No more typing reviews! Try our Samantha, our new voice AI agent.

Honeycomb Enterprise vs Splunk Enterprise Security comparison

 

Comparison Buyer's Guide

Executive SummaryUpdated on Feb 8, 2026

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

ROI

Sentiment score
4.2
Honeycomb Enterprise boosts debugging speed, customer satisfaction, and cost efficiency, enabling operational scaling with reduced staffing needs.
Sentiment score
6.2
Splunk Enterprise Security enhances efficiency, threat detection, and incident response, offering valuable insights despite concerns about pricing.
Honeycomb Enterprise played a vital role in identifying the problems in the initial calls itself. That has actually saved us a lot of incidents.
Lead Engineer at a tech vendor with 51-200 employees
The biggest return on investment with Honeycomb Enterprise is being able to find, if I am doing production support and something goes wrong, the exact scenario or the exact request and response and the details of that really quickly.
Software Engineer at a non-tech company with 501-1,000 employees
The documentation for Splunk Enterprise Security is outstanding. It is well-organized and easy to access.
DevOps&Cloud Engineer Mentee at CertDirectory.io
We couldn't calculate what would have been the cost if they had actually gotten compromised; however, they were in the process, so every investment was returned immediately.
Business Development Manager at Axians Germany
On average, my SecOps team takes probably at least a quarter of the time, if not more, to remediate security incidents with Splunk Enterprise Security compared to our previous solution.
IT Orchestration Architect at Penn State University
 

Customer Service

Sentiment score
3.1
Honeycomb Enterprise has generally positive customer service, but users face difficulties with technical queries and uneven support experiences.
Sentiment score
6.3
Support for Splunk Enterprise Security is mostly positive, but some users face delays and desire better escalation processes.
When I was looking at Honeycomb Enterprise support with Go Lambdas, it was a little tricky to find someone who could help me answer the question.
Software Engineer at a non-tech company with 501-1,000 employees
We have paid for Splunk support, and we’re not on the free tier hoping for assistance; we are a significant customer and invest a lot in this service.
Senior System Administrator at a tech services company with 5,001-10,000 employees
I have had nothing but good experiences with Splunk support, receiving timely and helpful replies.
Cyber Security Associate at SAP
We've had great customer success managers who have helped us navigate scaling from 600 gigs to 30 terabytes.
Principal Engineer at Aviatrix
 

Scalability Issues

Sentiment score
5.4
Honeycomb Enterprise efficiently supports scalable organizations with effective data management, though some users see room for pricing improvement.
Sentiment score
7.4
Splunk Enterprise Security is praised for scalable adaptability, seamless cloud integration, and high costs with increasing scalability demands.
When you send traces, you will get the complete view of the life of the code and how it has been executed.
Lead Engineer at a tech vendor with 51-200 employees
Honeycomb Enterprise scales best when all the products in the company use it because it allows tracing outside of individual products to see how they interact.
Software Engineer at a non-tech company with 501-1,000 employees
That is being used for at least eight thousand hosts.
Lead Engineer at Qualys
We currently rely on disaster recovery and backup recovery, which takes time to recover, during which you're basically blind, so I'm pushing my leadership team to switch over to a clustering environment for constant availability.
IT Security Engineer at a financial services firm with 201-500 employees
It is one of the things that separates it from other tooling, and if not, it is the most scalable solution out there.
Systems Development Engineer at a tech vendor with 10,001+ employees
They struggle a bit with pure virtual environments, but in terms of how much they can handle, it is pretty good.
CTO at a tech vendor with 10,001+ employees
 

Stability Issues

Sentiment score
7.1
Honeycomb Enterprise is praised for stability but faces mixed reviews due to integration issues and occasional tracing problems.
Sentiment score
7.6
Splunk Enterprise Security is stable, reliable, and handles large data well, with occasional issues in on-premises deployments.
They could not get proper tracing with Honeycomb Enterprise at that time.
Lead Engineer at Qualys
In terms of stability and availability, this is an impressive one.
Customer Support Engineer at a insurance company with 10,001+ employees
They test it very thoroughly before release, and our customers have Splunk running for months without issues.
Splunk System Engineer at a non-tech company with 11-50 employees
Splunk has been very reliable and very consistent.
Principal Engineer at Aviatrix
We need more SMEs, and there is no mechanism to tell us about indexer or search head issues.
Senior Manager at Bank of America
 

