Try our new research platform with insights from 80,000+ expert users

Check Point Infinity vs NetWitness Platform comparison

Sponsored
 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Cortex XDR by Palo Alto Net...
Sponsored
Average Rating
8.4
Reviews Sentiment
6.8
Number of Reviews
106
Ranking in other categories
Endpoint Protection Platform (EPP) (5th), Endpoint Detection and Response (EDR) (7th), Extended Detection and Response (XDR) (6th), Ransomware Protection (2nd), AI-Powered Cybersecurity Platforms (2nd)
Check Point Infinity
Average Rating
8.8
Reviews Sentiment
6.9
Number of Reviews
41
Ranking in other categories
Advanced Threat Protection (ATP) (9th), AI-Powered Cybersecurity Platforms (8th), AI Security (4th), AI Observability (5th)
NetWitness Platform
Average Rating
7.4
Reviews Sentiment
7.4
Number of Reviews
36
Ranking in other categories
Log Management (34th), Security Information and Event Management (SIEM) (33rd)
 

Mindshare comparison

AI-Powered Cybersecurity Platforms Mindshare Distribution
ProductMindshare (%)
Check Point Infinity2.8%
CrowdStrike Falcon17.1%
Darktrace14.1%
Other66.0%
AI-Powered Cybersecurity Platforms
Log Management Mindshare Distribution
ProductMindshare (%)
NetWitness Platform0.8%
Wazuh7.5%
Splunk Enterprise Security6.8%
Other84.9%
Log Management
 

Featured Reviews

ABHISHEK_SINGH - PeerSpot reviewer
Senior Process Expert at A.P. Moller - Maersk
Gained full visibility and streamlined threat detection through behavior-based insights and AI integration
Initially, we got to have a lot of false positives when we onboarded, but nowadays it's quite smooth. We have fine-tuned our security policies and allowed different levels of policies to get rid of those false positives. Currently, we are getting a fairly good amount of incidents that are not false positives or benign, but actionable items. The process is streamlined. In the initial days, the operations used to get involved in a lot of benign and other activities, but now the process is streamlined. We are leveraging the auto-detection and remediation plans. The operations teams are now more involved in other business roles as well, not just looking into the logs and fetching out what's happening there. They have fixed a lot of things. Initially, they didn't have IAC code drift detection, cloud posture management, or security posture management, but they have those now. They purchased different vendors and did a merger with that. They have now Prisma Cloud that gets integrated and now they are working with Cortex Cloud. Everything that was negative has now been addressed, and the product altogether looks to be in a very better and mature shape now. Currently, it's more or less detecting the workloads with AI-based best practices. Since most organizations are consuming AI agents and other things, we are looking forward to seeing what other feature enhancements Palo Alto can support in that.
Chetan Bhati - PeerSpot reviewer
Network Security Engineer at Arrow PC Network Pvt Ltd
Improves daily threat prevention with real-time detection and requires better alert tuning for faster prioritization
Check Point Infinity is powerful, but there are a few areas that could improve. The learning curve for new users can be steep, especially when managing multiple modules like CloudGuard, Quantum, and Harmony together. Some alerts can be overwhelming, making it harder to prioritize without fine-tuning. While automation helps, occasional manual adjustments are still needed. Overall, it is strong, but simplifying onboarding and alert management would make it even better. Integration with third-party tools could be smoother. The reporting dashboard could be more customizable for quick insights. Performance on very large networks can sometimes slow during updates. Overall, while the platform is strong, improving user experience, alert management, and integration would make it even more efficient for daily operations.
MOTASHIM Al Razi - PeerSpot reviewer
CISO at One Bank Limited
It is a stable solution, but they should make the user interface easier to understand
The solution's initial setup takes work. We have to organize multiple paths and many features. The deployment process takes less than a week. But it takes a month to complete if we want to make the solution smarter by integrating it with various devices. I rate the process as a six out of ten.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"There has been a significant reduction of approximately 70% to 80% in our internal MTTR and MTTD metrics, now around five to eight minutes whereas previously it was hours, which has helped tremendously."
"When the pandemic started, Palo Alto came up with many solutions, which helped with the quick shift from on-premises to the cloud."
"It has pretty much everything we need and works well within the Palo Alto ecosystem."
"Cortex XDR by Palo Alto Networks is easy to use and does not consume a lot of hardware resources."
"We can visualize and control the activities in the environment from anywhere."
"We have a complete overview of all our PCs and it's very easy to handle and to use the interface. It has a lot of benefits for us."
"The solution allows us to gain remote access without the user's knowledge and take the necessary actions on the device."
"The stability of the solution is very good. We have about 100 users on it right now, and we use it twice a week."
"Check Point Infinity has positively impacted my organization by streamlining security prevention and strengthening our overall posture."
"It is a scalable product."
"I recommend Check Point Infinity to other customers due to its notable benefits and positive experiences with a major financial institution."
"Since adopting Check Point Infinity, I have seen a noticeable improvement in how we manage and respond to security threats across our infrastructure."
"The Check Point Infinity security architecture enables organizations to fully implement all of the Zero Trust Principles."
"New Check Point technologies can be found via this portal."
"Check Point Infinity offers a multi-layered security approach that enhances our IT security environment."
"It provides fantastic visibility of security incidents through deconstructing and dissecting the threat's infection protocol."
"The product has a user-friendly interface and a valuable feature for threat intelligence integration."
"The product's initial setup phase was not at all difficult."
"NetWitness can be highly beneficial for incident detection and response."
"NetWitness Platform is valuable for creating rules that the solution must detect."
"The most valuable features are the integration and ease of use."
"The software is scalable to whatever is required, and you can also put a lot of resources in the cloud."
"The most valuable feature is that we can create our own connectors for any application, and NetWitness provides the training and tools to do it."
"It's quite economical compared to other solutions in the market."
 

