Try our new research platform with insights from 80,000+ expert users

Cisco Secure Network Analytics vs Splunk User Behavior Analytics comparison

 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Cisco Secure Network Analytics
Average Rating
8.2
Reviews Sentiment
6.9
Number of Reviews
59
Ranking in other categories
Network Monitoring Software (22nd), Network Traffic Analysis (NTA) (3rd), Network Detection and Response (NDR) (5th), Cisco Security Portfolio (4th)
Splunk User Behavior Analytics
Average Rating
8.2
Reviews Sentiment
6.7
Number of Reviews
21
Ranking in other categories
Intrusion Detection and Prevention Software (IDPS) (12th), User Entity Behavior Analytics (UEBA) (4th)
 

Mindshare comparison

While both are Network Security Systems solutions, they serve different purposes. Cisco Secure Network Analytics is designed for Network Monitoring Software and holds a mindshare of 1.3%, down 1.7% compared to last year.
Splunk User Behavior Analytics, on the other hand, focuses on User Entity Behavior Analytics (UEBA), holds 9.9% mindshare, down 11.3% since last year.
Network Monitoring Software
User Entity Behavior Analytics (UEBA)
 

Featured Reviews

Rainier S. - PeerSpot reviewer
You are able to drill down into a center's utilization, then create reports based on it
In the last year or two, we have been working with our Cisco NAS engineers to improve our security posturing. It is more our being proactive rather than reactive. While Stealthwatch and Lancope have this ability to look inside and give you visibility (a great feature), follow-up is the rule. We would like filters that you can put into place to tap onto certain types of behaviors, alerts out, and/or hopefully a block. This is sort of what we are looking for. I might be speaking too early, because we are not down this path yet. We know the feature set is there, we just do not know yet how to achieve it. That is proactive rather than more reactive. For Lancope Stealthwatch, we would like to see it more on the ASA Firewall platform. While this might already be available, this is more a failing of Cisco to inform us if it is there. For example: * Are we on the right or wrong version of the code? * What does the code look like? * Are we are really looking at firewalls? Or is it more about the foundation and route switches that we are seeing? It is about visibility.
AnupChapalgaonkar - PeerSpot reviewer
Efficient behavior analysis with potential for improved reporting
I use Splunk User Behavior Analytics for SAML authentication, behavior analysis, and integration purposes. Integration allows me to identify version controls in CRM systems and analyze remote users. Additionally, I use it for streaming and machine learning kit integration, focusing on behavior…

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"From what I understand, you can encrypt and unencrypt traffic moving in transit. This is one of the features that we liked about it."
"Another notable feature of Cisco Secure Network Analytics is its Layer 7 visibility, which allows us to monitor and analyze network communications at the application layer."
"The most valuable part is that Stealthwatch is part of a portfolio of security devices from Cisco. Cisco literally can touch every single end point, every single ingress and egress point in the network. Nobody else has that."
"Able to drill down into a center's utilization, then create reports based on it."
"Great network monitoring, looking at anomaly detection and evaluation."
"The ability to send data flow from other places and have them all in one place is very valuable for us."
"Being able to identify specific date closed across the network is invaluable."
"The most valuable features of this solution are its reporting and mitigation capabilities."
"Splunk User Behavior Analytics is a one hundred percent stable solution."
"It is a solution that helps test and measure customer satisfaction."
"The solution is definitely scalable."
"The most valuable features are the indexing and powerful search features."
"The solution's most valuable feature is Splunk queries, which allow us to query the logs and analyze the attack vectors."
"The solution appears to be stable, although we haven't used it heavily."
"Splunk is more user-friendly than some competing solutions we tried."
"The most effective one is the integration with other vendors."
 

