Try our new research platform with insights from 80,000+ expert users

IBM Tivoli Composite Application Manager vs Splunk Enterprise Security comparison

 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

IBM Tivoli Composite Applic...
Average Rating
6.6
Reviews Sentiment
4.3
Number of Reviews
2
Ranking in other categories
Application Performance Monitoring (APM) and Observability (55th)
Splunk Enterprise Security
Average Rating
8.4
Reviews Sentiment
7.6
Number of Reviews
308
Ranking in other categories
Log Management (2nd), Security Information and Event Management (SIEM) (1st), IT Operations Analytics (1st)
 

Mindshare comparison

While both are Application Lifecycle Management solutions, they serve different purposes. IBM Tivoli Composite Application Manager is designed for Application Performance Monitoring (APM) and Observability and holds a mindshare of 0.2%, up 0.2% compared to last year.
Splunk Enterprise Security, on the other hand, focuses on Security Information and Event Management (SIEM), holds 9.5% mindshare, down 12.6% since last year.
Application Performance Monitoring (APM) and Observability
Security Information and Event Management (SIEM)
 

Featured Reviews

CC
Integrates well with IBM technologies, but it's outdated and lacks essential features
Implementing synthetic monitoring for our Internet banking site has been challenging. The installation process is difficult, requiring continuous support and specialist expertise due to our limited knowledge of managing it effectively. I have concerns about the complexity of the tool and the challenges in managing it effectively. The support provided is not satisfactory, and the specialists available lack sufficient training and expertise in using the tool.
ROBERT-CHRISTIAN - PeerSpot reviewer
Has many predefined correlation rules and is brilliant for investigation and log analysis
It is very complicated to write your own correlation rules without the help of Splunk support. What Splunk could do better is to create an API to the standard SIEM tools, such as Microsoft Sentinel. The idea would be to make it less painful. In ELK Stack, Kibana is the query language with which you can search log files. I believe Splunk has also a query language in which they search their log files, but once you have identified the log file that you want to use for further security correlation, you want to very quickly transport that into your SIEM tool, such as Microsoft Sentinel. That is something that Splunk could make a little bit less painful because it is a lot of effort to find that log file and forward it. An API with Microsoft Sentinel or a similar SIEM tool would be a good idea.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"IBM's main value lies in its integration with its own technologies, which can be seen as a benefit in environments where IBM products are extensively used."
"The solution is very stable. We never had any issues with stability."
"The most valuable aspect of the solution is the dashboard. It's very intuitive."
"It is a one stop shop as a full monitoring and alerting solution for operations and application analysis for most of our back-end systems."
"We have created a few custom use cases for Splunk that have helped us detect threats faster. For example, we set up endpoint-related data models and specialized setups for various scenarios. It's more efficient than some other products I've used."
"Splunk setup is easy and straightforward. ​"
"The site is constantly up, and it's been really easy to adjust the data."
"Splunk Enterprise Security stands out for its ability to integrate with existing security tools, provide informative dashboards, and offer IT Service Assurance functionality that goes beyond basic threat detection to include service performance monitoring."
"We are much faster finding and addressing issues with Splunk."
"It is lovely to have everything we need in one tool. Everything is quite centralized."
 

Cons

"The user interface was not good."
"The installation process is difficult, requiring continuous support and specialist expertise due to our limited knowledge of managing it effectively."
"It needs more thoroughly tested releases. Every new big version (6, 7, etc.) has had so many bugs that it makes me wary of customers upgrading right away."
"Professional support is great, but too expensive."
"Improving the infrastructure behind Splunk Enterprise Security is vital—enhanced cores, CPUs, and memory should be prioritized to support better processing power."
"The solution could improve by giving more email details."
"More training on PetaData using artificial intelligence techniques to identify the events which are not normal and exceptions that would help the organization identify threats and malware on the go with results."
"Resource usage can probably be described as an area with shortcomings in the product where improvements are required."
"I haven't found a way for me to create my own plugins and integrate them into Splunk, but this isn't necessarily a limitation; it could simply be a lack of knowledge on my part."
"If it could be made available as a service, this would be much better than as a product."
 

Pricing and Cost Advice

"I would rate the pricing a nine to ten. It is very expensive."
"The tool's pricing model is great. You can choose between workloads or volume."
"The variables and the flexibility that Splunk provides are helpful, especially in a hybrid and multi-cloud environment."
"Expensive compared to other options."
"Truly evaluate the data you want to ingest and go slow. Pulling in data that can provide no use to your mission only wastes data against your license."
"The pricing is based on the volume of data fed into it, which can lead to substantial costs. This pricing model is complex and unpredictable, making cost management difficult."
"I've heard Splunk is often preferred over other options, but the cost can be prohibitive for smaller organizations."
"This product could use better pricing in general."
"Splunk Enterprise Security is expensive."
report
Use our free recommendation engine to learn which Application Performance Monitoring (APM) and Observability solutions are best for your needs.
850,760 professionals have used our research since 2012.
 

Comparison Review

VS
Feb 26, 2015
HP ArcSight vs. IBM QRadar vs. ​McAfee Nitro vs. Splunk vs. RSA Security vs. LogRhythm
We at Infosecnirvana.com have done several posts on SIEM. After the Dummies Guide on SIEM, we are following it up with a SIEM Product Comparison – 101 deck. So, here it is for your viewing pleasure. Let me know what you think by posting your comments below. The key products compared here are…
 

Top Industries

By visitors reading reviews
Financial Services Firm
39%
Computer Software Company
9%
Government
7%
Healthcare Company
7%
Financial Services Firm
15%
Computer Software Company
14%
Manufacturing Company
8%
Government
8%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
No data available
 

Questions from the Community

What do you like most about IBM Tivoli Composite Application Manager?
IBM's main value lies in its integration with its own technologies, which can be seen as a benefit in environments where IBM products are extensively used.
What needs improvement with IBM Tivoli Composite Application Manager?
Implementing synthetic monitoring for our Internet banking site has been challenging. The installation process is difficult, requiring continuous support and specialist expertise due to our limited...
What advice do you have for others considering IBM Tivoli Composite Application Manager?
I would rate IBM Tivoli Composite Application Manager a six out of ten. The monitoring tool we currently use is outdated and lacks essential features for monitoring customer experience. We face lim...
What SOC product do you recommend?
For tools I’d recommend: -SIEM- LogRhythm -SOAR- Palo Alto XSOAR Doing commercial w/o both (or at least an XDR) is asking to miss details that are critical, and ending up a statistic. Also, rememb...
What is a better choice, Splunk or Azure Sentinel?
It would really depend on (1) which logs you need to ingest and (2) what are your use cases Splunk is easy for ingestion of anything, but the charge per GB/Day Indexed and it gets expensive as log ...
How does Splunk compare with Azure Monitor?
Splunk handles a high amount of data very well. We use Splunk to capture information and as an aggregator for monitoring information from different sources. Splunk is very good at alerting us if we...
 

Also Known As

Tivoli Composite Application Manager
No data available
 

Overview

 

Sample Customers

Michelin Tire Corp
Splunk has more than 7,000 customers spread across over 90 countries. These customers include Telenor, UniCredit, ideeli, McKenney's, Tesco, and SurveyMonkey.
Find out what your peers are saying about Datadog, Dynatrace, Splunk and others in Application Performance Monitoring (APM) and Observability. Updated: April 2025.
850,760 professionals have used our research since 2012.