Try our new research platform with insights from 80,000+ expert users

Elastic Search vs Splunk User Behavior Analytics comparison

 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

ROI

Sentiment score
4.1
Elastic Search boosts efficiency, reduces search times, improves security, lowers costs, and enhances product scaling and performance.
Sentiment score
5.9
Splunk User Behavior Analytics improves productivity and ROI, with significant investment offset by enhanced data integration and strategic implementation.
We have not purchased any licensed products, and our use of Elastic Search is purely open-source, contributing positively to our ROI.
Software Engineer at Government of India
It is stable, and we do not encounter critical issues like server downtime, which could result in data loss.
SOC A2 at Innodata-ISOGEN
The main benefits observed from using Elastic Search include improvements in operational efficiency, along with cost, time, and resource savings.
Senior Devops Engineer at Ubique Digital LTD
The solution can save costs by improving incident resolution times and reducing security incident costs.
Enterprise Architect at Wipro Limited
 

Customer Service

Sentiment score
6.3
Elastic Search's support is praised for expertise and responsiveness, despite occasional delays and suggestions for faster response times.
Sentiment score
6.8
Splunk User Behavior Analytics support is generally well-rated, with satisfaction varying by support tier and community resources valued.
The customer support for Elastic Search is one of the best I have ever tried.
Software Developer at a media company with 10,001+ employees
They have always been really responsible and responsive to my requests.
Security Lead at a tech vendor with 501-1,000 employees
It has been sufficient to visit conferences such as SCALE in Southern California Linux Expo, where Elastic Search has a booth to talk to their staff.
Principal Scientific Computing Software Engineer at a educational organization with 1,001-5,000 employees
Mission-critical offering a dedicated team, proactive monitoring, and fast resolution.
Enterprise Architect at Wipro Limited
From the responsiveness perspective, Splunk is very responsive with SLA-bound support for premium tiers.
Enterprise Architect at Wipro Limited
I would rate their technical support as 8.5 out of 10.
Director at Techpace
 

Scalability Issues

Sentiment score
7.3
Elasticsearch is highly scalable and efficient, requiring proper infrastructure planning for expanding and managing large datasets successfully.
Sentiment score
7.3
Splunk User Behavior Analytics excels in scalability, supporting vast data and devices, despite some storage limitations for long-term logs.
I would rate its scalability a ten.
Backend Developer
Since we're on the cloud, whenever we need to upgrade or add resources, they handle everything.
Security Lead at a tech vendor with 501-1,000 employees
We haven't encountered any problems so far, and there is the potential for auto-scaling.
Head of Data Management at Zeno Health
Splunk User Behavior Analytics is highly scalable, designed for enterprise scalability, allowing expansion of data ingestion, indexing, and search capabilities as log volumes grow.
Enterprise Architect at Wipro Limited
 

Stability Issues

Sentiment score
7.7
Elastic Search offers strong stability, reliable performance, and efficient scalability across various environments, with occasional configuration needs.
Sentiment score
7.9
Splunk User Behavior Analytics is stable, reliable, and user-friendly, excelling in enterprise environments with high log volumes.
The data transfer sometimes exceeded the bandwidth limits without proper notification, which caused issues.
SOC A2 at Innodata-ISOGEN
The stability of Elasticsearch was very high.
Backend Developer
When you put one keyword, everything related to that keyword in your ecosystem will showcase all the results.
Chief Information Security Officer at CDSL Ventures Limited
With built-in redundancy across zones and regions, 99.9% uptime is achievable.
Enterprise Architect at Wipro Limited
Splunk User Behavior Analytics is a one hundred percent stable solution.
Cloud Solution Architect at Tech Mahindra Limited
Splunk User Behavior Analytics is highly stable and reliable, even in large-scale enterprise environments with high log injection rates.
Enterprise Architect at Wipro Limited
 

Room For Improvement

Elastic Search needs cost clarity, improved performance, user experience, configuration simplicity, scalability, documentation, and advanced machine learning features.
Splunk User Behavior Analytics needs enhancements in dashboards, integration, pricing, support, automation, machine learning, configuration, and storage management.
From a technical point of view, there are no significant issues recalled as Elastic Search has been absolutely awesome for this use case and covers 100% of the needs.
Principal Scientific Computing Software Engineer at a educational organization with 1,001-5,000 employees
If I need to parse one million records saved into Elastic Search, it becomes a nightmare because I need to do the pagination, and it is very problematic in that regard.
Lead Engineer at Spidersilk
Observability features like search latency, indexing rate, and maybe rejected requests should be added to make the platform more reliable and accessible for everyone.
Senior System Engineer at EPAM Systems
Global reach allows deployment of apps and services closer to users worldwide, but data sovereignty concerns exist and region selection must align with compliance requirements.
Enterprise Architect at Wipro Limited
I encountered several issues while trying to create solutions for this advanced version, which seem unrelated to query or data issues.
System Engineer at Infosys
High data ingestion costs can be an issue, especially for large enterprises, as Splunk charges based on the amount of data processed.
Enterprise Architect at Wipro Limited
 

