No more typing reviews! Try our Samantha, our new voice AI agent.

ITRS Geneos vs Splunk Enterprise Security comparison

 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

ITRS Geneos
Average Rating
8.2
Reviews Sentiment
7.1
Number of Reviews
57
Ranking in other categories
Application Performance Monitoring (APM) and Observability (48th), Network Monitoring Software (74th), IT Infrastructure Monitoring (50th)
Splunk Enterprise Security
Average Rating
8.4
Reviews Sentiment
7.3
Number of Reviews
381
Ranking in other categories
Log Management (2nd), Security Information and Event Management (SIEM) (1st), IT Operations Analytics (1st)
 

Mindshare comparison

While both are Application Lifecycle Management solutions, they serve different purposes. ITRS Geneos is designed for Application Performance Monitoring (APM) and Observability and holds a mindshare of 1.0%, down 1.3% compared to last year.
Splunk Enterprise Security, on the other hand, focuses on Security Information and Event Management (SIEM), holds 7.1% mindshare, down 9.5% since last year.
Application Performance Monitoring (APM) and Observability Mindshare Distribution
ProductMindshare (%)
ITRS Geneos1.0%
Dynatrace5.6%
Datadog4.9%
Other88.5%
Application Performance Monitoring (APM) and Observability
Security Information and Event Management (SIEM) Mindshare Distribution
ProductMindshare (%)
Splunk Enterprise Security7.1%
IBM Security QRadar5.3%
Wazuh5.1%
Other82.5%
Security Information and Event Management (SIEM)
 

Featured Reviews

reviewer2127225 - PeerSpot reviewer
Monitoring Specialist at a financial services firm with 51-200 employees
Does real-time monitoring, prevents failures, and has a reasonable price
Their cloud monitoring solution needs to be improved. I have already given them the feedback that it's not capable of meeting the latest technology needs. It's built like proprietary software. I can't expose the data to ITRS, and similarly, ITRS can't expose the data to the outside world. They have created a boundary. It's a bit binding solution. In the modern world, people like to be able to expose the data to do whatever they want. They can query the data, send it, or pull it. ITRS needs to provide more in terms of the API offering. They have documentation, but they can improve the documentation and provide videos to show how to do monitoring configuration or deployment.
Sathis-Kumar - PeerSpot reviewer
Senior Manager at Bank of America
Helps us detect cyber threats quickly and integrate multiple feeds effectively
Overall, the product is good, but when it comes to some infrastructure issues, we have to dig into more logs. There is no straightforward indication of an issue. Health check kind of dashboards are not available. More AI would help us, and more optimization, since security products run more queries. The AI module could suggest solutions, optimizing queries or workload balancing. If the product itself advises on running queries during peak times, it would be similar to what ChatGPT currently offers. We see quite a few issues on stability. Even last week, we faced something, and identifying bottlenecks is not easy. We need more SMEs, and there is no mechanism to tell us about indexer or search head issues. Self-monitoring dashboards could be beneficial. The technical support still requires more improvement. Often, primary support takes a lot of time and forwards most solutions to the engineering side. The primary support team has very limited knowledge to provide.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"Ability to monitor logs for potential issues to prevent app outages before problems get a chance to arise. That's invaluable for our teams in a fast-paced trading environment."
"ITRS uses SNMP to communicate with our devices as well as SNMP net probes installed on our servers."
"Once set-up, Geneos proved to be a very powerful and versatile tool to real-time monitor our IT infrastructure and - most important for us - our critical applications and business processes."
"We previously used Nagios, but switched to Geneos as it has better monitoring for applications, and it has more features and better configuration possibilities."
"Real-time log monitoring with desktop alerts is valuable as it tells us immediately when there is an issue."
"Geneos automatically sends email notifications when any batch job fails, the database is down or the website is down. It is automatically monitoring everything and reduces manual effort."
"It’s very easy to install and setup, offers high scalability, and has a low resource use."
"Customer service delivered by ITRS is to the highest standards from all points of view."
"I evaluate customer service and technical support as excellent."
"Splunk Enterprise Security is so easy as it scales with us as we grow."
"I would assess the stability and reliability of Splunk Enterprise Security as very reliable and very stable."
"The risk-based alerting is excellent."
"The most valuable features include agility and Splunk Enterprise Security's ability to quickly search for alerted items, as well as the capacity to create custom alerts using the SQL language employed by Splunk."
"The speed of the search engine"
"We found that Splunk has more capacity to do more in less time and provides a faster speed to index all the events, which is a huge asset."
"The feature I appreciate the most about Splunk Enterprise Security is the CIM data model, which allows users to bring in data from different technologies, such as firewalls, endpoints, and perimeter DMZs, enabling every device to pump data into Splunk Enterprise Security, with the data model normalizing all the data and placing it in a common plane."
 

