Our primary use is to monitor our network, especially our remote branches.
Network Manager at a financial services firm with 1,001-5,000 employees
Decreased troubleshooting steps to resolve issues and saves us time, money, and administrative work
Pros and Cons
- "The most valuable feature we got out of Stealthwatch is to be able to, while troubleshooting, go deep into one of our interfaces and verify what the bandwidth is and if there's any activity there that's causing problems."
- "The overall visibility into the actual device itself would be helpful. I don't just want support-specific data, but also to be able to see information such as CPU and other internal components or usage of the devices."
What is our primary use case?
How has it helped my organization?
Stealthwatch has decreased our troubleshooting steps and also cut down on the amount of time it takes us to resolve an issue.
We're able to map out our environment using Stealthwatch and we can see where our data is going, throughout our network.
Stealthwatch reduced our incident response rate, as well as the amount of time it takes to detect and remediate threats by about 25%.
This solution saves us time, money, and administrative work.
What is most valuable?
The most valuable feature we got out of Stealthwatch is to be able to, while troubleshooting, go deep into one of our interfaces and verify what the bandwidth is and if there's any activity there that's causing problems.
In terms of their analytics, we use the stats that we get from the tool itself to see that we're using a high utilization of the tool. As far as troubleshooting, it helps us to analyze some of the effects that our customers are seeing.
What needs improvement?
The overall visibility into the actual device itself would be helpful. I don't just want support-specific data, but also to be able to see information such as CPU and other internal components or usage of the devices.
Buyer's Guide
Cisco Secure Network Analytics
June 2025

Learn what your peers think about Cisco Secure Network Analytics. Get advice and tips from experienced pros sharing their opinions. Updated: June 2025.
856,873 professionals have used our research since 2012.
What do I think about the stability of the solution?
The solution's very stable. Even through the upgrades after Cisco's acquisition, it has proved to be very stable.
What do I think about the scalability of the solution?
It scales very well.
How are customer service and support?
We haven't had to use it much. When we have, it's been similar to most Cisco technical support, which is very knowledgeable and helpful.
Which solution did I use previously and why did I switch?
We previously used SolarWinds. The version of SolarWinds that we were using didn't give us the visibility that we needed, so we switched to Stealthwatch.
How was the initial setup?
The initial setup was straightforward.
What was our ROI?
We have seen a return on investment, from the fact that we now take less time to resolve an issue because we have Stealthwatch. We can capture some data in real time, or we can actually go back in the history base if we have to, to see where the issues may have started, and we also have baselines.
Their time to value is very good. We've upgraded and we just relicensed, so this is definitely a product that we use.
What's my experience with pricing, setup cost, and licensing?
The yearly licensing cost is about $50,000.
Which other solutions did I evaluate?
We evaluated SolarWinds, WhatsUp Gold, and a couple of others that I can't think of right now.
What other advice do I have?
My biggest lesson learned was how easy it is to use and to what extent it decreased our troubleshooting time. My advice is to buy Stealthwatch.
I would probably rate this as a nine out of ten. It gives us most of what we need. The one thing that's missing is probably being able to view a little deeper into the devices themselves, not just the port but the actual health of the devices.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.

Infosec Manager at a energy/utilities company with 1,001-5,000 employees
Enables us to have visibility but it needs improvement when it comes to speed
Pros and Cons
- "Stability is the most valuable feature we have seen in this solution."
- "Stealthwatch needs improvement when it comes to speed."
What is our primary use case?
Our main reason for using Stealthwatch is it gives us visibility.
What is most valuable?
Stability is the most valuable feature we have seen in this solution.
What needs improvement?
Stealthwatch needs improvement when it comes to speed.
What do I think about the stability of the solution?
The solution's stability is good.
What do I think about the scalability of the solution?
I think this solution is okay with scale.
How are customer service and technical support?
I think their technical support is great.
How was the initial setup?
The initial setup was straightforward.
What was our ROI?
Time to value is very good for Stealthwatch.
What other advice do I have?
I would rate Stealthwatch as an eight or nine out of ten.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Buyer's Guide
Cisco Secure Network Analytics
June 2025

Learn what your peers think about Cisco Secure Network Analytics. Get advice and tips from experienced pros sharing their opinions. Updated: June 2025.
