No more typing reviews! Try our Samantha, our new voice AI agent.

Cisco Secure Network Analytics vs Darktrace vs IBM Security Network IPS comparison

 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Mindshare comparison

Network Monitoring Software Mindshare Distribution
ProductMindshare (%)
Cisco Secure Network Analytics0.9%
Zabbix4.3%
SolarWinds NPM3.6%
Other91.2%
Network Monitoring Software
Network Detection and Response (NDR) Mindshare Distribution
ProductMindshare (%)
Darktrace15.5%
Vectra AI12.0%
ExtraHop Reveal(x)6.3%
Other66.2%
Network Detection and Response (NDR)
Intrusion Detection and Prevention Software (IDPS) Mindshare Distribution
ProductMindshare (%)
IBM Security Network IPS1.6%
Fortinet FortiGate11.4%
Darktrace10.8%
Other76.2%
Intrusion Detection and Prevention Software (IDPS)
 

Featured Reviews

Muhammad Harun-Owr-Roshid - PeerSpot reviewer
CEO at BRIGHT-i SYSTEMS LIMITED
Have streamlined network visibility and troubleshooting while seeing benefits from AI integration
In terms of improvements for Cisco Secure Network Analytics, from the implementation point of view, now that AI is in use, some other features need to be upgraded considering AI solutions. Proper management of the database is also important; it should be centralized for easier data collection from a single database. When precise manual analysis is needed, it's sometimes difficult, so having a centralized database will allow network admins to find actual scenarios more effectively, especially since some information may not be visible on the GUI. Cisco should upgrade their hardware part to run the database, because sometimes it cannot handle the load while all features are running in the network. The database management should indeed be centralized because while AI runs behind the systems, central management is essential. For example, in a network with 100 Cisco switches, a few routers, firewalls, and access points, all data generated should be preserved in a central database. This approach simplifies management and analysis for troubleshooting, as GUI interfaces may not always provide visible information. Centralizing the database will allow for better understanding of which information is preserved for each specific device.
AM
Technical Consultant - Unix Platform Services at BITS AND BYTE IT CONSULTING PVT LTD
Consistent threat hunting and anomaly detection deliver valuable insights for network security management
In terms of improvement for Darktrace, pricing is the main concern. Pricing bothers me and this is one of the major factors when choosing a solution. When we get feedback from customers, that's the only felt need. When we factor in Darktrace, we do it only limited. We put it on where the perimeters and connections are, but still, some gray areas are left out, especially if we have multiple branches. We need Darktrace on each branch to get the data out, and I suggest having some kind of a centralized product that gets data from multiple sources to aggregate and provide the data.
Jacob_Koithra - PeerSpot reviewer
Project & Program manager at Shell Grp
User-friendly and has a good blocking feature but is quite expensive
Defining the new security rules and policies sometimes becomes a challenge. Integration with other platforms becomes a challenge as well. I'd like to see more integration with other tools and technologies. XGS 7100 has an end of support for the 30th of December 2022. Many are losing support. All the products of the XGS, including XGS 3100, 4100, 5100, and 7100, support is ending in December 2022. We need to know what is the plan post that? Do we need to spend money on them? Will that be extended? There has been no communication on the website either. It's an expensive device.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"The amount of information that this product gives us for detecting threats is very valuable, and we don't have another product like this in our environment."
"It has improved our internal knowledge of what's going on with the network, and that's helpful."
"Cisco Stealthwatch has reduced the amount of time to detect an immediate threat."
"The most valuable feature of this solution is the way the net flow is being merged together in a single pane. That's been extremely useful for us, because can see what's going on with traffic in one single place."
"Stability is the most valuable feature we have seen in this solution."
"Most of the engineers I've worked with have been really good. Very knowledgeable and easy to work with."
"The most valuable features of this solution are its reporting and mitigation capabilities."
"Stealthwatch has greatly improved our network visibility, in terms of bandwidth, malware, and PCI violations."
"I am a very happy user and a happy seller of Darktrace."
"One thing I appreciate is Antigena Email, which is for email protection."
"Darktrace is very useful for us because it has a large number of models for detecting threats."
"The NDR is good in their solution and they have NTG for email."
"The autonomous mode, which is the Antigena AI response, is particularly valuable."
"Darktrace has improved our knowledge of abnormal phenomenen which could have potentially be hazardous for the organization."
"The models, triggers, and alerts are customizable."
"I have used multiple solutions, but its graphical user interface is quite interesting and quite descriptive. There are a lot of video animations, and we can easily see how the data is transferred between various points. That's something really interesting. It is also quite easy to understand for a new user."
"IPS has helped us in understanding more about the latest threats out there and made us realize that we need to be proactive when it comes to security rather than reactive."
"The most valuable feature is its simplicity."
"The blocking feature is great; it acts as an in-line blocker, and any malicious traffic that you see, or anything really, it can block the traffic."
"Signature based analysis and preventing different types of network attacks."
"This is definitely a product that I recommend, especially for organizations that want a quick integration of data from the transaction systems, with a very low cost of operations."
"The initial setup is simple."
 

