No more typing reviews! Try our Samantha, our new voice AI agent.

Cisco Secure Network Analytics vs NetWitness Platform comparison

Why PeerSpot?
 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Cisco Secure Network Analytics
Average Rating
8.2
Reviews Sentiment
6.6
Number of Reviews
62
Ranking in other categories
Network Monitoring Software (31st), Network Traffic Analysis (NTA) (5th), Network Detection and Response (NDR) (6th), Cisco Security Portfolio (9th)
NetWitness Platform
Average Rating
7.4
Reviews Sentiment
7.4
Number of Reviews
36
Ranking in other categories
Log Management (36th), Security Information and Event Management (SIEM) (34th)
 

Mindshare comparison

Cisco Secure Network Analytics and NetWitness Platform aren’t in the same category and serve different purposes. Cisco Secure Network Analytics is designed for Network Monitoring Software and holds a mindshare of 0.9%, down 1.2% compared to last year.
NetWitness Platform, on the other hand, focuses on Log Management, holds 1.1% mindshare, up 0.4% since last year.
Network Monitoring Software Mindshare Distribution
ProductMindshare (%)
Cisco Secure Network Analytics0.9%
Zabbix3.6%
SolarWinds NPM3.6%
Other91.9%
Network Monitoring Software
Log Management Mindshare Distribution
ProductMindshare (%)
NetWitness Platform1.1%
Splunk Enterprise Security6.8%
IBM Security QRadar4.5%
Other87.6%
Log Management
 

Featured Reviews

Muhammad Harun-Owr-Roshid - PeerSpot reviewer
CEO at BRIGHT-i SYSTEMS LIMITED
Have streamlined network visibility and troubleshooting while seeing benefits from AI integration
In terms of improvements for Cisco Secure Network Analytics, from the implementation point of view, now that AI is in use, some other features need to be upgraded considering AI solutions. Proper management of the database is also important; it should be centralized for easier data collection from a single database. When precise manual analysis is needed, it's sometimes difficult, so having a centralized database will allow network admins to find actual scenarios more effectively, especially since some information may not be visible on the GUI. Cisco should upgrade their hardware part to run the database, because sometimes it cannot handle the load while all features are running in the network. The database management should indeed be centralized because while AI runs behind the systems, central management is essential. For example, in a network with 100 Cisco switches, a few routers, firewalls, and access points, all data generated should be preserved in a central database. This approach simplifies management and analysis for troubleshooting, as GUI interfaces may not always provide visible information. Centralizing the database will allow for better understanding of which information is preserved for each specific device.
reviewer2256927 - PeerSpot reviewer
Head of Information Security, Cyber Defense and IT Risk Management at HCT. at a transportation company with 201-500 employees
A solid SIEM solution that should improve technical support and online resources to be easier to use
A big problem with the product is that we don't have much professional experience in Israel installing, implementing, and integrating this product. There is not enough of a knowledge base. There is no support for this product in this country, so problems have to be resolved through global technical teams. We like to work locally because of the language, and when the product is only supported outside the country, it's a little difficult to implement and use this product. Moreover, AI is something that must be added immediately. Artificial intelligence is a part of the competitors' products, and it's not been implemented for us.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"Stealthwatch has definitely reduced the incident response time, making troubleshooting now only minutes instead of a couple of hours and increasing our threat detection rate by around 25-30%."
"The ROI was immediate for us, in regard to how we implemented it."
"The most valuable features are encrypted threat analysis and the ability to run jobs on entire flows."
"The amount of information that this product gives us for detecting threats is very valuable, and we don't have another product like this in our environment."
"The most valuable feature of this solution is the way the net flow is being merged together in a single pane. That's been extremely useful for us, because can see what's going on with traffic in one single place."
"It has definitely helped us improve our mean time to resolution on network issues."
"The feature most valuable for us is to gain visibility of what is actually floating through, so we can stop it based on whether it's good or bad traffic."
"From what I understand, you can encrypt and unencrypt traffic moving in transit. This is one of the features that we liked about it."
"Since the solution has been under way we have seen a large decrease of threats and proactive reactions to incidents."
"The most valuable feature is that we can create our own connectors for any application, and NetWitness provides the training and tools to do it."
"Their technical support responds quickly and are knowledgable."
"The newer 11.5 version that my team is using has found it to have good mapping."
"The most valuable feature is the ability to write rules and triggers for network communication and then being able to investigate based on that, where you can see the payload and deconstruct the packets."
"NetWitness can be highly beneficial for incident detection and response."
"Setting up NetWitness is straightforward. There are multiple connectors, including standard and specialized connectors. One purpose of the connectors is the enhanced capability integrate the custom applications. NetWitness comes with E6 appliances and application images that we use for the initial configurations and for the OS stack information. From there, you can consider the correlation rules, integrate the different log sources, and easily create correlation rules and backlog reports."
"Over time, NetWitness Logs and Packets has matured from a boxed solution with multiple parts to the current, more streamlined version for which we only need the software license to put it up on our own cloud and deliver it to multiple clients."
 

