Honeycomb.io vs Splunk Enterprise Security comparison

 

Comparison Buyer's Guide

Executive SummaryUpdated on Mar 27, 2024
 

Categories and Ranking

Honeycomb.io
Average Rating
8.0
Number of Reviews
1
Ranking in other categories
Application Performance Monitoring (APM) and Observability (36th)
Splunk Enterprise Security
Average Rating
8.4
Number of Reviews
258
Ranking in other categories
Log Management (1st), Security Information and Event Management (SIEM) (1st), IT Operations Analytics (1st)
 

Mindshare comparison

As of June 2024, in the Application Performance Monitoring (APM) and Observability category, the mindshare of Honeycomb.io is 2.3%, up from 1.7% compared to the previous year. The mindshare of Splunk Enterprise Security is 2.8%, down from 5.5% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Application Performance Monitoring (APM) and Observability
Unique Categories:
No other categories found
Log Management
13.0%
Security Information and Event Management (SIEM)
13.7%
 

Featured Reviews

PR
Apr 6, 2023
A valuable solution for application teams to identify downtime and SLO-related issues
There aren't any specific use cases for the solution as such. In our company, we use the solution for SLA and SLO-related work Honeycomb.io facilitates the identification of service downtime by integrating with our logging endpoint in Splunk. We log the endpoint in Splunk, and Honeycomb.io…
AK
May 27, 2024
The user interface gives you a single dashboard to directly view all high-level information
I like Splunk's automated threat detection and orchestration capabilities. Splunk offers a single solution for analyzing, aggregating, correlating, monitoring, reporting, visualizing, etc. You can get all of these capabilities in one place. On top of that, it provides a cloud, testing, on-premise, and hybrid solution, giving customers more flexibility for their use cases. Splunk's real-time monitoring is one of its best features. The user interface gives you a single dashboard to directly view all the high-level information. The security incident monitoring and investigation page is also very helpful. You can document an investigation step by step. Many investigators can work on a single incident also based on their shifts. Everyone can add notes on the investigation page. The incident response features are based on real-time data. The monitoring team can immediately take over an incident and prioritize tasks based on risk scores. We can assign multiple technicians to one security incident based on their skill, improving resolution time. The incident review dashboard provides many useful details, like the indicators of compromise and risk scores. We can get threat intelligence from multiple platforms, including the latest known IOCs, to support our response to security incidents. We store the threat data from various sources in a centralized place, and it updates every six to 12 hours. The MITRE ATT&CK framework feature is helpful for understanding which phase an incident is in and what the next steps are so a technician can prevent it from progressing. It gives us a detailed overview of other tactics it might be associated with, enabling us to stay vigilant. We can correlate with other simultaneous or sequential incidents and take action to strengthen our security based on these incidents.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"The solution's initial setup process was straightforward since we were getting enough support from Honeycomb.io's team."
"The most valuable feature is the log aggregation, being able to scan through all of the logs."
"Integration with the cloud is pretty important and good for us. We found the integration with a lot of tools, not all tools yet, valuable. It does make the transfer of data, log files, and other things easier for us."
"The most useful feature for me is the ability to create different kinds of alerts and set a different kind of denominator that will capture the real event. That is helpful for a power user like me."
"It has helped us look at modern technology, as well as penetrate our legacy systems, to see where the bottlenecks are."
"To get visibility from your network devices, servers, and security devices is a great feature."
"Splunk Enterprise Security offers valuable features like seamless integration and a SQL-standard Structured Query Language for easy searching."
"Splunk Enterprise Security stands out for its ability to integrate with existing security tools, provide informative dashboards, and offer IT Service Assurance functionality that goes beyond basic threat detection to include service performance monitoring."
"Splunk's interface is user-friendly, and it has apps and add-ons for most applications. We can easily normalize the data to make it readable and understand the logs. We easily get all the field extractions and enrichment done by using the apps and add-ons. This helps us understand the application logs because the raw data is useless unless we extract some useful information from it. These add-ons make it so much easier."
 

