Try our new research platform with insights from 80,000+ expert users

Elastic Search vs Splunk User Behavior Analytics comparison

 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

ROI

Sentiment score
6.0
Organizations report increased efficiency and ROI from Elastic Search, with proper implementation and data integration being crucial.
Sentiment score
6.4
Splunk User Behavior Analytics boosts productivity and savings, though ROI varies with implementation; users report improved incident resolution.
We have not purchased any licensed products, and our use of Elastic Search is purely open-source, contributing positively to our ROI.
The solution can save costs by improving incident resolution times and reducing security incident costs.
 

Customer Service

Sentiment score
6.6
Elastic Search's customer service is supported by a strong community and resources, though response times can be slow.
Sentiment score
6.8
Splunk User Behavior Analytics offers reliable customer support, although geographic limitations may require some users to utilize online forums.
Mission-critical offering a dedicated team, proactive monitoring, and fast resolution.
Splunk's technical support is amazing.
I would rate the support at eight, meaning there's some room for improvement.
 

Scalability Issues

Sentiment score
7.2
Elastic Search offers strong scalability and ease of use but may face challenges with large databases and complex indexes.
Sentiment score
7.5
Splunk User Behavior Analytics offers scalable and versatile solutions for enterprises, adaptable to both on-premise and cloud environments.
I can actually add more storage and memory because I host it in the cloud.
Splunk User Behavior Analytics is highly scalable, designed for enterprise scalability, allowing expansion of data ingestion, indexing, and search capabilities as log volumes grow.
 

Stability Issues

Sentiment score
7.7
Elastic Search is stable and reliable for enterprise use, with occasional issues in large-scale data or new releases.
Sentiment score
8.2
Splunk User Behavior Analytics is praised for stability, ease of use, and reliable performance, despite minor long-term data issues.
Splunk User Behavior Analytics is a one hundred percent stable solution.
Splunk User Behavior Analytics is highly stable and reliable, even in large-scale enterprise environments with high log injection rates.
Sometimes issues occur when handling long-term data.
 

Room For Improvement

Elastic Search users seek improved security, scalability, integration, and support, alongside better UI, onboarding, and licensing enhancements.
Splunk User Behavior Analytics needs improved integration, automation, affordability, a better interface, and enhanced features for optimal user satisfaction.
This can create problems for new developers because they have to quickly switch to another version.
High data ingestion costs can be an issue, especially for large enterprises, as Splunk charges based on the amount of data processed.
I encountered several issues while trying to create solutions for this advanced version, which seem unrelated to query or data issues.
Advanced reporting could see enhancements as there are some issues with latency.
 

Setup Cost

Elastic Search is cost-effective initially but can become expensive with additional nodes and premium features despite flexible licensing.
Splunk User Behavior Analytics pricing is complex, influenced by data usage, licensing, and features, causing budgeting challenges.
The pricing is based on the amount of data processed, and it is considered a high-level investment for enterprises.
Comparing with the competitors, it's a bit expensive.
 

Valuable Features

ELK offers fast search, scalable architecture, advanced analytics, and integration with Logstash, X-Pack, for flexible, cost-effective enterprise data management.
Splunk User Behavior Analytics provides efficient data analysis, threat detection, and seamless integration, enhancing security with advanced analytics and automation.
Elastic Search makes handling large data volumes efficient and supports complex search operations.
Aggregation is faster than querying directly from a database, like Postgres or Vertica.
I also utilize it for anomaly detection and behavior analysis, particularly using Splunk's machine learning environment.
It correlates all the historical data, compares the upcoming behavior with what's already stored in the platform, and reduces false positives.
Splunk User Behavior Analytics is known for its advanced analytics and data correlation capabilities, which help in detecting patterns, anomalies, and security threats.
 

