Lumu vs Splunk User Behavior Analytics comparison

 

Comparison Buyer's Guide

Executive Summary
 

Categories and Ranking

Lumu
Ranking in Intrusion Detection and Prevention Software (IDPS)
13th
Average Rating
9.6
Number of Reviews
6
Ranking in other categories
Network Detection and Response (NDR) (6th)
Splunk User Behavior Analytics
Ranking in Intrusion Detection and Prevention Software (IDPS)
12th
Average Rating
8.2
Number of Reviews
18
Ranking in other categories
User Entity Behavior Analytics (UEBA) (2nd)
 

Market share comparison

As of June 2024, in the Intrusion Detection and Prevention Software (IDPS) category, the market share of Lumu is 3.5% and it increased by 419.2% compared to the previous year. The market share of Splunk User Behavior Analytics is 1.1% and it decreased by 59.5% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Intrusion Detection and Prevention Software (IDPS)
Unique Categories:
Network Detection and Response (NDR)
6.1%
User Entity Behavior Analytics (UEBA)
13.1%
 

Featured Reviews

OH
May 29, 2024
Has significantly improved our threat detection
When we deployed Lumu, we saw the benefits immediately. We noticed threat detection within the first week. Threat detection is the most compelling feature of Lumu for enhancing our incident response. When we first deployed it, we had an older version of our firewall, which Lumu outperformed in detecting threats. Even after upgrading our firewall, Lumu's detection algorithms provided earlier alerts. Regarding the compromised assessment, Lumu has significantly improved our threat detection. Before Lumu, we manually blocked threats on the firewall, but Lumu's alerts have allowed us to make proactive adjustments. For the past three months, we've had no detections on our network as Lumu efficiently identified and blocked suspicious sites and potential phishing threats.
NS
Aug 18, 2019
Easy to configure and easy to use solution that integrates with many applications and scripts
Actually, the most valuable aspect of Splunk is the data. You do not need to use your databases to perform all things from on all the servers we have. Splunk has three big things it can do with data: it can show it hot, warm and cold. The hot of it allows you to see the data as soon as things happen — maybe to the second. We have the warm, the warm will segment the data up to the hot up to three months ago. The cold will store all of the archives of all the data after the six months. After that, you can't make comparisons any further. In the future, we make Splunk in the SOC (Security Operations Center). In the SOC now, we use one feature, it's called the alert system. So in the future, we want to make it so we can send all the data and we can build its security and its management. It will be published in all the places as it is now. We need to do this so we can build more data centers from all the past and existing data crunch.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"I like Lumu's simple user interface. When we deployed it, we got full access, allowing us to identify IP addresses on the network and connect machine names to users. It helped us identify and block threats via the firewall. I also appreciate the chat support and ticket closure process. We're currently reviewing network detection solutions, and my recommendations include Lumu, Sentinel, and a few others. Regarding functionality and user-friendliness, I would recommend Lumu over the others."
"Most of it is automated, so I do not have to watch it to get alerts."
"The context provided by the tool is very complete, it includes the miter matrix, playbooks, links, hashes, and much more."
"You can access external links, playbooks, MITRE Matrix, and a lot of information."
"It's been helpful for overall extended network visibility."
"Lumu protects against threats immediately and handles them in time."
"The most valuable feature is the ability to search through a large amount of data."
"It's easily scalable."
"The most valuable feature is being able to take data and put it into other systems so that we could see the output, and to see where we need to apply our focus."
"It is a solution that helps test and measure customer satisfaction."
"This intelligent user behavior analytics package is easy to configure and use while remaining feature filled."
"The solution is definitely scalable."
"The solution is extremely scalable. Our customers are regularly scaling up after installing Splunk."
"It's straightforward in terms of configuration and troubleshooting and log management and monitoring as well. These are the edge points in addition to it being a modular solution where you can capitalize on your current licenses with extra licensing models, which can match the customer's business requirement and it can help the customer to design or to actually plan for their own roadmap."
 

Cons

"The free version is minimal compared to the full version."
"The reports need improvement."
"It would be good if we could access the physical logs."
"I am happy with the current features. However, one important one is to improve the reports."
"The integration with different vendors and endpoints could be improved."
"Nothing so far needs to be improved."
"They should work to add more built-in correlation searches and more use cases based on worldwide customer experiences. They need more ready-made use cases."
"Currently, a lot of network operations need improvement. We still need people to handle incidents. Our vision is to leverage status and convert it directly from the network devices. It would be ideal if we could take action using APIs and API code and remove manual processes."
"In the future I would like to see simplified statistics and analytical threats."
"I'm not aware of any lacking features."
"We want to have an automated system for bot hunting that enables us to detect anomalies predictively based on historical data. It would be helpful if Splunk included process mining as an alternative option. We have a threat workflow, but it would be useful if we could supplement that with some process mining capabilities over time."
"It could be easier to scale the solution if you are using it on-premise, not in the cloud."
"The solution is much more expensive than relative competitors like ArcSight or LogRhythm. It makes it hard to sell to customers sometimes."
"There are occasional bugs."
 

Pricing and Cost Advice

"It is the cheapest solution we found."
"Compared to Lumu, other solutions are more expensive. SentinelOne was a bit cheaper, and another provider's price structure is unclear, but Lumu fit our budget nicely. SentinelOne's cost depends on the number of devices, and it might be similar to Lumu's, depending on deployment."
"There are additional costs associated with the integrator."
"I am not aware of the price, but it is expensive."
"I hope we can increase the free license to be more than 5 gig a day. This would help people who want to introduce a POC or a demo license for the solution."
"My biggest complaint is the way they do pricing... You can never know the pricing for next year. Every single time you adjust to something new, the price goes up. It's impossible to truly budget for it. It goes up constantly."
"The licensing costs is around 10,000 dollars."
"Pricing varies based on the packages you choose and the volume of your usage."
report
Use our free recommendation engine to learn which Intrusion Detection and Prevention Software (IDPS) solutions are best for your needs.
787,061 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Wholesaler/Distributor
20%
Educational Organization
13%
Comms Service Provider
10%
Government
9%
Computer Software Company
15%
Financial Services Firm
14%
Government
10%
Manufacturing Company
8%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

What do you like most about Lumu?
Lumu protects against threats immediately and handles them in time.
What needs improvement with Lumu?
The integration with different vendors and endpoints could be improved. The reports are not so extensive, but they could be better.
What is your primary use case for Lumu?
When Lumu sends us a report that something is unsound, we respond to it. Some of the things we have are automated, and some are not.
What do you like most about Splunk User Behavior Analytics?
The solution's most valuable feature is Splunk queries, which allow us to query the logs and analyze the attack vectors.
What is your experience regarding pricing and costs for Splunk User Behavior Analytics?
I am not aware of the price, but it is expensive. A rough estimate would be around 150 gigabytes, given the huge amount of data. At the moment there are no additional costs for maintenance.
What needs improvement with Splunk User Behavior Analytics?
Sometimes, we need to write explicit queries. It would be good if the solution had an analytics tool that allowed us to analyze the data without writing specific queries. The solution's user interf...
 

Also Known As

No data available
Caspida, Splunk UBA
 

Learn More

Video not available
 

Overview

 

Sample Customers

Information Not Available
8 Securities, AAA Western, AdvancedMD, Amaya, Cerner Corporation, CJ O Shopping, CloudShare, Crossroads Foundation, 7-Eleven Indonesia
Find out what your peers are saying about Lumu vs. Splunk User Behavior Analytics and other solutions. Updated: May 2024.
787,061 professionals have used our research since 2012.