Splunk Enterprise Security and Elastic Observability compete in the realms of security and observability. Elastic Observability appears to have the upper hand owing to cost-effectiveness and user-friendly features.
Features: Splunk Enterprise Security is known for its comprehensive data analytics, alerting, and correlation capabilities. It handles vast amounts of data and provides robust security insights. Elastic Observability offers real-time monitoring, centralized logging, and seamless integration with other Elastic products. It is favored for its ease of use and lower learning curve.
Room for Improvement: Splunk Enterprise Security could improve in speed and performance with large datasets and could benefit from a more intuitive search language. Elastic Observability users point out the need for better visualization options and a more robust alerting system. Specific areas like visualization need attention in Elastic Observability.
Ease of Deployment and Customer Service: Splunk Enterprise Security's deployment is complex and time-consuming, requiring extensive support during setup. However, users report high satisfaction with customer service once deployed. Elastic Observability has a smoother and more straightforward deployment process. Users find the customer service responsive but occasionally lacking in-depth technical support.
Pricing and ROI: Splunk Enterprise Security faces criticism for high setup costs and ongoing expenses, impacting perceived ROI. Some users believe its advanced features justify the price. Elastic Observability is praised for its affordable pricing model and faster ROI, providing excellent value for the investment.
For smaller organizations, other products may provide better value for money.
If you want to write your own correlation rules, it is very difficult to do, and you need Splunk's support to write new correlation rules for the SIEM tool.
The technical support for Splunk met my expectations.
Elastic Observability seems to have a good scale-out capability.
What is not scalable for us is not on Elastic's side.
They struggle a bit with pure virtual environments, but in terms of how much they can handle, it is pretty good.
It is very stable, and I would rate it ten out of ten based on my interaction with it.
Elastic Observability is really stable.
It provides a stable environment but needs to integrate with ITSM platforms to achieve better visibility.
It is very stable.
One example is the inability to monitor very old databases with the newest version.
Elastic Observability could improve asset discovery as the current requirement to push the agent is not ideal.
An API with Microsoft Sentinel or a similar SIEM tool would be a good idea.
Splunk Enterprise Security would benefit from a more robust rule engine to reduce false positives.
The license is reasonably priced, however, the VMs where we host the solution are extremely expensive, making the overall cost in the public cloud high.
Elastic Observability is cost-efficient and provides all features in the enterprise license without asset-based licensing.
I saw clients spend two million dollars a year just feeding data into the Splunk solution.
Splunk is priced higher than other solutions.
The most valuable feature is the integrated platform that allows customers to start from observability and expand into other areas like security, EDR solutions, etc.
All the features that we use, such as monitoring, dashboarding, reporting, the possibility of alerting, and the way we index the data, are important.
The Splunk Enterprise Security's threat-hunting capabilities have been particularly useful in later releases.
They have approximately 50,000 predefined correlation rules.
Elastic Observability is primarily used for monitoring login events, application performance, and infrastructure, supporting significant data volumes through features like log aggregation, centralized logging, and system metric analysis.
Elastic Observability employs Elastic APM for performance and latency analysis, significantly aiding business KPIs and technical stability. It is popular among users for system and server monitoring, capacity planning, cyber security, and managing data pipelines. With the integration of Kibana, it offers robust visualization, reporting, and incident response capabilities through rapid log searches while supporting machine learning and hybrid cloud environments.
What are Elastic Observability's key features?Companies in technology, finance, healthcare, and other industries implement Elastic Observability for tailored monitoring solutions. They find its integration with existing systems useful for maintaining operation efficiency and security, particularly valuing the visualization capabilities through Kibana to monitor KPIs and improve incident response times.
Splunk Enterprise Security is widely used for security operations, including threat detection, incident response, and log monitoring. It centralizes log management, offers security analytics, and ensures compliance, enhancing the overall security posture of organizations.
Companies leverage Splunk Enterprise Security to monitor endpoints, networks, and users, detecting anomalies, brute force attacks, and unauthorized access. They use it for fraud detection, machine learning, and real-time alerts within their SOCs. The platform enhances visibility and correlates data from multiple sources to identify security threats efficiently. Key features include comprehensive dashboards, excellent reporting capabilities, robust log aggregation, and flexible data ingestion. Users appreciate its SIEM capabilities, threat intelligence, risk-based alerting, and correlation searches. Highly scalable and stable, it suits multi-cloud environments, reducing alert volumes and speeding up investigations.
What are the key features?Splunk Enterprise Security is implemented across industries like finance, healthcare, and retail. Financial institutions use it for fraud detection and compliance, while healthcare organizations leverage its capabilities to safeguard patient data. Retailers deploy it to protect customer information and ensure secure transactions.
We monitor all Log Management reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.