Try our new research platform with insights from 80,000+ expert users

Splunk Enterprise Security vs eG Enterprise comparison

 

Comparison Buyer's Guide

Executive Summary
 

Categories and Ranking

eG Enterprise
Average Rating
8.2
Reviews Sentiment
7.4
Number of Reviews
20
Ranking in other categories
Application Performance Monitoring (APM) and Observability (41st), Network Monitoring Software (49th), IT Infrastructure Monitoring (44th)
Splunk Enterprise Security
Average Rating
8.4
Reviews Sentiment
7.1
Number of Reviews
301
Ranking in other categories
Log Management (1st), Security Information and Event Management (SIEM) (1st), IT Operations Analytics (1st)
 

Mindshare comparison

While both are Application Lifecycle Management solutions, they serve different purposes. eG Enterprise is designed for Application Performance Monitoring (APM) and Observability and holds a mindshare of 0.2%, down 0.3% compared to last year.
Splunk Enterprise Security, on the other hand, focuses on Security Information and Event Management (SIEM), holds 11.2% mindshare, down 15.0% since last year.
Application Performance Monitoring (APM) and Observability
Security Information and Event Management (SIEM)
 

Featured Reviews

reviewer802371 - PeerSpot reviewer
Great visibility, easy to set up, and has very responsive technical support
The visibility and the ability to monitor user behavior are very useful to us. So is the fact that we have diagnostic capabilities. We divided the usage of these two parts - one for our business team and one for our support team where they can see the availability, performance, and application or service updates from a customer perspective. We appreciate that the team can understand the issue from our application, database, code, data integration, et cetera. We like that two different teams can use it and it fits each of their individual needs. Sometimes when we face issues with the new technologies or very old technologies where we cannot enhance the service, they move to work with us directly and start doing some development on this area which is very good for us. The initial setup is pretty simple. The solution can scale. Technical support has been great.
Avinash Gopu. - PeerSpot reviewer
Offers good visibility into multiple environments, significantly reduces our alert volume, and speeds up our security investigations
There are limitations with Splunk not detecting all user activity, especially on mainframes and network devices. This is because Splunk relies on agents, which cannot access certain workstations. In these cases, we have to rely on application data. For example, with mainframes, manual reports are generated and sent to Splunk, limiting visibility to what's manually reported. This lack of automation for specific platforms needs improvement from Splunk. Additionally, API access is limited for other applications that rely on API calls and requests. This requires heavy customization on Splunk's end. These are the main challenges we've encountered. Monitoring multiple cloud platforms, like Azure, GCP, and AWS, with Splunk Enterprise Security presents some challenges. While Splunk provides different connectors for each provider, consolidating data from two domains across distinct cloud environments can be complex. However, leveraging pre-built templates and Splunk's data collation capabilities can help overcome these hurdles. Despite initial difficulties, I believe Splunk can effectively address this task, earning it an eight out of ten rating for its multi-cloud monitoring capabilities. While Splunk Enterprise Security offers insider threat detection capabilities, its effectiveness could be enhanced by integrating with additional tools, such as endpoint security solutions. This integrated approach is particularly crucial for financial institutions, which often require dedicated endpoint security teams. While using multiple tools is valuable, further improvements within Splunk itself are also necessary. Considering both external integration and internal development, I would rate its current insider threat detection capabilities as three out of ten. Threat detection is where Splunk falls behind. While it offers tools, other use cases require additional work. PAM is an enterprise tool that centralizes information about users, servers, and everything else. It needs real-time monitoring, which I haven't seen in any of the companies I've worked for. They only rely on Splunk for alerting, but real-time monitoring should be handled by the endpoint security team's tools. This means there's no detection or analysis at the machine or endpoint level. Additionally, threat analysis reporting is also absent.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"What I like about eG Enterprise is that it's easy to use. It's a simple product. You can get up to seventy-five to eighty percent of the required information based on real user experience and diagnostics."
"The topology view which provides a visual representation of a service and quickly allows identification of errors or degraded performance."
"User session details"
"Its ability to monitor failures and to restart a Windows service when it fails."
"It gives good insight into inside of what's going on with Exchange."
"The product is simple to use."
"The most important feature is the ability to design, then implement monitoring tests on the fly as we are adapting to different situations."
"eG Enterprise has a single pane of glass for observability and monitoring."
"I like the ease with which dashboards can be created."
"Its dashboard is valuable. If you have a good knowledge of how to create a dashboard, you can create any dashboard related to cybersecurity. If fine-tuned, the alarms that are triggered for instant review are also very valuable and useful."
"It has quite extensive support in terms of integration. If you want to do anything, there are tools for that."
"The security part is useful as it helps secure the entire environment."
"It helps us uncover bottlenecks in the network."
"It's extremely scalable. It's a very robust solution and certainly has the capability of handling far bigger data requirements than a lot of the other tools. Generally what ends up happening with me is that my clients tend, for the most part, to be mid-tier organizations where the cost of that solutions would be accompanying requirements for people just becomes way too prohibitive. Especially considering the model that they use for costing, which is based on the volume of data. Of course, they're going to put everything including the Coke machine as the ability to collect data off of it, because of course the more they can put through the tool the more money they make."
"UBA, User Behavior Analytics, is a key feature."
"The benefits include the easy integration with other Splunk tools including Splunk UEBA, Splunk ITSI, and Splunk Core. The ease of integration and the organization's experience and familiarity with searching and passing logs through Splunk are the main benefits."
 

