Try our new research platform with insights from 80,000+ expert users

Elastic Search vs Splunk User Behavior Analytics comparison

 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

ROI

Sentiment score
4.4
Elastic Search enhanced efficiency and performance, offering substantial time and cost savings, despite mixed opinions on return metrics.
Sentiment score
5.5
Users report varied ROI from Splunk UBA, emphasizing productivity gains, time savings, and improved incident resolution efficiency.
We have not purchased any licensed products, and our use of Elastic Search is purely open-source, contributing positively to our ROI.
Software Engineer at Government of India
It is stable, and we do not encounter critical issues like server downtime, which could result in data loss.
SOC A2 at Innodata-ISOGEN
The main benefits observed from using Elastic Search include improvements in operational efficiency, along with cost, time, and resource savings.
Senior Devops Engineer at Ubique Digital LTD
The solution can save costs by improving incident resolution times and reducing security incident costs.
Enterprise Architect at Wipro Limited
 

Customer Service

Sentiment score
6.2
Elastic Search offers expert support and documentation, though response times and communication could improve for some users.
Sentiment score
6.9
Splunk User Behavior Analytics support is praised for its professionalism, extensive knowledge base, and prompt, reliable assistance despite regional limitations.
The customer support for Elastic Search is one of the best I have ever tried.
Software Developer at a media company with 10,001+ employees
They have always been really responsible and responsive to my requests.
Security Lead at a tech vendor with 501-1,000 employees
It has been sufficient to visit conferences such as SCALE in Southern California Linux Expo, where Elastic Search has a booth to talk to their staff.
Principal Scientific Computing Software Engineer at a educational organization with 1,001-5,000 employees
Mission-critical offering a dedicated team, proactive monitoring, and fast resolution.
Enterprise Architect at Wipro Limited
From the responsiveness perspective, Splunk is very responsive with SLA-bound support for premium tiers.
Enterprise Architect at Wipro Limited
I would rate their technical support as 8.5 out of 10.
Director at Techpace
 

Scalability Issues

Sentiment score
7.3
Elastic Search is highly scalable, enabling efficient node addition, though sharding, replication, and storage demands require careful management.
Sentiment score
7.2
Splunk User Behavior Analytics excels in scalable deployment, flexible expansion, and efficient data handling, overcoming on-premises storage challenges.
I would rate its scalability a ten.
Backend Developer
Since we're on the cloud, whenever we need to upgrade or add resources, they handle everything.
Security Lead at a tech vendor with 501-1,000 employees
We haven't encountered any problems so far, and there is the potential for auto-scaling.
Head of Data Management at Zeno Health
Splunk User Behavior Analytics is highly scalable, designed for enterprise scalability, allowing expansion of data ingestion, indexing, and search capabilities as log volumes grow.
Enterprise Architect at Wipro Limited
 

Stability Issues

Sentiment score
7.7
Elastic Search is stable and reliable, despite some challenges, as proper management ensures performance under varying loads.
Sentiment score
7.8
Splunk User Behavior Analytics is stable, reliable, easy to configure, and effective, achieving 99.9% uptime with proper deployment.
The data transfer sometimes exceeded the bandwidth limits without proper notification, which caused issues.
SOC A2 at Innodata-ISOGEN
The stability of Elasticsearch was very high.
Backend Developer
When you put one keyword, everything related to that keyword in your ecosystem will showcase all the results.
Chief Information Security Officer at CDSL Ventures Limited
With built-in redundancy across zones and regions, 99.9% uptime is achievable.
Enterprise Architect at Wipro Limited
Splunk User Behavior Analytics is a one hundred percent stable solution.
Cloud Solution Architect at Tech Mahindra Limited
Splunk User Behavior Analytics is highly stable and reliable, even in large-scale enterprise environments with high log injection rates.
Enterprise Architect at Wipro Limited
 

