No more typing reviews! Try our Samantha, our new voice AI agent.

Cisco Secure Network Analytics vs NetMon comparison

 

Comparison Buyer's Guide

Executive SummaryUpdated on Feb 1, 2026

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Cisco Secure Network Analytics
Ranking in Network Monitoring Software
33rd
Average Rating
8.2
Reviews Sentiment
6.6
Number of Reviews
63
Ranking in other categories
Network Traffic Analysis (NTA) (3rd), Network Detection and Response (NDR) (5th), Cisco Security Portfolio (7th)
NetMon
Ranking in Network Monitoring Software
55th
Average Rating
7.6
Reviews Sentiment
6.1
Number of Reviews
12
Ranking in other categories
Identity Threat Detection and Response (ITDR) (13th)
 

Mindshare comparison

As of June 2026, in the Network Monitoring Software category, the mindshare of Cisco Secure Network Analytics is 0.9%, down from 1.2% compared to the previous year. The mindshare of NetMon is 0.6%, up from 0.3% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Network Monitoring Software Mindshare Distribution
ProductMindshare (%)
Cisco Secure Network Analytics0.9%
NetMon0.6%
Other98.5%
Network Monitoring Software
 

Featured Reviews

Akash Das Barman - PeerSpot reviewer
Cyber Security Trainee at DataSpace Academy
Network analytics has reduced investigation time and provides deeper visibility into lateral movement
Several features often look very promising during evaluation or implementation but end up being used only lightly in day-to-day operations. Advanced reporting and scheduled compliance reports look very attractive for audit and compliance teams at implementation time and can generate structured reports for visibility, risk posture, and traffic summaries. In practice, many teams do not rely on it heavily because SIEM tools or GRC platforms already handle reporting better. Built-in threat intelligence feeds represent another area where expectations do not always match usage. The platform includes threat intelligence-based detection and classifications. Initially, teams expect to depend on this heavily, but later SOC teams often prefer their own threat intelligence feeds or correlate intelligence inside SIEM instead. The built-in feeds are used but not as a primary detection source. Automated incident summaries and guided investigation views are designed to simplify triage by automatically grouping related activity into incidents. However, teams often move away from them due to various factors affecting adoption.
SR
Pan India IT Infrastructure Management / End-user Services at Tata Group
Has supported real-time event detection and reporting accuracy while database integration has required extra effort
Sometimes it may be difficult to incorporate new additional databases in NetMon, and we faced some challenges at that time. However, currently, it is not giving many challenges.It is difficult to integrate NetMon with other databases. We can customize NetMon's monitoring views, but it is done by the team who handles it, as it is outsourced.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"The most valuable feature about this solution is that it gives me insight of my network."
"The deployment was a breeze. It is a very innovative and robust platform that allows us to bi-directionally stitch together data elements from Netflow-enabled devices to provide a context for network utilization."
"The most valuable feature of the solution is that it helps you gain visibility for your application."
"Cisco Stealthwatch has improved our organization's analytics and threat protection capabilities by catching threats early on and it saved us a net fortune when we caught an employee constantly pulling three or four GBs of data from an FTP server."
"This solution has increased our threat detection rate by forty to sixty percent."
"The artifacts available in the tool provide better information for analyzing network traffic. It enables a holistic view of network traffic and general packet analysis. It's easy to identify anomalies without the use of signatures. The way in which we implemented Stealthwatch Cloud has enabled my team to analyze traffic behind proxies."
"The fact that it can identify down to an IP address of a system that is causing problems, or potentially causing problems, is very valuable."
"The most valuable feature of Cisco Secure Network Analytics is the Threat Intelligence integration."
"But just having it there, it's incredibly smart, incredibly easy to use, and the breadth of information we get off it is really good for investigations for us."
"It is a stable solution...It is a scalable solution."
"The initial setup is straightforward because we can deploy an open server."
"We were sold on the product based on the fairly narrow use cases that the sales reps gave us, and what we're seeing during our usage is that we can get there, and we're very excited about the potential."
"It has a very strong artificial intelligence engine."
"We are using NetMon's real-time traffic analysis regularly with a team of four members who effectively monitor all alerts and events, which has helped them identify whether there could be a severe incident."
"LogRhythm NetMon's most impressive feature is that it's a bundled package, so you're not just relying on monthly data; you get a six-month view for more comprehensive indicators of compromise. This dual approach is precious. We implement LogRhythm NetMon in our cybersecurity strategy mainly for compliance and correlation of network, user, and decision activities, particularly for network firewalls and access control."
"The protocols with which you see the traffic for a particular website that a client has in their environment, for example, are valuable. We can monitor whether the traffic is up to the mark or whether they need to add more bandwidth. Also, we can see if we're able to get real-time environment data as well. The customization dashboard is really good. LogRhythm NetMon has its own in-built dashboards which are helpful in guiding customization."
 

