No more typing reviews! Try our Samantha, our new voice AI agent.

Microsoft Purview Insider Risk Management vs Splunk User Behavior Analytics comparison

 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

ROI

Sentiment score
6.6
Microsoft Purview boosted ROI by enhancing data protection, efficiency, and compliance, reducing false positives, and involving external agencies.
Sentiment score
5.9
Splunk User Behavior Analytics improves productivity and ROI, with significant investment offset by enhanced data integration and strategic implementation.
Purview saved us from potential lawsuits and the loss of confidential information, preventing legal issues.
Manager, Information Technology Security Compliance at a manufacturing company with 201-500 employees
The one example that I provided was worth significant attention, as the FBI and other organizations became involved, so I am assuming it was really important.
IC Sharepoint Administrator at a healthcare company with 1,001-5,000 employees
The solution can save costs by improving incident resolution times and reducing security incident costs.
Enterprise Architect at Wipro Limited
 

Customer Service

Sentiment score
4.8
Microsoft Purview Insider Risk Management's support varies by tier, with premium support praised and regular service facing challenges.
Sentiment score
6.8
Splunk User Behavior Analytics support is generally well-rated, with satisfaction varying by support tier and community resources valued.
Premium support provides excellent service, but it can be challenging for customers who cannot afford it.
Director at Scybers
Overall, I had a few issues, so I would rate the service a nine for Purview.
Manager, Information Technology Security Compliance at a manufacturing company with 201-500 employees
Mission-critical offering a dedicated team, proactive monitoring, and fast resolution.
Enterprise Architect at Wipro Limited
From the responsiveness perspective, Splunk is very responsive with SLA-bound support for premium tiers.
Enterprise Architect at Wipro Limited
I would rate their technical support as 8.5 out of 10.
Director at Techpace
 

Scalability Issues

Sentiment score
7.7
Microsoft Purview Insider Risk Management is praised for scalability, automation, policy creation, and multi-location efficiency despite alert speed concerns.
Sentiment score
7.3
Splunk User Behavior Analytics excels in scalability, supporting vast data and devices, despite some storage limitations for long-term logs.
The capability of creating policies to facilitate detections and responses improved.
Manager, Information Technology Security Compliance at a manufacturing company with 201-500 employees
I believe Microsoft Purview Insider Risk Management scales well with the growing needs of the organization.
IC Sharepoint Administrator at a healthcare company with 1,001-5,000 employees
Splunk User Behavior Analytics is highly scalable, designed for enterprise scalability, allowing expansion of data ingestion, indexing, and search capabilities as log volumes grow.
Enterprise Architect at Wipro Limited
 

Stability Issues

Sentiment score
7.6
Microsoft Purview Insider Risk Management is stable, dependable, and quickly resolves issues, with improved integration over time.
Sentiment score
7.9
Splunk User Behavior Analytics is stable, reliable, and user-friendly, excelling in enterprise environments with high log volumes.
We have experienced minimal downtime, with Microsoft resolving issues within five to ten minutes maximum.
Director at Scybers
I would assess the stability and reliability of Microsoft Purview Insider Risk Management as having improved.
IC Sharepoint Administrator at a healthcare company with 1,001-5,000 employees
With built-in redundancy across zones and regions, 99.9% uptime is achievable.
Enterprise Architect at Wipro Limited
Splunk User Behavior Analytics is a one hundred percent stable solution.
Cloud Solution Architect at Tech Mahindra Limited
Splunk User Behavior Analytics is highly stable and reliable, even in large-scale enterprise environments with high log injection rates.
Enterprise Architect at Wipro Limited
 

