FireMon vs. Splunk Enterprise

Overview
ProductRatingMost Used ByProduct SummaryStarting Price
FireMon
Score 7.8 out of 10
Enterprise companies (1,001+ employees)
FireMon is a real-time security policy management solution built for today’s complex multi-vendor, enterprise environments. Supporting the latest firewall and policy enforcement technologies spanning on-premises networks to the cloud, FireMon delivers visibility and control across the entire IT landscape to automate policy changes, meet compliance standards, to minimize policy-related risk. Since creating their policy management solution in 2004, FireMon states they've helped…N/A
Splunk Enterprise
Score 8.6 out of 10
N/A
Splunk is software for searching, monitoring, and analyzing machine-generated big data, via a web-style interface. It captures, indexes and correlates real-time data in a searchable repository from which it can generate graphs, reports, alerts, dashboards and visualizations.N/A
Pricing
FireMonSplunk Enterprise
Editions & Modules
No answers on this topic
No answers on this topic
Offerings
Pricing Offerings
FireMonSplunk Enterprise
Free Trial
YesYes
Free/Freemium Version
NoYes
Premium Consulting/Integration Services
YesNo
Entry-level Setup FeeOptionalNo setup fee
Additional Details
More Pricing Information
Community Pulse
FireMonSplunk Enterprise
Considered Both Products
FireMon
Chose FireMon
To be blunt, at the time of purchase most of these products appeared to do the same things in the same ways. What really brought us to the table with FireMon six years ago was their willingness to earn our business, and to this day they remain just as committed to keeping our …
Splunk Enterprise

