We performed a comparison between Splunk Enterprise Security and WhatsUp Gold based on real PeerSpot user reviews.
Find out in this report how the two Security Information and Event Management (SIEM) solutions compare in terms of features, pricing, service and support, easy of deployment, and ROI."It has basic out-of-the-box integrations with multiple log sources."
"The best functionality that you can get from Azure Sentinel is the SOAR capability. So, you can estimate any type of activity, such as when an alert was triggered or an incident was found."
"What is most useful, is that it has a good connection to the Microsoft ecosystem, and I think that's the key part."
"Sentinel uses Azure Logic Apps for automation, which is really powerful. This allows us to easily automate responses to incidents."
"The most valuable features in my experience are the UEBA, LDAP, the threat scheduler, and integration with third-party straight perform like the MISP."
"Free ingestion for Azure logs (with E5 licence)"
"I like the unified security console. You can close incidents using Sentinel in all other Microsoft Security portals, when it comes to incident response."
"We have no complaints about the features or functionality."
"Splunk helps us be more proactive. We can take predictive action to identify and block threats so that nothing harmful gets into the system."
"One key advantage of Splunk over competitors like IBM QRadar is its superior device integration capabilities."
"I have found the installation can be of medium difficulty to very complex depending on the use case."
"We have found all the features useful. However, the dashboarding and logging have been very helpful. Additionally, the log analysis does a great job."
"Integration with the cloud is pretty important and good for us. We found the integration with a lot of tools, not all tools yet, valuable. It does make the transfer of data, log files, and other things easier for us."
"The product is adept at log mining."
"We have a one stop dashboard for health of some of our services where you can click in and it takes you to other dashboards that have custom near real-time metrics that show the application's health."
"Splunk's interface is user-friendly, and it has apps and add-ons for most applications. We can easily normalize the data to make it readable and understand the logs. We easily get all the field extractions and enrichment done by using the apps and add-ons. This helps us understand the application logs because the raw data is useless unless we extract some useful information from it. These add-ons make it so much easier."
"The documentation is very good."
"The most valuable features are network bandwidth monitoring and monitoring device health."
"This is a good, stable network monitoring solution for devices."
"WhatsUp Gold is very easy to deploy."
"It is easy to access and discover devices, as well as monitor them automatically. The topology discover is also a useful feature."
"The most valuable feature of WhatsUp Gold is NetFlow and the virtualized maps."
"The user interface is good enough."
"It handles the basics of monitoring."
"It has been a challenge with Azure Sentinel to onboard the Syslog server from FortiGate. Azure Sentinel can work better on that shift between the Syslog server and a firewall."
"There is a wider thing called Jupyter Notebooks, which is around the automation side of things. It would be good if there are playbooks that you can utilize without having to have the developer experience to do it in-house. Microsoft could provide more playbooks or more Jupyter Notebooks around MITRE ATT&CK Framework."
"If I see an alert and I want to drill down and get more details about the alert, it's not just one click. In other SIEM tools, you just have to click the IP address of the entity and they give you the complete picture. In Sentinel, you have to write queries or use saved queries to get details."
"Microsoft Sentinel should provide an alternative query language to KQL for users who lack KQL expertise."
"Improvement-wise, I would like to see more integration with third-party solutions or old-school antivirus products that have some kind of logging capability. I wouldn't mind having that exposed within Sentinel. We do have situations where certain companies have bought licensing or have made an investment in a product, and that product will be there for the next two or three years. To be able to view information from those legacy products would be great. We can then better leverage the Sentinel solution and its capabilities."
"The only thing is sometimes you can have a false positive."
"In terms of features I would like to see in future releases, I'm interested in a few more use cases around automation. I do believe a lot of automation is available, and more is in progress, but that would be my area of interest."
"Microsoft Defender has a built-in threat expert option that enables you to contact an expert. That feature isn't available in Sentinel because it's a huge product that integrates all the technologies. I would like Microsoft to add the threat expert option so we can contact them. There are a few other features, like threat assessment that the PG team is working on. I expect them to release this feature in the next quarter."
"Splunk is not very user-friendly. It has a complex architecture in comparison to other solutions on the market."
"We will receive alerts only for the administrators and deployment servers, but not for all servers."
"The user access control could be much more granular, so that the admins can control r/w/x access for specific features of the product like dashboards, etc."
"Splunk Enterprise Security can be improved by including backup network detection and response and safe management to the paid platform."
"Its interface could be improved."
"The threat management part is still lagging. There are some gaps in threat management. Other vendors have built-in threat management systems, but Splunk lacks the threat management component in its portal. The UEBA and everything else is perfect, but it lacks a unified threat intelligence and management part."
"Being a SIEM solution with a centralized dashboard, we would like to have more options to customize it."
"The integration with all our tool sets felt like we were reinventing the wheel, which was a pain point for us."
"You have to invest a few days to become an expert in this solution."
"Adding on services increases the cost and on the version we have there is no option for ATM monitoring."
"We can never achieve or get a good picture of the network topology."
"I think there are a few bugs now. Although they give some resolution for this, we cannot share the network remotely because of our company policy."
"Importing the maps and being able to customize them could be easier."
"The licensing model could be improved. Right now, the levels are too far apart. This causes the solution to be more expensive than it needs to be."
"The interface needs some work."
"The product is old and not updated."
Splunk Enterprise Security is ranked 1st in Security Information and Event Management (SIEM) with 240 reviews while WhatsUp Gold is ranked 31st in Application Performance Monitoring (APM) and Observability with 22 reviews. Splunk Enterprise Security is rated 8.4, while WhatsUp Gold is rated 7.8. The top reviewer of Splunk Enterprise Security writes "It has a drag-and-drop interface, so you don't need to know SQL or Java to construct a query ". On the other hand, the top reviewer of WhatsUp Gold writes "If CPU, memory, or disk space is over-utilized, it alerts us immediately via text or email if there is an issue". Splunk Enterprise Security is most compared with Wazuh, Dynatrace, IBM Security QRadar, Elastic Security and Datadog, whereas WhatsUp Gold is most compared with Grafana, Zabbix, SolarWinds NPM, PRTG Network Monitor and Prometheus. See our Splunk Enterprise Security vs. WhatsUp Gold report.
We monitor all Security Information and Event Management (SIEM) reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.