No more typing reviews! Try our Samantha, our new voice AI agent.

NetWitness Platform vs ThreatConnect Threat Intelligence Platform (TIP) comparison

 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

NetWitness Platform
Average Rating
7.4
Reviews Sentiment
7.4
Number of Reviews
36
Ranking in other categories
Log Management (34th), Security Information and Event Management (SIEM) (33rd)
ThreatConnect Threat Intell...
Average Rating
8.2
Reviews Sentiment
6.5
Number of Reviews
7
Ranking in other categories
Threat Intelligence Platforms (TIP) (6th), Security Orchestration Automation and Response (SOAR) (15th)
 

Mindshare comparison

While both are Security Software solutions, they serve different purposes. NetWitness Platform is designed for Log Management and holds a mindshare of 0.8%, up 0.3% compared to last year.
ThreatConnect Threat Intelligence Platform (TIP), on the other hand, focuses on Threat Intelligence Platforms (TIP), holds 3.7% mindshare, down 5.6% since last year.
Log Management Mindshare Distribution
ProductMindshare (%)
NetWitness Platform0.8%
Wazuh7.5%
Splunk Enterprise Security6.8%
Other84.9%
Log Management
Threat Intelligence Platforms (TIP) Mindshare Distribution
ProductMindshare (%)
ThreatConnect Threat Intelligence Platform (TIP)3.7%
Recorded Future7.6%
CrowdStrike Falcon4.7%
Other84.0%
Threat Intelligence Platforms (TIP)
 

Featured Reviews

MOTASHIM Al Razi - PeerSpot reviewer
CISO at One Bank Limited
It is a stable solution, but they should make the user interface easier to understand
The solution's initial setup takes work. We have to organize multiple paths and many features. The deployment process takes less than a week. But it takes a month to complete if we want to make the solution smarter by integrating it with various devices. I rate the process as a six out of ten.
Nikhil Jethwa - PeerSpot reviewer
Technical Consultant at ProTechmanize Solutions (P) Ltd.
Centralized threat intelligence has streamlined IOC workflows and now improves response time
ThreatConnect Threat Intelligence Platform (TIP) has positively impacted our organization by significantly reducing response times and improving detection accuracy by ensuring only high-confidence, context-rich indicators are pushed to security controls. From an operational standpoint, ThreatConnect Threat Intelligence Platform (TIP) has helped us reduce IOC handling and response time from hours to minutes by automating injection, enrichment, and distribution workflows.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"It's fully scalable. There is no limit. Of course, the license limits per day the number of terabytes. In my opinion, it's very flexible."
"Overall, this is a good solution with suitable features and it very well fits our needs."
"It gives customers visibility about their most important servers and devices."
"The most valuable features are the integration and ease of use."
"Technical support is very good; they try to resolve issues with the proper SLAs which are defined by them and they understand the client's requirements as well as the client's infrastructure in a better manner."
"It gives the ability to investigate into network traffic in the Net and the organization what we couldn't do before."
"The detection of ransomware in the internal network has benefited my organization."
"The most valuable features are the packet decoder, log decoder, and concentrator."
"It's a solid platform and is stable enough. It is not complicated and is easy to use."
"ThreatConnect has a highly user-friendly interface; I loved it, and it's really great and easy to configure."
"It is used to help an operations team with the identification and resolution of threats in an automated, zero-touch fashion."
"ThreatConnect Threat Intelligence Platform (TIP) has positively impacted our organization by significantly reducing response times and improving detection accuracy by ensuring only high-confidence, context-rich indicators are pushed to security controls."
"I like their customer support."
"We have been able to see a return on investment as our clients believe in us more."
"The most valuable features are ease of use and the ability to customize it."
"The tool's installation, integration, and playbooks are very straightforward."
 

