Try our new research platform with insights from 80,000+ expert users

SolarWinds Server and Application Monitor vs Splunk Enterprise Security comparison

 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

SolarWinds Server and Appli...
Average Rating
8.0
Reviews Sentiment
5.0
Number of Reviews
42
Ranking in other categories
Application Performance Monitoring (APM) and Observability (18th), Server Monitoring (12th), Active Directory Management (10th)
Splunk Enterprise Security
Average Rating
8.4
Reviews Sentiment
7.6
Number of Reviews
315
Ranking in other categories
Log Management (2nd), Security Information and Event Management (SIEM) (1st), IT Operations Analytics (1st)
 

Mindshare comparison

While both are Application Lifecycle Management solutions, they serve different purposes. SolarWinds Server and Application Monitor is designed for Server Monitoring and holds a mindshare of 2.5%, down 3.2% compared to last year.
Splunk Enterprise Security, on the other hand, focuses on Security Information and Event Management (SIEM), holds 9.5% mindshare, down 12.4% since last year.
Server Monitoring
Security Information and Event Management (SIEM)
 

Featured Reviews

Carlos Camargo - PeerSpot reviewer
Provides user-friendly API features and has straightforward deployment process
One product area that could benefit from improvement is the synchronization of licensing periods across different modules. The misalignment of licensing terms can present commercial challenges when adding new modules or additional pollers. Additionally, the granularity of polling times for specific components could be enhanced to better meet individual customers' needs without impacting the entire polling pool.
ROBERT-CHRISTIAN - PeerSpot reviewer
Has many predefined correlation rules and is brilliant for investigation and log analysis
It is very complicated to write your own correlation rules without the help of Splunk support. What Splunk could do better is to create an API to the standard SIEM tools, such as Microsoft Sentinel. The idea would be to make it less painful. In ELK Stack, Kibana is the query language with which you can search log files. I believe Splunk has also a query language in which they search their log files, but once you have identified the log file that you want to use for further security correlation, you want to very quickly transport that into your SIEM tool, such as Microsoft Sentinel. That is something that Splunk could make a little bit less painful because it is a lot of effort to find that log file and forward it. An API with Microsoft Sentinel or a similar SIEM tool would be a good idea.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"The application dependency feature identifies issues between applications and servers or within the network where the application is hosted. It highlights related problems, whether related to packet processing or other issues, enabling the creation of alerts and reports accordingly."
"We use the solution as a central monitoring tool. We use it to monitor every transaction that has a relation to the organization’s infrastructure."
"I adore the NTA module that provides deep details on ingress/egress traffic for any interface. With a few clicks, you can correlate who is accessing what and when, beside the bandwidth consuming applications/users."
"The more valuable feature of this solution is the Exchange feature."
"I am impressed with the tool's AppStack feature which mainly helps us in the identification process. This feature can give an overview of the fault and help us identify the issues for performance degradation. Instead of looking at multiple places, we can look at a single place to identify the issues."
"There are many valuable features, including the network configuration manager, and the network performance manager."
"I'd rate technical support at eight out of ten. They are helpful and fast."
"The most beneficial aspect of SolarWinds Server and Application Monitor is its ability to monitor at the application level."
"Exporting is a good feature. It helps me out when I have to do reports. I do a lot of exporting and crunching of the numbers. Dashboards are okay for showing to the leadership, but for doing statistics and updating tickets, the export feature is very beneficial for me."
"I like the search feature and the indexing. It's very fast and comprehensive."
"It's very flexible. If you look from the cloud implementation it is there. Reports are made quickly. Unlike other tools, it caters to all kinds of technical information on the front very easily. There's no need to put in any technical information. You can pull on the reports very easily, take action, and notify stakeholders."
"Splunk Enterprise Security's value lies in its ability to collect and analyze security logs, providing insightful dashboards."
"Integrity with many vendors: This simplifies the implementation and integration with different devices"
"Splunk Enterprise Security provides the foundation for unified threat detection, investigation, and response, enabling fast identification of critical issues."
"The solution's most valuable feature is that it helps with our use cases to detect anomalies in our data and it is important to my company since we have a lot of data on different logs on the systems."
"The product provides visibility and enables us to correlate data and generate alerts."
 

