Try our new research platform with insights from 80,000+ expert users

BMC TrueSight Operations Management vs Splunk Enterprise Security comparison

 

Comparison Buyer's Guide

Executive Summary
 

Categories and Ranking

BMC TrueSight Operations Ma...
Average Rating
8.2
Reviews Sentiment
6.6
Number of Reviews
50
Ranking in other categories
Application Performance Monitoring (APM) and Observability (20th), Event Monitoring (2nd), IT Infrastructure Monitoring (16th), Cloud Monitoring Software (18th), AIOps (7th)
Splunk Enterprise Security
Average Rating
8.4
Reviews Sentiment
7.6
Number of Reviews
303
Ranking in other categories
Log Management (1st), Security Information and Event Management (SIEM) (1st), IT Operations Analytics (1st)
 

Mindshare comparison

While both are Application Lifecycle Management solutions, they serve different purposes. BMC TrueSight Operations Management is designed for IT Infrastructure Monitoring and holds a mindshare of 0.9%, down 1.4% compared to last year.
Splunk Enterprise Security, on the other hand, focuses on Security Information and Event Management (SIEM), holds 10.8% mindshare, down 14.6% since last year.
IT Infrastructure Monitoring
Security Information and Event Management (SIEM)
 

Featured Reviews

Srri G - PeerSpot reviewer
The product is reasonably priced, but the solution is a little obsolete because it is deployed on-premise
If I want custom monitoring across a very large estate of more than 50,000 units, the on-premise deployment gets quite slow. The on-premise product’s performance must be improved. The solution is a little obsolete. That is why the solution moved to Helix, a SaaS operating system. The SaaS platform has the features I like. There is no point in BMC expanding TrueSight Operations’ console. It's high time that BMC starts a demise path for the product and is associated only with Helix. If we need any additional function, we must switch to Helix. Since TrueSight is deployed on-premise, the scalability and usage of the product are mainly focused on providing basic features and not enhanced features like analytics or cost analysis. People should move to a SaaS platform because on-premise products have limited storage and capacity.
Avinash Gopu. - PeerSpot reviewer
Offers good visibility into multiple environments, significantly reduces our alert volume, and speeds up our security investigations
There are limitations with Splunk not detecting all user activity, especially on mainframes and network devices. This is because Splunk relies on agents, which cannot access certain workstations. In these cases, we have to rely on application data. For example, with mainframes, manual reports are generated and sent to Splunk, limiting visibility to what's manually reported. This lack of automation for specific platforms needs improvement from Splunk. Additionally, API access is limited for other applications that rely on API calls and requests. This requires heavy customization on Splunk's end. These are the main challenges we've encountered. Monitoring multiple cloud platforms, like Azure, GCP, and AWS, with Splunk Enterprise Security presents some challenges. While Splunk provides different connectors for each provider, consolidating data from two domains across distinct cloud environments can be complex. However, leveraging pre-built templates and Splunk's data collation capabilities can help overcome these hurdles. Despite initial difficulties, I believe Splunk can effectively address this task, earning it an eight out of ten rating for its multi-cloud monitoring capabilities. While Splunk Enterprise Security offers insider threat detection capabilities, its effectiveness could be enhanced by integrating with additional tools, such as endpoint security solutions. This integrated approach is particularly crucial for financial institutions, which often require dedicated endpoint security teams. While using multiple tools is valuable, further improvements within Splunk itself are also necessary. Considering both external integration and internal development, I would rate its current insider threat detection capabilities as three out of ten. Threat detection is where Splunk falls behind. While it offers tools, other use cases require additional work. PAM is an enterprise tool that centralizes information about users, servers, and everything else. It needs real-time monitoring, which I haven't seen in any of the companies I've worked for. They only rely on Splunk for alerting, but real-time monitoring should be handled by the endpoint security team's tools. This means there's no detection or analysis at the machine or endpoint level. Additionally, threat analysis reporting is also absent.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"The solution has a very good business event manager tool."
"Helix Innovation Studio is a very good feature. It allows us to develop our own enterprise applications and make them available for the customers."
"The tailoring of the knowledge modules has been particularly useful as I can streamline the agents to only report on critical events."
"The solution's event management capabilities are fantastic. We do a best of breed. If, on the network side, they use a different tool, we pull all that data in so that we have a single console. It's kind of like the monitor of monitors. We're able to aggregate all the different types of data sets, whether it's log data, app data, OS data, infrastructure data, or network data. We're able to aggregate all those events and then correlate and be able to say we're having an event."
"The most valuable features of the solution are alert management, alert generation, and event management."
"The ability to pull hosts together to show what processes are running, so it can be used for change management."
"It is a very stable product."
"We can verify uptimes as another source of keeping devices in compliance."
"It is a very stable solution. I never really had a hiccup with the tool."
"The tool helps with advanced reports and keeps the system scalable and flexible. It provides a clear picture of the current status of any incidents. As a CISO, I see a lot of potential for future innovation, which is interesting. I've noticed better performance, especially with the reports."
"The speed of the search engine"
"The log aggregation is great."
"We have a one stop dashboard for health of some of our services where you can click in and it takes you to other dashboards that have custom near real-time metrics that show the application's health."
"Splunk Enterprise Security offers valuable features like seamless integration and a SQL-standard Structured Query Language for easy searching."
"The alerts are very effective."
"It provides logs in one place, so they are easy to find. It collects the logs from multiple places, then you have just one place where you see the whole flow from the front-end to the back-end."
 

