Top 8 Network Traffic Analysis (NTA) Tools
DarktraceAuvikVectra AICisco StealthwatchArista NDRSolarWinds NetFlow Traffic AnalyzerExtraHop Reveal(x)Corelight
Popular Comparisons We are able to detect a lot of things, actually, and see what is happening in our network.
The active threat dashboard is the most valuable feature of this solution.
Popular Comparisons One of the most valuable features is the network overview charts and seeing how things are connected in real time. The overall intuitiveness of the network visualization is good. Its design works for us.
Popular Comparisons It keeps up with the network traffic, which is a good thing. It provides more context to plain alerts compared to using an older system. So, it helps an analyst reduce the information overload.
Popular Comparisons If you are using Darktrace or NAC solutions you can integrate Stealthwatch.
StealthWatch lets me see the ports running in and out and the country. It has excellent reporting, telemetry, and artificial intelligence features. With the telemetry, I can set thresholds to detect sudden changes and the alarms go through the PLC parts. I can see all the ports running on that trunk.
Popular Comparisons When I create a workbench query in Awake to do threat hunting, it's much easier to query. You get a dictionary popup immediately when you try to type a new query. It says, "You want to search for a device?" Then you type in "D-E," and it gives you a list of commands, like device, data set behavior, etc. That gives you the ability to build your own query.
Popular Comparisons What the network team found most valuable in SolarWinds NetFlow Traffic Analyzer is that it helps them to troubleshoot or analyze the issue. For example, traffic that comes from our location: India, goes to the US, so for the network team to analyze where the traffic comes from and where it is directed, and whether the packets are being dropped, they use SolarWinds NetFlow Traffic Analyzer. The network team also likes that through the solution, they can analyze the complete traffic utilization and how they're going to use it. SolarWinds NetFlow Traffic Analyzer is user-friendly. The team finds it comfortable to use.
Popular Comparisons We had useful information within the hour of deployment. The ability to trace back for historical analysis, as well as the behavioral analysis done with the security information, puts the user in a position to make an informed decision to mitigate the performance or security incidents. Regarding the security incidents, Reveal (x) is able to create incident cards that guide your teams through the incidents and gives you the option to delve into the transaction detail to potentially view payloads as well.
Popular Comparisons Corelight is easy to use.
The most valuable feature is the embedded IDS from Suricata.
Buyer's Guide
Network Traffic Analysis (NTA)
June 2022

Find out what your peers are saying about Darktrace, Auvik, Vectra AI and others in Network Traffic Analysis (NTA). Updated: June 2022.
611,060 professionals have used our research since 2012.
Use our free recommendation engine to learn which Network Traffic Analysis (NTA) solutions are best for your needs.
611,060 professionals have used our research since 2012.
See all 23 solutions in Network Traffic Analysis (NTA)
Advice From The Community
Read answers to top Network Traffic Analysis (NTA) questions. 611,060 professionals have gotten help from our community of experts.Network Traffic Analysis (NTA) Topics
NTA vs. NDR
Noticeably absent from the term “Network Traffic Analysis” is the word “response.” Network-based solutions should be able to not only investigate and detect threats, but also respond rapidly and effectively. There has been a recent shift in terminology to refer to NDR, or “network detection & response,” which uses NTA but then goes one step beyond, with automated threat response and threat-hunting, using intelligent integration with firewalls, NAC, SOAR, or EDR platforms.
Benefits of Network Traffic Analysis
Benefits of NTA include:
-
Broad Visibility: NTA tools can monitor and analyze a broad range of communication types, including traditional TCP/IP-style packets, traffic from (or within) cloud workloads, serverless computing instances, and API calls to SaaS apps.
-
Encrypted Traffic Analysis: Most (more than 70% of) web traffic is encrypted. NTA products offer an accessible method for decrypting network traffic that won’t disrupt data privacy implications. They are able to do this by analyzing the data without actually looking at it.
-
Comprehensive Baseline: Modern IT environments are constantly changing. NTA tools track behaviors that are unique to a particular entity or to a small number of entities in comparison to the rest of the entities in the environment. As behaviors change, their machine learning baselines are able to evolve in real time. Baselines are even more comprehensive now, due to entity-tracking capabilities, which allow them to understand not only traffic patterns but source and destination entities as well. (For example, normal workstation activity would not be normal activity for a camera.)
-
Entity Tracking: NTA solutions allow you to track and profile every entity on a network - from devices to users to applications and destinations. Behaviors and relationships are then attributed to each of these entities, which is much more valuable than just a list of IP addresses.
- Detection and Response: Because behaviors are attributed to specific entities, there is plenty of context for detection and response workflows. This means security professionals no longer need Instead of having to sift through multiple data sources, security professionals can quickly detect anomalies, track them down, and react accordingly.
What to Look for in an NTA Solution
There are two basic kinds of NTA tools: flow-based tools and DPI (deep packet inspection) tools. Within these, there will be options for historical data storage, software agents, and intrusion detection systems.
Consider the following things when deciding what NTA solution is right for you:
1. Availability of flow-enabled devices. Not all devices are capable of generating the kind of flows required by NTA tools. In contrast, DPI tools accept raw traffic that is vendor independent and found on every network through any managed switch. Network routers and switches don’t require any kinds of special modules or support.
2. The data source: Packet data and flow data come from different sources. Not all NTA tools can collect both. So decide on your priorities before deciding. And then be strategic in choosing what to monitor. Don’t take on too many sources too quickly.
3. Historical data vs. real-time. While historical data can be critical to analyzing past events, not all NTA tools retain this data over time. Have a clear idea of which kind of data is most important to you.
4. Is the software agent-based or agent-free?
5. Full packet capture, complexity, and cost. When looking at DPI tools, consider the cost and expertise required for those that capture and retain all packets versus one that extracts only the critical details and metadata.
Buyer's Guide
Network Traffic Analysis (NTA)
June 2022

Find out what your peers are saying about Darktrace, Auvik, Vectra AI and others in Network Traffic Analysis (NTA). Updated: June 2022.
611,060 professionals have used our research since 2012.