856,873 professionals have used our research since 2012.
Sr. Network Engineer at a tech services company with 10,001+ employees
We have seen improved network visibility of our organization but the setup is complex
Pros and Cons
- "Cisco Stealthwatch provides the solutions analytics and threat detection capabilities that I am looking for. It has also improved the network visibility of our organization."
- "The configuration of the solution was quite complex."
What is our primary use case?
Our primary use case for Cisco Stealthwatch is to ensure net flow.
How has it helped my organization?
Cisco Stealthwatch provides the solutions analytics and threat detection capabilities that I am looking for. It has also improved the network visibility of our organization.
What is most valuable?
The most valuable feature of this solution is that it give us insight into what's happening in our network.
What needs improvement?
I don't really think we really save time while using this solution.
What do I think about the stability of the solution?
Cisco Stealthwatch is quite stable.
What do I think about the scalability of the solution?
It all depends on the platform you are using, but I think it is pretty scalable.
How was the initial setup?
The configuration of the solution was quite complex so I won't say that it is straightforward to set everything up.
What about the implementation team?
We used a vendor, Cisco, for implementation.
What was our ROI?
I believe ROI will take around a year.
Which other solutions did I evaluate?
We also look at Red Hat.
What other advice do I have?
I will rate this solution a five or six out of ten because I do believe it is beneficial to our organization. I will recommend others to use endpoint management.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Service Engineer at a tech company with 10,001+ employees
Our protection rate has doubled and we can monitor our bandwidth or any other issues on our networks
Pros and Cons
- "Using this solution has helped us to detect and identify viruses or malicious activity in the network early on."
- "We haven't seen ROI."
What is our primary use case?
We mainly use Cisco Stealthwatch in our organization for bandwidth monitoring and other issues we experience on our networks. When someone reports an issue, this solution helps us to determine what's going on in the network by checking the cell blocks and see if there are any issues.
How has it helped my organization?
Using this solution has helped us to detect and identify viruses or malicious activity in the network early on. It has definitely given us more insight because it's a lot easier to check Stealthwatch's logs than to log into a router and do a bunch of show commands. I would say that it has at least doubled our protection rate.
Since we started using this solution, we've been saving time, money and administration work. It is now much easier to log into Stealthwatch and see what I want to see rather than logging into a router and checking everything out. The administration is also much less because everything's right there for me.
What do I think about the stability of the solution?
I haven't experienced any problems or downtime with Cisco Stealthwatch, so the stability is really good.
What do I think about the scalability of the solution?
The scalability of this solution is good. We don't have a very large network that we use it on. I support only around 200 routers or so. But for what we use it for, it is scalable.
How are customer service and technical support?
I never had to use technical support before.
How was the initial setup?
The initial setup was straightforward. We simply followed the instructions on how to use it, and so far everything is working great.
What was our ROI?
We haven't seen ROI.
What other advice do I have?
I will never rate a product ten, so my rating for this solution is eight out of ten. I highly recommend this solution.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Network Engineer at a university with 10,001+ employees
Enables us to detect and remediate threats much faster
Pros and Cons
- "The most valuable feature of this solution is the way the net flow is being merged together in a single pane. That's been extremely useful for us, because can see what's going on with traffic in one single place."
- "We are continuing down the road of ACI and ISE with Cisco, so we would like to see the continuation of Stealthwatch integrating into ISE for exchange of information, and also, more into the ACI environment too."
What is our primary use case?
For our organization, Cisco Stealthwatch is more of a confirmation of what is happening on our network, or compliance. And in addition to that, it helps us to troubleshoot issues. We get to see where traffic is flowing and it helps us figure out problems.
How has it helped my organization?
Cisco Stealthwatch helps us in finding unknown traffic, allowing us to audit the network and make sure things that are happening that we are expecting to happen.
I am a little versed about the solution's analytic and threat detection capabilities, even though it is pretty good. I know that we use it to validate that there's no east/west traffic. So that's been beneficial to us because we have things in place preventing that, and it's our way of proving it has actually happened. We haven't started using it for cloud protection or any analysis yet.
