Try our new research platform with insights from 80,000+ expert users

DX SaaS vs Splunk Enterprise Security comparison

 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

DX SaaS
Average Rating
6.6
Reviews Sentiment
6.7
Number of Reviews
3
Ranking in other categories
Application Performance Monitoring (APM) and Observability (71st), Digital Experience Monitoring (DEM) (17th)
Splunk Enterprise Security
Average Rating
8.4
Reviews Sentiment
7.3
Number of Reviews
369
Ranking in other categories
Log Management (2nd), Security Information and Event Management (SIEM) (1st), IT Operations Analytics (1st)
 

Mindshare comparison

While both are Application Lifecycle Management solutions, they serve different purposes. DX SaaS is designed for Digital Experience Monitoring (DEM) and holds a mindshare of 0.8%, up 0.4% compared to last year.
Splunk Enterprise Security, on the other hand, focuses on Security Information and Event Management (SIEM), holds 9.2% mindshare, down 11.2% since last year.
Digital Experience Monitoring (DEM) Market Share Distribution
ProductMarket Share (%)
DX SaaS0.8%
Nexthink22.8%
SysTrack13.0%
Other63.4%
Digital Experience Monitoring (DEM)
Security Information and Event Management (SIEM) Market Share Distribution
ProductMarket Share (%)
Splunk Enterprise Security9.2%
Wazuh10.2%
IBM Security QRadar7.0%
Other73.6%
Security Information and Event Management (SIEM)
 

Featured Reviews

JM
It's highly customizable but lacks many features of available in competing solutions
DX SaaS is a latecomer to the APM market. Some things that are straightforward in Dynatrace are complicated in DX. For example, upgrading the agents is a seamless process in Dynatrace, but it's a pain in DX SaaS. You should be able to upgrade in the Application Command Center. However, it is not working correctly. They upgrade the product every 15 to 30 days, and the process isn't seamless. It's like implementing the solution all over again. We monitor around 1,000-plus applications and have more than 100,000 agents, so we require a smooth upgrade process. It's nearly impossible to stay updated on the latest version. Upgrading the Dynatrace agent is smoother. You don't need to worry about it. If the agent is on the Dynatrace server, you only need to push it. After that, you will be notified to reboot the APM or CLM. That's it. It took us three years to deploy the agent on 1,000-plus applications across 40,000-plus servers. Now, they are saying they are ending support for 7.0.49, and we need to upgrade. The path to upgrading isn't straightforward. The first process is manual, and we can push it to different servers so it is visible. What's our configuration? Who is going to do the configuration? It's not typical or practical. I don't understand how product teams don't see that. That feature is not there. We hope they add this feature to the new product called DX Platform, which consists of net apps. All those network monitoring tools will be combined into DX Platform. All the monitoring functionality is moved to DX Platform. You can't see a trend of your metrics grouped according to the last month, six months, one year, etc. The resolution is not there. I want granular visibility into data captured in the last 15 seconds. Those are essential features. I am not saying that DX lacks solid features, but they need to consider it. Some core functionality of the product is missing. We have around 50-plus requests to add previously available features in the on-premise version. That is one reason application teams are reluctant to go to DX SaaS. We are struggling to make them understand and trying to find alternatives for the existing features. We've had many discussions with the product team, telling them we need this functionality. However, they tell us it's not on their product roadmap. They are gradually adding other features, but we need our requirements to be a priority. You cannot say you will try to add those requested features that aren't on your product roadmap. There is always a catch in the product. We use around 10 tenants in production and six in the test run. First of all, there is nothing in the pane. If we are trying to see the data from an application, how do we know which tenant and application are reporting? There was a feature called Enterprise Team Center, but that functionality has been removed. All the applications are connected to the manager, which is connected to ETC. If you go to ETC, you can find the server and see your data, but that functionality was not there. Every product should have a management feature, but that is missing, and they are saying that it is not there in the roadmap. It is a basic requirement. You need to understand that. That is not there, manager, and they are saying that is not there in the roadmap as well. They have created a new tenant page temporarily. It is not there currently. It is not a required thing. There is a feature called Domain, but that concept is gone. We've struggled a lot, and what they provided in the initial migration stage is no longer working. We were delayed for two months because we didn't give them the correct input. They don't know their product. We tell them there is a problem, and they say they're fixing it. Are we their Guinea pig? You cannot treat your customers like this.
Kyle Vernham - PeerSpot reviewer
Built-in searches and unified data access streamline alert investigation and boosts analyst efficiency
The two features I appreciate the most in Splunk Enterprise Security are the built-in searches, which have been very easy for us to get started with right out of the box, and the fact that it accesses all of our other systems. You can access it as a pane of glass rather than having to search individually. We also have the option to compare our analysts from our service to service. Splunk Enterprise Security helps our SOC team prioritize and investigate high-fidelity alerts more effectively by providing a more in-depth look and the ability to access a lot more of our data. Instead of jumping from several segmented systems, it allows us to have everything brought together in one place. For example, you have to move from our purview to our build system and to Splunk Enterprise Security, and it enables us to streamline that process. The built-in features of Splunk Enterprise Security, which we recently procured, have given us a good starting point and demonstrated the value of the product, providing an easy way to sell it to our company. The ease of getting everything into our purview helps us, and it serves as a good start for the investigation part in one location rather than what we usually have, which is jumping from system to system to system. Splunk Enterprise Security plays a role in our company's strategy to combat insider threats and advanced persistent threats by currently being in its technical test phase. We are still rolling it out, and it should help us find any insider threats based on information that our policy states should not be present in our system. Splunk Enterprise Security's risk-based alerting (RBA) has impacted our alert volume and analyst productivity because we've got many different systems feeding into it. However, it has helped to make it easier for our analysts to go through a set of events rather than 100 alerts. RBA allows us to streamline the process and customize it for our analysts. When it comes to leveraging Splunk Enterprise Security's dashboards and visualizations to communicate security posture to executives, it's pretty straightforward for any type of information. The visualization is easy to understand, but I haven't had any direct conversations with our executives.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"It supports numerous platforms."
"DX allows you to customize and gives you a high degree of control."
"Actionable insight is the most valuable feature."
"The most valuable features are how stable and easy to use Splunk is."
"What is nice about the solution is that it makes it easy to build the queries, search for the events and then do analysis."
"Splunk Enterprise Security is probably one of the first products that actually could handle all the ingest and do all the correlation without crumbling under its own weight."
"One key advantage of Splunk over competitors like IBM QRadar is its superior device integration capabilities."
"The product provides visibility and enables us to correlate data and generate alerts."
"The client site login is pretty extensible and probably cost-effective."
"The dashboard is amazing. Out-of-the-box dashboard is very good. It is very user-friendly."
"Three features stand out for me: the SDK for writing Python, the customizable and adaptable diagnostic dashboard, and the optimizer for collecting data."
 

