Try our new research platform with insights from 80,000+ expert users

Cisco Secure Network Analytics vs Trellix Intrusion Prevention System comparison

 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Cisco Secure Network Analytics
Average Rating
8.2
Reviews Sentiment
6.9
Number of Reviews
61
Ranking in other categories
Network Monitoring Software (31st), Network Traffic Analysis (NTA) (4th), Network Detection and Response (NDR) (8th), Cisco Security Portfolio (8th)
Trellix Intrusion Preventio...
Average Rating
8.4
Reviews Sentiment
7.1
Number of Reviews
14
Ranking in other categories
Intrusion Detection and Prevention Software (IDPS) (13th)
 

Mindshare comparison

While both are Network Security Systems solutions, they serve different purposes. Cisco Secure Network Analytics is designed for Network Monitoring Software and holds a mindshare of 1.2%, down 1.6% compared to last year.
Trellix Intrusion Prevention System, on the other hand, focuses on Intrusion Detection and Prevention Software (IDPS), holds 3.5% mindshare, up 3.0% since last year.
Network Monitoring Software
Intrusion Detection and Prevention Software (IDPS)
 

Featured Reviews

Muhammad Harun-Owr-Roshid - PeerSpot reviewer
Have streamlined network visibility and troubleshooting while seeing benefits from AI integration
In terms of improvements for Cisco Secure Network Analytics, from the implementation point of view, now that AI is in use, some other features need to be upgraded considering AI solutions. Proper management of the database is also important; it should be centralized for easier data collection from a single database. When precise manual analysis is needed, it's sometimes difficult, so having a centralized database will allow network admins to find actual scenarios more effectively, especially since some information may not be visible on the GUI. Cisco should upgrade their hardware part to run the database, because sometimes it cannot handle the load while all features are running in the network. The database management should indeed be centralized because while AI runs behind the systems, central management is essential. For example, in a network with 100 Cisco switches, a few routers, firewalls, and access points, all data generated should be preserved in a central database. This approach simplifies management and analysis for troubleshooting, as GUI interfaces may not always provide visible information. Centralizing the database will allow for better understanding of which information is preserved for each specific device.
Juan Muriel - PeerSpot reviewer
Protects from attacks in real-time and provides accurate threat intelligence updates
I rate the ease of setup a seven or eight out of ten. The platform functions very well. We need technical support to make improvements to the platform. The deployment takes eight months. We need two or three system engineers and one electronic engineer specialized in Trellix platforms to deploy the tool. We need only one system engineer to maintain the product.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"The most valuable features provided by this solution are visibility and information."
"The most valuable features are encrypted threat analysis and the ability to run jobs on entire flows."
"Overall, the implementation is very good."
"Ease of deployment, once you get your ducks in a row."
"The most valuable feature is its alerts and dashboard."
"The most valuable feature is integration."
"The most valuable feature of the solution is that it helps you gain visibility for your application."
"The artifacts available in the tool provide better information for analyzing network traffic. It enables a holistic view of network traffic and general packet analysis. It's easy to identify anomalies without the use of signatures. The way in which we implemented Stealthwatch Cloud has enabled my team to analyze traffic behind proxies."
"The most valuable features of the solution stem from the fact that it is a good product for dealing with DDoS attacks and for the inspection of network traffic."
"The solution can scale."
"The product is worth the investment."
"Great monitoring feature."
"The most valuable features are the customization of the signature and the unlimited amount of signatures in IPS."
"The threat intelligence updates are very accurate."
"It has a lot of functions, such as firewall. We are administrators, and we create some rules to protect our network. We also monitor the traffic in and out and have disk encryption on-premises. When we detect malware, we scan for the virus on the PC. We can then delete or block the malware."
"The feature I found most valuable is the network threat analyzer in the security platform. It also integrates with GTI, or Global Threat Intelligence. Otherwise, I just use the basic features."
 

