Try our new research platform with insights from 80,000+ expert users

IBM SevOne Network Performance Management (NPM) vs Splunk Enterprise Security comparison

 

Comparison Buyer's Guide

Executive SummaryUpdated on Jan 5, 2025

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

IBM SevOne Network Performa...
Ranking in Log Management
47th
Average Rating
8.4
Reviews Sentiment
7.2
Number of Reviews
53
Ranking in other categories
Network Monitoring Software (39th), Server Monitoring (19th), IT Infrastructure Monitoring (45th), Cloud Monitoring Software (27th)
Splunk Enterprise Security
Ranking in Log Management
1st
Average Rating
8.4
Reviews Sentiment
7.6
Number of Reviews
304
Ranking in other categories
Security Information and Event Management (SIEM) (1st), IT Operations Analytics (1st)
 

Mindshare comparison

As of February 2025, in the Log Management category, the mindshare of IBM SevOne Network Performance Management (NPM) is 0.3%, down from 0.4% compared to the previous year. The mindshare of Splunk Enterprise Security is 7.8%, down from 12.0% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Log Management
 

Featured Reviews

Grzegorz Nowak - PeerSpot reviewer
Improves infrastructure planning by helping us analyze network traffic
We use SevOne to collect and report on network flows SevOne improves infrastructure planning by helping us analyze network traffic. We can look at bandwidth for specific endpoints on the customer's network and analyze traffic to identify issues. For example, maybe some connectors are unavailable.…
ROBERT-CHRISTIAN - PeerSpot reviewer
Has many predefined correlation rules and is brilliant for investigation and log analysis
It is very complicated to write your own correlation rules without the help of Splunk support. What Splunk could do better is to create an API to the standard SIEM tools, such as Microsoft Sentinel. The idea would be to make it less painful. In ELK Stack, Kibana is the query language with which you can search log files. I believe Splunk has also a query language in which they search their log files, but once you have identified the log file that you want to use for further security correlation, you want to very quickly transport that into your SIEM tool, such as Microsoft Sentinel. That is something that Splunk could make a little bit less painful because it is a lot of effort to find that log file and forward it. An API with Microsoft Sentinel or a similar SIEM tool would be a good idea.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"It's a great solution for highlighting and discovering useful information regarding our network's elements."
"We find that the reporting is particularly valuable in terms of not only communicating with our peer teams but also with the executives."
"In 90% of the cases, new devices are plug-and-play, so when a new version comes out then SevOne has support for it out of the box."
"The feature that I have found most valuable is the scale-up and scale-down. The scale-up is an operation where the CPU boosts-up and then the memory will boost-up. That works awesomely."
"The most valuable feature is the NMS because that's the core of the system. Without the NMS, the other tools aren't that usable."
"SevOne provides support for all universal connectors. They internally work with other data sources to get features implemented. We have an SD-WAN implementation and use other app data to monitor performance. If you pull that data into one centralized location, that is very useful for management."
"The out of the box reports and workflows are pretty good and they meet our requirements well."
"The SMP and the xStats, which is for flat file integration, are both useful for integrating the various metrics that the device provides to monitor the performance of those systems."
"It gives me notifications of notable events."
"Splunk's strongest suit is its user interface. We can integrate multiple solutions and adjust settings in the Splunk interface."
"The solution's most valuable feature is that it helps with our use cases to detect anomalies in our data and it is important to my company since we have a lot of data on different logs on the systems."
"The incident review pane is the best part of it because that is where the SOC lives. It is the heartbeat of what the SOC needs to do. You are able to start the investigative process. As you are sitting in the incident review pane, you see the alert, and from that one alert, which is called a notable alert, you can drill in and see all the different specific details that are tied to that."
"It has increased our business resilience. It's a top-of-the-line SIEM security product. It's the best tool for our security analysts which helps them do their job better. That then protects our company from adversary actors."
"The search engine and indexes are fast and optimized, and the report generation dashboard is user-friendly."
"it can explain to management about what kind of traffic is visiting the network. It can also explain other traffic coming in and out, along with protecting against malware."
"The most valuable feature is the custom dashboard feature."
 

