Try our new research platform with insights from 80,000+ expert users

Gurucul Next Gen SIEM vs NetWitness Platform comparison

 

Comparison Buyer's Guide

Executive SummaryUpdated on Sep 18, 2024

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Gurucul Next Gen SIEM
Ranking in Security Information and Event Management (SIEM)
39th
Average Rating
7.6
Reviews Sentiment
7.1
Number of Reviews
3
Ranking in other categories
No ranking in other categories
NetWitness Platform
Ranking in Security Information and Event Management (SIEM)
30th
Average Rating
7.4
Reviews Sentiment
7.4
Number of Reviews
37
Ranking in other categories
Log Management (33rd)
 

Mindshare comparison

As of October 2025, in the Security Information and Event Management (SIEM) category, the mindshare of Gurucul Next Gen SIEM is 0.3%, up from 0.1% compared to the previous year. The mindshare of NetWitness Platform is 0.6%, up from 0.6% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Security Information and Event Management (SIEM) Market Share Distribution
ProductMarket Share (%)
NetWitness Platform0.6%
Gurucul Next Gen SIEM0.3%
Other99.1%
Security Information and Event Management (SIEM)
 

Featured Reviews

Ansar Monideen - PeerSpot reviewer
Provides almost all the SIEM features offered by the leaders at a low cost
Gurucul's data enrichment could be improved. As a security professional, I want to consolidate all these log sources and data to the user, entity, or resource. More advancements are required, especially in enriching security data or attack response. I would like to see more improvements there. The documentation could also be better. Every user and resource has a timeline that lists all the events so we can analyze that particular system and what is happening. We would like to have an option where we can only list the confirmed security threat-related activities for a particular user rather than all activities. This way, we can see what kind of risk is reported for this user and be able to monitor them better.
MOTASHIM Al Razi - PeerSpot reviewer
It is a stable solution, but they should make the user interface easier to understand
The solution's initial setup takes work. We have to organize multiple paths and many features. The deployment process takes less than a week. But it takes a month to complete if we want to make the solution smarter by integrating it with various devices. I rate the process as a six out of ten.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"I like the amount of customization we can do with Gurucul. We can customize each solution and evaluate it. We can investigate the alerts that it creates and fine-tune them to ensure that whatever is reported has some risk."
"The customization of reporting rules, reporting configuration, and alerting configuration are good."
"Gurucul Next Gen SIEM stands out for its user-friendliness, making it accessible to business users."
"In my opinion, the solution's most valuable feature is its capacity to monitor network traffic, logs from devices within the network, and network captures. This capability extends beyond logs to include full network capturing."
"Offers a good wireless feature."
"The most valuable feature is that we can create our own connectors for any application, and NetWitness provides the training and tools to do it."
"Incident management is its most valuable feature."
"It's quite economical compared to other solutions in the market."
"The software is scalable to whatever is required, and you can also put a lot of resources in the cloud."
"Performance and reporting are very good."
"The newer 11.5 version that my team is using has found it to have good mapping."
 

Cons

"Gurucul's data enrichment could be improved. As a security professional, I want to consolidate all these log sources and data to the user, entity, or resource. More advancements are required, especially in enriching security data or attack response. I would like to see more improvements there."
"I would like Gurucul to identify the use cases that have already been reviewed by someone when detection occurs."
"The user interface could be made simpler."
"The tool's integration capability isn't so great."
"RSA NetWitness Logs and Packets can improve the threat level aspect, it is lacking compared to other solutions. Whenever any hacking activity or any other threat factor occurred they used to provide the coverages very fast when comparing RSA NetWitness Logs and Packets. I heard the other three solutions, from a discussion with my team members who had experience in other solutions, they used to say that. Whenever any issues happened across the globe RSA NetWitness Logs and Packets are a little bit slow improving those detection mechanisms."
"The implementation needs assistance."
"More customizability is required, which is something that they need to improve on."
"We have encountered issues with unresolved crashes."
"The multi-tenant capabilities are lagging compared to IBM QRadar."
"The initial setup is complex. There are other solutions that are easier to implement."
"The system architecture is complex and sometimes it’s hard to troubleshoot potential problems."
 

Pricing and Cost Advice

"The pricing is exceptionally good"
"The licenses are good but the cost is very expensive."
"The NetWitness Platform may be affordable only for enterprise-level customers, as it may not be within the budget of small and medium-sized businesses."
"Our license is for one year."
"We are on an annual license for the use of the solution."
"This is a pricey solution; it's not cheap."
"We have a perpetual license, so the total cost of ownership is not very expensive. It's a good investment."
"There is a licensing fee and the customer can choose whether he wishes this to be subscription-based or perpetual."
"It’s cheaper to run virtual machines in a VMware environment."
report
Use our free recommendation engine to learn which Security Information and Event Management (SIEM) solutions are best for your needs.
869,566 professionals have used our research since 2012.
 

Comparison Review

VS
Feb 26, 2015
HP ArcSight vs. IBM QRadar vs. ​McAfee Nitro vs. Splunk vs. RSA Security vs. LogRhythm
We at Infosecnirvana.com have done several posts on SIEM. After the Dummies Guide on SIEM, we are following it up with a SIEM Product Comparison – 101 deck. So, here it is for your viewing pleasure. Let me know what you think by posting your comments below. The key products compared here are…
 

Top Industries

By visitors reading reviews
Computer Software Company
11%
Performing Arts
10%
Government
10%
Educational Organization
7%
Financial Services Firm
13%
Computer Software Company
12%
Comms Service Provider
7%
Performing Arts
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
No data available
By reviewers
Company SizeCount
Small Business9
Midsize Enterprise7
Large Enterprise20
 

Questions from the Community

What do you like most about Gurucul Next Gen SIEM?
The customization of reporting rules, reporting configuration, and alerting configuration are good.
What is your experience regarding pricing and costs for Gurucul Next Gen SIEM?
The pricing is exceptionally good. I have personally implemented several SIEM solutions that are significantly more expensive. I won't name the companies, but one particularly well-known and expens...
What needs improvement with Gurucul Next Gen SIEM?
Gurucul's data enrichment could be improved. As a security professional, I want to consolidate all these log sources and data to the user, entity, or resource. More advancements are required, espec...
What do you like most about NetWitness Platform?
The product's initial setup phase was not at all difficult.
What is your experience regarding pricing and costs for NetWitness Platform?
The pricing is comparable to others, and I consider the cost to be intermediate. Specific cost details are unknown to me.
What needs improvement with NetWitness Platform?
There is currently no need for improvement in the SIEM ( /categories/security-information-and-event-management-siem ), though there could be potential enhancements by integrating with AI.
 

Also Known As

No data available
RSA Security Analytics
 

Overview

 

Sample Customers

Information Not Available
Los Angeles World Airports, Reply
Find out what your peers are saying about Gurucul Next Gen SIEM vs. NetWitness Platform and other solutions. Updated: September 2025.
869,566 professionals have used our research since 2012.