Try our new research platform with insights from 80,000+ expert users

OpenText SiteScope vs Splunk Enterprise Security comparison

 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

OpenText SiteScope
Average Rating
7.8
Reviews Sentiment
6.5
Number of Reviews
28
Ranking in other categories
Application Performance Monitoring (APM) and Observability (25th)
Splunk Enterprise Security
Average Rating
8.4
Reviews Sentiment
7.3
Number of Reviews
369
Ranking in other categories
Log Management (2nd), Security Information and Event Management (SIEM) (1st), IT Operations Analytics (1st)
 

Mindshare comparison

While both are Application Lifecycle Management solutions, they serve different purposes. OpenText SiteScope is designed for Application Performance Monitoring (APM) and Observability and holds a mindshare of 0.6%, up 0.5% compared to last year.
Splunk Enterprise Security, on the other hand, focuses on Security Information and Event Management (SIEM), holds 8.7% mindshare, down 10.9% since last year.
Application Performance Monitoring (APM) and Observability Market Share Distribution
ProductMarket Share (%)
OpenText SiteScope0.6%
Dynatrace8.1%
Datadog6.6%
Other84.7%
Application Performance Monitoring (APM) and Observability
Security Information and Event Management (SIEM) Market Share Distribution
ProductMarket Share (%)
Splunk Enterprise Security8.7%
Wazuh9.3%
IBM Security QRadar6.5%
Other75.5%
Security Information and Event Management (SIEM)
 

Featured Reviews

Gyanesh Rahatekar - PeerSpot reviewer
Achieve seamless incident response with valuable monitoring capabilities and reliable alerts
There are multiple features related to OpenText SiteScope monitoring that I have found to be very useful, such as SSL monitoring. If SSL is present as a file in a server, then OpenText SiteScope is a very effective tool to monitor when that certificate expires. It provides comprehensive information related to SSL certificates and log monitoring. If any kind of required keyword monitoring is present in the log file, OpenText SiteScope has excellent functionality for monitoring. It is very easy to configure and obtain the correct information related to end-user requirements. The agentless monitoring feature of OpenText SiteScope is particularly impressive and easy to configure and gather information from. According to the operations team perspective, there is no impact related to resource management from the agentless monitoring. It demonstrates very low resource consumption related to its functionality.
Kyle Vernham - PeerSpot reviewer
Built-in searches and unified data access streamline alert investigation and boosts analyst efficiency
The two features I appreciate the most in Splunk Enterprise Security are the built-in searches, which have been very easy for us to get started with right out of the box, and the fact that it accesses all of our other systems. You can access it as a pane of glass rather than having to search individually. We also have the option to compare our analysts from our service to service. Splunk Enterprise Security helps our SOC team prioritize and investigate high-fidelity alerts more effectively by providing a more in-depth look and the ability to access a lot more of our data. Instead of jumping from several segmented systems, it allows us to have everything brought together in one place. For example, you have to move from our purview to our build system and to Splunk Enterprise Security, and it enables us to streamline that process. The built-in features of Splunk Enterprise Security, which we recently procured, have given us a good starting point and demonstrated the value of the product, providing an easy way to sell it to our company. The ease of getting everything into our purview helps us, and it serves as a good start for the investigation part in one location rather than what we usually have, which is jumping from system to system to system. Splunk Enterprise Security plays a role in our company's strategy to combat insider threats and advanced persistent threats by currently being in its technical test phase. We are still rolling it out, and it should help us find any insider threats based on information that our policy states should not be present in our system. Splunk Enterprise Security's risk-based alerting (RBA) has impacted our alert volume and analyst productivity because we've got many different systems feeding into it. However, it has helped to make it easier for our analysts to go through a set of events rather than 100 alerts. RBA allows us to streamline the process and customize it for our analysts. When it comes to leveraging Splunk Enterprise Security's dashboards and visualizations to communicate security posture to executives, it's pretty straightforward for any type of information. The visualization is easy to understand, but I haven't had any direct conversations with our executives.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"Simple deployment: The deployment uses protocols such as NetBios, SSH, WMI, SNMP, which means that any device with any of these protocols will be monitored."
"Simplest tool for monitoring servers, web content, databases and other hardware. Its dashboard is really good."
"It's a very flexible product so you can run a script out of it, even straight out of the box."
"It can monitor over a 100 technologies with built-in solution templates."
"The most valuable feature of SiteScope is its infrastructure monitoring."
"It's integrated with different monitoring tools, such as AppDynamics."
"Our experiences with Micro Focus SiteScope have been mostly positive as we can easily work with multiple monitors and different types of monitors pretty quickly. There are a lot of out-of-the-box solutions for us through Micro Focus SiteScope, so we don't have to do that much custom coding for the vast majority of requests that we get for monitoring. There are some limitations that we've run into and some problems every once in a while, but they've been relatively minor."
"The most valuable feature of OpenText SiteScope is that it is easy to manage and user-friendly."
"I am satisfied with the support."
"Splunk's strongest suit is its user interface. We can integrate multiple solutions and adjust settings in the Splunk interface."
"The stability and reliability of Splunk Enterprise Security is outstanding. It's a software and product that anybody can really pick up and use."
"The most valuable features are the logs, which allow us to identify what happened and who interacted with the web repository."
"The solution's most valuable feature is the aggregation of all the logs in one place, using enterprise securities built-in or ESCU use cases to find them."
"The metrics and trends that Splunk Enterprise Security generates using all the data points we send allow customers to understand better what their users are doing."
"The tool helps with advanced reports and keeps the system scalable and flexible. It provides a clear picture of the current status of any incidents. As a CISO, I see a lot of potential for future innovation, which is interesting. I've noticed better performance, especially with the reports."
"Splunk Enterprise Security is so easy as it scales with us as we grow."
 

