Try our new research platform with insights from 80,000+ expert users

BMC TrueSight Operations Management vs Splunk Enterprise Security comparison

 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

BMC TrueSight Operations Ma...
Average Rating
8.2
Reviews Sentiment
6.7
Number of Reviews
50
Ranking in other categories
Application Performance Monitoring (APM) and Observability (22nd), Event Monitoring (2nd), IT Infrastructure Monitoring (24th), Cloud Monitoring Software (19th), AIOps (8th)
Splunk Enterprise Security
Average Rating
8.4
Reviews Sentiment
7.6
Number of Reviews
306
Ranking in other categories
Log Management (2nd), Security Information and Event Management (SIEM) (1st), IT Operations Analytics (1st)
 

Mindshare comparison

While both are Application Lifecycle Management solutions, they serve different purposes. BMC TrueSight Operations Management is designed for IT Infrastructure Monitoring and holds a mindshare of 0.8%, down 1.3% compared to last year.
Splunk Enterprise Security, on the other hand, focuses on Security Information and Event Management (SIEM), holds 9.5% mindshare, down 12.6% since last year.
IT Infrastructure Monitoring
Security Information and Event Management (SIEM)
 

Featured Reviews

Srri G - PeerSpot reviewer
The product is reasonably priced, but the solution is a little obsolete because it is deployed on-premise
If I want custom monitoring across a very large estate of more than 50,000 units, the on-premise deployment gets quite slow. The on-premise product’s performance must be improved. The solution is a little obsolete. That is why the solution moved to Helix, a SaaS operating system. The SaaS platform has the features I like. There is no point in BMC expanding TrueSight Operations’ console. It's high time that BMC starts a demise path for the product and is associated only with Helix. If we need any additional function, we must switch to Helix. Since TrueSight is deployed on-premise, the scalability and usage of the product are mainly focused on providing basic features and not enhanced features like analytics or cost analysis. People should move to a SaaS platform because on-premise products have limited storage and capacity.
ROBERT-CHRISTIAN - PeerSpot reviewer
Has many predefined correlation rules and is brilliant for investigation and log analysis
It is very complicated to write your own correlation rules without the help of Splunk support. What Splunk could do better is to create an API to the standard SIEM tools, such as Microsoft Sentinel. The idea would be to make it less painful. In ELK Stack, Kibana is the query language with which you can search log files. I believe Splunk has also a query language in which they search their log files, but once you have identified the log file that you want to use for further security correlation, you want to very quickly transport that into your SIEM tool, such as Microsoft Sentinel. That is something that Splunk could make a little bit less painful because it is a lot of effort to find that log file and forward it. An API with Microsoft Sentinel or a similar SIEM tool would be a good idea.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"The Event Management is outstanding; still is the most interesting part of the product."
"The initial setup of BMC TrueSight Operations Management was easy."
"The fact that they have a very integrated relationship with Sentry Software, the Knowledge Module, is valuable... The richest feature for us is the number of Knowledge Modules that we can load into the product to add breadth of service to the customer. It enables us to move up the operational stack from hardware, to operating system, to application, and to cloud... That enables us to provide one pane of glass over all those layers - hardware, OS, app, and cloud."
"The noise reduction for ticketing works much better than we have seen in a lot of other companies."
"We're using native monitoring capabilities for all our server hardware, for visibility for applications, for URLs, for webpage response and accuracy, and for monitoring network throughput in a lot of particular instances. We're using lightweight protocols for pinging, for DNS, for LDAP."
"It has provided us with a single location to host all events to be viewed/monitored by our NOC. This has greatly helped them to streamline their processes."
"The ability of this platform to monitor the very diverse assets that we maintain around the world is its most valuable feature... We support a vast array of manufacturers' equipment, like HP, IBM, Cisco, Dell, EMC, Hitachi... We can do it all with [this] one [solution]."
"It works irrespective of the operating system we’re running."
"The search engine and indexes are fast and optimized, and the report generation dashboard is user-friendly."
"It is quite extensible. It is a platform that we can build our use instead of each case instead of each case being limited or restricted to each capability. This is probably the best feature."
"I have noticed a return on investment with Splunk Enterprise Security, as it delivers substantial value for money."
"The solution is very fast and succinct."
"The solution's most valuable features are the granularity and analysis of the logs."
"It is a one stop shop as a full monitoring and alerting solution for operations and application analysis for most of our back-end systems."
"It has a drag-and-drop interface, so you don't need to know SQL or Java to construct a query on Splunk. The resolution time is about the same, but it took longer to discover the issue with ArcSight. Our previous solution took about an hour or more, but Splunk can do it within a few minutes or an hour at most."
"The most valuable features of Splunk Enterprise Security are the enterprise search bar and the dashboards."
 

