Try our new research platform with insights from 80,000+ expert users

Elastic Search vs Splunk User Behavior Analytics comparison

 

Comparison Buyer's Guide

Executive Summary
 

Categories and Ranking

Elastic Search
Average Rating
8.2
Reviews Sentiment
7.2
Number of Reviews
65
Ranking in other categories
Indexing and Search (1st), Cloud Data Integration (11th), Search as a Service (1st), Vector Databases (1st)
Splunk User Behavior Analytics
Average Rating
8.2
Reviews Sentiment
8.7
Number of Reviews
18
Ranking in other categories
Intrusion Detection and Prevention Software (IDPS) (16th), User Entity Behavior Analytics (UEBA) (5th)
 

Mindshare comparison

Elastic Search and Splunk User Behavior Analytics aren’t in the same category and serve different purposes. Elastic Search is designed for Indexing and Search and holds a mindshare of 28.0%, up 24.6% compared to last year.
Splunk User Behavior Analytics, on the other hand, focuses on User Entity Behavior Analytics (UEBA), holds 9.8% mindshare, down 11.8% since last year.
Indexing and Search
User Entity Behavior Analytics (UEBA)
 

Featured Reviews

Saurav Kumar - PeerSpot reviewer
Provides us with the capability to execute multiple queries according to our requirements
Logsign provides us with the capability to execute multiple queries according to our requirements. The indexing is very high, making it effective for storing and retrieving logs. The real-time analytics with Elastic benefits us due to the huge traffic volume in our organization, which reaches up to 60,000 requests per second. With logs of approximately 25 GB per day, manually analyzing traffic behavior, payloads, headers, user agents, and other details is impractical.
Sharath Chander - PeerSpot reviewer
It's more user-friendly than other solutions we tried, but it could use more features like process mining and automation
We want to have an automated system for bot hunting that enables us to detect anomalies predictively based on historical data. It would be helpful if Splunk included process mining as an alternative option. We have a threat workflow, but it would be useful if we could supplement that with some process mining capabilities over time.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"Implementing the main requirements regarding my support portal​."
"The most valuable features are its user-friendly interface and seamless navigation."
"The products comes with REST APIs."
"The solution is valuable for log analytics."
"The initial installation and setup were straightforward."
"The most valuable features are the data store and the X-pack extension."
"We can easily collect all the data and view historical trends using the product. We can view the applications and identify the issues effectively."
"I value the feature that allows me to share the dashboards to different people with different levels of access."
"The solution appears to be stable, although we haven't used it heavily."
"The solution is extremely scalable. Our customers are regularly scaling up after installing Splunk."
"The solution is fast, flexible, and easy to use."
"The most valuable feature is the ability to search through a large amount of data."
"This is a good security product."
"The solution is definitely scalable."
"It's easily scalable."
"The most valuable features are its data aggregation and the ability to automatically identify a number of threats, then suggest recommended actions upon them."
 

Cons

"I would rate the stability a seven out of ten. We faced a few issues."
"Elastic Enterprise Search could improve the report templates."
"We have an issue with the volume of data that we can handle."
"The metadata gets stored along with indexes and isn't queryable."
"Elastic Search could benefit from a more user-friendly onboarding process for beginners."
"Elastic Enterprise Search can improve by adding some kind of search that can be used out of the box without too much struggle with configuration. With every kind of search engine, there is some kind of special function that you need to do. A simple out-of-the-box search would be useful."
"They should improve its documentation. Their official documentation is not very informative. They can also improve their technical support. They don't help you much with the customized stuff. They also need to add more visuals. Currently, they have line charts, bar charts, and things like that, and they can add more types of visuals. They should also improve the alerts. They are not very simple to use and are a bit complex. They could add more options to the alerting system."
"Enterprise scaling of what have been essentially separate, free open source software (FOSS) products has been a challenge, but the folks at Elastic have published new add-ons (X-Pack and ECE) to help large companies grow ELK to required scales."
"They should work to add more built-in correlation searches and more use cases based on worldwide customer experiences. They need more ready-made use cases."
"I would like improved downward integration with other tools such as McAfee and other GCP solutions."
"It would be good if the solution had an analytics tool that allowed us to analyze the data without writing specific queries."
"If the price was lowered and the setup process was less complex, I would consider rating it higher."
"We want to have an automated system for bot hunting that enables us to detect anomalies predictively based on historical data. It would be helpful if Splunk included process mining as an alternative option. We have a threat workflow, but it would be useful if we could supplement that with some process mining capabilities over time."
"Currently, a lot of network operations need improvement. We still need people to handle incidents. Our vision is to leverage status and convert it directly from the network devices. It would be ideal if we could take action using APIs and API code and remove manual processes."
"There are occasional bugs."
"The correlation engine should have persistent and definable rules."
 

