Try our new research platform with insights from 80,000+ expert users

Datadog vs NetWitness Platform comparison

 

Comparison Buyer's Guide

Executive SummaryUpdated on Apr 6, 2025

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Datadog
Ranking in Log Management
3rd
Average Rating
8.6
Reviews Sentiment
7.1
Number of Reviews
188
Ranking in other categories
Application Performance Monitoring (APM) and Observability (1st), Network Monitoring Software (3rd), IT Infrastructure Monitoring (2nd), Container Monitoring (1st), Cloud Monitoring Software (1st), AIOps (1st), Cloud Security Posture Management (CSPM) (7th)
NetWitness Platform
Ranking in Log Management
22nd
Average Rating
7.4
Reviews Sentiment
7.4
Number of Reviews
37
Ranking in other categories
Security Information and Event Management (SIEM) (22nd)
 

Mindshare comparison

As of May 2025, in the Log Management category, the mindshare of Datadog is 6.0%, down from 8.0% compared to the previous year. The mindshare of NetWitness Platform is 0.3%, down from 0.4% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Log Management
 

Featured Reviews

Kevin Palmer - PeerSpot reviewer
Useful log aggregation and management with helpful metrics aggregation
Datadog provides us value in three major ways: First, Datadog provides best-in-class functionality in many, if not all, of the products to which we subscribe (infrastructure, APM, log management, serverless, synthetics, real user monitoring, DB monitoring). In my experience with other tools that provide similar functionality, Datadog provides the largest feature set with the most flexibility and the best performance. Second, Datadog allows us to access all of those services in one place. Having to learn and manage only one tool for all of those purposes is a major benefit. Third, Datadog provides significant connectivity between those services so that we can view, summarize, organize, translate and correlate our data with maximum effect. Not needing to manually integrate them to draw lines between those pieces of information is a huge time savings for us.
MdZaman - PeerSpot reviewer
Really scalable for enterprise customers
The solution should have more integration capabilities with different platforms. The API is nearly open and scalable, so the solution can integrate with many platforms. The solution has more than 200 log sources in the scalability to support, but this is its limit. Installation is pretty easy. However, there are a couple of modules involved, so it is not as easy as it could be. We are talking about a distributed module, not a single-module type. This is what makes things a bit complex, instead of easier. I rate it as a seven out of ten on its installation and configuration capabilities.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"I don't have to worry about upgrades with the AWS version."
"The CCM, Workflows, Logs, APM, and RUM are all useful aspects of the solution."
"Its logs are most valuable."
"Dashboards are the most valuable."
"Overall, the Data UI and the usability of customer features continue to improve."
"Customizable views as well as the ability to "dive in" when we see someting anomalous has improved the workflow for handling incidents."
"Most of the features in the way Datadog does monitoring are commendable and that is the reason we choose it. We did some comparisons before picking Datadog. Datadog was recommended based on the features provided."
"The solution has improved the organization by providing good insights into app performance and offering good dashboards."
"It's quite economical compared to other solutions in the market."
"NetWitness Platform is valuable for creating rules that the solution must detect."
"The most valuable feature is that we can create our own connectors for any application, and NetWitness provides the training and tools to do it."
"Alerting Module: It provides real-time event processing language on all the logs/packets stream for advanced alerting, i.e., using SQL LIKE statements."
"What we are mainly using are the RSA concentrator, RSA Decoder, Archiver, Broker, and Log Decoder."
"The most valuable features are the packet decoder, log decoder, and concentrator."
"The most valuable feature of RSA NetWitness Logs and Packets are the alerts and correlations tools."
"Their technical support responds quickly and are knowledgable."
 

Cons

"Alerting timing should be improved to be more fine-tuned and exact."
"Some of the interface is still confusing to use."
"It is very difficult to make the solutions fit perfectly for large organizations, especially in terms of high cardinality objects and multi-tenancy, where the data needs to be rolled up to a summarized level while maintaining its individual data granularity and identifiers."
"It can have an artificial intelligence component. Even though I can seamlessly look at end-to-end security, it would be better to have alerts and notifications powered by an AI engine. I am not sure if they have an AI component. We have not reached out to them or looked at it, but this is something that I keep on talking about within our company in terms of features. Such a feature would be good to have, and it would further optimize my Security Ops team's abilities."
"Managing dashboards as IaC is a bit hard to work out at times."
"The parallel editing of the dashboards should not cause users to lose the work of another person."
"When the logs are too big, and Datadog splits them, the JSON format breaks and it is not so useful for us."
"As a new customer, the Datadog user interface is a bit daunting."
"Technical support could be improved."
"The multi-tenant capabilities are lagging compared to IBM QRadar."
"We have encountered issues with unresolved crashes."
"They should implement algorithms to digest that data and produce additional, more advanced reporting, alerting and support of internal security teams."
"The initial setup was complex because it takes a lot of time to complete the implementation."
"The threat detection capability and centralizing and upgrading capability need to be improved. The threat alert capability needs to be improved as well because there is some lag time at present. They need to work on their database search too."
"Sometimes, it gives me static when integrating Windows-based systems. It should produce a precise log of sorts as to where the problem is. For example, a few days ago because of the McAfee application firewall, I couldn't get access to the particular Windows machine. So, my team and I had to figure out by ourselves that there was a virus responsible for the obstacle. This solution should trigger a meaningful log or message indicating the reason the user or implementer can't get into the machine."
"The solution should have more integration capabilities with different platforms."
 

