

Sigma and Splunk Enterprise Platform compete in the data analysis and monitoring space. While Sigma is attractive for its pricing and customer service, Splunk Enterprise Platform is viewed as superior due to its robust features and value for the investment.
Features: Sigma provides powerful cloud-based analytics and collaboration tools, excelling in data visualization and integration capabilities. Splunk Enterprise Platform offers advanced machine learning, comprehensive search functions, and extensive data handling. Its broader feature set effectively addresses complex data analysis needs.
Ease of Deployment and Customer Service: Sigma is praised for straightforward cloud deployment and responsive customer service, with benefits for organizations seeking hassle-free setup. Splunk Enterprise Platform has a more complex installation but is supported by comprehensive resources and knowledgeable support, offsetting its intensive initial setup.
Pricing and ROI: Sigma's lower setup cost and rapid return on investment appeal to businesses with budget constraints. Its cost-effectiveness is balanced by Splunk's higher initial investment, justified by its extensive feature set and scalability, leading to substantial ROI for organizations with advanced data needs.
It's essential for everything data-related within our company.
I have seen a return on investment with Sigma; we already said that it saves about a quarter, it gets me to answers about 25% faster.
I have definitely seen a return on investment through time saving because once the dashboards are built, they are built.
Key impact areas are generally time saved in investigations, higher analyst productivity, lowered costs of security incidents due to faster detection and response, and reduced manual reporting effort.
Splunk Enterprise Platform helped reduce the time required to investigate incidents by centralizing logs and providing powerful search capabilities.
Splunk Enterprise Platform improved our reliability, and the time to investment ratio has been excellent.
Their support I really think is a 10 out of 10.
The support staff are all professional users of the product itself and they are available almost 24/7 and helped me to come up with solutions to all of the problems that I had.
As Sigma is a cloud platform, you do not need to do all that maintenance work.
We contacted support and they were able to provide us with the solution which is currently working fine.
It is crucial for anyone looking to deploy Splunk Enterprise Platform to first certify for their courses, such as the Splunk Administrator and the Power User Administrator certifications, which address all troubleshooting queries.
When we encounter issues, we utilize the Splunk community, which I believe showcases a big advantage of Splunk due to its strong community support.
Sigma seemed to scale just fine with our large data sets and could handle anything we threw at it.
Permissions are easily set, so you only get to see what you need to see and you can share what needs to be shared.
Splunk allows for scalability, as you can start with an all-in-one instance and, as your deployment grows, split it into distributed deployment, such as separating the search head and indexers.
It is highly stable and scalable for us.
In a day we get millions of hits for the APIs.
We did not face typical errors during our project with Sigma.
Our L1 and L2 teams get real-time alerts and query the SPL effectively without delays that other SIEM solutions may impose.
It is highly stable and scalable for us.
It requires managing configuration files and processing operations manually, limiting its auto-scaling capabilities.
The main improvement needed is in data modeling capabilities.
Sigma lacks a versioning feature to track changes.
It would be great if there was a way for me to create reports without relying on a data analyst.
The deep learning capabilities need enhancing, especially on Splunk Cloud, where customers find it challenging to use deep learning tools without setting up backend computing resources.
I could also build some pre-indexed summaries so that Splunk Enterprise Platform can search much faster than raw logs.
From an architectural standpoint, data onboarding, normalization, performance, and scalability improvements would be beneficial, particularly in optimizing search speed and query execution to handle larger searches efficiently.
The pricing of Sigma is a concern, as it restricts our ability to provide more users with report-creating capabilities due to the high cost of admin or report creator licenses.
The pricing model is based on ingesting data sizes, not user count, and includes a free tier for up to 500 MB of daily data.
We ingest terabytes of data, so I can say Splunk Enterprise Platform is somewhat costly.
The platform's ability to consolidate siloed tools into a single pane of glass provides immense value justifying the premium cost if the architecture is tightly managed.
The use of Sigma in decision-making, presentations to customers, and reporting to investors showcases its value in handling data-related tasks.
Sigma has positively affected my organization by saving us time in accessing information, which ultimately gets us to complete projects faster.
Sigma has positively impacted my organization because I think it has been a huge impact, and we use it for all our reporting and our dashboards for tracking.
Splunk Enterprise Platform also has its own Phantom as a SOAR, which is much more refined and gives more accurate results than any other AI integrated SIM tool.
The anomaly detection is very good for live production data. Whenever an anomaly comes in an application, it automatically resolves and just gives the notification.
Splunk Enterprise Platform will create an incident and detect this as a credential compromise because we have a successful login from another location.
| Product | Mindshare (%) |
|---|---|
| Splunk Enterprise Platform | 1.4% |
| Sigma | 1.7% |
| Other | 96.9% |

| Company Size | Count |
|---|---|
| Small Business | 7 |
| Midsize Enterprise | 3 |
| Large Enterprise | 2 |
| Company Size | Count |
|---|---|
| Small Business | 34 |
| Midsize Enterprise | 8 |
| Large Enterprise | 43 |
Sigma enhances data tasks with an Excel-like interface, encouraging collaboration and non-technical user engagement. Its strengths include handling vast datasets and facilitating real-time data exploration, appealing to industries aiming for data-driven decision-making.
Sigma stands out with its capabilities for real-time collaboration and ease of use due to its Excel-inspired interface. It supports engagement with large datasets and prioritizes strong data governance. Key features include live queries on cloud databases and seamless integration with Snowflake. Its AI capabilities and self-service access help users perform detailed reporting and pivot table creation from extensive datasets, significantly affecting organizational efficiency and decision-making processes.
What are Sigma's most important features?Sigma is predominantly used for creating dashboards, reporting, and data visualization. It assists in real-time data exploration and ad hoc analysis, connecting seamlessly with Snowflake for consistent data views. Sales teams use it for performance comparison dashboards, while marketing teams apply it for data migration assessments. Organizations leverage its comprehensive reporting and analytics for informed decision-making.
Splunk Enterprise Platform provides high flexibility and integration, featuring strong analytics, data ingestion, and real-time monitoring, catering to diverse industry needs and enhancing threat detection and data analysis.
Splunk Enterprise Platform is renowned for its powerful capabilities in log management, threat detection, and data visualization. It supports infrastructure monitoring and anomaly detection, crucial for Security Incident and Event Management operations. With its scalable architecture, users can efficiently manage data ingestion and create personalized dashboards, utilizing Splunk Processing Language for comprehensive querying and system performance assessment. This platform offers enhanced threat detection through its robust anomaly detection features and real-time monitoring capabilities, with machine learning enabling predictive analytics.
What features make Splunk Enterprise Platform stand out?In industries like finance, healthcare, and technology, Splunk Enterprise Platform is implemented to monitor infrastructure, manage logs, and enhance security protocols. Companies utilize its predictive analytics for strategic planning and operational efficiency, focusing on integration with AWS, EDR, and firewalls for comprehensive data visualization and threat management.
We monitor all Data Visualization reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.