Try our new research platform with insights from 80,000+ expert users

Dynatrace vs Splunk Enterprise Security comparison

 

Comparison Buyer's Guide

Executive SummaryUpdated on Sep 29, 2024
 

Categories and Ranking

Dynatrace
Ranking in Log Management
4th
Average Rating
8.8
Number of Reviews
344
Ranking in other categories
Application Performance Monitoring (APM) and Observability (2nd), Mobile APM (1st), Container Monitoring (2nd), AIOps (2nd)
Splunk Enterprise Security
Ranking in Log Management
1st
Average Rating
8.4
Number of Reviews
301
Ranking in other categories
Security Information and Event Management (SIEM) (1st), IT Operations Analytics (1st)
 

Mindshare comparison

As of November 2024, in the Log Management category, the mindshare of Dynatrace is 5.8%, down from 7.7% compared to the previous year. The mindshare of Splunk Enterprise Security is 9.4%, down from 13.6% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Log Management
 

Q&A Highlights

Miriam Tover - PeerSpot reviewer
Mar 18, 2020
 

Featured Reviews

Sathis-Kumar - PeerSpot reviewer
Nov 29, 2022
The single-agent format is easy to use and accurately captures issues
Our company uses the solution to identify performance issues. Our database is in Oracle and our user interface is Maps. The solution helps us to gather required information and manage systems.  For example, we just had a big data center issue with cluster settings, voting, and updating. The…
Avinash Gopu. - PeerSpot reviewer
Feb 1, 2024
Offers good visibility into multiple environments, significantly reduces our alert volume, and speeds up our security investigations
There are limitations with Splunk not detecting all user activity, especially on mainframes and network devices. This is because Splunk relies on agents, which cannot access certain workstations. In these cases, we have to rely on application data. For example, with mainframes, manual reports are generated and sent to Splunk, limiting visibility to what's manually reported. This lack of automation for specific platforms needs improvement from Splunk. Additionally, API access is limited for other applications that rely on API calls and requests. This requires heavy customization on Splunk's end. These are the main challenges we've encountered. Monitoring multiple cloud platforms, like Azure, GCP, and AWS, with Splunk Enterprise Security presents some challenges. While Splunk provides different connectors for each provider, consolidating data from two domains across distinct cloud environments can be complex. However, leveraging pre-built templates and Splunk's data collation capabilities can help overcome these hurdles. Despite initial difficulties, I believe Splunk can effectively address this task, earning it an eight out of ten rating for its multi-cloud monitoring capabilities. While Splunk Enterprise Security offers insider threat detection capabilities, its effectiveness could be enhanced by integrating with additional tools, such as endpoint security solutions. This integrated approach is particularly crucial for financial institutions, which often require dedicated endpoint security teams. While using multiple tools is valuable, further improvements within Splunk itself are also necessary. Considering both external integration and internal development, I would rate its current insider threat detection capabilities as three out of ten. Threat detection is where Splunk falls behind. While it offers tools, other use cases require additional work. PAM is an enterprise tool that centralizes information about users, servers, and everything else. It needs real-time monitoring, which I haven't seen in any of the companies I've worked for. They only rely on Splunk for alerting, but real-time monitoring should be handled by the endpoint security team's tools. This means there's no detection or analysis at the machine or endpoint level. Additionally, threat analysis reporting is also absent.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"Improved visibility on performance and application issues."
"It used to take a lot of time to troubleshoot. Now, we can actually see the logs anytime we want. I can just find the problem. It has improved performance from a time perspective."
"I think Dynatrace has good integration. I saw an integration with xMatters where, when there's a problem, it can kick out a message to the whomever it is, with xMatters."
"The most valuable feature is, I can quickly go to the PurePath and find the problem in the application. I can say that it provides me a way by which I can quickly find the root cause of the problem."
"Great for monitoring critical internal and public-facing applications."
"The best part of Dynatrace is that the tool is very lightweight and very easy to install."
"We spend less time on troubleshooting issues since Dynatrace proactively informs us of an impending bottle neck."
"I like the auto email alerting feature the most, as it is set up based on the application error or condition."
"Splunk helps us be more proactive. We can take predictive action to identify and block threats so that nothing harmful gets into the system."
"We can easily configure things as required in relation to our use cases."
"We have a one stop dashboard for health of some of our services where you can click in and it takes you to other dashboards that have custom near real-time metrics that show the application's health."
"The initial setup is pretty straightforward."
"In the past we used the different application to collect logs. We used SurfWatch and VMware to do so. But, we found that the Splunk has more capacity to do more in less time. They provide a aster speed to index all the events , and this is a huge asset."
"UBA, User Behavior Analytics, is a key feature."
"We can extract the metrics we want on the dashboards. We are able to react to the incidents."
"The most valuable feature is the incident dashboard, and the extensive use of correlation searches, which isn't available with a standard Splunk search package. This feature is important to me because it enables SOC analysts to do their job more efficiently and be able to investigate or mediate incidents at a faster pace."
 

