Try our new research platform with insights from 80,000+ expert users

NetWitness Platform vs Palo Alto Networks WildFire comparison

 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

NetWitness Platform
Average Rating
7.4
Reviews Sentiment
7.4
Number of Reviews
37
Ranking in other categories
Log Management (34th), Security Information and Event Management (SIEM) (30th)
Palo Alto Networks WildFire
Average Rating
8.4
Reviews Sentiment
7.2
Number of Reviews
71
Ranking in other categories
Advanced Threat Protection (ATP) (1st)
 

Mindshare comparison

NetWitness Platform and Palo Alto Networks WildFire aren’t in the same category and serve different purposes. NetWitness Platform is designed for Log Management and holds a mindshare of 0.4%, up 0.3% compared to last year.
Palo Alto Networks WildFire, on the other hand, focuses on Advanced Threat Protection (ATP), holds 10.7% mindshare, down 12.5% since last year.
Log Management Market Share Distribution
ProductMarket Share (%)
NetWitness Platform0.4%
Wazuh12.6%
Grafana Loki8.1%
Other78.9%
Log Management
Advanced Threat Protection (ATP) Market Share Distribution
ProductMarket Share (%)
Palo Alto Networks WildFire10.7%
Microsoft Defender for Endpoint8.9%
Fortinet FortiSandbox8.7%
Other71.7%
Advanced Threat Protection (ATP)
 

Featured Reviews

MOTASHIM Al Razi - PeerSpot reviewer
It is a stable solution, but they should make the user interface easier to understand
The solution's initial setup takes work. We have to organize multiple paths and many features. The deployment process takes less than a week. But it takes a month to complete if we want to make the solution smarter by integrating it with various devices. I rate the process as a six out of ten.
AjayKumar17 - PeerSpot reviewer
Enhanced cybersecurity with advanced sandboxing and effective in controlling DNS issues
Improvements are needed in the UI part. The dashboard should provide better visibility, especially in showing how many files are sent to Wildfire and their findings. This information should be integrated with the Dashboard so that system admins can see what is happening. Furthermore, technical support needs a lot of improvement, particularly in terms of responsiveness and adhering to service level agreements.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"The most valuable features are the packet inspection and the automated incident response."
"In my opinion, the solution's most valuable feature is its capacity to monitor network traffic, logs from devices within the network, and network captures. This capability extends beyond logs to include full network capturing."
"NetWitness Platform offers flexibility for deployment and robust integration capabilities."
"Alerting Module: It provides real-time event processing language on all the logs/packets stream for advanced alerting, i.e., using SQL LIKE statements."
"The most valuable feature is the correlation. It can report in real-time and monitor the management."
"Offers a good wireless feature."
"Setting up NetWitness is straightforward. There are multiple connectors, including standard and specialized connectors. One purpose of the connectors is the enhanced capability integrate the custom applications. NetWitness comes with E6 appliances and application images that we use for the initial configurations and for the OS stack information. From there, you can consider the correlation rules, integrate the different log sources, and easily create correlation rules and backlog reports."
"NetWitness Platform is valuable for creating rules that the solution must detect."
"The platform is scalable as it integrates with other threat prevention modules."
"It is the best device in comparison to other network products in the marketplace."
"Detailed reporting on analysis of content. The inspections are easily applied to security policy profiles and profile groups, and may be assigned on a per-rule basis."
"There are multiple features like management, intrusion prevention (IPS), URL filtering, anti-spam, and antivirus."
"Wildfire has excellent features and offers some of the best security measures available, although it requires a significant budget."
"Using WildFire has reduced the number of viruses and the amount of malware that comes into our system, which means that I don't have to rely on the end-users to identify it."
"The way that the solution quickly updates to adjust to threats is the solution's most valuable aspect. When there's a security attack, within five minutes, all Wildfire subscribers have access to updates so that all systems will be safe. Its threat prevention is way better than other vendor products."
"A good tool for file scanning and email threat detection, especially when it comes to attachments and communications."
 

