Try our new research platform with insights from 80,000+ expert users

Centreon vs Splunk Enterprise Security comparison

 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Centreon
Average Rating
8.4
Reviews Sentiment
7.2
Number of Reviews
29
Ranking in other categories
Network Monitoring Software (25th), IT Infrastructure Monitoring (22nd), Cloud Monitoring Software (18th)
Splunk Enterprise Security
Average Rating
8.4
Reviews Sentiment
7.6
Number of Reviews
306
Ranking in other categories
Log Management (2nd), Security Information and Event Management (SIEM) (1st), IT Operations Analytics (1st)
 

Mindshare comparison

While both are Systems Management solutions, they serve different purposes. Centreon is designed for IT Infrastructure Monitoring and holds a mindshare of 2.9%, down 3.0% compared to last year.
Splunk Enterprise Security, on the other hand, focuses on Security Information and Event Management (SIEM), holds 9.5% mindshare, down 12.6% since last year.
IT Infrastructure Monitoring
Security Information and Event Management (SIEM)
 

Featured Reviews

Caulson Chua - PeerSpot reviewer
With fewer staff resources, we can identify and address issues before the system goes down
Centreon's most valuable features are preventative maintenance and cost-efficiency. Everything is monitored, and we get a log before the system fails. We have an opportunity to fix the issue and avoid downtime. The dashboard is user-friendly, and the solution provides good reporting and visibility. The layout is straightforward. You can click on the drop-down list to select the server you want. The anomaly detection feature helped us reduce our average resolution time by 30 minutes to an hour.
ROBERT-CHRISTIAN - PeerSpot reviewer
Has many predefined correlation rules and is brilliant for investigation and log analysis
It is very complicated to write your own correlation rules without the help of Splunk support. What Splunk could do better is to create an API to the standard SIEM tools, such as Microsoft Sentinel. The idea would be to make it less painful. In ELK Stack, Kibana is the query language with which you can search log files. I believe Splunk has also a query language in which they search their log files, but once you have identified the log file that you want to use for further security correlation, you want to very quickly transport that into your SIEM tool, such as Microsoft Sentinel. That is something that Splunk could make a little bit less painful because it is a lot of effort to find that log file and forward it. An API with Microsoft Sentinel or a similar SIEM tool would be a good idea.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"I can't point to one valuable feature. All of Centreon is good."
"The product is available in ISO image format, ready for deployment. Centreon also has a comprehensive guide and documentation that are simple and easy to follow."
"It supports active monitoring so we don't have to use traps. From time to time traps are not very useful because we never know if they are actually working or not. The reporting part is also valuable as are the event logs. Using them we can check right away if something has had a hiccup."
"Valuable features include the ability to schedule downtime, intensity or depth of monitoring which it does, different plugin packs, Centreon MAP, Centreon BI."
"In addition, the flexibility, customizability, and analytics of Centreon's dashboards are all very good. The dashboards help us see the whole network map, and that is quite valuable for us. In addition, the dashboards have helped to improve our visibility and ability to proactively ensure the right data is available at the right time... The flexibility has given us the ability to add in our own monitoring metrics and that has been quite interesting and very useful for us."
"The most valuable feature is the monitoring of servers and networks, because we have a lot of them and need to maintain control."
"The most valuable feature of the solution is that most of its plug-ins are free."
"Centreon's most valuable feature is Opsgenie."
"I haven't had the chance to properly sink my teeth into Enterprise Security but so far I like that they added the MITRE ATT&CK features."
"We evaluated several solutions and selected Splunk due to the functionality and cost."
"The connections to the database are very good and updating the data files is simple to do. The dashboards are useful and user-friendly."
"Overall, Splunk is among the top three SIEM tools due to its capabilities and agility in bridging business analytics with security needs."
"Splunk has significantly helped with aggregation and correlation of critical logs. Not having to grep on each individual server has made everyone more efficient."
"On the cloud, we are pushing through less than half a petabyte of data. So far, it has been fairly stable because it runs on all the underlying AWS infrastructures."
"The consolidated overview of all the events that come in through our environment and an easy-to-access interface for all our end users are valuable."
"It is the best tool if you have a complex environment or if data ingestion is too huge."
 

Cons

"The product collects the information, but it fails to send them via SMS, WhatsApp or Telegram."
"Sometimes, when the GUI and some of the search fields are being reset, and I return to the page, then I have to set them again. Therefore, some improvement on the UI and the filtering is needed."
"There is room for improvement in the area of artificial intelligence. The product gives us a lot of information, but it's only information. We want the product to do more auto-remediation."
"Currently, we have to go through all of the different templates and take a look at how the template is configured, and how specific parameters may change across different templates with different precedents, megatons, etc. It's a lot of work and involves trial and error. I wish they could simplify the process."
"The most important issue is the capability to interconnect with other systems. It already exists for some of them. For example, the Stream Connector is something we use to populate data in another system. This kind of facility for connecting should exist for all products that it makes sense to have connected to a monitoring solution."
"To get it started is a lot of work, since it comes empty. We had to push information into it to make it work."
"Centreon supports officially 10,000 services per poller. That is not much for larger customers, because this limit is reached very quickly. We use it with three times the limit without any problems, but Centreon says, "Okay, we are only supporting it with 10,000 services." We are aware that increasing the limit has different impacts because they need to support it. However, for most customers, it would be be very good if they could increase the limit of services."
"The problem with the reporting is you have to configure the report, and after that, you will have the same report every month, every week, every day. You have to sync it in order to have a great report."
"Its reporting can be improved. That's the only complaint I have heard. I don't need the reporting part, but I know that other people in the organization need it."
"Considering the contract thing and the whole legal area, it takes forever to get the contracts signed and to be able to agree to the terms and conditions for my company as well as for Splunk's team."
"It could be more user friendly, in terms of the end-user experience."
"I would like to see ability to master management. In terms of clustering, how it manages clustering needs improvement."
"While Splunk offers SOAR as a separate product, integrating it into the next version of Splunk Enterprise Security as a unified solution would be beneficial."
"Given the ever-increasing number of threats, I would like Splunk to update its threat signatures more frequently."
"When we do a rollout from the server or host or anything, we'd like to see more automation. It would save us time."
"The access and identity features could be improved. For example, let's say we have onboarded 65 logs. Now, we can identify the various processes, but we run into trouble when we're updating the processes for AWS CloudTrail, EDR, MDR, and XDR."
 

