What users are saying about
Top Rated
303 Ratings
42 Ratings
Top Rated
303 Ratings
<a href='https://www.trustradius.com/static/about-trustradius-scoring' target='_blank' rel='nofollow noopener noreferrer'>trScore algorithm: Learn more.</a>
Score 8.7 out of 100
42 Ratings
<a href='https://www.trustradius.com/static/about-trustradius-scoring' target='_blank' rel='nofollow noopener noreferrer'>trScore algorithm: Learn more.</a>
Score 8.8 out of 100

Likelihood to Recommend

Splunk Enterprise

Pros: Splunk is very well suited if you have multiple log sources of related data. All of them can be correlated and tasks can be automated based on the requirement. Other than alerts, Splunk can also run a specific script of your choice, based on some defined conditions. Cons: If you have a few logs but a large number of log sources, Splunk can be very expensive.
Kuntal Das | TrustRadius Reviewer

Sumo Logic

SumoLogic is a fantastic log aggregator and analysis tool, a fine alternative to Splunk. Searching is powerful and mostly intuitive and results come fast. If you have application logs in clusters or Kubernetes pods that lose their logs every time they're restarted, Sumo is the solution for you
Anonymous | TrustRadius Reviewer

Feature Rating Comparison

Security Information and Event Management (SIEM)

Splunk Enterprise
8.9
Sumo Logic
Centralized event and log data collection
Splunk Enterprise
9.6
Sumo Logic
Correlation
Splunk Enterprise
9.1
Sumo Logic
Event and log normalization
Splunk Enterprise
9.1
Sumo Logic
Deployment flexibility
Splunk Enterprise
8.6
Sumo Logic
Integration with Identity and Access Management Tools
Splunk Enterprise
8.4
Sumo Logic
Custom dashboards and views
Splunk Enterprise
9.1
Sumo Logic
Host and network-based intrusion detection
Splunk Enterprise
8.5
Sumo Logic

Pros

Splunk Enterprise

  • Allow for separation of control where we don't let some employees have access to production but still can diagnose issues.
  • Common location to go for all logs even if the logs themselves aren't in the same place.
  • Ability to ingest logs from different locations without having to change the code to put logs in a certain place (pro and con).
Anonymous | TrustRadius Reviewer

Sumo Logic

  • Sumo Logic allowed for our InfoSec team to ingest logs from our CDN directly, in real-time, instead of massive compressed archives that were sent every two-hours (the only alternative at the time). Sumo Logic had an app for these logs, that allowed us to easily get an immediate payoff from the data, with canned dashboard and saved searches.
  • Sumo Logic has a fairly extensive REST API when it comes to log sources, source configurations, dashboard data, searches, etc. Their wiki for the API is usually kept up to date.
  • Sumo Logic, during the period of time I had used their product, had added the ability to configure agents via configuration files. This allowed customers to configure their endpoints, and modify the endpoints, with configuration management tools like Chef / Puppet / Salt. Beforehand, the only option was to always make changes either via the web portal or REST API.
  • The solutions engineers were extremely helpful, and easily reachable when issues would occur.
  • Users at our company found it easy to get started, working on new dashboards, scheduled searches, and alerting. The alerting worked well with our third-party paging tool.
Derek Ardolf | TrustRadius Reviewer

Cons

Splunk Enterprise

  • Even though there is a search tool as a help function, you still have to read through many documentation to find the answers you're looking for and sometimes you don't find it. The help function in Splunk could be improved to be more intuitive or have a built-in help per report, panel or dashboard.
  • Creating a Splunk dashboard is rather straightforward however, customization is not. Splunk could be improved to provide more tools or features for customization such as adding colors and font options for text and graphs or graphics.
  • My dashboard has a lot of useful information and I want the important panels and reports at the top but there is no easy way to do this. Perhaps Splunk could be improved to allow features such as adding URL links to other dashboards or some other clever way to emphasize the important data in my dashboard without compromising space.
Anonymous | TrustRadius Reviewer

Sumo Logic

  • I like the help center, but I think if it had more GUI tools, it could help new users.
  • Pulling out data is sometimes hard to read, (Maybe if I knew how to export data better, this would not be an issue for me).
  • I would like better know-how on how to create reports that will help our business.
M Phillip Yogore | TrustRadius Reviewer

Likelihood to Renew

Splunk Enterprise

Splunk Enterprise 10.0
Based on 17 answers
We are using Splunk extensively in our projects and we have recently upgraded to Splunk version 6.0 which is quite efficient and giving expected results. We keep track of updates and new features Splunk introduces periodically and try to introduce those features in our day to day activities for improvement in our reporting system and other tasks.
Anonymous | TrustRadius Reviewer

