Battlecard Splunk
Battlecard Splunk
Battlecard Splunk
Portfolio of high-quality reports: Splunk has a relatively smaller set of reports. Instead, Splunk encourages
RSA NetWitness Platform includes a broad array of pre-built reports, customers to create their own reports or use reports that have been shared
including compliance reports. by other users in its customer community, which may have varying levels of
quality and consistency.
RSA Confidential For RSA partners only and subject to non-disclosure agreement Last updated: November 26, 2018
Background on Splunk RSA NetWitness Splunk
Capability comparison
Platform ES
Security is just a portion of Splunk’s business. Its portfolio
consists of: Native data integration Yes Not applicable
Core platform: Third-party data integration Yes Yes
• Splunk Enterprise
Event correlation, classification, enrichment Yes Yes
Enterprise is a perquisite purchase for the other Splunk
products. Machine-learning based event analytics Yes Yes
Security products: Threat indicators weighted Yes Yes
• Splunk for Enterprise Security (ES) Age of collected data affects overall threat
No Yes
• Splunk User Behavior Analytics (UBA) risk score
• Splunk Insights for Ransomware Threat model is adjusted continuously Yes Yes
• Splunk Phantom
Other products: Ad hoc searches Yes Yes
• Splunk Insights for Infrastructure Native threat mitigation Yes No
• VictorOps (devOps management) On-premise deployment Yes Yes
• Splunk for IT Service Intelligence
• Splunk Insights for AWS Cloud Monitoring SaaS model No Yes