Cons

"It hasn't really improved our direct detection rate but it has definitely reduced our incident response time as we wouldn't have been able to detect threats or immediate risks without this solution."
"We would like the solution to make more advances in the way that Extreme Networks has been doing."
"If they can make this product more web-based, that would be amazing."
"The customizability of the UI should improve."
"Some of our customers find this solution to be a little bit tough because they don't understand how to configure and use it."
"The visualization could be improved, the GUI is not the best."
"It's a good solid solution but integration with Network Access Control products with Cisco ISE would be good."
"Many of these tools require extensive on-premises hardware to run."
"One thing that surprised me was the current version of LogRhythm does not natively support Windows 2016."
"Could use a topology diagram which would help get an exact visual."
"There is an issue with tunneling in relation to how the connectivity is established between the end devices and where NetMon is installed. On the console, I often observe that there's a difference of a few seconds or maybe a minute, and this lag time should not be there."
"I would like to see better integration with multiple products. Integration is not something that is readily available for most of the products."
"Their technical support isn't so great."
"The main concern is that LogRhythm has not improved NetMon but instead introduced a separate product, which many customers, including us, would prefer to be integrated into a single platform for easier management."
"The training for this product is not very good and needs to be improved."
"Sometimes it's hard to find the network devices' self-audit logs."
 

Pricing and Cost Advice

"Licensing is done by flows per second, not including outside>in traffic."
"The solution is expensive. It costs several hundred thousand dollars per year (depending on how many flows you are collecting)."
"The tool is not cheaply priced."
"Today, we are part of the big Cisco ELA, and it is a la carte. We can get orders for whatever we want. At the end of the day, we have to pay for it in one big expense, but that is fine. We are okay with that."
"On a yearly basis, licensing is somewhere around $30,000."
"Our fees are approximately $3,000 USD."
"The yearly licensing cost is about $50,000."
"There are additional licenses needed for the number of so-called network flows. It's hard to plan the number of flows you need in the network, this is a problem. The price of the Cisco Stealthwatch is relatively inexpensive"
"The price of this solution is too high, so it should be made more practical and more valuable for the customer."
"The product is expensive for smaller companies."
"Pricing is okay. There were some competitors that were extremely expensive and there were some which were really inexpensive but LogRhythm stayed in the middle of them."
"I don't have visibility into the pricing of LogRhythm NetMon as it's handled through our commercial partnerships."
"NetMon's licensing costs about $85k per year, with some extra costs for support."
"LogRhythm's licensing part is something that depends on the license you want since they offer it on a perpetual and subscription basis."
report
Use our free recommendation engine to learn which Network Monitoring Software solutions are best for your needs.
900,644 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Financial Services Firm
11%
Manufacturing Company
10%
Government
8%
Construction Company
8%
Financial Services Firm
12%
Transportation Company
12%
Construction Company
11%
Comms Service Provider
10%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business12
Midsize Enterprise7
Large Enterprise52
By reviewers
Company SizeCount
Small Business2
Midsize Enterprise2
Large Enterprise7
 

Questions from the Community

What is your experience regarding pricing and costs for Cisco Stealthwatch?
Regarding cost, for the Bangladesh context, Cisco Secure Network Analytics is a little bit high-priced because we are a developing country, making it tough to manage affordable solutions. However, ...
What needs improvement with Cisco Stealthwatch?
Several features often look very promising during evaluation or implementation but end up being used only lightly in day-to-day operations. Advanced reporting and scheduled compliance reports look ...
What is your primary use case for Cisco Stealthwatch?
My main use case for Cisco Secure Network Analytics has been network visibility and anomaly-based threat detection within the enterprise environment. In security operations and VAPT-related activit...
What needs improvement with LogRhythm NetMon?
Sometimes it may be difficult to incorporate new additional databases in NetMon, and we faced some challenges at that time. However, currently, it is not giving many challenges.It is difficult to i...
What is your primary use case for LogRhythm NetMon?
We have outsourced our SIEM solutions at the moment, and we are using it.We have been using LogRhythm in our organization as a SaaS offering. We have outsourced it as part of the actual scope where...
What advice do you have for others considering LogRhythm NetMon?
We use AWS as our cloud provider in a private cloud environment.It completely depends upon when incidents happen. To find the root cause analysis, we need to first gather the logs from the team. It...
 

Also Known As

Cisco Stealthwatch, Cisco Stealthwatch Enterprise, Lancope StealthWatch
LogRhythm Network Monitor
 

Overview

 

Sample Customers

Edge Web Hosting, Telenor Norway, Ivy Tech Community College of Indiana, Webster Financial Corporation, Westinghouse Electric, VMware, TIAA-CREF
Sera-Brynn
Find out what your peers are saying about Cisco Secure Network Analytics vs. NetMon and other solutions. Updated: June 2026.
900,644 professionals have used our research since 2012.