No more typing reviews! Try our Samantha, our new voice AI agent.

Exabeam vs NetWitness NDR comparison

Sponsored
 

Comparison Buyer's Guide

Executive SummaryUpdated on Dec 5, 2024

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

ROI

Sentiment score
4.9
Torq reduced alert handling time, increased efficiency and ROI, leading to customer satisfaction and renewal interest due to competitive pricing.
Sentiment score
6.3
Exabeam Fusion SIEM enhances anomaly detection with machine learning, benefiting financial institutions with cost savings, though pricing is unclear.
Sentiment score
8.0
Implementing NetWitness NDR enhances security, improves network visibility, reduces costs, and boosts efficiency and productivity for businesses.
Since we started working with Torq, I am handling much fewer alerts. It is becoming really easy for me to handle an alert.
SOC Analyst at AppsFlyer
By the time we officially bought Torq, we already had two workflows that were very helpful to us.
CyberSecurity Engineer at a real estate/law firm with 10,001+ employees
It pretty much took until we got to our first renewal where we said that this is the value we see, this is the things we want more, but that is the first place where we said we are happy enough that we want to renew.
Information Technology Specialist at a media company with 201-500 employees
Exabeam offers more machine learning models that detect anomalies.
Analyst at a government with 1,001-5,000 employees
 

Customer Service

Sentiment score
7.0
Torq's customer service is praised for quick, knowledgeable support, resolving issues effectively within 24 hours with minimal formal contact.
Sentiment score
6.3
Exabeam's support is praised for responsiveness and expertise but criticized for delays and inadequate regional assistance.
Sentiment score
7.3
NetWitness NDR's customer service is generally efficient and highly regarded, though some users report occasional slow response times.
The speed and quality of their answers have been pretty good, as I usually get a response within 24 hours, and they follow up well.
CyberSecurity Engineer at a real estate/law firm with 10,001+ employees
We can always get an answer, and the support team are experts in their own system.
Director Of Cyber Security at a tech vendor with 501-1,000 employees
Nine out of ten times, they give me a solution even if it is not the solution I wanted, and I still can get to the result.
Information Technology Specialist at a media company with 201-500 employees
Even with TAM support from Exabeam, many issues go unresolved.
Lead Technical Engineer Security at a tech services company with 11-50 employees
I also had the chance to look at the documentation, and the documentation is good.
Solution Architect at CTC
 

Scalability Issues

Sentiment score
7.4
Torq excels in scalability, supporting large teams and adapting efficiently, despite the no-code automation's inherent web interface limitations.
Sentiment score
7.3
Exabeam is scalable and suitable for growing needs, despite some latency issues and varying user ratings from six to nine.
Sentiment score
7.0
NetWitness NDR is scalable for large enterprises, though some users report issues with scalability and agent migration.
Our case management is super scalable.
CyberSecurity Engineer at a real estate/law firm with 10,001+ employees
In terms of scalability, you can do as long as you can build it, and they can support it.
Director Of Cyber Security at a tech vendor with 501-1,000 employees
Regarding the ability of the solution to grow in your work environment, if it is scalable, if it fits your business requirements, and if there is room to scale up, the answer is yes, for sure.
Global IT Director at OpenWeb
Regarding Exabeam's scalability and how well it adapts to its customers' needs, I would rate it an eight.
Solution Architect at CTC
 

Stability Issues

Sentiment score
5.4
Torq generally performs stably with minor bugs and glitches, but overall user satisfaction remains high without significant disruptions.
Sentiment score
7.2
Exabeam is stable and reliable, handling data well, though improvements are needed in patch application and scanning speed.
Sentiment score
7.7
NetWitness NDR is generally reliable, providing real-time data and stability, though minor technical issues are occasionally reported.
Most of the time, the system is stable as long as the components that they integrate with are stable.
Director Of Cyber Security at a tech vendor with 501-1,000 employees
Regarding stability, I have noticed some lagging, crashing, and downtime, which is one of my largest gripes.
CyberSecurity Engineer at a real estate/law firm with 10,001+ employees
I would rate Torq's product stability at eight, acknowledging that there are bugs, glitches, and downtimes.
Senior Cyber Architect at a manufacturing company with 10,001+ employees
These problems were not frequent, and the last six to eight months have been stable.
Lead Technical Engineer Security at a tech services company with 11-50 employees
Overall, I think Exabeam's stability level is good.
Solution Architect at CTC
 

