Try our new research platform with insights from 80,000+ expert users

Graylog vs Splunk Cloud Platform comparison

 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Graylog
Average Rating
8.0
Reviews Sentiment
7.2
Number of Reviews
21
Ranking in other categories
Log Management (15th)
Splunk Cloud Platform
Average Rating
8.2
Reviews Sentiment
6.0
Number of Reviews
58
Ranking in other categories
Data Visualization (2nd), IT Alerting and Incident Management (3rd)
 

Mindshare comparison

While both are Systems Management solutions, they serve different purposes. Graylog is designed for Log Management and holds a mindshare of 6.7%, up 5.9% compared to last year.
Splunk Cloud Platform, on the other hand, focuses on Data Visualization, holds 0.9% mindshare, up 0.4% since last year.
Log Management
Data Visualization
 

Featured Reviews

Ivan Kokalovic - PeerSpot reviewer
Facilitates backend service monitoring with efficient log retrieval and API flexibility
Graylog is valuable because it bridges technical knowledge to non-technical teams, presenting complex backend processes in a simple timeline. It boosts the knowledge of sales and customer support teams by allowing them to see the backend operations without needing to read the code. Its API is flexible for visualization, and its powerful search engine efficiently handles large volumes of log data. Moreover, its stability, fast search capabilities, and compatibility with languages like ANSI SQL enhance its utility in IT infrastructure.
Ian Gatundu - PeerSpot reviewer
It improves our visibility and decision-making while helping us meet compliance standards
The Cloud Platform interface is cleaner than Splunk Enterprise's monitoring console. You can easily understand what's happening with your indexes. It's more refined than Splunk Enterprise's console, but they have the same feel and function. It's easy to monitor multiple cloud environments because you can create custom dashboards for any use case you may have. It offers good visibility because it integrates with the ITSI app, providing a clear overview of your environment. Integrating Splunk with other components on the cloud and network resources is effortless because it can collect data from various sources, including stored data from long-term storage. Splunk's reporting offers a good visualization of your data. You can visualize the statistics based on your searches. It produces some helpful graphs that enable you to easily compare what's happening in your search. It's very comprehensive.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"UDP is a fast and lightweight protocol, perfect for sending large volumes of logs with minimal overhead."
"Storing logs in Elasticsearch means log retrieval is extremely fast, and full text search is available by default."
"The ability to write custom alerts is key to information security and compliance."
"The build is stable and requires little maintenance, even compared to some extremely expensive products."
"The product is scalable. The solution is stable."
"Open source and user friendly."
"I am very proud of how very stable the solution is."
"We run a containerized microservices environment. Being able to set up streams and search for errors and anomalies across hundreds of containers is why a log aggregation platform like Graylog is valuable to us."
"Splunk Cloud has helped us to be able to focus on getting more information out of our data."
"Everything is maintained by the Splunk support team. Users do not have to maintain any physical servers. They do not have to maintain indexes and searches. It reduces a lot of work on the user side."
"In terms of the benefits of the product, I would say it is my go-to tool."
"The most valuable feature of Splunk Cloud Platform is its robustness and ability to ingest logs."
"We use Splunk Cloud primarily as a troubleshooting tool, so the most valuable features are the analysis and visualization."
"Not having to maintain any infrastructure is valuable. That frees up a lot of time as well."
"The most valuable feature of Splunk Cloud Platform is its flexibility and readiness because it's already prebuilt, and everything is click-to-go."
"The most valuable feature is the SPL because without it we wouldn't be able to correlate and build our use cases and manage what we have for our data inside Splunk."
 

