No more typing reviews! Try our Samantha, our new voice AI agent.
Infosec Manager at a energy/utilities company with 1,001-5,000 employees
Real User
Jul 9, 2019
Enables us to have visibility but it needs improvement when it comes to speed
Pros and Cons
  • "Stability is the most valuable feature we have seen in this solution."
  • "Time to value is very good for Stealthwatch."
  • "Stealthwatch needs improvement when it comes to speed."
  • "Stealthwatch needs improvement when it comes to speed."

What is our primary use case?

Our main reason for using Stealthwatch is it gives us visibility.

What is most valuable?

Stability is the most valuable feature we have seen in this solution.

What needs improvement?

Stealthwatch needs improvement when it comes to speed.

What do I think about the stability of the solution?

The solution's stability is good.

Buyer's Guide
Cisco Secure Network Analytics
May 2026
Learn what your peers think about Cisco Secure Network Analytics. Get advice and tips from experienced pros sharing their opinions. Updated: May 2026.
896,692 professionals have used our research since 2012.

What do I think about the scalability of the solution?

I think this solution is okay with scale.

How are customer service and support?

I think their technical support is great.

How was the initial setup?

The initial setup was straightforward.

What was our ROI?

Time to value is very good for Stealthwatch.

What other advice do I have?

I would rate Stealthwatch as an eight or nine out of ten.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
SrNetworab58 - PeerSpot reviewer
Sr. Network Engineer at a tech services company with 10,001+ employees
Real User
Jul 9, 2019
We have seen improved network visibility of our organization but the setup is complex
Pros and Cons
  • "Cisco Stealthwatch provides the solutions analytics and threat detection capabilities that I am looking for. It has also improved the network visibility of our organization."
  • "Cisco Stealthwatch provides the solutions analytics and threat detection capabilities that I am looking for, and it has also improved the network visibility of our organization."
  • "The configuration of the solution was quite complex."
  • "I don't really think we really save time while using this solution."

What is our primary use case?

Our primary use case for Cisco Stealthwatch is to ensure net flow.

How has it helped my organization?

Cisco Stealthwatch provides the solutions analytics and threat detection capabilities that I am looking for. It has also improved the network visibility of our organization. 

What is most valuable?

The most valuable feature of this solution is that it give us insight into what's happening in our network. 

What needs improvement?

I don't really think we really save time while using this solution.

What do I think about the stability of the solution?

Cisco Stealthwatch is quite stable.

What do I think about the scalability of the solution?

It all depends on the platform you are using, but I think it is pretty scalable.

How was the initial setup?

The configuration of the solution was quite complex so I won't say that it is straightforward to set everything up.

What about the implementation team?

We used a vendor, Cisco, for implementation. 

What was our ROI?

I believe ROI will take around a year.

Which other solutions did I evaluate?

We also look at Red Hat.

What other advice do I have?

I will rate this solution a five or six out of ten because I do believe it is beneficial to our organization. I will recommend others to use endpoint management.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Buyer's Guide
Cisco Secure Network Analytics
May 2026
Learn what your peers think about Cisco Secure Network Analytics. Get advice and tips from experienced pros sharing their opinions. Updated: May 2026.
896,692 professionals have used our research since 2012.
ServiceE8f27 - PeerSpot reviewer
Service Engineer at a tech company with 10,001+ employees
Real User
Jul 9, 2019
Our protection rate has doubled and we can monitor our bandwidth or any other issues on our networks
Pros and Cons
  • "Using this solution has helped us to detect and identify viruses or malicious activity in the network early on."
  • "Using this solution has helped us to detect and identify viruses or malicious activity in the network early on."
  • "We haven't seen ROI."
  • "We haven't seen ROI."

What is our primary use case?

We mainly use Cisco Stealthwatch in our organization for bandwidth monitoring and other issues we experience on our networks. When someone reports an issue, this solution helps us to determine what's going on in the network by checking the cell blocks and see if there are any issues.

How has it helped my organization?

Using this solution has helped us to detect and identify viruses or malicious activity in the network early on. It has definitely given us more insight because it's a lot easier to check Stealthwatch's logs than to log into a router and do a bunch of show commands. I would say that it has at least doubled our protection rate. 

Since we started using this solution, we've been saving time, money and administration work. It is now much easier to log into Stealthwatch and see what I want to see rather than logging into a router and checking everything out. The administration is also much less because everything's right there for me.

What do I think about the stability of the solution?

I haven't experienced any problems or downtime with Cisco Stealthwatch, so the stability is really good.

