Try our new research platform with insights from 80,000+ expert users

Cisco Secure Network Analytics vs Trellix Intrusion Prevention System comparison

 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Cisco Secure Network Analytics
Average Rating
8.2
Reviews Sentiment
6.9
Number of Reviews
61
Ranking in other categories
Network Monitoring Software (33rd), Network Traffic Analysis (NTA) (5th), Network Detection and Response (NDR) (7th), Cisco Security Portfolio (8th)
Trellix Intrusion Preventio...
Average Rating
8.4
Reviews Sentiment
6.6
Number of Reviews
15
Ranking in other categories
Intrusion Detection and Prevention Software (IDPS) (12th)
 

Mindshare comparison

While both are Network Security Systems solutions, they serve different purposes. Cisco Secure Network Analytics is designed for Network Monitoring Software and holds a mindshare of 1.2%, down 1.4% compared to last year.
Trellix Intrusion Prevention System, on the other hand, focuses on Intrusion Detection and Prevention Software (IDPS), holds 3.5% mindshare, up 2.8% since last year.
Network Monitoring Software Market Share Distribution
ProductMarket Share (%)
Cisco Secure Network Analytics1.2%
Zabbix11.7%
LibreNMS4.6%
Other82.5%
Network Monitoring Software
Intrusion Detection and Prevention Software (IDPS) Market Share Distribution
ProductMarket Share (%)
Trellix Intrusion Prevention System3.5%
Darktrace18.0%
Vectra AI10.6%
Other67.9%
Intrusion Detection and Prevention Software (IDPS)
 

Featured Reviews

Muhammad Harun-Owr-Roshid - PeerSpot reviewer
Have streamlined network visibility and troubleshooting while seeing benefits from AI integration
In terms of improvements for Cisco Secure Network Analytics, from the implementation point of view, now that AI is in use, some other features need to be upgraded considering AI solutions. Proper management of the database is also important; it should be centralized for easier data collection from a single database. When precise manual analysis is needed, it's sometimes difficult, so having a centralized database will allow network admins to find actual scenarios more effectively, especially since some information may not be visible on the GUI. Cisco should upgrade their hardware part to run the database, because sometimes it cannot handle the load while all features are running in the network. The database management should indeed be centralized because while AI runs behind the systems, central management is essential. For example, in a network with 100 Cisco switches, a few routers, firewalls, and access points, all data generated should be preserved in a central database. This approach simplifies management and analysis for troubleshooting, as GUI interfaces may not always provide visible information. Centralizing the database will allow for better understanding of which information is preserved for each specific device.
Daniel_Martins - PeerSpot reviewer
Decade of experience empowers seamless problem resolution and support
I haven't seen threat intelligence and machine learning for predictive threat analysis in the Trellix Intrusion Prevention System yet. For Trellix IPS, AI improvements are an area where it can improve. It's a significant feature. Regarding the Trellix Intrusion Prevention System's flexibility for catering to our organization's specific infrastructure requirements, we have only on-premises and virtual appliances, but it's acceptable. The access and platform could potentially integrate with SaaS. Similar to when you put the EPO in mode integration with SaaS, you can connect with a local credential and with an X Console credential. Another possibility would be to connect with an integration login with the X Console. We have this with EPO on-premise, but with IPS, we don't have it.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"It has improved our internal knowledge of what's going on with the network, and that's helpful."
"The most valuable feature is having visibility into the data segments throughout our network."
"Overall, the implementation is very good."
"It is a good application, providing for real-time monitoring of the organization of data. It can basically identify points of peak traffic where possible issues are being caused."
"Able to drill down into a center's utilization, then create reports based on it."
"The solution's analytics and thrust detection capabilities are good. We're still adjusting it. It's a little hypersensitive, but it is working right now."
"The most valuable feature of this solution is the way the net flow is being merged together in a single pane. That's been extremely useful for us, because can see what's going on with traffic in one single place."
"If you are using Darktrace or NAC solutions you can integrate Stealthwatch."
"The threat intelligence updates are very accurate."
"The ability to centrally manage all the IPS sensors, track the different security events generated by it, and customize the different policies, depending on their location."
"Great monitoring feature."
"The initial setup is straightforward."
"The most valuable features are the customization of the signature and the unlimited amount of signatures in IPS."
"The most valuable features in Trellix for me are the automated signature updates. It is a great and convenient feature."
"McAfee NSP is much more stable than Cisco."
"There's a good dashboard you can drill down into. It helps you easily locate intrusions and the source of attacks."
 