This solution has definitely also reduced our incident response time because we had no visibility before. We can detect and remediate threats much faster now.
What is most valuable?
The most valuable feature of this solution is the way the net flow is being merged together in a single pane. That's been extremely useful for us because we can see what's going on with traffic in one single place.
I also believe the solution has increased our organization's threat protection rate. The actual threat reports are run by our Infosec security person, but we are actually using this solution for that too. We're having reports generated so that our network engineering doesn't have to do the review. That team is responsible for reviewing reports and then we work with them to locate and do the next steps.
What needs improvement?
We are continuing down the road of ACI and ISE with Cisco, so we would like to see the continuation of Stealthwatch integrating into ISE for exchange of information, and also, more into the ACI environment too.
What do I think about the stability of the solution?
The solution is very stable and we haven't had any crashes yet.
What do I think about the scalability of the solution?
Based on what we've used it so far, it looks like it's scaling. We're growing and it's growing with us, so it's doing what we need it to do.
How are customer service and technical support?
I do know we have used the support before and it was good enough to get our problems fixed.
Which solution did I use previously and why did I switch?
We switched to Cisco Stealthwatch for operational reasons. The solution we used before was very clunky, so it was clear that we needed a better solution. So we started looking around and this solution came to the top quickly.
How was the initial setup?
The initial setup was pretty straightforward and sufficient. It's good.
What other advice do I have?
I believe this solution has saved our organization a lot of time, money, and administrative work. It allows us to see what's going on as far as traffic flows in a single, very short period. That is the biggest value to us on the networking side. The security team uses the implications of that for auditing and clearing out, whether we have good or bad traffic going on.
Operationally, using it as a tool, it can definitely be rated up there at a nine out of ten. It's very good, easy to use, I can get into it and find out what I want.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Manager, Network Engineering & Telecommunications at a healthcare company with 1,001-5,000 employees
Enables us to detects threats early on, ensuring that our network stays secure
Pros and Cons
- "The solution reduces the amount of time it takes to detect and remediate threats."
- "The initial setup was straightforward but required a lot of data entry, to begin with building out the server types and network types."
What is our primary use case?
We use Cisco Stealthwatch mostly for network visibility and security. I believe the solution reduces false-positives by flagging it as potential threats.
How has it helped my organization?
In terms of how this solution has affected network visibility, we're finding devices that junior network engineers, people who don't want to wait for proper channels, have added to the network. This solution enables us to find them and shut them down.
It has reduced our incident response time. We can now narrow down where incidents are happening, so it very helpful for our organization.
What is most valuable?
The features I find most valuable is the deep level of knowledge that we get on every device as well as what other devices it's talking to.
Analytics and threat detection capabilities are a little overwhelming. I would say it's about average.
The solution reduces the amount of time it takes to detect and remediate threats.
For how long have I used the solution?
We've been using this solution for around a year now.
What do I think about the stability of the solution?
So far we haven't had any issues with the stability of the solution. We haven't gone through a major upgrade cycle yet.
What do I think about the scalability of the solution?
Our initial deployment was built out to the right size for our organization.
How are customer service and technical support?
There hasn't been any need to ask for technical support since our initial deployment, where we used a reseller.
How was the initial setup?
The initial setup was straightforward but required a lot of data entry, to begin with building out the server types and network types.
What about the implementation team?
We used a reseller for the deployment, CDW.
Which other solutions did I evaluate?
We evaluated Plixer, but the fact that Stealthwatch was Cisco integrated, sold it for us.
What other advice do I have?
My advice would be to really look at how many traffic rows you're generating on your network when you decide to do your deployment. Personally, it is too early to know if there is room for improvement, but I will rate this solution an eight out of ten.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Network Engineer at a tech services company
Offers better network visibility and has reduced incident response time
Pros and Cons
- "I believe this solution has reduced our incident response time."
- "I would like to see it better organized when I'm looking at it."
What is our primary use case?
The primary use case for Cisco Stealthwatch is for us to sell it.
How has it helped my organization?
It has improved my organization's network visibility from zero because before we had installed this solution, we weren't doing anything to protect us from threats. I believe this solution has reduced our incident response time.
