Try our new research platform with insights from 80,000+ expert users

Centreon vs Splunk Enterprise Security comparison

 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Centreon
Average Rating
8.4
Reviews Sentiment
7.2
Number of Reviews
28
Ranking in other categories
Network Monitoring Software (25th), IT Infrastructure Monitoring (22nd), Cloud Monitoring Software (18th)
Splunk Enterprise Security
Average Rating
8.4
Reviews Sentiment
7.6
Number of Reviews
305
Ranking in other categories
Log Management (2nd), Security Information and Event Management (SIEM) (1st), IT Operations Analytics (1st)
 

Mindshare comparison

While both are Systems Management solutions, they serve different purposes. Centreon is designed for IT Infrastructure Monitoring and holds a mindshare of 2.9%, up 2.9% compared to last year.
Splunk Enterprise Security, on the other hand, focuses on Security Information and Event Management (SIEM), holds 9.5% mindshare, down 12.8% since last year.
IT Infrastructure Monitoring
Security Information and Event Management (SIEM)
 

Featured Reviews

Caulson Chua - PeerSpot reviewer
With fewer staff resources, we can identify and address issues before the system goes down
Centreon's most valuable features are preventative maintenance and cost-efficiency. Everything is monitored, and we get a log before the system fails. We have an opportunity to fix the issue and avoid downtime. The dashboard is user-friendly, and the solution provides good reporting and visibility. The layout is straightforward. You can click on the drop-down list to select the server you want. The anomaly detection feature helped us reduce our average resolution time by 30 minutes to an hour.
ROBERT-CHRISTIAN - PeerSpot reviewer
Has many predefined correlation rules and is brilliant for investigation and log analysis
It is very complicated to write your own correlation rules without the help of Splunk support. What Splunk could do better is to create an API to the standard SIEM tools, such as Microsoft Sentinel. The idea would be to make it less painful. In ELK Stack, Kibana is the query language with which you can search log files. I believe Splunk has also a query language in which they search their log files, but once you have identified the log file that you want to use for further security correlation, you want to very quickly transport that into your SIEM tool, such as Microsoft Sentinel. That is something that Splunk could make a little bit less painful because it is a lot of effort to find that log file and forward it. An API with Microsoft Sentinel or a similar SIEM tool would be a good idea.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"Centreon helps me detect where the problem is quickly. When we resolve a problem quickly, this lowers our overall costs."
"In addition, the flexibility, customizability, and analytics of Centreon's dashboards are all very good. The dashboards help us see the whole network map, and that is quite valuable for us. In addition, the dashboards have helped to improve our visibility and ability to proactively ensure the right data is available at the right time... The flexibility has given us the ability to add in our own monitoring metrics and that has been quite interesting and very useful for us."
"The dashboards are valuable because they ease troubleshooting and viewing. It becomes easier to locate the source of a problem... The dashboards make it easier to communicate with our clients. They don't want to see the alert console, they want to see a beautiful dashboard representing their network and their business and to watch it in case something is wrong in their environment."
"I can't point to one valuable feature. All of Centreon is good."
"What I like most about Centreon is that it is very flexible and customizable, based on the user and/or business needs. Centreon is very flexible when it comes to monitoring parameters. We can use scripts found on the internet or scripts created by our infra/apps team. Also, the data visualization features are very simple and straightforward, yet very informative."
"The downtimes feature is helpful. If the ISP is doing some maintenance on its network, we have the option to put downtime on the devices or the services, so we won't get any false alarms."
"We are alerted on service impacts and not when something is down. We have saved a lot of time on non-business-hours intervention."
"It supports active monitoring so we don't have to use traps. From time to time traps are not very useful because we never know if they are actually working or not. The reporting part is also valuable as are the event logs. Using them we can check right away if something has had a hiccup."
"The correlation searches are most valuable just because we are able to do things like RBA."
"The ability to quickly search logs, performance data, and other inputs has helped tremendously with troubleshooting."
"The Splunk queries are valuable."
"The most valuable features in Splunk Enterprise Security are the cluster capabilities."
"Integration with the cloud is pretty important and good for us. We found the integration with a lot of tools, not all tools yet, valuable. It does make the transfer of data, log files, and other things easier for us."
"Splunk Enterprise Security's most valuable features are its stability and the robust Splunk Search Processing Language, allowing extensive customization and analysis capabilities."
"Splunk's advantage is its search capability. Its search is notably faster. With Splunk, I can search easily on keywords. That is great."
"With good domain knowledge, one can build almost anything. If you throw in Alert Manager or an integration with ServiceNow. Then, you have your own SIEM"
 

