Try our new research platform with insights from 80,000+ expert users

Gigamon Deep Observability Pipeline vs NetWitness Platform comparison

 

Comparison Buyer's Guide

Executive SummaryUpdated on Sep 18, 2024

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Gigamon Deep Observability ...
Ranking in Security Information and Event Management (SIEM)
45th
Average Rating
8.6
Reviews Sentiment
7.2
Number of Reviews
8
Ranking in other categories
Application Performance Monitoring (APM) and Observability (39th), Event Monitoring (10th), Data Loss Prevention (DLP) (30th), Web Application Firewall (WAF) (32nd), Advanced Threat Protection (ATP) (25th), Network Packet Broker (NPB) (1st), Network Detection and Response (NDR) (20th)
NetWitness Platform
Ranking in Security Information and Event Management (SIEM)
29th
Average Rating
7.4
Reviews Sentiment
7.4
Number of Reviews
37
Ranking in other categories
Log Management (38th)
 

Mindshare comparison

As of June 2025, in the Security Information and Event Management (SIEM) category, the mindshare of Gigamon Deep Observability Pipeline is 0.1%, up from 0.0% compared to the previous year. The mindshare of NetWitness Platform is 0.6%, down from 0.8% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Security Information and Event Management (SIEM)
 

Featured Reviews

LeonardoAlves - PeerSpot reviewer
Improved the capability to analyze the environment and network problems with easy setup
It improved the capability to analyze the environment and network problems. It also helped streamline your security and performance monitoring The application I use is a script. My environment is a mix of technologies. I have many passionate people in my network who are on a journey in…
MOTASHIM Al Razi - PeerSpot reviewer
It is a stable solution, but they should make the user interface easier to understand
The solution's initial setup takes work. We have to organize multiple paths and many features. The deployment process takes less than a week. But it takes a month to complete if we want to make the solution smarter by integrating it with various devices. I rate the process as a six out of ten.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"The most valuable feature is NetFlow."
"The solution is straightforward to set up."
"The most valuable feature for improving network visibility with Gigamon is the packet filtering capability."
"The tool's most valuable feature is the encryption feature. From a security perspective, the solution hasn't significantly strengthened our security posture. However, it has greatly improved performance by streamlining encryption processes and avoiding encryption at multiple layers. This has also simplified troubleshooting, as we can whitelist certain processes."
"It has high stability."
"It offers straightforward integration."
"It is a good product. It provides network visibility, which is important. Gigamon can bring some optimizations to my network. It is helpful for security inspection, and it makes my firewall work fast because my firewall doesn't have to do the inspection of the SSL connections, for example."
"NetWitness can be highly beneficial for incident detection and response."
"The most valuable feature is the ability to write rules and triggers for network communication, and then being able to investigate based on that."
"The most valuable features are the packet decoder, log decoder, and concentrator."
"The development of use cases on the SSA console is quite user friendly. This means that the security analyst or the researcher does not have to learn another language."
"The most valuable feature of RSA NetWitness Logs and Packets are the alerts and correlations tools."
"I can have enterprise security, email security, next generation firewall security log, HIDS and NIDS logs, etc. all on the same dashboard. It makes it easy to pinpoint or correlate our server to this. I can find out if there is lateral movement. This is the biggest advantage of this solution."
"The solution is really scalable for the high-end power, enterprise customer."
"It's fully scalable. There is no limit. Of course, the license limits per day the number of terabytes. In my opinion, it's very flexible."
 

