Try our new research platform with insights from 80,000+ expert users

Cisco Secure Network Analytics vs NetWitness Platform vs Zabbix comparison

 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Mindshare comparison

Network Monitoring Software
Log Management
Network Monitoring Software
 

Featured Reviews

Sudhakar T - PeerSpot reviewer
Strong network security analytics with excellent encrypted traffic analysis features
Improvements are needed on the application layer for complete security analysis. The solution should have the ability to analyze security events not only at the network layer but also at the application and OS layers. There's a need for a more comprehensive licensing model where all necessary licenses are included by default.
MdZaman - PeerSpot reviewer
Really scalable for enterprise customers
The solution should have more integration capabilities with different platforms. The API is nearly open and scalable, so the solution can integrate with many platforms. The solution has more than 200 log sources in the scalability to support, but this is its limit. Installation is pretty easy. However, there are a couple of modules involved, so it is not as easy as it could be. We are talking about a distributed module, not a single-module type. This is what makes things a bit complex, instead of easier. I rate it as a seven out of ten on its installation and configuration capabilities.
ASM Naushad Alam - PeerSpot reviewer
Allows any number of customizations but lacks functionality for finding root causes
We have not yet purchased the commercial version so have a lack of technical ability. We do not yet fully know the key points or key features of the solution. We just use what we use along with WhatsUp Gold. Based on our use only, stability is rated a seven out of ten.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"Stability is the most valuable feature we have seen in this solution."
"It's easy to set up. The deployment takes one or two days. You need to collect the data from a device and then direct it to the portal."
"The most valuable feature is integration."
"The most valuable features include encrypted traffic analytics and the ability to fulfill requirements at the network level."
"From a security standpoint, it is just seeing pockets as well. Visibility is very key for us."
"The ability to send data flow from other places and have them all in one place is very valuable for us."
"The beginning of any security investigation starts with net flow data."
"Cisco products are incredibly stable, boasting a 200% stability."
"The most valuable feature of RSA NetWitness Logs and Packets are the alerts and correlations tools."
"Their technical support responds quickly and are knowledgable."
"Offers a good wireless feature."
"The most valuable features are the packet decoder, log decoder, and concentrator."
"The product has a user-friendly interface and a valuable feature for threat intelligence integration."
"The most valuable features are the threat prediction and network forensics."
"In my opinion, the solution's most valuable feature is its capacity to monitor network traffic, logs from devices within the network, and network captures. This capability extends beyond logs to include full network capturing."
"NetWitness Platform offers flexibility for deployment and robust integration capabilities."
"The most valuable feature is that it provides network segregation for server monitoring."
"The integration capabilities and APIs are the best part."
"Zabbix helps to save time."
"Zabbix is very easy to implement."
"The most valuable features are the monitoring and the ease with which we can set it up at customer sites with our custom Zabbix proxy and tools."
"We have found that Zabbix is more easy to use than other applications."
"The most valuable feature is the alert and alarm monitoring."
"We are able to monitor our virtual infrastructure, virtual machines, windows servers, databases, and the network using a simple network management protocol. We are able to pull almost all the metrics that we want, receive notifications, and have them integrate with telegrams for certain devices that are critical, such as UPSs."
 

Cons

"One update that I would like to see is an agent-based client. Currently, Stealthwatch is network-based. A local agent could help manage endpoints."
"It would be better to let people know, up front, that is doesn't give you nice, clear information, as seen in the demos, without Cisco ISE installed."
"One thing I would like to see improved is if it could automatically be tied through ISE, instead of you having to manually get notifications and disable it yourself."
"The usability of this solution needs to be improved."
"Many of these tools require extensive on-premises hardware to run."
"There's a lot of traffic on our network that we don't see sometimes."
"It's too complicated to install, when starting out."
"I think the interface is a little lacking. The interface seems like it just needs to be modernized. It's been the same interface now, ever since I've seen it probably four years ago."
"The log system is a bit complex and has room for improvement."
"I believe that integrating the solution with other products such as Oracle would be beneficial."
"The multi-tenant capabilities are lagging compared to IBM QRadar."
"Nowadays, their support is a little subpar compared to other solutions. I rate RSA support six out of 10."
"There is no support for this product in this country, so problems have to be resolved through global technical teams."
"The system architecture is complex and sometimes it’s hard to troubleshoot potential problems."
"The initial setup was complex because it takes a lot of time to complete the implementation."
"Technical support could be improved."
"Zabbix isn't very good at automation just yet."
"The APM monitoring has room for improvement, although I hear that the new 5.2 version has some improvements in that area, and I'd like to give that a go. I would like to see a few more templates out there for different styles of monitoring. I use the Grafana interface for reporting. I would also like it to have an out-of-the-box ability to email reports. You can create reports, but to be able to email those reports would be really helpful. I've got users who are not interested in logging in and generating a report. They want it all pre-canned and sent to an email address. It would also be really handy if we could pin certain reports up onto platforms such as Teams or SharePoint. A GUI for the proxy server would be cool to have for debugging purposes and for the support teams to have a look at, but I don't know whether that's really feasible to do. I get enough from the log files themselves."
"There are not too much documentation or manuals. We found the tutorials very easy to understand but do not go deep enough in the use of Zabbix. We need more manuals, proper use, documentation, etc."
"The only issue we have had with Zabbix is when we decided to make an update or upgrade."
"The main problem with Zabbix is that you have to spend time writing templates for all of the products that you have."
"Outside of the normal standard monitoring, I would like to extend patching, importing patching, and supporting patching for Windows Servers."
"Zabbix claims that there is an auto-discovery process but my team member was facing difficulty and was told that it's not really automatic, and there are some manual steps."
"In the next release, I'm hoping for features targeted towards larger users with more customizable options. Despite this, I think pre-canned reports that can be used straight out of the box would be beneficial rather than having to configure each report individually. Additionally, a deeper dive into software configurations on the machines would be useful, although I understand there may be challenges in implementing this due to scripting requirements. More documentation would also be appreciated."
 