Room For Improvement

Elastic Search needs better security, pricing, machine learning, scalability, ease of use, and support, facing significant user challenges.
Splunk User Behavior Analytics needs better pricing, integration, automation, and machine learning to enhance functionality and user experience.
From a technical point of view, there are no significant issues recalled as Elastic Search has been absolutely awesome for this use case and covers 100% of the needs.
Principal Scientific Computing Software Engineer at a educational organization with 1,001-5,000 employees
If I need to parse one million records saved into Elastic Search, it becomes a nightmare because I need to do the pagination, and it is very problematic in that regard.
Lead Engineer at Spidersilk
Observability features like search latency, indexing rate, and maybe rejected requests should be added to make the platform more reliable and accessible for everyone.
Senior System Engineer at EPAM Systems
Global reach allows deployment of apps and services closer to users worldwide, but data sovereignty concerns exist and region selection must align with compliance requirements.
Enterprise Architect at Wipro Limited
I encountered several issues while trying to create solutions for this advanced version, which seem unrelated to query or data issues.
System Engineer at Infosys
High data ingestion costs can be an issue, especially for large enterprises, as Splunk charges based on the amount of data processed.
Enterprise Architect at Wipro Limited
 

Setup Cost

Elastic Search's open-source version is free, but enterprises face costs in skills, training, support, and premium features.
Splunk User Behavior Analytics pricing is perceived as complex and expensive, influenced by data volume, licensing, and integration needs.
On the AWS side, it is very expensive because they charge based on query basis or how much data is transferred in and out, making it very expensive.
Lead Engineer at Spidersilk
Having the hosted solution and not having to pay for essentially a DevOps person on staff to manage makes it affordable.
CTO at a tech services company with 1-10 employees
You can host it on-premises, which would incur zero cost, or take it as a SaaS-based service, where the expenses remain minimal.
Senior Software Engineer at Agoda
Reserved instances with one or three-year commitments offer lower rates, providing up to 70% savings.
Enterprise Architect at Wipro Limited
Compared to all other products in the market, it is the most expensive one in all aspects including professional service and licenses, even the cloud version.
Director at Techpace
Comparing with the competitors, it's a bit expensive.
Regional Director at iSecureMind
 

Valuable Features

Elasticsearch offers real-time monitoring, scalability, and integration with Kibana, enhancing data retrieval, security, customization, and decision-making.
Splunk User Behavior Analytics offers advanced threat detection, real-time data collection, and customizable dashboards for enhanced monitoring and decision-making.
Elastic Search makes handling large data volumes efficient and supports complex search operations.
Software Engineer at Government of India
The most valuable feature of Elasticsearch was the quick search capability, allowing us to search by any criteria needed.
Backend Developer
The speed with which Elastic Search is able to search through all of the documents we place into it is quite remarkable, as we search through 65 billion documents in less than a second in most cases, on a constant consistent basis.
Director, Software Engineering at a tech vendor with 10,001+ employees
I also utilize it for anomaly detection and behavior analysis, particularly using Splunk's machine learning environment.
Cloud Solution Architect at Tech Mahindra Limited
The dashboards themselves are nice, very good, and very helpful, but the accuracy of the data or the information that will be presented on the dashboard is something that needs to be questioned.
Director at Techpace
Features like alerts and auto report generation are valuable.
System Engineer at Infosys
 

Categories and Ranking

Elastic Search
Average Rating
8.2
Reviews Sentiment
6.5
Number of Reviews
88
Ranking in other categories
Indexing and Search (1st), Cloud Data Integration (6th), Search as a Service (1st), Vector Databases (2nd)
Splunk User Behavior Analytics
Average Rating
8.2
Reviews Sentiment
6.6
Number of Reviews
25
Ranking in other categories
Intrusion Detection and Prevention Software (IDPS) (13th), User Entity Behavior Analytics (UEBA) (5th)
 

Mindshare comparison

Elastic Search and Splunk User Behavior Analytics aren’t in the same category and serve different purposes. Elastic Search is designed for Indexing and Search and holds a mindshare of 13.6%, down 28.0% compared to last year.
Splunk User Behavior Analytics, on the other hand, focuses on User Entity Behavior Analytics (UEBA), holds 6.0% mindshare, down 9.5% since last year.
Indexing and Search Market Share Distribution
ProductMarket Share (%)
Elastic Search13.6%
Lucidworks7.5%
OpenText Knowledge Discovery (IDOL)6.7%
Other72.2%
Indexing and Search
User Entity Behavior Analytics (UEBA) Market Share Distribution
ProductMarket Share (%)
Splunk User Behavior Analytics6.0%
Exabeam7.5%
IBM Security QRadar6.8%
Other79.7%
User Entity Behavior Analytics (UEBA)
 

