Try our new research platform with insights from 80,000+ expert users

NetWitness Platform vs VMware Aria Operations for Logs comparison

 

Comparison Buyer's Guide

Executive SummaryUpdated on Oct 9, 2024

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

NetWitness Platform
Ranking in Log Management
38th
Average Rating
7.4
Reviews Sentiment
7.4
Number of Reviews
37
Ranking in other categories
Security Information and Event Management (SIEM) (29th)
VMware Aria Operations for ...
Ranking in Log Management
12th
Average Rating
8.2
Reviews Sentiment
6.4
Number of Reviews
28
Ranking in other categories
No ranking in other categories
 

Mindshare comparison

As of June 2025, in the Log Management category, the mindshare of NetWitness Platform is 0.3%, down from 0.4% compared to the previous year. The mindshare of VMware Aria Operations for Logs is 1.3%, up from 1.2% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Log Management
 

Featured Reviews

MOTASHIM Al Razi - PeerSpot reviewer
It is a stable solution, but they should make the user interface easier to understand
The solution's initial setup takes work. We have to organize multiple paths and many features. The deployment process takes less than a week. But it takes a month to complete if we want to make the solution smarter by integrating it with various devices. I rate the process as a six out of ten.
LarsChristensen - PeerSpot reviewer
Efficient troubleshooting with precise log filtering and an easy setup
The tool could benefit from improved filter settings and dashboarding. While there are dashboards available, they are often created by community members and may not work after updates. It would be beneficial to have a roadmap for these dashboards to ensure consistent functionality. It would also be advantageous if the tool could process even large amounts of data faster, though this may be more related to data movement challenges rather than the software itself.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"The product has a user-friendly interface and a valuable feature for threat intelligence integration."
"The most valuable feature is the security that it provides."
"Setting up NetWitness is straightforward. There are multiple connectors, including standard and specialized connectors. One purpose of the connectors is the enhanced capability integrate the custom applications. NetWitness comes with E6 appliances and application images that we use for the initial configurations and for the OS stack information. From there, you can consider the correlation rules, integrate the different log sources, and easily create correlation rules and backlog reports."
"Performance and reporting are very good."
"NetWitness Platform offers flexibility for deployment and robust integration capabilities."
"The software is scalable to whatever is required, and you can also put a lot of resources in the cloud."
"The newer 11.5 version that my team is using has found it to have good mapping."
"Alerting Module: It provides real-time event processing language on all the logs/packets stream for advanced alerting, i.e., using SQL LIKE statements."
"The tool helps my company deal with security and log analysis, which are very important areas for us...It is a scalable solution."
"What I like is that you can have different storage locations for different applications."
"Overall, I would recommend VMware Aria Operations for Logs because it is a good tool with many valuable features."
"It allows us to gain a comprehensive overview of our infrastructure."
"VMware Aria Operations for Logs is a very stable product."
"It is a very useful tool if you have a VMware environment."
"It is very scalable and can handle a large workload."
"We are using it because we have a VMware product. It has its own built in dashboards for VMware products, and that's a good thing."
 

Cons

"The initial setup is very complex and should be simplified."
"Log aggregation is an issue with this solution because there are a huge number of alerts in a single instance."
"Lots of competing products have vulnerability protection built into their products, and this solution would be improved by including that support."
"I believe that integrating the solution with other products such as Oracle would be beneficial."
"I'd like to see improvement in its ease of use. It's basically unusable. It's overly complex."
"The initial setup was complex because it takes a lot of time to complete the implementation."
"The product's licensing models are complex to understand. This particular area needs improvement."
"If we have the ability to run a dynamic analysis through malware in the same suite, it would be great to have a sandbox solution to analyze malware through dynamic analysis."
"I don't use the solution on a day to day basis, so I'm not sure what specifically can be improved."
"If data migration occurs during a search, it alters performance, causing delays."
"The monitoring landscape is getting bigger. When it comes to infrastructure monitoring, we need more visibility. VMware needs to integrate more related applications and third-party products. That would make it more appealing to an audience beyond the VMware team."
"What I'd like to improve in vRealize Log Insight is the licensing model. VMware provides vRealize Log Insight along with the VMware Cloud Foundation, but customers who would like to go for the native VMware would have to procure vRealize Log Insight separately. Today, vRealize Log Insight is offered on two different licenses, one is based on the number of VMs, and the other is based on the number of physical codes on the machine. If VMware can provide a bundle offer for customers who procure more than ten licenses, where you can have an option to run, for example, three hundred machines on vRealize Log Insight with no extra cost, this would encourage more people to adopt the solution. What I'd like to see in the next release of vRealize Log Insight is for a cloud option to be available, which would be a pay-as-you-go licensing model that would allow me to pick and choose what I'll monitor. For example, I have one thousand and three hundred critical servers, and the seven hundred servers for basic development, I don't want to monitor on vRealize Log Insight today, so I should be able to pick what I need to monitor on the solution and only pay for that specific instance. If VMware can apply these changes, it would help VMware customers to procure more or adopt more of vRealize Log Insight even in smaller projects."
"The solution should be more user-friendly. The user interface and dashboard could be simplified."
"Paid or free does not matter, but it is complex to find good training material for vRealize Log Insight."
"The pricing of the solution could be improved."
"The tool is expensive."
 