What do I think about the scalability of the solution?

The scalability of this solution is good. We don't have a very large network that we use it on. I support only around 200 routers or so. But for what we use it for, it is scalable.

How are customer service and technical support?

I never had to use technical support before.

How was the initial setup?

The initial setup was straightforward. We simply followed the instructions on how to use it, and so far everything is working great. 

What was our ROI?

We haven't seen ROI.

What other advice do I have?

I will never rate a product ten, so my rating for this solution is eight out of ten. I highly recommend this solution.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
reviewer1122741 - PeerSpot reviewer
Network Engineer at a university with 10,001+ employees
Real User
Jul 9, 2019
Enables us to detect and remediate threats much faster
Pros and Cons
  • "The most valuable feature of this solution is the way the net flow is being merged together in a single pane. That's been extremely useful for us, because can see what's going on with traffic in one single place."
  • "I believe this solution has saved our organization a lot of time, money, and administrative work."
  • "We are continuing down the road of ACI and ISE with Cisco, so we would like to see the continuation of Stealthwatch integrating into ISE for exchange of information, and also, more into the ACI environment too."
  • "We are continuing down the road of ACI and ISE with Cisco, so we would like to see the continuation of Stealthwatch integrating into ISE for exchange of information, and also, more into the ACI environment too."

What is our primary use case?

For our organization, Cisco Stealthwatch is more of a confirmation of what is happening on our network, or compliance. And in addition to that, it helps us to troubleshoot issues. We get to see where traffic is flowing and it helps us figure out problems.

How has it helped my organization?

Cisco Stealthwatch helps us in finding unknown traffic, allowing us to audit the network and make sure things that are happening that we are expecting to happen. 

I am a little versed about the solution's analytic and threat detection capabilities, even though it is pretty good. I know that we use it to validate that there's no east/west traffic. So that's been beneficial to us because we have things in place preventing that, and it's our way of proving it has actually happened. We haven't started using it for cloud protection or any analysis yet.
This solution has definitely also reduced our incident response time because we had no visibility before. We can detect and remediate threats much faster now. 

What is most valuable?

The most valuable feature of this solution is the way the net flow is being merged together in a single pane. That's been extremely useful for us because we can see what's going on with traffic in one single place.
I also believe the solution has increased our organization's threat protection rate. The actual threat reports are run by our Infosec security person, but we are actually using this solution for that too. We're having reports generated so that our network engineering doesn't have to do the review. That team is responsible for reviewing reports and then we work with them to locate and do the next steps.

What needs improvement?

We are continuing down the road of ACI and ISE with Cisco, so we would like to see the continuation of Stealthwatch integrating into ISE for exchange of information, and also, more into the ACI environment too.

What do I think about the stability of the solution?

The solution is very stable and we haven't had any crashes yet.

What do I think about the scalability of the solution?

Based on what we've used it so far, it looks like it's scaling. We're growing and it's growing with us, so it's doing what we need it to do.

How are customer service and technical support?

I do know we have used the support before and it was good enough to get our problems fixed.

Which solution did I use previously and why did I switch?

We switched to Cisco Stealthwatch for operational reasons. The solution we used before was very clunky, so it was clear that we needed a better solution. So we started looking around and this solution came to the top quickly.

How was the initial setup?

The initial setup was pretty straightforward and sufficient. It's good.

What other advice do I have?

I believe this solution has saved our organization a lot of time, money, and administrative work. It allows us to see what's going on as far as traffic flows in a single, very short period. That is the biggest value to us on the networking side. The security team uses the implications of that for auditing and clearing out, whether we have good or bad traffic going on. 

Operationally, using it as a tool, it can definitely be rated up there at a nine out of ten. It's very good, easy to use, I can get into it and find out what I want.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Network Operations Manager at a tech company with 10,001+ employees
Real User
Jul 9, 2019
Improved network visibility has saved us money and facilitates executive reporting
Pros and Cons
  • "This product alleviates the day-to-day headaches for us, in regards to metrics."
  • "The ROI was immediate for us, in regard to how we implemented it."
  • "The reporting of day-to-day metrics still has room for improvement."
  • "The reporting of day-to-day metrics still has room for improvement."

What is our primary use case?

Our primary use for this solution is to provide operational metrics. In terms of the analytics and threat detection capabilities, it basically cures our day-to-day for everything that we do. It helps us out tremendously.

How has it helped my organization?

