Elastic Search vs Splunk Enterprise Security comparison

Cancel
You must select at least 2 products to compare!
Elastic Logo
2,186 views|735 comparisons
98% willing to recommend
Splunk Logo
25,711 views|20,955 comparisons
92% willing to recommend
Comparison Buyer's Guide
Executive Summary

We performed a comparison between Elastic Search and Splunk Enterprise Security based on real PeerSpot user reviews.

Find out what your peers are saying about Elastic, IBM, OpenText and others in Indexing and Search.
To learn more, read our detailed Indexing and Search Report (Updated: March 2024).
769,065 professionals have used our research since 2012.
Q&A Highlights
Question: What are the advantages of ELK over Splunk?
Answer: First of all, we need to understand what those two softwares are; Splunk is a finished SIEM that is mainly used to analyze data, such as logs, net flows, etc. Splunk comes in different flavors, below I will include a link of all the products they have. https://www.splunk.com/en_us/software.html Some of them can be even downloaded or you can try them in the cloud, below I will give you a link of Splunk enterprise, in the link you can see that you can download it, as a trial. https://www.splunk.com/en_us/software/splunk-enterprise/features.html ELK can be used for the requirements that you included, such as log analysis, the difference is that you will have to write the normalizers (this is a configuration file based on regex that reads the raw log and devices the log in small pieces), you will have to write the configuration file of the different widgets in the dashboard, alerts will have to be also written, etc. Elastic.co has already made an app that works as a SIEM, from all the products I think this will be the one that will make the most sense, as a log storage/analyzer, below is the link and you can try it as a cloud deployment. https://www.elastic.co/products/siem Also, this is a more complete list of all the features that are included in the enterprise version, here you can check them out and decide if this is something that will work for you. https://www.elastic.co/subscriptions Those two softwares are very good, but it will be better if you give them a try by yourself and try to compare them to see which one is the best for your network environment.
Featured Review
Quotes From Members
We asked business professionals to review the solutions they use.
Here are some excerpts of what they said:
Pros
"The most valuable features are the detection and correlation features.""The UI is very nice, and performance wise it's quite good too.""Data indexing of historical data is the most beneficial feature of the product.""Logsign provides us with the capability to execute multiple queries according to our requirements. The indexing is very high, making it effective for storing and retrieving logs. The real-time analytics with Elastic benefits us due to the huge traffic volume in our organization, which reaches up to 60,000 requests per second. With logs of approximately 25 GB per day, manually analyzing traffic behavior, payloads, headers, user agents, and other details is impractical.""It gives us the possibility to store and query this data and also do this efficiently and securely and without delays.""Helps us to store the data in key value pairs and, based on that, we can produce visualisations in Kibana.""The products comes with REST APIs.""Elasticsearch includes a graphical user interface (GUI) called Kibana. The GUI features are extremely beneficial to us."

More Elastic Search Pros →

"It has a rapid response search environment in the event of an incident.""We saw the granularity that we could get from Splunk far exceeded what we already had. We had the ability to have our security team really focus on the platform and stay within the platform, but they could correlate with a variety of other stakeholders, and our stakeholders were growing.""What is nice about the solution is that it makes it easy to build the queries, search for the events and then do analysis.""The ability to digest any information and then correlate it in accordance with what you need is valuable. The ability to connect to pretty much everything and bring the information in the same format is also valuable. On top of that, we can use their language in order to create and customize the dashboards, correlations, or analytics that we want to incorporate.""The ability to rapidly diagnose problems in production and non-production, across hundreds of log files, is the most valuable feature.""Splunk setup is easy and straightforward. ​""It has quite extensive support in terms of integration. If you want to do anything, there are tools for that.""The data representation options in the dashboards are excellent."

More Splunk Enterprise Security Pros →

Cons
"The solution must provide AI integrations.""The solution has quite a steep learning curve. The usability and general user-friendliness could be improved. However, that is kind of typical with products that have a lot of flexibility, or a lot of capabilities. Sometimes having more choices makes things more complex. It makes it difficult to configure it, though. It's kind of a bitter pill that you have to swallow in the beginning and you really have to get through it.""We'd like more user-friendly integrations.""Something that could be improved is better integrations with Cortex and QRadar, for example.""It is hard to learn and understand because it is a very big platform. This is the main reason why we still have nothing in production. We have to learn some things before we get there.""I would like to see more integration for the solution with different platforms.""The different applications need to be individually deployed.""Machine learning on search needs improvement."

