Try our new research platform with insights from 80,000+ expert users

Lumu vs Splunk User Behavior Analytics comparison

 

Comparison Buyer's Guide

Executive SummaryUpdated on Dec 19, 2024

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Lumu
Ranking in Intrusion Detection and Prevention Software (IDPS)
11th
Average Rating
9.2
Reviews Sentiment
7.7
Number of Reviews
8
Ranking in other categories
Network Detection and Response (NDR) (6th), Extended Detection and Response (XDR) (17th)
Splunk User Behavior Analytics
Ranking in Intrusion Detection and Prevention Software (IDPS)
12th
Average Rating
8.2
Reviews Sentiment
6.8
Number of Reviews
23
Ranking in other categories
User Entity Behavior Analytics (UEBA) (4th)
 

Mindshare comparison

As of June 2025, in the Intrusion Detection and Prevention Software (IDPS) category, the mindshare of Lumu is 4.0%, up from 0.9% compared to the previous year. The mindshare of Splunk User Behavior Analytics is 2.2%, down from 2.6% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Intrusion Detection and Prevention Software (IDPS)
 

Featured Reviews

Juan Solano - PeerSpot reviewer
Protects against threats and handles it in time with moderate pricing
Mostly, Lumu is an automatic tool. We'll deploy on firewalls and DNS servers. Lumu detects every attack on our network. The other day, we had CLC, the command controller, and the tool reacted automatically. It detected the attack and immediately blocked it without intervention from my team. The improvement is in the security process, as it's now entirely automated. We no longer require a technician or engineer to monitor our network 24/7. Lumu updates with AI and global threat intelligence, which greatly assists us. Since our workload is lighter, Lumu handles all of our tasks. We're using FortiGate for the firewall and Kaspersky for endpoints. If you are going to Lumu, you need another solution for the endpoint. You need to integrate with other tools like firewalls or another antivirus. I recommend the solution based on the price, usability, and service offered by the solution. Overall, I rate the solution a nine out of ten.
Subhayu Chakraborty - PeerSpot reviewer
Automatic reports streamline tasks and offers easy report gathering
The dashboard part could be improved. While using it, I noticed two options: Classic, which is adequate yet only in black and white, and another one that is more advanced or smart, though I forgot the exact term. I encountered several issues while trying to create solutions for this advanced version, which seem unrelated to query or data issues.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"Lumu protects against threats immediately and handles them in time."
"The automated response to incidents works effectively out of the box, and the number of interfaces and platforms it can work with is impressive."
"It's been helpful for overall extended network visibility."
"Most of it is automated, so I do not have to watch it to get alerts."
"The tool's support team helps partners resolve any problems with the product."
"The context provided by the tool is very complete, it includes the miter matrix, playbooks, links, hashes, and much more."
"You can access external links, playbooks, MITRE Matrix, and a lot of information."
"I like Lumu's simple user interface. When we deployed it, we got full access, allowing us to identify IP addresses on the network and connect machine names to users. It helped us identify and block threats via the firewall. I also appreciate the chat support and ticket closure process. We're currently reviewing network detection solutions, and my recommendations include Lumu, Sentinel, and a few others. Regarding functionality and user-friendliness, I would recommend Lumu over the others."
"This intelligent user behavior analytics package is easy to configure and use while remaining feature filled."
"It's straightforward in terms of configuration and troubleshooting and log management and monitoring as well. These are the edge points in addition to it being a modular solution where you can capitalize on your current licenses with extra licensing models, which can match the customer's business requirement and it can help the customer to design or to actually plan for their own roadmap."
"The product is at the forefront of auto-remediation networking. It's great."
"The solution is fast, flexible, and easy to use."
"The most valuable feature is the ability to search through a large amount of data."
"We are really pleased with Splunk and its features. It would be practically impossible to function without it. To provide a general overview of the system, it's important to note that the standard log files are currently around 250 gigabytes per day. It would be impossible to manually walk through these logs by hand, which is why automation is essential."
"The most valuable feature is being able to take data and put it into other systems so that we could see the output, and to see where we need to apply our focus."
"It's easily scalable."
 

