Try our new research platform with insights from 80,000+ expert users

Cisco Provider Connectivity Assurance vs Splunk Enterprise Security comparison

 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Cisco Provider Connectivity...
Average Rating
8.8
Reviews Sentiment
6.9
Number of Reviews
24
Ranking in other categories
Application Performance Monitoring (APM) and Observability (43rd), Network Monitoring Software (40th)
Splunk Enterprise Security
Average Rating
8.4
Reviews Sentiment
7.3
Number of Reviews
369
Ranking in other categories
Log Management (2nd), Security Information and Event Management (SIEM) (1st), IT Operations Analytics (1st)
 

Mindshare comparison

While both are Application Lifecycle Management solutions, they serve different purposes. Cisco Provider Connectivity Assurance is designed for Application Performance Monitoring (APM) and Observability and holds a mindshare of 0.6%, up 0.4% compared to last year.
Splunk Enterprise Security, on the other hand, focuses on Security Information and Event Management (SIEM), holds 8.7% mindshare, down 10.9% since last year.
Application Performance Monitoring (APM) and Observability Market Share Distribution
ProductMarket Share (%)
Cisco Provider Connectivity Assurance0.6%
Dynatrace8.1%
Datadog6.6%
Other84.7%
Application Performance Monitoring (APM) and Observability
Security Information and Event Management (SIEM) Market Share Distribution
ProductMarket Share (%)
Splunk Enterprise Security8.7%
Wazuh9.3%
IBM Security QRadar6.5%
Other75.5%
Security Information and Event Management (SIEM)
 

Featured Reviews

Pifu Lin - PeerSpot reviewer
Addresses connectivity issues with real-time monitoring while offering good local support
I had prepared for COC and the client. I work as a vendor for a client using Flow Mount for network performance monitoring. I focus on resolving client-side issues related to Packy Performance and quality use. This involves addressing network device issues, specifically Cisco network devices One…
Kyle Vernham - PeerSpot reviewer
Built-in searches and unified data access streamline alert investigation and boosts analyst efficiency
The two features I appreciate the most in Splunk Enterprise Security are the built-in searches, which have been very easy for us to get started with right out of the box, and the fact that it accesses all of our other systems. You can access it as a pane of glass rather than having to search individually. We also have the option to compare our analysts from our service to service. Splunk Enterprise Security helps our SOC team prioritize and investigate high-fidelity alerts more effectively by providing a more in-depth look and the ability to access a lot more of our data. Instead of jumping from several segmented systems, it allows us to have everything brought together in one place. For example, you have to move from our purview to our build system and to Splunk Enterprise Security, and it enables us to streamline that process. The built-in features of Splunk Enterprise Security, which we recently procured, have given us a good starting point and demonstrated the value of the product, providing an easy way to sell it to our company. The ease of getting everything into our purview helps us, and it serves as a good start for the investigation part in one location rather than what we usually have, which is jumping from system to system to system. Splunk Enterprise Security plays a role in our company's strategy to combat insider threats and advanced persistent threats by currently being in its technical test phase. We are still rolling it out, and it should help us find any insider threats based on information that our policy states should not be present in our system. Splunk Enterprise Security's risk-based alerting (RBA) has impacted our alert volume and analyst productivity because we've got many different systems feeding into it. However, it has helped to make it easier for our analysts to go through a set of events rather than 100 alerts. RBA allows us to streamline the process and customize it for our analysts. When it comes to leveraging Splunk Enterprise Security's dashboards and visualizations to communicate security posture to executives, it's pretty straightforward for any type of information. The visualization is easy to understand, but I haven't had any direct conversations with our executives.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"The feature I used to like the most was its ability to decode layer seven protocols, although this is becoming less useful now that encryption is so widespread."
"What I like most about Accedian Skylight is that it's a UI application, so using it is easy. I also like that the support for Accedian Skylight is helpful."
"It is about finding operational problems. When sites go down, we try to determine who is at fault. While there is not much finger-pointing, the solution is just trying to analyse when there is an outage and where do we start looking to fix it. The very nature of why organization chooses to use the solution is to accelerate the meantime to resolution and find where problems lie to get them rectified as quickly as possible."
"I always have the Skylight dashboard on one of my screens... Now you can create your own dashboard, specific to an application, specific to a server, or to something else."
"Capturing traffic [is very interesting]. Currently, with our configuration, we don't capture the payload of the packets, just the header. But when we want the body, the payload of the packets, we can do a PCAP, and then analyze it within Wireshark."
"I think the analytics features are okay. My customer also likes the interface, the GUI, because it's easy to operate."
"One valuable feature we have is real-time monitoring for connection issues."
"For us, the most valuable feature is something called TWAMP that allows for real-time traffic in a way that is 10 times lighter than things like SolarWinds. It's in the sub-milliseconds of accuracy, and you can divide tasks so that you can literally see things like the tagging for Quality of Service. That had been incorrect with the carrier, but there was no way on this planet you'd be able to tell a carrier that they're wrong. I have dozens of scenarios where we found "No, that's not right," and got it resolved instantly."
"The feature I appreciate the most about Splunk Enterprise Security is Search Processing Language, which has benefited my organization by making searching data a lot easier than other tools I've used."
"It has quite extensive support in terms of integration. If you want to do anything, there are tools for that."
"Splunk is quite flexible for our customers. Splunk does not filter from a specific lock, you can define it later."
"Splunk allows us to customize processing and dashboards, which helps us take care of our customers' needs."
"I would assess the stability and reliability of Splunk Enterprise Security as good, as I have not had any issues with it."
"I really appreciate the all-integrated SIEM feature of Splunk Enterprise Security, which serves as a one-stop shop to get all security tasks done."
"Visualizations helped the organisation with a better understanding of its KPIs."
"Its dashboard is valuable. If you have a good knowledge of how to create a dashboard, you can create any dashboard related to cybersecurity. If fine-tuned, the alarms that are triggered for instant review are also very valuable and useful."
 

