Splunk Observability Cloud and Microsoft Defender for Cloud compete in observability and security management. Splunk stands out in visual analytics and integration, while Microsoft Defender leads in security features and multi-cloud compatibility.
Features: Splunk Observability Cloud provides customizable dashboards and adaptable log analytics. It offers robust monitoring and integration with third-party tools to enhance infrastructure insights. Microsoft Defender for Cloud offers comprehensive security features, network policy enforcement, and integrates seamlessly across cloud environments with a focus on compliance.
Room for Improvement: Splunk users report high costs, complex setup, and wish for better automation and analysis. They also mention limited integration capabilities. Microsoft Defender for Cloud could improve usability and simplify its pricing. Users seek better management of false positives and more real-time updates.
Ease of Deployment and Customer Service: Splunk supports versatile deployments in on-premises, hybrid, and cloud settings and has generally well-received technical support but needs quicker response times. Microsoft Defender focuses on cloud-based deployments and benefits from integration within the Azure ecosystem for smoother support.
Pricing and ROI: Splunk Observability Cloud is perceived as expensive, affecting retention despite its features, while offering high ROI in efficiency. Microsoft Defender for Cloud also carries a complex pricing model but offers good ROI when bundled with Microsoft services. Affordability remains a concern for both in the long term.
Defender proactively indexes and analyzes documents, identifying potential threats even when inactive, enhancing preventative security.
Identifying potential vulnerabilities has helped us avoid costly data losses.
The biggest return on investment is the rapid improvement of security posture.
Since security is critical, we prefer a quicker response time.
The support team was very responsive to queries.
They understand their product, but much like us, they struggle with the finer details, especially with new features.
They often require multiple questions, with five or six emails to get a response.
They did respond to us, but they did not explicitly inform us about the feature's absence.
If any issues arise, we can raise a vendor case, and resolutions are provided in a timely and accurate manner.
We are using infrastructure as a code, so we do not have any scalability issues with Microsoft Defender for Cloud implementation because our cloud automatically does it.
It has multiple licenses and features, covering infrastructures from a hundred to five hundred virtual machines, without any issues.
Defender won't replace our endpoint XDR, but it will likely adapt and support any growth in the Microsoft Cloud space.
We've used the solution across more than 250 people, including engineers.
I would rate its scalability an eight out of ten.
Defender's stability has been flawless for us.
Microsoft Defender for Cloud is very stable.
Microsoft sometimes changes settings or configurations without transparency.
I would rate its stability a nine out of ten.
We rarely have problems accessing the dashboard or the page.
Microsoft, in general, could significantly improve its communication and support.
It would be beneficial to streamline recommendations to avoid unnecessary alerts and to refine the severity of alerts based on specific environments or environmental attributes.
The artificial intelligence features could be expanded to allow the system to autonomously manage security issues without needing intervention from admins.
There is room for improvement in the alerting system, which is complicated and has less documentation available.
Customers sometimes need to create specific dashboards, particularly for applicative metrics such as Java and process terms.
It would be beneficial if server details could be retrieved directly in synthetic monitoring.
Every time we consider expanding usage, we carefully evaluate the necessity due to cost concerns.
We appreciate the licensing approach based on employee count rather than a big enterprise license.
Microsoft Defender for Cloud is pricey, especially for Kubernetes clusters.
It appears to be expensive compared to competitors.
Splunk Observability Cloud is expensive.
The most valuable feature for me is the variety of APIs available.
This feature significantly aids in threat detection and enhances the user experience by streamlining security management.
The most valuable feature is the recommendations provided on how to improve security.
For troubleshooting, we can detect problems in seconds, which is particularly helpful for digital teams.
It offers unified visibility for logs, metrics, and traces.
Splunk APM provides a holistic view of the application.
Microsoft Defender for Cloud is a comprehensive security solution that provides advanced threat protection for cloud workloads. It offers real-time visibility into the security posture of cloud environments, enabling organizations to quickly identify and respond to potential threats. With its advanced machine learning capabilities, Microsoft Defender for Cloud can detect and block sophisticated attacks, including zero-day exploits and fileless malware.
The solution also provides automated remediation capabilities, allowing security teams to quickly and easily respond to security incidents. With Microsoft Defender for Cloud, organizations can ensure the security and compliance of their cloud workloads, while reducing the burden on their security teams.
Splunk Observability Cloud combines log search, data integration, and dashboards for seamless monitoring, enhancing infrastructure visibility and security. Its cloud integration and scalability support diverse environments, improving operational efficiency.
Splunk Observability Cloud offers comprehensive monitoring tools with user-friendly interfaces, enabling end-to-end infrastructure visibility. Its real-time alerting and predictive capabilities enhance security monitoring, while centralized dashboards provide cross-platform visibility. Users benefit from fast data integration and extensive insights into application performance. Despite its advantages, improvements could be made in integration with other tools, data reliability, scalability, and cost management. Users face challenges in configuration complexity and require better automation and endpoint protection features. Enhancing AI integration, alerts, and adaptation for high-throughput services could further improve usability.
What are the key features of Splunk Observability Cloud?In industries like finance and healthcare, Splunk Observability Cloud is implemented for application performance monitoring and infrastructure metrics. Its ability to track incidents and analyze machine data benefits network infrastructure, while distributed tracing and log analysis aid in tackling security threats. Organizations often integrate it for compliance and auditing purposes, enhancing visibility into network traffic and optimizing performance.
We monitor all Container Management reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.