No more typing reviews! Try our Samantha, our new voice AI agent.

NetWitness Platform vs Trellix Network Detection and Response comparison

 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

NetWitness Platform
Average Rating
7.4
Reviews Sentiment
7.4
Number of Reviews
36
Ranking in other categories
Log Management (38th), Security Information and Event Management (SIEM) (39th)
Trellix Network Detection a...
Average Rating
8.4
Reviews Sentiment
7.1
Number of Reviews
45
Ranking in other categories
Advanced Threat Protection (ATP) (17th), Network Detection and Response (NDR) (13th)
 

Mindshare comparison

NetWitness Platform and Trellix Network Detection and Response aren’t in the same category and serve different purposes. NetWitness Platform is designed for Log Management and holds a mindshare of 1.0%, up 0.3% compared to last year.
Trellix Network Detection and Response, on the other hand, focuses on Advanced Threat Protection (ATP), holds 4.1% mindshare, up 3.9% since last year.
Log Management Mindshare Distribution
ProductMindshare (%)
NetWitness Platform1.0%
Splunk Enterprise Security6.8%
Wazuh5.4%
Other86.8%
Log Management
Advanced Threat Protection (ATP) Mindshare Distribution
ProductMindshare (%)
Trellix Network Detection and Response4.1%
Palo Alto Networks WildFire7.4%
Microsoft Defender for Office 3656.7%
Other81.8%
Advanced Threat Protection (ATP)
 

Featured Reviews

reviewer2256927 - PeerSpot reviewer
Head of Information Security, Cyber Defense and IT Risk Management at HCT. at a transportation company with 201-500 employees
A solid SIEM solution that should improve technical support and online resources to be easier to use
A big problem with the product is that we don't have much professional experience in Israel installing, implementing, and integrating this product. There is not enough of a knowledge base. There is no support for this product in this country, so problems have to be resolved through global technical teams. We like to work locally because of the language, and when the product is only supported outside the country, it's a little difficult to implement and use this product. Moreover, AI is something that must be added immediately. Artificial intelligence is a part of the competitors' products, and it's not been implemented for us.
Hassan Sheikh - PeerSpot reviewer
Network & Security Lead at Net-International
Integrated sensors have improved traffic inspection and now provide resilient east-west threat control
I believe Trellix Network Detection and Response can be improved by integrating machine learning into its detection response capabilities. Additionally, incorporating failover kits integrated into the sensors could be beneficial. It would be best if Trellix Network Detection and Response sensors were converted into a next-generation firewall with built-in capabilities for routing, switching, and Layer 7 functionality, as most next-generation firewalls today include these features. While Trellix Network Detection and Response sensors are highly capable, I think it would be advantageous to include features such as Layer 7 profiles, application profile filters, web filters, IDx, IP feature sets, signature detection features, and routing and switching capabilities all in one device. While the user interface of Trellix Network Detection and Response is very good, I suggest implementing a customizable dashboard. Additionally, there should be report generation for critical attacks and high alert severities, displayed graphically on the dashboard, and providing options to extract files in Excel format for better visibility.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"I can have enterprise security, email security, next generation firewall security log, HIDS and NIDS logs, etc. all on the same dashboard. It makes it easy to pinpoint or correlate our server to this. I can find out if there is lateral movement. This is the biggest advantage of this solution."
"What we are mainly using are the RSA concentrator, RSA Decoder, Archiver, Broker, and Log Decoder."
"The software is scalable to whatever is required, and you can also put a lot of resources in the cloud."
"The solution is really scalable for the high-end power, enterprise customer."
"Thanks to this tool, we have a small SOC running in our company."
"The most valuable features are the packet inspection and the automated incident response."
"Technically speaking, this is a good product."
"It gives the ability to investigate into network traffic in the Net and the organization what we couldn't do before."
"The most valuable feature of the solution stems from how it allows users to do the investigation part. Another important part of the product that is valuable is associated with how it gives information to users in the form of a storyline."
"FireEye has created an ecosystem of products integrated with their own SIEM, which is cloud-based and integrates with network security, email security, host security and the like."
"Improved our systems and our customers' by providing better malware protection, defense against zero-day threats, and improved network security."
"The most valuable feature is MVX, which tests all of the files that have been received in an email."
"By every measure, the FireEye Network Threat Prevention Platform has exceeded our expectations."
"The server appliance is good."
"We see ROI in the sense that we don't have to react because it stops anything from hurting the network. We can stop it before we have a bigger mess to clean up."
"It allows us to be more hands off in checking on emails and networking traffic. We can set up a bunch of different alerts and have it alert us."
 

