Cancel
You must select at least 2 products to compare!
Devo Logo
Read 16 Devo reviews
14,305 views|5,499 comparisons
Splunk Logo
82,897 views|67,727 comparisons
Zabbix Logo
51,623 views|40,208 comparisons
Comparison Buyer's Guide
Executive Summary
Updated on Sep 5, 2022

We performed a comparison between Splunk and Zabbix based on our users’ reviews in four categories. After reading all of the collected data, you can find our conclusion below.

  • Ease of Deployment: Splunk users share mixed reviews on deployment. Zabbix users say deployment is straightforward and fast.
  • Features: Users of both products are happy with their stability and scalability.

    Splunk users like the solution’s logging and data capabilities. Reviewers mention that the monitoring could be improved and that it is not so user-friendly.

    Zabbix users say it is a mature solution that integrates well with Microsoft Office but that its UI needs improvement.
  • Pricing: Most Splunk users say that it is an expensive solution. Zabbix is open-source and free of charge.
  • Service and Support: Most Splunk and Zabbix users are satisfied with the technical support.
  • ROI: Reviewers of both products report seeing an ROI.

Comparison Results: In this comparison, Zabbix comes out on top. When compared to Splunk, it is easier to deploy and is open-source.

To learn more, read our detailed Security Information and Event Management (SIEM) Report (Updated: November 2022).
656,862 professionals have used our research since 2012.
Featured Review
Quotes From Members
We asked business professionals to review the solutions they use.
Here are some excerpts of what they said:
Pros
"The alerting is much better than I anticipated. We don't get as many alerts as I thought we would, but that nobody's fault, it's just the way it is.""The user interface is really modern. As an end-user, there are a lot of possibilities to tailor the platform to your needs, and that can be done without needing much support from Devo. It's really flexible and modular. The UI is very clean.""The most valuable feature is definitely the ability that Devo has to ingest data. From the previous SIEM that I came from and helped my company administer, it really was the type of system where data was parsed on ingest. This meant that if you didn't build the parser efficiently or correctly, sometimes that would bring the system to its knees. You'd have a backlog of processing the logs as it was ingesting them.""Devo helps us to unlock the full power of our data because they have more than 450 parsers, which means that we can ingest pretty much any type of log data.""The ability to have high performance, high-speed search capability is incredibly important for us. When it comes to doing security analysis, you don't want to be doing is sitting around waiting to get data back while an attacker is sitting on a network, actively attacking it. You need to be able to answer questions quickly. If I see an indicator of attack, I need to be able to rapidly pivot and find data, then analyze it and find more data to answer more questions. You need to be able to do that quickly. If I'm sitting around just waiting to get my first response, then it ends up moving too slow to keep up with the attacker. Devo's speed and performance allows us to query in real-time and keep up with what is actually happening on the network, then respond effectively to events.""It's very, very versatile.""The most valuable feature is that it has native MSSP capabilities and maintains perfect data separation. It does all of that in a very easy-to-manage cloud-based solution.""Devo provides a multi-tenant, cloud-native architecture. This is critical for managed service provider environments or multinational organizations who may have subsidiaries globally. It gives organizations a way to consolidate their data in a single accessible location, yet keep the data separate. This allows for global views and/or isolated views restricted by access controls by company or business unit."

More Devo Pros →

"Its dashboard is valuable. If you have a good knowledge of how to create a dashboard, you can create any dashboard related to cybersecurity. If fine-tuned, the alarms that are triggered for instant review are also very valuable and useful.""The initial setup isn't overly complex.""The data analysis part is good in Splunk, which is something that I like the most. It is also quite easy to use. Its dashboards, visualizations, and analytics are good.""The level of robustness on offer is very good.""It allows us to digest the information, the data, the different data streams, so we can make decisions based upon information that we receive, and it is pretty robust.""There are quite a lot of things that we find useful. Splunk agents are useful and good. Its UI is quite impressive.""The integration is seamless with many devices and operating systems.""The most valuable features are how stable and easy to use Splunk is."

More Splunk Pros →

"Zabbix has a roadmap and they are continuously and frequently adding new features.""The solution is open-source, easy to manage, and user-friendly making it easy for anyone to use.""The most valuable features in Zabbix are those that help us overcome bottlenecks in CPU usage, as well as reduce memory delay. I know that we have only reached the tip of the iceberg of what Zabbix's features can do for us, and we have not used all of them yet.""The most valuable feature is the monitoring of virtual machines.""We have found that Zabbix is more easy to use than other applications.""There is a problems page that shows us every warning or problem that occurs on our VMs globally. The map screen is also really useful because this is something that was missing. I don't know every other tool in the market. So, I don't know if this is a good point of only Zabbix, or other tools are also doing it, but from my point of view, this is the most useful page that I use, along with the problems page that efficiently lists the problem, recovery time, ending hours, starting hours, and so on.""The initial setup was very quick. The first time it was long because I didn't know it yet. I was only using Windows. The first time was very difficult because of the operating system.""The performance and bandwidth are valuable features."