This product alleviates the day-to-day headaches for us, in regards to metrics. In terms of network visibility, the way we were looking at it before was kind of archaic. This solution has definitely opened up the metrics, as far as reporting is concerned.

This savings brought about by implementing this solution has allowed us to cut one position.

It has increased our threat detection rate and it has reduced our incident response time by ten to fifteen percent. 

What is most valuable?

The most valuable feature of this solution is the reporting, in terms of operational metrics and what I can show to the execs.

What needs improvement?

There is room for this solution to mature because there are still things that we want to see.

The reporting of day-to-day metrics still has room for improvement.

What do I think about the stability of the solution?

This solution is very stable.

What do I think about the scalability of the solution?

We're kind of immature, right now, in our implementation, but I see it growing.

How are customer service and technical support?

We have not used technical support at this point.

Which solution did I use previously and why did I switch?

We were archaic in terms of reporting.

How was the initial setup?

I wouldn't say that the initial setup was complex. It took us approximately one week, which included two days of off-screening and two days of prep.

It was more a case of red tape on our end in regards to getting it into production than anything else. It wasn't complicated at all.

What about the implementation team?

We handled the deployment in-house.

What was our ROI?

The ROI was immediate for us, in regard to how we implemented it. The implementation was super quick, and we saw returns right from the get-go.

What's my experience with pricing, setup cost, and licensing?

The pricing for this solution is good.

Which other solutions did I evaluate?

We evaluated Darktrace, but I didn’t have a good, happy experience with their Account Manager.

What other advice do I have?

My advice to anybody researching this type of solution is to put Cisco Stealthwatch on the shortlist. It is not complicated to install. The feature set is good, as well as the pricing.

The biggest lesson for us is that we needed improvement, compared to what we had before. We ran around naked for the previous four years that I have been with the company. We made a good decision.

This is a good product, but there are still things that we would like to see.

I would rate this solution a nine out of ten.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Manager at Indiana University Health
Real User
Jul 8, 2019
Increased our threat detection rate but the reporting needs improvement
Pros and Cons
  • "Stealthwatch has greatly improved our network visibility, in terms of bandwidth, malware, and PCI violations."
  • "Stealthwatch has greatly improved our network visibility, in terms of bandwidth, malware, and PCI violations."
  • "I would like to see some improvement when it comes to reporting."
  • "The licensing costs are outrageous, but Stealthwatch has a good time to value."

What is our primary use case?

We use Stealthwatch mainly for security.

How has it helped my organization?

Stealthwatch has greatly improved our network visibility, in terms of bandwidth, malware, and PCI violations.

It has increased our threat detection rate, by around 100%. Stealthwatch has also reduced the time to detect and remediate threats, as well as saves us time. We're using it for bandwidth detection, so that's helped. In addition, we use the solution's encrypted traffic analytics and cognitive analytics.

What is most valuable?

The single most valuable feature we get out of Stealthwatch is visibility. Also, analytics and threat protection capabilities are good, so far.

What needs improvement?

I would like to see some improvement when it comes to reporting.

What do I think about the stability of the solution?

The stability of the solution is fair.

What do I think about the scalability of the solution?

Stealthwatch has a good level of scalability.

How are customer service and technical support?

I would consider their technical support as "fair."

Which solution did I use previously and why did I switch?

We were using SolarWinds and we are still using SolarWinds, so we use both.

How was the initial setup?

The initial setup was complex, especially as it came to configurations.

What about the implementation team?

We used an integrator for deployment. We had a pretty good experience with them.

What's my experience with pricing, setup cost, and licensing?

The licensing costs are outrageous, but Stealthwatch has a good time to value.

What other advice do I have?

You've got to know what you're looking for. Tuning is really key. Have a plan before you implement on what you're going to use it for.

I would rate Stealthwatch as seven out of ten. It's easy to use.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
reviewer1122849 - PeerSpot reviewer
Manager, Network Engineering & Telecommunications at a healthcare company with 1,001-5,000 employees
Real User
Jul 8, 2019
Enables us to detects threats early on, ensuring that our network stays secure
Pros and Cons
  • "The solution reduces the amount of time it takes to detect and remediate threats."
  • "This solution enables us to find them and shut them down, and it has reduced our incident response time because we can now narrow down where incidents are happening, so it is very helpful for our organization."
  • "The initial setup was straightforward but required a lot of data entry, to begin with building out the server types and network types."
  • "The initial setup was straightforward but required a lot of data entry, to begin with building out the server types and network types."

What is our primary use case?

