Overview
ProductRatingMost Used ByProduct SummaryStarting Price
LogPoint
Score 7.0 out of 10
N/A
LogPoint detects, analyzes and responds to threats within an organization’s data for faster security investigations. LogPoint is dedicated to helping overloaded security analysts work more efficiently with accelerated detection and response. LogPoint's SIEM solution with UEBA provides…N/A
ScienceLogic SL1
Score 8.8 out of 10
Enterprise companies (1,001+ employees)
ScienceLogic is a system and application monitoring and performance management platform. ScienceLogic collects and aggregates data across and IT ecosystems and contextualizes it for actionable insights with the SL1 product offering.N/A
Splunk Enterprise Security
Score 8.6 out of 10
N/A
Splunk Enterprise Security is an analytics-driven SIEM that helps to combat threats with actionable intelligence and advanced analytics at scale.N/A
Pricing
LogPointScienceLogic SL1Splunk Enterprise Security
Editions & Modules
No answers on this topic
No answers on this topic
No answers on this topic
Offerings
Pricing Offerings
LogPointScienceLogic SL1Splunk Enterprise Security
Free Trial
YesNoNo
Free/Freemium Version
NoNoNo
Premium Consulting/Integration Services
YesYesNo
Entry-level Setup FeeNo setup feeRequiredNo setup fee
Additional DetailsScienceLogic SL1 offers four tiers: SL1 Advanced – Application Health, Automated Troubleshooting and Remediation Workflows SL1 Base – Infrastructure Monitoring, Topology & Event Correlation SL1 Premium – AI/ML-driven Analytics, Low-Code Automated Workflow Authoring SL1 Standard – Infrastructure Monitoring – with Agents, Business Services, Incident Automation, CMDB Synchronization, Behavioral Correlation To get pricing for each tier, please contact the vendor.
More Pricing Information
Community Pulse
LogPointScienceLogic SL1Splunk Enterprise Security
Features
LogPointScienceLogic SL1Splunk Enterprise Security
Security Information and Event Management (SIEM)
Comparison of Security Information and Event Management (SIEM) features of Product A and Product B
LogPoint
6.3
5 Ratings
22% below category average
ScienceLogic SL1
-
Ratings
Splunk Enterprise Security
8.4
106 Ratings
7% above category average
Centralized event and log data collection8.25 Ratings00 Ratings7.1104 Ratings
Correlation8.04 Ratings00 Ratings8.9103 Ratings
Event and log normalization/management8.35 Ratings00 Ratings8.9104 Ratings
Deployment flexibility6.55 Ratings00 Ratings7.9105 Ratings
Integration with Identity and Access Management Tools6.23 Ratings00 Ratings8.9100 Ratings
Custom dashboards and workspaces7.65 Ratings00 Ratings9.9106 Ratings
Host and network-based intrusion detection7.33 Ratings00 Ratings8.0100 Ratings
Data integration/API management4.51 Ratings00 Ratings7.9102 Ratings
Rules-based and algorithmic detection thresholds6.41 Ratings00 Ratings7.999 Ratings
Response orchestration and automation3.61 Ratings00 Ratings8.091 Ratings
Reporting and compliance management6.41 Ratings00 Ratings8.999 Ratings
Incident indexing/searching2.71 Ratings00 Ratings8.0105 Ratings
Behavioral analytics and baselining00 Ratings00 Ratings8.998 Ratings
AIOps Features
Comparison of AIOps Features features of Product A and Product B
LogPoint
-
Ratings
ScienceLogic SL1
7.3
26 Ratings
3% below category average
Splunk Enterprise Security
-
Ratings
Monitoring and Alerting00 Ratings8.025 Ratings00 Ratings
Performance Analytics00 Ratings7.426 Ratings00 Ratings
Incident Management00 Ratings6.726 Ratings00 Ratings
Service Desk Integration00 Ratings7.225 Ratings00 Ratings
Root Cause Analysis00 Ratings7.321 Ratings00 Ratings
Capacity Planning Tool00 Ratings6.822 Ratings00 Ratings
Configuration and Change Management00 Ratings7.223 Ratings00 Ratings
