Try our new research platform with insights from 80,000+ expert users

OpenText SiteScope vs Splunk Enterprise Security comparison

 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

OpenText SiteScope
Average Rating
7.8
Reviews Sentiment
7.7
Number of Reviews
26
Ranking in other categories
Application Performance Monitoring (APM) and Observability (34th)
Splunk Enterprise Security
Average Rating
8.4
Reviews Sentiment
7.6
Number of Reviews
308
Ranking in other categories
Log Management (2nd), Security Information and Event Management (SIEM) (1st), IT Operations Analytics (1st)
 

Mindshare comparison

While both are Application Lifecycle Management solutions, they serve different purposes. OpenText SiteScope is designed for Application Performance Monitoring (APM) and Observability and holds a mindshare of 0.5%, up 0.4% compared to last year.
Splunk Enterprise Security, on the other hand, focuses on Security Information and Event Management (SIEM), holds 9.5% mindshare, down 12.6% since last year.
Application Performance Monitoring (APM) and Observability
Security Information and Event Management (SIEM)
 

Featured Reviews

Ahmed Salman - PeerSpot reviewer
Instead of executing jobs multiple times, I can configure it once, schedule, and apply it on multiple servers in sequence
The system is really powerful; instead of executing jobs multiple times, I can configure it once, schedule, and apply it on multiple servers in sequence. It allows me to create scripts and automate several processes, making tasks simpler and more efficient. By using templates for systems or databases, I can monitor various needs easily, which saves time and increases productivity.
ROBERT-CHRISTIAN - PeerSpot reviewer
Has many predefined correlation rules and is brilliant for investigation and log analysis
It is very complicated to write your own correlation rules without the help of Splunk support. What Splunk could do better is to create an API to the standard SIEM tools, such as Microsoft Sentinel. The idea would be to make it less painful. In ELK Stack, Kibana is the query language with which you can search log files. I believe Splunk has also a query language in which they search their log files, but once you have identified the log file that you want to use for further security correlation, you want to very quickly transport that into your SIEM tool, such as Microsoft Sentinel. That is something that Splunk could make a little bit less painful because it is a lot of effort to find that log file and forward it. An API with Microsoft Sentinel or a similar SIEM tool would be a good idea.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"I find OpenText SiteScope itself to be uncomplicated and deserving of a ten out of ten due to its simplicity."
"The most valuable feature of OpenText SiteScope is that it is easy to manage and user-friendly."
"The product's readymade templates are perfect. It supports us a lot when we don't have much experience with the product. The templates offers us direction to proceed."
"SiteScope has built-in flat file DB, hence it removes the dependency of an external DB for higher stability."
"VM monitoring is pretty good showing good visualizations of how VMs are operating within the context of all the VMs running on the same hypervisor."
"Being able to create your monitors for monitoring your internal URLs and databases and other things like that is valuable."
"The Monitor Templates functionality allowed us to spin up monitoring with .csv files pretty easily."
"The URL monitoring is excellent."
"Splunk can deliver more information by going deeper. By creating a dashboard, we can identify the root cause of the threat. Let's say I have a firewall from Check Point. Splunk will find the dashboard for Check Point, implement it in our environment, and connect it to the Check Point firewall logs, which are shown on the dashboard. If we request a custom dashboard, the engineer will take longer to complete the task."
"With good domain knowledge, one can build almost anything. If you throw in Alert Manager or an integration with ServiceNow. Then, you have your own SIEM"
"It has increased our business resilience. It's a top-of-the-line SIEM security product. It's the best tool for our security analysts which helps them do their job better. That then protects our company from adversary actors."
"Integration with the cloud is pretty important and good for us. We found the integration with a lot of tools, not all tools yet, valuable. It does make the transfer of data, log files, and other things easier for us."
"It has a drag-and-drop interface, so you don't need to know SQL or Java to construct a query on Splunk. The resolution time is about the same, but it took longer to discover the issue with ArcSight. Our previous solution took about an hour or more, but Splunk can do it within a few minutes or an hour at most."
"The most valuable features for us include its robust log management capabilities, which allow us to efficiently handle and retain logs for extended periods as needed."
"Speeds up root cause analysis and can help identify issues that your organization never realized were occurring."
"Splunk helps us be more proactive. We can take predictive action to identify and block threats so that nothing harmful gets into the system."
 

Cons

"They should provide more templates for new vendor devices."
"The tool needs to support new technologies like Kubernetes. It also needs to improve scalability."
"While working with OpenText, I noticed sometimes teams refuse intervention due to compliance issues."
"It should improve its integrations with various tools, especially service management tools."
"We'd like a uniform interface for monitoring our system, since that's the purpose of SiteScope."
"They have not kept up with browser security requirements or advances in GUIs, they switched to a corruptible database architecture instead of text config files."
"While working with OpenText, I noticed sometimes teams refuse intervention due to compliance issues."
"We have four or five data centers around North America where we have it deployed into a single or a two-server primary backup type of deployment. All those are made available under a single GUI provided by Micro Focus that allows you to put them all together. A room for improvement would be an appliance or a server that would manage all of our other servers so that I don't have to remember to log on to all different servers and data centers. I could manage them from a single location."
"The default threat intel feeds create many false positives and noise, which is counterproductive."
"I think the only thing lacking is that there are some answers that I couldn't find about the tool without reaching out to support, and it had to be escalated to the engineering team."
"I want Splunk Enterprise Security to release more AI and machine learning features in the future."
"Deployment is not difficult but the lock sources and configurations can take time."
"Splunk can improve regex/asset analysis as we do not want to crawl until it is done."
"You can run a script from an event, but it needs many clicks to run that integration, which could be made easier."
"The configuration had a bit of a learning curve."
"The solution could improve by making it more business analysis oriented. The way it is now is designed more for developers."
 

