I've used Splunk, and it's a great event analyzer but it's a *very* heavy client; even the "light" installation. So it's not something I'd want to install on every average desktop in my enterprise. That's why I appreciated ossec because the client and protocol are very small, so the system scales well.
However, we lose some robustness because of that. I've struggled with how to handle lost events when the agent or server are down. Ossec doesn't "catch up" when the connection is restored (at least not with Windows) and that's unfortunate because its a great platform.
