Try our new research platform with insights from 80,000+ expert users

DX SaaS vs Splunk Enterprise Security comparison

 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

DX SaaS
Average Rating
6.6
Reviews Sentiment
6.7
Number of Reviews
3
Ranking in other categories
Application Performance Monitoring (APM) and Observability (69th), Digital Experience Monitoring (DEM) (17th)
Splunk Enterprise Security
Average Rating
8.4
Reviews Sentiment
7.6
Number of Reviews
315
Ranking in other categories
Log Management (2nd), Security Information and Event Management (SIEM) (1st), IT Operations Analytics (1st)
 

Mindshare comparison

While both are Application Lifecycle Management solutions, they serve different purposes. DX SaaS is designed for Digital Experience Monitoring (DEM) and holds a mindshare of 0.6%, up 0.5% compared to last year.
Splunk Enterprise Security, on the other hand, focuses on Security Information and Event Management (SIEM), holds 9.4% mindshare, down 12.1% since last year.
Digital Experience Monitoring (DEM)
Security Information and Event Management (SIEM)
 

Featured Reviews

JM
It's highly customizable but lacks many features of available in competing solutions
DX SaaS is a latecomer to the APM market. Some things that are straightforward in Dynatrace are complicated in DX. For example, upgrading the agents is a seamless process in Dynatrace, but it's a pain in DX SaaS. You should be able to upgrade in the Application Command Center. However, it is not working correctly. They upgrade the product every 15 to 30 days, and the process isn't seamless. It's like implementing the solution all over again. We monitor around 1,000-plus applications and have more than 100,000 agents, so we require a smooth upgrade process. It's nearly impossible to stay updated on the latest version. Upgrading the Dynatrace agent is smoother. You don't need to worry about it. If the agent is on the Dynatrace server, you only need to push it. After that, you will be notified to reboot the APM or CLM. That's it. It took us three years to deploy the agent on 1,000-plus applications across 40,000-plus servers. Now, they are saying they are ending support for 7.0.49, and we need to upgrade. The path to upgrading isn't straightforward. The first process is manual, and we can push it to different servers so it is visible. What's our configuration? Who is going to do the configuration? It's not typical or practical. I don't understand how product teams don't see that. That feature is not there. We hope they add this feature to the new product called DX Platform, which consists of net apps. All those network monitoring tools will be combined into DX Platform. All the monitoring functionality is moved to DX Platform. You can't see a trend of your metrics grouped according to the last month, six months, one year, etc. The resolution is not there. I want granular visibility into data captured in the last 15 seconds. Those are essential features. I am not saying that DX lacks solid features, but they need to consider it. Some core functionality of the product is missing. We have around 50-plus requests to add previously available features in the on-premise version. That is one reason application teams are reluctant to go to DX SaaS. We are struggling to make them understand and trying to find alternatives for the existing features. We've had many discussions with the product team, telling them we need this functionality. However, they tell us it's not on their product roadmap. They are gradually adding other features, but we need our requirements to be a priority. You cannot say you will try to add those requested features that aren't on your product roadmap. There is always a catch in the product. We use around 10 tenants in production and six in the test run. First of all, there is nothing in the pane. If we are trying to see the data from an application, how do we know which tenant and application are reporting? There was a feature called Enterprise Team Center, but that functionality has been removed. All the applications are connected to the manager, which is connected to ETC. If you go to ETC, you can find the server and see your data, but that functionality was not there. Every product should have a management feature, but that is missing, and they are saying that it is not there in the roadmap. It is a basic requirement. You need to understand that. That is not there, manager, and they are saying that is not there in the roadmap as well. They have created a new tenant page temporarily. It is not there currently. It is not a required thing. There is a feature called Domain, but that concept is gone. We've struggled a lot, and what they provided in the initial migration stage is no longer working. We were delayed for two months because we didn't give them the correct input. They don't know their product. We tell them there is a problem, and they say they're fixing it. Are we their Guinea pig? You cannot treat your customers like this.
ROBERT-CHRISTIAN - PeerSpot reviewer
Has many predefined correlation rules and is brilliant for investigation and log analysis
It is very complicated to write your own correlation rules without the help of Splunk support. What Splunk could do better is to create an API to the standard SIEM tools, such as Microsoft Sentinel. The idea would be to make it less painful. In ELK Stack, Kibana is the query language with which you can search log files. I believe Splunk has also a query language in which they search their log files, but once you have identified the log file that you want to use for further security correlation, you want to very quickly transport that into your SIEM tool, such as Microsoft Sentinel. That is something that Splunk could make a little bit less painful because it is a lot of effort to find that log file and forward it. An API with Microsoft Sentinel or a similar SIEM tool would be a good idea.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"It supports numerous platforms."
"Actionable insight is the most valuable feature."
"DX allows you to customize and gives you a high degree of control."
"The dashboard is amazing. Out-of-the-box dashboard is very good. It is very user-friendly."
"The most valuable feature is the custom dashboard feature."
"It has quite extensive support in terms of integration. If you want to do anything, there are tools for that."
"The correlation search functions that generate all the notables are valuable. That can get pretty complicated, and it handles that pretty well."
"Splunk Enterprise Security is able to process a huge amount of data without any issues."
"Being able to track impossible travel logins and things of that nature is valuable. We can track user logins from various IPs, various countries, and at various times to see if everything adds up."
"Splunk Enterprise Security's most valuable features are its stability and the robust Splunk Search Processing Language, allowing extensive customization and analysis capabilities."
"Splunk provides immediate visibility into key business metrics and new business insights that deliver immediate value."
 

