Splunk Enterprise Security Other Solutions Considered

MR
Manager, Security Engineering at a computer software company with 1,001-5,000 employees

I did not evaluate other options. This solution was in place when I arrived. 

View full review »
TB
Sr Cybersecurity Engineer at a energy/utilities company with 10,001+ employees

I have looked at other competitors. We recently looked at CrowdStrike's LogScale solution. It feels like Splunk to me. I cannot say how we would reproduce what we have done in Splunk on the infrastructure side or backend. Our environment is uniquely different. Technically, I am the only person who runs Splunk for our entire organization, similar to the way the previous person ran ArcSight for the organization. If I were to compare apples to apples, Splunk to me is still number one in that category.

Splunk's community is the biggest benefit. It is so easy to go to Slack and hit someone up. There is a good chance that you will find someone out there who has run into the exact same issue that you are having. Their documentation is fantastic. Because I am the only one who runs it for our organization, it is easy for me just to Google it, find the document, and just follow it. It is as simple as that. It gets a little dicey with XDR and all the other things that are happening in the market, such as using a data lake. Instead of putting our eggs in one basket or using Splunk, we might use something like Snowflake.

View full review »
DS
Security Analytics innovation lead at a pharma/biotech company with 10,001+ employees

The company evaluated a few tools before deciding on Splunk. I used ArcSight at a previous job. Splunk is more flexible than ArcSight, and it has various modules you can purchase to expand the functionality. You don't need to invest in a different solution because you can purchase add-ons for your existing infrastructure. 

It's modular, so you can tailor Splunk to your organization's size, structure, and specific needs. The customer can do it. You don't need to request it from a service provider. 

View full review »
Buyer's Guide
Splunk Enterprise Security
March 2024
Learn what your peers think about Splunk Enterprise Security. Get advice and tips from experienced pros sharing their opinions. Updated: March 2024.
768,415 professionals have used our research since 2012.
LC
Security Engineer at a recreational facilities/services company with 10,001+ employees

We briefly looked at the open source product and we obviously looked at a Check Point product. When we looked at Splunk it seemed like they had a smaller cost to procure it, and a much smaller cost to maintain it than all of those other solutions. So it was kind of why we went with Splunk. This is very non-intuitive since everybody says they love Splunk but it costs too much.

View full review »
Balamurali Vellalath - PeerSpot reviewer
Practice Head-CyberSecurity at ALTEN calsoft Labs

Before choosing Splunk, we have evaluated QRadar and LogRhythm. QRadar is much more expensive. LogRhythm lacked reporting.

We ended up choosing Splunk due to the pricing and the reporting features. It also had the kind of scalability that was required. We felt it would help us in terms of positioning from both a cost perspective and an incident alert perspective.

View full review »
JG
IT Director at Administrative Office U.S. Courts

We evaluated what was on the market, and fortunately, we picked Splunk. Looking back, it was the right decision.

View full review »
OO
Owner at Py Concepts

I'm not sure if any other options were evaluated by the company. 

View full review »
BC
IT Specialist at a government with 10,001+ employees

We evaluated other options. We had to evaluate the pros and cons in terms of the cost and the capabilities of each tool. A lot of that went into the proof of concept. We did our due diligence and determined that Splunk was the best fit for us.

View full review »
Hari Haran. - PeerSpot reviewer
Technical Associate at Positka

We tried some other solutions, but they didn't work like Splunk. We found that Splunk is the best one.

View full review »
Chetankumar Savalagimath - PeerSpot reviewer
Delivery Manager at a tech services company with 1,001-5,000 employees

I have worked with a number of other solutions including RSA enVision, IBM QRadar, as well as Microsoft, McAfee, and LogRhythm. 

If we want to build an add-on feature in Splunk, we have to build an application and then integrate it. But in other applications, there is a direct integration that only requires partial development and it will start functioning.

Also, there is something called correlation in a lot of other tools. Splunk also has it but it consumes a lot of memory. If we tag all the data, it is better, but tagging consumes storage and it makes it a little tough for us to run a search. 

