TrustRadius: an HG Insights company

Save this comparison

Save this comparison

Add Product

Recommended Comparisons

    Overview
    ProductRatingMost Used ByProduct SummaryStarting Price

    Looker

    Score8.1 out of 10
    N/ALooker is a BI application with an analytics-oriented application server that sits on top of relational data stores. It includes an end-user interface for exploring data, a reusable development paradigm for data discovery, and an API for supporting data in other systems.N/A

    Splunk Enterprise Security

    Score8.3 out of 10
    N/ASplunk Enterprise Security is an analytics-driven SIEM that helps to combat threats with actionable intelligence and advanced analytics at scale.N/A
    Pricing
    LookerSplunk Enterprise Security
    Editions & Modules
    No answers on this topic
    No answers on this topic
    Offerings
    Pricing Offerings
    LookerSplunk Enterprise Security
    Free Trial
    YesNo
    Free/Freemium Version
    NoNo
    Premium Consulting/Integration Services
    YesNo
    Entry-level Setup FeeRequiredNo setup fee
    Additional DetailsMust contact sales team for pricing.—
    More Pricing Information
    Community Pulse
    LookerSplunk Enterprise Security
    Considered Both Products
    Google
    No answer on this topic
    Cisco
    Chose Splunk Enterprise Security
    Exabeam is Elasticsearch based which has major limitations compared to Splunk's SPL language. Furthermore, in my previous company, we were using Exabeam and there were a lot of false-positive detections caused by the machine learning algorithms, Bayesian inference, and other …
    Incentivized
    Key User Insights
    Would buy again
    98%
    Would buy again
    85 Answers
    99%
    Would buy again
    109 Answers
    Delivers good value for the price
    99%
    Delivers good value for the price
    75 Answers
    94%
    Delivers good value for the price
    90 Answers
    Happy with the feature set
    100%
    Happy with the feature set
    87 Answers
    94%
    Happy with the feature set
    103 Answers
    Lived up to sales and marketing promises
    98%
    Lived up to sales and marketing promises
    55 Answers
    91%
    Lived up to sales and marketing promises
    80 Answers
    Implementation went as expected
    97%
    Implementation went as expected
    69 Answers
    91%
    Implementation went as expected
    90 Answers
    Features
    LookerSplunk Enterprise Security
    BI Standard Reporting
    Comparison of BI Standard Reporting features of Looker and Splunk Enterprise Security
    Feature
    Looker
    7.4
    134 Ratings
    10% below category average
    Splunk Enterprise Security
    -
    Ratings
    Pixel Perfect reports6.5110 Ratings00 Ratings
    Customizable dashboards8.2133 Ratings00 Ratings
    Report Formatting Templates7.5115 Ratings00 Ratings
    Ad-hoc Reporting
    Comparison of Ad-hoc Reporting features of Looker and Splunk Enterprise Security
    Feature
    Looker
    6.8
    132 Ratings
    16% below category average
    Splunk Enterprise Security
    -
    Ratings
    Drill-down analysis6.3128 Ratings00 Ratings
    Formatting capabilities6.6130 Ratings00 Ratings
    Integration with R or other statistical packages5.655 Ratings00 Ratings
    Report sharing and collaboration8.8131 Ratings00 Ratings
    Report Output and Scheduling
    Comparison of Report Output and Scheduling features of Looker and Splunk Enterprise Security
    Feature
    Looker
    7.9
    128 Ratings
    4% below category average
    Splunk Enterprise Security
    -
    Ratings
    Publish to Web7.7105 Ratings00 Ratings
    Publish to PDF7.8113 Ratings00 Ratings
    Report Versioning7.984 Ratings00 Ratings
    Report Delivery Scheduling8.2110 Ratings00 Ratings
    Data Discovery and Visualization
    Comparison of Data Discovery and Visualization features of Looker and Splunk Enterprise Security
    Feature
    Looker
    6.6
    128 Ratings
    19% below category average
    Splunk Enterprise Security
    -
    Ratings
    Pre-built visualization formats (heatmaps, scatter plots etc.)7.7124 Ratings00 Ratings
    Location Analytics / Geographic Visualization7.5110 Ratings00 Ratings
    Predictive Analytics4.66 Ratings00 Ratings
    Access Control and Security
    Comparison of Access Control and Security features of Looker and Splunk Enterprise Security
    Feature
    Looker
    7.3
    128 Ratings
    15% below category average
    Splunk Enterprise Security
    -
    Ratings
    Multi-User Support (named login)7.5120 Ratings00 Ratings
    Role-Based Security Model7.2105 Ratings00 Ratings
    Multiple Access Permission Levels (Create, Read, Delete)7.2122 Ratings00 Ratings
    Report-Level Access Control7.360 Ratings00 Ratings
    Mobile Capabilities
    Comparison of Mobile Capabilities features of Looker and Splunk Enterprise Security
    Feature
    Looker
    5.2
    95 Ratings
    40% below category average
    Splunk Enterprise Security
    -
    Ratings
    Responsive Design for Web Access4.991 Ratings00 Ratings
