Try our new research platform with insights from 80,000+ expert users

New Relic vs Splunk Enterprise Security comparison

 

Comparison Buyer's Guide

Executive SummaryUpdated on Sep 29, 2024
 

Categories and Ranking

New Relic
Ranking in IT Operations Analytics
2nd
Average Rating
8.4
Number of Reviews
157
Ranking in other categories
Application Performance Monitoring (APM) and Observability (3rd), Network Monitoring Software (6th), IT Infrastructure Monitoring (5th), Mobile APM (2nd), Cloud Monitoring Software (4th), AIOps (3rd)
Splunk Enterprise Security
Ranking in IT Operations Analytics
1st
Average Rating
8.4
Number of Reviews
301
Ranking in other categories
Log Management (1st), Security Information and Event Management (SIEM) (1st)
 

Mindshare comparison

As of November 2024, in the IT Operations Analytics category, the mindshare of New Relic is 16.3%, up from 14.8% compared to the previous year. The mindshare of Splunk Enterprise Security is 30.2%, down from 36.5% compared to the previous year. It is calculated based on PeerSpot user engagement data.
IT Operations Analytics
 

Featured Reviews

Iqbal Khowaja - PeerSpot reviewer
Dec 22, 2022
Has a simple user interface and end-to-end monitoring and self-healing features
My organization uses many application performance management solutions, such as AppDynamics, New Relic APM, Splunk, and Datadog. I'm the CTO for the state of Hawaii, and across the board, different departments use different APM tools. I'm using the latest version of New Relic APM, but I cannot recall the exact version. My company has a dozen engineers using and monitoring New Relic APM. I'd tell anyone planning to use New Relic APM that it has to fit what you have. For example, most of my company's payload is in AWS, and the tool has adopters and features that CloudWatch cannot provide. Still, New Relic APM can, so you should do a demo or trial run first and see if it's a tool that'll help you with end-to-end monitoring. New Relic APM is working well for my company, so an excellent way to start is to do a trial run to see how the tool works out for your current applications. My rating for the tool is nine out of ten because my experience with it has been great. New Relic also worked closely with my company and has always been upfront on what's available and what's not. My company is a New Relic APM customer.
Avinash Gopu. - PeerSpot reviewer
Feb 1, 2024
Offers good visibility into multiple environments, significantly reduces our alert volume, and speeds up our security investigations
There are limitations with Splunk not detecting all user activity, especially on mainframes and network devices. This is because Splunk relies on agents, which cannot access certain workstations. In these cases, we have to rely on application data. For example, with mainframes, manual reports are generated and sent to Splunk, limiting visibility to what's manually reported. This lack of automation for specific platforms needs improvement from Splunk. Additionally, API access is limited for other applications that rely on API calls and requests. This requires heavy customization on Splunk's end. These are the main challenges we've encountered. Monitoring multiple cloud platforms, like Azure, GCP, and AWS, with Splunk Enterprise Security presents some challenges. While Splunk provides different connectors for each provider, consolidating data from two domains across distinct cloud environments can be complex. However, leveraging pre-built templates and Splunk's data collation capabilities can help overcome these hurdles. Despite initial difficulties, I believe Splunk can effectively address this task, earning it an eight out of ten rating for its multi-cloud monitoring capabilities. While Splunk Enterprise Security offers insider threat detection capabilities, its effectiveness could be enhanced by integrating with additional tools, such as endpoint security solutions. This integrated approach is particularly crucial for financial institutions, which often require dedicated endpoint security teams. While using multiple tools is valuable, further improvements within Splunk itself are also necessary. Considering both external integration and internal development, I would rate its current insider threat detection capabilities as three out of ten. Threat detection is where Splunk falls behind. While it offers tools, other use cases require additional work. PAM is an enterprise tool that centralizes information about users, servers, and everything else. It needs real-time monitoring, which I haven't seen in any of the companies I've worked for. They only rely on Splunk for alerting, but real-time monitoring should be handled by the endpoint security team's tools. This means there's no detection or analysis at the machine or endpoint level. Additionally, threat analysis reporting is also absent.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"It allows the restriction of privileges and control of users."
"It is stable and scalable."
"New Relic has helped us in terms of the optimizing our print and loading times."
"It gives insights to non-technical people about what technical issues are most important, how much it impacts customers, and potentially, where we should be targeting our development teams when they have time."
"Support for plug-ins (RMQ, Redis etc.) is a valuable feature."
"The alert mechanism is quite accurate when something goes wrong in your system. For example, if you have hundreds of APIs on your server, and any of the APIs is not performing well, you get an alert. When there is a drop or change in the threshold value, the beauty of New Relic is that within a fraction of seconds, all the stakeholders who are configured in the New Relic system will get an alert. That's one good thing."
"One of the most outstanding features of any APM tool is the anomaly detection part."
"The product's initial setup phase was very easy."
"What I really like is that even if you have already collected the data, you can extract fields and can build searches."
"We have a one stop dashboard for health of some of our services where you can click in and it takes you to other dashboards that have custom near real-time metrics that show the application's health."
"Splunk Enterprise Security's value lies in its ability to collect and analyze security logs, providing insightful dashboards."
"Search language is easy to understand and teach to new users."
"The scalability is good."
"The scalability of the solution is amazing because it can collect a lot of data and you can have your own structure to monitor this data."
"Without Splunk Enterprise Security, it would be difficult for us to manage and prioritize alerts. There's a potential to lose track of important notifications, and it's essential to our security that we do not miss anything. Splunk has improved our investigations because the reporting and dashboarding make things so much easier. We can provide weekly or monthly reports. I also like Splunk's ability to integrate."
"Splunk works based on parsing log files."
 

