Splunk User Behavior Analytics vs WatchGuard Intrusion Prevention Service comparison

Cancel
You must select at least 2 products to compare!
Comparison Buyer's Guide
Executive Summary

We performed a comparison between Splunk User Behavior Analytics and WatchGuard Intrusion Prevention Service based on real PeerSpot user reviews.

Find out what your peers are saying about Darktrace, Vectra AI, Check Point Software Technologies and others in Intrusion Detection and Prevention Software (IDPS).
To learn more, read our detailed Intrusion Detection and Prevention Software (IDPS) Report (Updated: March 2024).
768,415 professionals have used our research since 2012.
Featured Review
Quotes From Members
We asked business professionals to review the solutions they use.
Here are some excerpts of what they said:
Pros
"The solution is fast, flexible, and easy to use.""It's straightforward in terms of configuration and troubleshooting and log management and monitoring as well. These are the edge points in addition to it being a modular solution where you can capitalize on your current licenses with extra licensing models, which can match the customer's business requirement and it can help the customer to design or to actually plan for their own roadmap.""The product is at the forefront of auto-remediation networking. It's great.""It's easily scalable.""The most valuable features are its data aggregation and the ability to automatically identify a number of threats, then suggest recommended actions upon them.""This intelligent user behavior analytics package is easy to configure and use while remaining feature filled.""We are really pleased with Splunk and its features. It would be practically impossible to function without it. To provide a general overview of the system, it's important to note that the standard log files are currently around 250 gigabytes per day. It would be impossible to manually walk through these logs by hand, which is why automation is essential.""Because of some of the visualizations that we utilize, we are able to understand strange, unusual traffic on our networks."

More Splunk User Behavior Analytics Pros →

"The most important feature of this solution is the SLAs.""The initial setup was straightforward and, because we only need intrusion detection and prevention, we needed only about four hours to deploy it.""The VPN and the filtering features are the most valuable. Its VPN is very strong, and its services are very nice. The main problem in India is the service. There are not enough Check Point and Fortinet Firewall services, but for this product, the service is very good.""The alarm system is valuable.""It works right out of the box. You just have to enable it and you can start working."

More WatchGuard Intrusion Prevention Service Pros →

Cons
"We'd like the ability to do custom searches.""I'm not aware of any lacking features.""The correlation engine should have persistent and definable rules.""They should work to add more built-in correlation searches and more use cases based on worldwide customer experiences. They need more ready-made use cases.""In the future I would like to see simplified statistics and analytical threats.""The ability to do more complicated data investigation would be a welcome addition for pros, though the functionality now gives most people what they need.""It could be easier to scale the solution if you are using it on-premise, not in the cloud.""The initial setup was complex because some of the configurations that we required needed customization."

More Splunk User Behavior Analytics Cons →

"Its graphical user interface could be improved because not everybody is technical. There is a lack of knowledge, and they can give some training for this solution.""Regarding technical support, they could use more engineers.""I would like to see faster automatation.""The user interface and configuration can be improved.""Multi properties could be added to the solution in the future to make it better."

More WatchGuard Intrusion Prevention Service Cons →

Pricing and Cost Advice
  • "I hope we can increase the free license to be more than 5 gig a day. This would help people who want to introduce a POC or a demo license for the solution."
  • "My biggest complaint is the way they do pricing... You can never know the pricing for next year. Every single time you adjust to something new, the price goes up. It's impossible to truly budget for it. It goes up constantly."
  • "There are additional costs associated with the integrator."
  • "The licensing costs is around 10,000 dollars."
  • "Pricing varies based on the packages you choose and the volume of your usage."
  • "I am not aware of the price, but it is expensive."
  • More Splunk User Behavior Analytics Pricing and Cost Advice →

