No more typing reviews! Try our Samantha, our new voice AI agent.

ArcSight Security Orchestration Automation Response vs Splunk Enterprise Security comparison

 

Comparison Buyer's Guide

Executive SummaryUpdated on Jan 25, 2026

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

ArcSight Security Orchestra...
Ranking in Security Information and Event Management (SIEM)
86th
Average Rating
0.0
Reviews Sentiment
5.4
Number of Reviews
1
Ranking in other categories
No ranking in other categories
Splunk Enterprise Security
Ranking in Security Information and Event Management (SIEM)
1st
Average Rating
8.4
Reviews Sentiment
7.3
Number of Reviews
381
Ranking in other categories
Log Management (2nd), IT Operations Analytics (1st)
 

Mindshare comparison

As of April 2026, in the Security Information and Event Management (SIEM) category, the mindshare of ArcSight Security Orchestration Automation Response is 0.2%, up from 0.0% compared to the previous year. The mindshare of Splunk Enterprise Security is 7.2%, down from 9.8% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Security Information and Event Management (SIEM) Mindshare Distribution
ProductMindshare (%)
Splunk Enterprise Security7.2%
ArcSight Security Orchestration Automation Response0.2%
Other92.6%
Security Information and Event Management (SIEM)
 

Featured Reviews

Gaurav Ranade - PeerSpot reviewer
CTO at Rah Infotech Pvt Ltd
Supports automation and orchestration workflows but has lost market traction recently
The data correlation feature in ArcSight Security Orchestration Automation Response helps to improve incident response times, but I believe that there are many other things that need to be done. The competition is coming up with new jargons and new features that need to be taken into account. I believe that ArcSight Security Orchestration Automation Response also has to change the user experience slightly to a phase-based view, which seems to be slightly dull, and many times customers or partners have reported this back. The UI could be slightly better and that is an area for improvement. ArcSight Security Orchestration Automation Response is taking an edge lesser than the competition. When I look at that, there is Splunk, Exabeam, Gurucul, Securonix, and others that are taking quite a leverage in the market. Three or four years ago, the market ratio was about 40 to 45% captured by ArcSight Security Orchestration Automation Response, but now it has been reduced to 10 to 12%. As much as the competition needs to be evaluated on the functionality perspective, I think ArcSight Security Orchestration Automation Response is losing its ground, so it needs to buckle up.
Sathis-Kumar - PeerSpot reviewer
Senior Manager at Bank of America
Helps us detect cyber threats quickly and integrate multiple feeds effectively
Overall, the product is good, but when it comes to some infrastructure issues, we have to dig into more logs. There is no straightforward indication of an issue. Health check kind of dashboards are not available. More AI would help us, and more optimization, since security products run more queries. The AI module could suggest solutions, optimizing queries or workload balancing. If the product itself advises on running queries during peak times, it would be similar to what ChatGPT currently offers. We see quite a few issues on stability. Even last week, we faced something, and identifying bottlenecks is not easy. We need more SMEs, and there is no mechanism to tell us about indexer or search head issues. Self-monitoring dashboards could be beneficial. The technical support still requires more improvement. Often, primary support takes a lot of time and forwards most solutions to the engineering side. The primary support team has very limited knowledge to provide.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"The advanced analytics in ArcSight Security Orchestration Automation Response helps to improve threat detection accuracy, which is an added advantage with the advanced analytics that ArcSight Security Orchestration Automation Response platform provides, which many times the competition cannot do."
"We can easily configure things as required in relation to our use cases."
"Splunk has a very knowledgeable support staff and the Splunk support website is outstanding."
"It's standardized and easy to use, so you don't have to have a lot of top-tier analysts to do the same job."
"Incident detection is the positive impact I have seen from Splunk Enterprise Security; it probably saved the company from financial losses because of the early detection of the incidents."
"What I appreciate the most about the product is the flexibility with data ingestion and searching, which is very powerful; you can do whatever you want with it."
"I also provided Splunk as a recommendation because it is a market leader, really powerful, and really good to use."
"Splunk setup is easy and straightforward. ​"
"The solution's most valuable feature is the incident review, which gives a good overview of our security incidents."
 

