Try our new research platform with insights from 80,000+ expert users

NetWitness Platform vs Symantec Advanced Threat Protection comparison

 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

NetWitness Platform
Average Rating
7.4
Reviews Sentiment
7.4
Number of Reviews
37
Ranking in other categories
Log Management (37th), Security Information and Event Management (SIEM) (29th)
Symantec Advanced Threat Pr...
Average Rating
7.8
Reviews Sentiment
7.1
Number of Reviews
16
Ranking in other categories
Advanced Threat Protection (ATP) (18th)
 

Mindshare comparison

NetWitness Platform and Symantec Advanced Threat Protection aren’t in the same category and serve different purposes. NetWitness Platform is designed for Log Management and holds a mindshare of 0.3%, down 0.4% compared to last year.
Symantec Advanced Threat Protection, on the other hand, focuses on Advanced Threat Protection (ATP), holds 2.0% mindshare, down 2.1% since last year.
Log Management
Advanced Threat Protection (ATP)
 

Featured Reviews

MOTASHIM Al Razi - PeerSpot reviewer
It is a stable solution, but they should make the user interface easier to understand
The solution's initial setup takes work. We have to organize multiple paths and many features. The deployment process takes less than a week. But it takes a month to complete if we want to make the solution smarter by integrating it with various devices. I rate the process as a six out of ten.
TapabrataSamanta - PeerSpot reviewer
Reliable platform with effective integration capabilities
Our primary use case for the product is to provide advanced threat protection to our clients, primarily in the banking and financial sectors Symantec ATP has been beneficial in ensuring robust security for our clients. Its effectiveness in detecting and mitigating threats has improved customer…

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"Setting up NetWitness is straightforward. There are multiple connectors, including standard and specialized connectors. One purpose of the connectors is the enhanced capability integrate the custom applications. NetWitness comes with E6 appliances and application images that we use for the initial configurations and for the OS stack information. From there, you can consider the correlation rules, integrate the different log sources, and easily create correlation rules and backlog reports."
"The most valuable feature is the hunting ability to work in a CERT."
"The product has a user-friendly interface and a valuable feature for threat intelligence integration."
"The most valuable features are the threat prediction and network forensics."
"The most valuable feature of RSA NetWitness Logs and Packets are the alerts and correlations tools."
"It's quite economical compared to other solutions in the market."
"The most valuable feature is the ability to write rules and triggers for network communication, and then being able to investigate based on that."
"The packet capture aspect of it is a valuable feature because it is quite different from a traditional SIEM solution that only carries out investigations based on captured logs."
"The Application Control code and the easy integration are valuable features."
"Currently we have 800-plus nodes connected with this solution, without any issues. The solution is scalable."
"What I like most about Symantec Advanced Threat Protection is its notification capability."
"Technical support is very responsive. You just have to open a ticket. They respond in a timely manner. Their response is good. I'm satisfied."
"You don't have to buy a separate email security platform. You can enable that using their endpoint, and I like that. You don't have to have two agents running on the same box."
"Endpoint to network protects the line."
"They manage to solve detection quite nicely. There is some rather elaborate detection compared to other providers."
"Technical support has been helpful and responsive."
 