Automated Remediation00 Ratings7.420 Ratings00 Ratings
Collaboration and Communication00 Ratings7.720 Ratings00 Ratings
Threat Intelligence00 Ratings7.119 Ratings00 Ratings
Best Alternatives
LogPointScienceLogic SL1Splunk Enterprise Security
Small Businesses
LevelBlue USM Anywhere
LevelBlue USM Anywhere
Score 7.6 out of 10

No answers on this topic

LevelBlue USM Anywhere
LevelBlue USM Anywhere
Score 7.6 out of 10
Medium-sized Companies
Sumo Logic
Sumo Logic
Score 8.8 out of 10
Sumo Logic
Sumo Logic
Score 8.8 out of 10
Sumo Logic
Sumo Logic
Score 8.8 out of 10
Enterprises
Sumo Logic
Sumo Logic
Score 8.8 out of 10
ignio AIOps
ignio AIOps
Score 8.1 out of 10
Sumo Logic
Sumo Logic
Score 8.8 out of 10
All AlternativesView all alternativesView all alternativesView all alternatives
User Ratings
LogPointScienceLogic SL1Splunk Enterprise Security
Likelihood to Recommend
7.3
(5 ratings)
8.7
(224 ratings)
7.0
(100 ratings)
Likelihood to Renew
8.2
(1 ratings)
8.5
(24 ratings)
9.0
(3 ratings)
Usability
6.8
(4 ratings)
9.7
(15 ratings)
6.0
(3 ratings)
Availability
-
(0 ratings)
9.5
(14 ratings)
9.1
(1 ratings)
Performance
-
(0 ratings)
8.2
(14 ratings)
8.2
(1 ratings)
Support Rating
8.3
(4 ratings)
6.3
(20 ratings)
6.6
(6 ratings)
In-Person Training
9.1
(1 ratings)
8.6
(6 ratings)
9.1
(1 ratings)
Online Training
-
(0 ratings)
8.0
(8 ratings)
8.2
(1 ratings)
Implementation Rating
-
(0 ratings)
7.9
(97 ratings)
9.1
(1 ratings)
Configurability
-
(0 ratings)
10.0
(7 ratings)
7.3
(1 ratings)
Contract Terms and Pricing Model
-
(0 ratings)
-
(0 ratings)
7.3
(1 ratings)
Ease of integration
-
(0 ratings)
8.0
(15 ratings)
6.4
(1 ratings)
Product Scalability
-
(0 ratings)
8.0
(1 ratings)
9.3
(96 ratings)
Professional Services
9.1
(3 ratings)
-
(0 ratings)
9.1
(1 ratings)
Vendor post-sale
-
(0 ratings)
9.1
(7 ratings)
8.2
(1 ratings)
Vendor pre-sale
-
(0 ratings)
8.5
(7 ratings)
8.2
(1 ratings)
User Testimonials
LogPointScienceLogic SL1Splunk Enterprise Security
Likelihood to Recommend
LogPoint
LogPoint is incredibly useful for pulling information from various log sources and combining them together to offer insights into suspicious or potentially malicious behaviour. It is not intuitive and can take some time to get used to. Once you're up and running though, it's easy to onboard new log sources. Search queries can again be tough to get used to, but LogPoint support is really helpful and can offer assistance with writing more complex searches.
Read full review
ScienceLogic
For Windows, the issue is in higher resource consumption related to WinRM monitoring, which provides better options then the SNMP monitoring, which on the other hand is less resource intensive. The problem is also with support for OS with other than English language.
Read full review
Cisco
Based on my experience, Splunk is a strong git for some environments and a poor match for others. The distinction is primarily based on infrastructure complexity and budget. It's perfect for large enterprises with a mix of on-prem/cloud infrastructure. It's not a perfect match for small teams with restricted resources.
Read full review
Pros
LogPoint
  • Technical support team is fast and competent
  • License management and cost
  • Log parsing
  • New logs can be provided to the support team for parser creation
  • High Availability architecture does not cost more
Read full review
ScienceLogic
  • Best overall coverage of montioring different technologies.
  • Easy to use in any environment
  • Customizable being able to generate your own reports, dashboards, DA's, RBA's, etc.
  • Have very good out of the box integrations with other monitoring solutions such as ServiceNow
  • Always improving and regularly releasing new versions and upgrades to the system/DA's.