Cons

"In a large company of our size, we need multiple people in our company trained. So, I have to take the training classes. Then, I have to go and train the rest of my organization. I would prefer to say to the other people on my team, "Go to this link and..." Or, "Here's a list of training sessions that you can go to which are online and that are free." I think it would help the adoption of their product in the marketplace, personally."
"Deployment requires lots of resources (servers). It has too many consoles."
"We have a unique use case because BMC typically sells this solution into enterprises that are deploying it within their IT, versus to a managed services provider like us where we're supporting thousands of customers. Multi-tenancy and the scalability have been challenges along the way, as we've grown... If anything could have gone better as we were ramping this up and adding a lot of volume to it, I would say it's the scalability. That would be one thing that could be improved."
"The solution could improve its price."
"BMC's online documentation is often incorrect or incomplete."
"I definitely would like to see more improvement in the self-diagnostics. I need to know when anything is not working or collecting, long before our customer finds it."
"The solution is a little obsolete."
"I would like them to improve the deep-dive details, tracing, and data agents in this product. We have EUEM, an end-user experience monitoring appliance. This one's quicker than the current one, and reporting side and filtration side are very bad. There are many details we look at and explain what we receive information in the current one, but we cannot have historical data like we do with EUEM. We cannot have a powerful point to look for specific traffic from a specific application and a specific browser. We don't have it in the new one. The current BMC also needs to add the thing that control versions."
"Data retention can be better. If we want to look at the data for five months or six months, that is not available to us."
"Splunk does not build apps. They only go back and validate the apps that somebody has already built. They should have remote consulting support. They have a wonderful solution. They have 24/7 security. Nobody needs to depend on any third party and will therefore just buy Splunk on the cloud."
"Splunk should have more regional data centers in the Middle East."
"It requires a significant amount of relatively complex architecture once you push past the single server instance."
"We do have to educate developers on how to not blow it up. It is a little to easy to write an expensive query and overly stress the system. This could be improved."
"Splunk is very expensive. The license is based on the volume of the logs ingested. I was responsible for managing the contract with our service integrator. I don't know the precise details of the competing solution, but I have heard that Splunk is more expensive than others. I don't know what the going rate is on the market, but I think there are at least two competitors that are less expensive. We have experienced a few issues with our service providers in terms of log filtering and ingestion, so we continue to pay a bit more per day for our logs."
"The user interface is not user-friendly for non-technical users."
"Splunk isn't appropriate for smaller companies. It's too expensive."
 

Pricing and Cost Advice

"The cost depends on the usage."
"BMC TrueSight Operations Management is not on the cheaper side, but its pricing is on a case by case basis. Its licensing model is simple and based on the number of devices."
"Use conservative figures. In terms of hardware, monitored servers and also effort. The product is not cheap. But as with other products, you get what you pay for."
"We did a five-year, multimillion dollar deal."
"Consider scalability very carefully: how much you want to monitor and what components are very important. Then, depending on these two things, filter out unwanted metrics or attributes. If you do a good job at filtering the data, then your licensing costs will be manageable."
"We're end-of-lifeing it now. Overall, the licensing costs of BMC are a challenge for us in that they're hard costs, whereas open-source monitoring has soft costs, where it's harder to line-item."
"They have changed the licensing fees."
"Other products are more expensive than BMC TrueSight."
"We have had a reduction in the time it takes to resolve issues and correlate what has failed."
"The price can always be lower, but it is fair at the moment. The cost efficiencies depend on the licensing and how much data we are bringing in. We have a fairly large footprint, so it is cost-effective."
"Licensing is a yearly, one-time cost."
"Splunk Enterprise Security is an expensive solution."
"Splunk's costing is a little more difficult. The pricing method is complicated, and the way that costing is calculated in Splunk is a little more difficult."
"I've heard Splunk is often preferred over other options, but the cost can be prohibitive for smaller organizations."
"The Splunk licensing is high."
"The pricing model is expensive and a nightmare based on the amount of data."
report
Use our free recommendation engine to learn which IT Infrastructure Monitoring solutions are best for your needs.
850,671 professionals have used our research since 2012.
 

Comparison Review

VS
Feb 26, 2015
HP ArcSight vs. IBM QRadar vs. ​McAfee Nitro vs. Splunk vs. RSA Security vs. LogRhythm
We at Infosecnirvana.com have done several posts on SIEM. After the Dummies Guide on SIEM, we are following it up with a SIEM Product Comparison – 101 deck. So, here it is for your viewing pleasure. Let me know what you think by posting your comments below. The key products compared here are…
 

Top Industries

By visitors reading reviews
Financial Services Firm
25%
Computer Software Company
14%
Manufacturing Company
6%
Government
6%
Financial Services Firm
15%
Computer Software Company
14%
Manufacturing Company
8%
Government
8%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

What do you like most about BMC TrueSight Operations Management?
The solution provides visibility to our infrastructure, how it is, the resources we are monitoring, and quick updates when it has any problems. We have integrated it with ServiceNow to open instances.
What is your experience regarding pricing and costs for BMC TrueSight Operations Management?
Though I have no clue about the tool's actual price, I know that it is astronomical.
What needs improvement with BMC TrueSight Operations Management?
Cost is an issue with BMC TrueSight Operations Management. Though I am not responsible for the budget, I know that it is an expensive tool set when used only for event management. The tool's issue ...
What SOC product do you recommend?
For tools I’d recommend: -SIEM- LogRhythm -SOAR- Palo Alto XSOAR Doing commercial w/o both (or at least an XDR) is asking to miss details that are critical, and ending up a statistic. Also, rememb...
What is a better choice, Splunk or Azure Sentinel?
It would really depend on (1) which logs you need to ingest and (2) what are your use cases Splunk is easy for ingestion of anything, but the charge per GB/Day Indexed and it gets expensive as log ...
How does Splunk compare with Azure Monitor?
Splunk handles a high amount of data very well. We use Splunk to capture information and as an aggregator for monitoring information from different sources. Splunk is very good at alerting us if we...
 

Also Known As

ProactiveNet, TrueSight Operations Management
No data available
 

Overview

 

Sample Customers

Ensono, Transamerica, Boston Scientific, Park Place Technologies, inContact, TD Ameritrade, PNC Bank
Splunk has more than 7,000 customers spread across over 90 countries. These customers include Telenor, UniCredit, ideeli, McKenney's, Tesco, and SurveyMonkey.
Find out what your peers are saying about BMC TrueSight Operations Management vs. Splunk Enterprise Security and other solutions. Updated: May 2023.
850,671 professionals have used our research since 2012.