Try our new research platform with insights from 80,000+ expert users

BMC TrueSight Operations Management vs Splunk Enterprise Security comparison

 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

BMC TrueSight Operations Ma...
Average Rating
8.2
Reviews Sentiment
6.7
Number of Reviews
50
Ranking in other categories
Application Performance Monitoring (APM) and Observability (21st), Event Monitoring (2nd), IT Infrastructure Monitoring (25th), Cloud Monitoring Software (20th), AIOps (8th)
Splunk Enterprise Security
Average Rating
8.4
Reviews Sentiment
7.6
Number of Reviews
305
Ranking in other categories
Log Management (2nd), Security Information and Event Management (SIEM) (1st), IT Operations Analytics (1st)
 

Mindshare comparison

While both are Application Lifecycle Management solutions, they serve different purposes. BMC TrueSight Operations Management is designed for IT Infrastructure Monitoring and holds a mindshare of 0.8%, down 1.4% compared to last year.
Splunk Enterprise Security, on the other hand, focuses on Security Information and Event Management (SIEM), holds 9.8% mindshare, down 13.3% since last year.
IT Infrastructure Monitoring
Security Information and Event Management (SIEM)
 

Featured Reviews

Srri G - PeerSpot reviewer
The product is reasonably priced, but the solution is a little obsolete because it is deployed on-premise
If I want custom monitoring across a very large estate of more than 50,000 units, the on-premise deployment gets quite slow. The on-premise product’s performance must be improved. The solution is a little obsolete. That is why the solution moved to Helix, a SaaS operating system. The SaaS platform has the features I like. There is no point in BMC expanding TrueSight Operations’ console. It's high time that BMC starts a demise path for the product and is associated only with Helix. If we need any additional function, we must switch to Helix. Since TrueSight is deployed on-premise, the scalability and usage of the product are mainly focused on providing basic features and not enhanced features like analytics or cost analysis. People should move to a SaaS platform because on-premise products have limited storage and capacity.
ROBERT-CHRISTIAN - PeerSpot reviewer
Has many predefined correlation rules and is brilliant for investigation and log analysis
It is very complicated to write your own correlation rules without the help of Splunk support. What Splunk could do better is to create an API to the standard SIEM tools, such as Microsoft Sentinel. The idea would be to make it less painful. In ELK Stack, Kibana is the query language with which you can search log files. I believe Splunk has also a query language in which they search their log files, but once you have identified the log file that you want to use for further security correlation, you want to very quickly transport that into your SIEM tool, such as Microsoft Sentinel. That is something that Splunk could make a little bit less painful because it is a lot of effort to find that log file and forward it. An API with Microsoft Sentinel or a similar SIEM tool would be a good idea.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"The fact that they have a very integrated relationship with Sentry Software, the Knowledge Module, is valuable... The richest feature for us is the number of Knowledge Modules that we can load into the product to add breadth of service to the customer. It enables us to move up the operational stack from hardware, to operating system, to application, and to cloud... That enables us to provide one pane of glass over all those layers - hardware, OS, app, and cloud."
"The solution's event management capabilities are fantastic. We do a best of breed. If, on the network side, they use a different tool, we pull all that data in so that we have a single console. It's kind of like the monitor of monitors. We're able to aggregate all the different types of data sets, whether it's log data, app data, OS data, infrastructure data, or network data. We're able to aggregate all those events and then correlate and be able to say we're having an event."
"Intelligent solution with a proactive monitoring feature and consolidated dashboard that's stable and easy to scale."
"The event management part of TrueSight Operations Management, in my experience, is probably the best in the market. You have endless flexibility. You can build your own rules, you have the MRL language, and you can implement any kind of logic on the alerts. It may be correlation, abstraction, or executing something as a result of the alerts. You have almost the whole range of options available for event management using the available customization."
"The solution has a very good business event manager tool."
"TSOM's ability to consolidate alerts into a single location and provide filtering of alerts is great."
"The solution provides visibility to our infrastructure, how it is, the resources we are monitoring, and quick updates when it has any problems. We have integrated it with ServiceNow to open instances."
"The tool is flexible enough to be customized based on customer requirements."
"Splunk is a user-friendly solution."
"Compared to IBM QRadar, Splunk Enterprise Security offers faster alert resolution."
"It has increased our business resilience. It's a top-of-the-line SIEM security product. It's the best tool for our security analysts which helps them do their job better. That then protects our company from adversary actors."
"Its compatibility with other SIEMS is very useful."
"The client site login is pretty extensible and probably cost-effective."
"Splunk has machine learning which is a valuable feature."
"The product is adept at log mining."
"We did not encounter any issues with scalability. It is almost seamless to add new index (storage) or search (used to analyze the data) nodes to the cluster."
 

