No more typing reviews! Try our Samantha, our new voice AI agent.

LogicMonitor vs Splunk Enterprise Security comparison

 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

ROI

Sentiment score
6.8
LogicMonitor reduced costs, enhanced efficiency, decreased false alerts, improved response times, and minimized downtime, benefiting overall operational efficiency.
Sentiment score
6.2
Splunk Enterprise Security is valued for automation, efficiency, and comprehensive visibility, despite high costs for smaller enterprises.
The return is more of value and savings in preventing costly downtime, making the savings of about $60,000 which we would have lost without LogicMonitor, and in IT staff efficiency, we save approximately 15 hours a week.
IT Infrastructure Engineer at Ethical Trade SErvices Africa
Because of LogicMonitor, we have reduced our EC2 infrastructure significantly, which has helped us reduce costs by 20%.
Site Reliability Engineer at a comms service provider with 501-1,000 employees
I can definitely notice a difference in our posture, uptime, and ability to solve problems and resolve outages much quicker since we have had LogicMonitor in place.
Sr. Systems Engineer at a financial services firm with 201-500 employees
The documentation for Splunk Enterprise Security is outstanding. It is well-organized and easy to access.
DevOps&Cloud Engineer Mentee at CertDirectory.io
We couldn't calculate what would have been the cost if they had actually gotten compromised; however, they were in the process, so every investment was returned immediately.
Business Development Manager at Axians Germany
On average, my SecOps team takes probably at least a quarter of the time, if not more, to remediate security incidents with Splunk Enterprise Security compared to our previous solution.
IT Orchestration Architect at Penn State University
 

Customer Service

Sentiment score
7.3
LogicMonitor support is knowledgeable and responsive, excelling in chat and email with room for improvement in phone support.
Sentiment score
6.2
Splunk Enterprise Security support gets mixed reviews with praise for responsiveness but critique for delays and tiered issues.
Within one day, I received a script, and LogicMonitor was able to provide the firewall configuration in LogicMonitor on the same day I submitted the request.
Network Administrator at i-level automatisering
Customer support is on point and very well trained.
IT Infrastructure Engineer at Ethical Trade SErvices Africa
We need to be able to reach them in real-time, and without those kinds of options available, we have to set up ad hoc calls, which could be improved.
Observability Engineer at Universal Music Group
We have paid for Splunk support, and we’re not on the free tier hoping for assistance; we are a significant customer and invest a lot in this service.
Senior System Administrator at a tech services company with 5,001-10,000 employees
I have had nothing but good experiences with Splunk support, receiving timely and helpful replies.
Cyber Security Associate at SAP
We've had great customer success managers who have helped us navigate scaling from 600 gigs to 30 terabytes.
Principal Engineer at Aviatrix
 

Scalability Issues

Sentiment score
7.5
LogicMonitor offers robust scalability across devices and environments, efficiently supporting growth and diverse user needs in cloud and on-premises.
Sentiment score
7.3
Splunk Enterprise Security is scalable and effective for large data, excelling in cloud but challenging on-premises.
They are not licensed, so you could deploy one collector or 1,000 collectors for the same cost.
Sr. Systems Engineer at a financial services firm with 201-500 employees
LogicMonitor's scalability absolutely meets our organization's growth needs.
Observability Engineer at Universal Music Group
LogicMonitor is pretty good at scaling things when it comes to monitoring AWS infrastructure because I can see that it scales very well for us.
Site Reliability Engineer at a comms service provider with 501-1,000 employees
We currently rely on disaster recovery and backup recovery, which takes time to recover, during which you're basically blind, so I'm pushing my leadership team to switch over to a clustering environment for constant availability.
IT Security Engineer at a financial services firm with 201-500 employees
It is one of the things that separates it from other tooling, and if not, it is the most scalable solution out there.
Systems Development Engineer at a tech vendor with 10,001+ employees
They struggle a bit with pure virtual environments, but in terms of how much they can handle, it is pretty good.
CTO at a tech vendor with 10,001+ employees
 

