Try our new research platform with insights from 80,000+ expert users

Cisco Provider Connectivity Assurance vs Splunk Enterprise Security comparison

 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Cisco Provider Connectivity...
Average Rating
8.8
Reviews Sentiment
6.9
Number of Reviews
24
Ranking in other categories
Application Performance Monitoring (APM) and Observability (34th), Network Monitoring Software (36th)
Splunk Enterprise Security
Average Rating
8.4
Reviews Sentiment
7.6
Number of Reviews
303
Ranking in other categories
Log Management (1st), Security Information and Event Management (SIEM) (1st), IT Operations Analytics (1st)
 

Mindshare comparison

While both are Application Lifecycle Management solutions, they serve different purposes. Cisco Provider Connectivity Assurance is designed for Application Performance Monitoring (APM) and Observability and holds a mindshare of 0.3%, down 0.4% compared to last year.
Splunk Enterprise Security, on the other hand, focuses on Security Information and Event Management (SIEM), holds 10.8% mindshare, down 14.6% since last year.
Application Performance Monitoring (APM) and Observability
Security Information and Event Management (SIEM)
 

Featured Reviews

Sylvain Germe - PeerSpot reviewer
Highly scalable, responsive support, but lacking new features
This solution is geared towards on-premise setups, and would not be useful if the company plans to move to the cloud within the next two years, such as Google Cloud for example. If the goal is to monitor bandwidth at remote sites and identify performance issues because the network is under the control, this solution is useful. However, if a company primarily uses cloud-based servers and does not manage the internet connection of its remote sites, the solution becomes less useful. I rate Accedian Skylight a seven out of ten. I have a positive opinion of the tool, but it can be challenging to set up. It is also limited in its applicability to certain use cases. I am familiar with the engineers behind the solution and have a good impression of them. However, I am not pleased with the fact that the company removed many features and raised prices after it was acquired by Accedian.
ROBERT-CHRISTIAN - PeerSpot reviewer
Has many predefined correlation rules and is brilliant for investigation and log analysis
It is very complicated to write your own correlation rules without the help of Splunk support. What Splunk could do better is to create an API to the standard SIEM tools, such as Microsoft Sentinel. The idea would be to make it less painful. In ELK Stack, Kibana is the query language with which you can search log files. I believe Splunk has also a query language in which they search their log files, but once you have identified the log file that you want to use for further security correlation, you want to very quickly transport that into your SIEM tool, such as Microsoft Sentinel. That is something that Splunk could make a little bit less painful because it is a lot of effort to find that log file and forward it. An API with Microsoft Sentinel or a similar SIEM tool would be a good idea.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"It is about finding operational problems. When sites go down, we try to determine who is at fault. While there is not much finger-pointing, the solution is just trying to analyse when there is an outage and where do we start looking to fix it. The very nature of why organization chooses to use the solution is to accelerate the meantime to resolution and find where problems lie to get them rectified as quickly as possible."
"For us, the most valuable feature is something called TWAMP that allows for real-time traffic in a way that is 10 times lighter than things like SolarWinds. It's in the sub-milliseconds of accuracy, and you can divide tasks so that you can literally see things like the tagging for Quality of Service. That had been incorrect with the carrier, but there was no way on this planet you'd be able to tell a carrier that they're wrong. I have dozens of scenarios where we found "No, that's not right," and got it resolved instantly."
"The ability to measure performance end-to-end across the cloud data center allows us to take corrective action to keep our channels online."
"Capturing traffic [is very interesting]. Currently, with our configuration, we don't capture the payload of the packets, just the header. But when we want the body, the payload of the packets, we can do a PCAP, and then analyze it within Wireshark."
"One valuable feature we have is real-time monitoring for connection issues."
"What I like most about Accedian Skylight is that it's a UI application, so using it is easy. I also like that the support for Accedian Skylight is helpful."
"One valuable feature we have is real-time monitoring for connection issues."
"I always have the Skylight dashboard on one of my screens... Now you can create your own dashboard, specific to an application, specific to a server, or to something else."
"The product is good, it satisfies our customers."
"The most valuable feature is the ability to look at threats and link them to the MITRE ATT&CK framework."
"The initial setup is pretty straightforward."
"We did not encounter any issues with scalability. It is almost seamless to add new index (storage) or search (used to analyze the data) nodes to the cluster."
"It has a drag-and-drop interface, so you don't need to know SQL or Java to construct a query on Splunk. The resolution time is about the same, but it took longer to discover the issue with ArcSight. Our previous solution took about an hour or more, but Splunk can do it within a few minutes or an hour at most."
"It's very flexible. If you look from the cloud implementation it is there. Reports are made quickly. Unlike other tools, it caters to all kinds of technical information on the front very easily. There's no need to put in any technical information. You can pull on the reports very easily, take action, and notify stakeholders."
"We can do things in minutes instead of days."
"The solution is very fast and succinct."
 

