Try our new research platform with insights from 80,000+ expert users

ITRS Geneos vs Splunk Enterprise Security comparison

 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

ITRS Geneos
Average Rating
8.2
Reviews Sentiment
7.1
Number of Reviews
57
Ranking in other categories
Application Performance Monitoring (APM) and Observability (33rd), Network Monitoring Software (68th), IT Infrastructure Monitoring (45th)
Splunk Enterprise Security
Average Rating
8.4
Reviews Sentiment
7.3
Number of Reviews
375
Ranking in other categories
Log Management (2nd), Security Information and Event Management (SIEM) (1st), IT Operations Analytics (1st)
 

Mindshare comparison

While both are Application Lifecycle Management solutions, they serve different purposes. ITRS Geneos is designed for Application Performance Monitoring (APM) and Observability and holds a mindshare of 1.1%, down 1.3% compared to last year.
Splunk Enterprise Security, on the other hand, focuses on Security Information and Event Management (SIEM), holds 7.4% mindshare, down 10.0% since last year.
Application Performance Monitoring (APM) and Observability Market Share Distribution
ProductMarket Share (%)
ITRS Geneos1.1%
Dynatrace6.6%
Datadog5.5%
Other86.8%
Application Performance Monitoring (APM) and Observability
Security Information and Event Management (SIEM) Market Share Distribution
ProductMarket Share (%)
Splunk Enterprise Security7.4%
Wazuh7.3%
IBM Security QRadar5.6%
Other79.7%
Security Information and Event Management (SIEM)
 

Featured Reviews

Durai CT - PeerSpot reviewer
Head FM Monitoring at a financial services firm with 10,001+ employees
A stable, scalable, and flexible monitoring tool
Real-time data is one of the unique features that ITRS Geneos offers. For example, if there is an impact on a particular server and a particular application, I want to see what the impact is or what the CPU or hardware usage information is, as well as the service in the same application. I can see the real-time data and the impact by accessing ITRS Geneos and looking at the tree. I don't want a tool that tells me when something is broken. I want the tool to tell me when something is going to break. That is the difference between ITRS Geneos and other tools. I want proactive monitoring, not reactive. I don't need to be notified after the fact that something has broken. If something is broken, I get a notification by email, and some of my customers are going to call me. ITRS Geneos provides proactive monitoring. The great advantage of this tool is real-time monitoring. ITRS Geneos not only alerts us but also gives us a real-time view of the data. This is the tool's first great advantage. It is also lightweight and flexible and can adapt to monitor even low-latency systems, which is the tool's second advantage. Another great feature of this tool is its good presentation layer, which allows us to build custom dashboards to present to business stakeholders. This gives them a high-level status of what is being monitored. If we compare ITRS Geneos to other tools, we will find that each one specializes in a specific area, but the ITRS Geneos tool is more comprehensive. This is its great advantage.
reviewer1469784 - PeerSpot reviewer
Senior Manager at a financial services firm with 10,001+ employees
Helps us detect cyber threats quickly and integrate multiple feeds effectively
Overall, the product is good, but when it comes to some infrastructure issues, we have to dig into more logs. There is no straightforward indication of an issue. Health check kind of dashboards are not available. More AI would help us, and more optimization, since security products run more queries. The AI module could suggest solutions, optimizing queries or workload balancing. If the product itself advises on running queries during peak times, it would be similar to what ChatGPT currently offers. We see quite a few issues on stability. Even last week, we faced something, and identifying bottlenecks is not easy. We need more SMEs, and there is no mechanism to tell us about indexer or search head issues. Self-monitoring dashboards could be beneficial. The technical support still requires more improvement. Often, primary support takes a lot of time and forwards most solutions to the engineering side. The primary support team has very limited knowledge to provide.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"ITRS uses SNMP to communicate with our devices as well as SNMP net probes installed on our servers."
"The Netprobe is so lightweight compared to the agents that most monitoring tools use. It's really superior to the competition. The agent that is used by almost every competitive tool takes a lot more system resources. It's slower and it requires a greater effort and more compromises in terms of security to install on the monitored servers. With Geneos, because it lives outside the code, it is far easier and far less taxing on the monitored systems."
"The ability to logically normalize data gathered from multiple types of sources via pre-built plugins is extremely powerful. This functionality, coupled with the ability to import custom data via the Toolkit plugin allows Geneos to be leveraged to monitor every system in the enterprise."
"One of the most valuable features of ITRS Geneos is the active time feature that helps with the trading applications that I support."
"Tons of default modules which are available out of the box"
"I would say that it is an easy-to-use monitoring tool. Amongst the available monitoring tools, it is a really good option."
"ITRS can define rules to alert when certain parameters that you monitor breach a threshold. Rules can be configured to fire recovery actions automatically to clear the alert"
"Geneos automatically sends email notifications when any batch job fails, the database is down or the website is down. It is automatically monitoring everything and reduces manual effort."
"We primarily use it to correlate logs throughout the enterprise for both searching and use in investigations."
"The feature that we use the most is the correlation search engine within ES."
"The feature I appreciate the most about Splunk Enterprise Security is the CIM data model, which allows users to bring in data from different technologies, such as firewalls, endpoints, and perimeter DMZs, enabling every device to pump data into Splunk Enterprise Security, with the data model normalizing all the data and placing it in a common plane."
"Splunk Enterprise Security has helped improve my organization's business resilience by fulfilling gaps in forensics, incident management, IRP, and data management while helping us mature our security operations."
"I like the ease of setting up dashboards on Splunk. They're easy to create, manage, alter, and share. You can fine-tune them any way you see fit."
"It scales better in the cloud than on-premise."
"The solution is the market leader."
"With good domain knowledge, one can build almost anything. If you throw in Alert Manager or an integration with ServiceNow. Then, you have your own SIEM"
 

