Try our new research platform with insights from 80,000+ expert users

Grafana Loki vs Splunk Enterprise Security comparison

 

Comparison Buyer's Guide

Executive SummaryUpdated on Jul 13, 2025

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Grafana Loki
Ranking in Log Management
4th
Average Rating
8.2
Reviews Sentiment
7.8
Number of Reviews
18
Ranking in other categories
No ranking in other categories
Splunk Enterprise Security
Ranking in Log Management
2nd
Average Rating
8.4
Reviews Sentiment
7.4
Number of Reviews
366
Ranking in other categories
Security Information and Event Management (SIEM) (1st), IT Operations Analytics (1st)
 

Mindshare comparison

As of September 2025, in the Log Management category, the mindshare of Grafana Loki is 8.1%, up from 6.1% compared to the previous year. The mindshare of Splunk Enterprise Security is 7.6%, down from 9.3% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Log Management Market Share Distribution
ProductMarket Share (%)
Splunk Enterprise Security7.6%
Grafana Loki8.1%
Other84.3%
Log Management
 

Featured Reviews

Volodymyr Bondarchuk - PeerSpot reviewer
Integrations enhance monitoring but problem-solving proves challenging
Different types of integrations with various sources are the most helpful and useful features of Grafana Loki that I found for myself. As part of Kubernetes technology, I noticed benefits from using this product such as availability, configuration balancing, high availability solutions for high performance, and failover clustering. It provides a clear picture about the state of the system and gives needed information for taking action and quickly fixing problems.
Kyle Vernham - PeerSpot reviewer
Built-in searches and unified data access streamline alert investigation and boosts analyst efficiency
The two features I appreciate the most in Splunk Enterprise Security are the built-in searches, which have been very easy for us to get started with right out of the box, and the fact that it accesses all of our other systems. You can access it as a pane of glass rather than having to search individually. We also have the option to compare our analysts from our service to service. Splunk Enterprise Security helps our SOC team prioritize and investigate high-fidelity alerts more effectively by providing a more in-depth look and the ability to access a lot more of our data. Instead of jumping from several segmented systems, it allows us to have everything brought together in one place. For example, you have to move from our purview to our build system and to Splunk Enterprise Security, and it enables us to streamline that process. The built-in features of Splunk Enterprise Security, which we recently procured, have given us a good starting point and demonstrated the value of the product, providing an easy way to sell it to our company. The ease of getting everything into our purview helps us, and it serves as a good start for the investigation part in one location rather than what we usually have, which is jumping from system to system to system. Splunk Enterprise Security plays a role in our company's strategy to combat insider threats and advanced persistent threats by currently being in its technical test phase. We are still rolling it out, and it should help us find any insider threats based on information that our policy states should not be present in our system. Splunk Enterprise Security's risk-based alerting (RBA) has impacted our alert volume and analyst productivity because we've got many different systems feeding into it. However, it has helped to make it easier for our analysts to go through a set of events rather than 100 alerts. RBA allows us to streamline the process and customize it for our analysts. When it comes to leveraging Splunk Enterprise Security's dashboards and visualizations to communicate security posture to executives, it's pretty straightforward for any type of information. The visualization is easy to understand, but I haven't had any direct conversations with our executives.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"Different types of integrations with various sources are the most helpful and useful features of Grafana Loki that I found for myself."
"The solution's stability has never been a problem. Stability-wise, I rate the solution a nine to ten out of ten."
"The most valuable feature of Grafana Loki is the dashboards which are really simple to create."
"Loki significantly saves time in troubleshooting by quickly pinpointing network issues."
"I appreciate the capability to process logs from microservices and seamlessly integrate them into Grafana."
"The best feature of Grafana Loki is that it integrates well with our other tool."
"We are using Grafana Loki as a database for real-time metrics."
"The log collection feature is good and the solution is easily understandable. v"
"Being able to aggregate detection and alerts from various sources is valuable. Like everyone else, we have a wide range of tools in our shop. We are able to stop at one spot and look at all the data. All the data is able to come through, and we can then jump from source to source or index to index. We can dig deep whenever we need to and get a good high-level understanding."
"Splunk Enterprise Security's value lies in its ability to collect and analyze security logs, providing insightful dashboards."
"Splunk Enterprise Security has helped improve my organization's business resilience, as we were able to detect an attack that was happening after hours and prevent it thanks to the detections."
"The most valuable features of Splunk Enterprise Security are reporting capabilities. It is a good tool for checking systems and analyzing situations. I find it useful to check my systems and analyze situations."
"The scalability of the solution is amazing because it can collect a lot of data and you can have your own structure to monitor this data."
"It's great for finding anonymous threats."
"Splunk Enterprise Security has helped improve my organization's business resilience by fulfilling gaps in forensics, incident management, IRP, and data management while helping us mature our security operations."
"Splunk Enterprise Security is a very useful application to collect all the logs and also to find out the problems. You can easily create whatever you want by using its features, and it also has the capability to collect from all kinds of different platforms. Splunk Enterprise Security provides me with all the alerts."
 