Cons

"One thing I'm missing and that is the JMX from the MBeans, it's missing completely."
"Graphically, it is not good."
"One piece that we think that's missing is, there were thread names that were missing in analytical information in the Dynatrace solution, versus the AppMon solution. The AppMon solution gives you that information, and it is very helpful for connecting dots and bringing all the pieces together."
"I would like more flexible data export functions and APIs. The end user experience data is very useful to the solutions team to determine actual system usage and misuse. Flexible, easier data APIs would allow us to export the data more easily to other analytics platforms to enable this analysis as well as enable storage of this data for longer term analysis since DynaTrace only holds user data for 35 days."
"sometimes it happens that we are not able to capture things. For example, if a person is logged in from India, from the city of Mumbai, and is using a Chrome browser, and his email ID is xyz@abc.com. But what happens is, Dynatrace just fetches two pieces of the information, not all of it. Sometimes it gets it all, sometimes it doesn't."
"Dashboards and monitoring capabilities can be improved for monitoring applications in Azure. In Azure, it would be cool to be able to monitor network consumption as well as flow communication."
"We are still struggling a bit with finding an answer quickly."
"Hard to use for beginners, to setup and explore."
"There are a lot of competitive products that are doing better than what Splunk is doing on the analytics side."
"Previously, they developed custom connectors or add-ons for a lot of applications. But that number can be upgraded still. There are a lot of applications in the world that are not supported."
"Some of the terminology can be confusing, even for seasoned vets. Renaming components at this point would be a serious undertaking. However, it might be beneficial in the long run."
"The support and the pricing can be better"
"Splunk isn't appropriate for smaller companies. It's too expensive."
"The solution's case management system could be further improved to make it easier for analysts to manage cases."
"I do not have any pain points for Splunk Enterprise Security. I am still trying to learn it, but there can be more information on the education side for Splunk Enterprise Security. It would be nice if the certification path was more specific to what I use instead of being so broad."
"Over time I will have more requirements and I can foresee the solution could improve the search algorithm to run and output the data faster."
 

Pricing and Cost Advice

"Look at the product and the product features, not the price. Too often people look at the price and turn away. Dynatrace costs a little bit more than the other products I researched, but it can do far more.​"
"Its license is a bit expensive. We renew it yearly."
"Price (of the product) is a major concern for all the clients I work with."
"Purchasing through the AWS Marketplace is excellent."
"The pricing and licensing are very expensive."
"We are buying more licenses, because we are seeing more value."
"I think the pricing is at a fair value for what it is."
"It is quite costly. Dynatrace was the most expensive, compared to the other products we looked at. But it was also a lot better. If you want value for your money, Dynatrace is the way to go."
"Splunk Enterprise Security incurs a significant cost because of the amount of data we send, but we are fine with the value we're getting for that price."
"Although Splunk is an expensive product, it is designed to be utilized across your organization in order to maximize your ROI and lower your TCO."
"Splunk Enterprise Security is expensive."
"The solution is a little expensive."
"Splunk Enterprise Security is not a cheap product, but I think it is worth every dollar that you pay."
"Luckily, we come under a large federal agency, and before the pandemic, they signed a large enterprise license agreement. It worked out great and to our advantage because we are a small organization. We got a 300 gig license, and we just did not have the buying power to be able to get products cheaply. Because we all partnered together under the agency umbrella, we were able to get Splunk Enterprise Security, UBA, and ITSI for cheap. This was good considering the fact that some of these premium apps require a minimum number of users, and we do not have the number of people needed to even justify buying it."
"The licensing model can be expensive, but the value it provides is significant."
"Its pricing model can be improved."
report
Use our free recommendation engine to learn which Log Management solutions are best for your needs.
815,854 professionals have used our research since 2012.
 

