| Category | Function | Share | Rank | Negative rate | Labels | Quadrant |
|---|---|---|---|---|---|---|
| Log management | IT operations and endpoint | 0% | 59 of 59 | 53% | 51 | criticized challenger |
| SIEM platforms | Security operations | 0% | 49 of 49 | 59% | 22 | criticized challenger |
| Observability platforms | IT operations and endpoint | 0% | 63 of 63 | 47% | 19 | criticized challenger |
| Infrastructure monitoring | IT operations and endpoint | 0% | 28 of 65 | 17% | 6 | under 10 labels · led by Site24x7 at 24% |
| Application performance monitoring | IT operations and endpoint | 0% | 56 of 70 | 25% | 4 | under 10 labels · led by New Relic at 54% |
| Container and Kubernetes security | Cloud and infrastructure | 0% | 70 of 78 | 100% | 1 | under 10 labels · led by Aqua Security at 18% |
| Error and crash monitoring | Developer platform | 0% | 38 of 44 | 100% | 1 | under 10 labels · led by Sentry at 82% |
| Threat intelligence platforms | Security operations | 0% | 118 of 128 | 100% | 1 | under 10 labels · led by NordStellar at 13% |
| Model | First choice | Alternative | Mention | Negative | Labels |
|---|---|---|---|---|---|
| Claude Haiku 4.5 | 0 | 0 | 4 | 7 | 11 |
| GPT-5.4 mini | 0 | 1 | 5 | 4 | 10 |
| Gemini 3.5 Flash | 0 | 2 | 1 | 5 | 8 |
| Perplexity Sonar | 0 | 0 | 1 | 1 | 2 |
| Grok 4.1 Fast | 0 | 1 | 3 | 6 | 10 |
| Mistral Small | 0 | 1 | 6 | 1 | 8 |
| DeepSeek V4 Flash | 0 | 2 | 2 | 6 | 10 |
| Llama 4 Maverick | 0 | 0 | 3 | 1 | 4 |
| Qwen 3.7 Flash | 0 | 1 | 3 | 9 | 13 |
| Kimi K2 | 0 | 0 | 6 | 6 | 12 |
| GLM 4.7 FlashX | 1 | 1 | 2 | 6 | 10 |
| MiniMax M2.5 | 0 | 3 | 2 | 2 | 7 |
Verbatim evidence the judge attached to positive labels.
“If you have a large Security team: Choose Splunk. The search capabilities and security integrations are unmatched.” GLM 4.7 FlashX · Logs · comparative prompt · first choice
“Large enterprise, strict security & compliance, heavy SIEM use | Splunk Enterprise / Splunk Cloud | Best-in-class search language” MiniMax M2.5 · Logs · comparative prompt · alternative
“Splunk is ideal only when you need its deep SIEM and query capabilities and can absorb its higher per‑GB pricing.” GLM 4.7 FlashX · Logs · direct prompt · alternative
“Choose Splunk if you are a large corporate entity where IT operations... must live inside the same data ecosystem.” Gemini 3.5 Flash · Observability · comparative prompt · alternative
Verbatim evidence attached to negative labels. A warning on a product with few labels is a warning; on a product with many, it is one voice among them.
“Why avoid: Even a modest log volume quickly pushes the budget well beyond what most SMEs can afford.” GLM 4.7 FlashX · SIEM · budget prompt · hard negative
“Avoid Splunk for mid-market—it's enterprise-priced (~$150/GB/day list, $10K+/mo easily) and overkill” Grok 4.1 Fast · Logs · direct prompt · hard negative
“Extremely expensive - Historically known for some of the highest costs in the industry” Kimi K2 · Observability · negative prompt · hard negative
“Avoid for lean teams: Splunk (unless you have dedicated admins and budget headroom).” DeepSeek V4 Flash · SIEM · negative prompt · hard negative
Citations exist only for the models that return a source list, four of the twelve in this edition, so these counts come from 218 of the 322 answers that named Splunk and are not a share of its labels.
593 of the 593 domain citations in answers naming Splunk came from somebody else's page.
Pages are listed as the models cited them.
Claiming is free and changes nothing in the data. A claimed page shows a verified contact who is told when each edition publishes and when Splunk's standing changes by more than the noise floor; the right to propose corrections to the vendor table, meaning names the judge wrote that should or should not read as Splunk, applied by version and listed in the change log; and a one-line description supplied by the vendor and marked as such.
It does not get any change to labels, shares or verdicts, any preview, or any say over which quotes appear. A verification link goes to your work email; an address at splunk.com is approved on the spot, any other address is reviewed by hand.
Your name and company appear on the claimed page, or the company alone if you ask below. A title and a LinkedIn address appear there too if you give them, and are left off if you do not. Your email address is never published.