Try our new research platform with insights from 80,000+ expert users

Cisco Sourcefire SNORT vs Plixer Scrutinizer comparison

 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Cisco Sourcefire SNORT
Average Rating
7.8
Reviews Sentiment
6.8
Number of Reviews
20
Ranking in other categories
Intrusion Detection and Prevention Software (IDPS) (15th)
Plixer Scrutinizer
Average Rating
8.6
Reviews Sentiment
6.9
Number of Reviews
15
Ranking in other categories
Network Monitoring Software (72nd), Network Traffic Analysis (NTA) (13th)
 

Mindshare comparison

Cisco Sourcefire SNORT and Plixer Scrutinizer aren’t in the same category and serve different purposes. Cisco Sourcefire SNORT is designed for Intrusion Detection and Prevention Software (IDPS) and holds a mindshare of 3.1%, up 2.2% compared to last year.
Plixer Scrutinizer, on the other hand, focuses on Network Traffic Analysis (NTA), holds 3.7% mindshare, up 2.2% since last year.
Intrusion Detection and Prevention Software (IDPS) Market Share Distribution
ProductMarket Share (%)
Cisco Sourcefire SNORT3.1%
Fortinet FortiGate13.2%
Darktrace11.5%
Other72.2%
Intrusion Detection and Prevention Software (IDPS)
Network Traffic Analysis (NTA) Market Share Distribution
ProductMarket Share (%)
Plixer Scrutinizer3.7%
Darktrace17.9%
Cisco Secure Network Analytics10.5%
Other67.9%
Network Traffic Analysis (NTA)
 

Featured Reviews

reviewer2772102 - PeerSpot reviewer
Cloud Architect at a consultancy with 1-10 employees
Logging and customizable rules have helped improve threat monitoring and detection
The logging is mainly what I consider one of the best features with Cisco Sourcefire SNORT. Being able to log and store it in a file allows you to push it to a centralized repository. The logging and reporting help improve incident response. You should always be logging threats, any sort of misconfiguration, and anything that could be an issue. It's important to at least log and monitor it. The basic rules provide a good baseline in assessing Cisco Sourcefire SNORT's ability in providing real-time analytics for threat detection, but as a professional, you should look to constantly modify that baseline. They provide extensive customizability so you can define your own rules. The customizability allows it to be adaptable in protecting against diverse network threats to the constant change.
Ira Mulyanti - PeerSpot reviewer
Sales Director at ARGA SOLUSI
An affordable product with great integration capabilities
Plixer Core Platform is a valuable feature and a good software. Plixer Scrutinizer uses NetFlow analysis to monitor whatever is there in a network. Price-wise, Plixer Scrutinizer is not an expensive product. Basically, Plixer Scrutinizer is an affordable product. Plixer Scrutinizer is a tool that allows for customization, especially in scenarios where customers need new product features. Plixer Scrutinizer is a tool that can integrate with any other brand or product in the market, so it is not an area of concern.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"The solution is rather easy to use."
"It simplifies the configuration process by offering pre-defined base configurations, including security and connectivity settings."
"The whole solution is very good, and stable."
"The solution is stable."
"It is quite an intelligent product."
"The logging is mainly what I consider one of the best features with Cisco Sourcefire SNORT; being able to log and store it in a file allows you to push it to a centralized repository."
"The most valuable feature is the visibility that we have across the virtual environment."
"The most valuable features of Cisco Sourcefire SNORT are the dashboard for monitoring events."
"We have had many requests to understand in the network which devices are connected to others. Most people don't have this information or are able to establish a map of data flow everywhere around the network. Scrutinizer can really help with this. We are using it to understand who is talking to what, how, and which protocols can help us to improve security and analyze flow."
"It helps us determine what is going on with our Internet and who is hogging it all up. If we get a real high throughput or a throughput that's going over and getting dropped fairly quickly, we can tell who (or what device) is consuming that traffic."
"Plixer Scrutinizer is an affordable product. Plixer Scrutinizer is a tool that allows for customization, especially in scenarios where customers need new product features."
"The reporting and generating troubleshooting reports would be the best feature; our host-to-host conversation reporting."
"Visualization of the network traffic is the most valuable feature. It allows you to drill into information quite quickly."
"One feature I found most valuable in Plixer Scrutinizer is the very extensive reporting. Reporting is very flexible, though sometimes you need a little bit of support from Plixer Scrutinizer to create custom-made reporting in a very short time. Reporting is a very strong feature of the product."
"The most valuable features of Plixer Scrutinizer are its ease of use, accessibility, and UI."
"It's agnostic as far as what your network gear is. As long as it supports an sFlow, JFlow, NetFlow, some kind of flow monitoring, Plixer will support it very well."
 

