Try our new research platform with insights from 80,000+ expert users

Palo Alto Networks Advanced Threat Prevention vs Splunk User Behavior Analytics comparison

 

Comparison Buyer's Guide

Executive SummaryUpdated on Dec 19, 2024

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

ROI

Sentiment score
7.5
Palo Alto Networks Advanced Threat Prevention offers fast, comprehensive security, boosting user satisfaction and revenue despite high costs.
Sentiment score
6.4
Splunk User Behavior Analytics boosts productivity and savings, though ROI varies with implementation; users report improved incident resolution.
It offers insights into security threats, despite the inability to quantify its impact in numbers.
The solution can save costs by improving incident resolution times and reducing security incident costs.
 

Customer Service

Sentiment score
6.4
Palo Alto Networks' support is generally effective despite communication issues and regional differences, with most users rating it positively.
Sentiment score
6.8
Splunk User Behavior Analytics offers reliable customer support, although geographic limitations may require some users to utilize online forums.
I rate technical support from Palo Alto as eight out of ten.
Mission-critical offering a dedicated team, proactive monitoring, and fast resolution.
Splunk's technical support is amazing.
I would rate the support at eight, meaning there's some room for improvement.
 

Scalability Issues

Sentiment score
7.9
Palo Alto Networks Advanced Threat Prevention is highly scalable, adaptable across environments, but cost considerations may affect scalability.
Sentiment score
7.5
Splunk User Behavior Analytics offers scalable and versatile solutions for enterprises, adaptable to both on-premise and cloud environments.
Palo Alto Networks Advanced Threat Prevention is scalable and works well wherever enforcement points exist.
Splunk User Behavior Analytics is highly scalable, designed for enterprise scalability, allowing expansion of data ingestion, indexing, and search capabilities as log volumes grow.
 

Stability Issues

Sentiment score
7.9
Palo Alto Networks Advanced Threat Prevention is preferred for its stability, outperforming competitors, and requires proper firewall sizing.
Sentiment score
8.2
Splunk User Behavior Analytics is praised for stability, ease of use, and reliable performance, despite minor long-term data issues.
Proper sizing of the firewall models ensures that the system does not experience crippling performance issues.
Splunk User Behavior Analytics is a one hundred percent stable solution.
Splunk User Behavior Analytics is highly stable and reliable, even in large-scale enterprise environments with high log injection rates.
Sometimes issues occur when handling long-term data.
 

Room For Improvement

Palo Alto Networks needs improvements in email security, user support, and analytics, while addressing complexity, false positives, and integration.
Splunk User Behavior Analytics needs improved integration, automation, affordability, a better interface, and enhanced features for optimal user satisfaction.
The behavioral detection capabilities could be expanded to address all threats at the perimeter, reducing the reliance on endpoint detection and response systems.
I encountered several issues while trying to create solutions for this advanced version, which seem unrelated to query or data issues.
High data ingestion costs can be an issue, especially for large enterprises, as Splunk charges based on the amount of data processed.
Advanced reporting could see enhancements as there are some issues with latency.
 

Setup Cost

Palo Alto Networks Advanced Threat Prevention is costly yet valued for its features, particularly in threat detection and scalability.
Splunk User Behavior Analytics pricing is complex, influenced by data usage, licensing, and features, causing budgeting challenges.
Palo Alto Networks Advanced Threat Prevention requires an add-on license and is considered expensive compared to competitors like Cisco AMP and FortiGate firewalls.
Comparing with the competitors, it's a bit expensive.
The pricing is based on the amount of data processed, and it is considered a high-level investment for enterprises.
 

Valuable Features

Palo Alto Networks Advanced Threat Prevention provides intuitive threat prevention with machine learning, excellent reporting, and seamless integration with other tools.
Splunk User Behavior Analytics provides efficient data analysis, threat detection, and seamless integration, enhancing security with advanced analytics and automation.
As traditional signature-based mechanisms become less effective due to the evolving nature of attacks, this solution's focus on behavioral analysis is crucial.
I also utilize it for anomaly detection and behavior analysis, particularly using Splunk's machine learning environment.
It is highly scalable and stable, even in large-scale enterprise environments.
Features like alerts and auto report generation are valuable.
 

