Try our new research platform with insights from 80,000+ expert users

Darktrace vs Splunk User Behavior Analytics comparison

 

Comparison Buyer's Guide

Executive Summary
 

Categories and Ranking

Darktrace
Ranking in Intrusion Detection and Prevention Software (IDPS)
1st
Average Rating
8.2
Reviews Sentiment
7.4
Number of Reviews
74
Ranking in other categories
Email Security (12th), Network Traffic Analysis (NTA) (1st), Network Detection and Response (NDR) (1st), Extended Detection and Response (XDR) (3rd), AI-Powered Chatbots (3rd), Cloud Security Posture Management (CSPM) (15th), Cloud-Native Application Protection Platforms (CNAPP) (12th), Attack Surface Management (ASM) (3rd), AI-Powered Cybersecurity Platforms (1st)
Splunk User Behavior Analytics
Ranking in Intrusion Detection and Prevention Software (IDPS)
16th
Average Rating
8.2
Number of Reviews
18
Ranking in other categories
User Entity Behavior Analytics (UEBA) (5th)
 

Mindshare comparison

As of November 2024, in the Intrusion Detection and Prevention Software (IDPS) category, the mindshare of Darktrace is 18.9%, up from 16.4% compared to the previous year. The mindshare of Splunk User Behavior Analytics is 2.3%, down from 3.2% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Intrusion Detection and Prevention Software (IDPS)
 

Featured Reviews

Luis KiambatA - PeerSpot reviewer
Nov 9, 2022
Great autonomous support, offers an easy setup, and has responsive support
We primarily use the solution for IT. Customers use it for banks or construction sites, depending on our customers. We haven't had an OT implementation yet. However, we have interest from two companies The autonomous response is great. It blocks basically everything that is outside the normal,…
Sharath Chander - PeerSpot reviewer
Mar 10, 2023
It's more user-friendly than other solutions we tried, but it could use more features like process mining and automation
We have an application running for our e-commerce site, and we use Splunk primarily to detect anomalous behavior like false orders and other bot-related threats. Splunk helps us analyze and eliminate threats using machine learning.  Splunk is more user-friendly than some competing solutions we…

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"The AI-based pattern is the most valuable feature."
"We have found the product to be stable and issue-free."
"I have found the most valuable features to be artificial intelligence for cybersecurity, advanced machine learning capabilities, enterprise Immune System, Antigena Network, and Antigena Email. The way the solution detects the threat over the network before it spreads is very good. It notifies you of what the threat is exactly doing and gives you all the details about the execution of that application that had created the threat over your network."
"The most valuable features are the AI and advanced learning tools that distinguish it from other products."
"The product offers us a very good user interface and we've found the network visibility to be very good so far."
"What I like about Darktrace, is that you can quickly identify threats."
"The most valuable feature of Darktrace is the AI that detects abnormal network activity."
"The most valuable feature of this solution is that it does not require human intervention to eliminate a threat."
"The solution is definitely scalable."
"The solution is fast, flexible, and easy to use."
"The solution's most valuable feature is Splunk queries, which allow us to query the logs and analyze the attack vectors."
"The solution appears to be stable, although we haven't used it heavily."
"The most valuable feature is being able to take data and put it into other systems so that we could see the output, and to see where we need to apply our focus."
"The solution is extremely scalable. Our customers are regularly scaling up after installing Splunk."
"The most valuable feature is the ability to search through a large amount of data."
"The most valuable features are its data aggregation and the ability to automatically identify a number of threats, then suggest recommended actions upon them."
 