Cons

"I would like to see some additional features related to email protection included."
"The installation should be easier and the Palo Alto pre-sales and sales teams should have more information on the product because they don't know what they are selling."
"Initially, we got to have a lot of false positives when we onboarded, but nowadays it's quite smooth."
"Dashboards do not allow everyone to see what's happening."
"The solution should add unwanted malicious hash values to a block list so that whenever the action is triggered, it will automatically prevent the malicious content."
"If Palo Alto reduces the pricing slightly for their products, it would make them more scalable in markets such as India and globally for cybersecurity."
"Data privacy is a matter of concern. You have to be careful with data privacy, it can be sensitive and Cortex can have most of your access."
"If you compare it to SentinelOne, which has more functionalities and detection capabilities on an open platform, the pricing on SentinelOne is far more reasonable and cheaper than Cortex XDR by Palo Alto Networks."
"One of the main improvements that can be made is the latency in the portal."
"We'd like to see support for fiber connections."
"Another improvement that would make our experience smoother with Check Point Infinity is simplifying the initial setup and configuration process; while powerful, it can feel overwhelming for smaller teams without dedicated security engineers, so more guides, wizards, or automatic best practice templates would be helpful."
"Check Point Infinity's web application is sometimes a little slow."
"Something that should be better in Check Point Infinity is the customization, though I don't have any specific suggestions at this time."
"There is an issue with high agent size, which impacts performance."
"Check Point Infinity price could improve."
"One area for improvement in Check Point Infinity is the user interface, as it can feel complex for new users."
"The multi-tenant capabilities are lagging compared to IBM QRadar."
"We have encountered issues with unresolved crashes."
"The documentation is not as structured as I would like, personally, and I think that it can be improved and made much more user-friendly."
"They should implement algorithms to digest that data and produce additional, more advanced reporting, alerting and support of internal security teams."
"The user interface is a little bit difficult for new users and it needs to be improved."
"Sometimes, it gives me static when integrating Windows-based systems. It should produce a precise log of sorts as to where the problem is. For example, a few days ago because of the McAfee application firewall, I couldn't get access to the particular Windows machine. So, my team and I had to figure out by ourselves that there was a virus responsible for the obstacle. This solution should trigger a meaningful log or message indicating the reason the user or implementer can't get into the machine."
"The implementation needs assistance."
"There is no support for this product in this country, so problems have to be resolved through global technical teams."
 