More Elastic Search Cons →

"Over time I will have more requirements and I can foresee the solution could improve the search algorithm to run and output the data faster.""While Splunk Enterprise Security offers valuable features, its cost is high and could be more competitive.""It is a good product, but the Achilles heel for a lot of organizations is the cost model for it because it gets expensive. That's because the model is based on how much data it processes a day, which can be prohibitive, especially if you have a lot of data. A lot of customers may not be ready for the sticker shock on how to fully leverage the product. I realized that the reason for that is that when it was originally designed, it was kind of like a big data modeling application. If they want to have a bigger customer base, they can come out with subsets of their product that are focused on specific things and have different pricing models. It may help with the cost.""While there aren't any major areas where the solution has to be improved, there are certain integrations that are still not available. I would specifically like to see legacy applications integrated.""The solution could improve by increasing the performance. We have run into problems when large amounts of data are processed.""Some of the search functions can be better. There has been a lot of talk at the conference about the update of SPL before each iteration. That will be a lot of help.""This is not really a monitoring solution.""Its interface and usability can always be improved."

More Splunk Enterprise Security Cons →

Pricing and Cost Advice
  • "ELK has been considered as an alternative to Splunk to reduce licensing costs."
  • "An X-Pack license is more affordable than Splunk."
  • "​The pricing and license model are clear: node-based model."
  • "This is a free, open source software (FOSS) tool, which means no cost on the front-end. There are no free lunches in this world though. Technical skill to implement and support are costly on the back-end with ELK, whether you train/hire internally or go for premium services from Elastic."
  • "We are using the free version and intend to upgrade."
  • "It can be expensive."
  • "This product is open-source and can be used free of charge."
  • "We are using the open-sourced version."
  • More Elastic Search Pricing and Cost Advice →

  • "Pricing and licensing is quite expensive. But for the value the product provides, it seems at par in the market."
  • "Although Splunk is an expensive product, it is designed to be utilized across your organization in order to maximize your ROI and lower your TCO."
  • "It is not cheap."
  • "Splunk Enterprise becomes extremely expensive after the 20GB/month license."
  • "You will eat up whatever you purchase quickly. The level of insights that Splunk empowers is addictive."
  • "Splunk licensing model might seem expensive but with all the gain in functionalities you will have compared to traditional SIEM solutions I think it’s worth the price."
  • "Pricing is pretty fair."
  • "While licensing can be a concern, there are ways to reduce the licensing costs including filtering some events."
  • More Splunk Enterprise Security Pricing and Cost Advice →

    report
    Use our free recommendation engine to learn which Indexing and Search solutions are best for your needs.
    769,065 professionals have used our research since 2012.
    Comparison Review
    Vinod Shankar
    Answers from the Community
    Vivek Vijayan
    reviewer1182204 - PeerSpot reviewerreviewer1182204 (Director of Marketing, US)
    Vendor

    Generally Elastic is very strong in datasearch, and Splunk has a strong security solution. However Elastic has partnered with SIEM provider empow and together this integration provides a very strong platform both in datasearch and next generation SIEM.

    Here's a thorough article on ELK vs. Splunk and here's a description from Elastic on what's included in the different versions.

    Alex Boz - PeerSpot reviewerAlex Boz (Logrhythm)
    Vendor

    Splunk: hard to use, expensive with predatory pricing, few OOTB rules, SOAR is a premium, good luck training analyst on their platform in under six months. SPLUNK SEARCH.

    ELK Stack: easy to use, open-source, no predatory pricing, more robust use cases OOTB, loved and used by millions all over the globe, open ecosystem that can integrate with almost any major IT stack out of the box. LUCENE.

    Norman Freitag - PeerSpot reviewerNorman Freitag
    Real User

    We use ELK or other freeware stacks in isolated small scenarios.