  • "The price of WatchGuard Intrusion Prevention Service is pretty reasonable compared to similar solutions."
  • "It is not expensive. Other products like Fortinet and Check Point are of the same price."
  • "The price of the solution is not expensive, it is less than FortiGate."
  • More WatchGuard Intrusion Prevention Service Pricing and Cost Advice →

    report
    Use our free recommendation engine to learn which Intrusion Detection and Prevention Software (IDPS) solutions are best for your needs.
    768,415 professionals have used our research since 2012.
    Questions from the Community
    Top Answer:We are really pleased with Splunk and its features. It would be practically impossible to function without it To provide a general overview of the system, it's important to note that the standard… more »
    Top Answer:I am not aware of the price, but it is expensive. A rough estimate would be around 150 gigabytes, given the huge amount of data. At the moment there are no additional costs for maintenance.
    Top Answer:Currently, we do not have any specific improvement projects in progress. However, we have partnered with some companies that are constantly working on improving the system. Therefore, I believe it's… more »
    Top Answer:The user interface can be improved because it is sometimes difficult to manage functionality. For example, the site interface is challenging to customize, and it isn't easy to retrieve information.
    Ranking
    Views
    1,934
    Comparisons
    1,231
    Reviews
    5
    Average Words per Review
    374
    Rating
    8.6
    Views
    233
    Comparisons
    170
    Reviews
    0
    Average Words per Review
    0
    Rating
    N/A
    Comparisons
    Also Known As
    Caspida, Splunk UBA
    WatchGuard IPS
    Learn More
    Splunk
    Video Not Available
    Overview

    Splunk User Behavior Analytics is a behavior-based threat detection is based on machine learning methodologies that require no signatures or human analysis, enabling multi-entity behavior profiling and peer group analytics for users, devices, service accounts and applications. It detects insider threats and external attacks using out-of-the-box purpose-built that helps organizations find known, unknown and hidden threats, but extensible unsupervised machine learning (ML) algorithms, provides context around the threat via ML driven anomaly correlation and visual mapping of stitched anomalies over various phases of the attack lifecycle (Kill-Chain View). It uses a data science driven approach that produces actionable results with risk ratings and supporting evidence that increases SOC efficiency and supports bi-directional integration with Splunk Enterprise for data ingestion and correlation and with Splunk Enterprise Security for incident scoping, workflow management and automated response. The result is automated, accurate threat and anomaly detection.

    Online attacks and malware continue to evolve, using sophisticated methods to exploit victims. WatchGuard Intrusion Prevention Service (IPS) provides a preemptive approach to network security that adds an essential layer of threat detection and prevention. IPS protects your network from a wide range of malicious activities, including SQL injections, cross-site scripting, and buffer overflows.

    Sample Customers
    8 Securities, AAA Western, AdvancedMD, Amaya, Cerner Corporation, CJ O Shopping, CloudShare, Crossroads Foundation, 7-Eleven Indonesia
    Chester School District
    Top Industries
    REVIEWERS
    Financial Services Firm44%
    Insurance Company11%
    Government11%
    Security Firm11%
    VISITORS READING REVIEWS
    Computer Software Company14%
    Financial Services Firm14%
    Government10%
    Manufacturing Company8%
    No Data Available
    Company Size
    REVIEWERS
    Small Business31%
    Midsize Enterprise31%
    Large Enterprise38%
    VISITORS READING REVIEWS
    Small Business20%
    Midsize Enterprise12%
    Large Enterprise69%
    No Data Available
    Buyer's Guide
    Intrusion Detection and Prevention Software (IDPS)
    March 2024
    Find out what your peers are saying about Darktrace, Vectra AI, Check Point Software Technologies and others in Intrusion Detection and Prevention Software (IDPS). Updated: March 2024.
    768,415 professionals have used our research since 2012.

    Splunk User Behavior Analytics is ranked 12th in Intrusion Detection and Prevention Software (IDPS) with 17 reviews while WatchGuard Intrusion Prevention Service is ranked 31st in Intrusion Detection and Prevention Software (IDPS) with 5 reviews. Splunk User Behavior Analytics is rated 8.2, while WatchGuard Intrusion Prevention Service is rated 6.6. The top reviewer of Splunk User Behavior Analytics writes "Easy to configure and easy to use solution that integrates with many applications and scripts ". On the other hand, the top reviewer of WatchGuard Intrusion Prevention Service writes "Good VPN and filtering features, 100% stable, but needs a better graphical user interface and more training". Splunk User Behavior Analytics is most compared with Darktrace, Microsoft Defender for Identity, IBM Security QRadar, Varonis Datalert and Cynet, whereas WatchGuard Intrusion Prevention Service is most compared with Fortinet FortiGate IPS and Cisco Sourcefire SNORT.

    See our list of best Intrusion Detection and Prevention Software (IDPS) vendors.

    We monitor all Intrusion Detection and Prevention Software (IDPS) reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.