Try our new research platform with insights from 80,000+ expert users

Icinga vs Splunk Enterprise Security comparison

 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Icinga
Average Rating
7.6
Reviews Sentiment
6.1
Number of Reviews
17
Ranking in other categories
Network Monitoring Software (17th), Server Monitoring (7th), IT Infrastructure Monitoring (15th), Cloud Monitoring Software (14th)
Splunk Enterprise Security
Average Rating
8.4
Reviews Sentiment
7.6
Number of Reviews
305
Ranking in other categories
Log Management (2nd), Security Information and Event Management (SIEM) (1st), IT Operations Analytics (1st)
 

Mindshare comparison

While both are Systems Management solutions, they serve different purposes. Icinga is designed for Network Monitoring Software and holds a mindshare of 3.3%, up 2.4% compared to last year.
Splunk Enterprise Security, on the other hand, focuses on Security Information and Event Management (SIEM), holds 9.8% mindshare, down 13.3% since last year.
Network Monitoring Software
Security Information and Event Management (SIEM)
 

Featured Reviews

Harrison Bulley - PeerSpot reviewer
A stable, scalable and cost-effective solution that helps with inbuilt scripts for easy modification
I think the software is quite good, but we have had problems with getting it to recognize certain areas and amend certain checks, where we needed so we would have to create backend scripts for those checks. Though, being open source, it has the support to create backend scripts, it would be better to have these scripts in-built.
ROBERT-CHRISTIAN - PeerSpot reviewer
Has many predefined correlation rules and is brilliant for investigation and log analysis
It is very complicated to write your own correlation rules without the help of Splunk support. What Splunk could do better is to create an API to the standard SIEM tools, such as Microsoft Sentinel. The idea would be to make it less painful. In ELK Stack, Kibana is the query language with which you can search log files. I believe Splunk has also a query language in which they search their log files, but once you have identified the log file that you want to use for further security correlation, you want to very quickly transport that into your SIEM tool, such as Microsoft Sentinel. That is something that Splunk could make a little bit less painful because it is a lot of effort to find that log file and forward it. An API with Microsoft Sentinel or a similar SIEM tool would be a good idea.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"We have found the solution to be stable."
"This solution has a self-healing handler where if the service is down, it is automatically restarted."
"I like the ability to amend and adjust things really easily, which is useful in a case where you could make it auto-discover and then set a template to say all of these applications or servers under this template have an automatic threshold set that you’d set up manually."
"It is really easy in Icinga to create your own plugin and integrate it without any fuss. And it works just perfectly fine."
"There's a module called Icinga Director, which helps us configure the product using an intuitive interface through clicks instead of creating a text configuration. It's very helpful for us."
"Icinga has multiple automation and integration features. There is an API for everything and a web UI for configurations. The APIs enable you to automate tasks in Icinga. We can also use plugins to talk to the API. The Icinga Director talks to a database in the background, and you can import settings from the CMDB to all systems in Icinga."
"The drafts are easy but what I like about Icinga is that there are many add-ons that you can download."
"An affordable solution for small organizations to do basic network monitoring."
"The incident review pane is the best part of it because that is where the SOC lives. It is the heartbeat of what the SOC needs to do. You are able to start the investigative process. As you are sitting in the incident review pane, you see the alert, and from that one alert, which is called a notable alert, you can drill in and see all the different specific details that are tied to that."
"The most valuable features include agility and Splunk Enterprise Security's ability to quickly search for alerted items, as well as the capacity to create custom alerts using the SQL language employed by Splunk."
"The solution's most valuable features are its ability to transact in the cloud and its ability to onboard data easily with minimum connectors."
"Recently, Splunk upgraded to version 9.0.02, which includes excellent data dashboards and visualization effects."
"The solution's most valuable features are the granularity and analysis of the logs."
"It is very scalable."
"We were able to create a catalog of dashboards and have a holistic view at all levels. We could understand our business much better. Real-time errors, which were buried in emails before now, surfaced up on dashboards."
"You can integrate Splunk with third-party security automation solutions and set rules for automatic response."
 

