Try our new research platform with insights from 80,000+ expert users

Elastic Security vs NetWitness NDR comparison

Sponsored
 

Comparison Buyer's Guide

Executive SummaryUpdated on Sep 9, 2024

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

ROI

Sentiment score
4.9
Torq reduced alert handling time, increased efficiency and ROI, leading to customer satisfaction and renewal interest due to competitive pricing.
Sentiment score
6.0
Elastic Security provides satisfactory ROI and cost savings, though users experience varied support levels and payback periods.
Sentiment score
8.0
Implementing NetWitness NDR enhances security, improves network visibility, reduces costs, and boosts efficiency and productivity for businesses.
Since we started working with Torq, I am handling much fewer alerts. It is becoming really easy for me to handle an alert.
SOC Analyst at AppsFlyer
By the time we officially bought Torq, we already had two workflows that were very helpful to us.
CyberSecurity Engineer at a real estate/law firm with 10,001+ employees
It pretty much took until we got to our first renewal where we said that this is the value we see, this is the things we want more, but that is the first place where we said we are happy enough that we want to renew.
Information Technology Specialist at a media company with 201-500 employees
It does not require hefty security budgets and can be deployed for enterprise security effectively.
Assistant Director at PTA
 

Customer Service

Sentiment score
7.0
Torq's customer service is praised for quick, knowledgeable support, resolving issues effectively within 24 hours with minimal formal contact.
Sentiment score
6.4
Elastic Security support is inconsistent; users favor community and documentation, while premium users seek more responsive and personalized help.
Sentiment score
7.3
NetWitness NDR's customer service is generally efficient and highly regarded, though some users report occasional slow response times.
The speed and quality of their answers have been pretty good, as I usually get a response within 24 hours, and they follow up well.
CyberSecurity Engineer at a real estate/law firm with 10,001+ employees
We can always get an answer, and the support team are experts in their own system.
Director Of Cyber Security at a tech vendor with 501-1,000 employees
Nine out of ten times, they give me a solution even if it is not the solution I wanted, and I still can get to the result.
Information Technology Specialist at a media company with 201-500 employees
Support is prompt and helpful.
Senior Cyber Security Manager at a tech services company with 11-50 employees
Most of the time when my team encounters issues, they receive responses within 24 hours.
Assistant Director at PTA
I have not faced any difficulties with Elastic Security, as we have a pretty good support service from them.
Chief Product Officer at ClusterPower
 

Scalability Issues

Sentiment score
7.4
Torq excels in scalability, supporting large teams and adapting efficiently, despite the no-code automation's inherent web interface limitations.
Sentiment score
7.3
Elastic Security offers scalable solutions adaptable to various environments, praised for flexibility and requiring careful planning for integration.
Sentiment score
7.0
NetWitness NDR is scalable for large enterprises, though some users report issues with scalability and agent migration.
Our case management is super scalable.
CyberSecurity Engineer at a real estate/law firm with 10,001+ employees
In terms of scalability, you can do as long as you can build it, and they can support it.
Director Of Cyber Security at a tech vendor with 501-1,000 employees
Regarding the ability of the solution to grow in your work environment, if it is scalable, if it fits your business requirements, and if there is room to scale up, the answer is yes, for sure.
Global IT Director at OpenWeb
It allows us to think about specific use cases, such as gathering malicious IPs in a single view and analyzing threats based on geolocation.
Assistant Director at PTA
Elastic Security is quite scalable.
Chief Product Officer at ClusterPower
 

Stability Issues

Sentiment score
5.4
Torq generally performs stably with minor bugs and glitches, but overall user satisfaction remains high without significant disruptions.
Sentiment score
7.7
Elastic Security is generally stable and reliable but can face challenges with big data and requires careful configuration.
Sentiment score
7.7
NetWitness NDR is generally reliable, providing real-time data and stability, though minor technical issues are occasionally reported.
Most of the time, the system is stable as long as the components that they integrate with are stable.
Director Of Cyber Security at a tech vendor with 501-1,000 employees
Regarding stability, I have noticed some lagging, crashing, and downtime, which is one of my largest gripes.
CyberSecurity Engineer at a real estate/law firm with 10,001+ employees
I would rate Torq's product stability at eight, acknowledging that there are bugs, glitches, and downtimes.
Senior Cyber Architect at a manufacturing company with 10,001+ employees
In terms of stability, I would rate Elastic a solid eight out of ten.
Senior Cyber Security Manager at a tech services company with 11-50 employees
 

