Try our new research platform with insights from 80,000+ expert users

AWS X-Ray vs Splunk Enterprise Security comparison

 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

AWS X-Ray
Average Rating
7.8
Reviews Sentiment
6.6
Number of Reviews
11
Ranking in other categories
Application Performance Monitoring (APM) and Observability (14th)
Splunk Enterprise Security
Average Rating
8.4
Reviews Sentiment
7.3
Number of Reviews
369
Ranking in other categories
Log Management (2nd), Security Information and Event Management (SIEM) (1st), IT Operations Analytics (1st)
 

Mindshare comparison

While both are Application Lifecycle Management solutions, they serve different purposes. AWS X-Ray is designed for Application Performance Monitoring (APM) and Observability and holds a mindshare of 2.5%, down 3.4% compared to last year.
Splunk Enterprise Security, on the other hand, focuses on Security Information and Event Management (SIEM), holds 8.7% mindshare, down 10.9% since last year.
Application Performance Monitoring (APM) and Observability Market Share Distribution
ProductMarket Share (%)
AWS X-Ray2.5%
Dynatrace8.1%
Datadog6.6%
Other82.8%
Application Performance Monitoring (APM) and Observability
Security Information and Event Management (SIEM) Market Share Distribution
ProductMarket Share (%)
Splunk Enterprise Security8.7%
Wazuh9.3%
IBM Security QRadar6.5%
Other75.5%
Security Information and Event Management (SIEM)
 

Featured Reviews

Muhmad Tabrez A Deewanji - PeerSpot reviewer
Improving performance through efficient trace metrics and data insights
As an application developer and architect, I appreciate AWS X-Ray for checking latency and identifying bottlenecks. I use it for performance tuning, conducting performance testing on applications, getting real-time traces, and gaining data insights. It helps in improving throughput and tuning infrastructure. The trace metrics and data collected provide valuable insights.
Kyle Vernham - PeerSpot reviewer
Built-in searches and unified data access streamline alert investigation and boosts analyst efficiency
The two features I appreciate the most in Splunk Enterprise Security are the built-in searches, which have been very easy for us to get started with right out of the box, and the fact that it accesses all of our other systems. You can access it as a pane of glass rather than having to search individually. We also have the option to compare our analysts from our service to service. Splunk Enterprise Security helps our SOC team prioritize and investigate high-fidelity alerts more effectively by providing a more in-depth look and the ability to access a lot more of our data. Instead of jumping from several segmented systems, it allows us to have everything brought together in one place. For example, you have to move from our purview to our build system and to Splunk Enterprise Security, and it enables us to streamline that process. The built-in features of Splunk Enterprise Security, which we recently procured, have given us a good starting point and demonstrated the value of the product, providing an easy way to sell it to our company. The ease of getting everything into our purview helps us, and it serves as a good start for the investigation part in one location rather than what we usually have, which is jumping from system to system to system. Splunk Enterprise Security plays a role in our company's strategy to combat insider threats and advanced persistent threats by currently being in its technical test phase. We are still rolling it out, and it should help us find any insider threats based on information that our policy states should not be present in our system. Splunk Enterprise Security's risk-based alerting (RBA) has impacted our alert volume and analyst productivity because we've got many different systems feeding into it. However, it has helped to make it easier for our analysts to go through a set of events rather than 100 alerts. RBA allows us to streamline the process and customize it for our analysts. When it comes to leveraging Splunk Enterprise Security's dashboards and visualizations to communicate security posture to executives, it's pretty straightforward for any type of information. The visualization is easy to understand, but I haven't had any direct conversations with our executives.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"AWS X-Ray is a strong solution and has a smooth integration process."
"AWS X-Ray shows us exactly when there are delays, helping us understand the depth of issues and what is happening point-to-point."
"The most beneficial feature is that it shows a dashboard for performance intervals, which reveals latencies."
"AWS X-Ray shows us exactly when there are delays, helping us understand the depth of issues and what is happening point-to-point."
"The solution has made it easier for us to trace the problems that we have with our requests and to monitor the timing of each step in each request we do in our endpoints."
"AWS X-RAY identifies bottlenecks in terms of stability and performance and how long certain data lives in terms of response time and duration."
"The most promising feature of AWS X-Ray is that you can debug the issues through the proper logs. You can also get an analysis out of the logs for some use cases, though I have yet to try all the features of AWS X-Ray."
"The error analysis capabilities of X-Ray are really good."
"The biggest advantage I can see in Splunk Enterprise Security is the big data analytics."
"The tool helps with advanced reports and keeps the system scalable and flexible. It provides a clear picture of the current status of any incidents. As a CISO, I see a lot of potential for future innovation, which is interesting. I've noticed better performance, especially with the reports."
"Exporting is a good feature. It helps me out when I have to do reports. I do a lot of exporting and crunching of the numbers. Dashboards are okay for showing to the leadership, but for doing statistics and updating tickets, the export feature is very beneficial for me."
"We were able to create a catalog of dashboards and have a holistic view at all levels. We could understand our business much better. Real-time errors, which were buried in emails before now, surfaced up on dashboards."
"Splunk Enterprise Security's most valuable features are its stability and the robust Splunk Search Processing Language, allowing extensive customization and analysis capabilities."
"If I need to integrate devices for logs, it is easier with Splunk. We can integrate different applications, network devices, and databases. It is also very rich in documents. It is the best."
"It has supported our SOC by improving it."
"The most valuable feature is the ability to look at threats and link them to the MITRE ATT&CK framework."
 

