Try our new research platform with insights from 80,000+ expert users

Elastic Observability vs Splunk Enterprise Security comparison

 

Comparison Buyer's Guide

Executive SummaryUpdated on Sep 29, 2024

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

ROI

Sentiment score
7.1
Elastic Observability enhances efficiency by reducing incidents and costs, with 50% time savings and improved data manageability.
Sentiment score
7.2
Splunk Enterprise Security cuts costs and boosts efficiency with automation, threat response, and real-time insights, enhancing user satisfaction.
For smaller organizations, other products may provide better value for money.
 

Customer Service

Sentiment score
7.9
Elastic Observability's customer service is praised for responsiveness, support resources, and comprehensive documentation, with stable system reducing support needs.
Sentiment score
6.7
Splunk Enterprise Security's customer service is praised for knowledgeable support but needs improvement in response times and consistency.
If you want to write your own correlation rules, it is very difficult to do, and you need Splunk's support to write new correlation rules for the SIEM tool.
The technical support for Splunk met my expectations.
 

Scalability Issues

Sentiment score
7.1
Elastic Observability offers strong scalability, receiving positive ratings, with improved performance in higher subscription tiers and cloud installations.
Sentiment score
7.7
Splunk Enterprise Security scales effectively, handling large data volumes and diverse environments, though costs may increase with scalability.
Elastic Observability seems to have a good scale-out capability.
What is not scalable for us is not on Elastic's side.
They struggle a bit with pure virtual environments, but in terms of how much they can handle, it is pretty good.
 

Stability Issues

Sentiment score
8.2
Elastic Observability is highly stable and dependable, with fast performance and positive user feedback across diverse environments.
Sentiment score
7.9
Splunk Enterprise Security is stable and reliable, but proper setup and careful capacity planning are crucial for optimal performance.
It is very stable, and I would rate it ten out of ten based on my interaction with it.
Elastic Observability is really stable.
It provides a stable environment but needs to integrate with ITSM platforms to achieve better visibility.
It is very stable.
 

Room For Improvement

Elastic Observability requires automation, improved metrics, advanced features, and better interfaces to address scalability, customization, and cost management challenges.
Splunk Enterprise Security needs better setup, integration, documentation, interfaces, access controls, data management, and pricing flexibility for improved user experience.
One example is the inability to monitor very old databases with the newest version.
Elastic Observability could improve asset discovery as the current requirement to push the agent is not ideal.
An API with Microsoft Sentinel or a similar SIEM tool would be a good idea.
Splunk Enterprise Security would benefit from a more robust rule engine to reduce false positives.
 

Setup Cost

Elastic Observability is cost-efficient for large enterprises but can be pricey for startups, with varied deployment pricing options.
Splunk Enterprise Security's cost is seen as high, prompting calls for flexible pricing to suit different budgets and needs.
The license is reasonably priced, however, the VMs where we host the solution are extremely expensive, making the overall cost in the public cloud high.
Elastic Observability is cost-efficient and provides all features in the enterprise license without asset-based licensing.
I saw clients spend two million dollars a year just feeding data into the Splunk solution.
Splunk is priced higher than other solutions.
 

Valuable Features

Elastic Observability offers cost-effective, scalable logging with machine learning, customization, and seamless Kibana integration for robust monitoring and security.
Splunk Enterprise Security offers robust data analysis, real-time alerts, and machine learning, enhancing threat detection and incident response.
The most valuable feature is the integrated platform that allows customers to start from observability and expand into other areas like security, EDR solutions, etc.
All the features that we use, such as monitoring, dashboarding, reporting, the possibility of alerting, and the way we index the data, are important.
The Splunk Enterprise Security's threat-hunting capabilities have been particularly useful in later releases.
They have approximately 50,000 predefined correlation rules.
 

Categories and Ranking

Elastic Observability
Ranking in Log Management
12th
Average Rating
8.0
Reviews Sentiment
6.9
Number of Reviews
26
Ranking in other categories
Application Performance Monitoring (APM) and Observability (7th), IT Infrastructure Monitoring (7th), Container Monitoring (4th), Cloud Monitoring Software (7th)
Splunk Enterprise Security
Ranking in Log Management
1st
Average Rating
8.4
Reviews Sentiment
7.6
Number of Reviews
303
Ranking in other categories
Security Information and Event Management (SIEM) (1st), IT Operations Analytics (1st)
 

Mindshare comparison

As of January 2025, in the Log Management category, the mindshare of Elastic Observability is 1.9%, down from 2.2% compared to the previous year. The mindshare of Splunk Enterprise Security is 8.7%, down from 12.8% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Log Management
 

