Try our new research platform with insights from 80,000+ expert users

Cisco Secure Network Analytics vs NetWitness Platform comparison

 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Cisco Secure Network Analytics
Average Rating
8.2
Reviews Sentiment
6.9
Number of Reviews
60
Ranking in other categories
Network Monitoring Software (22nd), Network Traffic Analysis (NTA) (3rd), Network Detection and Response (NDR) (5th), Cisco Security Portfolio (4th)
NetWitness Platform
Average Rating
7.4
Reviews Sentiment
7.5
Number of Reviews
36
Ranking in other categories
Log Management (22nd), Security Information and Event Management (SIEM) (23rd)
 

Mindshare comparison

Cisco Secure Network Analytics and NetWitness Platform aren’t in the same category and serve different purposes. Cisco Secure Network Analytics is designed for Network Monitoring Software and holds a mindshare of 1.3%, down 1.7% compared to last year.
NetWitness Platform, on the other hand, focuses on Log Management, holds 0.3% mindshare, down 0.4% since last year.
Network Monitoring Software
Log Management
 

Featured Reviews

Sudhakar T - PeerSpot reviewer
Strong network security analytics with excellent encrypted traffic analysis features
Improvements are needed on the application layer for complete security analysis. The solution should have the ability to analyze security events not only at the network layer but also at the application and OS layers. There's a need for a more comprehensive licensing model where all necessary licenses are included by default.
MdZaman - PeerSpot reviewer
Really scalable for enterprise customers
The solution should have more integration capabilities with different platforms. The API is nearly open and scalable, so the solution can integrate with many platforms. The solution has more than 200 log sources in the scalability to support, but this is its limit. Installation is pretty easy. However, there are a couple of modules involved, so it is not as easy as it could be. We are talking about a distributed module, not a single-module type. This is what makes things a bit complex, instead of easier. I rate it as a seven out of ten on its installation and configuration capabilities.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"Stability is the most valuable feature we have seen in this solution."
"The most valuable feature is having visibility into the data segments throughout our network."
"Cisco Secure Network Analytics has increased the visibility of what is happening in our network, and I think that's the most important reason to use it. We can see what is really happening instead of just looking at numbers from routers or switches."
"The most valuable feature is integration."
"The most valuable part is that Stealthwatch is part of a portfolio of security devices from Cisco. Cisco literally can touch every single end point, every single ingress and egress point in the network. Nobody else has that."
"Provides easily identifiable anomalies that you can't see with signature detections."
"The feature most valuable for us is to gain visibility of what is actually floating through, so we can stop it based on whether it's good or bad traffic."
"The most valuable features provided by this solution are visibility and information."
"Offers a good wireless feature."
"The most valuable feature is the hunting ability to work in a CERT."
"NetWitness can be highly beneficial for incident detection and response."
"The most valuable feature is the correlation. It can report in real-time and monitor the management."
"The packet capture aspect of it is a valuable feature because it is quite different from a traditional SIEM solution that only carries out investigations based on captured logs."
"The product's initial setup phase was not at all difficult."
"Their technical support responds quickly and are knowledgable."
"It's fully scalable. There is no limit. Of course, the license limits per day the number of terabytes. In my opinion, it's very flexible."
 

Cons

"The visualization could be improved, the GUI is not the best."
"One area that could be improved in SNA is the integration with Cisco ISE for user and session details, which currently requires additional setup."
"The version with the Dell server had iDRAC problems. Often, it reported iDRAC failure."
"Cisco could improve the administration for the customers."
"The expensive nature of the tool is an area of concern where improvements are required."
"We had some trouble with the installation as we migrated from our previous solution."
"I would like Cisco to make it easier for the administrators to use it."
"It's a good solid solution but integration with Network Access Control products with Cisco ISE would be good."
"The multi-tenant capabilities are lagging compared to IBM QRadar."
"The system architecture is complex and sometimes it’s hard to troubleshoot potential problems."
"Nowadays, their support is a little subpar compared to other solutions. I rate RSA support six out of 10."
"There are instances where you try to run the reports and then it does not give you the desired outcome."
"The solution should have more integration capabilities with different platforms."
"It is not so easy to customize this product."
"The tool's integration capability isn't so great."
"I'd like to see improvement in its ease of use. It's basically unusable. It's overly complex."
 

