Try our new research platform with insights from 80,000+ expert users

Cisco Secure Network Analytics vs Darktrace vs Splunk User Behavior Analytics comparison

 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

ROI

Sentiment score
8.0
Cisco Secure Network Analytics boosts incident detection and recovery, offering cost savings and labor efficiency for enhanced security.
Sentiment score
7.3
Darktrace enhances security and threat prevention, offering cost-effective solutions with improved visibility and indirect savings despite quantification challenges.
Sentiment score
6.4
Splunk User Behavior Analytics boosts productivity and savings, though ROI varies with implementation; users report improved incident resolution.
Using this solution provides financial benefits by securing from server attacks, which offers indirect savings.
The solution can save costs by improving incident resolution times and reducing security incident costs.
 

Customer Service

Sentiment score
7.3
Cisco Secure Network Analytics support is praised for technical expertise and responsiveness, despite occasional local support challenges and delays.
Sentiment score
7.7
Darktrace is praised for excellent, responsive tech support, offering prompt issue resolution and proactive assistance with global presence.
Sentiment score
6.8
Splunk User Behavior Analytics offers reliable customer support, although geographic limitations may require some users to utilize online forums.
There is a lack of adequate local support from the Indian side.
The technical support from Darktrace is of high quality.
Darktrace provides excellent technical support with a monthly meeting to review platform incidents, ensuring the system functions as expected.
The challenge lies in waiting for a response after logging a ticket.
Mission-critical offering a dedicated team, proactive monitoring, and fast resolution.
I would rate the support at eight, meaning there's some room for improvement.
Splunk's technical support is amazing.
 

Scalability Issues

Sentiment score
6.5
Cisco Secure Network Analytics excels in scalability and adaptability, though it can be costly and challenging in data management.
Sentiment score
7.6
Darktrace is highly scalable, supporting various company sizes and seamless integration, efficiently managing large traffic and endpoints.
Sentiment score
7.5
Splunk User Behavior Analytics offers scalable and versatile solutions for enterprises, adaptable to both on-premise and cloud environments.
Darktrace has high scalability, and I would rate it a nine out of ten.
Since it's cloud-based, it expands easily.
Splunk User Behavior Analytics is highly scalable, designed for enterprise scalability, allowing expansion of data ingestion, indexing, and search capabilities as log volumes grow.
 

Stability Issues

Sentiment score
8.4
Cisco Secure Network Analytics is stable, reliable under complex conditions, but users seek less Java and better product integration.
Sentiment score
8.5
Darktrace is highly rated for its stability, reliability, and smooth performance, meeting security needs without network issues.
Sentiment score
8.2
Splunk User Behavior Analytics is praised for stability, ease of use, and reliable performance, despite minor long-term data issues.
Cisco products are incredibly stable, boasting a 200% stability.
The stability of Darktrace is excellent, rated ten out of ten.
The appliance itself has never let me down.
Splunk User Behavior Analytics is a one hundred percent stable solution.
Splunk User Behavior Analytics is highly stable and reliable, even in large-scale enterprise environments with high log injection rates.
Sometimes issues occur when handling long-term data.
 

Room For Improvement

Cisco Secure Network Analytics needs enhanced usability, integration, filtering, AI, reporting, training, cost-efficiency, and endpoint management for better security.
Darktrace needs better integration, automation, and interface improvements, plus enhanced pricing, endpoint protection, and user-friendliness for broader appeal.
Splunk User Behavior Analytics needs improved integration, automation, affordability, a better interface, and enhanced features for optimal user satisfaction.
The solution should have the ability to analyze security events not only at the network layer but also at the application and OS layers.
There is no dedicated salesperson in Egypt, and having one would help to improve focus on this market.
Darktrace could improve by integrating with email security gateways like Mimecast or Ironscales.
The intelligence section and the incident view should be seamlessly connected in one view to avoid jumping between pages.
I encountered several issues while trying to create solutions for this advanced version, which seem unrelated to query or data issues.
High data ingestion costs can be an issue, especially for large enterprises, as Splunk charges based on the amount of data processed.
Advanced reporting could see enhancements as there are some issues with latency.
 

Setup Cost

Cisco Secure Network Analytics pricing is high, influenced by network flow requirements, with mixed user experiences on cost and licensing.
Darktrace is often seen as costly, yet some justify it for its advanced features and customizable licensing.
Splunk User Behavior Analytics pricing is complex, influenced by data usage, licensing, and features, causing budgeting challenges.
Cisco solutions are considered to be very expensive.
The product is considered expensive compared to others.
The pricing is costly in USD, and they charge based on device counts.
The licensing cost is approximately eight dollars a year.
Comparing with the competitors, it's a bit expensive.
The pricing is based on the amount of data processed, and it is considered a high-level investment for enterprises.
 

