No more typing reviews! Try our Samantha, our new voice AI agent.

Splunk Observability Cloud vs ThreatSync NDR comparison

Why PeerSpot?
 

Comparison Buyer's Guide

Executive SummaryUpdated on Jan 18, 2026

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Splunk Observability Cloud
Ranking in Network Monitoring Software
4th
Average Rating
8.2
Reviews Sentiment
6.7
Number of Reviews
107
Ranking in other categories
Application Performance Monitoring (APM) and Observability (5th), IT Infrastructure Monitoring (3rd), Cloud Monitoring Software (2nd), Container Management (4th), Digital Experience Monitoring (DEM) (3rd)
ThreatSync NDR
Ranking in Network Monitoring Software
55th
Average Rating
8.6
Reviews Sentiment
8.7
Number of Reviews
2
Ranking in other categories
Network Detection and Response (NDR) (18th)
 

Mindshare comparison

As of October 2026, in the Network Monitoring Software category, the mindshare of Splunk Observability Cloud is 1.6%, up from 1.2% compared to the previous year. The mindshare of ThreatSync NDR is 0.3%, up from 0.1% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Network Monitoring Software Mindshare Distribution
ProductMindshare (%)
Splunk Observability Cloud1.6%
ThreatSync NDR0.3%
Other98.1%
Network Monitoring Software
 

Featured Reviews

PK
Project Manager at AGRICULTURE SKILL COUNCIL OF INDIA (ASCI)
Unified observability has improved real-time governance and now drives data-led decisions
Log Observer Connect is embedded here, but we are facing some delays in centralized log collection and analysis, which can be further fastened. We are collecting all the data metrics and decision-making insights, but all these data-driven decisions coming from different applications are not connected somewhere. A consolidated form or correlation of these insights is not happening between each other due to which we feel we are missing something significant. Some generalized feedback includes that predictive alerts or alarms which can be integrated with AI-driven alarms and alerting features should be established so that there is AI-driven intelligence and anomaly detection happening with a complete systematic process in service delivery. Application dependencies are huge, and business and operational dashboards should be improved. Right now there are very interactive custom dashboards, and every now and then, the personalization of enhancements keeps happening. KPI monitoring, executive reporting, and analytics have definitely been introduced to a great extent. There are few things in cloud-native monitoring, such as integration with AWS and Azure, where we sometimes do face lags. Those things can definitely be improved upon. I have used Datadog and Dynatrace before using Splunk Observability Cloud. Datadog was definitely recommended by most of our peers because of its very strong comprehensive observability and very strong and unique dashboard systems. Dynatrace was also very good because they have offered a lot of AI-driven analysis methods and processes, which was helping our organization a lot. Since our organization has a very strong IT ecosystem for agriculture, very different kinds of customized things are required.
Michael-Foster - PeerSpot reviewer
Head of IT at Bulkhaul Limited
Has improved threat detection and reduced manual workload through real-time cloud insights
ThreatSync+ NDR has helped identify potential security gaps in my network, and we are currently working on resolving them. The impact on incident response time varies. During daytime operations, it reacts instantly with a notification delay of 10 to 20 minutes, while nighttime notifications can have up to eight hours delay. ThreatSync+ NDR has enhanced our ability to proactively manage network risks by enabling us to implement extra measures at a lower level based on its findings. The compliance reporting tools are comprehensive and meet our requirements. Though we haven't conducted official compliance reporting yet, we anticipate it will save approximately one day of work in report compilation. Regarding pricing, WatchGuard rates a nine out of ten. We maintain 1,001 licenses for ThreatSync+ NDR, serving approximately 1,000 users, with about 300 local users in the UK. ThreatSync+ NDR's effectiveness in identifying weaknesses before exploitation is excellent and very quick. I recommend ThreatSync+ NDR to other users based on its rapid deployment and immediate value delivery. I rate ThreatSync+ NDR 9 out of 10.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"Splunk Observability Cloud has positively impacted my organization by allowing us to have visibility into the environment."
"The most valuable thing that we have seen within our group is the ability to ingest all this raw data and have it organized in a certain way so that different groups can get effective alerting from this massive amount of raw data that is out there."
"Splunk APM provides a holistic view of the application. Unlike other APMs, Splunk's service map is quite effective."
"The integration of business context in the telemetry has helped to reduce MTTR by fifty percent, which has been the key metric."
"My impression of Splunk Observability Cloud's out-of-the-box dashboards and detectors is that the visualization looks excellent, and the implementation is straightforward."
"The feature I find most valuable, is the data integration."
"Customer service and technical support respond very quickly."
"Overall, I am satisfied with Splunk Observability Cloud, as it provides strong real-time monitoring, good visibility, and faster troubleshooting, being useful for improving our day-to-day operational efficiency."
"ThreatSync NDR is a strong addition to our company's security architecture."
"Implementing ThreatSync+ NDR has influenced our business significantly as it provides enhanced security and saves several hours daily by eliminating manual log reviews."
 