Cons

"One area that requires a little bit of improvement is the topology of visualization and being able to map out connections, end-to-end. It's able to do that, but it's not as impressive as we would like it to be. We would like to understand the different interface types and the connection points better, through the visualization. Heatmaps also need further development."
"There are a lot of pain points. My main problem is that we don't have a high availability system. There are 20 peers. We're going to lose the end-of-life appliances that are old. If we lose a peer and it doesn't come back, we lose all that data. The reason we don't have high availability is because it's double the charge."
"The reports are easy to configure but they are a bit outdated in terms of appearance and visualization."
"You need to plan integrations. That has been the biggest bug with SevOne so far. For the things that SevOne pulls directly, those are easy to understand, modify, and put into the database. For things that need to use the Universal Collector or xStats, you need to plan that stuff well in advance."
"Would benefit with the addition of AI modules for proactive data insights."
"Their virtualization solution is not compatible with our Kubernetes environment, which is one of the reasons we are ending our relationship with them."
"The method of searching for SIP and the way to create the groups."
"Software upgrades can be tricky is not easy."
"The solution has a high learning curve for users. It's a little complicated when you're trying to figure out all the features and what they do."
"Splunk Enterprise Security could improve in automation, flexibility, and providing more content out of the box."
"Its performance can be better. Sometimes, it takes longer when we do queries."
"The algorithms customization of Splunk could improve. They have limited algorithms for machine learning support. If they can allow the user to add more machine learning algorithms, such as the ability to choose the algorithm that a user might want. Additionally, they should provide the required libraries for those algorithms, and then analyzes the data for use."
"I think the machine learning should be emphasized. Now, it's really important to analyze Big Data, data mining. A SIEM solution, like Splunk, needs an improved data mining solution, artificial intelligence."
"The documentation is in definite need of improvement."
"Many of my clients want to get better at Splunk, but they're afraid of using the tool because they feel it's too complex for them."
"It is a good product, but the Achilles heel for a lot of organizations is the cost model for it because it gets expensive. That's because the model is based on how much data it processes a day, which can be prohibitive, especially if you have a lot of data. A lot of customers may not be ready for the sticker shock on how to fully leverage the product. I realized that the reason for that is that when it was originally designed, it was kind of like a big data modeling application. If they want to have a bigger customer base, they can come out with subsets of their product that are focused on specific things and have different pricing models. It may help with the cost."
 

Pricing and Cost Advice

"Many tools price things based on the number of KPIs that you're collecting around a device. In many cases, there could be hundreds of metrics that you need to collect. SevOne provides device-level pricing. That gives us the flexibility to turn on, and expand on, the metrics that we're collecting around those devices, without taking a financial hit."
"Choose a SevOne partner who can provide SevOne as a service and can deliver professional services and maintenance."
"A blocking point is the high upfront cost because it is challenging to get it accepted and the purchase approved."
"It is inexpensive compared to other monitoring tools."
"The pricing has not evolved with the market, which is one of the reasons we are moving to a new product."
"Although I don't have exact details in terms of cost, my experience has been that SevOne is willing to make a deal with the customer."
"The pricing has been fair."
"Have a bank of licenses, because it is about the number of objects (RAM, ports, CPU, etc.)."
"You will eat up whatever you purchase quickly. The level of insights that Splunk empowers is addictive."
"The tool's pricing model is great. You can choose between workloads or volume."
"The pricing of Splunk Enterprise Security is high."
"In terms of pricing, I believe Splunk is unreasonably costly for the majority of mid and small-sized companies."
"Some of the insights that we have obtained as a part of using Splunk have greatly helped us in increasing our revenue in terms of selling our products."
"Splunk Enterprise Security is expensive."
"The licensing is good, but the pricing absolutely needs some work. It is very high."
"It's a little bit expensive for a small to medium enterprise."
report
Use our free recommendation engine to learn which Log Management solutions are best for your needs.
838,640 professionals have used our research since 2012.
 

Comparison Review

VS
Feb 26, 2015
HP ArcSight vs. IBM QRadar vs. ​McAfee Nitro vs. Splunk vs. RSA Security vs. LogRhythm
We at Infosecnirvana.com have done several posts on SIEM. After the Dummies Guide on SIEM, we are following it up with a SIEM Product Comparison – 101 deck. So, here it is for your viewing pleasure. Let me know what you think by posting your comments below. The key products compared here are…
 

Top Industries

By visitors reading reviews
Computer Software Company
15%
Financial Services Firm
15%
Manufacturing Company
14%
Educational Organization
5%
Financial Services Firm
16%
Computer Software Company
14%
Manufacturing Company
8%
Government
8%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

What do you like most about SevOne Network Data Platform?
I like the tool’s scalability and real-time reports. Earlier, we struggled to give real-time reports to clients. I also like the tool’s deployment model where we can deploy it either on-premises or...
What is your experience regarding pricing and costs for SevOne Network Data Platform?
The tool is not expensive. We were able to negotiate with SevOne on pricing.
What needs improvement with SevOne Network Data Platform?
SevOne could improve its flexibility because it isn't fully customizable and its out-of-the-box configuration doesn't cover all use cases.
What SOC product do you recommend?
For tools I’d recommend: -SIEM- LogRhythm -SOAR- Palo Alto XSOAR Doing commercial w/o both (or at least an XDR) is asking to miss details that are critical, and ending up a statistic. Also, rememb...
What is a better choice, Splunk or Azure Sentinel?
It would really depend on (1) which logs you need to ingest and (2) what are your use cases Splunk is easy for ingestion of anything, but the charge per GB/Day Indexed and it gets expensive as log ...
How does Splunk compare with Azure Monitor?
Splunk handles a high amount of data very well. We use Splunk to capture information and as an aggregator for monitoring information from different sources. Splunk is very good at alerting us if we...
 

Also Known As

SevOne
No data available
 

Overview

 

Sample Customers

ATOS, Devereux, Spark New Zealand, Access4, Rogers Communication, Lumen (formerly known as CenturyLink)
Splunk has more than 7,000 customers spread across over 90 countries. These customers include Telenor, UniCredit, ideeli, McKenney's, Tesco, and SurveyMonkey.
Find out what your peers are saying about IBM SevOne Network Performance Management (NPM) vs. Splunk Enterprise Security and other solutions. Updated: January 2025.
838,640 professionals have used our research since 2012.