Try our new research platform with insights from 80,000+ expert users

CrowdStrike Observability vs Splunk Enterprise Security comparison

 

Comparison Buyer's Guide

Executive SummaryUpdated on Jul 13, 2025

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

CrowdStrike Observability
Ranking in Log Management
42nd
Average Rating
8.0
Reviews Sentiment
4.0
Number of Reviews
4
Ranking in other categories
No ranking in other categories
Splunk Enterprise Security
Ranking in Log Management
2nd
Average Rating
8.4
Reviews Sentiment
7.4
Number of Reviews
326
Ranking in other categories
Security Information and Event Management (SIEM) (1st), IT Operations Analytics (1st)
 

Mindshare comparison

As of August 2025, in the Log Management category, the mindshare of CrowdStrike Observability is 0.5%, down from 0.6% compared to the previous year. The mindshare of Splunk Enterprise Security is 7.4%, down from 9.6% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Log Management
 

Featured Reviews

ManelAlvarez - PeerSpot reviewer
Protection improves through superior global visibility and robust cloud integration
CrowdStrike Observability is especially useful when using a multi-cloud environment. Although it is expensive, the protection level it provides justifies the price. For users on Google Cloud, I prefer using Google's GTI technology. Overall, I would rate CrowdStrike Observability as nine out of ten. I rate the overall solution as nine.
ROBERT-CHRISTIAN - PeerSpot reviewer
Has many predefined correlation rules and is brilliant for investigation and log analysis
It is very complicated to write your own correlation rules without the help of Splunk support. What Splunk could do better is to create an API to the standard SIEM tools, such as Microsoft Sentinel. The idea would be to make it less painful. In ELK Stack, Kibana is the query language with which you can search log files. I believe Splunk has also a query language in which they search their log files, but once you have identified the log file that you want to use for further security correlation, you want to very quickly transport that into your SIEM tool, such as Microsoft Sentinel. That is something that Splunk could make a little bit less painful because it is a lot of effort to find that log file and forward it. An API with Microsoft Sentinel or a similar SIEM tool would be a good idea.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"I find the most effective feature of CrowdStrike Observability to be its cloud vision and attack surface vision, which enhance network traffic analysis."
"The price is worth it."
"The intelligence database provided by CrowdStrike is very impressive."
"The log aggregation and correlation of data are notable features that enhance our operations."
"The intelligence database provided by CrowdStrike is very impressive."
"Splunk incorporates a lot of elements that help to reduce security risks. For it to reach certain compliance, we need to have some security insight. Splunk is a very good SIEM, it’s a top solution, but the best feature is its cost of visibility. We have all the most important features to detect vulnerabilities or risks."
"It's very flexible. If you look from the cloud implementation it is there. Reports are made quickly. Unlike other tools, it caters to all kinds of technical information on the front very easily. There's no need to put in any technical information. You can pull on the reports very easily, take action, and notify stakeholders."
"It's the completeness of the solution that we like the most."
"Splunk Enterprise Security is amazing."
"It is very scalable."
"I am enjoying our implementation of risk-based alerting. That has helped very much with cutting out a lot of the noise that we have. It has reduced our alert volume significantly. There is about an 80% reduction."
"The fact that Splunk is a platform and not just a SIEM solution is a key benefit."
"The initial deployment was straightforward."
 

Cons

"The customer service is not satisfactory for me. The support is only available in English, and my users in LATAM regions such as Peru and Colombia require local language support, which is not currently provided."
"Integration with Huawei should be more straightforward."
"For reporting or log management, having a longer duration for backup without needing to purchase a paid subscription would be beneficial. Currently, there is a default ninety-day backup period."
"Integration with Huawei should be more straightforward."
"For reporting or log management, having a longer duration for backup without needing to purchase a paid subscription would be beneficial."
"Their technical support sucks."
"Splunk's ability to analyze malicious activities scores an 8 out of 10, but there's room for improvement. By analyzing emerging patterns, Splunk could identify and predict potential threats more effectively."
"It would be good if the solution had some kind of copilot to automate or help write correlation searches."
"The documentation and training resources available for knowledge and training can be expanded. We need to learn more about Splunk Enterprise Security and new security attacks."
"Splunk is query-based, which is not the case with most cybersecurity tools. It is based on search queries and can be difficult to use. It would be good if they can make it easier to understand how to create search queries. They can improve the knowledge base for better understanding. To create your dashboard, you need to have a search query. We have multiple firewalls in our company, and we need a dashboard for them. It would be helpful if a default firewall dashboard is included in Splunk to make monitoring easier. If a dashboard is available for a security device, the operation part will be more efficient. We won't have to follow a manual process for this."
"From the commercial point of view, they have to bring down their costs."
"Improving the infrastructure behind Splunk Enterprise Security is vital—enhanced cores, CPUs, and memory should be prioritized to support better processing power. When we execute heavy, resource-intensive queries over long periods, the performance dips."
"There is improvement needed when importing from some types of data sources."
 