Stability Issues

Sentiment score
8.2
LogicMonitor is highly stable, with minimal downtime, reliable performance, and disruptions mainly due to user network configurations.
Sentiment score
7.5
Splunk Enterprise Security is stable and reliable, with occasional performance issues and bugs quickly resolved with proper setup.
The platform is reliable, alerts are consistent, and once collectors and integrations are in place, monitoring runs smoothly with minimal disruption.
Site Reliability Engineer at a comms service provider with 501-1,000 employees
It is very stable. I have never seen LogicMonitor itself go down.
Sr. Systems Engineer at a financial services firm with 201-500 employees
Since we implemented LogicMonitor and got it working in production, there has been no downtime, no reliability issues, and nothing major regarding flare-ups from LogicMonitor's perspective.
Observability Engineer at Universal Music Group
They test it very thoroughly before release, and our customers have Splunk running for months without issues.
Splunk System Engineer at a non-tech company with 11-50 employees
Splunk has been very reliable and very consistent.
Principal Engineer at Aviatrix
We need more SMEs, and there is no mechanism to tell us about indexer or search head issues.
Senior Manager at Bank of America
 

Room For Improvement

LogicMonitor users want improved automation, intuitive interfaces, advanced monitoring, and streamlined features for better ease of use and management.
Splunk Enterprise Security requires enhancements in visualizations, ease of use, AI integration, and improved documentation and training.
I would also appreciate a stronger out-of-the-box AWS correlation, such as automatically grouping related issues across EC2, EBS, and ALBs in a way that reads as a single incident story.
Site Reliability Engineer at a comms service provider with 501-1,000 employees
I wish the user interface would be customizable to allow users to create personal context-specific workspaces to hide irrelevant data, rather than trying to have a one-size-fits-all interface.
IT Infrastructure Engineer at Ethical Trade SErvices Africa
The container monitoring seems to be really behind compared to some bespoke cloud-native monitoring solutions that are designed around Kubernetes, containers, and ephemeral environments.
Sr. Systems Engineer at a financial services firm with 201-500 employees
Improving the infrastructure behind Splunk Enterprise Security is vital—enhanced cores, CPUs, and memory should be prioritized to support better processing power.
Resident Consultant (Security Analyst) at helpag
Splunk Enterprise Security is not something that automatically picks things; you have to set up use cases, update data models, and link the right use cases to the right data models for those detections to happen.
Security & Risk Analyst at a computer software company with 1,001-5,000 employees
For any future enhancements or features, such as MLTK and SOAR platform integration, we need more visibility, training, and certification for the skilled professionals who are working.
Security Consultant at Matiq
 

Setup Cost

LogicMonitor is a comprehensive, competitively priced monitoring solution with robust features but may have confusing cloud licensing.
Splunk Enterprise Security is costly but valued for its extensive functionality, appealing mainly to larger enterprises with flexible licensing.
For small businesses that want to utilize LogicMonitor and are just starting out with limited customers, a pricing model targeted to this segment would be beneficial, perhaps at three or two dollars per device per month.
Network Security Engineer at a consultancy with 10,001+ employees
I experienced no issues with pricing, setup cost, and licensing; it was very transparent, and the licensing model is very clear and easy to understand.
Technical Lead: Enterprise Monitoring at a retailer with 10,001+ employees
I saw clients spend two million dollars a year just feeding data into the Splunk solution.
CTO at a tech vendor with 10,001+ employees
The platform requires significant financial investment and resources, making it expensive despite its comprehensive features.
System Engineer - Security Presales at Raya Integration
I find it to be affordable, which is why every industry uses it.
Vice President Research And Development at OSINT Ambition
 