Cons

"Visualization-wise, Grafana Loki's dashboard looks a little outdated compared to other open-source visualization tools like Chronograf."
"The correlation of requests is not simple in Grafana Loki and can be improved."
"The platform's stability needs improvement."
"In Grafana Loki, the creation of metrics is not so easy, making it an area that could be made easier."
"The solution's scalability depends on the team managing the Grafana instance."
"Enhancing speed could be a game-changer, and while it might vary depending on the application, it's a factor worth exploring."
"It's not intended for proprietary services, so you have to struggle with configuration a lot."
"The solution has shortcomings regarding security monitoring-oriented features that need improvement."
"The documentation and training resources available for knowledge and training can be expanded. We need to learn more about Splunk Enterprise Security and new security attacks."
"The incident response technique should be available out of the box. That isn't as available as we would expect."
"The most significant challenges I face when using Splunk Enterprise Security for advanced threat detection are the false positive alerts."
"One main change I would suggest is related to the incident board: when an incident is resolved, it should not appear on the incident board."
"I would like to see future development in terms of ML (Machine Learning)."
"Its user interface for everything other than the charts can be improved. Some parts of it can be simplified a bit, such as when importing documents that have the network traffic. When you're going through the information about the network traffic, you have to have the expertise, but even if a program is supposed to be for IT support, it is good to make it user-friendly because it gets easier to train people. When something goes wrong, the more difficult a program is in terms of UI, the harder it is to fix the issue."
"Splunk Enterprise Security can be improved mainly from the user interface regarding the visualizations. They are working on it, yet there are only five to ten very basic visualizations."
"It needs integration with a configuration management solution."
 

Pricing and Cost Advice

"We use a free version."
"Grafana Loki is a free, open-source solution."
"I use the solution's open-source version. Grafana Loki is a completely free solution for me."
"The pricing structure varies based on the number of users; there might be specific taxes to pay for it."
"You can use the free version of Grafana Loki on-premises."
"The cost is less than other paid services like CloudWatch."
"Grafana Loki is an open-source solution."
"My company doesn't need to pay for the licensing cost of the solution."
"It can be tough to determine if you are getting all of the value out of your investment at times."
"We had a yearly subscription."
"The pricing model is based on the number of gigabytes that you ingest into the Splunk system. So it can be an expensive solution."
"The pricing and licensing of the product are quite high."
"Further reductions would be fantastic, and I believe that more and more people would flock to it."
"Splunk is definitely not a cheap solution. It is an expensive product."
"It is pretty straightforward and based on the sizing. If I compare it with other competitors, it makes sense."
"Our customers often complain that the price of Splunk is too high."
report
Use our free recommendation engine to learn which Log Management solutions are best for your needs.
867,676 professionals have used our research since 2012.
 

Comparison Review

VS
Feb 26, 2015
HP ArcSight vs. IBM QRadar vs. ​McAfee Nitro vs. Splunk vs. RSA Security vs. LogRhythm
We at Infosecnirvana.com have done several posts on SIEM. After the Dummies Guide on SIEM, we are following it up with a SIEM Product Comparison – 101 deck. So, here it is for your viewing pleasure. Let me know what you think by posting your comments below. The key products compared here are…
 

Top Industries

By visitors reading reviews
Computer Software Company
16%
Comms Service Provider
10%
Financial Services Firm
10%
Manufacturing Company
9%
Computer Software Company
14%
Financial Services Firm
14%
Manufacturing Company
8%
Government
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business7
Midsize Enterprise8
Large Enterprise3
By reviewers
Company SizeCount
Small Business109
Midsize Enterprise49
Large Enterprise255
 

Questions from the Community

What do you like most about Grafana Loki?
We are using Grafana Loki as a database for real-time metrics.
What is your experience regarding pricing and costs for Grafana Loki?
Since it is an open source tool, there are no charges or fees.
What needs improvement with Grafana Loki?
I have no ideas at this moment about what could be improved in Grafana Loki.
What SOC product do you recommend?
For tools I’d recommend: -SIEM- LogRhythm -SOAR- Palo Alto XSOAR Doing commercial w/o both (or at least an XDR) is asking to miss details that are critical, and ending up a statistic. Also, rememb...
What is a better choice, Splunk or Azure Sentinel?
It would really depend on (1) which logs you need to ingest and (2) what are your use cases Splunk is easy for ingestion of anything, but the charge per GB/Day Indexed and it gets expensive as log ...
How does Splunk compare with Azure Monitor?
Splunk handles a high amount of data very well. We use Splunk to capture information and as an aggregator for monitoring information from different sources. Splunk is very good at alerting us if we...
 

Overview

 

Sample Customers

Information Not Available
Splunk has more than 7,000 customers spread across over 90 countries. These customers include Telenor, UniCredit, ideeli, McKenney's, Tesco, and SurveyMonkey.
Find out what your peers are saying about Grafana Loki vs. Splunk Enterprise Security and other solutions. Updated: September 2025.
867,676 professionals have used our research since 2012.