No more typing reviews! Try our Samantha, our new voice AI agent.

Cisco Secure Network Analytics vs NetWitness NDR comparison

 

Comparison Buyer's Guide

Executive SummaryUpdated on Nov 6, 2024

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

ROI

Sentiment score
6.7
Cisco Secure Network Analytics improves visibility and detection, aiding IT collaboration; value varies by environment and enhances security posture.
Sentiment score
8.0
Implementing NetWitness NDR enhances security, improves network visibility, reduces costs, and boosts efficiency and productivity for businesses.
 

Customer Service

Sentiment score
6.1
Cisco Secure Network Analytics receives praise for its knowledgeable international support, despite occasional challenges with local expertise.
Sentiment score
7.3
NetWitness NDR's customer service is generally efficient and highly regarded, though some users report occasional slow response times.
There is a lack of adequate local support from the Indian side.
Group Head at Stpi
For technical support of Cisco, the support they provide depends on how the client procures it, and so far, it's understandable.
CEO at BRIGHT-i SYSTEMS LIMITED
 

Scalability Issues

Sentiment score
6.3
Cisco Secure Network Analytics scales well for enterprises, though high costs and outdated hardware can limit effectiveness.
Sentiment score
7.0
NetWitness NDR is scalable for large enterprises, though some users report issues with scalability and agent migration.
The scope of the load balancing work was a team effort where we used three tools for load balancing.
Senior Developer at Atlas Laboratory
 

Stability Issues

Sentiment score
8.3
Cisco Secure Network Analytics is praised for stability, minimal downtime, and reliability despite initial setup challenges and infrastructure complexity.
Sentiment score
7.7
NetWitness NDR is generally reliable, providing real-time data and stability, though minor technical issues are occasionally reported.
Cisco products are incredibly stable, boasting a 200% stability.
Group Head at Stpi
Once resolved, the system works well, and overall I think it's good.
CEO at BRIGHT-i SYSTEMS LIMITED
 

Room For Improvement

Cisco Secure Network Analytics needs better integration, user interface, AI features, and simplified setup with improved training and database management.
NetWitness NDR requires improvements in UI, scalability, detectability, integration, session times, pricing, training, and features, making it complex and slow.
The solution should have the ability to analyze security events not only at the network layer but also at the application and OS layers.
Group Head at Stpi
Proper management of the database is also important; it should be centralized for easier data collection from a single database.
CEO at BRIGHT-i SYSTEMS LIMITED
Advanced reporting and scheduled compliance reports look very attractive for audit and compliance teams at implementation time and can generate structured reports for visibility, risk posture, and traffic summaries.
Cyber Security Trainee at DataSpace Academy
 

Setup Cost

Cisco Secure Network Analytics is costly with complex licensing, though valued for features; pricing strategy adjustments are suggested.
Cisco solutions are considered to be very expensive.
Group Head at Stpi
Regarding cost, for the Bangladesh context, Cisco Secure Network Analytics is a little bit high-priced because we are a developing country, making it tough to manage affordable solutions.
CEO at BRIGHT-i SYSTEMS LIMITED
 

Valuable Features

Cisco Secure Network Analytics offers comprehensive visibility and enhanced threat detection, improving security and reducing investigation times effectively.
NetWitness NDR offers high detection rates, real-time malware response, third-party integration, and a user-friendly, interoperable interface with advanced analytics.
Network-wide flow visibility is the foundation of the platform.
Cyber Security Trainee at DataSpace Academy
The most valuable features include encrypted traffic analytics and the ability to fulfill requirements at the network level.
Group Head at Stpi
The best feature of Cisco Secure Network Analytics is its reliability, which I find to be the one that gets used the most.
Senior Developer at Atlas Laboratory
 

Categories and Ranking

Cisco Secure Network Analytics
Ranking in Network Detection and Response (NDR)
5th
Average Rating
8.2
Reviews Sentiment
6.6
Number of Reviews
63
Ranking in other categories
Network Monitoring Software (33rd), Network Traffic Analysis (NTA) (3rd), Cisco Security Portfolio (7th)
NetWitness NDR
Ranking in Network Detection and Response (NDR)
19th
Average Rating
8.0
Reviews Sentiment
6.9
Number of Reviews
15
Ranking in other categories
Endpoint Protection Platform (EPP) (48th), Threat Intelligence Platforms (TIP) (34th), Endpoint Detection and Response (EDR) (58th), Security Orchestration Automation and Response (SOAR) (23rd), Extended Detection and Response (XDR) (39th)
 