More Zabbix Pros →

Cons
"Where Devo has room for improvement is the data ingestion and parsing. We tend to have to work with the Devo support team to bring on and ingest new sources of data.""From our experience, the Devo agent needs some work. They built it on top of OS Query's open-source framework. It seems like it wasn't tuned properly to handle a large volume of Windows event logs. In our experience, there would definitely be some room for improvement. A lot of SIEMs on the market have their own agent infrastructure. I think Devo's working towards that, but I think that it needs some improvement as far as keeping up with high-volume environments.""I would like to have the ability to create more complex dashboards.""There's room for improvement within the GUI. There is also some room for improvement within the native parsers they support. But I can say that about pretty much any solution in this space.""The Activeboards feature is not as mature regarding the look and feel. Its functionality is mature, but the look and feel is not there. For example, if you have some data sets and are trying to get some graphics, you cannot change anything. There's just one format for the graphics. You cannot change the size of the font, the font itself, etc.""We only use the core functionality and one of the reasons for this is that their security operation center needs improvement.""An admin who is trying to audit user activity usually cannot go beyond a day in the UI. I would like to have access to pages and pages of that data, going back as far as the storage we have, so I could look at every command or search or deletion or anything that a user has run. As an admin, that would really help. Going back just a day in the UI is not going to help, and that means I have to find a different way to do that.""The overall performance of extraction could be a lot faster, but that's a common problem in this space in general. Also, the stock or default alerting and detecting options could definitely be broader and more all-encompassing. The fact that they're not is why we had to write all our own alerts."

More Devo Cons →

"We had some connections issues with the solution at the beginning.""You do need a lot of training and certification with this product.""The cluster environment should be improved. We have a cluster. In the Splunk cluster environment, in the case of heavy searches and heavy load, the Splunk cluster goes down, and we have to put it in the maintenance mode to get it back. We are not able to find the actual culprit for this issue. I know that cluster has RF and SF, but it has been down so many times. There should be something in Splunk to help users to find the reason and the solution for such issues.""Splunk is more expensive than other solutions.""Splunk needs to be able to hold more days of data. At the moment it only holds three months of data.""The implementation and the scanning of the logs can be difficult.""I would like to see more SIEM functionality and a better ticket tool.""Splunk can be an expensive solution. Technical support could be improved as well."

More Splunk Cons →

"One of the things we don't like is that Zabbix has a license structure with a price that is high compared to the competition. It's very high, for example, compared to something like Microsoft Teams.""The user interface could be a bit better. They could update it a bit.""There's a small module of APM, however, it is not an enhanced version. People usually ask for a full-fledged APM solution.""The reports are not great and should be improved.""I would like to see a more flexible mobile client, and better HA out of the box.""There are not too much documentation or manuals. We found the tutorials very easy to understand but do not go deep enough in the use of Zabbix. We need more manuals, proper use, documentation, etc.""The System Center Operations Manager can be improved.""The APM monitoring has room for improvement, although I hear that the new 5.2 version has some improvements in that area, and I'd like to give that a go. I would like to see a few more templates out there for different styles of monitoring. I use the Grafana interface for reporting. I would also like it to have an out-of-the-box ability to email reports. You can create reports, but to be able to email those reports would be really helpful. I've got users who are not interested in logging in and generating a report. They want it all pre-canned and sent to an email address. It would also be really handy if we could pin certain reports up onto platforms such as Teams or SharePoint. A GUI for the proxy server would be cool to have for debugging purposes and for the support teams to have a look at, but I don't know whether that's really feasible to do. I get enough from the log files themselves."

