Try our new research platform with insights from 80,000+ expert users

Centreon vs Splunk Enterprise Security comparison

 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Centreon
Average Rating
8.4
Reviews Sentiment
7.2
Number of Reviews
28
Ranking in other categories
Network Monitoring Software (23rd), IT Infrastructure Monitoring (22nd), Cloud Monitoring Software (18th)
Splunk Enterprise Security
Average Rating
8.4
Reviews Sentiment
7.6
Number of Reviews
304
Ranking in other categories
Log Management (1st), Security Information and Event Management (SIEM) (1st), IT Operations Analytics (1st)
 

Mindshare comparison

While both are Systems Management solutions, they serve different purposes. Centreon is designed for IT Infrastructure Monitoring and holds a mindshare of 3.0%, down 3.1% compared to last year.
Splunk Enterprise Security, on the other hand, focuses on Security Information and Event Management (SIEM), holds 9.8% mindshare, down 13.5% since last year.
IT Infrastructure Monitoring
Security Information and Event Management (SIEM)
 

Featured Reviews

Caulson Chua - PeerSpot reviewer
With fewer staff resources, we can identify and address issues before the system goes down
Centreon's most valuable features are preventative maintenance and cost-efficiency. Everything is monitored, and we get a log before the system fails. We have an opportunity to fix the issue and avoid downtime. The dashboard is user-friendly, and the solution provides good reporting and visibility. The layout is straightforward. You can click on the drop-down list to select the server you want. The anomaly detection feature helped us reduce our average resolution time by 30 minutes to an hour.
ROBERT-CHRISTIAN - PeerSpot reviewer
Has many predefined correlation rules and is brilliant for investigation and log analysis
It is very complicated to write your own correlation rules without the help of Splunk support. What Splunk could do better is to create an API to the standard SIEM tools, such as Microsoft Sentinel. The idea would be to make it less painful. In ELK Stack, Kibana is the query language with which you can search log files. I believe Splunk has also a query language in which they search their log files, but once you have identified the log file that you want to use for further security correlation, you want to very quickly transport that into your SIEM tool, such as Microsoft Sentinel. That is something that Splunk could make a little bit less painful because it is a lot of effort to find that log file and forward it. An API with Microsoft Sentinel or a similar SIEM tool would be a good idea.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"The most valuable feature is that we can manually configure everything we need. After it comes inside the interface of Centreon, you can display it. Because the interface is quite user-friendly, you can manually configure the configuration very deeply, which is very pleasant and useful because you can monitor and see everything on your service list, dashboard, or MAP. The most useful feature for me is that you can create your own plugin and monitoring query."
"Another feature we use is Business Activity, which provides us with an end-user perspective when a service is down or isn't working correctly. This is helpful when monitoring the KPIs. When we see a device or server that isn't working, we find the root cause."
"The downtimes feature is helpful. If the ISP is doing some maintenance on its network, we have the option to put downtime on the devices or the services, so we won't get any false alarms."
"You can concentrate and orchestrate several other solutions from other vendors. You can consolidate those solutions all in one place, then maintain and monitor from that single point. This creates ease of use. It is a very powerful solution from this point of view."
"What I like most about Centreon is that it is very flexible and customizable, based on the user and/or business needs. Centreon is very flexible when it comes to monitoring parameters. We can use scripts found on the internet or scripts created by our infra/apps team. Also, the data visualization features are very simple and straightforward, yet very informative."
"We are alerted on service impacts and not when something is down. We have saved a lot of time on non-business-hours intervention."
"In addition, the flexibility, customizability, and analytics of Centreon's dashboards are all very good. The dashboards help us see the whole network map, and that is quite valuable for us. In addition, the dashboards have helped to improve our visibility and ability to proactively ensure the right data is available at the right time... The flexibility has given us the ability to add in our own monitoring metrics and that has been quite interesting and very useful for us."
"It is decentralized, which is better, because you can reduce the load from a single system. Also, you get a better view because it's more independent. Then, for the management, it's nice because they have one central system. With that, they can manage all the other systems, as well. This means they don't have to configure each system by system. They can configure it from one single interface."
"The search lookups are useful."
"The solution's most valuable feature is threat intelligence correlations."
"We primarily use it to correlate logs throughout the enterprise for both searching and use in investigations."
"Splunk Enterprise Security's dashboards are a key asset."
"It's better than IBM, in my opinion, because it's an independent entity."
"I am satisfied with the support."
"Splunk is extremely flexible, which allows us to create custom visualizations along with other customizations."
"The additional vendors we've brought on board, particularly the elastic, have been quite beneficial."
 