Cons

"The APIs could be better. I would also like more APIs and features to integrate with streaming solutions, like Kinesis or Kafka."
"I would like to see the company implement the AI auto-baseline feature which Dynatrace has."
"The product has good documentation for Linux, however, their documentation for Windows is lacking substantially. It's something they need to develop."
"The browser isn't exactly reliable."
"I would like if it could have predictive analysis. Today, we only have the option to configure thresholds."
"The monitoring is only as good as the alerts that it produces. By having it set up fine grain alerting, it is a bit of a pain."
"It would help customers if there were an on-premises version available."
"The price needs improvement."
"It is a hugely complicated product."
"Splunk could add more ways to manage archiving and storage. There isn't a web interface. You can do this on the SaaS version, but the on-premise platform doesn't have this option. It has other things but no option for remote NAS. I would like to have a personal web interface where I can specify how long logs should be stored. To have this readily available on the web, you need to adjust some settings on the backend. That is tricky."
"The product's price may be an area of concern where improvements are required."
"I'd love to see more integrations, which is one of the primary points of the key node with Splunk Enterprise Security."
"I do not have any pain points for Splunk Enterprise Security. I am still trying to learn it, but there can be more information on the education side for Splunk Enterprise Security. It would be nice if the certification path was more specific to what I use instead of being so broad."
"Splunk ES could have more pre-built integrations and rules. The detection is fairly accurate, but it depends on the rules you create. Splunk's out-of-the-box configuration isn't that useful."
"The glass table feature does not perform as expected."
"The UI could be better. This is applicable to Splunk in general. I know that a lot of people who get their hands on Splunk are hesitant to use it just because they find it overwhelming. There are a lot of options."
 

