Try our new research platform with insights from 80,000+ expert users

Splunk User Behavior Analytics vs Trellix Intrusion Prevention System comparison

 

Comparison Buyer's Guide

Executive SummaryUpdated on Dec 19, 2024

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Splunk User Behavior Analytics
Ranking in Intrusion Detection and Prevention Software (IDPS)
15th
Average Rating
8.2
Reviews Sentiment
6.6
Number of Reviews
25
Ranking in other categories
User Entity Behavior Analytics (UEBA) (4th)
Trellix Intrusion Preventio...
Ranking in Intrusion Detection and Prevention Software (IDPS)
10th
Average Rating
8.4
Reviews Sentiment
6.6
Number of Reviews
16
Ranking in other categories
No ranking in other categories
 

Mindshare comparison

As of October 2025, in the Intrusion Detection and Prevention Software (IDPS) category, the mindshare of Splunk User Behavior Analytics is 1.9%, up from 1.7% compared to the previous year. The mindshare of Trellix Intrusion Prevention System is 2.7%, up from 2.1% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Intrusion Detection and Prevention Software (IDPS) Market Share Distribution
ProductMarket Share (%)
Trellix Intrusion Prevention System2.7%
Splunk User Behavior Analytics1.9%
Other95.4%
Intrusion Detection and Prevention Software (IDPS)
 

Featured Reviews

Ahmed Naguib - PeerSpot reviewer
Dashboard design excels while prediction algorithms need improvement
Splunk User Behavior Analytics is still an immature product, so it still needs some R&D to be able to be mature in the market. The prediction, algorithms, and ML codes behind Splunk User Behavior Analytics need to be more tuned. The logic needs to be reviewed because it has many false positives. For Splunk User Behavior Analytics, it is not yet a mature product and we are not recommending this to mature customers for now. The machine learning algorithm in Splunk User Behavior Analytics is actually the core thing that needs to be updated because this feeds all the other functions inside it. If the ML functions are not good enough, that means the risk scoring and all other related information will not be correct.
Daniel_Martins - PeerSpot reviewer
Decade of experience empowers seamless problem resolution and support
I haven't seen threat intelligence and machine learning for predictive threat analysis in the Trellix Intrusion Prevention System yet. For Trellix IPS, AI improvements are an area where it can improve. It's a significant feature. Regarding the Trellix Intrusion Prevention System's flexibility for catering to our organization's specific infrastructure requirements, we have only on-premises and virtual appliances, but it's acceptable. The access and platform could potentially integrate with SaaS. Similar to when you put the EPO in mode integration with SaaS, you can connect with a local credential and with an X Console credential. Another possibility would be to connect with an integration login with the X Console. We have this with EPO on-premise, but with IPS, we don't have it.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"Splunk is highly valuable for query purposes."
"This is a good security product."
"This intelligent user behavior analytics package is easy to configure and use while remaining feature filled."
"Splunk's technical support is amazing."
"Splunk User Behavior Analytics is a one hundred percent stable solution."
"The product is at the forefront of auto-remediation networking. It's great."
"Because of some of the visualizations that we utilize, we are able to understand strange, unusual traffic on our networks."
"The solution appears to be stable, although we haven't used it heavily."
"Great monitoring feature."
"It has a lot of functions, such as firewall. We are administrators, and we create some rules to protect our network. We also monitor the traffic in and out and have disk encryption on-premises. When we detect malware, we scan for the virus on the PC. We can then delete or block the malware."
"The threat intelligence updates are very accurate."
"The feature I found most valuable is the network threat analyzer in the security platform. It also integrates with GTI, or Global Threat Intelligence. Otherwise, I just use the basic features."
"The initial setup is straightforward."
"Overall the solution is very good. It offers great protection and gives us a good overview of what is on the network."
"There's a good dashboard you can drill down into. It helps you easily locate intrusions and the source of attacks."
"The most valuable features of the solution stem from the fact that it is a good product for dealing with DDoS attacks and for the inspection of network traffic."
 

