Try our new research platform with insights from 80,000+ expert users

ArcSight Logger vs ManageEngine EventLog Analyzer vs Splunk Enterprise Security comparison

 

Comparison Buyer's Guide

Executive Summary
 

Mindshare comparison

As of September 2024, in the Log Management category, the mindshare of ArcSight Logger is 1.0%, down from 1.4% compared to the previous year. The mindshare of ManageEngine EventLog Analyzer is 1.1%, down from 1.4% compared to the previous year. The mindshare of Splunk Enterprise Security is 9.6%, down from 14.2% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Log Management
 

Featured Reviews

Hassan Moussafir - PeerSpot reviewer
Jan 27, 2020
Passes compliance thresholds and standard requirements and has good performance
The solution is scalable, but it depends on the license you acquire. You can expand your license as needed if you need to integrate more infrastructure. For us, our goal was to integrate all the infrastructure so we acquired a license with the expansion option so that we could integrate all the infrastructure that we wanted to. In order to expand, users should expect to pay additional fees. We are in the digital transformation space. This transformation means that very quickly we may need to be able to add more and more servers into our infrastructure. It was important that the solution we chose had a license that covered that capability.
AA
Mar 20, 2023
Easy to use with good monitoring and management
I've used the solution for a short time. I had to look at it and some other options to see which would fit the use case. We wanted to test it on our networks I used the solution alongside others to run some tests for a client, and they decided which solution they wanted to use. The monitoring is…
DS
Jun 8, 2023
Enables us to integrate the solution with other products to automate tasks, saving us time
You can integrate Splunk with third-party security automation solutions and set rules for automatic response. Splunk can monitor multiple cloud environments, but it's a little tricky if you're working with several vendors. Every cloud environment is slightly different, and some are better integrated. The visibility into multi-cloud environments is decent. It depends on the number of sources you have, and Splunk is pretty flexible from that perspective. You can add any type of data source. The challenge is the engineering effort some of these data sources require, but others are effortless to manage. We haven't used the insider threat capabilities yet, but it's an area that we want to explore. We have other tools for this. We use different products for threat intelligence.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"It's a robust, mature product and you can do some really complex operations and analytics."
"It's an efficient solution."
"The most valuable feature is the level of detail that you can see about certain events, even when they do not come up in the console."
"The most valuable feature is the search capability, which is simple to use."
"It's a brilliant log collection tool, and it can handle hundreds of thousands of servers in a single shot to ingest the data."
"The ability to customize the solution in great detail is its most valuable features. We can customize the use cases and also have the ability to do scripting. We can personalize our dashboard as well. The scalability the solution offers is quite impressive."
"Our return on investment for implementing ArcSight Logger over the past 12 months has been positive."
"We haven't had any crashes or bugs. It is stable."
"The initial setup is straightforward"
"The most valuable features of ManageEngine EventLog Analyzer are the number of capabilities, file integration monitoring, web server log collection, and alert configuration."
"It is stable."
"The user interface is very good."
"The reporting features are noteworthy, as they provide templates that streamline the process of generating reports"
"It's one of the easiest products. It's very simple to use."
"The log management has helped to improve my organization."
"ManageEngine EventLog Analyzer is easy to gather reports to give to management. My supervisor has access to the solution and he enjoys the graphs."
"Splunk's schema on demand is incredibly useful. I do not have to worry about what my users will need when we onboard their data."
"The solution's newly developed dashboard is pretty amazing."
"I have found the installation can be of medium difficulty to very complex depending on the use case."
"The ability to digest any information and then correlate it in accordance with what you need is valuable. The ability to connect to pretty much everything and bring the information in the same format is also valuable. On top of that, we can use their language in order to create and customize the dashboards, correlations, or analytics that we want to incorporate."
"Search language is easy to understand and teach to new users."
"It is quite extensible. It is a platform that we can build our use instead of each case instead of each case being limited or restricted to each capability. This is probably the best feature."
"The most valuable features of Splunk Enterprise Security are its high-performance data collection, flexible query language, and its versatility across the organization."
"You can check up on security from the dashboards."
 

Cons

"I would rate the technical support only 5 out of 10. The technical support is not satisfactory."
"I had some latency issues for two months. I had to increase our storage capacity significantly to reduce the latency."
"I would like to see better scheduling in the next release of this solution."
"In the next release, I want to see more intelligence."
"The console in older versions is not user-friendly."
"The solution must provide readymade connectors for different applications."
"Using the ArcSight Logger dashboard is not particularly intuitive or efficient, so it is important to be trained in its use."
"You have limited reporting capabilities and I wouldn't choose ArcSight Logger for this purpose."
"The first tier of customer service and support is not great."
"There's a lot to improve in terms of connectivity. Currently, we're utilizing it across various infrastructures and environments, including others' cloud. However, connecting it to our infrastructure and integrating it with some of our SMAX solutions poses difficulties."
"It may not be as easy to use as Splunk."
"What I'd like to see as an improvement to ManageEngine EventLog Analyzer is for it to be more AI-driven. Having more automation would also make the solution better."
"The scalability is limited."
"I would like to see more detailed reports."
"The solution should improve on its log capturing capabilities."
"The solution is stable. However, there are limits. For example, we can do 2,500 Syslog events per second, but if we want to do more we have to install the distributor structure, and then we can expand how many events we can do. They could improve the stability."
"The case management area of the ES could be improved. The ability to move cases through various stages and states. The ability to close a case would be key improvement."
"Sometimes the communication with support happens with multiple staff. They should reduce the time to resolution."
"I would like the ability to view logs for specific instances and not have to pull the logs for the entire Cloud environment in Splunk."
"We usually have to follow up with technical support on our open cases."
"​On the technical side, it would be nice to see aspects of the recent acquisition of Phantom make it into the core Splunk Enterprise, not just become a part of the premium Enterprise Security.​"
"Given the ever-increasing number of threats, I would like Splunk to update its threat signatures more frequently."
"Custom visualizations are real hard. While the default visualizations are good, creating enhanced visualizations are complex."
"Splunk Enterprise Security could improve in automation, flexibility, and providing more content out of the box."
 