Room For Improvement

Users request better documentation, pricing, AI features, a streamlined UI, tool integration, and improved microservices support for Honeycomb Enterprise.
Users find Splunk Enterprise Security costly and complex, needing better documentation, support, and enhanced AI for threat detection.
Rather, it must be treated as a powerful supplementary tool that augments the existing code security solutions (such as Snyk or Checkmarx) in a DevSecOps or Secure DevOps environment.
CEO at a computer software company with 10,001+ employees
The main thing is that I think everything should very hard aim for the direction of being AI compatible because every engineer, or most engineers now use AI to code.
Software Engineer at a financial services firm with 11-50 employees
That is what performance engineers and SREs need to see for each request, where it spent the entire time; how many other services or databases it interacted with and what took more or less time.
Lead Engineer at Qualys
Improving the infrastructure behind Splunk Enterprise Security is vital—enhanced cores, CPUs, and memory should be prioritized to support better processing power.
Resident Consultant (Security Analyst) at helpag
Splunk Enterprise Security is not something that automatically picks things; you have to set up use cases, update data models, and link the right use cases to the right data models for those detections to happen.
Security & Risk Analyst at a computer software company with 1,001-5,000 employees
For any future enhancements or features, such as MLTK and SOAR platform integration, we need more visibility, training, and certification for the skilled professionals who are working.
Security Consultant at Matiq
 

Setup Cost

Splunk Enterprise Security is costly, favoring large enterprises, with gigabyte-based pricing potentially challenging smaller organizations' budgets.
In terms of pricing, it was a little challenging to get the company to commit to the full pricing of Enterprise, but once we got there it was nice.
Software Engineer at a non-tech company with 501-1,000 employees
I saw clients spend two million dollars a year just feeding data into the Splunk solution.
CTO at a tech vendor with 10,001+ employees
The platform requires significant financial investment and resources, making it expensive despite its comprehensive features.
System Engineer - Security Presales at Raya Integration
I find it to be affordable, which is why every industry uses it.
Vice President Research And Development at OSINT Ambition
 

Valuable Features

Honeycomb Enterprise excels in real-time monitoring, scalability, and cost-effective observability, enhancing service management and streamlining operations.
Splunk Enterprise Security offers strong SIEM compliance, risk-based alerting, intuitive dashboards, and machine learning integration for enhanced threat detection.
We get alerts into Slack, and they work great. We see a lot of metrics go through into Slack, and they are really useful for keeping our team focused on only seeing one place to see alerts.
Software Engineer at Invevo
The most valuable feature of Honeycomb Enterprise for me is the root cause analysis part because it helps me greatly with the response messages and derived error messages which are very clearly mentioned in Honeycomb Enterprise logs.
Customer Support Engineer at a insurance company with 10,001+ employees
Automated pull requests streamline the remediation process, facilitating efficient mass updates across multiple repositories.
CEO at a computer software company with 10,001+ employees
This capability is useful for performance monitoring and issue identification.
Staff Performance Engineer at a tech vendor with 10,001+ employees
I assess Splunk Enterprise Security's insider threat detection capabilities for helping to find unknown threats and anomalous user behavior as great.
Splunk System Engineer at a non-tech company with 11-50 employees
Splunk Enterprise Security provides the foundation for unified threat detection, investigation, and response, enabling fast identification of critical issues.
Specialist-Infrastructure Opertions at Allianz Technology
 

Categories and Ranking

Honeycomb Enterprise
Average Rating
7.4
Reviews Sentiment
5.5
Number of Reviews
9
Ranking in other categories
Application Performance Monitoring (APM) and Observability (20th), AI Code Assistants (8th), AI Observability (19th)
Splunk Enterprise Security
Average Rating
8.4
Reviews Sentiment
7.3
Number of Reviews
387
Ranking in other categories
Log Management (1st), Security Information and Event Management (SIEM) (1st), IT Operations Analytics (1st)
 

Mindshare comparison

While both are Application Lifecycle Management solutions, they serve different purposes. Honeycomb Enterprise is designed for Application Performance Monitoring (APM) and Observability and holds a mindshare of 1.1%, down 1.7% compared to last year.
Splunk Enterprise Security, on the other hand, focuses on Security Information and Event Management (SIEM), holds 7.1% mindshare, down 9.2% since last year.
Application Performance Monitoring (APM) and Observability Mindshare Distribution
ProductMindshare (%)
Honeycomb Enterprise1.1%
Dynatrace5.5%
Datadog4.7%
Other88.7%
Application Performance Monitoring (APM) and Observability
Security Information and Event Management (SIEM) Mindshare Distribution
ProductMindshare (%)
Splunk Enterprise Security7.1%
IBM Security QRadar5.2%
Wazuh4.6%
Other83.1%
Security Information and Event Management (SIEM)
 