Pricing and Cost Advice

"​Licensing is done by flows per second, not including outside (in traffic)."
"Licensing is on a yearly basis."
"Pricing is much higher compared to other solutions."
"It is worth the cost."
"There are additional licenses needed for the number of so-called network flows. It's hard to plan the number of flows you need in the network, this is a problem. The price of the Cisco Stealthwatch is relatively inexpensive"
"Licensing is done by flows per second, not including outside>in traffic."
"We pay for support costs on a yearly basis."
"On a yearly basis, licensing is somewhere around $30,000."
"The tool is very expensive, so I rate the pricing a ten out of ten. The solution has an annual subscription."
"Compared to the competition, the is price is not that high."
"The product price was reasonable for my region and the market."
"We have yearly licensing costs. The license fee can be based on the volume of EPS. Some organizations may have, as a gentlemanly gesture, 10,000 EPS and get a 3,000 EPS license but actually use 5,000 EPS."
"The product is expensive."
"RSA NetWitness Logs and Packets do not have a subscription model, it's a one-time purchase. There is only a perpetual license."
"The new pricing and licensing mechanisms are fair. I would advise always to get the full solution (i.e., not only Logs)."
"There is a licensing fee and the customer can choose whether he wishes this to be subscription-based or perpetual."
"Zabbix is free but if you use it in production then you have to pay for it."
"It's an open-source solution that can be used free of charge."
"We use the open-source version of Zabbix."
"If you have 20,000 hosts, the support costs around €95,000 for a year."
"This is an open-source solution that can be used free of charge."
"I use the tool's free version."
"It is open source. If you want to have a subscription or official support, you can pay for it. They have different plans, which are not that expensive. The plans are based on per monitoring server, not per monitored equipment. So, it is not at all expensive, and you can also live without the support if you want a cheaper option."
"It's free software released under the GNU/GPL license."
report
Use our free recommendation engine to learn which Network Monitoring Software solutions are best for your needs.
850,491 professionals have used our research since 2012.
 

Comparison Review

it_user174738 - PeerSpot reviewer
May 31, 2015
Nagios vs. Zabbix vs. PRTG vs. Spiceworks vs. Solarwinds Network Performance Monitor
I have researched a quite a few network monitoring tools which can be used for various monitoring purposes of not only the servers, but the intermediate routers as well. There are majorly three types of these softwares. Ones which are completely open-source, you can do almost anything you want…
 

Top Industries

By visitors reading reviews
Computer Software Company
28%
Financial Services Firm
11%
Government
9%
Manufacturing Company
7%
Computer Software Company
18%
Financial Services Firm
18%
Government
6%
Insurance Company
6%
Educational Organization
32%
Computer Software Company
12%
Financial Services Firm
7%
Manufacturing Company
6%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

What do you like most about Cisco Stealthwatch?
The most valuable feature of Cisco Secure Network Analytics is the Threat Intelligence integration.
What is your experience regarding pricing and costs for Cisco Stealthwatch?
The organization experienced challenges with licensing as Cisco has multiple licensing factors, and there are concern...
What needs improvement with Cisco Stealthwatch?
Improvements are needed on the application layer for complete security analysis. The solution should have the ability...
What do you like most about NetWitness Platform?
The product's initial setup phase was not at all difficult.
What is your experience regarding pricing and costs for NetWitness Platform?
The pricing is comparable to others, and I consider the cost to be intermediate. Specific cost details are unknown to...
What needs improvement with NetWitness Platform?
There is currently no need for improvement in the SIEM ( /categories/security-information-and-event-management-siem )...
What do you like most about Zabbix?
The template system in Zabbix is very beneficial as it saves time in configuration.
What needs improvement with Zabbix?
For me, Zabbix is very straightforward. I cannot think of any improvements needed. It's a very mature product. The on...
 

Also Known As

Cisco Stealthwatch, Cisco Stealthwatch Enterprise, Lancope StealthWatch
RSA Security Analytics
No data available
 

Overview

 

Sample Customers

Edge Web Hosting, Telenor Norway, Ivy Tech Community College of Indiana, Webster Financial Corporation, Westinghouse Electric, VMware, TIAA-CREF
Los Angeles World Airports, Reply
1. IBM 2. Dell 3. Cisco 4. HP 5. Oracle 6. Microsoft 7. Amazon 8. Google 9. Facebook 10. Twitter 11. LinkedIn 12. Netflix 13. Adobe 14. VMware 15. Salesforce 16. SAP 17. Intel 18. AT&T 19. Verizon 20. T-Mobile 21. Vodafone 22. Ericsson 23. Nokia 24. Siemens 25. General Electric 26. Honeywell 27. Philips 28. Sony 29. Samsung 30. LG 31. Panasonic 32. Toshiba
Find out what your peers are saying about Zabbix, Auvik, Datadog and others in Network Monitoring Software. Updated: April 2025.
850,491 professionals have used our research since 2012.