Cons

"We've had problems with element licensing costs so scalability is a concern."
"The solution should have the ability to analyze security events not only at the network layer but also at the application and OS layers."
"The GUI could use some improvement. Being able to find features more easily would be a great improvement if it was simplified."
"If there was one improvement I’d suggest it would be that it detect traffic through an intranet. The product requires that traffic flow through a managed network device. The product is designed mostly for enterprise environments and not smaller environments or businesses."
"We haven't seen ROI."
"If they can make this product more web-based, that would be amazing."
"I don't really think we really save time while using this solution."
"The interface is sluggish and not updated."
"The product's licensing models are complex to understand. This particular area needs improvement."
"The initial setup is complex. There are other solutions that are easier to implement."
"It is not so easy to customize this product."
"Health monitoring of the event sources and devices."
"Cross Platform Integration could be improved."
"I am not happy with the RSA support. Sometimes they can be really annoying because it takes so long to get the support that you need."
"It should have a monitoring feature. It would help us analyze the current state of attacks faster from a single platform."
"I believe that integrating the solution with other products such as Oracle would be beneficial."
 

Pricing and Cost Advice

"It is worth the cost."
"Licensing is on a yearly basis."
"The pricing for this solution is good."
"Licensing is done by flows per second, not including outside>in traffic."
"One of the things which bugs me about Lancope is the licensing. We understand how licensing works. Our problem is when we bought and purchased most of these Lancope devices, we did so with our sister company. Somewhere within the purchase and distribution, licensing got mixed up. That is all on Cisco, and it is their responsibility. They allotted some of our sister company's equipment to us, and some of our equipment to them. To date, they have never been able to fix it."
"It has a subscription model. There is yearly support, and there is also three-year support. It depends on what the customers want."
"On a yearly basis, licensing is somewhere around $30,000."
"Today, we are part of the big Cisco ELA, and it is a la carte. We can get orders for whatever we want. At the end of the day, we have to pay for it in one big expense, but that is fine. We are okay with that."
"The NetWitness Platform may be affordable only for enterprise-level customers, as it may not be within the budget of small and medium-sized businesses."
"The licenses are good but the cost is very expensive."
"We have a perpetual license, so the total cost of ownership is not very expensive. It's a good investment."
"It provides tools to assist in selecting the appropriate license and usage scenarios."
"This is a pricey solution; it's not cheap."
"The product is expensive."
"The tool is very expensive, so I rate the pricing a ten out of ten. The solution has an annual subscription."
"It is cheap."
report
Use our free recommendation engine to learn which Network Monitoring Software solutions are best for your needs.
913,806 professionals have used our research since 2012.
 

Comparison Review

VS
Manager, Enterprise Risk Consulting at a tech company with 1,001-5,000 employees
Feb 26, 2015
HP ArcSight vs. IBM QRadar vs. ​McAfee Nitro vs. Splunk vs. RSA Security vs. LogRhythm
We at Infosecnirvana.com have done several posts on SIEM. After the Dummies Guide on SIEM, we are following it up with a SIEM Product Comparison – 101 deck. So, here it is for your viewing pleasure. Let me know what you think by posting your comments below. The key products compared here are…
 

Top Industries

By visitors reading reviews
Financial Services Firm
10%
Manufacturing Company
10%
Construction Company
9%
Outsourcing Company
8%
Construction Company
13%
Financial Services Firm
11%
Comms Service Provider
11%
Outsourcing Company
10%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business12
Midsize Enterprise7
Large Enterprise52
By reviewers
Company SizeCount
Small Business8
Midsize Enterprise7
Large Enterprise20
 

Questions from the Community

What is your experience regarding pricing and costs for Cisco Stealthwatch?
Regarding cost, for the Bangladesh context, Cisco Secure Network Analytics is a little bit high-priced because we are a developing country, making it tough to manage affordable solutions. However, ...
What needs improvement with Cisco Stealthwatch?
Several features often look very promising during evaluation or implementation but end up being used only lightly in day-to-day operations. Advanced reporting and scheduled compliance reports look ...
What is your primary use case for Cisco Stealthwatch?
My main use case for Cisco Secure Network Analytics has been network visibility and anomaly-based threat detection within the enterprise environment. In security operations and VAPT-related activit...
What is your experience regarding pricing and costs for NetWitness Platform?
The pricing is comparable to others, and I consider the cost to be intermediate. Specific cost details are unknown to me.
What needs improvement with NetWitness Platform?
There is currently no need for improvement in the SIEM ( /categories/security-information-and-event-management-siem ), though there could be potential enhancements by integrating with AI.
What is your primary use case for NetWitness Platform?
I use NetWitness Platform ( /products/netwitness-platform-reviews ) in the financial industry as a good product with excellent capabilities and integration with various devices.
 

Also Known As

Cisco Stealthwatch, Cisco Stealthwatch Enterprise, Lancope StealthWatch
RSA Security Analytics
 

Overview

 

Sample Customers

Edge Web Hosting, Telenor Norway, Ivy Tech Community College of Indiana, Webster Financial Corporation, Westinghouse Electric, VMware, TIAA-CREF
Los Angeles World Airports, Reply
Find out what your peers are saying about Zabbix, SolarWinds, Datadog and others in Network Monitoring Software. Updated: September 2026.
913,806 professionals have used our research since 2012.