Room For Improvement

Torq requires improvements in AI features, error handling, data handling, and workflow navigation for enhanced usability and reliability.
Elastic Security needs improvements in authentication, usability, automation, scalability, integration, and pricing, with user-friendly dashboards and documentation.
NetWitness NDR requires improvements in UI, scalability, detectability, integration, session times, pricing, training, and features, making it complex and slow.
It was able to capture data but was unable to differentiate between the agent hostname we are using and the hostname that resides on the back end of the Internet.
Senior Consultant at a university with 10,001+ employees
From an engineering perspective, I think more error messages and error handling information for our engineering team would be very helpful.
CyberSecurity Engineer at a real estate/law firm with 10,001+ employees
If a step is failing, the system could try to autocorrect it with AI or open a ticket from the workflow itself.
Director Of Cyber Security at a tech vendor with 501-1,000 employees
CrowdStrike and Defender have more established threat intelligence integration due to having a larger client base.
Senior Cyber Security Manager at a tech services company with 11-50 employees
My security testing team continuously reports vulnerabilities, and we have to fix and update the versions frequently.
Assistant Director at PTA
Machine learning algorithms become better with time; as they ingest a huge volume of data, they become better.
Chief Product Officer at ClusterPower
 

Setup Cost

Enterprise buyers find Torq's pricing high but worthwhile due to its modernization, automation, and strategic investment value.
Elastic Security provides a free open-source option, competitive pricing, and subscription plans, appealing to cost-conscious enterprises.
When they bring more and more value into the platform, it makes more sense to pay that price, but still, it is expensive.
Senior Cyber Architect at a manufacturing company with 10,001+ employees
Before deciding to implement Torq, I considered that compared to our old case management platform, Torq was a much better price and had a lot better value for what you get out of the platform, which was a key consideration for the company.
CyberSecurity Engineer at a real estate/law firm with 10,001+ employees
It is an expensive solution, not an inexpensive solution, but we get through the flexibility.
Director Of Cyber Security at a tech vendor with 501-1,000 employees
The pricing is reasonable, especially for Small Medium Enterprises (SMEs), making it a viable option for businesses building their security infrastructure.
Senior Cyber Security Manager at a tech services company with 11-50 employees
This is beneficial for SMEs as they do not need extensive budgets for security solutions.
Assistant Director at PTA
Elastic Security is considered cost-effective, especially at lower EPS levels.
Performance Practice Specialist at a local government with 10,001+ employees
 

Valuable Features

Torq enhances productivity by streamlining workflows, integrating systems, and utilizing AI for efficient SecOps and API management.
Elastic Security provides scalable, customizable threat response with fast search, real-time analysis, and strong community support for actionable insights.
NetWitness NDR offers high detection rates, real-time malware response, third-party integration, and a user-friendly, interoperable interface with advanced analytics.
Torq's unified platform approach to AI SOC automation and case management has significantly benefited us by integrating the case management platform with the automation, which saves time compared to managing multiple point solutions across our security stack.
CyberSecurity Engineer at a real estate/law firm with 10,001+ employees
The fact that I can build whatever I want within my own imagination and skills without relying on code is the best thing about Torq.
Director Of Cyber Security at a tech vendor with 501-1,000 employees
You can copy and paste a cURL command. If you have documentation or APIs, you usually have an example on the side. You basically have all the information on how the API call should be. You can just copy that and paste it into a step, and it will just build the step for you.
Global IT Director at OpenWeb
Elastic Security offers good insight regarding alerts, reports, and cases.
Senior Cyber Security Manager at a tech services company with 11-50 employees
Elastic Security offers advanced features such as machine learning and integration with ChatGPT.
Performance Practice Specialist at a local government with 10,001+ employees
We require rapid processing speed for alerts and event data, and Elastic Security is very efficient at handling this level of data.
Assistant Director at PTA
 

Categories and Ranking

Torq
Sponsored
Ranking in Security Orchestration Automation and Response (SOAR)
5th
Average Rating
8.6
Reviews Sentiment
6.6
Number of Reviews
7
Ranking in other categories
AI-SOC (3rd), AI-Powered Security Automation (2nd)
Elastic Security
Ranking in Security Orchestration Automation and Response (SOAR)
7th
Average Rating
7.8
Reviews Sentiment
6.8
Number of Reviews
66
Ranking in other categories
Log Management (9th), Security Information and Event Management (SIEM) (5th), Endpoint Detection and Response (EDR) (15th), Extended Detection and Response (XDR) (8th)
NetWitness NDR
Ranking in Security Orchestration Automation and Response (SOAR)
25th
Average Rating
8.0
Reviews Sentiment
6.9
Number of Reviews
15
Ranking in other categories
Endpoint Protection Platform (EPP) (50th), Threat Intelligence Platforms (TIP) (37th), Endpoint Detection and Response (EDR) (58th), Network Detection and Response (NDR) (19th), Extended Detection and Response (XDR) (37th)
 

