We performed a comparison between Splunk Enterprise Security and Splunk On-Call based on real PeerSpot user reviews.
Find out what your peers are saying about Microsoft, Splunk, Wazuh and others in Security Information and Event Management (SIEM)."The log query feature has been the most valuable because it's very good. You can put your data on the cloud and run queues from Sentinel. It will do it all very fast. I love that I don't have to upload it to an Excel file and then manually look for a piece of information. Sentinel is much faster and is good for big databases."
"Another area where it is helping us is in creating a single dashboard for our environment. We can collect all the logs into a log analytics workset and run queries on top of it. We get all the results in the dashboard. Even a layman can understand this stuff. The way Microsoft presents it is really incredible."
"Its inbuilt Kusto Query Language is a valuable feature. It provides the flexibility needed to leverage advanced data analytics rules and policies and enables us to easily navigate all our security events in a single view. It helps any user easily understand the data or any security lags in their data and applications."
"Free ingestion for Azure logs (with E5 licence)"
"The UI of Sentinel is very good and easy to use, even for beginners."
"Microsoft Sentinel comes preloaded with templates for teaching and analytics rules."
"One of the most valuable features of Microsoft Sentinel is that it's cloud-based."
"There are some very powerful features to Sentinel, such as the integration of various connectors. We have a lot of departments that use both IaaS and SaaS services, including M365 as well as Azure services. The ability to leverage connectors into these environments allows for large-scale data injection."
"The most valuable features include agility and Splunk Enterprise Security's ability to quickly search for alerted items, as well as the capacity to create custom alerts using the SQL language employed by Splunk."
"Alerts when a server is malfunctioning, monitors external attacks, and takes action to stop spreading viruses."
"The UI of Splunk makes it easier for our analysts to move around and see what they need to see."
"The most useful feature for me is the ability to create different kinds of alerts and set a different kind of denominator that will capture the real event. That is helpful for a power user like me."
"The product is adept at log mining."
"Splunk is a user-friendly solution."
"It has a big user base, so the community is useful."
"Our clients are easily able to modify and evolve their implementations."
"VictorOps has been good enough for us and it's effective for our needs in case of an on-call escalation process."
"The flexible schedule is the most valuable feature. It was very easy to set out a rotation."
"The alert calling feature is the best because notifications are delivered via phone messages."
"The most valuable feature of the solution is helpdesk escalation."
"Transmogrifier and automatic solution report gives me a report with the solution and the way to solve issues when an error occurred."
"If we want to use more features, we have to pay more. There are multiple solutions on the cloud itself, but the pricing model package isn't consistent, which is confusing to clients."
"The solution could improve the playbooks."
"The interface could be more user-friendly. It''s a small improvement that they could make if they wanted to."
"Microsoft should improve Sentinel, considering that from the legacy systems, it cannot collect logs."
"Sentinel's alerts and notifications are not fully optimized for mobile devices. The overall reporting and the analytics processes for the end user should also be improved. Also, the compatibility and availability of data sources and reports are not always perfect."
"They could use some kind of workbook. There is some limitation doing the editing and creating the workbook."
"The playbook development environment is not as rich as it should be. There are multiple occasions when we face problems while creating the playbook."
"The product can be improved by reducing the cost to use AI machine learning."
"The upgrading process could be smoother."
"It needs more thoroughly tested releases. Every new big version (6, 7, etc.) has had so many bugs that it makes me wary of customers upgrading right away."
"Better directions on search head clusters."
"The solution could improve by making it more business analysis oriented. The way it is now is designed more for developers."
"An area of improvement would be the licensing of the solution. They need a free license, which would allow faster lead times."
"Splunk is more expensive than other solutions."
"It's difficult to set up initially, and their billing model is also a bit complicated."
"The product could be cheaper."
"At that stage, all our needs are fulfilled, but at the beginning, we had some feature requests and they were deployed during their roadmap."
"Should have more YouTube webinars."
"There could be improvements with communicating an incident or alert."
"The solution can be improved by including a wider list of permissions."
"The third-party configuration tool could be easier to use."
Splunk Enterprise Security is ranked 2nd in Security Information and Event Management (SIEM) with 228 reviews while Splunk On-Call is ranked 8th in IT Alerting and Incident Management with 10 reviews. Splunk Enterprise Security is rated 8.4, while Splunk On-Call is rated 8.6. The top reviewer of Splunk Enterprise Security writes "It has a drag-and-drop interface, so you don't need to know SQL or Java to construct a query ". On the other hand, the top reviewer of Splunk On-Call writes "Allows us to create flexible schedules for on-call rotations". Splunk Enterprise Security is most compared with Wazuh, Dynatrace, IBM Security QRadar, Elastic Security and Azure Monitor, whereas Splunk On-Call is most compared with PagerDuty Operations Cloud, Opsgenie, New Relic, Everbridge IT Alerting and xMatters .
We monitor all Security Information and Event Management (SIEM) reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.