Try our new research platform with insights from 80,000+ expert users

Cisco Secure Network Analytics vs Darktrace vs IBM Security Network IPS comparison

 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Mindshare comparison

Network Monitoring Software Market Share Distribution
ProductMarket Share (%)
Cisco Secure Network Analytics1.2%
Zabbix11.7%
LibreNMS4.6%
Other82.5%
Network Monitoring Software
Network Detection and Response (NDR) Market Share Distribution
ProductMarket Share (%)
Darktrace22.7%
Vectra AI15.6%
ExtraHop Reveal(x)8.4%
Other53.300000000000004%
Network Detection and Response (NDR)
Intrusion Detection and Prevention Software (IDPS) Market Share Distribution
ProductMarket Share (%)
IBM Security Network IPS0.6%
Fortinet FortiGate17.1%
Darktrace13.7%
Other68.6%
Intrusion Detection and Prevention Software (IDPS)
 

Featured Reviews

Muhammad Harun-Owr-Roshid - PeerSpot reviewer
Have streamlined network visibility and troubleshooting while seeing benefits from AI integration
In terms of improvements for Cisco Secure Network Analytics, from the implementation point of view, now that AI is in use, some other features need to be upgraded considering AI solutions. Proper management of the database is also important; it should be centralized for easier data collection from a single database. When precise manual analysis is needed, it's sometimes difficult, so having a centralized database will allow network admins to find actual scenarios more effectively, especially since some information may not be visible on the GUI. Cisco should upgrade their hardware part to run the database, because sometimes it cannot handle the load while all features are running in the network. The database management should indeed be centralized because while AI runs behind the systems, central management is essential. For example, in a network with 100 Cisco switches, a few routers, firewalls, and access points, all data generated should be preserved in a central database. This approach simplifies management and analysis for troubleshooting, as GUI interfaces may not always provide visible information. Centralizing the database will allow for better understanding of which information is preserved for each specific device.
Malebo Lethoba Group - PeerSpot reviewer
Have found the AI analyst and detection functions highly valuable for network operations while managing complexity in initial setup
The functions I find most valuable in Darktrace are the AI analyst as well as the detection.The autonomous response capabilities of Darktrace are not crucial for me because it doesn't work in a network where there are no core switches. In a modern network, the autonomous response doesn't work, especially when sitting in a shared data center.If I'm running a traditional network where I am not in a shared data center with a layer two dedicated for my resources, then it can work for me. However, if I am in a data center where I don't have layer two, it becomes an issue because the autonomous response is reliant on sending spoofed TCP resets to my core switch to block traffic, which is a major issue.
Jacob_Koithra - PeerSpot reviewer
User-friendly and has a good blocking feature but is quite expensive
Defining the new security rules and policies sometimes becomes a challenge. Integration with other platforms becomes a challenge as well. I'd like to see more integration with other tools and technologies. XGS 7100 has an end of support for the 30th of December 2022. Many are losing support. All the products of the XGS, including XGS 3100, 4100, 5100, and 7100, support is ending in December 2022. We need to know what is the plan post that? Do we need to spend money on them? Will that be extended? There has been no communication on the website either. It's an expensive device.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"From a security standpoint, it is just seeing pockets as well. Visibility is very key for us."
"It works efficiently for encrypted traffic analysis."
"Great network monitoring, looking at anomaly detection and evaluation."
"Being able to graph and show data to management has improved our organization. We can show the data to the higher-ups. It shows them that it's picking up on these anomalies and doing its job."
"The most valuable features include encrypted traffic analytics and the ability to fulfill requirements at the network level."
"The most valuable feature is integration."
"We find that Stealthwatch can detect the unseen."
"The most valuable feature of Cisco Secure Network Analytics is the Threat Intelligence integration."
"The product offers us a very good user interface and we've found the network visibility to be very good so far."
"Darktrace is valuable since it offers full packet capture and detailed metadata."
"I particularly like Antigena and the analytics around the real-time monitoring of our network. I also like its reporting because it has got a seven-day reporting period within the system. Every time you run the reports, it gives you the data about the previous seven days. I like that because it is in real-time. I enjoy reading those reports and getting a very clear and decisive idea of what's happening on my network on a real-time basis. I like the actual real-time monitoring of spoofing and things like that. I also like the user monitoring as well as the network logging capabilities."
"Darktrace's most valuable features are its dashboards and its ability to summarize huge amounts of information about threats and suspicious traffic."
"It's a very stable product."
"The main valuable feature is that we don't need a lot of analysts. With few analysts, we have all the network monitored, 24/7."
"Darktrace is very useful for us because it has a large number of models for detecting threats."
"The ability to detect activity on the network is very useful to us. Even if it's not necessarily an illegal activity, if it is abnormal activity, it is able to detect it and notify us."
"The most valuable feature is its simplicity."
"The initial setup is simple."
 

