We compared Cisco Secure Network Analytics and ExtraHop Reveal(x) across 5 parameters based on our user reviews. After reading the collected data, you can find our conclusion below:
Cisco Secure Network Analytics users highly value its advanced threat detection capabilities, extensive visibility and control over network traffic, and proactive alerting system. They appreciate the commendable customer service and support provided by Cisco Secure Network Analytics. ExtraHop Reveal(x) also offers robust network visibility and real-time threat detection.
Initial Setup and Support: Cisco Secure Network Analytics has a relatively quick and simple setup process that typically takes one to two weeks for deployment. ExtraHop Reveal(x) setup can be more complex and time-consuming, often taking about a week to complete due to the involvement of network taps and packet brokers. Cisco Secure Network Analytics provides a range of management options and support services, including workshops for a better understanding of solutions. They also experience stability issues in new versions. ExtraHop Reveal(x) excels in efficiency and troubleshooting capabilities of their support team, although there are occasional sporadic support feedback.
Valuable Features: Cisco Secure Network Analytics is praised for its advanced threat detection capabilities, proactive alerting system, and effective security incident response. ExtraHop Reveal(x) stands out for its robust network visibility, comprehensive analytics capabilities, and data-driven decision-making features.
Room For Improvement: Cisco Secure Network Analytics could benefit from improvements in data processing speed, better visualization features, and advanced threat detection capabilities. ExtraHop Reveal(x) needs enhancements in user interface, accuracy, responsiveness, documentation, and customer support.
Setup Cost: Cisco Secure Network Analytics has been considered reasonable and competitive, yet with a potentially higher initial setup cost. ExtraHop Reveal(x) is praised for its relatively low setup cost, making implementation easy and cost-effective.
ROI: The ROI from Cisco Secure Network Analytics has been significant, providing improved network security, reduced risks, advanced analytics capabilities, and reliable support. ExtraHop Reveal(x) excels in network visibility, anomaly detection, and user-friendly interface.
The summary above is based on interviews we conducted recently with Cisco Secure Network Analytics and ExtraHop Reveal(x) users. To access the review's full transcripts, download our report.
"The most valuable feature is having visibility into the data segments throughout our network."
"The search options on Cisco Stealthwatch are the most valuable. You can get very granular with it, down to the kilobits or the seconds if you want. The product supports any time frame that you need, so that is nice."
"StealthWatch lets me see the ports running in and out and the country. It has excellent reporting, telemetry, and artificial intelligence features. With the telemetry, I can set thresholds to detect sudden changes and the alarms go through the PLC parts. I can see all the ports running on that trunk."
"The most valuable features provided by this solution are visibility and information."
"Cisco Stealthwatch has predefined alerts for different types of security issues that might happen in the network. Whether it's PCs or servers that are used for botnets or Bitcoin mining we receive the alerts automatically. This functionality is what we receive from the solution out of the box."
"The artifacts available in the tool provide better information for analyzing network traffic. It enables a holistic view of network traffic and general packet analysis. It's easy to identify anomalies without the use of signatures. The way in which we implemented Stealthwatch Cloud has enabled my team to analyze traffic behind proxies."
"The ability to send data flow from other places and have them all in one place is very valuable for us."
"It has improved our internal knowledge of what's going on with the network, and that's helpful."
"Reveal X integrates seamlessly with CrowdStrike. If you see something sketchy on the network, you can quarantine devices through ExtraHop and it'll push to the CrowdStrike server."
"The solution works well for sending sensors."
"With ExtraHop Reveal(x), it gives me more visibility into the packets. It doesn't provide the entire packet capture, but it offers more information on how connections are made at the network layer. This can be helpful for detecting network attacks. Additionally, I really like the customizable dashboards and reports. The incident dashboard and alerts provide a good summary initially, and diving deeper into them gives more detailed information. It's also great for analyzing specific attacks and victim logs. The feature that tracks the full attack chain makes it easier to monitor the progress of attacks. Plus, it's connected to the Netria.com app, which I find useful for certain tasks."
"The solution's initial setup process is easy."
"The most valuable features of ExtraHop Reveal(x) are the detection and alerting of network behavior and anomalies."
"It's a wire analytics tool. We use it for isolating and determining issues on our network or applications. It does a lot for crediting the network as opposed to discrediting the network. A lot of people come along and say that it's a network issue. It's always considered to be a network issue, but by using ExtraHop, we can quickly tell them that it's not a networking issue. It's something to do with your application or something at the other end. It could be a database issue. This tool gives us the ability to pinpoint with great accuracy the comings and goings on our network."
"Setting up the solution is relatively easy."
"We had useful information within the hour of deployment. The ability to trace back for historical analysis, as well as the behavioral analysis done with the security information, puts the user in a position to make an informed decision to mitigate the performance or security incidents. Regarding the security incidents, Reveal (x) is able to create incident cards that guide your teams through the incidents and gives you the option to delve into the transaction detail to potentially view payloads as well."
"One update I would like to see is an agent-based client. Currently StealthWatch is network based."
"Cisco could improve the administration for the customers."
"We need to be able to filter out internal IPs as non-threats."
"Cisco Stealthwatch needs more integration with device discovery. We have to do a lot of hard work to figure out what things are. Better service integration is required."
"It's not great as a standalone solution."
"If they can make this product more web-based, that would be amazing."
"The GUI could use some improvement. Being able to find features more easily would be a great improvement if it was simplified."
"The customizability of the UI should improve."
"There is a little training online, but it'd be cool if ExtraHop provided certifications. CrowdStrike does elective training that gives you a certification as a Falcon administrator. It'd be nice to see ExtraHop have something like that"
"The solution's reporting part and GUI are areas with certain shortcomings where improvements are required."
"The solution is expensive and gets more expensive if a company needs to scale it."
"I would like to see more cloud capability."
"They used to have the ability to decode Citrix sign-on, setup, and tear down. Unfortunately, Citrix has stopped sharing that knowledge. Citrix has continued to change its model of processing, making it harder and harder to troubleshoot."
"The solution should include more support protocols."
"I think the tuning capabilities could be improved. We're working on minimizing false positives. Apart from that, everything seems fine to me."
"Agent management could certainly use some focus. It should also be a little bit easier to work with collections. We should be able to nest collections within collections. There should be better nesting."
More Cisco Secure Network Analytics Pricing and Cost Advice →
Cisco Secure Network Analytics is ranked 4th in Network Traffic Analysis (NTA) with 57 reviews while ExtraHop Reveal(x) is ranked 5th in Network Traffic Analysis (NTA) with 12 reviews. Cisco Secure Network Analytics is rated 8.2, while ExtraHop Reveal(x) is rated 8.6. The top reviewer of Cisco Secure Network Analytics writes "Increased the visibility of what is happening in our network". On the other hand, the top reviewer of ExtraHop Reveal(x) writes "It helps you visualize how data moves across your network". Cisco Secure Network Analytics is most compared with Darktrace, Cisco Secure Cloud Analytics, ThousandEyes, Vectra AI and Corelight, whereas ExtraHop Reveal(x) is most compared with Darktrace, Vectra AI, Corelight, Arista NDR and ExtraHop Reveal(x) 360. See our Cisco Secure Network Analytics vs. ExtraHop Reveal(x) report.
See our list of best Network Traffic Analysis (NTA) vendors and best Network Detection and Response (NDR) vendors.
We monitor all Network Traffic Analysis (NTA) reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.