    Mobile Application5.01 Ratings00 Ratings
    Dashboard / Report / Visualization Interactivity on Mobile5.885 Ratings00 Ratings
    Security Information and Event Management (SIEM)
    Comparison of Security Information and Event Management (SIEM) features of Looker and Splunk Enterprise Security
    Feature
    Looker
    -
    Ratings
    Splunk Enterprise Security
    8.4
    107 Ratings
    6% above category average
    Centralized event and log data collection00 Ratings7.1105 Ratings
    Correlation00 Ratings8.9104 Ratings
    Event and log normalization/management00 Ratings8.9105 Ratings
    Deployment flexibility00 Ratings7.9106 Ratings
    Integration with Identity and Access Management Tools00 Ratings8.9101 Ratings
    Custom dashboards and workspaces00 Ratings9.8107 Ratings
    Host and network-based intrusion detection00 Ratings7.9101 Ratings
    Data integration/API management00 Ratings7.9103 Ratings
    Behavioral analytics and baselining00 Ratings8.899 Ratings
    Rules-based and algorithmic detection thresholds00 Ratings7.9100 Ratings
    Response orchestration and automation00 Ratings7.992 Ratings
    Reporting and compliance management00 Ratings8.9100 Ratings
    Incident indexing/searching00 Ratings8.0106 Ratings
    Best Alternatives
    LookerSplunk Enterprise Security
    Small Businesses
    Cyfe
    Score4 out of 10
    No answers on this topic
    Medium-sized Companies
    Qlik Cloud Analytics (Qlik Sense)
    Score8.1 out of 10
    IBM Security QRadar SIEM
    Score8.9 out of 10
    Enterprises
    Sisense
    Score6.9 out of 10
    SolarWinds Security Event Manager (SEM)
    Score8 out of 10
    All AlternativesView all alternativesView all alternatives
    User Ratings
    LookerSplunk Enterprise Security
    Likelihood to Recommend
    8.0
    (134 ratings)
    7.1
    (109 ratings)
    Likelihood to Renew
    9.2
    (8 ratings)
    9.1
    (4 ratings)
    Usability
    8.8
    (12 ratings)
    7.0
    (12 ratings)
    Availability
    10.0
    (1 ratings)
    9.1
    (4 ratings)
    Performance
    6.0
    (1 ratings)
    7.0
    (4 ratings)
    Support Rating
    8.8
    (14 ratings)
    7.3
    (8 ratings)
    In-Person Training
    -
    (0 ratings)
    9.1
    (1 ratings)
    Online Training
    -
    (0 ratings)
    8.2
    (1 ratings)
    Implementation Rating
    10.0
    (1 ratings)
    9.1
    (1 ratings)
    Configurability
    10.0
    (1 ratings)
    7.3
    (1 ratings)
    Contract Terms and Pricing Model
    10.0
    (1 ratings)
    7.3
    (1 ratings)
    Data Sharing and Collaboration
    8.5
    (51 ratings)
    -
    (0 ratings)
    Data Sources
    7.3
    (51 ratings)
    -
    (0 ratings)
    Ease of integration
    10.0
    (1 ratings)
    6.4
    (1 ratings)
    Product Scalability
    10.0
    (1 ratings)
    8.7
    (98 ratings)
    Professional Services
    10.0
    (1 ratings)
    9.1
    (1 ratings)
    Vendor post-sale
    10.0
    (1 ratings)
    8.2
    (1 ratings)
    Vendor pre-sale
    10.0
    (1 ratings)
    8.2
    (1 ratings)
    User Testimonials
    LookerSplunk Enterprise Security
    Likelihood to Recommend
    Google
    When data drives potential for new orders, Looker earns its place in our tech stack. If, on the other hand, we are hoping for pipeline generation, Looker is useful if you are willing to repeatedly go check customer utilizations .... it is not appropriate if you are hoping to automate data analysis for this purpose.
    Incentivized
    Read full review
    Cisco
    Based on my experience, Splunk is a strong git for some environments and a poor match for others. The distinction is primarily based on infrastructure complexity and budget. It's perfect for large enterprises with a mix of on-prem/cloud infrastructure. It's not a perfect match for small teams with restricted resources.
    Incentivized
    Read full review
    Pros
    Google
    • Show visited pages - sessions, pageviews - which programs are viewed the most.
    • Displays session source/medium views to see where users are coming from.
    • It shows the video titles, URLs, and event counts so we can monitor the performance of our videos.
    • It gives a graphic face to the numbers, such as using bar charts, pie graphs, and other charts to show user trends or which channels are driving engagement.
    • Our clients like to see the top pages visited for a month.
    • I like the drop-and-drag approach, and building charts is a little easier than it was before.
    Incentivized
    Read full review
    Cisco
    • Writes Powerful Queries: The queries that can be written using the Splunk Query Language are very powerful and highly customizable to meet every need. Ex: Writing queries to search the intersection of two different sources like Network and Endpoint Logs.
    • Offers Dashboard Abilities: Helps build complex panels for Dashboards in addition to providing several out-of-the-box panels. Ex: creating panels to calculate the performance of analysts in a given timezone.