Cons

"The UI interface of Accedian Skylight could improve."
"This solution is expensive compared to some others."
"I would like to see some improvements in parts of their synthetic transactions, which includes all the latency, jitter, and throughput. I would like to see some Layer 7 analytics in there. I want to be able to do a DNS request, HTTP GET request, or even SIP call point-to-point or via registration."
"Because of the policies in Vietnam, we cannot connect the system to the Accedian cloud. It would be good if Accedian could provide a local cloud. In the next release, I would like them to focus on improving and adding more reporting features. This will help the operations teams."
"If you want a new version, you go to the website. The hardest part is finding the link, where is that .bin file? Sometimes it's pretty hidden in a document... it's hidden in the release notes or in another file somewhere. And it's usually not on the first page either."
"For the PVX, they are in the process of getting the results to export to cloud and SaaS for analytics. They told me that this will happen later this year. Right now, for the most part, I create that data myself."
"Human resource costs can be high when dealing with connection issues."
"It's a bit slow. When I execute a query, something general with a short timeframe that covers one month, for instance, and I do not specify the IP source or IP destination, it can take ages because it has to query the whole database."
"At Splunk .conf24, I saw a demo for Splunk Enterprise Security 8. All the things that they have done in Splunk Enterprise Security 8 are what it can be better at."
"The documentation and training resources available for knowledge and training can be expanded. We need to learn more about Splunk Enterprise Security and new security attacks."
"Splunk is query-based, which is not the case with most cybersecurity tools. It is based on search queries and can be difficult to use. It would be good if they can make it easier to understand how to create search queries. They can improve the knowledge base for better understanding. To create your dashboard, you need to have a search query. We have multiple firewalls in our company, and we need a dashboard for them. It would be helpful if a default firewall dashboard is included in Splunk to make monitoring easier. If a dashboard is available for a security device, the operation part will be more efficient. We won't have to follow a manual process for this."
"Its deployment is difficult. I remember when I first started learning, I faced several challenges, especially when deploying VMware in a virtual environment."
"Splunk could have more built-in use case presets that customers can build on and customize."
"Writing queries is a bit complicated sometimes."
"Improving the infrastructure behind Splunk Enterprise Security is vital—enhanced cores, CPUs, and memory should be prioritized to support better processing power."
"The main issue that I have with it is that the field transformations sometimes overlap with those in Splunk Enterprise, and then you get permissions issues that lead to troubles."
 

