Try our new research platform with insights from 80,000+ expert users

Cisco Secure Network Analytics vs Darktrace vs Splunk User Behavior Analytics comparison

 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

ROI

Sentiment score
8.0
Cisco Secure Network Analytics boosts incident detection and recovery, offering cost savings and labor efficiency for enhanced security.
Sentiment score
7.3
Darktrace's threat prevention boosts security, saves costs, and offers significant value, especially for online businesses, despite quantification challenges.
Sentiment score
6.4
Splunk User Behavior Analytics boosts productivity and savings, though ROI varies with implementation; users report improved incident resolution.
Using this solution provides financial benefits by securing from server attacks, which offers indirect savings.
The solution can save costs by improving incident resolution times and reducing security incident costs.
 

Customer Service

Sentiment score
7.3
Cisco Secure Network Analytics support is praised for technical expertise and responsiveness, despite occasional local support challenges and delays.
Sentiment score
7.6
Darktrace support is praised for its responsive and efficient service, though a few cite improvement areas for complex issues.
Sentiment score
6.8
Splunk User Behavior Analytics offers reliable customer support, although geographic limitations may require some users to utilize online forums.
There is a lack of adequate local support from the Indian side.
Darktrace provides excellent technical support with a monthly meeting to review platform incidents, ensuring the system functions as expected.
The technical support from Darktrace is of high quality.
The response time and quality are satisfactory.
Mission-critical offering a dedicated team, proactive monitoring, and fast resolution.
Splunk's technical support is amazing.
I would rate the support at eight, meaning there's some room for improvement.
 

Scalability Issues

Sentiment score
6.5
Cisco Secure Network Analytics excels in scalability and adaptability, though it can be costly and challenging in data management.
Sentiment score
7.6
Darktrace is praised for its scalability, efficiently managing large networks with flexible deployment despite cost concerns, excelling in diverse environments.
Sentiment score
7.5
Splunk User Behavior Analytics offers scalable and versatile solutions for enterprises, adaptable to both on-premise and cloud environments.
Since it's cloud-based, it expands easily.
Darktrace has high scalability, and I would rate it a nine out of ten.
Splunk User Behavior Analytics is highly scalable, designed for enterprise scalability, allowing expansion of data ingestion, indexing, and search capabilities as log volumes grow.
 

Stability Issues

Sentiment score
8.4
Cisco Secure Network Analytics is stable, reliable under complex conditions, but users seek less Java and better product integration.
Sentiment score
8.5
Darktrace is highly stable, with users rating it 8-10, citing reliability despite rare minor issues like human error.
Sentiment score
8.2
Splunk User Behavior Analytics is praised for stability, ease of use, and reliable performance, despite minor long-term data issues.
Cisco products are incredibly stable, boasting a 200% stability.
The stability of Darktrace is excellent, rated ten out of ten.
Splunk User Behavior Analytics is a one hundred percent stable solution.
Splunk User Behavior Analytics is highly stable and reliable, even in large-scale enterprise environments with high log injection rates.
Sometimes issues occur when handling long-term data.
 

Room For Improvement

Cisco Secure Network Analytics needs enhanced usability, integration, filtering, AI, reporting, training, cost-efficiency, and endpoint management for better security.
Darktrace needs better integration, a simpler interface, automation enhancements, flexible pricing, improved documentation, and expanded notifications.
Splunk User Behavior Analytics needs improved integration, automation, affordability, a better interface, and enhanced features for optimal user satisfaction.
The solution should have the ability to analyze security events not only at the network layer but also at the application and OS layers.
There is no dedicated salesperson in Egypt, and having one would help to improve focus on this market.
There are still some issues with the network capturing or blocking traffic even after implementing exceptions.
The management dashboards and the meter dashboards should be more user-friendly and simple to use for easy management.
I encountered several issues while trying to create solutions for this advanced version, which seem unrelated to query or data issues.
High data ingestion costs can be an issue, especially for large enterprises, as Splunk charges based on the amount of data processed.
Advanced reporting could see enhancements as there are some issues with latency.
 

Setup Cost

Cisco Secure Network Analytics pricing is high, influenced by network flow requirements, with mixed user experiences on cost and licensing.
Darktrace is costly for small businesses but offers flexible plans and pricing varies with devices and modules chosen.
Splunk User Behavior Analytics pricing is complex, influenced by data usage, licensing, and features, causing budgeting challenges.
Cisco solutions are considered to be very expensive.
The product is considered expensive compared to others.
Comparing with the competitors, it's a bit expensive.
The pricing is based on the amount of data processed, and it is considered a high-level investment for enterprises.
 

