DNIF HYPERCLOUD vs NetWitness Platform comparison

 

Comparison Buyer's Guide

Executive Summary
 

Categories and Ranking

DNIF HYPERCLOUD
Ranking in Log Management
24th
Ranking in Security Information and Event Management (SIEM)
22nd
Average Rating
7.6
Number of Reviews
7
Ranking in other categories
User Entity Behavior Analytics (UEBA) (9th), Security Orchestration Automation and Response (SOAR) (12th)
NetWitness Platform
Ranking in Log Management
18th
Ranking in Security Information and Event Management (SIEM)
15th
Average Rating
7.4
Number of Reviews
36
Ranking in other categories
No ranking in other categories
 

Market share comparison

As of June 2024, in the Log Management category, the market share of DNIF HYPERCLOUD is 1.0% and it increased by 287.1% compared to the previous year. The market share of NetWitness Platform is 0.6% and it increased by 82.0% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Log Management
Unique Categories:
Security Information and Event Management (SIEM)
0.9%
User Entity Behavior Analytics (UEBA)
1.6%
 

Featured Reviews

SB
Oct 18, 2022
Simple and enhanced search capability although limited in other areas
The company was very dependent on the DNIF support team. Whenever we faced any backend issue in the software, we'd have to approach the support team. Unlike other SIEM tools where you can troubleshoot through the GUI, with DNIF they were all on LINUX platforms. Finding the log files and checking them had to be done manually and that was frustrating. In terms of integration, the company had a very limited list of devices that were supported on the go. They were out-of-the-box integrations that required forwarding logs to their server. Each time a new device was added, we had to request a new parcel for that device. I think things may have improved since I left the company.
Salah Sabouni - PeerSpot reviewer
Apr 8, 2023
Provides comprehensive network visibility, and has available helpful support
The initial setup is complex. It requires some knowledge in order to set it up. If one is the most difficult and ten is the easiest, I would rate it a three out of ten. It's quite complex. Initially, we need to prepare the hardware boxes, whether they are physical or virtual or offered as a service. This involves imaging them with the appropriate functions for the module. Then, for network packet capture, the mirror ports must be connected to the packet capture box. Regarding logs, the configuration process involves making NetWitness boxes communicate with each other through the appropriate protocols and ports. Following this, the next step involves configuring the log sources to send logs to the log box. This process requires the appropriate rules to be configured to initiate log transmission and generate metadata by appropriate parsers on NetWitness. After the setup, the focus shifts to building correlation rules, alerts, and other monitoring activities. These rules and alerts are crucial components for effective monitoring. The deployment process can vary based on the specific environment and requirements, but typically it takes about one to two weeks to complete. Maintaining the solution doesn't require a large number of resources. Typically, one or two capable resources are sufficient to maintain the solution effectively. It's important to continuously monitor and ensure the health and proper functioning of the solution. This involves regularly checking the log sources to ensure that the logs are being ingested correctly and there are no issues such as overutilization or spikes in network traffic.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"Great for scaling productivity for log monitoring purposes."
"I like the MITRE table, a feature I saw for the first time in the same solution. There was one MITRE tactic table, which can be used to identify threats if you have all kinds of rules enabled or if you have rules for all the tactics in the MITRE table. There are 14 tables in MITRE, and those 14 tables consist of multiple columns, tactics, and techniques. It was one of the first SIEM tools I saw that had that particular MITRE table. On that basis, you can create new rules and identify existing ones. At any point, if an alert is triggered, it will try to match it to any of those MITRE tactics. I liked that creating a workbook on MITRE business was straightforward. I also like that you can search using SQL or DQL."
"The dashboard is helpful, and it creates visualizations to let staff review event data and identify patterns and anomalies."
"The beauty of the solution is that you can develop infrastructure for a data lake using open sources that are separate from the licenses."
"The solution is quite stable and offers good performance. It also works on a virtual machine. We haven't found any issues with it so far. It's been reliable."
"The User Behavior Analytics is a built-in threat-hunting feature. It detects and reports on any kind of malware or ransomware that enters the network."
"Has a great search capability."
"The response time on queries is super-fast."
"It's fully scalable. There is no limit. Of course, the license limits per day the number of terabytes. In my opinion, it's very flexible."
"The most valuable features are the packet inspection and the automated incident response."
"The most valuable features are its ingestion of logs and raising of alerts based on those logs."
"The newer 11.5 version that my team is using has found it to have good mapping."
"In my opinion, the solution's most valuable feature is its capacity to monitor network traffic, logs from devices within the network, and network captures. This capability extends beyond logs to include full network capturing."
"The most valuable feature is the security that it provides."
"Incident management is its most valuable feature."
"Performance and reporting are very good."
 

