Try our new research platform with insights from 80,000+ expert users

NetWitness Platform vs OpenText Enterprise Security Manager vs Splunk Enterprise Security comparison

 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Mindshare comparison

As of August 2025, in the Security Information and Event Management (SIEM) category, the mindshare of NetWitness Platform is 0.6%, down from 0.7% compared to the previous year. The mindshare of OpenText Enterprise Security Manager is 1.4%, up from 1.3% compared to the previous year. The mindshare of Splunk Enterprise Security is 9.4%, down from 11.8% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Security Information and Event Management (SIEM)
 

Featured Reviews

MOTASHIM Al Razi - PeerSpot reviewer
It is a stable solution, but they should make the user interface easier to understand
The solution's initial setup takes work. We have to organize multiple paths and many features. The deployment process takes less than a week. But it takes a month to complete if we want to make the solution smarter by integrating it with various devices. I rate the process as a six out of ten.
Gaurav Ranade - PeerSpot reviewer
Excels at performing regression and correlation on the data
ArcSight is a legacy technology, and many customers want AI-powered technologies integrated with it. That hasn't been done yet, but ArcSight needs to catch up with the newer solutions and technologies available in the market. It can't just rely on the legacy technology from 2010 or 2012. You can't run that in 2024. It's a legacy technology with its own limitations. Customers often face issues that other software or newer solutions can resolve easily. That's the main challenge we face from customers right now. So, the only concerns are that AI needs to be integrated and scalability improved. Those are the main areas to be improved.
ROBERT-CHRISTIAN - PeerSpot reviewer
Has many predefined correlation rules and is brilliant for investigation and log analysis
It is very complicated to write your own correlation rules without the help of Splunk support. What Splunk could do better is to create an API to the standard SIEM tools, such as Microsoft Sentinel. The idea would be to make it less painful. In ELK Stack, Kibana is the query language with which you can search log files. I believe Splunk has also a query language in which they search their log files, but once you have identified the log file that you want to use for further security correlation, you want to very quickly transport that into your SIEM tool, such as Microsoft Sentinel. That is something that Splunk could make a little bit less painful because it is a lot of effort to find that log file and forward it. An API with Microsoft Sentinel or a similar SIEM tool would be a good idea.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"It gives the ability to investigate into network traffic in the Net and the organization what we couldn't do before."
"The most valuable feature is the hunting ability to work in a CERT."
"The most valuable features are the packet decoder, log decoder, and concentrator."
"NetWitness Platform is valuable for creating rules that the solution must detect."
"The most valuable feature is the ability to write rules and triggers for network communication, and then being able to investigate based on that."
"The most valuable features are the packet inspection and the automated incident response."
"Possibility to investigate incidents based on logs and raw packets, such as extracting files sent over the network"
"The most valuable feature is that we can create our own connectors for any application, and NetWitness provides the training and tools to do it."
"The tool is good for correlation and aggregation. We use it as a collection platform."
"The solution offers very good monitoring."
"I value the event correlation of this product."
"ArcSight Enterprise Security Manager (ESM) is very cheap compared to other tools."
"I really like the correlation part and the way the logs are correlated. I have never faced issues with parsing in this product. I like the way it parses, and everything is so clear to me."
"It prevented my users from getting infected by ransomware. It can also pinpoint the story behind every virus or network attack to our environment."
"Once the rules are defined, it becomes easy to detect changes and generate automated logs."
"On the positive side, ArcSight ESM's performance was excellent. It was very fast when writing queries. It provided good performance monitoring and had built-in rules to show which rules triggered most often and impacted performance. This performance monitoring was well-implemented."
"Splunk has facilitated the correlation of information security logs to look for incidents which could cause damage to the company's infrastructure, as well as financial losses from leaks."
"Splunk Enterprise Security gives us a single pane of glass so that we can use just one tool instead of having to use different tools."
"The user interface is excellent, and since I'm using Splunk as a power user, it's easy to create dashboards."
"The most valuable aspect of the solution is the dashboard. It's very intuitive."
"The security part is useful as it helps secure the entire environment."
"The product is adept at log mining."
"The product has a good security posture."
"The most valuable features in Splunk Enterprise Security are the cluster capabilities."
 

Cons

"We have encountered issues with unresolved crashes."
"Nowadays, their support is a little subpar compared to other solutions. I rate RSA support six out of 10."
"It is not so easy to customize this product."
"Technical support could be improved."
"The solution should have more integration capabilities with different platforms."
"The system looks like it is a mix of a bunch of different systems, and nothing looked like it was quite together."
"The implementation needs assistance."
"The initial setup is complex. There are other solutions that are easier to implement."
"The analytics feature is not reliable and needs improvement for more detailed analysis.​"
"Customer service during the transition from HPE to Micro Focus was abysmal where it became disruptive to our service delivery."
"I would like to have a feature that gives us an entire report listing what devices are integrated."
"The initial setup could be more straightforward."
"There are several improvements that we would like to see, including: Building a system based on a log collection (SOC), a scenario for external encroachment, and Operator training."
"The onboarding process for this solution could be better. It also needs a better GUI."
"When we need to consume old events, we have to wait for a long time. ArcSight should improve the database capability to reply to queries faster. It would also be interesting if they implemented network visibility. For example, they could add a feature like NetWitness with a model just for looking through the packets."
"ArcSight ESM is lacking cloud scalable technology."
"The level of scalability depends on the license you have. You can expand or reduce it based on the environment. It does cost more money to scale, however."
"The solution is expensive."
"More training on PetaData using artificial intelligence techniques to identify the events which are not normal and exceptions that would help the organization identify threats and malware on the go with results."
"It's difficult to set up initially, and their billing model is also a bit complicated."
"Spam has different plugins but by default, the logs are not organized, it shows that there are roll-ups that are out of the box. I saw many plugins that can help improve or extend Splunk's functionality but I haven't tried any of them."
"The solution could improve by making it more business analysis oriented. The way it is now is designed more for developers."
"Splunk Enterprise Security would benefit from a more robust rule engine to reduce false positives."
"​Not even Splunk's support guy, who came to our firm, could help with defining proper role management.​"
 