Cons

"Like most Amazon products, the user interface, configuration, and tuning aren't the easiest. That's the biggest reason why people tend to go to products like TerraForm and Terragrunt. We use TerraForm and Terragrunt. So, for setting things up and interacting with X-Ray, it's definitely the user interface that can be better."
"The user interface is sometimes kind of confusing to understand. It's not very user-friendly."
"A significant downside is that it is very expensive."
"I do not have any notes in terms of improvements."
"It should have X-Ray SDKs for different languages like Node.js, Python, or Java."
"If you have a small team, it's probably overkill."
"Compared to other open-source tools, AWS X-Ray needs improvement in providing discounts."
"They can improve how traces are sent to other providers."
"The first thing that comes to mind is a little bit of UI improvement. It sometimes can be a little bit buggy or it can be a little bit slow, but that varies from customer to customer."
"When we do a rollout from the server or host or anything, we'd like to see more automation. It would save us time."
"I would like to get visibility into the data pipelines on heavy forwarders and indexers to see exactly their source and the cause of saturation when it occurs. This would help us learn even more about our high use applications."
"Improving the infrastructure behind Splunk Enterprise Security is vital—enhanced cores, CPUs, and memory should be prioritized to support better processing power. When we execute heavy, resource-intensive queries over long periods, the performance dips."
"Splunk can improve its third-party device application plugins."
"There is improvement needed when importing from some types of data sources."
"If possible, we would like to have not only a log monitoring system but a network monitoring feature in this solution as well."
"We find that the maintenance process could be a lot better."
 

Pricing and Cost Advice

"As you develop a relationship with Amazon, your pricing gets lower. You get credits for the amount of the system you use, and then if you're the government, you can get government pricing. For commercial users, there's a hump when you go from small to medium to big enterprise. Small businesses can live pretty easily off the free tier in a lot of cases, but when you go from a medium to a big enterprise, it becomes more expensive on a per-user basis. I'd like to see that curve going in a different way where pricing can be driven down while people are trying to adopt the technology."
"The pricing for AWS X-Ray is a six out of ten."
"The solution is a bit expensive."
"It is expensive. I used to buy it early on, but then they combined it into a higher-up organization. They buy it for multiple systems now. Last time, I paid around 60K for it. There is just the licensing fee. That's all."
"Splunk's cost is very high. They need to review the pricing. They have to go back and totally readdress the market."
"While Splunk is more expensive than other solutions, we would still choose it because of its capabilities."
"Luckily, we come under a large federal agency, and before the pandemic, they signed a large enterprise license agreement. It worked out great and to our advantage because we are a small organization. We got a 300 gig license, and we just did not have the buying power to be able to get products cheaply. Because we all partnered together under the agency umbrella, we were able to get Splunk Enterprise Security, UBA, and ITSI for cheap. This was good considering the fact that some of these premium apps require a minimum number of users, and we do not have the number of people needed to even justify buying it."
"I think that most of the monitoring solutions are expensive."
"Splunk Enterprise Security is priced lower than competitors."
"Splunk can be expensive, as its licensing is based on the daily data ingestion volume."
"Our customers often complain that the price of Splunk is too high."
report
Use our free recommendation engine to learn which Application Performance Monitoring (APM) and Observability solutions are best for your needs.
873,085 professionals have used our research since 2012.
 

Comparison Review

VS
Feb 26, 2015
HP ArcSight vs. IBM QRadar vs. ​McAfee Nitro vs. Splunk vs. RSA Security vs. LogRhythm
We at Infosecnirvana.com have done several posts on SIEM. After the Dummies Guide on SIEM, we are following it up with a SIEM Product Comparison – 101 deck. So, here it is for your viewing pleasure. Let me know what you think by posting your comments below. The key products compared here are…
 

Top Industries

By visitors reading reviews
Financial Services Firm
16%
Computer Software Company
16%
Manufacturing Company
9%
Comms Service Provider
8%
Financial Services Firm
14%
Computer Software Company
14%
Manufacturing Company
8%
Government
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business8
Large Enterprise3
By reviewers
Company SizeCount
Small Business110
Midsize Enterprise50
Large Enterprise257
 

Questions from the Community

What is your experience regarding pricing and costs for AWS X-Ray?
While I have not compared it with GCP or Azure ( /products/microsoft-azure-reviews ), AWS generally offers cost-effective services. Some services, like Athena ( /products/odyssey-software-athena-eo...
What needs improvement with AWS X-Ray?
The challenges we faced with AWS X-Ray were that some of the AWS services we were using did not support it, which we discovered at a later stage. This was potentially a design consideration we shou...
What is your primary use case for AWS X-Ray?
I have been using AWS X-Ray for creating insights to our applications we have developed. It is used to correlate different services in AWS when a transaction happens, allowing us to see the flow of...
What SOC product do you recommend?
For tools I’d recommend: -SIEM- LogRhythm -SOAR- Palo Alto XSOAR Doing commercial w/o both (or at least an XDR) is asking to miss details that are critical, and ending up a statistic. Also, rememb...
What is a better choice, Splunk or Azure Sentinel?
It would really depend on (1) which logs you need to ingest and (2) what are your use cases Splunk is easy for ingestion of anything, but the charge per GB/Day Indexed and it gets expensive as log ...
How does Splunk compare with Azure Monitor?
Splunk handles a high amount of data very well. We use Splunk to capture information and as an aggregator for monitoring information from different sources. Splunk is very good at alerting us if we...
 

Overview

 

Sample Customers

COMCAST, ConnectWise, skyscanner, AirAsia, cookpad, cimpress, VTEX, zowdow
Splunk has more than 7,000 customers spread across over 90 countries. These customers include Telenor, UniCredit, ideeli, McKenney's, Tesco, and SurveyMonkey.
Find out what your peers are saying about AWS X-Ray vs. Splunk Enterprise Security and other solutions. Updated: May 2023.
873,085 professionals have used our research since 2012.