Try our new research platform with insights from 80,000+ expert users

IBM Tivoli Composite Application Manager vs Splunk Enterprise Security comparison

 

Comparison Buyer's Guide

Executive Summary
 

Categories and Ranking

IBM Tivoli Composite Applic...
Average Rating
6.6
Number of Reviews
2
Ranking in other categories
Application Performance Monitoring (APM) and Observability (59th)
Splunk Enterprise Security
Average Rating
8.4
Number of Reviews
301
Ranking in other categories
Log Management (1st), Security Information and Event Management (SIEM) (1st), IT Operations Analytics (1st)
 

Mindshare comparison

While both are Application Lifecycle Management solutions, they serve different purposes. IBM Tivoli Composite Application Manager is designed for Application Performance Monitoring (APM) and Observability and holds a mindshare of 0.2%, down 0.3% compared to last year.
Splunk Enterprise Security, on the other hand, focuses on Security Information and Event Management (SIEM), holds 10.9% mindshare, down 14.3% since last year.
Application Performance Monitoring (APM) and Observability
Security Information and Event Management (SIEM)
 

Featured Reviews

CC
May 19, 2023
Integrates well with IBM technologies, but it's outdated and lacks essential features
IBM's main value lies in its integration with its own technologies, which can be seen as a benefit in environments where IBM products are extensively used. However, this can also lead to vendor lock-in, limiting flexibility and potential compatibility with other technologies. Implementing…
Sameep Agarwal. - PeerSpot reviewer
Oct 23, 2023
It has a drag-and-drop interface, so you don't need to know SQL or Java to construct a query
The ingestion happens quickly, so you can run up the data costs if you use the default settings. It isn't a problem for government agencies in the Saudi market, but many of the corporations in India are small or medium-sized enterprises that cannot afford that kind of ingestion system. Splunk needs to be tweaked in JSON so you can limit what is coming from the endpoints, especially the events. One needs to filter that out so that only certain events are ingested, like login failures, Active Directory changes, password reset requests, privilege modifications, etc. Each Windows machine generates about 310 KB of information per event, but we can tweak that down to about 50 KB.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"IBM's main value lies in its integration with its own technologies, which can be seen as a benefit in environments where IBM products are extensively used."
"The solution is very stable. We never had any issues with stability."
"Splunk Enterprise Security's dashboards are a key asset."
"The search function for spam is like a google search. You just enter and it will quickly show you the results."
"The most valuable features for us include its robust log management capabilities, which allow us to efficiently handle and retain logs for extended periods as needed."
"Splunk is stable, and this is why many customers want it."
"To get visibility from your network devices, servers, and security devices is a great feature."
"The additional vendors we've brought on board, particularly the elastic, have been quite beneficial."
"We can automatically suspend or terminate suspicious sessions."
"We evaluated several solutions and selected Splunk due to the functionality and cost."
 

Cons

"The user interface was not good."
"The installation process is difficult, requiring continuous support and specialist expertise due to our limited knowledge of managing it effectively."
"I feel the solution to be too slow."
"If possible, we would like to have not only a log monitoring system but a network monitoring feature in this solution as well."
"Licensing costs can be a barrier for those with limited budgets."
"If it could be made available as a service, this would be much better than as a product."
"I think the tech support response time could be a bit better. Sometimes I need to wait more than 24 hours for a response to my tickets."
"It can be tough to determine if you are getting all of the value out of your investment at times."
"There can be a bit of complexity around some fields during the initial setup."
"It is a hugely complicated product."
 

Pricing and Cost Advice

"I would rate the pricing a nine to ten. It is very expensive."
"Splunk can be an expensive solution. It all depends on how we configure the alerts and the events from the endpoints. You can save some money if you do that correctly. If not, it becomes an expensive solution."
"Further reductions would be fantastic, and I believe that more and more people would flock to it."
"Price-wise, if you compare QRadar to Splunk for SIEM functionality then they are in the same range but when you integrate SOAR with these solutions, Splunk takes the lead and is more competitive."
"Splunk differs from other SIEM solutions by using a gigabyte-based pricing model, rather than the agent-based licenses common with its competitors."
"It's definitely worth it."
"I think that most of the monitoring solutions are expensive."
"I would highly recommend anyone evaluating this option to download the free trial which allows for the ingestion of 500MB of data per day in order to get a feel for what Splunk does at its core. It will get pricey once your ingestion rates start to sky rocket, but I would consider it expensive given the amount of information that it allows you to analyze and react on straight out-of-the-box."
"As a team, we prefer the old pricing model with a perpetual license. We are still evaluating the whole subscription-based model."
report
Use our free recommendation engine to learn which Application Performance Monitoring (APM) and Observability solutions are best for your needs.
814,763 professionals have used our research since 2012.
 

Comparison Review

VS
Feb 26, 2015
HP ArcSight vs. IBM QRadar vs. ​McAfee Nitro vs. Splunk vs. RSA Security vs. LogRhythm
We at Infosecnirvana.com have done several posts on SIEM. After the Dummies Guide on SIEM, we are following it up with a SIEM Product Comparison – 101 deck. So, here it is for your viewing pleasure. Let me know what you think by posting your comments below. The key products compared here are…
 

Top Industries

By visitors reading reviews
Financial Services Firm
36%
Government
11%
Computer Software Company
9%
Insurance Company
5%
Financial Services Firm
16%
Computer Software Company
14%
Government
9%
Manufacturing Company
8%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
No data available
 

Questions from the Community

What do you like most about IBM Tivoli Composite Application Manager?
IBM's main value lies in its integration with its own technologies, which can be seen as a benefit in environments where IBM products are extensively used.
What needs improvement with IBM Tivoli Composite Application Manager?
Implementing synthetic monitoring for our Internet banking site has been challenging. The installation process is difficult, requiring continuous support and specialist expertise due to our limited...
What advice do you have for others considering IBM Tivoli Composite Application Manager?
I would rate IBM Tivoli Composite Application Manager a six out of ten. The monitoring tool we currently use is outdated and lacks essential features for monitoring customer experience. We face lim...
What SOC product do you recommend?
For tools I’d recommend: -SIEM- LogRhythm -SOAR- Palo Alto XSOAR Doing commercial w/o both (or at least an XDR) is asking to miss details that are critical, and ending up a statistic. Also, rememb...
What is a better choice, Splunk or Azure Sentinel?
It would really depend on (1) which logs you need to ingest and (2) what are your use cases Splunk is easy for ingestion of anything, but the charge per GB/Day Indexed and it gets expensive as log ...
How does Splunk compare with Azure Monitor?
Splunk handles a high amount of data very well. We use Splunk to capture information and as an aggregator for monitoring information from different sources. Splunk is very good at alerting us if we...
 

Also Known As

Tivoli Composite Application Manager
No data available
 

Learn More

 

Overview

 

Sample Customers

Michelin Tire Corp
Splunk has more than 7,000 customers spread across over 90 countries. These customers include Telenor, UniCredit, ideeli, McKenney's, Tesco, and SurveyMonkey.
Find out what your peers are saying about Datadog, Dynatrace, New Relic and others in Application Performance Monitoring (APM) and Observability. Updated: October 2024.
814,763 professionals have used our research since 2012.