Try our new research platform with insights from 80,000+ expert users

Centreon vs Splunk Enterprise Security comparison

 

Comparison Buyer's Guide

Executive Summary
 

Categories and Ranking

Centreon
Average Rating
8.4
Number of Reviews
28
Ranking in other categories
Network Monitoring Software (15th), IT Infrastructure Monitoring (14th), Cloud Monitoring Software (14th)
Splunk Enterprise Security
Average Rating
8.4
Number of Reviews
301
Ranking in other categories
Log Management (1st), Security Information and Event Management (SIEM) (1st), IT Operations Analytics (1st)
 

Mindshare comparison

While both are Systems Management solutions, they serve different purposes. Centreon is designed for IT Infrastructure Monitoring and holds a mindshare of 3.2%, down 3.4% compared to last year.
Splunk Enterprise Security, on the other hand, focuses on Security Information and Event Management (SIEM), holds 10.9% mindshare, down 14.3% since last year.
IT Infrastructure Monitoring
Security Information and Event Management (SIEM)
 

Featured Reviews

Caulson Chua - PeerSpot reviewer
Jun 9, 2023
With fewer staff resources, we can identify and address issues before the system goes down
We're a software solutions provider using Centreon to monitor a client's database, application, and web servers. The system sends an email alert when something goes wrong.  Currently, we only have one customer using Centreon. Our client is a global automobile manufacturer headquartered in Europe…
Sameep Agarwal. - PeerSpot reviewer
Oct 23, 2023
It has a drag-and-drop interface, so you don't need to know SQL or Java to construct a query
The ingestion happens quickly, so you can run up the data costs if you use the default settings. It isn't a problem for government agencies in the Saudi market, but many of the corporations in India are small or medium-sized enterprises that cannot afford that kind of ingestion system. Splunk needs to be tweaked in JSON so you can limit what is coming from the endpoints, especially the events. One needs to filter that out so that only certain events are ingested, like login failures, Active Directory changes, password reset requests, privilege modifications, etc. Each Windows machine generates about 310 KB of information per event, but we can tweak that down to about 50 KB.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"In addition, the flexibility, customizability, and analytics of Centreon's dashboards are all very good. The dashboards help us see the whole network map, and that is quite valuable for us. In addition, the dashboards have helped to improve our visibility and ability to proactively ensure the right data is available at the right time... The flexibility has given us the ability to add in our own monitoring metrics and that has been quite interesting and very useful for us."
"The single-pane view provides us a view of all of our network infrastructure, and it is one of the most important tools that we use to see the status of our customers' networks."
"It is decentralized, which is better, because you can reduce the load from a single system. Also, you get a better view because it's more independent. Then, for the management, it's nice because they have one central system. With that, they can manage all the other systems, as well. This means they don't have to configure each system by system. They can configure it from one single interface."
"The product is available in ISO image format, ready for deployment. Centreon also has a comprehensive guide and documentation that are simple and easy to follow."
"The downtimes feature is helpful. If the ISP is doing some maintenance on its network, we have the option to put downtime on the devices or the services, so we won't get any false alarms."
"Valuable features include the ability to schedule downtime, intensity or depth of monitoring which it does, different plugin packs, Centreon MAP, Centreon BI."
"What we like about it is that, whereas with Nagios, by design, if you have five or six data centers, you have to open five or six web pages to see what's going on, In Centreon, this is all included in one page, a single site, one dashboard. You don't have to jump from one specific dashboard to the other."
"The most valuable feature is that we can manually configure everything we need. After it comes inside the interface of Centreon, you can display it. Because the interface is quite user-friendly, you can manually configure the configuration very deeply, which is very pleasant and useful because you can monitor and see everything on your service list, dashboard, or MAP. The most useful feature for me is that you can create your own plugin and monitoring query."
"Great platform with user-friendly interface and GUI."
"The additional vendors we've brought on board, particularly the elastic, have been quite beneficial."
"The most valuable feature is the custom dashboard feature."
"The flexibility of the solution is quite good."
"The solution is stable and reliable."
"The search function for spam is like a google search. You just enter and it will quickly show you the results."
"We did not encounter any issues with scalability. It is almost seamless to add new index (storage) or search (used to analyze the data) nodes to the cluster."
"The correlation search functions that generate all the notables are valuable. That can get pretty complicated, and it handles that pretty well."
 

Cons

"During the initial setup we faced some issues. Part of it was because we had to become more knowledgeable in the solution. There are some gray areas and if you don't know the product well you may have issues. Another part of it was some bugs that we came across, although that's part of every software solution in IT nowadays. But the initial setup could be easier."
"Currently, we have to go through all of the different templates and take a look at how the template is configured, and how specific parameters may change across different templates with different precedents, megatons, etc. It's a lot of work and involves trial and error. I wish they could simplify the process."
"I went through a few things with them to do with Centreon MAP, to do with active polygons, being able to draw an area and make that active. The functionality was in the older version of Centreon MAP and in the new version, which was a complete rewrite, they dropped it."
"The reporting has room for improvement."
"The problem with the reporting is you have to configure the report, and after that, you will have the same report every month, every week, every day. You have to sync it in order to have a great report."
"This solution lacks service monitoring in the cloud."
"Centreon supports officially 10,000 services per poller. That is not much for larger customers, because this limit is reached very quickly. We use it with three times the limit without any problems, but Centreon says, "Okay, we are only supporting it with 10,000 services." We are aware that increasing the limit has different impacts because they need to support it. However, for most customers, it would be be very good if they could increase the limit of services."
"It is necessary to improve service monitoring of database services in the free version."
"Being able to have a one-stop shop where you have the alert, but then you can generate the case right there from Splunk Enterprise Security instead of having to pivot to another tool such as Mission Control. You do not have to keep bouncing between them, so if you could do it all in one place, that would be great. The new release is supposed to start getting in that direction."
"Better directions on search head clusters."
"Its pricing is extremely high. There are other tools out in the market that are competitive. They do not necessarily have all the functionality, but they are competitive. The professional services we have used have been high as well in comparison to the market."
"Its interface and usability can always be improved."
"Splunk's reporting functionality would benefit from enhanced customization capabilities, allowing users to tailor reports to their specific needs for better data visualization and analysis."
"Its performance can be better. Sometimes, it takes longer when we do queries."
"Splunk's high cost, despite its recognition in our region, prevents many organizations from adopting Splunk Enterprise Security, suggesting there's room for improvement in their pricing strategy."
"When you get into large amounts of data, Splunk can get pretty slow. This is the same on-premise or AWS, it doesn't matter. The way that they handle large data sets could be improved."
 