Pricing and Cost Advice

"We deploy everything on AWS. Purchasing the product on AWS Marketplace made it easier for us."
"The pricing model is a little confusing for beginners. They find it a little expensive, and if you are using it already, then that is not good."
"Cost is significant with a lot of extras."
"The new licensing model is great, as we pay for what we use (in computational units). However, the pricing is expensive compared to other tools."
"The price depends on how many agents you want."
"The product is neither cheap nor expensive, and I believe that it is a competitively-priced tool."
"The solution is cheap, but prices can go up when users grow."
"The solution is quite expensive. It costs around $5,000 a month. There aren't any additional costs above that."
"We had a yearly subscription."
"The pricing seems good relative to the other vendors that we have had here. However, they need to find ways to be more flexible with the licensing and be able to deal with situations where we start generating more logs. Maybe having some controls in the Splunk interface to turn it off, so we don't have to change anything in our application."
"Splunk is expensive based on our current requirements, but it's obviously worth what we pay."
"The licensing is good, but the pricing absolutely needs some work. It is very high."
"Setup cost is cheap: It is free, it is user-friendly, and it is fast."
"It is expensive. That is why many customers have moved to IBM QRadar. The price is definitely a challenge for customers."
"Splunk is not free."
"Splunk Enterprise Security's pricing is competitive."
report
Use our free recommendation engine to learn which IT Operations Analytics solutions are best for your needs.
815,854 professionals have used our research since 2012.
 

Comparison Review

VS
Feb 26, 2015
HP ArcSight vs. IBM QRadar vs. ​McAfee Nitro vs. Splunk vs. RSA Security vs. LogRhythm
We at Infosecnirvana.com have done several posts on SIEM. After the Dummies Guide on SIEM, we are following it up with a SIEM Product Comparison – 101 deck. So, here it is for your viewing pleasure. Let me know what you think by posting your comments below. The key products compared here are…
 

Top Industries

By visitors reading reviews
Educational Organization
45%
Financial Services Firm
10%
Computer Software Company
9%
Manufacturing Company
5%
Financial Services Firm
16%
Computer Software Company
14%
Government
9%
Manufacturing Company
8%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

Any advice about APM solutions?
There are many factors and we know little about your requirements (size of org, technology stack, management systems, the scope of implementation). Our goal was to consolidate APM and infra monitor...
What do you like most about New Relic Insights?
The product's initial setup phase was very easy.
What needs improvement with New Relic Insights?
It helps prevent issues but does not cause losses. The error messages and deep insights may help us find the root cause and resolve the issue. It could be bit better. We are looking at sorting the ...
What SOC product do you recommend?
For tools I’d recommend: -SIEM- LogRhythm -SOAR- Palo Alto XSOAR Doing commercial w/o both (or at least an XDR) is asking to miss details that are critical, and ending up a statistic. Also, rememb...
What is a better choice, Splunk or Azure Sentinel?
It would really depend on (1) which logs you need to ingest and (2) what are your use cases Splunk is easy for ingestion of anything, but the charge per GB/Day Indexed and it gets expensive as log ...
How does Splunk compare with Azure Monitor?
Splunk handles a high amount of data very well. We use Splunk to capture information and as an aggregator for monitoring information from different sources. Splunk is very good at alerting us if we...
 

Also Known As

New Relic Browser, New Relic Applied Intelligence, New Relic Insights, New Relic Synthetics, New Relic Servers, New Relic APM
No data available
 

Learn More

 

Overview

 

Sample Customers

World Fuel Services, Verizon, FootLocker, McDonald's, Trainline, Mondia Media, Confused, Costa Coffee, Ryanair, Marks & Spencer, William Hill, Delivery Hero, Skyscanner, BASF, DAZN, Veygo, Virtuo, movingimage, talabat, Australia Post, Tokopedia, Seven Network, Virgin Australia, Zomato, BigBasket, Mercado Libre, Lending Club
Splunk has more than 7,000 customers spread across over 90 countries. These customers include Telenor, UniCredit, ideeli, McKenney's, Tesco, and SurveyMonkey.
Find out what your peers are saying about New Relic vs. Splunk Enterprise Security and other solutions. Updated: October 2024.
815,854 professionals have used our research since 2012.