Pricing and Cost Advice

"It is worth the cost."
"The licensing costs are outrageous."
"One of the things which bugs me about Lancope is the licensing. We understand how licensing works. Our problem is when we bought and purchased most of these Lancope devices, we did so with our sister company. Somewhere within the purchase and distribution, licensing got mixed up. That is all on Cisco, and it is their responsibility. They allotted some of our sister company's equipment to us, and some of our equipment to them. To date, they have never been able to fix it."
"It has a subscription model. There is yearly support, and there is also three-year support. It depends on what the customers want."
"Our fees are approximately $3,000 USD."
"Licensing is on a yearly basis."
"There are additional licenses needed for the number of so-called network flows. It's hard to plan the number of flows you need in the network, this is a problem. The price of the Cisco Stealthwatch is relatively inexpensive"
"​Licensing is done by flows per second, not including outside (in traffic)."
"In comparison to other SIEM solutions such as Splunk, NetWitness is less costly."
"It is cheap."
"We have a perpetual license, so the total cost of ownership is not very expensive. It's a good investment."
"The licenses are good but the cost is very expensive."
"This is a pricey solution; it's not cheap."
"The product is expensive."
"Compared to the competition, the is price is not that high."
"It’s cheaper to run virtual machines in a VMware environment."
report
Use our free recommendation engine to learn which Network Monitoring Software solutions are best for your needs.
838,713 professionals have used our research since 2012.
 

Comparison Review

VS
Feb 26, 2015
HP ArcSight vs. IBM QRadar vs. ​McAfee Nitro vs. Splunk vs. RSA Security vs. LogRhythm
We at Infosecnirvana.com have done several posts on SIEM. After the Dummies Guide on SIEM, we are following it up with a SIEM Product Comparison – 101 deck. So, here it is for your viewing pleasure. Let me know what you think by posting your comments below. The key products compared here are…
 

Top Industries

By visitors reading reviews
Computer Software Company
30%
Financial Services Firm
11%
Government
9%
Manufacturing Company
6%
Financial Services Firm
19%
Computer Software Company
17%
Insurance Company
6%
Government
6%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

What do you like most about Cisco Stealthwatch?
The most valuable feature of Cisco Secure Network Analytics is the Threat Intelligence integration.
What is your experience regarding pricing and costs for Cisco Stealthwatch?
The tool is not cheaply priced. In cybersecurity, you want an extra layer of security in your organization. Some sectors want NDR solutions, so you cannot deploy such tools everywhere, as they are ...
What needs improvement with Cisco Stealthwatch?
The expensive nature of the tool is an area of concern where improvements are required.
What do you like most about NetWitness Platform?
The product's initial setup phase was not at all difficult.
What is your experience regarding pricing and costs for NetWitness Platform?
The product price was reasonable for my region and the market.
What needs improvement with NetWitness Platform?
From an improvement perspective, the NetWitness Platform needs to release new features and improve in areas like log correlation. The tool needs to have easier integrations with the cloud. Building...
 

Also Known As

Cisco Stealthwatch, Cisco Stealthwatch Enterprise, Lancope StealthWatch
RSA Security Analytics
 

Overview

 

Sample Customers

Edge Web Hosting, Telenor Norway, Ivy Tech Community College of Indiana, Webster Financial Corporation, Westinghouse Electric, VMware, TIAA-CREF
Los Angeles World Airports, Reply
Find out what your peers are saying about Zabbix, Auvik, Datadog and others in Network Monitoring Software. Updated: February 2025.
838,713 professionals have used our research since 2012.