Try our new research platform with insights from 80,000+ expert users

NetWitness Platform vs Palo Alto Networks WildFire vs WatchGuard XTM [EOL] comparison

 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Featured Reviews

MOTASHIM Al Razi - PeerSpot reviewer
CISO at One Bank Limited
It is a stable solution, but they should make the user interface easier to understand
The solution's initial setup takes work. We have to organize multiple paths and many features. The deployment process takes less than a week. But it takes a month to complete if we want to make the solution smarter by integrating it with various devices. I rate the process as a six out of ten.
RK
Engineer at Taalumgroup
Achieve effective threat prevention and seamless integration with powerful technical support
Integration with third-party products is possible. For example, connecting a mail gateway with Palo Alto Networks WildFire allows them to handle prevention. Palo Alto Networks WildFire is a cloud-based sandboxing solution. The firewall is connected to WildFire, and XDR performs sandboxing from the cloud. WildFire conducts malware scanning and emulation, then informs the firewall to block threats based on the response. It also generates reports regarding malware and other issues. The sandboxing process involves sending sample files to the cloud for scanning, checking file authenticity, certificates, and detecting malicious code. WildFire performs multiple checks and informs the XDR agent about file status. This automatic process occurs within minutes or seconds. For unknown or suspicious files, immediate blocking occurs while samples are sent to WildFire for identification. I rate Palo Alto Networks WildFire a 9 out of 10.
Generalm4545 - PeerSpot reviewer
General Manager- IT & Automation - Serum at a pharma/biotech company with 1,001-5,000 employees
Protects from attack software and hacking but it doesn't provide the reports in a readable format
In my opinion, image clarity is very important, because I don't get the proper image product on reports. This means that functionality is not there. My engineer does not know how he can replace an order. We attach a log after any kind of keys using a utility instead. For the internet policies that we are implementing, the policy should be based on proper protocols. We use the default policies and there are a number of third-party protocols that appear here. Management with WatchGuard XTM means that out of policy is the problem from our side. In this way, we can not do effective services for people with this one. The policy definition with WatchGuard XTM is not proper for all use case requirements. I've got weekly business reports that I am expecting attachments with from WatchGuard XTM that display data for all kinds of consideration which should be required. Main User Functionality Level Order must adhere to using the admin functionality on the registry, or else our users publish their own name. Maybe these recommendations are irrelevant, but I say that the issue to improve most with WatchGuard XTM is the Main User Function.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"Offers a good wireless feature."
"The most valuable feature is the ability to write rules and triggers for network communication, and then being able to investigate based on that."
"The most valuable features are the integration and ease of use."
"The most valuable features are the packet decoder, log decoder, and concentrator."
"It gives the ability to investigate into network traffic in the Net and the organization what we couldn't do before."
"NetWitness can be highly beneficial for incident detection and response."
"NetWitness Platform offers flexibility for deployment and robust integration capabilities."
"Incident management is its most valuable feature."
"The most valuable feature is the cloud-based protection against zero-day malware attacks."
"The analysis is very fast."
"The way that the solution quickly updates to adjust to threats is the solution's most valuable aspect. When there's a security attack, within five minutes, all Wildfire subscribers have access to updates so that all systems will be safe. Its threat prevention is way better than other vendor products."
"The most valuable features of the solution are user-friendliness, price, good security, and cloud-related options."
"I love the idea of Palo Alto Networks WildFire. It's more geared toward preventing malware. If someone's laptop or phone is malware-infected, the tool prevents it from uploading valuable corporate data outside the corporate network. That's what I love about Palo Alto Networks WildFire. It stops malware in its tracks."
"The reporting feature helps our performance."
"The most valuable features of this solution are sandbox capabilities."
"The platform is scalable as it integrates with other threat prevention modules."
"They have a reporting system which can store data over a very long period of time. Not many other firewall vendors provide a reporting system, but if they do, like Fortinet does, then you've got buy that as an additional product and that can be more than twice as expensive as the initial investment in the firewall. And without reporting over a long-term period, you're just about wasting your time."
"Reputation Enabled Defense indicates that some websites are so infested that it's not even worth visiting them, and therefore saving the bandwidth of going through the detection process."
"There is a site-to-site VPN configuration between others people."
"It is stable and does not require you to reboot all the time.​"
"SNMP status monitoring and the Central Management Software."
"We have used technical support for WatchGuard many times and overall, we are satisfied with it. They are always listening and there is a good reaction time to our findings. When there are issues, they really try to resolve them."
"WatchGuard XTM is fairly basic. We use it as the perimeter firewall. The main point is to protect from attack software and hacking."
"After installing the product, we achieved awareness of our data protection needs and email misuse."
 

