Try our new research platform with insights from 80,000+ expert users

Elastic Search vs Splunk User Behavior Analytics comparison

 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

ROI

Sentiment score
6.4
Elastic Search offers high ROI, efficiency, and cost-effectiveness, with significant time-saving and security benefits despite some licensing costs.
Sentiment score
6.4
Users report varied ROI from Splunk, with productivity gains and security cost savings, but costs remain a concern.
We have not purchased any licensed products, and our use of Elastic Search is purely open-source, contributing positively to our ROI.
It is stable, and we do not encounter critical issues like server downtime, which could result in data loss.
The main benefits observed from using Elastic Search include improvements in operational efficiency, along with cost, time, and resource savings.
The solution can save costs by improving incident resolution times and reducing security incident costs.
 

Customer Service

Sentiment score
6.5
Elastic Search's customer service is praised for responsiveness and knowledge, but complex issue support may require improvement.
Sentiment score
6.8
Splunk User Behavior Analytics support is mostly praised, with professional service, tiered options, and valuable user groups enhancing experience.
I would rate technical support from Elastic Search as three out of ten.
Mission-critical offering a dedicated team, proactive monitoring, and fast resolution.
From the responsiveness perspective, Splunk is very responsive with SLA-bound support for premium tiers.
I would rate the support at eight, meaning there's some room for improvement.
 

Scalability Issues

Sentiment score
7.3
Elastic Search is scalable and integrates well, but challenges exist with large datasets and disaster recovery under rapid scaling.
Sentiment score
7.5
Splunk User Behavior Analytics is scalable and adaptable across environments, though storage limitations may affect scalability.
I would rate its scalability a ten.
I can actually add more storage and memory because I host it in the cloud.
I would rate the scalability of Elasticsearch as an eight.
Splunk User Behavior Analytics is highly scalable, designed for enterprise scalability, allowing expansion of data ingestion, indexing, and search capabilities as log volumes grow.
 

Stability Issues

Sentiment score
7.7
Elastic Search is stable and reliable, though version updates and data management can affect performance under stress.
Sentiment score
8.1
Splunk User Behavior Analytics offers reliable performance and stability, with 99.9% uptime and ease of configuration in enterprises.
The data transfer sometimes exceeded the bandwidth limits without proper notification, which caused issues.
The stability of Elasticsearch was very high.
With built-in redundancy across zones and regions, 99.9% uptime is achievable.
Splunk User Behavior Analytics is a one hundred percent stable solution.
Splunk User Behavior Analytics is highly stable and reliable, even in large-scale enterprise environments with high log injection rates.
 

Room For Improvement

Elastic Search needs improvements in security, scalability, usability, stability, integration, support, and enhanced features for a better user experience.
Splunk User Behavior Analytics needs better pricing, integration, user-friendly interfaces, enhanced features, and improved scalability and infrastructure.
This can create problems for new developers because they have to quickly switch to another version.
It is primarily based on Unix or Linux-based operating systems and cannot be easily configured in Windows systems.
The consistency and stability of Elasticsearch are commendable, and they should keep up the good work.
Global reach allows deployment of apps and services closer to users worldwide, but data sovereignty concerns exist and region selection must align with compliance requirements.
I encountered several issues while trying to create solutions for this advanced version, which seem unrelated to query or data issues.
High data ingestion costs can be an issue, especially for large enterprises, as Splunk charges based on the amount of data processed.
 

Setup Cost

Elastic Search's free open-source version can incur back-end costs for advanced features, expertise, and premium support.
Enterprise buyers find Splunk's User Behavior Analytics costly, with variable pricing based on data, hardware, and additional applications.
We used the open-source version of Elasticsearch, which was free.
Reserved instances with one or three-year commitments offer lower rates, providing up to 70% savings.
Comparing with the competitors, it's a bit expensive.
The pricing is based on the amount of data processed, and it is considered a high-level investment for enterprises.
 

Valuable Features

Elastic Search is valued for scalability, fast indexing, powerful analysis, security features, cloud readiness, and strong community support.
Splunk User Behavior Analytics provides scalable, user-friendly threat detection with advanced analytics, machine learning, and seamless data integration and reporting.
Elastic Search makes handling large data volumes efficient and supports complex search operations.
The most valuable feature of Elasticsearch was the quick search capability, allowing us to search by any criteria needed.
Aggregation is faster than querying directly from a database, like Postgres or Vertica.
I also utilize it for anomaly detection and behavior analysis, particularly using Splunk's machine learning environment.
Features like alerts and auto report generation are valuable.
Splunk User Behavior Analytics offers several beneficial features, such as Insider Threat Detection, account compromise detection, risk scoring, threat detection, and machine anomaly detection.
 