Setup Cost

Elastic Search pricing varies by usage and features, offering flexibility but potential high costs with complex deployments.
Splunk User Behavior Analytics is costly, with pricing based on processed data, transitioning to subscription models, and includes additional costs.
On the AWS side, it is very expensive because they charge based on query basis or how much data is transferred in and out, making it very expensive.
Lead Engineer at Spidersilk
Having the hosted solution and not having to pay for essentially a DevOps person on staff to manage makes it affordable.
CTO at a tech services company with 1-10 employees
You can host it on-premises, which would incur zero cost, or take it as a SaaS-based service, where the expenses remain minimal.
Senior Software Engineer at Agoda
Reserved instances with one or three-year commitments offer lower rates, providing up to 70% savings.
Enterprise Architect at Wipro Limited
Compared to all other products in the market, it is the most expensive one in all aspects including professional service and licenses, even the cloud version.
Director at Techpace
Comparing with the competitors, it's a bit expensive.
Regional Director at iSecureMind
 

Valuable Features

Elastic Search excels in full-text search, scalability, data indexing, visualization, AI features, and integrates well for enterprise solutions.
Splunk User Behavior Analytics offers advanced threat detection, scalability, and integration for robust security and data analysis solutions.
Elastic Search makes handling large data volumes efficient and supports complex search operations.
Software Engineer at Government of India
The most valuable feature of Elasticsearch was the quick search capability, allowing us to search by any criteria needed.
Backend Developer
The speed with which Elastic Search is able to search through all of the documents we place into it is quite remarkable, as we search through 65 billion documents in less than a second in most cases, on a constant consistent basis.
Director, Software Engineering at a tech vendor with 10,001+ employees
I also utilize it for anomaly detection and behavior analysis, particularly using Splunk's machine learning environment.
Cloud Solution Architect at Tech Mahindra Limited
The dashboards themselves are nice, very good, and very helpful, but the accuracy of the data or the information that will be presented on the dashboard is something that needs to be questioned.
Director at Techpace
Features like alerts and auto report generation are valuable.
System Engineer at Infosys
 

Categories and Ranking

Elastic Search
Average Rating
8.2
Reviews Sentiment
6.5
Number of Reviews
90
Ranking in other categories
Indexing and Search (1st), Cloud Data Integration (6th), Search as a Service (1st), Vector Databases (2nd)
Splunk User Behavior Analytics
Average Rating
8.2
Reviews Sentiment
6.6
Number of Reviews
25
Ranking in other categories
Intrusion Detection and Prevention Software (IDPS) (12th), User Entity Behavior Analytics (UEBA) (4th)
 

Mindshare comparison

Elastic Search and Splunk User Behavior Analytics aren’t in the same category and serve different purposes. Elastic Search is designed for Indexing and Search and holds a mindshare of 12.0%, down 26.3% compared to last year.
Splunk User Behavior Analytics, on the other hand, focuses on User Entity Behavior Analytics (UEBA), holds 5.7% mindshare, down 9.7% since last year.
Indexing and Search Mindshare Distribution
ProductMindshare (%)
Elastic Search12.0%
Lucidworks6.3%
OpenText Knowledge Discovery (IDOL)6.1%
Other75.6%
Indexing and Search
User Entity Behavior Analytics (UEBA) Mindshare Distribution
ProductMindshare (%)
Splunk User Behavior Analytics5.7%
Exabeam8.6%
IBM Security QRadar6.3%
Other79.4%
User Entity Behavior Analytics (UEBA)
 

