Try our new research platform with insights from 80,000+ expert users

NetWitness Platform vs Symantec Advanced Threat Protection comparison

 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

NetWitness Platform
Average Rating
7.4
Reviews Sentiment
7.4
Number of Reviews
36
Ranking in other categories
Log Management (33rd), Security Information and Event Management (SIEM) (30th)
Symantec Advanced Threat Pr...
Average Rating
7.8
Reviews Sentiment
7.1
Number of Reviews
16
Ranking in other categories
Advanced Threat Protection (ATP) (19th)
 

Mindshare comparison

NetWitness Platform and Symantec Advanced Threat Protection aren’t in the same category and serve different purposes. NetWitness Platform is designed for Log Management and holds a mindshare of 0.4%, up 0.3% compared to last year.
Symantec Advanced Threat Protection, on the other hand, focuses on Advanced Threat Protection (ATP), holds 2.0% mindshare, up 2.0% since last year.
Log Management Market Share Distribution
ProductMarket Share (%)
NetWitness Platform0.4%
Wazuh12.2%
Grafana Loki7.9%
Other79.5%
Log Management
Advanced Threat Protection (ATP) Market Share Distribution
ProductMarket Share (%)
Symantec Advanced Threat Protection2.0%
Palo Alto Networks WildFire10.7%
Microsoft Defender for Endpoint9.0%
Other78.3%
Advanced Threat Protection (ATP)
 

Featured Reviews

MOTASHIM Al Razi - PeerSpot reviewer
It is a stable solution, but they should make the user interface easier to understand
The solution's initial setup takes work. We have to organize multiple paths and many features. The deployment process takes less than a week. But it takes a month to complete if we want to make the solution smarter by integrating it with various devices. I rate the process as a six out of ten.
TapabrataSamanta - PeerSpot reviewer
Reliable platform with effective integration capabilities
Our primary use case for the product is to provide advanced threat protection to our clients, primarily in the banking and financial sectors Symantec ATP has been beneficial in ensuring robust security for our clients. Its effectiveness in detecting and mitigating threats has improved customer…

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"What we are mainly using are the RSA concentrator, RSA Decoder, Archiver, Broker, and Log Decoder."
"It's quite economical compared to other solutions in the market."
"NetWitness Platform is valuable for creating rules that the solution must detect."
"I can have enterprise security, email security, next generation firewall security log, HIDS and NIDS logs, etc. all on the same dashboard. It makes it easy to pinpoint or correlate our server to this. I can find out if there is lateral movement. This is the biggest advantage of this solution."
"NetWitness can be highly beneficial for incident detection and response."
"In my opinion, the solution's most valuable feature is its capacity to monitor network traffic, logs from devices within the network, and network captures. This capability extends beyond logs to include full network capturing."
"The most valuable feature is the security that it provides."
"The most valuable features are the threat prediction and network forensics."
"Real-time threat analysis is quick and takes action on threats immediately."
"The most valuable feature is Click-time URL protection."
"The technical support services are excellent."
"Technical support is very responsive. You just have to open a ticket. They respond in a timely manner. Their response is good. I'm satisfied."
"Endpoint to network protects the line."
"All of the solution's features are quite valuable for us. We especially like the threat protection it provides."
"What I like most about Symantec Advanced Threat Protection is its notification capability."
"Symantec Endpoint Protection provides end-to-end protection. Along with antivirus protection, it has a lot of key areas, including intrusive prevention, firewall features, and application and device control."
 

