Try our new research platform with insights from 80,000+ expert users

Splunk Enterprise Security vs Splunk ITSI (IT Service Intelligence) comparison

 

Comparison Buyer's Guide

Executive SummaryUpdated on Jul 31, 2024

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Splunk Enterprise Security
Average Rating
8.4
Reviews Sentiment
7.6
Number of Reviews
303
Ranking in other categories
Log Management (1st), Security Information and Event Management (SIEM) (1st), IT Operations Analytics (1st)
Splunk ITSI (IT Service Int...
Average Rating
8.2
Reviews Sentiment
7.1
Number of Reviews
49
Ranking in other categories
Application Performance Monitoring (APM) and Observability (10th), IT Alerting and Incident Management (4th)
 

Featured Reviews

ROBERT-CHRISTIAN - PeerSpot reviewer
Has many predefined correlation rules and is brilliant for investigation and log analysis
It is very complicated to write your own correlation rules without the help of Splunk support. What Splunk could do better is to create an API to the standard SIEM tools, such as Microsoft Sentinel. The idea would be to make it less painful. In ELK Stack, Kibana is the query language with which you can search log files. I believe Splunk has also a query language in which they search their log files, but once you have identified the log file that you want to use for further security correlation, you want to very quickly transport that into your SIEM tool, such as Microsoft Sentinel. That is something that Splunk could make a little bit less painful because it is a lot of effort to find that log file and forward it. An API with Microsoft Sentinel or a similar SIEM tool would be a good idea.
Sunil K R - PeerSpot reviewer
Helps improve our incident response time, and our mean time to resolve, but visibility is limited
In my previous project, I successfully led the end-to-end deployment of a Splunk migration. The process went smoothly thanks in part to Splunk's professional services team. They conducted a thorough assessment, identified all our potential pain points, and developed a tailored solution and migration plan. This comprehensive approach ensured a seamless transition. Our core deployment team consisted of 5 internal members and two specialists from Splunk. Additionally, the project included a project manager and a product owner. We also benefited from the expertise of two professional service consultants and two representatives from the customer's side. An on-site admin architect further provided valuable technical support. Throughout the deployment process, we leveraged support from various resources whenever necessary. This included assistance with configuration changes, deployments, and other related tasks. We also collaborated effectively with our teammates to ensure a smooth and successful implementation.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"Easy to deploy and simple to use."
"The dashboard is amazing. Out-of-the-box dashboard is very good. It is very user-friendly."
"Splunk Enterprise Security offers valuable features like seamless integration and a SQL-standard Structured Query Language for easy searching."
"It is very easy to use and integrate. There are connectors for every technology."
"Alerts when a server is malfunctioning, monitors external attacks, and takes action to stop spreading viruses."
"The most valuable feature is the DSS, also known as SPL, because it allows users to script advanced queries with limited knowledge."
"The most valuable features of Splunk Enterprise Security are its high-performance data collection, flexible query language, and its versatility across the organization."
"Splunk's strength lies in its single-page view."
"I find the episode review, glass tables, and correlation search features very useful."
"Splunk ITSI can be easily integrated with the incident management platform. You can automate workflows and certain actions can be taken."
"The root cause analysis is very helpful for us."
"The most valuable features are the mapping of the entities, which provides a comprehensive analysis, and the service analyzer for thresholding."
"Having a structure on how to resolve incidents is the most valuable aspect."
"Splunk Episodes are valuable because it correlates and aggregates all the information, and you do not have one million events to look at and triage, so it is quite convenient."
"The solution has been stable."
"Splunk's intuitive interface and scalability make it accessible to non-technical users, and its capacity to monitor every millisecond of data across multiple applications is truly impressive."
 

Cons

"There is improvement needed when importing from some types of data sources."
"While there aren't any major areas where the solution has to be improved, there are certain integrations that are still not available. I would specifically like to see legacy applications integrated."
"I have concerns about the architecture as well since I can see it is not very well defined."
"​Not even Splunk's support guy, who came to our firm, could help with defining proper role management.​"
"I feel as though a major focus of upcoming releases should be set on Machine Learning, Predictive Analytics, and I would enjoy to see more security focused add-ons and apps developed by the vendor."
"The user interface is not user-friendly for non-technical users."
"The level of scalability depends on the license you have. You can expand or reduce it based on the environment. It does cost more money to scale, however."
"Make it easy to use and the cost cheaper. This will help all organisations to implement Splunk."
"The end-to-end visibility in Splunk ITSI is limited and has room for improvement."
"Currently, Glass tables in ITSI only display metrics related to KPIs."
"The user interface visualization could be improved."
"Splunk ITSI's UI needs to be more interactive and user-friendly."
"Quality-of-life features have room for improvement."
"We're getting alerts with delays of maybe five minutes, however, we'd like to see real-time alerting in the future."
"We have problems doing upgrades and operating alternate new versions."
"The dashboard function inside the individual episodes, not at the ITSI Notable Event Aggregation Policy level but actually at the correlation search layer, is an area where improvements are required."
 