Pricing and Cost Advice

"I think Centreon's pricing is fair, especially given the criticality of our system. They were cheaper than the other solutions. The licensing terms were pretty straightforward. I believe it was based on the number of hosts."
"They only sell four hour slots for support, so if you have just one question, then you need to pay for four hours. Or, you need to wait until you have enough questions to fill those four hours. They are not flexible in this."
"It is perfect and very cheap if you are a little company or startup. After that, it is quite expensive for a big company."
"For more complex tasks, we use prepaid support days and ask Centreon to come onsite."
"Open-source solutions like this can be very cost effective for an organization looking for a product that they can quickly implement, as there is no initial cost and there are no license renewal fees. However, it is important to take into consideration some of the related costs that may come along as needed, such as training, support, and product enhancements."
"I would like to see improvement in the licensing model. You can purchase X number of licenses, up to 1,000 devices or 1,000 instances. Your next batch is 2,000. But what if you only need, say, 1,200? The model could be changed a little bit."
"The pricing starts at around 5000 euro. However, this depends on: Your environment, the size of your host, how many hosts you have, how many remote pollers you have, and if you want to use the Monitoring Business Intelligence or Centreon MAP functionalities."
"Centreon is always available to develop new plugins when needed. The most important thing is that their maintenance account yearly subscription fee includes the fact that they will maintain the new plugins that you requested them to deliver."
"Although Splunk is an expensive product, it is designed to be utilized across your organization in order to maximize your ROI and lower your TCO."
"Be upfront about your needs and expectations. Splunk is great to work with."
"The license for Splunk Enterprise Security is expensive."
"Splunk is definitely not a cheap solution. It is an expensive product."
"Our customers often complain that the price of Splunk is too high."
"Splunk Enterprise Security is expensive. I would rate the cost an eight out of ten with ten being the most expensive."
"Splunk is expensive based on our current requirements, but it's obviously worth what we pay."
"I work on the technical side, so I don't know precise figures. However, I know that Splunk is a premium product, so it's somewhat costly. Still, you get a lot of unique features for the money."
report
Use our free recommendation engine to learn which IT Infrastructure Monitoring solutions are best for your needs.
849,686 professionals have used our research since 2012.
 

Comparison Review

VS
Feb 26, 2015
HP ArcSight vs. IBM QRadar vs. ​McAfee Nitro vs. Splunk vs. RSA Security vs. LogRhythm
We at Infosecnirvana.com have done several posts on SIEM. After the Dummies Guide on SIEM, we are following it up with a SIEM Product Comparison – 101 deck. So, here it is for your viewing pleasure. Let me know what you think by posting your comments below. The key products compared here are…
 

Top Industries

By visitors reading reviews
Computer Software Company
19%
Financial Services Firm
11%
Government
10%
Comms Service Provider
7%
Financial Services Firm
15%
Computer Software Company
14%
Manufacturing Company
8%
Government
8%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

What do you like most about Centreon?
Centreon's most valuable features are preventative maintenance and cost-efficiency. Everything is monitored, and we get a log before the system fails. We have an opportunity to fix the issue and av...
What needs improvement with Centreon?
The issue my company has with the tool stems from the fact that it didn't give an on-time response to us. The product collects the information, but it fails to send them via SMS, WhatsApp or Telegr...
What SOC product do you recommend?
For tools I’d recommend: -SIEM- LogRhythm -SOAR- Palo Alto XSOAR Doing commercial w/o both (or at least an XDR) is asking to miss details that are critical, and ending up a statistic. Also, rememb...
What is a better choice, Splunk or Azure Sentinel?
It would really depend on (1) which logs you need to ingest and (2) what are your use cases Splunk is easy for ingestion of anything, but the charge per GB/Day Indexed and it gets expensive as log ...
How does Splunk compare with Azure Monitor?
Splunk handles a high amount of data very well. We use Splunk to capture information and as an aggregator for monitoring information from different sources. Splunk is very good at alerting us if we...
 

Overview

 

Sample Customers

Airbus, Bollore, BT, Canal Plus, Kuehne Nagel, Limagrain, LVMH, Oberthur Technologies, Orange, Darty, Addax Petroleum, Plastic Omnium, Auchan, Valeo, Saint Gobin, Clarins, Hugo Boss, JC Decaux, French Government (Defense, Justice, Environment, Agriculture), OptiComm, Thales, Zeiss.
Splunk has more than 7,000 customers spread across over 90 countries. These customers include Telenor, UniCredit, ideeli, McKenney's, Tesco, and SurveyMonkey.
Find out what your peers are saying about Zabbix, Datadog, Auvik and others in IT Infrastructure Monitoring. Updated: April 2025.
849,686 professionals have used our research since 2012.