Centreon vs Splunk Enterprise Security comparison


Comparison Buyer's Guide

Executive Summary

Categories and Ranking

Average Rating
Number of Reviews
Ranking in other categories
Network Monitoring Software (16th), IT Infrastructure Monitoring (15th), Cloud Monitoring Software (14th)
Splunk Enterprise Security
Average Rating
Number of Reviews
Ranking in other categories
Log Management (1st), Security Information and Event Management (SIEM) (1st), IT Operations Analytics (1st)

Mindshare comparison

As of July 2024, in the IT Infrastructure Monitoring category, the mindshare of Centreon is 4.4%, up from 3.3% compared to the previous year. The mindshare of Splunk Enterprise Security is 2.3%, down from 4.3% compared to the previous year. It is calculated based on PeerSpot user engagement data.
IT Infrastructure Monitoring
Unique Categories:
Network Monitoring Software
Cloud Monitoring Software
Log Management
Security Information and Event Management (SIEM)

Featured Reviews

Mar 18, 2024
An expensive solution to monitor network infrastructure
Centreon is a client application. We use the solution to monitor network infrastructure. In case of an incident, We can fix the issue Centreon makes me reactive. It allows the use of signal application over monitoring infrastructure to use signal. The solution allows us to study more analysis to…
Jun 13, 2024
Provides threat intelligence correlations and reduces lead time for identifying risks and threats
The solution's most valuable feature is threat intelligence correlations. It's too hard to stay up-to-date on all the different data feeds yourself. So, having a tool that does it for you is very beneficial. Splunk Enterprise Security has increased our alert volume because we now have new data to work with, and we're writing more alerts. We don't use the solution a lot for observability. Usually, our primary use case for Splunk Enterprise Security is cybersecurity. It is extremely important to our organization that Splunk Enterprise Security provides end-to-end visibility into our environment. That's the primary reason we use it. We want the ability to do everything from one tool without having to trash back and forth and take that precious time. Splunk Enterprise Security has helped reduce our mean time to resolve. We're at least twice as efficient with Splunk Enterprise Security at identifying risk, following up, tracing it throughout the chain, and resolving it. We still have various toolings, but over time, the goal is to nest everything into Splunk Enterprise Security to make it cohesive from end to end.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:


"We use the remote server functionality on some customer sites, because you can see an independent view and are not dependent on a single connection. If you have branch offices or bigger office outside your headquarters, you can use remote servers because if the connection is broken or disrupted, then remote server will obtain a view of your environment and server availability. This is a good point against using other solutions. Because with other solutions, you don't have this feature. Then, you will be blind if you have this type of a situation."
"Valuable features include the ability to schedule downtime, intensity or depth of monitoring which it does, different plugin packs, Centreon MAP, Centreon BI."
"The customizable reports and dashboards are really flexible. We started this partnership with Centreon, when we were looking for a solution, because of the flexibility of the reporting. That's what we found to be most attractive in the solution. You can display the data as you want."
"It is decentralized, which is better, because you can reduce the load from a single system. Also, you get a better view because it's more independent. Then, for the management, it's nice because they have one central system. With that, they can manage all the other systems, as well. This means they don't have to configure each system by system. They can configure it from one single interface."
"The most valuable feature is that we can manually configure everything we need. After it comes inside the interface of Centreon, you can display it. Because the interface is quite user-friendly, you can manually configure the configuration very deeply, which is very pleasant and useful because you can monitor and see everything on your service list, dashboard, or MAP. The most useful feature for me is that you can create your own plugin and monitoring query."
"I find the product's scalability to be one of the most valuable features since it allows us to add unlimited devices for monitoring and to set up additional polling servers without additional license cost or downtime in our monitoring."
"I really like the filtering capabilities of it. You can easily tell what's critical next to what's okay, the state of the services. It's very easy to get the whole picture quickly."
"We have a single GUI where we can view the status of all our infrastructure."
"On the cloud, we are pushing through less than half a petabyte of data. So far, it has been fairly stable because it runs on all the underlying AWS infrastructures."
"It provides a risk score for each object, device, or user. We can then take action if they are at a higher risk."
"The most valuable features in Splunk are the search function and the ability to run selected session reports. The session reports are important because I can use them to see what is going on in our environment weekly. Additionally, we can use the graph to see how often that particular event is happening."
"Splunk helps us be more proactive. We can take predictive action to identify and block threats so that nothing harmful gets into the system."
"Visualizations helped the organisation with a better understanding of its KPIs."
"We are much faster finding and addressing issues with Splunk."
"Splunk's strongest suit is its user interface. We can integrate multiple solutions and adjust settings in the Splunk interface."
"The solution's most valuable feature is its data modeling."