Cons

"The product must provide application or service monitoring features."
"The UI for the end users could be improved and more flexible than it is now."
"The solution could improve its price."
"It's too complex, too many servers are required, there are too many different components in the solution, and a lot of agents are required."
"The sizing (which is difficult), the maintenance of it and the upgrade paths. This is a difficult area which is not easy to cover, as every client has a different approach of implementing the product."
"The product must provide more AI capabilities."
"We were somewhat limited in TrueSight due to some of the RBAC controls not quite being what we wanted as far as delegating out administrative privileges for implementation. But because we were able to turn requests around pretty well, that burden wasn't too heavy."
"The stability of BMC TrueSight Operations Management needs improvement. My organization's infrastructure is vast and implemented based on BMC recommendations, but the solution needs to be optimized for large-capacity infrastructure."
"Splunk Enterprise Security can be improved by including backup network detection and response and safe management to the paid platform."
"While Splunkbase (the app repository) has a lot of great content, some apps are terribly old and could stand to be updated or purged."
"The documentation is in definite need of improvement."
"Delays in responses from the technical team can pose challenges for both vendors and clients, especially considering that Splunk applications and machine solutions are critical assets."
"You can run a script from an event, but it needs many clicks to run that integration, which could be made easier."
"We were inundated with the amount of alerts and alarms that we could get out of it. It is also a resource hog and we didn't have the resources to support it on-prem so we're taking it offline now."
"This is a costly solution."
"More training on PetaData using artificial intelligence techniques to identify the events which are not normal and exceptions that would help the organization identify threats and malware on the go with results."
 