Cons

"For the solution to stay relevant in the cloud-based monitoring environment Geneos needs more plug-ins with more features. Instead of offering clients workarounds, the solution should have a cloud-based out-of-the-box version."
"We all look at the same things - CPU, disk space, paging stats, service status with RAG status on each. That could be provided straight out, saving significant time."
"At the moment Geneos is excellent and handling real time monitoring, however not great at doing historical reporting."
"I would really like to see something from the Geneos side to set up automated reporting from ITRS. We have to send reporting to management every day. To do that we have to check the dashboard and then we have to report whether everything is fine or not. In the future, I want something, some reporting kind of feature in ITRS, where it can collect all the data and mention what is green, what is amber, what is red in a report."
"Mobile phone integration is probably not as rich as it could be."
"Geneos' application monitoring could be improved a lot. Products like AppDynamics and Dynatrace provide the process thread-level monitoring, but Geneos lacks these capabilities."
"ITRS Geneos is not on the cloud at a time when everyone is moving to the cloud."
"The deployment method for upgrading is a bit tricky. It takes a little bit of manual effort. If that could be a bit more automated, it would help us a lot."
"The integration feature with other applications, such as anti-DDoS application Arbor, needs to be more powerful."
"Missing capability for audio/video and image processing."
"I'd like a dashboard that allows me to connect elements through drag-and-drop functionality."
"They can improve their support teams. They can also improve their capability of ingesting data from different IoT sources."
"Most of my interaction is with the user community, which is how Splunk wants it. When I need help, that community is very hit or miss."
"I feel the solution to be too slow."
"Splunk has a steeper learning curve, making it feel less user-friendly."
"Splunk's reporting functionality would benefit from enhanced customization capabilities, allowing users to tailor reports to their specific needs for better data visualization and analysis."
 