Cons

"It's a good solid solution but integration with Network Access Control products with Cisco ISE would be good."
"We've had problems with element licensing costs so scalability is a concern."
"The usability of this solution needs to be improved."
"The initial setup is complex, as there is a lot to configure."
"I would like the search page available with Cisco Stealthwatch to be more intuitive. The previous release was better than the current one for the UI."
"There could be better integration on the programming side, which uses Python. StealthWatch could provide a template for Python to manage the switches. For example, it would be nice if StealthWatch bounced a port automatically it detected something anomalous."
"Initially, I felt Cisco Secure Network Analytics lacked integration with Splunk."
"One update that I would like to see is an agent-based client. Currently, Stealthwatch is network-based. A local agent could help manage endpoints."
"Darktrace should have more automation and integrations with other security monitoring tools."
"I believe their network monitoring device licensing module could use some improvement."
"The dashboard and reporting for this solution could be improved as it is currently complex. The GUI for this solution could also be improved."
"Updates keep coming, which is great, but I prefer a unified UI experience. The intelligence section and the incident view should be seamlessly connected in one view to avoid jumping between pages."
"The user interface and the configuration are a bit complex and should be improved or simplified."
"Needs to improve its collaboration with local partners."
"I did not use the AI features because they should make it more user-friendly which would be a benefit. Additionally, the solution could integrate with more SIEM or SOAR tools."
"In a shared environment, it doesn't work, and there are still some integration issues."
"I'd like to see more integration with other tools and technologies."
"In the future, I would like to see a hybrid option so that we can work both on-premises and in the cloud."
 

Pricing and Cost Advice

"One of the things which bugs me about Lancope is the licensing. We understand how licensing works. Our problem is when we bought and purchased most of these Lancope devices, we did so with our sister company. Somewhere within the purchase and distribution, licensing got mixed up. That is all on Cisco, and it is their responsibility. They allotted some of our sister company's equipment to us, and some of our equipment to them. To date, they have never been able to fix it."
"The yearly licensing cost is about $50,000."
"Pricing is much higher compared to other solutions."
"The solution is expensive. It costs several hundred thousand dollars per year (depending on how many flows you are collecting)."
"It is worth the cost."
"Today, we are part of the big Cisco ELA, and it is a la carte. We can get orders for whatever we want. At the end of the day, we have to pay for it in one big expense, but that is fine. We are okay with that."
"NetFlow is very expensive."
"This is an expensive product. We have quit paying for support because we don't want to have to upgrade it and keep paying for it."
"The pricing is subscription-based and it is high."
"The pricing is reasonable."
"Darktrace is expensive. You can pay for the license yearly."
"I'm unfamiliar with the exact cost, but we have a yearly license and had to pay for Darktrace's services before the deployment. The product is very expensive, so some organizations can't afford to pay the total amount directly, meaning they often seek a partner or pay in installments, which increases the price more."
"If you consider the features and the cost of market leaders, we are satisfied with the pricing."
"Darktrace is pricey, but the price is reasonable for what the solution does, and it's comparable to other products."
"It is a very expensive product."
"The tool's pricing is costly."
"The cost of operations is very low."
report
Use our free recommendation engine to learn which Network Monitoring Software solutions are best for your needs.
867,826 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Computer Software Company
22%
Government
11%
Financial Services Firm
9%
Manufacturing Company
9%
Computer Software Company
12%
Manufacturing Company
9%
Financial Services Firm
8%
Government
7%
No data available
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business11
Midsize Enterprise7
Large Enterprise52
By reviewers
Company SizeCount
Small Business43
Midsize Enterprise19
Large Enterprise29
No data available
 

Questions from the Community

What do you like most about Cisco Stealthwatch?
The most valuable feature of Cisco Secure Network Analytics is the Threat Intelligence integration.
What is your experience regarding pricing and costs for Cisco Stealthwatch?
Regarding cost, for the Bangladesh context, Cisco Secure Network Analytics is a little bit high-priced because we are...
What needs improvement with Cisco Stealthwatch?
In terms of improvements for Cisco Secure Network Analytics, from the implementation point of view, now that AI is in...
How does Crowdstrike Falcon compare with Darktrace?
Both of these products perform similarly and have many outstanding attributes. CrowdStrike Falcon offers an amazing u...
Which is better - SentinelOne or Darktrace?
Which solution is better depends on which is more suitable specifically for your company. Darktrace, for example, is ...
What do you like most about Darktrace?
A very useful feature in Darktrace for real-time threat analysis is the packet inspection that analyzes the packet tr...
Ask a question
Earn 20 points
 

Also Known As

Cisco Stealthwatch, Cisco Stealthwatch Enterprise, Lancope StealthWatch
No data available
Security Network Intrusion Prevention System, IBM Security Network Protection, XGS, GX
 

Overview

 

Sample Customers

Edge Web Hosting, Telenor Norway, Ivy Tech Community College of Indiana, Webster Financial Corporation, Westinghouse Electric, VMware, TIAA-CREF
Irwin Mitchell, Open Energi, Wellcome Trust, FirstGroup plc, Virgin Trains, Drax, QUI! Group, DNK, CreaCard, Macrosynergy, Sisley, William Hill plc, Toyota Canada, Royal British Legion, Vitol, Allianz, KKR, AIRBUS, dpd, Billabong, Mclaren Group.
Equifax, Christian Hospital Centre
Find out what your peers are saying about Zabbix, Auvik, SolarWinds and others in Network Monitoring Software. Updated: September 2025.
867,826 professionals have used our research since 2012.