Try our new research platform with insights from 80,000+ expert users

Splunk Enterprise Security vs Stackify comparison

 

Comparison Buyer's Guide

Executive SummaryUpdated on Jul 13, 2025

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Splunk Enterprise Security
Ranking in Log Management
2nd
Average Rating
8.4
Reviews Sentiment
7.4
Number of Reviews
327
Ranking in other categories
Security Information and Event Management (SIEM) (1st), IT Operations Analytics (1st)
Stackify
Ranking in Log Management
61st
Average Rating
7.8
Number of Reviews
6
Ranking in other categories
Application Performance Monitoring (APM) and Observability (61st), IT Infrastructure Monitoring (59th)
 

Mindshare comparison

As of August 2025, in the Log Management category, the mindshare of Splunk Enterprise Security is 7.4%, down from 9.6% compared to the previous year. The mindshare of Stackify is 0.2%, up from 0.1% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Log Management
 

Featured Reviews

ROBERT-CHRISTIAN - PeerSpot reviewer
Has many predefined correlation rules and is brilliant for investigation and log analysis
It is very complicated to write your own correlation rules without the help of Splunk support. What Splunk could do better is to create an API to the standard SIEM tools, such as Microsoft Sentinel. The idea would be to make it less painful. In ELK Stack, Kibana is the query language with which you can search log files. I believe Splunk has also a query language in which they search their log files, but once you have identified the log file that you want to use for further security correlation, you want to very quickly transport that into your SIEM tool, such as Microsoft Sentinel. That is something that Splunk could make a little bit less painful because it is a lot of effort to find that log file and forward it. An API with Microsoft Sentinel or a similar SIEM tool would be a good idea.
Kalyan Somisetty - PeerSpot reviewer
Simple, easy to configure, and offers trial versions
In the next version, which I want to try, it'll show the comparison of the old responses of the APS. For example, how much time the old response and the new response with the changes. Right now, I cannot differentiate. The graphical interface should be able to capture nicely how much time it has taken and it should be very clear. Sometimes it confuses us. For example, what is this APA for? What were the average responses and how many requests have happened? It needs to give a clear picture. They should enable request and response capturing in the Stackify user interface to show what the request for the APA is. Then, it'll be very good. It should be able to capture the payload. For example, what is the request and what is the response? If it has a nice way of capturing everything then it would be easy. There is no need of using ELK again for logging. As of now, people will use Stackify or maybe Grafana for seeing the stats of the application or responses, however, it doesn't have the capabilities to show everything. People will go for any exception handling or checking the request and response in the ELK. If Stackify can do this future, then it'll be an easier single tool. It is anyway intercepting the logs, application logs. I don't think it's a big matter to capture extra data with the requested response. That requested response capturing also should be configurable since some people want the question response to be captured and for the people that don't want it, we can use that feature. It can be enabled as desired. Many people are using different monitoring tools like ELK, LogStash, and Splunk - many other tools. However, if you can make this kind of performance tool cover everything, then they will not shift to other solutions. It should be easily scalable and configurable in different instances. For example, if the same application is scaled up to differently, it should be easily integrable into Kubernetes pipelines. They should offer plugins to make it more easily integratable. For development enrollment, it should be free to use.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"It allows us to digest the information, the data, the different data streams, so we can make decisions based upon information that we receive, and it is pretty robust."
"It provides a lot of analytics with the underlying AI engine, and it is a lot easier than other solutions. There are some products that do automated AI-based detection and drawing up charts, but for network monitoring and all of the monitoring aspects, it is quite a nice tool. It is very convenient for business users because they get more or less a lot of data readily available. If you're familiar with the Splunk query language, you can pretty much do whatever you want."
"Splunk allows us to customize processing and dashboards, which helps us take care of our customers' needs."
"The scalability of the solution is amazing because it can collect a lot of data and you can have your own structure to monitor this data."
"It is very simple to tweak or write a small piece of glue code to go ahead and create a new dashboard for a business unit to make near real-time decisions to focus more on other geographies when launching the product."
"The most valuable features for us include its robust log management capabilities, which allow us to efficiently handle and retain logs for extended periods as needed."
"Splunk has improved our operations by giving us access to more information and allowing us to deploy more use cases."
"The feature that we use the most is the correlation search engine within ES."
"The deployment is very fast."
"The performance dashboard and the accurate level of details are beneficial."
"The filter feature on Stackify is one of the features I found valuable. It's awesome. When I want to get the application logs, the solution gives me many filters. For example, if I want to get logs from my test environment, the option is there for me to select the environment from Stackify, and you can also select the particular application, and you'll see the information you need there. The filter feature alone and the fact that Stackify offers a lot of different filters is what I like the most about the solution because I've used other tools with the filter feature, but the filtering was very difficult, versus Stackify that has good filtering. On Stackify, you can filter the information by the last one hour, or the last four hours, and you can also select the date range and specify the timestamp, then the solution will give you the information based on the date range you specified. Another feature I found valuable on Stackify is its rating feature because it tells you how your application is faring. For example, a rating of A means excellent, while a rating of F means very bad, or that your application is not doing well at all. The ratings are from A to F. I also like that Stackify helps you in terms of load management because the solution gives you information on overutilized resources. These are the most valuable features of the solution."
"The solution is stable and reliable."
 