Cons

"It takes time to go through the interface and pick up things. If it were a more straightforward interface, then it would free up time."
"It would be useful if there was a way to check to see if there are certain devices that are not in sync with the solution. I'm not sure if this is an option or not."
"I'd love them to see maybe covering the cloud a bit more."
"The program is quite expensive."
"The pricing is a bit high for the region."
"Although we haven't detected any network threats since implementing Darktrace, we are unsure of its efficacy. It would be beneficial if the solution could offer additional details to the user regarding any potential or prevented threats. Additionally, there could be better search tools and integration."
"The solution would benefit from automation. Currently, you have to know what you are searching for."
"It would be helpful if they could recognize incidents and simplify the customer's challenge to identify what is happening."
"The solution is much more expensive than relative competitors like ArcSight or LogRhythm. It makes it hard to sell to customers sometimes."
"Currently, a lot of network operations need improvement. We still need people to handle incidents. Our vision is to leverage status and convert it directly from the network devices. It would be ideal if we could take action using APIs and API code and remove manual processes."
"We'd like the ability to do custom searches."
"The price of Splunk UBA is too high."
"I would like improved downward integration with other tools such as McAfee and other GCP solutions."
"I'm not aware of any lacking features."
"The ability to do more complicated data investigation would be a welcome addition for pros, though the functionality now gives most people what they need."
"The initial setup was complex because some of the configurations that we required needed customization."
 

Pricing and Cost Advice

"The pricing is subscription-based and it is high."
"It is expensive. I don't have the price for other competitors."
"Our customers feel that the price of Darktrace is quite high compared to other solutions."
"The cost of the solution can be reduced to make it more appealing to customers."
"Darktrace is expensive. You can pay for the license yearly."
"It is a very expensive product."
"The price of Darktrace is high and could be reduced. We pay approximately $30,000 to $54,000 annually."
"It is expensive."
"The licensing costs is around 10,000 dollars."
"There are additional costs associated with the integrator."
"I hope we can increase the free license to be more than 5 gig a day. This would help people who want to introduce a POC or a demo license for the solution."
"Pricing varies based on the packages you choose and the volume of your usage."
"I am not aware of the price, but it is expensive."
"My biggest complaint is the way they do pricing... You can never know the pricing for next year. Every single time you adjust to something new, the price goes up. It's impossible to truly budget for it. It goes up constantly."
report
Use our free recommendation engine to learn which Intrusion Detection and Prevention Software (IDPS) solutions are best for your needs.
815,854 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Computer Software Company
15%
Financial Services Firm
8%
Manufacturing Company
8%
Government
7%
Computer Software Company
15%
Financial Services Firm
12%
Government
9%
Manufacturing Company
8%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

How does Crowdstrike Falcon compare with Darktrace?
Both of these products perform similarly and have many outstanding attributes. CrowdStrike Falcon offers an amazing user interface that makes setup easy and seamless. CrowdStrike Falcon offers a cl...
Which is better - SentinelOne or Darktrace?
Which solution is better depends on which is more suitable specifically for your company. Darktrace, for example, is meant for smaller to medium-sized businesses. It is also a good option for organ...
What do you like most about Darktrace?
A very useful feature in Darktrace for real-time threat analysis is the packet inspection that analyzes the packet traffic in real time.
What do you like most about Splunk User Behavior Analytics?
The solution's most valuable feature is Splunk queries, which allow us to query the logs and analyze the attack vectors.
What is your experience regarding pricing and costs for Splunk User Behavior Analytics?
I am not aware of the price, but it is expensive. A rough estimate would be around 150 gigabytes, given the huge amount of data. At the moment there are no additional costs for maintenance.
What needs improvement with Splunk User Behavior Analytics?
Sometimes, we need to write explicit queries. It would be good if the solution had an analytics tool that allowed us to analyze the data without writing specific queries. The solution's user interf...
 

Also Known As

No data available
Caspida, Splunk UBA
 

Learn More

Video not available
 

Overview

 

Sample Customers

Irwin Mitchell, Open Energi, Wellcome Trust, FirstGroup plc, Virgin Trains, Drax, QUI! Group, DNK, CreaCard, Macrosynergy, Sisley, William Hill plc, Toyota Canada, Royal British Legion, Vitol, Allianz, KKR, AIRBUS, dpd, Billabong, Mclaren Group.
8 Securities, AAA Western, AdvancedMD, Amaya, Cerner Corporation, CJ O Shopping, CloudShare, Crossroads Foundation, 7-Eleven Indonesia
Find out what your peers are saying about Darktrace vs. Splunk User Behavior Analytics and other solutions. Updated: October 2024.
815,854 professionals have used our research since 2012.