More Zabbix Cons →

Pricing and Cost Advice
  • "I'm not involved in the financial aspect, but I think the licensing costs are similar to other solutions. If all the solutions have a similar cost, Devo provides more for the money."
  • "Devo is definitely cheaper than Splunk. There's no doubt about that. The value from Devo is good. It's definitely more valuable to me than QRadar or LogRhythm or any of the old, traditional SIEMs."
  • "[Devo was] in the ballpark with at least a couple of the other front-runners that we were looking at. Devo is a good value and, given the quality of the product, I would expect to pay more."
  • "Be cautious of metadata inclusion for log types in pricing, as there are some "gotchas" with that."
  • "Devo was very cost-competitive... Devo did come with that 400 days of hot data, and that was not the case with other products."
  • "Our licensing fees are billed annually and per terabyte."
  • "I like the pricing very much. They keep it simple. It is a single price based on data ingested, and they do it on an average. If you get a spike of data that flows in, they will not stick it to you or charge you for that. They are very fair about that."
  • "Pricing is based on the number of gigabytes of ingestion by volume, and it's on a 30-day average. If you go over one day, that's not a big deal as long as the average is what you expected it to be."
  • More Devo Pricing and Cost Advice →

  • "The price is comparable."
  • "The pricing model is expensive and a nightmare based on the amount of data."
  • "The solution is a little expensive."
  • "It is economical than other solutions."
  • "Price-wise, if you compare QRadar to Splunk for SIEM functionality then they are in the same range but when you integrate SOAR with these solutions, Splunk takes the lead and is more competitive."
  • "Its pricing model can be improved."
  • "The pricing model is based on the number of gigabytes that you ingest into the Splunk system. So it can be an expensive solution."
  • "My customers have found the price of the solution to be high."
  • More Splunk Pricing and Cost Advice →

  • "This solution is completely open-source, so it is quite affordable."
  • "Zabbix is free but if you use it in production then you have to pay for it."
  • "My manager is very happy because it doesn't cost anything."
  • "This is an open-source solution that can be used free of charge."
  • "We were searching for an open source solution and Zabbix fit the bill because it is free and open source under the GPL license."
  • "The solution is free. However, many open-sourced tools start out free but eventually start charging."
  • "Its licensing is fair. It seems to be much cheaper than others."
  • "It is open source. If you want to have a subscription or official support, you can pay for it. They have different plans, which are not that expensive. The plans are based on per monitoring server, not per monitored equipment. So, it is not at all expensive, and you can also live without the support if you want a cheaper option."
  • More Zabbix Pricing and Cost Advice →

    report
    Use our free recommendation engine to learn which Security Information and Event Management (SIEM) solutions are best for your needs.
    656,862 professionals have used our research since 2012.
    Questions from the Community
    Top Answer:Devo, like other vendors, doesn't charge extra for playbooks and automation. That way, you are only paying for the side… more »
    Top Answer:I need more empowerment in reporting. For example, when I'm using Qlik or Power BI in terms of reporting for the… more »
    Top Answer:For tools I’d recommend:  -SIEM- LogRhythm -SOAR- Palo Alto XSOAR Doing commercial w/o both (or at least an XDR)… more »
    Top Answer:It would really depend on (1) which logs you need to ingest and (2) what are your use cases Splunk is easy for… more »
    Top Answer:Splunk handles a high amount of data very well. We use Splunk to capture information and as an aggregator for monitoring… more »
    Top Answer:There is less computing power needed for scaling.
    Top Answer:The service module started with version six. There is room for improvement, due to the fact that this first step looks… more »
    Top Answer:I'd rate the solution a nine out of ten. The good thing is that it is easy to test. This is one of my favorite benefits… more »
    Comparisons
    Wazuh logo
    Compared 11% of the time.
    Elastic Security logo
    Compared 7% of the time.
    Microsoft Sentinel logo
    Compared 5% of the time.
    LogRhythm SIEM logo
    Compared 5% of the time.
    Sumo Logic Security logo
    Compared 4% of the time.
    Microsoft Sentinel logo
    Compared 10% of the time.
    Elastic Security logo
    Compared 7% of the time.
    Wazuh logo
    Compared 6% of the time.
    Azure Monitor logo
    Compared 6% of the time.
    AppDynamics logo
    Compared 2% of the time.
    Nagios XI logo
    Compared 14% of the time.
    Nagios Core logo
    Compared 8% of the time.
    Centreon logo
    Compared 7% of the time.
    PRTG Network Monitor logo
    Compared 5% of the time.
    SolarWinds NPM logo
    Compared 4% of the time.
    Also Known As
    Splunk Enterprise Security
    Learn More
    Overview

    Devo is the only cloud-native logging and security analytics platform that releases the full potential of all your data to empower bold, confident action when it matters most. Only the Devo platform delivers the powerful combination of real-time visibility, high-performance analytics, scalability, multitenancy, and low TCO crucial for monitoring and securing business operations as enterprises accelerate their shift to the cloud.

