Try our new research platform with insights from 80,000+ expert users

Prometheus vs Splunk Enterprise Security comparison

 

Comparison Buyer's Guide

Executive Summary
 

Categories and Ranking

Prometheus
Average Rating
8.4
Number of Reviews
33
Ranking in other categories
Application Performance Monitoring (APM) and Observability (9th)
Splunk Enterprise Security
Average Rating
8.4
Number of Reviews
301
Ranking in other categories
Log Management (1st), Security Information and Event Management (SIEM) (1st), IT Operations Analytics (1st)
 

Mindshare comparison

While both are Application Lifecycle Management solutions, they serve different purposes. Prometheus is designed for Application Performance Monitoring (APM) and Observability and holds a mindshare of 3.4%, down 3.8% compared to last year.
Splunk Enterprise Security, on the other hand, focuses on Security Information and Event Management (SIEM), holds 10.9% mindshare, down 14.3% since last year.
Application Performance Monitoring (APM) and Observability
Security Information and Event Management (SIEM)
 

Featured Reviews

Noam Blidstein - PeerSpot reviewer
Dec 22, 2022
A very flexible open box that can be used vastly to do anything you need
Make sure that you have dedicated manpower to configure and manage the solution. It requires handling, not necessarily on a daily basis, but it definitely requires someone who is focused and has expertise with the solution. Know in advance what you want to gain from the solution. Don't jump in to configuring or deploying before knowing what you expect from it. I like the solution very much. I think it is a major tool, especially in advanced environments. The open box provides a lot of flexibility and gives a very holistic view of the entire Kubernetes environment. Integrating with the Rancher management tool gives the solution even more abilities. There are several tools that we use behind the scenes to ease the process but the solution on its own is a very good tool. I rate the solution an eight out of ten.
Sameep Agarwal. - PeerSpot reviewer
Oct 23, 2023
It has a drag-and-drop interface, so you don't need to know SQL or Java to construct a query
The ingestion happens quickly, so you can run up the data costs if you use the default settings. It isn't a problem for government agencies in the Saudi market, but many of the corporations in India are small or medium-sized enterprises that cannot afford that kind of ingestion system. Splunk needs to be tweaked in JSON so you can limit what is coming from the endpoints, especially the events. One needs to filter that out so that only certain events are ingested, like login failures, Active Directory changes, password reset requests, privilege modifications, etc. Each Windows machine generates about 310 KB of information per event, but we can tweak that down to about 50 KB.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"Prometheus is a great solution for monitoring."
"Prometheus is an open-source product that helps mold and improve it per our requirements. It is a lightweight solution that gives you many different metrics you can use in your application. The product offers complete granularity of your infrastructure. It integrates seamlessly with other tools like Grafana, which offers dashboard visibility. Prometheus is an extensively used product. I haven't seen any organization that is not using it."
"I like its lightweight configuration functions."
"The solution is useful to collect huge metrics."
"The most valuable feature is that we can receive information in different formats."
"The most valuable features of Prometheus are the many functions available. The functions are helpful for understanding the behavior of applications and infrastructure."
"The product has an easy-to-understand interface."
"The most valuable feature of Prometheus is its ability to collect metrics."
"The risk-based alerting is excellent."
"The log aggregation is great."
"The correlation searches (properly configured) populate the Incident Management dashboard and provide me a quick birds-eye view of my most important concerns."
"It has a big user base, so the community is useful."
"The benefits include the easy integration with other Splunk tools including Splunk UEBA, Splunk ITSI, and Splunk Core. The ease of integration and the organization's experience and familiarity with searching and passing logs through Splunk are the main benefits."
"It is very scalable."
"The solution allows easy gathering and ingestion of the data."
"The solution's most valuable features are its ability to transact in the cloud and its ability to onboard data easily with minimum connectors."
 

