Try our new research platform with insights from 80,000+ expert users

Cisco Secure IPS (NGIPS) vs Splunk User Behavior Analytics comparison

 

Comparison Buyer's Guide

Executive SummaryUpdated on Dec 19, 2024

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

ROI

Sentiment score
6.7
Cisco Secure IPS effectively detects threats and integrates with NIST, yielding positive ROI despite setup costs and financial quantification challenges.
Sentiment score
5.5
Users report varied ROI from Splunk, with productivity gains and security cost savings, but costs remain a concern.
The solution can save costs by improving incident resolution times and reducing security incident costs.
 

Customer Service

Sentiment score
7.2
Cisco Secure IPS customer service is praised for expertise but noted for inconsistent response times and initial contact challenges.
Sentiment score
6.9
Splunk User Behavior Analytics support is mostly praised, with professional service, tiered options, and valuable user groups enhancing experience.
Fortinet, on the other hand, offers quicker response times and same-day RMAs, which gives them an edge in customer service.
The response was fast, and they provided experts to solve our issues quickly.
A few years ago, I had a very bad situation. We lost a lot of money, and I opened for the first time in my life, a case with priority one. The person responsible for the ticket didn't respond for two days.
Mission-critical offering a dedicated team, proactive monitoring, and fast resolution.
From the responsiveness perspective, Splunk is very responsive with SLA-bound support for premium tiers.
I would rate their technical support as 8.5 out of 10.
 

Scalability Issues

Sentiment score
7.0
Cisco Secure IPS scalability varies; effective for large environments but may need upgrades for extensive user capacity.
Sentiment score
7.2
Splunk User Behavior Analytics is scalable and adaptable across environments, though storage limitations may affect scalability.
Splunk User Behavior Analytics is highly scalable, designed for enterprise scalability, allowing expansion of data ingestion, indexing, and search capabilities as log volumes grow.
 

Stability Issues

Sentiment score
7.5
Cisco Secure IPS is stable but has bugs; continuous improvements are needed to compete with Fortinet and Palo Alto.
Sentiment score
7.8
Splunk User Behavior Analytics offers reliable performance and stability, with 99.9% uptime and ease of configuration in enterprises.
The software situation with Cisco is problematic.
With built-in redundancy across zones and regions, 99.9% uptime is achievable.
Splunk User Behavior Analytics is a one hundred percent stable solution.
Splunk User Behavior Analytics is highly stable and reliable, even in large-scale enterprise environments with high log injection rates.
 

Room For Improvement

Cisco Secure IPS needs better SIEM integration, user interface, stability, reporting, scalability, pricing, support, and cloud and endpoint integration.
Splunk User Behavior Analytics needs better pricing, integration, user-friendly interfaces, enhanced features, and improved scalability and infrastructure.
Incorporating AI capabilities would enhance its functionality.
CLI is very important in professional working, and it was an unwise decision by Cisco to remove it.
Global reach allows deployment of apps and services closer to users worldwide, but data sovereignty concerns exist and region selection must align with compliance requirements.
I encountered several issues while trying to create solutions for this advanced version, which seem unrelated to query or data issues.
High data ingestion costs can be an issue, especially for large enterprises, as Splunk charges based on the amount of data processed.
 

Setup Cost

Cisco Secure IPS is costly, especially versus competitors, with pricing influenced by features, support, and potential bundling discounts.
Enterprise buyers find Splunk's User Behavior Analytics costly, with variable pricing based on data, hardware, and additional applications.
It's cheaper to integrate with existing IT security solutions compared to other expensive brands with subscription costs.
Reserved instances with one or three-year commitments offer lower rates, providing up to 70% savings.
Compared to all other products in the market, it is the most expensive one in all aspects including professional service and licenses, even the cloud version.
Comparing with the competitors, it's a bit expensive.
 

Valuable Features

Cisco Secure IPS provides robust protection with strong integration, intelligence, and ease of use for comprehensive cybersecurity measures.
Splunk User Behavior Analytics provides scalable, user-friendly threat detection with advanced analytics, machine learning, and seamless data integration and reporting.
Cisco Secure IPS (NGIPS) is quite powerful for threat detection and includes botnet detection.
They can discover new versions of malware, which is very beneficial.
I also utilize it for anomaly detection and behavior analysis, particularly using Splunk's machine learning environment.
The dashboards themselves are nice, very good, and very helpful, but the accuracy of the data or the information that will be presented on the dashboard is something that needs to be questioned.
Features like alerts and auto report generation are valuable.
 

