No more typing reviews! Try our Samantha, our new voice AI agent.

Splunk Security Essentials vs VMware Carbon Black Endpoint comparison

Why PeerSpot?
 

Comparison Buyer's Guide

Executive SummaryUpdated on Jan 2, 2025

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Splunk Security Essentials
Ranking in Security Incident Response
9th
Average Rating
8.6
Reviews Sentiment
4.8
Number of Reviews
6
Ranking in other categories
Data Visualization (12th), IT Alerting and Incident Management (13th)
VMware Carbon Black Endpoint
Ranking in Security Incident Response
3rd
Average Rating
7.8
Reviews Sentiment
6.6
Number of Reviews
65
Ranking in other categories
Endpoint Protection Platform (EPP) (28th), Endpoint Detection and Response (EDR) (27th), Ransomware Protection (8th)
 

Mindshare comparison

As of September 2026, in the Security Incident Response category, the mindshare of Splunk Security Essentials is 2.7%, up from 2.0% compared to the previous year. The mindshare of VMware Carbon Black Endpoint is 7.3%, down from 7.7% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Security Incident Response Mindshare Distribution
ProductMindshare (%)
VMware Carbon Black Endpoint7.3%
Splunk Security Essentials2.7%
Other90.0%
Security Incident Response
 

Featured Reviews

reviewer2836941 - PeerSpot reviewer
Assistant Manager at a tech services company with 1-10 employees
Centralized monitoring has given our SOC real-time visibility into security and application activity
When I first implemented Splunk Security Essentials in this environment, it took a week for each log source to onboard and to create use cases and implement the data model, CIM, etc., for production readiness. Training is mandatory, and we need at least the Splunk Security Essentials User certification because it is a very critical resource in the organization, as we are handling security logs. In my organization, Splunk Security Essentials is used not only by the SOC but also for monitoring logs across different teams, as it is important for handling both security and application logs, given its capability to manage unstructured logs. Splunk Security Essentials has dramatically impacted my organization, as without it, we were blind to what is happening from both a security and application perspective, and it provides vital visibility into the organization's operations.
PM
CTO at Microsoft
Improved incident investigation has supported response while core protection still needs progress
VMware Carbon Black Endpoint does not have easy integration, as there are many complexities with the Ribitava API, which is very deep. I rate this solution overall as a five or six on a scale from one to ten. I have integrated VMware Carbon Black Endpoint with other tools that are helpful. I think this solution should be targeted at small clients, because adoption will grow more with small businesses tomorrow.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"They have a good catalog of plans to use to resist the attacks."
"The network monitoring feature is particularly valuable for gathering information about users, login times, and other statistics."
"We are focusing on security to ensure incidents are reported efficiently. In addition to that, for reporting purposes, we are utilizing our dashboards or creating new ones. We will be using free visualization tools for this purpose."
"I would have to rate Splunk Security Essentials a 10 out of 10 because it's free and there's tons of usable content."
"Splunk Security Essentials has impacted my organization in that we have been getting the results that we wanted."
"Splunk Security Essentials has dramatically impacted my organization, as without it, we were blind to what is happening from both a security and application perspective, and it provides vital visibility into the organization's operations."
"The most valuable feature of the solution stems from the fact that it is one of the best EDR tools in the market."
"It is a stable solution...The initial setup of VMware Carbon Black Endpoint was easy."
"The whole purpose of the product, like application control, is very good, and also if you need to update some policies, it works well and instantly."
"The product is very smooth and pretty simple."
"The portal is easy to use and manage."
"In our POC, we had 200 samples including ones that were available but not as popular and we received a 100% efficacy."
"The most valuable feature of the solution stems from the support it provides."
"Carbon Black CB Defense has helped improve my organization by allowing us to have better data so that we can do correlation and get visibility into the alerts."
 