Cons

"More customizability is required, which is something that they need to improve on."
"The initial setup was complex because it takes a lot of time to complete the implementation."
"The initial setup is complex. There are other solutions that are easier to implement."
"The implementation needs assistance."
"The log system is a bit complex and has room for improvement."
"Technical support could be improved."
"The multi-tenant capabilities are lagging compared to IBM QRadar."
"RSA NetWitness Logs and Packets can improve the threat level aspect, it is lacking compared to other solutions. Whenever any hacking activity or any other threat factor occurred they used to provide the coverages very fast when comparing RSA NetWitness Logs and Packets. I heard the other three solutions, from a discussion with my team members who had experience in other solutions, they used to say that. Whenever any issues happened across the globe RSA NetWitness Logs and Packets are a little bit slow improving those detection mechanisms."
"The price could be better."
"Unfortunately, the support is getting worse. We have had some open tickets for months, maybe half a year, and there is no real answer."
"High availability features are lacking."
"They should make their user interface a little more user-friendly."
"The product's user interface for investigations needs enhancement."
"The cost of the solution is excessively high."
"I think it would be nice for Palo Alto to work without the connection to the cloud. It is 100% powerful when connected to the cloud. But, if you disconnect from the cloud, you only get 40-50% power."
"The product integration with third-party systems need improvement."
"I would like them to improve the product's overall protections. This would be good for all product users."
"The initial setup is neither simple nor complex. If you know the base in networking and how the firewall works, you will be able to figure it out.​"
"WatchGuard doesn't have a product that allows them to get into the data center. And that's just because there is no hardware to do the job. The software could do it, but there's no hardware that allows that to happen at the moment. So it doesn't scale as well as some other products, that's for sure."
"One huge issue with WatchGuard XTM is that I'm not getting reports in a readable format. Readable means, I don't want Excel online. We repeat auditing when we trigger the report or setup calendar. That functionality is what we are looking for from WatchGuard XTM here."
"Sometimes we have had issues with stability of the product."
"Syslog (Dimension) is focused on presentation, but needs more focus on utility like SonicWall syslog (GMS/Analyzer)."
"The setting policies need improvement. It needs an easier way to do static NAT and check on what policy is being used for that specific traffic."
"The VPN errors are not helpful when troubleshooting."
 

Pricing and Cost Advice

"We have yearly licensing costs. The license fee can be based on the volume of EPS. Some organizations may have, as a gentlemanly gesture, 10,000 EPS and get a 3,000 EPS license but actually use 5,000 EPS."
"The tool is very expensive, so I rate the pricing a ten out of ten. The solution has an annual subscription."
"Our license is for one year."
"It’s cheaper to run virtual machines in a VMware environment."
"The NetWitness Platform may be affordable only for enterprise-level customers, as it may not be within the budget of small and medium-sized businesses."
"RSA NetWitness Logs and Packets do not have a subscription model, it's a one-time purchase. There is only a perpetual license."
"We have a perpetual license, so the total cost of ownership is not very expensive. It's a good investment."
"It is cheap."
"There are different types of licenses."
"The solution is a bit expensive."
"The pricing is affordable and fixed."
"We are on an annual subscription. When we purchased the firewall, we had activated this solutions license for a minimum of one year. The price of the solution is fair."
"The solution is overpriced."
"Palo Alto Networks WildFire is a product with a high price."
"We pay between $3,000 and $4,000 CAD ($2,200 - $3,000 USD) per year to maintain this solution."
"The solution is worth its price"
"Like all other manufacturers, there are a lot of features and different pricing. The best is to talk to a representative.​"
"It costs less than the SO works and others (like SonicWall, Cisco, and Barracuda) without increasing so much CPU use."
"Get at least a maintenance contract for the updates and take a larger WatchGuard than you need. A WatchGuard creates new ways to secure your network."
"The licensing and renewal is very expensive."
report
Use our free recommendation engine to learn which Log Management solutions are best for your needs.
881,821 professionals have used our research since 2012.
 

Comparison Review

VS
Manager, Enterprise Risk Consulting at a tech company with 1,001-5,000 employees
Feb 26, 2015
HP ArcSight vs. IBM QRadar vs. ​McAfee Nitro vs. Splunk vs. RSA Security vs. LogRhythm
We at Infosecnirvana.com have done several posts on SIEM. After the Dummies Guide on SIEM, we are following it up with a SIEM Product Comparison – 101 deck. So, here it is for your viewing pleasure. Let me know what you think by posting your comments below. The key products compared here are…
 

Top Industries

By visitors reading reviews
Financial Services Firm
13%
Performing Arts
8%
Computer Software Company
8%
Manufacturing Company
7%
Computer Software Company
11%
Manufacturing Company
8%
Financial Services Firm
8%
Comms Service Provider
7%
No data available
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business8
Midsize Enterprise7
Large Enterprise20
By reviewers
Company SizeCount
Small Business37
Midsize Enterprise16
Large Enterprise29
By reviewers
Company SizeCount
Small Business24
Midsize Enterprise7
Large Enterprise3
 

Questions from the Community

What do you like most about NetWitness Platform?
The product's initial setup phase was not at all difficult.
What is your experience regarding pricing and costs for NetWitness Platform?
The pricing is comparable to others, and I consider the cost to be intermediate. Specific cost details are unknown to...
What needs improvement with NetWitness Platform?
There is currently no need for improvement in the SIEM ( /categories/security-information-and-event-management-siem )...
How does Cisco Firepower NGFW Firewall compare with Palo Alto Networks Wildfire?
The Cisco Firepower NGFW Firewall is a very powerful and very complex piece of anti-viral software. When one conside...
Which is better - Wildfire or FortiGate?
FortiGate has a lot going for it and I consider it to be the best, most user-friendly firewall out there. What I like...
How does Cisco ASA Firewall compare with Palo Alto's WildFire?
When looking to change our ASA Firewall, we looked into Palo Alto’s WildFire. It works especially in preventing advan...
Ask a question
Earn 20 points
 

Also Known As

RSA Security Analytics
No data available
No data available
 

Overview

 

Sample Customers

Los Angeles World Airports, Reply
Novamedia, Nexon Asia Pacific, Lenovo, Samsonite, IOOF, Sinogrid, SanDisk Corporation
AVG, Cyren, Kaspersky Lab, Lastline, NCP engineering, Trend Micro, Websense
Find out what your peers are saying about Wazuh, Splunk, Datadog and others in Log Management. Updated: January 2026.
881,821 professionals have used our research since 2012.