Cons

"The scalability must be improved."
"They could provide efficient logs in terms of clarity and ease of access similar to Datadog’s paid version."
"A slight alteration to the user interface should be made to increase efficiency and streamline the process. Currently, we are utilizing Prometheus to gather and compile metrics and then utilizing Grafana to display them in the form of a graph. However, I believe that Prometheus has the capability to handle both of these tasks on its own, with perhaps the addition of a supplementary plugin. By doing so, the need for utilizing two separate applications will be eliminated."
"The query language in Prometheus is an area of concern where improvements are required."
"Prometheus requires improvement on the query side."
"The DSL could be improved."
"If you want to collect details of metrics, you should be able to write a query for it directly. I want the product to offer better queries for the metrics."
"There is a tool called Prometheus Exporter that doesn't work well."
"This is a costly solution."
"The support that is included with the standard licensing fee is very bad."
". Having a trial version or more training on Splunk would be helpful."
"There are new services which are coming up. If Splunk can catch up with the speed of Amazon, and with the integration, instead of us waiting for another year or so, that would be good."
"Splunk's implementation process for managing multiple indexes can be complex, especially when dealing with a large number of components."
"A problem that we had recently had was we licensed it based on how much data you upload to them every day. Something changed in one our applications, and it started generating three to four times as many logs and. So now, we are trying to assemble something with parts of the Splunk API to warn ourselves, then turn it off and throttle it back more. However it would be better if they had something systematically built into the product that if you're getting close to your license, then to shut things down."
"The case management area of the ES could be improved. The ability to move cases through various stages and states. The ability to close a case would be key improvement."
"The security can be improved."
 

Pricing and Cost Advice

"The product is free."
"My company uses the open-source version of the product."
"The product is expensive compared to Datadog."
"Prometheus is available as an open-source product."
"The price of Prometheus is good, it is affordable because it is open source and there is no cost to it. You put it on your own server and the costs incurred completely depend on how you set it up."
"Prometheus is an open-source solution."
"This is an open-source solution."
"The solution is open source."
"In terms of pricing, I believe Splunk is unreasonably costly for the majority of mid and small-sized companies."
"While Splunk offers generous developer licenses and obtaining annual licenses is straightforward, the cost is a major consideration."
"Splunk Enterprise Security is expensive."
"Splunk's cost is very high. They need to review the pricing. They have to go back and totally readdress the market."
"It's definitely worth it."
"The pricing model is expensive and a nightmare based on the amount of data."
"ROI is estimated at saving my team roughly 10 to 12 man hours per week in troubleshooting for our company as well as what our profits had been from our services of installing, configuring, and supporting other clients with the product."
"The pricing of Splunk Enterprise Security is high."
report
Use our free recommendation engine to learn which Application Performance Monitoring (APM) and Observability solutions are best for your needs.
814,763 professionals have used our research since 2012.
 

Comparison Review

VS
Feb 26, 2015
HP ArcSight vs. IBM QRadar vs. ​McAfee Nitro vs. Splunk vs. RSA Security vs. LogRhythm
We at Infosecnirvana.com have done several posts on SIEM. After the Dummies Guide on SIEM, we are following it up with a SIEM Product Comparison – 101 deck. So, here it is for your viewing pleasure. Let me know what you think by posting your comments below. The key products compared here are…
 

Top Industries

By visitors reading reviews
Financial Services Firm
26%
Computer Software Company
15%
Manufacturing Company
7%
Government
6%
Financial Services Firm
16%
Computer Software Company
14%
Government
9%
Manufacturing Company
8%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

What do you like most about Prometheus?
The most valuable feature of Prometheus is its ability to collect metrics.
What is your primary use case for Prometheus?
We use Prometheus for observability and analyzing data for business metrics and system metrics. It helps us with messaging services observability. It also helps a lot with the architecture and scal...
What SOC product do you recommend?
For tools I’d recommend: -SIEM- LogRhythm -SOAR- Palo Alto XSOAR Doing commercial w/o both (or at least an XDR) is asking to miss details that are critical, and ending up a statistic. Also, rememb...
What is a better choice, Splunk or Azure Sentinel?
It would really depend on (1) which logs you need to ingest and (2) what are your use cases Splunk is easy for ingestion of anything, but the charge per GB/Day Indexed and it gets expensive as log ...
How does Splunk compare with Azure Monitor?
Splunk handles a high amount of data very well. We use Splunk to capture information and as an aggregator for monitoring information from different sources. Splunk is very good at alerting us if we...
 

Learn More

 

Overview

 

Sample Customers

Information Not Available
Splunk has more than 7,000 customers spread across over 90 countries. These customers include Telenor, UniCredit, ideeli, McKenney's, Tesco, and SurveyMonkey.
Find out what your peers are saying about Prometheus vs. Splunk Enterprise Security and other solutions. Updated: May 2023.
814,763 professionals have used our research since 2012.