Try our new research platform with insights from 80,000+ expert users

Check Point Infinity vs NetWitness Platform comparison

Sponsored
 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Cortex XDR by Palo Alto Net...
Sponsored
Average Rating
8.4
Reviews Sentiment
6.9
Number of Reviews
105
Ranking in other categories
Endpoint Protection Platform (EPP) (5th), Endpoint Detection and Response (EDR) (8th), Extended Detection and Response (XDR) (7th), Ransomware Protection (2nd), AI-Powered Cybersecurity Platforms (2nd)
Check Point Infinity
Average Rating
8.8
Reviews Sentiment
6.9
Number of Reviews
41
Ranking in other categories
Advanced Threat Protection (ATP) (9th), AI-Powered Cybersecurity Platforms (8th), AI Security (4th), AI Observability (5th)
NetWitness Platform
Average Rating
7.4
Reviews Sentiment
7.4
Number of Reviews
36
Ranking in other categories
Log Management (35th), Security Information and Event Management (SIEM) (32nd)
 

Mindshare comparison

AI-Powered Cybersecurity Platforms Market Share Distribution
ProductMarket Share (%)
Check Point Infinity2.5%
CrowdStrike Falcon17.4%
Darktrace14.4%
Other65.7%
AI-Powered Cybersecurity Platforms
Log Management Market Share Distribution
ProductMarket Share (%)
NetWitness Platform0.7%
Wazuh8.3%
Splunk Enterprise Security6.9%
Other84.1%
Log Management
 

Featured Reviews

ABHISHEK_SINGH - PeerSpot reviewer
Senior Process Expert at A.P. Moller - Maersk
Gained full visibility and streamlined threat detection through behavior-based insights and AI integration
Initially, we got to have a lot of false positives when we onboarded, but nowadays it's quite smooth. We have fine-tuned our security policies and allowed different levels of policies to get rid of those false positives. Currently, we are getting a fairly good amount of incidents that are not false positives or benign, but actionable items. The process is streamlined. In the initial days, the operations used to get involved in a lot of benign and other activities, but now the process is streamlined. We are leveraging the auto-detection and remediation plans. The operations teams are now more involved in other business roles as well, not just looking into the logs and fetching out what's happening there. They have fixed a lot of things. Initially, they didn't have IAC code drift detection, cloud posture management, or security posture management, but they have those now. They purchased different vendors and did a merger with that. They have now Prisma Cloud that gets integrated and now they are working with Cortex Cloud. Everything that was negative has now been addressed, and the product altogether looks to be in a very better and mature shape now. Currently, it's more or less detecting the workloads with AI-based best practices. Since most organizations are consuming AI agents and other things, we are looking forward to seeing what other feature enhancements Palo Alto can support in that.
Chetan Bhati - PeerSpot reviewer
Network Security Engineer at Arrow PC Network Pvt Ltd
Improves daily threat prevention with real-time detection and requires better alert tuning for faster prioritization
Check Point Infinity is powerful, but there are a few areas that could improve. The learning curve for new users can be steep, especially when managing multiple modules like CloudGuard, Quantum, and Harmony together. Some alerts can be overwhelming, making it harder to prioritize without fine-tuning. While automation helps, occasional manual adjustments are still needed. Overall, it is strong, but simplifying onboarding and alert management would make it even better. Integration with third-party tools could be smoother. The reporting dashboard could be more customizable for quick insights. Performance on very large networks can sometimes slow during updates. Overall, while the platform is strong, improving user experience, alert management, and integration would make it even more efficient for daily operations.
MOTASHIM Al Razi - PeerSpot reviewer
CISO at One Bank Limited
It is a stable solution, but they should make the user interface easier to understand
The solution's initial setup takes work. We have to organize multiple paths and many features. The deployment process takes less than a week. But it takes a month to complete if we want to make the solution smarter by integrating it with various devices. I rate the process as a six out of ten.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"We can use Cortex XDR to get the entire graph of the incidents from source to destination, and we can take remedial action."
"Cortex XDR is a very capable solution for protecting large networks and a lot of endpoints. It's very useful because the automation is very high, and if you combine it with the features on Palo Alto firewalls, it provides very strong protection."
"When the pandemic started, Palo Alto came up with many solutions, which helped with the quick shift from on-premises to the cloud."
"Has great threat detection capabilities."
"From a single pane of glass, you can easily manage all of your endpoints."
"The solution allows us to gain remote access without the user's knowledge and take the necessary actions on the device."
"The most valuable features are incident creation, policy-based protection, IP whitelisting, and device encryption. These are beneficial for endpoint and server security."
"The product's initial setup phase is very easy."
"It provides fantastic visibility of security incidents through deconstructing and dissecting the threat's infection protocol."
"The most valuable feature of Check Point Infinity is the ease of use and navigation."
"Check Point Infinity has had a positive impact by providing a unified security framework that reduced complexity and improved visibility across all layers."
"The all-in-one management feature of Check Point Infinity saves time because I can manage everything and deploy everything from one place."
"I would rate the stability a ten out of ten. Stability is always important. I haven't faced any issues with the Infinity Portal in the last six or seven years."
"For me, one of the best features of Check Point Infinity is to be able to have the possibility of emulating the activity of attached files with malicious content in such a short time."
"Check Point Infinity has impacted my organization positively, as I have seen a reduction in security incidents and response times, with threats that used to slip through different point solutions now being blocked automatically thanks to the unified prevention layers."
"Since adopting Check Point Infinity, I have seen a noticeable improvement in how we manage and respond to security threats across our infrastructure."
"Their technical support responds quickly and are knowledgable."
"The most valuable feature is that we can create our own connectors for any application, and NetWitness provides the training and tools to do it."
"The product has a user-friendly interface and a valuable feature for threat intelligence integration."
"Performance and reporting are very good."
"NetWitness Platform offers flexibility for deployment and robust integration capabilities."
"It gives the capability for the incident response team to correlate logs to identify any kind of problem like malware and incidents in a general sense, both for logs and packets."
"Incident management is its most valuable feature."
"I can have enterprise security, email security, next generation firewall security log, HIDS and NIDS logs, etc. all on the same dashboard. It makes it easy to pinpoint or correlate our server to this. I can find out if there is lateral movement. This is the biggest advantage of this solution."
 