Cons

"The solution needs to enhance the management dashboards."
"The interface could be improved as it is not real intuitive. It is not user-friendly."
"The integration must be improved."
"Back-end configuration is not easy to implement."
"would like to see improvements in the alarm display console."
"Needs to improve the networking monitor capabilities."
"eG Enterprise's licensing could be cheaper. Even compared to Dynatrace, I think the price is quite expensive considering the APM functionalities, even though they have other benefits such as info monitoring."
"Dashboards are difficult to create, and not so useful."
"It would be nice if they had a wizard to construct searches, including more complex searches that include math or statistics."
"Most of my interaction is with the user community, which is how Splunk wants it. When I need help, that community is very hit or miss."
"Splunk can be an expensive solution. Technical support could be improved as well."
"Its reporting can be improved. That's the only complaint I have heard. I don't need the reporting part, but I know that other people in the organization need it."
"A problem that we had recently had was we licensed it based on how much data you upload to them every day. Something changed in one our applications, and it started generating three to four times as many logs and. So now, we are trying to assemble something with parts of the Splunk API to warn ourselves, then turn it off and throttle it back more. However it would be better if they had something systematically built into the product that if you're getting close to your license, then to shut things down."
"This is not really a monitoring solution."
"Splunk's ability to analyze malicious activities scores an 8 out of 10, but there's room for improvement. By analyzing emerging patterns, Splunk could identify and predict potential threats more effectively."
"We'd like to have the number of devices covered under the license to be increased."
 

Pricing and Cost Advice

"The product is very cheap."
"If using eG for virtual desktops, carefully calculate whether per named user, per concurrent user, or per server"
"The cost for eG Enterprise is almost $100,000 for one hundred and fifty services. It's subscription-based and the payment is yearly."
"They are aligned with other enterprise solutions."
"There are two licensing options: Perpetual and SaaS-based. The main offering, in terms of what eG prefers to offer, is the subscription-based rather than the Perpetual License. The price could be cheaper."
"It'd be nice if the price was lower. That would be an improvement."
"eG Enterprise is much cheaper than the other products it competes with."
"We paid about 300,000 Saudi Riyal for the solution and it was quite affordable compared to the competition."
"Setup cost is cheap: It is free, it is user-friendly, and it is fast."
"I believe there is room for improvement in reducing costs, particularly in the financial aspect, as Splunk tends to be pricier compared to other options."
"The price can always be lower, but it is fair at the moment. The cost efficiencies depend on the licensing and how much data we are bringing in. We have a fairly large footprint, so it is cost-effective."
"Splunk Enterprise Security is cheaper than competitors, but I do not know whether it is just our contract."
"Its price is fair. Like with anything else, if you go into the cloud, different providers cost more, and you are able to throttle back or throttle up. The cost is comparable with anything else."
"The pricing seems good relative to the other vendors that we have had here. However, they need to find ways to be more flexible with the licensing and be able to deal with situations where we start generating more logs. Maybe having some controls in the Splunk interface to turn it off, so we don't have to change anything in our application."
"Our ROI is high."
"I remember Splunk being relatively affordable. Kibana was more reasonable, but you get more with Splunk. If I was suggesting something, I would probably suggest Splunk because it is better to pay a little bit more and get a lot more."
report
Use our free recommendation engine to learn which Application Performance Monitoring (APM) and Observability solutions are best for your needs.
824,067 professionals have used our research since 2012.
 

Comparison Review

VS
Feb 26, 2015
HP ArcSight vs. IBM QRadar vs. ​McAfee Nitro vs. Splunk vs. RSA Security vs. LogRhythm
We at Infosecnirvana.com have done several posts on SIEM. After the Dummies Guide on SIEM, we are following it up with a SIEM Product Comparison – 101 deck. So, here it is for your viewing pleasure. Let me know what you think by posting your comments below. The key products compared here are…
 

Top Industries

By visitors reading reviews
Computer Software Company
15%
Financial Services Firm
12%
Manufacturing Company
11%
Healthcare Company
9%
Financial Services Firm
15%
Computer Software Company
14%
Government
9%
Manufacturing Company
8%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

Any advice about APM solutions?
Could you please share your requirements ? There are a lot tools can be added to the list. I spent almost 6 months to test and check many tools then I select eG enterprise.
Do you recommend eG Enterprise? Why or why not?
I feel that eG Enterprise is one of the top APM tools available on the market. Out of the solutions I have tried, it is the best for monitoring, diagnosis, analytics, and reporting of key IT servic...
What do you like most about eG Enterprise?
eG Enterprise has a single pane of glass for observability and monitoring.
What SOC product do you recommend?
For tools I’d recommend: -SIEM- LogRhythm -SOAR- Palo Alto XSOAR Doing commercial w/o both (or at least an XDR) is asking to miss details that are critical, and ending up a statistic. Also, rememb...
What is a better choice, Splunk or Azure Sentinel?
It would really depend on (1) which logs you need to ingest and (2) what are your use cases Splunk is easy for ingestion of anything, but the charge per GB/Day Indexed and it gets expensive as log ...
How does Splunk compare with Azure Monitor?
Splunk handles a high amount of data very well. We use Splunk to capture information and as an aggregator for monitoring information from different sources. Splunk is very good at alerting us if we...
 

Overview

 

Sample Customers

20th Century Fox, Allscripts, Anthem Blue Cross and Blue Shield, Aviva, AXA, Biogen, Cox Communications, Denver Health, eBay, JP Morgan Chase, PayPal, Southern California Edison, Samsung, and many more.
Splunk has more than 7,000 customers spread across over 90 countries. These customers include Telenor, UniCredit, ideeli, McKenney's, Tesco, and SurveyMonkey.
Find out what your peers are saying about Splunk Enterprise Security vs. eG Enterprise and other solutions. Updated: May 2023.
824,067 professionals have used our research since 2012.