Try our new research platform with insights from 80,000+ expert users

NetWitness Platform vs VMware Aria Operations for Logs comparison

 

Comparison Buyer's Guide

Executive SummaryUpdated on Oct 9, 2024

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

NetWitness Platform
Ranking in Log Management
34th
Average Rating
7.4
Reviews Sentiment
7.4
Number of Reviews
36
Ranking in other categories
Security Information and Event Management (SIEM) (31st)
VMware Aria Operations for ...
Ranking in Log Management
19th
Average Rating
8.2
Reviews Sentiment
6.4
Number of Reviews
28
Ranking in other categories
No ranking in other categories
 

Mindshare comparison

As of January 2026, in the Log Management category, the mindshare of NetWitness Platform is 0.6%, up from 0.3% compared to the previous year. The mindshare of VMware Aria Operations for Logs is 1.5%, up from 1.1% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Log Management Market Share Distribution
ProductMarket Share (%)
VMware Aria Operations for Logs1.5%
NetWitness Platform0.6%
Other97.9%
Log Management
 

Featured Reviews

MOTASHIM Al Razi - PeerSpot reviewer
CISO at One Bank Limited
It is a stable solution, but they should make the user interface easier to understand
The solution's initial setup takes work. We have to organize multiple paths and many features. The deployment process takes less than a week. But it takes a month to complete if we want to make the solution smarter by integrating it with various devices. I rate the process as a six out of ten.
reviewer2668767 - PeerSpot reviewer
Cloud Solution Engineer at a comms service provider with 10,001+ employees
Dashboard personalization enhances troubleshooting capabilities
A valuable feature of VMware Aria Operations for Logs is its ability to allow personalization of dashboards and requests. This personalization capability is crucial because it helps tailor the tool to specific needs. It also has many effective features for log analysis, making it a competent tool despite not having a comprehensive comparison with other tools.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"The most valuable features are the threat prediction and network forensics."
"Their technical support responds quickly and are knowledgable."
"What we are mainly using are the RSA concentrator, RSA Decoder, Archiver, Broker, and Log Decoder."
"The solution is really scalable for the high-end power, enterprise customer."
"NetWitness can be highly beneficial for incident detection and response."
"The product's initial setup phase was not at all difficult."
"Performance and reporting are very good."
"Alerting Module: It provides real-time event processing language on all the logs/packets stream for advanced alerting, i.e., using SQL LIKE statements."
"It allows us to gain a comprehensive overview of our infrastructure."
"Log Insight correlates with the VMware product log. It can assemble the logs you want, making it easier to find the output, incident, or keyword you want to search."
"The ability to narrow into a specific time to filter heavy hitters and anomalies is extremely valuable."
"I like the interface."
"The trace log is the solution's most valuable feature. It's very helpful in troubleshooting problems."
"The most valuable features are log centralization and long-term retention for logs."
"It is a highly stable solution...It is a highly scalable solution."
"One of the most valuable features of vRealize Log Insight is that it gives you a clear forecast about your existing machines, for example, how long your machines could be supported and how long the remaining capacity is to host your machines. This is one of the best options available within vRealize Log Insight. Another valuable feature of the solution is automation. My company deploys a lot of automation when required in a very, very short period, and in a very uniform manner, and even if the automation is being deployed for different processes and departments, it's pretty much the same across the environment, so vRealize Log Insight helps reduce a lot of ambiguities and helps my company manage operational efficiencies well."
 

Cons

"The system looks like it is a mix of a bunch of different systems, and nothing looked like it was quite together."
"They should implement algorithms to digest that data and produce additional, more advanced reporting, alerting and support of internal security teams."
"Technical support could be improved."
"It should have a monitoring feature. It would help us analyze the current state of attacks faster from a single platform."
"Log aggregation is an issue with this solution because there are a huge number of alerts in a single instance."
"The product's licensing models are complex to understand. This particular area needs improvement."
"RSA NetWitness Logs and Packets can improve the threat level aspect, it is lacking compared to other solutions. Whenever any hacking activity or any other threat factor occurred they used to provide the coverages very fast when comparing RSA NetWitness Logs and Packets. I heard the other three solutions, from a discussion with my team members who had experience in other solutions, they used to say that. Whenever any issues happened across the globe RSA NetWitness Logs and Packets are a little bit slow improving those detection mechanisms."
"I believe that integrating the solution with other products such as Oracle would be beneficial."
"It's great for VMware, but it would be good if they had third-party logins."
"The response time and quality need improvement. It takes too long to prove a problem and get a solution."
"The product's price falls on the higher end of the spectrum, making it an area of concern."
"I think that it should be able to integrate with other third-party backup and recovery solutions, more that it does now."
"The solution should be more user-friendly. The user interface and dashboard could be simplified."
"The solution is a very good tool, but it has a lot of limitations. One of the main issues is around how you define your retention policy, for instance, in Log Insight. It doesn't have it. You can't define a log retention policy. You also can't define the destination or location for your logs. All of the logs are in one index or one bucket."
"The tool could be cheaper."
"What I'd like to improve in vRealize Log Insight is the licensing model. VMware provides vRealize Log Insight along with the VMware Cloud Foundation, but customers who would like to go for the native VMware would have to procure vRealize Log Insight separately. Today, vRealize Log Insight is offered on two different licenses, one is based on the number of VMs, and the other is based on the number of physical codes on the machine. If VMware can provide a bundle offer for customers who procure more than ten licenses, where you can have an option to run, for example, three hundred machines on vRealize Log Insight with no extra cost, this would encourage more people to adopt the solution. What I'd like to see in the next release of vRealize Log Insight is for a cloud option to be available, which would be a pay-as-you-go licensing model that would allow me to pick and choose what I'll monitor. For example, I have one thousand and three hundred critical servers, and the seven hundred servers for basic development, I don't want to monitor on vRealize Log Insight today, so I should be able to pick what I need to monitor on the solution and only pay for that specific instance. If VMware can apply these changes, it would help VMware customers to procure more or adopt more of vRealize Log Insight even in smaller projects."
 

