Try our new research platform with insights from 80,000+ expert users

ConnectWise Automate vs Splunk Enterprise Security comparison

 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

ConnectWise Automate
Average Rating
7.4
Reviews Sentiment
7.2
Number of Reviews
15
Ranking in other categories
Remote Monitoring and Management (RMM) (10th)
Splunk Enterprise Security
Average Rating
8.4
Reviews Sentiment
7.5
Number of Reviews
318
Ranking in other categories
Log Management (2nd), Security Information and Event Management (SIEM) (1st), IT Operations Analytics (1st)
 

Mindshare comparison

While both are Systems Management solutions, they serve different purposes. ConnectWise Automate is designed for Remote Monitoring and Management (RMM) and holds a mindshare of 7.7%, down 9.3% compared to last year.
Splunk Enterprise Security, on the other hand, focuses on Security Information and Event Management (SIEM), holds 9.4% mindshare, down 12.1% since last year.
Remote Monitoring and Management (RMM)
Security Information and Event Management (SIEM)
 

Featured Reviews

MikeChacker - PeerSpot reviewer
Facilitates valuable patch cycles, but the web client is not very intuitive and needs updating, and the scripting has room for improvement
The fixed client for Automate is slow. The web client is not very intuitive. It could use some updating and some thought around the UX. Also, with the scripting, I would like to see something where it could have third-party scripts already pre-built, and all you have to do is say, "Hey, I need this," and go load it. It's not as automated as I'd like it to be.
ROBERT-CHRISTIAN - PeerSpot reviewer
Has many predefined correlation rules and is brilliant for investigation and log analysis
It is very complicated to write your own correlation rules without the help of Splunk support. What Splunk could do better is to create an API to the standard SIEM tools, such as Microsoft Sentinel. The idea would be to make it less painful. In ELK Stack, Kibana is the query language with which you can search log files. I believe Splunk has also a query language in which they search their log files, but once you have identified the log file that you want to use for further security correlation, you want to very quickly transport that into your SIEM tool, such as Microsoft Sentinel. That is something that Splunk could make a little bit less painful because it is a lot of effort to find that log file and forward it. An API with Microsoft Sentinel or a similar SIEM tool would be a good idea.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"The most value we get from this solution is that everything is on a patch cycle."
"We use monitors to keep track of our machines. We use a pretty good portion of information from Automate."
"It's definitely improved the help-desk servicing, et cetera."
"A good automated scripts feature."
"Scripting and patch management are really important for us. Patch Manager is something that we use a lot, and we would love to have it continually improved. It is one of the most useful features for us for controlling patches and other things for different clients."
"It allows us to manage all client requests, jobs and invoicing."
"It is very scalable."
"Maybe they could improve the capability to be multi-tenant."
"The client site login is pretty extensible and probably cost-effective."
"The community marketplace is useful; often, you do not need to rely on Splunk Enterprise Security support due to the wealth of online documentation available—Splunk docs are truly beneficial."
"The dashboard is amazing. Out-of-the-box dashboard is very good. It is very user-friendly."
"What I really like is that even if you have already collected the data, you can extract fields and can build searches."
"Its integration is most valuable. Its UI is also pretty much easy."
"Its alerting is most valuable. We have alerts set up in our environment for certain attacks, such as an SQL injection attempt. We have a front-facing server for the website. It is out there, and anybody can access it. When those SQL injection attempts come in, we are able to detect that with the alert."
"This solution helps us increase our productivity."
"The scalability of the solution is amazing because it can collect a lot of data and you can have your own structure to monitor this data."
 

Cons

"This is a raw system. Of course, it has some flaws that could be improved. But, it's something that we will have to work with to get to the point where we need this, we request it and they do their best to make it happen."
"They always change the GUI to some dumb-down version of tiles which are more "user-friendly", but slows my team down in the end."
"I have a problem with the reports available on the solution. I don't understand how to work with the reporting functionality. For example, when I want to give a report for a specific machine, ConnectWise doesn't seem to have this as an option. I'm not sure if I'm missing something, or if the reporting functionality is just poorly conceived."
"The menu doesn't always load properly."
"The fixed client for Automate is slow. The web client is not very intuitive."
"We would love to get feature updates and cumulative updates fixed. I know they aren't really supposed to be pushed with Patch Manager. We've got recommendations from ConnectWise to use the scripted feature update installs, scripted KB updates, etc. Having these in Patch Manager itself would be great."
"Scheduling of automation could be improved and made more simple."
"Technical support was helpful."
"The solution could use a different licensing model."
"The tool should include more real-world use case examples built out either through videos or in the community."
"The level of scalability depends on the license you have. You can expand or reduce it based on the environment. It does cost more money to scale, however."
"I do not have any pain points for Splunk Enterprise Security. I am still trying to learn it, but there can be more information on the education side for Splunk Enterprise Security. It would be nice if the certification path was more specific to what I use instead of being so broad."
"The solution could improve by making it more business analysis oriented. The way it is now is designed more for developers."
"Delays in responses from the technical team can pose challenges for both vendors and clients, especially considering that Splunk applications and machine solutions are critical assets."
"It can be tough to determine if you are getting all of the value out of your investment at times."
"The complexity could be worked on so that it's even easier and faster."
 

