Try our new research platform with insights from 80,000+ expert users

Cisco Provider Connectivity Assurance vs Splunk Enterprise Security comparison

 

Comparison Buyer's Guide

Executive Summary
 

Categories and Ranking

Cisco Provider Connectivity...
Average Rating
8.8
Reviews Sentiment
6.9
Number of Reviews
24
Ranking in other categories
Application Performance Monitoring (APM) and Observability (32nd), Network Monitoring Software (37th)
Splunk Enterprise Security
Average Rating
8.4
Reviews Sentiment
7.1
Number of Reviews
301
Ranking in other categories
Log Management (1st), Security Information and Event Management (SIEM) (1st), IT Operations Analytics (1st)
 

Mindshare comparison

While both are Application Lifecycle Management solutions, they serve different purposes. Cisco Provider Connectivity Assurance is designed for Application Performance Monitoring (APM) and Observability and holds a mindshare of 0.3%, down 0.4% compared to last year.
Splunk Enterprise Security, on the other hand, focuses on Security Information and Event Management (SIEM), holds 11.2% mindshare, down 15.0% since last year.
Application Performance Monitoring (APM) and Observability
Security Information and Event Management (SIEM)
 

Featured Reviews

Sylvain Germe - PeerSpot reviewer
Highly scalable, responsive support, but lacking new features
This solution is geared towards on-premise setups, and would not be useful if the company plans to move to the cloud within the next two years, such as Google Cloud for example. If the goal is to monitor bandwidth at remote sites and identify performance issues because the network is under the control, this solution is useful. However, if a company primarily uses cloud-based servers and does not manage the internet connection of its remote sites, the solution becomes less useful. I rate Accedian Skylight a seven out of ten. I have a positive opinion of the tool, but it can be challenging to set up. It is also limited in its applicability to certain use cases. I am familiar with the engineers behind the solution and have a good impression of them. However, I am not pleased with the fact that the company removed many features and raised prices after it was acquired by Accedian.
Avinash Gopu. - PeerSpot reviewer
Offers good visibility into multiple environments, significantly reduces our alert volume, and speeds up our security investigations
There are limitations with Splunk not detecting all user activity, especially on mainframes and network devices. This is because Splunk relies on agents, which cannot access certain workstations. In these cases, we have to rely on application data. For example, with mainframes, manual reports are generated and sent to Splunk, limiting visibility to what's manually reported. This lack of automation for specific platforms needs improvement from Splunk. Additionally, API access is limited for other applications that rely on API calls and requests. This requires heavy customization on Splunk's end. These are the main challenges we've encountered. Monitoring multiple cloud platforms, like Azure, GCP, and AWS, with Splunk Enterprise Security presents some challenges. While Splunk provides different connectors for each provider, consolidating data from two domains across distinct cloud environments can be complex. However, leveraging pre-built templates and Splunk's data collation capabilities can help overcome these hurdles. Despite initial difficulties, I believe Splunk can effectively address this task, earning it an eight out of ten rating for its multi-cloud monitoring capabilities. While Splunk Enterprise Security offers insider threat detection capabilities, its effectiveness could be enhanced by integrating with additional tools, such as endpoint security solutions. This integrated approach is particularly crucial for financial institutions, which often require dedicated endpoint security teams. While using multiple tools is valuable, further improvements within Splunk itself are also necessary. Considering both external integration and internal development, I would rate its current insider threat detection capabilities as three out of ten. Threat detection is where Splunk falls behind. While it offers tools, other use cases require additional work. PAM is an enterprise tool that centralizes information about users, servers, and everything else. It needs real-time monitoring, which I haven't seen in any of the companies I've worked for. They only rely on Splunk for alerting, but real-time monitoring should be handled by the endpoint security team's tools. This means there's no detection or analysis at the machine or endpoint level. Additionally, threat analysis reporting is also absent.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"Capturing traffic [is very interesting]. Currently, with our configuration, we don't capture the payload of the packets, just the header. But when we want the body, the payload of the packets, we can do a PCAP, and then analyze it within Wireshark."
"One valuable feature we have is real-time monitoring for connection issues."
"What I like most about Accedian Skylight is that it's a UI application, so using it is easy. I also like that the support for Accedian Skylight is helpful."
"For us, the most valuable feature is something called TWAMP that allows for real-time traffic in a way that is 10 times lighter than things like SolarWinds. It's in the sub-milliseconds of accuracy, and you can divide tasks so that you can literally see things like the tagging for Quality of Service. That had been incorrect with the carrier, but there was no way on this planet you'd be able to tell a carrier that they're wrong. I have dozens of scenarios where we found "No, that's not right," and got it resolved instantly."
"If [the problem] is something related to HTTP or VoIP, then I can have a quick look into the protocols, a process which gives me some good ideas..."
"It is about finding operational problems. When sites go down, we try to determine who is at fault. While there is not much finger-pointing, the solution is just trying to analyse when there is an outage and where do we start looking to fix it. The very nature of why organization chooses to use the solution is to accelerate the meantime to resolution and find where problems lie to get them rectified as quickly as possible."
"The response times, with the performance, are really interesting too, where you can see the packet loss."
"The feature I used to like the most was its ability to decode layer seven protocols, although this is becoming less useful now that encryption is so widespread."
"The ability to ingest different log types from many different products in our environment is most valuable."
"It provides a lot of analytics with the underlying AI engine, and it is a lot easier than other solutions. There are some products that do automated AI-based detection and drawing up charts, but for network monitoring and all of the monitoring aspects, it is quite a nice tool. It is very convenient for business users because they get more or less a lot of data readily available. If you're familiar with the Splunk query language, you can pretty much do whatever you want."
"Correlating data across different systems via one interface will allow you to know your environment or identify incident data in ways you never imagined."
"Our clients are easily able to modify and evolve their implementations."
"Splunk Enterprise Security's dashboards are a key asset."
"It helps streamline troubleshooting and log analysis."
"It is quite extensible. It is a platform that we can build our use instead of each case instead of each case being limited or restricted to each capability. This is probably the best feature."
"Ease of correlation, creating correlation searches are easy and you can combine multiple sources with little effort"
 

