Try our new research platform with insights from 80,000+ expert users

Splunk Enterprise Security vs vRealize Network Insight comparison

 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Splunk Enterprise Security
Average Rating
8.4
Reviews Sentiment
7.6
Number of Reviews
306
Ranking in other categories
Log Management (2nd), Security Information and Event Management (SIEM) (1st), IT Operations Analytics (1st)
vRealize Network Insight
Average Rating
8.6
Reviews Sentiment
7.6
Number of Reviews
46
Ranking in other categories
Network Monitoring Software (23rd), IT Infrastructure Monitoring (23rd)
 

Mindshare comparison

While both are Systems Management solutions, they serve different purposes. Splunk Enterprise Security is designed for Security Information and Event Management (SIEM) and holds a mindshare of 9.5%, down 12.6% compared to last year.
vRealize Network Insight, on the other hand, focuses on IT Infrastructure Monitoring, holds 0.5% mindshare, down 0.6% since last year.
Security Information and Event Management (SIEM)
IT Infrastructure Monitoring
 

Featured Reviews

ROBERT-CHRISTIAN - PeerSpot reviewer
Has many predefined correlation rules and is brilliant for investigation and log analysis
It is very complicated to write your own correlation rules without the help of Splunk support. What Splunk could do better is to create an API to the standard SIEM tools, such as Microsoft Sentinel. The idea would be to make it less painful. In ELK Stack, Kibana is the query language with which you can search log files. I believe Splunk has also a query language in which they search their log files, but once you have identified the log file that you want to use for further security correlation, you want to very quickly transport that into your SIEM tool, such as Microsoft Sentinel. That is something that Splunk could make a little bit less painful because it is a lot of effort to find that log file and forward it. An API with Microsoft Sentinel or a similar SIEM tool would be a good idea.
NiteshKumar1 - PeerSpot reviewer
The tool's configuration is easy and artifacts are easily accessible through professional services and the web
The product is highly regarded, and many customers have been using it along with other VMware products like vSphere and VMware vCloud Usage Insight. However, recently, there's been a trend among customers, especially those using VMware for a considerable period, to explore the potential of migrating to the public cloud. The common concern among these customers is how the VMware products will perform in the public cloud environment. Migrating instances from VMware to different platforms is not easy, especially when dealing with many instances across multiple customers. Customers are keen to maintain the functionality of their existing VMware products but prefer to run them on the public cloud instead of on-premise servers. Our clients for vRealize Network Insight are enterprise businesses. I rate it a nine out of ten.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"Splunk has improved our operations by giving us access to more information and allowing us to deploy more use cases."
"The solution's most valuable feature is threat intelligence correlations."
"What I really like is that even if you have already collected the data, you can extract fields and can build searches."
"The solution's most valuable feature is the incident review, which gives a good overview of our security incidents."
"I have found the installation can be of medium difficulty to very complex depending on the use case."
"I have not seen any outages in the product in the past two years that it has been running in our company, so I think it is good when it comes to the stability part."
"I like the Splunk dashboard and search engine."
"The incident review pane is the best part of it because that is where the SOC lives. It is the heartbeat of what the SOC needs to do. You are able to start the investigative process. As you are sitting in the incident review pane, you see the alert, and from that one alert, which is called a notable alert, you can drill in and see all the different specific details that are tied to that."
"It has definitely helped us to meet compliance rules by assuring that all traffic is going to where it's supposed to go. It can be used to report that you are in compliance, as well as helping you get into compliance."
"A lot of time is saved when you use this type of software solution for the network. We have moved systems into the new data center and the servers and systems are much faster because of the very low latency between virtual machines."
"The most valuable features are the monitoring and tracking. It's also intuitive and user-friendly. The screen looks exactly the same as the other appliances for VMware, so it's easy to navigate."
"As a troubleshooting tool, it's a level-3 troubleshooting-skills tool and it's very easy to use and very easy to find the information that you need."
"It helps a lot because, until now, we didn't have the tools to figure out the micro level, VM-to-VM kind of traffic; that was not in the current environment. We could not figure out VM-to-VM communication from the other tools. This is the tool which gives us end-to-end transparency."
"The graphical interface of this environment is so good with all the views, the graphics, and everything in them. It's really easy for me. It doesn't need an engineer to work on it. It's easy enough that anyone can get into the environment and look for issues or look at how communication is going on across the VMs. It's pretty much straightforward."
"The initial was straightforward. You can have it up and running in one hour."
"It's user-friendly. It's similar to the GUI that most VMware products are moving to, and the consistency across those makes it easy to switch from one product to another. Also, the search bar at the top is plain text and it helps you, it guides you along with your search query, so that helps. The first day you're in there you can start building actual queries."
 

