Try our new research platform with insights from 80,000+ expert users

Qlik Sense vs Splunk Enterprise Security comparison

 

Comparison Buyer's Guide

Executive Summary
 

Categories and Ranking

Qlik Sense
Average Rating
8.6
Reviews Sentiment
7.2
Number of Reviews
115
Ranking in other categories
Data Visualization (2nd), Embedded BI (2nd)
Splunk Enterprise Security
Average Rating
8.4
Reviews Sentiment
7.1
Number of Reviews
301
Ranking in other categories
Log Management (1st), Security Information and Event Management (SIEM) (1st), IT Operations Analytics (1st)
 

Mindshare comparison

Qlik Sense and Splunk Enterprise Security aren’t in the same category and serve different purposes. Qlik Sense is designed for Data Visualization and holds a mindshare of 8.0%, down 10.6% compared to last year.
Splunk Enterprise Security, on the other hand, focuses on Security Information and Event Management (SIEM), holds 11.2% mindshare, down 15.0% since last year.
Data Visualization
Security Information and Event Management (SIEM)
 

Featured Reviews

Bruno Preti - PeerSpot reviewer
Provides ability to analyze data independently without relying on IT for every query
I would rate the scalability a ten out of ten. You can start with one user and easily scale up to even a thousand without limitations. We mainly have medium and enterprise, though we also have some small clients. But in the Italian market, "small" and "medium" have different meanings than other markets. A typical Italian medium company might only have 10-15 users, while in other markets, this would be considered small.
Avinash Gopu. - PeerSpot reviewer
Offers good visibility into multiple environments, significantly reduces our alert volume, and speeds up our security investigations
There are limitations with Splunk not detecting all user activity, especially on mainframes and network devices. This is because Splunk relies on agents, which cannot access certain workstations. In these cases, we have to rely on application data. For example, with mainframes, manual reports are generated and sent to Splunk, limiting visibility to what's manually reported. This lack of automation for specific platforms needs improvement from Splunk. Additionally, API access is limited for other applications that rely on API calls and requests. This requires heavy customization on Splunk's end. These are the main challenges we've encountered. Monitoring multiple cloud platforms, like Azure, GCP, and AWS, with Splunk Enterprise Security presents some challenges. While Splunk provides different connectors for each provider, consolidating data from two domains across distinct cloud environments can be complex. However, leveraging pre-built templates and Splunk's data collation capabilities can help overcome these hurdles. Despite initial difficulties, I believe Splunk can effectively address this task, earning it an eight out of ten rating for its multi-cloud monitoring capabilities. While Splunk Enterprise Security offers insider threat detection capabilities, its effectiveness could be enhanced by integrating with additional tools, such as endpoint security solutions. This integrated approach is particularly crucial for financial institutions, which often require dedicated endpoint security teams. While using multiple tools is valuable, further improvements within Splunk itself are also necessary. Considering both external integration and internal development, I would rate its current insider threat detection capabilities as three out of ten. Threat detection is where Splunk falls behind. While it offers tools, other use cases require additional work. PAM is an enterprise tool that centralizes information about users, servers, and everything else. It needs real-time monitoring, which I haven't seen in any of the companies I've worked for. They only rely on Splunk for alerting, but real-time monitoring should be handled by the endpoint security team's tools. This means there's no detection or analysis at the machine or endpoint level. Additionally, threat analysis reporting is also absent.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"This solution has improved our organization by making our analysis results available to customers."
"It has high performance when interacting with dashboards and reports."
"We have had an easy time supplying content to our customers."
"The drag and drop functionality provides an easy and fast development approach."
"It is very easy to use, and the Qlik data engine has been able to handle everything we have thrown at it."
"From siloed reports, we went to a centralized knowledge hub, combining cross-functional data, and helping decision-makers see the data as a whole, therefore making more informed decisions."
"It is extremely clean to view, easy to use, and intuitive to develop with. There are a host of online resources to provide assistance to new users."
"The solution is scalable."
"The most valuable features in Splunk Enterprise Security are the cluster capabilities."
"If I need to integrate devices for logs, it is easier with Splunk. We can integrate different applications, network devices, and databases. It is also very rich in documents. It is the best."
"The two features I appreciate most in Splunk Enterprise Security are the content management system and the inter-incident review dashboard."
"The benefits include the easy integration with other Splunk tools including Splunk UEBA, Splunk ITSI, and Splunk Core. The ease of integration and the organization's experience and familiarity with searching and passing logs through Splunk are the main benefits."
"The solution's most valuable feature is the incident review, which gives a good overview of our security incidents."
"I haven't had the chance to properly sink my teeth into Enterprise Security but so far I like that they added the MITRE ATT&CK features."
"The most valuable feature is the log aggregation, being able to scan through all of the logs."
"It is easy to use, and easy to implement."
 

