Splunk has features that no other solutions have. We work in organizations that have a big volume of data. Our primary use case of this solution is for indexing. The best solution that we found that could fit our needs was Splunk.
Information Security Specialist at a financial services firm with 201-500 employees
Has powerful search, indexing, and scalability features
Pros and Cons
- "The most valuable features are the indexing and powerful search features."
- "The correlation engine should have persistent and definable rules."
What is our primary use case?
What is most valuable?
The most valuable features are the indexing and powerful search features.
What needs improvement?
The correlation engine should have persistent and definable rules. Splunk should have more features and options in regards to correlating in real-time. It should have the ability to set more permanent rules.
Correlation capabilities in ArcSight are better than in Splunk.
For how long have I used the solution?
I have been using Splunk for more than three years.
Buyer's Guide
Splunk User Behavior Analytics
December 2024
Learn what your peers think about Splunk User Behavior Analytics. Get advice and tips from experienced pros sharing their opinions. Updated: December 2024.
831,265 professionals have used our research since 2012.
What do I think about the stability of the solution?
The stability is good. It's reliable and can be used in enterprise environments.
What do I think about the scalability of the solution?
It is a scalable solution and can support many users. The scalability is another powerful feature of this solution.
We have around ten users using this solution in our company. We also provide this solution to our subsidiary companies so there are more than twenty users.
How are customer service and support?
We are in Iran and are under U.S. sanctions so we can only use online forums for support. We can't use their technical support.
How was the initial setup?
The initial setup was easy.
What about the implementation team?
We did the implementation in-house.
What's my experience with pricing, setup cost, and licensing?
Our licensing costs are on a yearly basis.
Which other solutions did I evaluate?
We researched many solutions before choosing Splunk like LogRhythm, ELK, and FortiSIEM.
What other advice do I have?
After more than three years of using this solution, I would recommend this solution, especially for environments that have a big volume of data. I would rate this solution a nine out of ten. It is a really great product.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
BS Systems Engineer at a tech services company with 501-1,000 employees
Great source for measuring customer satisfaction
Pros and Cons
- "It is a solution that helps test and measure customer satisfaction."
- "There are occasional bugs."
How has it helped my organization?
In Egypt, we have phones that provide wide internet services to the customer and the customer wants to know what the customer satisfaction and service was. Then, they post on their Facebook or Twitter page to measure the customer satisfaction and after one or two days they start to take the comments and they enter these comments to Splunk and the UBA starts to make correlations and analytics on this data. Finally, the managers or the decision maker get the results, which is wonderful, and the customer is satisfied. These results help to improve customer satisfaction.
What needs improvement?
Splunk can improve the UBA. There are occasional bugs, but they're not so much of an issue.
We can definitely improve the features, but it depends on the customer's needs. We need to modify or create new dashboards that increase the customer's satisfaction and customer's needs. It depends upon the customer. Not all of the pre-defined dashboards are suitable to the customers or the customer needs on the pre-defined dashboard so we can create dashboards that meet the customer needs.
For how long have I used the solution?
One to three years.
What do I think about the scalability of the solution?
The scalability of UBA is very useful and helpful but in our country, there is no such need. The customers need UBA as latent data storage. They don't know the efficiency and the usefulness of the app but I think in the near future it will have a better use.
How is customer service and technical support?
The last time we needed tech support help it was in order to restore some data from frozen parts. They clarified that the data was restored and the bug didn't affect restoring the data.
What's my experience with pricing, setup cost, and licensing?
I hope we can increase the free license to be more than five gig a day. This would help people who want to introduce a POC or a demo license for the solution.
What other advice do I have?
It is a helpful tool, especially for customers who deal with the service industry.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Buyer's Guide
Splunk User Behavior Analytics
December 2024
Learn what your peers think about Splunk User Behavior Analytics. Get advice and tips from experienced pros sharing their opinions. Updated: December 2024.
831,265 professionals have used our research since 2012.
Network Security Engineer at a tech services company with 51-200 employees
Easy to use with a great dashboard and a simple setup
Pros and Cons
- "It's easily scalable."
- "We'd like the ability to do custom searches."
What is our primary use case?
We have been using it for performing analytics for the logs.
We resell it to our customers. We are also using the tool so that we can build more use cases for our clients. We basically look into understanding how it is performing analytics with Office 365 and how it is correlating those things.