"The most important issue is the capability to interconnect with other systems. It already exists for some of them. For example, the Stream Connector is something we use to populate data in another system. This kind of facility for connecting should exist for all products that it makes sense to have connected to a monitoring solution."
"The problem with the reporting is you have to configure the report, and after that, you will have the same report every month, every week, every day. You have to sync it in order to have a great report."
"I would like to see an improvement of the communication with big data systems, because Centreon is a monitoring system. In our point of view, Centreon should be a part of a source for a big data system, not a big data system itself. So, it should be easier to add data from the Centreon system to a big data system. For example, it should be able to teach machine learning."
"Improvements are needed in the area of cloud monitoring, as that's a newer feature."
"Centreon supports officially 10,000 services per poller. That is not much for larger customers, because this limit is reached very quickly. We use it with three times the limit without any problems, but Centreon says, "Okay, we are only supporting it with 10,000 services." We are aware that increasing the limit has different impacts because they need to support it. However, for most customers, it would be be very good if they could increase the limit of services."
"I would like them to improve their documentation. When I faced some issues, I was looking for more documentation on the Internet. There is official documentation on Centreon's website, which sometimes is useful. Sometimes it is not very useful, as you cannot find the information or enough examples of configuration. The answer for me was to contact the support, who helped me, but I was not able to find all the information by myself on Centreon's website. A Centreon community or blog would be helpful."
"I would like to see a better UI, one which is more responsive."
"During the initial setup we faced some issues. Part of it was because we had to become more knowledgeable in the solution. There are some gray areas and if you don't know the product well you may have issues. Another part of it was some bugs that we came across, although that's part of every software solution in IT nowadays. But the initial setup could be easier."
"I would like to have fraud detection features. Fraud is within the same turf as with security operations. Fraud and cybersecurity work hand in hand. I would like to have detection capabilities, or at least dashboards in Enterprise Security for fraud."
"Spam has different plugins but by default, the logs are not organized, it shows that there are roll-ups that are out of the box. I saw many plugins that can help improve or extend Splunk's functionality but I haven't tried any of them."
"In the next releases, I would like to see more pricing flexibility."
"If you monitor too much, you can lose performance on your systems."
"They can incorporate the SOAR solution within the actual product so that we do not require two different products, two different installations, and two different pricing methods. In regards to UBA, I am familiar with the UBA that existed two years ago. I am not updated about it today, but two years ago, UBA required such an amount of data that from a cost perspective, it was not worth it. When you compare it to what you get out of the box with Microsoft Sentinel without additional costs, there is no match."
"Splunk is not very user-friendly. It has a complex architecture in comparison to other solutions on the market."
"The GUI could be improved to include some of the capabilities that other BI solutions have. The layout is a little restrictive where you can’t resize all the panels to exactly how you would like them without tweaking some XML code."
"The configuration had a bit of a learning curve."

