No more typing reviews! Try our Samantha, our new voice AI agent.

Fortinet FortiSandbox vs NetWitness Platform comparison

Why PeerSpot?
 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Fortinet FortiSandbox
Average Rating
8.2
Reviews Sentiment
7.1
Number of Reviews
39
Ranking in other categories
Advanced Threat Protection (ATP) (10th), Threat Deception Platforms (3rd)
NetWitness Platform
Average Rating
7.4
Reviews Sentiment
7.4
Number of Reviews
36
Ranking in other categories
Log Management (36th), Security Information and Event Management (SIEM) (34th)
 

Mindshare comparison

Fortinet FortiSandbox and NetWitness Platform aren’t in the same category and serve different purposes. Fortinet FortiSandbox is designed for Advanced Threat Protection (ATP) and holds a mindshare of 4.4%, down 6.9% compared to last year.
NetWitness Platform, on the other hand, focuses on Log Management, holds 1.1% mindshare, up 0.4% since last year.
Advanced Threat Protection (ATP) Mindshare Distribution
ProductMindshare (%)
Fortinet FortiSandbox4.4%
Palo Alto Networks WildFire6.7%
Microsoft Defender for Office 3656.1%
Other82.8%
Advanced Threat Protection (ATP)
Log Management Mindshare Distribution
ProductMindshare (%)
NetWitness Platform1.1%
Splunk Enterprise Security6.8%
IBM Security QRadar4.5%
Other87.6%
Log Management
 

Featured Reviews

AN
Security Manager at a computer software company with 11-50 employees
Advanced sandboxing has protected users from zero-day threats and has simplified secure file scanning
The smooth integrations between Fortinet FortiSandbox and other Fortinet solutions such as FortiWeb and FortiFirewall and with other Fortinet environments are what I really appreciate. We have minimum false positives during threat detection. Our clients have not given negative feedback from detection. As you know, it still needs some tuning after implementation. However, we never receive negative feedback for many false positives during implementation.
reviewer2256927 - PeerSpot reviewer
Head of Information Security, Cyber Defense and IT Risk Management at HCT. at a transportation company with 201-500 employees
A solid SIEM solution that should improve technical support and online resources to be easier to use
A big problem with the product is that we don't have much professional experience in Israel installing, implementing, and integrating this product. There is not enough of a knowledge base. There is no support for this product in this country, so problems have to be resolved through global technical teams. We like to work locally because of the language, and when the product is only supported outside the country, it's a little difficult to implement and use this product. Moreover, AI is something that must be added immediately. Artificial intelligence is a part of the competitors' products, and it's not been implemented for us.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"The product is great. It can be deployed on the cloud or on-premises."
"Fortinet FortiSandbox puts suspicious files in quarantine, analyzes for virus risks, and lets them out of quarantine if it detects no risk."
"I'm very satisfied with this product."
"Fortinet FortiSandbox's most valuable feature is the security it provides against threats, such as ransomware. Additionally, it integrates well with APIs."
"Fortinet FortiSandbox works fine, is easy to manage, and functions well."
"The solution is very good because it catches a lot of threats in emails."
"We have seen a measurable decrease in the mean time to detect or respond to threats, on the order of 20 percent."
"The installation is easy and straightforward."
"Offers a good wireless feature."
"The most valuable features are the packet decoder, log decoder, and concentrator."
"Setting up NetWitness is straightforward. There are multiple connectors, including standard and specialized connectors. One purpose of the connectors is the enhanced capability integrate the custom applications. NetWitness comes with E6 appliances and application images that we use for the initial configurations and for the OS stack information. From there, you can consider the correlation rules, integrate the different log sources, and easily create correlation rules and backlog reports."
"NetWitness Platform is valuable for creating rules that the solution must detect."
"What we are mainly using are the RSA concentrator, RSA Decoder, Archiver, Broker, and Log Decoder."
"Alerting Module: It provides real-time event processing language on all the logs/packets stream for advanced alerting, i.e., using SQL LIKE statements."
"This solution has a very good dashboard with a separate tab for incidents and alerts."
"It's fully scalable. There is no limit. Of course, the license limits per day the number of terabytes. In my opinion, it's very flexible."
 

