Try our new research platform with insights from 80,000+ expert users

SolarWinds Server and Application Monitor vs Splunk Enterprise Security comparison

 

Comparison Buyer's Guide

Executive Summary
 

Categories and Ranking

SolarWinds Server and Appli...
Average Rating
8.0
Reviews Sentiment
5.9
Number of Reviews
40
Ranking in other categories
Application Performance Monitoring (APM) and Observability (22nd), Server Monitoring (10th), Active Directory Management (14th)
Splunk Enterprise Security
Average Rating
8.4
Reviews Sentiment
7.6
Number of Reviews
303
Ranking in other categories
Log Management (1st), Security Information and Event Management (SIEM) (1st), IT Operations Analytics (1st)
 

Mindshare comparison

While both are Application Lifecycle Management solutions, they serve different purposes. SolarWinds Server and Application Monitor is designed for Server Monitoring and holds a mindshare of 4.7%, up 4.5% compared to last year.
Splunk Enterprise Security, on the other hand, focuses on Security Information and Event Management (SIEM), holds 10.8% mindshare, down 14.6% since last year.
Server Monitoring
Security Information and Event Management (SIEM)
 

Featured Reviews

Subhajit Nag - PeerSpot reviewer
The component and cable monitoring features are good, but the interface is slow
SolarWinds' interface is slow, and this is a global concern. Every SolarWinds user complains about the sluggishness. The response is slow. If you browse from one page to another, you have to wait. Our company is a massive user with plenty of licenses, so the performance issues could be due to the load per license. Ten thousand components can be mapped under one license. So SolarWinds needs to take care of the speed problem. It cannot be this slow. That is a huge complaint. Otherwise, the tool is good. It should also be easier to upgrade SolarWinds. AppDynamics is harder to deploy but easier to upgrade. So AppDynamics takes a lot of time and effort to install, but you can upgrade it in minutes. SolarWinds is the opposite. It's easy to deploy, but upgrades take forever. To date, nobody can complete it on time, so the production environment is sitting idle. The upgrade time matters because you only install the solution once, but you'll need to upgrade the solution repeatedly over the life of the product. A complex installation isn't an issue, but I mind if the upgrade takes too long because it's already in production.
Avinash Gopu. - PeerSpot reviewer
Offers good visibility into multiple environments, significantly reduces our alert volume, and speeds up our security investigations
There are limitations with Splunk not detecting all user activity, especially on mainframes and network devices. This is because Splunk relies on agents, which cannot access certain workstations. In these cases, we have to rely on application data. For example, with mainframes, manual reports are generated and sent to Splunk, limiting visibility to what's manually reported. This lack of automation for specific platforms needs improvement from Splunk. Additionally, API access is limited for other applications that rely on API calls and requests. This requires heavy customization on Splunk's end. These are the main challenges we've encountered. Monitoring multiple cloud platforms, like Azure, GCP, and AWS, with Splunk Enterprise Security presents some challenges. While Splunk provides different connectors for each provider, consolidating data from two domains across distinct cloud environments can be complex. However, leveraging pre-built templates and Splunk's data collation capabilities can help overcome these hurdles. Despite initial difficulties, I believe Splunk can effectively address this task, earning it an eight out of ten rating for its multi-cloud monitoring capabilities. While Splunk Enterprise Security offers insider threat detection capabilities, its effectiveness could be enhanced by integrating with additional tools, such as endpoint security solutions. This integrated approach is particularly crucial for financial institutions, which often require dedicated endpoint security teams. While using multiple tools is valuable, further improvements within Splunk itself are also necessary. Considering both external integration and internal development, I would rate its current insider threat detection capabilities as three out of ten. Threat detection is where Splunk falls behind. While it offers tools, other use cases require additional work. PAM is an enterprise tool that centralizes information about users, servers, and everything else. It needs real-time monitoring, which I haven't seen in any of the companies I've worked for. They only rely on Splunk for alerting, but real-time monitoring should be handled by the endpoint security team's tools. This means there's no detection or analysis at the machine or endpoint level. Additionally, threat analysis reporting is also absent.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"The most valuable feature of SolarWinds Server and Application Monitor is the network devices' performance monitor is the best."
"The features like trends, capacity planning, recommendations, and diagnostics are the main items I focus on for added value."
"The solution is great for monitoring. If something is going wrong, we can immediately find the root cause."
"The application dependency feature identifies issues between applications and servers or within the network where the application is hosted. It highlights related problems, whether related to packet processing or other issues, enabling the creation of alerts and reports accordingly."
"AppInsight for SQL: Enables us to see the relevant error log entries on the same page as performance parameters."
"SolarWinds SAM has provided us with dynamic thresholds based on historical trends and requirements. The threshold gets configured automatically, so it's no longer necessary to configure it manually every time."
"The component and cable monitoring are good. SolarWinds is more intuitive and user-friendly than AppDynamics. The AppDynamics console is more complex because it's a more feature-rich solution, so it's not easy for somebody to pick it up."
"Hardware health: It allows for proactive monitoring of the hardware health and is a game changer."
"It has been really good at consolidating a lot of data from different sources. It's really good at generating summaries."
"We are much faster finding and addressing issues with Splunk."
"The most valuable features include the incident review and Dashboard Studio."
"The dashboard is amazing. Out-of-the-box dashboard is very good. It is very user-friendly."
"The most valuable features of Splunk Enterprise Security are the enterprise search bar and the dashboards."
"It has virtual visualization, and other products do not."
"I very much enjoy Splunk's robust search nature, which enables me to find the data I want within the data I have."
"The correlation searches are most valuable just because we are able to do things like RBA."
 

