Try our new research platform with insights from 80,000+ expert users

Splunk Enterprise Security vs vRealize Network Insight comparison

 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Splunk Enterprise Security
Average Rating
8.4
Reviews Sentiment
7.6
Number of Reviews
304
Ranking in other categories
Log Management (1st), Security Information and Event Management (SIEM) (1st), IT Operations Analytics (1st)
vRealize Network Insight
Average Rating
8.6
Reviews Sentiment
8.1
Number of Reviews
45
Ranking in other categories
Network Monitoring Software (20th), IT Infrastructure Monitoring (18th)
 

Mindshare comparison

While both are Systems Management solutions, they serve different purposes. Splunk Enterprise Security is designed for Security Information and Event Management (SIEM) and holds a mindshare of 9.8%, down 13.5% compared to last year.
vRealize Network Insight, on the other hand, focuses on IT Infrastructure Monitoring, holds 0.5% mindshare, down 0.6% since last year.
Security Information and Event Management (SIEM)
IT Infrastructure Monitoring
 

Featured Reviews

ROBERT-CHRISTIAN - PeerSpot reviewer
Has many predefined correlation rules and is brilliant for investigation and log analysis
It is very complicated to write your own correlation rules without the help of Splunk support. What Splunk could do better is to create an API to the standard SIEM tools, such as Microsoft Sentinel. The idea would be to make it less painful. In ELK Stack, Kibana is the query language with which you can search log files. I believe Splunk has also a query language in which they search their log files, but once you have identified the log file that you want to use for further security correlation, you want to very quickly transport that into your SIEM tool, such as Microsoft Sentinel. That is something that Splunk could make a little bit less painful because it is a lot of effort to find that log file and forward it. An API with Microsoft Sentinel or a similar SIEM tool would be a good idea.
NiteshKumar1 - PeerSpot reviewer
The tool's configuration is easy and artifacts are easily accessible through professional services and the web
The product is highly regarded, and many customers have been using it along with other VMware products like vSphere and VMware vCloud Usage Insight. However, recently, there's been a trend among customers, especially those using VMware for a considerable period, to explore the potential of migrating to the public cloud. The common concern among these customers is how the VMware products will perform in the public cloud environment. Migrating instances from VMware to different platforms is not easy, especially when dealing with many instances across multiple customers. Customers are keen to maintain the functionality of their existing VMware products but prefer to run them on the public cloud instead of on-premise servers. Our clients for vRealize Network Insight are enterprise businesses. I rate it a nine out of ten.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"It provides logs in one place, so they are easy to find. It collects the logs from multiple places, then you have just one place where you see the whole flow from the front-end to the back-end."
"Splunk Enterprise Security offers valuable features like seamless integration and a SQL-standard Structured Query Language for easy searching."
"We used it to create a custom anomaly detection data model to monitor the activity of our back-end services on an hourly basis relative to the past three months of activity."
"The most valuable function is the notable events. When I joined the team, I asked them what they could currently see, and they said nothing. I was pretty shocked. I know for a fact that they're using Enterprise Security or at least they had purchased it. I told them that there are several dashboards within Splunk that we can leverage. There is also notable events where we can see potential incidents or potential alerts about the infrastructure and the network itself."
"I really like the user interface and how it works."
"it can explain to management about what kind of traffic is visiting the network. It can also explain other traffic coming in and out, along with protecting against malware."
"The stock analysts and security people use one single dashboard (one single location) to check our logs."
"Exporting is a good feature. It helps me out when I have to do reports. I do a lot of exporting and crunching of the numbers. Dashboards are okay for showing to the leadership, but for doing statistics and updating tickets, the export feature is very beneficial for me."
"The initial setup was straightforward."
"A lot of time is saved when you use this type of software solution for the network. We have moved systems into the new data center and the servers and systems are much faster because of the very low latency between virtual machines."
"I find it user-friendly and intuitive. With the GUI interface that we do use on a regular basis, it's easy to navigate, it's easy to see, easy to query. We get reports. It's easy to use."
"It has definitely helped us to meet compliance rules by assuring that all traffic is going to where it's supposed to go. It can be used to report that you are in compliance, as well as helping you get into compliance."
"We can see everything going on in NSX and get a good picture of our environment."
"The gradual way the Network Insight shows you all the relevant information about your networks. It's pretty good. You can really dig deep deep inside and see where the problem is, where it comes from, what you have inside, how did you configure it. Also, it has alerts so you can have pretty much quite a big overview about your network. This is really something good."
"One of the most valuable features is the ability to look at the traffic flows, to look at NetFlow data."
"It allows us to see how the network devices function as well as to see network glitches or fluctuations or dropping of packets."
 

