Try our new research platform with insights from 80,000+ expert users

Cisco Secure Network Analytics vs Forcepoint Next Generation Firewall vs Splunk User Behavior Analytics comparison

 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

ROI

Sentiment score
8.0
Reviews on Cisco Secure Network Analytics show mixed ROI perceptions, highlighting both immediate benefits and debated long-term monetary savings.
Sentiment score
7.0
Users report significant ROI with Forcepoint Next Generation Firewall due to cost reduction, improved security, enhanced performance, and easier management.
Sentiment score
5.5
Users report varied ROI from Splunk, with productivity gains and security cost savings, but costs remain a concern.
Cybersecurity ROI could be $1 or $100 million, depending on the risk of data behind it.
The solution can save costs by improving incident resolution times and reducing security incident costs.
 

Customer Service

Sentiment score
7.2
Cisco Secure Network Analytics' support is generally well-regarded for responsiveness and expertise, despite occasional difficulty finding the right engineer.
Sentiment score
5.5
Forcepoint Next Generation Firewall support is skilled but slow, with calls for local support and improved response times.
Sentiment score
6.9
Splunk User Behavior Analytics support is mostly praised, with professional service, tiered options, and valuable user groups enhancing experience.
There is a lack of adequate local support from the Indian side.
For technical support of Cisco, the support they provide depends on how the client procures it, and so far, it's understandable.
Unlike Fortinet where you can escalate an issue and quickly get responses from the development team, Forcepoint's process seems slow and challenging.
Technical support is sometimes slow to respond, and it takes longer to resolve issues.
Mission-critical offering a dedicated team, proactive monitoring, and fast resolution.
From the responsiveness perspective, Splunk is very responsive with SLA-bound support for premium tiers.
I would rate the support at eight, meaning there's some room for improvement.
 

Scalability Issues

Sentiment score
6.6
Cisco Secure Network Analytics excels in scalability and adaptability, though it can be costly and challenging in data management.
Sentiment score
7.4
Forcepoint Next Generation Firewall excels in scalability, though some users face challenges with large-scale and cloud deployments.
Sentiment score
7.2
Splunk User Behavior Analytics is scalable and adaptable across environments, though storage limitations may affect scalability.
There are restrictions in the firewall manager and limitations when deploying for cloud environments.
Splunk User Behavior Analytics is highly scalable, designed for enterprise scalability, allowing expansion of data ingestion, indexing, and search capabilities as log volumes grow.
 

Stability Issues

Sentiment score
8.3
Cisco Secure Network Analytics is highly stable with minimal downtime, improved firmware, and strong reliability reported by users.
Sentiment score
7.9
Forcepoint Next Generation Firewall is stable and reliable, with praised detection and minor stability concerns in complex deployments.
Sentiment score
7.8
Splunk User Behavior Analytics offers reliable performance and stability, with 99.9% uptime and ease of configuration in enterprises.
Cisco products are incredibly stable, boasting a 200% stability.
Once resolved, the system works well, and overall I think it's good.
With built-in redundancy across zones and regions, 99.9% uptime is achievable.
Splunk User Behavior Analytics is a one hundred percent stable solution.
Splunk User Behavior Analytics is highly stable and reliable, even in large-scale enterprise environments with high log injection rates.
 

Room For Improvement

Cisco Secure Network Analytics needs better filtering, AI, integration, interface, speed, visibility, management, reporting, licensing, and cost efficiency.
Forcepoint NGFW needs UI, policy management, and pricing enhancements, along with improved support, integration, and configuration flexibility.
Splunk User Behavior Analytics needs better pricing, integration, user-friendly interfaces, enhanced features, and improved scalability and infrastructure.
The solution should have the ability to analyze security events not only at the network layer but also at the application and OS layers.
Proper management of the database is also important; it should be centralized for easier data collection from a single database.
Fast response and efficient handling of issues, similar to how Fortinet responds, would be great.
I recommend that additional features be included in a single license to avoid the need for extra licensing costs.
Global reach allows deployment of apps and services closer to users worldwide, but data sovereignty concerns exist and region selection must align with compliance requirements.
I encountered several issues while trying to create solutions for this advanced version, which seem unrelated to query or data issues.
High data ingestion costs can be an issue, especially for large enterprises, as Splunk charges based on the amount of data processed.
 

