Try our new research platform with insights from 80,000+ expert users

NetWitness Platform vs Palo Alto Networks VM-Series comparison

 

Comparison Buyer's Guide

Executive Summary
 

Categories and Ranking

NetWitness Platform
Average Rating
7.4
Number of Reviews
36
Ranking in other categories
Log Management (25th), Security Information and Event Management (SIEM) (24th)
Palo Alto Networks VM-Series
Average Rating
8.6
Reviews Sentiment
6.8
Number of Reviews
57
Ranking in other categories
Firewalls (12th), Advanced Threat Protection (ATP) (10th)
 

Mindshare comparison

NetWitness Platform and Palo Alto Networks VM-Series aren’t in the same category and serve different purposes. NetWitness Platform is designed for Log Management and holds a mindshare of 0.4%, down 0.5% compared to last year.
Palo Alto Networks VM-Series, on the other hand, focuses on Firewalls, holds 0.7% mindshare, down 0.9% since last year.
Log Management
Firewalls
 

Featured Reviews

MdZaman - PeerSpot reviewer
Oct 22, 2021
Really scalable for enterprise customers
The solution should have more integration capabilities with different platforms. The API is nearly open and scalable, so the solution can integrate with many platforms. The solution has more than 200 log sources in the scalability to support, but this is its limit. Installation is pretty easy. However, there are a couple of modules involved, so it is not as easy as it could be. We are talking about a distributed module, not a single-module type. This is what makes things a bit complex, instead of easier. I rate it as a seven out of ten on its installation and configuration capabilities.
AshwaniTyagi - PeerSpot reviewer
Sep 16, 2024
Advanced protection and good integration capabilities with good reliability
We use Palo Alto Networks VM-Series to offer services to our customers as a managed security service provider. We provide solutions and services to our customers across the globe. For example, if I want to host a firewall in the cloud or somewhere where the physical appliance is not a possibility…

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"Setting up NetWitness is straightforward. There are multiple connectors, including standard and specialized connectors. One purpose of the connectors is the enhanced capability integrate the custom applications. NetWitness comes with E6 appliances and application images that we use for the initial configurations and for the OS stack information. From there, you can consider the correlation rules, integrate the different log sources, and easily create correlation rules and backlog reports."
"It gives the ability to investigate into network traffic in the Net and the organization what we couldn't do before."
"The product has a user-friendly interface and a valuable feature for threat intelligence integration."
"Their technical support responds quickly and are knowledgable."
"The most valuable features are the threat prediction and network forensics."
"Alerting Module: It provides real-time event processing language on all the logs/packets stream for advanced alerting, i.e., using SQL LIKE statements."
"Incident management is its most valuable feature."
"The packet capture aspect of it is a valuable feature because it is quite different from a traditional SIEM solution that only carries out investigations based on captured logs."
"In the newer version, there are 3850s, all of them are scalable. They fit better into the medium or small businesses."
"It scales linearly with load and no issues."
"The most valuable features are web control and IPS/IDS."
"The most valuable feature is the Posture Assessment."
"It is reliable and the support is very good."
"App-ID and User-ID have repeatedly shown value in securing business critical systems."
"The most valuable features are the User ID, URL filtering, and application filtering."
"Palo Alto Networks VM-Series is easy to maintain...From a security point of view, I find Palo Alto Networks VM-Series to be a better product compared to the other solutions in the market."
 

Cons

"An area for improvement would be better automation and more inbuilt use cases."
"The tool's integration capability isn't so great."
"It should have a monitoring feature. It would help us analyze the current state of attacks faster from a single platform."
"There is no support for this product in this country, so problems have to be resolved through global technical teams."
"The threat detection capability and centralizing and upgrading capability need to be improved. The threat alert capability needs to be improved as well because there is some lag time at present. They need to work on their database search too."
"Lots of competing products have vulnerability protection built into their products, and this solution would be improved by including that support."
"The product's licensing models are complex to understand. This particular area needs improvement."
"The solution should have more integration capabilities with different platforms."
"With Palo Alto Networks VM-Series, it is hard for me to manage its network configuration part."
"It can definitely improve on the performance."
"The disadvantage with Palo Alto is that they don't have a cloud-based solution that includes a secure web gateway."
"It'll help if Palo Alto Networks provided better documentation."
"Just sometimes it can be a bit sluggish navigating through pages. That is just purely because of Java.​"
"In the next release, I would like to see better integration between the endpoints and the firewalls."
"Enhancing the ease of accessing technical support would be useful."
"The solution needs to have more easily searchable details or documentation about it online, so it's easier to Google if you have queries."
 