Cons

"It needs the possibility to export data because it is not easy to see larger data sets, e.g., for one month. It would be interesting to export data into a PDF or dashboard to keep a history of the situation."
"Human resource costs can be high when dealing with connection issues."
"I would like to see some improvements in parts of their synthetic transactions, which includes all the latency, jitter, and throughput. I would like to see some Layer 7 analytics in there. I want to be able to do a DNS request, HTTP GET request, or even SIP call point-to-point or via registration."
"Human resource costs can be high when dealing with connection issues."
"This solution is expensive compared to some others."
"The Accedian Skylight user interface still has room for improvement."
"For the PVX, they are in the process of getting the results to export to cloud and SaaS for analytics. They told me that this will happen later this year. Right now, for the most part, I create that data myself."
"Some of the Skylight applications are a little newer, and they're still moving through initial revs. There are certain bugs, but nothing is insurmountable... It will just take a little bit of time for their user interface to get a little bit better."
"Integrating tools and creating use cases could be easier. It's hard for a junior security engineer with only a couple of years of experience to write use cases. They can do it, but it's much easier in a solution like IBM QRadar. Setting conditions is like a multiple-choice type of thing. It's a more user-friendly process."
"If you have to do your own stuff, such as customized charts, it is a little bit more work, but once you're familiar with the Splunk query language, you can pretty much do whatever you want. In terms of features, it should probably have the features that other competitors provide."
"The Enterprise Security app could be improved. We have had trouble with it working from the first day."
"For on-premise, it's more about optimization. With such a heavy byte scale of data that we are operating on, the search for disparate data sometimes takes about a minute. This is understandable considering the amount of data that we are pumping into it. The only optimization that I recommend is better sharding, when it comes to Splunk, so that data retrieval can be faster."
"Resource usage can probably be described as an area with shortcomings in the product where improvements are required."
"If possible, we would like to have not only a log monitoring system but a network monitoring feature in this solution as well."
"It's missing some features that other solutions have, such as the ability to upgrade the endpoint and perform endpoint universal forwarders from a deployment server instead of using a third-party solution, such as Puppet or Ansible."
"Its interface and usability can always be improved."
 

