Try our new research platform with insights from 80,000+ expert users
it_user735195 - PeerSpot reviewer
Senior Information Security Engineer at a transportation company with 10,001+ employees
Real User
Mar 8, 2018
Provides easily identifiable anomalies that you can't see with signature detections
Pros and Cons
  • "Provides easily identifiable anomalies that you can't see with signature detections."
  • "The beginning of any security investigation starts with net flow data."
  • "One update that I would like to see is an agent-based client. Currently, Stealthwatch is network-based. A local agent could help manage endpoints."

What is our primary use case?

  • ID managers
  • Flow replicators
  • Flow sensors
  • Thick client

How has it helped my organization?

Provides easily identifiable anomalies that you can't see with signature detections. 

What is most valuable?

NetFlow: The beginning of any security investigation starts with NetFlow data. 

What needs improvement?

One update that I would like to see is an agent-based client. Currently, Stealthwatch is network-based. A local agent could help manage endpoints. 

Buyer's Guide
Cisco Secure Network Analytics
January 2026
Learn what your peers think about Cisco Secure Network Analytics. Get advice and tips from experienced pros sharing their opinions. Updated: January 2026.
879,711 professionals have used our research since 2012.

For how long have I used the solution?

More than five years.

What do I think about the stability of the solution?

No issues.

What do I think about the scalability of the solution?

No issues.

How are customer service and support?

I have known these guys for a long time. They are completely familiar with their product.

Which solution did I use previously and why did I switch?

We did not have a previous solution.

How was the initial setup?

The initial setup is very straightforward. 

What about the implementation team?

The vendor helped in every step of the installation. 

What's my experience with pricing, setup cost, and licensing?

Licensing is done by flows per second, not including outside (in traffic). 

Which other solutions did I evaluate?

I have tried the Sourcefire solution, but Stealthwatch won out through its ease of use. 

What other advice do I have?

There is nothing like it. It is a dream to operate. It is very intuitive. Go for it.

Also, it is great for a network segmentation project.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
it_user734160 - PeerSpot reviewer
Senior Technical Consultant
Consultant
Sep 14, 2017
​Provides complete network visibility and has made troubleshooting easy
Pros and Cons
  • "Most valuable features are the network maps and server and network response time."
  • "The version with the Dell server had iDRAC problems. Often, it reported iDRAC failure."

What is most valuable?

SMC and FC, though they are components, not features.

Most valuable features are the network maps and server and network response time. Maps is a unique feature which provides logical grouping of different segments of the network with complete visibility and alerting based on a total or protocol base as per defined threshold. So, one can check how many connections to the server and/or on the protocol, and who is consuming the most bandwidth. This is done, while the server and network response time provide quick identification of root cause of slow response from the server.

How has it helped my organization?

Provided complete network visibility and made troubleshooting easy.

For how long have I used the solution?

I have used Cisco Stealthwatch for four to five years: versions 5.0 to 6.22.

What do I think about the stability of the solution?

Yes. The version with the Dell server had iDRAC problems. Often, it reported iDRAC failure.

What do I think about the scalability of the solution?

No.

How are customer service and technical support?

Very good.

Which solution did I use previously and why did I switch?

No, we did not use a different solution.

How was the initial setup?

Straightforward.

What's my experience with pricing, setup cost, and licensing?

Pricing is much higher compared to other solutions.

Which other solutions did I evaluate?

Yes, SolarWinds.

What other advice do I have?

It is a good product. I don't see any matching product with level of detailed information.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Buyer's Guide
Cisco Secure Network Analytics
January 2026
Learn what your peers think about Cisco Secure Network Analytics. Get advice and tips from experienced pros sharing their opinions. Updated: January 2026.
879,711 professionals have used our research since 2012.
it_user735216 - PeerSpot reviewer
Highly motivated Security Engineer incident Response, Vuln Mgmt, Malware Analysis, IDS/IPS, DLP, Network Security +more at a transportation company with 10,001+ employees
Vendor
Sep 12, 2017
NetFlow data is the beginning of any security investigation, very easy to use
Pros and Cons
  • "The most valuable feature is NetFlow. The beginning of any security investigation starts with NetFlow data."
  • "One update I would like to see is an agent-based client. Currently StealthWatch is network based."

