Try our new research platform with insights from 80,000+ expert users

Splunk Enterprise Security vs vRealize Network Insight comparison

 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Splunk Enterprise Security
Average Rating
8.4
Reviews Sentiment
7.6
Number of Reviews
303
Ranking in other categories
Log Management (1st), Security Information and Event Management (SIEM) (1st), IT Operations Analytics (1st)
vRealize Network Insight
Average Rating
8.6
Reviews Sentiment
8.1
Number of Reviews
45
Ranking in other categories
Network Monitoring Software (21st), IT Infrastructure Monitoring (17th)
 

Mindshare comparison

While both are Systems Management solutions, they serve different purposes. Splunk Enterprise Security is designed for Security Information and Event Management (SIEM) and holds a mindshare of 10.8%, down 14.6% compared to last year.
vRealize Network Insight, on the other hand, focuses on IT Infrastructure Monitoring, holds 0.5% mindshare, down 0.7% since last year.
Security Information and Event Management (SIEM)
IT Infrastructure Monitoring
 

Featured Reviews

ROBERT-CHRISTIAN - PeerSpot reviewer
Has many predefined correlation rules and is brilliant for investigation and log analysis
It is very complicated to write your own correlation rules without the help of Splunk support. What Splunk could do better is to create an API to the standard SIEM tools, such as Microsoft Sentinel. The idea would be to make it less painful. In ELK Stack, Kibana is the query language with which you can search log files. I believe Splunk has also a query language in which they search their log files, but once you have identified the log file that you want to use for further security correlation, you want to very quickly transport that into your SIEM tool, such as Microsoft Sentinel. That is something that Splunk could make a little bit less painful because it is a lot of effort to find that log file and forward it. An API with Microsoft Sentinel or a similar SIEM tool would be a good idea.
NiteshKumar1 - PeerSpot reviewer
The tool's configuration is easy and artifacts are easily accessible through professional services and the web
The product is highly regarded, and many customers have been using it along with other VMware products like vSphere and VMware vCloud Usage Insight. However, recently, there's been a trend among customers, especially those using VMware for a considerable period, to explore the potential of migrating to the public cloud. The common concern among these customers is how the VMware products will perform in the public cloud environment. Migrating instances from VMware to different platforms is not easy, especially when dealing with many instances across multiple customers. Customers are keen to maintain the functionality of their existing VMware products but prefer to run them on the public cloud instead of on-premise servers. Our clients for vRealize Network Insight are enterprise businesses. I rate it a nine out of ten.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"My favorite example of improving of organization is saving a $60k/mo in payroll fraud and $10k/mo in wasted API credits by using simple searches and clear reports."
"The feature that we use the most is the correlation search engine within ES."
"The scalability is good."
"You can integrate Splunk with third-party security automation solutions and set rules for automatic response."
"The most valuable feature of Splunk Enterprise Security is the comprehensive logging capabilities it provides."
"With good domain knowledge, one can build almost anything. If you throw in Alert Manager or an integration with ServiceNow. Then, you have your own SIEM"
"It gives us good visibility into multiple environments, including cloud, on-premises, and hybrid; irrespective of platform."
"We are using Microsoft 365 and we're using the Exchange Mail Service. It's good for monitoring that in particular."
"It is user-friendly. It's pretty simple to deploy and to run. It gives you pretty easy-to-understand reports, very graphically intense, so you can visualize what's going on in your network."
"It's a very powerful, very manageable product."
"The graphical interface of this environment is so good with all the views, the graphics, and everything in them. It's really easy for me. It doesn't need an engineer to work on it. It's easy enough that anyone can get into the environment and look for issues or look at how communication is going on across the VMs. It's pretty much straightforward."
"It's user-friendly. It's similar to the GUI that most VMware products are moving to, and the consistency across those makes it easy to switch from one product to another. Also, the search bar at the top is plain text and it helps you, it guides you along with your search query, so that helps. The first day you're in there you can start building actual queries."
"It allows us to see how the network devices function as well as to see network glitches or fluctuations or dropping of packets."
"The most valuable feature for us is that insight into what our network is really doing - it's a fairly complex network. Not having to go through thousands of lines of network configuration to find firewall ports that were open or closed, for various ports, was very valuable. It went out and found everything we need very quickly."
"It gives the visibility that was either broken or there in pieces only. This solution provides a unified view of the whole system, back and forth. It has helped to reduce time to value, increase performance, more easily manage networks, and provide deep visibility."
"Whenever we say "valuable" with respect to the network, it's more towards the security. The firewall rule issues it shows us and the recommendations that we get from vRNI are the most valuable features because they are actually making our network more secure."
 

