Elastic Security vs. Splunk User Behavior Analytics (UBA)

Overview
ProductRatingMost Used ByProduct SummaryStarting Price
Elastic Security
Score 8.8 out of 10
N/A
Elastic Security equips analysts to prevent, detect, and respond to threats. The free and open solution delivers SIEM, endpoint security, threat hunting, and cloud monitoring. The solution encompasses Elastic SIEM, which brings Elasticsearch to SIEM and threat hunting. The Elastic Agent (or Elastic Endpoint Security based on the former Endgame security product acquired by Elastic in late 2019) brings signatureless malware prevention to endpoints, as well as security data collection for…N/A
Splunk User Behavior Analytics (UBA)
Score 5.5 out of 10
N/A
Splunk supplies security analytics as a standalone solution or priced as an add-on for users of its popular SIEM products, to protect enterprises against unknown threats and malicious behavior, via the Splunk User Behavior Analytics (UBA) application.N/A
Pricing
Elastic SecuritySplunk User Behavior Analytics (UBA)
Editions & Modules
No answers on this topic
No answers on this topic
Offerings
Pricing Offerings
Elastic SecuritySplunk User Behavior Analytics (UBA)
Free Trial
NoNo
Free/Freemium Version
NoNo
Premium Consulting/Integration Services
NoNo
Entry-level Setup FeeNo setup feeNo setup fee
Additional Details
More Pricing Information
Community Pulse
Elastic SecuritySplunk User Behavior Analytics (UBA)
Top Pros
Top Cons
Best Alternatives
Elastic SecuritySplunk User Behavior Analytics (UBA)
Small Businesses
AlienVault USM
AlienVault USM
Score 8.0 out of 10
ActivTrak
ActivTrak
Score 8.8 out of 10
Medium-sized Companies
InsightIDR
InsightIDR
Score 8.6 out of 10
ActivTrak
ActivTrak
Score 8.8 out of 10
Enterprises
Microsoft Sentinel
Microsoft Sentinel
Score 8.4 out of 10
Darktrace
Darktrace
Score 8.6 out of 10
All AlternativesView all alternativesView all alternatives
User Ratings
Elastic SecuritySplunk User Behavior Analytics (UBA)
Likelihood to Recommend
9.0
(1 ratings)
10.0
(2 ratings)
Support Rating
7.0
(1 ratings)
9.0
(1 ratings)
User Testimonials
Elastic SecuritySplunk User Behavior Analytics (UBA)
Likelihood to Recommend
Elastic
I believe Endgame is well suited to organizations that have their own Cybersecurity department. Its not well suited for organizations that don't have a Cybersecurity department.
Read full review
Splunk
Splunk User Behavior Analytics application is necessary when any company wants to capture the threat based on user behavior instead of just counting the number of occurrences of particular event. With Splunk UBA, we can analyse number of anomalies captured and which in turn creating threats which are nearly true positive.
Read full review
Pros
Elastic
  • Identify 0-day malware.
  • Provides a few forensic details on endpoints.
  • Very easy to administer.
Read full review
Splunk
  • Monitor and troubleshoot for any system errors.
  • Get the insights on application data sets and do some predictive analysis.
Read full review
Cons
Elastic
  • I would love that it provided more memory analysis details.
  • Being able to edit sensor profiles after creating them.
  • I would love it if it provided more automation features.
Read full review
Splunk
  • Performance-wise, it can be improved. Queries take a long time.
  • Dataset exploration - More data visualization charts can be added.
Read full review
Support Rating
Elastic
Even though their support is good, I think there are some areas where they need to provide more thorough solutions to issues, some of their solutions are pretty basic and have already been tried.
Read full review
Splunk
No answers on this topic
Alternatives Considered
Elastic
Endgame is based on the MITRE framework which has proven to be a successful framework to identify various attack patterns that attackers use. Also, compared to the others it's easier to administer and manage.
Read full review
Splunk
Easier we were using Splunk Enterprise on heavy forwarder on which all the add-on were installed and were using Splunk Cloud with respect to search head and indexers stack. And with Splunk Enterprise Security premium app, we were relying on correlation rules which were throwing more number of false positive but after implementing Splunk UBA, we are now getting real-time true positive threat or incidents.
Read full review
Return on Investment
Elastic
  • Being able to identify threats we couldn't identify before.
  • Easier management of endpoints.
  • Being able to immediately isolate endpoints remotely that have high severity threats.
Read full review
Splunk
  • Fewer team members to work on real threats.
  • Less time required to deal with real incidents.
  • Easy to implement across the network.
Read full review
ScreenShots