

BigPanda and Splunk Enterprise Platform are two main competitors in the IT operations and data analytics category. BigPanda holds an advantage when it comes to pricing and support, while Splunk Enterprise Platform stands out for its extensive features that justify the higher cost for many users.
Features: BigPanda is equipped with AI-driven event correlation and automation, aiding efficient incident management, alert noise reduction, and integration with systems like WatchGuard. Splunk Enterprise Platform is recognized for its data analytics capabilities, scalability for data visualization and log management, and SPL language for robust data analysis and customization.
Room for Improvement: BigPanda may improve by enhancing customization options, expanding AI functionalities for advanced analytics, and refining integrations for more seamless operation. Splunk Enterprise Platform could benefit from a simplified deployment process, improved initial user training, and reducing costs associated with its advanced features.
Ease of Deployment and Customer Service: BigPanda offers a rapid and straightforward deployment process that requires minimal configuration, supported by responsive customer service. On the other hand, Splunk Enterprise Platform provides comprehensive documentation and support, though its deployment process may require significant setup and integration efforts.
Pricing and ROI: BigPanda presents a cost-effective solution with a quicker return on investment due to its efficient deployment and management capabilities. Splunk Enterprise Platform comes with a higher initial investment, yet its advanced analytics often prove valuable for organizations needing thorough data insights, making it preferred by those focused on detailed analytics despite the cost.
BigPanda offers significant time-saving, cost-saving, and resource-saving benefits.
BigPanda saves time with its advanced features and manages large environments while requiring fewer resources compared to our previous tool, Netcool.
Resource count has probably reduced by about ten to twenty percent due to the reduced incident count, which enables me to identify issues faster, meaning business recovery is quicker.
Key impact areas are generally time saved in investigations, higher analyst productivity, lowered costs of security incidents due to faster detection and response, and reduced manual reporting effort.
Splunk Enterprise Platform helped reduce the time required to investigate incidents by centralizing logs and providing powerful search capabilities.
Splunk Enterprise Platform improved our reliability, and the time to investment ratio has been excellent.
If BigPanda can consistently provide such competent contacts, I would rate the support ten out of ten, otherwise, it is an eight out of ten.
Companies like CoreLogix, which is a log platform, achieve ten out of ten due to their responsiveness.
For technical support, we have only had to address password resets and alert mismatching.
We contacted support and they were able to provide us with the solution which is currently working fine.
It is crucial for anyone looking to deploy Splunk Enterprise Platform to first certify for their courses, such as the Splunk Administrator and the Power User Administrator certifications, which address all troubleshooting queries.
When we encounter issues, we utilize the Splunk community, which I believe showcases a big advantage of Splunk due to its strong community support.
It handles large volumes of alerts without limitations.
We manage a large environment with over 50,000 servers and various monitoring tools like Dynatrace, New Relic, Splunk, Nagios, and Datadog.
I rate the scalability of BigPanda at eight.
Splunk allows for scalability, as you can start with an all-in-one instance and, as your deployment grows, split it into distributed deployment, such as separating the search head and indexers.
It is highly stable and scalable for us.
In a day we get millions of hits for the APIs.
BigPanda is now stable.
I would rate the availability of BigPanda at nine because it's almost 99.99% available.
However, when handling critical traffic, the BigPanda site can slow down, which we manage with a load balancer.
Our L1 and L2 teams get real-time alerts and query the SPL effectively without delays that other SIEM solutions may impose.
It is highly stable and scalable for us.
It requires managing configuration files and processing operations manually, limiting its auto-scaling capabilities.
A 'deep dive' analysis feature would be appreciated to give detailed insights such as CPU usage and disk space analysis.
It would be beneficial if BigPanda leveraged AI to solve critical issues related to editing and sending alerts based on enrichment mapping files.
If BigPanda could integrate AI, it would enhance the platform significantly by offering chatbot functionality within the BigPanda UI.