Cons

"Specifically around application performance monitoring, BMC is definitely not the market leader. The Dynatraces, the New Relics and the like are more of the market leaders in that space. I would like to see them grow that space a little bit more aggressively. It has not really been their bread and butter."
"The knowledge modules could be more lightweight in size. At present, the installation packages can be quite large."
"More modules for less popular applications and better documentation."
"One of the things that the TrueSight environment is missing is some of the HA abilities. The data collection server called the ISM doesn't really have the HA functionality or workload balancing. It was missing from the previous product as well. It's missing redundancy."
"In our company, we faced some issues with the solution’s application endpoint, IP, and the physical location of the transactions."
"The product must provide application or service monitoring features."
"The dashboards are not good. We have a limited dashboard, and if we want better dashboards, we need to use other solutions like Grafana because the TrueSight dashboards are not good."
"Deployment requires lots of resources (servers). It has too many consoles."
"It would be good if the solution had some kind of copilot to automate or help write correlation searches."
"Being a SIEM solution with a centralized dashboard, we would like to have more options to customize it."
"Splunk could enhance its services by providing more comprehensive professional assistance aimed at optimizing our investment."
"The solution could use a different licensing model."
"Their technical support sucks."
"One issue is that we are getting a lot of false positives. We are trying to reduce them by customizing the default rules, changing thresholds, and using white-listing and black-listing. It's getting better and better as a result. But they need to build components that would reduce the false positives."
"The use cases provided by Splunk are a good starting point, but could cover many additional topics to ensure that a smaller or less experienced shop might maximize the value of an ES deployment."
"I would like additional features in different programming models with the support for writing queries in SQL or other languages, such as C#, Java, or some other type of query definitions."
 

Pricing and Cost Advice

"The tool is moderately expensive."
"Though I have no clue about the tool's actual price, I know that it is astronomical."
"Pricing is very high."
"Use conservative figures. In terms of hardware, monitored servers and also effort. The product is not cheap. But as with other products, you get what you pay for."
"We're end-of-lifeing it now. Overall, the licensing costs of BMC are a challenge for us in that they're hard costs, whereas open-source monitoring has soft costs, where it's harder to line-item."
"The only possible additional cost that I can mention, that you might not be aware of, is that it uses Oracle partitioning, if you use Oracle. There are Oracle partitioning fees that go with that."
"We did a five-year, multimillion dollar deal."
"It is a large, complex product. So, there is a commitment of manpower to deploy it, as it is not a cheap product."
"Splunk Enterprise Security is a worthwhile investment given the comprehensive range of features it offers."
"I believe there is room for improvement in reducing costs, particularly in the financial aspect, as Splunk tends to be pricier compared to other options."
"I think the price could be improved."
"The pricing is based on the volume of data fed into it, which can lead to substantial costs. This pricing model is complex and unpredictable, making cost management difficult."
"Free Splunk license for PoCs on personal machines and the ability to scale the PoC to an enterprise level app."
"The tool's pricing model is great. You can choose between workloads or volume."
"Splunk should be able to integrate with other product using the free version."
"Pricing is probably its weakest spot. As compared to some competitors, Splunk is really expensive."
report
Use our free recommendation engine to learn which IT Infrastructure Monitoring solutions are best for your needs.
841,004 professionals have used our research since 2012.
 

Comparison Review

VS
Feb 26, 2015
HP ArcSight vs. IBM QRadar vs. ​McAfee Nitro vs. Splunk vs. RSA Security vs. LogRhythm
We at Infosecnirvana.com have done several posts on SIEM. After the Dummies Guide on SIEM, we are following it up with a SIEM Product Comparison – 101 deck. So, here it is for your viewing pleasure. Let me know what you think by posting your comments below. The key products compared here are…
 

Top Industries

By visitors reading reviews
Financial Services Firm
24%
Computer Software Company
14%
Manufacturing Company
8%
Government
6%
Financial Services Firm
15%
Computer Software Company
14%
Government
8%
Manufacturing Company
8%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

What do you like most about BMC TrueSight Operations Management?
The solution provides visibility to our infrastructure, how it is, the resources we are monitoring, and quick updates when it has any problems. We have integrated it with ServiceNow to open instances.
What is your experience regarding pricing and costs for BMC TrueSight Operations Management?
Though I have no clue about the tool's actual price, I know that it is astronomical.
What needs improvement with BMC TrueSight Operations Management?
Cost is an issue with BMC TrueSight Operations Management. Though I am not responsible for the budget, I know that it is an expensive tool set when used only for event management. The tool's issue ...
What SOC product do you recommend?
For tools I’d recommend: -SIEM- LogRhythm -SOAR- Palo Alto XSOAR Doing commercial w/o both (or at least an XDR) is asking to miss details that are critical, and ending up a statistic. Also, rememb...
What is a better choice, Splunk or Azure Sentinel?
It would really depend on (1) which logs you need to ingest and (2) what are your use cases Splunk is easy for ingestion of anything, but the charge per GB/Day Indexed and it gets expensive as log ...
How does Splunk compare with Azure Monitor?
Splunk handles a high amount of data very well. We use Splunk to capture information and as an aggregator for monitoring information from different sources. Splunk is very good at alerting us if we...
 

Also Known As

ProactiveNet, TrueSight Operations Management
No data available
 

Overview

 

Sample Customers

Ensono, Transamerica, Boston Scientific, Park Place Technologies, inContact, TD Ameritrade, PNC Bank
Splunk has more than 7,000 customers spread across over 90 countries. These customers include Telenor, UniCredit, ideeli, McKenney's, Tesco, and SurveyMonkey.
Find out what your peers are saying about BMC TrueSight Operations Management vs. Splunk Enterprise Security and other solutions. Updated: May 2023.
841,004 professionals have used our research since 2012.