Cons

"Splunk needs local technical support."
"For on-premise, it's more about optimization. With such a heavy byte scale of data that we are operating on, the search for disparate data sometimes takes about a minute. This is understandable considering the amount of data that we are pumping into it. The only optimization that I recommend is better sharding, when it comes to Splunk, so that data retrieval can be faster."
"Splunk is such a large product. Allowing it to be more easily used by people who have not had a lot of training on it would be an improvement."
"Its interface and usability can always be improved."
"The solution has a high learning curve for users. It's a little complicated when you're trying to figure out all the features and what they do."
"The search could be improved. Now, it is a bit difficult to write search queries because they become quite long, then maintaining those long search queries is a quite challenging."
"The access and identity features could be improved. For example, let's say we have onboarded 65 logs. Now, we can identify the various processes, but we run into trouble when we're updating the processes for AWS CloudTrail, EDR, MDR, and XDR."
"It'd be really nice if Splunk Enterprise Security had a better and solid configuration guide."
"It just needs to be more reliable and more accurate. At some point, there are some things where it does not match properly."
"When we talk about those micro-segmentation rules, there's an Export function. It is very macro-segmentation oriented instead. So if you choose an application, it will find the tiers within that application and say that it's communicating on, say, port 80 to a separate VLAN. There might be 200 machines in that other VLAN. You don't want to open port 80 at all of them. So we need a lot more granularity in those suggested firewall rules."
"There is room for improvement when it comes to pricing because we pay here in Brazil, and all the costs are based on the dollar."
"The product is slightly complex use, while still being user-friendly. It could use more training modules, as it is not a straightforward product."
"The IT infrastructure industry is expected to evolve towards a hybrid cloud model in the next five to ten years. In this model, most of the customer's resources reside on-premise within a private cloud setup, such as VMware. Another segment operates within public cloud environments like Azure and AWS, and a portion remains in traditional data centers. There should be seamless interoperability between public and private clouds. AWS and VMware need to work together to make it possible. Whether users interact with on-premise infrastructure or configure resources in the public cloud, the user experience must be seamless."
"The only real improvement they can make is to add more third-party vendors into the environment, mostly switch manufacturers, because it's really limited to Cisco equipment and there are a lot of companies out there other than Cisco."
"After you use it for a little while you become accustomed to it but the layout doesn't feel very intuitive. You have to dig around and find the exact place where you can find the information, where you can actually see your east-west traffic, etc. I would like them to bring that information more to the forefront, instead of having to find it."
"Support could be much better."
 

Pricing and Cost Advice

"Splunk is priced higher than other solutions."
"The licensing model can be expensive, but the value it provides is significant."
"Splunk is costly but it’s worth it due to the high-end features."
"Unlike other security tools, Splunk provides a fixed amount of gigabytes per day, and we are required to pay for any additional usage beyond that limit, in addition to our monthly cost."
"The pricing can be better. We are already considering Elastic because Splunk is too expensive. You have to pay based on per-day ingestion. There should be a more flexible model for the use cases where one day you have a huge amount, and on other days, it is quite less."
"The price of Splunk Enterprise Security is reasonable, falling somewhere in the middle range."
"The price can always be lower, but it is fair at the moment. The cost efficiencies depend on the licensing and how much data we are bringing in. We have a fairly large footprint, so it is cost-effective."
"I've heard Splunk is often preferred over other options, but the cost can be prohibitive for smaller organizations."
"I rate vRealize Network Insight's pricing a seven point five out of ten."
"It's an expensive product because we have a lot of nodes."
"It's a little expensive, but for what you're getting out of the product, you often see the trade-off. It depends on the type of licensing you have. It might be a little too pricey for some."
"Cost always has room for improvement, you could always make it cheaper. But I think it's a good value for what you pay for it."
"We have spent less time investigating network flows, so it is absolutely cost-effective."
"The solution has helped us to reduce time, increase performance, reduce costs, and even easily manage networks. We are probably seeing 10 to 20 percent labor savings because we are able to be very specific and focused on what we want to do. It ends up saving the customer money and makes us be more efficient on our cost deliveries."
"They should include the product in NSX because it's important to have it for deployment."
"It reduces costs. It takes something that may be challenging and makes it more usable and visual by being able to bring in tools, seeing what their impact is, such as microsegmentation and application rationalization, and seeing it quickly."
report
Use our free recommendation engine to learn which Security Information and Event Management (SIEM) solutions are best for your needs.
838,713 professionals have used our research since 2012.
 

Comparison Review

VS
Feb 26, 2015
HP ArcSight vs. IBM QRadar vs. ​McAfee Nitro vs. Splunk vs. RSA Security vs. LogRhythm
We at Infosecnirvana.com have done several posts on SIEM. After the Dummies Guide on SIEM, we are following it up with a SIEM Product Comparison – 101 deck. So, here it is for your viewing pleasure. Let me know what you think by posting your comments below. The key products compared here are…
 

Top Industries

By visitors reading reviews
Financial Services Firm
16%
Computer Software Company
14%
Manufacturing Company
8%
Government
8%
Financial Services Firm
16%
Computer Software Company
13%
Manufacturing Company
11%
Government
10%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

What SOC product do you recommend?
For tools I’d recommend: -SIEM- LogRhythm -SOAR- Palo Alto XSOAR Doing commercial w/o both (or at least an XDR) is asking to miss details that are critical, and ending up a statistic. Also, rememb...
What is a better choice, Splunk or Azure Sentinel?
It would really depend on (1) which logs you need to ingest and (2) what are your use cases Splunk is easy for ingestion of anything, but the charge per GB/Day Indexed and it gets expensive as log ...
How does Splunk compare with Azure Monitor?
Splunk handles a high amount of data very well. We use Splunk to capture information and as an aggregator for monitoring information from different sources. Splunk is very good at alerting us if we...
What do you like most about vRealize Network Insight?
The tool's ease of configuration and use and the availability of information and artifacts through professional services and the web are key factors that customers find valuable.
What is your experience regarding pricing and costs for vRealize Network Insight?
The sales team often complains about the cost whenever we need to quote vRealize Network.
What needs improvement with vRealize Network Insight?
Since Broadcom acquired VMware, it has been experiencing challenges. Many sales processes are not well defined. They can show a little bit more information because vRealize Network Insight is virtu...
 

Also Known As

No data available
Arkin
 

Overview

 

Sample Customers

Splunk has more than 7,000 customers spread across over 90 countries. These customers include Telenor, UniCredit, ideeli, McKenney's, Tesco, and SurveyMonkey.
NTTi3, VCIX-NV, VMware Networking and Security Business Unit, Illumio, CompuNet
Find out what your peers are saying about Splunk, Wazuh, Microsoft and others in Security Information and Event Management (SIEM). Updated: January 2025.
838,713 professionals have used our research since 2012.