Pricing and Cost Advice

"Pricing and licensing are reasonable."
"I pay $85 a month per user for a ConnectWise package that contains multiple solutions."
"From what I've overheard, it is pretty comparable to other solutions in terms of price."
"I believe Automate is available for around $2."
"ROI is estimated at saving my team roughly 10 to 12 man hours per week in troubleshooting for our company as well as what our profits had been from our services of installing, configuring, and supporting other clients with the product."
"Splunk Enterprise Security is an expensive solution."
"The pricing model is based on the number of gigabytes that you ingest into the Splunk system. So it can be an expensive solution."
"The pricing could be made more competitive."
"It's more expensive than the other tools, but it's worth it. Every penny is worth it."
"Splunk Enterprise Security is a worthwhile investment given the comprehensive range of features it offers."
"Most people share the same thought that the ingestion rates can get pretty pricey. There is a lot of work we do to curate the data that we send to Splunk so that it is not too noisy or too expensive."
"It can be cost-prohibitive when you start to scale and have terabytes of data. Its cost model is based on how much data it processes a day. If they're able to create scaled-down niche or custom package offerings, it may help with the cost. Instead of the full-blown features, if they can narrow the scope where it can only be used for a specific purpose, it would kind of create that market for the product, and it may help with the costing. When you start using it as a central aggregator and you're pumping tons of logs at it, pretty soon, you'll start hitting your cap on what it can process a day. Once you've got that, you're kind of defeating the purpose because you're going to have to scale back."
report
Use our free recommendation engine to learn which Remote Monitoring and Management (RMM) solutions are best for your needs.
862,499 professionals have used our research since 2012.
 

Comparison Review

VS
Feb 26, 2015
HP ArcSight vs. IBM QRadar vs. ​McAfee Nitro vs. Splunk vs. RSA Security vs. LogRhythm
We at Infosecnirvana.com have done several posts on SIEM. After the Dummies Guide on SIEM, we are following it up with a SIEM Product Comparison – 101 deck. So, here it is for your viewing pleasure. Let me know what you think by posting your comments below. The key products compared here are…
 

Top Industries

By visitors reading reviews
Educational Organization
16%
Computer Software Company
14%
Performing Arts
7%
Real Estate/Law Firm
6%
Financial Services Firm
14%
Computer Software Company
14%
Manufacturing Company
8%
Government
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

Ask a question
Earn 20 points
What SOC product do you recommend?
For tools I’d recommend: -SIEM- LogRhythm -SOAR- Palo Alto XSOAR Doing commercial w/o both (or at least an XDR) is asking to miss details that are critical, and ending up a statistic. Also, rememb...
What is a better choice, Splunk or Azure Sentinel?
It would really depend on (1) which logs you need to ingest and (2) what are your use cases Splunk is easy for ingestion of anything, but the charge per GB/Day Indexed and it gets expensive as log ...
How does Splunk compare with Azure Monitor?
Splunk handles a high amount of data very well. We use Splunk to capture information and as an aggregator for monitoring information from different sources. Splunk is very good at alerting us if we...
 

Also Known As

LabTech for IT Service Providers, ConnectWise Automate for Corporate IT Departments, ConnectWise Automate for IT Service Providers
No data available
 

Overview

 

Sample Customers

I-M Technology, Mainstay Technologies, PC Works Plus, Integrity IT, Kerkhoff Technologies Inc., Marathon Consulting, Christenberry Sales Company, EDTS, Secom Technology, Ready to View, ARRC Technology, DaVinci Digital, JNR Networks, Quinn Technology Solutions, PCIT, Liberty Technology, Capital Computers & Networks, Atlanta Technology Force, Doberman Technologies, First Column Enterprises, CisCom Solutions
Splunk has more than 7,000 customers spread across over 90 countries. These customers include Telenor, UniCredit, ideeli, McKenney's, Tesco, and SurveyMonkey.
Find out what your peers are saying about Kaseya, NinjaOne, N-able and others in Remote Monitoring and Management (RMM). Updated: June 2025.
862,499 professionals have used our research since 2012.