways to reduce the licensing costs including filtering some events."
  • More Splunk Enterprise Security Pricing and Cost Advice →

    report
    Use our free recommendation engine to learn which Indexing and Search solutions are best for your needs.
    771,157 professionals have used our research since 2012.
    Comparison Review
    Vinod Shankar
    Answers from the Community
    Vivek Vijayan
    reviewer1182204 - PeerSpot reviewerreviewer1182204 (Director of Marketing, US)
    Vendor

    Generally Elastic is very strong in datasearch, and Splunk has a strong security solution. However Elastic has partnered with SIEM provider empow and together this integration provides a very strong platform both in datasearch and next generation SIEM.

    Here's a thorough article on ELK vs. Splunk and here's a description from Elastic on what's included in the different versions.

    Alex Boz - PeerSpot reviewerAlex Boz (Logrhythm)
    Vendor

    Splunk: hard to use, expensive with predatory pricing, few OOTB rules, SOAR is a premium, good luck training analyst on their platform in under six months. SPLUNK SEARCH.

    ELK Stack: easy to use, open-source, no predatory pricing, more robust use cases OOTB, loved and used by millions all over the globe, open ecosystem that can integrate with almost any major IT stack out of the box. LUCENE.

    Norman Freitag - PeerSpot reviewerNorman Freitag
    Real User

    We use ELK or other freeware stacks in isolated small scenarios.

    Think of a small or medium company with a „midsized“ webshop. You can easily do your Log management with an ELK-Stack, let's say size 5 up to 10 GB, no Problem. Please keep in mind to order Hardware. The best thing on ELK is that you can start immediately you don't have to wait for licensing and it's easy to build the first small things.

    Another Example:
    Your Marketing Dep. wants to do some singular evaluations and very specialized marketing stuff. It is temporary and they don't have the budget for licensing. The results are not for permanent use. Just use ELK.

    In my opinion, ELK is only cost-effective if you don't need to buy their professional service. You must leave the cases small.

    If you are looking for bigger scenarios or you want to build-up a SIEM, SOC or even doing elevated things like SOAR it is a very different kind of thing.
    There can be account issues that a developer usually won't mind at the first glance but a Controller will.
    You have to look at the Total Cost of Ownership, Scalability, Time to Market, Secureness of future development, maintenance e.g.

    If you want to build up a complex scenario with the secureness of scalability you should go with SPLUNK. If tomorrow there is a better tool with lower costs and less need for input of manpower I will refer to this.

    Questions from the Community
    Top Answer:Logsign provides us with the capability to execute multiple queries according to our requirements. The indexing is very high, making it effective for storing and retrieving logs. The real-time… more »
    Top Answer:I don't see improvements at the moment. The current setup is working well for me, and I'm satisfied with it. Integrating with different platforms is also fine, and I'm not recommending any changes or… more »
    Top Answer:For tools I’d recommend:  -SIEM- LogRhythm -SOAR- Palo Alto XSOAR Doing commercial w/o both (or at least an XDR) is asking to miss details that are critical, and ending up a statistic. Also,… more »
    Top Answer:It would really depend on (1) which logs you need to ingest and (2) what are your use cases Splunk is easy for ingestion of anything, but the charge per GB/Day Indexed and it gets expensive as log… more »
    Top Answer:Splunk handles a high amount of data very well. We use Splunk to capture information and as an aggregator for monitoring information from different sources. Splunk is very good at alerting us if we… more »
    Ranking
    1st
    out of 25 in Indexing and Search
    Views
    2,215
    Comparisons
    742
    Reviews
    27
    Average Words per Review
    501
    Rating
    8.3
    Views
    24,689
    Comparisons
    20,244
    Reviews
    69
    Average Words per Review
    930
    Rating
    8.4
    Comparisons
    Also Known As
    Elastic Enterprise Search, Swiftype, Elastic Cloud
    Learn More
    Overview

    Elasticsearch is a prominent open-source search and analytics engine known for its scalability, reliability, and straightforward management. It's a favored choice among enterprises for real-time data search, analysis, and visualization. Open-source Elasticsearch is free, offering a comprehensive feature set and scalability. It allows full control over deployments but requires managing and maintaining the infrastructure. On the other hand, Elastic Cloud provides a managed service with features like automated provisioning, high availability, security, and global reach.

    Elasticsearch excels in handling time-sensitive data and complex search requirements across large datasets. Its scalability allows it to handle growing data volumes efficiently, maintaining high performance and fast response times. Integrated with Kibana, Elasticsearch enables powerful data visualization, providing real-time insights crucial for data-driven decision-making.

    Elastic Cloud reduces operational overhead and improves scalability and performance, though it comes with associated costs. It is available on your preferred cloud provider — AWS, Azure, or Google Cloud. Customers who want to manage the software themselves, whether on public, private, or hybrid cloud, can download the Elastic Stack.

