

Splunk Observability Cloud and Cribl compete in the observability and data management sector. Splunk Observability Cloud seems to have an edge with its strong real-time monitoring capabilities, while Cribl offers cost-effective data management solutions.
Features: Splunk Observability Cloud is praised for highly responsive incident management and comprehensive dashboards, offering features like APM, real-time metrics, and ServiceNow integration for seamless operations. On the other hand, Cribl shines with its efficient data routing and reduction features, a user-friendly interface, and flexibility in handling diverse data types.
Room for Improvement: Splunk Observability Cloud needs to enhance its onboarding process, improve AI integration, and offer more transparency in pricing. Cribl should work on refining its integrations, enhancing documentation, and providing built-in templates for various workflows.
Ease of Deployment and Customer Service: Splunk Observability Cloud supports multiple deployment options including on-premises and hybrid environments, with customer service that is responsive yet can be delayed. Cribl offers flexible deployment but can encounter performance issues with large data loads; their customer service is generally regarded positively.
Pricing and ROI: Splunk Observability Cloud is considered expensive with complex pricing models, but delivers strong ROI through reduced downtime and enhanced efficiency. Cribl offers a more cost-effective solution, especially beneficial for handling large data volumes, making it attractive for organizations looking to manage licensing costs efficiently.
What we've seen is really an overall reduction of just shy of 40% in our ingest into our SIM platform versus prior to having Cribl.
The second thing is that data aggregation, sampling, and reduction that we're able to do of the data, lowering our overall data volume, both traversing the network as well as what's being stored inside of our final solutions.
In terms of reduction, we were able to save almost ~40% of our total cost.
Using Splunk has saved my organization about 30% of our budget compared to using multiple different monitoring products.
Anyone working in front-end management should recognize the market price to see the true value of end-user monitoring.
I have definitely seen a return on investment with Splunk Observability Cloud, particularly through how fast it has grown and how comfortable other teams are in relying on its outputs for monitoring and observability.
They had extensive expertise with the product and were able to facilitate everything we needed.
Usually, within an hour, we get a response, and we are able to work with them back and forth until we resolve the issues.
Sometimes by hearing the problem itself, they will know what the solution is, and they will let us know how to resolve it, and we do it immediately.
On a scale of 1 to 10, the customer service and technical support deserve a 10.
They have consistently helped us resolve any issues we've encountered.
They often require multiple questions, with five or six emails to get a response.
The infrastructure behind Cribl Search is also scalable as it uses a CPU and just spawns horizontally more instances as it demands and requires.
Compared to other SIEM tools I use, any slight change on the operating system end impacts a lot on our SIEM tools and other things, but Cribl performs well in that regard.
Cribl performs effectively across both market segments.
We've used the solution across more than 250 people, including engineers.
As we are a growing company transitioning all our applications to the cloud, and with the increasing number of cloud-native applications, Splunk Observability Cloud will help us achieve digital resiliency and reduce our mean time to resolution.
I would rate its scalability a nine out of ten.
Migrating from those SC4S servers to Cribl worker nodes has truly been a game-changer.
Regarding scalability, we started with zero servers and have around 285 servers now.
Cribl is designed to deal with certain kinds of loads and is not designed to handle any scenario in the market.
When downtime occurs, it raises concerns about how we measure and receive alerts, as everything needs to be in place.
I would rate its stability a nine out of ten.
We rarely have problems accessing the dashboard or the page.
A more stringent role-based access control feature would enhance security and allow granular control over what users can see and access.
When passing query logs or DNS logs, if certain malicious query patterns need to be identified or if fast-flux attacks are happening, Cribl can report that and those would definitely be a plus for them.
I would advise others looking to implement Cribl that if they are evolving Cribl Search, it would be very interesting to see more capability, more flexibility, and more ways to share the data similar to Splunk.
The out-of-the-box customizable dashboards in Splunk Observability Cloud are very effective in showcasing IT performance to business leaders.
