Try our new research platform with insights from 80,000+ expert users

Palo Alto Networks Advanced Threat Prevention vs Splunk User Behavior Analytics comparison

 

Comparison Buyer's Guide

Executive SummaryUpdated on Dec 19, 2024

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

ROI

Sentiment score
5.7
Palo Alto Networks Advanced Threat Prevention offers financial benefits and high user satisfaction despite its cost, boosting revenues, especially in Italy.
Sentiment score
5.5
Users report varied ROI from Splunk, with productivity gains and security cost savings, but costs remain a concern.
It offers insights into security threats, despite the inability to quantify its impact in numbers.
The solution can save costs by improving incident resolution times and reducing security incident costs.
 

Customer Service

Sentiment score
5.9
Palo Alto Networks' support is praised for expertise but faces inconsistent response times and communication challenges with third-party facilitation.
Sentiment score
6.9
Splunk User Behavior Analytics support is mostly praised, with professional service, tiered options, and valuable user groups enhancing experience.
Overall, I find the technical support from Palo Alto Networks quite good, although getting a hold of the TAC can be challenging and sometimes requires long phone calls.
I have proof of this rating - when I escalate a case, I receive a reply from TAC support after two days.
I rate technical support from Palo Alto as eight out of ten.
Mission-critical offering a dedicated team, proactive monitoring, and fast resolution.
From the responsiveness perspective, Splunk is very responsive with SLA-bound support for premium tiers.
Splunk's technical support is amazing.
 

Scalability Issues

Sentiment score
7.7
Palo Alto Networks Advanced Threat Prevention is scalable, adaptable, and efficient, though cost may constrain its broad deployment.
Sentiment score
7.2
Splunk User Behavior Analytics is scalable and adaptable across environments, though storage limitations may affect scalability.
Palo Alto Networks Advanced Threat Prevention is scalable and works well wherever enforcement points exist.
Splunk User Behavior Analytics is highly scalable, designed for enterprise scalability, allowing expansion of data ingestion, indexing, and search capabilities as log volumes grow.
 

Stability Issues

Sentiment score
7.7
Palo Alto Networks Advanced Threat Prevention is praised for its superior stability and performance, though requires careful version selection.
Sentiment score
7.8
Splunk User Behavior Analytics offers reliable performance and stability, with 99.9% uptime and ease of configuration in enterprises.
Proper sizing of the firewall models ensures that the system does not experience crippling performance issues.
With built-in redundancy across zones and regions, 99.9% uptime is achievable.
Splunk User Behavior Analytics is a one hundred percent stable solution.
Splunk User Behavior Analytics is highly stable and reliable, even in large-scale enterprise environments with high log injection rates.
 

Room For Improvement

Palo Alto Networks needs improvements in email filtering, setup ease, user experience, support services, and enhanced security features.
Splunk User Behavior Analytics needs better pricing, integration, user-friendly interfaces, enhanced features, and improved scalability and infrastructure.
Palo Alto needs to focus on how to bring that technology to end users and how easy it is to use, especially in a hybrid environment where users work from various locations.
The behavioral detection capabilities could be expanded to address all threats at the perimeter, reducing the reliance on endpoint detection and response systems.
Global reach allows deployment of apps and services closer to users worldwide, but data sovereignty concerns exist and region selection must align with compliance requirements.
I encountered several issues while trying to create solutions for this advanced version, which seem unrelated to query or data issues.
High data ingestion costs can be an issue, especially for large enterprises, as Splunk charges based on the amount of data processed.
 

Setup Cost

Palo Alto Networks Advanced Threat Prevention is costly but valued for strong threat detection, with pricing challenging for smaller businesses.
Enterprise buyers find Splunk's User Behavior Analytics costly, with variable pricing based on data, hardware, and additional applications.
Palo Alto Networks Advanced Threat Prevention requires an add-on license and is considered expensive compared to competitors like Cisco AMP and FortiGate firewalls.
Reserved instances with one or three-year commitments offer lower rates, providing up to 70% savings.
Comparing with the competitors, it's a bit expensive.
The pricing is based on the amount of data processed, and it is considered a high-level investment for enterprises.
 

Valuable Features

Palo Alto Networks excels in threat prevention with features like sandboxing, machine learning, and user-friendly design, enhancing efficiency.
Splunk User Behavior Analytics provides scalable, user-friendly threat detection with advanced analytics, machine learning, and seamless data integration and reporting.
As traditional signature-based mechanisms become less effective due to the evolving nature of attacks, this solution's focus on behavioral analysis is crucial.
We are satisfied with the analytic capabilities of Palo Alto Networks Advanced Threat Prevention, especially the reporting features available in the Palo Alto portal in terms of their application visibility interface, which is very good for us to get visibility on all critical applications and the associated users, as well as the risks associated with every category of traffic.
I also utilize it for anomaly detection and behavior analysis, particularly using Splunk's machine learning environment.
The best features in Splunk User Behavior Analytics include anomaly detection, behavioral profiling, and risk scoring and prioritization functionality.
It correlates all the historical data, compares the upcoming behavior with what's already stored in the platform, and reduces false positives.
 

