No more typing reviews! Try our Samantha, our new voice AI agent.

NetWitness Platform vs Symantec Advanced Threat Protection comparison

 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

NetWitness Platform
Average Rating
7.4
Reviews Sentiment
7.4
Number of Reviews
36
Ranking in other categories
Log Management (34th), Security Information and Event Management (SIEM) (33rd)
Symantec Advanced Threat Pr...
Average Rating
7.8
Reviews Sentiment
7.1
Number of Reviews
16
Ranking in other categories
Advanced Threat Protection (ATP) (21st)
 

Mindshare comparison

NetWitness Platform and Symantec Advanced Threat Protection aren’t in the same category and serve different purposes. NetWitness Platform is designed for Log Management and holds a mindshare of 0.8%, up 0.3% compared to last year.
Symantec Advanced Threat Protection, on the other hand, focuses on Advanced Threat Protection (ATP), holds 2.2% mindshare, up 1.5% since last year.
Log Management Mindshare Distribution
ProductMindshare (%)
NetWitness Platform0.8%
Wazuh7.5%
Splunk Enterprise Security6.8%
Other84.9%
Log Management
Advanced Threat Protection (ATP) Mindshare Distribution
ProductMindshare (%)
Symantec Advanced Threat Protection2.2%
Microsoft Defender for Office 3657.6%
Palo Alto Networks WildFire7.5%
Other82.7%
Advanced Threat Protection (ATP)
 

Featured Reviews

reviewer2256927 - PeerSpot reviewer
Head of Information Security, Cyber Defense and IT Risk Management at HCT. at a transportation company with 201-500 employees
A solid SIEM solution that should improve technical support and online resources to be easier to use
A big problem with the product is that we don't have much professional experience in Israel installing, implementing, and integrating this product. There is not enough of a knowledge base. There is no support for this product in this country, so problems have to be resolved through global technical teams. We like to work locally because of the language, and when the product is only supported outside the country, it's a little difficult to implement and use this product. Moreover, AI is something that must be added immediately. Artificial intelligence is a part of the competitors' products, and it's not been implemented for us.
TapabrataSamanta - PeerSpot reviewer
Lead Architect at Zones
Reliable platform with effective integration capabilities
Our primary use case for the product is to provide advanced threat protection to our clients, primarily in the banking and financial sectors Symantec ATP has been beneficial in ensuring robust security for our clients. Its effectiveness in detecting and mitigating threats has improved customer…

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"Over time, NetWitness Logs and Packets has matured from a boxed solution with multiple parts to the current, more streamlined version for which we only need the software license to put it up on our own cloud and deliver it to multiple clients."
"It gives the capability for the incident response team to correlate logs to identify any kind of problem like malware and incidents in a general sense, both for logs and packets."
"Their technical support responds quickly and are knowledgable."
"Setting up NetWitness is straightforward. There are multiple connectors, including standard and specialized connectors. One purpose of the connectors is the enhanced capability integrate the custom applications. NetWitness comes with E6 appliances and application images that we use for the initial configurations and for the OS stack information. From there, you can consider the correlation rules, integrate the different log sources, and easily create correlation rules and backlog reports."
"NetWitness can be highly beneficial for incident detection and response."
"The most valuable feature is the hunting ability to work in a CERT."
"Incident management is its most valuable feature."
"Technically speaking, this is a good product."
"You don't have to buy a separate email security platform. You can enable that using their endpoint, and I like that. You don't have to have two agents running on the same box."
"Overall, the product supports everything already feature-wise, because it has email protection, monitoring detection, network intrusion detection, and advanced threat protection."
"The product integrates well with our systems, and we have not encountered any problems."
"Real-time threat analysis is quick and takes action on threats immediately."
"The most valuable feature is NetFlow threat protection."
"The stability is excellent."
"They manage to solve detection quite nicely, with rather elaborate detection compared to other providers, and Symantec also provides a useful set of information linked to each of the attacked computers."
"Technical support has been helpful and responsive."
 