Pricing and Cost Advice

"The pricing of Accedian Skylight is really good. The sensors are low cost. Their model to analytics for sensors is by license, endpoint, or session. With the probes for their analytics, if they get deployed virtually, they are free. The licensing is only based on flows. So, you can effectively deploy probes everywhere in your network. Then, if you want to look at a specific type of traffic, you can enter into it with a very low cost license. You can just use things like spam ports, mirrors, TAPs, and aggregators to optimize what sort of traffic you send to these analysis tools. Then, if you want to start looking at more, you can up your licensed as you go. You are not getting forced into expensive appliances or subscription models."
"It's not for free, clearly. But on the other hand, it offers very interesting functionality. We pay around €100,000."
"If you look into Riverbed, it's a licensing nightmare. You need to pay for every type of analysis... If you don't look into licensing, Riverbed and SolarWinds are pretty comparable. But if you look into licensing it would not be smart to go for either of them. On the pure, bare-metal basis, it's the same. But when you get the bare metal and a few basic licenses, then you need all those other licenses just to be sure that there's no issue... One of the great things about Skylight is you have them all, and you actually need them all."
"The solution was previously well-regarded, but after being acquired by Accedian, the prices have significantly increased. This has made it challenging to sell the product due to its high cost. It is an expensive solution."
"The pricing is cheaper than other competing products, which is better for our budgets."
"Pricing is a little bit expensive."
"We understand there's a significant cost difference, but have yet to investigate fully."
"The price is competitive overall, depending on the type of customer."
"Splunk Enterprise Security is expensive."
"Be upfront about your needs and expectations. Splunk is great to work with."
"The price of Splunk is too high for our market."
"Splunk's cost is very high. They need to review the pricing. They have to go back and totally readdress the market."
"Truly evaluate the data you want to ingest and go slow. Pulling in data that can provide no use to your mission only wastes data against your license."
"It is possible to use a developer's license, which is up to 10GB per day of volume traffic, which is usually enough for most use cases."
"Splunk Enterprise Security is expensive. I would rate the cost an eight out of ten with ten being the most expensive."
"Splunk can be expensive, as its licensing is based on the daily data ingestion volume."
report
Use our free recommendation engine to learn which Application Performance Monitoring (APM) and Observability solutions are best for your needs.
873,209 professionals have used our research since 2012.
 

Comparison Review

VS
Feb 26, 2015
HP ArcSight vs. IBM QRadar vs. ​McAfee Nitro vs. Splunk vs. RSA Security vs. LogRhythm
We at Infosecnirvana.com have done several posts on SIEM. After the Dummies Guide on SIEM, we are following it up with a SIEM Product Comparison – 101 deck. So, here it is for your viewing pleasure. Let me know what you think by posting your comments below. The key products compared here are…
 

Top Industries

By visitors reading reviews
Computer Software Company
33%
Manufacturing Company
8%
Financial Services Firm
8%
Government
6%
Financial Services Firm
14%
Computer Software Company
13%
Manufacturing Company
8%
Government
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business14
Midsize Enterprise6
Large Enterprise9
By reviewers
Company SizeCount
Small Business110
Midsize Enterprise50
Large Enterprise257
 

Questions from the Community

What needs improvement with Accedian Skylight?
Human resource costs can be high when dealing with connection issues. I require more tools to file and resolve these issues efficiently.
What is your primary use case for Accedian Skylight?
I had prepared for COC and the client. I work as a vendor for a client using Flow Mount for network performance monitoring. I focus on resolving client-side issues related to Packy Performance and ...
What SOC product do you recommend?
For tools I’d recommend: -SIEM- LogRhythm -SOAR- Palo Alto XSOAR Doing commercial w/o both (or at least an XDR) is asking to miss details that are critical, and ending up a statistic. Also, rememb...
What is a better choice, Splunk or Azure Sentinel?
It would really depend on (1) which logs you need to ingest and (2) what are your use cases Splunk is easy for ingestion of anything, but the charge per GB/Day Indexed and it gets expensive as log ...
How does Splunk compare with Azure Monitor?
Splunk handles a high amount of data very well. We use Splunk to capture information and as an aggregator for monitoring information from different sources. Splunk is very good at alerting us if we...
 

Also Known As

Accedian Skylight, Accedian SkyLIGHT PVX, SkyLIGHT PVX, SecurActive, Performance Vision
No data available
 

Overview

 

Sample Customers

T-Systems, Thomson Reuters, Bordeaux Metropole, CGI, Citadelle Regional Hospital Center, Lorraine Institute of Oncology, Luxembourg Institute of Health, Groupe BPCE, Group S, Splitpoint, Horus-Net, Audatex, Indexis, Province de Liège, EASI, Spie Batignolles, Faymonville
Splunk has more than 7,000 customers spread across over 90 countries. These customers include Telenor, UniCredit, ideeli, McKenney's, Tesco, and SurveyMonkey.
Find out what your peers are saying about Cisco Provider Connectivity Assurance vs. Splunk Enterprise Security and other solutions. Updated: May 2023.
873,209 professionals have used our research since 2012.