FortiSIEM vs. Splunk User Behavior Analytics

Overview
ProductRatingMost Used ByProduct SummaryStarting Price
FortiSIEM
Score 7.7 out of 10
N/A
Fortinet offers security information and event management via FortiSIEM, their product line featuring asset discovery and rapid assessment for location of threat and their remediation.N/A
Splunk User Behavior Analytics
Score 10.0 out of 10
N/A
Splunk supplies security analytics as a standalone solution or priced as an add-on for users of its popular SIEM products, to protect enterprises against unknown threats and malicious behavior, via the Splunk User Behavior Analytics application.N/A
Pricing
FortiSIEMSplunk User Behavior Analytics
Editions & Modules
No answers on this topic
No answers on this topic
Offerings
Pricing Offerings
FortiSIEMSplunk User Behavior Analytics
Free Trial
NoNo
Free/Freemium Version
NoNo
Premium Consulting/Integration Services
NoNo
Entry-level Setup FeeNo setup feeNo setup fee
Additional Details
More Pricing Information
Community Pulse
FortiSIEMSplunk User Behavior Analytics
Features
FortiSIEMSplunk User Behavior Analytics
Security Information and Event Management (SIEM)
Comparison of Security Information and Event Management (SIEM) features of Product A and Product B
FortiSIEM
5.3
1 Ratings
40% below category average
Splunk User Behavior Analytics
-
Ratings
Centralized event and log data collection6.01 Ratings00 Ratings
Correlation7.01 Ratings00 Ratings
Event and log normalization/management6.01 Ratings00 Ratings
Deployment flexibility3.01 Ratings00 Ratings
Custom dashboards and workspaces4.01 Ratings00 Ratings
Host and network-based intrusion detection6.01 Ratings00 Ratings
Best Alternatives
FortiSIEMSplunk User Behavior Analytics
Small Businesses
LevelBlue USM Anywhere
LevelBlue USM Anywhere
Score 7.5 out of 10
ActivTrak
ActivTrak
Score 8.6 out of 10
Medium-sized Companies
Sumo Logic
Sumo Logic
Score 8.8 out of 10
ManageEngine ADAudit Plus
ManageEngine ADAudit Plus
Score 9.0 out of 10
Enterprises
Sumo Logic
Sumo Logic
Score 8.8 out of 10
ManageEngine ADAudit Plus
ManageEngine ADAudit Plus
Score 9.0 out of 10
All AlternativesView all alternativesView all alternatives
User Ratings
FortiSIEMSplunk User Behavior Analytics
Likelihood to Recommend
6.0
(1 ratings)
10.0
(2 ratings)
Support Rating
-
(0 ratings)
9.0
(1 ratings)
User Testimonials
FortiSIEMSplunk User Behavior Analytics
Likelihood to Recommend
Fortinet
If budget is an issue then Fortisiem fits well, as it's more than a typical SIEM solution. It can integrate with environmental monitoring systems, UPS HVAC etc. It can be used as the CMDB solution etc. If fine-tuned and looked after it can actually bring a lot of value for less.
Read full review
Cisco
Splunk User Behavior Analytics application is necessary when any company wants to capture the threat based on user behavior instead of just counting the number of occurrences of particular event. With Splunk UBA, we can analyse number of anomalies captured and which in turn creating threats which are nearly true positive.
Read full review
Pros
Fortinet
  • Log aggregation and analytics
  • CMDB
  • Device inventory and remote management .
  • It can be used by Managed Security Providers who have multiple customers as it offers multi organization support .
Read full review
Cisco
  • Monitor and troubleshoot for any system errors.
  • Get the insights on application data sets and do some predictive analysis.
Read full review
Cons
Fortinet
  • Non-intuitive/unattractive user interface
  • Too many features that will usually remain unused
  • Very crowded (too many icons) portal
  • The reporting feature is confusing, e.g. you have to click on the "refresh" button to get the result of your inquiry. The report generation process can be much easier, as the user interaction is not pleasant.
Read full review
Cisco
  • Performance-wise, it can be improved. Queries take a long time.
  • Dataset exploration - More data visualization charts can be added.
Read full review
Alternatives Considered
Fortinet
No answers on this topic
Cisco
Easier we were using Splunk Enterprise on heavy forwarder on which all the add-on were installed and were using Splunk Cloud with respect to search head and indexers stack. And with Splunk Enterprise Security premium app, we were relying on correlation rules which were throwing more number of false positive but after implementing Splunk UBA, we are now getting real-time true positive threat or incidents.
Read full review
Return on Investment
Fortinet
  • Other SIEM solutions were cost prohibitive at the time of purchase (2016).
  • Just like any other SIEM, it helped draw a better picture of our current security posture.
Read full review
Cisco
  • Fewer team members to work on real threats.
  • Less time required to deal with real incidents.
  • Easy to implement across the network.
Read full review
ScreenShots