Cisco Secure Network Analytics vs NetWitness Platform comparison

Sponsored
 

Comparison Buyer's Guide

Executive Summary
 

Categories and Ranking

Juniper Mist Premium Analytics
Sponsored
Average Rating
8.0
Number of Reviews
2
Ranking in other categories
Network Monitoring Software (60th)
Cisco Secure Network Analytics
Average Rating
8.2
Number of Reviews
58
Ranking in other categories
Network Monitoring Software (25th), Network Traffic Analysis (NTA) (4th), Network Detection and Response (NDR) (3rd), Cisco Security Portfolio (3rd)
NetWitness Platform
Average Rating
7.4
Number of Reviews
36
Ranking in other categories
Log Management (18th), Security Information and Event Management (SIEM) (15th)
 

Market share comparison

As of June 2024, in the Network Monitoring Software category, the market share of Juniper Mist Premium Analytics is 0.4% and it decreased by 34.8% compared to the previous year. The market share of Cisco Secure Network Analytics is 1.5% and it decreased by 26.3% compared to the previous year. The market share of NetWitness Platform is 0.1% and it increased by Infinity% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Network Monitoring Software
Unique Categories:
No other categories found
Network Traffic Analysis (NTA)
9.1%
Network Detection and Response (NDR)
10.5%
Log Management
0.6%
Security Information and Event Management (SIEM)
1.2%
 

Featured Reviews

Shiva_Prasad - PeerSpot reviewer
Jan 25, 2024
A cloud solution for warehousing with a troubleshooting feature
The initial setup is straightforward. It's based on user requirements. We also conduct heat mapping using a couple of tools. The only requirement is to understand the technical or configuration aspects from the user's end and then configure it. Mist takes no more than 15 to 20 minutes for a particular deployment. You need to understand the end user's environment and have a concrete plan on whether it's a greenfield installation or an existing one, considering the density and height. Based on that, we need to develop a passive heat map. Then, you need to discuss with the user to understand exactly what needs to be configured and what they require in their environment. Based on that, you can proceed with the installation. Additionally, you can perform post-installation heat mapping to ensure it matches the earlier heat map. I rate the initial setup an eight out of ten, where one is difficult, and ten is easy.
JT
Feb 20, 2023
Increased the visibility of what is happening in our network
We're currently using it to figure out what is happening in our network. For example, to see whether there's any incorrect traffic in our network. We are also using it to monitor traffic coming from the internet into our network. We have about 30,000 end users and about 60,000 end devices in the…
Salah Sabouni - PeerSpot reviewer
Apr 8, 2023
Provides comprehensive network visibility, and has available helpful support
The initial setup is complex. It requires some knowledge in order to set it up. If one is the most difficult and ten is the easiest, I would rate it a three out of ten. It's quite complex. Initially, we need to prepare the hardware boxes, whether they are physical or virtual or offered as a service. This involves imaging them with the appropriate functions for the module. Then, for network packet capture, the mirror ports must be connected to the packet capture box. Regarding logs, the configuration process involves making NetWitness boxes communicate with each other through the appropriate protocols and ports. Following this, the next step involves configuring the log sources to send logs to the log box. This process requires the appropriate rules to be configured to initiate log transmission and generate metadata by appropriate parsers on NetWitness. After the setup, the focus shifts to building correlation rules, alerts, and other monitoring activities. These rules and alerts are crucial components for effective monitoring. The deployment process can vary based on the specific environment and requirements, but typically it takes about one to two weeks to complete. Maintaining the solution doesn't require a large number of resources. Typically, one or two capable resources are sufficient to maintain the solution effectively. It's important to continuously monitor and ensure the health and proper functioning of the solution. This involves regularly checking the log sources to ensure that the logs are being ingested correctly and there are no issues such as overutilization or spikes in network traffic.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"We can manage the entire system across the network and troubleshoot the pain points."
"The single dashboard is a valuable feature."
"Using the Cognitive Analytics feature, we have complete visibility that we didn’t have before."
"The most valuable feature of this solution is data hoarding because it catches threats on a frequent basis that we had no idea of."
"The most valuable feature is having visibility into the data segments throughout our network."
"The most valuable feature of Cisco Secure Network Analytics is the Threat Intelligence integration."
"It does change the way we troubleshoot and it is relatively easy to use once you learn it. I would recommend it to someone considering it."
"Ease of deployment, once you get your ducks in a row."
"Cisco Stealthwatch has reduced the amount of time to detect an immediate threat."
"The artifacts available in the tool provide better information for analyzing network traffic. It enables a holistic view of network traffic and general packet analysis. It's easy to identify anomalies without the use of signatures. The way in which we implemented Stealthwatch Cloud has enabled my team to analyze traffic behind proxies."
"The most valuable features are the integration and ease of use."
"Setting up NetWitness is straightforward. There are multiple connectors, including standard and specialized connectors. One purpose of the connectors is the enhanced capability integrate the custom applications. NetWitness comes with E6 appliances and application images that we use for the initial configurations and for the OS stack information. From there, you can consider the correlation rules, integrate the different log sources, and easily create correlation rules and backlog reports."
"The most valuable feature is that we can create our own connectors for any application, and NetWitness provides the training and tools to do it."
"The packet capture aspect of it is a valuable feature because it is quite different from a traditional SIEM solution that only carries out investigations based on captured logs."
"The solution is really scalable for the high-end power, enterprise customer."
"The most valuable features are the packet inspection and the automated incident response."
"The software is scalable to whatever is required, and you can also put a lot of resources in the cloud."
"Performance and reporting are very good."
 