Sumo Logic

No score
No answers yet
No answers on this topic

Usability

Splunk Enterprise

Splunk Enterprise 9.0
Based on 3 answers
You can literally throw in a single word into Splunk and it will pull back all instances of that word across all of your logs for the time span you select (provided you have permission to see that data). We have several users who have taken a few of the free courses from Splunk that are able to pull data out of it everyday with little help at all.
Kenneth Taitingfong | TrustRadius Reviewer

Sumo Logic

No score
No answers yet
No answers on this topic

Reliability and Availability

Splunk Enterprise

Splunk Enterprise 10.0
Based on 1 answer
When properly setup and configured, Splunk is extremely reliable.
Anonymous | TrustRadius Reviewer

Sumo Logic

No score
No answers yet
No answers on this topic

Support Rating

Splunk Enterprise

Splunk Enterprise 8.7
Based on 24 answers
Splunk maintains a well resourced support system that has been consistent since we purchased the product. They help out in a timely manner and provide expert level information as needed. We typically open cases online and communicate when possible via e-mail and are able to resolve most issues with that method.
Anonymous | TrustRadius Reviewer

Sumo Logic

Sumo Logic 9.0
Based on 5 answers
I would give this rating because I attended a free Sumo Logic training at a WeWork in Chicago. I found the training very useful, and I learned a lot of features that I was not aware of before I went to the training. I like the idea that SumoLogic provides free training seminars. I am certified in level1, and I plan on certifying to level2.
M Phillip Yogore | TrustRadius Reviewer

Implementation Rating

Splunk Enterprise

Splunk Enterprise 9.0
Based on 2 answers
Smooth without too many major issues.
Anonymous | TrustRadius Reviewer

Sumo Logic

Sumo Logic 9.0
Based on 2 answers
I was satisfied with the implementation, as at the time, it was the best way to implement the product with the available feature sets in Sumo Logic. User creation and management became more of an issue during continued use, instead of it being an issue related to deploying the product in our environment.
Derek Ardolf | TrustRadius Reviewer

Alternatives Considered

Splunk Enterprise

Splunk is proving to be a formidable replacement for Qradar, which we had as our previous SIEM. Qradar was powerful, but not easy to customize and quite limited. Splunk is not per se a "SIEM" but it can be in the way you used it. Also there is an Enterprise Security App that is available to buy and sit on top of Splunk, and that will take care of any concerns with needing a full-fledged SIEM. Splunk wins.
Anonymous | TrustRadius Reviewer

Sumo Logic

Sumo Logic works very well out of the gate. For a small business it has given us what we need. I worked at a larger company previously, and we produced so many logs we had to create a custom logging service to handle them all. Cost and availability are big issues when deciding between the different services, whether self maintained and hosted, or provided by another company.
David Tanner | TrustRadius Reviewer

Scalability

Splunk Enterprise

Splunk Enterprise 9.1
Based on 1 answer
Splunk can scale in to the petabyte per day range which of course is awesome
Rick Yetter | TrustRadius Reviewer

Sumo Logic

No score
No answers yet
No answers on this topic

Return on Investment

Splunk Enterprise

  • I'm not a data analyst so I can not provide concrete examples on how the business has benefited from implementing Splunk. However, the analysts I have worked with have provided a wealth of support in reducing workstation issues across the enterprise. This alone reduces the time it takes to determine where the exact problem lies between a workstation and the servers it tries to communicate with.
Anonymous | TrustRadius Reviewer

Sumo Logic

  • I can't think of any negative side effects other than it being SO slow sometimes, but compared to Splunk everything is slow
  • It's SO much cheaper than Splunk that the time it takes to query information is well worth it
  • In the times that we've had Sumo go down or stop logging information, we've found that we'd be absolutely lost without Sumo
Anonymous | TrustRadius Reviewer

Pricing Details

Splunk Enterprise

General

Free Trial
Yes
Free/Freemium Version
Yes
Premium Consulting/Integration Services
Entry-level set up fee?
No

Splunk Enterprise Editions & Modules

Additional Pricing Details

Sumo Logic

General

Free Trial
Free/Freemium Version
Premium Consulting/Integration Services
Entry-level set up fee?
No

Sumo Logic Editions & Modules

Edition
Essentials$3.001
Enterprise$4.001
Enterprise Security$4.251
Enterprise Suite$4.751
  1. Per GB Logs
Additional Pricing Details

Rating Summary

Likelihood to Recommend

Splunk Enterprise
9.0
Sumo Logic
9.3

Likelihood to Renew

Splunk Enterprise
10.0
Sumo Logic

Usability

Splunk Enterprise
9.0
Sumo Logic

Reliability and Availability

Splunk Enterprise
10.0
Sumo Logic

Support Rating

Splunk Enterprise
8.7
Sumo Logic
9.0

Implementation Rating

Splunk Enterprise
9.0
Sumo Logic
9.0

Scalability

Splunk Enterprise
9.1
Sumo Logic

Add comparison