Cons

"There is a need to enhance the reporting feature in OpenText SiteScope. Reporting related to performance information for historical data needs improvement to provide better reporting related to application availability and end node availability."
"Full application functionality available via the API. There are some functions you can perform managing monitors, that are only available through the UI."
"The graphs and dashboard in the solution are areas that need improvement."
"More out of the box Cloud integration and capabilities."
"I would be very interested in having transaction traceability included in the product, to give us a better view of what is really going wrong in a particular method and action."
"We have four or five data centers around North America where we have it deployed into a single or a two-server primary backup type of deployment. All those are made available under a single GUI provided by Micro Focus that allows you to put them all together. A room for improvement would be an appliance or a server that would manage all of our other servers so that I don't have to remember to log on to all different servers and data centers. I could manage them from a single location."
"While working with OpenText, I noticed sometimes teams refuse intervention due to compliance issues."
"The interface of OpenText SiteScope needs improvement. It has a Java-based interface, which is slow and could be simplified for better usability."
"There is a definite learning curve to starting out."
"Search head clustering is often temperamental in its current state and should be improved, replaced by something better, or be reverted to search head pooling."
"I would like more assistance with use cases and help with teaching us how to use it once it's installed."
"Splunk's implementation process for managing multiple indexes can be complex, especially when dealing with a large number of components."
"Splunk Enterprise Security can provide more details and help CISOs resolve vulnerability situations better. The reason is that the tools we choose for data analysis and log collection cannot collect all the data and logs. Splunk Enterprise Security should help me with this, but it cannot."
"While Splunk offers SOAR as a separate product, integrating it into the next version of Splunk Enterprise Security as a unified solution would be beneficial."
"There are limitations with Splunk not detecting all user activity, especially on mainframes and network devices."
"We find that the maintenance process could be a lot better."
 

