No more typing reviews! Try our Samantha, our new voice AI agent.

Arbor DDoS vs NetWitness Platform comparison

Why PeerSpot?
 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Arbor DDoS
Average Rating
8.8
Reviews Sentiment
6.9
Number of Reviews
57
Ranking in other categories
Distributed Denial-of-Service (DDoS) Protection (3rd)
NetWitness Platform
Average Rating
7.4
Reviews Sentiment
7.4
Number of Reviews
36
Ranking in other categories
Log Management (37th), Security Information and Event Management (SIEM) (36th)
 

Mindshare comparison

Arbor DDoS and NetWitness Platform aren’t in the same category and serve different purposes. Arbor DDoS is designed for Distributed Denial-of-Service (DDoS) Protection and holds a mindshare of 6.1%, down 12.1% compared to last year.
NetWitness Platform, on the other hand, focuses on Log Management, holds 1.1% mindshare, up 0.4% since last year.
Distributed Denial-of-Service (DDoS) Protection Mindshare Distribution
ProductMindshare (%)
Arbor DDoS6.1%
Cloudflare12.4%
Imperva Application Security Platform8.0%
Other73.5%
Distributed Denial-of-Service (DDoS) Protection
Log Management Mindshare Distribution
ProductMindshare (%)
NetWitness Platform1.1%
Splunk Enterprise Security7.0%
IBM Security QRadar4.5%
Other87.4%
Log Management
 

Featured Reviews

reviewer1331304 - PeerSpot reviewer
Director Of Research And Development at a comms service provider with 11-50 employees
Automated threat intelligence and flow-based mitigation have improved our DDoS defense
A very useful feature in Arbor DDoS is its ability to send flow spec announcements to routers. For example, if it is clear that a Layer 3 or Layer 4 attack is occurring and the attack pattern is identified through source and destination IP addresses and ports, you can generate flow spec filters. These filters are transferred through BGP to border routers, which automatically build filters, mitigating the attack even at the network's boundary and preventing it from reaching the TMS. This allows the TMS to focus on other tasks. This is a highly effective feature that can mitigate huge volumetric attacks; for example, we experienced a 32-gigabit attack, and all those 32 gigabits were dropped by our border routers, not by Arbor DDoS itself. The flow spec announcement was generated by Arbor DDoS, and as far as I know, the same technology is used by Radware, but it comes under a different feature and a different license. At the time, we were told that flow spec mitigation was an additional very expensive license to purchase from Radware, while Radware included everything in one package.
reviewer2256927 - PeerSpot reviewer
Head of Information Security, Cyber Defense and IT Risk Management at HCT. at a transportation company with 201-500 employees
A solid SIEM solution that should improve technical support and online resources to be easier to use
A big problem with the product is that we don't have much professional experience in Israel installing, implementing, and integrating this product. There is not enough of a knowledge base. There is no support for this product in this country, so problems have to be resolved through global technical teams. We like to work locally because of the language, and when the product is only supported outside the country, it's a little difficult to implement and use this product. Moreover, AI is something that must be added immediately. Artificial intelligence is a part of the competitors' products, and it's not been implemented for us.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"I like all the features together as a whole."
"The artificial intelligence feature is most appreciated. This solution can lower the throughput and clear the traffic, which is something really important for us. It also provides good protection. It is user-friendly, and its integration has also been really fast. We have many critical applications, and it was easy to integrate Arbor DDoS with our website, mobile application, and web banking."
"In terms of Arbor DDoS's reporting and analytics, Arbor DDoS is superior to Radware, especially when comparing it to the Radware model which I used previously."
"Don't worry that it is complex because, out-of-the-box, it protects you from the basics."
"The AI capabilities and anomaly detection using machine learning modules like isolation forests and auto-encoders are the most effective in mitigating DDoS attacks."
"Arbor DDoS's best feature is that we can put the certificates in, and it will look at layer seven and the encrypted traffic and do the required signaling."
"They have done a considerable amount of development in the last few years when it comes to features."
"Arbor DDoS has given us a very good ROI."
"Technically speaking, this is a good product."
"NetWitness can be highly beneficial for incident detection and response."
"Technical support is very good; they try to resolve issues with the proper SLAs which are defined by them and they understand the client's requirements as well as the client's infrastructure in a better manner."
"This solution has a very good dashboard with a separate tab for incidents and alerts."
"Performance and reporting are very good."
"The product's initial setup phase was not at all difficult."
"The most valuable features are the packet decoder, log decoder, and concentrator."
"Stability has not been an issue with this product."
 

