Splunk Enterprise Security and ScienceLogic are leaders in the data collection and analysis sector. Splunk appears to have a slight edge with its rapid data searching capabilities and comprehensive integration options.
Features: Splunk Enterprise Security offers advanced operational intelligence with rapid data searching and comprehensive log management. It integrates machine learning and provides detailed visualization options. It collects and correlates data from various sources, offering flexible and fast queries through its Search Processing Language (SPL). ScienceLogic excels in infrastructure monitoring with strong customization features and dynamic application integration. It emphasizes network performance and device management, supported by its flexible API and multi-tenant capabilities.
Room for Improvement: Splunk Enterprise struggles with integrating operational workflows, its GUI is complex, and visualization tools need a more user-friendly approach. Improvements in usability and ticketing system integrations are necessary. ScienceLogic requires enhancements in network processing, a simplified user interface, and better integration with third-party platforms. Its reporting capabilities could also be improved.
Ease of Deployment and Customer Service: Splunk Enterprise Security is adaptable across public, private, hybrid clouds, and on-premises environments. While it has active community support, response times from customer service could be better. ScienceLogic is deployed in private and hybrid clouds, with strong vendor support, but requires significant customization efforts during deployment.
Pricing and ROI: Splunk Enterprise Security is known for its high costs, driven by data volume, positioning it for large enterprises. It yields significant ROI through operational efficiencies despite licensing expenses. ScienceLogic's flexible pricing based on device count can also become costly for extensive scalability. Both solutions offer substantial returns through improved efficiency and data insights.
The return on investment is fair but often challenged by medium-sized businesses who may question its adequacy.
Splunk's cost is justified for large environments with extensive assets.
I received excellent support from ScienceLogic.
Problems with Skylar may require longer wait times due to limited resource expertise.
If you want to write your own correlation rules, it is very difficult to do, and you need Splunk's support to write new correlation rules for the SIEM tool.
The technical support for Splunk met my expectations.
It is easy to scale.
They struggle a bit with pure virtual environments, but in terms of how much they can handle, it is pretty good.
The stability rating is nine out of ten, acknowledging some bugs, but indicating these are minor issues.
It provides a stable environment but needs to integrate with ITSM platforms to achieve better visibility.
It is very stable.
If the knowledge for implementation could be spread through articles, it would reduce this dependency.
While some other companies have easier APIs, using this solution demands significant expertise.
Integrating observability and APM monitoring into the overall portfolio would be beneficial.
Splunk Enterprise Security would benefit from a more robust rule engine to reduce false positives.
What Splunk could do better is to create an API to the standard SIEM tools, such as Microsoft Sentinel.
Data retention can be better. If we want to look at the data for five months or six months, that is not available to us. We only have a history of 20 or 30 days.
It could be cheaper.
ScienceLogic is not that expensive and is cost-effective overall.
The platform requires significant financial investment and resources, making it expensive despite its comprehensive features.
I saw clients spend two million dollars a year just feeding data into the Splunk solution.
Splunk is priced higher than other solutions.
Notably, its automation features, such as Runbook action, enable domain experts like me to execute one-click automation solutions, which contributes significantly to reducing MTTR.
It offers over 500 integrations with a wide range of device types, referred to as PowerPacks, which are prebuilt integrations for hundreds, if not thousands, of integration types.
The CMDB update and the automatic CMDB update are valuable.
This capability is useful for performance monitoring and issue identification.
They have approximately 50,000 predefined correlation rules.
Splunk Enterprise Security's most valuable features are its stability and the robust Splunk Search Processing Language.
ScienceLogic is a comprehensive IT infrastructure monitoring solution that supports networks, servers, cloud environments, and applications, suitable for private cloud and on-premises deployments.
Organizations leverage ScienceLogic for its robust capabilities in monitoring IT infrastructures of all sizes. It offers granular discovery, integration with CMDB, and ticketing systems. Valued for its flexibility, incident automation, remediation, and real-time relationship mapping, it supports hybrid environments with scalable and efficient monitoring functionalities. AI and machine learning enhance its feature set, while ease of deployment and strong support are crucial benefits.
What are ScienceLogic's most important features?ScienceLogic is implemented across multiple industries, including large enterprises, for its capability to handle complex IT ecosystems. Its integration with CMDB and ticketing systems ensures it fits within existing workflows. Organizations use it to monitor diverse infrastructure landscapes, ensuring seamless performance and quick incident resolution.
Splunk Enterprise Security is widely used for security operations, including threat detection, incident response, and log monitoring. It centralizes log management, offers security analytics, and ensures compliance, enhancing the overall security posture of organizations.
Companies leverage Splunk Enterprise Security to monitor endpoints, networks, and users, detecting anomalies, brute force attacks, and unauthorized access. They use it for fraud detection, machine learning, and real-time alerts within their SOCs. The platform enhances visibility and correlates data from multiple sources to identify security threats efficiently. Key features include comprehensive dashboards, excellent reporting capabilities, robust log aggregation, and flexible data ingestion. Users appreciate its SIEM capabilities, threat intelligence, risk-based alerting, and correlation searches. Highly scalable and stable, it suits multi-cloud environments, reducing alert volumes and speeding up investigations.
What are the key features?Splunk Enterprise Security is implemented across industries like finance, healthcare, and retail. Financial institutions use it for fraud detection and compliance, while healthcare organizations leverage its capabilities to safeguard patient data. Retailers deploy it to protect customer information and ensure secure transactions.
We monitor all IT Operations Analytics reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.