  • Interactive community
Read full review
Cisco
  • Writes Powerful Queries: The queries that can be written using the Splunk Query Language are very powerful and highly customizable to meet every need. Ex: Writing queries to search the intersection of two different sources like Network and Endpoint Logs.
  • Offers Dashboard Abilities: Helps build complex panels for Dashboards in addition to providing several out-of-the-box panels. Ex: creating panels to calculate the performance of analysts in a given timezone.
  • Helpful Search Aids: It helps to set up complex custom alerts very easily. The interesting fields section is very helpful while threat hunting. Ex: It shows all the users and the frequency of each in a failed login event. The user list on the interesting fields is useful to look for suspicious logins.
Read full review
Cons
LogPoint
  • Providing a full Cloud solution
  • Having more documentation for complex deployment
Read full review
ScienceLogic
  • Dashboards are quite old and are of Iron age. Need to have AP2 dashboards only instead of AP1 and consistent new design across all functionalities.
  • Reporting is not improved since Y2020 and need to revamp completely. Need to integrate Dashboards and Reporting. PowerBI Like functionality to be given OOTB. Reports should be extracted in Excel, PDF, HTML and should be heavily automated.
  • Create and Open APIs for basic and advanced monitoring data extraction.
  • Topology based Event Correlation and Suppression should be improved drastically. Need to identify critical network interfaces based on Topology and monitor them. Basic customization of Dynamic App and/or Powerpack to exclude/include certain metrics/events to be permitted OOTB instead of customizations.
  • Integration with ServiceNow to be improved and to be taken to next level. Automation Powerpack should be made available OOTB as part of base product and to be priced attractively.
  • Take product to next level where we can monitor actual impacted IT or Business Service instead of metrics and events BSM and Topology map to be auto discovered and identify the network dependencies and alternate paths automatically instead of manual creation of BSM.
Read full review
Cisco
  • Improved User Interface Customization: While the interface is generally intuitive, providing more options for users to customize their dashboards and views would enhance the overall user experience. Tailoring the interface to specific roles or use cases could be a valuable addition.
  • Simplified Alert Management: Streamlining the process of managing alerts, such as grouping or categorizing them based on severity or type, would make it easier for security teams to prioritize and respond to incidents effectively.
  • Expanded Threat Intelligence Feeds: Increasing the variety and sources of threat intelligence feeds available within ES would provide a broader context for identifying and mitigating emerging threats, ensuring a more comprehensive defense against evolving attack vectors.
Read full review
Likelihood to Renew
LogPoint
We are confident with the solution and we are using it daily
Read full review
ScienceLogic
It is simply because of all the best possible autonomy solutions it is providing and getting better day by day. Using AI and Devops along with handy automation, The monitoring and Management of devices becomes much easier and the way it is growing in all the aspects is one the best reasons too. Evolution of the SL1 platform in the autonomy monitoring and management is quite appreciable.
Read full review
Cisco
We are very happy with Splunk and would advise anyone to take a serious look at it. It might look pricey but the rewards Splunk offers seem endless.
Read full review
Usability
LogPoint
Overall, LogPoint is pretty easy to get started with but faces issues with specific things (syslog on custom ports, script log collection, etc.).
Read full review
ScienceLogic
The core functions are there.
The complexity is due to the complexity of the space.
The score is based on comfort (I no longer notice the legacy UI) and the promise that I see in the 8.12 Unified UI (a vast improvement).
It is also based on the fact that with 8.12, you can now do everything in the new UI but you still have the legacy UI as a fallback (which should now be unnecessary for new installations)
Read full review
Cisco
Maintaining hundreds or even 1000+ SOC use cases is really difficult, considering that the Data sources may not always send the data. A module that detects data freshness issues and detect data format changes would be a great help. the main challenge today using Splunk Enterprise Security is making sure that the detection rules are still working properly given all the changes that occur in data source applications. Also, maintaining the data collects on tens of thousands of servers and more than 100k workstations is a real company IT challenge: the splunkbase forwarder may not support old OS anymore, while these are the most important to monitor. Moving to the Open Telemetry collector has become essential so that only 1 agent is required for both SIEM and application observability.
