Try our new research platform with insights from 80,000+ expert users

ExtraHop Reveal(x) vs NetWitness NDR comparison

 

Comparison Buyer's Guide

Executive SummaryUpdated on Nov 6, 2024

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

ROI

Sentiment score
7.8
ExtraHop Reveal(x) reduces MTTR, improves efficiency, and delivers swift ROI through rapid issue detection and resolution for financial transactions.
Sentiment score
8.0
Implementing NetWitness NDR enhances security, improves network visibility, reduces costs, and boosts efficiency and productivity for businesses.
 

Customer Service

Sentiment score
7.6
ExtraHop Reveal(x) customer service is highly rated for effectiveness, though time zone issues occasionally cause slower responses.
Sentiment score
7.3
NetWitness NDR's customer service is generally efficient and highly regarded, though some users report occasional slow response times.
I would rate their technical support nine out of ten.
 

Scalability Issues

Sentiment score
7.4
ExtraHop Reveal(x) is versatile, highly scalable, and globally used, despite potential capacity and cost challenges for smaller organizations.
Sentiment score
7.0
NetWitness NDR is scalable for large enterprises, though some users report issues with scalability and agent migration.
 

Stability Issues

Sentiment score
8.0
ExtraHop Reveal(x) is praised for its stability, reliability, and consistent performance, with users rating it highly overall.
Sentiment score
7.7
NetWitness NDR is generally reliable, providing real-time data and stability, though minor technical issues are occasionally reported.
 

Room For Improvement

ExtraHop Reveal(x) needs better pricing, enhanced protocol support, improved UI, integration, training, and swift technical support.
NetWitness NDR requires improvements in UI, scalability, detectability, integration, session times, pricing, training, and features, making it complex and slow.
Currently, we have to check manually as we do not receive any notifications about new patches, maintenance, or firmware releases.
I would like to see improvements in areas where events are getting dropped; we're not able to view complete insights.
 

Setup Cost

ExtraHop Reveal(x) is costly, especially for scalability and features, but offers value with potential discounts for some users.
 

Valuable Features

ExtraHop Reveal(x) enhances security and performance insights with user-friendly analytics, machine learning, and extensive integration capabilities.
NetWitness NDR offers high detection rates, real-time malware response, third-party integration, and a user-friendly, interoperable interface with advanced analytics.
If I want to know a specific IP and which server it has been connected to, it's easy to gather those kinds of trees from the NDR.
The solution offers a friendly GUI for security features.
 

Categories and Ranking

ExtraHop Reveal(x)
Ranking in Network Detection and Response (NDR)
5th
Average Rating
8.6
Reviews Sentiment
7.4
Number of Reviews
14
Ranking in other categories
Network Traffic Analysis (NTA) (5th)
NetWitness NDR
Ranking in Network Detection and Response (NDR)
21st
Average Rating
8.0
Reviews Sentiment
6.9
Number of Reviews
15
Ranking in other categories
Endpoint Protection Platform (EPP) (59th), Threat Intelligence Platforms (39th), Endpoint Detection and Response (EDR) (60th), Security Orchestration Automation and Response (SOAR) (25th), Extended Detection and Response (XDR) (38th)
 

Mindshare comparison

As of June 2025, in the Network Detection and Response (NDR) category, the mindshare of ExtraHop Reveal(x) is 8.7%, down from 10.7% compared to the previous year. The mindshare of NetWitness NDR is 2.1%, up from 1.9% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Network Detection and Response (NDR)
 

Featured Reviews

Jordan Swanson - PeerSpot reviewer
It helps you visualize how data moves across your network
I rate ExtraHop Reveal(x) 10 out of 10. This is more of a nice-to-have rather than a must-have solution. Something like a CrowdStrike or a next-gen AV is an essential product, whereas NDR is more of a nice-to-have thing. If you only have a little bit of traffic, you're probably not going to get anything out of it. It's better for a medium-to-large enterprise. It's more appropriate for companies wh a massfootprints or industrial applications using use nonstandard devices. It's helpful for things that use SCADA, the Internet of Things, somethingings that don't fit neatly into other management categories. Itty common for industrial, construction, or maintenance devices to be a little lackluster in their security. Major breaches like the Colonial Pipeline hack and attempted hacks on nuclear power plants all went through Internet of Things vulnerabilities and other devices where security wasn't part of their plan. This helps you cover yourself by monitoring the traffic. With something like CrowdStrike, you need to put the CrowdStrike sensor on it, but Reveal(x) looks at everything on the network.
SupravatMaji - PeerSpot reviewer
Beneficial single unified dashboard, good native application integration, and high availability
My advice to those wanting to implement RSA NetWitness Network is they have to first do a little due diligence, such as the exact requirement based on their needs. That will give them a direction for their investment because otherwise, the bill of material or bill of quantity (BOQ) may be higher side. It is important to do good due intelligence on the environment, see the exact requirement, and then go ahead with the solution. The solution is perfectly stable. I rate RSA NetWitness Network a nine out of ten.
report
Use our free recommendation engine to learn which Network Detection and Response (NDR) solutions are best for your needs.
856,873 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Financial Services Firm
18%
Computer Software Company
12%
Government
7%
Healthcare Company
7%
Computer Software Company
17%
Financial Services Firm
16%
Government
10%
Manufacturing Company
9%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

What is the best network monitoring software for large enterprises?
We just did an assessment for our 47 datacenters around North America. The top two enterprise-level network monitoring solutions were ExtraHop first, Riverbed SteelCenter second. Their negotiated c...
What open source tool can one use to measure bandwidth from one's upstream service provider?
One I am looking closely at is AppNeta. They have an appliance that can digest the flow and do a better job than Netflow. The other one we are using is ExtraHop. This has both a Datacenter Hig...
What do you like most about ExtraHop Reveal(x)?
With ExtraHop Reveal(x), it gives me more visibility into the packets. It doesn't provide the entire packet capture, but it offers more information on how connections are made at the network layer....
Ask a question
Earn 20 points
 

Also Known As

Reveal(x), Revealx
RSA ECAT, NetWitness Network
 

Overview

 

Sample Customers

Wood County Hospital
ADP, Ameritas, Partners Healthcare
Find out what your peers are saying about ExtraHop Reveal(x) vs. NetWitness NDR and other solutions. Updated: June 2025.
856,873 professionals have used our research since 2012.