    Think of a small or medium company with a „midsized“ webshop. You can easily do your Log management with an ELK-Stack, let's say size 5 up to 10 GB, no Problem. Please keep in mind to order Hardware. The best thing on ELK is that you can start immediately you don't have to wait for licensing and it's easy to build the first small things.

    Another Example:
    Your Marketing Dep. wants to do some singular evaluations and very specialized marketing stuff. It is temporary and they don't have the budget for licensing. The results are not for permanent use. Just use ELK.

    In my opinion, ELK is only cost-effective if you don't need to buy their professional service. You must leave the cases small.

    If you are looking for bigger scenarios or you want to build-up a SIEM, SOC or even doing elevated things like SOAR it is a very different kind of thing.
    There can be account issues that a developer usually won't mind at the first glance but a Controller will.
    You have to look at the Total Cost of Ownership, Scalability, Time to Market, Secureness of future development, maintenance e.g.

    If you want to build up a complex scenario with the secureness of scalability you should go with SPLUNK. If tomorrow there is a better tool with lower costs and less need for input of manpower I will refer to this.

    Questions from the Community
    Top Answer:Logsign provides us with the capability to execute multiple queries according to our requirements. The indexing is very high, making it effective for storing and retrieving logs. The real-time… more »
    Top Answer:I don't see improvements at the moment. The current setup is working well for me, and I'm satisfied with it. Integrating with different platforms is also fine, and I'm not recommending any changes or… more »
    Top Answer:For tools I’d recommend:  -SIEM- LogRhythm -SOAR- Palo Alto XSOAR Doing commercial w/o both (or at least an XDR) is asking to miss details that are critical, and ending up a statistic. Also,… more »
    Top Answer:It would really depend on (1) which logs you need to ingest and (2) what are your use cases Splunk is easy for ingestion of anything, but the charge per GB/Day Indexed and it gets expensive as log… more »
    Top Answer:Splunk handles a high amount of data very well. We use Splunk to capture information and as an aggregator for monitoring information from different sources. Splunk is very good at alerting us if we… more »
    Ranking
    1st
    out of 25 in Indexing and Search
    Views
    2,186
    Comparisons
    735
    Reviews
    27
    Average Words per Review
    501
    Rating
    8.3
    Views
    25,711
    Comparisons
    20,955
    Reviews
    63
    Average Words per Review
    958
    Rating
    8.4
    Comparisons
    Also Known As
    Elastic Enterprise Search, Swiftype, Elastic Cloud
    Learn More
    Overview

    Elasticsearch is a prominent open-source search and analytics engine known for its scalability, reliability, and straightforward management. It's a favored choice among enterprises for real-time data search, analysis, and visualization. Open-source Elasticsearch is free, offering a comprehensive feature set and scalability. It allows full control over deployments but requires managing and maintaining the infrastructure. On the other hand, Elastic Cloud provides a managed service with features like automated provisioning, high availability, security, and global reach.

    Elasticsearch excels in handling time-sensitive data and complex search requirements across large datasets. Its scalability allows it to handle growing data volumes efficiently, maintaining high performance and fast response times. Integrated with Kibana, Elasticsearch enables powerful data visualization, providing real-time insights crucial for data-driven decision-making.

    Elastic Cloud reduces operational overhead and improves scalability and performance, though it comes with associated costs. It is available on your preferred cloud provider — AWS, Azure, or Google Cloud. Customers who want to manage the software themselves, whether on public, private, or hybrid cloud, can download the Elastic Stack.

    At its core, Elasticsearch is renowned for its full-text search capabilities, capable of performing complex queries and supporting features like fuzzy matching and auto-complete.

    Peer reviews from various professionals highlight its strengths and weaknesses. Pros include its detection and correlation features, flexibility, cloud-readiness, extensibility, and efficient search capabilities. However, users have noted challenges like steep learning curves, data analysis limitations, and integration complexities. The platform is generally viewed as stable and scalable, with varying degrees of satisfaction regarding its usability and feature set.

    In summary, Elasticsearch stands out for its high-speed search, scalability, and versatile analytics, making it a go-to solution for organizations managing large datasets. Its adaptability to different enterprise needs, robust community support, and continuous development keep it at the forefront of enterprise search and analytics solutions. However, potential users should be aware of its learning curve and the need for skilled personnel for optimization.

