Splunk is miles ahead when it comes to search and visualizations. You can just do things and join that the other tools don't support at all.
The only downside is speed, Splunk can only find a few hundreds thousands results a second so it's slow as hell when there are lots of matches. (Kibana doesn't give more than the first 500 results so it's totally cheating on that aspect).
ElasticSearch and everything built on top of it has catastrophic issues with typing. Every field is typed, say integer or string, and sending/having data in the wrong type will prevent to do operations (smaller than, greater than, sum, additional) and can crash the database. It's wild whereas Splunk can ingest and aggregate mixed data just fine.
However there is no alternative to these when it comes to search and accessibility. SSH somewhere and awk is not a real option.
Cheaper alternatives? You can roll your own logging server with fluentd and a database. Some folks will recommend elasticsearch, but we tried it and it was challenging to set up just right.
Running and managing an ELK stack is just a hassle and a managing nightmare conpared to Splunk. Humio is a great alternative, if you need something cheaper, but you have to give up a lot of features.
By far elasticsearch is the easiest distributed database to setup and scale.
Yes, it's not big. But that's all we need.
It has lots of query processing operations, sure. But it can't do (at least not easily) some things you could do with bash/grep in "traditional" settings (example, get the context between lines that match a pattern)
Splunk has a more powerful feature though “| transaction“ - often in multithreaded logs i want the context but ignoring entries not from my thread. This feature does that