Softwr

Security & Cybersecurity · head to head

Splunk Enterprise Security vs Keygen

Splunk Enterprise Security logo

Splunk Enterprise Security

Security & Cybersecurity

The platform for operational intelligence

From
On request
Rated
-
K

Keygen

Security & Cybersecurity

Open, source-available software licensing API

From
On request
Rated
-

The short version

  • Each has a real cost: Splunk Enterprise Security splunk Enterprise Security is licensed separately from the Splunk platform, so a SIEM deployment needs both; Keygen cloud hosted plans start at $995 per month billed per domain, a floor aimed at established software vendors rather than solo developers

Where they differ

Only the attributes on which Splunk Enterprise Security and Keygen actually diverge.

Attributes where Splunk Enterprise Security and Keygen differ
AttributeSplunk Enterprise SecurityKeygen
PlatformsWeb, ApiWeb
Founded2003Unknown

Identical on both: starting price (On request), pricing model (subscription), free tier (No), user rating (Not yet rated), category (Security & Cybersecurity).

What each one covers

Drawn from each product's published feature list. An absence here means we hold no record of it - not that the product lacks it.

Only in Splunk Enterprise Security

  • Security monitoring
  • Incident review
  • Risk-based alerting
  • Threat intelligence
  • Investigation workbench
  • MITRE ATT&CK mapping
  • Automated response
  • Compliance reporting

Only in Keygen

Nothing recorded that Splunk Enterprise Security does not also cover.

What people use each for

The jobs each tool is most often brought in to do.

Splunk Enterprise Security

  • Running a security operations centre on Splunk indexed log datanot Keygen
  • Correlation searches, risk based alerting and incident investigationnot Keygen
  • Compliance reporting from pooled security telemetrynot Keygen

Keygen

No use cases recorded yet. See the Keygen review.

Where each one falls short

Documented limitations, not opinions. Every one is a constraint you would hit in normal use.

Splunk Enterprise Security

  • Splunk Enterprise Security is licensed separately from the Splunk platform, so a SIEM deployment needs both
  • Splunk publishes no rate for Enterprise Security and directs buyers to contact a pricing expert
  • UEBA, SOAR and automated threat analysis require the Premier edition rather than Essentials
  • The platform underneath can be billed by ingest volume, workload or activity, so the total cost depends on a pricing model chosen at contract time rather than a list price

Keygen

  • Cloud hosted plans start at $995 per month billed per domain, a floor aimed at established software vendors rather than solo developers

Pricing, plan by plan

Splunk Enterprise Security

On request
  • Workload PricingFree
    • Pay per compute
    • Flexible scaling
    • All features
  • Ingest PricingFree
    • Pay per GB ingested
    • Predictable costs
    • All features
  • Entity PricingFree
    • Pay per monitored entity
    • Security focused
    • All features

Keygen

On request

No published plan breakdown. See the Keygen review.

Which should you pick?

Choose Splunk Enterprise Security if

  • You need security monitoring.
  • You work on Web, Api.
  • You also want incident review.

Choose Keygen if

Nothing in the data separates Keygen from Splunk Enterprise Security on the points above - pick on price and on how each one feels to use.

Questions people ask

Is Splunk Enterprise Security or Keygen better?
Neither clearly leads. Splunk Enterprise Security starts at On request and Keygen at On request, and user ratings are close enough to be indistinguishable. Choose on capability and platform support.
Which is cheaper, Splunk Enterprise Security or Keygen?
Splunk Enterprise Security starts at On request and Keygen at On request.
Does Splunk Enterprise Security or Keygen run on more platforms?
Splunk Enterprise Security runs on Web, Api. Keygen runs on Web.
What is Splunk Enterprise Security best used for?
Splunk Enterprise Security is most often used for running a security operations centre on splunk indexed log data, correlation searches, risk based alerting and incident investigation, compliance reporting from pooled security telemetry. Of those, running a security operations centre on splunk indexed log data and correlation searches, risk based alerting and incident investigation are not what Keygen is typically brought in for.
What can Splunk Enterprise Security do that Keygen cannot?
Splunk Enterprise Security covers Security monitoring, Incident review, Risk-based alerting, Threat intelligence.

Related pages

Other head to heads