Mindshare comparison

As of June 2026, in the Network Detection and Response (NDR) category, the mindshare of Cisco Secure Network Analytics is 5.8%, down from 7.2% compared to the previous year. The mindshare of NetWitness NDR is 3.4%, up from 2.2% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Network Detection and Response (NDR) Mindshare Distribution
ProductMindshare (%)
Cisco Secure Network Analytics5.8%
NetWitness NDR3.4%
Other90.8%
Network Detection and Response (NDR)
 

Featured Reviews

Akash Das Barman - PeerSpot reviewer
Cyber Security Trainee at DataSpace Academy
Network analytics has reduced investigation time and provides deeper visibility into lateral movement
Several features often look very promising during evaluation or implementation but end up being used only lightly in day-to-day operations. Advanced reporting and scheduled compliance reports look very attractive for audit and compliance teams at implementation time and can generate structured reports for visibility, risk posture, and traffic summaries. In practice, many teams do not rely on it heavily because SIEM tools or GRC platforms already handle reporting better. Built-in threat intelligence feeds represent another area where expectations do not always match usage. The platform includes threat intelligence-based detection and classifications. Initially, teams expect to depend on this heavily, but later SOC teams often prefer their own threat intelligence feeds or correlate intelligence inside SIEM instead. The built-in feeds are used but not as a primary detection source. Automated incident summaries and guided investigation views are designed to simplify triage by automatically grouping related activity into incidents. However, teams often move away from them due to various factors affecting adoption.
reviewer1799727 - PeerSpot reviewer
Manager, IT Security Operations at a non-profit with 11-50 employees
Reliable and good support but can be expensive
I have no real complaints about the solution. Threat detection could be better. They need to enhance their threat intelligence feeds. We would like to have more IOCs or more trade intelligence to not only rely on the intelligence of the engineer in charge but to have some threat intelligence and some seeds of IOCs and to have the host have some artificial intelligence to reduce the number of false positives. I don't see this solution being very scalable. The solution is pricey.
report
Use our free recommendation engine to learn which Network Detection and Response (NDR) solutions are best for your needs.
902,270 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Financial Services Firm
11%
Manufacturing Company
10%
Government
8%
Construction Company
8%
Financial Services Firm
13%
Manufacturing Company
9%
Construction Company
8%
Computer Software Company
8%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business12
Midsize Enterprise7
Large Enterprise52
By reviewers
Company SizeCount
Small Business10
Midsize Enterprise2
Large Enterprise6
 

Questions from the Community

What is your experience regarding pricing and costs for Cisco Stealthwatch?
Regarding cost, for the Bangladesh context, Cisco Secure Network Analytics is a little bit high-priced because we are a developing country, making it tough to manage affordable solutions. However, ...
What needs improvement with Cisco Stealthwatch?
Several features often look very promising during evaluation or implementation but end up being used only lightly in day-to-day operations. Advanced reporting and scheduled compliance reports look ...
What is your primary use case for Cisco Stealthwatch?
My main use case for Cisco Secure Network Analytics has been network visibility and anomaly-based threat detection within the enterprise environment. In security operations and VAPT-related activit...
Ask a question
Earn 20 points
 

Also Known As

Cisco Stealthwatch, Cisco Stealthwatch Enterprise, Lancope StealthWatch
RSA ECAT, NetWitness Network
 

Overview

 

Sample Customers

Edge Web Hosting, Telenor Norway, Ivy Tech Community College of Indiana, Webster Financial Corporation, Westinghouse Electric, VMware, TIAA-CREF
ADP, Ameritas, Partners Healthcare
Find out what your peers are saying about Cisco Secure Network Analytics vs. NetWitness NDR and other solutions. Updated: June 2026.
902,270 professionals have used our research since 2012.