Cons

"I think the software is quite good, but we have had problems with getting it to recognize certain areas and amend certain checks, where we needed so we would have to create backend scripts for those checks. Though, being open source, it has the support to create backend scripts, it would be better to have these scripts in-built."
"We have found some problems with Nagios, and support isn't very responsive."
"Icinga’s automation could be improved."
"One thing that Icinga lacks is the capability to create advanced and customized dashboards within the tool itself."
"Icinga is a complex solution that's hard to learn. It's a powerful product for monitoring, but new users will have a hard time figuring out what to do."
"It needs Trap SNMP. I saw the documentation for Zabbix, that it has its own built-in product which handles SNMP traps, and there's nothing similar in Icinga or Nagios. I think this feature is most important for me."
"The user interface should be improved."
"The solution lacks many features important to higher-level IT management and network support."
"We'd like to have the number of devices covered under the license to be increased."
"The UI can be difficult to understand for non-technical people."
"Some of the search functions can be better. There has been a lot of talk at the conference about the update of SPL before each iteration. That will be a lot of help."
"We usually have to follow up with technical support on our open cases."
"They can incorporate the SOAR solution within the actual product so that we do not require two different products, two different installations, and two different pricing methods. In regards to UBA, I am familiar with the UBA that existed two years ago. I am not updated about it today, but two years ago, UBA required such an amount of data that from a cost perspective, it was not worth it. When you compare it to what you get out of the box with Microsoft Sentinel without additional costs, there is no match."
"Most of my interaction is with the user community, which is how Splunk wants it. When I need help, that community is very hit or miss."
"The user interface is not user-friendly for non-technical users."
"I think the only thing lacking is that there are some answers that I couldn't find about the tool without reaching out to support, and it had to be escalated to the engineering team."
 

Pricing and Cost Advice

"It's an open-source solution."
"We're using the free version of Icinga."
"This is an open-source solution with paid support."
"The solution is free to use."
"The solution is cheap."
"Even though Icinga's financial cost is low, it is an expensive product regarding the resources required to maintain and operate it."
"The product is inexpensive compared to other DBM products."
"It is cost-effective, and the return on investment can be very interesting because the price is low."
"The price of Splunk is reasonable."
"The tool's pricing model is great. You can choose between workloads or volume."
"Splunk Enterprise Security is expensive. I would rate the cost an eight out of ten with ten being the most expensive."
"Splunk Enterprise Security is expensive but the solution is equipped with a lot of features."
"Price-wise, if you compare QRadar to Splunk for SIEM functionality then they are in the same range but when you integrate SOAR with these solutions, Splunk takes the lead and is more competitive."
"Some of the insights that we have obtained as a part of using Splunk have greatly helped us in increasing our revenue in terms of selling our products."
"Splunk licensing model might seem expensive but with all the gain in functionalities you will have compared to traditional SIEM solutions I think it’s worth the price."
"Splunk Enterprise Security is an expensive solution."
report
Use our free recommendation engine to learn which Network Monitoring Software solutions are best for your needs.
842,690 professionals have used our research since 2012.
 

Comparison Review

VS
Feb 26, 2015
HP ArcSight vs. IBM QRadar vs. ​McAfee Nitro vs. Splunk vs. RSA Security vs. LogRhythm
We at Infosecnirvana.com have done several posts on SIEM. After the Dummies Guide on SIEM, we are following it up with a SIEM Product Comparison – 101 deck. So, here it is for your viewing pleasure. Let me know what you think by posting your comments below. The key products compared here are…
 

Top Industries

By visitors reading reviews
Computer Software Company
15%
Financial Services Firm
10%
Comms Service Provider
10%
Manufacturing Company
9%
Financial Services Firm
15%
Computer Software Company
14%
Manufacturing Company
8%
Government
8%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

What do you like most about Icinga?
The best thing about the solution is how it highlights errors, the issues, and what needs my attention. The solution directs me to areas that I should look for first.
What is your experience regarding pricing and costs for Icinga?
It is cost-effective, and the return on investment can be very interesting because the price is low. If you want to include this product in the services you offer to your customers, the return on i...
What needs improvement with Icinga?
There is room for improvement in multi-tenancy. It's not perfect, not even really good. It's average, but it should be improved. For instance, multi-tenancy for monitoring the virtual infrastructur...
What SOC product do you recommend?
For tools I’d recommend: -SIEM- LogRhythm -SOAR- Palo Alto XSOAR Doing commercial w/o both (or at least an XDR) is asking to miss details that are critical, and ending up a statistic. Also, rememb...
What is a better choice, Splunk or Azure Sentinel?
It would really depend on (1) which logs you need to ingest and (2) what are your use cases Splunk is easy for ingestion of anything, but the charge per GB/Day Indexed and it gets expensive as log ...
How does Splunk compare with Azure Monitor?
Splunk handles a high amount of data very well. We use Splunk to capture information and as an aggregator for monitoring information from different sources. Splunk is very good at alerting us if we...
 

Also Known As

Icinga Cloud Monitoring
No data available
 

Overview

 

Sample Customers

Puppet Labs, Audi, Spacex, Debian, Snapdeal, McGill, RIPE Network Coordination Centre
Splunk has more than 7,000 customers spread across over 90 countries. These customers include Telenor, UniCredit, ideeli, McKenney's, Tesco, and SurveyMonkey.
Find out what your peers are saying about Zabbix, Auvik, Datadog and others in Network Monitoring Software. Updated: March 2025.
842,690 professionals have used our research since 2012.