    Splunk is a tool that provides log management, security information, and event management solutions that help organizations easily make their machine data accessible, usable, and valuable for everybody. Splunk utilizes operational intelligence to turn machine data into valuable information by monitoring and to analyze all activities. 

    Splunk is ideal for data monitoring and searching, since it correlates and indexes large volumes of data into a searchable container. This enables users to create alerts, reports, and visualizations in real time. Splunk provides an in-depth, real-time view of the health and performance of all layers of your tech stack so you can optimize your system’s performance by proactively detecting errors and quickly fixing them.

    These days, it is becoming more and more difficult to maintain a strong security posture. Cyber attacks are becoming more and more sophisticated, and attackers have access to more entrance points. By implementing Splunk’s threat intelligence tools, you can modernize your security operations in any setting or framework, making your corporate growth more effective and flexible. The advanced visibility that Splunk provides, allows security teams to quickly detect and remove malicious threats in their environment. 

    Some of the benefits of using Splunk include:

    • Complete visibility into your environment: With Splunk, you can break down data silos and get actionable insights from data sent from multi-cloud and on-premises deployments.
       
    • Multi-environment troubleshooting: Detect and remedy problems fast with real-time, complete visibility and insight into the performance of your entire IT environment.

    • Advanced threat detection: Protect your organization from threats with Splunk’s advanced machine learning, security analytics, and threat intelligence tools that provide a sophisticated alert system to help shorten triage times and raise true positive rates.

    • Access to updated security information: Stay on top of new and emerging threats from automatic security content updates delivered directly from the Splunk Threat Research Team.

    • Multiple deployment options: Splunk has flexible deployment options. It can be deployed on the cloud, on-premises, or hybrid - depending on your organization’s needs.

    • Automated insights: Splunk’s AI-driven insights can help you predict problems by applying multiple conditions, thresholds, and complex rules. The solution’s built-in data science capabilities automatically reduce background noise and speed up error resolution times.

    • Multiple integration options: Splunk seamlessly integrates with many devices and operating systems, including:

      • Amazon Web Services (AWS)
      • Google Cloud Platform (GCP)
      • Microsoft Azure
      • NewRelic

    Reviews from Real Users

    Splunk stands out among its competitors for a number of reasons. Two major ones are its flexible search query tools and its strong AI capabilities.

    A Solutions Consultant at a tech services company notes, “It provides a lot of analytics with the underlying AI engine, and it is a lot easier than other solutions. There are some products that do automated AI-based detection and drawing up charts, but for network monitoring and all of the monitoring aspects, it is quite a nice tool. It is very convenient for business users because they get more or less a lot of data readily available. If you're familiar with the Splunk query language, you can pretty much do whatever you want.”

    Zabbix is a free software tool traditionally used for monitoring your organization’s IT infrastructure, including networks, servers, virtual machines, and cloud services. Zabbix makes it possible for you to maintain control of your infrastructure by collecting any metric from any source. The solution also offers agentless monitoring, synthetic monitoring, custom collection methods, and data transformation.

    Zabbix offers:

    • Network monitoring
    • Server monitoring
    • Cloud monitoring
    • Application monitoring
    • Service monitoring

    Zabbix Features

    Zabbix has many valuable key features, including:

    Action Log, Anomaly Detection, Auditing, Automated Actions, Availability Reports, Capacity Planning, Custom Scripts, Custom Templates, Data Retrieval, Drill-Down Reports, Encryption, Event Correlation, History Data Analysis, Metric Collection, Multiple Authentication Methods, Multiple Severity Levels, Native WMI Support for Windows Agent, Network Discovery, Notifications, Root Cause Analysis, Trend Prediction, WMI Support, Web Services Widget-based Dashboards, Zero-Maintenance

    Zabbix Benefits

    There are several benefits to implementing Zabbix. Some of the biggest advantages the solution offers include:

    • Flexible deployment options: Zabbix can be deployed on-premises or in the cloud to help you stay fully in control of your data.

    • Unlimited scalability: Zabbix is scalable to any infrastructure. It can easily scale for your personal home, or can scale for a large enterprise environment.

    • Ready-to-use templates: Zabbix comes with ready-to-use templates which makes it easy to integrate with systems you already use.

    • External vault: Zabbix enables you to keep your data secure and safe by providing an external vault storage option.

    • High availability: By using Zabbix’s high availability solution, you can negate the risk of data loss and gain 24/7 uptime.

    • Partner and vendor-backed: The solution is backed by 250+ global partners and multiple external vendors, giving you confidence in the solution.