Pricing and Cost Advice

"The NetWitness Platform may be affordable only for enterprise-level customers, as it may not be within the budget of small and medium-sized businesses."
"The product price was reasonable for my region and the market."
"In comparison to other SIEM solutions such as Splunk, NetWitness is less costly."
"The product is expensive."
"RSA NetWitness Logs and Packets do not have a subscription model, it's a one-time purchase. There is only a perpetual license."
"The licenses are good but the cost is very expensive."
"Many clients are not able to purchase the packet capability because there is a huge amount of data, and the cost depends on the number of EPS (Events per second), as well as the number of gigabytes of data per day."
"It is cheap."
"The license cost for any other monitoring tool is too high compared to this product."
"I think it is a reasonably priced product."
"Pricing could always be lower. If it were free, I would be more satisfied."
"I am not sure what the exact cost is. However, I believe the vRealize suite costs $2,500.00 per year."
"The pricing has been updated recently."
"The product's price is reasonable, but when it comes to SQL licensing, it's a bit expensive."
"It is not cheap. But it is worth it."
"Pricing is good because it is part of the suite package. It comes in a bundle for us."
report
Use our free recommendation engine to learn which Log Management solutions are best for your needs.
859,129 professionals have used our research since 2012.
 

Comparison Review

VS
Feb 26, 2015
HP ArcSight vs. IBM QRadar vs. ​McAfee Nitro vs. Splunk vs. RSA Security vs. LogRhythm
We at Infosecnirvana.com have done several posts on SIEM. After the Dummies Guide on SIEM, we are following it up with a SIEM Product Comparison – 101 deck. So, here it is for your viewing pleasure. Let me know what you think by posting your comments below. The key products compared here are…
 

Top Industries

By visitors reading reviews
Computer Software Company
18%
Financial Services Firm
18%
Government
5%
Manufacturing Company
5%
Computer Software Company
15%
Financial Services Firm
12%
Government
12%
Manufacturing Company
8%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

What do you like most about NetWitness Platform?
The product's initial setup phase was not at all difficult.
What is your experience regarding pricing and costs for NetWitness Platform?
The pricing is comparable to others, and I consider the cost to be intermediate. Specific cost details are unknown to me.
What needs improvement with NetWitness Platform?
There is currently no need for improvement in the SIEM ( /categories/security-information-and-event-management-siem ), though there could be potential enhancements by integrating with AI.
What do you like most about vRealize Log Insight?
The events are notably more descriptive, aiding in security and event analysis. We've also integrated Sky Collector, providing valuable insights and solutions for troubleshooting.
What is your experience regarding pricing and costs for vRealize Log Insight?
The cost of using VMware Aria Operations for Logs was very high, around two to three million dollars, although the exact figure is uncertain. The price was proving to be too much, especially with t...
What needs improvement with vRealize Log Insight?
VMware Aria Operations for Logs is not a cost-effective tool. Changing any telemetry requires creating a new template, such as changes to the VM disk size. Always having to create a new template ma...
 

Also Known As

RSA Security Analytics
vRealize Log Insight
 

Overview

 

Sample Customers

Los Angeles World Airports, Reply
Wildlands Adventure Zoo, Medic Mobile, IBM, Seventy Seven Energy, Baystate Health, Osis, Oxford University, Columbia University, Siemens, Cardinal Health, Ashdod Port, Vasakronan, Sydney Adventist Hospital, University of Derby
Find out what your peers are saying about NetWitness Platform vs. VMware Aria Operations for Logs and other solutions. Updated: June 2025.
859,129 professionals have used our research since 2012.