Room For Improvement

Microsoft Purview Insider Risk Management needs better alert customization, simplified UI, affordable pricing, optimized ML components, and non-Microsoft integration.
Splunk User Behavior Analytics needs enhancements in dashboards, integration, pricing, support, automation, machine learning, configuration, and storage management.
Microsoft's pricing is very expensive.
Director at Scybers
I feel Microsoft Purview Insider Risk Management can be improved by being able to identify patterns and practices of users to determine whether or not they fit the normal use case of a developer, an architect, and other roles.
IC Sharepoint Administrator at a healthcare company with 1,001-5,000 employees
It could be improved in terms of producing reports to provide information to the C-suite or others.
Manager, Information Technology Security Compliance at a manufacturing company with 201-500 employees
Global reach allows deployment of apps and services closer to users worldwide, but data sovereignty concerns exist and region selection must align with compliance requirements.
Enterprise Architect at Wipro Limited
I encountered several issues while trying to create solutions for this advanced version, which seem unrelated to query or data issues.
System Engineer at Infosys
High data ingestion costs can be an issue, especially for large enterprises, as Splunk charges based on the amount of data processed.
Enterprise Architect at Wipro Limited
 

Setup Cost

Splunk User Behavior Analytics is costly, with pricing based on processed data, transitioning to subscription models, and includes additional costs.
Reserved instances with one or three-year commitments offer lower rates, providing up to 70% savings.
Enterprise Architect at Wipro Limited
Compared to all other products in the market, it is the most expensive one in all aspects including professional service and licenses, even the cloud version.
Director at Techpace
Comparing with the competitors, it's a bit expensive.
Regional Director at iSecureMind Integrated Solutions
 

Valuable Features

Microsoft Purview Insider Risk Management enhances threat detection and prevention with advanced analytics, role-based access, and seamless investigations.
Splunk User Behavior Analytics offers advanced threat detection, scalability, and integration for robust security and data analysis solutions.
It has saved us money on lawsuits and the loss of important confidential information that could lead to legal issues.
Manager, Information Technology Security Compliance at a manufacturing company with 201-500 employees
The scoring mechanism is exceptional because it eliminates the need to reinvent criteria for identifying risks, misconfigurations, or vulnerabilities.
Director at Scybers
We were able to remediate the fact that we had a North Korean spy working for us.
IC Sharepoint Administrator at a healthcare company with 1,001-5,000 employees
I also utilize it for anomaly detection and behavior analysis, particularly using Splunk's machine learning environment.
Cloud Solution Architect at Tech Mahindra Limited
The dashboards themselves are nice, very good, and very helpful, but the accuracy of the data or the information that will be presented on the dashboard is something that needs to be questioned.
Director at Techpace
Features like alerts and auto report generation are valuable.
System Engineer at Infosys
 

Categories and Ranking

Microsoft Purview Insider R...
Average Rating
8.0
Reviews Sentiment
6.2
Number of Reviews
5
Ranking in other categories
Microsoft Security Suite (27th), Insider Risk Management (2nd)
Splunk User Behavior Analytics
Average Rating
8.2
Reviews Sentiment
6.6
Number of Reviews
25
Ranking in other categories
Intrusion Detection and Prevention Software (IDPS) (12th), User Entity Behavior Analytics (UEBA) (4th)
 

Mindshare comparison

While both are Security Software solutions, they serve different purposes. Microsoft Purview Insider Risk Management is designed for Insider Risk Management and holds a mindshare of 14.3%, up 13.7% compared to last year.
Splunk User Behavior Analytics, on the other hand, focuses on User Entity Behavior Analytics (UEBA), holds 5.2% mindshare, down 9.1% since last year.
Insider Risk Management Mindshare Distribution
ProductMindshare (%)
Microsoft Purview Insider Risk Management14.3%
Varonis Platform11.4%
Proofpoint Insider Threat Management11.4%
Other62.9%
Insider Risk Management
User Entity Behavior Analytics (UEBA) Mindshare Distribution
ProductMindshare (%)
Splunk User Behavior Analytics5.2%
Exabeam8.7%
IBM Security QRadar7.0%
Other79.1%
User Entity Behavior Analytics (UEBA)
 