Cons

"The ability to scale presents a challenge as the cost of handling vast amounts of data in the cloud must be taken into account."
"Old user interface and dashboards could be improved."
"DX SaaS is a latecomer to the APM market. Some things that are straightforward in Dynatrace are complicated in DX. For example, upgrading the agents is a seamless process in Dynatrace, but it's a pain in DX SaaS. You should be able to upgrade in the Application Command Center. However, it is not working correctly."
"We'd like Splunk to reduce false positives."
"The on-premise integration with SOAR could be more simple; the cloud version integrates with SOAR very easily, but the on-premise SOAR and on-premise Splunk Enterprise Security are really not that easy, so I would appreciate if that could be improved."
"The prices are complicated as we operate in a small third-world country."
"We haven't saved any money with Splunk Enterprise Security. Instead, we have spent excess of the budget on this with unexpected costs."
"It would be good if the solution had some kind of copilot to automate or help write correlation searches."
"Having analysts put their notes directly within the investigation feature in the incident review would be beneficial."
"At Splunk .conf24, I saw a demo for Splunk Enterprise Security 8. All the things that they have done in Splunk Enterprise Security 8 are what it can be better at."
"Splunk's high cost, despite its recognition in our region, prevents many organizations from adopting Splunk Enterprise Security, suggesting there's room for improvement in their pricing strategy."
 

Pricing and Cost Advice

"Our monthly cost for DX SaaS is approximately $5 per user, which I considered affordable."
"Be upfront about your needs and expectations. Splunk is great to work with."
"The price of Splunk is reasonable."
"Our customers often complain that the price of Splunk is too high."
"Free Splunk license for PoCs on personal machines and the ability to scale the PoC to an enterprise level app."
"I think that most of the monitoring solutions are expensive."
"Pricing can be a limiting factor. You have to continuously tune what you are bringing in and make sure what you bring in is of value."
"It can be expensive, especially the licensing costs. However, there is added value in what it can do, not just log aggregation."
"It's a little bit expensive for a small to medium enterprise."
report
Use our free recommendation engine to learn which Digital Experience Monitoring (DEM) solutions are best for your needs.
869,952 professionals have used our research since 2012.
 

Comparison Review

VS
Feb 26, 2015
HP ArcSight vs. IBM QRadar vs. ​McAfee Nitro vs. Splunk vs. RSA Security vs. LogRhythm
We at Infosecnirvana.com have done several posts on SIEM. After the Dummies Guide on SIEM, we are following it up with a SIEM Product Comparison – 101 deck. So, here it is for your viewing pleasure. Let me know what you think by posting your comments below. The key products compared here are…
 

Top Industries

By visitors reading reviews
Computer Software Company
14%
Outsourcing Company
14%
Legal Firm
12%
Financial Services Firm
8%
Computer Software Company
14%
Financial Services Firm
13%
Manufacturing Company
8%
Government
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
No data available
By reviewers
Company SizeCount
Small Business110
Midsize Enterprise50
Large Enterprise257
 

Questions from the Community

Ask a question
Earn 20 points
What SOC product do you recommend?
For tools I’d recommend: -SIEM- LogRhythm -SOAR- Palo Alto XSOAR Doing commercial w/o both (or at least an XDR) is asking to miss details that are critical, and ending up a statistic. Also, rememb...
What is a better choice, Splunk or Azure Sentinel?
It would really depend on (1) which logs you need to ingest and (2) what are your use cases Splunk is easy for ingestion of anything, but the charge per GB/Day Indexed and it gets expensive as log ...
How does Splunk compare with Azure Monitor?
Splunk handles a high amount of data very well. We use Splunk to capture information and as an aggregator for monitoring information from different sources. Splunk is very good at alerting us if we...
 

Also Known As

CA DXI, CA Digital Experience Insights
No data available
 

Overview

 

Sample Customers

CNN
Splunk has more than 7,000 customers spread across over 90 countries. These customers include Telenor, UniCredit, ideeli, McKenney's, Tesco, and SurveyMonkey.
Find out what your peers are saying about DX SaaS vs. Splunk Enterprise Security and other solutions. Updated: May 2023.
869,952 professionals have used our research since 2012.