Try our new research platform with insights from 80,000+ expert users

Nagios XI vs SolarWinds NPM vs Splunk Enterprise Security comparison

 

Comparison Buyer's Guide

Executive Summary
 

Mindshare comparison

IT Infrastructure Monitoring
Network Monitoring Software
Security Information and Event Management (SIEM)
 

Featured Reviews

HM
Aug 2, 2022
Great for monitoring IT services infrastructure with nice tools and helpful notifications
It is a very good solution to monitoring infrastructure of IT services It's got very nice tools. We have notifications via email or short messages via SMS. It's great for monitoring IT services infrastructure. You can monitor all your servers, your database, and server virtualization.  I don't…
RK
Jul 2, 2024
Optimally utilizes the resources of the underlying hardware used for monitoring and management and offers a very good GUI
SolarWinds is always up to date with the latest versions and firmware. The earlier challenge of increasing resources has been solved since moving to the cloud. We can now increase resources anytime and reduce downtime for monitoring services. With around 10,000 devices and 30,000+ elements, manual monitoring during downtime was a headache. But now there is no problem, as we can increase the underlying infrastructure resources in real-time, and performance is increased on the SolarWinds cloud. We lack database monitoring. I have proposed that the DPA license be onboarded for database monitoring. In the current infrastructure, database monitoring is done manually. I have proposed this enhancement to the client, but there are some commercial constraints. It is in process, and maybe next year, they will budget for it. The market is changing, and people are expecting automation. I think that's a disadvantage, but it's temporary because SolarWinds is continuously pushing clients to onboard the observability AI feature. They have already worked on it, and people only need to invest in it and onboard to meet the current market requirement, which is AI-driven automation for monitoring and decision-making.
SM
Jun 19, 2024
Improves our ability to handle data from applications
We managed Splunk's large clustered environments, I oversaw data collection from roughly 750 applications via universal deployment clients. This experience, coupled with my nearly six years of Splunk expertise, made monitoring application logs and creating Splunk knowledge bases straightforward tasks. While processing task cut-off tickets from the application team could be time-consuming, the actual monitoring itself was easy to manage. The end-to-end visibility provided by Splunk is important because our company uses applications like K-Connect and Splunk to monitor user activity across different sectors. Having previously worked in both healthcare and finance, I'm familiar with how this process works. We access user information including personal data to track their activity from start to finish within our systems. Splunk allows us to mark specific user data points for further analysis, ensuring we have a full view of user or patient activity within each organization we serve. Splunk helps me find security events across multi-cloud and on-prem platforms. I would identify missing data by checking the last hour's timeframe (span=1h). If on-prem or cloud data was missing, I'd investigate which logs weren't being ingested, whether an indexer was down, or if a forwarder wasn't sending data. Additionally, I'd check if the application or event log volume was overwhelming the universal forwarder, requiring a queue to process the data effectively. Splunk improves our ability to handle data from applications. This data is often unstructured or unavailable in a usable format. To make it usable, we used to normalize the logs manually through back-end commands and edit various Splunk consoles and platforms. This process transformed the data into a structured, human-readable event format, allowing us to extract the information we needed. We can identify potential malicious activity through Splunk by analyzing database logs with SQL queries. For instance, a high number of failed login attempts within a short timeframe could indicate unauthorized access attempts. Additionally, with multi-factor authentication systems like Duo, a user logging in from two geographically distant countries within a short period might be suspicious. To address this, I've developed SQL queries that check for logins within a one-hour timeframe across different countries. These queries trigger alerts on a dashboard, allowing IT to investigate the user's IP address and determine if the login is legitimate. Splunk has significantly improved our business resilience by providing a single pane of view for all our data. This visualization allows us to monitor for anomalies, including unusual application activity, unauthorized executables, and suspicious shell scripts running on both Linux and Windows servers. By triggering alerts for these events, Splunk empowers our organization to proactively identify and address potential threats, ultimately improving overall stability. Splunk allows us to easily check the data for malicious activity. It also helps reduce the alert volume by allowing us to set thresholds for alerts. For example, we only receive an alert when the CPU usage exceeds 90 percent or the number of failed logs is more than 15. Splunk helps us investigate by providing relevant context from system logs. We can search the Splunk logs for specific applications and timeframes, and then examine all the data fields for suspicious activity, failed login attempts, or any other anomalies. It helps security teams investigate threats faster by providing a central platform to collect and analyze data from various security applications. This focus on enterprise security allows teams to identify and respond to threats across the organization, leveraging frameworks like MITRE ATT&CK to match attacker techniques and tactics.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"The most valuable feature is the monitoring of processes."
"Nagios XI is a simple monitoring tool with performance management."
"The Script Module in Nagios is really easy to use and is really cost efficient."
"Nagios is a custom API manager, and we can expose custom APIs for our integration. This is a great feature."
"It's great for monitoring IT services infrastructure."
"An excellent solution that is easy and intuitive to implement."
"The dashboard allows you to see what's going on in the overall system."
"Nagios is stable and it's easy to use the monitoring software, which is why we chose this product."
"SolarWinds dashboard is very fast. Also, their interface is very good, it looks very user-friendly. The product allows me to see a summary of the network being monitored at a glance."
"This solution offers a very good view of our network and allows us to effectively monitor performance."
"It's a very good tool and a very stable tool."
"The most valuable features of SolarWinds NPM are network performance monitoring and the overall benefit for servers."
"SolarWinds' network and server application monitoring features are strong."
"The solution ranks as one of the top five monitoring tools."
"Being able to easily, and quickly obtain disc space statistics from servers and determine how much was free or used on various volumes."
"I like the tracking feature to track devices and see where they are connected. This is very practical."
"The most valuable features in Splunk Enterprise Security are the cluster capabilities."
"Splunk UBA is useful for fraud detection and for detection of APTs, advanced persistent threats."
"I like the ease of setting up dashboards on Splunk. They're easy to create, manage, alter, and share. You can fine-tune them any way you see fit."
"The solution helped reduce our alert volume."
"The solution is the market leader."
"The correlation capabilities are the first value that our clients say they like with Splunk."
"It is lovely to have everything we need in one tool. Everything is quite centralized."
"Splunk would be my choice for the presentation layer because it comes with inbuilt reports and a dashboard that you can customize."
 

