Try our new research platform with insights from 80,000+ expert users

Splunk Enterprise Security vs eG Enterprise comparison

 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

eG Enterprise
Average Rating
8.2
Reviews Sentiment
7.7
Number of Reviews
21
Ranking in other categories
Application Performance Monitoring (APM) and Observability (35th), Network Monitoring Software (51st), IT Infrastructure Monitoring (43rd)
Splunk Enterprise Security
Average Rating
8.4
Reviews Sentiment
7.4
Number of Reviews
366
Ranking in other categories
Log Management (2nd), Security Information and Event Management (SIEM) (1st), IT Operations Analytics (1st)
 

Mindshare comparison

While both are Application Lifecycle Management solutions, they serve different purposes. eG Enterprise is designed for Application Performance Monitoring (APM) and Observability and holds a mindshare of 0.4%, up 0.3% compared to last year.
Splunk Enterprise Security, on the other hand, focuses on Security Information and Event Management (SIEM), holds 9.3% mindshare, down 11.6% since last year.
Application Performance Monitoring (APM) and Observability Market Share Distribution
ProductMarket Share (%)
eG Enterprise0.4%
Dynatrace8.8%
Datadog7.2%
Other83.6%
Application Performance Monitoring (APM) and Observability
Security Information and Event Management (SIEM) Market Share Distribution
ProductMarket Share (%)
Splunk Enterprise Security9.3%
Wazuh10.9%
IBM Security QRadar7.2%
Other72.6%
Security Information and Event Management (SIEM)
 

Featured Reviews

Jose Ramon Crespo - PeerSpot reviewer
Utilize artificial intelligence for faster issue response and seamless ITSM integration
The data gathering capabilities and the automation, which utilizes artificial intelligence, are the most valuable features. These capabilities help us gather more information and analyze it faster, leading to better responses to issues. The tool is also excellent at integrating with ITSM services, providing a seamless alerting system for our customers.
Kyle Vernham - PeerSpot reviewer
Built-in searches and unified data access streamline alert investigation and boosts analyst efficiency
The two features I appreciate the most in Splunk Enterprise Security are the built-in searches, which have been very easy for us to get started with right out of the box, and the fact that it accesses all of our other systems. You can access it as a pane of glass rather than having to search individually. We also have the option to compare our analysts from our service to service. Splunk Enterprise Security helps our SOC team prioritize and investigate high-fidelity alerts more effectively by providing a more in-depth look and the ability to access a lot more of our data. Instead of jumping from several segmented systems, it allows us to have everything brought together in one place. For example, you have to move from our purview to our build system and to Splunk Enterprise Security, and it enables us to streamline that process. The built-in features of Splunk Enterprise Security, which we recently procured, have given us a good starting point and demonstrated the value of the product, providing an easy way to sell it to our company. The ease of getting everything into our purview helps us, and it serves as a good start for the investigation part in one location rather than what we usually have, which is jumping from system to system to system. Splunk Enterprise Security plays a role in our company's strategy to combat insider threats and advanced persistent threats by currently being in its technical test phase. We are still rolling it out, and it should help us find any insider threats based on information that our policy states should not be present in our system. Splunk Enterprise Security's risk-based alerting (RBA) has impacted our alert volume and analyst productivity because we've got many different systems feeding into it. However, it has helped to make it easier for our analysts to go through a set of events rather than 100 alerts. RBA allows us to streamline the process and customize it for our analysts. When it comes to leveraging Splunk Enterprise Security's dashboards and visualizations to communicate security posture to executives, it's pretty straightforward for any type of information. The visualization is easy to understand, but I haven't had any direct conversations with our executives.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"What I like about eG Enterprise is that it's easy to use. It's a simple product. You can get up to seventy-five to eighty percent of the required information based on real user experience and diagnostics."
"The ability to see what the end user response is, so I can get a better understanding of what the end user is seeing when they connect to the Citrix servers."
"It gives good insight into inside of what's going on with Exchange."
"Its ability to monitor failures and to restart a Windows service when it fails."
"The auto-configuration or auto-Thresholding is very important because it saves a phenomenal amount of labor and setup costs and time."
"User session details"
"eG Enterprise has a single pane of glass for observability and monitoring."
"The product is simple to use."
"My security ops team takes around 30 minutes to one hour to remediate security incidents with Splunk Enterprise Security compared to a previous solution."
"The solution's most valuable feature is the criticality of alerts."
"Its integration is most valuable. Its UI is also pretty much easy."
"Splunk allows us to find insights that we were not able to with traditional BI tools using ETL​. It allows us to dig into raw events."
"Speeds up root cause analysis and can help identify issues that your organization never realized were occurring."
"The benefits include the easy integration with other Splunk tools including Splunk UEBA, Splunk ITSI, and Splunk Core. The ease of integration and the organization's experience and familiarity with searching and passing logs through Splunk are the main benefits."
"It is quite extensible. It is a platform that we can build our use instead of each case instead of each case being limited or restricted to each capability. This is probably the best feature."
"The features I find most valuable in Splunk Enterprise Security are Incident Review, Security Essentials, Asset and Identity Management, and Machine Learning Toolkit."
 