Cons

"Some of the Skylight applications are a little newer, and they're still moving through initial revs. There are certain bugs, but nothing is insurmountable... It will just take a little bit of time for their user interface to get a little bit better."
"Human resource costs can be high when dealing with connection issues."
"The Accedian Skylight user interface still has room for improvement."
"It needs the possibility to export data because it is not easy to see larger data sets, e.g., for one month. It would be interesting to export data into a PDF or dashboard to keep a history of the situation."
"Human resource costs can be high when dealing with connection issues."
"There should be an option to update and upgrade the solution to the new version without having to re-buy it. I have clients switching to other solutions. The old solution is great, but if you change your license to a new one, you have to almost re-buy it completely."
"It's a bit slow. When I execute a query, something general with a short timeframe that covers one month, for instance, and I do not specify the IP source or IP destination, it can take ages because it has to query the whole database."
"For the PVX, they are in the process of getting the results to export to cloud and SaaS for analytics. They told me that this will happen later this year. Right now, for the most part, I create that data myself."
"Some of the queries are difficult to run and have room for improvement."
"The user experience could be improved."
"When files are absent, troubleshooting becomes difficult, and performance issues inevitably arise."
"Splunk can improve regex/asset analysis as we do not want to crawl until it is done."
"Splunk does not build apps. They only go back and validate the apps that somebody has already built. They should have remote consulting support. They have a wonderful solution. They have 24/7 security. Nobody needs to depend on any third party and will therefore just buy Splunk on the cloud."
"DMC should be a little more intuitive with better dashboarding. Seeing the cause of data flow can be tough to track down."
"Most of my interaction is with the user community, which is how Splunk wants it. When I need help, that community is very hit or miss."
"I'd love to see more integrations, which is one of the primary points of the key node with Splunk Enterprise Security."
 