Cons

"The main feature that needs work is the Dashboard designer. Currently we have to export metrics data in real-time into some other visualization tools in order to get better picture and have a bit more functional dashboard."
"Backward compatibility with deprecated features and in-system documentation on what configuration areas are needed to be updated can be improved."
"They have the Webslinger solution where you can see when something is alerting. It's a little bit cumbersome."
"There is a part of the rules for monitoring alerts. I want to understand more about how to choose the samples and the requirements for the rules. That is the part that I want to understand better and get better training for."
"A lightweight version which could host more than 100 gateways, as we can see slowness while loading all our gateways."
"We sometimes experienced disconnects of the gateways which was a hard one to resolve."
"Currently, it is difficult to monitor secure websites using SSL or with SSO enabled."
"It needs to have better middleware integration for things such as application and Microsoft SQL servers."
"The solution's case management system could be further improved to make it easier for analysts to manage cases."
"The threat management part is still lagging. There are some gaps in threat management. Other vendors have built-in threat management systems, but Splunk lacks the threat management component in its portal. The UEBA and everything else is perfect, but it lacks a unified threat intelligence and management part."
"This is not really a monitoring solution."
"Code understanding requirement is complicated for most users."
"The system can be intimidating, and sometimes the concepts conveyed in the documentation require adjustment."
"The GUI can be improved. Splunk has always suffered from having a kind of goofy UI, it needs some updating."
"Sometimes the communication with support happens with multiple staff. They should reduce the time to resolution."
"When deploying Enterprise Security, the biggest challenge or the most amount of work that you're going to spend time on is onboarding your data and getting it into a position that allows you to search it uniformly."
 

Pricing and Cost Advice

"The licensing cost may seem expensive upfront. However, the service is outstanding, the tool does things that no other tools can do, and the customizability more than makes up for the cost of licensing."
"Pricing is the touchy subject, even here. Upper management always wants us to find a cheaper solution. But we have so much integrated with ITRS... It's expensive, but it does its job very well. And you set it and go."
"The market tools are on par with this solution, but if the solution included more features, then it would be well within the range for the cost."
"Given our spend and the amount of service we have in it, the pricing is quite reasonable."
"The organization is not just purchasing a license for the product, but also managing services and professional services from ITRS. Another factor is if the implementation is going to be in production, non-production, or both."
"The product is priced quite high. There are pricing options for customers based on the size of the environment and plug-ins used by the monitoring system."
"Its price is reasonable. It isn't too expensive, and it isn't too cheap, but it also depends on a company's volume and negotiation."
"You will get the best price if you get a single global deal."
"In terms of pricing, I believe Splunk is unreasonably costly for the majority of mid and small-sized companies."
"Splunk Enterprise Security is a bit expensive overall, but it provides good value."
"Licensing is a yearly, one-time cost."
"Splunk is expensive based on our current requirements, but it's obviously worth what we pay."
"The price of Splunk Enterprise Security fluctuates based on the customer, but I believe it's quite costly, especially for our clientele."
"Splunk Enterprise Security is an expensive solution."
"It is expensive. I used to buy it early on, but then they combined it into a higher-up organization. They buy it for multiple systems now. Last time, I paid around 60K for it. There is just the licensing fee. That's all."
"Our ROI is high."
report
Use our free recommendation engine to learn which Application Performance Monitoring (APM) and Observability solutions are best for your needs.
886,011 professionals have used our research since 2012.
 

Comparison Review

VS
Manager, Enterprise Risk Consulting at a tech company with 1,001-5,000 employees
Feb 26, 2015
HP ArcSight vs. IBM QRadar vs. ​McAfee Nitro vs. Splunk vs. RSA Security vs. LogRhythm
We at Infosecnirvana.com have done several posts on SIEM. After the Dummies Guide on SIEM, we are following it up with a SIEM Product Comparison – 101 deck. So, here it is for your viewing pleasure. Let me know what you think by posting your comments below. The key products compared here are…
 

Top Industries

By visitors reading reviews
Financial Services Firm
67%
Computer Software Company
6%
Construction Company
3%
Outsourcing Company
3%
Financial Services Firm
14%
Computer Software Company
9%
Manufacturing Company
9%
Government
5%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business6
Midsize Enterprise12
Large Enterprise39
By reviewers
Company SizeCount
Small Business112
Midsize Enterprise50
Large Enterprise267
 

Questions from the Community

What is your experience regarding pricing and costs for ITRS Geneos?
The pricing is high. Licensing fees might be around 500$ per server monthly.
What needs improvement with ITRS Geneos?
ITRS Geneos is a legacy system. It predicts or provides proactive measures once an issue is resolved. It doesn't offer any predictive capabilities or root cause analysis. They throw a lot of data i...
What is your primary use case for ITRS Geneos?
ITRS offers multiple products, including upgrades for synthetic monitoring and a SaaS platform. Geneos is used for infrastructure monitoring, covering KPIs such as CPU, memory, processes, network l...
What SOC product do you recommend?
For tools I’d recommend: -SIEM- LogRhythm -SOAR- Palo Alto XSOAR Doing commercial w/o both (or at least an XDR) is asking to miss details that are critical, and ending up a statistic. Also, rememb...
What is a better choice, Splunk or Azure Sentinel?
It would really depend on (1) which logs you need to ingest and (2) what are your use cases Splunk is easy for ingestion of anything, but the charge per GB/Day Indexed and it gets expensive as log ...
How does Splunk compare with Azure Monitor?
Splunk handles a high amount of data very well. We use Splunk to capture information and as an aggregator for monitoring information from different sources. Splunk is very good at alerting us if we...
 

Also Known As

Geneos
No data available
 

Overview

 

Sample Customers

ITRS Geneos is used by over 170 financial institutions, including JPMorgan, HSBC, RBS, Deutsche Bank and Goldman Sachs. Clients range from investment banks to exchanges and brokers.
Splunk has more than 7,000 customers spread across over 90 countries. These customers include Telenor, UniCredit, ideeli, McKenney's, Tesco, and SurveyMonkey.
Find out what your peers are saying about ITRS Geneos vs. Splunk Enterprise Security and other solutions. Updated: May 2023.
886,011 professionals have used our research since 2012.