ConnectWise Automate, formerly LabTech, is a remote monitoring and management (RMM) platform. It provides powerful automation to discover and manage devices, monitor for problems, and scripts repetitive action.
$700
Splunk Enterprise Security
Score8.3 out of 10
N/A
Splunk Enterprise Security is an analytics-driven SIEM that helps to combat threats with actionable intelligence and advanced analytics at scale.
I recommend it to all IT colleagues; regardless of the size of the PCs with which you work most of the time, the application allows connection stability between computers that make it possible to continue working or taking care of the infrastructure from afar.
A de minimis incentive was given to thank the reviewer for their time. The incentive was not used to bias or drive a particular response, nor was the incentive contingent on a positive endorsement. More Info
Based on my experience, Splunk is a strong git for some environments and a poor match for others. The distinction is primarily based on infrastructure complexity and budget. It's perfect for large enterprises with a mix of on-prem/cloud infrastructure. It's not a perfect match for small teams with restricted resources.
A de minimis incentive was given to thank the reviewer for their time. The incentive was not used to bias or drive a particular response, nor was the incentive contingent on a positive endorsement. More Info
A de minimis incentive was given to thank the reviewer for their time. The incentive was not used to bias or drive a particular response, nor was the incentive contingent on a positive endorsement. More Info
Writes Powerful Queries: The queries that can be written using the Splunk Query Language are very powerful and highly customizable to meet every need. Ex: Writing queries to search the intersection of two different sources like Network and Endpoint Logs.
Offers Dashboard Abilities: Helps build complex panels for Dashboards in addition to providing several out-of-the-box panels. Ex: creating panels to calculate the performance of analysts in a given timezone.
Helpful Search Aids: It helps to set up complex custom alerts very easily. The interesting fields section is very helpful while threat hunting. Ex: It shows all the users and the frequency of each in a failed login event. The user list on the interesting fields is useful to look for suspicious logins.
A de minimis incentive was given to thank the reviewer for their time. The incentive was not used to bias or drive a particular response, nor was the incentive contingent on a positive endorsement. More Info
They have conflicting scheduling paradigms. When scheduling patching for clients, the 1st Friday is interpreted as the very first Friday of the month, even if this is the 1st of the month. For scripting, the 1st Friday of the month is interpreted as the 1st Friday of the 1st FULL WEEK of the month. This makes no sense to have two different interpretations, and makes it unreliable to schedule recurring scripts to fall when recurring maintenance does. The scripts need to be done manually because of this.
There is no way to dictate reboot orders for patch policies. This tied directly in with my first point. We have some clients that require reboot orders. This is not possible without having different patch policies for each server and specifying a time this way. But, there aren't small enough increments of time to make this reliable, plus patching duration might vary. Excluding reboots with patching and scheduling reboot scripts fixes this. However, this can't be done once on a recurring schedule due to the different scheduling paradigms already discussed. We have to schedule these manually each month.
A de minimis incentive was given to thank the reviewer for their time. The incentive was not used to bias or drive a particular response, nor was the incentive contingent on a positive endorsement. More Info
Improved User Interface Customization: While the interface is generally intuitive, providing more options for users to customize their dashboards and views would enhance the overall user experience. Tailoring the interface to specific roles or use cases could be a valuable addition.
Simplified Alert Management: Streamlining the process of managing alerts, such as grouping or categorizing them based on severity or type, would make it easier for security teams to prioritize and respond to incidents effectively.
Expanded Threat Intelligence Feeds: Increasing the variety and sources of threat intelligence feeds available within ES would provide a broader context for identifying and mitigating emerging threats, ensuring a more comprehensive defense against evolving attack vectors.
A de minimis incentive was given to thank the reviewer for their time. The incentive was not used to bias or drive a particular response, nor was the incentive contingent on a positive endorsement. More Info
The primary reason for this rating is that ConnectWise Automate is currently so integral to our operations that moving away would involve more man hours than we would realistically have to invest. However, ConnectWise Automate is also completely capable of meeting all of our business needs and customizable to the point where if something is not meeting those needs out of the box, it can be modified to do what we want. From only installing software on machines if a different software package exists, to push a new version of that software is available, to check if credentials for user/machine have been updated to our new standards and then updating them if they have not, ConnectWise Automate is capable of doing everything we ask of it.