Cons

"The initial setup is complex, as there is a lot to configure."
"I would like to see a hybrid solution that can work without being connected directly to the internet for those destinations."
"It would be better to let people know, up front, that is doesn't give you nice, clear information, as seen in the demos, without Cisco ISE installed."
"Initially, I felt Cisco Secure Network Analytics lacked integration with Splunk."
"The initial setup was complex."
"Improvements are needed on the application layer for complete security analysis."
"They should include Citrix VDIs in the next release."
"I would like to see it better organized when I'm looking at it."
"The management component could be simplified."
"The area of concern where the tool needs improvement is how the product prompts users at a network level that helps prevent any wireless network attacks through alerts and notifications."
"The Network Security Managers could be more stable, agile, and work faster. When it comes to instability, there is room for improvement."
"Some of the documentation is not as straightforward as it could be."
"The technical support must be improved."
"The platform’s GUI could be the latest."
"The pricing could be improved."
"There are limited resources for configuration guidance."
 

Pricing and Cost Advice

"The licensing costs are outrageous."
"The yearly licensing cost is about $50,000."
"Pricing is much higher compared to other solutions."
"We pay for support costs on a yearly basis."
"It has a subscription model. There is yearly support, and there is also three-year support. It depends on what the customers want."
"It is worth the cost."
"​Licensing is done by flows per second, not including outside (in traffic)."
"NetFlow is very expensive."
"I rate the product’s pricing an eight out of ten."
"The tool is competitively priced."
report
Use our free recommendation engine to learn which Network Monitoring Software solutions are best for your needs.
866,956 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Computer Software Company
23%
Government
10%
Financial Services Firm
9%
Manufacturing Company
9%
Manufacturing Company
12%
Computer Software Company
10%
Financial Services Firm
8%
Comms Service Provider
8%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business11
Midsize Enterprise7
Large Enterprise52
By reviewers
Company SizeCount
Small Business6
Midsize Enterprise6
Large Enterprise5
 

Questions from the Community

What do you like most about Cisco Stealthwatch?
The most valuable feature of Cisco Secure Network Analytics is the Threat Intelligence integration.
What is your experience regarding pricing and costs for Cisco Stealthwatch?
Regarding cost, for the Bangladesh context, Cisco Secure Network Analytics is a little bit high-priced because we are a developing country, making it tough to manage affordable solutions. However, ...
What needs improvement with Cisco Stealthwatch?
In terms of improvements for Cisco Secure Network Analytics, from the implementation point of view, now that AI is in use, some other features need to be upgraded considering AI solutions. Proper m...
What do you like most about McAfee Network Security Platform?
The threat intelligence updates are very accurate.
What is your experience regarding pricing and costs for McAfee Network Security Platform?
The tool is competitively priced. I rate the pricing a six out of ten.
What needs improvement with McAfee Network Security Platform?
I haven't seen threat intelligence and machine learning for predictive threat analysis in the Trellix Intrusion Prevention System yet. For Trellix IPS, AI improvements are an area where it can impr...
 

Also Known As

Cisco Stealthwatch, Cisco Stealthwatch Enterprise, Lancope StealthWatch
McAfee Network Security Platform, McAfee NSP, IntruShield Network Intrusion Prevention System, IntruShield Network IPS
 

Overview

 

Sample Customers

Edge Web Hosting, Telenor Norway, Ivy Tech Community College of Indiana, Webster Financial Corporation, Westinghouse Electric, VMware, TIAA-CREF
Desjardins Group, HollyFrontier, Nubia, Agbar, WNS Global Services, INAIL, Universidad de Las Américas Puebla (UDLAP), Cook County, China Pacific Insurance, Bank Central Asia, California Department of Corrections and Rehabilitation, City of Chicago, Macquarie Telecom, Sutherland Global Services, Texas Tech University Health Sciences Center, United Automotive Electronic Systems
Find out what your peers are saying about Cisco Secure Network Analytics vs. Trellix Intrusion Prevention System and other solutions. Updated: January 2020.
866,956 professionals have used our research since 2012.