Elastic Search vs Splunk Enterprise Security comparison

Cancel
You must select at least 2 products to compare!
Elastic Logo
2,220 views|754 comparisons
98% willing to recommend
Splunk Logo
23,657 views|19,419 comparisons
93% willing to recommend
Comparison Buyer's Guide
Executive Summary

We performed a comparison between Elastic Search and Splunk Enterprise Security based on real PeerSpot user reviews.

Find out what your peers are saying about Elastic, IBM, Luigi's Box and others in Indexing and Search.
To learn more, read our detailed Indexing and Search Report (Updated: June 2024).
787,033 professionals have used our research since 2012.
Q&A Highlights
Question: What are the advantages of ELK over Splunk?
Answer: First of all, we need to understand what those two softwares are; Splunk is a finished SIEM that is mainly used to analyze data, such as logs, net flows, etc. Splunk comes in different flavors, below I will include a link of all the products they have. https://www.splunk.com/en_us/software.html Some of them can be even downloaded or you can try them in the cloud, below I will give you a link of Splunk enterprise, in the link you can see that you can download it, as a trial. https://www.splunk.com/en_us/software/splunk-enterprise/features.html ELK can be used for the requirements that you included, such as log analysis, the difference is that you will have to write the normalizers (this is a configuration file based on regex that reads the raw log and devices the log in small pieces), you will have to write the configuration file of the different widgets in the dashboard, alerts will have to be also written, etc. Elastic.co has already made an app that works as a SIEM, from all the products I think this will be the one that will make the most sense, as a log storage/analyzer, below is the link and you can try it as a cloud deployment. https://www.elastic.co/products/siem Also, this is a more complete list of all the features that are included in the enterprise version, here you can check them out and decide if this is something that will work for you. https://www.elastic.co/subscriptions Those two softwares are very good, but it will be better if you give them a try by yourself and try to compare them to see which one is the best for your network environment.
Featured Review
Quotes From Members
We asked business professionals to review the solutions they use.
Here are some excerpts of what they said:
Pros
"The ability to aggregate log and machine data into a searchable index reduces time to identify and isolate issues for an application. Saves time in triage and incident response by eliminating manual steps to access and parse logs on separate systems, within large infrastructure footprints.""The solution is stable and reliable.""The special text processing features in this solution are very important for me.""Elasticsearch includes a graphical user interface (GUI) called Kibana. The GUI features are extremely beneficial to us.""The most valuable features are the data store and the X-pack extension.""I appreciate that Elastic Enterprise Search is easy to use and that we have people on our team who are able to manage it effectively.""The most valuable features of Elastic Enterprise Search are it's cloud-ready and we do a lot of infrastructure as code. By using ELK, we're able to deploy the solution as part of our ISC deployment.""The most valuable feature for us is the analytics that we can configure and view using Kibana."

More Elastic Search Pros →

"The most valuable feature of Splunk Enterprise Security is website activity monitoring.""This solution helps us increase our productivity.""Our clients use the solution to find any threats or vulnerabilities inside their environment.""The logs on the solution are excellent.""It's basically one of the best SIEM products on the market.""Support is quick and competent.""The solution has made us more secure.""The most valuable feature of Splunk is the management and built-in workflows."

More Splunk Enterprise Security Pros →

Cons
"We have an issue with the volume of data that we can handle.""Technical support should be faster.""Enterprise scaling of what have been essentially separate, free open source software (FOSS) products has been a challenge, but the folks at Elastic have published new add-ons (X-Pack and ECE) to help large companies grow ELK to required scales.""The different applications need to be individually deployed.""I have not been using the solution for many years to know exactly the improvements needed. However, they could simplify how the YML files have to be structured properly.""I would rate the stability a seven out of ten. We faced a few issues.""Elastic Search could benefit from a more user-friendly onboarding process for beginners.""We'd like to see more integration in the future, especially around service desks or other ITSM tools."