Room For Improvement

Torq requires improvements in AI features, error handling, data handling, and workflow navigation for enhanced usability and reliability.
<p>Exabeam faces issues with integration, support, UI usability, documentation, performance, staffing, and MITRE ATT&amp;CK coverage, impacting overall efficiency.</p>
NetWitness NDR requires improvements in UI, scalability, detectability, integration, session times, pricing, training, and features, making it complex and slow.
It was able to capture data but was unable to differentiate between the agent hostname we are using and the hostname that resides on the back end of the Internet.
Senior Consultant at a university with 10,001+ employees
From an engineering perspective, I think more error messages and error handling information for our engineering team would be very helpful.
CyberSecurity Engineer at a real estate/law firm with 10,001+ employees
If a step is failing, the system could try to autocorrect it with AI or open a ticket from the workflow itself.
Director Of Cyber Security at a tech vendor with 501-1,000 employees
Exabeam needs to improve its documentation and provide more customization for dashboards and case management.
Lead Technical Engineer Security at a tech services company with 11-50 employees
I have explored the SaaS version; it offers many new features.
Analyst at a government with 1,001-5,000 employees
Exabeam's integration capabilities are not good, as Exabeam has a very limited number of integrations and no out-of-box integration.
Solution Architect at CTC
 

Setup Cost

Enterprise buyers find Torq's pricing high but worthwhile due to its modernization, automation, and strategic investment value.
Exabeam offers a flexible and reasonably priced model with competitive annual licensing, considered more affordable than Palo Alto.
When they bring more and more value into the platform, it makes more sense to pay that price, but still, it is expensive.
Senior Cyber Architect at a manufacturing company with 10,001+ employees
Before deciding to implement Torq, I considered that compared to our old case management platform, Torq was a much better price and had a lot better value for what you get out of the platform, which was a key consideration for the company.
CyberSecurity Engineer at a real estate/law firm with 10,001+ employees
It is an expensive solution, not an inexpensive solution, but we get through the flexibility.
Director Of Cyber Security at a tech vendor with 501-1,000 employees
 

Valuable Features

Torq enhances productivity by streamlining workflows, integrating systems, and utilizing AI for efficient SecOps and API management.
Exabeam stands out for its user-friendly interface, automation, integration with AWS, and powerful machine learning for threat detection.
NetWitness NDR offers high detection rates, real-time malware response, third-party integration, and a user-friendly, interoperable interface with advanced analytics.
Torq's unified platform approach to AI SOC automation and case management has significantly benefited us by integrating the case management platform with the automation, which saves time compared to managing multiple point solutions across our security stack.
CyberSecurity Engineer at a real estate/law firm with 10,001+ employees
The fact that I can build whatever I want within my own imagination and skills without relying on code is the best thing about Torq.
Director Of Cyber Security at a tech vendor with 501-1,000 employees
You can copy and paste a cURL command. If you have documentation or APIs, you usually have an example on the side. You basically have all the information on how the API call should be. You can just copy that and paste it into a step, and it will just build the step for you.
Global IT Director at OpenWeb
Exabeam's AI capabilities, like the natural language mode, convert natural language into Exabeam queries, enhancing ease of use.
Lead Technical Engineer Security at a tech services company with 11-50 employees
The product offers useful features like the dashboard, timeline, and session views, which enhance our security tools.
Analyst at a government with 1,001-5,000 employees
Exabeam's UEBA is the most valuable feature that I have found so far.
Solution Architect at CTC
 

Categories and Ranking

Torq
Sponsored
Ranking in Security Orchestration Automation and Response (SOAR)
4th
Average Rating
8.6
Reviews Sentiment
6.6
Number of Reviews
7
Ranking in other categories
AI-SOC (3rd), AI-Powered Security Automation (2nd)
Exabeam
Ranking in Security Orchestration Automation and Response (SOAR)
12th
Average Rating
7.8
Reviews Sentiment
6.6
Number of Reviews
20
Ranking in other categories
Security Information and Event Management (SIEM) (14th), User Entity Behavior Analytics (UEBA) (1st), Security Incident Response (4th), Threat Intelligence Platforms (TIP) (8th), AI-Powered Cybersecurity Platforms (10th)
NetWitness NDR
Ranking in Security Orchestration Automation and Response (SOAR)
25th
Average Rating
8.0
Reviews Sentiment
6.9
Number of Reviews
15
Ranking in other categories
Endpoint Protection Platform (EPP) (49th), Threat Intelligence Platforms (TIP) (36th), Endpoint Detection and Response (EDR) (57th), Network Detection and Response (NDR) (19th), Extended Detection and Response (XDR) (38th)
 

