Try our new research platform with insights from 80,000+ expert users

Everbridge IT Alerting vs Splunk Enterprise Security comparison

 

Comparison Buyer's Guide

Executive Summary
 

Categories and Ranking

Everbridge IT Alerting
Average Rating
8.8
Number of Reviews
23
Ranking in other categories
IT Alerting and Incident Management (8th)
Splunk Enterprise Security
Average Rating
8.4
Reviews Sentiment
7.1
Number of Reviews
303
Ranking in other categories
Log Management (1st), Security Information and Event Management (SIEM) (1st), IT Operations Analytics (1st)
 

Mindshare comparison

While both are Systems Management solutions, they serve different purposes. Everbridge IT Alerting is designed for IT Alerting and Incident Management and holds a mindshare of 14.5%, up 9.0% compared to last year.
Splunk Enterprise Security, on the other hand, focuses on Security Information and Event Management (SIEM), holds 11.2% mindshare, down 15.0% since last year.
IT Alerting and Incident Management
Security Information and Event Management (SIEM)
 

Featured Reviews

CQ
We have seen substantial savings with its usage as it drives down our MTTR
The automated escalations are the most valuable feature. We program in our escalation chains for each individual IT group. Being able to go out and request a resource from that team, and if they don't respond, that automated escalation makes it very hands off. So, our major incident managers and our network operations center can focus more on the other work that they need to do rather than chasing down those resources. They can rest assured that somebody will be answering. Another valuable feature is the ease of integration into our ServiceNow platform, where we are doing all of our work between two teams. They are able to make requests from within the tickets that we can manage rather than having to use another portal or logging into Everbridge directly. Reliability is their biggest value.
Avinash Gopu. - PeerSpot reviewer
Offers good visibility into multiple environments, significantly reduces our alert volume, and speeds up our security investigations
There are limitations with Splunk not detecting all user activity, especially on mainframes and network devices. This is because Splunk relies on agents, which cannot access certain workstations. In these cases, we have to rely on application data. For example, with mainframes, manual reports are generated and sent to Splunk, limiting visibility to what's manually reported. This lack of automation for specific platforms needs improvement from Splunk. Additionally, API access is limited for other applications that rely on API calls and requests. This requires heavy customization on Splunk's end. These are the main challenges we've encountered. Monitoring multiple cloud platforms, like Azure, GCP, and AWS, with Splunk Enterprise Security presents some challenges. While Splunk provides different connectors for each provider, consolidating data from two domains across distinct cloud environments can be complex. However, leveraging pre-built templates and Splunk's data collation capabilities can help overcome these hurdles. Despite initial difficulties, I believe Splunk can effectively address this task, earning it an eight out of ten rating for its multi-cloud monitoring capabilities. While Splunk Enterprise Security offers insider threat detection capabilities, its effectiveness could be enhanced by integrating with additional tools, such as endpoint security solutions. This integrated approach is particularly crucial for financial institutions, which often require dedicated endpoint security teams. While using multiple tools is valuable, further improvements within Splunk itself are also necessary. Considering both external integration and internal development, I would rate its current insider threat detection capabilities as three out of ten. Threat detection is where Splunk falls behind. While it offers tools, other use cases require additional work. PAM is an enterprise tool that centralizes information about users, servers, and everything else. It needs real-time monitoring, which I haven't seen in any of the companies I've worked for. They only rely on Splunk for alerting, but real-time monitoring should be handled by the endpoint security team's tools. This means there's no detection or analysis at the machine or endpoint level. Additionally, threat analysis reporting is also absent.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"We have been able to use it to track and verify that people are on the bridge."
"The most important feature, from our perspective, is the integration with our ticketing system. That eliminates wasted motion and time in drafting and sending and finding the right distribution list."
"You can program in rotations, shifts, and scenarios of different kinds and it allows you to page multiple people, or people in sequence, or a group of people simultaneously."
"A robust solution with multiple modules that can be leveraged."
"Our performance showed us that, for major incidents, we spent over 40 minutes just making manual call-outs. That is why we implement the tool in the first place and that time has been cut down to two or three minutes."
"The post mortem reports are descriptive, indicating who joined the call and when."
"The system has a lot of great features and they keep adding to it."
"The most valuable feature is automated escalation, as it eliminates a manual process which is prone to errors."
"Search language is easy to understand and teach to new users."
"The data representation options in the dashboards are excellent."
"The ability to ingest different log types from many different products in our environment is most valuable."
"Its huge, versatile AppBase helped me to configure and bring data from different sources to a unified platform."
"The most valuable feature of Splunk Enterprise Security is the comprehensive logging capabilities it provides."
"They have approximately 50,000 predefined correlation rules, which is quite a lot, and I find that good."
"Splunk Enterprise Security helped us with faster detection of threats."
"The additional vendors we've brought on board, particularly the elastic, have been quite beneficial."
 