Cons

"In the next releases, I would like to see more pricing flexibility."
"Our two main complaints are about the difficulty of the initial setup and the licensing model."
"Make it easier to include roles and user controls, as it is horrible now."
"There are a lot of competitive products that are doing better than what Splunk is doing on the analytics side."
"The main issue that I have with it is that the field transformations sometimes overlap with those in Splunk Enterprise, and then you get permissions issues that lead to troubles."
"The solution's automation could be improved."
"It needs integration with a configuration management solution."
"I've never had too many issues with the stability. Years ago we had indexes crash but that was more on us. We didn't understand how to properly size Splunk."
"While it's not exactly a feature, what normally happens when we are trying to look at the VM flow portion is - although Network Insight does have options to integrate a few physical switches into it - we can't really get an end-to-end flow of the network. We might be using a few switches that are not supported by Network Insight. That is where they can improve, in the support for more physical switches and network devices."
"I would like to see more reporting features, more dashboards."
"When we talk about those micro-segmentation rules, there's an Export function. It is very macro-segmentation oriented instead. So if you choose an application, it will find the tiers within that application and say that it's communicating on, say, port 80 to a separate VLAN. There might be 200 machines in that other VLAN. You don't want to open port 80 at all of them. So we need a lot more granularity in those suggested firewall rules."
"If it were more application-aware, more descriptive; if it were able to determine the application that is actually doing the communication, that would be easier. More application information: which user or account it's accessing, is it accessing this application, doing these calls, if it is accessing a script, what script is it accessing. Things like that would provide deeper analytics so I can track what's going on. It would not just be, "These people shouldn't be talking," but who is actually doing these calls."
"There is room for improvement when it comes to pricing because we pay here in Brazil, and all the costs are based on the dollar."
"There's enough information there, especially in the visualizations, but I would love to see this in a kiosk mode, where I could have a dashboard for interested stakeholders to see and appreciate what's going on. Then, moving on to a more practical level for our Help Desk, our operations team could benefit by seeing, in real-time, a visual view of the network."
"The only real improvement they can make is to add more third-party vendors into the environment, mostly switch manufacturers, because it's really limited to Cisco equipment and there are a lot of companies out there other than Cisco."
"There could be some deeper analytics into packet inspection and trace flows. It could use some kind of machine learning to look at Layer 7 traffic for potential malware or corrupt packets."
 

Pricing and Cost Advice

"Most people share the same thought that the ingestion rates can get pretty pricey. There is a lot of work we do to curate the data that we send to Splunk so that it is not too noisy or too expensive."
"The subscription is monthly."
"In addition to the licensing fee, there is also a support and maintenance charge."
"Splunk Enterprise Security is a worthwhile investment given the comprehensive range of features it offers."
"While Splunk is more expensive than other solutions, we would still choose it because of its capabilities."
"The licensing is good, but the pricing absolutely needs some work. It is very high."
"It's a yearly subscription."
"Splunk's cost is very high. They need to review the pricing. They have to go back and totally readdress the market."
"It's a little expensive, but for what you're getting out of the product, you often see the trade-off. It depends on the type of licensing you have. It might be a little too pricey for some."
"It has brought more money into our company."
"vRealize Network Insight is expensive."
"It reduces costs. It takes something that may be challenging and makes it more usable and visual by being able to bring in tools, seeing what their impact is, such as microsegmentation and application rationalization, and seeing it quickly."
"Cost always has room for improvement, you could always make it cheaper. But I think it's a good value for what you pay for it."
"They should include the product in NSX because it's important to have it for deployment."
"It's an expensive product because we have a lot of nodes."
"We have spent less time investigating network flows, so it is absolutely cost-effective."
report
Use our free recommendation engine to learn which Security Information and Event Management (SIEM) solutions are best for your needs.
831,158 professionals have used our research since 2012.
 

Comparison Review

VS
Feb 26, 2015
HP ArcSight vs. IBM QRadar vs. ​McAfee Nitro vs. Splunk vs. RSA Security vs. LogRhythm
We at Infosecnirvana.com have done several posts on SIEM. After the Dummies Guide on SIEM, we are following it up with a SIEM Product Comparison – 101 deck. So, here it is for your viewing pleasure. Let me know what you think by posting your comments below. The key products compared here are…
 

Top Industries

By visitors reading reviews
Financial Services Firm
15%
Computer Software Company
14%
Manufacturing Company
9%
Government
9%
Financial Services Firm
16%
Computer Software Company
13%
Government
11%
Manufacturing Company
10%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

What SOC product do you recommend?
For tools I’d recommend: -SIEM- LogRhythm -SOAR- Palo Alto XSOAR Doing commercial w/o both (or at least an XDR) is asking to miss details that are critical, and ending up a statistic. Also, rememb...
What is a better choice, Splunk or Azure Sentinel?
It would really depend on (1) which logs you need to ingest and (2) what are your use cases Splunk is easy for ingestion of anything, but the charge per GB/Day Indexed and it gets expensive as log ...
How does Splunk compare with Azure Monitor?
Splunk handles a high amount of data very well. We use Splunk to capture information and as an aggregator for monitoring information from different sources. Splunk is very good at alerting us if we...
What do you like most about vRealize Network Insight?
The tool's ease of configuration and use and the availability of information and artifacts through professional services and the web are key factors that customers find valuable.
What is your experience regarding pricing and costs for vRealize Network Insight?
The sales team often complains about the cost whenever we need to quote vRealize Network.
What needs improvement with vRealize Network Insight?
Since Broadcom acquired VMware, it has been experiencing challenges. Many sales processes are not well defined. They can show a little bit more information because vRealize Network Insight is virtu...
 

Also Known As

No data available
Arkin
 

Learn More

 

Overview

 

Sample Customers

Splunk has more than 7,000 customers spread across over 90 countries. These customers include Telenor, UniCredit, ideeli, McKenney's, Tesco, and SurveyMonkey.
NTTi3, VCIX-NV, VMware Networking and Security Business Unit, Illumio, CompuNet
Find out what your peers are saying about Splunk, Wazuh, Microsoft and others in Security Information and Event Management (SIEM). Updated: December 2024.
831,158 professionals have used our research since 2012.