Try our new research platform with insights from 80,000+ expert users

Check Point IPS vs Splunk User Behavior Analytics comparison

 

Comparison Buyer's Guide

Executive SummaryUpdated on Dec 19, 2024

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Check Point IPS
Ranking in Intrusion Detection and Prevention Software (IDPS)
3rd
Average Rating
8.6
Reviews Sentiment
7.2
Number of Reviews
51
Ranking in other categories
No ranking in other categories
Splunk User Behavior Analytics
Ranking in Intrusion Detection and Prevention Software (IDPS)
14th
Average Rating
8.2
Reviews Sentiment
6.5
Number of Reviews
20
Ranking in other categories
User Entity Behavior Analytics (UEBA) (4th)
 

Mindshare comparison

As of January 2025, in the Intrusion Detection and Prevention Software (IDPS) category, the mindshare of Check Point IPS is 6.3%, down from 10.5% compared to the previous year. The mindshare of Splunk User Behavior Analytics is 2.2%, down from 3.2% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Intrusion Detection and Prevention Software (IDPS)
 

Featured Reviews

Greg Tate - PeerSpot reviewer
Great for detection and access with the capabilities of defining specific rules
Support is the biggest area for improvement. Check Point is responsive, however, their support agents seem to be very siloed in their ability and/or product knowledge. It takes time and escalation to get through most tickets as they are passed from one group to another and then back again. We are able to navigate our support issues with the aid of our account team, so I want to underscore that support is indeed responsive. However, the processes support techs have to follow seem to be the root cause of the support response issues.
AnupChapalgaonkar - PeerSpot reviewer
Efficient behavior analysis with potential for improved reporting
I use Splunk User Behavior Analytics for SAML authentication, behavior analysis, and integration purposes. Integration allows me to identify version controls in CRM systems and analyze remote users. Additionally, I use it for streaming and machine learning kit integration, focusing on behavior…

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"The most valuable feature is that it protects us against hundreds of different attack vectors, like ransomware. The protection is always being triggered. People try to access websites that are categorized as malware, so when the users do a DNS request for the IP of those malware websites, the IPS Blade replaces the real IP of the website that is malware with a bogus IP. The user gets an IP that doesn't exist and when he tries to access, it won't work."
"Check Point is one of the best security brands worldwide."
"Behavior analytics and monitoring capabilities of Check Point IPS are valuable, especially for cybersecurity purposes."
"Some of the features for views and visualization are already predefined as default files."
"I can generate reports for management automatically based on the threats of the last day/week/whatever is needed."
"The solution is user-friendly and the interface is easy to configure."
"Check Point helps reduce downtime and costs associated with detected cyberattacks and can block those threats to ensure protection from any significant damage that may be caused within the organization."
"The Check Point IPS feature I find the most valuable is the firewall. It is great and easy to work with."
"It is a solution that helps test and measure customer satisfaction."
"It's straightforward in terms of configuration and troubleshooting and log management and monitoring as well. These are the edge points in addition to it being a modular solution where you can capitalize on your current licenses with extra licensing models, which can match the customer's business requirement and it can help the customer to design or to actually plan for their own roadmap."
"Splunk is more user-friendly than some competing solutions we tried."
"This intelligent user behavior analytics package is easy to configure and use while remaining feature filled."
"The most valuable features are the indexing and powerful search features."
"It's easily scalable."
"We are really pleased with Splunk and its features. It would be practically impossible to function without it. To provide a general overview of the system, it's important to note that the standard log files are currently around 250 gigabytes per day. It would be impossible to manually walk through these logs by hand, which is why automation is essential."
"Splunk User Behavior Analytics is a one hundred percent stable solution."
 