More Elastic Search Cons →

"The solution could improve by giving more email details.""It requires a significant amount of relatively complex architecture once you push past the single server instance.""An improved user interface along with multi-tenancy support would be beneficial.""Customizing our commands should be simpler. Creating custom commands in Splunk requires a long, complex process. For example, we have a command to add all the column data, but we don't have a command to get the average of the column data at the end. It would be useful to have a blank at the end to create our commands and leave the rest to others.""Configuring a few apps is complex, not straightforward.""Splunk Enterprise Security is complicated in terms of developing specific cybersecurity use cases.""Previously, they developed custom connectors or add-ons for a lot of applications. But that number can be upgraded still. There are a lot of applications in the world that are not supported.""While Splunk Enterprise Security offers valuable features, its cost is high and could be more competitive."

More Splunk Enterprise Security Cons →

Pricing and Cost Advice
  • "ELK has been considered as an alternative to Splunk to reduce licensing costs."
  • "An X-Pack license is more affordable than Splunk."
  • "​The pricing and license model are clear: node-based model."
  • "This is a free, open source software (FOSS) tool, which means no cost on the front-end. There are no free lunches in this world though. Technical skill to implement and support are costly on the back-end with ELK, whether you train/hire internally or go for premium services from Elastic."
  • "We are using the free version and intend to upgrade."
  • "It can be expensive."
  • "This product is open-source and can be used free of charge."
  • "We are using the open-sourced version."
  • More Elastic Search Pricing and Cost Advice →

  • "Pricing and licensing is quite expensive. But for the value the product provides, it seems at par in the market."
  • "Although Splunk is an expensive product, it is designed to be utilized across your organization in order to maximize your ROI and lower your TCO."
  • "It is not cheap."
  • "Splunk Enterprise becomes extremely expensive after the 20GB/month license."
  • "You will eat up whatever you purchase quickly. The level of insights that Splunk empowers is addictive."
  • "Splunk licensing model might seem expensive but with all the gain in functionalities you will have compared to traditional SIEM solutions I think it’s worth the price."
  • "Pricing is pretty fair."
  • "While licensing can be a concern, there are ways to reduce the licensing costs including filtering some events."
  • More Splunk Enterprise Security Pricing and Cost Advice →

    report
    Use our free recommendation engine to learn which Indexing and Search solutions are best for your needs.
    787,033 professionals have used our research since 2012.
    Comparison Review
    Vinod Shankar
    Answers from the Community
    Vivek Vijayan
    reviewer1182204 - PeerSpot reviewerreviewer1182204 (Director of Marketing, US)
    Vendor

    Generally Elastic is very strong in datasearch, and Splunk has a strong security solution. However Elastic has partnered with SIEM provider empow and together this integration provides a very strong platform both in datasearch and next generation SIEM.

    Here's a thorough article on ELK vs. Splunk and here's a description from Elastic on what's included in the different versions.

    Alex Boz - PeerSpot reviewerAlex Boz (Logrhythm)
    Vendor

    Splunk: hard to use, expensive with predatory pricing, few OOTB rules, SOAR is a premium, good luck training analyst on their platform in under six months. SPLUNK SEARCH.

    ELK Stack: easy to use, open-source, no predatory pricing, more robust use cases OOTB, loved and used by millions all over the globe, open ecosystem that can integrate with almost any major IT stack out of the box. LUCENE.

    Norman Freitag - PeerSpot reviewerNorman Freitag
    Real User

    We use ELK or other freeware stacks in isolated small scenarios.

    Think of a small or medium company with a „midsized“ webshop. You can easily do your Log management with an ELK-Stack, let's say size 5 up to 10 GB, no Problem. Please keep in mind to order Hardware. The best thing on ELK is that you can start immediately you don't have to wait for licensing and it's easy to build the first small things.

    Another Example:
    Your Marketing Dep. wants to do some singular evaluations and very specialized marketing stuff. It is temporary and they don't have the budget for licensing. The results are not for permanent use. Just use ELK.