Cons

"Currently, we have to go through all of the different templates and take a look at how the template is configured, and how specific parameters may change across different templates with different precedents, megatons, etc. It's a lot of work and involves trial and error. I wish they could simplify the process."
"I would like them to improve their documentation. When I faced some issues, I was looking for more documentation on the Internet. There is official documentation on Centreon's website, which sometimes is useful. Sometimes it is not very useful, as you cannot find the information or enough examples of configuration. The answer for me was to contact the support, who helped me, but I was not able to find all the information by myself on Centreon's website. A Centreon community or blog would be helpful."
"I would like to see more plugins. That is something it needs. There is also room for improvement through dynamic thresholds, or self-discover thresholds. I would also like to see a discovery feature that could map the whole network environment and automatically suggest things."
"I would like to see an improvement of the communication with big data systems, because Centreon is a monitoring system. In our point of view, Centreon should be a part of a source for a big data system, not a big data system itself. So, it should be easier to add data from the Centreon system to a big data system. For example, it should be able to teach machine learning."
"I think Centreon's security could be improved by leveraging AI. That's where things are heading in the industry."
"Opening a ticket on the website of Centreon can be difficult for my colleague, but not for me because my English is good. However, my colleague doesn't speak English well, as our company is in Quebec and our first language is French."
"I would like to see a better UI, one which is more responsive."
"It is necessary to improve service monitoring of database services in the free version."
"I would like more assistance with use cases and help with teaching us how to use it once it's installed."
"Splunk's high cost, despite its recognition in our region, prevents many organizations from adopting Splunk Enterprise Security, suggesting there's room for improvement in their pricing strategy."
"Configuring a few apps is complex, not straightforward."
"Customizing our commands should be simpler. Creating custom commands in Splunk requires a long, complex process. For example, we have a command to add all the column data, but we don't have a command to get the average of the column data at the end. It would be useful to have a blank at the end to create our commands and leave the rest to others."
"It would be great if I could have a certain dialogue box in Splunk that uses innovative AI tools like ChatGPT, which are available now in the tech department."
"Due to its high licensing cost, Splunk is out of reach for many organizations."
"Splunk can improve its third-party device application plugins."
"The Enterprise Security app could be improved. We have had trouble with it working from the first day."
 

