Try our new research platform with insights from 80,000+ expert users
Security PS Supervisor at a tech services company with 1,001-5,000 employees
Real User
A powerful platform with straightforward configuration, but needs to be more scalable
Pros and Cons
  • "It's straightforward in terms of configuration and troubleshooting and log management and monitoring as well. These are the edge points in addition to it being a modular solution where you can capitalize on your current licenses with extra licensing models, which can match the customer's business requirement and it can help the customer to design or to actually plan for their own roadmap."
  • "The solution is much more expensive than relative competitors like ArcSight or LogRhythm. It makes it hard to sell to customers sometimes."

What is our primary use case?

The solution has two main uses. The primary use is for log management and storage. The secondary use is related to solution log coordination and selection.

What is most valuable?

Splunk is a very powerful platform. It's a machine data platform, and it can provide several models that use the same appliance and on the same platform, including some business platforms. I do believe when it comes to functionality and ease of use, Splunk is one of the market leaders in this area.

When it comes to quality, I believe Splunk is the easiest platform on the market. It has a lot of subscripts, and a lot of licenses, which can provide the customer with all the requirements they need.

The solution has some predefined use cases that we count on. It's a customizable platform as well, which can be easily customizable based on the customer requirements and the environment itself. 

It provides ease of use. It's straightforward in terms of configuration and troubleshooting and log management and monitoring as well. These are the edge points in addition to it being a modular solution where you can capitalize on your current licenses with extra licensing models, which can match the customer's business requirements. It can help the customer to design or to actually plan their own roadmap. And it can be rolled out in several phases.

What needs improvement?

The solution is much more expensive than relative competitors like ArcSight or LogRhythm. It makes it hard to sell to customers sometimes.

I would like to see a better tracking intelligence module with lower costs fully integrated with a user behavior analytics module. It would empower this module with the keys and real-time updates in terms of security.

For how long have I used the solution?

I've been using the solution for three years.
Buyer's Guide
Splunk User Behavior Analytics
March 2025
Learn what your peers think about Splunk User Behavior Analytics. Get advice and tips from experienced pros sharing their opinions. Updated: March 2025.
842,672 professionals have used our research since 2012.

What do I think about the stability of the solution?

It's stable. I used to deal with other vendors in the UBA such as HP ArcSight, which is a bit more sophisticated and complicated in terms of configuration and in terms of monitoring. Splunk is much easier and very straightforward in terms of configuration and monitoring and customization as well.

What do I think about the scalability of the solution?

There is a question as to how to scale up, especially in the log management area. Customers have their own predefined retention period, which means storing the logs for a long time. It's usually a minimum of six months or in some cases, up to one year. So the scalability has a little bit a limitation or restriction in storage components.

How are customer service and support?

I'm not an end-user, so I'm not supposed to open any end-user cases. However, the team that receives requests from customers and end-users themselves feels comfortable with the level of support they get. They're being provided with answers from a strong technical support team. So I do believe that it's going good. I haven't heard anything about them suffering from any problem of latency or shortage of resources, or a lack of knowledge and so on. I think technical support is fine.

Which solution did I use previously and why did I switch?

I used to deal with several solutions, like HP or Micro Focus ArcSight, IBM Curator, and LogRhythm.

What's my experience with pricing, setup cost, and licensing?

The solution is relatively expensive. There are costs above the standard licensing as well.

Pricing varies according to the customer's needs and set up. Pricing depends on the licensing model and if the normal log management licensing model or the security plus license. It also depends on the licensing model and the platform required by the customer. It can further depend on if the customer owns a Splunk hardware platform, or if they can host these licenses and subscriptions on their own platform. It can vary depending on the OPEX model and CAPEX model as well. There are a lot of variables that encompass the total cost of the solution.

I believe that Splunk is about 50% more expensive than other solutions.

What other advice do I have?

I'm a system integrator, which provides the solution to end-users and customers.

We handle the on-premises deployment model.