Pricing and Cost Advice

"Pricing is reasonable compared to similar tools on the market. They offer perpetual licenses."
"We have a lifetime license, so we don't pay a monthly fee."
"I would rate the product a seven out of ten since it's an enterprise product."
"The pricing is quite harsh."
"ArcSight Logger is very expensive compared to their competitors, but when we talk to the customer and explain what the features are and how we can scale, they understand. Still, ArcSight is more expensive than the competition."
"I rate the product’s pricing a seven out of ten, where one is inexpensive, and ten is expensive."
"It's not cheap at all as it's a big product and has been in the market for quite some time now."
"ArcSight is an expensive solution."
"There is a license required for these solutions. The customer can choose the license type, such as an annual license purchase or a perpetual license. If the customer wants maintenance they will have to pay annually."
"There is a yearly subscription for the solution."
"ManageEngine EventLog Analyzer is expensive. Its licensing costs are annual."
"Licensing for ManageEngine EventLog Analyzer is paid yearly."
"We paid for the license of the solution and the deployment. The price of ManageEngine EventLog Analyzer is less expensive than other solutions."
"ManageEngine EventLog Analyzer is a low-cost solution. It costs approximately $1,000 per month per server for a perpetual license."
"In terms of pricing, I believe Splunk is unreasonably costly for the majority of mid and small-sized companies."
"Splunk should be able to integrate with other product using the free version."
"Most people share the same thought that the ingestion rates can get pretty pricey. There is a lot of work we do to curate the data that we send to Splunk so that it is not too noisy or too expensive."
"It is expensive. I used to buy it early on, but then they combined it into a higher-up organization. They buy it for multiple systems now. Last time, I paid around 60K for it. There is just the licensing fee. That's all."
"Splunk Enterprise Security is expensive but the solution is equipped with a lot of features."
"While licensing can be a concern, there are ways to reduce the licensing costs including filtering some events."
"There is an annual license required to use this solution."
"Splunk is not a cheap solution and the license is billed annually."
report
Use our free recommendation engine to learn which Log Management solutions are best for your needs.
805,335 professionals have used our research since 2012.
 

Comparison Review

VS
Feb 26, 2015
HP ArcSight vs. IBM QRadar vs. ​McAfee Nitro vs. Splunk vs. RSA Security vs. LogRhythm
We at Infosecnirvana.com have done several posts on SIEM. After the Dummies Guide on SIEM, we are following it up with a SIEM Product Comparison – 101 deck. So, here it is for your viewing pleasure. Let me know what you think by posting your comments below. The key products compared here are…
 

Top Industries

By visitors reading reviews
Financial Services Firm
19%
Computer Software Company
15%
Government
10%
Manufacturing Company
6%
Computer Software Company
19%
Government
9%
Manufacturing Company
8%
Financial Services Firm
7%
Financial Services Firm
15%
Computer Software Company
15%
Government
9%
Manufacturing Company
8%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

What do you like most about ArcSight Logger?
We have a trigger. So, Logger automatically blocks these IP addresses. We could have Logger put them on a blacklist.
What is your experience regarding pricing and costs for ArcSight Logger?
The pricing isn't the problem. We have a lifetime license, so we don't pay a monthly fee.
What needs improvement with ArcSight Logger?
The solution has room for improvement. We're currently upgrading to the newer version, where they have something like...
What do you like most about ManageEngine EventLog Analyzer?
The reporting features are noteworthy, as they provide templates that streamline the process of generating reports
What needs improvement with ManageEngine EventLog Analyzer?
There's a lot to improve in terms of connectivity. Currently, we're utilizing it across various infrastructures and e...
What is your primary use case for ManageEngine EventLog Analyzer?
We use ManageEngine EventLog Analyzer to collect logs from all our IT assets, including servers and databases. We uti...
What SOC product do you recommend?
For tools I’d recommend: -SIEM- LogRhythm -SOAR- Palo Alto XSOAR Doing commercial w/o both (or at least an XDR) is a...
What is a better choice, Splunk or Azure Sentinel?
It would really depend on (1) which logs you need to ingest and (2) what are your use cases Splunk is easy for ingest...
How does Splunk compare with Azure Monitor?
Splunk handles a high amount of data very well. We use Splunk to capture information and as an aggregator for monitor...
 

Also Known As

Micro Focus Arcsight Logger, HPE Arcsight Logger
EventLog Analyzer
No data available
 

Overview

 

Sample Customers

China Merchants Bank, Bank AlJazira, Banca Intesa
Moody National Bank, EnCircle, Goldleaf Financial Solutions, Inc, IBM, Ernst & Young, Micro Linear, Silverbeck-Rymer Solicitors, Provincial Court of British Columbia, Eleventh Judicial Circuit of Florida, OGILVY & MATHER, E! Entertainment, Tribune-Review Publishing Co.
Splunk has more than 7,000 customers spread across over 90 countries. These customers include Telenor, UniCredit, ideeli, McKenney's, Tesco, and SurveyMonkey.
Find out what your peers are saying about Splunk, Wazuh, Datadog and others in Log Management. Updated: August 2024.
805,335 professionals have used our research since 2012.