Pricing and Cost Advice

"The solution has a free part and after that threshold, you will need to pay. For example, if you believe you can create an interesting map, most of the time, you will have to pay 10,000 Euros per year for having access to these components."
"Open-source solutions like this can be very cost effective for an organization looking for a product that they can quickly implement, as there is no initial cost and there are no license renewal fees. However, it is important to take into consideration some of the related costs that may come along as needed, such as training, support, and product enhancements."
"Centreon is better than Nagios XI in regards to cost and support response times, when you have a problem. If you have a problem, it costs money to contact the Nagios XI support."
"Centreon is an open source product. Thus, there is no need for licensing."
"The price is not too high. Licensing is driven by how many hosts you monitor, but because you can run the agentless version, you don't have to declare every host to Centreon, one at a time. That means you can drive your infrastructure supervision with a very low number of declared hosts."
"You purchase a package. You have a support contract (there is also a platinum support contract) and it is per module. That means you have to pay, e.g., for the MBI module or the BAM module. Or, if you want to save a lot of money, you can pay for IMP, which is the complete package."
"The pricing is acceptable."
"The pricing works out well for us, given our environment and where we are."
"The pricing seems good relative to the other vendors that we have had here. However, they need to find ways to be more flexible with the licensing and be able to deal with situations where we start generating more logs. Maybe having some controls in the Splunk interface to turn it off, so we don't have to change anything in our application."
"The cost is on the high end, which makes it difficult for some organizations to use."
"Its pricing model can be improved."
"I would highly recommend anyone evaluating this option to download the free trial which allows for the ingestion of 500MB of data per day in order to get a feel for what Splunk does at its core. It will get pricey once your ingestion rates start to sky rocket, but I would consider it expensive given the amount of information that it allows you to analyze and react on straight out-of-the-box."
"Pricing can be a limiting factor. You have to continuously tune what you are bringing in and make sure what you bring in is of value."
"Splunk is definitely not a cheap solution. It is an expensive product."
"The pricing model is based on the number of gigabytes that you ingest into the Splunk system. So it can be an expensive solution."
"It's definitely worth it."
report
Use our free recommendation engine to learn which IT Infrastructure Monitoring solutions are best for your needs.
845,406 professionals have used our research since 2012.
 

Comparison Review

VS
Feb 26, 2015
HP ArcSight vs. IBM QRadar vs. ​McAfee Nitro vs. Splunk vs. RSA Security vs. LogRhythm
We at Infosecnirvana.com have done several posts on SIEM. After the Dummies Guide on SIEM, we are following it up with a SIEM Product Comparison – 101 deck. So, here it is for your viewing pleasure. Let me know what you think by posting your comments below. The key products compared here are…
 

Top Industries

By visitors reading reviews
Computer Software Company
19%
Financial Services Firm
11%
Government
10%
Comms Service Provider
7%
Financial Services Firm
15%
Computer Software Company
14%
Manufacturing Company
8%
Government
8%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

What do you like most about Centreon?
Centreon's most valuable features are preventative maintenance and cost-efficiency. Everything is monitored, and we get a log before the system fails. We have an opportunity to fix the issue and av...
What needs improvement with Centreon?
The issue my company has with the tool stems from the fact that it didn't give an on-time response to us. The product collects the information, but it fails to send them via SMS, WhatsApp or Telegr...
What SOC product do you recommend?
For tools I’d recommend: -SIEM- LogRhythm -SOAR- Palo Alto XSOAR Doing commercial w/o both (or at least an XDR) is asking to miss details that are critical, and ending up a statistic. Also, rememb...
What is a better choice, Splunk or Azure Sentinel?
It would really depend on (1) which logs you need to ingest and (2) what are your use cases Splunk is easy for ingestion of anything, but the charge per GB/Day Indexed and it gets expensive as log ...
How does Splunk compare with Azure Monitor?
Splunk handles a high amount of data very well. We use Splunk to capture information and as an aggregator for monitoring information from different sources. Splunk is very good at alerting us if we...
 

Overview

 

Sample Customers

Airbus, Bollore, BT, Canal Plus, Kuehne Nagel, Limagrain, LVMH, Oberthur Technologies, Orange, Darty, Addax Petroleum, Plastic Omnium, Auchan, Valeo, Saint Gobin, Clarins, Hugo Boss, JC Decaux, French Government (Defense, Justice, Environment, Agriculture), OptiComm, Thales, Zeiss.
Splunk has more than 7,000 customers spread across over 90 countries. These customers include Telenor, UniCredit, ideeli, McKenney's, Tesco, and SurveyMonkey.
Find out what your peers are saying about Zabbix, Datadog, Auvik and others in IT Infrastructure Monitoring. Updated: March 2025.
845,406 professionals have used our research since 2012.