What is most valuable?

There's nothing like it and a dream to operate, very intuitive. The most valuable feature is NetFlow. The beginning of any security investigation starts with NetFlow data.

How has it helped my organization?

Easily identifiable anomalies that you can't see with signature detections.

What needs improvement?

I am so familiar with the product I would say none. Lancope has always listened to customer input for product enhancements. One update I would like to see is an agent-based client. Currently StealthWatch is network based. A local agent could help manage endpoints.

For how long have I used the solution?

12 years.

What do I think about the stability of the solution?

No.

What do I think about the scalability of the solution?

No.

How are customer service and technical support?

I've known those guys for a long time. They are completely familiar with their product.

Which solution did I use previously and why did I switch?

No.

How was the initial setup?

Very straightforward. They helped in every step of the installation.

What's my experience with pricing, setup cost, and licensing?

Licensing is done by flows per second, not including outside>in traffic.

Which other solutions did I evaluate?

I have tried the Sourcefire solution but StealthWatch wins because of ease of use.

What other advice do I have?

Go for it. Also great for your network segmentation project.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
PeerSpot user
Information Security Analyst at a non-profit with 1,001-5,000 employees
Real User
Top 20
Jun 5, 2017
Enables me to detect devices talking to suspect IPs.
Pros and Cons
  • "I value the feature which enables me to detect devices talking to suspect IPs."
  • "We need to be able to filter out internal IPs as non-threats."

What is most valuable?

I value the feature which enables me to detect devices talking to suspect IPs.

How has it helped my organization?

We can now see what is going on in our network.

What needs improvement?

We need to be able to filter out internal IPs as non-threats.

For how long have I used the solution?

We have been using the product since 2008.

What do I think about the stability of the solution?

We did not encounter any issues with stability.

What do I think about the scalability of the solution?

We did not encounter any issues with scalability.

How are customer service and technical support?

The technical support is good.

Which solution did I use previously and why did I switch?

We did not use any other solution previously.

How was the initial setup?

The initial setup was relatively easy, though different devices need different configurations for the flow exports.

What's my experience with pricing, setup cost, and licensing?

It is worth the cost.

Which other solutions did I evaluate?

We evaluated Arbor.

What other advice do I have?

Get it in and see what you can see!

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
reviewer1432242 - PeerSpot reviewer
Ingenieria at a tech services company with 11-50 employees
Real User
Feb 7, 2021
Good routing and switching with an easy implementation
Pros and Cons
  • "Overall, the implementation is very good."
  • "We would like the solution to make more advances in the way that Extreme Networks has been doing."

What is our primary use case?

We primarily handle the design, implementation, and support for the solution and we also manage collaboration, routing and switching, security products, et cetera.

What is most valuable?

Overall, the implementation is very good.

The solution offers good security. 

We find the solution is very good at collaborating with other solutions.

What needs improvement?

We don't really see any limitations on the product. Overall, it's been good.

We would like the solution to make more advances in the way that Extreme Networks has been doing.

For how long have I used the solution?

We've been using the solution for about two months. It hasn't been too long just yet.

How are customer service and technical support?

We can handle technical support if our clients run into any issues. It's part of the services we offer.

Which solution did I use previously and why did I switch?

We also use Extreme Networks. We find it is a bit better than Cisco. We're also partners with Fortinet.

How was the initial setup?

The implementation is very easy and straightforward. 

What about the implementation team?

We implement the solution for our clients. We're Cisco partners, and therefore can manage all kinds of deployments.

What other advice do I have?

We are a Cisco premier partner.

In general, I would rate the solution ten out of ten. We've had very good experiences so far.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Buyer's Guide
Download our free Cisco Secure Network Analytics Report and get advice and tips from experienced pros sharing their opinions.
Updated: January 2026
Buyer's Guide
Download our free Cisco Secure Network Analytics Report and get advice and tips from experienced pros sharing their opinions.