Cons

"It could be easier to scale the solution if you are using it on-premise, not in the cloud."
"The machine learning algorithm in Splunk User Behavior Analytics is actually the core thing that needs to be updated because this feeds all the other functions inside it."
"The initial setup was complex because some of the configurations that we required needed customization."
"In terms of improvements, advanced reporting could see enhancements as there are some issues with latency."
"Currently, a lot of network operations need improvement. We still need people to handle incidents. Our vision is to leverage status and convert it directly from the network devices. It would be ideal if we could take action using APIs and API code and remove manual processes."
"In terms of improvements, advanced reporting could see enhancements as there are some issues with latency. Additionally, there are challenges with configuration findings during lexical analysis."
"The price of Splunk UBA is too high."
"I'm not aware of any lacking features."
"The pricing could be improved."
"Trellix Intrusion Prevention System does not provide virtual patching."
"The technical support has room for improvement."
"The solution could improve some aspects of detection."
"The solution needs to improve the graphical interface. And they had a limitation in some of the sensor modems as well."
"The management component could be simplified."
"The management console needs to be less complex and easier to navigate."
"The technical support must be improved."
 

Pricing and Cost Advice

"I am not aware of the price, but it is expensive."
"The licensing costs is around 10,000 dollars."
"I hope we can increase the free license to be more than 5 gig a day. This would help people who want to introduce a POC or a demo license for the solution."
"Pricing varies based on the packages you choose and the volume of your usage."
"There are additional costs associated with the integrator."
"My biggest complaint is the way they do pricing... You can never know the pricing for next year. Every single time you adjust to something new, the price goes up. It's impossible to truly budget for it. It goes up constantly."
"I rate the product’s pricing an eight out of ten."
"The tool is competitively priced."
report
Use our free recommendation engine to learn which Intrusion Detection and Prevention Software (IDPS) solutions are best for your needs.
870,701 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Computer Software Company
18%
Financial Services Firm
9%
Government
8%
Manufacturing Company
7%
Manufacturing Company
14%
Financial Services Firm
9%
Computer Software Company
9%
Comms Service Provider
8%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business7
Midsize Enterprise5
Large Enterprise12
By reviewers
Company SizeCount
Small Business6
Midsize Enterprise7
Large Enterprise5
 

Questions from the Community

What do you like most about Splunk User Behavior Analytics?
The solution's most valuable feature is Splunk queries, which allow us to query the logs and analyze the attack vectors.
What is your experience regarding pricing and costs for Splunk User Behavior Analytics?
In terms of setup cost, pricing, and licensing, Splunk User Behavior Analytics is not an inexpensive product. The setup requires numerous components including storage, networking, identity access, ...
What needs improvement with Splunk User Behavior Analytics?
There are improvements that could be made to Splunk User Behavior Analytics as any product will have advantages and disadvantages. Scalability is one consideration. For example, the advantages incl...
What do you like most about McAfee Network Security Platform?
The threat intelligence updates are very accurate.
What is your experience regarding pricing and costs for McAfee Network Security Platform?
The tool is competitively priced. I rate the pricing a six out of ten.
What needs improvement with McAfee Network Security Platform?
Trellix Intrusion Prevention System does not provide virtual patching. Patching involves updates on the OS side to address vulnerabilities, which is a different functionality. Trellix Intrusion Pre...
 

Also Known As

Caspida, Splunk UBA
McAfee Network Security Platform, McAfee NSP, IntruShield Network Intrusion Prevention System, IntruShield Network IPS
 

Overview

 

Sample Customers

8 Securities, AAA Western, AdvancedMD, Amaya, Cerner Corporation, CJ O Shopping, CloudShare, Crossroads Foundation, 7-Eleven Indonesia
Desjardins Group, HollyFrontier, Nubia, Agbar, WNS Global Services, INAIL, Universidad de Las Américas Puebla (UDLAP), Cook County, China Pacific Insurance, Bank Central Asia, California Department of Corrections and Rehabilitation, City of Chicago, Macquarie Telecom, Sutherland Global Services, Texas Tech University Health Sciences Center, United Automotive Electronic Systems
Find out what your peers are saying about Splunk User Behavior Analytics vs. Trellix Intrusion Prevention System and other solutions. Updated: September 2025.
870,701 professionals have used our research since 2012.