Categories and Ranking

Cisco Secure IPS (NGIPS)
Ranking in Intrusion Detection and Prevention Software (IDPS)
12th
Average Rating
8.0
Reviews Sentiment
6.7
Number of Reviews
69
Ranking in other categories
No ranking in other categories
Splunk User Behavior Analytics
Ranking in Intrusion Detection and Prevention Software (IDPS)
15th
Average Rating
8.2
Reviews Sentiment
6.6
Number of Reviews
25
Ranking in other categories
User Entity Behavior Analytics (UEBA) (4th)
 

Mindshare comparison

As of October 2025, in the Intrusion Detection and Prevention Software (IDPS) category, the mindshare of Cisco Secure IPS (NGIPS) is 3.4%, up from 3.0% compared to the previous year. The mindshare of Splunk User Behavior Analytics is 1.9%, up from 1.7% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Intrusion Detection and Prevention Software (IDPS) Market Share Distribution
ProductMarket Share (%)
Cisco Secure IPS (NGIPS)3.4%
Splunk User Behavior Analytics1.9%
Other94.7%
Intrusion Detection and Prevention Software (IDPS)
 

Featured Reviews

Yosevan Sinaga Sinaga - PeerSpot reviewer
Effectively identifies malicious behavior while future automation and AI advancements hold potential
Cisco Secure IPS (NGIPS) is quite powerful for threat detection and includes botnet detection. It effectively blocks unwanted software, hashes, and suspicious behaviors. The tool is easy to integrate with other IT security solutions due to similar protocols. The system offers effective threat detection features, although automation capabilities are not yet fully utilized.
Subhayu Chakraborty - PeerSpot reviewer
Automatic reports streamline tasks and offers easy report gathering
The dashboard part could be improved. While using it, I noticed two options: Classic, which is adequate yet only in black and white, and another one that is more advanced or smart, though I forgot the exact term. I encountered several issues while trying to create solutions for this advanced version, which seem unrelated to query or data issues.
report
Use our free recommendation engine to learn which Intrusion Detection and Prevention Software (IDPS) solutions are best for your needs.
869,566 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Computer Software Company
12%
University
9%
Educational Organization
9%
Comms Service Provider
8%
Computer Software Company
18%
Financial Services Firm
9%
Government
8%
Manufacturing Company
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business26
Midsize Enterprise17
Large Enterprise26
By reviewers
Company SizeCount
Small Business7
Midsize Enterprise5
Large Enterprise12
 

Questions from the Community

What do you like most about Cisco NGIPS?
The product's initial setup phase was easy.
What is your experience regarding pricing and costs for Cisco NGIPS?
Cisco is one of the top brands known for cost-effectiveness, making it worth the money. It's cheaper to integrate with existing IT security solutions compared to other expensive brands with subscri...
What needs improvement with Cisco NGIPS?
There are numerous things that could be improved about Cisco Secure IPS (NGIPS) to get it back on track. Sollution for small branches: when we have to connect a lot very small branches (or sometime...
What do you like most about Splunk User Behavior Analytics?
The solution's most valuable feature is Splunk queries, which allow us to query the logs and analyze the attack vectors.
What is your experience regarding pricing and costs for Splunk User Behavior Analytics?
In terms of setup cost, pricing, and licensing, Splunk User Behavior Analytics is not an inexpensive product. The setup requires numerous components including storage, networking, identity access, ...
What needs improvement with Splunk User Behavior Analytics?
There are improvements that could be made to Splunk User Behavior Analytics as any product will have advantages and disadvantages. Scalability is one consideration. For example, the advantages incl...
 

Also Known As

Sourcefire NGIPS, Firepower NGIPS
Caspida, Splunk UBA
 

Overview

 

Sample Customers

American Electric Power, Huntington Bank, Keycorp, Nationwide, Transunion, Marriott, Inova Health, Ford, Thomson Reuters, Dow Chemical, Equifax, Chevron, Walmart, Coca Cola
8 Securities, AAA Western, AdvancedMD, Amaya, Cerner Corporation, CJ O Shopping, CloudShare, Crossroads Foundation, 7-Eleven Indonesia
Find out what your peers are saying about Cisco Secure IPS (NGIPS) vs. Splunk User Behavior Analytics and other solutions. Updated: September 2025.
869,566 professionals have used our research since 2012.