Cons

"I would like to see better protection, specifically to protect email applications."
"Cortex XDR could improve its sales support team, including better commission structures and referral programs."
"Whenever the tool releases a new version when deploying the product across the organization, I feel like there are some disturbances in the CPU usage after upgrading the tool to the latest version."
"Initially, we got to have a lot of false positives when we onboarded, but nowadays it's quite smooth."
"There's an overall lack of features."
"Cortex XDR by Palo Alto Networks is a very good product, but financially, it is very expensive, so the company should look into that area."
"Managing the product should be easier."
"While using Cortex, I noticed some aspects that could be improved, such as increasing the synchronization speed between XDR and Xnor."
"The cost of maintaining and purchasing the security components is high."
"The management console has given us some trouble, and the documentation is a little bit rigid in its solution paths."
"In the future, I would like to see new developments that allow us to centralize the cloud."
"One area where Check Point Infinity could improve is in the reporting and analytics customization."
"Another improvement that would make our experience smoother with Check Point Infinity is simplifying the initial setup and configuration process; while powerful, it can feel overwhelming for smaller teams without dedicated security engineers, so more guides, wizards, or automatic best practice templates would be helpful."
"Another improvement that would make our experience smoother with Check Point Infinity is simplifying the initial setup and configuration process; while powerful, it can feel overwhelming for smaller teams without dedicated security engineers, so more guides, wizards, or automatic best practice templates would be helpful."
"The improvements needed for Check Point Infinity include that the documentation is not intuitive, and we needed more pictures or steps to make it more intuitive for all people when deploying it for the first time."
"One point that led to the nine rating was an incident about two months ago where our inbound and outbound mail were going to quarantine and we could not do anything."
"RSA NetWitness Logs and Packets can improve the threat level aspect, it is lacking compared to other solutions. Whenever any hacking activity or any other threat factor occurred they used to provide the coverages very fast when comparing RSA NetWitness Logs and Packets. I heard the other three solutions, from a discussion with my team members who had experience in other solutions, they used to say that. Whenever any issues happened across the globe RSA NetWitness Logs and Packets are a little bit slow improving those detection mechanisms."
"Lots of competing products have vulnerability protection built into their products, and this solution would be improved by including that support."
"If we have the ability to run a dynamic analysis through malware in the same suite, it would be great to have a sandbox solution to analyze malware through dynamic analysis."
"The multi-tenant capabilities are lagging compared to IBM QRadar."
"They should implement algorithms to digest that data and produce additional, more advanced reporting, alerting and support of internal security teams."
"Its technical support could be better."
"The product's licensing models are complex to understand. This particular area needs improvement."
"More customizability is required, which is something that they need to improve on."
 