Cons

"It can be difficult if you need to use the Command Line Interface (CLI). It's much easier if you only have to deal with the GUI."
"I think there are problems with the scalability. If you need to extend or add more sizing, that means more files per day, we have to change the kind of appliance."
"Most people are confused about how to use the right integration of the right Fortinet product."
"The product is good but it could be speedier. In addition, it's quite complex."
"If they plan to provide a feature that would make it easier for the customer to configure themselves, that would be appropriate."
"Fortinet FortiSandbox can improve by decreasing the time of analysis response. Other solutions have a better response time, such as WildFire."
"We sometimes face a delay in email scanning due to not having multiple virtual machines."
"For additional features, maybe a form of execution pain files in a non-virtual environment because it has threats that identify when it is being run in a virtual machine."
"But the 11.3 version is a complete disaster. You cannot analyze anything."
"The product continues to crash. Even with tech support help, it does not resolve itself."
"The implementation needs assistance."
"The system looks like it is a mix of a bunch of different systems, and nothing looked like it was quite together."
"One thing to be improved in NetWitness is the capability to correlate event logs in a general sense."
"The multi-tenant capabilities are lagging compared to IBM QRadar."
"It should have a monitoring feature. It would help us analyze the current state of attacks faster from a single platform."
"RSA NetWitness Logs and Packets is far behind the competition."
 

Pricing and Cost Advice

"Fortinet FortiSandbox is a nominally priced product, so I would not say that it is a very cheap tool."
"The solution is not expensive at all."
"The license for Fortinet FortiSandbox depends on the use case."
"The price of Fortinet FortiSandbox is not expensive."
"It is an expensive solution."
"There are no costs in addition to the standard licensing fees."
"The solution is affordable."
"Fortinet is more reasonable than Palo Alto."
"Our license is for one year."
"Many clients are not able to purchase the packet capability because there is a huge amount of data, and the cost depends on the number of EPS (Events per second), as well as the number of gigabytes of data per day."
"We have yearly licensing costs. The license fee can be based on the volume of EPS. Some organizations may have, as a gentlemanly gesture, 10,000 EPS and get a 3,000 EPS license but actually use 5,000 EPS."
"RSA NetWitness Logs and Packets do not have a subscription model, it's a one-time purchase. There is only a perpetual license."
"The product price was reasonable for my region and the market."
"There is a licensing fee and the customer can choose whether he wishes this to be subscription-based or perpetual."
"We are on an annual license for the use of the solution."
"Compared to the competition, the is price is not that high."
report
Use our free recommendation engine to learn which Advanced Threat Protection (ATP) solutions are best for your needs.
912,069 professionals have used our research since 2012.
 

Comparison Review

VS
Manager, Enterprise Risk Consulting at a tech company with 1,001-5,000 employees
Feb 26, 2015
HP ArcSight vs. IBM QRadar vs. ​McAfee Nitro vs. Splunk vs. RSA Security vs. LogRhythm
We at Infosecnirvana.com have done several posts on SIEM. After the Dummies Guide on SIEM, we are following it up with a SIEM Product Comparison – 101 deck. So, here it is for your viewing pleasure. Let me know what you think by posting your comments below. The key products compared here are…
 

Top Industries

By visitors reading reviews
Manufacturing Company
12%
Financial Services Firm
11%
Comms Service Provider
10%
Construction Company
8%
Construction Company
12%
Financial Services Firm
11%
Outsourcing Company
10%
Comms Service Provider
10%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business16
Midsize Enterprise13
Large Enterprise9
By reviewers
Company SizeCount
Small Business8
Midsize Enterprise7
Large Enterprise20
 

Questions from the Community

What is your experience regarding pricing and costs for Fortinet FortiSandbox?
The cost is in the mid-range. It is not low and it is not high.
What needs improvement with Fortinet FortiSandbox?
I think Fortinet FortiSandbox could introduce more automation tools and AI tools.
What is your primary use case for Fortinet FortiSandbox?
Clients primarily ask us to integrate Fortinet FortiSandbox either with FortiMail or with firewalls to scan downloadable files and ensure that client access browsing is secure with no harmful files...
What is your experience regarding pricing and costs for NetWitness Platform?
The pricing is comparable to others, and I consider the cost to be intermediate. Specific cost details are unknown to me.
What needs improvement with NetWitness Platform?
There is currently no need for improvement in the SIEM ( /categories/security-information-and-event-management-siem ), though there could be potential enhancements by integrating with AI.
What is your primary use case for NetWitness Platform?
I use NetWitness Platform ( /products/netwitness-platform-reviews ) in the financial industry as a good product with excellent capabilities and integration with various devices.
 

Also Known As

FortiSandbox
RSA Security Analytics
 

Overview

 

Sample Customers

Lush, Barnabas Health, Options, Riverside Healthcare, Hillsbourough County Schools, Columbia Public Schools, Schiller AG
Los Angeles World Airports, Reply
Find out what your peers are saying about Palo Alto Networks, Proofpoint, Microsoft and others in Advanced Threat Protection (ATP). Updated: August 2026.
912,069 professionals have used our research since 2012.