Try our new research platform with insights from 80,000+ expert users

NetWitness NDR vs ServiceNow Security Operations comparison

 

Comparison Buyer's Guide

Executive Summary
 

Categories and Ranking

NetWitness NDR
Ranking in Security Orchestration Automation and Response (SOAR)
22nd
Average Rating
8.0
Number of Reviews
15
Ranking in other categories
Endpoint Protection Platform (EPP) (53rd), Threat Intelligence Platforms (24th), Endpoint Detection and Response (EDR) (50th), Network Detection and Response (NDR) (15th), Extended Detection and Response (XDR) (28th)
ServiceNow Security Operations
Ranking in Security Orchestration Automation and Response (SOAR)
9th
Average Rating
7.8
Number of Reviews
18
Ranking in other categories
Security Incident Response (2nd), Risk-Based Vulnerability Management (8th)
 

Mindshare comparison

As of September 2024, in the Security Orchestration Automation and Response (SOAR) category, the mindshare of NetWitness NDR is 0.3%, down from 0.4% compared to the previous year. The mindshare of ServiceNow Security Operations is 4.7%, up from 4.0% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Security Orchestration Automation and Response (SOAR)
 

Featured Reviews

SupravatMaji - PeerSpot reviewer
Jun 23, 2022
Beneficial single unified dashboard, good native application integration, and high availability
The most valuable feature of RSA NetWitness Network is the single unified dashboard from which you can manage all the different products of RSA. Additionally, the integration with native applications is good RSA NetWitness Network could improve on integration with non-native application…
Chandra Singala - PeerSpot reviewer
Oct 13, 2022
Stable and reliable and is useful for any incoming vulnerability as it helps you avoid vulnerability attacks
I have strong experience with ServiceNow products, including ServiceNow Security Operations. After ServiceNow Security Operations is deployed, you need to maintain the data, but the maintenance is easy in terms of data security and data scanning. Suppose you need to do some customizations, for example. In that case, you have different tools, so you'll need other data maps. Suppose you want to import more information from XML files, for instance. In that case, you need to customize, so this is what you have to do in terms of maintaining ServiceNow Security Operations data. In my organization, three people use ServiceNow Security Operations, and four take care of other tools such as Qualys and Data Stream. I'd recommend ServiceNow Security Operations, especially if you want to maintain your data and prevent any vulnerability attacks, for example, on the infrastructure. Suppose you have customers and you want to convince your customers to go with ServiceNow Security Operations. In that case, you should explain the benefits and consequences of not having the solution. You should also explain to potential customers how ServiceNow Security Operations can prevent vulnerabilities and how it can maintain the current CMDB. This solution is what I recommend for vulnerability response as it's beneficial for any customer and can help maintain infrastructure. My rating for ServiceNow Security Operations is eight out of ten because it's a must-have tool in my organization to avoid any impact on the infrastructure and is always used for infrastructure monitoring. ServiceNow Security Operations should be mandatory for any organization to maintain data. My organization is a gold partner of ServiceNow.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"It is very easy to use, and its usability is great. The use cases are also very easy. The visualizations of the use cases are magnificent. You cannot find this in any other solution. From my point of view, it is great."
"The most valuable feature is the way it captures the traffic, and it contains every detail of the communication."
"The stability of the RSA NetWitness Endpoint is very good."
"This solution allows us to locate the malware in real-time."
"NetWitness Endpoint's most valuable features are its interoperability across many different operating systems and the ease of pivoting from network to endpoint via a single console."
"It's a scalable solution. We have around five to eight customers using RSA NetWitness Endpoint, and we hope to increase the number of users."
"RSA NetWitness does market analysis in a more granular form. It gives you full visibility."
"It helps our security team respond more accurately when there are threats, then we get less false positives or negatives."
"The SOAR module of ServiceNow Security Operations is the most valuable feature"
"The solution is stable."
"ServiceNow Security Operations also takes care of GRC, governance, risk and compliance, enabling it to provide risk assessment."
"The ease of use is great."
"The solution is available over the cloud and is easy to manage."
"What I found most valuable in ServiceNow Security Operations is that it's very useful for any incoming vulnerability. For example, if my team finds any vulnerability on servers such as the CA and CMDB integrated with ServiceNow Security Operations, my team can make some changes. My team can map the vulnerabilities found on the CA server, make the changes required, and resolve the vulnerabilities before the system is attacked. You can avoid vulnerability attacks through ServiceNow Security Operations, so this is the best feature of the solution. ServiceNow Security Operations is beneficial mainly for vulnerability response and engagement purposes."
"We refer to the setup and installation guide provided by ServiceNow. They have good documentation, which makes it easier to handle the process."
"The product has a very simple UI."
 