Cons

"The Configuration Wizard needs improvement, because not all vendors are present."
"The pricing has recently risen. I know they've changed what is covered under the license, however, it doesn't change the way we use it and adds nothing to our experience, and yet we now have to pay more."
"Nagios XI can improve its GUI for users with a new look."
"The product's stability could be even better."
"The product does not have SAP monitoring."
"We often need to develop custom plugins to get Nagios to work the way we want it to work because the features we need are not always available in Nagios."
"I would like to see support for notification via SMS."
"The product uses the backend as Perl and could be modified to a more lightweight solution like what's being offered by other vendors."
"The integration with the APIs and the web servers deployed can definitely be improved."
"Technical support can be slow to respond."
"I would like to see integration with antivirus or other security endpoint solutions."
"The SolarWinds notification and alerting configuration could be simplified as it would be easier to find if it was within the NPM web application instead of in a separate client application."
"One of the challenges with SolarWinds is that in order to pull the data, we have to have a lot of false positives."
"The solution's database performance could be improved."
"Application Performance Monitoring should be included in this solution."
"In terms of scalability, there is room for improvement. When you start monitoring, if you have so many interfaces and you're trying to monitor them at a faster interval, or a shorter interval, you get to a point where you need to request another node."
"The use cases provided by Splunk are a good starting point, but could cover many additional topics to ensure that a smaller or less experienced shop might maximize the value of an ES deployment."
"I feel as though a major focus of upcoming releases should be set on Machine Learning, Predictive Analytics, and I would enjoy to see more security focused add-ons and apps developed by the vendor."
"Splunk's ability to analyze malicious activities scores an 8 out of 10, but there's room for improvement. By analyzing emerging patterns, Splunk could identify and predict potential threats more effectively."
"The GUI can be improved. Splunk has always suffered from having a kind of goofy UI, it needs some updating."
"Enterprise security: Splunk must work on clarifying the solution to customers and explain how to gain more from it."
"Delays in responses from the technical team can pose challenges for both vendors and clients, especially considering that Splunk applications and machine solutions are critical assets."
"The threat detection library needs to increase the frequency at which the playbooks are updated."
"In the next release, they should include machine learning-based rules that would streamline the process of finding anomalies."
 

