No more typing reviews! Try our Samantha, our new voice AI agent.

IBM Resilient vs Splunk Security Essentials comparison

 

Comparison Buyer's Guide

Executive SummaryUpdated on Jan 2, 2025

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

IBM Resilient
Ranking in Security Incident Response
7th
Average Rating
7.4
Reviews Sentiment
6.6
Number of Reviews
18
Ranking in other categories
Security Orchestration Automation and Response (SOAR) (19th)
Splunk Security Essentials
Ranking in Security Incident Response
10th
Average Rating
8.6
Reviews Sentiment
4.8
Number of Reviews
6
Ranking in other categories
Data Visualization (14th), IT Alerting and Incident Management (14th)
 

Mindshare comparison

As of August 2026, in the Security Incident Response category, the mindshare of IBM Resilient is 7.3%, down from 8.5% compared to the previous year. The mindshare of Splunk Security Essentials is 2.7%, up from 2.0% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Security Incident Response Mindshare Distribution
ProductMindshare (%)
IBM Resilient7.3%
Splunk Security Essentials2.7%
Other90.0%
Security Incident Response
 

Featured Reviews

ZaidHaddad - PeerSpot reviewer
Technical Seller at Alawtad group
Suitable for different industries and ensures effective incident response
IBM Resilient is great in many aspects like its wide range of integrations and customizable playbooks. However, one thing to improve is how it handles data formats, which currently might require scripting for conversion to CSV before uploading. Despite this, it stands out for incident response, case management, task organization, and team collaboration, making it a strong choice for organizations compared to competitors like Demisto Palo Alto. When it comes to additional features, I think IBM Resilient is on the right track with its AI capabilities, like linking related incidents and providing recommended actions. It would be nice to see more enhancements in this area, but overall, it looks good.
reviewer2836941 - PeerSpot reviewer
Assistant Manager at a tech services company with 1-10 employees
Centralized monitoring has given our SOC real-time visibility into security and application activity
When I first implemented Splunk Security Essentials in this environment, it took a week for each log source to onboard and to create use cases and implement the data model, CIM, etc., for production readiness. Training is mandatory, and we need at least the Splunk Security Essentials User certification because it is a very critical resource in the organization, as we are handling security logs. In my organization, Splunk Security Essentials is used not only by the SOC but also for monitoring logs across different teams, as it is important for handling both security and application logs, given its capability to manage unstructured logs. Splunk Security Essentials has dramatically impacted my organization, as without it, we were blind to what is happening from both a security and application perspective, and it provides vital visibility into the organization's operations.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"It's really simple and has a flexible interface."
"This is a good solution that we recommend for customers."
"What I like most about IBM Resilient is that it has a complete stack, which means you don't need to use different OEM products because you have all you need under the IBM Resilient umbrella. You don't need to worry much about integrations and components because you're working with tested and proven architecture."
"The solution is easy to use."
"The interlinking of the offenses is the most valuable aspect of the solution for us."
"The product is very good at incident response."
"As a whole, the product is stable...Technical support is very good."
"The most valuable features of IBM Resilient are its flexibility and customization options for incident response."
"We are focusing on security to ensure incidents are reported efficiently. In addition to that, for reporting purposes, we are utilizing our dashboards or creating new ones. We will be using free visualization tools for this purpose."
"They have a good catalog of plans to use to resist the attacks."
"Splunk Security Essentials has dramatically impacted my organization, as without it, we were blind to what is happening from both a security and application perspective, and it provides vital visibility into the organization's operations."
"Splunk Security Essentials has impacted my organization in that we have been getting the results that we wanted."
"I would have to rate Splunk Security Essentials a 10 out of 10 because it's free and there's tons of usable content."
"The network monitoring feature is particularly valuable for gathering information about users, login times, and other statistics."
 

Cons

"Its price and technical support need improvement."
"The implementation could be a bit simpler."
"What could make IBM Resilient better is if IBM increased the number of built-in integrations with different products from other vendors or third-party products."
"The initial setup is not straightforward or simple. It's quite complex."
"The product needs a bit more development."
"IBM Resilient could integrate better with my tools."
"Right now, sometimes it can take up to two to three months to resolve an issue, which is far too long."
"IBM Resilient is quite complex, including its configuration."
"They could add more AI content or AI and machine learning."
"The reporting feature needs to be more user-friendly."
"The price could be improved."
"The biggest friction points I have with Splunk Security Essentials are the high license costs and user behavior that causes performance issues due to inappropriate wildcard searches."
"If I could change one thing about Splunk Security Essentials, it would be pricing. I believe they are still very costly as compared to the competition."
"It takes a lot of time to install Splunk Security Essentials. It's not very difficult, but it requires time."
 

Pricing and Cost Advice

"Pricing for the solution is good, in my opinion."
"The cost of the product is quite high."
"There are no costs except for the support services that our company pays in addition to the licensing charges attached to the solution."
"It is very expensive."
"I would rate the tool’s pricing a three out of ten. The tool’s pricing is on a yearly basis."
"We could create unlimited users using the license we had purchased."
"The licensing cost for IBM Resilient is not too expensive, but it's not affordable, so it's moderately expensive. Regarding price, I'm rating the solution seven out of ten. The company pays for the license yearly, based on the number of users. Apart from the cost of the license you need to pay for each user, you also need to spend an initial investment for the base platform. You also have to pay for IBM Resilient support."
"There is a license you need to pay for in order to use this product."
Information not available
report
Use our free recommendation engine to learn which Security Incident Response solutions are best for your needs.
909,725 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Financial Services Firm
25%
Construction Company
9%
Outsourcing Company
9%
Government
8%
Construction Company
18%
Comms Service Provider
11%
Financial Services Firm
11%
Healthcare Company
8%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business9
Midsize Enterprise2
Large Enterprise7
No data available
 

Questions from the Community

What is your experience regarding pricing and costs for IBM Resilient?
I am not the one in charge of pricing, so I am not sure about the costs.
What needs improvement with IBM Resilient?
Integration with some devices, including Cisco PowerPower and certain antivirus products, has limitations.
What is your experience regarding pricing and costs for Splunk Security Essentials?
Our SecOps manager and CISO were more familiar with Splunk, and the price was right. That was probably the primary driver, and we did evaluation as well with strict criteria and Gartner ratings.
What needs improvement with Splunk Security Essentials?
The biggest friction points I have with Splunk Security Essentials are the high license costs and user behavior that causes performance issues due to inappropriate wildcard searches. Additionally, ...
What is your primary use case for Splunk Security Essentials?
My main use case for Splunk Security Essentials is for Enterprise Security, specifically the ES app. Splunk Security Essentials is my primary tool for threat detection and monitoring because as a S...
 

Overview

 

Sample Customers

Golden Living, Health Equity, USA Funds
Information Not Available
Find out what your peers are saying about IBM Resilient vs. Splunk Security Essentials and other solutions. Updated: August 2026.
909,725 professionals have used our research since 2012.