Valuable Features

Cisco Secure Network Analytics enhances security with visibility, real-time anomaly detection, automation, and intuitive management for improved threat response.
Darktrace excels in AI threat detection, real-time monitoring, and autonomous response, offering seamless integration and an intuitive interface.
Splunk User Behavior Analytics provides efficient data analysis, threat detection, and seamless integration, enhancing security with advanced analytics and automation.
The most valuable features include encrypted traffic analytics and the ability to fulfill requirements at the network level.
The most valuable features are the AI and advanced learning tools that distinguish it from other products.
The features that are most valuable to me include detection, response with analytics, and network detection.
Darktrace is valuable since it offers full packet capture and detailed metadata.
I also utilize it for anomaly detection and behavior analysis, particularly using Splunk's machine learning environment.
It correlates all the historical data, compares the upcoming behavior with what's already stored in the platform, and reduces false positives.
Features like alerts and auto report generation are valuable.
 

Mindshare comparison

Network Monitoring Software
Extended Detection and Response (XDR)
User Entity Behavior Analytics (UEBA)
 

Featured Reviews

Sudhakar T - PeerSpot reviewer
Strong network security analytics with excellent encrypted traffic analysis features
Improvements are needed on the application layer for complete security analysis. The solution should have the ability to analyze security events not only at the network layer but also at the application and OS layers. There's a need for a more comprehensive licensing model where all necessary licenses are included by default.
Peter-Murphy - PeerSpot reviewer
Enables proactive threat detection and immediate response through AI monitoring
The most valuable feature of Darktrace is its ability to detect and counter threats before they occur. The autonomous response capability is always enabled, blocking threats immediately without hesitation. Additionally, the Darktrace email platform is a significant asset since it addresses incoming threats before they reach the network, enhancing our security measures. Protecting the business is essential, and ensuring security through 24/7 AI monitoring is invaluable.
Subhayu Chakraborty - PeerSpot reviewer
Automatic reports streamline tasks and offers easy report gathering
The dashboard part could be improved. While using it, I noticed two options: Classic, which is adequate yet only in black and white, and another one that is more advanced or smart, though I forgot the exact term. I encountered several issues while trying to create solutions for this advanced version, which seem unrelated to query or data issues.
report
Use our free recommendation engine to learn which Network Monitoring Software solutions are best for your needs.
845,712 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Computer Software Company
29%
Financial Services Firm
12%
Government
9%
Manufacturing Company
7%
Computer Software Company
14%
Manufacturing Company
8%
Financial Services Firm
8%
Government
7%
Computer Software Company
17%
Financial Services Firm
12%
Government
10%
Manufacturing Company
8%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

What do you like most about Cisco Stealthwatch?
The most valuable feature of Cisco Secure Network Analytics is the Threat Intelligence integration.
What is your experience regarding pricing and costs for Cisco Stealthwatch?
The organization experienced challenges with licensing as Cisco has multiple licensing factors, and there are concern...
What needs improvement with Cisco Stealthwatch?
Improvements are needed on the application layer for complete security analysis. The solution should have the ability...
How does Crowdstrike Falcon compare with Darktrace?
Both of these products perform similarly and have many outstanding attributes. CrowdStrike Falcon offers an amazing u...
Which is better - SentinelOne or Darktrace?
Which solution is better depends on which is more suitable specifically for your company. Darktrace, for example, is ...
What do you like most about Darktrace?
A very useful feature in Darktrace for real-time threat analysis is the packet inspection that analyzes the packet tr...
What do you like most about Splunk User Behavior Analytics?
The solution's most valuable feature is Splunk queries, which allow us to query the logs and analyze the attack vectors.
What is your experience regarding pricing and costs for Splunk User Behavior Analytics?
Splunk is up to the mark in terms of pricing. However, I cannot provide specific comments on the pricing at the moment.
What needs improvement with Splunk User Behavior Analytics?
The dashboard part could be improved. While using it, I noticed two options: Classic, which is adequate yet only in b...
 

Also Known As

Cisco Stealthwatch, Cisco Stealthwatch Enterprise, Lancope StealthWatch
No data available
Caspida, Splunk UBA
 

Overview

 

Sample Customers

Edge Web Hosting, Telenor Norway, Ivy Tech Community College of Indiana, Webster Financial Corporation, Westinghouse Electric, VMware, TIAA-CREF
Irwin Mitchell, Open Energi, Wellcome Trust, FirstGroup plc, Virgin Trains, Drax, QUI! Group, DNK, CreaCard, Macrosynergy, Sisley, William Hill plc, Toyota Canada, Royal British Legion, Vitol, Allianz, KKR, AIRBUS, dpd, Billabong, Mclaren Group.
8 Securities, AAA Western, AdvancedMD, Amaya, Cerner Corporation, CJ O Shopping, CloudShare, Crossroads Foundation, 7-Eleven Indonesia
Find out what your peers are saying about Zabbix, Auvik, Datadog and others in Network Monitoring Software. Updated: March 2025.
845,712 professionals have used our research since 2012.