Cons

"I would like to have the ability to better customize the visuals including changing fonts, sizing, colors, axes, and titles."
"Areas for improvement include user-friendliness, self-service, and some of the visualization options for generating reports."
"Qlik Sense requires one to have a lot of technical knowledge."
"I wish the product had the ability for slightly more customization. The out-of-the box charts and visualizations are fantastic, but I want to be able to tweak it without having to add outside extensions and widgets."
"Qlik Sense could include additional features for data preparation and integration, making it easier for users to clean, transform, and integrate data from various sources."
"Ability for the administrator to approve Community Sheets in the QMC and then move them into base sheets."
"Advanced graphs or visualizations must be in the built-in product, instead of building with open API extensions or mashups."
"Right now, it is complex and you have to understand the data model prior to analyzing it, so basically I would like to see an integration with Excel in the future."
"It would be nice if Splunk reduced the cost of training. Their training sessions are way too costly."
"I feel as though a major focus of upcoming releases should be set on Machine Learning, Predictive Analytics, and I would enjoy to see more security focused add-ons and apps developed by the vendor."
"Deployment is not difficult but the lock sources and configurations can take time."
"Stability is there, but every release has some bugs."
"Some of the search functions can be better. There has been a lot of talk at the conference about the update of SPL before each iteration. That will be a lot of help."
"I would like more assistance with use cases and help with teaching us how to use it once it's installed."
"The monitoring aspect of Splunk could be improved. We have to do some queries to get as much information as CrowdStrike or other solutions provide. If you run a big query, you will see a delay. That is the only concern we have because it will take some time if you query large data sets."
"Splunk does not build apps. They only go back and validate the apps that somebody has already built. They should have remote consulting support. They have a wonderful solution. They have 24/7 security. Nobody needs to depend on any third party and will therefore just buy Splunk on the cloud."
 

Pricing and Cost Advice

"Costs are a little high on the license/token side. However, if you look at the TCO, it is not too bad, particularly against Power BI."
"I would rate Qlik's pricing four out of five."
"Start small with tokens. You can always buy more."
"Qlik Sense pricing and licensing is like that of QlikView. It's on the high side for a small company, but it’s competitive among its peers. Use of licenses (referred to as tokens) is a bit confusing. There is a login access pass for infrequent or anonymous access."
"Understand the break over price point for switching to the Enterprise license."
"I'm not able to reveal the licensing cost for Qlik Sense, but because it was a huge deal, the cost was less than the usual cost. The license wasn't that costly. It was the infrastructure that was very costly."
"You need to pay 5,000 Norwegian kroner per user. Microsoft Power BI is slightly more expensive than Qlik Sense."
"Qlik Sense is pretty good in terms of price."
"Splunk Enterprise Security is priced lower than competitors."
"Its price is fair. Like with anything else, if you go into the cloud, different providers cost more, and you are able to throttle back or throttle up. The cost is comparable with anything else."
"Pricing is pretty fair."
"It's a yearly subscription."
"Splunk Enterprise Security is expensive but the solution is equipped with a lot of features."
"Free Splunk license for PoCs on personal machines and the ability to scale the PoC to an enterprise level app."
"While some clients find the cost of Splunk Enterprise Security to be on the higher end, its pricing is comparable to other SIEM solutions."
"The subscription is monthly."
report
Use our free recommendation engine to learn which Data Visualization solutions are best for your needs.
824,053 professionals have used our research since 2012.
 

Comparison Review

VS
Feb 26, 2015
HP ArcSight vs. IBM QRadar vs. ​McAfee Nitro vs. Splunk vs. RSA Security vs. LogRhythm
We at Infosecnirvana.com have done several posts on SIEM. After the Dummies Guide on SIEM, we are following it up with a SIEM Product Comparison – 101 deck. So, here it is for your viewing pleasure. Let me know what you think by posting your comments below. The key products compared here are…
 

Top Industries

By visitors reading reviews
Educational Organization
58%
Financial Services Firm
9%
Computer Software Company
5%
Manufacturing Company
5%
Financial Services Firm
15%
Computer Software Company
14%
Government
9%
Manufacturing Company
8%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

Seeking lightweight open source BI software
It depends on the Data architecture and the complexity of your requirement. Some great tools in the market are Qlik Sense, Power BI, OBIEE, Tableau, etc. I have recently started using Cognos Enter...
Seeking lightweight open source BI software
There are many...It would rather depend what System BI architecture or Enterprise legacy you have at your end...I would recommend as follows: 1) If you have legacies of SAP, Oracle - look for SAP...
What do you like most about Qlik Sense?
The most valuable features of Qlik Sense are its speed and seamless development of web technologies.
What SOC product do you recommend?
For tools I’d recommend: -SIEM- LogRhythm -SOAR- Palo Alto XSOAR Doing commercial w/o both (or at least an XDR) is asking to miss details that are critical, and ending up a statistic. Also, rememb...
What is a better choice, Splunk or Azure Sentinel?
It would really depend on (1) which logs you need to ingest and (2) what are your use cases Splunk is easy for ingestion of anything, but the charge per GB/Day Indexed and it gets expensive as log ...
How does Splunk compare with Azure Monitor?
Splunk handles a high amount of data very well. We use Splunk to capture information and as an aggregator for monitoring information from different sources. Splunk is very good at alerting us if we...
 

Also Known As

QlikSense
No data available
 

Learn More

 

Overview

 

Sample Customers

Abbvie, Airbus, Barclays, BT Openreach, BMW, Daimler AG, HSBC, IKEA, Nationwide Building Society, Royal Mail Group, Sanofi, Siemens, Wendy'', Vodafone, Volvo
Splunk has more than 7,000 customers spread across over 90 countries. These customers include Telenor, UniCredit, ideeli, McKenney's, Tesco, and SurveyMonkey.
Find out what your peers are saying about Salesforce, Qlik, Splunk and others in Data Visualization. Updated: November 2024.
824,053 professionals have used our research since 2012.