Try our new research platform with insights from 80,000+ expert users

ManageEngine Log360 vs NetWitness Platform comparison

 

Comparison Buyer's Guide

Executive SummaryUpdated on Sep 18, 2024

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

ManageEngine Log360
Ranking in Log Management
19th
Ranking in Security Information and Event Management (SIEM)
18th
Average Rating
7.4
Reviews Sentiment
6.9
Number of Reviews
17
Ranking in other categories
User Entity Behavior Analytics (UEBA) (10th)
NetWitness Platform
Ranking in Log Management
35th
Ranking in Security Information and Event Management (SIEM)
31st
Average Rating
7.4
Reviews Sentiment
7.4
Number of Reviews
37
Ranking in other categories
No ranking in other categories
 

Mindshare comparison

As of August 2025, in the Log Management category, the mindshare of ManageEngine Log360 is 1.1%, down from 1.1% compared to the previous year. The mindshare of NetWitness Platform is 0.4%, up from 0.3% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Log Management
 

Featured Reviews

Md Abdul Hakim - PeerSpot reviewer
Integration capabilities impress while room for improvement exists in cloud compatibility
1. Enhanced Cloud Integration Current Gap: Log360 lacks native integration with Microsoft Intune and cloud-based Active Directory (Azure AD), limiting visibility for organizations transitioning to hybrid or fully cloud environments. Requested Improvements: Direct Intune Log Collection: Ability to ingest and correlate logs from Intune-managed devices to monitor compliance, device health, and security policies. Azure AD Deep Integration: Support for Azure AD audit logs, conditional access events, and identity protection alerts to provide end-to-end visibility. Cloud Workload Monitoring: Extend coverage to SaaS applications (e.g., Microsoft 365, AWS, GCP) for unified threat detection. Why It Matters: Many clients have migrated from on-prem AD to cloud-first setups this year. Without cloud-native log collection, critical security events (e.g., rogue Intune policies or Azure AD breaches) go unmonitored. 2. Improved Automation and Response Current Gap: Limited automated remediation (e.g., auto-isolating compromised devices) forces manual intervention. Requested Features: Playbook Automation: Pre-built workflows to auto-resolve common issues (e.g., disabling users after brute-force attacks). SOAR Integration: APIs to connect with SIEM/SOAR platforms (e.g., Splunk, Palo Alto Cortex) for escalated threat response.
MOTASHIM Al Razi - PeerSpot reviewer
It is a stable solution, but they should make the user interface easier to understand
The solution's initial setup takes work. We have to organize multiple paths and many features. The deployment process takes less than a week. But it takes a month to complete if we want to make the solution smarter by integrating it with various devices. I rate the process as a six out of ten.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"The deployment is quite simple and pretty straightforward."
"The solution could be improved by including XDR, remediation and Sandbox."
"ManageEngine Log360 is not difficult to deploy."
"The Sharecon feature is the most valuable."
"The product is very user-friendly."
"The reporting is great. Everything you need is in the report for you already."
"It basically helps us. We have to stay in compliance with certain issues with some of our customers. We have to have these types of tools in place for protecting our network and our data. We're in the aerospace industry, so we have a lot of defense contracts. So, all those guys will make sure that we're protecting their information, and it does a good job in that aspect."
"The reports that you can run are really nice."
"Incident management is its most valuable feature."
"The most valuable feature is the hunting ability to work in a CERT."
"The newer 11.5 version that my team is using has found it to have good mapping."
"The packet capture aspect of it is a valuable feature because it is quite different from a traditional SIEM solution that only carries out investigations based on captured logs."
"The most valuable feature is that we can create our own connectors for any application, and NetWitness provides the training and tools to do it."
"In my opinion, the solution's most valuable feature is its capacity to monitor network traffic, logs from devices within the network, and network captures. This capability extends beyond logs to include full network capturing."
"Alerting Module: It provides real-time event processing language on all the logs/packets stream for advanced alerting, i.e., using SQL LIKE statements."
"Possibility to investigate incidents based on logs and raw packets, such as extracting files sent over the network"
 

