FortiAnalyzer vs. Splunk User Behavior Analytics (UBA)

Overview
ProductRatingMost Used ByProduct SummaryStarting Price
FortiAnalyzer
Score 8.6 out of 10
N/A
As part of the Fortinet Security Fabric, FortiAnalyzer provides security fabric analytics and automation to provide better detection and response against cyber risks.N/A
Splunk User Behavior Analytics (UBA)
Score 7.2 out of 10
N/A
Splunk supplies security analytics as a standalone solution or priced as an add-on for users of its popular SIEM products, to protect enterprises against unknown threats and malicious behavior, via the Splunk User Behavior Analytics (UBA) application.N/A
Pricing
FortiAnalyzerSplunk User Behavior Analytics (UBA)
Editions & Modules
No answers on this topic
No answers on this topic
Offerings
Pricing Offerings
FortiAnalyzerSplunk User Behavior Analytics (UBA)
Free Trial
NoNo
Free/Freemium Version
NoNo
Premium Consulting/Integration Services
NoNo
More Pricing Information
Community Pulse
FortiAnalyzerSplunk User Behavior Analytics (UBA)
Top Pros
Top Cons
User Ratings
FortiAnalyzerSplunk User Behavior Analytics (UBA)
Likelihood to Recommend
10.0
(1 ratings)
10.0
(2 ratings)
Usability
10.0
(1 ratings)
-
(0 ratings)
Support Rating
-
(0 ratings)
9.0
(2 ratings)
User Testimonials
FortiAnalyzerSplunk User Behavior Analytics (UBA)
Likelihood to Recommend
Fortinet
FortiAnalyzer is a must have when you administer multiple FortiGate firewalls in a defense in depth enterprise environment. Total visibility can be achieved across multiple physical and virtual firewalls. Complete analysis of your threat landscape is possible along with real time detection, compliance reporting, and wholistic firewall rule analysis and reporting. Eliminating shadow rules, tuning unnecessarily permissive rules, automation and other analysis are built in to this easy to deploy software.
Read full review
Splunk
Splunk User Behavior Analytics application is necessary when any company wants to capture the threat based on user behavior instead of just counting the number of occurrences of particular event. With Splunk UBA, we can analyse number of anomalies captured and which in turn creating threats which are nearly true positive.
Read full review
Pros
Fortinet
  • Event correlation
  • Real-time detection
  • Compliance Reporting
  • Security Tools orchestration
  • Security workflow automation
  • Integration with ServiceNOW
  • Centralized NOC/SOC visibility
Read full review
Splunk
  • Monitor and troubleshoot for any system errors.
  • Get the insights on application data sets and do some predictive analysis.
Read full review
Cons
Fortinet
  • Administrative Domains and Software Versions are difficult to maintain
  • managing different FortiOS versions gets complicated quite easily
  • Administrative Domains must be well architected from the beginning
Read full review
Splunk
  • Performance-wise, it can be improved. Queries take a long time.
  • Dataset exploration - More data visualization charts can be added.
Read full review
Usability
Fortinet
FortiAnalyzer is easy to deploy are ready to use right out of the box. The user interface is intuitive and the reporting engine is very customizable however most of the 'canned' reports are usable right away. It is easy to add firewalls under management and event correlation happens immediately. FortiAnalyzer is a great log aggregator for all of your firewalls and then upload meaningful data to a SEIM.
Read full review
Splunk
No answers on this topic
Alternatives Considered
Fortinet
FortiAnalyzer is significantly cheaper and a better value for the money especially if you have FortiGate firewalls in the datacenter or in the cloud. FortiAnalyzer manages physical, virtual, and cloud firewalls in a single pane of glass providing a wholistic enterprise view of your security landscape. Compliance reporting comes built-in with the most popular reports ready at a click of a button. FortiAnalyzer is a great aggregation point before uploading logs to a SEIM / SOC tool.
Read full review
Splunk
Easier we were using Splunk Enterprise on heavy forwarder on which all the add-on were installed and were using Splunk Cloud with respect to search head and indexers stack. And with Splunk Enterprise Security premium app, we were relying on correlation rules which were throwing more number of false positive but after implementing Splunk UBA, we are now getting real-time true positive threat or incidents.
Read full review
Return on Investment
Fortinet
  • we were able to retire 3 legacy security tools in favor of FortiAnalyzer
  • Automate 155 security tasks and reporting
  • one click compliance reporting for PCI-DSS
  • Enterprise security governance
  • Visualize the security landscape
  • Eliminate and or prune unnecessary rules
  • Tune overly permissive rules for tighter security
Read full review
Splunk
  • Fewer team members to work on real threats.
  • Less time required to deal with real incidents.
  • Easy to implement across the network.
Read full review