What users are saying about

Anomali Threat Platform

2 Ratings
<a href='https://www.trustradius.com/static/about-trustradius-scoring' target='_blank' rel='nofollow'>trScore algorithm: Learn more.</a>
Score 8.1 out of 101

Splunk Enterprise

188 Ratings
<a href='https://www.trustradius.com/static/about-trustradius-scoring' target='_blank' rel='nofollow'>trScore algorithm: Learn more.</a>
Score 8.5 out of 101

Add comparison

Likelihood to Recommend

Anomali Threat Platform

Being the best threat intelligence platform/tool on the market, it is fantastic in terms of performance and it has taken a lot of burden of curating and weeding through false positives off of our team freeing them up to focus on manual threat hunting and content building.
No photo available

Splunk Enterprise

Splunk is a great data analytics tool for you if you have a large amount of data to analyze. Splunk provides accurate and real-time analysis of data through its dashboard. But if you not quite a technical person or not willing to learn Splunk before using it, I will not recommend it to you. Also, Splunk is less appropriate for static data.
Rahul Shinde profile photo

Feature Rating Comparison

Security Information and Event Management (SIEM)

Anomali Threat Platform
Splunk Enterprise
8.8
Centralized event and log data collection
Anomali Threat Platform
Splunk Enterprise
9.4
Correlation
Anomali Threat Platform
Splunk Enterprise
8.0
Event and log normalization
Anomali Threat Platform
Splunk Enterprise
9.3
Deployment flexibility
Anomali Threat Platform
Splunk Enterprise
9.0
Integration with Identity and Access Management Tools
Anomali Threat Platform
Splunk Enterprise
7.8
Custom dashboards and views
Anomali Threat Platform
Splunk Enterprise
9.5
Host and network-based intrusion detection
Anomali Threat Platform
Splunk Enterprise
8.8

Pros

  • Fantastic UI
  • STAXXX for sharing intelligence
  • Threat Intelligence feeds
  • Automation and collaboration cuts work down for the analysts
No photo available
  • Splunk is flexible and extensible, able to ingest logs from disparate systems using disparate formats and disparate file types. If the ability exists to make the logs human readable (either natively or via a script), Splunk can ingest it.
  • Splunk's flexibility in how you parse, format, and enhance your data is amazingly deep. When you start event typing, tagging, aliasing, and creating data models, you start to really open up Splunk's capabilities.
  • Splunk scales very well in large environments. Adding additional indexers as your environment grows is pretty trivial and its ability to do multi-site clustering and search head clustering provides load balancing and redundancy that's inherent to the product.
Kenneth Taitingfong profile photo

Cons

No answers on this topic
  • Splunk's search language goes very deep. To do some of the more advanced formatting or statistical analysis, there's a bit of a learning curve. Splunk training for learning the search language and manipulating your data can cost anywhere from $500.00 to $1500.00 (although a good number of free training exists).
  • Splunk's dashboard capabilities are pretty decent but to do more exciting visualizations requires a bit of development using simple XML, Java script, and CSS.
  • Splunk releases minor revisions very quickly but because of the sheer number of bugs we've run into, we've upgraded our environment four times in nine months.
Kenneth Taitingfong profile photo

Likelihood to Renew

No score
No answers yet
No answers on this topic
Splunk Enterprise7.7
Based on 15 answers
We are using Splunk extensively in our projects and we have recently upgraded to Splunk version 6.0 which is quite efficient and giving expected results. We keep track of updates and new features Splunk introduces periodically and try to introduce those features in our day to day activities for improvement in our reporting system and other tasks.
No photo available

Usability

No score
No answers yet
No answers on this topic
Splunk Enterprise9.9
Based on 2 answers
You can literally throw in a single word into Splunk and it will pull back all instances of that word across all of your logs for the time span you select (provided you have permission to see that data). We have several users who have taken a few of the free courses from Splunk that are able to pull data out of it everyday with little help at all.
Kenneth Taitingfong profile photo

Reliability and Availability

No score
No answers yet
No answers on this topic
Splunk Enterprise10.0
Based on 1 answer
When properly setup and configured, Splunk is extremely reliable.
No photo available

Support

No score
No answers yet
No answers on this topic
Splunk Enterprise8.9
Based on 3 answers
Support from Splunk to our company is extremely good . Our team developed many dash boards , reports and alerts in Splunk which saved so many hours of our development time and made us very very efficient . We are extremely happy with current functionality provided by Splunk and have no complaints at all . I would definitely recommend it to everyone
No photo available

Implementation

No score
No answers yet
No answers on this topic
Splunk Enterprise8.0
Based on 1 answer
Engage professional service early on in the implementation
No photo available

Alternatives Considered

No answers on this topic
I have used base syslog, which does not have the parse capabilities and Arcsight which has major limitations. Splunk is easy to roll out and very easy to evaluate. The interface is very intuitive and there are a lot of Splunk apps for different devices and technologies which makes the rollout and ROI time faster. Also, the SE's at Splunk are awesome.
Richard Wilbert, MBA profile photo

Scalability

No score
No answers yet
No answers on this topic
Splunk Enterprise9.1
Based on 1 answer
Splunk can scale in to the petabyte per day range which of course is awesome
Rick Yetter profile photo

Return on Investment

  • After the Initial startup cost, it has overall had a positive impact by increasing efficiency of the team and freeing up analysts to do manual threat hunting
No photo available
  • Dashboarding allows us to immediately get value without having to have a query to find things in logs.
  • Allows us to troubleshoot bugs faster.
  • Having everyone have access to certain indexes is less of a headache for it to manage.
No photo available

Pricing Details

Anomali Threat Platform

General
Free Trial
Free/Freemium Version
Premium Consulting/Integration Services
Entry-level set up fee?
No
Additional Pricing Details

Splunk Enterprise

General
Free Trial
Yes
Free/Freemium Version
Yes
Premium Consulting/Integration Services
Entry-level set up fee?
No
Additional Pricing Details