Try our new research platform with insights from 80,000+ expert users

Cisco Secure Network Analytics vs Darktrace vs Splunk User Behavior Analytics comparison

 

Comparison Buyer's Guide

Executive Summary
 

Mindshare comparison

Network Monitoring Software
Extended Detection and Response (XDR)
User Entity Behavior Analytics (UEBA)
 

Featured Reviews

Rainier S. - PeerSpot reviewer
You are able to drill down into a center's utilization, then create reports based on it
In the last year or two, we have been working with our Cisco NAS engineers to improve our security posturing. It is more our being proactive rather than reactive. While Stealthwatch and Lancope have this ability to look inside and give you visibility (a great feature), follow-up is the rule. We would like filters that you can put into place to tap onto certain types of behaviors, alerts out, and/or hopefully a block. This is sort of what we are looking for. I might be speaking too early, because we are not down this path yet. We know the feature set is there, we just do not know yet how to achieve it. That is proactive rather than more reactive. For Lancope Stealthwatch, we would like to see it more on the ASA Firewall platform. While this might already be available, this is more a failing of Cisco to inform us if it is there. For example: * Are we on the right or wrong version of the code? * What does the code look like? * Are we are really looking at firewalls? Or is it more about the foundation and route switches that we are seeing? It is about visibility.
Luis KiambatA - PeerSpot reviewer
Great autonomous support, offers an easy setup, and has responsive support
The autonomous response is great. It blocks basically everything that is outside the normal, and what's happening 24/7. When we don't have anybody looking, it's great. The visibility that it gives you into any incident is great. You can see everything. I would say these two are the biggest aspects we really appreciate. It is easy to set everything up. The solution is stable. Users can scale the product. Technical support is helpful and responsive.
Hamada-Elewa - PeerSpot reviewer
Decreases the false positives but storage model complexity hampers efficiency
I recommend it to my customers, but I'm a salesman. I am not implementing it myself It decreases the false positives, so it will decrease the time consumed by the operation team to work on Splunk. The most effective one is the integration with other vendors. This is the most attractive one.…

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"It's easy to set up. The deployment takes one or two days. You need to collect the data from a device and then direct it to the portal."
"The artifacts available in the tool provide better information for analyzing network traffic. It enables a holistic view of network traffic and general packet analysis. It's easy to identify anomalies without the use of signatures. The way in which we implemented Stealthwatch Cloud has enabled my team to analyze traffic behind proxies."
"We find that Stealthwatch can detect the unseen."
"The most valuable feature of Cisco Secure Network Analytics is the Threat Intelligence integration."
"From what I understand, you can encrypt and unencrypt traffic moving in transit. This is one of the features that we liked about it."
"I value the feature which enables me to detect devices talking to suspect IPs."
"Cisco Secure Network Analytics has increased the visibility of what is happening in our network, and I think that's the most important reason to use it. We can see what is really happening instead of just looking at numbers from routers or switches."
"The most valuable feature of this solution is the way the net flow is being merged together in a single pane. That's been extremely useful for us, because can see what's going on with traffic in one single place."
"It has helped the organization to detect any malware affecting the machines...The network monitoring and the email monitoring features are very valuable for us."
"The active threat dashboard is the most valuable feature of this solution."
"It's a very stable product."
"The most valuable feature of this solution is that it does not require human intervention to eliminate a threat."
"The scalability of Darktrace is very high."
"We are able to detect a lot of things, actually, and see what is happening in our network."
"I am impressed with the product's ability to give insights into network traffic."
"The ability to see what we have not seen before is most valuable. It is very interesting to find out the most vulnerable devices in our network."
"The solution is fast, flexible, and easy to use."
"The solution is extremely scalable. Our customers are regularly scaling up after installing Splunk."
"This is a good security product."
"The most valuable feature is the ability to search through a large amount of data."
"It is a solution that helps test and measure customer satisfaction."
"It's straightforward in terms of configuration and troubleshooting and log management and monitoring as well. These are the edge points in addition to it being a modular solution where you can capitalize on your current licenses with extra licensing models, which can match the customer's business requirement and it can help the customer to design or to actually plan for their own roadmap."
"This intelligent user behavior analytics package is easy to configure and use while remaining feature filled."
"Splunk User Behavior Analytics is a one hundred percent stable solution."
 

Cons

"I would like to see interoperability with other Cisco products because we have ThousandEyes, Cisco Prime, and others. The interaction among these is important to us."
"The overall visibility into the actual device itself would be helpful. I don't just want support-specific data, but also to be able to see information such as CPU and other internal components or usage of the devices."
"If they can make this product more web-based, that would be amazing."
"It's too complicated to install, when starting out."
"I think the interface is a little lacking. The interface seems like it just needs to be modernized. It's been the same interface now, ever since I've seen it probably four years ago."
"We are continuing down the road of ACI and ISE with Cisco, so we would like to see the continuation of Stealthwatch integrating into ISE for exchange of information, and also, more into the ACI environment too."
"The version with the Dell server had iDRAC problems. Often, it reported iDRAC failure."
"Stealthwatch needs improvement when it comes to speed."
"Darktrace should have more automation and integrations with other security monitoring tools."
"It's quite expensive to have."
"Upper management wasn't sold on the value proposition."
"There is a high ratio of false positive information."
"It should be easier to access the Darktrace portal and its documentation. Only the customer can access their portal and support. It could be cheaper."
"The interface is too mathematical and it should be simplified."
"The dashboard and reporting for this solution could be improved as it is currently complex. The GUI for this solution could also be improved."
"The Darktrace Mobile app needs improvement as it's currently limited in functionality, and the learning AI takes a while to adapt to new devices, flagging new users as threats for up to a month before recognizing them as regular network users."
"Enhancing the storage model that they are using is necessary."
"I'm not aware of any lacking features."
"In the future I would like to see simplified statistics and analytical threats."
"They should work to add more built-in correlation searches and more use cases based on worldwide customer experiences. They need more ready-made use cases."
"In terms of improvements, advanced reporting could see enhancements as there are some issues with latency."
"Currently, a lot of network operations need improvement. We still need people to handle incidents. Our vision is to leverage status and convert it directly from the network devices. It would be ideal if we could take action using APIs and API code and remove manual processes."
"It could be easier to scale the solution if you are using it on-premise, not in the cloud."
"There are occasional bugs."
 