Cons

"ArcSight Security Orchestration Automation Response is taking an edge lesser than the competition."
"Its user interface for everything other than the charts can be improved."
"Missing capability for audio/video and image processing."
"The solution could use a different licensing model."
"We had some connections issues with the solution at the beginning."
"Splunk Enterprise Security could improve in automation, flexibility, and providing more content out of the box."
"They could offer pre-built search queries for everyday use cases like brute force attacks, DDoS attacks, and other security threats."
"The upgrading process could be smoother."
"Custom visualizations are real hard. While the default visualizations are good, creating enhanced visualizations are complex."
 

Pricing and Cost Advice

Information not available
"The pricing and licensing of the product are quite high."
"The price of Splunk is too high for our market."
"As a team, we prefer the old pricing model with a perpetual license. We are still evaluating the whole subscription-based model."
"Splunk can be expensive, as its licensing is based on the daily data ingestion volume."
"Splunk Enterprise Security is cheaper than competitors, but I do not know whether it is just our contract."
"Splunk has always been on the expensive side."
"Splunk Enterprise Security is affordable."
"This product could use better pricing in general."
report
Use our free recommendation engine to learn which Security Information and Event Management (SIEM) solutions are best for your needs.
885,667 professionals have used our research since 2012.
 

Comparison Review

VS
Manager, Enterprise Risk Consulting at a tech company with 1,001-5,000 employees
Feb 26, 2015
HP ArcSight vs. IBM QRadar vs. ​McAfee Nitro vs. Splunk vs. RSA Security vs. LogRhythm
We at Infosecnirvana.com have done several posts on SIEM. After the Dummies Guide on SIEM, we are following it up with a SIEM Product Comparison – 101 deck. So, here it is for your viewing pleasure. Let me know what you think by posting your comments below. The key products compared here are…
 

Top Industries

By visitors reading reviews
No data available
Financial Services Firm
12%
Computer Software Company
9%
Manufacturing Company
9%
Government
6%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
No data available
By reviewers
Company SizeCount
Small Business112
Midsize Enterprise50
Large Enterprise267
 

Questions from the Community

What needs improvement with ArcSight Security Orchestration Automation Response?
The data correlation feature in ArcSight Security Orchestration Automation Response helps to improve incident response times, but I believe that there are many other things that need to be done. Th...
What is your primary use case for ArcSight Security Orchestration Automation Response?
ArcSight Security Orchestration Automation Response is required in most security projects. Whenever there are security operation centers and logs to be ingested and correlated, any event triggered ...
What SOC product do you recommend?
For tools I’d recommend: -SIEM- LogRhythm -SOAR- Palo Alto XSOAR Doing commercial w/o both (or at least an XDR) is asking to miss details that are critical, and ending up a statistic. Also, rememb...
What is a better choice, Splunk or Azure Sentinel?
It would really depend on (1) which logs you need to ingest and (2) what are your use cases Splunk is easy for ingestion of anything, but the charge per GB/Day Indexed and it gets expensive as log ...
How does Splunk compare with Azure Monitor?
Splunk handles a high amount of data very well. We use Splunk to capture information and as an aggregator for monitoring information from different sources. Splunk is very good at alerting us if we...
 

Overview

 

Sample Customers

Information Not Available
Splunk has more than 7,000 customers spread across over 90 countries. These customers include Telenor, UniCredit, ideeli, McKenney's, Tesco, and SurveyMonkey.
Find out what your peers are saying about Splunk, Wazuh, IBM and others in Security Information and Event Management (SIEM). Updated: March 2026.
885,667 professionals have used our research since 2012.