Try our new research platform with insights from 80,000+ expert users

Splunk User Behavior Analytics vs Trend Micro Deep Discovery comparison

 

Comparison Buyer's Guide

Executive SummaryUpdated on Dec 19, 2024

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

ROI

Sentiment score
5.5
Users report varied ROI from Splunk UBA, emphasizing productivity gains, time savings, and improved incident resolution efficiency.
Sentiment score
6.7
Trend Micro Deep Discovery enhances threat visibility and detection, effectively preventing substantial losses from ransomware, spam, and phishing.
The solution can save costs by improving incident resolution times and reducing security incident costs.
Enterprise Architect at Wipro Limited
 

Customer Service

Sentiment score
6.9
Splunk User Behavior Analytics support is praised for its professionalism, extensive knowledge base, and prompt, reliable assistance despite regional limitations.
Sentiment score
6.6
Trend Micro Deep Discovery support is praised for responsiveness and effectiveness, with some users noting a need for quicker responses.
Mission-critical offering a dedicated team, proactive monitoring, and fast resolution.
Enterprise Architect at Wipro Limited
From the responsiveness perspective, Splunk is very responsive with SLA-bound support for premium tiers.
Enterprise Architect at Wipro Limited
I would rate their technical support as 8.5 out of 10.
Director at Techpace
If I were to rate them from 0 to 10, I would give them a nine or a ten.
Senior IT Security Engineer at a financial services firm with 5,001-10,000 employees
 

Scalability Issues

Sentiment score
7.2
Splunk User Behavior Analytics excels in scalable deployment, flexible expansion, and efficient data handling, overcoming on-premises storage challenges.
Sentiment score
7.4
Trend Micro Deep Discovery is scalable but may face limitations due to network design, integration costs, and organizational needs.
Splunk User Behavior Analytics is highly scalable, designed for enterprise scalability, allowing expansion of data ingestion, indexing, and search capabilities as log volumes grow.
Enterprise Architect at Wipro Limited
If the appliance supports scalability, Trend Micro support will inform us, and we can implement it without replacing the hardware.
Senior IT Security Engineer at a financial services firm with 5,001-10,000 employees
 

Stability Issues

Sentiment score
7.8
Splunk User Behavior Analytics is stable, reliable, easy to configure, and effective, achieving 99.9% uptime with proper deployment.
Sentiment score
8.3
Trend Micro Deep Discovery is praised for stability and performance, with users appreciating its threat intelligence and consistent updates.
With built-in redundancy across zones and regions, 99.9% uptime is achievable.
Enterprise Architect at Wipro Limited
Splunk User Behavior Analytics is a one hundred percent stable solution.
Cloud Solution Architect at Tech Mahindra Limited
Splunk User Behavior Analytics is highly stable and reliable, even in large-scale enterprise environments with high log injection rates.
Enterprise Architect at Wipro Limited
The product updates and security updates are kept current, allowing us seamless integration with Trend Micro and getting daily updates and signatures without problems.
Senior IT Security Engineer at a financial services firm with 5,001-10,000 employees
 

Room For Improvement

Splunk User Behavior Analytics needs better pricing, integration, automation, and machine learning to enhance functionality and user experience.
Trend Micro Deep Discovery needs better integration, user-friendliness, scalability, pricing, support, speed, and IT infrastructure compatibility.
Global reach allows deployment of apps and services closer to users worldwide, but data sovereignty concerns exist and region selection must align with compliance requirements.
Enterprise Architect at Wipro Limited
I encountered several issues while trying to create solutions for this advanced version, which seem unrelated to query or data issues.
System Engineer at Infosys
High data ingestion costs can be an issue, especially for large enterprises, as Splunk charges based on the amount of data processed.
Enterprise Architect at Wipro Limited
We have multiple components such as Deep Discovery Email Inspector for mail gateways, Deep Discovery Analyzer for sandboxing, and Deep Discovery Inspector, which serves as an IDS detecting malicious network traffic.
Senior IT Security Engineer at a financial services firm with 5,001-10,000 employees
The solution is not scalable as it is an agent product rather than a product designed for scalability.
Owner at Darcom
 