Cons

"I think the interface is a little lacking. The interface seems like it just needs to be modernized. It's been the same interface now, ever since I've seen it probably four years ago."
"Stealthwatch is still maturing in AI. It uses artificial intelligence for predictions, but AI still needs to mature. It is in a phase where you get 95% correct detection. As its AI engine learns more, it will become more accurate. This is applicable to all the devices that are using AI because they support both supervised and unsupervised machine learning. The accuracy in the case of supervised machine learning is dependent on the data you feed into the box. The accuracy in the case of unsupervised machine learning is dependent on the algorithm. The algorithm matures depending on retrospective learning, and this is how it is able to detect zero-day attacks."
"At my company, we might not be using it enough with other applications that we have that can integrate with it."
"There's a lot of traffic on our network that we don't see sometimes."
"We need to be able to filter out internal IPs as non-threats."
"Initially, I felt Cisco Secure Network Analytics lacked integration with Splunk."
"I would like Cisco to make it easier for the administrators to use it."
"I would like to see some improvement when it comes to reporting."
"Currently, a lot of network operations need improvement. We still need people to handle incidents. Our vision is to leverage status and convert it directly from the network devices. It would be ideal if we could take action using APIs and API code and remove manual processes."
"The ability to do more complicated data investigation would be a welcome addition for pros, though the functionality now gives most people what they need."
"The dashboard part could be improved."
"I would like improved downward integration with other tools such as McAfee and other GCP solutions."
"The price of Splunk UBA is too high."
"In terms of improvements, advanced reporting could see enhancements as there are some issues with latency."
"In terms of improvements, advanced reporting could see enhancements as there are some issues with latency. Additionally, there are challenges with configuration findings during lexical analysis."
"In the future I would like to see simplified statistics and analytical threats."
 

Pricing and Cost Advice

"One of the things which bugs me about Lancope is the licensing. We understand how licensing works. Our problem is when we bought and purchased most of these Lancope devices, we did so with our sister company. Somewhere within the purchase and distribution, licensing got mixed up. That is all on Cisco, and it is their responsibility. They allotted some of our sister company's equipment to us, and some of our equipment to them. To date, they have never been able to fix it."
"Licensing is done by flows per second, not including outside>in traffic."
"On a yearly basis, licensing is somewhere around $30,000."
"​Licensing is done by flows per second, not including outside (in traffic)."
"NetFlow is very expensive."
"The pricing for this solution is good."
"The licensing costs are outrageous."
"The tool is not cheaply priced."
"I hope we can increase the free license to be more than 5 gig a day. This would help people who want to introduce a POC or a demo license for the solution."
"The licensing costs is around 10,000 dollars."
"My biggest complaint is the way they do pricing... You can never know the pricing for next year. Every single time you adjust to something new, the price goes up. It's impossible to truly budget for it. It goes up constantly."
"Pricing varies based on the packages you choose and the volume of your usage."
"There are additional costs associated with the integrator."
"I am not aware of the price, but it is expensive."
report
Use our free recommendation engine to learn which Network Monitoring Software solutions are best for your needs.
832,138 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Computer Software Company
30%
Financial Services Firm
11%
Government
9%
Manufacturing Company
6%
Computer Software Company
16%
Financial Services Firm
12%
Government
9%
Manufacturing Company
8%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

What do you like most about Cisco Stealthwatch?
The most valuable feature of Cisco Secure Network Analytics is the Threat Intelligence integration.
What is your experience regarding pricing and costs for Cisco Stealthwatch?
The tool is not cheaply priced. In cybersecurity, you want an extra layer of security in your organization. Some sectors want NDR solutions, so you cannot deploy such tools everywhere, as they are ...
What needs improvement with Cisco Stealthwatch?
The expensive nature of the tool is an area of concern where improvements are required.
What do you like most about Splunk User Behavior Analytics?
The solution's most valuable feature is Splunk queries, which allow us to query the logs and analyze the attack vectors.
What is your experience regarding pricing and costs for Splunk User Behavior Analytics?
Splunk is up to the mark in terms of pricing. However, I cannot provide specific comments on the pricing at the moment.
What needs improvement with Splunk User Behavior Analytics?
In terms of improvements, advanced reporting could see enhancements as there are some issues with latency. Additionally, there are challenges with configuration findings during lexical analysis.
 

Also Known As

Cisco Stealthwatch, Cisco Stealthwatch Enterprise, Lancope StealthWatch
Caspida, Splunk UBA
 

Overview

 

Sample Customers

Edge Web Hosting, Telenor Norway, Ivy Tech Community College of Indiana, Webster Financial Corporation, Westinghouse Electric, VMware, TIAA-CREF
8 Securities, AAA Western, AdvancedMD, Amaya, Cerner Corporation, CJ O Shopping, CloudShare, Crossroads Foundation, 7-Eleven Indonesia
Find out what your peers are saying about Cisco Secure Network Analytics vs. Splunk User Behavior Analytics and other solutions. Updated: January 2020.
832,138 professionals have used our research since 2012.