Cons

"The deployment process is complex. I don't know why, but this solution will suddenly stop working. Logs stop coming. Often, one thing or another stops working. Most of the time, one of my team members is working with troubleshooting and working with technical support. Log passing is also one of the biggest challenge."
"RSA NetWitness Network could improve on integration with non-native application integration."
"The solution is modular, for example you can buy the RSA ePack, which you buy as a module is not part of the conduit solution. They could include it and have it as an all-in-one solution."
"The threat intelligence could improve in RSA NetWitness Endpoint."
"This solution needs an upgrade in reporting. I have heard from RSA that they are working on this, but as of yet it is not available."
"I would like to see Security Orchestration and Response Automation (SOAR) integration."
"We would like to see the hunting and investigation features of this solution improved, in order to provide better visibility of issues."
"Threat detection could be better."
"The product is called SecOps, but it is not security operations in terms of SIEM solutions."
"It doesn't interact with things very well."
"We'd like customization to be easier in terms of the UI and using the dashboards."
"It is challenging for the customers to understand the processes for SecOps. It needs to be simplified."
"The threat intelligence module needs a better dashboard."
"In future releases, I would like to add a follow-up and reminder feature. For the tickets in our queue, we could set reminders. This would help us prioritize older tickets before moving on to new ones."
"The initial setup is difficult."
"It's very slow. When you click a button or update a field, it takes forever to actually react."
 

Pricing and Cost Advice

"NetWitness Endpoint is less costly than its competitors, but it offers fewer features."
"It is highly scalable. It can be bought based on your requirements."
"The pricing is not very economical. It is a quite costly product for India. One thing is that when you purchase it, you have to purchase a module separately."
"We are on a three-year contract to use RSA NetWitness Network."
"The price of the solution depends on the environment. If the environment is large then it will cost more. However, the larger the environment with more endpoints, you will receive an increased discount. If the environment is very small, then you might think it is expensive. It is always better to buy in bulk to receive a discount. The minimum number of assets is usually 500, with discounts on 1000 and 2000."
"I do not have any opinion on the pricing or licensing of the product."
"It is an expensive product."
"They can easily adjust if you have the requirements which are required. If you have a budget cut or a budget constraint, they can bend."
"This product is a good value for the money."
"It is an expensive product."
"The solution is more expensive than BMC Remedy, the other ITSM tool available in the market."
"Compared to competitor tools, ServiceNow Security Operations is more affordable"
"The product is more expensive than other solutions."
"If you're going to implement it on your own, there would be internal costs. If you're going to implement it through a contractor or consultant, you have to pay for that."
report
Use our free recommendation engine to learn which Security Orchestration Automation and Response (SOAR) solutions are best for your needs.
801,634 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Financial Services Firm
16%
Computer Software Company
14%
Government
9%
Manufacturing Company
7%
Financial Services Firm
21%
Computer Software Company
11%
Government
10%
Manufacturing Company
8%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

What is your experience regarding pricing and costs for NetWitness XDR?
The solution is expensive. I'd rate it at a one or two out of five. They need to adjust it to keep up with the competition. I cannot speak to the exact pricing of the product.
What needs improvement with NetWitness XDR?
I have no real complaints about the solution. Threat detection could be better. They need to enhance their threat intelligence feeds. We would like to have more IOCs or more trade intelligence to n...
What do you like most about ServiceNow Security Operations?
The most valuable aspect of working with ServiceNow is its meaningful and feature-rich product.
What is your experience regarding pricing and costs for ServiceNow Security Operations?
The product is more expensive than other solutions like Archer but offers more features, making the pricing justifiable.
What needs improvement with ServiceNow Security Operations?
One area for improvement for the product is the need to tailor and alter some codes for customization, which can cause issues during upgrades. It does not support customized operations.
 

Also Known As

RSA ECAT, NetWitness Network
No data available
 

Learn More

Video not available
Video not available
 

Overview

 

Sample Customers

ADP, Ameritas, Partners Healthcare
DXC Technology, Freedom Security Alliance, Prime Therapeutics, Seton Hall University, York Risk Services
Find out what your peers are saying about NetWitness NDR vs. ServiceNow Security Operations and other solutions. Updated: September 2024.
801,634 professionals have used our research since 2012.