Cons

"There is a definite learning curve to starting out."
"The upgrading process could be smoother."
"The security can be improved."
"Their technical support sucks."
"Many of my clients want to get better at Splunk, but they're afraid of using the tool because they feel it's too complex for them."
"Technical support needs to be more responsive."
"It needs integration with a configuration management solution."
"There is improvement needed when importing from some types of data sources."
"I've not used Stackify for a while, and I'm currently using a solution now that's not as good as Stackify. Among the solutions I've been using so far, Stackify has been one of the best for me, but there's always room for improvement. For example, I don't know if it's just me, but when I try to get the log from Stackify, sometimes it doesn't appear in real-time. It takes a few minutes before the logs appear. When I redeploy my solution and the application starts, I don't see the logs immediately, and it would take two to three minutes before I see the logs. I don't know if other customers have a similar experience. It's the wait time for the logs to appear that's a concern for me, could be improved, and is what the Stackify team should be looking into. In terms of any additional feature that I'd like added to the solution, I'm not sure if Stackify has a way to export logs out. I've been trying to do it. On the solution, you can click on a spiral-like icon and it shows you the entire error, and I'd prefer an export button that would let me download the error and save that into a text file, for example, so it'll be available on my local machine for me to reference it, especially because the log keeps going and as you're using the solution, the system keeps pushing messages on to Stackify, so if I'm looking at a particular error at 12:05 PM, for example, by the time I go back to my system and would like to revisit the error at 12:25 PM, on Stackify, the logs would have gone past that level and I won't see it again which makes it difficult. When you now go back to that timestamp, you don't tend to see it immediately, but if the solution had an export feature for me to save that particular error information on my local machine for reference at a later time, I won't have to go back to Stackify. I just go to that log, specifically to that particular export that I've received on my local machine. I can get it and review it, and it would be easier that way versus me going back to Stackify to find that particular error and request that particular information."
"I would like to be able to see metrics about individual running containers on the host machines."
"It should be easily scalable and configurable in different instances."
"The search feature could be improved."
 

Pricing and Cost Advice

"Be upfront about your needs and expectations. Splunk is great to work with."
"Pricing can be a limiting factor. You have to continuously tune what you are bringing in and make sure what you bring in is of value."
"I am not personally involved with the pricing of the solution."
"Some of the insights that we have obtained as a part of using Splunk have greatly helped us in increasing our revenue in terms of selling our products."
"Splunk is really expensive compared to all the other tools on the market, including Microsoft Sentinel."
"I believe there is room for improvement in reducing costs, particularly in the financial aspect, as Splunk tends to be pricier compared to other options."
"Splunk Enterprise Security is expensive. I would rate the cost an eight out of ten with ten being the most expensive."
"The solution is a little expensive."
"The price is variable. It depends on how much data we have received in that particular month. Usually, it goes up to $2,000, or, at times, $3,000 USD per month."
report
Use our free recommendation engine to learn which Log Management solutions are best for your needs.
865,164 professionals have used our research since 2012.
 

Comparison Review

VS
Feb 26, 2015
HP ArcSight vs. IBM QRadar vs. ​McAfee Nitro vs. Splunk vs. RSA Security vs. LogRhythm
We at Infosecnirvana.com have done several posts on SIEM. After the Dummies Guide on SIEM, we are following it up with a SIEM Product Comparison – 101 deck. So, here it is for your viewing pleasure. Let me know what you think by posting your comments below. The key products compared here are…
 

Top Industries

By visitors reading reviews
Computer Software Company
14%
Financial Services Firm
14%
Manufacturing Company
8%
Government
7%
Financial Services Firm
15%
Computer Software Company
9%
Media Company
9%
Comms Service Provider
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

What SOC product do you recommend?
For tools I’d recommend: -SIEM- LogRhythm -SOAR- Palo Alto XSOAR Doing commercial w/o both (or at least an XDR) is asking to miss details that are critical, and ending up a statistic. Also, rememb...
What is a better choice, Splunk or Azure Sentinel?
It would really depend on (1) which logs you need to ingest and (2) what are your use cases Splunk is easy for ingestion of anything, but the charge per GB/Day Indexed and it gets expensive as log ...
How does Splunk compare with Azure Monitor?
Splunk handles a high amount of data very well. We use Splunk to capture information and as an aggregator for monitoring information from different sources. Splunk is very good at alerting us if we...
Ask a question
Earn 20 points
 

Overview

 

Sample Customers

Splunk has more than 7,000 customers spread across over 90 countries. These customers include Telenor, UniCredit, ideeli, McKenney's, Tesco, and SurveyMonkey.
MyRacePass, ClearSale, Newitts, Carbonite, Boston Software, Children's International, Starkwood Media Group, Fewzion
Find out what your peers are saying about Splunk Enterprise Security vs. Stackify and other solutions. Updated: July 2025.
865,164 professionals have used our research since 2012.