A de minimis incentive was given to thank the reviewer for their time. The incentive was not used to bias or drive a particular response, nor was the incentive contingent on a positive endorsement. More Info
A de minimis incentive was given to thank the reviewer for their time. The incentive was not used to bias or drive a particular response, nor was the incentive contingent on a positive endorsement. More Info
Basic use of the product is fairly easy. Information about the machines you manage can be found in customizable dashboards, which can be unique for each user, and, therefore, properly suited to the users' needs/job function. This is not a 10 because some of the interfaces are very clunky (Patch Management), and some features are not intuitive and not well documented (reporting). Scripting and Patch Management have a fairly steep learning curve (For structure in patch management and syntax in scripting), but once learned, they work well.
A de minimis incentive was given to thank the reviewer for their time. The incentive was not used to bias or drive a particular response, nor was the incentive contingent on a positive endorsement. More Info
Maintaining hundreds or even 1000+ SOC use cases is really difficult, considering that the Data sources may not always send the data. A module that detects data freshness issues and detect data format changes would be a great help. the main challenge today using Splunk Enterprise Security is making sure that the detection rules are still working properly given all the changes that occur in data source applications. Also, maintaining the data collects on tens of thousands of servers and more than 100k workstations is a real company IT challenge: the splunkbase forwarder may not support old OS anymore, while these are the most important to monitor. Moving to the Open Telemetry collector has become essential so that only 1 agent is required for both SIEM and application observability.
A de minimis incentive was given to thank the reviewer for their time. The incentive was not used to bias or drive a particular response, nor was the incentive contingent on a positive endorsement. More Info
A de minimis incentive was given to thank the reviewer for their time. The incentive was not used to bias or drive a particular response, nor was the incentive contingent on a positive endorsement. More Info
It used to be great, but then they broke reporting, speed and responsiveness with version 11 and the new Patch Manager. It's really bad and their support people are way behind on fixing so many bugs. They have really gone downhill. If they don't get it together soon, we'll start looking around.
A de minimis incentive was given to thank the reviewer for their time. The incentive was not used to bias or drive a particular response, nor was the incentive contingent on a positive endorsement. More Info
It takes a long time for items to load if you are just generally searching through logs. It is best to use the data models which load faster but can be strange in terms of what is coming from which logs where. Yes, you can look it up, but this also requires familiarity with where things are and how to look them up.
A de minimis incentive was given to thank the reviewer for their time. The incentive was not used to bias or drive a particular response, nor was the incentive contingent on a positive endorsement. More Info
ConnectWise Automate lets you manage more endpoints, with enhanced productivity and improved service, all without increasing expenses. It can manage patches and updates across thousands of computers. We also use it for customized monitoring and alerting on workstations and servers. Monitoring is really robust and granular. It does a great job of gathering a TON of data about the network, and that data is searchable. There are a bunch of different reports built in. Integrates with Manage, Control, and other applications. It does a ton of stuff out of the box, and has endless customization options.
A de minimis incentive was given to thank the reviewer for their time. The incentive was not used to bias or drive a particular response, nor was the incentive contingent on a positive endorsement. More Info
It's good when it's responsive, but I've had times where I had to wait quite a while for a response. But these are typically the exceptions rather than the rule. When you do get a response it is always well-informed and appropriate. I would say they've been trending better over time with this.
A de minimis incentive was given to thank the reviewer for their time. The incentive was not used to bias or drive a particular response, nor was the incentive contingent on a positive endorsement. More Info
I experienced only on-line training, but the trainers were very professional and competent. Maybe it could be more useful if they also have an experience in projects because sometimes they didn't have a real project experience to communicate to the students. Anyway, it was very interesting and I learned many thing that's very difficoult (or maybe impossible!) to have by myself, aven if I have more than 10 years of Splunk activity experience.
A de minimis incentive was given to thank the reviewer for their time. The incentive was not used to bias or drive a particular response, nor was the incentive contingent on a positive endorsement. More Info
The Online training has been re-done and needs a lot more work. When you look at training in different roles, it shows a lot of the same topics but no explanation to what is different about them. Several times that topics are the exact same, but they make you re-take the same information for a different topic, instead of marking that you have already completed that portion of training.