Cons

"While Splunkbase (the app repository) has a lot of great content, some apps are terribly old and could stand to be updated or purged."
"Features related to content management must be improved."
"Having analysts put their notes directly within the investigation feature in the incident review would be beneficial."
"The implementation and the scanning of the logs can be difficult."
"The upgrading process could be smoother."
"The product must improve insider threat detection."
"The solution's case management system could be further improved to make it easier for analysts to manage cases."
"The presence of multiple layers creates a significant challenge for monitoring across cloud environments."
"vRNI needs more remediation where it hooks into NSX."
"When we talk about those micro-segmentation rules, there's an Export function. It is very macro-segmentation oriented instead. So if you choose an application, it will find the tiers within that application and say that it's communicating on, say, port 80 to a separate VLAN. There might be 200 machines in that other VLAN. You don't want to open port 80 at all of them. So we need a lot more granularity in those suggested firewall rules."
"I want to see more in terms of microsegmentation. As of now, I can see the rules, but they are not in a readable format that I can convert to microsegmentation and can fit into NSX Manager."
"The compatibility with each and every component of the infrastructure is the main thing that I am looking for. I would like them to make sure that it's compatible with different kinds of storage systems, etc. I have seen the compatibility list. I feel it can be more compatible than it is right now."
"I would like to see more interoperability on the firewall and low balancer sides."
"While it's not exactly a feature, what normally happens when we are trying to look at the VM flow portion is - although Network Insight does have options to integrate a few physical switches into it - we can't really get an end-to-end flow of the network. We might be using a few switches that are not supported by Network Insight. That is where they can improve, in the support for more physical switches and network devices."
"There could be some deeper analytics into packet inspection and trace flows. It could use some kind of machine learning to look at Layer 7 traffic for potential malware or corrupt packets."
"In a very general way, I would like to see an improvement in interoperability with third-party product, from other vendors."
 

Pricing and Cost Advice

"Splunk can be an expensive solution. It all depends on how we configure the alerts and the events from the endpoints. You can save some money if you do that correctly. If not, it becomes an expensive solution."
"It is quite expensive."
"We have an unlimited one, and we pay yearly, but I don't know how much it costs. Previously, I worked for a startup, and when they started building it up, it was complicated for them because they didn't have the budget for that many licenses. It was very costly for them. So, startups might find it a little bit problematic because of the licensing, but for bigger companies, there is no issue."
"Pricing and licensing is quite expensive. But for the value the product provides, it seems at par in the market."
"Splunk is not free."
"Splunk Enterprise Security is expensive but the solution is equipped with a lot of features."
"Setup cost is cheap: It is free, it is user-friendly, and it is fast."
"This solution is costly. Splunk is obviously a great product, but you should only choose this product if you need all the features provided. Otherwise, if you don't need all the features to meet your requirements, there are probably other products that will be more cost-effective. It's cost versus the functionality requirement."
"I rate vRealize Network Insight's pricing a seven point five out of ten."
"It has brought more money into our company."
"The solution has helped us to reduce time, increase performance, reduce costs, and even easily manage networks. We are probably seeing 10 to 20 percent labor savings because we are able to be very specific and focused on what we want to do. It ends up saving the customer money and makes us be more efficient on our cost deliveries."
"Cost always has room for improvement, you could always make it cheaper. But I think it's a good value for what you pay for it."
"vRealize Network Insight is expensive."
"They should include the product in NSX because it's important to have it for deployment."
"It's a little expensive, but for what you're getting out of the product, you often see the trade-off. It depends on the type of licensing you have. It might be a little too pricey for some."
"We have spent less time investigating network flows, so it is absolutely cost-effective."
report
Use our free recommendation engine to learn which Security Information and Event Management (SIEM) solutions are best for your needs.
850,671 professionals have used our research since 2012.
 

Comparison Review

VS
Feb 26, 2015
HP ArcSight vs. IBM QRadar vs. ​McAfee Nitro vs. Splunk vs. RSA Security vs. LogRhythm
We at Infosecnirvana.com have done several posts on SIEM. After the Dummies Guide on SIEM, we are following it up with a SIEM Product Comparison – 101 deck. So, here it is for your viewing pleasure. Let me know what you think by posting your comments below. The key products compared here are…
 

Top Industries

By visitors reading reviews
Financial Services Firm
15%
Computer Software Company
14%
Manufacturing Company
8%
Government
8%
Financial Services Firm
15%
Computer Software Company
15%
Manufacturing Company
10%
Government
9%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

What SOC product do you recommend?
For tools I’d recommend: -SIEM- LogRhythm -SOAR- Palo Alto XSOAR Doing commercial w/o both (or at least an XDR) is asking to miss details that are critical, and ending up a statistic. Also, rememb...
What is a better choice, Splunk or Azure Sentinel?
It would really depend on (1) which logs you need to ingest and (2) what are your use cases Splunk is easy for ingestion of anything, but the charge per GB/Day Indexed and it gets expensive as log ...
How does Splunk compare with Azure Monitor?
Splunk handles a high amount of data very well. We use Splunk to capture information and as an aggregator for monitoring information from different sources. Splunk is very good at alerting us if we...
What do you like most about vRealize Network Insight?
The tool's ease of configuration and use and the availability of information and artifacts through professional services and the web are key factors that customers find valuable.
What is your experience regarding pricing and costs for vRealize Network Insight?
Broadcom is known for increasing product prices, making them expensive compared to what people used to pay. I liken the subscription model to not truly owning what you pay for.
What needs improvement with vRealize Network Insight?
Right now, I do not see a specific area for improvement. My main concern is understanding the intentions of Broadcom, which has acquired VMware. Broadcom should improve by going back to what was wo...
 

Also Known As

No data available
Arkin
 

Overview

 

Sample Customers

Splunk has more than 7,000 customers spread across over 90 countries. These customers include Telenor, UniCredit, ideeli, McKenney's, Tesco, and SurveyMonkey.
NTTi3, VCIX-NV, VMware Networking and Security Business Unit, Illumio, CompuNet
Find out what your peers are saying about Splunk, Wazuh, Microsoft and others in Security Information and Event Management (SIEM). Updated: April 2025.
850,671 professionals have used our research since 2012.