Categories and Ranking

Palo Alto Networks Advanced...
Ranking in Intrusion Detection and Prevention Software (IDPS)
6th
Average Rating
8.6
Reviews Sentiment
6.9
Number of Reviews
27
Ranking in other categories
No ranking in other categories
Splunk User Behavior Analytics
Ranking in Intrusion Detection and Prevention Software (IDPS)
11th
Average Rating
8.2
Reviews Sentiment
6.8
Number of Reviews
23
Ranking in other categories
User Entity Behavior Analytics (UEBA) (4th)
 

Mindshare comparison

As of May 2025, in the Intrusion Detection and Prevention Software (IDPS) category, the mindshare of Palo Alto Networks Advanced Threat Prevention is 7.4%, down from 8.0% compared to the previous year. The mindshare of Splunk User Behavior Analytics is 2.0%, down from 2.8% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Intrusion Detection and Prevention Software (IDPS)
 

Featured Reviews

Carlos Bracamonte - PeerSpot reviewer
Robust, reliable, simple to install and good technical support
We are attempting to improve the use of URL filtering beyond threat protection. I'm not sure what the remaining threat protection features are off the top of my head. But beyond that, we use URL filtering. We have three approved cases for using external dynamic lists that are stored in a bucket repository. Then, for each URL site that needs to be whitelisted, we add it to the external dynamic list in order to gain access to this email. I would like Wildfire to be implemented. We use the equivalent in Cisco is the integration policies. We have the Wildfire but we are not currently implementing it. We don't have the license to use it, but we are not currently implementing it until we present the use cases that the company gives some value to and they approve the use of it.
Subhayu Chakraborty - PeerSpot reviewer
Automatic reports streamline tasks and offers easy report gathering
The dashboard part could be improved. While using it, I noticed two options: Classic, which is adequate yet only in black and white, and another one that is more advanced or smart, though I forgot the exact term. I encountered several issues while trying to create solutions for this advanced version, which seem unrelated to query or data issues.
report
Use our free recommendation engine to learn which Intrusion Detection and Prevention Software (IDPS) solutions are best for your needs.
850,760 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Computer Software Company
16%
Financial Services Firm
10%
Manufacturing Company
10%
Government
9%
Computer Software Company
17%
Financial Services Firm
12%
Government
9%
Manufacturing Company
8%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

Which is the best DDoS protection solution for a big ISP for monitoring and mitigating?
Arbor would be the best bid, apart from Arbor, Palo Alto and Fortinet have good solutions. As this is an ISP, I would prefer Arbor.
What is your experience regarding pricing and costs for Palo Alto Networks Threat Prevention?
The pricing is competitive, and with current campaigns and discounts, it provides an excellent device for a reasonable price.
What do you like most about Splunk User Behavior Analytics?
The solution's most valuable feature is Splunk queries, which allow us to query the logs and analyze the attack vectors.
What is your experience regarding pricing and costs for Splunk User Behavior Analytics?
The pricing is based on the amount of data processed, and it is considered a high-level investment for enterprises. Costs can be cut through efficient use and implementation.
What needs improvement with Splunk User Behavior Analytics?
High data ingestion costs can be an issue, especially for large enterprises, as Splunk charges based on the amount of data processed. Complex dashboards may require additional scripting. Some integ...
 

Also Known As

No data available
Caspida, Splunk UBA
 

Overview

 

Sample Customers

University of Arkansas, JBG SMITH, SkiStar AB, TRI-AD, Temple University, Telkom Indonesia
8 Securities, AAA Western, AdvancedMD, Amaya, Cerner Corporation, CJ O Shopping, CloudShare, Crossroads Foundation, 7-Eleven Indonesia
Find out what your peers are saying about Palo Alto Networks Advanced Threat Prevention vs. Splunk User Behavior Analytics and other solutions. Updated: April 2025.
850,760 professionals have used our research since 2012.