Pricing and Cost Advice

Information not available
"The variables and the flexibility that Splunk provides are helpful, especially in a hybrid and multi-cloud environment."
"The pricing modules could be improved."
"Splunk Enterprise becomes extremely expensive after the 20GB/month license."
"It is pretty straightforward and based on the sizing. If I compare it with other competitors, it makes sense."
"We have had a reduction in the time it takes to resolve issues and correlate what has failed."
"This solution is costly. Splunk is obviously a great product, but you should only choose this product if you need all the features provided. Otherwise, if you don't need all the features to meet your requirements, there are probably other products that will be more cost-effective. It's cost versus the functionality requirement."
"Further reductions would be fantastic, and I believe that more and more people would flock to it."
"Splunk is really expensive compared to all the other tools on the market, including Microsoft Sentinel."
report
Use our free recommendation engine to learn which Log Management solutions are best for your needs.
864,574 professionals have used our research since 2012.
 

Comparison Review

VS
Feb 26, 2015
HP ArcSight vs. IBM QRadar vs. ​McAfee Nitro vs. Splunk vs. RSA Security vs. LogRhythm
We at Infosecnirvana.com have done several posts on SIEM. After the Dummies Guide on SIEM, we are following it up with a SIEM Product Comparison – 101 deck. So, here it is for your viewing pleasure. Let me know what you think by posting your comments below. The key products compared here are…
 

Top Industries

By visitors reading reviews
Computer Software Company
15%
Financial Services Firm
14%
Manufacturing Company
8%
Healthcare Company
8%
Computer Software Company
14%
Financial Services Firm
14%
Manufacturing Company
8%
Government
8%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
No data available
 

Questions from the Community

What needs improvement with CrowdStrike Observability?
The areas of CrowdStrike Observability that have room for improvement include the approach towards customer issues, where resolution takes time. When raising a ticket for a customer, it takes time ...
What is your primary use case for CrowdStrike Observability?
The typical use case for CrowdStrike Observability is for customers who are looking for the best protection for their endpoints, data, and overall EDR and XDR solution. CrowdStrike Observability wo...
What advice do you have for others considering CrowdStrike Observability?
The complete portfolio of CrowdStrike Observability includes multiple solutions for various customers. I am currently on medical leave due to an accident that required surgery. My previous position...
What SOC product do you recommend?
For tools I’d recommend: -SIEM- LogRhythm -SOAR- Palo Alto XSOAR Doing commercial w/o both (or at least an XDR) is asking to miss details that are critical, and ending up a statistic. Also, rememb...
What is a better choice, Splunk or Azure Sentinel?
It would really depend on (1) which logs you need to ingest and (2) what are your use cases Splunk is easy for ingestion of anything, but the charge per GB/Day Indexed and it gets expensive as log ...
How does Splunk compare with Azure Monitor?
Splunk handles a high amount of data very well. We use Splunk to capture information and as an aggregator for monitoring information from different sources. Splunk is very good at alerting us if we...
 

Overview

 

Sample Customers

Information Not Available
Splunk has more than 7,000 customers spread across over 90 countries. These customers include Telenor, UniCredit, ideeli, McKenney's, Tesco, and SurveyMonkey.
Find out what your peers are saying about CrowdStrike Observability vs. Splunk Enterprise Security and other solutions. Updated: July 2025.
864,574 professionals have used our research since 2012.