Try our new research platform with insights from 80,000+ expert users

IBM Tivoli Composite Application Manager vs Splunk Enterprise Security comparison

 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

IBM Tivoli Composite Applic...
Average Rating
6.6
Reviews Sentiment
4.3
Number of Reviews
2
Ranking in other categories
Application Performance Monitoring (APM) and Observability (59th)
Splunk Enterprise Security
Average Rating
8.4
Reviews Sentiment
7.5
Number of Reviews
318
Ranking in other categories
Log Management (2nd), Security Information and Event Management (SIEM) (1st), IT Operations Analytics (1st)
 

Mindshare comparison

While both are Application Lifecycle Management solutions, they serve different purposes. IBM Tivoli Composite Application Manager is designed for Application Performance Monitoring (APM) and Observability and holds a mindshare of 0.2%, up 0.2% compared to last year.
Splunk Enterprise Security, on the other hand, focuses on Security Information and Event Management (SIEM), holds 9.4% mindshare, down 12.1% since last year.
Application Performance Monitoring (APM) and Observability
Security Information and Event Management (SIEM)
 

Featured Reviews

CC
Integrates well with IBM technologies, but it's outdated and lacks essential features
Implementing synthetic monitoring for our Internet banking site has been challenging. The installation process is difficult, requiring continuous support and specialist expertise due to our limited knowledge of managing it effectively. I have concerns about the complexity of the tool and the challenges in managing it effectively. The support provided is not satisfactory, and the specialists available lack sufficient training and expertise in using the tool.
ROBERT-CHRISTIAN - PeerSpot reviewer
Has many predefined correlation rules and is brilliant for investigation and log analysis
It is very complicated to write your own correlation rules without the help of Splunk support. What Splunk could do better is to create an API to the standard SIEM tools, such as Microsoft Sentinel. The idea would be to make it less painful. In ELK Stack, Kibana is the query language with which you can search log files. I believe Splunk has also a query language in which they search their log files, but once you have identified the log file that you want to use for further security correlation, you want to very quickly transport that into your SIEM tool, such as Microsoft Sentinel. That is something that Splunk could make a little bit less painful because it is a lot of effort to find that log file and forward it. An API with Microsoft Sentinel or a similar SIEM tool would be a good idea.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"The solution is very stable. We never had any issues with stability."
"IBM's main value lies in its integration with its own technologies, which can be seen as a benefit in environments where IBM products are extensively used."
"There are quite a lot of things that we find useful. Splunk agents are useful and good. Its UI is quite impressive."
"The ability to quickly search logs, performance data, and other inputs has helped tremendously with troubleshooting."
"The best part of Splunk Enterprise Security is its customizable settings."
"Splunk has facilitated the correlation of information security logs to look for incidents which could cause damage to the company's infrastructure, as well as financial losses from leaks."
"The incident review in Splunk Enterprise Security seems to be the most helpful feature."
"Splunk incorporates a lot of elements that help to reduce security risks. For it to reach certain compliance, we need to have some security insight. Splunk is a very good SIEM, it’s a top solution, but the best feature is its cost of visibility. We have all the most important features to detect vulnerabilities or risks."
"Splunk has machine learning which is a valuable feature."
"The SIEM is the most valuable feature of the product."
 

Cons

"The installation process is difficult, requiring continuous support and specialist expertise due to our limited knowledge of managing it effectively."
"The user interface was not good."
"The default threat intel feeds create many false positives and noise, which is counterproductive."
"The configuration had a bit of a learning curve."
"It's difficult to set up initially, and their billing model is also a bit complicated."
"Sometimes, the data does not match what we're looking for, or the tool contains incorrect data."
"Data retention can be better. If we want to look at the data for five months or six months, that is not available to us."
"We'd like Splunk to reduce false positives."
"We find that the maintenance process could be a lot better."
"We've sometimes faced issues with upgrades. The incident review dashboard sometimes breaks after updates. When we add a space or something in the description or anywhere in the SQL, the drill-down value may be reset with a blank value. Before rolling out any software, they should test it thoroughly and ensure clients won't have issues with the upgraded version. It should be compatible with all or most of the apps. All major issues must be addressed before rolling out the upgrade."
 

Pricing and Cost Advice

"I would rate the pricing a nine to ten. It is very expensive."
"It is economical than other solutions."
"I assume that the pricing is reasonable, because if it was too costly, there are other alternatives."
"I believe that Splunk Enterprise Security is worth the price, but it is expensive."
"While Splunk offers generous developer licenses and obtaining annual licenses is straightforward, the cost is a major consideration."
"I am fine with the licensing, but in terms of the cost, it is expensive for the data that we have. We have an open discussion with our account rep about this."
"It's a yearly subscription."
"The variables and the flexibility that Splunk provides are helpful, especially in a hybrid and multi-cloud environment."
"Splunk Enterprise Security is expensive."
report
Use our free recommendation engine to learn which Application Performance Monitoring (APM) and Observability solutions are best for your needs.
862,514 professionals have used our research since 2012.
 

Comparison Review

VS
Feb 26, 2015
HP ArcSight vs. IBM QRadar vs. ​McAfee Nitro vs. Splunk vs. RSA Security vs. LogRhythm
We at Infosecnirvana.com have done several posts on SIEM. After the Dummies Guide on SIEM, we are following it up with a SIEM Product Comparison – 101 deck. So, here it is for your viewing pleasure. Let me know what you think by posting your comments below. The key products compared here are…
 

Top Industries

By visitors reading reviews
Financial Services Firm
36%
Government
9%
Healthcare Company
8%
Non Profit
6%
Financial Services Firm
14%
Computer Software Company
14%
Manufacturing Company
8%
Government
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
No data available
 

Questions from the Community

Ask a question
Earn 20 points
What SOC product do you recommend?
For tools I’d recommend: -SIEM- LogRhythm -SOAR- Palo Alto XSOAR Doing commercial w/o both (or at least an XDR) is asking to miss details that are critical, and ending up a statistic. Also, rememb...
What is a better choice, Splunk or Azure Sentinel?
It would really depend on (1) which logs you need to ingest and (2) what are your use cases Splunk is easy for ingestion of anything, but the charge per GB/Day Indexed and it gets expensive as log ...
How does Splunk compare with Azure Monitor?
Splunk handles a high amount of data very well. We use Splunk to capture information and as an aggregator for monitoring information from different sources. Splunk is very good at alerting us if we...
 

Also Known As

Tivoli Composite Application Manager
No data available
 

Overview

 

Sample Customers

Michelin Tire Corp
Splunk has more than 7,000 customers spread across over 90 countries. These customers include Telenor, UniCredit, ideeli, McKenney's, Tesco, and SurveyMonkey.
Find out what your peers are saying about Datadog, Dynatrace, Splunk and others in Application Performance Monitoring (APM) and Observability. Updated: July 2025.
862,514 professionals have used our research since 2012.