Pricing and Cost Advice

"Use conservative figures. In terms of hardware, monitored servers and also effort. The product is not cheap. But as with other products, you get what you pay for."
"The cost depends on the usage."
"Annual licensing amount depends on the customers requirements. Support is an additional fee and there are options for three and five year support."
"There is a big upfront cost when you buy the license, then there is annual maintenance. We look at, if I bought a license and paid for maintenance for five years, then average it out, what would be my monthly cost. We have had some of the competing tools come in around four dollars. This is coming in as a premium, which is why I don't have it deployed as I would like it. Therefore, we're in negotiations right now. If I can get it down to the four dollar range, I will triple my deployment in a year and a half."
"Though I have no clue about the tool's actual price, I know that it is astronomical."
"The solutions are not the cheapest but are robust and stable. License model is rather complex and BMC do often change the model."
"BMC TrueSight Operations Management is not on the cheaper side, but its pricing is on a case by case basis. Its licensing model is simple and based on the number of devices."
"Pricing is all volume-driven. I think we were paying between $80 and $85 per license. That's per unit, for a perpetual license. You pay it one time and then, every year, you pay 20 percent of that for annual maintenance and support. But now that we've grown, we've purchased tens of thousands of licenses and the cost per license has gone down to something like less than $30..."
"We have an unlimited one, and we pay yearly, but I don't know how much it costs. Previously, I worked for a startup, and when they started building it up, it was complicated for them because they didn't have the budget for that many licenses. It was very costly for them. So, startups might find it a little bit problematic because of the licensing, but for bigger companies, there is no issue."
"Luckily, we come under a large federal agency, and before the pandemic, they signed a large enterprise license agreement. It worked out great and to our advantage because we are a small organization. We got a 300 gig license, and we just did not have the buying power to be able to get products cheaply. Because we all partnered together under the agency umbrella, we were able to get Splunk Enterprise Security, UBA, and ITSI for cheap. This was good considering the fact that some of these premium apps require a minimum number of users, and we do not have the number of people needed to even justify buying it."
"Splunk has always been on the expensive side."
"I remember Splunk being relatively affordable. Kibana was more reasonable, but you get more with Splunk. If I was suggesting something, I would probably suggest Splunk because it is better to pay a little bit more and get a lot more."
"I think that most of the monitoring solutions are expensive."
"Splunk is costly but it’s worth it due to the high-end features."
"The license for Splunk Enterprise Security is expensive."
"The licensing costs are high for Splunk Enterprise Security."
report
Use our free recommendation engine to learn which IT Infrastructure Monitoring solutions are best for your needs.
825,399 professionals have used our research since 2012.
 

Comparison Review

VS
Feb 26, 2015
HP ArcSight vs. IBM QRadar vs. ​McAfee Nitro vs. Splunk vs. RSA Security vs. LogRhythm
We at Infosecnirvana.com have done several posts on SIEM. After the Dummies Guide on SIEM, we are following it up with a SIEM Product Comparison – 101 deck. So, here it is for your viewing pleasure. Let me know what you think by posting your comments below. The key products compared here are…
 

Top Industries

By visitors reading reviews
Financial Services Firm
25%
Computer Software Company
14%
Manufacturing Company
7%
Energy/Utilities Company
6%
Financial Services Firm
15%
Computer Software Company
14%
Government
9%
Manufacturing Company
8%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

What do you like most about BMC TrueSight Operations Management?
The solution provides visibility to our infrastructure, how it is, the resources we are monitoring, and quick updates when it has any problems. We have integrated it with ServiceNow to open instances.
What is your experience regarding pricing and costs for BMC TrueSight Operations Management?
Though I have no clue about the tool's actual price, I know that it is astronomical.
What needs improvement with BMC TrueSight Operations Management?
Cost is an issue with BMC TrueSight Operations Management. Though I am not responsible for the budget, I know that it is an expensive tool set when used only for event management. The tool's issue ...
What SOC product do you recommend?
For tools I’d recommend: -SIEM- LogRhythm -SOAR- Palo Alto XSOAR Doing commercial w/o both (or at least an XDR) is asking to miss details that are critical, and ending up a statistic. Also, rememb...
What is a better choice, Splunk or Azure Sentinel?
It would really depend on (1) which logs you need to ingest and (2) what are your use cases Splunk is easy for ingestion of anything, but the charge per GB/Day Indexed and it gets expensive as log ...
How does Splunk compare with Azure Monitor?
Splunk handles a high amount of data very well. We use Splunk to capture information and as an aggregator for monitoring information from different sources. Splunk is very good at alerting us if we...
 

Also Known As

ProactiveNet, TrueSight Operations Management
No data available
 

Learn More

 

Overview

 

Sample Customers

Ensono, Transamerica, Boston Scientific, Park Place Technologies, inContact, TD Ameritrade, PNC Bank
Splunk has more than 7,000 customers spread across over 90 countries. These customers include Telenor, UniCredit, ideeli, McKenney's, Tesco, and SurveyMonkey.
Find out what your peers are saying about BMC TrueSight Operations Management vs. Splunk Enterprise Security and other solutions. Updated: May 2023.
825,399 professionals have used our research since 2012.