Pricing and Cost Advice

"Today, we are part of the big Cisco ELA, and it is a la carte. We can get orders for whatever we want. At the end of the day, we have to pay for it in one big expense, but that is fine. We are okay with that."
"The solution is expensive. It costs several hundred thousand dollars per year (depending on how many flows you are collecting)."
"The pricing for this solution is good."
"It has a subscription model. There is yearly support, and there is also three-year support. It depends on what the customers want."
"One of the things which bugs me about Lancope is the licensing. We understand how licensing works. Our problem is when we bought and purchased most of these Lancope devices, we did so with our sister company. Somewhere within the purchase and distribution, licensing got mixed up. That is all on Cisco, and it is their responsibility. They allotted some of our sister company's equipment to us, and some of our equipment to them. To date, they have never been able to fix it."
"NetFlow is very expensive."
"We pay for support costs on a yearly basis."
"Licensing is on a yearly basis."
"The cost is moderate."
"The pricing is reasonable."
"The cost of the solution can be reduced to make it more appealing to customers."
"All of the other modules, such as the licensing modules, are on par. It's one for one."
"The cost of the solution is expensive for smaller businesses. They will not be able to afford it or might not need this type of security solution."
"It is expensive."
"It is a very expensive product."
"The pricing is very flexible for Darktrace. Sometimes, a customer does not have the appropriate budget, but Darktrace can handle that. They offer monthly payments, so the customer can acquire the solution very easily."
"There are additional costs associated with the integrator."
"I am not aware of the price, but it is expensive."
"Pricing varies based on the packages you choose and the volume of your usage."
"I hope we can increase the free license to be more than 5 gig a day. This would help people who want to introduce a POC or a demo license for the solution."
"The licensing costs is around 10,000 dollars."
"My biggest complaint is the way they do pricing... You can never know the pricing for next year. Every single time you adjust to something new, the price goes up. It's impossible to truly budget for it. It goes up constantly."
report
Use our free recommendation engine to learn which Network Monitoring Software solutions are best for your needs.
824,052 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Computer Software Company
30%
Financial Services Firm
11%
Government
8%
Manufacturing Company
6%
Computer Software Company
15%
Financial Services Firm
8%
Manufacturing Company
8%
Government
7%
Computer Software Company
15%
Financial Services Firm
13%
Government
9%
Manufacturing Company
8%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

What do you like most about Cisco Stealthwatch?
The most valuable feature of Cisco Secure Network Analytics is the Threat Intelligence integration.
What is your experience regarding pricing and costs for Cisco Stealthwatch?
The tool is not cheaply priced. In cybersecurity, you want an extra layer of security in your organization. Some sect...
What needs improvement with Cisco Stealthwatch?
The expensive nature of the tool is an area of concern where improvements are required.
How does Crowdstrike Falcon compare with Darktrace?
Both of these products perform similarly and have many outstanding attributes. CrowdStrike Falcon offers an amazing u...
Which is better - SentinelOne or Darktrace?
Which solution is better depends on which is more suitable specifically for your company. Darktrace, for example, is ...
What do you like most about Darktrace?
A very useful feature in Darktrace for real-time threat analysis is the packet inspection that analyzes the packet tr...
What do you like most about Splunk User Behavior Analytics?
The solution's most valuable feature is Splunk queries, which allow us to query the logs and analyze the attack vectors.
What is your experience regarding pricing and costs for Splunk User Behavior Analytics?
It's too expensive. If you need observability, you will pay for the whole package of observability. But if you need a...
What needs improvement with Splunk User Behavior Analytics?
Enhancing the storage model that they are using is necessary. It's too much. The number of VMs, the total number of V...
 

Also Known As

Cisco Stealthwatch, Cisco Stealthwatch Enterprise, Lancope StealthWatch
No data available
Caspida, Splunk UBA
 

Learn More

Video not available
Video not available
 

Overview

 

Sample Customers

Edge Web Hosting, Telenor Norway, Ivy Tech Community College of Indiana, Webster Financial Corporation, Westinghouse Electric, VMware, TIAA-CREF
Irwin Mitchell, Open Energi, Wellcome Trust, FirstGroup plc, Virgin Trains, Drax, QUI! Group, DNK, CreaCard, Macrosynergy, Sisley, William Hill plc, Toyota Canada, Royal British Legion, Vitol, Allianz, KKR, AIRBUS, dpd, Billabong, Mclaren Group.
8 Securities, AAA Western, AdvancedMD, Amaya, Cerner Corporation, CJ O Shopping, CloudShare, Crossroads Foundation, 7-Eleven Indonesia
Find out what your peers are saying about Zabbix, Auvik, Datadog and others in Network Monitoring Software. Updated: December 2024.
824,052 professionals have used our research since 2012.