Cons

"The free version is minimal compared to the full version."
"The reports need improvement."
"The integration with different vendors and endpoints could be improved."
"I am happy with the current features. However, one important one is to improve the reports."
"Nothing so far needs to be improved."
"Lumu's ability to discover threats is an area of concern where improvements are needed."
"It would be good if we could access the physical logs."
"Having a larger support network would be beneficial. Nobody I know has heard of Lumu, so they are in the same space as Darktrace or CrowdStrike, but people give blank stares."
"If the price was lowered and the setup process was less complex, I would consider rating it higher."
"There are occasional bugs."
"The correlation engine should have persistent and definable rules."
"In the future I would like to see simplified statistics and analytical threats."
"In terms of improvements, advanced reporting could see enhancements as there are some issues with latency."
"They should work to add more built-in correlation searches and more use cases based on worldwide customer experiences. They need more ready-made use cases."
"The dashboard part could be improved."
"In terms of improvements, advanced reporting could see enhancements as there are some issues with latency. Additionally, there are challenges with configuration findings during lexical analysis."
 

Pricing and Cost Advice

"It is the cheapest solution we found."
"The tool is available at a good price. The tool offers a good and competitive price for customers."
"Compared to Lumu, other solutions are more expensive. SentinelOne was a bit cheaper, and another provider's price structure is unclear, but Lumu fit our budget nicely. SentinelOne's cost depends on the number of devices, and it might be similar to Lumu's, depending on deployment."
"Pricing varies based on the packages you choose and the volume of your usage."
"I hope we can increase the free license to be more than 5 gig a day. This would help people who want to introduce a POC or a demo license for the solution."
"The licensing costs is around 10,000 dollars."
"There are additional costs associated with the integrator."
"I am not aware of the price, but it is expensive."
"My biggest complaint is the way they do pricing... You can never know the pricing for next year. Every single time you adjust to something new, the price goes up. It's impossible to truly budget for it. It goes up constantly."
report
Use our free recommendation engine to learn which Intrusion Detection and Prevention Software (IDPS) solutions are best for your needs.
857,028 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Educational Organization
14%
Financial Services Firm
8%
Computer Software Company
8%
Comms Service Provider
8%
Computer Software Company
17%
Financial Services Firm
13%
Government
9%
Manufacturing Company
8%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

What do you like most about Lumu?
Lumu protects against threats immediately and handles them in time.
What needs improvement with Lumu?
There is always room for improvement. I am not giving it a perfect score because I am sure there is something that could be enhanced.Having some sort of certification or training, along with more p...
What is your primary use case for Lumu?
We use it as our managed SOC instead of contracting with an MSP. It coordinates endpoint and gives us a single pane of glass for our security events.It fulfills the role of a SIEM, serving as our d...
What do you like most about Splunk User Behavior Analytics?
The solution's most valuable feature is Splunk queries, which allow us to query the logs and analyze the attack vectors.
What is your experience regarding pricing and costs for Splunk User Behavior Analytics?
The pricing is based on the amount of data processed, and it is considered a high-level investment for enterprises. Costs can be cut through efficient use and implementation.
What needs improvement with Splunk User Behavior Analytics?
High data ingestion costs can be an issue, especially for large enterprises, as Splunk charges based on the amount of data processed. Complex dashboards may require additional scripting. Some integ...
 

Also Known As

No data available
Caspida, Splunk UBA
 

Overview

 

Sample Customers

Information Not Available
8 Securities, AAA Western, AdvancedMD, Amaya, Cerner Corporation, CJ O Shopping, CloudShare, Crossroads Foundation, 7-Eleven Indonesia
Find out what your peers are saying about Lumu vs. Splunk User Behavior Analytics and other solutions. Updated: June 2025.
857,028 professionals have used our research since 2012.