Try our new research platform with insights from 80,000+ expert users
reviewer1679841 - PeerSpot reviewer
Owner at a computer software company with 11-50 employees
Real User
Stable with good dashboards and a free demo version
Pros and Cons
  • "The solution appears to be stable, although we haven't used it heavily."
  • "I'm not aware of any lacking features."

What is our primary use case?

We do technical training and so we do training on the platform. We deploy it on our lab machines for students.

What is most valuable?

We're building some Splunk dashboards with it and it's useful.

We're currently monitoring students' log in, log out and verifying how they can collect the information. It's a good system for a learning environment. 

We're not specifically using it, we're doing training on it.

The solution appears to be stable, although we haven't used it heavily.

You can use the demo version in order to try the solution for free.

What needs improvement?

I'm not aware of any lacking features. 

For how long have I used the solution?

I've been using the solution for six years. 

Buyer's Guide
Splunk User Behavior Analytics
May 2025
Learn what your peers think about Splunk User Behavior Analytics. Get advice and tips from experienced pros sharing their opinions. Updated: May 2025.
856,873 professionals have used our research since 2012.

What do I think about the stability of the solution?

We don't generate enough data to know whether it's reliable or not.

That said, with the small usage that we do utilize, it's pretty stable.

How are customer service and support?

I've never dealt with technical support. I cannot rate their services or speak to how helpful or responsive they are.

Which solution did I use previously and why did I switch?

We did not previously use a different solution before choosing Splunk. 

How was the initial setup?

The initial setup is pretty straightforward. It's a couple of scripts you run. It's pretty easy.

What's my experience with pricing, setup cost, and licensing?

We simply use the free demo version of the product. We do not pay any licensing fees at this time. 

What other advice do I have?

We're just end-users. We don't have a business relationship with Splunk.

I'm not sure what version of the solution we are on currently. I believe it's about a year and a half or so old.

This product is the easiest way to check if the work's correct.

It works well. It does what we need it to. I'd rate it a ten out of ten.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
reviewer1418904 - PeerSpot reviewer
Global Engineer at a financial services firm with 10,001+ employees
Real User
Stable, with good automation capabilities, however, we want to be able to automate even more
Pros and Cons
  • "The product is at the forefront of auto-remediation networking. It's great."
  • "Currently, a lot of network operations need improvement. We still need people to handle incidents. Our vision is to leverage status and convert it directly from the network devices. It would be ideal if we could take action using APIs and API code and remove manual processes."

What is our primary use case?

We use the solution to feed telemetry data from the network into the collective for display-only. We haven't yet come to a point where we have decided on the process of the status for subsequent operational automation. 

What is most valuable?

The automation is very good.

The product is at the forefront of auto-remediation networking. It's great.

The pricing of the solution is very reasonable.

What needs improvement?

Currently, a lot of network operations need improvement. We still need people to handle incidents. Our vision is to leverage status and convert it directly from the network devices. It would be ideal if we could take action using APIs and API code and remove manual processes.  

For how long have I used the solution?

I've been using the solution for one year at this point.

What do I think about the stability of the solution?

The solution, from what I have witnessed, is stable. There aren't bugs or glitches. It doesn't crash or freeze. A company can rely on its performance.

What do I think about the scalability of the solution?

The scalability is pretty good. A company that wants to expand it out shouldn't have an issue doing so.

There's a handful of people on it at my organization. We have maybe ten users on it in total. They are mostly admins and engineers. We do have plans to continue to use the solution.

How are customer service and technical support?

Technical support has been adequate. We aren't blown away by amazing service, however, they do help if we need them to. I personally haven't had any direct contact with them.

Which solution did I use previously and why did I switch?

We didn't previously use a different product. We're rather new to automation and Splunk in general.

How was the initial setup?

The solution doesn't have a complex setup. It's rather straightforward. 

If you are talking of simply spinning off a container, it's very easy.

The complexity should be on the workflow. It's also the most time-consiuming process. For example, how do you handle this incident? It has to be very careful to ensure you don't have false positives that could mistakenly trigger actions. That can to be the most costly mistake. Other than that, a lot of products you can acquire from open source.

What about the implementation team?

There were a few of us that were tained specifically for the implementation. There were a number of us to speed up the process in order to get automation happening quickly for hte company. 

What's my experience with pricing, setup cost, and licensing?

The solution isn't overly expensive. It's quite affordable. It's not the priciest option on the market. I'm not sure of the exact cost as its not an aspect of the solution I directly deal with.

What other advice do I have?

We're simply customers. We don't have a business relationship with Splunk.

We're using the latest version of the solution. I'm not sure of the exact version number.

I'd recommend the solution to other companies.