Pricing and Cost Advice

"Licensing is based on the retention period of logs and metrics."
"Sometimes it's very hard to project how much it will cost for the monthly subscription for the next month when you add certain features. Having better visibility of the cost would give a better experience."
"My advice is to really keep an eye on your overage costs, as they can spiral really fast."
"They prefer monthly subscriptions."
"The pricing and licensing through AWS Marketplace has been good. It would be nice if it was cheaper, but their pricing is reasonable for what it is. Sometimes, for their newer features, they charge as if it's fully fleshed out, even though it is a newer feature and it may have less stuff than their other items."
"Pricing and licensing are reasonable for what they give you. You get the first five hosts free, which is fun to play around with. Then it's about four dollars a month per host, which is very affordable for what you get out of it. We have a lot of hosts that we put a lot of custom metrics into, and every host gives you an allowance for the number of custom metrics."
"It is easy to run up a large bill, so become familiar with the cost of each piece of your bill and use the metrics they supply to estimate and monitor your bill."
"Pricing seemed easy until the bill came in and some things were not accounted for."
"There is a licensing fee and the customer can choose whether he wishes this to be subscription-based or perpetual."
"The product price was reasonable for my region and the market."
"The NetWitness Platform may be affordable only for enterprise-level customers, as it may not be within the budget of small and medium-sized businesses."
"Compared to the competition, the is price is not that high."
"We are on an annual license for the use of the solution."
"Our license is for one year."
"The licenses are good but the cost is very expensive."
"It’s cheaper to run virtual machines in a VMware environment."
report
Use our free recommendation engine to learn which Log Management solutions are best for your needs.
850,028 professionals have used our research since 2012.
 

Comparison Review

VS
Feb 26, 2015
HP ArcSight vs. IBM QRadar vs. ​McAfee Nitro vs. Splunk vs. RSA Security vs. LogRhythm
We at Infosecnirvana.com have done several posts on SIEM. After the Dummies Guide on SIEM, we are following it up with a SIEM Product Comparison – 101 deck. So, here it is for your viewing pleasure. Let me know what you think by posting your comments below. The key products compared here are…
 

Top Industries

By visitors reading reviews
Educational Organization
30%
Computer Software Company
11%
Financial Services Firm
11%
Manufacturing Company
6%
Computer Software Company
19%
Financial Services Firm
18%
Government
6%
Insurance Company
6%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

Any advice about APM solutions?
There are many factors and we know little about your requirements (size of org, technology stack, management systems, the scope of implementation). Our goal was to consolidate APM and infra monitor...
Datadog vs ELK: which one is good in terms of performance, cost and efficiency?
With Datadog, we have near-live visibility across our entire platform. We have seen APM metrics impacted several times lately using the dashboards we have created with Datadog; they are very good c...
Which would you choose - Datadog or Dynatrace?
Our organization ran comparison tests to determine whether the Datadog or Dynatrace network monitoring software was the better fit for us. We decided to go with Dynatrace. Dynatrace offers network ...
What do you like most about NetWitness Platform?
The product's initial setup phase was not at all difficult.
What is your experience regarding pricing and costs for NetWitness Platform?
The pricing is comparable to others, and I consider the cost to be intermediate. Specific cost details are unknown to me.
What needs improvement with NetWitness Platform?
There is currently no need for improvement in the SIEM ( /categories/security-information-and-event-management-siem ), though there could be potential enhancements by integrating with AI.
 

Also Known As

No data available
RSA Security Analytics
 

Overview

 

Sample Customers

Adobe, Samsung, facebook, HP Cloud Services, Electronic Arts, salesforce, Stanford University, CiTRIX, Chef, zendesk, Hearst Magazines, Spotify, mercardo libre, Slashdot, Ziff Davis, PBS, MLS, The Motley Fool, Politico, Barneby's
Los Angeles World Airports, Reply
Find out what your peers are saying about Datadog vs. NetWitness Platform and other solutions. Updated: April 2025.
850,028 professionals have used our research since 2012.