Pricing and Cost Advice

"We have yearly licensing costs. The license fee can be based on the volume of EPS. Some organizations may have, as a gentlemanly gesture, 10,000 EPS and get a 3,000 EPS license but actually use 5,000 EPS."
"The new pricing and licensing mechanisms are fair. I would advise always to get the full solution (i.e., not only Logs)."
"In comparison to other SIEM solutions such as Splunk, NetWitness is less costly."
"RSA NetWitness Logs and Packets do not have a subscription model, it's a one-time purchase. There is only a perpetual license."
"The licenses are good but the cost is very expensive."
"The tool is very expensive, so I rate the pricing a ten out of ten. The solution has an annual subscription."
"The product price was reasonable for my region and the market."
"It’s cheaper to run virtual machines in a VMware environment."
"​It is best to be an institutional buyer and directly contact the sales team, as they can provide over-the-top discounts for bulk orders.​"
"We're paying a fee for an MSSP, and the cost of the total cost of ArcSight ESM was approximately three to four million dollars a year. The price was less than similar solutions. We did not have additional fees."
"The product licenses are inexpensive."
"There is a license required for this solution."
"The cost of the solution is not very high, although hiring a qualified analyst to work with the product is expensive."
"The pricing model is expensive compared to open-source alternatives."
"Customers without a ton of resources to dedicate to deployment may be better served by a managed ArcSight service."
"ArcSight ESM is an affordable solution, it cost approximately $200,000 for three years. This price was at a substantial discount."
"We have seen ROI and improvements as we have continued to use the product, but they are more reactive."
"Free Splunk license for PoCs on personal machines and the ability to scale the PoC to an enterprise level app."
"It can be tough to determine if you are getting all of the value out of your investment at times."
"The solution is costly."
"Expensive compared to other options."
"Splunk should be able to integrate with other product using the free version."
"Our ROI is high."
"The price of this solution is expensive. However, it has great features. If you want a great solution you need to pay a price matching the features."
report
Use our free recommendation engine to learn which Security Information and Event Management (SIEM) solutions are best for your needs.
865,164 professionals have used our research since 2012.
 

Comparison Review

VS
Feb 26, 2015
HP ArcSight vs. IBM QRadar vs. ​McAfee Nitro vs. Splunk vs. RSA Security vs. LogRhythm
We at Infosecnirvana.com have done several posts on SIEM. After the Dummies Guide on SIEM, we are following it up with a SIEM Product Comparison – 101 deck. So, here it is for your viewing pleasure. Let me know what you think by posting your comments below. The key products compared here are…
 

Top Industries

By visitors reading reviews
Financial Services Firm
13%
Computer Software Company
13%
Comms Service Provider
6%
Manufacturing Company
6%
Financial Services Firm
15%
Computer Software Company
13%
Manufacturing Company
11%
Educational Organization
7%
Computer Software Company
14%
Financial Services Firm
14%
Manufacturing Company
8%
Government
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

What do you like most about NetWitness Platform?
The product's initial setup phase was not at all difficult.
What is your experience regarding pricing and costs for NetWitness Platform?
The pricing is comparable to others, and I consider the cost to be intermediate. Specific cost details are unknown to...
What needs improvement with NetWitness Platform?
There is currently no need for improvement in the SIEM ( /categories/security-information-and-event-management-siem )...
Which is the best SIEM tool for a mid-sized financial services firm: Arcsight or Securonix?
In my market, a lot of financial companies had or have an ArcSight installation. Just because in former times it was ...
What do you like most about ArcSight Enterprise Security Manager (ESM)?
We utilize ArcSight ESM for real-time threat detection in our organization. We have custom rules that we've developed...
What is your experience regarding pricing and costs for ArcSight Enterprise Security Manager (ESM)?
ArcSight Enterprise Security Manager (ESM) is very cheap compared to other tools. It is worth the investment if you a...
What SOC product do you recommend?
For tools I’d recommend: -SIEM- LogRhythm -SOAR- Palo Alto XSOAR Doing commercial w/o both (or at least an XDR) is a...
What is a better choice, Splunk or Azure Sentinel?
It would really depend on (1) which logs you need to ingest and (2) what are your use cases Splunk is easy for ingest...
How does Splunk compare with Azure Monitor?
Splunk handles a high amount of data very well. We use Splunk to capture information and as an aggregator for monitor...
 

Also Known As

RSA Security Analytics
Micro Focus ArcSight, HPE ArcSight, ArcSight
No data available
 

Overview

 

Sample Customers

Los Angeles World Airports, Reply
Lake Health, U.S. Department of Health and Human Services, Bank AlJazira, Banca Intesa, and Obrela.
Splunk has more than 7,000 customers spread across over 90 countries. These customers include Telenor, UniCredit, ideeli, McKenney's, Tesco, and SurveyMonkey.
Find out what your peers are saying about Splunk, Wazuh, Microsoft and others in Security Information and Event Management (SIEM). Updated: August 2025.
865,164 professionals have used our research since 2012.