Try our new research platform with insights from 80,000+ expert users

Splunk Enterprise Platform vs Unit 42 Managed Detection and Response comparison

 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Splunk Enterprise Platform
Average Rating
8.4
Reviews Sentiment
7.7
Number of Reviews
33
Ranking in other categories
Data Visualization (4th), IT Alerting and Incident Management (5th)
Unit 42 Managed Detection a...
Average Rating
0.0
Reviews Sentiment
7.8
Number of Reviews
1
Ranking in other categories
Managed Security Services Providers (MSSP) (60th), Managed Detection and Response (MDR) (47th)
 

Featured Reviews

Kundan Nagare - PeerSpot reviewer
Offers excellent data analysis and visualization capabilities
I use the Platform to monitor my IT infrastructure. There are apps for Linux and Windows servers that capture performance metrics like CPU and memory usage. These metrics are collected and sent to the blank index through forwarders. Splunk helps with security information and event management by detecting and monitoring network equipment and firewalls. It saves searches for specific terms, like threats, in firewall logs. When a match is found, it alerts about potential security breaches, helping to detect and address them. The real-time processing capability in Splunk enhances data monitoring by centrally collecting all data. This allows for easy searching and scheduling of searches, reducing the need for manual intervention. The dashboard and visualization features in Splunk impact data analysis by providing a clear status of data analysis. Users can create customized views for management, helping them understand what is happening within the infrastructure more effectively. I would recommend Splunk to others, especially from the CIM perspective. Its data analysis and visualization capabilities are unmatched, making it an excellent choice for SIM. Overall, I would rate Splunk Enterprise Platform as a nine out of ten.
MohammedSirajuddin - PeerSpot reviewer
Flexible and reduces IT operations but requires local data sovereignty and competitive pricing
I prefer having local data sovereignty. It would be advantageous for Palo Alto to have local data centers across different countries to adhere to this requirement. I also have a concern regarding pricing, which is perceived as high compared to competitors. Improvements should focus on response times and reducing the time taken to reach solutions.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"Splunk Enterprise Platform is an easy-to-use and easy-to-configure solution."
"It's not just one feature I like the most. Every person wants to collect and rate logs, and I value how the Splunk Enterprise Platform handles this.The most valuable part for us is setting up the alerts and reports to manage the logs and log metrics. We use it to support every tool across the entire bank.We are the ones who manage all the data, and if there's any issue, everything depends on the Splunk Enterprise Platform."
"The most valuable feature I've found in the Splunk Enterprise Platform is its log readability and filtering capabilities. The filters on the left side are particularly useful, allowing me to quickly narrow down the data to what's relevant for any application or server service. The interesting fields feature helps me get the values I need most of the time."
"Splunk Enterprise Platform saves approximately 20 to 30 percent of my time without having to perform different actions separately."
"The product is very easy to use."
"I found the incident notification to be very helpful."
"It can handle large datasets, swiftly consolidating outputs from every server and device across the network."
"Splunk is very flexible in handling various formats of data as long as basic rules are adhered to."
"Unit 42 MDR provides us with managed detection and response functionalities, eliminating the need for capital expenditure since it is an operational expenditure-based service."
"Unit 42 MDR provides us with managed detection and response functionalities, eliminating the need for capital expenditure since it is an operational expenditure-based service."
 

Cons

"Splunk is not an out-of-the-box solution like Micro Focus or Zabbix. You have to create your request to collect the data and add crucial components to the software."
"The Splunk Enterprise Platform has room for improvement, particularly in automating the permissions process during app promotions. Currently, permissions are manually set when different teams request an application move to production, which is time-consuming. Automating this process would streamline operations by automatically assigning the appropriate permissions and roles to specific services or teams, reducing the need to review each request ticket manually."
"Based on my experience, I've noticed areas for improvement, particularly in support. Developers typically interact with support personnel who may lack technical expertise when raising support tickets. This can result in delays as initial interactions involve sharing documents before escalation to higher support levels."
"Sometimes, queries don't give proper results, and the indexes go down."
"Splunk Enterprise Platform should include more integrations with other security tools."
"It's not easy or feasible to reach out to Splunk directly."
"he product's initial setup phase needs to be made easy since it looks like it is very complex compared to the other tools in the market."
"Splunk can be used primarily to port log files, allowing for easy and quick management of large amounts of logs. However, this can also be a drawback due to the configuration, parsing, and dashboard creation limitations. Communication is stream-based, which means you need to do a lot of pre-emptive setup to get a nice export."
"I have a concern regarding pricing, which is perceived as high compared to competitors."
"I also have a concern regarding pricing, which is perceived as high compared to competitors."
 

Pricing and Cost Advice

"Product pricing is typically annual, and discounts are often available for longer-term commitments."
"If you exceed your licensed limit, the product will issue a warning, typically a five-license warning. Additionally, they send daily email notifications informing you about the breach. This prompts you to consider options such as minimizing logs or acquiring additional licensing to address the issue."
"Splunk Enterprise Platform is an expensive solution."
"I rate the product's pricing a ten on a scale of one to ten, where one is cheap, and ten is expensive. It is a very pricey tool."
"On a scale from one to ten, where one is cheap, and ten is expensive, I rate the solution's pricing around seven or eight out of ten."
"The solution's pricing increases with the amount of data used. This pricing model is acceptable because it aligns with the security features provided. It ensures that the price reflects the level of security and the amount of data we're managing."
"There are yearly payments to be made towards the licensing costs attached to the solution."
"The tool is expensive."
Information not available
report
Use our free recommendation engine to learn which Data Visualization solutions are best for your needs.
850,028 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Hospitality Company
16%
Financial Services Firm
14%
Manufacturing Company
13%
Healthcare Company
12%
No data available
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
No data available
 

Questions from the Community

What do you like most about Splunk Enterprise Platform?
The most valuable features of the solution are the load balancing technique, the forwarding technique, and SSL certification.
What needs improvement with Splunk Enterprise Platform?
While Splunk Enterprise Platform is a good product, it is expensive. Additionally, it is complex for inexperienced cybersecurity engineers and requires experienced personnel to handle it effectively.
What is your primary use case for Splunk Enterprise Platform?
We are working with AppDynamics, Splunk Enterprise Platform, and other Splunk products. However, the main use case here is with Splunk Enterprise Platform.
What is your experience regarding pricing and costs for Unit 42 Managed Detection and Response?
I find the pricing to be expensive, especially when compared with competitors who offer significant discounts. Palo Alto has room to become more competitive in its pricing.
What needs improvement with Unit 42 Managed Detection and Response?
I prefer having local data sovereignty. It would be advantageous for Palo Alto to have local data centers across different countries to adhere to this requirement. I also have a concern regarding p...
What is your primary use case for Unit 42 Managed Detection and Response?
Unit 42 is a Managed Detection and Response solution with MDR capabilities. I use it in a managed service context where my organization's security needs are catered to by Palo Alto. Generally, it i...
 

Overview

Find out what your peers are saying about Salesforce, Qlik, Splunk and others in Data Visualization. Updated: April 2025.
850,028 professionals have used our research since 2012.