Categories and Ranking

Elastic Search
Average Rating
8.2
Reviews Sentiment
6.8
Number of Reviews
71
Ranking in other categories
Indexing and Search (1st), Cloud Data Integration (9th), Search as a Service (1st), Vector Databases (3rd)
Splunk User Behavior Analytics
Average Rating
8.2
Reviews Sentiment
6.8
Number of Reviews
24
Ranking in other categories
Intrusion Detection and Prevention Software (IDPS) (12th), User Entity Behavior Analytics (UEBA) (4th)
 

Mindshare comparison

Elastic Search and Splunk User Behavior Analytics aren’t in the same category and serve different purposes. Elastic Search is designed for Indexing and Search and holds a mindshare of 23.1%, down 27.8% compared to last year.
Splunk User Behavior Analytics, on the other hand, focuses on User Entity Behavior Analytics (UEBA), holds 8.9% mindshare, down 11.1% since last year.
Indexing and Search
User Entity Behavior Analytics (UEBA)
 

Featured Reviews

Anand_Kumar - PeerSpot reviewer
Captures data from all other sources and becomes a MOM aka monitoring of monitors
Scalability and ROI are the areas they have to improve. Their license terms are based on the number of cores. If you increase the number of cores, it becomes very difficult to manage at a large scale. For example, if I have a $3 million project, I won't sell it because if we're dealing with a 10 TB or 50 TB system, there are a lot of systems and applications to monitor, and I have to make an MOM (Mean of Max) for everything. This is because of the cost impact. Also, when you have horizontal scaling, it's like a multi-story building with only one elevator. You have to run around, and it's not efficient. Even the smallest task becomes difficult. That's the problem with horizontal scaling. They need to improve this because if they increase the cores and adjust the licensing accordingly, it would make more sense.
Subhayu Chakraborty - PeerSpot reviewer
Automatic reports streamline tasks and offers easy report gathering
The dashboard part could be improved. While using it, I noticed two options: Classic, which is adequate yet only in black and white, and another one that is more advanced or smart, though I forgot the exact term. I encountered several issues while trying to create solutions for this advanced version, which seem unrelated to query or data issues.
report
Use our free recommendation engine to learn which Indexing and Search solutions are best for your needs.
860,592 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Computer Software Company
16%
Financial Services Firm
14%
Manufacturing Company
9%
Government
9%
Computer Software Company
17%
Financial Services Firm
12%
Government
9%
Manufacturing Company
8%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

What do you like most about ELK Elasticsearch?
Logsign provides us with the capability to execute multiple queries according to our requirements. The indexing is very high, making it effective for storing and retrieving logs. The real-time anal...
What is your experience regarding pricing and costs for ELK Elasticsearch?
We used the open-source version of Elasticsearch, which was free.
What needs improvement with ELK Elasticsearch?
It would be useful if a feature for renaming indices could be added without affecting the performance of other features. However, overall, the consistency and stability of Elasticsearch are already...
What do you like most about Splunk User Behavior Analytics?
The solution's most valuable feature is Splunk queries, which allow us to query the logs and analyze the attack vectors.
What is your experience regarding pricing and costs for Splunk User Behavior Analytics?
In terms of setup cost, pricing, and licensing, Splunk User Behavior Analytics is not an inexpensive product. The setup requires numerous components including storage, networking, identity access, ...
What needs improvement with Splunk User Behavior Analytics?
There are improvements that could be made to Splunk User Behavior Analytics as any product will have advantages and disadvantages. Scalability is one consideration. For example, the advantages incl...
 

Also Known As

Elastic Enterprise Search, Swiftype, Elastic Cloud
Caspida, Splunk UBA
 

Overview

 

Sample Customers

T-Mobile, Adobe, Booking.com, BMW, Telegraph Media Group, Cisco, Karbon, Deezer, NORBr, Labelbox, Fingerprint, Relativity, NHS Hospital, Met Office, Proximus, Go1, Mentat, Bluestone Analytics, Humanz, Hutch, Auchan, Sitecore, Linklaters, Socren, Infotrack, Pfizer, Engadget, Airbus, Grab, Vimeo, Ticketmaster, Asana, Twilio, Blizzard, Comcast, RWE and many others.
8 Securities, AAA Western, AdvancedMD, Amaya, Cerner Corporation, CJ O Shopping, CloudShare, Crossroads Foundation, 7-Eleven Indonesia
Find out what your peers are saying about Elastic Search vs. Splunk User Behavior Analytics and other solutions. Updated: January 2022.
860,592 professionals have used our research since 2012.