Cons

"This product has no real downside unless they fail to continue development of its capabilities."
"The templates could use improvement. Currently, they are quite complex. They should have drag-and-drop functionality instead. It would make it easier to use."
"An additional feature that would improve this solution is the ability to complete root cause analysis."
"I believe that some of the trends, environmental maps, and items like those found in Orion would be very beneficial."
"Downside of the tools is the web console are hung or crash. It need to improve the performance."
"I think they need to make reporting easier and more simple & dynamic."
"Nodes in Azure are able to be monitored with the use of agents, but this does not apply to cloud service offerings that are not node based."
"They should incorporate more artificial intelligence. There should also be more predictive features."
"I've never had too many issues with the stability. Years ago we had indexes crash but that was more on us. We didn't understand how to properly size Splunk."
"It currently has limited default rules and customizations. If they can concentrate more on the compliance part and the security information part, it would be helpful. The platform part is good, but it requires many features from the security aspect."
"The solution could improve by making it more business analysis oriented. The way it is now is designed more for developers."
"Splunk could add more ways to manage archiving and storage. There isn't a web interface. You can do this on the SaaS version, but the on-premise platform doesn't have this option. It has other things but no option for remote NAS. I would like to have a personal web interface where I can specify how long logs should be stored. To have this readily available on the web, you need to adjust some settings on the backend. That is tricky."
"More training on PetaData using artificial intelligence techniques to identify the events which are not normal and exceptions that would help the organization identify threats and malware on the go with results."
"The pricing can be better."
"The user access control could be much more granular, so that the admins can control r/w/x access for specific features of the product like dashboards, etc."
"The UI can be improved. Dashboards and reports can be better in terms of graphics."
 

Pricing and Cost Advice

"I have always said SolarWinds is very “proud” of their products, meaning they are expensive. I cannot afford to purchase all the licenses I need for all the SolarWinds products."
"SAM is not per server so the pricing model can be deceiving. If you have an enterprise environment, you will quickly exceed your licensing quickly. You should know this before going in."
"The tool is available for my company at a good price point."
"Pricing and licensing is fair for what you get. It does have a great bang-for-the-buck appeal."
"I think SolarWinds' pricing is very decent compared to other competitors in the market."
"When compared to other licensed models in the market, it stands out as one of the more cost-effective options."
"The licenses start from USD 3000.00 and go up to USD 20,000.00 for the year. It's a perpetual license. Nothing is free in SolarWinds, anything that you need is an additional cost."
"The product is expensive."
"Pricing is probably its weakest spot. As compared to some competitors, Splunk is really expensive."
"The Splunk licensing is high."
"Splunk Enterprise becomes extremely expensive after the 20GB/month license."
"It is quite expensive."
"Splunk Enterprise Security is not a cheap product, but I think it is worth every dollar that you pay."
"Splunk Enterprise Security is a worthwhile investment given the comprehensive range of features it offers."
"The pricing of Splunk Enterprise Security is high."
"Further reductions would be fantastic, and I believe that more and more people would flock to it."
report
Use our free recommendation engine to learn which Server Monitoring solutions are best for your needs.
825,399 professionals have used our research since 2012.
 

Comparison Review

VS
Feb 26, 2015
HP ArcSight vs. IBM QRadar vs. ​McAfee Nitro vs. Splunk vs. RSA Security vs. LogRhythm
We at Infosecnirvana.com have done several posts on SIEM. After the Dummies Guide on SIEM, we are following it up with a SIEM Product Comparison – 101 deck. So, here it is for your viewing pleasure. Let me know what you think by posting your comments below. The key products compared here are…
 

Top Industries

By visitors reading reviews
Educational Organization
45%
Computer Software Company
8%
Financial Services Firm
6%
Government
6%
Financial Services Firm
15%
Computer Software Company
14%
Government
9%
Manufacturing Company
8%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

What needs improvement with SolarWinds Server and Application Monitor?
One product area that could benefit from improvement is the synchronization of licensing periods across different modules. The misalignment of licensing terms can present commercial challenges when...
What SOC product do you recommend?
For tools I’d recommend: -SIEM- LogRhythm -SOAR- Palo Alto XSOAR Doing commercial w/o both (or at least an XDR) is asking to miss details that are critical, and ending up a statistic. Also, rememb...
What is a better choice, Splunk or Azure Sentinel?
It would really depend on (1) which logs you need to ingest and (2) what are your use cases Splunk is easy for ingestion of anything, but the charge per GB/Day Indexed and it gets expensive as log ...
How does Splunk compare with Azure Monitor?
Splunk handles a high amount of data very well. We use Splunk to capture information and as an aggregator for monitoring information from different sources. Splunk is very good at alerting us if we...
 

Also Known As

SolarWinds SAM
No data available
 

Learn More

 

Overview

 

Sample Customers

Andr. L. Riis AS, NetSuite
Splunk has more than 7,000 customers spread across over 90 countries. These customers include Telenor, UniCredit, ideeli, McKenney's, Tesco, and SurveyMonkey.
Find out what your peers are saying about SolarWinds Server and Application Monitor vs. Splunk Enterprise Security and other solutions. Updated: May 2023.
825,399 professionals have used our research since 2012.