Try our new research platform with insights from 80,000+ expert users

Elastic Security vs Splunk Cloud Platform comparison

 

Comparison Buyer's Guide

Executive Summary
 

Categories and Ranking

Elastic Security
Average Rating
7.6
Number of Reviews
61
Ranking in other categories
Log Management (5th), Security Information and Event Management (SIEM) (5th), Endpoint Detection and Response (EDR) (16th), Security Orchestration Automation and Response (SOAR) (6th), Extended Detection and Response (XDR) (8th)
Splunk Cloud Platform
Average Rating
8.2
Number of Reviews
56
Ranking in other categories
Data Visualization (3rd), IT Alerting and Incident Management (3rd)
 

Mindshare comparison

While both are Systems Management solutions, they serve different purposes. Elastic Security is designed for Log Management and holds a mindshare of 5.0%, down 8.1% compared to last year.
Splunk Cloud Platform, on the other hand, focuses on Data Visualization, holds 0.4% mindshare, up 0.3% since last year.
Log Management
Data Visualization
 

Featured Reviews

Gajewski Marek - PeerSpot reviewer
Aug 13, 2024
Provides good anomaly detection and connectivity reporting
I use Elastic Security to aggregate all logs from different devices in one place. It works pretty well and provides one overview of everything The solution's most valuable features are anomaly detection and connectivity reporting. Elastic Security also has many automation capabilities, which can…
Raul Lapaz - PeerSpot reviewer
Aug 17, 2023
Does not require backend maintenance, is easily integrated and utilized
Splunk Cloud Platform helps us with our security incident response. The cloud security logs are integrated with all the cloud providers. The federated search feature enables us to search between Europe and the US, from one Splunk instance to another, all from a single location. This federated search simplifies how we handle data, making it easy to swiftly search for and manage information. We monitor several cloud environments and find it easy to utilize the Splunk Cloud Platform for this purpose. Each cloud provider offers its own prebuilt dashboard, or customers can create their own. The Splunk Cloud Platform offers excellent visibility into multiple environments. In the past, we utilized hybrid integrations, and they seamlessly worked right out of the box. The reporting functionality provided by the Splunk Cloud Platform resembles that of the on-premise platform. It is readily available without requiring integration or the installation of reporting visualizations. From a security standpoint, the Splunk Cloud Platform provides us with comprehensive visibility into all security logs. This enables us to implement security incident responses with great efficiency. Additionally, we have discovered that internal employees, such as product teams, are utilizing the platform as intended for various other use cases. For instance, it has proven valuable in troubleshooting performance issues and monitoring within Kubernetes. As such, we are leveraging a wide array of use cases within the company. Splunk is a highly mature software that has been in the market for many years, which greatly influenced our decision-making process. Another factor was the user-friendly nature of the latest version, making it easy to initiate. We don't require a large workforce for installing components; it's as simple as out-of-the-box. Consequently, minimal time investment is needed for training. The Splunk Cloud Platform assists us in accessing data to meet critical compliance and privacy regulations. For instance, this is particularly important for regulations such as GDPR and HIPAA. We are utilizing Splunk Cloud with a specific focus on HIPAA compliance, allocating extra attention to this aspect. In the case of GDPR, Splunk offers a range of built-in capabilities. For instance, it allows for log masking. Moreover, there are novel features available in Splunk Cloud, such as ingest actions. This feature is exceptionally useful as it enables us to mask the data before it's ingested into Splunk. Consequently, this approach ensures our adherence to compliance regulations, exemplified by GDPR. The Splunk Cloud Platform has had a significant impact on our organization's security posture. It serves as our primary visibility tool and is the main source of trust for all login activities. Without Splunk, we would lose essential visibility and access to security updates. Currently, Splunk stands as one of the primary tools we utilize due to its utmost importance.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"Elastic Security makes data communication easier."
"ELK Logstash is easy and fast, at least for the initial setup with the out of box uses."
"It's open-source and free to use."
"The most valuable feature of Elastic Security is that you can install agents, and they are not separately licensed."
"The stability of the solution is good."
"The solution's most valuable features are anomaly detection and connectivity reporting."
"The most valuable features of Elastic Security are it is open-source and provides a high level of security."
"The most valuable feature is the ability to collect authentication information from service providers."
"The most valuable feature of Splunk Cloud Platform is its flexibility and readiness because it's already prebuilt, and everything is click-to-go."
"For my purposes, I like the ability to aggregate lots of data from different sources. I like being able to report for management and being able to get alerts on thresholds being out of sync."
"I like the Cloud monitoring console feature."
"Splunk Cloud Platform's search modes are a powerful feature."
"It has definitely improved our organization by virtue of reducing the amount of overhead we would have had for those environments. Having to implement, maintain, or even update the existing stuff would have been extremely time-consuming. Splunk Cloud handles all of that for us. So it's definitely been helpful from that perspective. It's allowed them to maintain upgrades for far further than they are. Some of the hosts of that environment were still on version 7 so they could get upgraded feature parity."
"Index manager is most valuable because we do not have to bother about internal storage. It is all managed by the Splunk team."
"The ability to correlate data and then present it in a meaningful and valuable way is crucial."
"The Splunk search is powerful compared to similar solutions. We get millions of data points within seconds."
 