Cons

"I think DNIF HYPERCLOUD can implement the ability to export more than 100,000. At the moment, we can't go beyond that. So many times, if you're checking for the firewall logs and working on something related to authentication or network-related traffic, while that log count is low, the account goes beyond that. You can't restrict the logs or the amount of data you can export. It's very important for my situation. It would be better if they could increase the capacity of exports. Although there are many more types of searching in DNIF HYPERCLOUD, people still struggle to query out what they want because not everyone is good at SQL or DQL. The easiest way to query out in DNIF is using the GUI-based interface. But in the GUI interface, you can use operator calls. It gets tricky when you want to search for a specific type of event. You don't know where it will be passed and whether it will be consistent. In the initial phase, it's tough for us to use DNIF. You cannot pass every event in a stable DNIF. When we used that particular tool, we used to get those logs, but sometimes many things are not getting passed. So, we used to export the sheet or export the data into Excel and weigh the required details. In the next release, I would like them to improve the export of the columns and make the application more user-friendly. I would also like a threat-hunting feature in the next release."
"The vendor is fairly new and it's not as big as some of the international competitors. It's not a mature product. If you ask them to move data, it might take a lot of time."
"Dependency on the DNIF support team was frustrating."
"The EBA could be improved."
"The solution's command line should be simpler so that routine commands can be used."
"The solution should be able to connect to endpoints, such as desktops and laptops... If this solution had a smart connector to these logs- Windows, Linux, or any other logs - without affecting the performance of the connector, that would be wonderful."
"There are currently some issues with machine learning plug-ins."
"Log aggregation is an issue with this solution because there are a huge number of alerts in a single instance."
"Lots of competing products have vulnerability protection built into their products, and this solution would be improved by including that support."
"The initial setup is complex. There are other solutions that are easier to implement."
"The system looks like it is a mix of a bunch of different systems, and nothing looked like it was quite together."
"An area for improvement would be better automation and more inbuilt use cases."
"It should have a monitoring feature. It would help us analyze the current state of attacks faster from a single platform."
"The initial setup was complex because it takes a lot of time to complete the implementation."
"I believe that integrating the solution with other products such as Oracle would be beneficial."
 

Pricing and Cost Advice

"The solution requires a huge infrastructure and that is costly."
"The pricing is based on the log size."
"Our license is for one year."
"We have yearly licensing costs. The license fee can be based on the volume of EPS. Some organizations may have, as a gentlemanly gesture, 10,000 EPS and get a 3,000 EPS license but actually use 5,000 EPS."
"Compared to the competition, the is price is not that high."
"The product price was reasonable for my region and the market."
"It provides tools to assist in selecting the appropriate license and usage scenarios."
"We have a perpetual license, so the total cost of ownership is not very expensive. It's a good investment."
"The tool is very expensive, so I rate the pricing a ten out of ten. The solution has an annual subscription."
"The NetWitness Platform may be affordable only for enterprise-level customers, as it may not be within the budget of small and medium-sized businesses."
report
Use our free recommendation engine to learn which Log Management solutions are best for your needs.
787,061 professionals have used our research since 2012.
 

Comparison Review

VS
Feb 26, 2015
HP ArcSight vs. IBM QRadar vs. ​McAfee Nitro vs. Splunk vs. RSA Security vs. LogRhythm
We at Infosecnirvana.com have done several posts on SIEM. After the Dummies Guide on SIEM, we are following it up with a SIEM Product Comparison – 101 deck. So, here it is for your viewing pleasure. Let me know what you think by posting your comments below. The key products compared here are…
 

Top Industries

By visitors reading reviews
Computer Software Company
17%
Financial Services Firm
16%
Construction Company
10%
Real Estate/Law Firm
10%
Computer Software Company
15%
Financial Services Firm
15%
Government
10%
Insurance Company
6%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

What do you like most about DNIF HYPERCLOUD?
The dashboard is helpful, and it creates visualizations to let staff review event data and identify patterns and anomalies.
What needs improvement with DNIF HYPERCLOUD?
The EBA could be improved. The graphs and kill chain are not operational most of the time. Some dashboards are not showing data that is important to have for management review or meetings. The dash...
What is your primary use case for DNIF HYPERCLOUD?
In our project, we are mostly using authentication activities, real-time notification & alerting, log correlation & threat intelligence solutions. The DNIF tool is very authentic and capabl...
What do you like most about NetWitness Platform?
The product's initial setup phase was not at all difficult.
What is your experience regarding pricing and costs for NetWitness Platform?
The product price was reasonable for my region and the market.
What needs improvement with NetWitness Platform?
From an improvement perspective, the NetWitness Platform needs to release new features and improve in areas like log correlation. The tool needs to have easier integrations with the cloud. Building...
 

Also Known As

No data available
RSA Security Analytics
 

Learn More

Video not available
 

Overview

 

Sample Customers

Mahindra & Mahindra, Tata Consultancy Services (TCS), ICICI Bank, Yes Bank, Tata Motors, RBL Bank
Los Angeles World Airports, Reply
Find out what your peers are saying about DNIF HYPERCLOUD vs. NetWitness Platform and other solutions. Updated: June 2024.
787,061 professionals have used our research since 2012.