Try our new research platform with insights from 80,000+ expert users

Palo Alto Networks Advanced Threat Prevention vs Splunk User Behavior Analytics comparison

 

Comparison Buyer's Guide

Executive SummaryUpdated on Dec 19, 2024

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

ROI

Sentiment score
7.5
Palo Alto Networks Advanced Threat Prevention offers fast, comprehensive security, boosting user satisfaction and revenue despite high costs.
Sentiment score
6.4
Users report varied ROI from Splunk, with productivity gains and security cost savings, but costs remain a concern.
It offers insights into security threats, despite the inability to quantify its impact in numbers.
The solution can save costs by improving incident resolution times and reducing security incident costs.
 

Customer Service

Sentiment score
6.4
Palo Alto Networks' support is generally effective despite communication issues and regional differences, with most users rating it positively.
Sentiment score
6.8
Splunk User Behavior Analytics support is mostly praised, with professional service, tiered options, and valuable user groups enhancing experience.
I rate technical support from Palo Alto as eight out of ten.
Mission-critical offering a dedicated team, proactive monitoring, and fast resolution.
The support quality is excellent for paid tiers, following enterprise-grade SLAs with proactive support and deep expertise.
Splunk's technical support is amazing.
 

Scalability Issues

Sentiment score
7.9
Palo Alto Networks Advanced Threat Prevention is highly scalable, adaptable across environments, but cost considerations may affect scalability.
Sentiment score
7.5
Splunk User Behavior Analytics is scalable and adaptable across environments, though storage limitations may affect scalability.
Palo Alto Networks Advanced Threat Prevention is scalable and works well wherever enforcement points exist.
Splunk User Behavior Analytics is highly scalable, designed for enterprise scalability, allowing expansion of data ingestion, indexing, and search capabilities as log volumes grow.
 

Stability Issues

Sentiment score
7.9
Palo Alto Networks Advanced Threat Prevention is preferred for its stability, outperforming competitors, and requires proper firewall sizing.
Sentiment score
8.1
Splunk User Behavior Analytics offers reliable performance and stability, with 99.9% uptime and ease of configuration in enterprises.
Proper sizing of the firewall models ensures that the system does not experience crippling performance issues.
With built-in redundancy across zones and regions, 99.9% uptime is achievable.
Splunk User Behavior Analytics is a one hundred percent stable solution.
Splunk User Behavior Analytics is highly stable and reliable, even in large-scale enterprise environments with high log injection rates.
 

Room For Improvement

Palo Alto Networks needs improvements in email security, user support, and analytics, while addressing complexity, false positives, and integration.
Splunk User Behavior Analytics needs better pricing, integration, user-friendly interfaces, enhanced features, and improved scalability and infrastructure.
The behavioral detection capabilities could be expanded to address all threats at the perimeter, reducing the reliance on endpoint detection and response systems.
Global reach allows deployment of apps and services closer to users worldwide, but data sovereignty concerns exist and region selection must align with compliance requirements.
High data ingestion costs can be an issue, especially for large enterprises, as Splunk charges based on the amount of data processed.
I encountered several issues while trying to create solutions for this advanced version, which seem unrelated to query or data issues.
 

Setup Cost

Palo Alto Networks Advanced Threat Prevention is costly yet valued for its features, particularly in threat detection and scalability.
Enterprise buyers find Splunk's User Behavior Analytics costly, with variable pricing based on data, hardware, and additional applications.
Palo Alto Networks Advanced Threat Prevention requires an add-on license and is considered expensive compared to competitors like Cisco AMP and FortiGate firewalls.
Reserved instances with one or three-year commitments offer lower rates, providing up to 70% savings.
Comparing with the competitors, it's a bit expensive.
The pricing is based on the amount of data processed, and it is considered a high-level investment for enterprises.
 