If we want to work towards SOAR, if there were a little bit more integration so that our customers could taste SOAR, they could then move to Splunk Phantom or other tools. Right now, people are not using automation. Everything is done manually. Hopefully, that's the next goal. Security operations will surely use SOAR and, once they start tasting it, they'll get to know how it works. They can design playbooks and start using it. That's an additional feature I would like Splunk to bring in. 

Splunk's advantage is its search capability. Its search is notably faster. With Splunk, I can search easily on keywords. That is great. It also has something called "stats" and it runs much faster. Within minutes, it gives the data from a very large set. Spunk's dashboards are also a very good thing. No other application or tool is as versatile in presenting the dashboard. It all comes down to presentation. It may take a little bit of engineering work to develop and customize, to parse the fields and fetch the data, but the presentation is good.

View full review »
Alex Adamovici - PeerSpot reviewer
Head of Knowledge Capture Cloud at Integritie

We did test AT&T and LogRhythm as well. We chose this solution as a balance between cost and functionality.

AT&T was a great security tool, however, it lacked a lot of the infrastructure things that Splunk does, in terms of server monitoring and network monitoring. LogRhythm did have a dose, however, at a very prohibitive price. It was almost twice the cost of Splunk.

View full review »
RV
CEO at a retailer with 51-200 employees

Before choosing Splunk, I evaluated other options, including QRadar. However, if I were to evaluate them today, my choice might be different.

View full review »
Yash-Gupta - PeerSpot reviewer
Analyst, TSG Information Security Cyber Operations at a consultancy with 5,001-10,000 employees

I did not evaluate other options. I adopted this tool when I joined my current organization. 

View full review »
Kenny Corbett - PeerSpot reviewer
Associate Director of IT at Rigel Pharmaceuticals Inc

We are not evaluating any solutions because we already have Splunk, and we do not want to leave Splunk. I like it, so it is just a matter of making the commitment.

View full review »
VA
Tech Director at a government with 10,001+ employees

We have evaluated other solutions, and Splunk definitely comes out as one of the top competitors due to its interoperability with a lot of data sources that are sprinkled around in our environment. This interoperability is a key piece because we have such a diverse asset environment.

View full review »
RB
Engineer at a government with 10,001+ employees

We did not evaluate other solutions. Splunk came in with the modernization effort that we were going through, so it just came with the system.

View full review »
JC
Cyber Security at a financial services firm with 5,001-10,000 employees

We do an evaluation annually. It is important for us to do a market comparison and make sure we are looking at options in our work. What makes Splunk Enterprise Security competitive is the variabilities that they bring to the table for the overall solution. It has things like APIs that you can tie into. There is also the bonus functionality of being able to do analytics there. User behavior analytics is important for us.

View full review »
reviewer1331706 - PeerSpot reviewer
I&T Design & Execution Reliability Engineering Leader at a financial services firm with 10,001+ employees

The other product that I've seen is Elastic, and I think that it would be a better choice than Splunk. This is something that I'm basing on performance, as well as the other features.

View full review »
OS
Information Security Advisor, CISO & CIO, Docutek Services at Docutek Services

We were using QRadar as a POC. We were using for real at our cloud but also it was a POC for us because we were watching the product. But, QRadar needs a lot of fine tuning.

View full review »
DL
Head of Cybersecurity at a computer software company with 51-200 employees

We also looked at Dynatrace before choosing Splunk. 

View full review »
RC
Security Compliance Program Manager at a educational organization with 5,001-10,000 employees

I have worked with Wazuh and ManageEngine Endpoint Central.

View full review »
Robert Cheruiyot - PeerSpot reviewer
IT Security Consultant at Microlan Kenya Limited

I have been proposing to management to take the solution to be a primary product in our dealings with it. We do not encounter many issues involving the solution. One of the problems I have with the RSA Netwitness platform is its complexity. Splunk is straightforward for us when it comes to views and it provides us the network security posture.

The ability for the solution to work with Cisco shows that the solution can work with other products. The only thing is that when the solution is compared with other vendors, one sees that there is only a single other vendor that has endpoint security like this one, Netwitness platform having its component for the endpoint. This is why an integrated endpoint would be a nice feature, even though the solution works on Cisco. 