Cons

"There's a lot of traffic on our network that we don't see sometimes."
"Initially, I felt Cisco Secure Network Analytics lacked integration with Splunk."
"The configuration of the solution was quite complex."
"It's not great as a standalone solution."
"This is a good solution, but Java is still in the SMC, the Firepower integration is not really there, and I would really appreciate people being told about the necessity of ISE beforehand."
"It's too complicated to install when starting out."
"We determined that Stealthwatch wouldn't provide the machine learning model that we required."
"Some of our customers find this solution to be a little bit tough because they don't understand how to configure and use it."
"It's quite expensive to have."
"This product needs more in terms of prevention. The detection capabilities work well but once a threat has been detected, Darktrace should work to prevent it from doing anything malicious."
"If asked to rate Darktrace support on a scale from zero to ten where ten is the best, I would give them five points."
"There aren't so many third-party vendor platforms natively integrated with the platform."
"I would like to see more protection in the endpoint. Especially because we have a lot of people using VPNs."
"Needs to improve its collaboration with local partners."
"Its threat analyzer could be better. It should also have agents. They should improve this product by installing agents for the machine to get more visibility. Currently, they are monitoring only the network. They should also monitor the agents from inside. It should also have a better pricing plan because it is an expensive product."
"The interface is too mathematical and it should be simplified."
"The management server can be made more user friendly and also the database configuration could be made simpler."
"In terms of scalability, I would say that it is a little on the poor side."
"I'd like to see more integration with other tools and technologies."
"It's an expensive device."
"The configuration of this product is complex. It could be made more user friendly."
"In the future, I would like to see a hybrid option so that we can work both on-premises and in the cloud."
 

Pricing and Cost Advice

"It is worth the cost."
"Pricing is much higher compared to other solutions."
"Today, we are part of the big Cisco ELA, and it is a la carte. We can get orders for whatever we want. At the end of the day, we have to pay for it in one big expense, but that is fine. We are okay with that."
"One of the things which bugs me about Lancope is the licensing. We understand how licensing works. Our problem is when we bought and purchased most of these Lancope devices, we did so with our sister company. Somewhere within the purchase and distribution, licensing got mixed up. That is all on Cisco, and it is their responsibility. They allotted some of our sister company's equipment to us, and some of our equipment to them. To date, they have never been able to fix it."
"The pricing for this solution is good."
"It has a subscription model. There is yearly support, and there is also three-year support. It depends on what the customers want."
"The yearly licensing cost is about $50,000."
"NetFlow is very expensive."
"The pricing is very flexible for Darktrace. Sometimes, a customer does not have the appropriate budget, but Darktrace can handle that. They offer monthly payments, so the customer can acquire the solution very easily."
"All of the other modules, such as the licensing modules, are on par. It's one for one."
"The price of the solution is not cheap. It is not a one-time purchase, there is a subscription that needs to be paid every one to five years depending on your choice. It is expensive but you can reduce the price by only using the services that you want."
"Prior to negotiating, Darktrace offered their appliance and service for $80,000 per year."
"In the ballpark, we're talking about $30K, $50K, and up. It can even be as much as $50K or $100K."
"The pricing is reasonable."
"The solution is about $6,000 per quarter."
"The price of Darktrace is high and could be reduced. We pay approximately $30,000 to $54,000 annually."
"The cost of operations is very low."
report
Use our free recommendation engine to learn which Network Monitoring Software solutions are best for your needs.
889,955 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Financial Services Firm
10%
Manufacturing Company
10%
Computer Software Company
10%
Government
9%
Computer Software Company
10%
Manufacturing Company
9%
Financial Services Firm
9%
Government
7%
Performing Arts
16%
Media Company
10%
Comms Service Provider
8%
Financial Services Firm
8%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business11
Midsize Enterprise7
Large Enterprise52
By reviewers
Company SizeCount
Small Business45
Midsize Enterprise19
Large Enterprise29
No data available
 

Questions from the Community

What is your experience regarding pricing and costs for Cisco Stealthwatch?
Regarding cost, for the Bangladesh context, Cisco Secure Network Analytics is a little bit high-priced because we are...
What needs improvement with Cisco Stealthwatch?
In terms of improvements for Cisco Secure Network Analytics, from the implementation point of view, now that AI is in...
What is your primary use case for Cisco Stealthwatch?
Our customers mainly use Cisco Secure Network Analytics to get whole network visibility and easy troubleshooting to f...
How does Crowdstrike Falcon compare with Darktrace?
Both of these products perform similarly and have many outstanding attributes. CrowdStrike Falcon offers an amazing u...
Which is better - SentinelOne or Darktrace?
Which solution is better depends on which is more suitable specifically for your company. Darktrace, for example, is ...
What is your experience regarding pricing and costs for Darktrace?
Concerning pricing for the product, I would say it is somewhat expensive.
Ask a question
Earn 20 points
 

Also Known As

Cisco Stealthwatch, Cisco Stealthwatch Enterprise, Lancope StealthWatch
No data available
Security Network Intrusion Prevention System, IBM Security Network Protection, XGS, GX
 

Overview

 

Sample Customers

Edge Web Hosting, Telenor Norway, Ivy Tech Community College of Indiana, Webster Financial Corporation, Westinghouse Electric, VMware, TIAA-CREF
Irwin Mitchell, Open Energi, Wellcome Trust, FirstGroup plc, Virgin Trains, Drax, QUI! Group, DNK, CreaCard, Macrosynergy, Sisley, William Hill plc, Toyota Canada, Royal British Legion, Vitol, Allianz, KKR, AIRBUS, dpd, Billabong, Mclaren Group.
Equifax, Christian Hospital Centre
Find out what your peers are saying about Zabbix, Auvik, Datadog and others in Network Monitoring Software. Updated: April 2026.
889,955 professionals have used our research since 2012.