Try our new research platform with insights from 80,000+ expert users

Exabeam vs NetWitness NDR comparison

Sponsored
 

Comparison Buyer's Guide

Executive SummaryUpdated on Dec 5, 2024

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Torq
Sponsored
Ranking in Security Orchestration Automation and Response (SOAR)
8th
Average Rating
8.0
Reviews Sentiment
2.2
Number of Reviews
1
Ranking in other categories
AI-SOC (13th), AI-Powered Security Automation (2nd)
Exabeam
Ranking in Security Orchestration Automation and Response (SOAR)
12th
Average Rating
7.8
Reviews Sentiment
6.7
Number of Reviews
19
Ranking in other categories
Security Information and Event Management (SIEM) (20th), User Entity Behavior Analytics (UEBA) (2nd), Security Incident Response (5th), Threat Intelligence Platforms (TIP) (12th), AI-Powered Cybersecurity Platforms (10th)
NetWitness NDR
Ranking in Security Orchestration Automation and Response (SOAR)
25th
Average Rating
8.0
Reviews Sentiment
6.9
Number of Reviews
15
Ranking in other categories
Endpoint Protection Platform (EPP) (55th), Threat Intelligence Platforms (TIP) (40th), Endpoint Detection and Response (EDR) (57th), Network Detection and Response (NDR) (19th), Extended Detection and Response (XDR) (38th)
 

Featured Reviews

reviewer2767650 - PeerSpot reviewer
Senior Consultant at a university with 10,001+ employees
Have found automation to save analyst time but miss more accurate data classification
From our research and testing with the tool, we determined there need to be modifications and changes to train the LLM on the back end. It was able to capture data but was unable to differentiate between the agent hostname we are using and the hostname that resides on the back end of the Internet. It was unable to do that sort of classification. We concluded this tool would be more suitable for initial ticket management rather than security automation. Regarding data handling, I would give preference to Torq. For case management, Cortex and its dashboards prove more useful. Cortex and Palo's solutions do not have as much capability as Torq provides with the same tools. However, Torq's dashboards could be improved, especially on the case management side.
reviewer2650449 - PeerSpot reviewer
Analyst at a government with 1,001-5,000 employees
Machine learning features improve security insight but on-prem limitations prompt consideration of migration
We only use Exabeam for Advanced Analytics. We don't do all those other aspects like ticketing plugins. We just use it for the integration purposes, which are kind of basic. We send alerts via the dashboard for our SOC to identify risky users Exabeam includes machine learning features and…
reviewer1799727 - PeerSpot reviewer
Manager, IT Security Operations at a non-profit with 11-50 employees
Reliable and good support but can be expensive
I have no real complaints about the solution. Threat detection could be better. They need to enhance their threat intelligence feeds. We would like to have more IOCs or more trade intelligence to not only rely on the intelligence of the engineer in charge but to have some threat intelligence and some seeds of IOCs and to have the host have some artificial intelligence to reduce the number of false positives. I don't see this solution being very scalable. The solution is pricey.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"As an analyst, it has demonstrated potential to reduce workforce requirements and time needed for related activities."
"It's a very user-friendly product and it's a very comprehensive technology."
"Exabeam includes machine learning features and out-of-the-box rules that we rely on."
"The solution's automation capabilities are great."
"Exabeam has improved our organization by speeding up the investigation process."
"The advanced analytics has a really great overview of user behavior."
"Exabeam is very easy to use, with a straightforward platform and workflow, unlike other tools that require more expertise."
"The most valuable feature of Exabeam Fusion SIEM is the easy-to-use user interface."
"The Exabeam SIEM has a user friendly UI interface."
"The interface of this solution is very flexible and easy to use."
"It helps our security team respond more accurately when there are threats, then we get less false positives or negatives."
"It's a scalable solution. We have around five to eight customers using RSA NetWitness Endpoint, and we hope to increase the number of users."
"We've contacted technical support several times. They've been very good. They have been able to help us resolve our issues."
"They have recently updated the features and the most valuable ones are the instant threat response, ease of use, web interface, integration, and easy access. RSA NetWitness Endpoint is very compatible with other solutions and technologies. However, they do not rely on third-party solutions and have most features built-in."
"Technical support is knowledgeable."
"The log correlation is good."
"Ability to isolate the machine when there are malicious files."
 