What is most valuable?
The features I find most valuable about Cisco Stealthwatch its integration with the pxGrid and all of our other devices that are tied in with pxGrid, so they can communicate with each other and be able to dynamically change, quarantine a suspicious device, or do whatever necessary in case of a malware attack or similar problem.
What needs improvement?
Considering all the data on the network, I believe that the analytics of Cisco Stealthwatch are pretty decent. I would like to see it better organized when I'm looking at it. If I hand it to another NOC engineer, they may not know what they're looking at, so I would prefer it to be more clean and structured, making it easier to use.
For how long have I used the solution?
We are currently also using AMP and a few other Cisco products to assist us with threat protection and it's only been running for a couple of months.
What do I think about the stability of the solution?
This solution is very stable.
What do I think about the scalability of the solution?
I believe there isn't much to scale for it and I think it all depends on how many nodes you're running in the environment. I will say the scalability is fairly decent.
How are customer service and technical support?
I haven't had to use technical support yet. I've only read through the pages of documentation.
How was the initial setup?
The initial setup was a little complex since I haven't set it up before.
What was our ROI?
It is hard to say yet, but at least we can tell customers that we've detected a threat, and it can be stopped in time.
What's my experience with pricing, setup cost, and licensing?
For our organization, it is cheap, but for other customers, it may be fairly expensive.
As we are resellers of Cisco Stealthwatch, we hope to save time, money, and administrative costs once we start selling more of these solutions.
Which other solutions did I evaluate?
I am responsible for the security of our organization's devices, so I did look at other options. Since this solution ties into other products, I wanted to use Duo Security and tie that together with StealthWatch.
What other advice do I have?
I will rate this solution a seven and a half or eight out of ten. This is mostly due to our exposure and having customers relying upon us to only look at it, as well as the layout.
My advice to others would be to go for it, play around with it and see what you like about it. If you don't like it, move on to something else, but at least try it first.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PIC for Cyber Security at a university with 51-200 employees
Scalable and good for training students
Pros and Cons
- "There are already many functionalities, so I don't think there is anything to improve."
What is most valuable?
The Cisco IOS is very important because that is what we have to teach our students.
What needs improvement?
There are already many functionalities, so I don't think there is anything to improve. Its the best one on the market I have seen.
For how long have I used the solution?
We've been using Cisco equipemnt for four or five years.
What do I think about the scalability of the solution?
It's scalable, there are many models that we can use for a small network. Cisco offers the scalability that we need. We have about eighty students, and all the students have to do some training on it. We have plans to increase the usage of Cisco.
How was the initial setup?
I think in order to master the network security issues it's complex. The deployment took a week or so.
What other advice do I have?
I think that maybe we need more products for our students to try and to master. It's part of their learning.
I would rate this solution as nine or ten out of ten.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.

Buyer's Guide
Download our free Cisco Secure Network Analytics Report and get advice and tips from experienced pros
sharing their opinions.
Updated: June 2025
Product Categories
Network Monitoring Software Network Traffic Analysis (NTA) Network Detection and Response (NDR) Cisco Security PortfolioPopular Comparisons
Cisco Umbrella
Cisco Identity Services Engine (ISE)
SolarWinds NPM
PRTG Network Monitor
ThousandEyes
Auvik Network Management (ANM)
LogicMonitor
Cisco Secure Workload
Gigamon Deep Observability Pipeline
Buyer's Guide
Download our free Cisco Secure Network Analytics Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- I'm building a next-gen AI powered threat intelligence platform. What's missing from existing solutions?
- When evaluating Network Performance Monitoring, what aspect do you think is the most important to look for?
- What is the best network monitoring software for large enterprises?
- What Questions Should I Ask Before Buying a Network Monitoring Tool?
- UIM OnPrem - SaaS
- Anyone switching from SolarWinds NPM? What is a good alternative and why?
- What is the best tool for SQL monitoring in a large enterprise?
- What tool do you recommend using for VoIP monitoring for a mid-sized enterprise?
- Should we choose Nagios or PRTG?
- Which is the best network monitoring tool: Zabbix or Solarwinds? Pros and Cons?