Setup Cost

Enterprise users find Cisco Secure Network Analytics costly due to complex licensing, with costs varying widely based on usage.
Forcepoint NGFW pricing varies, with costs perceived as high due to licensing models and additional feature charges.
Enterprise buyers find Splunk's User Behavior Analytics costly, with variable pricing based on data, hardware, and additional applications.
Cisco solutions are considered to be very expensive.
Regarding cost, for the Bangladesh context, Cisco Secure Network Analytics is a little bit high-priced because we are a developing country, making it tough to manage affordable solutions.
The costs can be high since additional features require separate licenses.
In terms of pricing, I would place Forcepoint in the middle when compared to other firewalls like Fortinet and Palo Alto.
Reserved instances with one or three-year commitments offer lower rates, providing up to 70% savings.
Comparing with the competitors, it's a bit expensive.
The pricing is based on the amount of data processed, and it is considered a high-level investment for enterprises.
 

Valuable Features

Cisco Secure Network Analytics offers visibility, threat detection, and analytics, enhancing security with AI-driven insights and encrypted traffic analysis.
Forcepoint Next Generation Firewall offers comprehensive security features and integration for effective network and systems application management.
Splunk User Behavior Analytics provides scalable, user-friendly threat detection with advanced analytics, machine learning, and seamless data integration and reporting.
The most valuable features include encrypted traffic analytics and the ability to fulfill requirements at the network level.
Every solution is gradually integrated with AI, and Cisco has already implemented AI building features in their solution.
With Forcepoint, this process is simplified compared to others like Fortinet.
The most valuable features of Forcepoint Next Generation Firewall are the advanced threat protection, including features like IPS and DDoS prevention, which help avoid internal DDoS attacks.
I also utilize it for anomaly detection and behavior analysis, particularly using Splunk's machine learning environment.
Features like alerts and auto report generation are valuable.
Splunk User Behavior Analytics offers several beneficial features, such as Insider Threat Detection, account compromise detection, risk scoring, threat detection, and machine anomaly detection.
 

Mindshare comparison

Network Monitoring Software Market Share Distribution
ProductMarket Share (%)
Cisco Secure Network Analytics1.2%
Zabbix11.7%
LibreNMS4.6%
Other82.5%
Network Monitoring Software
Firewalls Market Share Distribution
ProductMarket Share (%)
Forcepoint Next Generation Firewall0.5%
Fortinet FortiGate20.1%
Netgate pfSense11.1%
Other68.3%
Firewalls
User Entity Behavior Analytics (UEBA) Market Share Distribution
ProductMarket Share (%)
Splunk User Behavior Analytics8.9%
IBM Security QRadar10.2%
Exabeam10.1%
Other70.8%
User Entity Behavior Analytics (UEBA)
 