Pricing and Cost Advice

"When we first bought it, it was a bit expensive, but it was worth it. The licensing was straightforward."
"The solution has one subscription for endpoint protection and one subscription for detection and response. The two licenses combined give you the BRO version."
"In terms of the cost Cortex XDR by Palo Alto Networks is very expensive because we are a Mexican company and when you translate dollars to pesos the cost is very high. The solution is very expensive for Mexican companies. I understand that they have international prices, but I do not think it offsets the price enough for many companies in countries, such as Mexico. The amount it is reduced is not a massive percentage."
"The price of the product is not very economical."
"The pricing is a little bit on the expensive side."
"I don't like that they have different types of licenses."
"We pay about $50,000 USD per year for a bundle that includes Cortex XDR."
"I did PoCs on products called Cylance and CrowdStrike. Although, I consider these products and they were also good, when it come to cost and budgetary factors, Traps has been proven to be better than the other two products. It is quite cost-effective and delivers all the entire solution which we require."
"Choosing the correct set of licenses is essential because, without the additional software blade licenses, the Check Point gateways are just a stateful firewall."
"The pricing of Check Point Infinity could be better. There is a license needed to use the solution and we pay annually."
"The product has good pricing considering the features and a global approach."
"I rate the product's price a six on a scale of one to ten, where one is cheap, and ten is expensive."
"The solution's price is quite high, and the licensing model requires extra licenses for various features like SD-WAN."
"Check Point should provide an enterprise-wide license where the organization should be provided free hand of using any license or services for an agreed period of time (EULA)."
"The flexibility in pricing is advantageous, and being a special partner allows for negotiating special rates based on the project requirements."
"When it comes to price, the paramount consideration is the strength of the security. If the security measures provided by the product, such as Check Point Infinity, are robust and meet our requirements, price becomes a secondary concern."
"The new pricing and licensing mechanisms are fair. I would advise always to get the full solution (i.e., not only Logs)."
"The product price was reasonable for my region and the market."
"Our license is for one year."
"The licenses are good but the cost is very expensive."
"It’s cheaper to run virtual machines in a VMware environment."
"The tool is very expensive, so I rate the pricing a ten out of ten. The solution has an annual subscription."
"We are on an annual license for the use of the solution."
"In comparison to other SIEM solutions such as Splunk, NetWitness is less costly."
report
Use our free recommendation engine to learn which AI-Powered Cybersecurity Platforms solutions are best for your needs.
882,886 professionals have used our research since 2012.
 

Comparison Review

VS
Manager, Enterprise Risk Consulting at a tech company with 1,001-5,000 employees
Feb 26, 2015
HP ArcSight vs. IBM QRadar vs. ​McAfee Nitro vs. Splunk vs. RSA Security vs. LogRhythm
We at Infosecnirvana.com have done several posts on SIEM. After the Dummies Guide on SIEM, we are following it up with a SIEM Product Comparison – 101 deck. So, here it is for your viewing pleasure. Let me know what you think by posting your comments below. The key products compared here are…
 

Top Industries

By visitors reading reviews
Computer Software Company
10%
Financial Services Firm
10%
Manufacturing Company
8%
Government
6%
Security Firm
20%
Educational Organization
10%
Manufacturing Company
10%
Computer Software Company
9%
Financial Services Firm
13%
Performing Arts
8%
Computer Software Company
8%
Marketing Services Firm
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business42
Midsize Enterprise21
Large Enterprise47
By reviewers
Company SizeCount
Small Business40
Midsize Enterprise9
Large Enterprise10
By reviewers
Company SizeCount
Small Business8
Midsize Enterprise7
Large Enterprise20
 

Questions from the Community

Cortex XDR by Palo Alto vs. Sentinel One
Cortex XDR by Palo Alto vs. SentinelOne SentinelOne offers very detailed specifics with regard to risks or attacks. ...
Comparing CrowdStrike Falcon to Cortex XDR (Palo Alto)
Cortex XDR by Palo Alto vs. CrowdStrike Falcon Both Cortex XDR and Crowd Strike Falcon offer cloud-based solutions th...
How is Cortex XDR compared with Microsoft Defender?
Microsoft Defender for Endpoint is a cloud-delivered endpoint security solution. The tool reduces the attack surface,...
What do you like most about Check Point Infinity?
Check Point Infinity's threat prevention capabilities benefitted our organization.
What needs improvement with Check Point Infinity?
Check Point Infinity could be improved with more intuitive documentation.
What is your primary use case for Check Point Infinity?
Check Point Infinity is used primarily for consolidating security across networks, including cloud and on-premise, an...
What do you like most about NetWitness Platform?
The product's initial setup phase was not at all difficult.
What is your experience regarding pricing and costs for NetWitness Platform?
The pricing is comparable to others, and I consider the cost to be intermediate. Specific cost details are unknown to...
What needs improvement with NetWitness Platform?
There is currently no need for improvement in the SIEM ( /categories/security-information-and-event-management-siem )...
 

Also Known As

Cyvera, Cortex XDR, Palo Alto Networks Traps
R80, Infinity
RSA Security Analytics
 

Overview

 

Sample Customers

CBI Health Group, University Honda, VakifBank
Edel AG
Los Angeles World Airports, Reply
Find out what your peers are saying about Check Point Infinity vs. NetWitness Platform and other solutions. Updated: September 2022.
882,886 professionals have used our research since 2012.