Cons

"Security needs improvement. We would still like to know how the traffic is entering the organization."
"The multi-tenant capabilities are lagging compared to IBM QRadar."
"The system architecture is complex and sometimes it’s hard to troubleshoot potential problems."
"I believe that integrating the solution with other products such as Oracle would be beneficial."
"The initial setup is complex. There are other solutions that are easier to implement."
"Health monitoring of the event sources and devices."
"The solution is pretty complex to set up. Comparatively, I have worked on IBM QRadar and Splunk; they are much easier to set up."
"It is not so easy to customize this product."
"The administration interface needs a lot of improvement. It should be UI based, and simple. They need to improve it. It's pretty much not that friendly compared to what we were using as Bitdefender before. It's okay but is improving, actually."
"An improvement could be made on the reporting because then it would be easier to collect information and submit it for compliance."
"There are some ‎features that would add value to this product. One of them would be a graphical presentation of threats that the system has encountered."
"Not ideal for advanced threat protection."
"One area for improvement could be the pricing model."
"Scalability could be better."
"Entire threat protection is not available for the advanced features."
"The endpoint protection looks old."
 

Pricing and Cost Advice

"Compared to the competition, the is price is not that high."
"The new pricing and licensing mechanisms are fair. I would advise always to get the full solution (i.e., not only Logs)."
"Our license is for one year."
"Many clients are not able to purchase the packet capability because there is a huge amount of data, and the cost depends on the number of EPS (Events per second), as well as the number of gigabytes of data per day."
"The NetWitness Platform may be affordable only for enterprise-level customers, as it may not be within the budget of small and medium-sized businesses."
"It provides tools to assist in selecting the appropriate license and usage scenarios."
"There is a licensing fee and the customer can choose whether he wishes this to be subscription-based or perpetual."
"The licenses are good but the cost is very expensive."
"Symantec Advanced Threat Protection's pricing is comparable."
"Pricing is good. It is nice to have a great product at a fair price."
"The price is quite expensive."
"Symantec Endpoint Protection has an average price."
"The pricing of this solution is inexpensive and affordable."
report
Use our free recommendation engine to learn which Log Management solutions are best for your needs.
885,789 professionals have used our research since 2012.
 

Comparison Review

VS
Manager, Enterprise Risk Consulting at a tech company with 1,001-5,000 employees
Feb 26, 2015
HP ArcSight vs. IBM QRadar vs. ​McAfee Nitro vs. Splunk vs. RSA Security vs. LogRhythm
We at Infosecnirvana.com have done several posts on SIEM. After the Dummies Guide on SIEM, we are following it up with a SIEM Product Comparison – 101 deck. So, here it is for your viewing pleasure. Let me know what you think by posting your comments below. The key products compared here are…
 

Top Industries

By visitors reading reviews
Financial Services Firm
12%
Construction Company
8%
Performing Arts
7%
Comms Service Provider
7%
Marketing Services Firm
12%
University
10%
Construction Company
10%
Manufacturing Company
6%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business8
Midsize Enterprise7
Large Enterprise20
By reviewers
Company SizeCount
Small Business9
Midsize Enterprise3
Large Enterprise13
 

Questions from the Community

What do you like most about NetWitness Platform?
The product's initial setup phase was not at all difficult.
What is your experience regarding pricing and costs for NetWitness Platform?
The pricing is comparable to others, and I consider the cost to be intermediate. Specific cost details are unknown to me.
What needs improvement with NetWitness Platform?
There is currently no need for improvement in the SIEM ( /categories/security-information-and-event-management-siem ), though there could be potential enhancements by integrating with AI.
What is your experience regarding pricing and costs for Symantec Advanced Threat Protection?
The price is quite expensive because a different entity has taken over the company.
What needs improvement with Symantec Advanced Threat Protection?
One area for improvement could be the pricing model. Future releases could further enhance integration capabilities with other platforms and simplify the licensing model to compete more with Micros...
What is your primary use case for Symantec Advanced Threat Protection?
Our primary use case for the product is to provide advanced threat protection to our clients, primarily in the banking and financial sectors.
 

Also Known As

RSA Security Analytics
No data available
 

Overview

 

Sample Customers

Los Angeles World Airports, Reply
ECI
Find out what your peers are saying about NetWitness Platform vs. Symantec Advanced Threat Protection and other solutions. Updated: September 2022.
885,789 professionals have used our research since 2012.