    Splunk Enterprise Security is a SIEM, log management, and IT operations analytics tool. The solution provides users with the ability to secure their information and manage their data in the cloud, data centers, or other applications. Splunk Enterprise Security also offers visibility from different areas, levels, and devices, rather than from a single system, thus, providing its users with flexibility. Splunk Enterprise Security can monitor data and analyze, detect, and prevent intrusions. This benefits users as it provides alerts to possible intrusions, helps users to be proactive, and reduces risk factors. 

    Full visibility across your environment

    Break down data silos and gain actionable intelligence by ingesting data from multicloud and on-premises deployments. Get full visibility to quickly detect malicious threats in your environment.

    Fast threat detection

    Defend against threats with advanced security analytics, machine learning and threat intelligence that focus detection and provide high-fidelity alerts to shorten triage times and raise true positive rates.

    Efficient investigations

    Gather all the context you need and initiate flexible investigations with security analytics at your fingertips. The built-in open and extensible data platform boosts productivity and drives down fatigue.

    Open and scalable

    Built on an open and scalable data platform, you can stay agile in the face of evolving threats and business needs. Splunk meets you where you are on your cloud journey, and integrates across your data, tools and content.

    Sample Customers
    T-Mobile, Adobe, Booking.com, BMW, Telegraph Media Group, Cisco, Karbon, Deezer, NORBr, Labelbox, Fingerprint, Relativity, NHS Hospital, Met Office, Proximus, Go1, Mentat, Bluestone Analytics, Humanz, Hutch, Auchan, Sitecore, Linklaters, Socren, Infotrack, Pfizer, Engadget, Airbus, Grab, Vimeo, Ticketmaster, Asana, Twilio, Blizzard, Comcast, RWE and many others.
    Splunk has more than 7,000 customers spread across over 90 countries. These customers include Telenor, UniCredit, ideeli, McKenney's, Tesco, and SurveyMonkey.
    Top Industries
    REVIEWERS
    Financial Services Firm33%
    Computer Software Company27%
    Manufacturing Company10%
    Insurance Company7%
    VISITORS READING REVIEWS
    Computer Software Company18%
    Financial Services Firm15%
    Manufacturing Company8%
    Government7%
    REVIEWERS
    Computer Software Company19%
    Financial Services Firm15%
    Government10%
    Energy/Utilities Company7%
    VISITORS READING REVIEWS
    Financial Services Firm15%
    Computer Software Company14%
    Government9%
    Manufacturing Company7%
    Company Size
    REVIEWERS
    Small Business41%
    Midsize Enterprise11%
    Large Enterprise48%
    VISITORS READING REVIEWS
    Small Business24%
    Midsize Enterprise13%
    Large Enterprise63%
    REVIEWERS
    Small Business31%
    Midsize Enterprise12%
    Large Enterprise57%
    VISITORS READING REVIEWS
    Small Business19%
    Midsize Enterprise13%
    Large Enterprise68%
    Buyer's Guide
    Indexing and Search
    March 2024
    Find out what your peers are saying about Elastic, IBM, OpenText and others in Indexing and Search. Updated: March 2024.
    769,065 professionals have used our research since 2012.

    Elastic Search is ranked 1st in Indexing and Search with 59 reviews while Splunk Enterprise Security is ranked 2nd in Security Information and Event Management (SIEM) with 228 reviews. Elastic Search is rated 8.2, while Splunk Enterprise Security is rated 8.4. The top reviewer of Elastic Search writes "Played a crucial role in enhancing our cybersecurity efforts ". On the other hand, the top reviewer of Splunk Enterprise Security writes "It has a drag-and-drop interface, so you don't need to know SQL or Java to construct a query ". Elastic Search is most compared with Faiss, Milvus, Azure Search, Pinecone and Amazon Kendra, whereas Splunk Enterprise Security is most compared with Wazuh, Dynatrace, IBM Security QRadar, Microsoft Sentinel and Elastic Security.

    We monitor all Indexing and Search reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.