<a href='https://www.trustradius.com/static/about-trustradius-scoring#question3' target='_blank' rel='nofollow'>Customer Verified: Read more.</a>
Top Rated
228 Ratings
2 Ratings
<a href='https://www.trustradius.com/static/about-trustradius-scoring' target='_blank' rel='nofollow'>trScore algorithm: Learn more.</a>
Score 9 out of 101

Splunk Enterprise

<a href='https://www.trustradius.com/static/about-trustradius-scoring#question3' target='_blank' rel='nofollow'>Customer Verified: Read more.</a>
Top Rated
228 Ratings
<a href='https://www.trustradius.com/static/about-trustradius-scoring' target='_blank' rel='nofollow'>trScore algorithm: Learn more.</a>
Score 8.7 out of 101

Likelihood to Recommend

Alert Logic Log Correlation and Analysis

Alert Logic is ideally placed to support and protect cloud infrastructure and services such as AWS hosted services. It is less appropriate for platform as a service as this would be addressed by the provider in question. It would also be ideally suited to on-premise and hybrid cloud scenarios to protect services from attacks and breaches.
No photo available

Splunk Enterprise

Splunk is well suited for applications or companies that process and store large data. Some of these applications may be legacy but as long as you can retrieve this data, then you can use Splunk to transform this data into meaningful reports or dashboards. In addition, Splunk is great for a 24/7 monitoring operations tool that can be set up to send alerts for production support. Splunk is less suited for applications that may already have a GUI because the Splunk features would be less superior than what a graphical user interface could provide in terms of features and customization.
Trung Pham profile photo

Feature Rating Comparison

Security Information and Event Management (SIEM)

Alert Logic Log Correlation and Analysis
Splunk Enterprise
8.7
Centralized event and log data collection
Alert Logic Log Correlation and Analysis
Splunk Enterprise
9.2
Correlation
Alert Logic Log Correlation and Analysis
Splunk Enterprise
8.4
Event and log normalization
Alert Logic Log Correlation and Analysis
Splunk Enterprise
9.0
Deployment flexibility
Alert Logic Log Correlation and Analysis
Splunk Enterprise
8.1
Integration with Identity and Access Management Tools
Alert Logic Log Correlation and Analysis
Splunk Enterprise
7.8
Custom dashboards and views
Alert Logic Log Correlation and Analysis
Splunk Enterprise
9.2
Host and network-based intrusion detection
Alert Logic Log Correlation and Analysis
Splunk Enterprise
8.8

Pros

Alert Logic Log Correlation and Analysis

  • Alert Logic provides very technical solutions to address security risks. However much of the benefit is from a human level understanding of the threats seen.
  • As a company, they are profiling thousands of companies and are better able to predict threats such as denial of service attacks and warn organisations ahead of time.
No photo available

Splunk Enterprise

  • SPLUNK has a quick learning curve and can be easily self-taught. For example, there are plenty of resources available such as tutorials and search tools. There is really no prerequisite for learning how to use Splunk.
  • SPLUNK Enterprise provides plenty of useful documentation and user support which makes it easy for anyone to learn and start using SPLUNK in a very short period of time. There are also examples and user feedback that is helpful if you need more advanced implementations.
  • SPLUNK is very powerful, yet simple. For instance, you can set up a dashboard in one day provided you have admin rights and access to the data you want to Splunk.
Trung Pham profile photo

Cons

Alert Logic Log Correlation and Analysis

  • Overall the product and service works well and addresses all our key requirements so we have no real negatives to share.
No photo available

Splunk Enterprise

  • Search head clustering is great for reducing configuration differences among standalone search heads. The biggest problem with search head clustering (at the moment) is administration of non-knowledge object functions, like user roles and capabilities. Tasks like these must be done using Linux text editors and forces a rolling restart of all the search heads in the cluster.
  • Creating custom applications in a search head cluster has also taken a step backwards. One strength I didn't mention earlier, is the ability to segregate users from data sets they shouldn't see. One method to assist partitioning users is with custom applications (aka sandboxes). However, like user administration, creating the "sandbox" requires Linux skills as opposed to the previous GUI-driven method.
  • Querying LDAP datasets is limited to users with admin capabilities. That's okay only if the entire user community in your shop are administrators. Thus a great source for analyzing active directory membership is hindered until Splunk gets this fixed.
No photo available