I would recommend the solution because of the ease of use, the simple administration, the good level of support, the predefined use cases, and the predefined user behavior analytics.

I would rate the solution seven out of ten.

Disclosure: My company has a business relationship with this vendor other than being a customer: Reseller.
PeerSpot user
Director5e75 - PeerSpot reviewer
Director of Technology at a insurance company with 10,001+ employees
Real User
Enables us to collect data from multiple different sources to be able to use it to prevent damages proactively
Pros and Cons
  • "The most valuable feature is being able to take data and put it into other systems so that we could see the output, and to see where we need to apply our focus."

    What is our primary use case?

    The primary use case for this solution is to collect data from multiple different sources to be able to use it to proactively prevent damages.

    How has it helped my organization?

    We have 81000 desktops and we could take logs off those machines and see patterns, and from those patterns, we've been able to reduce the outages going forward proactively.

    What is most valuable?

    The most valuable feature is being able to take data and put it into other systems so that we could see the output and see where we need to apply our focus.

    What needs improvement?

    I'm not that close to the actual hands-on usage to suggest improvements. One thing I would say is that they should continue to expand it on more devices. I would say continue to broaden the horizon where there are limitations now.

    What do I think about the stability of the solution?

    It's been very stable so far in its core. The company's been great.

    What do I think about the scalability of the solution?

    It's very scalable. We have it on servers, around 19000 servers, 81000 desktops. We have it on a lot of security devices, so it's been very scalable.

    How are customer service and technical support?

    The support's been good from what I've heard. If it weren't, it would've been escalated to me.

    Which solution did I use previously and why did I switch?

    We have logs everywhere and trying to look at those logs on an individual basis is quite cumbersome, so taking a tool like this that brings all the logs together for us to dissect and analyze is something that we knew would provide great value.

    How was the initial setup?

    The initial setup was straightforward. All that was required was a fundamental understanding of what needed to be installed, the virtual control, the backend database, and how you generate the reports. I would think from those aspects it was pretty straightforward.

    What about the implementation team?

    We implemented through a combination of a reseller and integrator. I'd say for deployment, probably more so through the integrator, and the experience was positive. One company would be DSS. 

    What was our ROI?

    I have seen ROI but they're soft call savings, so hard call savings are hard to pinpoint. There's nothing that I could comment on that would be hard savings. Everything's been soft.

    Which other solutions did I evaluate?

    Vendors on our shortlist included IBM and DSS.

    What other advice do I have?

    If I had to rate Splunk from one through ten, one being the worst and ten being the best, 
    I would give it a nine. There's always room for opportunity, but I think it's been working pretty good. 

    I rate it a nine because I think that the ease of use with the product, like the installation and the support that we receive. From what I hear everything goes well. There's nothing that stands out. We haven't had any vulnerabilities or compliance issues with the product, and we do with others, so those are the reasons why I'd rate it a nine.

    Anyone else looking for a product that can consolidate logs this product does what it says it will do.

    Disclosure: I am a real user, and this review is based on my own experience and opinions.
    PeerSpot user
    Buyer's Guide
    Splunk User Behavior Analytics
    March 2025
    Learn what your peers think about Splunk User Behavior Analytics. Get advice and tips from experienced pros sharing their opinions. Updated: March 2025.
    842,672 professionals have used our research since 2012.
    Sharath Chander - PeerSpot reviewer
    Business Transformation specialist at a tech consulting company with 10,001+ employees
    Real User
    It's more user-friendly than other solutions we tried, but it could use more features like process mining and automation
    Pros and Cons
    • "Splunk is more user-friendly than some competing solutions we tried."
    • "We want to have an automated system for bot hunting that enables us to detect anomalies predictively based on historical data. It would be helpful if Splunk included process mining as an alternative option. We have a threat workflow, but it would be useful if we could supplement that with some process mining capabilities over time."

    What is our primary use case?

    We have an application running for our e-commerce site, and we use Splunk primarily to detect anomalous behavior like false orders and other bot-related threats. Splunk helps us analyze and eliminate threats using machine learning. 