The main advantage of the solution is that it provides an easy setup platform in the new environment. When set up afresh, it is also easy to build queries. Historical queries can be used to site for a new event, which makes it easy to use, deploy and understand. 

When it comes to a data platform, there is RSA NetWitness, which may also be a good platform. I have not done much training of my own on Splunk, but have gained much experience through learning and working with clients that I support. This is because the platform is understandable. 

I would rate Splunk as one of the big five platforms. I would give it a high rating based on the efficiency of the platform. Clearly, I cannot include Wazuh in the top five categories, as its rating is not up there with Splunk, Qradar and LogRythm.

View full review »
SD
Technical Project Manager at Altran

We also looked at HP ArcSight and two other solutions. 

View full review »
RB
Engineering Manager at Cengage Learning

I would consider ELK Kibana a competitor for this solution. If you have time, and you want to do it yourself, you can save a little money going with Kibana. However, Splunk is pretty good and I would recommend an enterprise to switch to Splunk.

View full review »
SP
CHRO at a computer software company with 5,001-10,000 employees

By comparison, I feel QRadar to be better than Splunk Cloud, since it comes with Watson. 

Another advantage is that QRadar works like a threat intelligence tool. It, also, does not require queries, which Splunk Cloud does. It is important that we have an understanding of the queries for the purpose of pulling the logs which we seek. I feel QRadar to be better than Splunk Cloud, as it does not require us to work on the queries. 

I have worked on Splunk Cloud in the past, as well as on QRadar. As there is no SIEM solution in my current organization, we have plans to build it up. This is an ongoing process. I have suggested QRadar to my team and others are considering Sentinel. 

View full review »
it_user664632 - PeerSpot reviewer
Senior IT Security Operations at a pharma/biotech company with 10,001+ employees

We were using ArcSight before.

View full review »
MY
Systems Engineer at a consultancy with 201-500 employees

I have not evaluated other options. 

View full review »
CM
Incident Manager at CyberCore Technologies

Other options were evaluated, such as ELK, but Splunk was identified to be more feature rich out-of-the-box.

View full review »
RE
Cyber Security Consultant at a tech services company with 10,001+ employees

I did some research for a school project. I needed to compare it to Splunk and a few other tools. As a result, I'm not particularly interested in purchasing them.

View full review »
MS
Senior security consultant at a comms service provider with 51-200 employees
KB
DevOps Engineer at Amplify Education, Inc.

There are a lot of vendors in the space at the conference this year. Therefore, we probably talked to six or seven different ones, and the market seems to be consolidating. The market's metrics and log monitoring all seem to be rolling up into a single provider. It looks like that is what will be happening in the next few years.

Right now, there are a ton of different smaller providers doing little pieces of this and that. All the big players, like Splunk, New Relic, and Datadog, seem to be rolling them all up into one offering. 

View full review »
it_user340983 - PeerSpot reviewer
Infrastructure Engineer at Zirous, Inc.

We evaluated the ELK Stack, of which recently we have implemented with a customer who was looking for a more lightweight, cheaper alternative that would work "Good Enough". They felt they did not need all of the bells and whistles that came with Splunk.

View full review »
it_user126027 - PeerSpot reviewer
Owner with 1-10 employees

The other SIEM solution providers we looked at were ArcSight, QRadar and SolarWinds LEM.

View full review »
KB
CTA\Owner at UCSolutions

I evaluated other things. I also integrated with other solutions too. I decided to go with Splunk due to the fact that it worked well.

View full review »
PB
Principal Systems Engineer at Aricent

We work with Splunk, but we are looking for some LOG Kinetics solutions for our clients.

View full review »
MK
Senior Consultant at Securian Financial Group

We evaluated our existing tool, LogRhythm.

View full review »
it_user525171 - PeerSpot reviewer
Specialist Master, Cyber Risk at a tech vendor with 10,001+ employees

We evaluated HPE ArcSight.

View full review »
it_user257376 - PeerSpot reviewer
Lead Splunk Architect at a financial services firm with 10,001+ employees

Yes, Graylog and QRadar.

View full review »
it_user575310 - PeerSpot reviewer
Engineer, Infrastructure Applications at a healthcare company with 1,001-5,000 employees

We evaluated Graylog, Elastic.io, etc.