Featured Reviews

Muhammad Harun-Owr-Roshid - PeerSpot reviewer
Have streamlined network visibility and troubleshooting while seeing benefits from AI integration
In terms of improvements for Cisco Secure Network Analytics, from the implementation point of view, now that AI is in use, some other features need to be upgraded considering AI solutions. Proper management of the database is also important; it should be centralized for easier data collection from a single database. When precise manual analysis is needed, it's sometimes difficult, so having a centralized database will allow network admins to find actual scenarios more effectively, especially since some information may not be visible on the GUI. Cisco should upgrade their hardware part to run the database, because sometimes it cannot handle the load while all features are running in the network. The database management should indeed be centralized because while AI runs behind the systems, central management is essential. For example, in a network with 100 Cisco switches, a few routers, firewalls, and access points, all data generated should be preserved in a central database. This approach simplifies management and analysis for troubleshooting, as GUI interfaces may not always provide visible information. Centralizing the database will allow for better understanding of which information is preserved for each specific device.
OusaidAbaz - PeerSpot reviewer
Provides decent protection for the LAN but complicated interface
We had some licensing issues with its web filtering capabilities. That's why we migrated our web filtering to Cisco Umbrella. Moreover, the interface is complicated. It's difficult to locate all the necessary menus and functions. For example, one of the many issues is with SSH. Even now, we haven't successfully opened the port to connect using SSH mode when we want to change the configuration. It's like a black box—not very open to changes and customization. It's simply not easy to configure. There are other problems, too. For example regarding Forcepoint's Websense component. We had a lot of problems managing the web settings within Websense. That's why we migrated to Cisco Umbrella for cloud-based web filtering. It's not that Forcepoint is inherently bad. The issue is that it's not user-friendly. It is not easy to use. The developers need to redesign the interface (GUI) for better management. It is very difficult to manage. For example, simple actions require too many clicks compared to FortiGate or Palo Alto. That's the main problem.
Subhayu Chakraborty - PeerSpot reviewer
Automatic reports streamline tasks and offers easy report gathering
The dashboard part could be improved. While using it, I noticed two options: Classic, which is adequate yet only in black and white, and another one that is more advanced or smart, though I forgot the exact term. I encountered several issues while trying to create solutions for this advanced version, which seem unrelated to query or data issues.
report
Use our free recommendation engine to learn which Network Monitoring Software solutions are best for your needs.
866,561 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Computer Software Company
23%
Government
10%
Financial Services Firm
9%
Manufacturing Company
9%
Computer Software Company
15%
Manufacturing Company
10%
Government
8%
Financial Services Firm
7%
Computer Software Company
17%
Financial Services Firm
10%
Government
8%
Manufacturing Company
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business11
Midsize Enterprise7
Large Enterprise52
By reviewers
Company SizeCount
Small Business25
Midsize Enterprise8
Large Enterprise11
By reviewers
Company SizeCount
Small Business7
Midsize Enterprise5
Large Enterprise12
 

Questions from the Community

What do you like most about Cisco Stealthwatch?
The most valuable feature of Cisco Secure Network Analytics is the Threat Intelligence integration.
What is your experience regarding pricing and costs for Cisco Stealthwatch?
Regarding cost, for the Bangladesh context, Cisco Secure Network Analytics is a little bit high-priced because we are...
What needs improvement with Cisco Stealthwatch?
In terms of improvements for Cisco Secure Network Analytics, from the implementation point of view, now that AI is in...
What is your experience regarding pricing and costs for Forcepoint Next Generation Firewall?
The licensing model is dependent on negotiation skills, but there is room for improvement. The costs can be high sinc...
What needs improvement with Forcepoint Next Generation Firewall?
The licensing model should be more flexible. I recommend that additional features be included in a single license to ...
What do you like most about Splunk User Behavior Analytics?
The solution's most valuable feature is Splunk queries, which allow us to query the logs and analyze the attack vectors.
What is your experience regarding pricing and costs for Splunk User Behavior Analytics?
In terms of setup cost, pricing, and licensing, Splunk User Behavior Analytics is not an inexpensive product. The set...
What needs improvement with Splunk User Behavior Analytics?
There are improvements that could be made to Splunk User Behavior Analytics as any product will have advantages and d...
 

Also Known As

Cisco Stealthwatch, Cisco Stealthwatch Enterprise, Lancope StealthWatch
Forcepoint NGFW, Stonesoft Next Generation Firewall, McAfee Network Security Platform, Intel Security Network Security Platform
Caspida, Splunk UBA
 

Overview

 

Sample Customers

Edge Web Hosting, Telenor Norway, Ivy Tech Community College of Indiana, Webster Financial Corporation, Westinghouse Electric, VMware, TIAA-CREF
California Department of Corrections and Rehabilitation (CDCR)
8 Securities, AAA Western, AdvancedMD, Amaya, Cerner Corporation, CJ O Shopping, CloudShare, Crossroads Foundation, 7-Eleven Indonesia
Find out what your peers are saying about Zabbix, Auvik, SolarWinds and others in Network Monitoring Software. Updated: August 2025.
866,561 professionals have used our research since 2012.