Cons

"The Wi-Fi side needs improvement."
"The technical support needs improvement."
"There's a lot of traffic on our network that we don't see sometimes."
"We determined that Stealthwatch wouldn't provide the machine learning model that we required."
"The version with the Dell server had iDRAC problems. Often, it reported iDRAC failure."
"Better integration between Cisco Secure Network Analytics and Cisco Secure Workload would be beneficial."
"Cisco Stealthwatch can improve by having bundled packages for popular add-ons. It would be a lot easier for people implementing it, have let's say a better way to use the product."
"Initially, I felt Cisco Secure Network Analytics lacked integration with Splunk."
"There could be better integration on the programming side, which uses Python. StealthWatch could provide a template for Python to manage the switches. For example, it would be nice if StealthWatch bounced a port automatically it detected something anomalous."
"One thing I would like to see improved is if it could automatically be tied through ISE, instead of you having to manually get notifications and disable it yourself."
"RSA NetWitness Logs and Packets can improve the threat level aspect, it is lacking compared to other solutions. Whenever any hacking activity or any other threat factor occurred they used to provide the coverages very fast when comparing RSA NetWitness Logs and Packets. I heard the other three solutions, from a discussion with my team members who had experience in other solutions, they used to say that. Whenever any issues happened across the globe RSA NetWitness Logs and Packets are a little bit slow improving those detection mechanisms."
"Technical support could be improved."
"I'd like to see improvement in its ease of use. It's basically unusable. It's overly complex."
"Log aggregation is an issue with this solution because there are a huge number of alerts in a single instance."
"We have encountered issues with unresolved crashes."
"The product's licensing models are complex to understand. This particular area needs improvement."
"Its technical support could be better."
"Health monitoring of the event sources and devices."
 

Pricing and Cost Advice

"The solution is expensive."
"NetFlow is very expensive."
"Licensing is on a yearly basis."
"It has a subscription model. There is yearly support, and there is also three-year support. It depends on what the customers want."
"The yearly licensing cost is about $50,000."
"One of the things which bugs me about Lancope is the licensing. We understand how licensing works. Our problem is when we bought and purchased most of these Lancope devices, we did so with our sister company. Somewhere within the purchase and distribution, licensing got mixed up. That is all on Cisco, and it is their responsibility. They allotted some of our sister company's equipment to us, and some of our equipment to them. To date, they have never been able to fix it."
"The solution is expensive. It costs several hundred thousand dollars per year (depending on how many flows you are collecting)."
"Pricing is much higher compared to other solutions."
"This is an expensive product. We have quit paying for support because we don't want to have to upgrade it and keep paying for it."
"The NetWitness Platform may be affordable only for enterprise-level customers, as it may not be within the budget of small and medium-sized businesses."
"This is a pricey solution; it's not cheap."
"The new pricing and licensing mechanisms are fair. I would advise always to get the full solution (i.e., not only Logs)."
"We have a perpetual license, so the total cost of ownership is not very expensive. It's a good investment."
"In comparison to other SIEM solutions such as Splunk, NetWitness is less costly."
"It’s cheaper to run virtual machines in a VMware environment."
"There is a licensing fee and the customer can choose whether he wishes this to be subscription-based or perpetual."
"RSA NetWitness Logs and Packets do not have a subscription model, it's a one-time purchase. There is only a perpetual license."
report
Use our free recommendation engine to learn which Network Monitoring Software solutions are best for your needs.
787,061 professionals have used our research since 2012.
 

Comparison Review

VS
Feb 26, 2015
HP ArcSight vs. IBM QRadar vs. ​McAfee Nitro vs. Splunk vs. RSA Security vs. LogRhythm
We at Infosecnirvana.com have done several posts on SIEM. After the Dummies Guide on SIEM, we are following it up with a SIEM Product Comparison – 101 deck. So, here it is for your viewing pleasure. Let me know what you think by posting your comments below. The key products compared here are…
 

Top Industries

By visitors reading reviews
Computer Software Company
18%
Financial Services Firm
12%
Manufacturing Company
9%
Government
8%
Computer Software Company
28%
Financial Services Firm
11%
Government
8%
Manufacturing Company
6%
Computer Software Company
15%
Financial Services Firm
15%
Government
10%
Insurance Company
6%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
No data available
 

Questions from the Community

What do you like most about Juniper Mist Premium Analytics?
We can manage the entire system across the network and troubleshoot the pain points.
What do you like most about Cisco Stealthwatch?
The most valuable feature of Cisco Secure Network Analytics is the Threat Intelligence integration.
What is your experience regarding pricing and costs for Cisco Stealthwatch?
I would rate Cisco SNA as a nine out of ten in terms of costliness.
What needs improvement with Cisco Stealthwatch?
Initially, I felt Cisco Secure Network Analytics lacked integration with Splunk. However, with Cisco's recent acquisi...
What do you like most about NetWitness Platform?
The product's initial setup phase was not at all difficult.
What is your experience regarding pricing and costs for NetWitness Platform?
The product price was reasonable for my region and the market.
What needs improvement with NetWitness Platform?
From an improvement perspective, the NetWitness Platform needs to release new features and improve in areas like log ...
 

Also Known As

No data available
Cisco Stealthwatch, Cisco Stealthwatch Enterprise, Lancope StealthWatch
RSA Security Analytics
 

Learn More

Video not available
Video not available
 

Overview

 

Sample Customers

Information Not Available
Edge Web Hosting, Telenor Norway, Ivy Tech Community College of Indiana, Webster Financial Corporation, Westinghouse Electric, VMware, TIAA-CREF
Los Angeles World Airports, Reply
Find out what your peers are saying about Zabbix, Datadog, Auvik and others in Network Monitoring Software. Updated: June 2024.
787,061 professionals have used our research since 2012.