The next release of Splunk Observability Cloud should include a feature that makes it so that when looking at charts and dashboards, and also looking at one environment regardless of the product feature that you're in, APM, infrastructure, RUM, the environment that is chosen in the first location when you sign into Splunk Observability Cloud needs to stay persistent all the way through.
There should be a solution to update OTeL agents from Splunk Observability Cloud itself.
Over time, the licensing cost has increased.
It was cheaper than the Splunk license.
Splunk is more expensive, and Cribl appears to be more affordable.
Splunk is a bit expensive since it charges based on the indexing rate of data.
It is expensive, especially when there are other vendors that offer something similar for much cheaper.
I can confidently say our availability improved by forty percent, and downtime was reduced by approximately seventy to eighty percent.
The data reduction and preprocessing capabilities make Cribl really unique.
Cribl has a feature called JSON Unroll or Unroll function that allows you to differentiate the events; each event will come ingested as a single log instead of piling it up with multiple events.
The Cribl UI is very simple and easy to use, particularly when working with data from various sources; it makes it very easy to create pipelines, add complex logic to those pipelines, and then gives you a preview of what your data looks like before applying that pipeline and what you get after.
Splunk provides advanced notifications of roadblocks in the application, which helps us to improve and avoid impacts during high-volume days.
For troubleshooting, we can detect problems in seconds, which is particularly helpful for digital teams.
It offers unified visibility for logs, metrics, and traces.
| Product | Mindshare (%) |
|---|---|
| Cribl | 1.2% |
| Splunk Observability Cloud | 2.3% |
| Other | 96.5% |


| Company Size | Count |
|---|---|
| Small Business | 41 |
| Midsize Enterprise | 7 |
| Large Enterprise | 34 |
| Company Size | Count |
|---|---|
| Small Business | 30 |
| Midsize Enterprise | 10 |
| Large Enterprise | 53 |
Cribl offers advanced data transformation and routing with features such as data reduction, plugin configurations, and log collection within a user-friendly framework supporting various deployments, significantly reducing data volumes and costs.
Cribl is designed to streamline data management, offering real-time data transformation and efficient log management. It supports seamless SIEM migration, enabling organizations to optimize costs associated with platforms like Splunk through data trimming. The capability to handle multiple data destinations and compression eases log control. With flexibility across on-prem, cloud, or hybrid environments, Cribl provides an adaptable interface that facilitates quick data model replication. While it significantly reduces data volumes, enhancing overall efficiency, there are areas for improvement, including compatibility with legacy systems and integration with enterprise products. Organizations can enhance their operational capabilities through certification opportunities and explore added functionalities tailored towards specific industry needs.
What are Cribl's most important features?Cribl sees extensive use in industries prioritizing efficient data management and cost optimization. Organizations leverage its capabilities to connect between different data sources, including cloud environments, improving both data handling and storage efficiency. Its customization options appeal to firms needing specific industry compliance and operational enhancements.
Splunk Observability Cloud offers sophisticated log searching, data integration, and customizable dashboards. With rapid deployment and ease of use, this cloud service enhances monitoring capabilities across IT infrastructures for comprehensive end-to-end visibility.
Focused on enhancing performance management and security, Splunk Observability Cloud supports environments through its data visualization and analysis tools. Users appreciate its robust application performance monitoring and troubleshooting insights. However, improvements in integrations, interface customization, scalability, and automation are needed. Users find value in its capabilities for infrastructure and network monitoring, as well as log analytics, albeit cost considerations and better documentation are desired. Enhancements in real-time monitoring and network protection are also noted as areas for development.
What are the key features?In industries, Splunk Observability Cloud is implemented for security management by analyzing logs from detection systems, offering real-time alerts and troubleshooting for cloud-native applications. It is leveraged for machine data analysis, improving infrastructure visibility and supporting network and application performance management efforts.
We monitor all Application Performance Monitoring (APM) and Observability reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.