Splunk Enterprise Security vs VMware Aria Operations for Applications comparison

 

Comparison Buyer's Guide

Executive Summary
 

Categories and Ranking

Splunk Enterprise Security
Average Rating
8.4
Number of Reviews
255
Ranking in other categories
Log Management (1st), Security Information and Event Management (SIEM) (1st), IT Operations Analytics (1st)
VMware Aria Operations for ...
Average Rating
7.6
Number of Reviews
9
Ranking in other categories
Application Performance Monitoring (APM) and Observability (33rd), IT Infrastructure Monitoring (34th), Container Monitoring (9th), Cloud Monitoring Software (29th)
 

Market share comparison

As of June 2024, in the Security Information and Event Management (SIEM) category, the market share of Splunk Enterprise Security is 13.7% and it decreased by 3.4% compared to the previous year. The market share of VMware Aria Operations for Applications is 0.1% and it decreased by 50.8% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Security Information and Event Management (SIEM)
Unique Categories:
Log Management
17.6%
IT Operations Analytics
28.2%
Application Performance Monitoring (APM) and Observability
0.9%
IT Infrastructure Monitoring
1.1%
 

Featured Reviews

RB
May 8, 2024
Provides a centralized place to consolidate everything and start investigations
The end-to-end visibility the tool provides is not that big of a deal. They have so many tools that can do that kind of part. Splunk doesn't have to be the one place for total visibility, but at least for visibility when it consolidates on threats. Splunk has helped improve our organization's ability to ingest and normalize data. The tool pretty much consumes everything that we have. Everything from dozens of different vendor products gets ingested into Splunk. Splunk Enterprise Security is just that one central place where everything goes. Splunk Enterprise Security has helped speed up our security investigations. Something that requires someone to work on it at the beginning of the day would not take more than 15 minutes with Splunk Enterprise Security. Overall, I rate the solution an eight out of ten.
OG
Mar 16, 2023
Useful technology with helpful support but it's hard to set up Tanzu clusters
I primarily use the solution for consulting. I help company DevOps teams.  The companies are already using VMware technologies and Tanzu helps them be compatible with other technologies.  The company is able to use native Kubernetes. It can support open-source technologies. If you have trouble…

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"We saw the granularity that we could get from Splunk far exceeded what we already had. We had the ability to have our security team really focus on the platform and stay within the platform, but they could correlate with a variety of other stakeholders, and our stakeholders were growing."
"The flexibility of the search capability is most valuable. You can use it for more than just a basic log aggregator. It is powerful in that regard."
"The ability to view all of these different logs, then drilling down into specific times or into specific data sources, has proved to be the greatest aspect in decreasing our troubleshooting overhead time."
"The product is good, it satisfies our customers."
"The correlation searches are most valuable just because we are able to do things like RBA."
"It gives us the liberty to do more in terms of use cases."
"The client site login is pretty extensible and probably cost-effective."
"Good for log collection and log management."
"The solution is great for virtualization and preparing the infrastructure in Tanzu to test products. It's very fast and has good visibility."
"The features I find most valuable is the querying and alerting capabilities."
"The most valuable aspects of the solution are its ease of use and its ease of implementation."
"For us, the ease of deployment in combination with TMZ was the most important part because we don't have to manually deploy a complex monitoring solution. We can more or less do that with the click of a button, and we are not dependent on the developers to provide us with all the necessary features and functions to make that work. We can just deploy it on a workload cluster and monitor at least a good part of the workload. If we want to go into detail, we clearly need to make changes, but for a good part of application monitoring, it gives us good insights."
"No issues with stability."
"Tanzu itself, integrated with multiple solutions, bestows support and security upon a container platform, especially when it comes to managing open-source container platforms such as Kubernetes."
"VMware comes with a support team, and if you have trouble, you can easily create a ticket, and VMware will help you. Therefore, the best aspect is the support."
"People are very pleased with the implementation."
 

Cons

"Sometimes the communication with support happens with multiple staff. They should reduce the time to resolution."
"Better directions on search head clusters."
"The product's price may be an area of concern where improvements are required."
"The product's price may be an area of concern where improvements are required."
"Technical support needs to be more responsive."
"Many of my clients want to get better at Splunk, but they're afraid of using the tool because they feel it's too complex for them."
"It will be helpful for customers if they can create some real-world cases, and we can find a case study to align with. I know that Splunk has tremendous potential. We only include a tiny piece of it. There is a lot of stuff that we need to learn. If Splunk can provide more real-time examples, that will be helpful for customers."
"Given the ever-increasing number of threats, I would like Splunk to update its threat signatures more frequently."
"The main problem I have is that the license cost is very high."
"The implementation is a long process that should be improved."
"Its billing model is consumption-based. I understand the consumption-based model, but it is not necessarily easy to estimate and guess how many points or how much we are going to consume on a specific application up until we get to that point. So, for us, it would be helpful to have more insights or predictability into what we can expect from a cost perspective if we are starting to use specific features. This can potentially also drive our consumption a bit more."
"In the new version, I would love to see more prediction capabilities. It would be great if one could see the alerts get a little more enriched with information and become more human-friendly instead of the technical stuff that they put in there. I think those would be really awesome outcomes to get."
"The documentation and integration with Kubernetes could be improved."
"It could use a URL document server. Everything in the market is moving towards automation and everybody's looking for the single click operations as well relational data locality."
"They could make it more easy to plug-in data so that a nontechnical person will be able to use it, like accountants or finance people. That way they don't have to ask us."
"The initial setup should be easier and more seamless."
 