Cons

"Log aggregation is an issue with this solution because there are a huge number of alerts in a single instance."
"Its technical support could be better."
"The log system is a bit complex and has room for improvement."
"The solution should have more integration capabilities with different platforms."
"RSA NetWitness Logs and Packets can improve the threat level aspect, it is lacking compared to other solutions. Whenever any hacking activity or any other threat factor occurred they used to provide the coverages very fast when comparing RSA NetWitness Logs and Packets. I heard the other three solutions, from a discussion with my team members who had experience in other solutions, they used to say that. Whenever any issues happened across the globe RSA NetWitness Logs and Packets are a little bit slow improving those detection mechanisms."
"The multi-tenant capabilities are lagging compared to IBM QRadar."
"The documentation is not as structured as I would like, personally, and I think that it can be improved and made much more user-friendly."
"It is not so easy to customize this product."
"The product's support services need improvement."
"They could enhance the solution to work across all devices, including Android, iOS, and Mac, and make it more user-friendly."
"The administration interface needs a lot of improvement. It should be UI based, and simple. They need to improve it. It's pretty much not that friendly compared to what we were using as Bitdefender before. It's okay but is improving, actually."
"It should be able to collect information if the agent is disabled."
"The support has dropped down to a five out of ten."
"There are limits with respect to blocking files by hash value or blocking IP addresses, and these limits should be removed."
"It also needs network-based threat protection for shared folders and files."
"Entire threat protection is not available for the advanced features."
 

Pricing and Cost Advice

"Many clients are not able to purchase the packet capability because there is a huge amount of data, and the cost depends on the number of EPS (Events per second), as well as the number of gigabytes of data per day."
"We have a perpetual license, so the total cost of ownership is not very expensive. It's a good investment."
"It’s cheaper to run virtual machines in a VMware environment."
"Our license is for one year."
"The licenses are good but the cost is very expensive."
"It is cheap."
"There is a licensing fee and the customer can choose whether he wishes this to be subscription-based or perpetual."
"The product price was reasonable for my region and the market."
"Symantec Endpoint Protection has an average price."
"Pricing is good. It is nice to have a great product at a fair price."
"Symantec Advanced Threat Protection's pricing is comparable."
"The price is quite expensive."
"The pricing of this solution is inexpensive and affordable."
report
Use our free recommendation engine to learn which Log Management solutions are best for your needs.
871,469 professionals have used our research since 2012.
 

Comparison Review

VS
Feb 26, 2015
HP ArcSight vs. IBM QRadar vs. ​McAfee Nitro vs. Splunk vs. RSA Security vs. LogRhythm
We at Infosecnirvana.com have done several posts on SIEM. After the Dummies Guide on SIEM, we are following it up with a SIEM Product Comparison – 101 deck. So, here it is for your viewing pleasure. Let me know what you think by posting your comments below. The key products compared here are…
 

Top Industries

By visitors reading reviews
Financial Services Firm
13%
Computer Software Company
11%
Comms Service Provider
7%
Performing Arts
7%
Financial Services Firm
10%
University
10%
Manufacturing Company
9%
Government
6%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business8
Midsize Enterprise7
Large Enterprise20
By reviewers
Company SizeCount
Small Business9
Midsize Enterprise3
Large Enterprise13
 

Questions from the Community

What do you like most about NetWitness Platform?
The product's initial setup phase was not at all difficult.
What is your experience regarding pricing and costs for NetWitness Platform?
The pricing is comparable to others, and I consider the cost to be intermediate. Specific cost details are unknown to me.
What needs improvement with NetWitness Platform?
There is currently no need for improvement in the SIEM ( /categories/security-information-and-event-management-siem ), though there could be potential enhancements by integrating with AI.
What do you like most about Symantec Advanced Threat Protection?
Symantec Endpoint Protection provides end-to-end protection. Along with antivirus protection, it has a lot of key areas, including intrusive prevention, firewall features, and application and devic...
What is your experience regarding pricing and costs for Symantec Advanced Threat Protection?
The price is quite expensive because a different entity has taken over the company.
What needs improvement with Symantec Advanced Threat Protection?
One area for improvement could be the pricing model. Future releases could further enhance integration capabilities with other platforms and simplify the licensing model to compete more with Micros...
 

Also Known As

RSA Security Analytics
No data available
 

Overview

 

Sample Customers

Los Angeles World Airports, Reply
ECI
Find out what your peers are saying about NetWitness Platform vs. Symantec Advanced Threat Protection and other solutions. Updated: September 2022.
871,469 professionals have used our research since 2012.