Featured Reviews

Karthik Ekambaram - PeerSpot reviewer
Director at Scybers
Have consistently built secure internal environments while implementing compliance tools for diverse customer needs
The customizable alerts system needs improvement. The detection rules are not extensive enough. There should be more possibilities for creating alerts based on additional criteria. While rules can be customized, the available criteria for creating detection rules should be expanded. Microsoft's pricing is very expensive. The Business Premium offering should be extended to enterprise customers, as it's currently limited to 300 users. There should be a tier below E5 that includes Microsoft Purview and other features. Currently, E5 licensing costs approximately 6,000 INR per user per month including taxes. Competitive solutions offer similar functionality at about 50% of Microsoft's cost. Email DLP is included in Business Premium or P1 licenses, while P2 licenses cover endpoint DLP and additional channels. Microsoft should introduce an intermediate tier below E5 that covers all P1 licenses, as customers often need coverage across the entire M365 suite.
SK
Enterprise Architect at Wipro Limited
Offers intuitive deployment with strong customer support and advanced analytics features
There are improvements that could be made to Splunk User Behavior Analytics as any product will have advantages and disadvantages. Scalability is one consideration. For example, the advantages include rapid auto scaling to meet demand. A disadvantage is that it can lead to cost overrun if not properly factored or governed. The speed of deployment offers faster provisioning as an advantage, but it can require substantial automation skills and infrastructure as code expertise, which can be challenging. Cloud provides major operational benefits such as agility, automation, resilience, and global access when setting up on Cloud. However, it introduces challenges such as cost control, complexity, and vendor dependency. For example, global reach allows deployment of apps and services closer to users worldwide, but data sovereignty concerns exist and region selection must align with compliance requirements.
report
Use our free recommendation engine to learn which Insider Risk Management solutions are best for your needs.
893,244 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Computer Software Company
16%
Financial Services Firm
11%
Outsourcing Company
8%
Media Company
6%
Financial Services Firm
12%
Computer Software Company
8%
Comms Service Provider
7%
Government
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
No data available
By reviewers
Company SizeCount
Small Business7
Midsize Enterprise6
Large Enterprise12
 

Questions from the Community

What needs improvement with Microsoft Purview Insider Risk Management?
I feel Microsoft Purview Insider Risk Management can be improved by being able to identify patterns and practices of users to determine whether or not they fit the normal use case of a developer, a...
What is your primary use case for Microsoft Purview Insider Risk Management?
My main use cases involve identifying issues related to problems with the current software deployments and whether or not it is being utilized correctly.
What advice do you have for others considering Microsoft Purview Insider Risk Management?
My advice to another organization that is considering using Microsoft Purview Insider Risk Management is to make sure they plan out their deployment very carefully because the biggest sticking poin...
What do you like most about Splunk User Behavior Analytics?
The solution's most valuable feature is Splunk queries, which allow us to query the logs and analyze the attack vectors.
What is your experience regarding pricing and costs for Splunk User Behavior Analytics?
Splunk User Behavior Analytics is a premium product. Compared to all other products in the market, it is the most expensive one in all aspects including professional service and licenses, even the ...
What needs improvement with Splunk User Behavior Analytics?
Splunk User Behavior Analytics is still an immature product, so it still needs some R&D to be able to be mature in the market. The prediction, algorithms, and ML codes behind Splunk User Behavi...
 

Also Known As

Microsoft Insider Risk Management
Caspida, Splunk UBA
 

Overview

 

Sample Customers

Information Not Available
8 Securities, AAA Western, AdvancedMD, Amaya, Cerner Corporation, CJ O Shopping, CloudShare, Crossroads Foundation, 7-Eleven Indonesia
Find out what your peers are saying about Varonis, Microsoft, Dtex Systems and others in Insider Risk Management. Updated: April 2026.
893,244 professionals have used our research since 2012.