Valuable Features

Palo Alto Networks Advanced Threat Prevention provides intuitive threat prevention with machine learning, excellent reporting, and seamless integration with other tools.
Splunk User Behavior Analytics provides scalable, user-friendly threat detection with advanced analytics, machine learning, and seamless data integration and reporting.
As traditional signature-based mechanisms become less effective due to the evolving nature of attacks, this solution's focus on behavioral analysis is crucial.
I also utilize it for anomaly detection and behavior analysis, particularly using Splunk's machine learning environment.
Features like alerts and auto report generation are valuable.
It correlates all the historical data, compares the upcoming behavior with what's already stored in the platform, and reduces false positives.
 

Categories and Ranking

Palo Alto Networks Advanced...
Ranking in Intrusion Detection and Prevention Software (IDPS)
7th
Average Rating
8.6
Reviews Sentiment
6.9
Number of Reviews
27
Ranking in other categories
No ranking in other categories
Splunk User Behavior Analytics
Ranking in Intrusion Detection and Prevention Software (IDPS)
12th
Average Rating
8.2
Reviews Sentiment
6.8
Number of Reviews
24
Ranking in other categories
User Entity Behavior Analytics (UEBA) (4th)
 

Mindshare comparison

As of July 2025, in the Intrusion Detection and Prevention Software (IDPS) category, the mindshare of Palo Alto Networks Advanced Threat Prevention is 7.6%, down from 8.0% compared to the previous year. The mindshare of Splunk User Behavior Analytics is 2.3%, down from 2.6% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Intrusion Detection and Prevention Software (IDPS)
 

Featured Reviews

NenadMijatovic - PeerSpot reviewer
Offers threat detection and prevention empowered by advanced machine learning capabilities
The most valuable feature is its use of machine learning to detect potentially unknown threats. Using various techniques, the system can conclude if there is a malware threat in network traffic. It offers inline security, stopping malware quickly without relying on cloud support. Advanced Threat Prevention integrates other tools from Palo Alto like virus definitions and application behavior checking.
Subhayu Chakraborty - PeerSpot reviewer
Automatic reports streamline tasks and offers easy report gathering
The dashboard part could be improved. While using it, I noticed two options: Classic, which is adequate yet only in black and white, and another one that is more advanced or smart, though I forgot the exact term. I encountered several issues while trying to create solutions for this advanced version, which seem unrelated to query or data issues.
report
Use our free recommendation engine to learn which Intrusion Detection and Prevention Software (IDPS) solutions are best for your needs.
860,592 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Computer Software Company
15%
Manufacturing Company
10%
Financial Services Firm
9%
Government
9%
Computer Software Company
17%
Financial Services Firm
12%
Government
9%
Manufacturing Company
8%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

Which is the best DDoS protection solution for a big ISP for monitoring and mitigating?
Arbor would be the best bid, apart from Arbor, Palo Alto and Fortinet have good solutions. As this is an ISP, I would prefer Arbor.
What is your experience regarding pricing and costs for Palo Alto Networks Threat Prevention?
Palo Alto Networks Advanced Threat Prevention requires an add-on license and is considered expensive compared to competitors like Cisco AMP and FortiGate ( /products/fortinet-fortigate-reviews ) fi...
What do you like most about Splunk User Behavior Analytics?
The solution's most valuable feature is Splunk queries, which allow us to query the logs and analyze the attack vectors.
What is your experience regarding pricing and costs for Splunk User Behavior Analytics?
In terms of setup cost, pricing, and licensing, Splunk User Behavior Analytics is not an inexpensive product. The setup requires numerous components including storage, networking, identity access, ...
What needs improvement with Splunk User Behavior Analytics?
There are improvements that could be made to Splunk User Behavior Analytics as any product will have advantages and disadvantages. Scalability is one consideration. For example, the advantages incl...
 

Also Known As

No data available
Caspida, Splunk UBA
 

Overview

 

Sample Customers

University of Arkansas, JBG SMITH, SkiStar AB, TRI-AD, Temple University, Telkom Indonesia
8 Securities, AAA Western, AdvancedMD, Amaya, Cerner Corporation, CJ O Shopping, CloudShare, Crossroads Foundation, 7-Eleven Indonesia
Find out what your peers are saying about Palo Alto Networks Advanced Threat Prevention vs. Splunk User Behavior Analytics and other solutions. Updated: June 2025.
860,592 professionals have used our research since 2012.