Cons

"Currently, we have to go through all of the different templates and take a look at how the template is configured, and how specific parameters may change across different templates with different precedents, megatons, etc. It's a lot of work and involves trial and error. I wish they could simplify the process."
"Opening a ticket on the website of Centreon can be difficult for my colleague, but not for me because my English is good. However, my colleague doesn't speak English well, as our company is in Quebec and our first language is French."
"It is necessary to improve service monitoring of database services in the free version."
"Release management and quality of testing need improvement, because with each major upgrade we have many issues coming in. Then, it takes several minor upgrades to get rid of them."
"I would like to see an improvement of the communication with big data systems, because Centreon is a monitoring system. In our point of view, Centreon should be a part of a source for a big data system, not a big data system itself. So, it should be easier to add data from the Centreon system to a big data system. For example, it should be able to teach machine learning."
"I would like to see a better UI, one which is more responsive."
"Centreon is actually missing an easy way to create a trendline for the metrics. Actually it is possible to create it, but you need a good knowledge of math, Centreon, and RRD."
"This solution lacks service monitoring in the cloud."
"I have concerns about the architecture as well since I can see it is not very well defined."
"Endpoint access is the only issue I can think to mention, even though the endpoint access we have with Cisco is fine."
"Could be more user friendly."
"At Splunk .conf24, I saw a demo for Splunk Enterprise Security 8. All the things that they have done in Splunk Enterprise Security 8 are what it can be better at."
"Although the technical support is adequate, there is still room for improvement."
"It will be helpful for customers if they can create some real-world cases, and we can find a case study to align with. I know that Splunk has tremendous potential. We only include a tiny piece of it. There is a lot of stuff that we need to learn. If Splunk can provide more real-time examples, that will be helpful for customers."
"The threat management part is still lagging. There are some gaps in threat management. Other vendors have built-in threat management systems, but Splunk lacks the threat management component in its portal. The UEBA and everything else is perfect, but it lacks a unified threat intelligence and management part."
"The upgrading process could be smoother."
 

Pricing and Cost Advice

"The pricing works out well for us, given our environment and where we are."
"The pricing starts at around 5000 euro. However, this depends on: Your environment, the size of your host, how many hosts you have, how many remote pollers you have, and if you want to use the Monitoring Business Intelligence or Centreon MAP functionalities."
"It is perfect and very cheap if you are a little company or startup. After that, it is quite expensive for a big company."
"The solution is very effective, despite the low price."
"If you need basic monitoring without dashboards, just monitoring, the plugins are very useful and really cheap. If you want a more complete solution with dashboards and reporting, the EMS solution is great and it is not that much more expensive. It's a good value. Really good."
"The tool is cheaply priced."
"Centreon is always available to develop new plugins when needed. The most important thing is that their maintenance account yearly subscription fee includes the fact that they will maintain the new plugins that you requested them to deliver."
"The solution has a free part and after that threshold, you will need to pay. For example, if you believe you can create an interesting map, most of the time, you will have to pay 10,000 Euros per year for having access to these components."
"It is economical than other solutions."
"Setup cost is cheap: It is free, it is user-friendly, and it is fast."
"Be upfront about your needs and expectations. Splunk is great to work with."
"I am not personally involved with the pricing of the solution."
"It's definitely worth it."
"Our customers often complain that the price of Splunk is too high."
"It can be tough to determine if you are getting all of the value out of your investment at times."
"The variables and the flexibility that Splunk provides are helpful, especially in a hybrid and multi-cloud environment."
report
Use our free recommendation engine to learn which IT Infrastructure Monitoring solutions are best for your needs.
838,713 professionals have used our research since 2012.
 

Comparison Review

VS
Feb 26, 2015
HP ArcSight vs. IBM QRadar vs. ​McAfee Nitro vs. Splunk vs. RSA Security vs. LogRhythm
We at Infosecnirvana.com have done several posts on SIEM. After the Dummies Guide on SIEM, we are following it up with a SIEM Product Comparison – 101 deck. So, here it is for your viewing pleasure. Let me know what you think by posting your comments below. The key products compared here are…
 

Top Industries

By visitors reading reviews
Computer Software Company
19%
Government
10%
Financial Services Firm
9%
Comms Service Provider
6%
Financial Services Firm
16%
Computer Software Company
14%
Manufacturing Company
8%
Government
8%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

What do you like most about Centreon?
Centreon's most valuable features are preventative maintenance and cost-efficiency. Everything is monitored, and we get a log before the system fails. We have an opportunity to fix the issue and av...
What needs improvement with Centreon?
The issue my company has with the tool stems from the fact that it didn't give an on-time response to us. The product collects the information, but it fails to send them via SMS, WhatsApp or Telegr...
What SOC product do you recommend?
For tools I’d recommend: -SIEM- LogRhythm -SOAR- Palo Alto XSOAR Doing commercial w/o both (or at least an XDR) is asking to miss details that are critical, and ending up a statistic. Also, rememb...
What is a better choice, Splunk or Azure Sentinel?
It would really depend on (1) which logs you need to ingest and (2) what are your use cases Splunk is easy for ingestion of anything, but the charge per GB/Day Indexed and it gets expensive as log ...
How does Splunk compare with Azure Monitor?
Splunk handles a high amount of data very well. We use Splunk to capture information and as an aggregator for monitoring information from different sources. Splunk is very good at alerting us if we...
 

Overview

 

Sample Customers

Airbus, Bollore, BT, Canal Plus, Kuehne Nagel, Limagrain, LVMH, Oberthur Technologies, Orange, Darty, Addax Petroleum, Plastic Omnium, Auchan, Valeo, Saint Gobin, Clarins, Hugo Boss, JC Decaux, French Government (Defense, Justice, Environment, Agriculture), OptiComm, Thales, Zeiss.
Splunk has more than 7,000 customers spread across over 90 countries. These customers include Telenor, UniCredit, ideeli, McKenney's, Tesco, and SurveyMonkey.
Find out what your peers are saying about Zabbix, Datadog, Auvik and others in IT Infrastructure Monitoring. Updated: February 2025.
838,713 professionals have used our research since 2012.