Pricing and Cost Advice

"The Splunk licensing is high."
"Splunk licensing model might seem expensive but with all the gain in functionalities you will have compared to traditional SIEM solutions I think it’s worth the price."
"Splunk Enterprise Security's pricing is based on data volume, which generally suits large enterprises."
"Luckily, we come under a large federal agency, and before the pandemic, they signed a large enterprise license agreement. It worked out great and to our advantage because we are a small organization. We got a 300 gig license, and we just did not have the buying power to be able to get products cheaply. Because we all partnered together under the agency umbrella, we were able to get Splunk Enterprise Security, UBA, and ITSI for cheap. This was good considering the fact that some of these premium apps require a minimum number of users, and we do not have the number of people needed to even justify buying it."
"Splunk is not free."
"Splunk Enterprise Security incurs a significant cost because of the amount of data we send, but we are fine with the value we're getting for that price."
"Free Splunk license for PoCs on personal machines and the ability to scale the PoC to an enterprise level app."
"The pricing and licensing of the product are quite high."
"It is interesting. I am not involved that much lately, but if I recall correctly, you license primarily on the volume of data that you are using in Splunk ITSI, but there is no way Splunk can ever check if that is true, so that is interesting. We are not doing it, but someone can pretend to just use 10%, and it would be super cheap. It is tricky, but it is more tricky for Splunk than for us."
"Splunk ITSI is an expensive tool, and we need to purchase the utility license."
"Splunk ITSI is expensive."
"I would prefer that the price be reduced, as it would be easier to implement it and to sell it."
"The pricing of Splunk is a bit high."
"I wouldn't say there's been an issue with the solution's pricing because we went through the AWS marketplace and negotiated directly with Splunk."
"Its pricing has been changed as per the market. You get a good support service with it as well. They have 24/7 customer support. There is a portal, and if you are having issues, they are available in order to resolve them. So, its pricing isn't too much."
"Splunk ITSI is expensive compared to other tools."
report
Use our free recommendation engine to learn which Security Information and Event Management (SIEM) solutions are best for your needs.
831,265 professionals have used our research since 2012.
 

Comparison Review

VS
Feb 26, 2015
HP ArcSight vs. IBM QRadar vs. ​McAfee Nitro vs. Splunk vs. RSA Security vs. LogRhythm
We at Infosecnirvana.com have done several posts on SIEM. After the Dummies Guide on SIEM, we are following it up with a SIEM Product Comparison – 101 deck. So, here it is for your viewing pleasure. Let me know what you think by posting your comments below. The key products compared here are…
 

Top Industries

By visitors reading reviews
Financial Services Firm
15%
Computer Software Company
14%
Manufacturing Company
9%
Government
9%
Financial Services Firm
20%
Computer Software Company
13%
Government
13%
Manufacturing Company
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

What SOC product do you recommend?
For tools I’d recommend: -SIEM- LogRhythm -SOAR- Palo Alto XSOAR Doing commercial w/o both (or at least an XDR) is asking to miss details that are critical, and ending up a statistic. Also, rememb...
What is a better choice, Splunk or Azure Sentinel?
It would really depend on (1) which logs you need to ingest and (2) what are your use cases Splunk is easy for ingestion of anything, but the charge per GB/Day Indexed and it gets expensive as log ...
How does Splunk compare with Azure Monitor?
Splunk handles a high amount of data very well. We use Splunk to capture information and as an aggregator for monitoring information from different sources. Splunk is very good at alerting us if we...
What needs improvement with Splunk ITSI (IT Service Intelligence)?
Currently, Glass tables in ITSI only display metrics related to KPIs. I proposed adding an option to show metrics related to entities. This would eliminate the need for custom SPL to achieve this f...
 

Overview

 

Sample Customers

Splunk has more than 7,000 customers spread across over 90 countries. These customers include Telenor, UniCredit, ideeli, McKenney's, Tesco, and SurveyMonkey.
TransUnion, Cox Automotive, Carnival Cruises, Leidos, Econocom, National Ignition Factory, Entrust Datacard, Molina Healthcare, United States Census Bureau
Find out what your peers are saying about Splunk Enterprise Security vs. Splunk ITSI (IT Service Intelligence) and other solutions. Updated: May 2023.
831,265 professionals have used our research since 2012.