No answer on this topic

Features
FireMonSplunk Enterprise
Security Information and Event Management (SIEM)
Comparison of Security Information and Event Management (SIEM) features of Product A and Product B
FireMon
-
Ratings
Splunk Enterprise
7.2
58 Ratings
8% below category average
Centralized event and log data collection00 Ratings8.255 Ratings
Correlation00 Ratings8.256 Ratings
Event and log normalization/management00 Ratings8.557 Ratings
Deployment flexibility00 Ratings7.151 Ratings
Integration with Identity and Access Management Tools00 Ratings6.451 Ratings
Custom dashboards and workspaces00 Ratings6.857 Ratings
Host and network-based intrusion detection00 Ratings5.440 Ratings
Data integration/API management00 Ratings8.17 Ratings
Behavioral analytics and baselining00 Ratings6.46 Ratings
Rules-based and algorithmic detection thresholds00 Ratings7.66 Ratings
Response orchestration and automation00 Ratings7.05 Ratings
Reporting and compliance management00 Ratings6.87 Ratings
Incident indexing/searching00 Ratings7.28 Ratings
Best Alternatives
FireMonSplunk Enterprise
Small Businesses
NinjaOne
NinjaOne
Score 9.1 out of 10
AlienVault USM
AlienVault USM
Score 6.8 out of 10
Medium-sized Companies
NinjaOne
NinjaOne
Score 9.1 out of 10
Sumo Logic
Sumo Logic
Score 8.9 out of 10
Enterprises
Cisco Routers
Cisco Routers
Score 8.9 out of 10
Sumo Logic
Sumo Logic
Score 8.9 out of 10
All AlternativesView all alternativesView all alternatives
User Ratings
FireMonSplunk Enterprise
Likelihood to Recommend
7.8
(69 ratings)
7.8
(78 ratings)
Likelihood to Renew
6.8
(7 ratings)
10.0
(17 ratings)
Usability
7.3
(3 ratings)
8.3
(11 ratings)
Availability
7.3
(1 ratings)
10.0
(1 ratings)
Performance
9.1
(1 ratings)
-
(0 ratings)
Support Rating
7.7
(17 ratings)
8.4
(17 ratings)
Online Training
-
(0 ratings)
8.0
(1 ratings)
Implementation Rating
9.1
(1 ratings)
9.0
(2 ratings)
Product Scalability
7.8
(48 ratings)
9.1
(1 ratings)
User Testimonials
FireMonSplunk Enterprise
Likelihood to Recommend
FireMon
FireMon is best used in a large environment (for example, I have >100
firewalls in my environment). It's best used when trying to improve
security posture and showing changes in firewall security over time. It
might not be the best choice for smaller environments or those that aren't concerned about security management.
Read full review
Cisco
It's well suited for what I do, which is network security operations. And that's for anything from troubleshooting incidents, troubleshooting performance, troubleshooting for the purpose of a compliance and auditing. It's not best suited for users who are new in terms of they're new to the product and they have expectations that probably Splunk cannot meet.
Read full review
Pros
FireMon
  • Give good real time reporting for anyone making a change to any of our firewalls
  • Provides good reporting tools that are out of box
  • Provide good customization tools that is specific to our needs
  • Upgrades are a simple process and support does relatively well with assisting us.
Read full review
Cisco
  • It is very useful in creating custom rules for analyzing system logs and display relevant information. The query language is very easy to learn.
  • We can create custom UI to visualize the output of our data. The interface is very flexible. It also allows the sharing of rules among users.
  • There is an open online community to help others. Stackoverflow also has a splunk community. These resources make it more convenient to learn.
Read full review
Cons
FireMon
  • Some features could be added to the existing functionality which include NAT rules usage
  • Rule expiration normalization from firewalls rather than entering them in rule documentation
  • .csv exports of the files from the firewall pane only gives usage for 30 days by default and that should be increased
Read full review
Cisco
  • Splunk light limits number of users to 5. Wish there was a flexible license, where one could add more users.
  • Splunk light does not let you add > few realtime alerts. Wish there was a flexible license, where one could add as many realtime alerts as wanted.
  • Better insight into daily ingestion values
Read full review
Likelihood to Renew
FireMon
The shell is locked out and we can't run any general centos commands. The implementation and maintainence of the arch is very complex. Even with the right identifiers on log messages the log collection keeps failing. The warning messages on the device are ambiguous. The log messages on firemon are a bit confusing and don't show the exact issue.
Read full review
Cisco
We are using Splunk extensively in our projects and we have recently upgraded to Splunk version 6.0 which is quite efficient and giving expected results. We keep track of updates and new features Splunk introduces periodically and try to introduce those features in our day to day activities for improvement in our reporting system and other tasks.
Read full review
Usability
FireMon
It save me time and I'm able to have the review - review the rule independently with using my time.
Read full review
Cisco
You can literally throw in a single word into Splunk and it will pull back all instances of that word across all of your logs for the time span you select (provided you have permission to see that data). We have several users who have taken a few of the free courses from Splunk that are able to pull data out of it everyday with little help at all.
Read full review
Reliability and Availability
FireMon
FireMon has been relatively stable overall. However, there have been a handful of times where we had issues with the console. For example, we couldn't update which devices to include in a security assessment. The initial suggestion from support was to just reboot it. It seems like there weren't many other options available such as to restart services before going to the extreme of a complete reboot.
Read full review
Cisco
When properly setup and configured, Splunk is extremely reliable.
Read full review
Performance
FireMon
I'm not sure we have the largest implementation of FireMon out there but we do have a few 1000 devices being probed by FireMon. Overall, the system's performance has been rock solid. The console refreshes quickly and reports are generated within an expected timeframe.
Read full review
Cisco
No answers on this topic
Support Rating
FireMon
FireMon technical support is awesome! They respond quickly to our requests and they are well trained and very knowledgeable about the tool. Some issues have to be referred to the development team, but technical support largely provides solutions for any issues that we may have.
Read full review
Cisco
Splunk maintains a well resourced support system that has been consistent since we purchased the product. They help out in a timely manner and provide expert level information as needed. We typically open cases online and communicate when possible via e-mail and are able to resolve most issues with that method.
Read full review
Online Training
FireMon
No answers on this topic
Cisco
The online course was simple clear and described the main capabilities of the solution. There is also an initial module that can be done for free so anyone can familiarize themselves with the functionality of this solution. On the other hand, however, there could be more free online courses. Maybe even with a certificate, this would broaden the group of people who are familiar with the platform while increasing familiarity with the solution itself.
Read full review
Implementation Rating
FireMon
Implementation is fairly simple. Most issues can be resolved by referencing manuals.
Read full review
Cisco
Smooth without too many major issues.
Read full review
Alternatives Considered
FireMon
I has worked with AlgoSec and while they are very similar product, I find the FireMon is easier to understand and get rolling with. While both require some learning, FireMon is by far the easier one. Once you have an understanding of how things are arranged and labeled you can easily import firewalls and begin to work on them to improve them
Read full review
Cisco
I didn't get to fully evaluate Logstash as our corporation was already using Logstash, but both seemed like viable solutions to the problem that we were having. I wanted to evaluate Logstash some more, both did seem like they would work for the business needs that we had, we went with splunk as many teams were already using it.
Read full review
Scalability
FireMon
Firemon Is easily scalable and maintainable with any size team. Although it requires some tech debt, it is well worth the time to invest to ensure compliance is visible and reports are accurate. Although our environment is very large we do not fully utilize the scalability of the Firemon product.
Read full review
Cisco
Splunk can scale in to the petabyte per day range which of course is awesome
Read full review
Return on Investment
FireMon
  • FireMon's Compliance Reporting provided an immediate and tangible benefit
  • FireMon helps identify egregious or erroneous rules quickly across multiple platforms
  • FireMon took our audit process from an Excel spreadsheet into a far more advanced process with readily available context for reviewers
Read full review
Cisco
  • I don't have any numbers to share but Splunk has positively served as a 24/7 monitoring tool that has saved hours of work by self-detecting, saving statistics and alerting problems in the system or from external interfaces as soon as they happen.
  • Splunk dashboards does a solid job in collecting, analyzing data and creating reports that contain an entire day's activity and then automatically sent out to the business.
  • Splunk is very easy to learn and very useful to any program or business application.
Read full review
ScreenShots