Try our new research platform with insights from 80,000+ expert users

NetWitness Platform vs Palo Alto Networks VM-Series comparison

 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

NetWitness Platform
Average Rating
7.4
Reviews Sentiment
7.4
Number of Reviews
36
Ranking in other categories
Log Management (35th), Security Information and Event Management (SIEM) (32nd)
Palo Alto Networks VM-Series
Average Rating
8.6
Reviews Sentiment
6.9
Number of Reviews
66
Ranking in other categories
Firewalls (12th), Advanced Threat Protection (ATP) (11th)
 

Mindshare comparison

NetWitness Platform and Palo Alto Networks VM-Series aren’t in the same category and serve different purposes. NetWitness Platform is designed for Log Management and holds a mindshare of 0.7%, up 0.3% compared to last year.
Palo Alto Networks VM-Series, on the other hand, focuses on Firewalls, holds 1.5% mindshare, up 0.7% since last year.
Log Management Market Share Distribution
ProductMarket Share (%)
NetWitness Platform0.7%
Wazuh8.3%
Splunk Enterprise Security6.9%
Other84.1%
Log Management
Firewalls Market Share Distribution
ProductMarket Share (%)
Palo Alto Networks VM-Series1.5%
Fortinet FortiGate18.7%
OPNsense10.5%
Other69.3%
Firewalls
 

Featured Reviews

MOTASHIM Al Razi - PeerSpot reviewer
CISO at One Bank Limited
It is a stable solution, but they should make the user interface easier to understand
The solution's initial setup takes work. We have to organize multiple paths and many features. The deployment process takes less than a week. But it takes a month to complete if we want to make the solution smarter by integrating it with various devices. I rate the process as a six out of ten.
AV
Cyber security consultant at L&T Technology Services
Enhance cybersecurity for large enterprises using advanced threat management
An improvement could be the integration of security intelligence with Palo Alto cloud via APIs. This would allow IOCs, domains, and hash values to be automatically entered, reducing manual entry. Integration with CSIRT across all use levels would make it easier for administrators to stay updated on the blocked entities without manual intervention.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"Setting up NetWitness is straightforward. There are multiple connectors, including standard and specialized connectors. One purpose of the connectors is the enhanced capability integrate the custom applications. NetWitness comes with E6 appliances and application images that we use for the initial configurations and for the OS stack information. From there, you can consider the correlation rules, integrate the different log sources, and easily create correlation rules and backlog reports."
"In my opinion, the solution's most valuable feature is its capacity to monitor network traffic, logs from devices within the network, and network captures. This capability extends beyond logs to include full network capturing."
"The development of use cases on the SSA console is quite user friendly. This means that the security analyst or the researcher does not have to learn another language."
"NetWitness Platform is valuable for creating rules that the solution must detect."
"Offers a good wireless feature."
"The most valuable features are its ingestion of logs and raising of alerts based on those logs."
"Incident management is its most valuable feature."
"What we are mainly using are the RSA concentrator, RSA Decoder, Archiver, Broker, and Log Decoder."
"It is reliable and the support is very good."
"In terms of security breaches, the product aids in categorizing and monitoring traffic, allowing for the identification of potentially malicisous or incorrectly formatted applications."
"I have not actually called their support line, because we have a direct contact to a senior engineer in the company for any issues that we handle with them. I will say they are very responsive, and they do give you the information you need when you need it.​"
"It is nice to have a rock solid security platform that we can count on."
"The product provides more visibility into our traffic."
"It offers robust solutions, making it valuable to my customers."
"You already can scale it if you put it in Auto Scaling groups. If you put it in a load balancer, it should already be able to scale."
"Palo Alto Networks VM-Series has everything centralized. You have the VPN solution, firewall, routing, UDR, flexibility, updates, and full visibility of your traffic."
 

