Find out in this report how the two Application Performance Monitoring (APM) and Observability solutions compare in terms of features, pricing, service and support, easy of deployment, and ROI.
The documentation for Splunk Enterprise Security is outstanding. It is well-organized and easy to access.
We couldn't calculate what would have been the cost if they had actually gotten compromised; however, they were in the process, so every investment was returned immediately.
On average, my SecOps team takes probably at least a quarter of the time, if not more, to remediate security incidents with Splunk Enterprise Security compared to our previous solution.
My advice for people who are new to Grafana or considering it is to reach out to the community mainly, as that's the primary benefit of Grafana.
I do not use Grafana's support for technical issues because I have found solutions on Stack Overflow and ChatGPT helps me as well.
I very rarely get in touch with technical support as we don't have that option.
We have paid for Splunk support, and we’re not on the free tier hoping for assistance; we are a significant customer and invest a lot in this service.
I have had nothing but good experiences with Splunk support, receiving timely and helpful replies.
We've had great customer success managers who have helped us navigate scaling from 600 gigs to 30 terabytes.
In terms of our company, the infrastructure is using two availability zones in AWS.
In assessing Grafana's scalability, we started noticing logs missing or metrics not syncing in time.
We currently rely on disaster recovery and backup recovery, which takes time to recover, during which you're basically blind, so I'm pushing my leadership team to switch over to a clustering environment for constant availability.
They struggle a bit with pure virtual environments, but in terms of how much they can handle, it is pretty good.
It is easy to scale.
When something in their dashboard does not work, because it is open source, I am able to find all the relative combinations that people are having, making it much easier for me to fix.
Once you get to a higher load, you need to re-evaluate your architecture and put that into account.
The product has been stable.
They test it very thoroughly before release, and our customers have Splunk running for months without issues.
Splunk has been very reliable and very consistent.
It provides a stable environment but needs to integrate with ITSM platforms to achieve better visibility.
It would be better if they made the technology easy to use without needing to read extensive documentation.
Grafana cannot be easily embedded into certain applications and offers limited customization options for graphs.
I would want to see improvements, especially in the tracing part, where following different requests between different services could be more powerful.
Improving the infrastructure behind Splunk Enterprise Security is vital—enhanced cores, CPUs, and memory should be prioritized to support better processing power.
Splunk Enterprise Security is not something that automatically picks things; you have to set up use cases, update data models, and link the right use cases to the right data models for those detections to happen.
For any future enhancements or features, such as MLTK and SOAR platform integration, we need more visibility, training, and certification for the skilled professionals who are working.
In an enterprise setting, pricing is reasonable, as many customers use it.
The costs associated with using Grafana are somewhere in the ten thousands because we are able to control the logs in a more efficient way to reduce it.
I saw clients spend two million dollars a year just feeding data into the Splunk solution.
The platform requires significant financial investment and resources, making it expensive despite its comprehensive features.
I find it to be affordable, which is why every industry uses it.
Users can monitor metrics with greater ease, and the tool aids in quickly identifying issues by providing a visual representation of data.
Its alerting feature is effective because it allows me to set thresholds to send an email if a certain threshold is met.
It's definitely useful for monitoring, alerting, logs, and analysis.
This capability is useful for performance monitoring and issue identification.
I assess Splunk Enterprise Security's insider threat detection capabilities for helping to find unknown threats and anomalous user behavior as great.
Splunk Enterprise Security provides the foundation for unified threat detection, investigation, and response, enabling fast identification of critical issues.
Product | Market Share (%) |
---|---|
Grafana | 5.2% |
Dynatrace | 8.8% |
Datadog | 7.2% |
Other | 78.8% |
Product | Market Share (%) |
---|---|
Splunk Enterprise Security | 9.3% |
Wazuh | 10.9% |
IBM Security QRadar | 7.2% |
Other | 72.6% |
Company Size | Count |
---|---|
Small Business | 13 |
Midsize Enterprise | 8 |
Large Enterprise | 24 |
Company Size | Count |
---|---|
Small Business | 109 |
Midsize Enterprise | 49 |
Large Enterprise | 255 |
Grafana is an open-source visualization and analytics platform that stands out in the field of monitoring solutions. Grafana is widely recognized for its powerful, easy-to-set-up dashboards and visualizations. Grafana supports integration with a wide array of data sources and tools, including Prometheus, InfluxDB, MySQL, Splunk, and Elasticsearch, enhancing its versatility. Grafana has open-source and cloud options; the open-source version is a good choice for organizations with the resources to manage their infrastructure and want more control over their deployment. The cloud service is a good choice if you want a fully managed solution that is easy to start with and scale.
A key strength of Grafana lies in its ability to explore, visualize, query, and alert on the collected data through operational dashboards. These dashboards are highly customizable and visually appealing, making them a valuable asset for data analysis, performance tracking, trend spotting, and detecting irregularities.
Grafana provides both an open-source solution with an active community and Grafana Cloud, a fully managed and composable observability offering that packages together metrics, logs, and traces with Grafana. The open-source version is licensed under the Affero General Public License version 3.0 (AGPLv3), being free and unlimited. Grafana Cloud and Grafana Enterprise are available for more advanced needs, catering to a wider range of organizational requirements. Grafana offers options for self-managed backend systems or fully managed services via Grafana Cloud. Grafana Cloud extends observability with a wide range of solutions for infrastructure monitoring, IRM, load testing, Kubernetes monitoring, continuous profiling, frontend observability, and more.
The Grafana users we interviewed generally appreciate Grafana's ability to connect with various data sources, its straightforward usability, and its integration capabilities, especially in developer-oriented environments. The platform is noted for its practical alert configurations, ticketing backend integration, and as a powerful tool for developing dashboards. However, some users find a learning curve in the initial setup and mention the need for time investment to customize and leverage Grafana effectively. There are also calls for clearer documentation and simplification of notification alert templates.
In summary, Grafana is a comprehensive solution for data visualization and monitoring, widely used across industries for its versatility, ease of use, and extensive integration options. It suits organizations seeking a customizable and scalable platform for visualizing time-series data from diverse sources. However, users should be prepared for some complexity in setup and customization and may need to invest time in learning and tailoring the system to their specific needs.
Splunk Enterprise Security delivers powerful log management, rapid searches, and intuitive dashboards, enhancing real-time analytics and security measures. Its advanced machine learning and wide system compatibility streamline threat detection and incident response across diverse IT environments.
Splunk Enterprise Security stands out in security operations with robust features like comprehensive threat intelligence and seamless data integration. Its real-time analytics and customizable queries enable proactive threat analysis and efficient incident response. Integration with multiple third-party feeds allows detailed threat correlation and streamlined data visualization. Users find the intuitive UI and broad compatibility support efficient threat detection while reducing false positives. Despite its strengths, areas such as visualization capabilities and integration processes with cloud environments need enhancement. Users face a high learning curve, and improvements in automation, AI, documentation, and training are desired to maximize its potential.
What Are the Key Features of Splunk Enterprise Security?In specific industries like finance and healthcare, Splunk Enterprise Security is instrumental for log aggregation, SIEM functionalities, and compliance monitoring. Companies leverage its capabilities for proactive threat analysis and response, ensuring comprehensive security monitoring and integration with various tools for heightened operational intelligence.
We monitor all Application Performance Monitoring (APM) and Observability reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.