Valuable Features

Cisco Secure Network Analytics enhances security with visibility, real-time anomaly detection, automation, and intuitive management for improved threat response.
Darktrace excels in AI-driven threat detection, autonomous response, and user-friendly interface, making it a top cybersecurity solution.
Splunk User Behavior Analytics provides efficient data analysis, threat detection, and seamless integration, enhancing security with advanced analytics and automation.
The most valuable features include encrypted traffic analytics and the ability to fulfill requirements at the network level.
It is capable of responding to lateral movement and ransomware deployment within environments where there is data exfiltration.
I do not need to manually process incidents as Darktrace provides an incident summary, potential detection paths, and other details, all exportable with just a click.
The most valuable features are the AI and advanced learning tools that distinguish it from other products.
I also utilize it for anomaly detection and behavior analysis, particularly using Splunk's machine learning environment.
Features like alerts and auto report generation are valuable.
Splunk User Behavior Analytics offers several beneficial features, such as Insider Threat Detection, account compromise detection, risk scoring, threat detection, and machine anomaly detection.
 

Mindshare comparison

Network Monitoring Software
Extended Detection and Response (XDR)
User Entity Behavior Analytics (UEBA)
 

Featured Reviews

Sudhakar T - PeerSpot reviewer
Strong network security analytics with excellent encrypted traffic analysis features
Improvements are needed on the application layer for complete security analysis. The solution should have the ability to analyze security events not only at the network layer but also at the application and OS layers. There's a need for a more comprehensive licensing model where all necessary licenses are included by default.
Peter-Murphy - PeerSpot reviewer
Enables proactive threat detection and immediate response through AI monitoring
The most valuable feature of Darktrace is its ability to detect and counter threats before they occur. The autonomous response capability is always enabled, blocking threats immediately without hesitation. Additionally, the Darktrace email platform is a significant asset since it addresses incoming threats before they reach the network, enhancing our security measures. Protecting the business is essential, and ensuring security through 24/7 AI monitoring is invaluable.
Subhayu Chakraborty - PeerSpot reviewer
Automatic reports streamline tasks and offers easy report gathering
The dashboard part could be improved. While using it, I noticed two options: Classic, which is adequate yet only in black and white, and another one that is more advanced or smart, though I forgot the exact term. I encountered several issues while trying to create solutions for this advanced version, which seem unrelated to query or data issues.
report
Use our free recommendation engine to learn which Network Monitoring Software solutions are best for your needs.
850,834 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Computer Software Company
28%
Financial Services Firm
11%
Government
9%
Manufacturing Company
7%
Computer Software Company
14%
Manufacturing Company
8%
Financial Services Firm
8%
Government
7%
Computer Software Company
17%
Financial Services Firm
12%
Government
9%
Manufacturing Company
8%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

What do you like most about Cisco Stealthwatch?
The most valuable feature of Cisco Secure Network Analytics is the Threat Intelligence integration.
What is your experience regarding pricing and costs for Cisco Stealthwatch?
The organization experienced challenges with licensing as Cisco has multiple licensing factors, and there are concern...
What needs improvement with Cisco Stealthwatch?
Improvements are needed on the application layer for complete security analysis. The solution should have the ability...
How does Crowdstrike Falcon compare with Darktrace?
Both of these products perform similarly and have many outstanding attributes. CrowdStrike Falcon offers an amazing u...
Which is better - SentinelOne or Darktrace?
Which solution is better depends on which is more suitable specifically for your company. Darktrace, for example, is ...
What do you like most about Darktrace?
A very useful feature in Darktrace for real-time threat analysis is the packet inspection that analyzes the packet tr...
What do you like most about Splunk User Behavior Analytics?
The solution's most valuable feature is Splunk queries, which allow us to query the logs and analyze the attack vectors.
What is your experience regarding pricing and costs for Splunk User Behavior Analytics?
The pricing is based on the amount of data processed, and it is considered a high-level investment for enterprises. C...
What needs improvement with Splunk User Behavior Analytics?
High data ingestion costs can be an issue, especially for large enterprises, as Splunk charges based on the amount of...
 

Also Known As

Cisco Stealthwatch, Cisco Stealthwatch Enterprise, Lancope StealthWatch
No data available
Caspida, Splunk UBA
 

Overview

 

Sample Customers

Edge Web Hosting, Telenor Norway, Ivy Tech Community College of Indiana, Webster Financial Corporation, Westinghouse Electric, VMware, TIAA-CREF
Irwin Mitchell, Open Energi, Wellcome Trust, FirstGroup plc, Virgin Trains, Drax, QUI! Group, DNK, CreaCard, Macrosynergy, Sisley, William Hill plc, Toyota Canada, Royal British Legion, Vitol, Allianz, KKR, AIRBUS, dpd, Billabong, Mclaren Group.
8 Securities, AAA Western, AdvancedMD, Amaya, Cerner Corporation, CJ O Shopping, CloudShare, Crossroads Foundation, 7-Eleven Indonesia
Find out what your peers are saying about Zabbix, Auvik, Datadog and others in Network Monitoring Software. Updated: April 2025.
850,834 professionals have used our research since 2012.