Cons

"To be frank, the product is not really stable, although they're working on that. Whenever I go to the technical community with an issue, they will usually say that it is not there yet, but the technical team are working on it. The issues are not insolvable. I think they should just keep working on the product to make sure that the product can become very stable. The technical support is great. I appreciate that. We have a lot of communities supporting Firepower now, so you can find help for whatever issue you have."
"The customization of the rules can be simplified."
"If the price is brought down then everybody will be happy."
"The cloud can be improved."
"Performance needs improvement."
"I did not experience any pain points that required improvement. Maybe a couple of false-positives, but that's about it."
"The implementation could be a bit easier."
"While the alerts they offer are good, it could improve it in the sense that they should be more detailed to make the alerts more useful to us in general. Sometimes the solution will offer up false positives. Due to the fact that the alerts aren't detailed, we have to go dig around to see why is it being blocked. The solution would be infinitely better if there was just a bit more detail in the alert information and logging we receive."
"From what I understand it is that the solution is not very scalable in a high volume traffic environment with a large number of flows."
"I wish the reporting side was easier to work with, but it does a decent job. I also wish the reporting side was a little more intuitive or they offered more reporting examples."
"The visual acuity of how it presents data can sometimes be confusing. It takes a bit for people to spin up how to look at the graphs."
"It would be useful if there was a way to back up the configuration information. E.g., if you wanted to deploy a new instance or disaster recovery, you could quite easily deploy and restore the config, as opposed to having to restore all the NetFlow data. If there was just a button that said "backup config information", that would be good."
"The reporting structure, the front-end GUI, also needs some work. It needs some getting used to. It works fairly well, but it's a technical tool rather than a user tool. You have to understand the structure of the databases before you can really use it."
"Data retention needs improvement. Data retention is a thing where we are looking for a better way to collect flow data for a longer time to do forensic research on security incidents. By default, data retention is quite low. We need detailed data in safe storage for a longer time, e.g., for a couple of months. An improvement would be a way to export data into a secure long-term storage."
"There is room for improvement around the data that they have on the website about solutions... they should have more templated solutions on their website. Going out and identifying how to do RTP performance with a Cisco router, or how to do application response times in an Arrista data center deployment was where most of the work was... They should spend some more time documenting solutions and putting together white papers."
"There was a price lift because previously the product was privately owned, and now there is some external capital in the organization, so pricing could be lower, though, for Plixer Scrutinizer, there is almost no competition at this price point."
 

Pricing and Cost Advice

"Licensing for this solution is paid on a yearly basis."
"We have a three-year license for this solution."
"If one is an extremely expensive product, and ten is cheap, I rate the tool's price as a five."
"I don't know the exact amount, but most of the time when I go to a company with a proposition, they will say, "This thing that you are selling is good, but it's expensive. Why don't you propose something like FortiGate, Check Point, or Palo Alto?" Cisco device are expensive compared to other devices."
"The cost is per port and can be expensive but it does include training and support for three years."
"We recently bought a license upgrade, so we will integrate more exporters. We upgraded from a 25 exporter license to a 50 exporter license. Therefore, there will be more flows, and this will be an extension. I don't know when we will purchase a faster server, because the server that we have is quite new."
"We pay our one-off cost for the licenses, per device, in blocks of 50. And then we pay an annual maintenance fee of about $15,000 Australian, which is, at this point in time, about $9,000 US, for those 250 devices. The upfront costs for the 250-license use, were about $50,000 Australian, which is about $32,000 US."
"We have increased the license over time. We have added more licenses as the network has grown."
"There is a recurring maintenance fee after the initial purchase or if we want the license upgrade."
"The license is per device. We have 50 devices."
"Compared to some of the other tools we have, it's incredibly reasonably priced."
"There are no extra costs. It's about $8,000 a year. The bang for the buck (cost) is definitely a plus."
"Our entire solution, amortized over five years, is in the vicinity of $40,000 to $50,000 a year."
report
Use our free recommendation engine to learn which Intrusion Detection and Prevention Software (IDPS) solutions are best for your needs.
881,757 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
University
12%
Financial Services Firm
10%
Comms Service Provider
10%
Government
8%
Financial Services Firm
11%
Government
9%
Manufacturing Company
8%
University
6%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business6
Midsize Enterprise8
Large Enterprise7
By reviewers
Company SizeCount
Small Business4
Midsize Enterprise2
Large Enterprise8
 

Questions from the Community

What do you like most about Cisco Sourcefire SNORT?
The product is inexpensive compared to leading brands such as Palo Alto or Fortinet.
What is your experience regarding pricing and costs for Cisco Sourcefire SNORT?
If one is an extremely expensive product, and ten is cheap, I rate the tool's price as a five. There are some other tools in the market that are more expensive than Cisco. There are no additional c...
What needs improvement with Cisco Sourcefire SNORT?
I have not had much experience with the community-driven rule set while utilizing Cisco Sourcefire SNORT. I don't have experience with recognizing zero-day vulnerabilities, but based on my knowledg...
Ask a question
Earn 20 points
 

Also Known As

Sourcefire SNORT
No data available
 

Overview

 

Sample Customers

CareCore, City of Biel, Dimension Data, LightEdge, Lone Star College System, National Rugby League, Port Aventura, Smart City Networks, Telecom Italia, The Department of Education in Western Australia
Oxford Networks, Squaw Valley Ski Holdings, UltiSat, Wipro, West Aurora School District 129, SUNY Geneseo College, Bloomington Public Schools, First National Bank of Pennsylvania, Kitsap Credit Union, Metropolitan Transit Authority of Harris County Houston Texas, Carilion Clinic, Banner Health, IDEXX Laboratories, Phibro Animal Health Corporation, Goodwill Industries, Parmalat, Armstrong Coal Company, Flybe, James Walker
Find out what your peers are saying about Fortinet, Darktrace, Check Point Software Technologies and others in Intrusion Detection and Prevention Software (IDPS). Updated: January 2026.
881,757 professionals have used our research since 2012.