Cons

"On the logging system, there's a local on-client side that is encrypted, and there's one that is not encrypted. It is only for diagnostical purposes. However, both being encrypted would be very valuable for some audits."
"The support needs improvement."
"Their technical support should be improved."
"It is not expensive compared to other solutions."
"Log360 currently cannot gather information from Intune logs or cloud-integrated systems."
"It's difficult to find which conditions have been applied to a report because they are provided by default by ManageEngine. However, with other SIEMs if you want to create a report, they provide details, like which conditions are triggering certain reports. This needs to be there in ManageEngine. It would be good to know which parameter has been applied to the report that is updating the system."
"The integration with SharePoint and Teams should be improved."
"There is room for improvement, especially in the reporting aspect. The reports are not as good as those in Splunk."
"The initial setup was complex because it takes a lot of time to complete the implementation."
"An area for improvement would be better automation and more inbuilt use cases."
"The tool's integration capability isn't so great."
"Security needs improvement."
"Technical support could be improved."
"The implementation needs assistance."
"It should have a monitoring feature. It would help us analyze the current state of attacks faster from a single platform."
"The system architecture is complex and sometimes it’s hard to troubleshoot potential problems."
 

Pricing and Cost Advice

"ManageEngine Log360 is expensive compared to other products."
"My client has a yearly license. I think the cost is not expensive compared to that of other SIEMs, given the service it is providing."
"Its pricing is definitely huge compared to some of the other SIEMs. Its price should be improved."
"Affordable pricing is provided by the solution."
"There is a cost for each feature used."
"The licenses are good but the cost is very expensive."
"Our license is for one year."
"The product is expensive."
"RSA NetWitness Logs and Packets do not have a subscription model, it's a one-time purchase. There is only a perpetual license."
"There is a licensing fee and the customer can choose whether he wishes this to be subscription-based or perpetual."
"Many clients are not able to purchase the packet capability because there is a huge amount of data, and the cost depends on the number of EPS (Events per second), as well as the number of gigabytes of data per day."
"The new pricing and licensing mechanisms are fair. I would advise always to get the full solution (i.e., not only Logs)."
"The tool is very expensive, so I rate the pricing a ten out of ten. The solution has an annual subscription."
report
Use our free recommendation engine to learn which Log Management solutions are best for your needs.
865,384 professionals have used our research since 2012.
 

Comparison Review

VS
Feb 26, 2015
HP ArcSight vs. IBM QRadar vs. ​McAfee Nitro vs. Splunk vs. RSA Security vs. LogRhythm
We at Infosecnirvana.com have done several posts on SIEM. After the Dummies Guide on SIEM, we are following it up with a SIEM Product Comparison – 101 deck. So, here it is for your viewing pleasure. Let me know what you think by posting your comments below. The key products compared here are…
 

Top Industries

By visitors reading reviews
Computer Software Company
14%
Manufacturing Company
9%
Financial Services Firm
7%
Healthcare Company
6%
Financial Services Firm
14%
Computer Software Company
13%
Comms Service Provider
6%
Manufacturing Company
6%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

What is your experience regarding pricing and costs for ManageEngine Log360?
The price is suitable from a perspective of different pricing options. We already have an ongoing project where some features analytics can be escaped, and companies can manage their budgets carefu...
What needs improvement with ManageEngine Log360?
1. Enhanced Cloud Integration Current Gap: Log360 lacks native integration with Microsoft Intune and cloud-based Active Directory (Azure AD), limiting visibility for organizations transitioning to ...
What do you like most about NetWitness Platform?
The product's initial setup phase was not at all difficult.
What is your experience regarding pricing and costs for NetWitness Platform?
The pricing is comparable to others, and I consider the cost to be intermediate. Specific cost details are unknown to me.
What needs improvement with NetWitness Platform?
There is currently no need for improvement in the SIEM ( /categories/security-information-and-event-management-siem ), though there could be potential enhancements by integrating with AI.
 

Also Known As

No data available
RSA Security Analytics
 

Overview

 

Sample Customers

First Mountain Bank, TRA, Citadel Group, OnPoint Financial Corp, Florida Dept. of Transportation
Los Angeles World Airports, Reply
Find out what your peers are saying about ManageEngine Log360 vs. NetWitness Platform and other solutions. Updated: July 2025.
865,384 professionals have used our research since 2012.