No more typing reviews! Try our Samantha, our new voice AI agent.

Chronosphere vs NetWitness Platform comparison

Why PeerSpot?
 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Chronosphere
Ranking in Log Management
33rd
Average Rating
8.4
Reviews Sentiment
7.0
Number of Reviews
3
Ranking in other categories
Application Performance Monitoring (APM) and Observability (35th), AIOps (21st)
NetWitness Platform
Ranking in Log Management
36th
Average Rating
7.4
Reviews Sentiment
7.4
Number of Reviews
36
Ranking in other categories
Security Information and Event Management (SIEM) (35th)
 

Mindshare comparison

As of October 2026, in the Log Management category, the mindshare of Chronosphere is 0.8%, up from 0.2% compared to the previous year. The mindshare of NetWitness Platform is 1.2%, up from 0.4% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Log Management Mindshare Distribution
ProductMindshare (%)
Chronosphere0.8%
NetWitness Platform1.2%
Other98.0%
Log Management
 

Featured Reviews

Karthik Doreswamy - PeerSpot reviewer
Dev Ops Engineer at a tech services company with 11-50 employees
Centralized monitoring has unified alerts and dashboards for critical cloud applications
We can improve a bit of UI aspects. The UI could be made more user friendly. Sometimes when identifying the specific logs patterns and identifying what metrics and what logs are coming in, going to a specific log explorer and finding it there is a little difficult. It would be very useful if we could group according to projects and have that UI a little more user friendly. The user interface part was a bit confusing in the beginning. To make it better, I believe we would need some more open sourced or freely available courses on Chronosphere which would help us understand the platform a bit more. The team provides detailed walkthroughs whenever you get into that. However, it would be better if we could have proper video sessions or documentation which would help us understand the tool a bit more.
reviewer1130436 - PeerSpot reviewer
Information Technology Security and Infrastructure Expert at a government with 201-500 employees
Helps to deal with potential attacks and is available at a reasonable price
My company has had many benefits from the use of the product in the last eight years. The tool has streamlined our company's incident response process since it serves as a log repository, which allows us to correlate events and access different technology stacks. In our company, we were able to actually find some potential attacks, so it has been very helpful. The tool's integration capability isn't so great. In my company, we managed to integrate it with our Microsoft Azure Subscription, after which we managed to integrate it with other tools. You will face a lot of difficulties if you want to integrate it with your database monitoring tool, PAM solutions, or IAM products. The product has done well overall for my company's teams to deal with their workflow efficiency. I would not recommend the product to others. I rate the tool a seven out of ten.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"The alerting features are good"
"Chronosphere has impacted my organization positively as for starters, we brought down the cost drastically since we completely moved to Chronosphere."
"Integrating Chronosphere was pretty much easy coming from an open source tool and it helped us to streamline our monitoring and alerting setup across our organization, which directly impacted on the streamlining of the process as well as reducing errors and also keeping our environment uptime to a greater extent by those alerts and quick responses."
"Possibility to investigate incidents based on logs and raw packets, such as extracting files sent over the network"
"The product has a user-friendly interface and a valuable feature for threat intelligence integration."
"NetWitness Platform is valuable for creating rules that the solution must detect."
"Once it is deployed and you are used to it, you can do whatever you want."
"Technical support is very good; they try to resolve issues with the proper SLAs which are defined by them and they understand the client's requirements as well as the client's infrastructure in a better manner."
"Overall, I feel that the product is very good and my biggest complaint is about their support."
"The development of use cases on the SSA console is quite user friendly, which means that the security analyst or the researcher does not have to learn another language."
"The most valuable features are the packet decoder, log decoder, and concentrator."
 

