Splunk Enterprise Security and ScienceLogic are leaders in the data collection and analysis sector. Splunk appears to have a slight edge with its rapid data searching capabilities and comprehensive integration options.
Features: Splunk Enterprise Security offers advanced operational intelligence with rapid data searching and comprehensive log management. It integrates machine learning and provides detailed visualization options. It collects and correlates data from various sources, offering flexible and fast queries through its Search Processing Language (SPL). ScienceLogic excels in infrastructure monitoring with strong customization features and dynamic application integration. It emphasizes network performance and device management, supported by its flexible API and multi-tenant capabilities.
Room for Improvement: Splunk Enterprise struggles with integrating operational workflows, its GUI is complex, and visualization tools need a more user-friendly approach. Improvements in usability and ticketing system integrations are necessary. ScienceLogic requires enhancements in network processing, a simplified user interface, and better integration with third-party platforms. Its reporting capabilities could also be improved.
Ease of Deployment and Customer Service: Splunk Enterprise Security is adaptable across public, private, hybrid clouds, and on-premises environments. While it has active community support, response times from customer service could be better. ScienceLogic is deployed in private and hybrid clouds, with strong vendor support, but requires significant customization efforts during deployment.
Pricing and ROI: Splunk Enterprise Security is known for its high costs, driven by data volume, positioning it for large enterprises. It yields significant ROI through operational efficiencies despite licensing expenses. ScienceLogic's flexible pricing based on device count can also become costly for extensive scalability. Both solutions offer substantial returns through improved efficiency and data insights.
The return on investment is fair but often challenged by medium-sized businesses who may question its adequacy.
I have noticed a return on investment with Splunk Enterprise Security, as it delivers substantial value for money.
Splunk's cost is justified for large environments with extensive assets.
Problems with Skylar may require longer wait times due to limited resource expertise.
I received excellent support from ScienceLogic.
If you want to write your own correlation rules, it is very difficult to do, and you need Splunk's support to write new correlation rules for the SIEM tool.
I have sought assistance from Splunk Enterprise Security support in the past, particularly during deployment, and they provide friendly and effective help.
The technical support for Splunk met my expectations.
They struggle a bit with pure virtual environments, but in terms of how much they can handle, it is pretty good.
It is easy to scale.
I find it easy to scale Splunk Enterprise Security for our environment.
Stability should relate to whether the platform fails, stops working, or breaks.
It provides a stable environment but needs to integrate with ITSM platforms to achieve better visibility.
It is very stable.
While some other companies have easier APIs, using this solution demands significant expertise.
If the knowledge for implementation could be spread through articles, it would reduce this dependency.
Integrating observability and APM monitoring into the overall portfolio would be beneficial.
Improving the infrastructure behind Splunk Enterprise Security is vital—enhanced cores, CPUs, and memory should be prioritized to support better processing power.
What Splunk could do better is to create an API to the standard SIEM tools, such as Microsoft Sentinel.
Splunk Enterprise Security would benefit from a more robust rule engine to reduce false positives.
It could be cheaper.
ScienceLogic is not that expensive and is cost-effective overall.
I saw clients spend two million dollars a year just feeding data into the Splunk solution.
The platform requires significant financial investment and resources, making it expensive despite its comprehensive features.
Splunk is priced higher than other solutions.
Notably, its automation features, such as Runbook action, enable domain experts like me to execute one-click automation solutions, which contributes significantly to reducing MTTR.
The solution excels in three areas: application monitoring, server monitoring, and network performance monitoring.
The CMDB update and the automatic CMDB update are valuable.
This capability is useful for performance monitoring and issue identification.
They have approximately 50,000 predefined correlation rules.
The Splunk Enterprise Security's threat-hunting capabilities have been particularly useful in later releases.
ScienceLogic is a comprehensive IT infrastructure monitoring solution that supports networks, servers, cloud environments, and applications, suitable for private cloud and on-premises deployments.
Organizations leverage ScienceLogic for its robust capabilities in monitoring IT infrastructures of all sizes. It offers granular discovery, integration with CMDB, and ticketing systems. Valued for its flexibility, incident automation, remediation, and real-time relationship mapping, it supports hybrid environments with scalable and efficient monitoring functionalities. AI and machine learning enhance its feature set, while ease of deployment and strong support are crucial benefits.
What are ScienceLogic's most important features?ScienceLogic is implemented across multiple industries, including large enterprises, for its capability to handle complex IT ecosystems. Its integration with CMDB and ticketing systems ensures it fits within existing workflows. Organizations use it to monitor diverse infrastructure landscapes, ensuring seamless performance and quick incident resolution.
Splunk Enterprise Security is widely used for security operations, including threat detection, incident response, and log monitoring. It centralizes log management, offers security analytics, and ensures compliance, enhancing the overall security posture of organizations.
Companies leverage Splunk Enterprise Security to monitor endpoints, networks, and users, detecting anomalies, brute force attacks, and unauthorized access. They use it for fraud detection, machine learning, and real-time alerts within their SOCs. The platform enhances visibility and correlates data from multiple sources to identify security threats efficiently. Key features include comprehensive dashboards, excellent reporting capabilities, robust log aggregation, and flexible data ingestion. Users appreciate its SIEM capabilities, threat intelligence, risk-based alerting, and correlation searches. Highly scalable and stable, it suits multi-cloud environments, reducing alert volumes and speeding up investigations.
What are the key features?Splunk Enterprise Security is implemented across industries like finance, healthcare, and retail. Financial institutions use it for fraud detection and compliance, while healthcare organizations leverage its capabilities to safeguard patient data. Retailers deploy it to protect customer information and ensure secure transactions.
We monitor all IT Operations Analytics reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.