Featured Reviews

MukeshSharma - PeerSpot reviewer
Lead Engineer at Qualys
Tracing microservices has exposed gaps in visibility but has provided high-cardinality insights
I have used better tools, I would say. I would not say that I prefer Honeycomb Enterprise as much. I have used Dynatrace, and I found it more comprehensive, and AppDynamics and other tools. These tools can also provide good information, but I find other tools better. Most of the products, I would say, such as Dynatrace or AppDynamics or New Relic, are targeting this microservices market. I think Honeycomb Enterprise can have something very dedicated for microservices because there is an explosion in the migration from monolithic to microservices. If Honeycomb Enterprise can create a stable solution which is easy to use and which gives additional value and helps for faster debugging with microservices, they can certainly gain market share from others. Tracing is already there. I just wish that these tools are a bit less cryptic. These tools sometimes get quite cryptic for new users. The less cryptic they can be made, that can help these tools. Another thing is that for microservices, when you have multiple microservices installed, that is also required. There are tools where you install on a single microservice, but then these microservices interact with multiple microservices. That kind of picture, I have seen that in AppDynamics; they do give a picture showing that a particular request which arrived here had interaction with these other third-party services or microservices and databases. That is what we need. That is what performance engineers and SREs need to see for each request, where it spent the entire time; how many other services or databases it interacted with and what took more or less time, and if there is a sequence, it should highlight that also. Was it parallel or if, for instance, a call to service A and then a call was made to a database, or a call to service A and a database were in parallel, that kind of information.
Sathis-Kumar - PeerSpot reviewer
Senior Manager at Bank of America
Helps us detect cyber threats quickly and integrate multiple feeds effectively
Overall, the product is good, but when it comes to some infrastructure issues, we have to dig into more logs. There is no straightforward indication of an issue. Health check kind of dashboards are not available. More AI would help us, and more optimization, since security products run more queries. The AI module could suggest solutions, optimizing queries or workload balancing. If the product itself advises on running queries during peak times, it would be similar to what ChatGPT currently offers. We see quite a few issues on stability. Even last week, we faced something, and identifying bottlenecks is not easy. We need more SMEs, and there is no mechanism to tell us about indexer or search head issues. Self-monitoring dashboards could be beneficial. The technical support still requires more improvement. Often, primary support takes a lot of time and forwards most solutions to the engineering side. The primary support team has very limited knowledge to provide.
report
Use our free recommendation engine to learn which Application Performance Monitoring (APM) and Observability solutions are best for your needs.
893,244 professionals have used our research since 2012.
 

Comparison Review

VS
Manager, Enterprise Risk Consulting at a tech company with 1,001-5,000 employees
Feb 26, 2015
HP ArcSight vs. IBM QRadar vs. ​McAfee Nitro vs. Splunk vs. RSA Security vs. LogRhythm
We at Infosecnirvana.com have done several posts on SIEM. After the Dummies Guide on SIEM, we are following it up with a SIEM Product Comparison – 101 deck. So, here it is for your viewing pleasure. Let me know what you think by posting your comments below. The key products compared here are…
 

Top Industries

By visitors reading reviews
Computer Software Company
13%
Financial Services Firm
12%
Comms Service Provider
8%
Manufacturing Company
7%
Financial Services Firm
14%
Manufacturing Company
9%
Computer Software Company
9%
Comms Service Provider
5%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business5
Midsize Enterprise1
Large Enterprise6
By reviewers
Company SizeCount
Small Business118
Midsize Enterprise50
Large Enterprise270
 

Questions from the Community

What needs improvement with Honeycomb.io?
The only complaint I have is that even though we are on a paid tier where we are paying one hundred thirty dollars per month, we are still lacking the amount of ingestion we have to do. It counts e...
What is your primary use case for Honeycomb.io?
I received information from your team regarding a peer review of Honeycomb Enterprise. As an observability engineer using Honeycomb Enterprise extensively, I can provide substantial input. My prima...
What advice do you have for others considering Honeycomb.io?
In those scenarios where you are not getting the complete data to the customer, it will cap the data to one megabyte. For tracing solution, definitely, I will always suggest Honeycomb Enterprise is...
What SOC product do you recommend?
For tools I’d recommend: -SIEM- LogRhythm -SOAR- Palo Alto XSOAR Doing commercial w/o both (or at least an XDR) is asking to miss details that are critical, and ending up a statistic. Also, rememb...
What is a better choice, Splunk or Azure Sentinel?
It would really depend on (1) which logs you need to ingest and (2) what are your use cases Splunk is easy for ingestion of anything, but the charge per GB/Day Indexed and it gets expensive as log ...
How does Splunk compare with Azure Monitor?
Splunk handles a high amount of data very well. We use Splunk to capture information and as an aggregator for monitoring information from different sources. Splunk is very good at alerting us if we...
 

Also Known As

Grit
No data available
 

Overview

 

Sample Customers

Clover Health, Eaze, Intercom, Fender
Splunk has more than 7,000 customers spread across over 90 countries. These customers include Telenor, UniCredit, ideeli, McKenney's, Tesco, and SurveyMonkey.
Find out what your peers are saying about Datadog, Dynatrace, Splunk and others in Application Performance Monitoring (APM) and Observability. Updated: April 2026.
893,244 professionals have used our research since 2012.