Splunk Enterprise Security vs. Splunk Observability Cloud

Overview
ProductRatingMost Used ByProduct SummaryStarting Price
Splunk Enterprise Security
Score 8.6 out of 10
N/A
Splunk Enterprise Security is an analytics-driven SIEM that helps to combat threats with actionable intelligence and advanced analytics at scale.N/A
Splunk Observability Cloud
Score 8.4 out of 10
N/A
Splunk Observability Cloud aims to enable operational agility and better customer experience through real-time AI-driven streaming analytics allowing accurate alerts in seconds. It is designed to shorten MTTD and MTTR by providing real-time visibility into cloud infrastructure and services.
$180
per year per host
Pricing
Splunk Enterprise SecuritySplunk Observability Cloud
Editions & Modules
No answers on this topic
Infrastructure
$15
per month (billed annually) per host
App & Infra
$60
per month (billed annually) per host
End-to-End
$75
per month (billed annually) per host
Offerings
Pricing Offerings
Splunk Enterprise SecuritySplunk Observability Cloud
Free Trial
NoYes
Free/Freemium Version
NoNo
Premium Consulting/Integration Services
NoNo
Entry-level Setup FeeNo setup feeNo setup fee
Additional Details
More Pricing Information
Community Pulse
Splunk Enterprise SecuritySplunk Observability Cloud
Features
Splunk Enterprise SecuritySplunk Observability Cloud
Security Information and Event Management (SIEM)
Comparison of Security Information and Event Management (SIEM) features of Product A and Product B
Splunk Enterprise Security
8.4
105 Ratings
6% above category average
Splunk Observability Cloud
-
Ratings
Centralized event and log data collection7.1103 Ratings00 Ratings
Correlation8.9102 Ratings00 Ratings
Event and log normalization/management8.9103 Ratings00 Ratings
Deployment flexibility8.0104 Ratings00 Ratings
Integration with Identity and Access Management Tools9.099 Ratings00 Ratings
Custom dashboards and workspaces9.9105 Ratings00 Ratings
Host and network-based intrusion detection8.099 Ratings00 Ratings
Data integration/API management8.0101 Ratings00 Ratings
Behavioral analytics and baselining8.997 Ratings00 Ratings
Rules-based and algorithmic detection thresholds7.998 Ratings00 Ratings
Response orchestration and automation8.090 Ratings00 Ratings
Reporting and compliance management8.998 Ratings00 Ratings
Incident indexing/searching8.0104 Ratings00 Ratings
Best Alternatives
Splunk Enterprise SecuritySplunk Observability Cloud
Small Businesses
LevelBlue USM Anywhere
LevelBlue USM Anywhere
Score 7.6 out of 10
InfluxDB
InfluxDB
Score 8.8 out of 10
Medium-sized Companies
Sumo Logic
Sumo Logic
Score 8.8 out of 10
Logz.io
Logz.io
Score 8.5 out of 10
Enterprises
Sumo Logic
Sumo Logic
Score 8.8 out of 10
NetBrain Technologies
NetBrain Technologies
Score 9.2 out of 10
All AlternativesView all alternativesView all alternatives
User Ratings
Splunk Enterprise SecuritySplunk Observability Cloud
Likelihood to Recommend
7.0
(100 ratings)
7.7
(57 ratings)
Likelihood to Renew
9.0
(3 ratings)
7.0
(2 ratings)
Usability
6.0
(3 ratings)
7.6
(16 ratings)
Availability
9.1
(1 ratings)
-
(0 ratings)
Performance
8.2
(1 ratings)
-
(0 ratings)
Support Rating
6.6
(6 ratings)
10.0
(1 ratings)
In-Person Training
9.1
(1 ratings)
-
(0 ratings)
Online Training
8.2
(1 ratings)
-
(0 ratings)
Implementation Rating
9.1
(1 ratings)
10.0
(1 ratings)
Configurability
7.3
(1 ratings)
-
(0 ratings)
Contract Terms and Pricing Model
7.3
(1 ratings)
-
(0 ratings)
Ease of integration
6.4
(1 ratings)
-
(0 ratings)
Product Scalability
9.3
(96 ratings)
-
(0 ratings)
Professional Services
9.1
(1 ratings)
-
(0 ratings)
Vendor post-sale
8.2
(1 ratings)
-
(0 ratings)
Vendor pre-sale
8.2
(1 ratings)
-
(0 ratings)
User Testimonials
Splunk Enterprise SecuritySplunk Observability Cloud
Likelihood to Recommend
Cisco
Well suited: Splunk ES is highly recommended in an environment with many data sources and experienced computer engineers. It has a steep learning curve, but once that hurdle is crossed, it is absolutely a beast. It is also very expensive, so a company putting a high amount of budget in Security is needed. Not well suited: Splunk ES is not recommended if a company has only a few sources and some non-technical IT users. The price won't justify the fewer data sources and scratching just the surface level. Moreover, non-technical IT users would be better off with something that has a query builder, unlike Splunk.
