No more typing reviews! Try our Samantha, our new voice AI agent.

NetWitness Platform vs Trellix Network Detection and Response comparison

 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

NetWitness Platform
Average Rating
7.4
Reviews Sentiment
7.4
Number of Reviews
36
Ranking in other categories
Log Management (37th), Security Information and Event Management (SIEM) (37th)
Trellix Network Detection a...
Average Rating
8.4
Reviews Sentiment
7.1
Number of Reviews
45
Ranking in other categories
Advanced Threat Protection (ATP) (10th), Network Detection and Response (NDR) (7th)
 

Mindshare comparison

NetWitness Platform and Trellix Network Detection and Response aren’t in the same category and serve different purposes. NetWitness Platform is designed for Log Management and holds a mindshare of 1.1%, up 0.3% compared to last year.
Trellix Network Detection and Response, on the other hand, focuses on Advanced Threat Protection (ATP), holds 4.1% mindshare, up 4.0% since last year.
Log Management Mindshare Distribution
ProductMindshare (%)
NetWitness Platform1.1%
Splunk Enterprise Security6.8%
Wazuh4.8%
Other87.3%
Log Management
Advanced Threat Protection (ATP) Mindshare Distribution
ProductMindshare (%)
Trellix Network Detection and Response4.1%
Palo Alto Networks WildFire7.3%
Microsoft Defender for Office 3656.5%
Other82.1%
Advanced Threat Protection (ATP)
 

Featured Reviews

reviewer2256927 - PeerSpot reviewer
Head of Information Security, Cyber Defense and IT Risk Management at HCT. at a transportation company with 201-500 employees
A solid SIEM solution that should improve technical support and online resources to be easier to use
A big problem with the product is that we don't have much professional experience in Israel installing, implementing, and integrating this product. There is not enough of a knowledge base. There is no support for this product in this country, so problems have to be resolved through global technical teams. We like to work locally because of the language, and when the product is only supported outside the country, it's a little difficult to implement and use this product. Moreover, AI is something that must be added immediately. Artificial intelligence is a part of the competitors' products, and it's not been implemented for us.
Hassan Sheikh - PeerSpot reviewer
Network & Security Lead at Net-International
Integrated sensors have improved traffic inspection and now provide resilient east-west threat control
I believe Trellix Network Detection and Response can be improved by integrating machine learning into its detection response capabilities. Additionally, incorporating failover kits integrated into the sensors could be beneficial. It would be best if Trellix Network Detection and Response sensors were converted into a next-generation firewall with built-in capabilities for routing, switching, and Layer 7 functionality, as most next-generation firewalls today include these features. While Trellix Network Detection and Response sensors are highly capable, I think it would be advantageous to include features such as Layer 7 profiles, application profile filters, web filters, IDx, IP feature sets, signature detection features, and routing and switching capabilities all in one device. While the user interface of Trellix Network Detection and Response is very good, I suggest implementing a customizable dashboard. Additionally, there should be report generation for critical attacks and high alert severities, displayed graphically on the dashboard, and providing options to extract files in Excel format for better visibility.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"Integration is exceedingly minimal, since its project development is much easier than that of LogRythm or IBM."
"The most valuable features are the packet decoder, log decoder, and concentrator."
"The solution is reliable."
"Their customer service is excellent, one of the best."
"Once it is deployed and you are used to it, you can do whatever you want."
"The most valuable feature is the correlation, as it can report in real-time and monitor the management."
"Alerting Module: It provides real-time event processing language on all the logs/packets stream for advanced alerting, i.e., using SQL LIKE statements."
"Prior to implementing the solution, the customers had no visibility of their assets, however, after adopting the solution, they have gained complete visibility over all their assets, including a comprehensive understanding of the network and attack symptoms."
"We wanted to cross-reference that activity with the network traffic just to be sure there was no lateral movement. With Trellix, we easily confirmed that there was no lateral network involvement and that nothing else was infected. It helped us correlate the events and feel confident in our containment."
"By every measure, the FireEye Network Threat Prevention Platform has exceeded our expectations."
"Anyone who is looking for a complete network protection solution and does not have any budget issues should definitely go for it."
"The product is very easy to configure."
"The biggest impact Trellix Network Detection and Response has had on our organization is improved visibility across our environment and better confidence during investigations, as security analysts can understand suspicious behavior more clearly instead of depending solely on isolated alerts."
"Trellix Network Detection and Response has positively impacted my organization by addressing performance issues, specifically by offloading heavy traffic inspection and SSL inspection through sensors due to the limitations of the firewall."
"The best features that Trellix Network Detection and Response offers are visibility, threat detection, and immediate response, which allows us to take action almost instantly while keeping proof through proper data capture and maintaining logs for future analysis to prevent attacks and ensure that we have the right policies and controls."
"The most valuable feature is MVX, which tests all of the files that have been received in an email."
 

