Try our new research platform with insights from 80,000+ expert users

Cisco Secure Network Analytics vs Cisco Sourcefire SNORT comparison

Sponsored
 

Comparison Buyer's Guide

Executive Summary
 

Categories and Ranking

Juniper Mist Premium Analytics
Sponsored
Average Rating
8.0
Number of Reviews
2
Ranking in other categories
Network Monitoring Software (58th)
Cisco Secure Network Analytics
Average Rating
8.2
Number of Reviews
59
Ranking in other categories
Network Monitoring Software (24th), Network Traffic Analysis (NTA) (3rd), Network Detection and Response (NDR) (5th), Cisco Security Portfolio (4th)
Cisco Sourcefire SNORT
Average Rating
7.6
Number of Reviews
19
Ranking in other categories
Intrusion Detection and Prevention Software (IDPS) (10th)
 

Mindshare comparison

Network Monitoring Software
Intrusion Detection and Prevention Software (IDPS)
 

Featured Reviews

ALEXANDRE VIANNA - PeerSpot reviewer
May 3, 2024
Has a single dashboard, but is expensive
We use this solution to manage our mission environment The single dashboard is a valuable feature.  The technical support needs improvement. The initial setup is straightforward. The solution is expensive. I rate the pricing an eight out of ten.  Overall, I rate the solution a seven out of…
Rainier S. - PeerSpot reviewer
Mar 22, 2018
You are able to drill down into a center's utilization, then create reports based on it
In the last year or two, we have been working with our Cisco NAS engineers to improve our security posturing. It is more our being proactive rather than reactive. While Stealthwatch and Lancope have this ability to look inside and give you visibility (a great feature), follow-up is the rule. We would like filters that you can put into place to tap onto certain types of behaviors, alerts out, and/or hopefully a block. This is sort of what we are looking for. I might be speaking too early, because we are not down this path yet. We know the feature set is there, we just do not know yet how to achieve it. That is proactive rather than more reactive. For Lancope Stealthwatch, we would like to see it more on the ASA Firewall platform. While this might already be available, this is more a failing of Cisco to inform us if it is there. For example: * Are we on the right or wrong version of the code? * What does the code look like? * Are we are really looking at firewalls? Or is it more about the foundation and route switches that we are seeing? It is about visibility.
Jack Poon - PeerSpot reviewer
Jul 31, 2024
Offers ease of setup and good documentation
When it comes to the product's deployment phase, we have a lot of vendor support. We have a lot of skills here in Hong Kong. Our company doesn't find any problem deploying Cisco solutions. The solution is deployed on an on-premises version. Speaking about the time required to deploy the solution, I would say that we have quite a lot of previous experience with deploying Cisco products. We have our company's standard design document, which we need to follow. We have a standard testing procedure for all those features. We just take out some appropriate parts and then compile them into one document for an individual project. It is actually quite easy for us to do the documentation, so it just takes one or two hours, and we can do the implementation because all the materials and testing procedures are already in our company standard documents, so it is not that difficult for us.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"We can manage the entire system across the network and troubleshoot the pain points."
"The single dashboard is a valuable feature."
"The most valuable features of this solution are its reporting and mitigation capabilities."
"The feature most valuable for us is to gain visibility of what is actually floating through, so we can stop it based on whether it's good or bad traffic."
"From a security standpoint, it is just seeing pockets as well. Visibility is very key for us."
"The most valuable features of this solution are the logging, keeping threats under control, and keeping our data and environment secure."
"The most valuable part is that Stealthwatch is part of a portfolio of security devices from Cisco. Cisco literally can touch every single end point, every single ingress and egress point in the network. Nobody else has that."
"Cisco Secure Network Analytics has increased the visibility of what is happening in our network, and I think that's the most important reason to use it. We can see what is really happening instead of just looking at numbers from routers or switches."
"It does change the way we troubleshoot and it is relatively easy to use once you learn it. I would recommend it to someone considering it."
"The most valuable feature we got out of Stealthwatch is to be able to, while troubleshooting, go deep into one of our interfaces and verify what the bandwidth is and if there's any activity there that's causing problems."
"The solution can be integrated with some network electors like Cisco Stealthwatch, Cisco ISE, and Active Directory to provide the client with authentication certificates."
"The most valuable feature is the ability to automatically learn the traffic in our environment, and change the merit recommendations based on that."
"In general, the features are all great. However, if I need to take hardware for ASA, because they need to upgrade to Firepower, we want to create rules. For that, most of the time we go to the command line. Right now Firepower is working really hard on the grid. You can apply all those rules to the grid. Even if you want to monitor the logs, for example, the activity will tell you which particular user has been blocked because of that rule. Firepower's monitoring interface is very good, because you can see each and every piece. ASA also had it, but there you needed to type the command and be under the server to see all that stuff. In Firepower you have the possibility to go directly to the firewall. The way the monitoring is displayed is also very nice. The feature I appreciate most in Firepower is actually the grid. The grid has worked very well."
"The URL filtering is very good and you can create a group for customized URLs."
"It is quite an intelligent product."
"The solution is rather easy to use."
"The solution is stable."
"It simplifies the configuration process by offering pre-defined base configurations, including security and connectivity settings."
 

