Try our new research platform with insights from 80,000+ expert users

Pros & Cons summary

Buyer's Guide

Get pricing advice, tips, use cases and valuable features from real users of this product.
Get the report

Prominent pros & cons

PROS

Technical support for NetWitness NDR is very good, helping resolve issues effectively.
NetWitness NDR captures traffic comprehensively, detailing every aspect of the communication.
It allows for real-time malware detection.
Recent updates include instant threat response and enhanced integration features.
NetWitness NDR offers strong log correlation and stability.

CONS

The price and training costs of NetWitness NDR are high and could be improved.
There are issues with the deployment process, causing unexpected stops and log passing challenges.
RSA NetWitness Endpoint's blocking feature does not work properly for malicious processes.
Threat detection and threat intelligence in NetWitness NDR need enhancements.
There is a need for better integration with non-native applications and improved overall integration.
 

NetWitness NDR Pros review quotes

AA
Account Manager at a tech services company with 11-50 employees
Jul 4, 2018
It helps our security team respond more accurately when there are threats, then we get less false positives or negatives.
it_user629541 - PeerSpot reviewer
Security Consultant at a tech services company with 10,001+ employees
Nov 6, 2018
It is stable. We have been using it for some time, without any issues.
reviewer1259418 - PeerSpot reviewer
Senior Cyber Security Analyst (SAFe Agile) at a transportation company with 1,001-5,000 employees
Jan 16, 2020
We've contacted technical support several times. They've been very good. They have been able to help us resolve our issues.
Learn what your peers think about NetWitness NDR. Get advice and tips from experienced pros sharing their opinions. Updated: December 2025.
879,259 professionals have used our research since 2012.
reviewer973458 - PeerSpot reviewer
CEO & Founder at a tech services company with 1-10 employees
Feb 2, 2020
The most valuable feature is the way it captures the traffic, and it contains every detail of the communication.
TM
Senior Cybersecurity Consultant at CIA Botswana
Nov 9, 2020
This solution allows us to locate the malware in real-time.
MM
Security Consultant at Global Solutions
Mar 5, 2021
It is very easy to use, and its usability is great. The use cases are also very easy. The visualizations of the use cases are magnificent. You cannot find this in any other solution. From my point of view, it is great.
reviewer1724928 - PeerSpot reviewer
Manager, Soc
Nov 23, 2021
The log correlation is good.
HananSyed - PeerSpot reviewer
Cyber Security Consultant at Mideast Data Systems
Apr 25, 2022
The stability of the RSA NetWitness Endpoint is very good.
reviewer1110027 - PeerSpot reviewer
Security Information & Incident Analyst at a financial services firm with 1,001-5,000 employees
May 21, 2022
Ability to isolate the machine when there are malicious files.
SupravatMaji - PeerSpot reviewer
Associate Vice President - IT Security at Inspira Enterprise
Jun 23, 2022
The most valuable feature of RSA NetWitness Network is the single unified dashboard from which you can manage all the different products of RSA. Additionally, the integration with native applications is good.
 

NetWitness NDR Cons review quotes

AA
Account Manager at a tech services company with 11-50 employees
Jul 4, 2018
The initial setup requires a high level of skill.
it_user629541 - PeerSpot reviewer
Security Consultant at a tech services company with 10,001+ employees
Nov 6, 2018
This solution needs an upgrade in reporting. I have heard from RSA that they are working on this, but as of yet it is not available.
reviewer1259418 - PeerSpot reviewer
Senior Cyber Security Analyst (SAFe Agile) at a transportation company with 1,001-5,000 employees
Jan 16, 2020
The contamination feature could be improved.
Learn what your peers think about NetWitness NDR. Get advice and tips from experienced pros sharing their opinions. Updated: December 2025.
879,259 professionals have used our research since 2012.
reviewer973458 - PeerSpot reviewer
CEO & Founder at a tech services company with 1-10 employees
Feb 2, 2020
When analyzing something, you have to click several times. It requires a lot of effort to find something.
TM
Senior Cybersecurity Consultant at CIA Botswana
Nov 9, 2020
I would like to see Security Orchestration and Response Automation (SOAR) integration.
MM
Security Consultant at Global Solutions
Mar 5, 2021
Its price could be improved. It is an expensive product. Its training is also too expensive. It would be great if they can have a better pricing scheme for the training.
reviewer1724928 - PeerSpot reviewer
Manager, Soc
Nov 23, 2021
The deployment process is complex. I don't know why, but this solution will suddenly stop working. Logs stop coming. Often, one thing or another stops working. Most of the time, one of my team members is working with troubleshooting and working with technical support. Log passing is also one of the biggest challenge.
HananSyed - PeerSpot reviewer
Cyber Security Consultant at Mideast Data Systems
Apr 25, 2022
The threat intelligence could improve in RSA NetWitness Endpoint.
reviewer1110027 - PeerSpot reviewer
Security Information & Incident Analyst at a financial services firm with 1,001-5,000 employees
May 21, 2022
The solution lacks a reporting engine.
SupravatMaji - PeerSpot reviewer
Associate Vice President - IT Security at Inspira Enterprise
Jun 23, 2022
RSA NetWitness Network could improve on integration with non-native application integration.