Read full review
Cisco
Its great if you need real-time visibility across complex or regulated environments. Also strong for hybrid or multi-cloud setups where uptime, observability and fast IR are required. It’s probably overkill for smaller teams or environments that don’t have constant changes or compliance reporting needs. It's expensive and has a steep learning curve. Also, in my opinion, do not get yourself into a consumption based model. Costs can certainly get out of control quickly.
Read full review
Pros
Cisco
  • Advanced Threat Detection and Correlation: ES stands out in its ability to detect sophisticated threats by correlating data from multiple sources. For instance, it can identify unusual patterns in user behavior, cross-referencing with network logs to flag potential insider threats.
  • Real-time Monitoring and Alerting: ES offers robust real-time monitoring capabilities. It excels in promptly alerting us to critical security events, such as suspicious network traffic spikes or unauthorized access attempts, allowing for immediate response.
  • Comprehensive Log Analysis: ES ingests and analyzes an extensive range of log data. It's particularly adept at parsing and making sense of complex log formats, making it a versatile tool for understanding system activities and security events.
Read full review
Cisco
  • The first one is its Kubernetes container monitoring.
  • I really like this features because as we know how much K8s is vast and to manually monitor each part of the Kubernetes it takes so much time but Splunk Observability Cloud makes it easier. And even once we integrate K8s with Splunk Observability Cloud it gives us some prebuilt dashboards which gives holistic view of our Cluster and its nodes, pods, etc.
  • The dashbaord feature of Splunk Observability Cloud, it gives us full flexibility to customize our dashboard with a wide range of predefined chart types.
  • Now it also supports OTEL, which is a plus point for observability. As now everyone is moving towards Otel and in current market there are only few tools who supports OTEL based integrations, Splunk Observability Cloud is one out of them.
Read full review
Cons
Cisco
  • ES on the cloud (SaaS) has too many limitations with platform administration.
  • Supported integrations are not always on par with enterprise support especially when dependent on 3rd-party proprietary APIs.
  • In later versions, unforeseen glitches seem to show up that have no resolution except version upgrade. This used to not be the case in prior versions which were very stable.
Read full review
Cisco
  • You can use table-like functionality to generate dashboards, but these queries are heavy on the system.
  • It could be easier to give insight into what type of line parsing is used for specific documents in a company-managed environment and/or show ways to gain the insights needed.
  • I would like to see ways to anonymize specific data for shared reports without pre-formatting this in a dashboard on which reports could be based.
Read full review
Likelihood to Renew
Cisco
We are very happy with Splunk and would advise anyone to take a serious look at it. It might look pricey but the rewards Splunk offers seem endless.
Read full review
Cisco
Good: Stable system with low error rate Easy to use for simple use cases Bad: UI is not very clear for complex usage Mobile view (when logged in from phone) is bad No library for .net
Read full review
Usability
Cisco
Maintaining hundreds or even 1000+ SOC use cases is really difficult, considering that the Data sources may not always send the data. A module that detects data freshness issues and detect data format changes would be a great help. the main challenge today using Splunk Enterprise Security is making sure that the detection rules are still working properly given all the changes that occur in data source applications. Also, maintaining the data collects on tens of thousands of servers and more than 100k workstations is a real company IT challenge: the splunkbase forwarder may not support old OS anymore, while these are the most important to monitor. Moving to the Open Telemetry collector has become essential so that only 1 agent is required for both SIEM and application observability.
Read full review
Cisco
When there is an issue, it’s a win if one can easily identify the root cause. To do the same, it should allow the user to dig deep with multiple data points and compare the data and identify the anomaly. In this use case, it’s good to drive from Splunk 011y.
Read full review
Reliability and Availability
Cisco
I don't think I've ever seen Splunk ES go fully offline or have any downtime greater than a few minutes on rare occasions.