Pricing and Cost Advice

"Based on feedback from colleagues and friends working in the financial sector, Geneos is relatively costly. Many companies have been switching from Geneos to Dynatrace, Sysdig, or other monitoring tools in the past two years because of the price."
"Pricing and licensing is based on the requirements."
"The market tools are on par with this solution, but if the solution included more features, then it would be well within the range for the cost."
"The product is priced quite high. There are pricing options for customers based on the size of the environment and plug-ins used by the monitoring system."
"The organization is not just purchasing a license for the product, but also managing services and professional services from ITRS. Another factor is if the implementation is going to be in production, non-production, or both."
"ITRS Geneos is not a cheap tool. It's a moderate price for the banking industry. The reason we are not able to add the ITRS monitoring tool for the non-banking industries, and non-finance industries, is that the pricing is too high."
"The licensing cost may seem expensive upfront. However, the service is outstanding, the tool does things that no other tools can do, and the customizability more than makes up for the cost of licensing."
"The pricing seems reasonable. We're happy enough with it."
"Splunk Enterprise Security is an expensive solution."
"Most people share the same thought that the ingestion rates can get pretty pricey. There is a lot of work we do to curate the data that we send to Splunk so that it is not too noisy or too expensive."
"The pricing is based on the volume of data fed into it, which can lead to substantial costs. This pricing model is complex and unpredictable, making cost management difficult."
"It's more expensive than the other tools, but it's worth it. Every penny is worth it."
"Splunk Enterprise becomes extremely expensive after the 20GB/month license."
"It's a yearly subscription."
"The pricing depends on the bandwidth of an organization and is good compared to some SIEM tools. IBM, for example, is quite costly. But Microsoft Sentinel is notably cheaper."
"It can be cost-prohibitive when you start to scale and have terabytes of data. Its cost model is based on how much data it processes a day. If they're able to create scaled-down niche or custom package offerings, it may help with the cost. Instead of the full-blown features, if they can narrow the scope where it can only be used for a specific purpose, it would kind of create that market for the product, and it may help with the costing. When you start using it as a central aggregator and you're pumping tons of logs at it, pretty soon, you'll start hitting your cap on what it can process a day. Once you've got that, you're kind of defeating the purpose because you're going to have to scale back."
report
Use our free recommendation engine to learn which Application Performance Monitoring (APM) and Observability solutions are best for your needs.
881,082 professionals have used our research since 2012.
 

Comparison Review

VS
Manager, Enterprise Risk Consulting at a tech company with 1,001-5,000 employees
Feb 26, 2015
HP ArcSight vs. IBM QRadar vs. ​McAfee Nitro vs. Splunk vs. RSA Security vs. LogRhythm
We at Infosecnirvana.com have done several posts on SIEM. After the Dummies Guide on SIEM, we are following it up with a SIEM Product Comparison – 101 deck. So, here it is for your viewing pleasure. Let me know what you think by posting your comments below. The key products compared here are…
 

Top Industries

By visitors reading reviews
Financial Services Firm
70%
Computer Software Company
5%
Construction Company
3%
Outsourcing Company
2%
Financial Services Firm
13%
Computer Software Company
11%
Manufacturing Company
9%
Government
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business6
Midsize Enterprise12
Large Enterprise39
By reviewers
Company SizeCount
Small Business109
Midsize Enterprise50
Large Enterprise264
 

Questions from the Community

What is your experience regarding pricing and costs for ITRS Geneos?
The pricing is high. Licensing fees might be around 500$ per server monthly.
What needs improvement with ITRS Geneos?
ITRS Geneos is a legacy system. It predicts or provides proactive measures once an issue is resolved. It doesn't offer any predictive capabilities or root cause analysis. They throw a lot of data i...
What is your primary use case for ITRS Geneos?
ITRS offers multiple products, including upgrades for synthetic monitoring and a SaaS platform. Geneos is used for infrastructure monitoring, covering KPIs such as CPU, memory, processes, network l...
What SOC product do you recommend?
For tools I’d recommend: -SIEM- LogRhythm -SOAR- Palo Alto XSOAR Doing commercial w/o both (or at least an XDR) is asking to miss details that are critical, and ending up a statistic. Also, rememb...
What is a better choice, Splunk or Azure Sentinel?
It would really depend on (1) which logs you need to ingest and (2) what are your use cases Splunk is easy for ingestion of anything, but the charge per GB/Day Indexed and it gets expensive as log ...
How does Splunk compare with Azure Monitor?
Splunk handles a high amount of data very well. We use Splunk to capture information and as an aggregator for monitoring information from different sources. Splunk is very good at alerting us if we...
 

Also Known As

Geneos
No data available
 

Overview

 

Sample Customers

ITRS Geneos is used by over 170 financial institutions, including JPMorgan, HSBC, RBS, Deutsche Bank and Goldman Sachs. Clients range from investment banks to exchanges and brokers.
Splunk has more than 7,000 customers spread across over 90 countries. These customers include Telenor, UniCredit, ideeli, McKenney's, Tesco, and SurveyMonkey.
Find out what your peers are saying about ITRS Geneos vs. Splunk Enterprise Security and other solutions. Updated: May 2023.
881,082 professionals have used our research since 2012.