Cons

"The solution should have more integration capabilities with different platforms."
"An area for improvement would be better automation and more inbuilt use cases."
"The user interface is a little bit difficult for new users and it needs to be improved."
"I'd like to see improvement in its ease of use. It's basically unusable. It's overly complex."
"Security needs improvement."
"Log aggregation is an issue with this solution because there are a huge number of alerts in a single instance."
"Sometimes, it gives me static when integrating Windows-based systems. It should produce a precise log of sorts as to where the problem is. For example, a few days ago because of the McAfee application firewall, I couldn't get access to the particular Windows machine. So, my team and I had to figure out by ourselves that there was a virus responsible for the obstacle. This solution should trigger a meaningful log or message indicating the reason the user or implementer can't get into the machine."
"I believe that integrating the solution with other products such as Oracle would be beneficial."
"When managing the firewall, it involves a Strata Cloud web browser that requires improvement to enhance deployment ease and call center efficiency."
"The user interface could use some improvement."
"Palo Alto Networks VM-Series is a complex product to work with."
"The interface is all Java-based. I would prefer an HTML5 interface."
"The solution must improve Zero Trust integration and use cases."
"The reporting part of the product is an area of concern where improvements are required."
"At the beginning of the implementation, we had some difficulties with the scripts, but Palo Alto Networks support together with a local partner finally fixed it."
"The web interface is very slow, and it needs to be faster."
 

Pricing and Cost Advice

"It is cheap."
"This is a pricey solution; it's not cheap."
"There is a licensing fee and the customer can choose whether he wishes this to be subscription-based or perpetual."
"The NetWitness Platform may be affordable only for enterprise-level customers, as it may not be within the budget of small and medium-sized businesses."
"The new pricing and licensing mechanisms are fair. I would advise always to get the full solution (i.e., not only Logs)."
"RSA NetWitness Logs and Packets do not have a subscription model, it's a one-time purchase. There is only a perpetual license."
"Our license is for one year."
"The licenses are good but the cost is very expensive."
"It is a little bit of crazy if you compare it to Vanguard, Sophos, or even Cisco. The newest version of Cisco, the Next-Generation Firewall of Cisco, is less expensive than Palo Alto. It is more comparable to Check Point."
"The license fee is slightly high."
"We used BYOL, because of the cost to own."
"We found purchasing process the product on the AWS Marketplace to be very good."
"The pricing and licensing of this product on AWS should be from $1.28/hr or $4,500.00/yr. Then, it would be a good price for the performance that it delivers."
"For what you get, it does do what it says. It is a good value for an enterprise firewall.​"
"The pricing for Palo Alto is quite high compared to FortiGate, which is more affordable. I don't have the exact figures as my manager handles that, but from my research, Palo Alto's licensing costs are significantly higher."
"When you have a client compare box against box, a lot of times Palo Alto is a bit more expensive, but its network firewalls have a very rich ratio."
report
Use our free recommendation engine to learn which Log Management solutions are best for your needs.
881,821 professionals have used our research since 2012.
 

Comparison Review

VS
Manager, Enterprise Risk Consulting at a tech company with 1,001-5,000 employees
Feb 26, 2015
HP ArcSight vs. IBM QRadar vs. ​McAfee Nitro vs. Splunk vs. RSA Security vs. LogRhythm
We at Infosecnirvana.com have done several posts on SIEM. After the Dummies Guide on SIEM, we are following it up with a SIEM Product Comparison – 101 deck. So, here it is for your viewing pleasure. Let me know what you think by posting your comments below. The key products compared here are…
 

Top Industries

By visitors reading reviews
Financial Services Firm
13%
Performing Arts
8%
Computer Software Company
8%
Manufacturing Company
7%
Computer Software Company
11%
Financial Services Firm
10%
Manufacturing Company
10%
University
6%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business8
Midsize Enterprise7
Large Enterprise20
By reviewers
Company SizeCount
Small Business29
Midsize Enterprise17
Large Enterprise24
 

Questions from the Community

What do you like most about NetWitness Platform?
The product's initial setup phase was not at all difficult.
What is your experience regarding pricing and costs for NetWitness Platform?
The pricing is comparable to others, and I consider the cost to be intermediate. Specific cost details are unknown to me.
What needs improvement with NetWitness Platform?
There is currently no need for improvement in the SIEM ( /categories/security-information-and-event-management-siem ), though there could be potential enhancements by integrating with AI.
Features comparison between Palo Alto and Fortinet firewalls
In the best tradition of these questions, Feature-wise both are quite similar, but each has things it's better at, it kind of depends what you value most. PA is good at app control, web filtering a...
How does Azure Firewall compare with Palo Alto Networks VM Series?
Both products are very stable and easily scalable. The setup of Azure Firewall is easy and very user-friendly and the overall cost is reasonable. Azure Firewall offers a solid threat awareness, can...
 

Also Known As

RSA Security Analytics
No data available
 

Overview

 

Sample Customers

Los Angeles World Airports, Reply
Warren Rogers Associates
Find out what your peers are saying about NetWitness Platform vs. Palo Alto Networks VM-Series and other solutions. Updated: September 2022.
881,821 professionals have used our research since 2012.