Categories and Ranking

Elastic Search
Average Rating
8.2
Reviews Sentiment
6.7
Number of Reviews
67
Ranking in other categories
Indexing and Search (1st), Cloud Data Integration (9th), Search as a Service (1st), Vector Databases (2nd)
Splunk User Behavior Analytics
Average Rating
8.2
Reviews Sentiment
6.8
Number of Reviews
23
Ranking in other categories
Intrusion Detection and Prevention Software (IDPS) (11th), User Entity Behavior Analytics (UEBA) (4th)
 

Mindshare comparison

Elastic Search and Splunk User Behavior Analytics aren’t in the same category and serve different purposes. Elastic Search is designed for Indexing and Search and holds a mindshare of 25.4%, down 26.6% compared to last year.
Splunk User Behavior Analytics, on the other hand, focuses on User Entity Behavior Analytics (UEBA), holds 9.5% mindshare, down 11.6% since last year.
Indexing and Search
User Entity Behavior Analytics (UEBA)
 

Featured Reviews

Anand_Kumar - PeerSpot reviewer
Captures data from all other sources and becomes a MOM aka monitoring of monitors
Scalability and ROI are the areas they have to improve. Their license terms are based on the number of cores. If you increase the number of cores, it becomes very difficult to manage at a large scale. For example, if I have a $3 million project, I won't sell it because if we're dealing with a 10 TB or 50 TB system, there are a lot of systems and applications to monitor, and I have to make an MOM (Mean of Max) for everything. This is because of the cost impact. Also, when you have horizontal scaling, it's like a multi-story building with only one elevator. You have to run around, and it's not efficient. Even the smallest task becomes difficult. That's the problem with horizontal scaling. They need to improve this because if they increase the cores and adjust the licensing accordingly, it would make more sense.
Subhayu Chakraborty - PeerSpot reviewer
Automatic reports streamline tasks and offers easy report gathering
The dashboard part could be improved. While using it, I noticed two options: Classic, which is adequate yet only in black and white, and another one that is more advanced or smart, though I forgot the exact term. I encountered several issues while trying to create solutions for this advanced version, which seem unrelated to query or data issues.
report
Use our free recommendation engine to learn which Indexing and Search solutions are best for your needs.
845,564 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Computer Software Company
18%
Financial Services Firm
15%
Government
9%
Manufacturing Company
8%
Computer Software Company
17%
Financial Services Firm
12%
Government
9%
Manufacturing Company
8%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

What do you like most about ELK Elasticsearch?
Logsign provides us with the capability to execute multiple queries according to our requirements. The indexing is very high, making it effective for storing and retrieving logs. The real-time anal...
What is your experience regarding pricing and costs for ELK Elasticsearch?
I don't know about pricing. That is dealt with by the sales team and our account team. I was not involved with that.
What needs improvement with ELK Elasticsearch?
I found an issue with Elasticsearch in terms of aggregation. They are good, yet the rules written for this are not really good. There is a maximum of 10,000 entries, so the limitation means that if...
What do you like most about Splunk User Behavior Analytics?
The solution's most valuable feature is Splunk queries, which allow us to query the logs and analyze the attack vectors.
What is your experience regarding pricing and costs for Splunk User Behavior Analytics?
Splunk is up to the mark in terms of pricing. However, I cannot provide specific comments on the pricing at the moment.
What needs improvement with Splunk User Behavior Analytics?
The dashboard part could be improved. While using it, I noticed two options: Classic, which is adequate yet only in black and white, and another one that is more advanced or smart, though I forgot ...
 

Also Known As

Elastic Enterprise Search, Swiftype, Elastic Cloud
Caspida, Splunk UBA
 

Overview

 

Sample Customers

T-Mobile, Adobe, Booking.com, BMW, Telegraph Media Group, Cisco, Karbon, Deezer, NORBr, Labelbox, Fingerprint, Relativity, NHS Hospital, Met Office, Proximus, Go1, Mentat, Bluestone Analytics, Humanz, Hutch, Auchan, Sitecore, Linklaters, Socren, Infotrack, Pfizer, Engadget, Airbus, Grab, Vimeo, Ticketmaster, Asana, Twilio, Blizzard, Comcast, RWE and many others.
8 Securities, AAA Western, AdvancedMD, Amaya, Cerner Corporation, CJ O Shopping, CloudShare, Crossroads Foundation, 7-Eleven Indonesia
Find out what your peers are saying about Elastic Search vs. Splunk User Behavior Analytics and other solutions. Updated: January 2022.
845,564 professionals have used our research since 2012.