Cons

"Sometimes Check Point documentation is not always updated, which is why when some implementations change, it generates confusion about details."
"What I would like to improve in IPS would be the capacity of the hardware. I would also like to be able to sort signatures by severity. This would greatly impact how well I can manage my environment."
"Some challenges might exist with integration depending on the environment."
"Sometimes protections are 'aggregated' into a single threat name when you look at the logs. I would prefer to see all protections named individually (for example, right now, 'web enforcement' is a category that contains several signatures)."
"We have a lot of false positives and the list of IPs are not up to date in terms of their location."
"The solution needs enhanced reporting. The reporting on Cisco Stealthwatch and Darktrace is much bigger. The visibility that they grant for the filtering capabilities over large infrastructures are far superior."
"The installation documentation has room for improvement."
"The only thing they could maybe improve is that we notice right away that the performance decreases when we enable the IPS, especially beyond the CPU and memory usage. If you want to enable the IPS and you have a lot of traffic, it can have an impact. The performance could be improved."
"In terms of improvements, advanced reporting could see enhancements as there are some issues with latency."
"Currently, a lot of network operations need improvement. We still need people to handle incidents. Our vision is to leverage status and convert it directly from the network devices. It would be ideal if we could take action using APIs and API code and remove manual processes."
"We'd like the ability to do custom searches."
"Enhancing the storage model that they are using is necessary."
"I'm not aware of any lacking features."
"We want to have an automated system for bot hunting that enables us to detect anomalies predictively based on historical data. It would be helpful if Splunk included process mining as an alternative option. We have a threat workflow, but it would be useful if we could supplement that with some process mining capabilities over time."
"The correlation engine should have persistent and definable rules."
"There are occasional bugs."
 

Pricing and Cost Advice

"The pricing for Check Point IPS is competitive and brings good value for the money."
"The price of this product should be reduced."
"I give the price of the solution a five out of ten."
"You can pay for Check Point IPS yearly, or you can go with a three-year license. There's no extra cost apart from the standard licensing fee."
"My company pays for the yearly licensing of Check Point IPS. It is a very expensive tool."
"There is a license needed to use the Check Point IPS which is not expensive. However, the Check Point IPS device is expensive."
"Enabling IPS does not require any additional license purchase from OEM, as it comes by default with the NGFW bundle."
"The tool's licensing model is good. The licensing costs are yearly. I rate it an eight out of ten."
"I hope we can increase the free license to be more than 5 gig a day. This would help people who want to introduce a POC or a demo license for the solution."
"The licensing costs is around 10,000 dollars."
"I am not aware of the price, but it is expensive."
"There are additional costs associated with the integrator."
"Pricing varies based on the packages you choose and the volume of your usage."
"My biggest complaint is the way they do pricing... You can never know the pricing for next year. Every single time you adjust to something new, the price goes up. It's impossible to truly budget for it. It goes up constantly."
report
Use our free recommendation engine to learn which Intrusion Detection and Prevention Software (IDPS) solutions are best for your needs.
831,265 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Computer Software Company
20%
Government
10%
Financial Services Firm
10%
Manufacturing Company
8%
Computer Software Company
15%
Financial Services Firm
13%
Government
9%
Manufacturing Company
8%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

What do you like most about Check Point IPS?
The most valuable feature of the solution is called tunneling. Tunneling is one of the major security features that hackers cannot penetrate through.
What is your experience regarding pricing and costs for Check Point IPS?
The price could be lower. It's always better for an end user when prices are reduced. The cost makes it difficult to implement in smaller companies.
What needs improvement with Check Point IPS?
Currently, the solution is good for my needs, so I don't have any particular improvements to recommend. However, a reduction in price would always be welcome.
What do you like most about Splunk User Behavior Analytics?
The solution's most valuable feature is Splunk queries, which allow us to query the logs and analyze the attack vectors.
What is your experience regarding pricing and costs for Splunk User Behavior Analytics?
Splunk is up to the mark in terms of pricing. However, I cannot provide specific comments on the pricing at the moment.
What needs improvement with Splunk User Behavior Analytics?
In terms of improvements, advanced reporting could see enhancements as there are some issues with latency. Additionally, there are challenges with configuration findings during lexical analysis.
 

Also Known As

Check Point Intrusion Prevention System
Caspida, Splunk UBA
 

Learn More

 

Overview

 

Sample Customers

Morton Salt, Medical Advocacy and Outreach, BH Telecom, Lightbeam Health Solutions, X by Orange, Cadence, Nihondentsu, Datastream Connexion, Good Sam, Omnyway, FIASA, Pacific Life, Banco del Pacifico, Control Southern, Xero, Centrify
8 Securities, AAA Western, AdvancedMD, Amaya, Cerner Corporation, CJ O Shopping, CloudShare, Crossroads Foundation, 7-Eleven Indonesia
Find out what your peers are saying about Check Point IPS vs. Splunk User Behavior Analytics and other solutions. Updated: January 2025.
831,265 professionals have used our research since 2012.