Cons

"In terms of the dashboards on offer, they should work to improve them. The types of dashboards that you get in terms of the graphs on offer aren't ideal right now."
"The stability, flexibility, and ease of use could be improved."
"Mapping interactions between systems."
"Some custom applications cannot be monitored, and a lot more applications need to be included."
"The current script monitoring feature has limitations, especially when dealing with custom scripts."
"The tool’s report feature created issues for us. We needed to gain skills to use that feature. The tool’s customization is not easy since you have to reconfigure the whole system."
"One area that could benefit from improvement is its performance"
"It should also be easier to upgrade SolarWinds. AppDynamics is harder to deploy but easier to upgrade. So AppDynamics takes a lot of time and effort to install, but you can upgrade it in minutes. SolarWinds is the opposite. It's easy to deploy, but upgrades take forever. To date, nobody can complete it on time, so the production environment is sitting idle."
"It is a hugely complicated product."
"Data retention can be better. If we want to look at the data for five months or six months, that is not available to us. We only have a history of 20 or 30 days. After that, the information gets lost. That is a drawback."
"The solution could improve by increasing the performance. We have run into problems when large amounts of data are processed."
"Its user interface for everything other than the charts can be improved. Some parts of it can be simplified a bit, such as when importing documents that have the network traffic. When you're going through the information about the network traffic, you have to have the expertise, but even if a program is supposed to be for IT support, it is good to make it user-friendly because it gets easier to train people. When something goes wrong, the more difficult a program is in terms of UI, the harder it is to fix the issue."
"​On the technical side, it would be nice to see aspects of the recent acquisition of Phantom make it into the core Splunk Enterprise, not just become a part of the premium Enterprise Security.​"
"I would like to see more SIEM functionality and a better ticket tool."
"Its setup is a little bit complex for a distributed environment. Their support can also be better. If we miss the response for more than a week, they usually close the case. Sometimes, it can take us more than a week to reply."
"Splunk Enterprise Security can provide more details and help CISOs resolve vulnerability situations better. The reason is that the tools we choose for data analysis and log collection cannot collect all the data and logs. Splunk Enterprise Security should help me with this, but it cannot."
 

Pricing and Cost Advice

"I think SolarWinds' pricing is very decent compared to other competitors in the market."
"Pricing is inexpensive, starting at 2440 euros. For that, you get the ability to monitor a couple of nodes and one year of maintenance and support."
"The solution is overpriced in terms of application management."
"When planning for the number of licenses to purchase, make sure you understand all of the elements within an application required to really understand performance well. In our case, we quickly came to the conclusion that an unlimited license for SAM was the way to go."
"We are on an annual license to use the solution. The price of the solution is expensive. The price is based on a bunch of factors, such as the number of engines and elements."
"Price can always be lower. It is neither on the expensive side nor on the cheap side. We have worked with them for a lot of years, so we get a discount due to the size of the installation."
"I like the pricing for this SolarWinds product."
"Pricing and licensing is fair for what you get. It does have a great bang-for-the-buck appeal."
"Splunk licensing model might seem expensive but with all the gain in functionalities you will have compared to traditional SIEM solutions I think it’s worth the price."
"It is economical than other solutions."
"Luckily, we come under a large federal agency, and before the pandemic, they signed a large enterprise license agreement. It worked out great and to our advantage because we are a small organization. We got a 300 gig license, and we just did not have the buying power to be able to get products cheaply. Because we all partnered together under the agency umbrella, we were able to get Splunk Enterprise Security, UBA, and ITSI for cheap. This was good considering the fact that some of these premium apps require a minimum number of users, and we do not have the number of people needed to even justify buying it."
"Splunk Enterprise Security is expensive."
"Pricing and licensing are quite high compared to other tools or SIEM tools, but the features justify it."
"The pricing depends on the bandwidth of an organization and is good compared to some SIEM tools. IBM, for example, is quite costly. But Microsoft Sentinel is notably cheaper."
"The pricing model is based on the number of gigabytes that you ingest into the Splunk system. So it can be an expensive solution."
"I am fine with the licensing, but in terms of the cost, it is expensive for the data that we have. We have an open discussion with our account rep about this."
report
Use our free recommendation engine to learn which Server Monitoring solutions are best for your needs.
859,533 professionals have used our research since 2012.
 

Comparison Review

VS
Feb 26, 2015
HP ArcSight vs. IBM QRadar vs. ​McAfee Nitro vs. Splunk vs. RSA Security vs. LogRhythm
We at Infosecnirvana.com have done several posts on SIEM. After the Dummies Guide on SIEM, we are following it up with a SIEM Product Comparison – 101 deck. So, here it is for your viewing pleasure. Let me know what you think by posting your comments below. The key products compared here are…
 

Top Industries

By visitors reading reviews
Educational Organization
22%
Computer Software Company
11%
Financial Services Firm
9%
Government
8%
Computer Software Company
15%
Financial Services Firm
15%
Manufacturing Company
8%
Government
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

What needs improvement with SolarWinds Server and Application Monitor?
There are no specific features or functionality I would like to see improved or enhanced in SolarWinds Server and Application Monitor at this time. I have not encountered any missing features or fu...
What SOC product do you recommend?
For tools I’d recommend: -SIEM- LogRhythm -SOAR- Palo Alto XSOAR Doing commercial w/o both (or at least an XDR) is asking to miss details that are critical, and ending up a statistic. Also, rememb...
What is a better choice, Splunk or Azure Sentinel?
It would really depend on (1) which logs you need to ingest and (2) what are your use cases Splunk is easy for ingestion of anything, but the charge per GB/Day Indexed and it gets expensive as log ...
How does Splunk compare with Azure Monitor?
Splunk handles a high amount of data very well. We use Splunk to capture information and as an aggregator for monitoring information from different sources. Splunk is very good at alerting us if we...
 

Also Known As

SolarWinds SAM
No data available
 

Overview

 

Sample Customers

Andr. L. Riis AS, NetSuite
Splunk has more than 7,000 customers spread across over 90 countries. These customers include Telenor, UniCredit, ideeli, McKenney's, Tesco, and SurveyMonkey.
Find out what your peers are saying about SolarWinds Server and Application Monitor vs. Splunk Enterprise Security and other solutions. Updated: May 2023.
859,533 professionals have used our research since 2012.