Cons

"They could add more AI content or AI and machine learning."
"If I could change one thing about Splunk Security Essentials, it would be pricing. I believe they are still very costly as compared to the competition."
"The price could be improved."
"It takes a lot of time to install Splunk Security Essentials. It's not very difficult, but it requires time."
"The reporting feature needs to be more user-friendly."
"The biggest friction points I have with Splunk Security Essentials are the high license costs and user behavior that causes performance issues due to inappropriate wildcard searches."
"With the on-prem one, the bug has been reported by the community in early January or February, something like that, at the beginning of the year, and it's still not addressed. They have released two versions since then, and yet neither of them addresses this specific issue."
"Sensor deployment requires extensive fine-tuning, and creating deployment packages is time-consuming."
"Sometimes the solution blocks items that were previously approved and we don't know why."
"Right now, I get a lot of what I call noise email alerts. All I hear from them is, "Well, we're working on it. We're working on it." Well, they've been working on it for four years now, and nothing has changed."
"The Mac support needs improvement, as it had next to none."
"The endpoint machines need improvement."
"I haven't run into anything that needs improvement. The website interface can be a little bit better, but it's still good as compared to most others."
"The solution would be more effective if there was a way to block automatically based on behavior."
 

Pricing and Cost Advice

Information not available
"It is more expensive, but it's worth it. There are no additional costs beyond the standard licensing fee."
"We have branches, we have different companies, but we cannot buy less than 100 licenses. This does not make sense to me... It should be more flexible. I can understand their saying, "Okay, to be a customer you need 100," but to add on to that number it should be something very straightforward. If I need to add five, for example, I shouldn't need to add 100."
"Its pricing was very good, which is one of the reasons I went to it as an alternative. It is on a yearly basis. There are no additional fees."
"The pricing [is] more or less the same as other similar solutions."
"The pricing is annually based and operates through another department than mine."
"The product is quite reasonable."
"The product’s price is less expensive than other vendors."
"The solution has almost the same price as other different kinds of infrastructures, but it offers a lot of different features."
report
Use our free recommendation engine to learn which Security Incident Response solutions are best for your needs.
913,683 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Construction Company
18%
Financial Services Firm
11%
Comms Service Provider
9%
Healthcare Company
8%
Outsourcing Company
10%
Financial Services Firm
9%
Construction Company
9%
Comms Service Provider
8%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
No data available
By reviewers
Company SizeCount
Small Business31
Midsize Enterprise9
Large Enterprise33
 

Questions from the Community

What is your experience regarding pricing and costs for Splunk Security Essentials?
Our SecOps manager and CISO were more familiar with Splunk, and the price was right. That was probably the primary driver, and we did evaluation as well with strict criteria and Gartner ratings.
What needs improvement with Splunk Security Essentials?
The biggest friction points I have with Splunk Security Essentials are the high license costs and user behavior that causes performance issues due to inappropriate wildcard searches. Additionally, ...
What is your primary use case for Splunk Security Essentials?
My main use case for Splunk Security Essentials is for Enterprise Security, specifically the ES app. Splunk Security Essentials is my primary tool for threat detection and monitoring because as a S...
What to choose: an endpoint antivirus, an EDR solution or both?
I can recommend Carbon Black, an award-winning next-gen anti-virus (NGAV) and endpoint detection and response (EDR) security solution. The CB Predictive Security Cloud platform combines multiple hi...
What's the difference between Carbon Black CB Response and Carbon Black CB Defense?
Carbon Black offers two different levels of Endpoint Detection and Response. One is the VM Carbon Black Cloud Endpoint Standard (CB Defense), and the other is the Carbon Black Endpoint Detection an...
What is your experience regarding pricing and costs for Carbon Black CB Defense?
My rating for the pricing of VMware Carbon Black Endpoint is that it is not cheap, but it is also not as inexpensive as I would prefer.
 

Also Known As

No data available
Carbon Black CB Defense, Bit9, Confer
 

Overview

 

Sample Customers

Information Not Available
Netflix, Progress Residential, Indeed, Hologic, Gentle Giant, Samsung Research America
Find out what your peers are saying about Splunk Security Essentials vs. VMware Carbon Black Endpoint and other solutions. Updated: September 2026.
913,683 professionals have used our research since 2012.