Read full review
Cisco
No answers on this topic
Performance
Cisco
It takes a long time for items to load if you are just generally searching through logs. It is best to use the data models which load faster but can be strange in terms of what is coming from which logs where. Yes, you can look it up, but this also requires familiarity with where things are and how to look them up.
Read full review
Cisco
No answers on this topic
Support Rating
Cisco
It's good when it's responsive, but I've had times where I had to wait quite a while for a response. But these are typically the exceptions rather than the rule. When you do get a response it is always well-informed and appropriate. I would say they've been trending better over time with this.
Read full review
Cisco
Splunk support is very quick and efficient. Pre-sale specialists are very skilled and available.
Read full review
In-Person Training
Cisco
I experienced only on-line training, but the trainers were very professional and competent. Maybe it could be more useful if they also have an experience in projects because sometimes they didn't have a real project experience to communicate to the students. Anyway, it was very interesting and I learned many thing that's very difficoult (or maybe impossible!) to have by myself, aven if I have more than 10 years of Splunk activity experience.
Read full review
Cisco
No answers on this topic
Online Training
Cisco
It was very interesting and I learned many thing that's very difficoult (or maybe impossible!) to have by myself. The only problem was that, when I worked with the Splunk Professional Services, I found some difference between the training contents and the information from PS. In addition is required a long experience on Splunk Enterprise for the data ingestion part, in other words I'm able to work with ES because I'm worling on Splunk since 11 years, otherwise I'd some problem.
Read full review
Cisco
No answers on this topic
Implementation Rating
Cisco
It's a fantatic product and it was very useful the presence of Splunk Professional Services for the Design Phase and the final Health Check.
Read full review
Cisco
Follow a training before starting.
Read full review
Alternatives Considered
Cisco
Splunk enterprise is the only solution that we’ve been able to identify that provides risk based alerting, which allows our SOC to reduce analyst fatigue which would be a huge problem without it. Before RBA, there were thousands of alerts a day and it was impossible to review all of them
Read full review
Cisco
Splunk Infrastructure Monitoring provides far superior options for anybody using a complex hybrid multi-cloud environment and allows both your SOC and NOC to work together on the same data while driving their own insights. We found other products are still in the old world view of servers and agents residing together within a single data centre, but modern apps are no longer like this.
Read full review
Contract Terms and Pricing Model
Cisco
for my exterience, unit pricing and billing frequency are correct. As I already said, I hint to have more discount flexibility, expecially with new customers, because there are competitors less expensive and very aggressive that are dangerous. In addition the possibility to don't pay the license for the development period could be a very interesting feature for the final customers.
Read full review
Cisco
No answers on this topic
Scalability
Cisco
- 8 out of 10 and took 2 for the data pipeline and administration part. Even if you'd like to improve yourself or your team, you have to pay a lot of money and it could be more than GIAC education + cert. - Normalization for Data models and CPU-based searches can be a problem sometimes.
Read full review
Cisco
No answers on this topic
Professional Services
Cisco
I had a fantastic experience with Splunk Professional Services: they worked with us in our last SON project (a SOC migration for a very large customer) and helped to build a multi tenent environment even if ES isn't a multi tenant platform. Th Splunk PS was a very professional and competent people, he is italian and was able to speak with our italian customers.
Read full review
Cisco
No answers on this topic
Return on Investment
Cisco
  • ES has highly impacted ROI because as the customer of the ES the work we do for creating use cases for clients in terms of security-related aspects by their logs has given more return than investment.
  • The correlation searches we run to get detailed results from the Data models are very less time-consuming than Splunk Enterprise itself we can get quick responses to the use cases and dashboards populated because of ES.
  • The CIM compliance feature is ES has made more jobs easy in the terms of finding more Authentication related data we can get data onboarded in the Email data model from O365 and search is email data model instead of searching for particular indexes.
Read full review
Cisco
  • Significantly reduced the MTTR (Mean Time To Recovery), which in turn has improved the end-user experience tremendously.
  • Meets compliance requirements of security policies, audit, regulation, and forensics.
  • Helps us to track/manage the resource usage on our cloud instances which has a direct implication on the recurring cost.
Read full review
ScreenShots

Splunk Observability Cloud Screenshots

Screenshot of Real-time monitoring for public, private and hybrid cloud