Cons

"Log aggregation is an issue with this solution because there are a huge number of alerts in a single instance."
"We encountered stability issues in the earlier versions, and much fewer in the newer versions."
"The threat detection capability and centralizing and upgrading capability need to be improved. The threat alert capability needs to be improved as well because there is some lag time at present. They need to work on their database search too."
"The product's licensing models are complex to understand. This particular area needs improvement."
"The solution should have more integration capabilities with different platforms."
"The documentation is not as structured as I would like, personally, and I think that it can be improved and made much more user-friendly."
"Security needs improvement."
"The initial setup is very complex and should be simplified."
"It would be good to have more feeds and more integrated sources for enrichment."
"They should make it a little bit easier to generate events and share them with the community"
"Integration is an area that could use some improvement."
"Integration is an area that could use some improvement."
"They should make it a little bit easier to generate events and share them with the community."
"Sometimes, when using the solution, it slows down, affecting our ability to mitigate threats."
"ThreatConnect Threat Intelligence Platform (TIP) could be improved by simplifying the user interface to better fit day-to-day analyst workflow and reducing the complexity of configuring playbook and score logic."
"Support is an area with which nobody is ever fully satisfied, so it can be improved."
 

Pricing and Cost Advice

"It provides tools to assist in selecting the appropriate license and usage scenarios."
"In comparison to other SIEM solutions such as Splunk, NetWitness is less costly."
"It’s cheaper to run virtual machines in a VMware environment."
"RSA NetWitness Logs and Packets do not have a subscription model, it's a one-time purchase. There is only a perpetual license."
"Compared to the competition, the is price is not that high."
"It is cheap."
"There is a licensing fee and the customer can choose whether he wishes this to be subscription-based or perpetual."
"We have a perpetual license, so the total cost of ownership is not very expensive. It's a good investment."
"I rate the product price as six on a scale of one to ten, where one is extremely expensive, and ten means it is cheap."
"The price of this product is in the mid-range, not too expensive, nor inexpensive."
"The price could be better."
"The tool is expensive."
report
Use our free recommendation engine to learn which Log Management solutions are best for your needs.
885,667 professionals have used our research since 2012.
 

Comparison Review

VS
Manager, Enterprise Risk Consulting at a tech company with 1,001-5,000 employees
Feb 26, 2015
HP ArcSight vs. IBM QRadar vs. ​McAfee Nitro vs. Splunk vs. RSA Security vs. LogRhythm
We at Infosecnirvana.com have done several posts on SIEM. After the Dummies Guide on SIEM, we are following it up with a SIEM Product Comparison – 101 deck. So, here it is for your viewing pleasure. Let me know what you think by posting your comments below. The key products compared here are…
 

Top Industries

By visitors reading reviews
Financial Services Firm
11%
Construction Company
8%
Performing Arts
7%
Comms Service Provider
7%
Financial Services Firm
15%
Comms Service Provider
9%
Retailer
6%
Computer Software Company
6%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business8
Midsize Enterprise7
Large Enterprise20
By reviewers
Company SizeCount
Small Business8
Midsize Enterprise23
Large Enterprise4
 

Questions from the Community

What do you like most about NetWitness Platform?
The product's initial setup phase was not at all difficult.
What is your experience regarding pricing and costs for NetWitness Platform?
The pricing is comparable to others, and I consider the cost to be intermediate. Specific cost details are unknown to me.
What needs improvement with NetWitness Platform?
There is currently no need for improvement in the SIEM ( /categories/security-information-and-event-management-siem ), though there could be potential enhancements by integrating with AI.
What is your experience regarding pricing and costs for ThreatConnect Threat Intelligence Platform (TIP)?
My experience with ThreatConnect Threat Intelligence Platform (TIP) pricing, setup cost, and licensing indicates that it is typical for an enterprise-grade threat intelligence solution and perceive...
What needs improvement with ThreatConnect Threat Intelligence Platform (TIP)?
Based on my experience, ThreatConnect Threat Intelligence Platform (TIP) is already doing a great job in the market by decreasing threats from external sources. A few improvements I would suggest i...
What is your primary use case for ThreatConnect Threat Intelligence Platform (TIP)?
Our main use case for ThreatConnect Threat Intelligence Platform (TIP) is to centralize, analyze, and operationalize threat intelligence across our organization. We use it to aggregate threat data ...
 

Also Known As

RSA Security Analytics
No data available
 

Interactive Demo

Demo not available
 

Overview

 

Sample Customers

Los Angeles World Airports, Reply
Customer Case Studies & Use Cases
Find out what your peers are saying about Wazuh, Splunk, Cribl and others in Log Management. Updated: March 2026.
885,667 professionals have used our research since 2012.