Cons

"Lacks ability to customize messages."
"The ability to not have to worry about the IT alerting and calendar resources. I would like it to be simpler in the sense of a different cost structure."
"I would like to have a little bit more flexibility in the member portal."
"An ability to get to the database that houses our information would be great. Currently, we are at the mercy of Everbridge and, if they do not have the function built, we cannot gather the information that we would like."
"A key area for improvement - and I think they are working towards these things - is analytics. If I want to do sophisticated reporting and analysis of the data that's being captured in IT Alerting, at the moment, the reporting interface is immature."
"Explanations are limited to 500 characters in description fields."
"What I would like to see is vendor alerting. It's not structured to take into account that users outside of our environment, users outside of IT, may not be in the group. IBM is an outside vendor for us, and we have IBM CEs who come in on a regular basis. If there's a problem, we call those vendors in. That should be tied into the system where we can say that vendors A, B, and C have these users and we want them available to come into the office when there's an issue. We want to be able to alert them in the same way we alert internally."
"An incident management feature would be nice because, as it stands now, you select different items when you're filling out a form to launch a notification. If those were more conditional it would help. Right now it just puts out whatever you put into the form, whereas, if you could specify a "yes" or "no" and it would input a different verbiage, that would be nice to have, instead of having to spell out all the verbiage."
"A lot of people are averse to using new tools so if they make it even more user-friendly than it already is, I think that could go a long way."
"It's costly."
"We had some connections issues with the solution at the beginning."
"The configuration had a bit of a learning curve."
"Splunk Enterprise Security would benefit from a more robust rule engine to reduce false positives."
"Splunk could add more ways to manage archiving and storage. There isn't a web interface. You can do this on the SaaS version, but the on-premise platform doesn't have this option. It has other things but no option for remote NAS. I would like to have a personal web interface where I can specify how long logs should be stored. To have this readily available on the web, you need to adjust some settings on the backend. That is tricky."
"The complexity could be worked on so that it's even easier and faster."
"The monitoring aspect of Splunk could be improved. We have to do some queries to get as much information as CrowdStrike or other solutions provide. If you run a big query, you will see a delay. That is the only concern we have because it will take some time if you query large data sets."
 

Pricing and Cost Advice

"As far as I'm aware, there are no costs beyond the standard licensing fees."
"We thought the base product was pretty reasonable. It can pricey once you start adding stuff on."
"The current pricing model is adequate. We feel that the pricing model for our IT Alerting solution is competitive with similar solutions on the market."
"When we did our contract, we did a three year contract with fixed pricing. We locked in the pricing for three years. As we have grown, we locked in pricing for additional units of employees."
"The annual cost is $125,000 USD. That is for everything. It includes the 11,000 mass notifications. Technically, we have 500 licenses for IT Alerting."
"The pricing was under $25 a month per user. We had about 1,000 defined users."
"It's a seven out of ten for us in terms of pricing. We've just gone through a process of looking at other solutions."
"The end result is that we have driven down our MTTR by an average of about 45 minutes across all major outages. That is very substantial considering the cost of every minute of outage can be thousands of dollars lost."
"The licensing costs are high for Splunk Enterprise Security."
"In terms of pricing, I believe Splunk is unreasonably costly for the majority of mid and small-sized companies."
"Its pricing model can be improved."
"Splunk Enterprise Security is a worthwhile investment given the comprehensive range of features it offers."
"Splunk should be able to integrate with other product using the free version."
"It would be nice if the pricing were cheaper. However, we did purchase it."
"Splunk Enterprise Security is priced lower than competitors."
"Splunk Enterprise Security is an expensive solution."
report
Use our free recommendation engine to learn which IT Alerting and Incident Management solutions are best for your needs.
824,067 professionals have used our research since 2012.
 

Comparison Review

VS
Feb 26, 2015
HP ArcSight vs. IBM QRadar vs. ​McAfee Nitro vs. Splunk vs. RSA Security vs. LogRhythm
We at Infosecnirvana.com have done several posts on SIEM. After the Dummies Guide on SIEM, we are following it up with a SIEM Product Comparison – 101 deck. So, here it is for your viewing pleasure. Let me know what you think by posting your comments below. The key products compared here are…
 

Top Industries

By visitors reading reviews
Computer Software Company
17%
Financial Services Firm
12%
Government
10%
Healthcare Company
9%
Financial Services Firm
15%
Computer Software Company
14%
Government
9%
Manufacturing Company
8%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

What do you like most about Everbridge IT Alerting?
It's mainly for mass notification and pooling of contacts. Pooling of customers is valuable.
What needs improvement with Everbridge IT Alerting?
The solution's non-targeted communication with external parties could be enhanced.
What SOC product do you recommend?
For tools I’d recommend: -SIEM- LogRhythm -SOAR- Palo Alto XSOAR Doing commercial w/o both (or at least an XDR) is asking to miss details that are critical, and ending up a statistic. Also, rememb...
What is a better choice, Splunk or Azure Sentinel?
It would really depend on (1) which logs you need to ingest and (2) what are your use cases Splunk is easy for ingestion of anything, but the charge per GB/Day Indexed and it gets expensive as log ...
How does Splunk compare with Azure Monitor?
Splunk handles a high amount of data very well. We use Splunk to capture information and as an aggregator for monitoring information from different sources. Splunk is very good at alerting us if we...
 

Learn More

 

Overview

 

Sample Customers

Choice Hotels, Alexion, Navy Federal Credit Union, EastWest Bank, IBM, Core Logic, Paypal, Charter Communications, Lowes, Express Scripts, Finastra, Worldpay
Splunk has more than 7,000 customers spread across over 90 countries. These customers include Telenor, UniCredit, ideeli, McKenney's, Tesco, and SurveyMonkey.
Find out what your peers are saying about PagerDuty, Atlassian, Splunk and others in IT Alerting and Incident Management. Updated: November 2024.
824,067 professionals have used our research since 2012.