Likelihood to Recommend
As a SIEM tool for investigations, Exabeam is the best in class. The AI assigns numeric values to observed logs them presents high scores to the analyst in a simple dashboard. We can see what is a real threat and ignore so many false positives. Exabeam is the best SIEM was used from an alert fatigue perspective. The simple interface allows other teams not just InfoSec to utilize the tool; helpdesk for asset diagnoses, HR for staffing questions, etc.
Read full review
I will highly recommend this software because using Splunk
Cloud has helped us become more proactive about handling our security concerns and better manage our environment. It is one of the finest security software that is easy to use and also provides analytics. It has excellent features like creating dashboard security and managing features etc. So you must give it a try once! Read full review Pros Fast search times, unlike other competing solutions. The ability for engineers to obtain access to the command line interface for troubleshooting, at least for on-premise deployments. License is suitable for organisations with lots of logs to ingest. Hardware required for on premise deployments is well supported. Read full review Splunk Cloud allows me to search the volumes of information help in Windows Server Logs quickly and accurately. Splunk Cloud allows me to create Dashboards for everyday monitoring of multiple parameters. Splunk Cloud allows me to create and schedule reports for Management on network usage and statistics. Read full review Cons More and better drop-down menus, some items in threat hunter require you know subsets. Less dashboards, combine AA and DL without having separate logins. More complete playbooks are already built out. You have the structure set up for templates like malware and phishing, go further and completely build them out from start to finish, most companies would just use them and not personalize their configurations. Quarterly health checkup diagnostics of systems sent out to users. Read full review Splunk Cloud support is increasing a lot now a days and I see no cons other than the price factor to the other compared products. Overall Splunk Cloud is a very good product all together. I can see that Splunk Cloud can still improve in the form of SLA. Splunk Cloud generally lags behind the available splunk upgrades. They are always one version behind the one available for enterprise. Read full review Usability
Exabeam is very good at processing lots of logs without excessive licensing costs. It has a professional support team that's very quick to resolve any issues and provides custom parsers quickly and enables our analysts to search vast data sets without having to wait long for results to be returned. The product is getting more mature with new features every major release.
Read full review
Overall, it is very usable. I would like if recent searches were saved for longer because I always have to refer to my notes when I'm looking for something specific and it's been a few weeks. But that's a small issue, and the actual search and browsing interface is easy to use and powerful.
Read full review Support Rating
Exabeam Fusion has so many diffferent out reach meetings, webinars, community virtual coffees, and events that you can always stay abreast of what if happening and get new ideas for use cases. Their support actually answers their phones and can respond in chat instantly. With our cloud deployment Exabeam support teams can instantly see our systems and help us.
Read full review
Splunk Cloud support is sorely lacking unfortunately. The portal where you submit tickets is not very good and is lacking polish. Tickets are left for days without any updates and when chased it is only sometimes you get a reply back. I get the feeling the support team are very understaffed and have far too much going on. From what I know, Splunk is aware of this and seem to be trying to remedy it.
Read full review Alternatives Considered
Splunk Cloud blows
out of the water. The experience is night and day. We went from several highly stressed IT security professionals who were unsure if the data they were getting was valuable, to very happy IT security professionals who can now be more proactive and get all the information they need.
Read full review Return on Investment Reduced time to triage alerts. Reduced number of alerts which need escalation to senior tiers. The ability for analysts to quickly run playbooks for additional information and enrichment. Ability to retain data for longer periods for forensics purposes. Improved search performance compared with other SIEM solutions. Read full review The biggest return on investment is how quickly logs are now consumed, and how quickly we can follow events that occur in logs. The number of logs that can be consumed by Splunk is much higher than previous solutions. We have much better visibility into our logs, and are able to spot patterns in events with the built-in graphs and reports. Read full review ScreenShots