Pricing and Cost Advice

"The tool is an open-source product."
"The tool is not expensive. Its licensing costs are yearly."
"The price of Elastic Enterprise is very, very competitive."
"The price of Elasticsearch is fair. It is a more expensive solution, like QRadar. The price for Elasticsearch is not much more than other solutions we have."
"We are using the free version and intend to upgrade."
"Although the ELK Elasticsearch software is open-source, we buy the hardware."
"The version of Elastic Enterprise Search I am using is open source which is free. The pricing model should improve for the enterprise version because it is very expensive."
"We use the free version for some logs, but not extensive use."
"I am not aware of the price, but it is expensive."
"Pricing varies based on the packages you choose and the volume of your usage."
"My biggest complaint is the way they do pricing... You can never know the pricing for next year. Every single time you adjust to something new, the price goes up. It's impossible to truly budget for it. It goes up constantly."
"I hope we can increase the free license to be more than 5 gig a day. This would help people who want to introduce a POC or a demo license for the solution."
"The licensing costs is around 10,000 dollars."
"There are additional costs associated with the integrator."
report
Use our free recommendation engine to learn which Indexing and Search solutions are best for your needs.
816,562 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Computer Software Company
18%
Financial Services Firm
15%
Manufacturing Company
9%
Government
7%
Computer Software Company
15%
Financial Services Firm
13%
Government
9%
Manufacturing Company
8%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

What do you like most about ELK Elasticsearch?
Logsign provides us with the capability to execute multiple queries according to our requirements. The indexing is very high, making it effective for storing and retrieving logs. The real-time anal...
What is your experience regarding pricing and costs for ELK Elasticsearch?
I am not directly involved with pricing or setup costs. While I know a portion is open-source, a paid version might be necessary.
What needs improvement with ELK Elasticsearch?
An improvement would be to have an interface that allows easier navigation and tracing of logs. The current system requires manually inputting dates to verify alerts. A visual timeline that pinpoin...
What do you like most about Splunk User Behavior Analytics?
The solution's most valuable feature is Splunk queries, which allow us to query the logs and analyze the attack vectors.
What is your experience regarding pricing and costs for Splunk User Behavior Analytics?
I am not aware of the price, but it is expensive. A rough estimate would be around 150 gigabytes, given the huge amount of data. At the moment there are no additional costs for maintenance.
What needs improvement with Splunk User Behavior Analytics?
Sometimes, we need to write explicit queries. It would be good if the solution had an analytics tool that allowed us to analyze the data without writing specific queries. The solution's user interf...
 

Also Known As

Elastic Enterprise Search, Swiftype, Elastic Cloud
Caspida, Splunk UBA
 

Learn More

Video not available
 

Overview

 

Sample Customers

T-Mobile, Adobe, Booking.com, BMW, Telegraph Media Group, Cisco, Karbon, Deezer, NORBr, Labelbox, Fingerprint, Relativity, NHS Hospital, Met Office, Proximus, Go1, Mentat, Bluestone Analytics, Humanz, Hutch, Auchan, Sitecore, Linklaters, Socren, Infotrack, Pfizer, Engadget, Airbus, Grab, Vimeo, Ticketmaster, Asana, Twilio, Blizzard, Comcast, RWE and many others.
8 Securities, AAA Western, AdvancedMD, Amaya, Cerner Corporation, CJ O Shopping, CloudShare, Crossroads Foundation, 7-Eleven Indonesia
Find out what your peers are saying about Elastic Search vs. Splunk User Behavior Analytics and other solutions. Updated: January 2022.
816,562 professionals have used our research since 2012.