Cons

"The security could be better."
"We never had any issues when it comes to the type of use cases we are using it for. We did not need more advancement on it, but I know that, in general, everything can be updated. There are tiny little tweaks that can be made regardless of whether it looks better or has a different flow to it than it does right now, but it works pretty well for what we use it for."
"The initial setup of Splunk Real User Monitoring (RUM) was easy. The solution is deployed on-premises."
"Unfortunately, with our current setup, we just have to implement Log Observer in a couple of instances so that we can have that integration with Splunk Observability Cloud."
"I've only experienced downtime, crashes, or performance issues when it isn't configured correctly."
"Regarding the negative side, I think the licensing can be much better because it is based upon host units and there is additional licensing for the number of traces that I can bring in."
"I haven't seen any return on investment yet, but I do definitely expect to see ROI soon, once we bring in everything and reduce workload."
"It is essential for the monitoring tool to deliver quick response times when generating analytical reports, instead of prolonged delays."
"There are definitely areas for improvements in ThreatSync NDR, as no product is perfect. Its effectiveness depends on proper network visibility, so if important traffic segments are not mirrored or monitored, detection may be incomplete."
"After using ThreatSync+ NDR for about a year, areas for improvement include the ability to pull logs from other vendors using an API."
 

Pricing and Cost Advice

"I am not in that circle, but we are currently licensing based on our queries. That is working out for us. Previously, it was by volume of data, and now, we can store as much data as we want."
"The solution's pricing is competitive. I rate the solution's pricing a seven out of ten. The price of the solution could be cheaper."
"The solution's pricing is costly."
"Splunk has been fairly expensive, but it has been predictable."
"Licensing cost is the biggest argument I get from those divesting from Splunk. There are those within our organization who say we are going to go to other tools since Splunk is too expensive."
"Splunk Infrastructure Monitoring is an expensive solution."
"Splunk Observability Cloud is expensive."
"This is an expensive solution."
Information not available
report
Use our free recommendation engine to learn which Network Monitoring Software solutions are best for your needs.
915,341 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Financial Services Firm
11%
Manufacturing Company
9%
Outsourcing Company
8%
Construction Company
8%
Comms Service Provider
18%
Construction Company
13%
Outsourcing Company
12%
University
6%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business36
Midsize Enterprise10
Large Enterprise72
No data available
 

Questions from the Community

What needs improvement with SignalFx?
Regarding dashboard customization, while Splunk has many dashboard building options, customers sometimes need to create specific dashboards, particularly for applicative metrics such as Java and pr...
What is your primary use case for SignalFx?
The solution involves observability in general, such as Application Performance Monitoring, and generally addresses digital applications, web applications, sites, and mobile applications. I worked ...
What advice do you have for others considering SignalFx?
We're a customer and end-user. Currently, in France, we cannot use the artificial intelligence option. While this option is enabled for the United States and many countries, it's not yet available ...
What needs improvement with ThreatSync+ NDR?
There are definitely areas for improvements in ThreatSync NDR, as no product is perfect. Its effectiveness depends on proper network visibility, so if important traffic segments are not mirrored or...
What is your primary use case for ThreatSync+ NDR?
I use ThreatSync NDR for monitoring across our hybrid and cloud infrastructure. For monitoring in our hybrid and cloud infrastructure using ThreatSync NDR, we investigate indicators such as IP addr...
What advice do you have for others considering ThreatSync+ NDR?
If I am evaluating an NDR solution for medium to large enterprises, especially with our experience using it with our WatchGuard security products, ThreatSync NDR delivers strong visibility, intelli...
 

Also Known As

Splunk Infrastructure Monitoring, Splunk Real User Monitoring (RUM), Splunk Synthetic Monitoring
No data available
 

Overview

 

Sample Customers

Sunrun, Yelp, Onshape, Tapjoy, Symphony Commerce, Chairish, Clever, Grovo, Bazaar Voice, Zenefits, Avalara
Information Not Available
Find out what your peers are saying about Splunk Observability Cloud vs. ThreatSync NDR and other solutions. Updated: September 2026.
915,341 professionals have used our research since 2012.