    At its core, Elasticsearch is renowned for its full-text search capabilities, capable of performing complex queries and supporting features like fuzzy matching and auto-complete.

    Peer reviews from various professionals highlight its strengths and weaknesses. Pros include its detection and correlation features, flexibility, cloud-readiness, extensibility, and efficient search capabilities. However, users have noted challenges like steep learning curves, data analysis limitations, and integration complexities. The platform is generally viewed as stable and scalable, with varying degrees of satisfaction regarding its usability and feature set.

    In summary, Elasticsearch stands out for its high-speed search, scalability, and versatile analytics, making it a go-to solution for organizations managing large datasets. Its adaptability to different enterprise needs, robust community support, and continuous development keep it at the forefront of enterprise search and analytics solutions. However, potential users should be aware of its learning curve and the need for skilled personnel for optimization.

    Splunk Enterprise Security is a SIEM, log management, and IT operations analytics tool. The solution provides users with the ability to secure their information and manage their data in the cloud, data centers, or other applications. Splunk Enterprise Security also offers visibility from different areas, levels, and devices, rather than from a single system, thus, providing its users with flexibility. Splunk Enterprise Security can monitor data and analyze, detect, and prevent intrusions. This benefits users as it provides alerts to possible intrusions, helps users to be proactive, and reduces risk factors. 

    Full visibility across your environment

    Break down data silos and gain actionable intelligence by ingesting data from multicloud and on-premises deployments. Get full visibility to quickly detect malicious threats in your environment.

    Fast threat detection

    Defend against threats with advanced security analytics, machine learning and threat intelligence that focus detection and provide high-fidelity alerts to shorten triage times and raise true positive rates.

    Efficient investigations

    Gather all the context you need and initiate flexible investigations with security analytics at your fingertips. The built-in open and extensible data platform boosts productivity and drives down fatigue.

    Open and scalable

    Built on an open and scalable data platform, you can stay agile in the face of evolving threats and business needs. Splunk meets you where you are on your cloud journey, and integrates across your data, tools and content.

    Sample Customers
    T-Mobile, Adobe, Booking.com, BMW, Telegraph Media Group, Cisco, Karbon, Deezer, NORBr, Labelbox, Fingerprint, Relativity, NHS Hospital, Met Office, Proximus, Go1, Mentat, Bluestone Analytics, Humanz, Hutch, Auchan, Sitecore, Linklaters, Socren, Infotrack, Pfizer, Engadget, Airbus, Grab, Vimeo, Ticketmaster, Asana, Twilio, Blizzard, Comcast, RWE and many others.
    Splunk has more than 7,000 customers spread across over 90 countries. These customers include Telenor, UniCredit, ideeli, McKenney's, Tesco, and SurveyMonkey.
    Top Industries
    REVIEWERS
    Financial Services Firm33%
    Computer Software Company27%
    Manufacturing Company10%
    Insurance Company7%
    VISITORS READING REVIEWS
    Computer Software Company18%
    Financial Services Firm15%
    Manufacturing Company8%
    Government7%
    REVIEWERS
    Computer Software Company20%
    Financial Services Firm15%
    Government9%
    Energy/Utilities Company8%
    VISITORS READING REVIEWS
    Financial Services Firm15%
    Computer Software Company14%
    Government9%
    Manufacturing Company7%
    Company Size
    REVIEWERS
    Small Business41%
    Midsize Enterprise11%
    Large Enterprise48%
    VISITORS READING REVIEWS
    Small Business24%
    Midsize Enterprise13%
    Large Enterprise62%
    REVIEWERS
    Small Business31%
    Midsize Enterprise11%
    Large Enterprise57%
    VISITORS READING REVIEWS
    Small Business19%
    Midsize Enterprise13%
    Large Enterprise68%
    Buyer's Guide
    Indexing and Search
    May 2024
    Find out what your peers are saying about Elastic, IBM, OpenText and others in Indexing and Search. Updated: May 2024.
    771,157 professionals have used our research since 2012.

    Elastic Search is ranked 1st in Indexing and Search with 59 reviews while Splunk Enterprise Security is ranked 1st in Security Information and Event Management (SIEM) with 240 reviews. Elastic Search is rated 8.2, while Splunk Enterprise Security is rated 8.4. The top reviewer of Elastic Search writes "Played a crucial role in enhancing our cybersecurity efforts ". On the other hand, the top reviewer of Splunk Enterprise Security writes "It has a drag-and-drop interface, so you don't need to know SQL or Java to construct a query ". Elastic Search is most compared with Faiss, Milvus, Pinecone, Azure Search and Amazon Kendra, whereas Splunk Enterprise Security is most compared with Wazuh, Dynatrace, IBM Security QRadar, Elastic Security and Microsoft Sentinel.

    We monitor all Indexing and Search reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.