Featured Reviews

Anurag Pal - PeerSpot reviewer
Technical Lead at a consultancy with 10,001+ employees
Search and aggregations have transformed how I manage and visualize complex real estate data
Elastic Search consumes lots of memory. You have to provide the heap size a lot if you want the best out of it. The major problem is when a company wants to use Elastic Search but it is at a startup stage. At a startup stage, there is a lot of funds to consider. However, their use case is that they have to use a pretty significant amount of data. For that, it is very expensive. For example, if you take OLTP-based databases in the current scenario, such as ClickHouse or Iceberg, you can do it on 4GB RAM also. Elastic Search is for analytical records. You have to do the analytics on it. According to me, as far as I have seen, people will start moving from Elastic Search sooner or later. Why? Because it is expensive. Another thing is that there is an open source available for that, such as ClickHouse. Around 2014 and 2012, there was only one competitor at that time, which was Solr. But now, not only is Solr there, but you can take ClickHouse and you have Iceberg also. How are we going to compete with them? There is also a fork of Elastic Search that is OpenSearch. As far as I have seen in lots of articles I am reading, users are using it as the ELK stack for logs and analyzing logs. That is not the exact use case. It can do more than that if used correctly. But as it involves lots of cost, people are shifting from Elastic Search to other sources. When I am talking about pricing, it is not only the server pricing. It is the amount of memory it is using. The pricing is basically the heap Java, which is taking memory. That is the major problem happening here. If we have to run an MVP, a client comes to me and says, "Anurag, we need to do a proof of concept. Can we do it if I can pay a 4GB or 16GB expense?" How can I suggest to them that a minimum of 16GB is needed for Elastic Search so that your proof of concept will be proved? In that case, what I have to suggest from the beginning is to go with Cassandra or at the initial stage, go with PostgreSQL. The problem is the memory it is taking. That is the only thing.
SK
Enterprise Architect at Wipro Limited
Offers intuitive deployment with strong customer support and advanced analytics features
There are improvements that could be made to Splunk User Behavior Analytics as any product will have advantages and disadvantages. Scalability is one consideration. For example, the advantages include rapid auto scaling to meet demand. A disadvantage is that it can lead to cost overrun if not properly factored or governed. The speed of deployment offers faster provisioning as an advantage, but it can require substantial automation skills and infrastructure as code expertise, which can be challenging. Cloud provides major operational benefits such as agility, automation, resilience, and global access when setting up on Cloud. However, it introduces challenges such as cost control, complexity, and vendor dependency. For example, global reach allows deployment of apps and services closer to users worldwide, but data sovereignty concerns exist and region selection must align with compliance requirements.
report
Use our free recommendation engine to learn which Indexing and Search solutions are best for your needs.
884,192 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Financial Services Firm
12%
Computer Software Company
11%
Manufacturing Company
9%
Retailer
7%
Computer Software Company
10%
Financial Services Firm
10%
Government
9%
University
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business37
Midsize Enterprise10
Large Enterprise45
By reviewers
Company SizeCount
Small Business7
Midsize Enterprise6
Large Enterprise12
 

Questions from the Community

What do you like most about ELK Elasticsearch?
Logsign provides us with the capability to execute multiple queries according to our requirements. The indexing is very high, making it effective for storing and retrieving logs. The real-time anal...
What is your experience regarding pricing and costs for ELK Elasticsearch?
On the subject of pricing, Elastic Search is very cost-efficient. You can host it on-premises, which would incur zero cost, or take it as a SaaS-based service, where the expenses remain minimal.
What needs improvement with ELK Elasticsearch?
Elastic Search consumes lots of memory. You have to provide the heap size a lot if you want the best out of it. The major problem is when a company wants to use Elastic Search but it is at a startu...
What do you like most about Splunk User Behavior Analytics?
The solution's most valuable feature is Splunk queries, which allow us to query the logs and analyze the attack vectors.
What is your experience regarding pricing and costs for Splunk User Behavior Analytics?
Splunk User Behavior Analytics is a premium product. Compared to all other products in the market, it is the most expensive one in all aspects including professional service and licenses, even the ...
What needs improvement with Splunk User Behavior Analytics?
Splunk User Behavior Analytics is still an immature product, so it still needs some R&D to be able to be mature in the market. The prediction, algorithms, and ML codes behind Splunk User Behavi...
 

Also Known As

Elastic Enterprise Search, Swiftype, Elastic Cloud
Caspida, Splunk UBA
 

Overview

 

Sample Customers

T-Mobile, Adobe, Booking.com, BMW, Telegraph Media Group, Cisco, Karbon, Deezer, NORBr, Labelbox, Fingerprint, Relativity, NHS Hospital, Met Office, Proximus, Go1, Mentat, Bluestone Analytics, Humanz, Hutch, Auchan, Sitecore, Linklaters, Socren, Infotrack, Pfizer, Engadget, Airbus, Grab, Vimeo, Ticketmaster, Asana, Twilio, Blizzard, Comcast, RWE and many others.
8 Securities, AAA Western, AdvancedMD, Amaya, Cerner Corporation, CJ O Shopping, CloudShare, Crossroads Foundation, 7-Eleven Indonesia
Find out what your peers are saying about Elastic Search vs. Splunk User Behavior Analytics and other solutions. Updated: January 2022.
884,192 professionals have used our research since 2012.