View full review »
KK
IT Analyst at a energy/utilities company with 1,001-5,000 employees

We also looked at Selopene SIEM. It is a premier logging site.

View full review »
TF
CTO at IHS Markit

We knew we were going to go with Splunk. It was the leader and the one we liked. We didn't consider any others since Splunk met our needs.

We chose Splunk because of the ease of the UI, querying, and creating dashboards. It has a standardized query language, which a lot of the IT staff were already familiar with it. It was the market leader from our prospective for our needs.

View full review »
CJ
Information Security Engineer/Architect at The Church of Jesus Christ of Latter-day Saints
SM
Engineering Manager at a manufacturing company with 10,001+ employees

I wasn't there when the evaluation was done. When I came on board, this product was handed down to me, and we have not evaluated any other solutions or products since then.

View full review »
it_user865026 - PeerSpot reviewer
Lead Systems Architect at a energy/utilities company with 10,001+ employees

We also evaluated ELK, Dynatrace, and New Relic, but Splunk provided a comprehensive solution to fit our all around needs.

View full review »
it_user250131 - PeerSpot reviewer
Information Architect at a financial services firm with 5,001-10,000 employees

We started researching ELK (Elastic, Logstash, Kibana). But management was so impressed with Splunk that we ended this research.

View full review »
SS
Consultant at a financial services firm with 5,001-10,000 employees

We are a partner of Splunk. So, we did not evaluate other solutions.

View full review »
JD
Enterprise Architect at a tech services company with 10,001+ employees

Splunk has no real competition. It is just Splunk, and that is it.

View full review »
AM
Senior Technical Lead at a financial services firm with 10,001+ employees

We have evaluated SoapUI and Postman, and we are still evaluating others.

View full review »
AT
Managing Director at Hayyan Horizons

Yes all the other competitors, Splunk by far is the best.

View full review »
SO
Founder at a marketing services firm with 11-50 employees

We studied four or five tools including Logrhythm and Exabeam. We went with Splunk for now and will see how that goes.

View full review »
PN
Director at a tech services company with 10,001+ employees

We considered Oracle Enterprise Manager, but Splunk is way more powerful. Splunk is product-agnostic, as it can move across different platforms and products. 

View full review »
Yosef Tavin - PeerSpot reviewer
DevOps Engineer at BigPanda

We evaluated ELK Stack and QlikView.

View full review »
it_user399819 - PeerSpot reviewer
Security Architect at a energy/utilities company with 1,001-5,000 employees

We evaluated ArcSight, QRadar, and LogRhythm.

View full review »
VA
Security Architect at a tech services company with 51-200 employees

We provide IT consulting services. Our customers occasionally ask us to assist them in locating specific solutions.

View full review »
ID
Senior Network Engineer at a tech services company with 51-200 employees

I have evaluated DataDog.

View full review »
GW
Consultant at Splunxter, Inc.

No,we went with the free trial and got so much value so quickly we bought in.

View full review »
AK
Senior Informatica Administrator at a computer software company with 10,001+ employees

We considered a few alternative products because the logging was faster. In the end, we decided to go to Splunk.

View full review »
GM
Application Engineer at Expedia

We looked at the Elk Stack, Kibana, and Sumo Logic.

We chose Splunk because their cost is better, the maintenance factor is a little higher, and the core functionality is higher than what other products provide. The core functionality is out-of-the-box. E.g., with a Toyota Scion, you can customize the parts to make it whatever you want, but it's a lot of work to get there. Where if you buy a Cadillac, you pay the Cadillac's price, but it's a Cadillac. It will work right out-of-the-box.

View full review »
it_user867087 - PeerSpot reviewer
Security Engineer at Information Innovators Inc. (Triple-i)

We evaluated Trustwave and QRadar.

View full review »
it_user782697 - PeerSpot reviewer
Security Operation Center Analyst at Sadad

There are a lot of solutions: IBM QRadar, Splunk, LogRhythm. Splunk was good for us because of the support, the documentation, the scalability, the stability. It gives us everything that we need in our business, everything necessary for helping us do our job.

View full review »
MA
System Administrator at Abdullah Al-Othaim Markets

We evaluated QRadar.