Cons

"The initial setup is very complex and should be simplified."
"The system architecture is complex and sometimes it’s hard to troubleshoot potential problems."
"The initial setup is complex. There are other solutions that are easier to implement."
"More customizability is required, which is something that they need to improve on."
"RSA NetWitness Logs and Packets can improve the threat level aspect, it is lacking compared to other solutions. Whenever any hacking activity or any other threat factor occurred they used to provide the coverages very fast when comparing RSA NetWitness Logs and Packets. I heard the other three solutions, from a discussion with my team members who had experience in other solutions, they used to say that. Whenever any issues happened across the globe RSA NetWitness Logs and Packets are a little bit slow improving those detection mechanisms."
"Log aggregation is an issue with this solution because there are a huge number of alerts in a single instance."
"The product's licensing models are complex to understand. This particular area needs improvement."
"They should implement algorithms to digest that data and produce additional, more advanced reporting, alerting and support of internal security teams."
"The integration is almost not easy because it depends on the vendor."
"I think it would be nice for Palo Alto to work without the connection to the cloud. It is 100% powerful when connected to the cloud. But, if you disconnect from the cloud, you only get 40-50% power."
"Improving detection on non-Windows formats would be beneficial as there are many samples, such as Linux or ransomware for macOS."
"Other vendors have some sort of bandwidth management built into the firewall itself and Palo Alto is missing that."
"The global product feature needs improvement, the VPN, and we need some enhanced features."
"In the future, Palo Alto could reduce the time it takes to process the file."
"As a firewall and 360 degrees of security, there needs to be more maturity."
"The free version does not have real-time updates. It is slow."
 

Pricing and Cost Advice

"The new pricing and licensing mechanisms are fair. I would advise always to get the full solution (i.e., not only Logs)."
"We have a perpetual license, so the total cost of ownership is not very expensive. It's a good investment."
"Many clients are not able to purchase the packet capability because there is a huge amount of data, and the cost depends on the number of EPS (Events per second), as well as the number of gigabytes of data per day."
"Compared to the competition, the is price is not that high."
"In comparison to other SIEM solutions such as Splunk, NetWitness is less costly."
"We are on an annual license for the use of the solution."
"The NetWitness Platform may be affordable only for enterprise-level customers, as it may not be within the budget of small and medium-sized businesses."
"Our license is for one year."
"The pricing is highly expensive."
"Palo Alto Networks solutions are typically on the higher end of pricing, but considering the value and integration with our existing infrastructure, it is worth the investment."
"The solution is worth its price"
"The licensing fees are on an annual basis, and there are no costs in addition to the standard fees."
"It's not particularly cheap, but it is absolutely worth it."
"For the last three years, the price of Palo Alto in Vietnam has been very high."
"I rate the pricing an eight out of ten since it can be pretty expensive."
"It's pretty expensive but with respect to value for money, it's okay."
report
Use our free recommendation engine to learn which Log Management solutions are best for your needs.
867,497 professionals have used our research since 2012.
 

Comparison Review

VS
Feb 26, 2015
HP ArcSight vs. IBM QRadar vs. ​McAfee Nitro vs. Splunk vs. RSA Security vs. LogRhythm
We at Infosecnirvana.com have done several posts on SIEM. After the Dummies Guide on SIEM, we are following it up with a SIEM Product Comparison – 101 deck. So, here it is for your viewing pleasure. Let me know what you think by posting your comments below. The key products compared here are…
 

Top Industries

By visitors reading reviews
Financial Services Firm
13%
Computer Software Company
12%
Performing Arts
7%
Manufacturing Company
6%
Computer Software Company
14%
Financial Services Firm
9%
Manufacturing Company
9%
Government
8%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business9
Midsize Enterprise7
Large Enterprise20
By reviewers
Company SizeCount
Small Business35
Midsize Enterprise17
Large Enterprise28
 

Questions from the Community

What do you like most about NetWitness Platform?
The product's initial setup phase was not at all difficult.
What is your experience regarding pricing and costs for NetWitness Platform?
The pricing is comparable to others, and I consider the cost to be intermediate. Specific cost details are unknown to me.
What needs improvement with NetWitness Platform?
There is currently no need for improvement in the SIEM ( /categories/security-information-and-event-management-siem ), though there could be potential enhancements by integrating with AI.
How does Cisco Firepower NGFW Firewall compare with Palo Alto Networks Wildfire?
The Cisco Firepower NGFW Firewall is a very powerful and very complex piece of anti-viral software. When one considers that fact, it is all the more impressive that the setup is a fairly straightf...
Which is better - Wildfire or FortiGate?
FortiGate has a lot going for it and I consider it to be the best, most user-friendly firewall out there. What I like the most about it is that it has an attractive web dashboard with very easy nav...
How does Cisco ASA Firewall compare with Palo Alto's WildFire?
When looking to change our ASA Firewall, we looked into Palo Alto’s WildFire. It works especially in preventing advanced malware and zero-day exploits with real-time intelligence. The sandbox featu...
 

Also Known As

RSA Security Analytics
No data available
 

Overview

 

Sample Customers

Los Angeles World Airports, Reply
Novamedia, Nexon Asia Pacific, Lenovo, Samsonite, IOOF, Sinogrid, SanDisk Corporation
Find out what your peers are saying about NetWitness Platform vs. Palo Alto Networks WildFire and other solutions. Updated: September 2022.
867,497 professionals have used our research since 2012.