Cons

"The initial setup is complex. There are other solutions that are easier to implement."
"The user interface is a little bit difficult for new users and it needs to be improved."
"The product's licensing models are complex to understand. This particular area needs improvement."
"The product continues to crash. Even with tech support help, it does not resolve itself."
"One thing to be improved in NetWitness is the capability to correlate event logs in a general sense."
"Nowadays, their support is a little subpar compared to other solutions. I rate RSA support six out of 10."
"RSA NetWitness Logs and Packets can improve the threat level aspect, it is lacking compared to other solutions. Whenever any hacking activity or any other threat factor occurred they used to provide the coverages very fast when comparing RSA NetWitness Logs and Packets. I heard the other three solutions, from a discussion with my team members who had experience in other solutions, they used to say that. Whenever any issues happened across the globe RSA NetWitness Logs and Packets are a little bit slow improving those detection mechanisms."
"The threat detection capability and centralizing and upgrading capability need to be improved. The threat alert capability needs to be improved as well because there is some lag time at present. They need to work on their database search too."
"If you want to search the hashes in the environment, you need to put in IOCs one by one, making it a very hectic job."
"FireEye’s main feature is its sandboxing or threat emulation capabilities to detect malware with extra add-ons such as signature-based IPS or endpoint protection, but these features are lacking compared to most IPS or endpoint vendors."
"It is an expensive solution."
"A lot of false positives."
"As far as future inclusions, it would be useful to display more threat intelligence, such as the actual area of the threat and the origin of the web crawling (Tor and Dark Web)."
"Technical packaging could be improved."
"The world is currently shifting to AI, but FIreEye is not following suit."
"Stability issues manifested in terms of throughput maximization."
 

Pricing and Cost Advice

"The NetWitness Platform may be affordable only for enterprise-level customers, as it may not be within the budget of small and medium-sized businesses."
"The product is expensive."
"The new pricing and licensing mechanisms are fair. I would advise always to get the full solution (i.e., not only Logs)."
"We have yearly licensing costs. The license fee can be based on the volume of EPS. Some organizations may have, as a gentlemanly gesture, 10,000 EPS and get a 3,000 EPS license but actually use 5,000 EPS."
"Compared to the competition, the is price is not that high."
"We are on an annual license for the use of the solution."
"Our license is for one year."
"It is cheap."
"FireEye is comparable to other products, such as HX, but seems expensive. It may cause us to look at other products in the market."
"When you purchase FireEye Network Security NX, will need to purchase a megabit per second package. You must know your needs from day one."
"We're partners with Cisco so we get a reasonable price. It's cheaper than Palo Alto in terms of licensing."
"Pricing and licensing are reasonable compared to competitors."
"When I compare this solution to its competitors in the market, I find that it is a little expensive."
"There are some additional services that I understand the vendor provides, but our approach was to package all of the features that we were looking to use into the product."
"Because of what the FireEye product does, it has significantly decreased our mean time in being able to identify and detect malicious threats. The company that I work with is a very mature organization, and we have seen the meantime to analysis decrease by at least tenfold."
"The pricing is fair, a little expensive, but fair. We've evaluated other products, and they're similarly priced."
report
Use our free recommendation engine to learn which Log Management solutions are best for your needs.
896,942 professionals have used our research since 2012.
 

Comparison Review

VS
Manager, Enterprise Risk Consulting at a tech company with 1,001-5,000 employees
Feb 26, 2015
HP ArcSight vs. IBM QRadar vs. ​McAfee Nitro vs. Splunk vs. RSA Security vs. LogRhythm
We at Infosecnirvana.com have done several posts on SIEM. After the Dummies Guide on SIEM, we are following it up with a SIEM Product Comparison – 101 deck. So, here it is for your viewing pleasure. Let me know what you think by posting your comments below. The key products compared here are…
 

Top Industries

By visitors reading reviews
Financial Services Firm
11%
Comms Service Provider
10%
Construction Company
8%
Performing Arts
7%
Financial Services Firm
14%
Comms Service Provider
12%
Manufacturing Company
11%
Government
8%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business8
Midsize Enterprise7
Large Enterprise20
By reviewers
Company SizeCount
Small Business22
Midsize Enterprise8
Large Enterprise21
 

Questions from the Community

What is your experience regarding pricing and costs for NetWitness Platform?
The pricing is comparable to others, and I consider the cost to be intermediate. Specific cost details are unknown to me.
What needs improvement with NetWitness Platform?
There is currently no need for improvement in the SIEM ( /categories/security-information-and-event-management-siem ), though there could be potential enhancements by integrating with AI.
What is your primary use case for NetWitness Platform?
I use NetWitness Platform ( /products/netwitness-platform-reviews ) in the financial industry as a good product with excellent capabilities and integration with various devices.
What is your experience regarding pricing and costs for FireEye Network Security?
The price for Trellix Network Detection and Response is reasonable. The pricing is reasonable, and I do not need to bargain with Trellix or customers.
What needs improvement with FireEye Network Security?
The negative aspect is support. When I need urgent support from Trellix, there is a response after four hours or three hours, which is my main concern regarding the negative point of Trellix Networ...
What is your primary use case for FireEye Network Security?
I am working with Trellix Network Detection and Response as part of my overall experience with these products today. Trellix Network Detection and Response is used for threat and response use cases...
 

Also Known As

RSA Security Analytics
FireEye Network Security, FireEye
 

Overview

 

Sample Customers

Los Angeles World Airports, Reply
FFRDC, Finansbank, Japan Advanced Institute of Science and Technology, Investis, Kelsey-Seybold Clinic, Bank of Thailand, City of Miramar, Citizens National Bank, D-Wave Systems
Find out what your peers are saying about NetWitness Platform vs. Trellix Network Detection and Response and other solutions. Updated: September 2022.
896,942 professionals have used our research since 2012.