Valuable Features

LogicMonitor provides customizable dashboards, comprehensive visualization, and user-friendly features for efficient, reliable, and adaptable monitoring solutions.
Splunk Enterprise Security enhances threat detection and response with risk-based alerting, integration, and advanced visualization for cybersecurity teams.
The dynamic alerting and root cause analysis have helped us fix issues before they cause a full-blown outage or degrade performance for end users.
IT Infrastructure Engineer at Ethical Trade SErvices Africa
Our SLAs and SLOs were averaging about 10 to 15 failed SLAs and SLOs that were over the time allotted to get those resolved, and those are now down to about two to three per week.
Observability Engineer at Universal Music Group
When talking about the statistics, it has helped us reduce downtime to about 40 to 50% because without LogicMonitor, we used to know about the downtime only when the application was actually down.
Site Reliability Engineer at a comms service provider with 501-1,000 employees
This capability is useful for performance monitoring and issue identification.
Staff Performance Engineer at ServiceNow
I assess Splunk Enterprise Security's insider threat detection capabilities for helping to find unknown threats and anomalous user behavior as great.
Splunk System Engineer at a non-tech company with 11-50 employees
Splunk Enterprise Security provides the foundation for unified threat detection, investigation, and response, enabling fast identification of critical issues.
Specialist-Infrastructure Opertions at Allianz Technology
 

Categories and Ranking

LogicMonitor
Average Rating
9.0
Reviews Sentiment
7.1
Number of Reviews
34
Ranking in other categories
Application Performance Monitoring (APM) and Observability (13th), Network Monitoring Software (6th), IT Infrastructure Monitoring (8th), Container Monitoring (4th), Cloud Monitoring Software (7th), AIOps (5th)
Splunk Enterprise Security
Average Rating
8.4
Reviews Sentiment
7.3
Number of Reviews
381
Ranking in other categories
Log Management (2nd), Security Information and Event Management (SIEM) (1st), IT Operations Analytics (1st)
 

Mindshare comparison

While both are Application Lifecycle Management solutions, they serve different purposes. LogicMonitor is designed for IT Infrastructure Monitoring and holds a mindshare of 2.8%, up 2.2% compared to last year.
Splunk Enterprise Security, on the other hand, focuses on Security Information and Event Management (SIEM), holds 7.2% mindshare, down 9.8% since last year.
IT Infrastructure Monitoring Mindshare Distribution
ProductMindshare (%)
LogicMonitor2.8%
Zabbix6.1%
Datadog4.1%
Other87.0%
IT Infrastructure Monitoring
Security Information and Event Management (SIEM) Mindshare Distribution
ProductMindshare (%)
Splunk Enterprise Security7.2%
Wazuh5.8%
IBM Security QRadar5.3%
Other81.7%
Security Information and Event Management (SIEM)
 

Featured Reviews

Anshuman Thakur - PeerSpot reviewer
Site Reliability Engineer at a comms service provider with 501-1,000 employees
Monitoring has reduced downtime and now enables proactive alerts across cloud workloads
When it comes to the improvement of LogicMonitor, I think there are a few points that can be improved. The first one is alert tuning, which takes time. It requires effort when trying to understand it for the first time. The defaults do not always match our workload patterns, so I have to adjust the thresholds to reduce noise and avoid alert fatigue. While the dashboards are solid, I sometimes wish that the UI was a bit more intuitive when drilling down quickly during an incident. There are many options and finding the exact view where I can identify the exact problem takes a few extra clicks. When an alert comes and I click on a LogicMonitor alert, it takes time to understand what the alert actually is and to go through the data points. The alert page specifically could be better. The alert tuning part can also be made more simple. The first area that could be better is alert clarity and routing. Sometimes alerts do not include enough immediate context, so I still have to spend a few minutes correlating data across views. Adding more actionable details directly in the alert would make the response even faster. LogicMonitor sometimes gives false alerts as well. For example, if an EC2 instance is down, it will not determine whether the EC2 instance has been deliberately turned off or if it is actually not responding. At that time, it will give false alerts. The clearing of alerts is also an issue. Once an issue is fixed, the alert should be cleared, but it takes a little time for that alert to be cleared. Another improvement that would be helpful is simpler customization for complex dashboards. It is powerful, but building highly tailored dashboards, especially across multiple environments, can feel heavy and time-consuming. I would also appreciate a stronger out-of-the-box AWS correlation, such as automatically grouping related issues across EC2, EBS, and ALBs in a way that reads as a single incident story. This would reduce the mental overhead during outages. Grouping incidents together, such as all the EC2 alerts, all the EBS alerts, or all the load balancer alerts would be beneficial. Overall, none of these are blockers, just some improving areas. There could be smarter anomaly detection out of the box that can catch unusual but important behavior without manual tuning of every threshold. Better tagging and dynamic grouping for EC2 instances would also be helpful. Cleaner alert de-duplication so a single underlying issue does not generate multiple redundant alerts would improve the system. More guided root cause workflows would be beneficial, such as providing the most likely causes based on correlated metrics. Faster search navigation across devices, dashboards, and alerts during incidents would also improve the platform.
Sathis-Kumar - PeerSpot reviewer
Senior Manager at Bank of America
Helps us detect cyber threats quickly and integrate multiple feeds effectively
Overall, the product is good, but when it comes to some infrastructure issues, we have to dig into more logs. There is no straightforward indication of an issue. Health check kind of dashboards are not available. More AI would help us, and more optimization, since security products run more queries. The AI module could suggest solutions, optimizing queries or workload balancing. If the product itself advises on running queries during peak times, it would be similar to what ChatGPT currently offers. We see quite a few issues on stability. Even last week, we faced something, and identifying bottlenecks is not easy. We need more SMEs, and there is no mechanism to tell us about indexer or search head issues. Self-monitoring dashboards could be beneficial. The technical support still requires more improvement. Often, primary support takes a lot of time and forwards most solutions to the engineering side. The primary support team has very limited knowledge to provide.
report
Use our free recommendation engine to learn which IT Infrastructure Monitoring solutions are best for your needs.
885,667 professionals have used our research since 2012.
 