Cons

"More customizability is required, which is something that they need to improve on."
"The product's licensing models are complex to understand. This particular area needs improvement."
"Security needs improvement."
"There are instances where you try to run the reports and then it does not give you the desired outcome."
"An area for improvement would be better automation and more inbuilt use cases."
"Health monitoring of the event sources and devices."
"I believe that integrating the solution with other products such as Oracle would be beneficial."
"Its technical support could be better."
"Not ideal for advanced threat protection."
"Scalability could be better."
"An improvement could be made on the reporting because then it would be easier to collect information and submit it for compliance."
"It should be able to collect information if the agent is disabled."
"It also needs network-based threat protection for shared folders and files."
"The support for new OSs and older OSs could be a little tighter. They need to be more upfront about what protection services they're going to provide on new OSs. I haven't seen the Windows 11 version out yet. It is either already released in Beta, or the Beta will be released soon. There could be a little bit more advanced updates on what they're doing to help protect Windows 11 environments. They can let us know in advance so that we know it is going to be protected. We can't roll out the new OS without putting end-point protection on it. So, they should tell us what is their support model for that, and what are they doing to protect Windows 11. They're not telling me, and that's a criticism. The same issue is applicable to all the other antivirus tools. It is not just Symantec; all of them have this problem."
"They could enhance the solution to work across all devices, including Android, iOS, and Mac, and make it more user-friendly."
"Entire threat protection is not available for the advanced features."
 

Pricing and Cost Advice

"We are on an annual license for the use of the solution."
"It is cheap."
"We have yearly licensing costs. The license fee can be based on the volume of EPS. Some organizations may have, as a gentlemanly gesture, 10,000 EPS and get a 3,000 EPS license but actually use 5,000 EPS."
"Many clients are not able to purchase the packet capability because there is a huge amount of data, and the cost depends on the number of EPS (Events per second), as well as the number of gigabytes of data per day."
"There is a licensing fee and the customer can choose whether he wishes this to be subscription-based or perpetual."
"The licenses are good but the cost is very expensive."
"RSA NetWitness Logs and Packets do not have a subscription model, it's a one-time purchase. There is only a perpetual license."
"Compared to the competition, the is price is not that high."
"Pricing is good. It is nice to have a great product at a fair price."
"Symantec Advanced Threat Protection's pricing is comparable."
"Symantec Endpoint Protection has an average price."
"The pricing of this solution is inexpensive and affordable."
"The price is quite expensive."
report
Use our free recommendation engine to learn which Log Management solutions are best for your needs.
861,481 professionals have used our research since 2012.
 

Comparison Review

VS
Feb 26, 2015
HP ArcSight vs. IBM QRadar vs. ​McAfee Nitro vs. Splunk vs. RSA Security vs. LogRhythm
We at Infosecnirvana.com have done several posts on SIEM. After the Dummies Guide on SIEM, we are following it up with a SIEM Product Comparison – 101 deck. So, here it is for your viewing pleasure. Let me know what you think by posting your comments below. The key products compared here are…
 

Top Industries

By visitors reading reviews
Financial Services Firm
17%
Computer Software Company
17%
Manufacturing Company
5%
Real Estate/Law Firm
5%
Educational Organization
38%
Financial Services Firm
12%
Manufacturing Company
7%
Computer Software Company
5%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

What do you like most about NetWitness Platform?
The product's initial setup phase was not at all difficult.
What is your experience regarding pricing and costs for NetWitness Platform?
The pricing is comparable to others, and I consider the cost to be intermediate. Specific cost details are unknown to me.
What needs improvement with NetWitness Platform?
There is currently no need for improvement in the SIEM ( /categories/security-information-and-event-management-siem ), though there could be potential enhancements by integrating with AI.
What do you like most about Symantec Advanced Threat Protection?
Symantec Endpoint Protection provides end-to-end protection. Along with antivirus protection, it has a lot of key areas, including intrusive prevention, firewall features, and application and devic...
What is your experience regarding pricing and costs for Symantec Advanced Threat Protection?
The price is quite expensive because a different entity has taken over the company.
What needs improvement with Symantec Advanced Threat Protection?
One area for improvement could be the pricing model. Future releases could further enhance integration capabilities with other platforms and simplify the licensing model to compete more with Micros...
 

Also Known As

RSA Security Analytics
No data available
 

Overview

 

Sample Customers

Los Angeles World Airports, Reply
ECI
Find out what your peers are saying about NetWitness Platform vs. Symantec Advanced Threat Protection and other solutions. Updated: September 2022.
861,481 professionals have used our research since 2012.