Comparison Review

VS
Feb 26, 2015
HP ArcSight vs. IBM QRadar vs. ​McAfee Nitro vs. Splunk vs. RSA Security vs. LogRhythm
We at Infosecnirvana.com have done several posts on SIEM. After the Dummies Guide on SIEM, we are following it up with a SIEM Product Comparison – 101 deck. So, here it is for your viewing pleasure. Let me know what you think by posting your comments below. The key products compared here are…
 

Answers from the Community

Miriam Tover - PeerSpot reviewer
Mar 18, 2020
Mar 18, 2020
The two things are entirely different. Splunk is primarily a log collection, analysis, and visualization solution. It can collect metrics now as well. Its purpose is after the fact forensics (what happened) as a part of a problem resolution process. That problem can span the entire gamut from security, to infrastructure operations to application operations. The primary competitors to Splunk ar...
2 out of 7 answers
BH
Jun 25, 2019
The two things are entirely different. Splunk is primarily a log collection, analysis, and visualization solution. It can collect metrics now as well. Its purpose is after the fact forensics (what happened) as a part of a problem resolution process. That problem can span the entire gamut from security, to infrastructure operations to application operations. The primary competitors to Splunk are Elastic and Sumologic. Dynatrace is an Application Performance Management solution designed to automatically measure the performance of an application (or a micro-service), discover the topology and dependencies that the application relies upon, and determine if a problem is in the code or in the software and hardware infrastructure that supports the application. The key to Dynatrace's ability to do this is its real-time topology and dependency mapping engine called SmartScape. There is no similar capability in Splunk. The principal competitors to Dynatrace are AppDynamics, New Relic, and Instana. Rather than viewing these things as competitors, many companies use them together. In fact, Dynatrace has integration with Splunk, and Splunk has a Splunk App for Dynatrace up in Splunkbase. The most common use case for using them together is that Dynatrace finds the problem, determines if it is the code or not and if not determines where in the software and hardware infrastructure the problem resides. Splunk is then used to drill down into the part of the identified infrastructure to determine the exact nature of the problem (for example a security breach).
informat792312 - PeerSpot reviewer
Jun 25, 2019
Splunk and Dynatrace are two different solutions. Most organizations use both of them. Splunk can aggregate logs from Dynatrace. It also depends on what is the purpose of the usage. If you intend to measure end to end application performance and the application logs are instrumenting the metrics, then Splunk alone can do the job. It also allows you to correlate other events like firewall, network and other dependent applications/services.
 

Top Industries

By visitors reading reviews
Educational Organization
33%
Financial Services Firm
17%
Computer Software Company
8%
Manufacturing Company
6%
Financial Services Firm
16%
Computer Software Company
14%
Government
9%
Manufacturing Company
8%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

Any advice about APM solutions?
The key is to have a holistic view over the complete infrastructure, the ones you have listed are great for APM if you need to monitor applications end to end. I have tested them all and have not f...
What cloud monitoring software did you choose and why?
While the environment does matter in the selection of an APM tool, I prefer to use Dynatrace to manage the entire stack. Both production and Dev/Test. I find it to be quite superior to anything els...
Any advice about APM solutions?
There are many factors and we know little about your requirements (size of org, technology stack, management systems, the scope of implementation). Our goal was to consolidate APM and infra monitor...
What SOC product do you recommend?
For tools I’d recommend: -SIEM- LogRhythm -SOAR- Palo Alto XSOAR Doing commercial w/o both (or at least an XDR) is asking to miss details that are critical, and ending up a statistic. Also, rememb...
What is a better choice, Splunk or Azure Sentinel?
It would really depend on (1) which logs you need to ingest and (2) what are your use cases Splunk is easy for ingestion of anything, but the charge per GB/Day Indexed and it gets expensive as log ...
How does Splunk compare with Azure Monitor?
Splunk handles a high amount of data very well. We use Splunk to capture information and as an aggregator for monitoring information from different sources. Splunk is very good at alerting us if we...
 

Learn More

 

Overview

 

Sample Customers

Audi, Best Buy, LinkedIn, CISCO, Intuit, KRONOS, Scottrade, Wells Fargo, ULTA Beauty, Lenovo, Swarovsk, Nike, Whirlpool, American Express
Splunk has more than 7,000 customers spread across over 90 countries. These customers include Telenor, UniCredit, ideeli, McKenney's, Tesco, and SurveyMonkey.
Find out what your peers are saying about Dynatrace vs. Splunk Enterprise Security and other solutions. Updated: October 2024.
815,854 professionals have used our research since 2012.