Read full review
Reliability and Availability
LogPoint
No answers on this topic
ScienceLogic
SL is always there and online when you need to get info from it. The only times when SL was not available in our own data center, was when network links from out side of the data center was down and those links were not in our controll. Having a central database and people accessing it all over the world, may put a bit of constarin on the performance of the dashboards when reports gets generated, but that is far and few n between.
Read full review
Cisco
I don't think I've ever seen Splunk ES go fully offline or have any downtime greater than a few minutes on rare occasions.
Read full review
Performance
LogPoint
No answers on this topic
ScienceLogic
SceinceLogic SL1 architecture helps the platform to give a top-notch performance in every respect, Data collection to reporting happens very smoothly. With the new user interface pages load much faster. Individual appliances carrying the individual task ensure things are working without lag. Integration with ticketing tool(SNOW) is well managed by the ScienceLogic, no issue or much delay has been observed while interacting with an external tool.
Read full review
Cisco
It takes a long time for items to load if you are just generally searching through logs. It is best to use the data models which load faster but can be strange in terms of what is coming from which logs where. Yes, you can look it up, but this also requires familiarity with where things are and how to look them up.
Read full review
Support Rating
LogPoint
LogPoint support is outstanding. They are incredibly helpful, and on occasions have proactively identified issues with our setup, and logged cases on our behalf before we had even noticed there was a problem. If there is a search we need to write that is beyond our skills, LogPoint support can typically write it for us within a couple of days. They are always very responsive, and I am yet to have a bad support experience.
Read full review
ScienceLogic
So far, it's good as part of my overall experience, except for a couple of use cases. The support team is well knowledgeable, has technical sound, and is efficient. When support escalates to engineering, the issue gets stuck and takes months to resolve.
Read full review
Cisco
It's good when it's responsive, but I've had times where I had to wait quite a while for a response. But these are typically the exceptions rather than the rule. When you do get a response it is always well-informed and appropriate. I would say they've been trending better over time with this.
Read full review
In-Person Training
LogPoint
Really nice person with huge skills on LogPoint
Read full review
ScienceLogic
It was good, Do the online training first and understand it and you will get the most out of the in-person training that way. This also takes you to an advanced level which is very good and the training as been overhauled once again along with new product coming in such as Zebruim / Skylar, worth going through again if it a while back that you first did this.
Read full review
Cisco
I experienced only on-line training, but the trainers were very professional and competent. Maybe it could be more useful if they also have an experience in projects because sometimes they didn't have a real project experience to communicate to the students. Anyway, it was very interesting and I learned many thing that's very difficoult (or maybe impossible!) to have by myself, aven if I have more than 10 years of Splunk activity experience.
Read full review
Online Training
LogPoint
No answers on this topic
ScienceLogic
There are a lot of educational materials and courses on the SL1 training site (Litmos university). However the recording quality is sometimes not very good - screen resolution is low. There is a lack of professional rather than user-oriented documents and there are mistakes in documentation and education is not well structured.
Read full review
Cisco
It was very interesting and I learned many thing that's very difficoult (or maybe impossible!) to have by myself. The only problem was that, when I worked with the Splunk Professional Services, I found some difference between the training contents and the information from PS. In addition is required a long experience on Splunk Enterprise for the data ingestion part, in other words I'm able to work with ES because I'm worling on Splunk since 11 years, otherwise I'd some problem.
Read full review
Implementation Rating
LogPoint
No answers on this topic
ScienceLogic
Implementation is smooth if we are to just support the out-of-the-box features available in ScienceLogic. For any custom requirement, having to go to SL1 Professional Services is the worst part of procuring this suite. And more often than not, SL1 Professional Services also ask to raise feature request. So, you subscribe to Professional Services to only hear back from them that "This feature is not supported and needs to have a separate feature request". At times frustrating.
Read full review
Cisco
It's a fantatic product and it was very useful the presence of Splunk Professional Services for the Design Phase and the final Health Check.
Read full review
Alternatives Considered
LogPoint
LogPoint is easier to implement and less expensive.
Read full review
ScienceLogic
Science logic SL1 is so user friendly and it's really easy to navigate between function. I would recommend Sciene logic SL1 to all of them who are looking for really useful monitoring tool and expecting easy way of managing it.