We use Cisco Stealthwatch mostly for network visibility and security. I believe the solution reduces false-positives by flagging it as potential threats.

How has it helped my organization?

In terms of how this solution has affected network visibility, we're finding devices that junior network engineers, people who don't want to wait for proper channels, have added to the network. This solution enables us to find them and shut them down. 

It has reduced our incident response time. We can now narrow down where incidents are happening, so it very helpful for our organization.

What is most valuable?

The features I find most valuable is the deep level of knowledge that we get on every device as well as what other devices it's talking to. 

Analytics and threat detection capabilities are a little overwhelming. I would say it's about average. 

The solution reduces the amount of time it takes to detect and remediate threats.

For how long have I used the solution?

We've been using this solution for around a year now.

What do I think about the stability of the solution?

So far we haven't had any issues with the stability of the solution. We haven't gone through a major upgrade cycle yet.

What do I think about the scalability of the solution?

Our initial deployment was built out to the right size for our organization.

How are customer service and technical support?

There hasn't been any need to ask for technical support since our initial deployment, where we used a reseller. 

How was the initial setup?

The initial setup was straightforward but required a lot of data entry, to begin with building out the server types and network types. 

What about the implementation team?

We used a reseller for the deployment, CDW.

Which other solutions did I evaluate?

We evaluated Plixer, but the fact that Stealthwatch was Cisco integrated, sold it for us.

What other advice do I have?

My advice would be to really look at how many traffic rows you're generating on your network when you decide to do your deployment. Personally, it is too early to know if there is room for improvement, but I will rate this solution an eight out of ten.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
NetworkEd59a - PeerSpot reviewer
Network Engineer at a tech services company
Real User
Jul 8, 2019
Offers better network visibility and has reduced incident response time
Pros and Cons
  • "I believe this solution has reduced our incident response time."
  • "It has improved my organization's network visibility from zero because before we had installed this solution, we weren't doing anything to protect us from threats."
  • "I would like to see it better organized when I'm looking at it."
  • "I would like to see it better organized when I'm looking at it, so I would prefer it to be more clean and structured, making it easier to use."

What is our primary use case?

The primary use case for Cisco Stealthwatch is for us to sell it. 

How has it helped my organization?

It has improved my organization's network visibility from zero because before we had installed this solution, we weren't doing anything to protect us from threats. I believe this solution has reduced our incident response time. 

What is most valuable?

The features I find most valuable about Cisco Stealthwatch its integration with the pxGrid and all of our other devices that are tied in with pxGrid, so they can communicate with each other and be able to dynamically change, quarantine a suspicious device, or do whatever necessary in case of a malware attack or similar problem.

What needs improvement?

Considering all the data on the network, I believe that the analytics of Cisco Stealthwatch are pretty decent. I would like to see it better organized when I'm looking at it. If I hand it to another NOC engineer, they may not know what they're looking at, so I would prefer it to be more clean and structured, making it easier to use.

For how long have I used the solution?

We are currently also using AMP and a few other Cisco products to assist us with threat protection and it's only been running for a couple of months.

What do I think about the stability of the solution?

This solution is very stable.

What do I think about the scalability of the solution?

I believe there isn't much to scale for it and I think it all depends on how many nodes you're running in the environment. I will say the scalability is fairly decent.

How are customer service and technical support?

I haven't had to use technical support yet. I've only read through the pages of documentation.

How was the initial setup?

The initial setup was a little complex since I haven't set it up before. 

What was our ROI?

It is hard to say yet, but at least we can tell customers that we've detected a threat, and it can be stopped in time.

What's my experience with pricing, setup cost, and licensing?

For our organization, it is cheap, but for other customers, it may be fairly expensive. 
As we are resellers of Cisco Stealthwatch, we hope to save time, money, and administrative costs once we start selling more of these solutions.

Which other solutions did I evaluate?

I am responsible for the security of our organization's devices, so I did look at other options. Since this solution ties into other products, I wanted to use Duo Security and tie that together with StealthWatch.

What other advice do I have?

I will rate this solution a seven and a half or eight out of ten. This is mostly due to our exposure and having customers relying upon us to only look at it, as well as the layout. 

My advice to others would be to go for it, play around with it and see what you like about it. If you don't like it, move on to something else, but at least try it first.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Buyer's Guide
Download our free Cisco Secure Network Analytics Report and get advice and tips from experienced pros sharing their opinions.
Updated: May 2026
Buyer's Guide
Download our free Cisco Secure Network Analytics Report and get advice and tips from experienced pros sharing their opinions.