No more typing reviews! Try our Samantha, our new voice AI agent.

Cisco Secure Network Analytics vs Icinga comparison

 

Comparison Buyer's Guide

Executive SummaryUpdated on Oct 10, 2024

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Cisco Secure Network Analytics
Ranking in Network Monitoring Software
32nd
Average Rating
8.2
Reviews Sentiment
6.6
Number of Reviews
63
Ranking in other categories
Network Traffic Analysis (NTA) (4th), Network Detection and Response (NDR) (6th), Cisco Security Portfolio (6th)
Icinga
Ranking in Network Monitoring Software
40th
Average Rating
7.6
Reviews Sentiment
6.1
Number of Reviews
17
Ranking in other categories
Server Monitoring (16th), IT Infrastructure Monitoring (47th), Cloud Monitoring Software (31st)
 

Mindshare comparison

As of July 2026, in the Network Monitoring Software category, the mindshare of Cisco Secure Network Analytics is 0.9%, down from 1.2% compared to the previous year. The mindshare of Icinga is 1.2%, down from 3.3% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Network Monitoring Software Mindshare Distribution
ProductMindshare (%)
Cisco Secure Network Analytics0.9%
Icinga1.2%
Other97.9%
Network Monitoring Software
 

Featured Reviews

Akash Das Barman - PeerSpot reviewer
Cyber Security Trainee at DataSpace Academy
Network analytics has reduced investigation time and provides deeper visibility into lateral movement
Several features often look very promising during evaluation or implementation but end up being used only lightly in day-to-day operations. Advanced reporting and scheduled compliance reports look very attractive for audit and compliance teams at implementation time and can generate structured reports for visibility, risk posture, and traffic summaries. In practice, many teams do not rely on it heavily because SIEM tools or GRC platforms already handle reporting better. Built-in threat intelligence feeds represent another area where expectations do not always match usage. The platform includes threat intelligence-based detection and classifications. Initially, teams expect to depend on this heavily, but later SOC teams often prefer their own threat intelligence feeds or correlate intelligence inside SIEM instead. The built-in feeds are used but not as a primary detection source. Automated incident summaries and guided investigation views are designed to simplify triage by automatically grouping related activity into incidents. However, teams often move away from them due to various factors affecting adoption.
reviewer2292201 - PeerSpot reviewer
Innovation Service Manager at a tech services company with 201-500 employees
Easy to use, and it's possible to customize the product as per the needs we may have but average multi-tenancy aspect
It's supported by the community. We use Icinga, which is not part of the Open-Source platform but is wrapped into a commercial solution from another provider, a local provider in Italy. Icinga is an open-source platform, so it is supported by the community. It's quite easy to use, and it's possible to customize the product as per the needs we may have. So it's not expensive, and it's quite a general purpose. We can easily monitor any kind of infrastructure we encounter. The ability to customize scripts and build your own queries to request information from the infrastructure elements you want to monitor. This level of personalization and customization is highly appreciated. The alerting is the same as any other monitoring platform. It's not a "wow" feature that has changed our lives, but it's perfectly adequate.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"The ROI was immediate for us, in regard to how we implemented it."
"It has been pretty stable since we deployed it, and everything seems to be working fine."
"It is a good application, providing for real-time monitoring of the organization of data. It can basically identify points of peak traffic where possible issues are being caused."
"The amount of information that this product gives us for detecting threats is very valuable, and we don't have another product like this in our environment."
"Time to value is very good for Stealthwatch."
"The most valuable feature of this solution is the way the net flow is being merged together in a single pane. That's been extremely useful for us, because can see what's going on with traffic in one single place."
"The most valuable features of this solution are the logging, keeping threats under control, and keeping our data and environment secure."
"The solution's analytics and thrust detection capabilities are good. We're still adjusting it. It's a little hypersensitive, but it is working right now."
"The drafts are easy but what I like about Icinga is that there are many add-ons that you can download."
"Icinga2 was designed to delegate, distribute and balance tasks between several nodes."
"Icinga does the job and is fairly stable."
"An affordable solution for small organizations to do basic network monitoring."
"I like the ability to amend and adjust things really easily, which is useful in a case where you could make it auto-discover and then set a template to say all of these applications or servers under this template have an automatic threshold set that you’d set up manually."
"The apply rules feature saves a lot of time."
"We have found the solution to be stable."
"The best thing about the solution is how it highlights errors, the issues, and what needs my attention. The solution directs me to areas that I should look for first."
 