Pricing and Cost Advice

"Free Splunk license for PoCs on personal machines and the ability to scale the PoC to an enterprise level app."
"The price of this solution is expensive. However, it has great features. If you want a great solution you need to pay a price matching the features."
"Splunk Enterprise Security's pricing is pretty competitive."
"It can be cost-prohibitive when you start to scale and have terabytes of data. Its cost model is based on how much data it processes a day. If they're able to create scaled-down niche or custom package offerings, it may help with the cost. Instead of the full-blown features, if they can narrow the scope where it can only be used for a specific purpose, it would kind of create that market for the product, and it may help with the costing. When you start using it as a central aggregator and you're pumping tons of logs at it, pretty soon, you'll start hitting your cap on what it can process a day. Once you've got that, you're kind of defeating the purpose because you're going to have to scale back."
"We have seen ROI and improvements as we have continued to use the product, but they are more reactive."
"It can be expensive, especially the licensing costs. However, there is added value in what it can do, not just log aggregation."
"We have an unlimited one, and we pay yearly, but I don't know how much it costs. Previously, I worked for a startup, and when they started building it up, it was complicated for them because they didn't have the budget for that many licenses. It was very costly for them. So, startups might find it a little bit problematic because of the licensing, but for bigger companies, there is no issue."
"The pricing and licensing of the product are quite high."
"I would rate the pricing as three out of five."
"I don't have the details. In our case, there is a mixture in place. We have production usage, and we are also doing training for VMware. So, we also have a training instance. It is worth the money you would spend on it. That's because if you were to build all of this yourself by using some of the open source tools, then you would need a lot of time."
"The licensing costs are very high, particularly when you consider that we have to purchase a level 1 license for every integration, such as the load balancer, HAProxy, and the MSSP. And if you want to use vSAN, that's another license. Then, of course, Tanzu Observability has its own separate license."
"Different locations require different setups. In your terms, around 300 to around 400K USD."
report
Use our free recommendation engine to learn which Security Information and Event Management (SIEM) solutions are best for your needs.
787,061 professionals have used our research since 2012.
 

Comparison Review

VS
Feb 26, 2015
HP ArcSight vs. IBM QRadar vs. ​McAfee Nitro vs. Splunk vs. RSA Security vs. LogRhythm
We at Infosecnirvana.com have done several posts on SIEM. After the Dummies Guide on SIEM, we are following it up with a SIEM Product Comparison – 101 deck. So, here it is for your viewing pleasure. Let me know what you think by posting your comments below. The key products compared here are…
 

Top Industries

By visitors reading reviews
Financial Services Firm
15%
Computer Software Company
14%
Government
9%
Manufacturing Company
8%
Financial Services Firm
17%
Computer Software Company
17%
Manufacturing Company
7%
Government
6%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

What SOC product do you recommend?
For tools I’d recommend: -SIEM- LogRhythm -SOAR- Palo Alto XSOAR Doing commercial w/o both (or at least an XDR) is asking to miss details that are critical, and ending up a statistic. Also, rememb...
What is a better choice, Splunk or Azure Sentinel?
It would really depend on (1) which logs you need to ingest and (2) what are your use cases Splunk is easy for ingestion of anything, but the charge per GB/Day Indexed and it gets expensive as log ...
How does Splunk compare with Azure Monitor?
Splunk handles a high amount of data very well. We use Splunk to capture information and as an aggregator for monitoring information from different sources. Splunk is very good at alerting us if we...
What do you like most about VMware Tanzu Observability by Wavefront?
VMware comes with a support team, and if you have trouble, you can easily create a ticket, and VMware will help you. Therefore, the best aspect is the support.
What needs improvement with VMware Tanzu Observability by Wavefront?
It's hard to set up Tanzu clusters. It's hard to do a POC. Once you set up a customer's environment, you easily see the problems. The initial setup should be easier and more seamless.
 

Also Known As

No data available
Tanzu Observability, Wavefront, Wavefront by VMware, VMware Tanzu Observability
 

Learn More

 

Overview

 

Sample Customers

Splunk has more than 7,000 customers spread across over 90 countries. These customers include Telenor, UniCredit, ideeli, McKenney's, Tesco, and SurveyMonkey.
1. Atlassian 2. Cisco 3. Databricks 4. DigitalOcean 5. Equinix 6. Fidelity Investments 7. Google 8. Hewlett Packard Enterprise 9. Honeywell 10. IBM 11. Intel 12. JetBlue Airways 13. LinkedIn 14. Lyft 15. Mastercard 16. Microsoft 17. MongoDB 18. Netflix 19. Nvidia 20. Oracle 21. PayPal 22. Pinterest 23. Qualcomm 24. Red Hat 25. Salesforce 26. SAP 27. Spotify 28. Square 29. TMobile 30. Twitter 31. Uber 32. VMware
Find out what your peers are saying about Splunk Enterprise Security vs. VMware Aria Operations for Applications and other solutions. Updated: May 2023.
787,061 professionals have used our research since 2012.