Categories and Ranking

Palo Alto Networks Advanced...
Ranking in Intrusion Detection and Prevention Software (IDPS)
5th
Average Rating
8.4
Reviews Sentiment
6.6
Number of Reviews
29
Ranking in other categories
No ranking in other categories
Splunk User Behavior Analytics
Ranking in Intrusion Detection and Prevention Software (IDPS)
15th
Average Rating
8.2
Reviews Sentiment
6.7
Number of Reviews
24
Ranking in other categories
User Entity Behavior Analytics (UEBA) (4th)
 

Mindshare comparison

As of September 2025, in the Intrusion Detection and Prevention Software (IDPS) category, the mindshare of Palo Alto Networks Advanced Threat Prevention is 7.4%, down from 7.6% compared to the previous year. The mindshare of Splunk User Behavior Analytics is 2.4%, up from 2.3% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Intrusion Detection and Prevention Software (IDPS) Market Share Distribution
ProductMarket Share (%)
Palo Alto Networks Advanced Threat Prevention7.4%
Splunk User Behavior Analytics2.4%
Other90.2%
Intrusion Detection and Prevention Software (IDPS)
 

Featured Reviews

Partha Dash - PeerSpot reviewer
Advanced protection enables us to confidently secure against evolving threats
Palo Alto Networks can improve Advanced Threat Prevention by catering to the growing adoption of AI and agentic tooling. The Threat Protection modules should have the necessary intelligence to protect against those types of threats, as AI will be there to do a human job; this is an evolving area. From an Advanced Threat Protection perspective, the technology associated with Palo Alto Networks, such as their sandboxing environment, is quite good. However, Palo Alto needs to focus on how to bring that technology to end users and how easy it is to use, especially in a hybrid environment where users work from various locations. While Palo Alto excels in certain setups, they need to improve the user experience in distributed working conditions.
Subhayu Chakraborty - PeerSpot reviewer
Automatic reports streamline tasks and offers easy report gathering
The dashboard part could be improved. While using it, I noticed two options: Classic, which is adequate yet only in black and white, and another one that is more advanced or smart, though I forgot the exact term. I encountered several issues while trying to create solutions for this advanced version, which seem unrelated to query or data issues.
report
Use our free recommendation engine to learn which Intrusion Detection and Prevention Software (IDPS) solutions are best for your needs.
867,370 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Computer Software Company
13%
Manufacturing Company
9%
Financial Services Firm
9%
Government
8%
Computer Software Company
17%
Financial Services Firm
10%
Government
8%
Manufacturing Company
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business8
Midsize Enterprise4
Large Enterprise15
By reviewers
Company SizeCount
Small Business7
Midsize Enterprise5
Large Enterprise12
 

Questions from the Community

Which is the best DDoS protection solution for a big ISP for monitoring and mitigating?
Arbor would be the best bid, apart from Arbor, Palo Alto and Fortinet have good solutions. As this is an ISP, I would prefer Arbor.
What is your experience regarding pricing and costs for Palo Alto Networks Threat Prevention?
Palo Alto Networks Advanced Threat Prevention requires an add-on license and is considered expensive compared to competitors like Cisco AMP and FortiGate ( /products/fortinet-fortigate-reviews ) fi...
What do you like most about Splunk User Behavior Analytics?
The solution's most valuable feature is Splunk queries, which allow us to query the logs and analyze the attack vectors.
What is your experience regarding pricing and costs for Splunk User Behavior Analytics?
In terms of setup cost, pricing, and licensing, Splunk User Behavior Analytics is not an inexpensive product. The setup requires numerous components including storage, networking, identity access, ...
What needs improvement with Splunk User Behavior Analytics?
There are improvements that could be made to Splunk User Behavior Analytics as any product will have advantages and disadvantages. Scalability is one consideration. For example, the advantages incl...
 

Also Known As

No data available
Caspida, Splunk UBA
 

Overview

 

Sample Customers

University of Arkansas, JBG SMITH, SkiStar AB, TRI-AD, Temple University, Telkom Indonesia
8 Securities, AAA Western, AdvancedMD, Amaya, Cerner Corporation, CJ O Shopping, CloudShare, Crossroads Foundation, 7-Eleven Indonesia
Find out what your peers are saying about Palo Alto Networks Advanced Threat Prevention vs. Splunk User Behavior Analytics and other solutions. Updated: September 2025.
867,370 professionals have used our research since 2012.