

Find out what your peers are saying about Splunk, Wazuh, Cribl and others in Log Management.
It does not require hefty security budgets and can be deployed for enterprise security effectively.
The incident response time to any failure has increased more than 50 percent.
It centralizes log monitoring and automation, offering real-time analytics that help our organization detect issues faster, reduce downtime, and improve operational efficiency.
It is definitely not a beginner-friendly tool, but it is definitely the best tool that is available in the market for insurance-related products.
Support is prompt and helpful.
Most of the time when my team encounters issues, they receive responses within 24 hours.
I have not faced any difficulties with Elastic Security, as we have a pretty good support service from them.
I feel that Splunk's documentation is highly maintained, regular updates seem to happen, and I don't have any suggestions for improvement as it is currently at its best.
However, as I mentioned, sometimes they might not have proper knowledge or sometimes they are not sufficiently technical.
The CSMs and account managers in the channel team are great, providing assistance not just with selling the product but also for implementation, deployment, and aftercare.
It allows us to think about specific use cases, such as gathering malicious IPs in a single view and analyzing threats based on geolocation.
Elastic Security is quite scalable.
If we have compliance requirements to just store logs, then Splunk Cloud Platform is not the right platform.
If you purchase something initially and later have increased requirements, they can scale up and scale down your environment.
Splunk Cloud Platform's scalability works well, especially for smaller businesses, but can present issues for larger enterprises facing stricter regulations and greater integration requirements.
In terms of stability, I would rate Elastic a solid eight out of ten.
Its stability is commendable, enabling easy visibility into logs, effective data ingestion, and successful operations with diverse integrations and third-party platforms.
This is usually improved by following best practices such as optimizing SPL queries, using the proper index, and managing data correctly.
I rate Splunk Cloud Platform a ten out of ten for stability and reliability.
CrowdStrike and Defender have more established threat intelligence integration due to having a larger client base.
My security testing team continuously reports vulnerabilities, and we have to fix and update the versions frequently.
Machine learning algorithms become better with time; as they ingest a huge volume of data, they become better.
I know there are tutorials on the website, but I feel if they rolled out more free courses on such things that provide a link to a free course for beginner training, I feel people would be interested in it.
In terms of enhancement for Splunk Cloud Platform, I would say if we could create add-ons or if we get the capability to build add-ons directly through cloud, not talking about the add-on builder framework, but something editor-like where we will directly edit our conf files from any specific app or TA provided by Splunk Cloud Platform itself.
I would suggest going for Splunk Cloud Platform because AWS, Microsoft Azure, and Google Cloud are very expensive in comparison.
The pricing is reasonable, especially for Small Medium Enterprises (SMEs), making it a viable option for businesses building their security infrastructure.
This is beneficial for SMEs as they do not need extensive budgets for security solutions.
Elastic Security is considered cost-effective, especially at lower EPS levels.
Once you are in the partnership with Splunk Cloud Platform and with Cisco, you can have good discounts, you can make the deal and discuss, and they are willing to help you as a partner in finding the solution and finding your target.
When it comes to the cost of Splunk Cloud Platform, I would rate it a five from one to ten, with one being cheap and ten being expensive.
If you really need the SIEM solution, then it is very cost-effective for your company.
Elastic Security offers good insight regarding alerts, reports, and cases.
Elastic Security offers advanced features such as machine learning and integration with ChatGPT.
We require rapid processing speed for alerts and event data, and Elastic Security is very efficient at handling this level of data.
The most valuable feature of Splunk Cloud Platform is its robustness and ability to ingest logs.
The search capability utilizes the same compute assigned, and compared to on-premises, it is very efficient and fast because on-premises we had fixed compute assigned with limits set for searching per role or application.
The platform's alerting mechanism is valuable, as there is software that makes alarms in case of attacks.
| Product | Mindshare (%) |
|---|---|
| Elastic Security | 3.3% |
| Splunk Enterprise Security | 6.8% |
| Wazuh | 4.8% |
| Other | 85.1% |
| Product | Mindshare (%) |
|---|---|
| Splunk Cloud Platform | 1.0% |
| Tableau Enterprise | 9.7% |
| Qlik Sense | 4.8% |
| Other | 84.5% |

| Company Size | Count |
|---|---|
| Small Business | 40 |
| Midsize Enterprise | 12 |
| Large Enterprise | 15 |
| Company Size | Count |
|---|---|
| Small Business | 36 |
| Midsize Enterprise | 14 |
| Large Enterprise | 54 |
Elastic Security stands out for its speed, scalability, and intuitive interface. It integrates seamlessly with Elasticsearch and Kibana, providing efficient data indexing, centralized log management, and intelligent threat identification, all while being open-source.
Elastic Security offers robust capabilities in security monitoring, threat identification, and SIEM functionalities. Its open-source nature enhances scalability, facilitating log aggregation and infrastructure monitoring. Users appreciate the intuitive dashboards and machine learning integration, which aid in proactive security measures and anomaly detection. Despite its strengths, improvements are needed in documentation, scalability, and configuration complexity. High data volume pricing and limited machine learning support are concerns, while dashboard enhancement and seamless integration with existing systems are desirable. The platform is widely used for alerting suspicious activities, analyzing logs from firewalls and Active Directory, and providing endpoint protection. It serves as a key tool for security awareness and auditing, integrating effectively with technologies like Kibana and OpenShift.
What are the most notable features of Elastic Security?Organizations deploy Elastic Security across industries for log aggregation and security monitoring, detecting unauthorized access, and analyzing system logs. It is essential for infrastructure monitoring and integrates effectively with systems such as Fluentd and OpenShift, supporting comprehensive security views across enterprise environments.
Splunk Cloud Platform enhances operational efficiency with streamlined log management and real-time data analysis, offering customizable dashboards, seamless system integration, and a user-friendly interface that simplifies infrastructure management.
Splunk Cloud Platform stands out for its robust indexing and powerful search capabilities, delivering end-to-end visibility across environments. AI-driven security measures enhance cybersecurity intelligence, while its flexible log management reduces resolution times. The platform integrates effortlessly with diverse systems, supporting centralized log management, security monitoring, and application performance analysis. Users leverage its comprehensive analytics for troubleshooting, alerting, and visualization, optimizing costs and ensuring compliance with unified data sources.
What are the key features of Splunk Cloud Platform?In many industries, Splunk Cloud Platform is implemented primarily for unified log management, cybersecurity initiatives, and application performance monitoring. Businesses utilize it to streamline IT operations, integrate data sources, and leverage insights for troubleshooting and strategic decision-making, ensuring compliance and optimized resource use.
We monitor all Log Management reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.