Cons

"The technical support needs improvement."
"The Wi-Fi side needs improvement."
"I would like to see some improvement when it comes to reporting."
"It's too complicated to install, when starting out."
"The overall visibility into the actual device itself would be helpful. I don't just want support-specific data, but also to be able to see information such as CPU and other internal components or usage of the devices."
"We had some trouble with the installation as we migrated from our previous solution."
"It hasn't really improved our direct detection rate but it has definitely reduced our incident response time as we wouldn't have been able to detect threats or immediate risks without this solution."
"We've had problems with element licensing costs so scalability is a concern."
"Complexity on integration is not so straightforward and you really need an expert to help build it out."
"Reliance on Java. Get away from that."
"The pricing needs to be improved. We have lots of low-budget clients around us. Budget constraints are always a deterrent in our market."
"I don't think this solution is a time-based control system, because one cannot filter traffic based on time."
"We are unhappy with technical support for this solution, and it is not as professional as what we typically expect from Cisco."
"The main dashboard of Cisco Sourcefire SNORT could improve."
"Integration with other components — even Cisco's own products — can be enhanced to improve administrative experience."
"I would like to have analytics included in the suite."
"I did not experience any pain points that required improvement. Maybe a couple of false-positives, but that's about it."
"The customization of the rules can be simplified."
 

Pricing and Cost Advice

"The solution is expensive."
"The licensing costs are outrageous."
"The tool is not cheaply priced."
"Our fees are approximately $3,000 USD."
"Licensing is done by flows per second, not including outside>in traffic."
"Today, we are part of the big Cisco ELA, and it is a la carte. We can get orders for whatever we want. At the end of the day, we have to pay for it in one big expense, but that is fine. We are okay with that."
"This is an expensive product. We have quit paying for support because we don't want to have to upgrade it and keep paying for it."
"​Licensing is done by flows per second, not including outside (in traffic)."
"NetFlow is very expensive."
"I don't know the exact amount, but most of the time when I go to a company with a proposition, they will say, "This thing that you are selling is good, but it's expensive. Why don't you propose something like FortiGate, Check Point, or Palo Alto?" Cisco device are expensive compared to other devices."
"The cost is per port and can be expensive but it does include training and support for three years."
"We have a three-year license for this solution."
"Licensing for this solution is paid on a yearly basis."
"If one is an extremely expensive product, and ten is cheap, I rate the tool's price as a five."
report
Use our free recommendation engine to learn which Network Monitoring Software solutions are best for your needs.
814,649 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Computer Software Company
16%
Financial Services Firm
12%
Manufacturing Company
9%
Government
8%
Computer Software Company
31%
Financial Services Firm
11%
Government
8%
Manufacturing Company
6%
Computer Software Company
22%
Financial Services Firm
9%
University
7%
Government
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
No data available
 

Questions from the Community

What do you like most about Juniper Mist Premium Analytics?
We can manage the entire system across the network and troubleshoot the pain points.
What do you like most about Cisco Stealthwatch?
The most valuable feature of Cisco Secure Network Analytics is the Threat Intelligence integration.
What is your experience regarding pricing and costs for Cisco Stealthwatch?
The tool is not cheaply priced. In cybersecurity, you want an extra layer of security in your organization. Some sect...
What needs improvement with Cisco Stealthwatch?
The expensive nature of the tool is an area of concern where improvements are required.
What do you like most about Cisco Sourcefire SNORT?
The product is inexpensive compared to leading brands such as Palo Alto or Fortinet.
What is your experience regarding pricing and costs for Cisco Sourcefire SNORT?
If one is an extremely expensive product, and ten is cheap, I rate the tool's price as a five. There are some other t...
What needs improvement with Cisco Sourcefire SNORT?
Cisco offers the Cisco DNA Center, which is a source that provides crucial information for us to monitor performance,...
 

Also Known As

No data available
Cisco Stealthwatch, Cisco Stealthwatch Enterprise, Lancope StealthWatch
Sourcefire SNORT
 

Learn More

Video not available
 

Overview

 

Sample Customers

Information Not Available
Edge Web Hosting, Telenor Norway, Ivy Tech Community College of Indiana, Webster Financial Corporation, Westinghouse Electric, VMware, TIAA-CREF
CareCore, City of Biel, Dimension Data, LightEdge, Lone Star College System, National Rugby League, Port Aventura, Smart City Networks, Telecom Italia, The Department of Education in Western Australia
Find out what your peers are saying about Cisco Secure Network Analytics vs. Cisco Sourcefire SNORT and other solutions. Updated: January 2020.
814,649 professionals have used our research since 2012.