Try our new research platform with insights from 80,000+ expert users

Splunk Enterprise Security vs vRealize Network Insight comparison

 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Splunk Enterprise Security
Average Rating
8.4
Reviews Sentiment
7.5
Number of Reviews
318
Ranking in other categories
Log Management (2nd), Security Information and Event Management (SIEM) (1st), IT Operations Analytics (1st)
vRealize Network Insight
Average Rating
8.6
Reviews Sentiment
7.6
Number of Reviews
46
Ranking in other categories
Network Monitoring Software (38th), IT Infrastructure Monitoring (41st)
 

Mindshare comparison

While both are Systems Management solutions, they serve different purposes. Splunk Enterprise Security is designed for Security Information and Event Management (SIEM) and holds a mindshare of 9.4%, down 12.1% compared to last year.
vRealize Network Insight, on the other hand, focuses on IT Infrastructure Monitoring, holds 0.5% mindshare, down 0.6% since last year.
Security Information and Event Management (SIEM)
IT Infrastructure Monitoring
 

Featured Reviews

ROBERT-CHRISTIAN - PeerSpot reviewer
Has many predefined correlation rules and is brilliant for investigation and log analysis
It is very complicated to write your own correlation rules without the help of Splunk support. What Splunk could do better is to create an API to the standard SIEM tools, such as Microsoft Sentinel. The idea would be to make it less painful. In ELK Stack, Kibana is the query language with which you can search log files. I believe Splunk has also a query language in which they search their log files, but once you have identified the log file that you want to use for further security correlation, you want to very quickly transport that into your SIEM tool, such as Microsoft Sentinel. That is something that Splunk could make a little bit less painful because it is a lot of effort to find that log file and forward it. An API with Microsoft Sentinel or a similar SIEM tool would be a good idea.
NiteshKumar1 - PeerSpot reviewer
The tool's configuration is easy and artifacts are easily accessible through professional services and the web
The product is highly regarded, and many customers have been using it along with other VMware products like vSphere and VMware vCloud Usage Insight. However, recently, there's been a trend among customers, especially those using VMware for a considerable period, to explore the potential of migrating to the public cloud. The common concern among these customers is how the VMware products will perform in the public cloud environment. Migrating instances from VMware to different platforms is not easy, especially when dealing with many instances across multiple customers. Customers are keen to maintain the functionality of their existing VMware products but prefer to run them on the public cloud instead of on-premise servers. Our clients for vRealize Network Insight are enterprise businesses. I rate it a nine out of ten.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"The ability to view all of these different logs, then drilling down into specific times or into specific data sources, has proved to be the greatest aspect in decreasing our troubleshooting overhead time."
"It gives us good visibility into multiple environments, including cloud, on-premises, and hybrid; irrespective of platform."
"Ease of correlation, creating correlation searches are easy and you can combine multiple sources with little effort"
"Its dashboard is valuable. If you have a good knowledge of how to create a dashboard, you can create any dashboard related to cybersecurity. If fine-tuned, the alarms that are triggered for instant review are also very valuable and useful."
"Splunk setup is easy and straightforward. ​"
"I like the ease of setting up dashboards on Splunk. They're easy to create, manage, alter, and share. You can fine-tune them any way you see fit."
"I like Splunk's data aggregation and search capabilities."
"I really like the user interface and how it works."
"It has definitely helped us to meet compliance rules by assuring that all traffic is going to where it's supposed to go. It can be used to report that you are in compliance, as well as helping you get into compliance."
"It gives the visibility that was either broken or there in pieces only. This solution provides a unified view of the whole system, back and forth. It has helped to reduce time to value, increase performance, more easily manage networks, and provide deep visibility."
"It allows us to go from virtual through NSX, up to the core, and see all of that in one pane of glass, it's pretty easy."
"By doing dependency mapping, it makes migrations more efficient. There are less outages that require engineers to spend additional hours troubleshooting the migration failures."
"The most valuable features are the packet trace flow and that the view of the whole environment is deep."
"I find it user-friendly and intuitive. With the GUI interface that we do use on a regular basis, it's easy to navigate, it's easy to see, easy to query. We get reports. It's easy to use."
"As a troubleshooting tool, it's a level-3 troubleshooting-skills tool and it's very easy to use and very easy to find the information that you need."
"The automation collects all the relationships between servers, allowing us to visualize these relationships and organize the migration into waves."
 