    What is most valuable?

    Splunk is more user-friendly than some competing solutions we tried. 

    What needs improvement?

    We want to have an automated system for bot hunting that enables us to detect anomalies predictively based on historical data. It would be helpful if Splunk included process mining as an alternative option. We have a threat workflow, but it would be useful if we could supplement that with some process mining capabilities over time.

    For how long have I used the solution?

    I have been using Splunk for a month. 

    What do I think about the stability of the solution?

    Splunk hasn't gone down since we started using it. 

    Which solution did I use previously and why did I switch?

    We previously had a solution that we developed in-house but recently started to use Splunk. Our in-house solution was unstable and had frequent issues, so we wanted something from a reliable vendor. We were already using other Splunk products, so we were familiar with the company.

    How was the initial setup?

    Splunk was quite easy to set up compared to similar products we've used.  to we are using few other things like this. For example, it was easier to deploy than New Relic. We finished the setup in two or three hours. 

    What other advice do I have?

    I rate Splunk User Behavior Analytics seven out of 10. There is still some room for Splunk to incorporate new capabilities and automate workflows. It's a solid solution for protecting against external threats like bots and unauthorized access. If you've experienced cybersecurity issues in the recent past, Splunk could help you develop a predictive approach based on user behavior. 

    Which deployment model are you using for this solution?

    Public Cloud

    If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

    Google
    Disclosure: I am a real user, and this review is based on my own experience and opinions.
    PeerSpot user
    Head of cybersecurity at NOVARED SA
    MSP
    A fast and flexible solution for conducting analytics on large data sets
    Pros and Cons
    • "The solution is fast, flexible, and easy to use."
    • "I would like improved downward integration with other tools such as McAfee and other GCP solutions."

    What is our primary use case?

    Four technicians in our company work within the active directory to look for compartmental behaviors associated with users and conduct analytics like clustering, grouping, and searching. 

    What is most valuable?

    The solution is fast, flexible, and easy to use. 

    What needs improvement?

    I would like improved downward integration with other tools such as McAfee and other GCP solutions. 

    For how long have I used the solution?

    I have been using the solution for four years. 

    What do I think about the stability of the solution?

    The solution is stable. 

    What do I think about the scalability of the solution?

    The solution is scalable. 

    How are customer service and support?

    Technical support is very good and answers my questions. 

    How was the initial setup?

    The initial setup is easy. 

    What other advice do I have?

    The solution works very well with large data sets. 

    I rate the solution a ten out of ten. 

    Which deployment model are you using for this solution?

    On-premises
    Disclosure: I am a real user, and this review is based on my own experience and opinions.
    PeerSpot user
    reviewer1679841 - PeerSpot reviewer
    Owner at a computer software company with 11-50 employees
    Real User
    Stable with good dashboards and a free demo version
    Pros and Cons
    • "The solution appears to be stable, although we haven't used it heavily."
    • "I'm not aware of any lacking features."

    What is our primary use case?

    We do technical training and so we do training on the platform. We deploy it on our lab machines for students.

    What is most valuable?

    We're building some Splunk dashboards with it and it's useful.

    We're currently monitoring students' log in, log out and verifying how they can collect the information. It's a good system for a learning environment. 

    We're not specifically using it, we're doing training on it.

    The solution appears to be stable, although we haven't used it heavily.

    You can use the demo version in order to try the solution for free.

    What needs improvement?

    I'm not aware of any lacking features. 

    For how long have I used the solution?

    I've been using the solution for six years. 

    What do I think about the stability of the solution?

    We don't generate enough data to know whether it's reliable or not.

    That said, with the small usage that we do utilize, it's pretty stable.

    How are customer service and support?

    I've never dealt with technical support. I cannot rate their services or speak to how helpful or responsive they are.

    Which solution did I use previously and why did I switch?

    We did not previously use a different solution before choosing Splunk. 

    How was the initial setup?