On a scale from one to ten, I'd rate it at a seven. If the cost was more reasonable, I might rate it a bit higher. It's not too expensive, but it could always be better.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Buyer's Guide
Splunk User Behavior Analytics
May 2025
Learn what your peers think about Splunk User Behavior Analytics. Get advice and tips from experienced pros sharing their opinions. Updated: May 2025.
856,873 professionals have used our research since 2012.
Senior Security Engineer at a government with 1,001-5,000 employees
Real User
Easy to configure and easy to use solution that integrates with many applications and scripts
Pros and Cons
  • "This intelligent user behavior analytics package is easy to configure and use while remaining feature filled."
  • "The ability to do more complicated data investigation would be a welcome addition for pros, though the functionality now gives most people what they need."

What is our primary use case?

Our primary use is intrusion detection and analysis. It is a great product because it is intelligent and does everything for us.

How has it helped my organization?

It is a great product because it is intelligent and does everything for us. We have a LAN (Local Area Network) and sensitive, classified data and we have to be sure it is well-protected.

What is most valuable?

It's a component that is easy to configure and easy to use. They have familiar and friendly dashboards for the users. You can make a lot of the dashboards if you want to integrate with it. If you have the basic skills and basic codes you can just create more use cases. You can also have alert systems. You have a lot of different alerts that you can use. You can integrate with all the applications and scripts, like with Kaspersky. We integrate multiple publications with this product.

What needs improvement?

Actually, the most valuable aspect of Splunk is the data. You do not need to use your databases to perform all things from on all the servers we have. Splunk has three big things it can do with data: it can show it hot, warm and cold. The hot of it allows you to see the data as soon as things happen — maybe to the second. We have the warm, the warm will segment the data up to the hot up to three months ago. The cold will store all of the archives of all the data after the six months. After that, you can't make comparisons any further. 

In the future, we make Splunk in the SOC (Security Operations Center). In the SOC now, we use one feature, it's called the alert system. So in the future, we want to make it so we can send all the data and we can build its security and its management. It will be published in all the places as it is now. We need to do this so we can build more data centers from all the past and existing data crunch.

For how long have I used the solution?

We have been using the product for three years.

What do I think about the stability of the solution?

From the IP end and from ArchSight from HP, I think that Splunk works out very good for me. Not 100%, but 80%. IBM has a lot of features not familiar to the user and the support is very bad. ArcSight thas support, but they forget they have small issues. So, we use Splunk because it is the pinnacle of the organizations. We have specificity. We don't want any kind of application that can corrupt all our data. So we use the Splunk because we see more admirable organizations using it. So we share the knowledge with them.

What do I think about the scalability of the solution?

This solution is scalable depending on your need. The security department belongs to Splunk, so we have approximately 25 people using the system.

We have plans to increase usage soon.

How are customer service and technical support?

If you implement something with this product I think you need one-year technical support. But the first thing you need is your BUC (Business Use Case). The BUC allows you to know how much deploying the application costs and how many prerequisites you need to fulfill. After defining the BUC you will kick off the project, and after you have implemented, you have to purchase from the vendors one year of support. After that, they give you support until you are ready for the kick-off of the live project but have their support if something goes wrong.

Which solution did I use previously and why did I switch?

For SIEM (Security Information and Event Management), we used to use McAfee, and it was not good for us. And also we used ArcSight. But we also realized it could not do some things. After that, we networked and decided to use Splunk.

How was the initial setup?

It's good we are using the firewall and it's very good for Splunk. To implement the system depends in most cases your prerequisites. You have to know what you are building in the environment, how many servers you have, how many other devices, restrictions, and routing. It's a different environment depending on how many applications you have.

So the choices depend on what you need most of the time. We assigned a project manager for technical support for planning. I think it cost us six months to have it running. But it could be very different in other situations.

What's my experience with pricing, setup cost, and licensing?

There are a few things about the price. There are several packages but if you want to use it as an enterprise, you have to pay enterprise price. That is the initial price is for the basic enterprise application, but you get charges for volume use, not per user. Initially, we bought 100GB and now we bought 200GB.

Other applications you want to install for additional, integrated functionality costs more. For example, for Splunk they have two modules you need to use it optimally, I think. One is for applications. It's called Splunk Enterprise Security. After that, you will want to purchase another application called Defense. So it's more than one model for pricing. The more you use, the more you pay. It comes with unlimited users and volume discounts.

Which other solutions did I evaluate?

We worked with McAfee and ArcSight, but Splunk turned out to be better.

What other advice do I have?

From my experience and from the security perspective, I recommend this product for all the people that need good security for investigation. The Splunk team and products are good for those purposes.

The storage gets better priced with the amount you use. The storage is very expensive if you take some of the license options from the company. We won't be using unlimited storage for how much data will be imported from our bandwidth. I think the unlimited license is good because we will use a lot.