Likelihood to Renew

Alert Logic Log Correlation and Analysis

No score
No answers yet
No answers on this topic

Splunk Enterprise

Splunk Enterprise 10.0
Based on 16 answers
We are using Splunk extensively in our projects and we have recently upgraded to Splunk version 6.0 which is quite efficient and giving expected results. We keep track of updates and new features Splunk introduces periodically and try to introduce those features in our day to day activities for improvement in our reporting system and other tasks.
No photo available

Usability

Alert Logic Log Correlation and Analysis

No score
No answers yet
No answers on this topic

Splunk Enterprise

Splunk Enterprise 9.0
Based on 3 answers
You can literally throw in a single word into Splunk and it will pull back all instances of that word across all of your logs for the time span you select (provided you have permission to see that data). We have several users who have taken a few of the free courses from Splunk that are able to pull data out of it everyday with little help at all.
Kenneth Taitingfong profile photo

Reliability and Availability

Alert Logic Log Correlation and Analysis

No score
No answers yet
No answers on this topic

Splunk Enterprise

Splunk Enterprise 10.0
Based on 1 answer
When properly setup and configured, Splunk is extremely reliable.
No photo available

Support

Alert Logic Log Correlation and Analysis

No score
No answers yet
No answers on this topic

Splunk Enterprise

Splunk Enterprise 9.0
Based on 4 answers
Support has been good and prompt when needed.
No photo available

Implementation

Alert Logic Log Correlation and Analysis

No score
No answers yet
No answers on this topic

Splunk Enterprise

Splunk Enterprise 9.0
Based on 2 answers
Smooth without too many major issues.
No photo available

Alternatives Considered

Alert Logic Log Correlation and Analysis

There are alternatives some of which have a greater overhead and require more in-house technical skills. Alert Logic provide a full service so for us this was a better solution.
No photo available

Splunk Enterprise

Splunk is certainly much more versatile than either of these three products. Unless ArcSight makes a "connector" for your product, you will be required to use Flex Connectors which is an additional license and apparently requires some serious development. Without Logger, you can't perform free form searches so you must know how your data is being normalized before you can find it.
McAfee Nitro uses Flash which presents a number of challenges itself. During our POC, it also misidentified McAfee Virus Scan Enterprise updates as malware traffic.
QRadar neither excelled in any one place and performed poorly during our POC, but it was unable to be as flexible as Splunk with custom data sources.
Kenneth Taitingfong profile photo

Scalability

Alert Logic Log Correlation and Analysis

No score
No answers yet
No answers on this topic

Splunk Enterprise

Splunk Enterprise 9.1
Based on 1 answer
Splunk can scale in to the petabyte per day range which of course is awesome
Rick Yetter profile photo

Return on Investment

Alert Logic Log Correlation and Analysis

  • Return on Investment is measured in how protected our reputation is and Alert Logic contributes to this is a large way.
  • Alert Logic provides excellent information security assurance to the business and allows us to feel more proactive.
No photo available

Splunk Enterprise

  • Positive - Less time to investigate logs and come up with a solution.
  • Positive - Splunk alerts help us to identify the problems beforehand.
  • Positive - Splunk reporting helps us to visualize everyday application performance and business analysis
No photo available

Pricing Details

Alert Logic Log Correlation and Analysis

General

Free Trial
Free/Freemium Version
Premium Consulting/Integration Services
Entry-level set up fee?
No
Additional Pricing Details

Splunk Enterprise

General

Free Trial
Yes
Free/Freemium Version
Yes
Premium Consulting/Integration Services
Entry-level set up fee?
No
Additional Pricing Details

Add comparison