Pricing and Cost Advice

"I don't have any issues with the pricing. We are satisfied with the price."
"The cost of Cortex XDR by Palo Alto Networks is $55 to $90 USD per endpoint per month."
"Our customers have expressed that the price is high."
"I don't like that they have different types of licenses."
"When we first bought it, it was a bit expensive, but it was worth it. The licensing was straightforward."
"Cortex XDR by Palo Alto Networks is an expensive solution."
"Cortex XDR's pricing is ok."
"This is an expensive solution."
"The flexibility in pricing is advantageous, and being a special partner allows for negotiating special rates based on the project requirements."
"When it comes to price, the paramount consideration is the strength of the security. If the security measures provided by the product, such as Check Point Infinity, are robust and meet our requirements, price becomes a secondary concern."
"The product has good pricing considering the features and a global approach."
"I rate the product's price a six on a scale of one to ten, where one is cheap, and ten is expensive."
"The solution's price is quite high, and the licensing model requires extra licenses for various features like SD-WAN."
"Check Point should provide an enterprise-wide license where the organization should be provided free hand of using any license or services for an agreed period of time (EULA)."
"Choosing the correct set of licenses is essential because, without the additional software blade licenses, the Check Point gateways are just a stateful firewall."
"The pricing of Check Point Infinity could be better. There is a license needed to use the solution and we pay annually."
"Many clients are not able to purchase the packet capability because there is a huge amount of data, and the cost depends on the number of EPS (Events per second), as well as the number of gigabytes of data per day."
"The licenses are good but the cost is very expensive."
"The NetWitness Platform may be affordable only for enterprise-level customers, as it may not be within the budget of small and medium-sized businesses."
"We have yearly licensing costs. The license fee can be based on the volume of EPS. Some organizations may have, as a gentlemanly gesture, 10,000 EPS and get a 3,000 EPS license but actually use 5,000 EPS."
"There is a licensing fee and the customer can choose whether he wishes this to be subscription-based or perpetual."
"We are on an annual license for the use of the solution."
"In comparison to other SIEM solutions such as Splunk, NetWitness is less costly."
"It is cheap."
report
Use our free recommendation engine to learn which AI-Powered Cybersecurity Platforms solutions are best for your needs.
883,546 professionals have used our research since 2012.
 

Comparison Review

VS
Manager, Enterprise Risk Consulting at a tech company with 1,001-5,000 employees
Feb 26, 2015
HP ArcSight vs. IBM QRadar vs. ​McAfee Nitro vs. Splunk vs. RSA Security vs. LogRhythm
We at Infosecnirvana.com have done several posts on SIEM. After the Dummies Guide on SIEM, we are following it up with a SIEM Product Comparison – 101 deck. So, here it is for your viewing pleasure. Let me know what you think by posting your comments below. The key products compared here are…
 

Top Industries

By visitors reading reviews
Computer Software Company
10%
Financial Services Firm
9%
Manufacturing Company
9%
Government
7%
Security Firm
20%
Educational Organization
10%
Manufacturing Company
10%
Computer Software Company
9%
Financial Services Firm
13%
Performing Arts
8%
Computer Software Company
8%
Marketing Services Firm
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business44
Midsize Enterprise20
Large Enterprise47
By reviewers
Company SizeCount
Small Business40
Midsize Enterprise9
Large Enterprise10
By reviewers
Company SizeCount
Small Business8
Midsize Enterprise7
Large Enterprise20
 

Questions from the Community

Cortex XDR by Palo Alto vs. Sentinel One
Cortex XDR by Palo Alto vs. SentinelOne SentinelOne offers very detailed specifics with regard to risks or attacks. ...
Comparing CrowdStrike Falcon to Cortex XDR (Palo Alto)
Cortex XDR by Palo Alto vs. CrowdStrike Falcon Both Cortex XDR and Crowd Strike Falcon offer cloud-based solutions th...
How is Cortex XDR compared with Microsoft Defender?
Microsoft Defender for Endpoint is a cloud-delivered endpoint security solution. The tool reduces the attack surface,...
What do you like most about Check Point Infinity?
Check Point Infinity's threat prevention capabilities benefitted our organization.
What needs improvement with Check Point Infinity?
Check Point Infinity could be improved with more intuitive documentation.
What is your primary use case for Check Point Infinity?
Check Point Infinity is used primarily for consolidating security across networks, including cloud and on-premise, an...
What do you like most about NetWitness Platform?
The product's initial setup phase was not at all difficult.
What is your experience regarding pricing and costs for NetWitness Platform?
The pricing is comparable to others, and I consider the cost to be intermediate. Specific cost details are unknown to...
What needs improvement with NetWitness Platform?
There is currently no need for improvement in the SIEM ( /categories/security-information-and-event-management-siem )...
 

Also Known As

Cyvera, Cortex XDR, Palo Alto Networks Traps
R80, Infinity
RSA Security Analytics
 

Overview

 

Sample Customers

CBI Health Group, University Honda, VakifBank
Edel AG
Los Angeles World Airports, Reply
Find out what your peers are saying about Check Point Infinity vs. NetWitness Platform and other solutions. Updated: September 2022.
883,546 professionals have used our research since 2012.