    Reviews from Real Users

    Below are some reviews and helpful feedback written by Zabbix users.

    PeerSpot user Shibu B., Regional Manager/ Service Delivery at ASPL Info Services, says, "The solution is quite mature and very stable. The monitoring capabilities of the product are excellent.” He also adds, “The solution is very easy to scale and the product is open-source, meaning there aren't any licensing costs associated with it.”

    Julian L., Senior Specialist Critical Infrastructure at an educational organization, comments that the solution is “A complete solution that doesn't cost anything, does what I need it to do, and has easy-to-use templates and very good scalability.” He also mentions “The agents are pretty cool. They're easy to roll out. The standard out-of-the-box templates are also pretty easy to use. The integration with other learning products is also good.”

    Faycal N., CEO/Founder at Zen Networks, praises the product, mentioning, “Its overall flexibility is most valuable. When our customers have some custom applications that are not necessarily covered by the community or a standard monitoring tool, we use Zabbix to build our own modules with our own templates. This feature has been useful in using Zabbix for infrastructure and IT monitoring. It has also been useful for industrial equipment monitoring. Zabbix is very lightweight. It is efficient in terms of performance because it doesn't use a lot of resources."

    Offer
    See Devo in Action

    See how Devo allows you to free yourself from data management, and make machine data and insights accessible.

    Learn more about Splunk
    Learn more about Zabbix
    Sample Customers
    United States Air Force, Rubrik, SentinelOne, Critical Start, NHL, Panda Security, Telefonica, CaixaBank, OpenText, IGT, OneMain Financial, SurveyMonkey, FanDuel, H&R Block, Ulta Beauty, Manulife, Moneylion, Chime Bank, Magna International, American Express Global Business Travel
    Splunk has more than 7,000 customers spread across over 90 countries. These customers include Telenor, UniCredit, ideeli, McKenney's, Tesco, and SurveyMonkey.
    Bodybuilding.com, LLC., ITtelligent Consulting Services,Eltele AS, Total Server Solutions, LLC., ChinaNetCloud
    Top Industries
    REVIEWERS
    Computer Software Company50%
    Comms Service Provider10%
    Retailer10%
    Insurance Company10%
    VISITORS READING REVIEWS
    Computer Software Company21%
    Comms Service Provider12%
    Government9%
    Financial Services Firm9%
    REVIEWERS
    Financial Services Firm19%
    Energy/Utilities Company10%
    Computer Software Company10%
    Government7%
    VISITORS READING REVIEWS
    Computer Software Company19%
    Financial Services Firm14%
    Comms Service Provider11%
    Government9%
    REVIEWERS
    Computer Software Company24%
    Comms Service Provider9%
    Aerospace/Defense Firm9%
    Retailer6%
    VISITORS READING REVIEWS
    Computer Software Company20%
    Comms Service Provider19%
    Government9%
    Financial Services Firm7%
    Company Size
    REVIEWERS
    Small Business21%
    Midsize Enterprise21%
    Large Enterprise58%
    VISITORS READING REVIEWS
    Small Business23%
    Midsize Enterprise16%
    Large Enterprise62%
    REVIEWERS
    Small Business32%
    Midsize Enterprise14%
    Large Enterprise54%
    VISITORS READING REVIEWS
    Small Business18%
    Midsize Enterprise14%
    Large Enterprise69%
    REVIEWERS
    Small Business47%
    Midsize Enterprise22%
    Large Enterprise31%
    VISITORS READING REVIEWS
    Small Business23%
    Midsize Enterprise18%
    Large Enterprise59%
    Buyer's Guide
    Security Information and Event Management (SIEM)
    November 2022
    Find out what your peers are saying about Splunk, Microsoft, IBM and others in Security Information and Event Management (SIEM). Updated: November 2022.
    656,862 professionals have used our research since 2012.

    Splunk is ranked 1st in Security Information and Event Management (SIEM) with 61 reviews while Zabbix is ranked 2nd in Network Monitoring Software with 41 reviews. Splunk is rated 8.2, while Zabbix is rated 8.6. The top reviewer of Splunk writes "Very versatile for many use cases". On the other hand, the top reviewer of Zabbix writes "Very mature, easy to scale, and free to use". Splunk is most compared with Microsoft Sentinel, Elastic Security, Wazuh, Azure Monitor and AppDynamics, whereas Zabbix is most compared with Nagios XI, Nagios Core, Centreon, PRTG Network Monitor and SolarWinds NPM.

    We monitor all Security Information and Event Management (SIEM) reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.