Pricing and Cost Advice

"The product's pricing should be lower since there are many open-source products that can do the same job with better user interfaces. The tool's pricing is yearly and you need to pay for support."
"When Micro Focus Voltage SiteScope has introduced approximately eight years ago and there was not very much competition making the price high. However, when comparing the price of Micro Focus Voltage SiteScope now to other tools, they should reduce the price. It is similar to a legacy tool at this point."
"SiteScope licensing can be node based-or monitor-based. I would recommend for node-based licensing."
"The pricing or licensing cost for Micro Focus SiteScope is often bundled with other things, so the cost for each individual would be difficult to calculate. Pricing could be $2,000,000 a year. My company pays for technical support because it's part of the contract with Micro Focus SiteScope. You buy the licenses, but you're also paying for the support. With Nagios, it's much more bare-bones as far as paying for licenses and the software itself, and my company didn't have to use as much Nagios support yet in one or two years because there weren't too many problems using Nagios, and it's much more cost-effective, so that's one of the reasons why my company is migrating to Nagios from Micro Focus SiteScope."
"I rate the solution's pricing a six out of ten on a scale where one is cheap and ten is expensive."
"Licensing is a little steep."
"Depending on your requirements, there are two licensing models available. A simple point model, or an endpoint model."
"It is expensive. I don't like its licensing. I don't like anything where you have to license it by individual licenses. I'm not a fan of that, but that's just me."
"It can be cost-prohibitive when you start to scale and have terabytes of data. Its cost model is based on how much data it processes a day. If they're able to create scaled-down niche or custom package offerings, it may help with the cost. Instead of the full-blown features, if they can narrow the scope where it can only be used for a specific purpose, it would kind of create that market for the product, and it may help with the costing. When you start using it as a central aggregator and you're pumping tons of logs at it, pretty soon, you'll start hitting your cap on what it can process a day. Once you've got that, you're kind of defeating the purpose because you're going to have to scale back."
"Splunk Enterprise Security incurs a significant cost because of the amount of data we send, but we are fine with the value we're getting for that price."
"Splunk Enterprise Security is cheaper than competitors, but I do not know whether it is just our contract."
"It is quite expensive."
"Although Splunk is an expensive product, it is designed to be utilized across your organization in order to maximize your ROI and lower your TCO."
"Splunk Enterprise Security is an expensive solution."
"Splunk Enterprise Security is priced lower than competitors."
"Pricing can be a limiting factor. You have to continuously tune what you are bringing in and make sure what you bring in is of value."
report
Use our free recommendation engine to learn which Application Performance Monitoring (APM) and Observability solutions are best for your needs.
873,085 professionals have used our research since 2012.
 

Comparison Review

VS
Feb 26, 2015
HP ArcSight vs. IBM QRadar vs. ​McAfee Nitro vs. Splunk vs. RSA Security vs. LogRhythm
We at Infosecnirvana.com have done several posts on SIEM. After the Dummies Guide on SIEM, we are following it up with a SIEM Product Comparison – 101 deck. So, here it is for your viewing pleasure. Let me know what you think by posting your comments below. The key products compared here are…
 

Top Industries

By visitors reading reviews
Financial Services Firm
21%
Manufacturing Company
17%
Computer Software Company
8%
University
7%
Financial Services Firm
14%
Computer Software Company
14%
Manufacturing Company
8%
Government
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business8
Midsize Enterprise4
Large Enterprise20
By reviewers
Company SizeCount
Small Business110
Midsize Enterprise50
Large Enterprise257
 

Questions from the Community

What do you like most about Micro Focus Voltage SiteScope?
The most valuable feature of SiteScope is its infrastructure monitoring.
What is your experience regarding pricing and costs for Micro Focus Voltage SiteScope?
The licensing scheme for Micro Focus tools is reasonable, and more affordable. It's seen as medium or de-receivable.
What needs improvement with Micro Focus Voltage SiteScope?
The new version D2 has improved with a smart plan UI interface. However, while still using the classic WebTop UI, it looks outdated and not HTML5 compatible. They are currently in progress to migra...
What SOC product do you recommend?
For tools I’d recommend: -SIEM- LogRhythm -SOAR- Palo Alto XSOAR Doing commercial w/o both (or at least an XDR) is asking to miss details that are critical, and ending up a statistic. Also, rememb...
What is a better choice, Splunk or Azure Sentinel?
It would really depend on (1) which logs you need to ingest and (2) what are your use cases Splunk is easy for ingestion of anything, but the charge per GB/Day Indexed and it gets expensive as log ...
How does Splunk compare with Azure Monitor?
Splunk handles a high amount of data very well. We use Splunk to capture information and as an aggregator for monitoring information from different sources. Splunk is very good at alerting us if we...
 

Also Known As

Micro Focus SiteScope, HPE SiteScope, SiteScope
No data available
 

Overview

 

Sample Customers

Vodafone Ireland, Kuveyt Turk Participation Bank
Splunk has more than 7,000 customers spread across over 90 countries. These customers include Telenor, UniCredit, ideeli, McKenney's, Tesco, and SurveyMonkey.
Find out what your peers are saying about OpenText SiteScope vs. Splunk Enterprise Security and other solutions. Updated: May 2023.
873,085 professionals have used our research since 2012.