Cons

"We've had problems with element licensing costs so scalability is a concern."
"Several features often look very promising during evaluation or implementation but end up being used only lightly in day-to-day operations."
"It's a good solid solution but integration with Network Access Control products with Cisco ISE would be good."
"Stealthwatch is still maturing in AI. It uses artificial intelligence for predictions, but AI still needs to mature. It is in a phase where you get 95% correct detection. As its AI engine learns more, it will become more accurate. This is applicable to all the devices that are using AI because they support both supervised and unsupervised machine learning. The accuracy in the case of supervised machine learning is dependent on the data you feed into the box. The accuracy in the case of unsupervised machine learning is dependent on the algorithm. The algorithm matures depending on retrospective learning, and this is how it is able to detect zero-day attacks."
"There could be better integration on the programming side, which uses Python. StealthWatch could provide a template for Python to manage the switches. For example, it would be nice if StealthWatch bounced a port automatically it detected something anomalous."
"I don't really think we really save time while using this solution."
"It is time-consuming to set it up and understand how the tool works."
"Many of these tools require extensive on-premises hardware to run."
"I think the software is quite good, but we have had problems with getting it to recognize certain areas and amend certain checks, where we needed so we would have to create backend scripts for those checks. Though, being open source, it has the support to create backend scripts, it would be better to have these scripts in-built."
"Icinga’s automation could be improved."
"Scalability is problematic. If you have a stable environment it's good, but if the environment is growing, I had some problems with Icinga."
"Network Discovery capabilities would be extremely helpful."
"There is room for improvement in multi-tenancy. It's not perfect, not even really good. It's average, but it should be improved."
"Icinga is a complex solution that's hard to learn. It's a powerful product for monitoring, but new users will have a hard time figuring out what to do."
"One thing that Icinga lacks is the capability to create advanced and customized dashboards within the tool itself."
"It needs Trap SNMP. I saw the documentation for Zabbix, that it has its own built-in product which handles SNMP traps, and there's nothing similar in Icinga or Nagios. I think this feature is most important for me."
 

Pricing and Cost Advice

"The yearly licensing cost is about $50,000."
"NetFlow is very expensive."
"Today, we are part of the big Cisco ELA, and it is a la carte. We can get orders for whatever we want. At the end of the day, we have to pay for it in one big expense, but that is fine. We are okay with that."
"Licensing is on a yearly basis."
"The pricing for this solution is good."
"This is an expensive product. We have quit paying for support because we don't want to have to upgrade it and keep paying for it."
"One of the things which bugs me about Lancope is the licensing. We understand how licensing works. Our problem is when we bought and purchased most of these Lancope devices, we did so with our sister company. Somewhere within the purchase and distribution, licensing got mixed up. That is all on Cisco, and it is their responsibility. They allotted some of our sister company's equipment to us, and some of our equipment to them. To date, they have never been able to fix it."
"Licensing is done by flows per second, not including outside>in traffic."
"It's an open-source solution."
"The product is inexpensive compared to other DBM products."
"The solution is cheap."
"The solution is free to use."
"This is an open-source solution with paid support."
"We're using the free version of Icinga."
"Even though Icinga's financial cost is low, it is an expensive product regarding the resources required to maintain and operate it."
"It is cost-effective, and the return on investment can be very interesting because the price is low."
report
Use our free recommendation engine to learn which Network Monitoring Software solutions are best for your needs.
902,988 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Financial Services Firm
11%
Manufacturing Company
10%
Construction Company
8%
Government
8%
Educational Organization
14%
Financial Services Firm
11%
Comms Service Provider
10%
University
9%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business12
Midsize Enterprise7
Large Enterprise52
By reviewers
Company SizeCount
Small Business9
Midsize Enterprise4
Large Enterprise8
 

Questions from the Community

What is your experience regarding pricing and costs for Cisco Stealthwatch?
Regarding cost, for the Bangladesh context, Cisco Secure Network Analytics is a little bit high-priced because we are a developing country, making it tough to manage affordable solutions. However, ...
What needs improvement with Cisco Stealthwatch?
Several features often look very promising during evaluation or implementation but end up being used only lightly in day-to-day operations. Advanced reporting and scheduled compliance reports look ...
What is your primary use case for Cisco Stealthwatch?
My main use case for Cisco Secure Network Analytics has been network visibility and anomaly-based threat detection within the enterprise environment. In security operations and VAPT-related activit...
Ask a question
Earn 20 points
 

Also Known As

Cisco Stealthwatch, Cisco Stealthwatch Enterprise, Lancope StealthWatch
Icinga Cloud Monitoring
 

Overview

 

Sample Customers

Edge Web Hosting, Telenor Norway, Ivy Tech Community College of Indiana, Webster Financial Corporation, Westinghouse Electric, VMware, TIAA-CREF
Puppet Labs, Audi, Spacex, Debian, Snapdeal, McGill, RIPE Network Coordination Centre
Find out what your peers are saying about Cisco Secure Network Analytics vs. Icinga and other solutions. Updated: June 2026.
902,988 professionals have used our research since 2012.