Pricing and Cost Advice

"When Micro Focus Voltage SiteScope has introduced approximately eight years ago and there was not very much competition making the price high. However, when comparing the price of Micro Focus Voltage SiteScope now to other tools, they should reduce the price. It is similar to a legacy tool at this point."
"You have to pay for their "solution templates". Other tools do not charge you for knowledge-based monitoring bundles."
"Depending on your requirements, there are two licensing models available. A simple point model, or an endpoint model."
"The product's pricing should be lower since there are many open-source products that can do the same job with better user interfaces. The tool's pricing is yearly and you need to pay for support."
"I rate the solution's pricing a six out of ten on a scale where one is cheap and ten is expensive."
"The pricing or licensing cost for Micro Focus SiteScope is often bundled with other things, so the cost for each individual would be difficult to calculate. Pricing could be $2,000,000 a year. My company pays for technical support because it's part of the contract with Micro Focus SiteScope. You buy the licenses, but you're also paying for the support. With Nagios, it's much more bare-bones as far as paying for licenses and the software itself, and my company didn't have to use as much Nagios support yet in one or two years because there weren't too many problems using Nagios, and it's much more cost-effective, so that's one of the reasons why my company is migrating to Nagios from Micro Focus SiteScope."
"SiteScope licensing can be node based-or monitor-based. I would recommend for node-based licensing."
"Licensing is a little steep."
"It is expensive. I used to buy it early on, but then they combined it into a higher-up organization. They buy it for multiple systems now. Last time, I paid around 60K for it. There is just the licensing fee. That's all."
"Splunk Enterprise Security is expensive."
"The tool's pricing model is great. You can choose between workloads or volume."
"It is quite expensive."
"There is an annual license required to use this solution."
"The price can always be lower, but it is fair at the moment. The cost efficiencies depend on the licensing and how much data we are bringing in. We have a fairly large footprint, so it is cost-effective."
"I think that most of the monitoring solutions are expensive."
"It is expensive. I work for multiple clients. I am working for more than five clients, but most of the clients are switching from Splunk to Sentinel because of the cost. Even though Sentinel is very limited, clients are moving to Sentinel."
report
Use our free recommendation engine to learn which Application Performance Monitoring (APM) and Observability solutions are best for your needs.
850,900 professionals have used our research since 2012.
 

Comparison Review

VS
Feb 26, 2015
HP ArcSight vs. IBM QRadar vs. ​McAfee Nitro vs. Splunk vs. RSA Security vs. LogRhythm
We at Infosecnirvana.com have done several posts on SIEM. After the Dummies Guide on SIEM, we are following it up with a SIEM Product Comparison – 101 deck. So, here it is for your viewing pleasure. Let me know what you think by posting your comments below. The key products compared here are…
 

Top Industries

By visitors reading reviews
Financial Services Firm
35%
Manufacturing Company
14%
Computer Software Company
10%
Government
5%
Financial Services Firm
15%
Computer Software Company
14%
Manufacturing Company
8%
Government
8%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

What do you like most about Micro Focus Voltage SiteScope?
The most valuable feature of SiteScope is its infrastructure monitoring.
What is your experience regarding pricing and costs for Micro Focus Voltage SiteScope?
The licensing scheme for Micro Focus tools is reasonable, and more affordable. It's seen as medium or de-receivable.
What needs improvement with Micro Focus Voltage SiteScope?
While working with OpenText, I noticed sometimes teams refuse intervention due to compliance issues. Overcoming control restrictions for different applications could be improved.
What SOC product do you recommend?
For tools I’d recommend: -SIEM- LogRhythm -SOAR- Palo Alto XSOAR Doing commercial w/o both (or at least an XDR) is asking to miss details that are critical, and ending up a statistic. Also, rememb...
What is a better choice, Splunk or Azure Sentinel?
It would really depend on (1) which logs you need to ingest and (2) what are your use cases Splunk is easy for ingestion of anything, but the charge per GB/Day Indexed and it gets expensive as log ...
How does Splunk compare with Azure Monitor?
Splunk handles a high amount of data very well. We use Splunk to capture information and as an aggregator for monitoring information from different sources. Splunk is very good at alerting us if we...
 

Also Known As

Micro Focus SiteScope, HPE SiteScope, SiteScope
No data available
 

Overview

 

Sample Customers

Vodafone Ireland, Kuveyt Turk Participation Bank
Splunk has more than 7,000 customers spread across over 90 countries. These customers include Telenor, UniCredit, ideeli, McKenney's, Tesco, and SurveyMonkey.
Find out what your peers are saying about OpenText SiteScope vs. Splunk Enterprise Security and other solutions. Updated: May 2023.
850,900 professionals have used our research since 2012.