ExtraHop Reveal(x) vs. Splunk User Behavior Analytics

Overview
ProductRatingMost Used ByProduct SummaryStarting Price
ExtraHop Reveal(x)
Score 9.9 out of 10
N/A
ExtraHop now offers Reveal(x), the company's network traffic analysis (NTA) and anomaly detection security application.
$1.69
per GB/per day
Splunk User Behavior Analytics
Score 10.0 out of 10
N/A
Splunk supplies security analytics as a standalone solution or priced as an add-on for users of its popular SIEM products, to protect enterprises against unknown threats and malicious behavior, via the Splunk User Behavior Analytics application.N/A
Pricing
ExtraHop Reveal(x)Splunk User Behavior Analytics
Editions & Modules
Additional Record Capacity
$1.69
per GB/per day
On-Demand Record Capacity
$1.69
per GB
AWS Cloud Sensor Size and List Pricing - X Small
$5.04
per hour
AWS Ultra Sensor for Packet Capture - X Small
$8
per hour
AWS Cloud Sensor Size and List Pricing - Small
$12.34
per hour
AWS Cloud Sensor Size and List Pricing - Medium
$18.76
per hour
AWS Ultra Sensor for Packet Capture - Small
$24.33
per hour
No answers on this topic
Offerings
Pricing Offerings
ExtraHop Reveal(x)Splunk User Behavior Analytics
Free Trial
NoNo
Free/Freemium Version
NoNo
Premium Consulting/Integration Services
NoNo
Entry-level Setup FeeNo setup feeNo setup fee
Additional Details
More Pricing Information
Community Pulse
ExtraHop Reveal(x)Splunk User Behavior Analytics
Considered Both Products
ExtraHop Reveal(x)
Chose ExtraHop Reveal(x)
I evaluated ExtraHop against Dark Trace. Against all criteria, ExtraHop had a clear edge including visibility, price, effectiveness, integrations, and more.
Splunk User Behavior Analytics
Chose Splunk User Behavior Analytics
Easier we were using Splunk Enterprise on heavy forwarder on which all the add-on were installed and were using Splunk Cloud with respect to search head and indexers stack. And with Splunk Enterprise Security premium app, we were relying on correlation rules which were throwing …
Chose Splunk User Behavior Analytics
Splunk UBA is a great debugging tool, and it helps me analyze the application logs and get a better idea about the problem. It also helps in analyzing the user behavior in a nutshell over the entire application.
Best Alternatives
ExtraHop Reveal(x)Splunk User Behavior Analytics
Small Businesses
Auvik
Auvik
Score 8.8 out of 10
ActivTrak
ActivTrak
Score 8.5 out of 10
Medium-sized Companies
SolarWinds NetFlow Traffic Analyzer (NTA)
SolarWinds NetFlow Traffic Analyzer (NTA)
Score 9.2 out of 10
ManageEngine ADAudit Plus
ManageEngine ADAudit Plus
Score 9.0 out of 10
Enterprises
SolarWinds NetFlow Traffic Analyzer (NTA)
SolarWinds NetFlow Traffic Analyzer (NTA)
Score 9.2 out of 10
ManageEngine ADAudit Plus
ManageEngine ADAudit Plus
Score 9.0 out of 10
All AlternativesView all alternativesView all alternatives
User Ratings
ExtraHop Reveal(x)Splunk User Behavior Analytics
Likelihood to Recommend
10.0
(0 ratings)
10.0
(0 ratings)
Usability
8.0
(0 ratings)
-
(0 ratings)
Support Rating
-
(0 ratings)
9.0
(0 ratings)
User Testimonials
ExtraHop Reveal(x)Splunk User Behavior Analytics
Likelihood to Recommend
ExtraHop is a must have for on-premise environments where traffic passes through a physical data centre or network operations centre giving complete visibility into what is happening on the corporate network. This works flawlessly if business operations are in office. For hybrid or remote setups, the solution still works well by placing ExtraHop traffic between the VPN termination and firewall and setting up a span port. ExtraHop works well for cloud based deployments as well with their virtual appliances; however, it does not have the same edge against competition as many CNAPP solutions can gather similar data using graph API's provided by the cloud service provider. That said, ExtraHop does provide some unique features that CNAPP's do not around network operations.
Read full review
Splunk is well suited for applications with large amounts of data, and large enterprise applications. Especially if the application has interconnected modules, it helps us to analyze and monitor the application greatly.
Read full review
Pros
  • Network discovery
  • Network based detections for suspicious/malicious activity and behaviour
  • Insight into data flow between systems
  • Visibility into network errors
Read full review
  • Monitor and troubleshoot for any system errors.
  • Get the insights on application data sets and do some predictive analysis.
Read full review
Cons
No answers on this topic
  • Performance-wise, it can be improved. Queries take a long time.
  • Dataset exploration - More data visualization charts can be added.
Read full review
Usability
Console is easy to use use and familiarize oneself with. Some points deducted as it can be annoying at times to have to drill down using the drop down menu, and then selecting tabs to get the data you want.
Read full review
No answers on this topic
Alternatives Considered
I evaluated ExtraHop against Dark Trace. Against all criteria, ExtraHop had a clear edge including visibility, price, effectiveness, integrations, and more.
Read full review
Easier we were using Splunk Enterprise on heavy forwarder on which all the add-on were installed and were using Splunk Cloud with respect to search head and indexers stack. And with Splunk Enterprise Security premium app, we were relying on correlation rules which were throwing more number of false positive but after implementing Splunk UBA, we are now getting real-time true positive threat or incidents.
Read full review
Return on Investment
  • Increased visibility into network based attacks
  • Increase visibility into data flows aiding in data loss prevention capabilities
  • Assisting network infrastructure teams with visibility into network based performance metrics
Read full review
  • Fewer team members to work on real threats.
  • Less time required to deal with real incidents.
  • Easy to implement across the network.
Read full review
ScreenShots