Read full review
Cisco
Splunk enterprise is the only solution that we’ve been able to identify that provides risk based alerting, which allows our SOC to reduce analyst fatigue which would be a huge problem without it. Before RBA, there were thousands of alerts a day and it was impossible to review all of them
Read full review
Contract Terms and Pricing Model
LogPoint
No answers on this topic
ScienceLogic
No answers on this topic
Cisco
for my exterience, unit pricing and billing frequency are correct. As I already said, I hint to have more discount flexibility, expecially with new customers, because there are competitors less expensive and very aggressive that are dangerous. In addition the possibility to don't pay the license for the development period could be a very interesting feature for the final customers.
Read full review
Scalability
LogPoint
No answers on this topic
ScienceLogic
Our deployment model is vastly different from product expectations. Our global / internal monitoring foot print is 8 production stacks in dual data centers with 50% collection capacity allocated to each data center with minimal numbers of collection groups. General Collection is our default collection group. Special Collection is for monitoring our ASA and other hardware that cannot be polled by a large number of IP addresses, so this collection group is usually 2 collectors). Because most of our stacks are in different physical data centers, we cannot use the provided HA solution. We have to use the DR solution (DRBD + CNAMEs). We routinely test power in our data centers (yearly). Because we have to use DR, we have a hand-touch to flip nodes and change the DNS CNAME half of the times when there is an outage (by design). When the outage is planned, we do this ahead of the outage so that we don't care that the Secondary has dropped away from the Primary. Hopefully, we'll be able to find a way to meet our constraints and improve our resiliency and reduce our hand-touch in future releases. For now, this works for us and our complexity. (I hear that the HA option is sweet. I just can't consume that.)
Read full review
Cisco
- 8 out of 10 and took 2 for the data pipeline and administration part. Even if you'd like to improve yourself or your team, you have to pay a lot of money and it could be more than GIAC education + cert. - Normalization for Data models and CPU-based searches can be a problem sometimes.
Read full review
Professional Services
LogPoint
N/A
(Cannot skip without answer)
Read full review
ScienceLogic
No answers on this topic
Cisco
I had a fantastic experience with Splunk Professional Services: they worked with us in our last SON project (a SOC migration for a very large customer) and helped to build a multi tenent environment even if ES isn't a multi tenant platform. Th Splunk PS was a very professional and competent people, he is italian and was able to speak with our italian customers.
Read full review
Return on Investment
LogPoint
  • Keep the same team to manage more IT resources
  • Having a better logs visibility
Read full review
ScienceLogic
  • Once a powerpack is developed and configured for a device for one customer, it is easy to deploy the same powerpack on a second customer estate and configure specifically for that customer without having to reinvent the powerpack. This saves time and therefore money.
  • Once the customer estate tuning is complete, the Operations team have come trust the alerts. This is especially true when transient or self-correcting alerts are automatically cleared without ops team involvement, but a record is still available for audit and debugging purposes. This saves time and therefore money.
  • When setup correctly, it provides good visibility into applications, devices and whole customer estates. This saves time and therefore money when issues arise.
Read full review
Cisco
  • We have a 100% success rate on all our ES implementations due to the amazing documentation and Splunk enablement on the subject.
  • Our Splunk ES business has grown 100% YoY for the last 3 years.
  • In terms of long term management and maintenance, ES has been highly stable and predictable, reducing our overhead on costly services team for ad hoc maintenance work.
Read full review
ScreenShots

LogPoint Screenshots

Screenshot of LogPoint SIEM dashboardScreenshot of LogPoint UEBA dashboardScreenshot of LogPoint threat intelligence dashboardScreenshot of All LogPoint alerts are mapped to the MITRE ATT&CK framework

ScienceLogic SL1 Screenshots

Screenshot of Application to infrastructure mapping with APM toolsScreenshot of CRM Business Service MapScreenshot of Mobile Banking Business Service Dashboard OverviewScreenshot of Mobile Banking Business Service Dashboard Availability ViewScreenshot of Mobile Banking Business Service Dashboard Anomalies ViewScreenshot of Business Services Leaderboard Dashboard Overview