Setup Cost

Splunk User Behavior Analytics pricing is perceived as complex and expensive, influenced by data volume, licensing, and integration needs.
Trend Micro Deep Discovery pricing varies with requirements, seen as reasonable for advanced features but higher than standard antivirus.
Reserved instances with one or three-year commitments offer lower rates, providing up to 70% savings.
Enterprise Architect at Wipro Limited
Compared to all other products in the market, it is the most expensive one in all aspects including professional service and licenses, even the cloud version.
Director at Techpace
Comparing with the competitors, it's a bit expensive.
Regional Director at iSecureMind
I do not consider it an expensive tool; its price is justified based on the capabilities that we receive when compared to another mail gateway or other vendors.
Senior IT Security Engineer at a financial services firm with 5,001-10,000 employees
The solution is very expensive.
Owner at Darcom
 

Valuable Features

Splunk User Behavior Analytics offers advanced threat detection, real-time data collection, and customizable dashboards for enhanced monitoring and decision-making.
Trend Micro Deep Discovery provides intuitive installation, strong threat detection, and comprehensive visibility, enhancing security across multiple platforms with responsive support.
I also utilize it for anomaly detection and behavior analysis, particularly using Splunk's machine learning environment.
Cloud Solution Architect at Tech Mahindra Limited
The dashboards themselves are nice, very good, and very helpful, but the accuracy of the data or the information that will be presented on the dashboard is something that needs to be questioned.
Director at Techpace
Features like alerts and auto report generation are valuable.
System Engineer at Infosys
The most valuable capabilities of Trend Micro Deep Discovery Email Inspector include its ability to perform mail detection and mail filtration against various email attacks such as phishing and spam, serving as an email gateway for both inbound and outbound traffic.
Senior IT Security Engineer at a financial services firm with 5,001-10,000 employees
This solution allows us to see anomalies, network traffic in our network, and zero-day threats.
Owner at Darcom
 

Categories and Ranking

Splunk User Behavior Analytics
Ranking in Intrusion Detection and Prevention Software (IDPS)
13th
Average Rating
8.2
Reviews Sentiment
6.6
Number of Reviews
25
Ranking in other categories
User Entity Behavior Analytics (UEBA) (5th)
Trend Micro Deep Discovery
Ranking in Intrusion Detection and Prevention Software (IDPS)
7th
Average Rating
8.4
Reviews Sentiment
6.9
Number of Reviews
28
Ranking in other categories
Advanced Threat Protection (ATP) (17th), Network Detection and Response (NDR) (8th)
 

Mindshare comparison

As of December 2025, in the Intrusion Detection and Prevention Software (IDPS) category, the mindshare of Splunk User Behavior Analytics is 2.0%, up from 1.6% compared to the previous year. The mindshare of Trend Micro Deep Discovery is 3.7%, down from 4.8% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Intrusion Detection and Prevention Software (IDPS) Market Share Distribution
ProductMarket Share (%)
Trend Micro Deep Discovery3.7%
Splunk User Behavior Analytics2.0%
Other94.3%
Intrusion Detection and Prevention Software (IDPS)
 