Featured Reviews

Nimrod Vardi - PeerSpot reviewer
Global IT Director at OpenWeb
Automation workflows have transformed our IT, enabling secure just-in-time access control
We work with them quite often, so we have a direct line regarding areas in Torq that have room for improvement. If we have a feature request, we can request it. I do not have anything in mind at the moment. We were a design partner for a short while, so we feel that they listen and that users of the system have an impact on the way the system is designed for the better. They have a new community, which is something that I personally suggested years ago. There are many people like me in different places and they might have already built the workflow that I need. Having the option to share workflows or to jump on a thread and say I have this need, did anyone ever build a workflow for it, is amazing. Someone would jump in and say yes, sure, here, take this workflow. I think this is an amazing thing and I really hope that the community will come alive because I think this is really powerful. This is something that I already suggested and it did happen eventually, and I am quite happy with it. I do not have any specific feature in mind that I have a need for at the moment.
Laurentiu Popescu - PeerSpot reviewer
Chief Product Officer at ClusterPower
Has improved threat detection with deep log analysis and streamlined investigation workflows
The most useful features I find in Elastic Security are the forensic ones that allow us to carry deeper analysis into the logs for in-depth investigations, and the dashboards, with the reporting dashboard being quite user-friendly. Elastic Security is quite good at identifying threats, as it is part of the deep investigation tool that I mentioned before. Unless we need to look further into a certain log, we can carry out a deeper analysis and forensics on those particular logs. I can assess the impact of Elastic Security's real-time data analysis on our threat response efficiency as working pretty good. We are looking for real-time analysis because we have a continuous inflow of logs from different sources: from our cloud, from Active Directory, from our network. So it works pretty well.
reviewer1799727 - PeerSpot reviewer
Manager, IT Security Operations at a non-profit with 11-50 employees
Reliable and good support but can be expensive
I have no real complaints about the solution. Threat detection could be better. They need to enhance their threat intelligence feeds. We would like to have more IOCs or more trade intelligence to not only rely on the intelligence of the engineer in charge but to have some threat intelligence and some seeds of IOCs and to have the host have some artificial intelligence to reduce the number of false positives. I don't see this solution being very scalable. The solution is pricey.
report
Use our free recommendation engine to learn which Endpoint Detection and Response (EDR) solutions are best for your needs.
885,264 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Financial Services Firm
13%
Manufacturing Company
9%
Comms Service Provider
8%
Healthcare Company
6%
Computer Software Company
10%
Government
9%
Comms Service Provider
9%
Manufacturing Company
7%
Computer Software Company
9%
Financial Services Firm
9%
Manufacturing Company
9%
Outsourcing Company
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Midsize Enterprise3
Large Enterprise4
By reviewers
Company SizeCount
Small Business40
Midsize Enterprise11
Large Enterprise15
By reviewers
Company SizeCount
Small Business10
Midsize Enterprise2
Large Enterprise5
 

Questions from the Community

What needs improvement with Torq?
We do not utilize the AI features that much. When it comes to general AI features of Torq, we are just slowly startin...
What is your primary use case for Torq?
Torq markets itself as a security tool, and we do use them for security, but not in the traditional sense they market...
What advice do you have for others considering Torq?
I would rate Torq an eight overall. I feel that Torq is as good as the effort you put into it. The limitations are ve...
Datadog vs ELK: which one is good in terms of performance, cost and efficiency?
With Datadog, we have near-live visibility across our entire platform. We have seen APM metrics impacted several time...
What do you like most about Elastic Security?
Elastic provides the capability to index quickly due to the reverse indexes it offers. This data is crucial as it con...
What is your experience regarding pricing and costs for Elastic Security?
I am satisfied with the pricing, setup cost, and licensing cost. It is a pure 10.
Ask a question
Earn 20 points
 

Also Known As

No data available
Elastic SIEM, ELK Logstash
RSA ECAT, NetWitness Network
 

Overview

 

Sample Customers

Information Not Available
Texas A&M, U.S. Air Force, NuScale Power, Martin's Point Health Care
ADP, Ameritas, Partners Healthcare
Find out what your peers are saying about Elastic Security vs. NetWitness NDR and other solutions. Updated: March 2026.
885,264 professionals have used our research since 2012.