Cons

"When it comes to configuring the processing pipeline, writing the rules can be very tedious, especially since the documentation isn't extensive on how the functions provided for these rules work."
"I hope to see improvements in Graylog for more interactivity, user-friendliness, and creating alerts. The initial setup is complex."
"The area in Graylog that needs to be improved or enhanced would be the integrations."
"More complex visualizations and the ability to execute custom Elasticsearch queries would be great."
"Its scalability gets complicated when we have to update or edit multiple nodes."
"We ran into problems with Elasticsearch throwing a circuit-breaking exception due to field data size being too large. It turned out that the heap size directly impacted this size in a high-throughput environment, causing unexplained instability in Graylog. We were able to troubleshoot on the Elasticsearch size, but we should have been able to reference some minimum requirements for Graylog to know that our settings weren't sufficient."
"Over six months, I had two similar issues where searches were performed on field "messages". It exhausted all the memory of the ES node causing an ES crash and a Graylog halt."
"I would like to see a date and time in the Graylog Grok patterns so that I can save time when searching for a log. I like how the streams and the search query work, but adding a date and time will allow me to pull out a log in a milli-second."
"Splunk Cloud Platform should have better integrations with its suite of tools."
"The pricing model makes the product costly."
"There can be more modules and more integration with other areas in the cloud and on-prem. I am not sure whether it includes network devices and things like that."
"The only thing I would say is an issue is the cost. It matches other products. The costs can be justified for the value that we gain. The entire threat analysis stack should come in a bundle. If the cost was matchable with other products I think Splunk would pick up in the market."
"When one of my customers needs an app, and I am able to find that app on the Splunk base, I have to create a ticket and wait for five days for them to download the app into the cloud environment. That is probably one of the main things. It is painful because I have to wait to get that app in the cloud."
"Splunk Cloud Platform should improve its integrations and consider multiple integrations or direct integration with other platforms like Microsoft Azure, Google Cloud, or AWS."
"The Splunk interface is on-premises, so we have limited access to Splunk Cloud. Splunk support is not so good on Splunk Cloud. The Splunk side of the Splunk Cloud should also be more customizable. Integrating Splunk UBA, Splunk Phantom, and Splunk Cloud is also a bit difficult."
"There is sometimes no documentation or updated documentation available."
 

Pricing and Cost Advice

"Having paid official support is wise for projects."
"There is an open source version and an enterprise version. I wouldn't recommend the enterprise version, but as an open source solution, it is solid and works really well."
"We are using the free version of the product. However, the paid version is expensive."
"It's open source and free. They have a paid version, but we never looked into that because we never needed the features of the paid version."
"I use the free version of Graylog."
"Graylog is a free open-source solution. The free version has a capacity limitation of 2 GB daily, if you want to go above this you have to purchase a license."
"If you want something that works and do not have the money for Splunk or QRadar, take Graylog.​​"
"We're using the Community edition."
"I know that Splunk Cloud Platform is an expensive product."
"The Splunk Cloud Platform is expensive."
"We were involved in the renewal process, and our organization does reviews of all our partnerships that we have every two to three years to ensure they are meeting our needs, there isn't a better solution out there, and we won't save money by going somewhere else."
"The lack of transparency around the SVC licensing makes it difficult to explain the costs to our clients."
"My company has a license for Splunk Cloud Platform. My company also has a license for Splunk Enterprise."
"It was a good model."
"The cost of the Splunk Cloud Platform is high, and in addition to the standard licensing fee, we also have a premium support fee."
"Splunk Cloud Platform's pricing is a little on the higher end."
report
Use our free recommendation engine to learn which Log Management solutions are best for your needs.
859,129 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Computer Software Company
17%
Comms Service Provider
10%
Educational Organization
7%
University
7%
Computer Software Company
30%
Financial Services Firm
11%
Manufacturing Company
5%
University
5%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

What do you like most about Graylog?
The product is scalable. The solution is stable.
What is your experience regarding pricing and costs for Graylog?
I am not familiar with the pricing details of Graylog, as I was not responsible for that aspect. It was determined that we didn't need an enterprise plan, which is more suited for clients with less...
What needs improvement with Graylog?
An improvement I would suggest is in Graylog's user interface, such as allowing for font size adjustments. A potential enhancement could be the integration with Ollama to run large language models ...
What do you like most about Splunk Cloud Platform?
Splunk has sped up our response and reduced the time we spend manually monitoring any logs for ticketing tools or servers. It saves us around two hours daily.
What is your experience regarding pricing and costs for Splunk Cloud Platform?
If I were to rate the price for the product from 1 to 10, I would rate it nine.
What needs improvement with Splunk Cloud Platform?
The disadvantage of Splunk Cloud Platform is that its integration process should be improved. The challenges I have encountered while integrating Splunk Cloud Platform include that integration is a...
 

Comparisons

 

Also Known As

Graylog2
No data available
 

Overview

 

Sample Customers

Blue Cross Blue Shield, eBay, Cisco, LinkedIn, SAP, King.com, Twilio, Deutsche Presse-Agentur
Mindtouch
Find out what your peers are saying about Graylog vs. Splunk Cloud Platform and other solutions. Updated: March 2023.
859,129 professionals have used our research since 2012.