Cons

"I believe that integrating the solution with other products such as Oracle would be beneficial."
"Lots of competing products have vulnerability protection built into their products, and this solution would be improved by including that support."
"RSA NetWitness Logs and Packets can improve the threat level aspect, it is lacking compared to other solutions. Whenever any hacking activity or any other threat factor occurred they used to provide the coverages very fast when comparing RSA NetWitness Logs and Packets. I heard the other three solutions, from a discussion with my team members who had experience in other solutions, they used to say that. Whenever any issues happened across the globe RSA NetWitness Logs and Packets are a little bit slow improving those detection mechanisms."
"Technical support could be improved."
"It should have a monitoring feature. It would help us analyze the current state of attacks faster from a single platform."
"I am not happy with the RSA support. Sometimes they can be really annoying because it takes so long to get the support that you need."
"The solution is pretty complex to set up. Comparatively, I have worked on IBM QRadar and Splunk; they are much easier to set up."
"The multi-tenant capabilities are lagging compared to IBM QRadar."
"I would love to see better reporting. Because you can't export some of the reports in proper formats, it is hard to extract the data from reports."
"We'd like the potential for better scaling."
"I would love to see better reporting. Because you can't export some of the reports in proper formats, it is hard to extract the data from reports."
"FireEye Network Security should have better integration with other vendors' firewalls or proxies, such as Palo Alto and Fortinet. Files that are being submitted should happen through the API or automatically."
"A better depth of view, being able to see deeper into the management process, is what I'd like to see."
"Its documentation can be improved. The main problem that I see with FireEye is the documentation. We are an official distributor and partner of FireEye, and we have access to complete documentation about how to configure or implement this technology, but for customers, very limited documentation is available openly. This is the area in which FireEye should evolve. All documents should be easily available for everyone."
"It would be very helpful if there were better integration with other solutions from other vendors, such as Fortinet and Palo Alto."
"I heard that FireEye recently was hacked, and a lot of things were revealed."
 

Pricing and Cost Advice

"It is cheap."
"Our license is for one year."
"We are on an annual license for the use of the solution."
"There is a licensing fee and the customer can choose whether he wishes this to be subscription-based or perpetual."
"The licenses are good but the cost is very expensive."
"We have a perpetual license, so the total cost of ownership is not very expensive. It's a good investment."
"Many clients are not able to purchase the packet capability because there is a huge amount of data, and the cost depends on the number of EPS (Events per second), as well as the number of gigabytes of data per day."
"The product price was reasonable for my region and the market."
"We're partners with Cisco so we get a reasonable price. It's cheaper than Palo Alto in terms of licensing."
"FireEye is comparable to other products, such as HX, but seems expensive. It may cause us to look at other products in the market."
"When you purchase FireEye Network Security NX, will need to purchase a megabit per second package. You must know your needs from day one."
"There are some additional services that I understand the vendor provides, but our approach was to package all of the features that we were looking to use into the product."
"The pricing is fair, a little expensive, but fair. We've evaluated other products, and they're similarly priced."
"The tool is a bit pricey."
"When I compare this solution to its competitors in the market, I find that it is a little expensive."
"It's an expensive solution."
report
Use our free recommendation engine to learn which Log Management solutions are best for your needs.
896,034 professionals have used our research since 2012.
 

Comparison Review

VS
Manager, Enterprise Risk Consulting at a tech company with 1,001-5,000 employees
Feb 26, 2015
HP ArcSight vs. IBM QRadar vs. ​McAfee Nitro vs. Splunk vs. RSA Security vs. LogRhythm
We at Infosecnirvana.com have done several posts on SIEM. After the Dummies Guide on SIEM, we are following it up with a SIEM Product Comparison – 101 deck. So, here it is for your viewing pleasure. Let me know what you think by posting your comments below. The key products compared here are…
 

Top Industries

By visitors reading reviews
Financial Services Firm
11%
Comms Service Provider
10%
Construction Company
8%
Performing Arts
7%
Financial Services Firm
14%
Comms Service Provider
12%
Manufacturing Company
11%
Government
8%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business8
Midsize Enterprise7
Large Enterprise20
By reviewers
Company SizeCount
Small Business22
Midsize Enterprise8
Large Enterprise21
 

Questions from the Community

What is your experience regarding pricing and costs for NetWitness Platform?
The pricing is comparable to others, and I consider the cost to be intermediate. Specific cost details are unknown to me.
What needs improvement with NetWitness Platform?
There is currently no need for improvement in the SIEM ( /categories/security-information-and-event-management-siem ), though there could be potential enhancements by integrating with AI.
What is your primary use case for NetWitness Platform?
I use NetWitness Platform ( /products/netwitness-platform-reviews ) in the financial industry as a good product with excellent capabilities and integration with various devices.
What is your experience regarding pricing and costs for FireEye Network Security?
My experience with pricing, setup cost, and licensing for Trellix Network Detection and Response is very great.
What needs improvement with FireEye Network Security?
I would like to see in Trellix Network Detection and Response more explanation about some details of the threat, and I wish it had more actions that you can take to contain the host or move it some...
What is your primary use case for FireEye Network Security?
My main use case for Trellix Network Detection and Response is providing support for our customers, and one of our customers has Trellix, so we had to provide monitoring or specific XDR tools for t...
 

Also Known As

RSA Security Analytics
FireEye Network Security, FireEye
 

Overview

 

Sample Customers

Los Angeles World Airports, Reply
FFRDC, Finansbank, Japan Advanced Institute of Science and Technology, Investis, Kelsey-Seybold Clinic, Bank of Thailand, City of Miramar, Citizens National Bank, D-Wave Systems
Find out what your peers are saying about NetWitness Platform vs. Trellix Network Detection and Response and other solutions. Updated: September 2022.
896,034 professionals have used our research since 2012.