Try our new research platform with insights from 80,000+ expert users

Cisco Secure Network Analytics vs Darktrace vs IBM Security Network IPS comparison

 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Mindshare comparison

Network Monitoring Software Market Share Distribution
ProductMarket Share (%)
Cisco Secure Network Analytics1.2%
Zabbix11.7%
LibreNMS4.6%
Other82.5%
Network Monitoring Software
Network Detection and Response (NDR) Market Share Distribution
ProductMarket Share (%)
Darktrace22.7%
Vectra AI15.6%
ExtraHop Reveal(x)8.4%
Other53.300000000000004%
Network Detection and Response (NDR)
Intrusion Detection and Prevention Software (IDPS) Market Share Distribution
ProductMarket Share (%)
IBM Security Network IPS0.6%
Fortinet FortiGate17.1%
Darktrace13.7%
Other68.6%
Intrusion Detection and Prevention Software (IDPS)
 

Featured Reviews

Muhammad Harun-Owr-Roshid - PeerSpot reviewer
Have streamlined network visibility and troubleshooting while seeing benefits from AI integration
In terms of improvements for Cisco Secure Network Analytics, from the implementation point of view, now that AI is in use, some other features need to be upgraded considering AI solutions. Proper management of the database is also important; it should be centralized for easier data collection from a single database. When precise manual analysis is needed, it's sometimes difficult, so having a centralized database will allow network admins to find actual scenarios more effectively, especially since some information may not be visible on the GUI. Cisco should upgrade their hardware part to run the database, because sometimes it cannot handle the load while all features are running in the network. The database management should indeed be centralized because while AI runs behind the systems, central management is essential. For example, in a network with 100 Cisco switches, a few routers, firewalls, and access points, all data generated should be preserved in a central database. This approach simplifies management and analysis for troubleshooting, as GUI interfaces may not always provide visible information. Centralizing the database will allow for better understanding of which information is preserved for each specific device.
Malebo Lethoba Group - PeerSpot reviewer
Have found the AI analyst and detection functions highly valuable for network operations while managing complexity in initial setup
The functions I find most valuable in Darktrace are the AI analyst as well as the detection.The autonomous response capabilities of Darktrace are not crucial for me because it doesn't work in a network where there are no core switches. In a modern network, the autonomous response doesn't work, especially when sitting in a shared data center.If I'm running a traditional network where I am not in a shared data center with a layer two dedicated for my resources, then it can work for me. However, if I am in a data center where I don't have layer two, it becomes an issue because the autonomous response is reliant on sending spoofed TCP resets to my core switch to block traffic, which is a major issue.
Jacob_Koithra - PeerSpot reviewer
User-friendly and has a good blocking feature but is quite expensive
Defining the new security rules and policies sometimes becomes a challenge. Integration with other platforms becomes a challenge as well. I'd like to see more integration with other tools and technologies. XGS 7100 has an end of support for the 30th of December 2022. Many are losing support. All the products of the XGS, including XGS 3100, 4100, 5100, and 7100, support is ending in December 2022. We need to know what is the plan post that? Do we need to spend money on them? Will that be extended? There has been no communication on the website either. It's an expensive device.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"Cisco Secure Network Analytics has increased the visibility of what is happening in our network, and I think that's the most important reason to use it. We can see what is really happening instead of just looking at numbers from routers or switches."
"Using the Cognitive Analytics feature, we have complete visibility that we didn’t have before."
"The most valuable features include encrypted traffic analytics and the ability to fulfill requirements at the network level."
"StealthWatch lets me see the ports running in and out and the country. It has excellent reporting, telemetry, and artificial intelligence features. With the telemetry, I can set thresholds to detect sudden changes and the alarms go through the PLC parts. I can see all the ports running on that trunk."
"It has definitely helped us improve our mean time to resolution on network issues."
"The most valuable feature we got out of Stealthwatch is to be able to, while troubleshooting, go deep into one of our interfaces and verify what the bandwidth is and if there's any activity there that's causing problems."
"If you are using Darktrace or NAC solutions you can integrate Stealthwatch."
"The fact that it can identify down to an IP address of a system that is causing problems, or potentially causing problems, is very valuable."
"The Antigena feature is most valuable. Once it learns your environment, Antigena can step in and block a denial of service attack, a ransomware attack, or just about anything that doesn't belong in the environment. It can detect any type of attack that hits the environment because it understands what normal looks like for the network. It is very useful for an autonomous response."
"It's a very stable product."
"The most valuable features of Darktrace are the tracing of unusual external emails and monitoring the local network."
"The solution is outstanding from a monitoring perspective."
"It is autonomous. So, it learns. It uses algorithms and AI to learn the common behavioral patterns on the network, and it is able to identify threats based on abnormal patterns."
"The most valuable feature is the solution's ability to trim out the false positives and point your attention to the real important stuff."
"Darktrace is very useful for us because it has a large number of models for detecting threats."
"The solution is stable. We've never had any problems with it."
"The initial setup is simple."
"The most valuable feature is its simplicity."
 

