Try our new research platform with insights from 80,000+ expert users

Splunk Enterprise Platform vs Unit 42 Managed Detection and Response comparison

 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Splunk Enterprise Platform
Average Rating
8.4
Reviews Sentiment
7.7
Number of Reviews
33
Ranking in other categories
Data Visualization (4th), IT Alerting and Incident Management (5th)
Unit 42 Managed Detection a...
Average Rating
0.0
Reviews Sentiment
7.8
Number of Reviews
1
Ranking in other categories
Managed Security Services Providers (MSSP) (60th), Managed Detection and Response (MDR) (47th)
 

Featured Reviews

Kundan Nagare - PeerSpot reviewer
Offers excellent data analysis and visualization capabilities
I use the Platform to monitor my IT infrastructure. There are apps for Linux and Windows servers that capture performance metrics like CPU and memory usage. These metrics are collected and sent to the blank index through forwarders. Splunk helps with security information and event management by detecting and monitoring network equipment and firewalls. It saves searches for specific terms, like threats, in firewall logs. When a match is found, it alerts about potential security breaches, helping to detect and address them. The real-time processing capability in Splunk enhances data monitoring by centrally collecting all data. This allows for easy searching and scheduling of searches, reducing the need for manual intervention. The dashboard and visualization features in Splunk impact data analysis by providing a clear status of data analysis. Users can create customized views for management, helping them understand what is happening within the infrastructure more effectively. I would recommend Splunk to others, especially from the CIM perspective. Its data analysis and visualization capabilities are unmatched, making it an excellent choice for SIM. Overall, I would rate Splunk Enterprise Platform as a nine out of ten.
MohammedSirajuddin - PeerSpot reviewer
Flexible and reduces IT operations but requires local data sovereignty and competitive pricing
I prefer having local data sovereignty. It would be advantageous for Palo Alto to have local data centers across different countries to adhere to this requirement. I also have a concern regarding pricing, which is perceived as high compared to competitors. Improvements should focus on response times and reducing the time taken to reach solutions.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"The most valuable features of Splunk Enterprise Platform include its performance, ease of implementation, and user interface, which are superior compared to other on-premises products."
"It is a scalable solution."
"It's not just one feature I like the most. Every person wants to collect and rate logs, and I value how the Splunk Enterprise Platform handles this.The most valuable part for us is setting up the alerts and reports to manage the logs and log metrics. We use it to support every tool across the entire bank.We are the ones who manage all the data, and if there's any issue, everything depends on the Splunk Enterprise Platform."
"Easy setup and maintenance"
"Splunk's real-time processing capability has been pretty good for my use cases."
"The most valuable feature I've found in the Splunk Enterprise Platform is its log readability and filtering capabilities. The filters on the left side are particularly useful, allowing me to quickly narrow down the data to what's relevant for any application or server service. The interesting fields feature helps me get the values I need most of the time."
"I found the incident notification to be very helpful."
"Splunk Enterprise Platform is a good tool to have, but it is expensive."
"Unit 42 MDR provides us with managed detection and response functionalities, eliminating the need for capital expenditure since it is an operational expenditure-based service."
"Unit 42 MDR provides us with managed detection and response functionalities, eliminating the need for capital expenditure since it is an operational expenditure-based service."
 

Cons

"While Splunk Enterprise Platform is a good product, it is expensive. Additionally, it is complex for inexperienced cybersecurity engineers and requires experienced personnel to handle it effectively."
"The solution's license cost is high and can be improved."
"The Splunk Processing Language (SPL) poses a steep learning curve for new users."
"It's not easy or feasible to reach out to Splunk directly."
"Splunk Enterprise Platform could improve in the area of basic log readability. When performing basic searches without advanced filters, the logs often contain timestamps and various unknown codes or other elements that can be confusing. Removing or simplifying these parts would make it easier for users who are not developers or do not have a development background to understand and find relevant information easily."
"There is room for improvement in introducing more AI capabilities onto Splunk Enterprise Platform."
"Based on my experience, I've noticed areas for improvement, particularly in support. Developers typically interact with support personnel who may lack technical expertise when raising support tickets. This can result in delays as initial interactions involve sharing documents before escalation to higher support levels."
"The tool lacked in providing a shareable format. I had to use pivot tables and manually parse and edit the data to create a visualization-friendly format. It was helpful when we had an issue. What would make it stronger is if it were more proactive. For example, if it highlighted major incidents and their impact on users without digging through notifications, that would be better. Typically, the first question we get is, "Oh, we had an incident. How bad was it? How many customers were impacted?" So having that information pop up from the notification would be helpful."
"I also have a concern regarding pricing, which is perceived as high compared to competitors."
"I have a concern regarding pricing, which is perceived as high compared to competitors."
 

Pricing and Cost Advice

"Product pricing is typically annual, and discounts are often available for longer-term commitments."
"I rate the product's pricing a ten on a scale of one to ten, where one is cheap, and ten is expensive. It is a very pricey tool."
"Splunk Enterprise Platform is an expensive solution."
"The product is expensive, and the cost depends on the amount of data ingestion."
"There are yearly payments to be made towards the licensing costs attached to the solution."
"On a scale from one to ten, where one is cheap, and ten is expensive, I rate the solution's pricing around seven or eight out of ten."
"The solution's pricing increases with the amount of data used. This pricing model is acceptable because it aligns with the security features provided. It ensures that the price reflects the level of security and the amount of data we're managing."
"I have heard from my managers that Splunk Enterprise Platform is an expensive solution."
Information not available
report
Use our free recommendation engine to learn which Data Visualization solutions are best for your needs.
849,190 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Hospitality Company
15%
Financial Services Firm
15%
Manufacturing Company
13%
Healthcare Company
12%
No data available
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
No data available
 

Questions from the Community

What do you like most about Splunk Enterprise Platform?
The most valuable features of the solution are the load balancing technique, the forwarding technique, and SSL certification.
What needs improvement with Splunk Enterprise Platform?
While Splunk Enterprise Platform is a good product, it is expensive. Additionally, it is complex for inexperienced cybersecurity engineers and requires experienced personnel to handle it effectively.
What is your primary use case for Splunk Enterprise Platform?
We are working with AppDynamics, Splunk Enterprise Platform, and other Splunk products. However, the main use case here is with Splunk Enterprise Platform.
What is your experience regarding pricing and costs for Unit 42 Managed Detection and Response?
I find the pricing to be expensive, especially when compared with competitors who offer significant discounts. Palo Alto has room to become more competitive in its pricing.
What needs improvement with Unit 42 Managed Detection and Response?
I prefer having local data sovereignty. It would be advantageous for Palo Alto to have local data centers across different countries to adhere to this requirement. I also have a concern regarding p...
What is your primary use case for Unit 42 Managed Detection and Response?
Unit 42 is a Managed Detection and Response solution with MDR capabilities. I use it in a managed service context where my organization's security needs are catered to by Palo Alto. Generally, it i...
 

Overview

Find out what your peers are saying about Salesforce, Qlik, Splunk and others in Data Visualization. Updated: April 2025.
849,190 professionals have used our research since 2012.