    The initial setup is pretty straightforward. It's a couple of scripts you run. It's pretty easy.

    What's my experience with pricing, setup cost, and licensing?

    We simply use the free demo version of the product. We do not pay any licensing fees at this time. 

    What other advice do I have?

    We're just end-users. We don't have a business relationship with Splunk.

    I'm not sure what version of the solution we are on currently. I believe it's about a year and a half or so old.

    This product is the easiest way to check if the work's correct.

    It works well. It does what we need it to. I'd rate it a ten out of ten.

    Disclosure: I am a real user, and this review is based on my own experience and opinions.
    PeerSpot user
    reviewer1418904 - PeerSpot reviewer
    Global Engineer at a financial services firm with 10,001+ employees
    Real User
    Stable, with good automation capabilities, however, we want to be able to automate even more
    Pros and Cons
    • "The product is at the forefront of auto-remediation networking. It's great."
    • "Currently, a lot of network operations need improvement. We still need people to handle incidents. Our vision is to leverage status and convert it directly from the network devices. It would be ideal if we could take action using APIs and API code and remove manual processes."

    What is our primary use case?

    We use the solution to feed telemetry data from the network into the collective for display-only. We haven't yet come to a point where we have decided on the process of the status for subsequent operational automation. 

    What is most valuable?

    The automation is very good.

    The product is at the forefront of auto-remediation networking. It's great.

    The pricing of the solution is very reasonable.

    What needs improvement?

    Currently, a lot of network operations need improvement. We still need people to handle incidents. Our vision is to leverage status and convert it directly from the network devices. It would be ideal if we could take action using APIs and API code and remove manual processes.  

    For how long have I used the solution?

    I've been using the solution for one year at this point.

    What do I think about the stability of the solution?

    The solution, from what I have witnessed, is stable. There aren't bugs or glitches. It doesn't crash or freeze. A company can rely on its performance.

    What do I think about the scalability of the solution?

    The scalability is pretty good. A company that wants to expand it out shouldn't have an issue doing so.

    There's a handful of people on it at my organization. We have maybe ten users on it in total. They are mostly admins and engineers. We do have plans to continue to use the solution.

    How are customer service and technical support?

    Technical support has been adequate. We aren't blown away by amazing service, however, they do help if we need them to. I personally haven't had any direct contact with them.

    Which solution did I use previously and why did I switch?

    We didn't previously use a different product. We're rather new to automation and Splunk in general.

    How was the initial setup?

    The solution doesn't have a complex setup. It's rather straightforward. 

    If you are talking of simply spinning off a container, it's very easy.

    The complexity should be on the workflow. It's also the most time-consiuming process. For example, how do you handle this incident? It has to be very careful to ensure you don't have false positives that could mistakenly trigger actions. That can to be the most costly mistake. Other than that, a lot of products you can acquire from open source.

    What about the implementation team?

    There were a few of us that were tained specifically for the implementation. There were a number of us to speed up the process in order to get automation happening quickly for hte company. 

    What's my experience with pricing, setup cost, and licensing?

    The solution isn't overly expensive. It's quite affordable. It's not the priciest option on the market. I'm not sure of the exact cost as its not an aspect of the solution I directly deal with.

    What other advice do I have?

    We're simply customers. We don't have a business relationship with Splunk.

    We're using the latest version of the solution. I'm not sure of the exact version number.

    I'd recommend the solution to other companies.

    On a scale from one to ten, I'd rate it at a seven. If the cost was more reasonable, I might rate it a bit higher. It's not too expensive, but it could always be better.

    Which deployment model are you using for this solution?

    On-premises
    Disclosure: I am a real user, and this review is based on my own experience and opinions.
    PeerSpot user
    CISO at a financial services firm with 201-500 employees
    Real User
    Professional technical team but I would like to see a more user-friendly interface
    Pros and Cons
    • "The solution is definitely scalable."
    • "In the future I would like to see simplified statistics and analytical threats."