    In my opinion, ELK is only cost-effective if you don't need to buy their professional service. You must leave the cases small.

    If you are looking for bigger scenarios or you want to build-up a SIEM, SOC or even doing elevated things like SOAR it is a very different kind of thing.
    There can be account issues that a developer usually won't mind at the first glance but a Controller will.
    You have to look at the Total Cost of Ownership, Scalability, Time to Market, Secureness of future development, maintenance e.g.

    If you want to build up a complex scenario with the secureness of scalability you should go with SPLUNK. If tomorrow there is a better tool with lower costs and less need for input of manpower I will refer to this.

    Questions from the Community
    Top Answer:Logsign provides us with the capability to execute multiple queries according to our requirements. The indexing is very high, making it effective for storing and retrieving logs. The real-time… more »
    Top Answer:I don't see improvements at the moment. The current setup is working well for me, and I'm satisfied with it. Integrating with different platforms is also fine, and I'm not recommending any changes or… more »
    Top Answer:For tools I’d recommend:  -SIEM- LogRhythm -SOAR- Palo Alto XSOAR Doing commercial w/o both (or at least an XDR) is asking to miss details that are critical, and ending up a statistic. Also,… more »
    Top Answer:It would really depend on (1) which logs you need to ingest and (2) what are your use cases Splunk is easy for ingestion of anything, but the charge per GB/Day Indexed and it gets expensive as log… more »
    Top Answer:Splunk handles a high amount of data very well. We use Splunk to capture information and as an aggregator for monitoring information from different sources. Splunk is very good at alerting us if we… more »
    Ranking
    1st
    out of 25 in Indexing and Search
    Views
    2,220
    Comparisons
    754
    Reviews
    27
    Average Words per Review
    507
    Rating
    8.3
    Views
    23,657
    Comparisons
    19,419
    Reviews
    85
    Average Words per Review
    894
    Rating
    8.4
    Comparisons
    Also Known As
    Elastic Enterprise Search, Swiftype, Elastic Cloud
    Learn More
    Overview

    Elasticsearch is a prominent open-source search and analytics engine known for its scalability, reliability, and straightforward management. It's a favored choice among enterprises for real-time data search, analysis, and visualization. Open-source Elasticsearch is free, offering a comprehensive feature set and scalability. It allows full control over deployments but requires managing and maintaining the infrastructure. On the other hand, Elastic Cloud provides a managed service with features like automated provisioning, high availability, security, and global reach.

    Elasticsearch excels in handling time-sensitive data and complex search requirements across large datasets. Its scalability allows it to handle growing data volumes efficiently, maintaining high performance and fast response times. Integrated with Kibana, Elasticsearch enables powerful data visualization, providing real-time insights crucial for data-driven decision-making.

    Elastic Cloud reduces operational overhead and improves scalability and performance, though it comes with associated costs. It is available on your preferred cloud provider — AWS, Azure, or Google Cloud. Customers who want to manage the software themselves, whether on public, private, or hybrid cloud, can download the Elastic Stack.

    At its core, Elasticsearch is renowned for its full-text search capabilities, capable of performing complex queries and supporting features like fuzzy matching and auto-complete.

    Peer reviews from various professionals highlight its strengths and weaknesses. Pros include its detection and correlation features, flexibility, cloud-readiness, extensibility, and efficient search capabilities. However, users have noted challenges like steep learning curves, data analysis limitations, and integration complexities. The platform is generally viewed as stable and scalable, with varying degrees of satisfaction regarding its usability and feature set.

    In summary, Elasticsearch stands out for its high-speed search, scalability, and versatile analytics, making it a go-to solution for organizations managing large datasets. Its adaptability to different enterprise needs, robust community support, and continuous development keep it at the forefront of enterprise search and analytics solutions. However, potential users should be aware of its learning curve and the need for skilled personnel for optimization.