Featured Reviews

SK
Enterprise Architect at Wipro Limited
Offers intuitive deployment with strong customer support and advanced analytics features
There are improvements that could be made to Splunk User Behavior Analytics as any product will have advantages and disadvantages. Scalability is one consideration. For example, the advantages include rapid auto scaling to meet demand. A disadvantage is that it can lead to cost overrun if not properly factored or governed. The speed of deployment offers faster provisioning as an advantage, but it can require substantial automation skills and infrastructure as code expertise, which can be challenging. Cloud provides major operational benefits such as agility, automation, resilience, and global access when setting up on Cloud. However, it introduces challenges such as cost control, complexity, and vendor dependency. For example, global reach allows deployment of apps and services closer to users worldwide, but data sovereignty concerns exist and region selection must align with compliance requirements.
reviewer2266119 - PeerSpot reviewer
Senior IT Security Engineer at a financial services firm with 5,001-10,000 employees
Has improved email security through advanced filtration and timely threat detection
I work with Trend Micro Apex One. I have used the Deep Discovery's Sandbox analysis feature, and we utilize another appliance known as Deep Discovery Analyzer, abbreviated as DDA. This tool makes analysis for URLs and attachments contained in inbound emails, so whenever we receive an email with a URL or attachment, it will be analyzed by Trend Micro Deep Discovery Analyzer. In evaluating Deep Discovery's real-time visibility on network traffic, it is important to note that we applied our Deep Discovery Analyzer for Trend Micro to conduct sandboxing specifically for email channels only, and we do not utilize it for network channels. For network channel sandboxing, we use a solution called FortiAnalyzer, which belongs to another team called network security. I assess Deep Discovery's effectiveness in identifying sophisticated attack patterns by looking at how it handles high traffic loads, and how effectively it can use its instances and images to analyze numerous URLs and attachments simultaneously. Additionally, I evaluate its ability to maintain round-robin or load balancing across different analyses without leaving samples queued for analysis. The performance is critical when the product updates for signatures are up-to-date, as this aids in the detection and classification of URLs and attachments without delay in the analysis process. On a scale of one to ten, I rate Trend Micro Deep Discovery a nine.
report
Use our free recommendation engine to learn which Intrusion Detection and Prevention Software (IDPS) solutions are best for your needs.
879,259 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Computer Software Company
19%
Financial Services Firm
9%
Government
8%
Educational Organization
7%
Computer Software Company
12%
Financial Services Firm
8%
Healthcare Company
7%
Manufacturing Company
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business7
Midsize Enterprise5
Large Enterprise12
By reviewers
Company SizeCount
Small Business15
Midsize Enterprise6
Large Enterprise9
 

Questions from the Community

What do you like most about Splunk User Behavior Analytics?
The solution's most valuable feature is Splunk queries, which allow us to query the logs and analyze the attack vectors.
What is your experience regarding pricing and costs for Splunk User Behavior Analytics?
Splunk User Behavior Analytics is a premium product. Compared to all other products in the market, it is the most expensive one in all aspects including professional service and licenses, even the ...
What needs improvement with Splunk User Behavior Analytics?
Splunk User Behavior Analytics is still an immature product, so it still needs some R&D to be able to be mature in the market. The prediction, algorithms, and ML codes behind Splunk User Behavi...
What do you like most about Trend Micro Deep Discovery?
The tool's most valuable feature is its collaboration with other products. Integrating with other security products was simple and easy.
What needs improvement with Trend Micro Deep Discovery?
Server Protect is not commonly used. When considering the Sandbox feature, it only inspects small files, and not all types of files are supported. The solution is very expensive. The solution is no...
 

Also Known As

Caspida, Splunk UBA
Trend Micro Deep Discovery Inspector, Trend Micro Deep Discovery Analyzer
 

Overview

 

Sample Customers

8 Securities, AAA Western, AdvancedMD, Amaya, Cerner Corporation, CJ O Shopping, CloudShare, Crossroads Foundation, 7-Eleven Indonesia
Allied Telesis, Atma Jaya Catholic University of Indonesia, Babou, Blekinge County Council, Delacour, Hiroshima Prefectural Government, Live Nation Entertainment Inc., Mazda Motor Logistics Europe, McGill University Health Centre, Mikuni Corporation, OKWAVE, Sinar Mas Land, SWICA, UTOC Corporation
Find out what your peers are saying about Splunk User Behavior Analytics vs. Trend Micro Deep Discovery and other solutions. Updated: December 2025.
879,259 professionals have used our research since 2012.