Cons

"We haven't seen ROI."
"I would like to see a hybrid solution that can work without being connected directly to the internet for those destinations."
"Initially, I felt Cisco Secure Network Analytics lacked integration with Splunk."
"The visualization could be improved, the GUI is not the best."
"The reporting of day-to-day metrics still has room for improvement."
"The ability to be natively integrated into Port Aggregator would be beneficial because it would reduce just one more component that's needed in order to have that type of view."
"It's not great as a standalone solution."
"It hasn't really improved our direct detection rate but it has definitely reduced our incident response time as we wouldn't have been able to detect threats or immediate risks without this solution."
"The Network Security Managers could be more stable, agile, and work faster. When it comes to instability, there is room for improvement."
"The management console needs to be less complex and easier to navigate."
"The technical support must be improved."
"The area of concern where the tool needs improvement is how the product prompts users at a network level that helps prevent any wireless network attacks through alerts and notifications."
"Some of the documentation is not as straightforward as it could be."
"The solution could improve some aspects of detection."
"The management component could be simplified."
"The solution needs to improve the graphical interface. And they had a limitation in some of the sensor modems as well."
 

Pricing and Cost Advice

"On a yearly basis, licensing is somewhere around $30,000."
"Today, we are part of the big Cisco ELA, and it is a la carte. We can get orders for whatever we want. At the end of the day, we have to pay for it in one big expense, but that is fine. We are okay with that."
"​Licensing is done by flows per second, not including outside (in traffic)."
"It has a subscription model. There is yearly support, and there is also three-year support. It depends on what the customers want."
"Pricing is much higher compared to other solutions."
"The solution is expensive. It costs several hundred thousand dollars per year (depending on how many flows you are collecting)."
"NetFlow is very expensive."
"Licensing is on a yearly basis."
"The tool is competitively priced."
"I rate the product’s pricing an eight out of ten."
report
Use our free recommendation engine to learn which Network Monitoring Software solutions are best for your needs.
855,347 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Computer Software Company
26%
Financial Services Firm
11%
Government
9%
Manufacturing Company
7%
Financial Services Firm
13%
Computer Software Company
11%
Manufacturing Company
10%
Comms Service Provider
8%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

What do you like most about Cisco Stealthwatch?
The most valuable feature of Cisco Secure Network Analytics is the Threat Intelligence integration.
What is your experience regarding pricing and costs for Cisco Stealthwatch?
The organization experienced challenges with licensing as Cisco has multiple licensing factors, and there are concerns about the price. Cisco solutions are considered to be very expensive.
What needs improvement with Cisco Stealthwatch?
Improvements are needed on the application layer for complete security analysis. The solution should have the ability to analyze security events not only at the network layer but also at the applic...
What do you like most about McAfee Network Security Platform?
The threat intelligence updates are very accurate.
What is your experience regarding pricing and costs for McAfee Network Security Platform?
The tool is competitively priced. I rate the pricing a six out of ten.
What needs improvement with McAfee Network Security Platform?
Network Threat Behavior Analysis must be improved. The technical support must be improved. The support team must provide better help with configurations of devices and enabling NTBA.
 

Also Known As

Cisco Stealthwatch, Cisco Stealthwatch Enterprise, Lancope StealthWatch
McAfee Network Security Platform, McAfee NSP, IntruShield Network Intrusion Prevention System, IntruShield Network IPS
 

Overview

 

Sample Customers

Edge Web Hosting, Telenor Norway, Ivy Tech Community College of Indiana, Webster Financial Corporation, Westinghouse Electric, VMware, TIAA-CREF
Desjardins Group, HollyFrontier, Nubia, Agbar, WNS Global Services, INAIL, Universidad de Las Américas Puebla (UDLAP), Cook County, China Pacific Insurance, Bank Central Asia, California Department of Corrections and Rehabilitation, City of Chicago, Macquarie Telecom, Sutherland Global Services, Texas Tech University Health Sciences Center, United Automotive Electronic Systems
Find out what your peers are saying about Cisco Secure Network Analytics vs. Trellix Intrusion Prevention System and other solutions. Updated: January 2020.
855,347 professionals have used our research since 2012.