The deep learning capabilities need enhancing, especially on Splunk Cloud, where customers find it challenging to use deep learning tools without setting up backend computing resources.
I could also build some pre-indexed summaries so that Splunk Enterprise Platform can search much faster than raw logs.
From an architectural standpoint, data onboarding, normalization, performance, and scalability improvements would be beneficial, particularly in optimizing search speed and query execution to handle larger searches efficiently.
The pricing for BigPanda is reasonable compared to other event management tools, given its advantages.
There are indirect costs related to managing open-source products, leading to resource investment in maintaining the dashboards for these capabilities.
The pricing model is based on ingesting data sizes, not user count, and includes a free tier for up to 500 MB of daily data.
We ingest terabytes of data, so I can say Splunk Enterprise Platform is somewhat costly.
The platform's ability to consolidate siloed tools into a single pane of glass provides immense value justifying the premium cost if the architecture is tightly managed.
Its automation has significantly improved incident response times, reducing the process to within one minute.
It can correlate multiple issues within a single device, create a single incident, and thus reduce noise and provide faster resolution.
BigPanda improves service reliability with instant resolution, increased uptime, and reduced mean time to resolution, thus enhancing service quality.
Splunk Enterprise Platform also has its own Phantom as a SOAR, which is much more refined and gives more accurate results than any other AI integrated SIM tool.
The anomaly detection is very good for live production data. Whenever an anomaly comes in an application, it automatically resolves and just gives the notification.
Splunk Enterprise Platform will create an incident and detect this as a credential compromise because we have a successful login from another location.
| Product | Mindshare (%) |
|---|---|
| Splunk Enterprise Platform | 2.7% |
| BigPanda | 2.7% |
| Other | 94.6% |


| Company Size | Count |
|---|---|
| Small Business | 6 |
| Large Enterprise | 12 |
| Company Size | Count |
|---|---|
| Small Business | 34 |
| Midsize Enterprise | 8 |
| Large Enterprise | 43 |
BigPanda enhances incident management through root cause analysis, alert deduplication, and event correlation. The AI-driven platform is designed for environments with high alert volumes, providing insights for data-driven decisions and seamless integration with tools like ServiceNow and Teams.
BigPanda addresses the complexities of incident management by offering an AI-focused approach to anomaly detection. Automation improves response times, while unified analytics supports informed decision-making. Despite AI integration and usability needing enhancement, the platform simplifies observability and ticketing through integrations with New Relic and Slack. Features like enrichment mapping and unified search improve functionality, though reporting and visualization aspects require development.
What are the key features of BigPanda?BigPanda is widely implemented in industries focusing on observability and predictive analysis, providing efficient alert processing and incident management. Users utilize its capabilities to seamlessly integrate with solutions like Dynatrace, particularly in environments that handle high volumes of alerts, ensuring effective notification delivery through various platforms.
Splunk Enterprise Platform provides high flexibility and integration, featuring strong analytics, data ingestion, and real-time monitoring, catering to diverse industry needs and enhancing threat detection and data analysis.
Splunk Enterprise Platform is renowned for its powerful capabilities in log management, threat detection, and data visualization. It supports infrastructure monitoring and anomaly detection, crucial for Security Incident and Event Management operations. With its scalable architecture, users can efficiently manage data ingestion and create personalized dashboards, utilizing Splunk Processing Language for comprehensive querying and system performance assessment. This platform offers enhanced threat detection through its robust anomaly detection features and real-time monitoring capabilities, with machine learning enabling predictive analytics.
What features make Splunk Enterprise Platform stand out?In industries like finance, healthcare, and technology, Splunk Enterprise Platform is implemented to monitor infrastructure, manage logs, and enhance security protocols. Companies utilize its predictive analytics for strategic planning and operational efficiency, focusing on integration with AWS, EDR, and firewalls for comprehensive data visualization and threat management.
We monitor all IT Alerting and Incident Management reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.