Cons

"The process of log scraping gets delayed on Honeycomb.io. At times, it gives false alerts to the application team."
"The setup time is quite long."
"It is a good product, but the Achilles heel for a lot of organizations is the cost model for it because it gets expensive. That's because the model is based on how much data it processes a day, which can be prohibitive, especially if you have a lot of data. A lot of customers may not be ready for the sticker shock on how to fully leverage the product. I realized that the reason for that is that when it was originally designed, it was kind of like a big data modeling application. If they want to have a bigger customer base, they can come out with subsets of their product that are focused on specific things and have different pricing models. It may help with the cost."
"Cybersecurity and infrastructure monitoring have room for improvement."
"Splunk can improve regex/asset analysis as we do not want to crawl until it is done."
"Their technical support sucks."
"Its user interface for everything other than the charts can be improved. Some parts of it can be simplified a bit, such as when importing documents that have the network traffic. When you're going through the information about the network traffic, you have to have the expertise, but even if a program is supposed to be for IT support, it is good to make it user-friendly because it gets easier to train people. When something goes wrong, the more difficult a program is in terms of UI, the harder it is to fix the issue."
"Splunk Enterprise Security can be improved by including backup network detection and response and safe management to the paid platform."
"Enterprise security: Splunk must work on clarifying the solution to customers and explain how to gain more from it."
 

Pricing and Cost Advice

Information not available
"The tool's licensing is good and we haven't received any complaints from the team handling it."
"From what I have seen so far, Splunk has multiple cost models. The one that we are using is pretty good when it comes to ingesting data into the environment. It has worked out pretty well."
"Expensive compared to other options."
"Our ROI is high."
"Splunk Enterprise Security is affordable."
"The solution is costly."
"It is expensive. I used to buy it early on, but then they combined it into a higher-up organization. They buy it for multiple systems now. Last time, I paid around 60K for it. There is just the licensing fee. That's all."
"Licensing is a yearly, one-time cost."
report
Use our free recommendation engine to learn which Application Performance Monitoring (APM) and Observability solutions are best for your needs.
787,817 professionals have used our research since 2012.
 

Comparison Review

VS
Feb 26, 2015
HP ArcSight vs. IBM QRadar vs. ​McAfee Nitro vs. Splunk vs. RSA Security vs. LogRhythm
We at Infosecnirvana.com have done several posts on SIEM. After the Dummies Guide on SIEM, we are following it up with a SIEM Product Comparison – 101 deck. So, here it is for your viewing pleasure. Let me know what you think by posting your comments below. The key products compared here are…
 

Top Industries

By visitors reading reviews
Financial Services Firm
21%
Computer Software Company
15%
Comms Service Provider
7%
Manufacturing Company
6%
Financial Services Firm
15%
Computer Software Company
14%
Government
9%
Manufacturing Company
8%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
No data available
 

Questions from the Community

What do you like most about Honeycomb.io?
The solution's initial setup process was straightforward since we were getting enough support from Honeycomb.io's team.
What needs improvement with Honeycomb.io?
The process of log scraping gets delayed on Honeycomb.io. At times, it gives false alerts to the application team. It would be good if Honeycomb.io could integrate with third-party tools or paid se...
What is your primary use case for Honeycomb.io?
There aren't any specific use cases for the solution as such. In our company, we use the solution for SLA and SLO-related work.
What SOC product do you recommend?
For tools I’d recommend: -SIEM- LogRhythm -SOAR- Palo Alto XSOAR Doing commercial w/o both (or at least an XDR) is asking to miss details that are critical, and ending up a statistic. Also, rememb...
What is a better choice, Splunk or Azure Sentinel?
It would really depend on (1) which logs you need to ingest and (2) what are your use cases Splunk is easy for ingestion of anything, but the charge per GB/Day Indexed and it gets expensive as log ...
How does Splunk compare with Azure Monitor?
Splunk handles a high amount of data very well. We use Splunk to capture information and as an aggregator for monitoring information from different sources. Splunk is very good at alerting us if we...
 

Learn More

Video not available
 

Overview

 

Sample Customers

Clover Health, Eaze, Intercom, Fender
Splunk has more than 7,000 customers spread across over 90 countries. These customers include Telenor, UniCredit, ideeli, McKenney's, Tesco, and SurveyMonkey.
Find out what your peers are saying about Datadog, Dynatrace, New Relic and others in Application Performance Monitoring (APM) and Observability. Updated: May 2024.
787,817 professionals have used our research since 2012.