Cons

"Its filtering feature needs improvement."
"It only inspects a specific kind of traffic. There should be different kinds of use cases."
"They should increase the solution's cluster capacity."
"The security should be improved."
"The graphical user interface could be improved."
"In terms of improvement, while the initial setup is not overly complicated, we did encounter a few issues."
"The Gigamon Deep Observability Pipeline should have a feature showing the traffic flow within its platform. Currently, customers have to use separate tools for monitoring, which is inconvenient. If it had its visibility feature, it would make monitoring easier and more complete without needing extra tools."
"Security needs improvement."
"We have encountered issues with unresolved crashes."
"The log system is a bit complex and has room for improvement."
"RSA NetWitness Logs and Packets can improve the threat level aspect, it is lacking compared to other solutions. Whenever any hacking activity or any other threat factor occurred they used to provide the coverages very fast when comparing RSA NetWitness Logs and Packets. I heard the other three solutions, from a discussion with my team members who had experience in other solutions, they used to say that. Whenever any issues happened across the globe RSA NetWitness Logs and Packets are a little bit slow improving those detection mechanisms."
"The user interface is a little bit difficult for new users and it needs to be improved."
"Health monitoring of the event sources and devices."
"There are instances where you try to run the reports and then it does not give you the desired outcome."
"I believe that integrating the solution with other products such as Oracle would be beneficial."
 

Pricing and Cost Advice

"I would rate the solution as expensive, around an eight or nine out of ten. There are other competitive solutions available."
"The solution is highly-priced."
"The solution's price is reasonable."
"We are on an annual license for the use of the solution."
"We have a perpetual license, so the total cost of ownership is not very expensive. It's a good investment."
"It’s cheaper to run virtual machines in a VMware environment."
"This is a pricey solution; it's not cheap."
"We have yearly licensing costs. The license fee can be based on the volume of EPS. Some organizations may have, as a gentlemanly gesture, 10,000 EPS and get a 3,000 EPS license but actually use 5,000 EPS."
"Compared to the competition, the is price is not that high."
"It is cheap."
"In comparison to other SIEM solutions such as Splunk, NetWitness is less costly."
report
Use our free recommendation engine to learn which Security Information and Event Management (SIEM) solutions are best for your needs.
859,129 professionals have used our research since 2012.
 

Comparison Review

VS
Feb 26, 2015
HP ArcSight vs. IBM QRadar vs. ​McAfee Nitro vs. Splunk vs. RSA Security vs. LogRhythm
We at Infosecnirvana.com have done several posts on SIEM. After the Dummies Guide on SIEM, we are following it up with a SIEM Product Comparison – 101 deck. So, here it is for your viewing pleasure. Let me know what you think by posting your comments below. The key products compared here are…
 

Top Industries

By visitors reading reviews
Financial Services Firm
16%
Computer Software Company
15%
Healthcare Company
7%
Manufacturing Company
7%
Computer Software Company
18%
Financial Services Firm
18%
Government
5%
Manufacturing Company
5%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

What do you like most about Gigamon Deep Observability Pipeline?
The most valuable feature for improving network visibility with Gigamon is the packet filtering capability.
What needs improvement with Gigamon Deep Observability Pipeline?
The challenge is monitoring the cloud network. In on-premises environments, monitoring is straightforward, as I can verify all packets and communications. However, due to the way access tools and p...
What is your primary use case for Gigamon Deep Observability Pipeline?
It improved the capability to analyze the environment and network problems. It also helped streamline your security and performance monitoring.
What do you like most about NetWitness Platform?
The product's initial setup phase was not at all difficult.
What is your experience regarding pricing and costs for NetWitness Platform?
The pricing is comparable to others, and I consider the cost to be intermediate. Specific cost details are unknown to me.
What needs improvement with NetWitness Platform?
There is currently no need for improvement in the SIEM ( /categories/security-information-and-event-management-siem ), though there could be potential enhancements by integrating with AI.
 

Also Known As

Gigamon, GigaSecure
RSA Security Analytics
 

Overview

 

Sample Customers

Amica Insurance, College of William & Mary, Gamma, IntercontinentalExchange, OppenheimerFunds
Los Angeles World Airports, Reply
Find out what your peers are saying about Gigamon Deep Observability Pipeline vs. NetWitness Platform and other solutions. Updated: June 2025.
859,129 professionals have used our research since 2012.