Cons

"The interface could be improved as it is not real intuitive. It is not user-friendly."
"There should be more price flexibility to adapt to different kinds of customers. For small and medium businesses, eG Enterprise is usually too expensive."
"Dashboards are difficult to create, and not so useful."
"In terms of areas for improvement in eG Enterprise, we are now moving most of our services to the OpenShift platform, and we need a way to monitor even containerized services or any service deployed on OpenShift, but that feature is still not available in eG Enterprise, so it's not good enough for us."
"The solution should improve on the security side and include some more API integrations into wider application platforms."
"Back-end configuration is not easy to implement."
"The solution needs to enhance the management dashboards."
"I can understand why they designed the user interface (UI) the way they did, but sometimes in the management of the eG Manager, it can be a bit clunky."
"Many of my clients want to get better at Splunk, but they're afraid of using the tool because they feel it's too complex for them."
"Some additional features that should be included in the next release of Splunk Enterprise Security are an integrated Attack Range, not as a separate solution, providing a way to test the rules in the production environment."
"Splunk ES could have more pre-built integrations and rules. The detection is fairly accurate, but it depends on the rules you create. Splunk's out-of-the-box configuration isn't that useful."
"The setup time is quite long."
"The system can be intimidating, and sometimes the concepts conveyed in the documentation require adjustment."
"The product is relatively expensive."
"Writing queries is a bit complicated sometimes."
"Splunk can improve regex/asset analysis as we do not want to crawl until it is done."
 

Pricing and Cost Advice

"They are aligned with other enterprise solutions."
"If using eG for virtual desktops, carefully calculate whether per named user, per concurrent user, or per server"
"They gave us a good price, when they were found out we were looking at other products because their price was very high. We were looking at another solution, then we came back to them was because they brought the price down. We selected them for three years."
"The product is very cheap."
"It is not expensive."
"There are two licensing options: Perpetual and SaaS-based. The main offering, in terms of what eG prefers to offer, is the subscription-based rather than the Perpetual License. The price could be cheaper."
"eG Enterprise is much cheaper than the other products it competes with."
"You may get some monitoring products with certain licensing you may own. Some of these can take ages to configure and setup, along with needing a license to drive the software."
"The licensing model can be expensive, but the value it provides is significant."
"The price is comparable."
"I am not personally involved with the pricing of the solution."
"I remember Splunk being relatively affordable. Kibana was more reasonable, but you get more with Splunk. If I was suggesting something, I would probably suggest Splunk because it is better to pay a little bit more and get a lot more."
"The Splunk licensing is high."
"Splunk is a bit pricier, but the benefits and ROI are huge."
"Splunk can be an expensive solution. It all depends on how we configure the alerts and the events from the endpoints. You can save some money if you do that correctly. If not, it becomes an expensive solution."
"Our customers often complain that the price of Splunk is too high."
report
Use our free recommendation engine to learn which Application Performance Monitoring (APM) and Observability solutions are best for your needs.
868,275 professionals have used our research since 2012.
 

Comparison Review

VS
Feb 26, 2015
HP ArcSight vs. IBM QRadar vs. ​McAfee Nitro vs. Splunk vs. RSA Security vs. LogRhythm
We at Infosecnirvana.com have done several posts on SIEM. After the Dummies Guide on SIEM, we are following it up with a SIEM Product Comparison – 101 deck. So, here it is for your viewing pleasure. Let me know what you think by posting your comments below. The key products compared here are…
 

Top Industries

By visitors reading reviews
Computer Software Company
16%
Retailer
13%
Government
11%
Financial Services Firm
10%
Computer Software Company
14%
Financial Services Firm
14%
Manufacturing Company
8%
Government
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business9
Midsize Enterprise1
Large Enterprise10
By reviewers
Company SizeCount
Small Business109
Midsize Enterprise49
Large Enterprise255
 

Questions from the Community

Any advice about APM solutions?
Could you please share your requirements ? There are a lot tools can be added to the list. I spent almost 6 months to test and check many tools then I select eG enterprise.
Do you recommend eG Enterprise? Why or why not?
I feel that eG Enterprise is one of the top APM tools available on the market. Out of the solutions I have tried, it is the best for monitoring, diagnosis, analytics, and reporting of key IT servic...
What do you like most about eG Enterprise?
eG Enterprise has a single pane of glass for observability and monitoring.
What SOC product do you recommend?
For tools I’d recommend: -SIEM- LogRhythm -SOAR- Palo Alto XSOAR Doing commercial w/o both (or at least an XDR) is asking to miss details that are critical, and ending up a statistic. Also, rememb...
What is a better choice, Splunk or Azure Sentinel?
It would really depend on (1) which logs you need to ingest and (2) what are your use cases Splunk is easy for ingestion of anything, but the charge per GB/Day Indexed and it gets expensive as log ...
How does Splunk compare with Azure Monitor?
Splunk handles a high amount of data very well. We use Splunk to capture information and as an aggregator for monitoring information from different sources. Splunk is very good at alerting us if we...
 

Overview

 

Sample Customers

20th Century Fox, Allscripts, Anthem Blue Cross and Blue Shield, Aviva, AXA, Biogen, Cox Communications, Denver Health, eBay, JP Morgan Chase, PayPal, Southern California Edison, Samsung, and many more.
Splunk has more than 7,000 customers spread across over 90 countries. These customers include Telenor, UniCredit, ideeli, McKenney's, Tesco, and SurveyMonkey.
Find out what your peers are saying about Splunk Enterprise Security vs. eG Enterprise and other solutions. Updated: May 2023.
868,275 professionals have used our research since 2012.