    • Helpful Search Aids: It helps to set up complex custom alerts very easily. The interesting fields section is very helpful while threat hunting. Ex: It shows all the users and the frequency of each in a failed login event. The user list on the interesting fields is useful to look for suspicious logins.
    Incentivized
    Read full review
    Cons
    Google
    • Documentation is scarce, and very difficult to find when you need it.
    • Pricing is unclear, particularly as you look to scale your reports across the business.
    • Data from other sources is not represented in the system as well as first party Google services.
    Incentivized
    Read full review
    Cisco
    • Improved User Interface Customization: While the interface is generally intuitive, providing more options for users to customize their dashboards and views would enhance the overall user experience. Tailoring the interface to specific roles or use cases could be a valuable addition.
    • Simplified Alert Management: Streamlining the process of managing alerts, such as grouping or categorizing them based on severity or type, would make it easier for security teams to prioritize and respond to incidents effectively.
    • Expanded Threat Intelligence Feeds: Increasing the variety and sources of threat intelligence feeds available within ES would provide a broader context for identifying and mitigating emerging threats, ensuring a more comprehensive defense against evolving attack vectors.
    Incentivized
    Read full review
    Likelihood to Renew
    Google
    I give it this rating because it deems as effective, I am able to complete majority of my tasks using this app. It is very helpful when analyzing the data provided and shown in the app and it's just overall a great app for Operational use, despite the small hiccups it has (live data).
    Incentivized
    Read full review
    Cisco
    We are very happy with Splunk and would advise anyone to take a serious look at it. It might look pricey but the rewards Splunk offers seem endless.
    Incentivized
    Read full review
    Usability
    Google
    Looker is relatively easy to use, even as it is set up. The customers for the front-end only have issues with the initial setup for looker ml creations. Other "looks" are relatively easy to set up, depending on the ETL and the data which is coming into Looker on a regular basis.
    Incentivized
    Read full review
    Cisco
    Maintaining hundreds or even 1000+ SOC use cases is really difficult, considering that the Data sources may not always send the data. A module that detects data freshness issues and detect data format changes would be a great help. the main challenge today using Splunk Enterprise Security is making sure that the detection rules are still working properly given all the changes that occur in data source applications. Also, maintaining the data collects on tens of thousands of servers and more than 100k workstations is a real company IT challenge: the splunkbase forwarder may not support old OS anymore, while these are the most important to monitor. Moving to the Open Telemetry collector has become essential so that only 1 agent is required for both SIEM and application observability.
    Incentivized
    Read full review
    Reliability and Availability
    Google
    No objections
    Incentivized
    Read full review
    Cisco
    I don't think I've ever seen Splunk ES go fully offline or have any downtime greater than a few minutes on rare occasions.
    Incentivized
    Read full review
    Performance
    Google
    Somehow resources heavy, both on server and client. I recommned at least 50Mbs data rate and high performance desktop comouter to be abke to run comolex tasks and configure larger amount of data. On the other hand, the client does not need to worry when viewing, the performance is usually ok
    Incentivized
    Read full review
    Cisco
    It takes a long time for items to load if you are just generally searching through logs. It is best to use the data models which load faster but can be strange in terms of what is coming from which logs where. Yes, you can look it up, but this also requires familiarity with where things are and how to look them up.
    Incentivized
    Read full review
    Support Rating
    Google
    Never had to work with support for issues. Any questions we had, they would respond promptly and clearly. The one-time setup was easy, by reading documentation. If the feature is not supported, they will add a feature request. In this case, LDAP support was requested over OKTA. They are looking into it.
    Incentivized
    Read full review
    Cisco
    It's good when it's responsive, but I've had times where I had to wait quite a while for a response. But these are typically the exceptions rather than the rule. When you do get a response it is always well-informed and appropriate. I would say they've been trending better over time with this.
    Incentivized
    Read full review
    In-Person Training