Cons

"An improvement to Arbor DDoS would be to make evaluation licenses and virtual machines available."
"Implementation could be better."
"The prices for Arbor DDoS are expensive. The licensing is subscription-based."
"It could include a lot of enhancements related to AI and automation."
"Arbor Pravail APS devices do not sync features or config the backup enough. This needs to be improved."
"They should improve the reporting section and make it a little bit more detailed. I would like to have much better and more detailed reports."
"The solution could be more granular to include logs per second and enhanced pipeline monitoring for router licenses."
"If we want to see live traffic, we can see do so. But once an attack that lasts for five minutes is done, the data is no longer there. It would be an improvement if we could see recent traffic in the dashboard. We can check and download live traffic, but a past attack, with all the details, such as why it happened and how to mitigate and prevent such future attacks, would be helpful to see."
"The log system is a bit complex and has room for improvement."
"We have encountered issues with unresolved crashes."
"The system looks like it is a mix of a bunch of different systems, and nothing looked like it was quite together."
"Log aggregation is an issue with this solution because there are a huge number of alerts in a single instance."
"The product continues to crash. Even with tech support help, it does not resolve itself."
"The solution should have more integration capabilities with different platforms."
"The product's licensing models are complex to understand. This particular area needs improvement."
"If we have the ability to run a dynamic analysis through malware in the same suite, it would be great to have a sandbox solution to analyze malware through dynamic analysis."
 

Pricing and Cost Advice

"The price is a little high."
"I don't know about the pricing details as our company's service provider offers us the solution as an inbuilt feature within the internet bandwidth they provide us."
"Regarding pricing, I would rate it as average. Arbor DDoS offers good value for money with our DDoS filter device. For higher protection needs, Arbor’s CloudMeter’s DDoS mitigation or hardware devices might be more expensive, but customers who need them are usually prepared for the cost and the additional resources required."
"The licensing of a complete Arbor solution, including fire-walling and unified site management, can get expensive."
"The solution's pricing is based on a licensing model that is expensive when compared to other tools."
"I'm a technical guy. But I know it's expensive compared to its competitors. After you have the on-premise solution, for your solution to be effective you have to subscribe to an "upper level," so there's another cost. There is also a subscription to cloud services, which is another cost."
"Because the solutions from competitors are very different, it's not easy to compare. However, the licensing from Arbor is clear and understandable and the pricing is reasonable when looking at the market, in general."
"I don't deal with the pricing, but it seems that you need to get basic support in order to upgrade the software and implement some patches."
"The new pricing and licensing mechanisms are fair. I would advise always to get the full solution (i.e., not only Logs)."
"It is cheap."
"The product price was reasonable for my region and the market."
"It’s cheaper to run virtual machines in a VMware environment."
"The licenses are good but the cost is very expensive."
"It provides tools to assist in selecting the appropriate license and usage scenarios."
"This is a pricey solution; it's not cheap."
"We are on an annual license for the use of the solution."
report
Use our free recommendation engine to learn which Distributed Denial-of-Service (DDoS) Protection solutions are best for your needs.
911,473 professionals have used our research since 2012.
 

Comparison Review

VS
Manager, Enterprise Risk Consulting at a tech company with 1,001-5,000 employees
Feb 26, 2015
HP ArcSight vs. IBM QRadar vs. ​McAfee Nitro vs. Splunk vs. RSA Security vs. LogRhythm
We at Infosecnirvana.com have done several posts on SIEM. After the Dummies Guide on SIEM, we are following it up with a SIEM Product Comparison – 101 deck. So, here it is for your viewing pleasure. Let me know what you think by posting your comments below. The key products compared here are…
 

Top Industries

By visitors reading reviews
Financial Services Firm
15%
Comms Service Provider
13%
Outsourcing Company
8%
Manufacturing Company
7%
Construction Company
13%
Financial Services Firm
11%
Outsourcing Company
10%
Comms Service Provider
9%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business26
Midsize Enterprise14
Large Enterprise29
By reviewers
Company SizeCount
Small Business8
Midsize Enterprise7
Large Enterprise20
 

Questions from the Community

Which is the best DDoS protection solution for a big ISP for monitoring and mitigating?
I would say if it’s an ISP that will build a scrubbing center, Netscout/Arbor is a good solution. In all other solutions, Imperva is a great choice.
Which is the best DDoS protection solution for a big ISP for monitoring and mitigating?
Arbor would be the best bid, apart from Arbor, Palo Alto and Fortinet have good solutions. As this is an ISP, I would prefer Arbor.
What is your experience regarding pricing and costs for Arbor DDoS?
The prices for Arbor DDoS are expensive. The licensing is subscription-based. From our sales department, they discuss that prices are very high.
What is your experience regarding pricing and costs for NetWitness Platform?
The pricing is comparable to others, and I consider the cost to be intermediate. Specific cost details are unknown to me.
What needs improvement with NetWitness Platform?
There is currently no need for improvement in the SIEM ( /categories/security-information-and-event-management-siem ), though there could be potential enhancements by integrating with AI.
What is your primary use case for NetWitness Platform?
I use NetWitness Platform ( /products/netwitness-platform-reviews ) in the financial industry as a good product with excellent capabilities and integration with various devices.
 

Also Known As

Arbor Networks SP, Arbor Networks TMS, Arbor Cloud for ENT
RSA Security Analytics
 

Overview

 

Sample Customers

Xtel Communications
Los Angeles World Airports, Reply
Find out what your peers are saying about Radware, Cloudflare, NETSCOUT and others in Distributed Denial-of-Service (DDoS) Protection. Updated: August 2026.
911,473 professionals have used our research since 2012.