Pricing and Cost Advice

"The pricing of Accedian Skylight is really good. The sensors are low cost. Their model to analytics for sensors is by license, endpoint, or session. With the probes for their analytics, if they get deployed virtually, they are free. The licensing is only based on flows. So, you can effectively deploy probes everywhere in your network. Then, if you want to look at a specific type of traffic, you can enter into it with a very low cost license. You can just use things like spam ports, mirrors, TAPs, and aggregators to optimize what sort of traffic you send to these analysis tools. Then, if you want to start looking at more, you can up your licensed as you go. You are not getting forced into expensive appliances or subscription models."
"The pricing is cheaper than other competing products, which is better for our budgets."
"The solution was previously well-regarded, but after being acquired by Accedian, the prices have significantly increased. This has made it challenging to sell the product due to its high cost. It is an expensive solution."
"If you look into Riverbed, it's a licensing nightmare. You need to pay for every type of analysis... If you don't look into licensing, Riverbed and SolarWinds are pretty comparable. But if you look into licensing it would not be smart to go for either of them. On the pure, bare-metal basis, it's the same. But when you get the bare metal and a few basic licenses, then you need all those other licenses just to be sure that there's no issue... One of the great things about Skylight is you have them all, and you actually need them all."
"We understand there's a significant cost difference, but have yet to investigate fully."
"It provides value and the cost is not huge."
"The price is competitive overall, depending on the type of customer."
"It's not for free, clearly. But on the other hand, it offers very interesting functionality. We pay around €100,000."
"I think that most of the log analytics solutions are expensive and I'm not sure if it's worth it."
"Splunk is expensive based on our current requirements, but it's obviously worth what we pay."
"The variables and the flexibility that Splunk provides are helpful, especially in a hybrid and multi-cloud environment."
"Our customers often complain that the price of Splunk is too high."
"I think that most of the monitoring solutions are expensive."
"Splunk Enterprise Security is expensive."
"I remember Splunk being relatively affordable. Kibana was more reasonable, but you get more with Splunk. If I was suggesting something, I would probably suggest Splunk because it is better to pay a little bit more and get a lot more."
"Most people share the same thought that the ingestion rates can get pretty pricey. There is a lot of work we do to curate the data that we send to Splunk so that it is not too noisy or too expensive."
report
Use our free recommendation engine to learn which Application Performance Monitoring (APM) and Observability solutions are best for your needs.
831,265 professionals have used our research since 2012.
 

Comparison Review

VS
Feb 26, 2015
HP ArcSight vs. IBM QRadar vs. ​McAfee Nitro vs. Splunk vs. RSA Security vs. LogRhythm
We at Infosecnirvana.com have done several posts on SIEM. After the Dummies Guide on SIEM, we are following it up with a SIEM Product Comparison – 101 deck. So, here it is for your viewing pleasure. Let me know what you think by posting your comments below. The key products compared here are…
 

Top Industries

By visitors reading reviews
Computer Software Company
40%
Financial Services Firm
10%
Government
6%
Manufacturing Company
6%
Financial Services Firm
15%
Computer Software Company
14%
Manufacturing Company
9%
Government
9%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

What do you like most about Accedian Skylight?
The feature I used to like the most was its ability to decode layer seven protocols, although this is becoming less useful now that encryption is so widespread.
What is your experience regarding pricing and costs for Accedian Skylight?
The solution was previously well-regarded, but after being acquired by Accedian, the prices have significantly increased. This has made it challenging to sell the product due to its high cost. It i...
What needs improvement with Accedian Skylight?
Human resource costs can be high when dealing with connection issues. I require more tools to file and resolve these issues efficiently.
What SOC product do you recommend?
For tools I’d recommend: -SIEM- LogRhythm -SOAR- Palo Alto XSOAR Doing commercial w/o both (or at least an XDR) is asking to miss details that are critical, and ending up a statistic. Also, rememb...
What is a better choice, Splunk or Azure Sentinel?
It would really depend on (1) which logs you need to ingest and (2) what are your use cases Splunk is easy for ingestion of anything, but the charge per GB/Day Indexed and it gets expensive as log ...
How does Splunk compare with Azure Monitor?
Splunk handles a high amount of data very well. We use Splunk to capture information and as an aggregator for monitoring information from different sources. Splunk is very good at alerting us if we...
 

Also Known As

Accedian Skylight, Accedian SkyLIGHT PVX, SkyLIGHT PVX, SecurActive, Performance Vision
No data available
 

Learn More

Video not available
 

Overview

 

Sample Customers

T-Systems, Thomson Reuters, Bordeaux Metropole, CGI, Citadelle Regional Hospital Center, Lorraine Institute of Oncology, Luxembourg Institute of Health, Groupe BPCE, Group S, Splitpoint, Horus-Net, Audatex, Indexis, Province de Liège, EASI, Spie Batignolles, Faymonville
Splunk has more than 7,000 customers spread across over 90 countries. These customers include Telenor, UniCredit, ideeli, McKenney's, Tesco, and SurveyMonkey.
Find out what your peers are saying about Cisco Provider Connectivity Assurance vs. Splunk Enterprise Security and other solutions. Updated: May 2023.
831,265 professionals have used our research since 2012.