Pricing and Cost Advice

"If you look into Riverbed, it's a licensing nightmare. You need to pay for every type of analysis... If you don't look into licensing, Riverbed and SolarWinds are pretty comparable. But if you look into licensing it would not be smart to go for either of them. On the pure, bare-metal basis, it's the same. But when you get the bare metal and a few basic licenses, then you need all those other licenses just to be sure that there's no issue... One of the great things about Skylight is you have them all, and you actually need them all."
"The pricing is cheaper than other competing products, which is better for our budgets."
"The solution was previously well-regarded, but after being acquired by Accedian, the prices have significantly increased. This has made it challenging to sell the product due to its high cost. It is an expensive solution."
"The pricing of Accedian Skylight is really good. The sensors are low cost. Their model to analytics for sensors is by license, endpoint, or session. With the probes for their analytics, if they get deployed virtually, they are free. The licensing is only based on flows. So, you can effectively deploy probes everywhere in your network. Then, if you want to look at a specific type of traffic, you can enter into it with a very low cost license. You can just use things like spam ports, mirrors, TAPs, and aggregators to optimize what sort of traffic you send to these analysis tools. Then, if you want to start looking at more, you can up your licensed as you go. You are not getting forced into expensive appliances or subscription models."
"Pricing is a little bit expensive."
"The price is competitive overall, depending on the type of customer."
"It's not for free, clearly. But on the other hand, it offers very interesting functionality. We pay around €100,000."
"We understand there's a significant cost difference, but have yet to investigate fully."
"I think the price could be improved."
"I am not personally involved with the pricing of the solution."
"The Splunk licensing is high."
"It's a yearly subscription."
"Splunk Enterprise Security is expensive."
"The pricing depends on the bandwidth of an organization and is good compared to some SIEM tools. IBM, for example, is quite costly. But Microsoft Sentinel is notably cheaper."
"The tool's pricing model is great. You can choose between workloads or volume."
"Splunk Enterprise Security is not a cheap product, but I think it is worth every dollar that you pay."
report
Use our free recommendation engine to learn which Application Performance Monitoring (APM) and Observability solutions are best for your needs.
824,053 professionals have used our research since 2012.
 

Comparison Review

VS
Feb 26, 2015
HP ArcSight vs. IBM QRadar vs. ​McAfee Nitro vs. Splunk vs. RSA Security vs. LogRhythm
We at Infosecnirvana.com have done several posts on SIEM. After the Dummies Guide on SIEM, we are following it up with a SIEM Product Comparison – 101 deck. So, here it is for your viewing pleasure. Let me know what you think by posting your comments below. The key products compared here are…
 

Top Industries

By visitors reading reviews
Computer Software Company
39%
Financial Services Firm
10%
Government
7%
Manufacturing Company
6%
Financial Services Firm
15%
Computer Software Company
14%
Government
9%
Manufacturing Company
8%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

What do you like most about Accedian Skylight?
The feature I used to like the most was its ability to decode layer seven protocols, although this is becoming less useful now that encryption is so widespread.
What is your experience regarding pricing and costs for Accedian Skylight?
The solution was previously well-regarded, but after being acquired by Accedian, the prices have significantly increased. This has made it challenging to sell the product due to its high cost. It i...
What needs improvement with Accedian Skylight?
There should be an option to update and upgrade the solution to the new version without having to re-buy it. I have clients switching to other solutions. The old solution is great, but if you chang...
What SOC product do you recommend?
For tools I’d recommend: -SIEM- LogRhythm -SOAR- Palo Alto XSOAR Doing commercial w/o both (or at least an XDR) is asking to miss details that are critical, and ending up a statistic. Also, rememb...
What is a better choice, Splunk or Azure Sentinel?
It would really depend on (1) which logs you need to ingest and (2) what are your use cases Splunk is easy for ingestion of anything, but the charge per GB/Day Indexed and it gets expensive as log ...
How does Splunk compare with Azure Monitor?
Splunk handles a high amount of data very well. We use Splunk to capture information and as an aggregator for monitoring information from different sources. Splunk is very good at alerting us if we...
 

Also Known As

Accedian Skylight, Accedian SkyLIGHT PVX, SkyLIGHT PVX, SecurActive, Performance Vision
No data available
 

Learn More

Video not available
 

Overview

 

Sample Customers

T-Systems, Thomson Reuters, Bordeaux Metropole, CGI, Citadelle Regional Hospital Center, Lorraine Institute of Oncology, Luxembourg Institute of Health, Groupe BPCE, Group S, Splitpoint, Horus-Net, Audatex, Indexis, Province de Liège, EASI, Spie Batignolles, Faymonville
Splunk has more than 7,000 customers spread across over 90 countries. These customers include Telenor, UniCredit, ideeli, McKenney's, Tesco, and SurveyMonkey.
Find out what your peers are saying about Cisco Provider Connectivity Assurance vs. Splunk Enterprise Security and other solutions. Updated: May 2023.
824,053 professionals have used our research since 2012.