Cons

"In logging, I would prefer if Chronosphere could do something in the way of a dictionary or a JSON lookup kind of logging, which would be much easier in terms of directly searching for a particular keyword rather than a string match."
"It's not easy for everyone."
"Sometimes when identifying the specific logs patterns and identifying what metrics and what logs are coming in, going to a specific log explorer and finding it there is a little difficult."
"The implementation needs assistance."
"The log system is a bit complex and has room for improvement."
"I am not happy with the RSA support. Sometimes they can be really annoying because it takes so long to get the support that you need."
"The tool's integration capability isn't so great."
"We encountered stability issues in the earlier versions, and much fewer in the newer versions."
"I cannot say that the solution was stable because it tended to crash."
"The threat detection capability and centralizing and upgrading capability need to be improved. The threat alert capability needs to be improved as well because there is some lag time at present. They need to work on their database search too."
"The documentation is not as structured as I would like, personally, and I think that it can be improved and made much more user-friendly."
 

Pricing and Cost Advice

Information not available
"The tool is very expensive, so I rate the pricing a ten out of ten. The solution has an annual subscription."
"It’s cheaper to run virtual machines in a VMware environment."
"We have yearly licensing costs. The license fee can be based on the volume of EPS. Some organizations may have, as a gentlemanly gesture, 10,000 EPS and get a 3,000 EPS license but actually use 5,000 EPS."
"In comparison to other SIEM solutions such as Splunk, NetWitness is less costly."
"Many clients are not able to purchase the packet capability because there is a huge amount of data, and the cost depends on the number of EPS (Events per second), as well as the number of gigabytes of data per day."
"The product is expensive."
"The new pricing and licensing mechanisms are fair. I would advise always to get the full solution (i.e., not only Logs)."
"We have a perpetual license, so the total cost of ownership is not very expensive. It's a good investment."
report
Use our free recommendation engine to learn which Log Management solutions are best for your needs.
915,341 professionals have used our research since 2012.
 

Comparison Review

VS
Manager, Enterprise Risk Consulting at a tech company with 1,001-5,000 employees
Feb 26, 2015
HP ArcSight vs. IBM QRadar vs. ​McAfee Nitro vs. Splunk vs. RSA Security vs. LogRhythm
We at Infosecnirvana.com have done several posts on SIEM. After the Dummies Guide on SIEM, we are following it up with a SIEM Product Comparison – 101 deck. So, here it is for your viewing pleasure. Let me know what you think by posting your comments below. The key products compared here are…
 

Top Industries

By visitors reading reviews
Construction Company
12%
Transportation Company
12%
Outsourcing Company
9%
Financial Services Firm
9%
Construction Company
12%
Financial Services Firm
11%
Comms Service Provider
10%
Outsourcing Company
10%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
No data available
By reviewers
Company SizeCount
Small Business8
Midsize Enterprise7
Large Enterprise20
 

Questions from the Community

What needs improvement with Chronosphere?
In logging, I would prefer if Chronosphere could do something in the way of a dictionary or a JSON lookup kind of logging, which would be much easier in terms of directly searching for a particular...
What is your primary use case for Chronosphere?
My main use case for Chronosphere is logging, metrics, traceability, and raising alerts. A specific example of how I use Chronosphere for logging metrics or raising alerts is that we had a free int...
What advice do you have for others considering Chronosphere?
My advice to others looking into using Chronosphere is to go ahead for it. I gave Chronosphere a rating of 8 out of 10.
What is your experience regarding pricing and costs for NetWitness Platform?
The pricing is comparable to others, and I consider the cost to be intermediate. Specific cost details are unknown to me.
What needs improvement with NetWitness Platform?
There is currently no need for improvement in the SIEM ( /categories/security-information-and-event-management-siem ), though there could be potential enhancements by integrating with AI.
What is your primary use case for NetWitness Platform?
I use NetWitness Platform ( /products/netwitness-platform-reviews ) in the financial industry as a good product with excellent capabilities and integration with various devices.
 

Also Known As

No data available
RSA Security Analytics
 

Overview

 

Sample Customers

Information Not Available
Los Angeles World Airports, Reply
Find out what your peers are saying about Chronosphere vs. NetWitness Platform and other solutions. Updated: September 2026.
915,341 professionals have used our research since 2012.