Home > ManageEngine Log360 vs Splunk Enterprise

Looking for an alternative to
Splunk Enterprise

100000+ Technicians trust Log360 to manage their Windows environment

Try Log360

Thank you for downloading!

Your download should begin automatically in 15 seconds. If not, click here to download manually.

    Download fully functional
    30-days FREE trial!

  • By clicking 'Start a free trial', you agree to processing of personal data according to the Privacy Policy.

Thanks!

One of our solution experts will get in touch with you shortly

ManageEngine Log360 vs Splunk Enterprise

  • ManageEngine Log360 is a comprehensive SIEM solution that helps enterprises of all sizes combat threats and mitigate attacks with its threat intelligence, event correlation, file integrity monitoring, network device auditing and user activity monitoring capabilities. On-premises, cloud, or both - Log360 has it covered. It is simple to deploy, has a centralized console to manage multiple environments, and licensed based on the pay only for what you use model.
  • Splunk is a SIEM solution that identifies, prioritizes and manages security events with event sequencing, alert management, risk scores, and customizable dashboards and visualizations.
  • This document aims to compare the capabilities of Splunk with that of the capabilities of ManageEngine Log360.

Feature-wise comparison of ManageEngine Log360 and Splunk:

ManageEngine Log360

Features ManageEngine Log360
Try now
Splunk
Log collection
Agentless    
Agent-based    
Cross platform log collection    
Heterogeneous device support    
Import logs    
Periodical import of logs    
Log filter    
Custom log parsing and indexing    
Log collection rate 20,000 logs/second with peak event handling capacity upto 25,000 logs/second. For Windows event logs the EPS is 2000 logs/second. 1,54,000 EPS
Log formats supported
Windows event log    
Syslog    
Any format – with custom log parsing and indexing technology    
Amazon Web Services (AWS) EC2 Instance    
Application logs supported
Proprietary applications
  • Microsoft IIS Web Server
  • FTP Server (W3C logs)
  • Apache Web Server
  • DHCP Windows
  • DHCP Linux
   
Database applications:
Oracle and MS SQL Server
   
Any application – with custom log parsing and indexing    
Other devices supported
IBM iSeries (AS/400), And VMware    
Custom devices
  • Firewalls
  • Intrusion Detection System/ Intrusion Prevention System (IDS/IPS)
  • Anti-virus application
  • Mail and web application
  • Vulnerability Scanners
  • Unified threat management solutions
    • Symantec DLP Application
    • FireEye
    • Symantec Endpoint Solution
   
Alerts
Canned    
Correlation    
Compliance    
In-built incident management module    
Custom alerting    
Threat intelligence
Real-time alerts for global blacklisted IPs intruding the network    
Reports
File integrity monitoring    
Canned reports    
Custom reports    
Scheduled reports    
Report distribution via email    
Reports in PDF, CSV, and HTML formats    
Drill down to raw logs    
Filter using mouse gesture    
Management specific reports(Ask ME)    
Trend reports    
Privileged user activity monitoring reports    
Active Directory auditing
Reports for user, computer, group, and OU management    
Reports for auditing other AD object including
  • DNS
  • Permission
  • Schema
  • Contacts
  • Container configuration
  • Domain changes
   
Reports on attribute value changes (before and after)    
GPO audit reports    
Member server auditing
Summary report for member server changes    
Out-of-the-box reports for
  • Policy changes
  • System events
  • Object management
  • Scheduled tasks
   
File Integrity Monitoring
Reports on file integrity monitoring    
Report scheduling    
Real-time alerts when critical changes are made to files/folders that are being monitored    
Audit Trail reports on files/folders changes    
Compliance reports
Canned reports    
Customizing existing reports    
Reports for new compliance   Not specified
PCI-DSS    
ISO 27001:2013    
HIPAA    
FISMA    
SOX    
GLBA    
Real-time event correlation
Event correlation    
Field-level filters to build correlation rules    
Pre-defined rules to detect various attacks, including ransomware, brute-force and more    
User session monitoring    
Log search
Advanced search using Boolean, wildcards, grouped search, range search, and phrase search    
Formatted logs    
Raw logs    
Save search results as reports and alerts    
Log archival
Flexible log retention    
Secured (Encrypted    
Tamper-proof    
Service Provider feature
User based views    
User based dashboards    
Rebranding   Not specified
User Management
Realm & user based access    
Active Directory based user authentication    
RADIUS server based user authentication    
Other Key Features
Incident workflows    
UEBA    
Risk Assessment    
Advanced threat analytics    
Implementation
Easy to install    
Web based Client    
Appliance    
System Requirements
Bundled database (PostgreSQL/MySQL)    
Windows & Linux platforms support    
64 Bit support    
Pricing
Pricing basis Based on the number of servers, devices & applications Based on volume of log data collected.
Subscription model Available Available
Perpetual model Available Available

Can the solution be considered value for money?

Component-based pricing model.
Starts at $595* per year

Conclusion

  • From the comparison, it can be concluded that both ManageEngine's Log360 and Splunk helps to understand what's happening in your network and to gain insights into potential threats and stop them before they turn into an attack by monitoring your logs.
  • Both the solutions support a wide range of devices and applications and provide an extensive number of reports.
customer-testimonial-logo

What customers say about us

  • CAMH will be able to save close to $26,000 a year on service desk calls related to Active Directory password resets and locked accounts, and will see a return on investment within the first six months of product implementation.

    Judy OlivierProject Manager, CAMH

About ManageEngine Log360

Log360 is a simple yet powerful security information and event management (SIEM) solution that can help enterprises overcome network security challenges and strengthen their cybersecurity posture. The solution helps you mitigate security threats, spot ongoing attack attempts, detect suspicious user activities, and comply with regulatory mandates.

For more information about Log360, please visit

www.manageengine.com/log-management/
Download
Demo

Thank you for downloading!

Your download should begin automatically in 15 seconds. If not, click here to download manually.

Download fully functional30-days FREE trial!

  •  
    By clicking 'Claim Your Free Trial', you agree to processing of personal data according to the Privacy Policy.

Thank you

Thank you for your interest in ManageEngine Log360. We have received your request for a personalized demo and will contact you shortly.

Schedule apersonalized web demo

  • By clicking 'Submit', you agree to processing of personal data according to the Privacy Policy.

Disclaimer: ManageEngine does not guarantee the accuracy of any information presented in this document, and there is no commitment, expressed or implied, on ManageEngine’s part to update or otherwise amend this document. The furnishing of this document does not provide any license to patents, trademarks, copyrights or other intellectual property rights owned or held by ManageEngine.