On a scale from one to ten when one is the worst and ten is the best, I would rate Splunk User Behavior as a nine. I didn't give them ten because Splunk does not provide something for the professional investigation. There is something that prevents you from using data the way you want to use data for in an investigation. Sometimes with Splunk, we cannot bring the data out in a better form and some users cannot understand it exactly. What I am talking about is options for a more professional investigation, not for normal behaviors. If you want to just look at normal behavior the program will give all you need. But sometimes you need other use cases to see the action.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Security PS Supervisor at a tech services company with 1,001-5,000 employees
Real User
A powerful platform with straightforward configuration, but needs to be more scalable
Pros and Cons
  • "It's straightforward in terms of configuration and troubleshooting and log management and monitoring as well. These are the edge points in addition to it being a modular solution where you can capitalize on your current licenses with extra licensing models, which can match the customer's business requirement and it can help the customer to design or to actually plan for their own roadmap."
  • "The solution is much more expensive than relative competitors like ArcSight or LogRhythm. It makes it hard to sell to customers sometimes."

What is our primary use case?

The solution has two main uses. The primary use is for log management and storage. The secondary use is related to solution log coordination and selection.

What is most valuable?

Splunk is a very powerful platform. It's a machine data platform, and it can provide several models that use the same appliance and on the same platform, including some business platforms. I do believe when it comes to functionality and ease of use, Splunk is one of the market leaders in this area.

When it comes to quality, I believe Splunk is the easiest platform on the market. It has a lot of subscripts, and a lot of licenses, which can provide the customer with all the requirements they need.

The solution has some predefined use cases that we count on. It's a customizable platform as well, which can be easily customizable based on the customer requirements and the environment itself. 

It provides ease of use. It's straightforward in terms of configuration and troubleshooting and log management and monitoring as well. These are the edge points in addition to it being a modular solution where you can capitalize on your current licenses with extra licensing models, which can match the customer's business requirements. It can help the customer to design or to actually plan their own roadmap. And it can be rolled out in several phases.

What needs improvement?

The solution is much more expensive than relative competitors like ArcSight or LogRhythm. It makes it hard to sell to customers sometimes.

I would like to see a better tracking intelligence module with lower costs fully integrated with a user behavior analytics module. It would empower this module with the keys and real-time updates in terms of security.

For how long have I used the solution?

I've been using the solution for three years.

What do I think about the stability of the solution?

It's stable. I used to deal with other vendors in the UBA such as HP ArcSight, which is a bit more sophisticated and complicated in terms of configuration and in terms of monitoring. Splunk is much easier and very straightforward in terms of configuration and monitoring and customization as well.

What do I think about the scalability of the solution?

There is a question as to how to scale up, especially in the log management area. Customers have their own predefined retention period, which means storing the logs for a long time. It's usually a minimum of six months or in some cases, up to one year. So the scalability has a little bit a limitation or restriction in storage components.

How are customer service and technical support?

I'm not an end-user, so I'm not supposed to open any end-user cases. However, the team that receives requests from customers and end-users themselves feels comfortable with the level of support they get. They're being provided with answers from a strong technical support team. So I do believe that it's going good. I haven't heard anything about them suffering from any problem of latency or shortage of resources, or a lack of knowledge and so on. I think technical support is fine.

Which solution did I use previously and why did I switch?

I used to deal with several solutions, like HP or Micro Focus ArcSight, IBM Curator, and LogRhythm.

What's my experience with pricing, setup cost, and licensing?

The solution is relatively expensive. There are costs above the standard licensing as well.

Pricing varies according to the customer's needs and set up. Pricing depends on the licensing model and if the normal log management licensing model or the security plus license. It also depends on the licensing model and the platform required by the customer. It can further depend on if the customer owns a Splunk hardware platform, or if they can host these licenses and subscriptions on their own platform. It can vary depending on the OPEX model and CAPEX model as well. There are a lot of variables that encompass the total cost of the solution.

I believe that Splunk is about 50% more expensive than other solutions.

What other advice do I have?

I'm a system integrator, which provides the solution to end-users and customers.

We handle the on-premises deployment model.

I would recommend the solution because of the ease of use, the simple administration, the good level of support, the predefined use cases, and the predefined user behavior analytics.

I would rate the solution seven out of ten.

Disclosure: My company has a business relationship with this vendor other than being a customer: Reseller.
PeerSpot user
reviewer1276995 - PeerSpot reviewer
Sr. CyberSecurity Solutions Architect at a security firm with 11-50 employees
Real User
Good support, stable, and provides good security
Pros and Cons
  • "This is a good security product."
  • "The price of Splunk UBA is too high."

What is our primary use case?

We are a cybersecurity vendor and Splunk is the main product that we work with. We are predominantly a Splunk shop. We sell security solutions, so our primary use case for Splunk UBA is security.