Cons

"It was able to capture data but was unable to differentiate between the agent hostname we are using and the hostname that resides on the back end of the Internet."
"Exabeam's reporting dashboard could have included a filtering option to filter by the most recent detection."
"The initial setup of Exabeam Fusion SIEM is complex because it needs to integrate with the SIEM solution, but after this is complete it is straightforward."
"Updating the new release of Exabeam Fusion SIEM takes time and slows our performance."
"We use the on-prem Exabeam product and face limitations using the web UI and administration of custom models and rules."
"I believe if it were more flexible it would be a better product."
"Exabeam needs to improve its adaptive nature towards rules and its capability to understand the entire client environment faster."
"Exabeam should be a bit faster, especially in loading and vulnerability scanning."
"Exabeam lacks customizable dashboards, which might be a limitation if visualization is a key requirement."
"The solution is modular, for example you can buy the RSA ePack, which you buy as a module is not part of the conduit solution. They could include it and have it as an all-in-one solution."
"The solution lacks a reporting engine."
"The deployment process is complex. I don't know why, but this solution will suddenly stop working. Logs stop coming. Often, one thing or another stops working. Most of the time, one of my team members is working with troubleshooting and working with technical support. Log passing is also one of the biggest challenge."
"Threat detection could be better."
"The initial setup requires a high level of skill."
"The threat intelligence could improve in RSA NetWitness Endpoint."
"I would like to see Security Orchestration and Response Automation (SOAR) integration."
"The integration of the solution needs to be improved. The dashboard needs lots of updates as well. In the next release, we would like to see advanced fraud detection features."
 

Pricing and Cost Advice

Information not available
"Exabeam Fusion SIEM's pricing is reasonable."
"They have a great model for pricing that can be based either on user count or gigabits per day."
"Exabeam is not a cheap solution."
"The platform is not extremely expensive compared to its direct competitors; I would rate its pricing around six out of ten."
"The solution is expensive."
"There is an annual license required to use Exabeam Fusion SIEM. The price of the solution should be reduced."
"It is an expensive product."
"It is highly scalable. It can be bought based on your requirements."
"The price of the solution depends on the environment. If the environment is large then it will cost more. However, the larger the environment with more endpoints, you will receive an increased discount. If the environment is very small, then you might think it is expensive. It is always better to buy in bulk to receive a discount. The minimum number of assets is usually 500, with discounts on 1000 and 2000."
"The cost depends on the number of endpoints that you want to monitor, but it is not expensive."
"NetWitness Endpoint is less costly than its competitors, but it offers fewer features."
"With RSA, there is flexibility in choosing the service, products, and the range that meets your requirement, as well as they are flexible in terms of pricing."
"I do not have any opinion on the pricing or licensing of the product."
"We are on a three-year contract to use RSA NetWitness Network."
report
Use our free recommendation engine to learn which Threat Intelligence Platforms (TIP) solutions are best for your needs.
879,927 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Financial Services Firm
15%
Computer Software Company
9%
Manufacturing Company
7%
Healthcare Company
6%
Financial Services Firm
12%
Computer Software Company
11%
Manufacturing Company
9%
Healthcare Company
6%
Financial Services Firm
10%
Computer Software Company
10%
Manufacturing Company
9%
Performing Arts
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
No data available
By reviewers
Company SizeCount
Small Business12
Midsize Enterprise3
Large Enterprise7
By reviewers
Company SizeCount
Small Business10
Midsize Enterprise2
Large Enterprise5
 

Questions from the Community

What needs improvement with Torq?
From our research and testing with the tool, we determined there need to be modifications and changes to train the LL...
What is your primary use case for Torq?
I used Torq for conducting one of the proof of evaluations for a vendor we are connected with. I am currently working...
What advice do you have for others considering Torq?
One of our members uses AWS, and we receive their feed. This involves triaging AWS-related logs. While I do not have ...
What are the biggest differences between Securonix UEBA, Exabeam, and IBM QRadar?
It mostly depends on your use-cases and environment. Exabeam and Securonix have a stronger UEBA feature set, friendli...
What is your experience regarding pricing and costs for Exabeam Fusion SIEM?
I do not have much information about the pricing. However, I am aware that Exabeam is cheaper than Palo Alto based on...
What needs improvement with Exabeam Fusion SIEM?
We use the on-prem Exabeam product and face limitations using the web UI and administration of custom models and rule...
Ask a question
Earn 20 points
 

Comparisons

 

Also Known As

No data available
No data available
RSA ECAT, NetWitness Network
 

Overview

 

Sample Customers

Information Not Available
Hulu, ADP, Safeway, BBCN Bank
ADP, Ameritas, Partners Healthcare
Find out what your peers are saying about Exabeam vs. NetWitness NDR and other solutions. Updated: December 2025.
879,927 professionals have used our research since 2012.