No more typing reviews! Try our Samantha, our new voice AI agent.

NetWitness Platform vs SentinelOne Singularity AI SIEM comparison

 

Comparison Buyer's Guide

Executive SummaryUpdated on Jun 3, 2026

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

NetWitness Platform
Ranking in Security Information and Event Management (SIEM)
36th
Average Rating
7.4
Reviews Sentiment
7.4
Number of Reviews
36
Ranking in other categories
Log Management (37th)
SentinelOne Singularity AI ...
Ranking in Security Information and Event Management (SIEM)
8th
Average Rating
8.6
Reviews Sentiment
6.4
Number of Reviews
15
Ranking in other categories
AI Observability (6th)
 

Mindshare comparison

As of August 2026, in the Security Information and Event Management (SIEM) category, the mindshare of NetWitness Platform is 1.0%, up from 0.6% compared to the previous year. The mindshare of SentinelOne Singularity AI SIEM is 1.3%, up from 0.6% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Security Information and Event Management (SIEM) Mindshare Distribution
ProductMindshare (%)
SentinelOne Singularity AI SIEM1.3%
NetWitness Platform1.0%
Other97.7%
Security Information and Event Management (SIEM)
 

Featured Reviews

reviewer2256927 - PeerSpot reviewer
Head of Information Security, Cyber Defense and IT Risk Management at HCT. at a transportation company with 201-500 employees
A solid SIEM solution that should improve technical support and online resources to be easier to use
A big problem with the product is that we don't have much professional experience in Israel installing, implementing, and integrating this product. There is not enough of a knowledge base. There is no support for this product in this country, so problems have to be resolved through global technical teams. We like to work locally because of the language, and when the product is only supported outside the country, it's a little difficult to implement and use this product. Moreover, AI is something that must be added immediately. Artificial intelligence is a part of the competitors' products, and it's not been implemented for us.
Dev Reshwal - PeerSpot reviewer
Technical Support Executive at Softcell Technologies Limited
Automation has reduced workload and real-time monitoring provides faster incident response
SentinelOne Singularity AI SIEM is the best, but sometimes the dashboards are a little simple compared to other tools. The custom dashboard is not available in their features. Therefore, I would suggest adding the custom dashboard for any of our requirements. The AI-driven analytics from SentinelOne Singularity AI SIEM has not affected our ability to reduce false positives. SentinelOne Singularity AI SIEM has affected my SOC's efficiency in investigating alerts and responding to incidents. If we receive any alerts, we can observe what activity is being done. We can see if it is malicious or something suspicious, or a true positive. We can analyze the path, the hash, and whether the signature is verified or not. We can see if it is an alert triggered by any engine. We can see the source of this. We will do that type of analysis and raise it to the client side. Also, if I identify anything suspicious or malicious in the alert, I will forcefully kill and quarantine it immediately.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"Offers a good wireless feature."
"It gives customers visibility about their most important servers and devices."
"Their customer service is excellent, one of the best."
"Setting up NetWitness is straightforward. There are multiple connectors, including standard and specialized connectors. One purpose of the connectors is the enhanced capability integrate the custom applications. NetWitness comes with E6 appliances and application images that we use for the initial configurations and for the OS stack information. From there, you can consider the correlation rules, integrate the different log sources, and easily create correlation rules and backlog reports."
"This solution has a very good dashboard with a separate tab for incidents and alerts."
"The most valuable features are the integration and ease of use."
"The newer 11.5 version that my team is using has found it to have good mapping."
"The most valuable feature is the security that it provides."
"SentinelOne Singularity AI SIEM has improved our overall security posture and is reducing the workload on the SOC team."
"The AI features of SentinelOne Singularity AI SIEM are absolutely perfect."
"AI-driven capabilities will give me real-time detection and will protect my autonomous AI interruption."
"SentinelOne Singularity AI SIEM's AI-powered analytics does affect our SOC's ability to reduce false positives; that is one of the biggest advantages because the manpower that I have is limited."
"SentinelOne Singularity AI SIEM has positively impacted my organization by improving visibility, reducing investigation time, and helping the security team respond to incidents faster."
"Overall, I would assess the overall security posture after implementing SentinelOne Singularity AI SIEM as significantly better."
"The beauty of the integration is that it integrates very smoothly with third-party tools, so we do not need to think about the parsers, coding, depending on the codes, or the software developers."
"SentinelOne Singularity AI SIEM has impacted my organization positively because I am observing some improvement, including real-time monitoring and real-time threat detection that help secure both our and the client's organization from anything suspicious or any malicious types of alerts."
 