Cons

"Improving the infrastructure behind Splunk Enterprise Security is vital—enhanced cores, CPUs, and memory should be prioritized to support better processing power."
"Some of the terminology can be confusing, even for seasoned vets. Renaming components at this point would be a serious undertaking. However, it might be beneficial in the long run."
"The incident response technique should be available out of the box. That isn't as available as we would expect."
"The use cases provided by Splunk are a good starting point, but could cover many additional topics to ensure that a smaller or less experienced shop might maximize the value of an ES deployment."
"Most importantly, Splunk can be outrageously expensive. That is the problem with both Splunk and Sentinel. Their pricing literally explodes based on the amount of data you feed in."
"A problem that we had recently had was we licensed it based on how much data you upload to them every day. Something changed in one our applications, and it started generating three to four times as many logs and. So now, we are trying to assemble something with parts of the Splunk API to warn ourselves, then turn it off and throttle it back more. However it would be better if they had something systematically built into the product that if you're getting close to your license, then to shut things down."
"They can incorporate the SOAR solution within the actual product so that we do not require two different products, two different installations, and two different pricing methods. In regards to UBA, I am familiar with the UBA that existed two years ago. I am not updated about it today, but two years ago, UBA required such an amount of data that from a cost perspective, it was not worth it. When you compare it to what you get out of the box with Microsoft Sentinel without additional costs, there is no match."
"We can only increase the environment. For instance, with an ES server, we cannot make a cluster of ES. If you have two servers and want to make a cluster of these two servers for ES, that is not possible."
"If it had some kind of plugins with vSphere, more effective plugins with Horizon View or other VMWare products, if it had interconnectivity, I think it would be more effective than it is today."
"I want to be able to monitor a network flow that is approximately two weeks back, but I haven't found an easy way to do this."
"There is room for improvement when it comes to pricing because we pay here in Brazil, and all the costs are based on the dollar."
"After Broadcom acquired VMware, I would rate their support at five or less in many cases. It's difficult to find necessary documentation, open tickets, and get support."
"It needs to be a little easier to use and to understand the information it's putting out. That would make it more helpful. If you're not a network person you need to understand things like network policies and concepts. If you gave it to a regular admin, it would be nice if it were easier for them to pick up what is going on, understand the flows and whether or not stuff should be talking to each other, as opposed to just port groups and IP addresses."
"In a very general way, I would like to see an improvement in interoperability with third-party product, from other vendors."
"The UI, even though once you get to know it, it's easier, still it's hard to figure out by yourself. You have to go read, watch videos. It has a lot of data on it. So that is an issue."
"Support could be much better."
 

Pricing and Cost Advice

"It's definitely worth it."
"Splunk differs from other SIEM solutions by using a gigabyte-based pricing model, rather than the agent-based licenses common with its competitors."
"My experience with the solution's setup cost, pricing, and licensing was really good."
"The solution is costly."
"The price of Splunk is too high for our market."
"Splunk is priced higher than other solutions."
"The subscription is monthly."
"Personnel costs are saved by not having to involve the domain developers from multiple teams when tracing a problem that spans multiple platforms."
"We have spent less time investigating network flows, so it is absolutely cost-effective."
"It's an expensive product because we have a lot of nodes."
"The solution has reduced the time that we spend on other products. For example, with NSX, we were able to quickly find things that we would normally spend days trying to figure out."
"It has brought more money into our company."
"I rate vRealize Network Insight's pricing a seven point five out of ten."
"vRealize Network Insight is expensive."
"It's a little expensive, but for what you're getting out of the product, you often see the trade-off. It depends on the type of licensing you have. It might be a little too pricey for some."
"The solution has helped us to reduce time, increase performance, reduce costs, and even easily manage networks. We are probably seeing 10 to 20 percent labor savings because we are able to be very specific and focused on what we want to do. It ends up saving the customer money and makes us be more efficient on our cost deliveries."
report
Use our free recommendation engine to learn which Security Information and Event Management (SIEM) solutions are best for your needs.
861,481 professionals have used our research since 2012.
 

Comparison Review

VS
Feb 26, 2015
HP ArcSight vs. IBM QRadar vs. ​McAfee Nitro vs. Splunk vs. RSA Security vs. LogRhythm
We at Infosecnirvana.com have done several posts on SIEM. After the Dummies Guide on SIEM, we are following it up with a SIEM Product Comparison – 101 deck. So, here it is for your viewing pleasure. Let me know what you think by posting your comments below. The key products compared here are…
 

Top Industries

By visitors reading reviews
Financial Services Firm
14%
Computer Software Company
14%
Manufacturing Company
8%
Government
7%
Computer Software Company
15%
Financial Services Firm
15%
Manufacturing Company
10%
Healthcare Company
8%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

What SOC product do you recommend?
For tools I’d recommend: -SIEM- LogRhythm -SOAR- Palo Alto XSOAR Doing commercial w/o both (or at least an XDR) is asking to miss details that are critical, and ending up a statistic. Also, rememb...
What is a better choice, Splunk or Azure Sentinel?
It would really depend on (1) which logs you need to ingest and (2) what are your use cases Splunk is easy for ingestion of anything, but the charge per GB/Day Indexed and it gets expensive as log ...
How does Splunk compare with Azure Monitor?
Splunk handles a high amount of data very well. We use Splunk to capture information and as an aggregator for monitoring information from different sources. Splunk is very good at alerting us if we...
What do you like most about vRealize Network Insight?
The tool's ease of configuration and use and the availability of information and artifacts through professional services and the web are key factors that customers find valuable.
What is your experience regarding pricing and costs for vRealize Network Insight?
Broadcom is known for increasing product prices, making them expensive compared to what people used to pay. I liken the subscription model to not truly owning what you pay for.
What needs improvement with vRealize Network Insight?
Right now, I do not see a specific area for improvement. My main concern is understanding the intentions of Broadcom, which has acquired VMware. Broadcom should improve by going back to what was wo...
 

Also Known As

No data available
Arkin
 

Overview

 

Sample Customers

Splunk has more than 7,000 customers spread across over 90 countries. These customers include Telenor, UniCredit, ideeli, McKenney's, Tesco, and SurveyMonkey.
NTTi3, VCIX-NV, VMware Networking and Security Business Unit, Illumio, CompuNet
Find out what your peers are saying about Splunk, Wazuh, Microsoft and others in Security Information and Event Management (SIEM). Updated: June 2025.
861,481 professionals have used our research since 2012.