    Google
    No answers on this topic
    Cisco
    I experienced only on-line training, but the trainers were very professional and competent. Maybe it could be more useful if they also have an experience in projects because sometimes they didn't have a real project experience to communicate to the students. Anyway, it was very interesting and I learned many thing that's very difficoult (or maybe impossible!) to have by myself, aven if I have more than 10 years of Splunk activity experience.
    Incentivized
    Read full review
    Online Training
    Google
    No answers on this topic
    Cisco
    It was very interesting and I learned many thing that's very difficoult (or maybe impossible!) to have by myself. The only problem was that, when I worked with the Splunk Professional Services, I found some difference between the training contents and the information from PS. In addition is required a long experience on Splunk Enterprise for the data ingestion part, in other words I'm able to work with ES because I'm worling on Splunk since 11 years, otherwise I'd some problem.
    Incentivized
    Read full review
    Implementation Rating
    Google
    Very satisfied, easy to implement
    Incentivized
    Read full review
    Cisco
    It's a fantatic product and it was very useful the presence of Splunk Professional Services for the Design Phase and the final Health Check.
    Incentivized
    Read full review
    Alternatives Considered
    Google
    Looker Studio, you can easily report on data from various sources without programming. Looker Studio is available at no charge for creators and report viewers. Enterprise customers who upgrade to Looker Studio Pro will receive support and expanded administrative features, including team content management. So it's good.
    Incentivized
    Read full review
    Cisco
    Splunk enterprise is the only solution that we’ve been able to identify that provides risk based alerting, which allows our SOC to reduce analyst fatigue which would be a huge problem without it. Before RBA, there were thousands of alerts a day and it was impossible to review all of them
    Incentivized
    Read full review
    Contract Terms and Pricing Model
    Google
    Perfect price to performance
    Incentivized
    Read full review
    Cisco
    for my exterience, unit pricing and billing frequency are correct. As I already said, I hint to have more discount flexibility, expecially with new customers, because there are competitors less expensive and very aggressive that are dangerous. In addition the possibility to don't pay the license for the development period could be a very interesting feature for the final customers.
    Incentivized
    Read full review
    Scalability
    Google
    No answers on this topic
    Cisco
    - 8 out of 10 and took 2 for the data pipeline and administration part. Even if you'd like to improve yourself or your team, you have to pay a lot of money and it could be more than GIAC education + cert. - Normalization for Data models and CPU-based searches can be a problem sometimes.
    Incentivized
    Read full review
    Professional Services
    Google
    No answers on this topic
    Cisco
    I had a fantastic experience with Splunk Professional Services: they worked with us in our last SON project (a SOC migration for a very large customer) and helped to build a multi tenent environment even if ES isn't a multi tenant platform. Th Splunk PS was a very professional and competent people, he is italian and was able to speak with our italian customers.
    Incentivized
    Read full review
    Return on Investment
    Google
    • Looker has a poignant impact on our business's ROI objectives. As an advertising exchange we have specific goals for daily requests and fill, and having premade Looks to monitor this is an integral piece of our operational capability
    • To facilitate an efficient monthly billing cycle in our organization, Looker is essential to track estimated revenue and impression delivery by publisher. Without the Looks we have set up, we would spend considerably more time and effort segmenting revenue by vertical.
    • Looker's unique value proposition is making analytical tools more digestible to people without conventional analytical experience. Other competing tools like Tableau require considerably more training and context to successfully use, and the ability to easily plot different visualizations is one of its greatest selling points.
    Incentivized
    Read full review
    Cisco
    • We have a 100% success rate on all our ES implementations due to the amazing documentation and Splunk enablement on the subject.
    • Our Splunk ES business has grown 100% YoY for the last 3 years.
    • In terms of long term management and maintenance, ES has been highly stable and predictable, reducing our overhead on costly services team for ad hoc maintenance work.
    Read full review
    ScreenShots

    Looker Screenshots

    Screenshot of a Looker dashboard with a geo chart.