Cons

"It should have a monitoring feature. It would help us analyze the current state of attacks faster from a single platform."
"I believe that integrating the solution with other products such as Oracle would be beneficial."
"The initial setup is complex. It requires some knowledge in order to set it up."
"The product's licensing models are complex to understand. This particular area needs improvement."
"The log system is a bit complex and has room for improvement."
"The system looks like it is a mix of a bunch of different systems, and nothing looked like it was quite together."
"Sometimes, it gives me static when integrating Windows-based systems. It should produce a precise log of sorts as to where the problem is. For example, a few days ago because of the McAfee application firewall, I couldn't get access to the particular Windows machine. So, my team and I had to figure out by ourselves that there was a virus responsible for the obstacle. This solution should trigger a meaningful log or message indicating the reason the user or implementer can't get into the machine."
"But the 11.3 version is a complete disaster. You cannot analyze anything."
"SentinelOne Singularity AI SIEM is the best, but sometimes the dashboards are a little simple compared to other tools."
"SentinelOne Singularity AI SIEM is a strong platform, but there are a few areas where it could be improved."
"In AI SIEM, the areas that have room for improvement are the parsers for third-party integrated data or for third-party data sources that are not native integrations, which could be made a bit easier."
"While it provides many built-in decorations and dashboards, creating highly customized decoration rules and reports can sometimes require additional efforts."
"Unfortunately, I was not happy with SentinelOne Singularity AI SIEM because it is not mature yet."
"I would want the false positive ratio to be lower and would want to improve that aspect so the true will be more, and the false will be lesser."
"SentinelOne Singularity AI SIEM has some performance and reliability issues that need improvement."
"Another area for improvement is that the product is somewhat expensive. Pricing could be improved as well."
 

Pricing and Cost Advice

"The NetWitness Platform may be affordable only for enterprise-level customers, as it may not be within the budget of small and medium-sized businesses."
"Our license is for one year."
"Many clients are not able to purchase the packet capability because there is a huge amount of data, and the cost depends on the number of EPS (Events per second), as well as the number of gigabytes of data per day."
"The new pricing and licensing mechanisms are fair. I would advise always to get the full solution (i.e., not only Logs)."
"Compared to the competition, the is price is not that high."
"The product price was reasonable for my region and the market."
"It’s cheaper to run virtual machines in a VMware environment."
"In comparison to other SIEM solutions such as Splunk, NetWitness is less costly."
Information not available
report
Use our free recommendation engine to learn which Security Information and Event Management (SIEM) solutions are best for your needs.
909,725 professionals have used our research since 2012.
 

Comparison Review

VS
Manager, Enterprise Risk Consulting at a tech company with 1,001-5,000 employees
Feb 26, 2015
HP ArcSight vs. IBM QRadar vs. ​McAfee Nitro vs. Splunk vs. RSA Security vs. LogRhythm
We at Infosecnirvana.com have done several posts on SIEM. After the Dummies Guide on SIEM, we are following it up with a SIEM Product Comparison – 101 deck. So, here it is for your viewing pleasure. Let me know what you think by posting your comments below. The key products compared here are…
 

Top Industries

By visitors reading reviews
Construction Company
13%
Financial Services Firm
11%
Outsourcing Company
10%
Comms Service Provider
9%
Outsourcing Company
22%
Construction Company
7%
Manufacturing Company
6%
Media Company
6%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business8
Midsize Enterprise7
Large Enterprise20
By reviewers
Company SizeCount
Small Business12
Midsize Enterprise5
Large Enterprise4
 

Questions from the Community

What is your experience regarding pricing and costs for NetWitness Platform?
The pricing is comparable to others, and I consider the cost to be intermediate. Specific cost details are unknown to me.
What needs improvement with NetWitness Platform?
There is currently no need for improvement in the SIEM ( /categories/security-information-and-event-management-siem ), though there could be potential enhancements by integrating with AI.
What is your primary use case for NetWitness Platform?
I use NetWitness Platform ( /products/netwitness-platform-reviews ) in the financial industry as a good product with excellent capabilities and integration with various devices.
What needs improvement with SentinelOne Singularity AI SIEM?
They could expand more integrations for other third-party products that are not currently available. Those are areas they can improve or have yet to improve. For example, we have firewall integrati...
What is your primary use case for SentinelOne Singularity AI SIEM?
Clients can use SentinelOne Singularity AI SIEM for endpoint security solutions, and apart from that, we currently have something called prompt security where it is helping us to enhance control ov...
What advice do you have for others considering SentinelOne Singularity AI SIEM?
The automated workflow feature impacts my security tasks and manual efforts significantly. Downtime is not necessarily required in scenarios where a particular system has to be isolated. Whether it...
 

Also Known As

RSA Security Analytics
No data available
 

Overview

 

Sample Customers

Los Angeles World Airports, Reply
Information Not Available
Find out what your peers are saying about NetWitness Platform vs. SentinelOne Singularity AI SIEM and other solutions. Updated: August 2026.
909,725 professionals have used our research since 2012.