What is most valuable?

This is a good security product.

What needs improvement?

The price of Splunk UBA is too high.

For how long have I used the solution?

I have been working with Splunk UBA at this company for the past year.

What do I think about the stability of the solution?

Everything that Splunk does is great, as far as stability.

What do I think about the scalability of the solution?

Scalability is excellent on all Splunk products that I've dealt with.

How are customer service and support?

The technical support is excellent.

What other advice do I have?

The biggest lesson that I have learned from working with this product is that it is priced high, and you can achieve much of what it does through other methods. That combination makes it hard to sell.

I would rate this solution a nine out of ten.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Head of cybersecurity at NOVARED SA
MSP
A fast and flexible solution for conducting analytics on large data sets
Pros and Cons
  • "The solution is fast, flexible, and easy to use."
  • "I would like improved downward integration with other tools such as McAfee and other GCP solutions."

What is our primary use case?

Four technicians in our company work within the active directory to look for compartmental behaviors associated with users and conduct analytics like clustering, grouping, and searching. 

What is most valuable?

The solution is fast, flexible, and easy to use. 

What needs improvement?

I would like improved downward integration with other tools such as McAfee and other GCP solutions. 

For how long have I used the solution?

I have been using the solution for four years. 

What do I think about the stability of the solution?

The solution is stable. 

What do I think about the scalability of the solution?

The solution is scalable. 

How are customer service and support?

Technical support is very good and answers my questions. 

How was the initial setup?

The initial setup is easy. 

What other advice do I have?

The solution works very well with large data sets. 

I rate the solution a ten out of ten. 

Which deployment model are you using for this solution?

On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
CISO at a financial services firm with 201-500 employees
Real User
Professional technical team but I would like to see a more user-friendly interface
Pros and Cons
  • "The solution is definitely scalable."
  • "In the future I would like to see simplified statistics and analytical threats."

What is our primary use case?

Our main use of this solution is threat intelligence and we are very satisfied with it, as it is exactly what we need in our situation. 

What needs improvement?

In the future I would like to see simplified statistics and analytical threats, as well as a more user-friendly interface for dashboards.

For how long have I used the solution?

I have been using Splunk User Behaviour Analytics for two years now.

What do I think about the stability of the solution?

I think the solution is very stable.

What do I think about the scalability of the solution?

The solution is definitely scalable, because we currently have 1000 users in our company and we plan to increase.

How are customer service and technical support?

I am really satisfied with their technical support. The technicians are very professional.

What's my experience with pricing, setup cost, and licensing?

The licensing costs is around 10,000 dollars.

What other advice do I have?

I will rate this product a seven out of ten, and I would definitely recommend it to others.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
reviewer890208 - PeerSpot reviewer
Information Security Specialist at a financial services firm with 201-500 employees
Real User
Has powerful search, indexing, and scalability features
Pros and Cons
  • "The most valuable features are the indexing and powerful search features."
  • "The correlation engine should have persistent and definable rules."

What is our primary use case?

Splunk has features that no other solutions have. We work in organizations that have a big volume of data. Our primary use case of this solution is for indexing. The best solution that we found that could fit our needs was Splunk.

What is most valuable?

The most valuable features are the indexing and powerful search features. 

What needs improvement?

The correlation engine should have persistent and definable rules. Splunk should have more features and options in regards to correlating in real-time. It should have the ability to set more permanent rules.  

Correlation capabilities in ArcSight are better than in Splunk. 

For how long have I used the solution?

I have been using Splunk for more than three years.

What do I think about the stability of the solution?

The stability is good. It's reliable and can be used in enterprise environments. 

What do I think about the scalability of the solution?

It is a scalable solution and can support many users. The scalability is another powerful feature of this solution.

We have around ten users using this solution in our company. We also provide this solution to our subsidiary companies so there are more than twenty users.

How are customer service and technical support?

We are in Iran and are under U.S. sanctions so we can only use online forums for support. We can't use their technical support. 

How was the initial setup?

The initial setup was easy. 

What about the implementation team?

We did the implementation in-house. 

What's my experience with pricing, setup cost, and licensing?

Our licensing costs are on a yearly basis. 

Which other solutions did I evaluate?

We researched many solutions before choosing Splunk like LogRhythm, ELK, and FortiSIEM.

What other advice do I have?

After more than three years of using this solution, I would recommend this solution, especially for environments that have a big volume of data. I would rate this solution a nine out of ten. It is a really great product. 

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Buyer's Guide
Download our free Splunk User Behavior Analytics Report and get advice and tips from experienced pros sharing their opinions.
Updated: May 2025
Buyer's Guide
Download our free Splunk User Behavior Analytics Report and get advice and tips from experienced pros sharing their opinions.