    What is our primary use case?

    Our main use of this solution is threat intelligence and we are very satisfied with it, as it is exactly what we need in our situation. 

    What needs improvement?

    In the future I would like to see simplified statistics and analytical threats, as well as a more user-friendly interface for dashboards.

    For how long have I used the solution?

    I have been using Splunk User Behaviour Analytics for two years now.

    What do I think about the stability of the solution?

    I think the solution is very stable.

    What do I think about the scalability of the solution?

    The solution is definitely scalable, because we currently have 1000 users in our company and we plan to increase.

    How are customer service and technical support?

    I am really satisfied with their technical support. The technicians are very professional.

    What's my experience with pricing, setup cost, and licensing?

    The licensing costs is around 10,000 dollars.

    What other advice do I have?

    I will rate this product a seven out of ten, and I would definitely recommend it to others.

    Disclosure: I am a real user, and this review is based on my own experience and opinions.
    PeerSpot user
    Informat0a7b - PeerSpot reviewer
    Information Security Manager at a financial services firm with 201-500 employees
    Real User
    Enables searching through a lot of data, but pricing is problematic - you can't budget for it
    Pros and Cons
    • "The most valuable feature is the ability to search through a large amount of data."

      What is our primary use case?

      Threat hunting is our primary use case.

      How has it helped my organization?

      It hasn't really improved the way our organization functions. It has been neutral.

      We have, however, seen a decrease in the mean time to detect threats, by about 15 to 20 percent. We can do more hunting so we can find stuff quicker, but we had other tools that could also do that. It's not bad. It's fine.

      What is most valuable?

      The most valuable feature is the ability to search through a large amount of data.

      What needs improvement?

      The feature set isn't too bad as is. My biggest complaint is the way they do pricing.

      What do I think about the stability of the solution?

      It is fairly stable.

      What do I think about the scalability of the solution?

      It's scalable.

      How are customer service and technical support?

      I don't like their support.

      Which solution did I use previously and why did I switch?

      Our previous solution was a really limited version of what Splunk is. Splunk is the number-one leader in this area, so we went with it. It works. But it's the pricing model which is the problem. And you really don't understand upfront how bad the pricing model is until you get stuck with it.

      How was the initial setup?

      The initial setup was complex. There were a lot of moving pieces. It took a lot to get it going.

      What about the implementation team?

      We did not use an integrator or consultant.

      What was our ROI?

      There's a reason everyone is using other tools to reduce the cost of using Splunk. The ROI is not great, that's why. But once you already have all your data in it, if you have so much already invested in the infrastructure, it's hard to leave it, so you do other stuff to reduce the cost.

      What's my experience with pricing, setup cost, and licensing?

      Pricing is the problem with Splunk. You can never know the pricing for next year. Every single time you adjust to something new, the price goes up. It's impossible to truly budget for it. It goes up constantly. You can plan for 2x and it will be 3x. You only find out in the long run.

      What other advice do I have?

      I wouldn't buy Splunk because of the cost, because you can't budget for it. You think you can and then you find out later you can't.

      The company is still using it, but they're adding other pieces in to reduce the cost of Splunk. They're spending money to buy another product to pre-process so then they can save money on it.

      We've been improving and the maturity's pretty great. This is just one small piece in the overall platform. And the overall platform, from a cybersecurity maturity perspective, is doing well. If you look at it from that perspective, it's had a positive impact, it has not been a drag.

      The product itself is a seven out of ten. It's somewhat efficient, if you have the right staff and if everything's working properly. You have to have at least one person do care and feeding at the backend to make sure the infrastructure's working.

      Disclosure: I am a real user, and this review is based on my own experience and opinions.
      PeerSpot user
      Buyer's Guide
      Download our free Splunk User Behavior Analytics Report and get advice and tips from experienced pros sharing their opinions.
      Updated: March 2025
      Buyer's Guide
      Download our free Splunk User Behavior Analytics Report and get advice and tips from experienced pros sharing their opinions.