Featured Reviews

Vaibhav Shukla - PeerSpot reviewer
Senior Software Engineer at Agoda
Search performance has transformed large-scale intent discovery and hybrid query handling
While Elastic Search is a good product, I see areas for improvement, particularly regarding the misconception that any amount of data can simply be dumped into Elastic Search. When creating an index, careful consideration of data massaging is essential. Elastic Search stores mappings for various data types, which must remain below a certain threshold to maintain functionality. Users need to throttle the number of fields for searching to avoid overloading the system and ensure that the design of the document is efficient for the Elastic Search index. Additionally, I suggest utilizing ILM periodically throughout the year to manage data shuffling between clusters, preventing hotspots in the distribution of requests across nodes.
SK
Enterprise Architect at Wipro Limited
Offers intuitive deployment with strong customer support and advanced analytics features
There are improvements that could be made to Splunk User Behavior Analytics as any product will have advantages and disadvantages. Scalability is one consideration. For example, the advantages include rapid auto scaling to meet demand. A disadvantage is that it can lead to cost overrun if not properly factored or governed. The speed of deployment offers faster provisioning as an advantage, but it can require substantial automation skills and infrastructure as code expertise, which can be challenging. Cloud provides major operational benefits such as agility, automation, resilience, and global access when setting up on Cloud. However, it introduces challenges such as cost control, complexity, and vendor dependency. For example, global reach allows deployment of apps and services closer to users worldwide, but data sovereignty concerns exist and region selection must align with compliance requirements.
report
Use our free recommendation engine to learn which Indexing and Search solutions are best for your needs.
881,346 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Financial Services Firm
12%
Computer Software Company
12%
Manufacturing Company
9%
Government
6%
Computer Software Company
12%
Financial Services Firm
10%
Government
8%
Educational Organization
8%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business37
Midsize Enterprise10
Large Enterprise43
By reviewers
Company SizeCount
Small Business7
Midsize Enterprise5
Large Enterprise12
 

Questions from the Community

What do you like most about ELK Elasticsearch?
Logsign provides us with the capability to execute multiple queries according to our requirements. The indexing is very high, making it effective for storing and retrieving logs. The real-time anal...
What is your experience regarding pricing and costs for ELK Elasticsearch?
Elastic Search's pricing totally depends on the server. Managed services from AWS are used, and we have worked on a self-managed Elastic Search cluster. On the AWS side, it is very expensive becaus...
What needs improvement with ELK Elasticsearch?
To be honest, there is only one downside of Elastic Search that makes sense because we use a basic license, which is a free license. We do not have some features available because of the free licen...
What do you like most about Splunk User Behavior Analytics?
The solution's most valuable feature is Splunk queries, which allow us to query the logs and analyze the attack vectors.
What is your experience regarding pricing and costs for Splunk User Behavior Analytics?
Splunk User Behavior Analytics is a premium product. Compared to all other products in the market, it is the most expensive one in all aspects including professional service and licenses, even the ...
What needs improvement with Splunk User Behavior Analytics?
Splunk User Behavior Analytics is still an immature product, so it still needs some R&D to be able to be mature in the market. The prediction, algorithms, and ML codes behind Splunk User Behavi...
 

Also Known As

Elastic Enterprise Search, Swiftype, Elastic Cloud
Caspida, Splunk UBA
 

Overview

 

Sample Customers

T-Mobile, Adobe, Booking.com, BMW, Telegraph Media Group, Cisco, Karbon, Deezer, NORBr, Labelbox, Fingerprint, Relativity, NHS Hospital, Met Office, Proximus, Go1, Mentat, Bluestone Analytics, Humanz, Hutch, Auchan, Sitecore, Linklaters, Socren, Infotrack, Pfizer, Engadget, Airbus, Grab, Vimeo, Ticketmaster, Asana, Twilio, Blizzard, Comcast, RWE and many others.
8 Securities, AAA Western, AdvancedMD, Amaya, Cerner Corporation, CJ O Shopping, CloudShare, Crossroads Foundation, 7-Eleven Indonesia
Find out what your peers are saying about Elastic Search vs. Splunk User Behavior Analytics and other solutions. Updated: January 2022.
881,346 professionals have used our research since 2012.