What is most valuable?
For us, it has been working great as of now.
We enjoy the overall usability. You just look at the dashboard and you have all the data that you need at a glance. That is probably the best part, I would say. It's easy enough to understand that anyone can pick it up.
My understanding is that the setup is easy.
The solution is stable.
It's easily scalable.
What needs improvement?
UBA is a separate tool and it should be a part of the Splunk base itself so that we can download it. It should be easier to use just like the normal Splunk in that we should be able to put in queries or add custom things.
We'd like the ability to do custom searches.
For how long have I used the solution?
I've been using the solution for the last three months.
What do I think about the stability of the solution?
It's a stable, reliable product with good performance. There aren't bugs or glitches. It doesn't crash or freeze.
What do I think about the scalability of the solution?
It is a scalable product. It can expand with ease.
How are customer service and support?
I've never dealt with technical support.
Which solution did I use previously and why did I switch?
We use all different types of solutions from Splunk, whether it is the SIEM, or ITSI, or even Splunk Enterprise. It's all Splunk. That it's.
We have not used SignalFx. We have been looking into it, however.
How was the initial setup?
From what I have heard, the setup is easy, although I did not set it up myself.
What's my experience with pricing, setup cost, and licensing?
I'm not sure of the exact licensing fees.
What other advice do I have?
I'm not sure which version of the solution we're using.
We have been using Splunk for a while, and we were looking for some solutions that incorporate a lot of ML and AI to get insights into the activities that are going on in the user's end devices. We feel that UBA was a much better solution than other options. There are different products, however, we went with Splunk as we have been using other Splunk tools for a while now.
I'd recommend the product to others.
I would rate the solution eight out of ten due to the lack of custom search and the fact it is sort of disconnected from the complete Splunk environment.
Which deployment model are you using for this solution?
Public Cloud
Disclosure: My company has a business relationship with this vendor other than being a customer: Reseller
IT Consultant at Red Hat
It has the ability to automatically identify a number of threats, then suggest recommended actions upon them
Pros and Cons
- "The most valuable features are its data aggregation and the ability to automatically identify a number of threats, then suggest recommended actions upon them."
- "It could be easier to scale the solution if you are using it on-premise, not in the cloud."
What is our primary use case?
We are performing a couple of integrations with other products.
We are using the latest version that is available.
How has it helped my organization?
Right now we are working with them as partners, so is more of an integration play. I am not personally using it internally. There is another team that is using it as a consumer. For me, it's more of a technical integration.
What is most valuable?
The most valuable features are its data aggregation and the ability to automatically identify a number of threats, then suggest recommended actions upon them.
What needs improvement?
I would love to see more integration with other solutions and the ability to perform some actions straightaway from the dashboard.
What do I think about the stability of the solution?
It is stable.
What do I think about the scalability of the solution?
It could be easier to scale the solution if you are using it on-premise, not in the cloud.
What other advice do I have?
There is a lot of potential in the product. We have seen the product grow over time. There is potential to grow a bit more and become more proactive than it is right now.
First assess the use cases. Then, assess the scale and complexity of the use cases that you are trying to solve before implementing the solution. Do not try to find a solution which fits the use case after the implementation.
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner.
Buyer's Guide
Download our free Splunk User Behavior Analytics Report and get advice and tips from experienced pros
sharing their opinions.
Updated: December 2024
Product Categories
User Entity Behavior Analytics (UEBA) Intrusion Detection and Prevention Software (IDPS)Popular Comparisons
IBM Security QRadar
Rapid7 InsightIDR
LogRhythm UEBA
Proofpoint Insider Threat Management
Gurucul UEBA
ArcSight Intelligence
Dtex Systems
Securonix UEBA
ArcSight Analytics
Netskope Advanced Analytics
Buyer's Guide
Download our free Splunk User Behavior Analytics Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- Which is the best UEBA solution?
- Viable, Cost-Effective Competitors to Rapid7 InsightIDK
- What is your recommended cost-effective solution to detect and prevent APT attacks?
- Looking for recommendations and a pros/cons template for software to detect insider threats
- What are the main differences between UEBA and SIEM solutions?
- Monitoring Web Hosted Servers for unwanted guests
- Which is the best UEBA solution?
- What are the different types of insider threats that UEBA solutions help to detect?
- Which UEBA solution do you recommend and why?
- What is the best UEBA solution?