Cons

"Old user interface and dashboards could be improved."
"DX SaaS is a latecomer to the APM market. Some things that are straightforward in Dynatrace are complicated in DX. For example, upgrading the agents is a seamless process in Dynatrace, but it's a pain in DX SaaS. You should be able to upgrade in the Application Command Center. However, it is not working correctly."
"The ability to scale presents a challenge as the cost of handling vast amounts of data in the cloud must be taken into account."
"The GUI could be improved to include some of the capabilities that other BI solutions have. The layout is a little restrictive where you can’t resize all the panels to exactly how you would like them without tweaking some XML code."
"Make it easier to include roles and user controls, as it is horrible now."
"I didn't face any major issues with Splunk Enterprise Security. There were only one or two issues related to the user account, but nothing major."
"Splunk could add more ways to manage archiving and storage. There isn't a web interface. You can do this on the SaaS version, but the on-premise platform doesn't have this option. It has other things but no option for remote NAS. I would like to have a personal web interface where I can specify how long logs should be stored. To have this readily available on the web, you need to adjust some settings on the backend. That is tricky."
"The product's price may be an area of concern where improvements are required."
"The support that is included with the standard licensing fee is very bad."
"The incident response dashboard could be more user-friendly."
"​Not even Splunk's support guy, who came to our firm, could help with defining proper role management.​"
 

Pricing and Cost Advice

"Our monthly cost for DX SaaS is approximately $5 per user, which I considered affordable."
"Splunk differs from other SIEM solutions by using a gigabyte-based pricing model, rather than the agent-based licenses common with its competitors."
"Splunk Enterprise Security is not at all cost-friendly to be deployed in very small enterprises like start-ups."
"It is economical than other solutions."
"Splunk is really expensive compared to all the other tools on the market, including Microsoft Sentinel."
"As a team, we prefer the old pricing model with a perpetual license. We are still evaluating the whole subscription-based model."
"You will eat up whatever you purchase quickly. The level of insights that Splunk empowers is addictive."
"I think that most of the log analytics solutions are expensive and I'm not sure if it's worth it."
"Splunk is not a cheap solution and the license is billed annually."
report
Use our free recommendation engine to learn which Digital Experience Monitoring (DEM) solutions are best for your needs.
861,034 professionals have used our research since 2012.
 

Comparison Review

VS
Feb 26, 2015
HP ArcSight vs. IBM QRadar vs. ​McAfee Nitro vs. Splunk vs. RSA Security vs. LogRhythm
We at Infosecnirvana.com have done several posts on SIEM. After the Dummies Guide on SIEM, we are following it up with a SIEM Product Comparison – 101 deck. So, here it is for your viewing pleasure. Let me know what you think by posting your comments below. The key products compared here are…
 

Top Industries

By visitors reading reviews
Financial Services Firm
23%
Computer Software Company
16%
Real Estate/Law Firm
15%
Manufacturing Company
7%
Financial Services Firm
14%
Computer Software Company
14%
Manufacturing Company
8%
Government
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
No data available
 

Questions from the Community

Ask a question
Earn 20 points
What SOC product do you recommend?
For tools I’d recommend: -SIEM- LogRhythm -SOAR- Palo Alto XSOAR Doing commercial w/o both (or at least an XDR) is asking to miss details that are critical, and ending up a statistic. Also, rememb...
What is a better choice, Splunk or Azure Sentinel?
It would really depend on (1) which logs you need to ingest and (2) what are your use cases Splunk is easy for ingestion of anything, but the charge per GB/Day Indexed and it gets expensive as log ...
How does Splunk compare with Azure Monitor?
Splunk handles a high amount of data very well. We use Splunk to capture information and as an aggregator for monitoring information from different sources. Splunk is very good at alerting us if we...
 

Also Known As

CA DXI, CA Digital Experience Insights
No data available
 

Overview

 

Sample Customers

CNN
Splunk has more than 7,000 customers spread across over 90 countries. These customers include Telenor, UniCredit, ideeli, McKenney's, Tesco, and SurveyMonkey.
Find out what your peers are saying about DX SaaS vs. Splunk Enterprise Security and other solutions. Updated: May 2023.
861,034 professionals have used our research since 2012.