Cons

"I would like the search page available with Cisco Stealthwatch to be more intuitive. The previous release was better than the current one for the UI."
"Cisco Stealthwatch needs more integration with device discovery. We have to do a lot of hard work to figure out what things are. Better service integration is required."
"We are continuing down the road of ACI and ISE with Cisco, so we would like to see the continuation of Stealthwatch integrating into ISE for exchange of information, and also, more into the ACI environment too."
"Its granularity for RBAC roles-based access control needs improvement."
"Cisco Stealthwatch can improve by having bundled packages for popular add-ons. It would be a lot easier for people implementing it, have let's say a better way to use the product."
"One update that I would like to see is an agent-based client. Currently, Stealthwatch is network-based. A local agent could help manage endpoints."
"If they can make this product more web-based, that would be amazing."
"I would like to see some improvement when it comes to reporting."
"The solution would benefit from automation. Currently, you have to know what you are searching for."
"In the next version, I'd like to see penetration testing."
"The product is considered expensive compared to others."
"I feel that Darktrace could be improved, particularly in the support aspect which is currently very poor. We need to chase Darktrace instead of them being proactive with us."
"The user interface and the configuration are a bit complex and should be improved or simplified."
"They just need to make it a little bit more accurate as far as their alerts are concerned. It does generate some false positives that you have to tune. You have to do a lot of tuning when you first get it because of the false positives, but once it is all tuned up and ready to go, it will do its thing from there."
"This product needs more in terms of prevention. The detection capabilities work well but once a threat has been detected, Darktrace should work to prevent it from doing anything malicious."
"Darktrace does not have any capabilities to configure."
"In the future, I would like to see a hybrid option so that we can work both on-premises and in the cloud."
"I'd like to see more integration with other tools and technologies."
 

Pricing and Cost Advice

"We pay for support costs on a yearly basis."
"On a yearly basis, licensing is somewhere around $30,000."
"NetFlow is very expensive."
"Our fees are approximately $3,000 USD."
"It has a subscription model. There is yearly support, and there is also three-year support. It depends on what the customers want."
"Licensing is on a yearly basis."
"​Licensing is done by flows per second, not including outside (in traffic)."
"The pricing for this solution is good."
"If you consider the features and the cost of market leaders, we are satisfied with the pricing."
"In the ballpark, we're talking about $30K, $50K, and up. It can even be as much as $50K or $100K."
"The product is expensive."
"We've budgeted about 50,000 Kuwaiti dinars for the solution. That is a yearly operating cost."
"Prior to negotiating, Darktrace offered their appliance and service for $80,000 per year."
"I'm unfamiliar with the exact cost, but we have a yearly license and had to pay for Darktrace's services before the deployment. The product is very expensive, so some organizations can't afford to pay the total amount directly, meaning they often seek a partner or pay in installments, which increases the price more."
"There is an annual license to use Darktrace."
"The cost of the solution can be reduced to make it more appealing to customers."
"The cost of operations is very low."
report
Use our free recommendation engine to learn which Network Monitoring Software solutions are best for your needs.
867,826 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Computer Software Company
22%
Government
11%
Financial Services Firm
9%
Manufacturing Company
9%
Computer Software Company
12%
Manufacturing Company
9%
Financial Services Firm
8%
Government
7%
No data available
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business11
Midsize Enterprise7
Large Enterprise52
By reviewers
Company SizeCount
Small Business43
Midsize Enterprise19
Large Enterprise29
No data available
 

Questions from the Community

What do you like most about Cisco Stealthwatch?
The most valuable feature of Cisco Secure Network Analytics is the Threat Intelligence integration.
What is your experience regarding pricing and costs for Cisco Stealthwatch?
Regarding cost, for the Bangladesh context, Cisco Secure Network Analytics is a little bit high-priced because we are...
What needs improvement with Cisco Stealthwatch?
In terms of improvements for Cisco Secure Network Analytics, from the implementation point of view, now that AI is in...
How does Crowdstrike Falcon compare with Darktrace?
Both of these products perform similarly and have many outstanding attributes. CrowdStrike Falcon offers an amazing u...
Which is better - SentinelOne or Darktrace?
Which solution is better depends on which is more suitable specifically for your company. Darktrace, for example, is ...
What do you like most about Darktrace?
A very useful feature in Darktrace for real-time threat analysis is the packet inspection that analyzes the packet tr...
Ask a question
Earn 20 points
 

Also Known As

Cisco Stealthwatch, Cisco Stealthwatch Enterprise, Lancope StealthWatch
No data available
Security Network Intrusion Prevention System, IBM Security Network Protection, XGS, GX
 

Overview

 

Sample Customers

Edge Web Hosting, Telenor Norway, Ivy Tech Community College of Indiana, Webster Financial Corporation, Westinghouse Electric, VMware, TIAA-CREF
Irwin Mitchell, Open Energi, Wellcome Trust, FirstGroup plc, Virgin Trains, Drax, QUI! Group, DNK, CreaCard, Macrosynergy, Sisley, William Hill plc, Toyota Canada, Royal British Legion, Vitol, Allianz, KKR, AIRBUS, dpd, Billabong, Mclaren Group.
Equifax, Christian Hospital Centre
Find out what your peers are saying about Zabbix, Auvik, SolarWinds and others in Network Monitoring Software. Updated: September 2025.
867,826 professionals have used our research since 2012.