Pricing and Cost Advice

"The new pricing and licensing mechanisms are fair. I would advise always to get the full solution (i.e., not only Logs)."
"There is a licensing fee and the customer can choose whether he wishes this to be subscription-based or perpetual."
"In comparison to other SIEM solutions such as Splunk, NetWitness is less costly."
"The tool is very expensive, so I rate the pricing a ten out of ten. The solution has an annual subscription."
"It’s cheaper to run virtual machines in a VMware environment."
"The product price was reasonable for my region and the market."
"Many clients are not able to purchase the packet capability because there is a huge amount of data, and the cost depends on the number of EPS (Events per second), as well as the number of gigabytes of data per day."
"The NetWitness Platform may be affordable only for enterprise-level customers, as it may not be within the budget of small and medium-sized businesses."
"The licensing cost for vRealize Log Insight is a little higher, so in terms of cost, it all depends upon what kind of environment you have. If you have a complete virtualized environment, or at least you're using a ninety-five percent virtualized environment, then vRealize Log Insight will play a very good role because it is a VMware component, so it has very tight integration with other VMware components and systems. This means you don't have to procure any other monitoring and management tool, and you don't need a separate automation tool. vRealize Log Insight will have an upper hand if your environment is purely virtualized on VMware. If you're using a mix of physical and virtual components, for example, a 50:50 ratio, then you need to have a third-party component to manage overall monitoring."
"I rate the product's price a six on a scale of one to ten, where one is cheap, and ten is expensive."
"Pricing could always be lower. If it were free, I would be more satisfied."
"I am not sure what the exact cost is. However, I believe the vRealize suite costs $2,500.00 per year."
"The license cost for any other monitoring tool is too high compared to this product."
"I think it is a reasonably priced product."
"It is not cheap. But it is worth it."
"The pricing has been updated recently."
report
Use our free recommendation engine to learn which Log Management solutions are best for your needs.
881,082 professionals have used our research since 2012.
 

Comparison Review

VS
Manager, Enterprise Risk Consulting at a tech company with 1,001-5,000 employees
Feb 26, 2015
HP ArcSight vs. IBM QRadar vs. ​McAfee Nitro vs. Splunk vs. RSA Security vs. LogRhythm
We at Infosecnirvana.com have done several posts on SIEM. After the Dummies Guide on SIEM, we are following it up with a SIEM Product Comparison – 101 deck. So, here it is for your viewing pleasure. Let me know what you think by posting your comments below. The key products compared here are…
 

Top Industries

By visitors reading reviews
Financial Services Firm
13%
Performing Arts
9%
Computer Software Company
8%
Manufacturing Company
7%
Government
12%
Financial Services Firm
11%
Computer Software Company
10%
Manufacturing Company
8%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business8
Midsize Enterprise7
Large Enterprise20
By reviewers
Company SizeCount
Small Business7
Midsize Enterprise9
Large Enterprise12
 

Questions from the Community

What do you like most about NetWitness Platform?
The product's initial setup phase was not at all difficult.
What is your experience regarding pricing and costs for NetWitness Platform?
The pricing is comparable to others, and I consider the cost to be intermediate. Specific cost details are unknown to me.
What needs improvement with NetWitness Platform?
There is currently no need for improvement in the SIEM ( /categories/security-information-and-event-management-siem ), though there could be potential enhancements by integrating with AI.
What do you like most about vRealize Log Insight?
The events are notably more descriptive, aiding in security and event analysis. We've also integrated Sky Collector, providing valuable insights and solutions for troubleshooting.
What is your experience regarding pricing and costs for vRealize Log Insight?
The cost of using VMware Aria Operations for Logs was very high, around two to three million dollars, although the exact figure is uncertain. The price was proving to be too much, especially with t...
What needs improvement with vRealize Log Insight?
VMware Aria Operations for Logs is not a cost-effective tool. Changing any telemetry requires creating a new template, such as changes to the VM disk size. Always having to create a new template ma...
 

Also Known As

RSA Security Analytics
vRealize Log Insight
 

Overview

 

Sample Customers

Los Angeles World Airports, Reply
Wildlands Adventure Zoo, Medic Mobile, IBM, Seventy Seven Energy, Baystate Health, Osis, Oxford University, Columbia University, Siemens, Cardinal Health, Ashdod Port, Vasakronan, Sydney Adventist Hospital, University of Derby
Find out what your peers are saying about NetWitness Platform vs. VMware Aria Operations for Logs and other solutions. Updated: December 2025.
881,082 professionals have used our research since 2012.