Comparison Review

VS
Manager, Enterprise Risk Consulting at a tech company with 1,001-5,000 employees
Feb 26, 2015
HP ArcSight vs. IBM QRadar vs. ​McAfee Nitro vs. Splunk vs. RSA Security vs. LogRhythm
We at Infosecnirvana.com have done several posts on SIEM. After the Dummies Guide on SIEM, we are following it up with a SIEM Product Comparison – 101 deck. So, here it is for your viewing pleasure. Let me know what you think by posting your comments below. The key products compared here are…
 

Top Industries

By visitors reading reviews
Manufacturing Company
11%
Computer Software Company
10%
Financial Services Firm
9%
Healthcare Company
8%
Financial Services Firm
12%
Computer Software Company
9%
Manufacturing Company
9%
Government
6%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business13
Midsize Enterprise11
Large Enterprise11
By reviewers
Company SizeCount
Small Business112
Midsize Enterprise50
Large Enterprise267
 

Questions from the Community

What is the best network monitoring software for large enterprises?
It actually depends on the exact purpose or requirements. Some tools are better for only network devices while others are better from a cloud monitoring or APM monitoring perspective. You can check...
What do you like most about LogicMonitor?
LogicMonitor helps us prevent potential downtime. It's pretty good. It generates low-level warnings that aren't necessarily preemptive but can still alert us to issues we should investigate. These ...
What is your experience regarding pricing and costs for LogicMonitor?
I researched the pricing of LogicMonitor, and it costs around ten dollars per device per month, which is somewhat expensive compared to other products. Some monitoring tools such as Zabbix are free...
What SOC product do you recommend?
For tools I’d recommend: -SIEM- LogRhythm -SOAR- Palo Alto XSOAR Doing commercial w/o both (or at least an XDR) is asking to miss details that are critical, and ending up a statistic. Also, rememb...
What is a better choice, Splunk or Azure Sentinel?
It would really depend on (1) which logs you need to ingest and (2) what are your use cases Splunk is easy for ingestion of anything, but the charge per GB/Day Indexed and it gets expensive as log ...
How does Splunk compare with Azure Monitor?
Splunk handles a high amount of data very well. We use Splunk to capture information and as an aggregator for monitoring information from different sources. Splunk is very good at alerting us if we...
 

Overview

 

Sample Customers

Kayak, Zendesk, Ted Baker, Trulia, Sophos, iVision, TekLinks, Siemens
Splunk has more than 7,000 customers spread across over 90 countries. These customers include Telenor, UniCredit, ideeli, McKenney's, Tesco, and SurveyMonkey.
Find out what your peers are saying about Zabbix, Datadog, Auvik and others in IT Infrastructure Monitoring. Updated: March 2026.
885,667 professionals have used our research since 2012.