Featured Reviews

Adelina Craciun - PeerSpot reviewer
Customization enables tailored monitoring and alerting across departments
The possibility to customize it has been quite useful. Whatever the other departments want to dream up, we implement. Whatever they want to monitor, the granularity of it, the changes in the threshold, and the anomalies that they want reported all require some development. So far, every single request has been fulfilled.
Avinash Gopu. - PeerSpot reviewer
Offers good visibility into multiple environments, significantly reduces our alert volume, and speeds up our security investigations
There are limitations with Splunk not detecting all user activity, especially on mainframes and network devices. This is because Splunk relies on agents, which cannot access certain workstations. In these cases, we have to rely on application data. For example, with mainframes, manual reports are generated and sent to Splunk, limiting visibility to what's manually reported. This lack of automation for specific platforms needs improvement from Splunk. Additionally, API access is limited for other applications that rely on API calls and requests. This requires heavy customization on Splunk's end. These are the main challenges we've encountered. Monitoring multiple cloud platforms, like Azure, GCP, and AWS, with Splunk Enterprise Security presents some challenges. While Splunk provides different connectors for each provider, consolidating data from two domains across distinct cloud environments can be complex. However, leveraging pre-built templates and Splunk's data collation capabilities can help overcome these hurdles. Despite initial difficulties, I believe Splunk can effectively address this task, earning it an eight out of ten rating for its multi-cloud monitoring capabilities. While Splunk Enterprise Security offers insider threat detection capabilities, its effectiveness could be enhanced by integrating with additional tools, such as endpoint security solutions. This integrated approach is particularly crucial for financial institutions, which often require dedicated endpoint security teams. While using multiple tools is valuable, further improvements within Splunk itself are also necessary. Considering both external integration and internal development, I would rate its current insider threat detection capabilities as three out of ten. Threat detection is where Splunk falls behind. While it offers tools, other use cases require additional work. PAM is an enterprise tool that centralizes information about users, servers, and everything else. It needs real-time monitoring, which I haven't seen in any of the companies I've worked for. They only rely on Splunk for alerting, but real-time monitoring should be handled by the endpoint security team's tools. This means there's no detection or analysis at the machine or endpoint level. Additionally, threat analysis reporting is also absent.
report
Use our free recommendation engine to learn which Log Management solutions are best for your needs.
825,399 professionals have used our research since 2012.
 

Comparison Review

VS
Feb 26, 2015
HP ArcSight vs. IBM QRadar vs. ​McAfee Nitro vs. Splunk vs. RSA Security vs. LogRhythm
We at Infosecnirvana.com have done several posts on SIEM. After the Dummies Guide on SIEM, we are following it up with a SIEM Product Comparison – 101 deck. So, here it is for your viewing pleasure. Let me know what you think by posting your comments below. The key products compared here are…
 

Top Industries

By visitors reading reviews
Financial Services Firm
22%
Computer Software Company
15%
Manufacturing Company
8%
Government
6%
Financial Services Firm
15%
Computer Software Company
14%
Government
9%
Manufacturing Company
8%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

What do you like most about Elastic Observability?
Elastic Observability significantly improves incident response time by providing quick access to logs and data across various sources. For instance, searching for specific keywords in logs spanning...
What is your experience regarding pricing and costs for Elastic Observability?
Elastic Observability is cost-efficient and provides all features in the enterprise license without asset-based licensing. However, sizing and licensing information could be clearer.
What needs improvement with Elastic Observability?
Elastic Observability could improve asset discovery as the current requirement to push the agent is not ideal. Simplifying the parsing of logs and manual efforts would also be beneficial.
What SOC product do you recommend?
For tools I’d recommend: -SIEM- LogRhythm -SOAR- Palo Alto XSOAR Doing commercial w/o both (or at least an XDR) is asking to miss details that are critical, and ending up a statistic. Also, rememb...
What is a better choice, Splunk or Azure Sentinel?
It would really depend on (1) which logs you need to ingest and (2) what are your use cases Splunk is easy for ingestion of anything, but the charge per GB/Day Indexed and it gets expensive as log ...
How does Splunk compare with Azure Monitor?
Splunk handles a high amount of data very well. We use Splunk to capture information and as an aggregator for monitoring information from different sources. Splunk is very good at alerting us if we...
 

Learn More

 

Overview

 

Sample Customers

PSCU, Entel, VITAS, Mimecast, Barrett Steel, Butterfield Bank
Splunk has more than 7,000 customers spread across over 90 countries. These customers include Telenor, UniCredit, ideeli, McKenney's, Tesco, and SurveyMonkey.
Find out what your peers are saying about Elastic Observability vs. Splunk Enterprise Security and other solutions. Updated: December 2024.
825,399 professionals have used our research since 2012.