A de minimis incentive was given to thank the reviewer for their time. The incentive was not used to bias or drive a particular response, nor was the incentive contingent on a positive endorsement. More Info
It was very interesting and I learned many thing that's very difficoult (or maybe impossible!) to have by myself. The only problem was that, when I worked with the Splunk Professional Services, I found some difference between the training contents and the information from PS. In addition is required a long experience on Splunk Enterprise for the data ingestion part, in other words I'm able to work with ES because I'm worling on Splunk since 11 years, otherwise I'd some problem.
A de minimis incentive was given to thank the reviewer for their time. The incentive was not used to bias or drive a particular response, nor was the incentive contingent on a positive endorsement. More Info
Start small and learn the in's and out's before making policies and rolling things out company wide. Ask the questions of why if you don't agree with something or your company does things a different way. Usually they are done a certain way for a reason. Start simple with roll out and slowly enable or add on the functionality that is needed.
A de minimis incentive was given to thank the reviewer for their time. The incentive was not used to bias or drive a particular response, nor was the incentive contingent on a positive endorsement. More Info
A de minimis incentive was given to thank the reviewer for their time. The incentive was not used to bias or drive a particular response, nor was the incentive contingent on a positive endorsement. More Info
I believe the monitoring and alerts in Continuum command is better, but [ConnectWise Automate (formerly LabTech)] does have stronger scripting, and perhaps a better interface. N-Central is inferior on all fronts to both. I did not make the purchasing decision. I would myself likely pick Continuum if I had to make a on the spot choice.
A de minimis incentive was given to thank the reviewer for their time. The incentive was not used to bias or drive a particular response, nor was the incentive contingent on a positive endorsement. More Info
Splunk enterprise is the only solution that we’ve been able to identify that provides risk based alerting, which allows our SOC to reduce analyst fatigue which would be a huge problem without it. Before RBA, there were thousands of alerts a day and it was impossible to review all of them
A de minimis incentive was given to thank the reviewer for their time. The incentive was not used to bias or drive a particular response, nor was the incentive contingent on a positive endorsement. More Info
for my exterience, unit pricing and billing frequency are correct. As I already said, I hint to have more discount flexibility, expecially with new customers, because there are competitors less expensive and very aggressive that are dangerous. In addition the possibility to don't pay the license for the development period could be a very interesting feature for the final customers.
A de minimis incentive was given to thank the reviewer for their time. The incentive was not used to bias or drive a particular response, nor was the incentive contingent on a positive endorsement. More Info
- 8 out of 10 and took 2 for the data pipeline and administration part. Even if you'd like to improve yourself or your team, you have to pay a lot of money and it could be more than GIAC education + cert. - Normalization for Data models and CPU-based searches can be a problem sometimes.
A de minimis incentive was given to thank the reviewer for their time. The incentive was not used to bias or drive a particular response, nor was the incentive contingent on a positive endorsement. More Info
I had a fantastic experience with Splunk Professional Services: they worked with us in our last SON project (a SOC migration for a very large customer) and helped to build a multi tenent environment even if ES isn't a multi tenant platform. Th Splunk PS was a very professional and competent people, he is italian and was able to speak with our italian customers.
A de minimis incentive was given to thank the reviewer for their time. The incentive was not used to bias or drive a particular response, nor was the incentive contingent on a positive endorsement. More Info
We found we were able to provide good monitoring of our customers sites which was an objective. However, that came at a significant time investment that never seemed to be finished.
We were able to negotiate a price that worked for us for an up-front purchase which was nice.
We found the pricing to be very competitive.
Bottom line for us was despite the pros of the product, we found other RMM solutions to be a better overall "value" due to not having to dedicate technicians to maintaining the product.
A de minimis incentive was given to thank the reviewer for their time. The incentive was not used to bias or drive a particular response, nor was the incentive contingent on a positive endorsement. TR verified that a representative sample of customers was invited. More Info
We have a 100% success rate on all our ES implementations due to the amazing documentation and Splunk enablement on the subject.
Our Splunk ES business has grown 100% YoY for the last 3 years.
In terms of long term management and maintenance, ES has been highly stable and predictable, reducing our overhead on costly services team for ad hoc maintenance work.