We performed a comparison between Splunk Enterprise Security and vRealize Network Insight based on real PeerSpot user reviews.
Find out what your peers are saying about Splunk, Microsoft, Wazuh and others in Security Information and Event Management (SIEM)."Exporting is a good feature. It helps me out when I have to do reports. I do a lot of exporting and crunching of the numbers. Dashboards are okay for showing to the leadership, but for doing statistics and updating tickets, the export feature is very beneficial for me."
"The correlation search functions that generate all the notables are valuable. That can get pretty complicated, and it handles that pretty well."
"It has quite extensive support in terms of integration. If you want to do anything, there are tools for that."
"Three features stand out for me: the SDK for writing Python, the customizable and adaptable diagnostic dashboard, and the optimizer for collecting data."
"It allows the centralization of data and makes possible new sorts of correlations that were previously impossible using traditional SIEMs such as ArcSight or QRadar."
"The ability to manipulate data in Splunk is unparalleled. Splunk’s powerful, flexible query language can morph difficult to understand log formats into usable data."
"Splunk Enterprise Security helped us with faster detection of threats."
"Splunk is extremely flexible, which allows us to create custom visualizations along with other customizations."
"The tool's ease of configuration and use and the availability of information and artifacts through professional services and the web are key factors that customers find valuable."
"It allows you to see traffic that you couldn't otherwise see, which is traffic within your Layer 3-bounded network, meaning east-west traffic. It's hard to get that any other way."
"It provides deep visibility into what is happening with traffic and helps us manage our network."
"The solution is extremely intuitive and user-friendly. When you log in to the application you are presented with a dashboard that is very reasonable for an initial user, and you can then customize it to your specific needs. But for all the data that we've found, we've only had to go through two or three drill-downs to get into that information."
"It gives the visibility that was either broken or there in pieces only. This solution provides a unified view of the whole system, back and forth. It has helped to reduce time to value, increase performance, more easily manage networks, and provide deep visibility."
"The most valuable feature for us is that insight into what our network is really doing - it's a fairly complex network. Not having to go through thousands of lines of network configuration to find firewall ports that were open or closed, for various ports, was very valuable. It went out and found everything we need very quickly."
"The gradual way the Network Insight shows you all the relevant information about your networks. It's pretty good. You can really dig deep deep inside and see where the problem is, where it comes from, what you have inside, how did you configure it. Also, it has alerts so you can have pretty much quite a big overview about your network. This is really something good."
"The initial setup was straightforward."
"The only improvement I am expecting is the cost of the licensing. Clients are going to other solutions just because of the cost."
"I haven't found a way for me to create my own plugins and integrate them into Splunk, but this isn't necessarily a limitation; it could simply be a lack of knowledge on my part."
"Sometimes, there is latency in the logs."
"Their technical support sucks."
"The configuration could be better."
"While Splunkbase (the app repository) has a lot of great content, some apps are terribly old and could stand to be updated or purged."
"Although the technical support is adequate, there is still room for improvement."
"It can be tough to get a hold of somebody in technical support depending on the complexity of the issue."
"The only real improvement they can make is to add more third-party vendors into the environment, mostly switch manufacturers, because it's really limited to Cisco equipment and there are a lot of companies out there other than Cisco."
"I would like to see more interoperability on the firewall and low balancer sides."
"If it were more application-aware, more descriptive; if it were able to determine the application that is actually doing the communication, that would be easier. More application information: which user or account it's accessing, is it accessing this application, doing these calls, if it is accessing a script, what script is it accessing. Things like that would provide deeper analytics so I can track what's going on. It would not just be, "These people shouldn't be talking," but who is actually doing these calls."
"I would like to see application identification. That would be cool."
"In a very general way, I would like to see an improvement in interoperability with third-party product, from other vendors."
"It needs to be a little easier to use and to understand the information it's putting out. That would make it more helpful. If you're not a network person you need to understand things like network policies and concepts. If you gave it to a regular admin, it would be nice if it were easier for them to pick up what is going on, understand the flows and whether or not stuff should be talking to each other, as opposed to just port groups and IP addresses."
"vRNI needs more remediation where it hooks into NSX."
"After you use it for a little while you become accustomed to it but the layout doesn't feel very intuitive. You have to dig around and find the exact place where you can find the information, where you can actually see your east-west traffic, etc. I would like them to bring that information more to the forefront, instead of having to find it."
Splunk Enterprise Security is ranked 1st in Security Information and Event Management (SIEM) with 240 reviews while vRealize Network Insight is ranked 24th in IT Infrastructure Monitoring with 44 reviews. Splunk Enterprise Security is rated 8.4, while vRealize Network Insight is rated 8.6. The top reviewer of Splunk Enterprise Security writes "It has a drag-and-drop interface, so you don't need to know SQL or Java to construct a query ". On the other hand, the top reviewer of vRealize Network Insight writes "Provides deep analytical insights and makes migrations efficient with dependency mapping". Splunk Enterprise Security is most compared with Wazuh, Dynatrace, IBM Security QRadar, Elastic Security and Microsoft Sentinel, whereas vRealize Network Insight is most compared with ThousandEyes, NETSCOUT vSTREAM, AppNeta by Broadcom, Zabbix and Cisco Secure Network Analytics.
We monitor all Security Information and Event Management (SIEM) reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.