Cons

"The interface could be more user friendly because it is sometimes hard to deal with."
"It's a little bit of a learning curve to understand the logic of searching for things and trying to find what you're looking for in Elastic Security."
"Email notification should be done the same way as Logentries does it."
"They don't provide user authentication and authorisation features (Shield) as a part of their open-source version."
"I would like the process of retrieving archived data and viewing it in Kibana to be simplified."
"There are connectors to gather logs for Windows PCs and Linux PCs, but if we have to get the logs from Syslog then we have to do it manually, and this should be automated."
"This type of monitoring is not very mature just yet. We need more real-time information in a way that's easier to manage."
"The solution's query building is not that intuitive compared to other solutions."
"The security connection should have a seamless integration. Other than that, the way we are using it, so far, it seems quite good."
"The training models can only be accessed for 30 days, even if it is paid training."
"Splunk Cloud Platform should improve its integrations and consider multiple integrations or direct integration with other platforms like Microsoft Azure, Google Cloud, or AWS."
"Every time they launch new versions, we experience a few bugs. The most recent version had a couple of bugs in the databases. We contacted the vendor and got assistance solving these bugs, so the environment is more stable."
"It is sometimes slow. Some of that has to do with the queries themselves not being efficient, but sometimes it is slow."
"When one of my customers needs an app, and I am able to find that app on the Splunk base, I have to create a ticket and wait for five days for them to download the app into the cloud environment. That is probably one of the main things. It is painful because I have to wait to get that app in the cloud."
"They can streamline the process of creating custom apps."
"The administration could use improvement. We have to rely on support more often than we're used to."
 

Pricing and Cost Advice

"Elastic Security is free to use."
"The tool's pricing is flexible and comes at unit cost. You don't have to pay for everything."
"The solution is free."
"We are using the free, open-source version of this solution."
"It's a monthly cost with Elastic SIEM, but I am not sure of the exact cost."
"Affordable but with additional costs"
"The pricing is in the middle. I think it is not an expensive experience if we compare it with big names, for example, QRadar, and also Oxide. I think Elastic Security is quite cheap. I would rate the pricing of this solution a five out of ten."
"It is easy to deploy, easy to use, and you get everything you need to become operational with it, and have nothing further to pay unless you want the OLED plugin."
"The Splunk Cloud Platform is expensive."
"Splunk Cloud Platform is more expensive than some of its competitors, but it offers a wider range of features."
"The licensing is based on the amount of data that we send to the cloud on a daily basis."
"My company has a license for Splunk Cloud Platform. My company also has a license for Splunk Enterprise."
"Currently, we have the ingest-based license. They are offering SVC-based licenses as well, but I am not a fan of SVC-based licensing. At the end of the day, I want to predict my budget and how much I am going to pay to the vendor so that I can plan my yearly budget."
"The licensing costs depend on the state of your environment and the fees are paid on a monthly basis."
"The lack of transparency around the SVC licensing makes it difficult to explain the costs to our clients."
"I know that Splunk Cloud Platform is an expensive product."
report
Use our free recommendation engine to learn which Log Management solutions are best for your needs.
814,649 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Computer Software Company
17%
Financial Services Firm
10%
Government
10%
University
7%
Computer Software Company
26%
Financial Services Firm
13%
Educational Organization
6%
University
6%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

Datadog vs ELK: which one is good in terms of performance, cost and efficiency?
With Datadog, we have near-live visibility across our entire platform. We have seen APM metrics impacted several times lately using the dashboards we have created with Datadog; they are very good c...
What do you like most about Elastic Security?
Elastic provides the capability to index quickly due to the reverse indexes it offers. This data is crucial as it contains critical information. The reverse index allows fast data indexing because ...
What is your experience regarding pricing and costs for Elastic Security?
Compared to other tools, Elastic Security is a cheaper solution.
What do you like most about Splunk Cloud Platform?
Splunk has sped up our response and reduced the time we spend manually monitoring any logs for ticketing tools or servers. It saves us around two hours daily.
What is your experience regarding pricing and costs for Splunk Cloud Platform?
Splunk Cloud is affordable, depending on your license. I don't know how much it costs exactly, but my colleague said it depends on your licensing and which features you use.
What needs improvement with Splunk Cloud Platform?
First-time users may struggle with the user interface. When I first used Splunk, I entered my username and password. After that, we get a dashboard on the left side with apps. At the top, you can c...
 

Also Known As

Elastic SIEM, ELK Logstash
No data available
 

Learn More

 

Overview

 

Sample Customers

Texas A&M, U.S. Air Force, NuScale Power, Martin's Point Health Care
Mindtouch
Find out what your peers are saying about Elastic Security vs. Splunk Cloud Platform and other solutions. Updated: March 2023.
814,649 professionals have used our research since 2012.