Try our new research platform with insights from 80,000+ expert users
Cisco Secure Network Analytics Logo

Cisco Secure Network Analytics pros and cons

Vendor: Cisco
4.1 out of 5

Pros & Cons summary

Buyer's Guide

Get pricing advice, tips, use cases and valuable features from real users of this product.
Get the report

Prominent pros & cons

PROS

NetFlow data is crucial for starting security investigations and provides a holistic view of network traffic.
Stealthwatch enhances threat detection rates and reduces detection times with improved network visibility.
Cisco Secure Network Analytics offers integration with other Cisco security devices and provides comprehensive coverage of endpoints and traffic flows.
Visibility and anomaly detection features help in identifying suspicious activities without relying on signatures.
The platform's analytics, including reporting and mitigation capabilities, improve overall network security management.

CONS

Cisco Secure Network Analytics needs to improve its integration with Cisco ISE for user and session details, which currently requires additional setup.
Scalability is a concern due to problems with element licensing costs.
The initial setup and configuration of Cisco Secure Network Analytics are complex and time-consuming.
Cisco Secure Network Analytics requires better integration with device discovery to reduce manual efforts.
Cisco Secure Network Analytics still needs to mature in artificial intelligence and machine learning capabilities.
 

Cisco Secure Network Analytics Pros review quotes

it_user631224 - PeerSpot reviewer
Information Security Analyst at a non-profit with 1,001-5,000 employees
May 29, 2017
I value the feature which enables me to detect devices talking to suspect IPs.
it_user734160 - PeerSpot reviewer
Senior Technical Consultant
Sep 10, 2017
Most valuable features are the network maps and server and network response time.
it_user735195 - PeerSpot reviewer
Senior Information Security Engineer at a transportation company with 10,001+ employees
Sep 12, 2017
Provides easily identifiable anomalies that you can't see with signature detections.
Learn what your peers think about Cisco Secure Network Analytics. Get advice and tips from experienced pros sharing their opinions. Updated: January 2026.
879,899 professionals have used our research since 2012.
it_user735216 - PeerSpot reviewer
Highly motivated Security Engineer incident Response, Vuln Mgmt, Malware Analysis, IDS/IPS, DLP, Network Security +more at a transportation company with 10,001+ employees
Sep 12, 2017
The most valuable feature is NetFlow. The beginning of any security investigation starts with NetFlow data.
Rainier S. - PeerSpot reviewer
Head of Integration Engineering / Enterprise Technology & Innovation at a healthcare company with 10,001+ employees
Mar 22, 2018
Able to drill down into a center's utilization, then create reports based on it.
Forensic60e5 - PeerSpot reviewer
Forensic Analyst at a pharma/biotech company with 1,001-5,000 employees
Mar 28, 2018
The artifacts available in the tool provide better information for analyzing network traffic. It enables a holistic view of network traffic and general packet analysis. It's easy to identify anomalies without the use of signatures. The way in which we implemented Stealthwatch Cloud has enabled my team to analyze traffic behind proxies.
NetworkSddc6 - PeerSpot reviewer
Network Section Chief at a government with 1,001-5,000 employees
Jun 17, 2019
Cisco Stealthwatch has reduced the amount of time to detect an immediate threat.
NetworkE7689 - PeerSpot reviewer
Network Engineer at a government with 1,001-5,000 employees
Jun 17, 2019
The search options on Cisco Stealthwatch are the most valuable. You can get very granular with it, down to the kilobits or the seconds if you want. The product supports any time frame that you need, so that is nice.
BG
Manager of Digital Communications at Memorial Hermann Healthcare System
Jun 17, 2019
The solution has increased our threat detection rate. Cisco Stealthwatch has not reduced our incident response times. It has not reduced the amount of time it takes us to detect immediate threats. It has reduced false positives.
SG
Engineer at Charter Communications, Inc.
Jun 17, 2019
Being able to identify specific date closed across the network is invaluable.
 

Cisco Secure Network Analytics Cons review quotes

it_user631224 - PeerSpot reviewer
Information Security Analyst at a non-profit with 1,001-5,000 employees
May 29, 2017
We need to be able to filter out internal IPs as non-threats.
it_user734160 - PeerSpot reviewer
Senior Technical Consultant
Sep 10, 2017
The version with the Dell server had iDRAC problems. Often, it reported iDRAC failure.
it_user735195 - PeerSpot reviewer
Senior Information Security Engineer at a transportation company with 10,001+ employees
Sep 12, 2017
One update that I would like to see is an agent-based client. Currently, Stealthwatch is network-based. A local agent could help manage endpoints.
Learn what your peers think about Cisco Secure Network Analytics. Get advice and tips from experienced pros sharing their opinions. Updated: January 2026.
879,899 professionals have used our research since 2012.
it_user735216 - PeerSpot reviewer
Highly motivated Security Engineer incident Response, Vuln Mgmt, Malware Analysis, IDS/IPS, DLP, Network Security +more at a transportation company with 10,001+ employees
Sep 12, 2017
One update I would like to see is an agent-based client. Currently StealthWatch is network based.
Rainier S. - PeerSpot reviewer
Head of Integration Engineering / Enterprise Technology & Innovation at a healthcare company with 10,001+ employees
Mar 22, 2018
Reliance on Java. Get away from that.
Forensic60e5 - PeerSpot reviewer
Forensic Analyst at a pharma/biotech company with 1,001-5,000 employees
Mar 28, 2018
If there was one improvement I’d suggest it would be that it detect traffic through an intranet. The product requires that traffic flow through a managed network device. The product is designed mostly for enterprise environments and not smaller environments or businesses.
NetworkSddc6 - PeerSpot reviewer
Network Section Chief at a government with 1,001-5,000 employees
Jun 17, 2019
There's a lot of traffic on our network that we don't see sometimes.
NetworkE7689 - PeerSpot reviewer
Network Engineer at a government with 1,001-5,000 employees
Jun 17, 2019
I would like the search page available with Cisco Stealthwatch to be more intuitive. The previous release was better than the current one for the UI.
BG
Manager of Digital Communications at Memorial Hermann Healthcare System
Jun 17, 2019
The ability to be natively integrated into Port Aggregator would be beneficial because it would reduce just one more component that's needed in order to have that type of view.
SG
Engineer at Charter Communications, Inc.
Jun 17, 2019
We've had problems with element licensing costs so scalability is a concern.