Pricing and Cost Advice

"Our license is for one year."
"The product is expensive."
"Many clients are not able to purchase the packet capability because there is a huge amount of data, and the cost depends on the number of EPS (Events per second), as well as the number of gigabytes of data per day."
"We are on an annual license for the use of the solution."
"There is a licensing fee and the customer can choose whether he wishes this to be subscription-based or perpetual."
"The new pricing and licensing mechanisms are fair. I would advise always to get the full solution (i.e., not only Logs)."
"RSA NetWitness Logs and Packets do not have a subscription model, it's a one-time purchase. There is only a perpetual license."
"The NetWitness Platform may be affordable only for enterprise-level customers, as it may not be within the budget of small and medium-sized businesses."
"Palo Alto definitely needs to be more competitive compared to other products. The problem that I have faced is that the price of licensing is very high and not very competitive."
"The product is cheaper than the on-premise version."
"Initially, pricing was high. Later on, we were able to negotiate the pricing and get something that fits our budget."
"The product is costly but provides all essential security features. I rate the pricing a seven out of ten."
"The pricing and licensing of this product on AWS for a three-year commitment is a great deal, if you can plan that far ahead."
"I know Palo Alto is not cheap. They have been telling me, the members of the finance team, it is not a cheap solution. It is a solution whose target is that no matter how big your organization is, small, medium, or large, it is about the maturity of your security team or infrastructure team whom you want to work with."
"The price is not bad. They have a yearly renewal fee, and the pricing is exactly where we expect it to be."
"The pricing and licensing are reasonable."
report
Use our free recommendation engine to learn which Log Management solutions are best for your needs.
814,649 professionals have used our research since 2012.
 

Comparison Review

VS
Feb 26, 2015
HP ArcSight vs. IBM QRadar vs. ​McAfee Nitro vs. Splunk vs. RSA Security vs. LogRhythm
We at Infosecnirvana.com have done several posts on SIEM. After the Dummies Guide on SIEM, we are following it up with a SIEM Product Comparison – 101 deck. So, here it is for your viewing pleasure. Let me know what you think by posting your comments below. The key products compared here are…
 

Top Industries

By visitors reading reviews
Financial Services Firm
17%
Computer Software Company
17%
Government
7%
Insurance Company
6%
Computer Software Company
17%
Financial Services Firm
11%
Manufacturing Company
7%
Government
6%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

What do you like most about NetWitness Platform?
The product's initial setup phase was not at all difficult.
What is your experience regarding pricing and costs for NetWitness Platform?
The product price was reasonable for my region and the market.
What needs improvement with NetWitness Platform?
From an improvement perspective, the NetWitness Platform needs to release new features and improve in areas like log correlation. The tool needs to have easier integrations with the cloud. Building...
Features comparison between Palo Alto and Fortinet firewalls
In the best tradition of these questions, Feature-wise both are quite similar, but each has things it's better at, it kind of depends what you value most. PA is good at app control, web filtering a...
How does Azure Firewall compare with Palo Alto Networks VM Series?
Both products are very stable and easily scalable. The setup of Azure Firewall is easy and very user-friendly and the overall cost is reasonable. Azure Firewall offers a solid threat awareness, can...
 

Also Known As

RSA Security Analytics
No data available
 

Learn More

Video not available
 

Overview

 

Sample Customers

Los Angeles World Airports, Reply
Warren Rogers Associates
Find out what your peers are saying about NetWitness Platform vs. Palo Alto Networks VM-Series and other solutions. Updated: September 2022.
814,649 professionals have used our research since 2012.