Pricing and Cost Advice

"Licensing costs are reasonable."
"For our country in North Africa, it's expensive and we could purchase another solution for that price. But it's a reasonable price if we're speaking in international terms."
"This solution is very expensive, at approximately $5,000 USD when I purchased it, which is why I haven't upgraded my version in several years."
"You can grow into the higher-priced scale as they learn how to utilize the features for Nagios XI."
"Nagios Core does not have any payment, but Nagios XI requires payment for the license."
"For the cost of the commercial product and support, and taking into account the open source characteristics of it, I believe it is difficult to a better value."
"It is good to contact experts for advice about what is the best solution for your specific infrastructure and enterprise."
"The licensing fees for this solution are approximately $3,000 USD per year."
"I believe the original setup cost was around $3500 with an annual cost of around $1200-$1500 to renew the support license. This would bring the average day-to-day cost of around $5-$6 over three years."
"Some solutions are open source and free."
"It was inexpensive when we installed it and gradually became more expensive, but it was a very inexpensive product at first."
"Price could be improved on"
"The pricing is very expensive for SolarWinds. That's a huge disadvantage for it."
"SolarWinds is expensive. That's why it's primarily banks using the solution. Small businesses can't afford it. Due to its pricing, most smaller enterprises like manufacturing companies are not interested. For example, we have a client who is also interested in traffic monitoring, but they are not purchasing SolarWinds because of the cost."
"We pay approximately $700 per year for renewal of the license."
"There are a lot of sub-products and it just continued to increase the price."
"Splunk Enterprise Security is expensive but the solution is equipped with a lot of features."
"You will eat up whatever you purchase quickly. The level of insights that Splunk empowers is addictive."
"It's definitely worth it."
"ROI is estimated at saving my team roughly 10 to 12 man hours per week in troubleshooting for our company as well as what our profits had been from our services of installing, configuring, and supporting other clients with the product."
"It is quite expensive."
"Its pricing model can be improved."
"Splunk Enterprise Security incurs a significant cost because of the amount of data we send, but we are fine with the value we're getting for that price."
"This solution is costly. Splunk is obviously a great product, but you should only choose this product if you need all the features provided. Otherwise, if you don't need all the features to meet your requirements, there are probably other products that will be more cost-effective. It's cost versus the functionality requirement."
report
Use our free recommendation engine to learn which IT Infrastructure Monitoring solutions are best for your needs.
800,688 professionals have used our research since 2012.
 

Comparison Review

it_user174738 - PeerSpot reviewer
May 31, 2015
Nagios vs. Zabbix vs. PRTG vs. Spiceworks vs. Solarwinds Network Performance Monitor
I have researched a quite a few network monitoring tools which can be used for various monitoring purposes of not only the servers, but the intermediate routers as well. There are majorly three types of these softwares. Ones which are completely open-source, you can do almost anything you want…
 

Top Industries

By visitors reading reviews
Educational Organization
55%
Computer Software Company
8%
Financial Services Firm
5%
Government
5%
Educational Organization
54%
Computer Software Company
7%
Manufacturing Company
5%
Government
5%
Financial Services Firm
16%
Computer Software Company
14%
Government
10%
Manufacturing Company
8%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

What do you like most about Nagios XI?
It is an open-source platform with valuable features for performance and stability.
What needs improvement with Nagios XI?
The product's stability could be even better.
What is your primary use case for Nagios XI?
We use Nagios XI for server monitoring.
What is the best network monitoring software for large enterprises?
It actually depends on the exact purpose or kind of devices (network devices, servers, something else). Some tools ar...
What is the best network monitoring software for large enterprises?
We are partners with SolarWinds and we sell a lot of Network management to large enterprises also because of scalabil...
What SOC product do you recommend?
For tools I’d recommend: -SIEM- LogRhythm -SOAR- Palo Alto XSOAR Doing commercial w/o both (or at least an XDR) is a...
What is a better choice, Splunk or Azure Sentinel?
It would really depend on (1) which logs you need to ingest and (2) what are your use cases Splunk is easy for ingest...
How does Splunk compare with Azure Monitor?
Splunk handles a high amount of data very well. We use Splunk to capture information and as an aggregator for monitor...
 

Also Known As

No data available
Solarwinds Network Performance Monitor, SolarWinds Network Bandwidth Analyzer
No data available
 

Overview

 

Sample Customers

Nagios has over one million users globally, including AOL, DHL, McAfee, MCI, MTV, Yahoo!, Universal, Toshiba, Sony, Siemens, and JPMorgan Chase.
Microsoft, Federal Express, Hewlett-Packard, and MasterCard
Splunk has more than 7,000 customers spread across over 90 countries. These customers include Telenor, UniCredit, ideeli, McKenney's, Tesco, and SurveyMonkey.
Find out what your peers are saying about Zabbix, Datadog, Auvik and others in IT Infrastructure Monitoring. Updated: August 2024.
800,688 professionals have used our research since 2012.