View full review »
JS
Product Manager, FX Solutions at a tech services company with 10,001+ employees

I have evaluated Tableau.

View full review »
JC
Chief Architect at PathMaker Group

We evaluated Alert Logic and Splunk. We still use both products heavily. 

We have different use cases for the products. At first, Splunk was free, so we started to take more advantage of it.

View full review »
it_user664626 - PeerSpot reviewer
Business Analyst at a retailer with 10,001+ employees

We evaluated Logstash and others, but Splunk plays a pivotal role.

View full review »
it_user1415322 - PeerSpot reviewer
Senior Consultant at sectecs

I have done some research on LogRhythm, IBM QRadar, and ArcSight, but I don't have any hands-on experience yet.

I did a comparison for a customer two weeks ago and the outcome of my comparison was SIEMonster, effortable price model, even though it's a niche player, it's quite powerful. I also provided Splunk as a recommendation because it is a market leader, really powerful, and really good to use. I also recommended LogRhythm; it is also expensive but it's also really powerful, and the feedback of customers is really good.

With respect to Splunk, I would recommend it but when a customer is budget-driven then Splunk is not the solution. Money shouldn't be the question.

View full review »
AK
System Engineer at NetScout Systems

I have evaluated other solutions, such as IBM QRadar.

View full review »
SO
Software Engineer at Tableau Software

We have other log searching tools, but we have standardized on Splunk. 

View full review »
it_user664635 - PeerSpot reviewer
Performance Consultant at a tech services company with 10,001+ employees

We looked at IBM SmartCloud Analytics and Log Analytics.

View full review »
it_user645663 - PeerSpot reviewer
Sr. Program Manager at a consultancy with 51-200 employees

We didn’t evaluate any alternatives.

View full review »
it_user396600 - PeerSpot reviewer
Vice Manager at a comms service provider with 10,001+ employees

We evaluated Elastic Stack and Sumo Logic.

View full review »
it_user313119 - PeerSpot reviewer
Integration Architect at a manufacturing company with 1,001-5,000 employees
it_user717477 - PeerSpot reviewer
Account Manager at a tech services company with 10,001+ employees

It was the customer's choice.

View full review »
MC
Presales IT at a tech services company with 201-500 employees

We give support for VMware and other technologies. We purchased Splunk because our customers were asking for our services to take control of the implementation from another company.

View full review »
LF
Técnico Judiciário at a government with 1,001-5,000 employees

We also looked at AlienVault.

View full review »
it_user859464 - PeerSpot reviewer
Senior Cloud Operations Analyst at a tech vendor with 1,001-5,000 employees

We evaluated LogRhythm.

View full review »
it_user635271 - PeerSpot reviewer
Foundation Technology Specialist at a insurance company with 1,001-5,000 employees

We looked at ELK Stack.

View full review »
TB
Technical Director at a consultancy with 11-50 employees

We did a SIEM solutions review with this and other systems for one of our customers.

View full review »
SA
CyberSecurity Consultant at Information Technology Solutions- ITS

Curator is more scalable than certain other solutions. 

View full review »
JN
IT Infrastructure Architect at a tech company with 201-500 employees

We did not look at alternatives. It was a consulting provider recommendation. It was a rapid implementation to accomplish legal requirements. After we used it for a while, we decided to keep it.

View full review »
it_user363165 - PeerSpot reviewer
Products Manager at a tech services company with 5,001-10,000 employees

Our client was considering the other solutions as well. However, due to their overall assessment, they still considered going with it.

View full review »
TS
Project Manager at a comms service provider with 10,001+ employees

We considered Datadog and Zabbix. In comparison to those options, Splunk has virtual visualization. Furthermore, it can be a host on our environment. Typically, we cannot deploy SaaS on our environment, but with Splunk, we can. 

View full review »
MC
Net Sec at a tech services company with 11-50 employees

We also looked at AlienVault.

View full review »
Buyer's Guide
Splunk Enterprise Security
March 2024
Learn what your peers think about Splunk Enterprise Security. Get advice and tips from experienced pros sharing their opinions. Updated: March 2024.
768,415 professionals have used our research since 2012.