Featured Reviews

Nimrod Vardi - PeerSpot reviewer
Global IT Director at OpenWeb
Automation workflows have transformed our IT, enabling secure just-in-time access control
We work with them quite often, so we have a direct line regarding areas in Torq that have room for improvement. If we have a feature request, we can request it. I do not have anything in mind at the moment. We were a design partner for a short while, so we feel that they listen and that users of the system have an impact on the way the system is designed for the better. They have a new community, which is something that I personally suggested years ago. There are many people like me in different places and they might have already built the workflow that I need. Having the option to share workflows or to jump on a thread and say I have this need, did anyone ever build a workflow for it, is amazing. Someone would jump in and say yes, sure, here, take this workflow. I think this is an amazing thing and I really hope that the community will come alive because I think this is really powerful. This is something that I already suggested and it did happen eventually, and I am quite happy with it. I do not have any specific feature in mind that I have a need for at the moment.
DH
Solution Architect at CTC
Improved threat detection has provided clear user risk insights and streamlined incident response
Exabeam's UEBA is the most valuable feature that I have found so far. Exabeam's UEBA displays the type of description that it could show in a console regarding one particular user, the rating that it shows, and how vulnerable the user is, which is very good. Exabeam's automation for incident response is very good. The machine learning capabilities of Exabeam are also good.
reviewer1799727 - PeerSpot reviewer
Manager, IT Security Operations at a non-profit with 11-50 employees
Reliable and good support but can be expensive
I have no real complaints about the solution. Threat detection could be better. They need to enhance their threat intelligence feeds. We would like to have more IOCs or more trade intelligence to not only rely on the intelligence of the engineer in charge but to have some threat intelligence and some seeds of IOCs and to have the host have some artificial intelligence to reduce the number of false positives. I don't see this solution being very scalable. The solution is pricey.
report
Use our free recommendation engine to learn which Threat Intelligence Platforms (TIP) solutions are best for your needs.
889,955 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Financial Services Firm
13%
Construction Company
10%
Comms Service Provider
8%
Manufacturing Company
8%
Financial Services Firm
12%
Manufacturing Company
8%
Computer Software Company
8%
Construction Company
7%
Financial Services Firm
12%
Manufacturing Company
9%
Computer Software Company
8%
Construction Company
6%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Midsize Enterprise3
Large Enterprise4
By reviewers
Company SizeCount
Small Business12
Midsize Enterprise4
Large Enterprise7
By reviewers
Company SizeCount
Small Business10
Midsize Enterprise2
Large Enterprise5
 

Questions from the Community

What needs improvement with Torq?
This is exactly what we discussed two days ago with the Torq team. We told them where we want to see improvements. Fo...
What is your primary use case for Torq?
I use Torq as my case management and alert system. Working as a SOC analyst, the first thing I do every morning is ge...
What advice do you have for others considering Torq?
I would definitely recommend Torq. I have no doubt, really. When we looked for another vendor, Torq really answered a...
What are the biggest differences between Securonix UEBA, Exabeam, and IBM QRadar?
It mostly depends on your use-cases and environment. Exabeam and Securonix have a stronger UEBA feature set, friendli...
What is your experience regarding pricing and costs for Exabeam Fusion SIEM?
I do not have much information about the pricing. However, I am aware that Exabeam is cheaper than Palo Alto based on...
What needs improvement with Exabeam Fusion SIEM?
Exabeam's integration capabilities are not good, as Exabeam has a very limited number of integrations and no out-of-b...
Ask a question
Earn 20 points
 

Also Known As

No data available
No data available
RSA ECAT, NetWitness Network
 

Overview

 

Sample Customers

Information Not Available
Hulu, ADP, Safeway, BBCN Bank
ADP, Ameritas, Partners Healthcare
Find out what your peers are saying about Exabeam vs. NetWitness NDR and other solutions. Updated: April 2026.
889,955 professionals have used our research since 2012.