    Splunk Enterprise Security is a SIEM, log management, and IT operations analytics tool. The solution provides users with the ability to secure their information and manage their data in the cloud, data centers, or other applications. Splunk Enterprise Security also offers visibility from different areas, levels, and devices, rather than from a single system, thus, providing its users with flexibility. Splunk Enterprise Security can monitor data and analyze, detect, and prevent intrusions. This benefits users as it provides alerts to possible intrusions, helps users to be proactive, and reduces risk factors. 

    Full visibility across your environment

    Break down data silos and gain actionable intelligence by ingesting data from multicloud and on-premises deployments. Get full visibility to quickly detect malicious threats in your environment.

    Fast threat detection

    Defend against threats with advanced security analytics, machine learning and threat intelligence that focus detection and provide high-fidelity alerts to shorten triage times and raise true positive rates.

    Efficient investigations

    Gather all the context you need and initiate flexible investigations with security analytics at your fingertips. The built-in open and extensible data platform boosts productivity and drives down fatigue.

    Open and scalable

    Built on an open and scalable data platform, you can stay agile in the face of evolving threats and business needs. Splunk meets you where you are on your cloud journey, and integrates across your data, tools and content.

    Sample Customers
    T-Mobile, Adobe, Booking.com, BMW, Telegraph Media Group, Cisco, Karbon, Deezer, NORBr, Labelbox, Fingerprint, Relativity, NHS Hospital, Met Office, Proximus, Go1, Mentat, Bluestone Analytics, Humanz, Hutch, Auchan, Sitecore, Linklaters, Socren, Infotrack, Pfizer, Engadget, Airbus, Grab, Vimeo, Ticketmaster, Asana, Twilio, Blizzard, Comcast, RWE and many others.
    Splunk has more than 7,000 customers spread across over 90 countries. These customers include Telenor, UniCredit, ideeli, McKenney's, Tesco, and SurveyMonkey.
    Top Industries
    REVIEWERS
    Financial Services Firm33%
    Computer Software Company27%
    Manufacturing Company10%
    Insurance Company7%
    VISITORS READING REVIEWS
    Computer Software Company18%
    Financial Services Firm15%
    Manufacturing Company8%
    Government8%
    REVIEWERS
    Computer Software Company19%
    Financial Services Firm14%
    Government9%
    Energy/Utilities Company8%
    VISITORS READING REVIEWS
    Financial Services Firm15%
    Computer Software Company14%
    Government9%
    Manufacturing Company8%
    Company Size
    REVIEWERS
    Small Business41%
    Midsize Enterprise11%
    Large Enterprise48%
    VISITORS READING REVIEWS
    Small Business24%
    Midsize Enterprise14%
    Large Enterprise62%
    REVIEWERS
    Small Business31%
    Midsize Enterprise12%
    Large Enterprise58%
    VISITORS READING REVIEWS
    Small Business19%
    Midsize Enterprise13%
    Large Enterprise68%
    Buyer's Guide
    Indexing and Search
    June 2024
    Find out what your peers are saying about Elastic, IBM, Luigi's Box and others in Indexing and Search. Updated: June 2024.
    787,033 professionals have used our research since 2012.

    Elastic Search is ranked 1st in Indexing and Search with 59 reviews while Splunk Enterprise Security is ranked 1st in Security Information and Event Management (SIEM) with 255 reviews. Elastic Search is rated 8.2, while Splunk Enterprise Security is rated 8.4. The top reviewer of Elastic Search writes "Played a crucial role in enhancing our cybersecurity efforts ". On the other hand, the top reviewer of Splunk Enterprise Security writes "It has a drag-and-drop interface, so you don't need to know SQL or Java to construct a query ". Elastic Search is most compared with Faiss, Milvus, Pinecone, Azure Search and Amazon Kendra, whereas Splunk Enterprise Security is most compared with Wazuh, IBM Security QRadar, Dynatrace, Elastic Security and Microsoft Sentinel.

    We monitor all Indexing and Search reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.