Pricing and Cost Advice

"The pricing works out well for us, given our environment and where we are."
"It's quite expensive when you use the Enterprise version, but if you compare it to other providers, it's more like a middle-of-the-line product. It's always good to have a price that is lower, but I would say the price is okay because we get very good support and if we have any other issues we can always contact them. There has never been a time when I didn't get help from them."
"Their licensing model is really easy. You have one license and you have access to all the features, compared to other tools where you have to purchase add-ons."
"The pricing is acceptable."
"If you need basic monitoring without dashboards, just monitoring, the plugins are very useful and really cheap. If you want a more complete solution with dashboards and reporting, the EMS solution is great and it is not that much more expensive. It's a good value. Really good."
"The pricing starts at around 5000 euro. However, this depends on: Your environment, the size of your host, how many hosts you have, how many remote pollers you have, and if you want to use the Monitoring Business Intelligence or Centreon MAP functionalities."
"For more complex tasks, we use prepaid support days and ask Centreon to come onsite."
"The solution is very effective, despite the low price."
"Splunk Enterprise Security is not at all cost-friendly to be deployed in very small enterprises like start-ups."
"The price of Splunk Enterprise Security is high."
"I assume that the pricing is reasonable, because if it was too costly, there are other alternatives."
"The price can always be lower, but it is fair at the moment. The cost efficiencies depend on the licensing and how much data we are bringing in. We have a fairly large footprint, so it is cost-effective."
"We have an unlimited one, and we pay yearly, but I don't know how much it costs. Previously, I worked for a startup, and when they started building it up, it was complicated for them because they didn't have the budget for that many licenses. It was very costly for them. So, startups might find it a little bit problematic because of the licensing, but for bigger companies, there is no issue."
"The pricing can be better. We are already considering Elastic because Splunk is too expensive. You have to pay based on per-day ingestion. There should be a more flexible model for the use cases where one day you have a huge amount, and on other days, it is quite less."
"Pricing is pretty fair."
"It is quite expensive."
report
Use our free recommendation engine to learn which IT Infrastructure Monitoring solutions are best for your needs.
814,649 professionals have used our research since 2012.
 

Comparison Review

VS
Feb 26, 2015
HP ArcSight vs. IBM QRadar vs. ​McAfee Nitro vs. Splunk vs. RSA Security vs. LogRhythm
We at Infosecnirvana.com have done several posts on SIEM. After the Dummies Guide on SIEM, we are following it up with a SIEM Product Comparison – 101 deck. So, here it is for your viewing pleasure. Let me know what you think by posting your comments below. The key products compared here are…
 

Top Industries

By visitors reading reviews
Computer Software Company
19%
Government
11%
Financial Services Firm
9%
Manufacturing Company
7%
Financial Services Firm
16%
Computer Software Company
14%
Government
9%
Manufacturing Company
8%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

What do you like most about Centreon?
Centreon's most valuable features are preventative maintenance and cost-efficiency. Everything is monitored, and we get a log before the system fails. We have an opportunity to fix the issue and av...
What needs improvement with Centreon?
The issue my company has with the tool stems from the fact that it didn't give an on-time response to us. The product collects the information, but it fails to send them via SMS, WhatsApp or Telegr...
What SOC product do you recommend?
For tools I’d recommend: -SIEM- LogRhythm -SOAR- Palo Alto XSOAR Doing commercial w/o both (or at least an XDR) is asking to miss details that are critical, and ending up a statistic. Also, rememb...
What is a better choice, Splunk or Azure Sentinel?
It would really depend on (1) which logs you need to ingest and (2) what are your use cases Splunk is easy for ingestion of anything, but the charge per GB/Day Indexed and it gets expensive as log ...
How does Splunk compare with Azure Monitor?
Splunk handles a high amount of data very well. We use Splunk to capture information and as an aggregator for monitoring information from different sources. Splunk is very good at alerting us if we...
 

Learn More

 

Overview

 

Sample Customers

Airbus, Bollore, BT, Canal Plus, Kuehne Nagel, Limagrain, LVMH, Oberthur Technologies, Orange, Darty, Addax Petroleum, Plastic Omnium, Auchan, Valeo, Saint Gobin, Clarins, Hugo Boss, JC Decaux, French Government (Defense, Justice, Environment, Agriculture), OptiComm, Thales, Zeiss.
Splunk has more than 7,000 customers spread across over 90 countries. These customers include Telenor, UniCredit, ideeli, McKenney's, Tesco, and SurveyMonkey.
Find out what your peers are saying about Zabbix, Datadog, Auvik and others in IT Infrastructure Monitoring. Updated: October 2024.
814,649 professionals have used our research since 2012.