Try our new research platform with insights from 80,000+ expert users

NetWitness Platform vs Palo Alto Networks VM-Series comparison

 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

NetWitness Platform
Average Rating
7.4
Reviews Sentiment
7.4
Number of Reviews
37
Ranking in other categories
Log Management (34th), Security Information and Event Management (SIEM) (30th)
Palo Alto Networks VM-Series
Average Rating
8.6
Reviews Sentiment
7.0
Number of Reviews
65
Ranking in other categories
Firewalls (12th), Advanced Threat Protection (ATP) (9th)
 

Mindshare comparison

NetWitness Platform and Palo Alto Networks VM-Series aren’t in the same category and serve different purposes. NetWitness Platform is designed for Log Management and holds a mindshare of 0.4%, up 0.3% compared to last year.
Palo Alto Networks VM-Series, on the other hand, focuses on Firewalls, holds 1.0% mindshare, up 0.6% since last year.
Log Management Market Share Distribution
ProductMarket Share (%)
NetWitness Platform0.4%
Wazuh12.6%
Grafana Loki8.1%
Other78.9%
Log Management
Firewalls Market Share Distribution
ProductMarket Share (%)
Palo Alto Networks VM-Series1.0%
Fortinet FortiGate20.1%
Netgate pfSense11.1%
Other67.8%
Firewalls
 

Featured Reviews

MOTASHIM Al Razi - PeerSpot reviewer
It is a stable solution, but they should make the user interface easier to understand
The solution's initial setup takes work. We have to organize multiple paths and many features. The deployment process takes less than a week. But it takes a month to complete if we want to make the solution smarter by integrating it with various devices. I rate the process as a six out of ten.
RonnieYazdani - PeerSpot reviewer
User-friendly CLI and efficient dashboard streamline operations with robust security features
I find Palo Alto Networks VM-Series easy to deploy, and none of my customers have had significant complaints. My customers have high certifications provided by Palo Alto Networks. The friendly dashboard and the ability to easily command and use the CLI make Palo Alto Networks VM-Series a better product. It offers robust solutions, making it valuable to my customers.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"The product's initial setup phase was not at all difficult."
"NetWitness can be highly beneficial for incident detection and response."
"The packet capture aspect of it is a valuable feature because it is quite different from a traditional SIEM solution that only carries out investigations based on captured logs."
"The most valuable features are the integration and ease of use."
"The most valuable features are the packet decoder, log decoder, and concentrator."
"The most valuable features are the threat prediction and network forensics."
"The most valuable features are the packet inspection and the automated incident response."
"It gives the ability to investigate into network traffic in the Net and the organization what we couldn't do before."
"We use the product on our Azure network firewalls."
"Palo Alto offers excellent security, with features such as email scanning, malware protection, and efficient VPN and antivirus capabilities."
"The filtering feature is good."
"You already can scale it if you put it in Auto Scaling groups. If you put it in a load balancer, it should already be able to scale."
"It is very stable. It is fairly easy to use."
"We can monitor the traffic manually and detect threats. Additionally, we can block different IP addresses and URLs."
"The most effective features for threat prevention include the threat prevention signature level, the application filter capability, and the visibility provided by the firewalls."
"Palo Alto Networks VM-Series has everything centralized. You have the VPN solution, firewall, routing, UDR, flexibility, updates, and full visibility of your traffic."
 

Cons

"We have encountered issues with unresolved crashes."
"Sometimes, it gives me static when integrating Windows-based systems. It should produce a precise log of sorts as to where the problem is. For example, a few days ago because of the McAfee application firewall, I couldn't get access to the particular Windows machine. So, my team and I had to figure out by ourselves that there was a virus responsible for the obstacle. This solution should trigger a meaningful log or message indicating the reason the user or implementer can't get into the machine."
"There is no support for this product in this country, so problems have to be resolved through global technical teams."
"An area for improvement would be better automation and more inbuilt use cases."
"The multi-tenant capabilities are lagging compared to IBM QRadar."
"Health monitoring of the event sources and devices."
"It should have a monitoring feature. It would help us analyze the current state of attacks faster from a single platform."
"It is not so easy to customize this product."
"It would be helpful if we had a direct number for the support manager or the supporting engineer. That would be better than having to email every time because there would be less wait."
"The only minor issue we've faced is with the app's ID configuration, which requires specific matching for application filtering."
"Palo Alto Networks VM-Series is a complex product to work with."
"Enhancing the ease of accessing technical support would be useful."
"From time to time, they have released some content updates that have some issues, maybe twice a year."
"I find it difficult to reach technical support at Palo Alto Networks."
"When managing the firewall, it involves a Strata Cloud web browser that requires improvement to enhance deployment ease and call center efficiency."
"Palo Alto is that it is really bad when it comes to technical support."
 