Pricing and Cost Advice

"The solution has a free part and after that threshold, you will need to pay. For example, if you believe you can create an interesting map, most of the time, you will have to pay 10,000 Euros per year for having access to these components."
"Open-source solutions like this can be very cost effective for an organization looking for a product that they can quickly implement, as there is no initial cost and there are no license renewal fees. However, it is important to take into consideration some of the related costs that may come along as needed, such as training, support, and product enhancements."
"You purchase a package. You have a support contract (there is also a platinum support contract) and it is per module. That means you have to pay, e.g., for the MBI module or the BAM module. Or, if you want to save a lot of money, you can pay for IMP, which is the complete package."
"Their licensing model is really easy. You have one license and you have access to all the features, compared to other tools where you have to purchase add-ons."
"In terms of licensing, you have to think through if the components that need licensing are really needed. For example, the Map module: If you don't need a map to be shown, I don't see a point in paying for those licenses, if you just use it a couple of times a month or a couple of times a week... You can use the Centreon free version and get the main features. The licensing part is, I would say, only for bigger customers who have the option to pay more and who really need those kinds of modules, fancy reports, etc."
"Centreon is an open source product. Thus, there is no need for licensing."
"It's quite expensive when you use the Enterprise version, but if you compare it to other providers, it's more like a middle-of-the-line product. It's always good to have a price that is lower, but I would say the price is okay because we get very good support and if we have any other issues we can always contact them. There has never been a time when I didn't get help from them."
"They only sell four hour slots for support, so if you have just one question, then you need to pay for four hours. Or, you need to wait until you have enough questions to fill those four hours. They are not flexible in this."
"You will eat up whatever you purchase quickly. The level of insights that Splunk empowers is addictive."
"Regarding the product's pricing, I think it has always been difficult to have a conversation with Splunk."
"Splunk licensing model might seem expensive but with all the gain in functionalities you will have compared to traditional SIEM solutions I think it’s worth the price."
"Splunk Enterprise Security's pricing is pretty competitive."
"We have an unlimited one, and we pay yearly, but I don't know how much it costs. Previously, I worked for a startup, and when they started building it up, it was complicated for them because they didn't have the budget for that many licenses. It was very costly for them. So, startups might find it a little bit problematic because of the licensing, but for bigger companies, there is no issue."
"The price can always be lower, but it is fair at the moment. The cost efficiencies depend on the licensing and how much data we are bringing in. We have a fairly large footprint, so it is cost-effective."
"It's a yearly subscription."
"Further reductions would be fantastic, and I believe that more and more people would flock to it."
Use our free recommendation engine to learn which IT Infrastructure Monitoring solutions are best for your needs.
793,295 professionals have used our research since 2012.

Comparison Review

Feb 26, 2015
HP ArcSight vs. IBM QRadar vs. ​McAfee Nitro vs. Splunk vs. RSA Security vs. LogRhythm
We at Infosecnirvana.com have done several posts on SIEM. After the Dummies Guide on SIEM, we are following it up with a SIEM Product Comparison – 101 deck. So, here it is for your viewing pleasure. Let me know what you think by posting your comments below. The key products compared here are…

Top Industries

By visitors reading reviews
Computer Software Company
Financial Services Firm
Educational Organization
Financial Services Firm
Computer Software Company
Manufacturing Company

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business

Questions from the Community

What do you like most about Centreon?
Centreon's most valuable features are preventative maintenance and cost-efficiency. Everything is monitored, and we get a log before the system fails. We have an opportunity to fix the issue and av...
What needs improvement with Centreon?
Prometheus provides the ability to automate the backup of my infrastructure. This automatic backup capability allows me to integrate it into GitLab for versioning, among other functionalities. Thus...
What SOC product do you recommend?
For tools I’d recommend: -SIEM- LogRhythm -SOAR- Palo Alto XSOAR Doing commercial w/o both (or at least an XDR) is asking to miss details that are critical, and ending up a statistic. Also, rememb...
What is a better choice, Splunk or Azure Sentinel?
It would really depend on (1) which logs you need to ingest and (2) what are your use cases Splunk is easy for ingestion of anything, but the charge per GB/Day Indexed and it gets expensive as log ...
How does Splunk compare with Azure Monitor?
Splunk handles a high amount of data very well. We use Splunk to capture information and as an aggregator for monitoring information from different sources. Splunk is very good at alerting us if we...

Learn More




Sample Customers

Airbus, Bollore, BT, Canal Plus, Kuehne Nagel, Limagrain, LVMH, Oberthur Technologies, Orange, Darty, Addax Petroleum, Plastic Omnium, Auchan, Valeo, Saint Gobin, Clarins, Hugo Boss, JC Decaux, French Government (Defense, Justice, Environment, Agriculture), OptiComm, Thales, Zeiss.
Splunk has more than 7,000 customers spread across over 90 countries. These customers include Telenor, UniCredit, ideeli, McKenney's, Tesco, and SurveyMonkey.
Find out what your peers are saying about Zabbix, Datadog, Auvik and others in IT Infrastructure Monitoring. Updated: June 2024.
793,295 professionals have used our research since 2012.