Pricing and Cost Advice

"Many clients are not able to purchase the packet capability because there is a huge amount of data, and the cost depends on the number of EPS (Events per second), as well as the number of gigabytes of data per day."
"This is a pricey solution; it's not cheap."
"RSA NetWitness Logs and Packets do not have a subscription model, it's a one-time purchase. There is only a perpetual license."
"There is a licensing fee and the customer can choose whether he wishes this to be subscription-based or perpetual."
"Compared to the competition, the is price is not that high."
"Our license is for one year."
"The NetWitness Platform may be affordable only for enterprise-level customers, as it may not be within the budget of small and medium-sized businesses."
"We have yearly licensing costs. The license fee can be based on the volume of EPS. Some organizations may have, as a gentlemanly gesture, 10,000 EPS and get a 3,000 EPS license but actually use 5,000 EPS."
"There is a need to make payments toward a yearly subscription-based model in which you need to add modules that you want to use in your company."
"The price is not bad. They have a yearly renewal fee, and the pricing is exactly where we expect it to be."
"The product is costly but provides all essential security features. I rate the pricing a seven out of ten."
"Palo Alto definitely needs to be more competitive compared to other products. The problem that I have faced is that the price of licensing is very high and not very competitive."
"We found purchasing process the product on the AWS Marketplace to be very good."
"Palo Alto is more expensive than other products."
"Purchasing on the AWS Marketplace was simple, effective, and easy."
"The box, if you do not want to buy the threat prevention license in the box, you can buy it only with the support license. It is for the support of the hardware. It works like a simple firewall. It integrates what it calls user IDs and application IDs. If you do not buy any other license, only the firewall, Palo Alto will also help you improve a lot of your security."
report
Use our free recommendation engine to learn which Log Management solutions are best for your needs.
867,370 professionals have used our research since 2012.
 

Comparison Review

VS
Feb 26, 2015
HP ArcSight vs. IBM QRadar vs. ​McAfee Nitro vs. Splunk vs. RSA Security vs. LogRhythm
We at Infosecnirvana.com have done several posts on SIEM. After the Dummies Guide on SIEM, we are following it up with a SIEM Product Comparison – 101 deck. So, here it is for your viewing pleasure. Let me know what you think by posting your comments below. The key products compared here are…
 

Top Industries

By visitors reading reviews
Financial Services Firm
13%
Computer Software Company
12%
Performing Arts
7%
Manufacturing Company
6%
Computer Software Company
15%
Financial Services Firm
11%
Manufacturing Company
9%
Performing Arts
5%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business9
Midsize Enterprise7
Large Enterprise20
By reviewers
Company SizeCount
Small Business27
Midsize Enterprise17
Large Enterprise25
 

Questions from the Community

What do you like most about NetWitness Platform?
The product's initial setup phase was not at all difficult.
What is your experience regarding pricing and costs for NetWitness Platform?
The pricing is comparable to others, and I consider the cost to be intermediate. Specific cost details are unknown to me.
What needs improvement with NetWitness Platform?
There is currently no need for improvement in the SIEM ( /categories/security-information-and-event-management-siem ), though there could be potential enhancements by integrating with AI.
Features comparison between Palo Alto and Fortinet firewalls
In the best tradition of these questions, Feature-wise both are quite similar, but each has things it's better at, it kind of depends what you value most. PA is good at app control, web filtering a...
How does Azure Firewall compare with Palo Alto Networks VM Series?
Both products are very stable and easily scalable. The setup of Azure Firewall is easy and very user-friendly and the overall cost is reasonable. Azure Firewall offers a solid threat awareness, can...
 

Also Known As

RSA Security Analytics
No data available
 

Overview

 

Sample Customers

Los Angeles World Airports, Reply
Warren Rogers Associates
Find out what your peers are saying about NetWitness Platform vs. Palo Alto Networks VM-Series and other solutions. Updated: September 2022.
867,370 professionals have used our research since 2012.